Skip to content
You can now search across every topic, entity and event.What's new
GDPR
LegislationBE

GDPR

EU data protection regulation that sets rights over personal data and imposes global compliance obligations.

Bruegel costed the EU cloud law's public-sector migration, driven by GDPR's incompatibility with the US CLOUD Act, at up to EUR 86 billion on 11 June 2026, a sum dwarfing the rest of the sovereignty budget.

Last refreshed: 4 August 2026 · Appears in 1 active topic

Key Question

Is the GDPR strong enough to prevent US intelligence services accessing EU citizen data?

Timeline for GDPR

View full timeline →

Background

The General Data Protection Regulation (Regulation EU 2016/679) is the EU's foundational data-protection law, in force since 25 May 2018. It gives EU residents rights of access, erasure, portability and objection over their personal data, and binds any organisation processing that data regardless of where it is based, with maximum fines of the greater of EUR20 million or 4% of global annual turnover.

GDPR replaced the 1995 Data Protection Directive, introducing privacy by design, mandatory 72-hour breach notification, and impact assessments for high-risk processing. The European Data Protection Board coordinates enforcement across national authorities including France's CNIL, Germany's BfDI and Ireland's DPC, the last of which handles most cases against US tech firms headquartered in the bloc.

Its influence extends beyond the EU: the UK retained its principles as UK GDPR after Brexit, and it shaped similar laws in Brazil, California, Japan and South Korea.

Key Issues
Cloud sovereignty cost

Its CLOUD Act clash costs billions

GDPR's structural incompatibility with US CLOUD Act jurisdiction underpins Brussels' push to migrate public-sector data away from US-headquartered cloud providers. Bruegel costed that migration, required under the EU's cloud law, at up to EUR 86 billion on 11 June 2026, using the Commission's own impact assessment, and called the assessment's 5% price-premium assumption unrealistic .

The figure dwarfs the rest of the sovereignty budget: the same-month AI Gigafactories call, EUR 4.12 billion, and Open Source Strategy, EUR 2 billion, together total under a tenth of it, making GDPR-driven cloud sovereignty the single largest cost line in the EU's technology-independence programme.

Common Questions
What is the GDPR and who does it apply to?
The GDPR (General Data Protection Regulation) is the EU's data protection law that applies to any organisation processing personal data of EU residents, regardless of where the organisation is based. It grants rights including data access, erasure, and portability, and can fine organisations up to EUR 20m or 4% of global turnover.Source: EUR-Lex
Why can't US cloud providers guarantee GDPR compliance under the CLOUD Act?
The US CLOUD Act requires US-headquartered companies to disclose customer data to US authorities on court order, even if the data is stored in Europe. This potentially conflicts with GDPR's requirement to protect EU data subjects from unlawful international transfers, making US cloud providers structurally unable to guarantee compliance for sensitive public-sector data.
What is the difference between GDPR and UK GDPR?
UK GDPR is the version of the regulation retained in UK law after Brexit. It is substantively identical to EU GDPR but enforced by the UK ICO rather than the EDPB. The EU has granted the UK an adequacy decision, allowing data transfers without additional safeguards, though this decision is periodically reviewed.
Source Material