The General Data Protection Regulation decides when an organisation may process information about an identified or identifiable person in Europe, and what that person can demand once processing has begun. Its formal name is Regulation (EU) 2016/679. It replaced Directive 95/46/EC, a 1995 instrument each member state had transposed in its own way, with a single directly applicable text running to 99 articles and 173 recitals. For advertising the consequence is narrow and severe. Almost every identifier used to target, frequency-cap, measure or attribute a campaign in Europe counts as personal data, and each use of one needs a lawful basis established before the bid request leaves the page.

What counts as personal data, and what makes processing lawful

Article 4(1) defines personal data as any information relating to an identified or identifiable natural person, and names online identifiers explicitly. Cookie IDs, mobile advertising IDs, IP addresses and hashed email addresses all sit inside that definition when they allow a person to be singled out, which is why the regulation reaches into ad tech rather than stopping at customer databases.

Two roles carry the obligations. A controller determines the purposes and means of processing. A processor acts on documented instructions under a contract that Article 28 specifies in detail. Where two parties jointly determine purposes and means, Article 26 makes them joint controllers. Publishers, consent management platforms and the platforms on either side of the auction have spent years arguing over which label attaches where.

Article 6(1) lists six lawful bases: consent, contractual necessity, legal obligation, vital interests, public task and legitimate interests. Advertising runs almost entirely on the first and the last. Recital 47 states that direct marketing may be regarded as carried out for a legitimate interest, a sentence the industry leans on heavily and regulators read narrowly once cross-site profiling is involved.

Consent is a demanding standard here. Article 4(11) requires it to be freely given, specific, informed and unambiguous, expressed through a clear affirmative act. Article 7(3) requires withdrawal to be as easy as giving, and Article 7(4) treats consent as suspect where a service is conditioned on it. Article 9 goes further, prohibiting processing of special category data, including health, political opinions and sexual orientation, unless a listed exemption applies.

Rights sit in Articles 12 to 22: transparency, access, rectification, erasure, restriction, portability and objection. Article 21(2) gives an unconditional right to object to direct marketing, with no balancing test. Article 22 restricts decisions taken solely by automated processing that produce legal or similarly significant effects.

Compliance is documented rather than assumed. Article 5(2) imposes accountability, Article 30 requires records of processing activities, and Article 35 mandates an impact assessment for high-risk processing. Article 33 sets a 72-hour breach notification deadline. Chapter V governs transfers outside the European Economic Area.

Penalties come in two tiers. Article 83(4) caps fines at 10 million euros or 2% of total worldwide annual turnover. Article 83(5) doubles both to 20 million euros or 4%, whichever is higher, for breaches of the principles, the lawful basis rules, data subject rights or transfer restrictions. Article 82 adds a separate route: compensation claims in national courts.

Enforcement is decentralised. Each member state appoints at least one supervisory authority, and Article 56 routes cross-border cases to the regulator where a company holds its main establishment. That mechanism, the one-stop shop, concentrates the largest cases in a few capitals.

Where the rules touch the transaction

In programmatic buying, the legal question resolves into a string of characters. A consent management platform presents choices, encodes them into a TC String under the Transparency and Consent Framework run by IAB Europe, and passes that string into the OpenRTB bid request alongside a flag indicating whether the regulation applies. Downstream vendors read it before deciding whether to bid.

That plumbing has been litigated directly. Belgium's data protection authority found the framework incompatible with Article 6 and fined IAB Europe 250,000 euros in February 2022. The Belgian Market Court later confined that joint controllership to TC String processing rather than downstream OpenRTB operations on 14 May 2025, then annulled the authority's validation of the corrective action plan on 7 January 2026.

A second signal path runs through tag configuration rather than the bidstream. Consent Mode carries the banner decision into Google's measurement and advertising tags, which change what they collect accordingly. One frequently missed distinction: the rule requiring prior consent to store or read information on a device sits in Article 5(3) of the ePrivacy Directive, not in this regulation. The regulation governs what happens to the personal data afterwards.

