The EU fined Meta $1.3 billion under GDPR in 2023. Amazon was fined $781 million in 2021. Ireland’s DPC fined WhatsApp $267 million. These are not edge cases involving obvious violations — they involve legitimate, well-resourced companies that underestimated compliance complexity. In 2026, privacy compliance is not optional and the cost of getting it wrong is material. This guide covers what GDPR and CCPA actually require, where most organizations fall short, and how to build a program that works.
GDPR in 2026: The Essentials
GDPR applies to any organization processing personal data of EU residents, regardless of where the organization is based. The six lawful bases for processing are: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Most commercial data processing relies on legitimate interests or contract performance — consent is often the wrong basis and creates ongoing compliance obligations you do not want.
What regulators are actually enforcing
Recent enforcement priorities from the EDPB and national DPAs reveal where scrutiny is focused in 2026:
- Data transfers to third countries: SCCs (Standard Contractual Clauses) are required for transfers outside the EU/EEA. The EU-US Data Privacy Framework provides a transfer mechanism, but regulators watch these closely.
- Cookie consent: Pre-ticked consent boxes, bundled consent, and “legitimate interest” for advertising cookies are consistently fined. Your CMP must offer genuine, granular choice.
- AI systems: GDPR Article 22 restricts fully automated decision-making with legal effects. AI-driven hiring, credit scoring, and medical decisions require specific safeguards.
- Breach notification: 72-hour notification to the supervisory authority is a hard deadline. Most DPAs fine organizations that notify late even when the breach itself was minor.
Practical warning: Article 37 requires a Data Protection Officer for organizations processing sensitive data at scale or systematically monitoring individuals. Misclassifying your DPO requirement is a common compliance gap that becomes apparent only during audits.
CCPA and the US State Law Patchwork
California’s Consumer Privacy Act (CCPA), enhanced by CPRA in 2023, gives California consumers rights to know what data is collected, delete it, correct it, opt out of its sale, and limit use of sensitive personal information. As of July 2026, 22 US states have active comprehensive privacy laws. They are not uniform — Virginia, Texas, and Florida have different thresholds, exemptions, and enforcement mechanisms.
The practical approach for US organizations: build your privacy program to CCPA/CPRA standard (the most stringent of current US laws) and layer state-specific requirements on top. Areas where laws diverge: employee data exemptions, nonprofit exemptions, revenue and data volume thresholds, and sensitive data categories.
The Six Components of a Working Privacy Program
1. Data Inventory and Mapping
You cannot protect what you do not know you have. Build a data inventory that captures: what personal data you collect, where it is stored, who has access, where it flows (third parties, processors, transfers), and what legal basis applies to each processing activity. This is the foundation for every other compliance requirement. Tools like OneTrust, TrustArc, and open-source alternatives like CookieConsent help automate discovery, but the initial inventory requires cross-functional input from IT, marketing, HR, and legal.
2. Privacy Notices
Your privacy notice must describe what you collect, why, the legal basis, retention periods, third-party sharing, and individual rights. The notice must be layered (short version at point of collection, full version available), written in plain language, and updated when processing activities change. Most privacy notices fail on specificity — “we may share your data with partners” is not compliant disclosure.
3. Consent and Preference Management
Deploy a Consent Management Platform for cookie consent. Valid GDPR consent requires: specific, informed, unambiguous, freely given, and withdrawable without negative consequence. Bundling consent with terms of service is invalid. Pre-ticking boxes is invalid. Using dark patterns to discourage opt-out is now explicitly fined under GDPR guidance published in 2023.
4. Data Subject Request Handling
You have 30 days (CCPA) or one month (GDPR, extensible to 3 months for complex requests) to respond to access, deletion, correction, and portability requests. Build a DSR workflow with: intake form for identity verification, routing to relevant data stores, response template library, and audit trail. Manual processes fail when request volume scales. Automate what you can.
5. Vendor Management
Every vendor processing personal data on your behalf is a data processor under GDPR and requires a Data Processing Agreement (DPA). Build a vendor privacy review into your procurement process: assess the vendor’s privacy posture before signing contracts, require DPAs, and review annually. Include data deletion requirements on contract termination.
6. Breach Response
GDPR’s 72-hour notification clock starts the moment you become aware of a breach that is likely to result in a risk to individuals’ rights and freedoms. Build your breach response procedure before an incident: define what constitutes a notifiable breach, identify your supervisory authority contact, and have notification templates pre-approved by legal. Most regulatory penalties come not from the breach itself but from delayed or incomplete notifications.
Risk-based approach: Not every breach requires individual notification. Low-risk incidents (encrypted device lost, no evidence of access) typically require only supervisory authority notification. High-risk incidents (unencrypted data, malicious actor, financial data) require individual notification too. Document your risk assessment for every incident.
Takeaway: Privacy compliance is a cross-functional program, not a legal checkbox. The organizations that handle regulatory scrutiny well have: a current data inventory, tested DSR workflows, and documented evidence of their compliance decisions. Start with the inventory and work outward. Our Security Tools page covers CMP and privacy management platforms.
🔗 Further Reading
Frequently Asked Questions
What is GDPR?
GDPR (General Data Protection Regulation) is the EU's comprehensive data protection law, effective since May 2018. It applies to any organization processing personal data of EU residents, regardless of the organization's location. GDPR establishes six lawful bases for data processing, grants individuals eight data subject rights, requires data breach notification within 72 hours, and imposes fines of up to 4% of global annual revenue or €20 million (whichever is higher) for violations.
What is the difference between GDPR and CCPA?
GDPR (EU) applies to all organizations processing EU resident data globally and covers all personal data with opt-in consent as the standard. CCPA (California) applies to for-profit businesses meeting revenue or data volume thresholds and focuses on opt-out rights for data sale. Key differences: GDPR has broader scope and higher penalties; CCPA/CPRA introduced data correction rights and sensitive personal information protections GDPR lacks. Both require privacy notices, data subject request processes, and data processing agreements with vendors.
What is a Data Processing Agreement (DPA)?
A Data Processing Agreement is a contractual document required under GDPR Article 28 between a data controller (the organization deciding how data is processed) and a data processor (a third-party vendor processing data on the controller's behalf). DPAs must specify: the subject matter and duration of processing, the nature and purpose of processing, the type of personal data and categories of data subjects, and the controller's obligations and rights. Every cloud vendor, SaaS tool, or service provider handling personal data on your behalf requires a DPA.
How long do you have to respond to a GDPR data subject request?
Under GDPR, organizations must respond to data subject requests (access, deletion, correction, portability) within one month of receipt. This can be extended by two additional months for complex or numerous requests, but the individual must be informed within the first month of the extension and reason. The one-month clock starts from receipt of a valid, identifiable request. Under CCPA, the response deadline is 45 days, extendable by an additional 45 days with prior notice.