Origin and evolution

The European Commission proposed the text on 25 January 2012. Parliament and Council adopted it on 27 April 2016, publication in Official Journal L 119 followed on 4 May 2016, and entry into force came on 24 May 2016 with a two-year runway. Application began on 25 May 2018, without national transposition, though member states kept scope to legislate on specific points.

Court of Justice rulings have done much of the shaping since. Fashion ID, decided on 29 July 2019, established joint controller liability for publishers embedding third-party tools. Planet49, on 1 October 2019, killed pre-ticked consent boxes. Schrems I and Schrems II struck down two successive transatlantic transfer frameworks, in October 2015 and July 2020. Case C-252/21 held on 4 July 2023 that consent requirements bite hardest on dominant platforms, and on 4 October 2024 the court applied the data minimisation principle in Article 5(1)(c) to targeted advertising, ruling that personal data cannot be used indefinitely or without distinction as to type even where a user has consented.

Legislative revision came later. The Commission proposed substantial amendments through the Digital Omnibus packageon 19 November 2025: a narrower relative definition of personal data, an explicit legitimate interest basis for artificial intelligence training, and higher breach notification thresholds.

Enforcement and the record so far

National authorities issued 1,145,760,374 euros in fines during 2025, a figure recorded in the European Data Protection Board's annual report of 9 April 2026. Ireland accounted for 530,773,000 euros of that total from a small number of decisions.

Announced totals and collected totals diverge sharply. Analysis published in May 2026 found close to 40% of the 7.1 billion euros in cumulative fines annulled or under challenge. Luxembourg's Administrative Court annulled the 746 million euro penalty against Amazon on 12 March 2026 and remanded the case, without denying the violations. France's Conseil d'Etat went the other way on 4 March 2026, confirming the 40 million euro fine against Criteo in full.

Why it matters for the marketing community

Consent status determines whether an impression sells as personalised or as limited inventory, a gap put at 50% to 70% of revenue in a European market IAB Europe sized at 131.1 billion euros for 2025. Signal quality matters as much as the legal position: a banner that collects choices but fails to transmit them produces the same commercial outcome as a refusal, and conversion tracking has collapsed overnight when that transmission breaks.

The regulation also shapes what platforms may build. Google's move to process IP addresses for measurement and personalisation across the EEA, the United Kingdom and Switzerland from 3 August 2026 required a new framework feature registration before valid consent could be transmitted for it.

Limitations and disputes

Concentration is the most persistent complaint. Because most large American platforms hold their European establishment in Dublin, the one-stop shop hands Ireland an outsized caseload. Privacy group noyb has claimed that only 0.6% of announced Irish fines were ever collected, a criticism it repeated when a former Meta executive was appointed Data Protection Commissioner in September 2025.

Consent-or-pay remains unsettled. The board determined in Opinion 08/2024 that most such models fail the freely given test, Meta filed an annulment action against that opinion on 27 June 2024, and the UK regulator took a more permissive line in January 2025.

The reform package is contested on its own terms. Supervisors rejected key elements of the Digital Omnibus in a joint opinion adopted on 10 February 2026, warning that the proposed personal data amendment would narrow protection rather than simplify compliance. The Council then removed the automated consent signal in Article 88b from its fifth compromise text on 18 June 2026, leaving Parliament as the only route to restore it.

Not the same as

The ePrivacy Directive, 2002/58/EC as amended, carries the device-access consent rule at Article 5(3) and reaches controllers through national law rather than directly. The Digital Markets Act imposes ex ante obligations on designated gatekeepers only, including a consent condition for cross-service data combination that binds nobody else. The Digital Services Act covers advertising transparency and profiling of minors on platforms rather than lawfulness of processing generally. UK GDPR is the domestic instrument retained after Britain left the European Union, and Switzerland runs its own revised act, which makes a single European compliance footprint a commercial convenience rather than a legal category.

Recent developments

Transfers moved back into doubt during 2026. The General Court had upheld the EU-US Data Privacy Framework in the Latombe case on 3 September 2025. Then, after a United States Supreme Court ruling on the removal protections of Federal Trade Commission members, noyb called on the Commission to begin an orderly repeal of the adequacy decisionin a letter dated 30 June 2026, and the board raised its own concerns about the framework in August 2026.

Enforcement scale kept climbing. On 21 August 2026 the Dutch authority imposed a fine of 824,990,000 euros on Uber over fully automated decisions about drivers, an Article 22 case that dwarfs most advertising penalties.

Timeline

  • 24 October 1995: Directive 95/46/EC adopted, harmonising data protection through national transposition
  • 25 January 2012: European Commission proposes the General Data Protection Regulation
  • 27 April 2016: Regulation (EU) 2016/679 adopted by Parliament and Council
  • 4 May 2016: Published in Official Journal L 119
  • 24 May 2016: Entry into force, opening a two-year transition
  • 25 May 2018: Regulation becomes applicable across the European Union
  • 20 July 2018: Extended to the EFTA members of the European Economic Area
  • 29 July 2019: Court of Justice decides Fashion ID on joint controllership
  • 1 October 2019: Planet49 judgment invalidates pre-ticked consent boxes
  • 16 July 2020: Schrems II invalidates the Privacy Shield adequacy decision
  • 2 February 2022: Belgian authority fines IAB Europe 250,000 euros over the consent framework
  • 10 July 2023: Commission adopts the EU-US Data Privacy Framework adequacy decision
  • 4 July 2023: Court of Justice rules on consent and dominant platforms in Case C-252/21
  • 17 April 2024: European Data Protection Board adopts Opinion 08/2024 on consent-or-pay models
  • 4 October 2024: Court of Justice applies data minimisation to targeted advertising
  • 14 May 2025: Belgian Market Court limits IAB Europe's joint controllership to TC String processing
  • 3 September 2025: General Court dismisses the Latombe challenge to the adequacy decision
  • 19 November 2025: Commission publishes the Digital Omnibus package
  • 7 January 2026: Belgian Market Court annuls validation of the framework action plan
  • 10 February 2026: EDPB and EDPS adopt a joint opinion rejecting key Digital Omnibus amendments
  • 4 March 2026: France's Conseil d'Etat confirms the Criteo fine
  • 12 March 2026: Luxembourg's Administrative Court annuls the Amazon fine
  • 9 April 2026: EDPB annual report records 1,145,760,374 euros in 2025 fines
  • 18 June 2026: Council removes Article 88b from its compromise text
  • 3 August 2026: Google begins processing IP addresses for ads across the EEA, UK and Switzerland
  • 21 August 2026: Dutch authority fines Uber 824,990,000 euros under Article 22

Summary

Who: Every controller and processor handling personal data about people in the European Economic Area, policed by national supervisory authorities coordinated through the European Data Protection Board and, for cross-border cases, by the lead authority in the country of main establishment.

What: Regulation (EU) 2016/679, 99 articles setting out lawful bases for processing, a strict consent standard, a prohibition on special category data, eight data subject rights, accountability documentation duties, transfer restrictions, and fines reaching 20 million euros or 4% of worldwide annual turnover.

When: Adopted 27 April 2016, in force since 24 May 2016 and applicable since 25 May 2018. Amendments proposed through the Digital Omnibus on 19 November 2025 remain in negotiation, with the Council position published on 18 June 2026 and Parliament yet to vote.

Where: The 30 states of the European Economic Area, with extraterritorial reach under Article 3 wherever a controller targets or monitors people located in that territory, regardless of where the company sits.

Why: The 1995 directive fragmented across national transpositions and predated the commercial internet. A directly applicable regulation with turnover-based penalties was intended to harmonise the rules and give them force proportionate to the revenue that personal data now generates.