
GDPR
EU data protection regulation that sets rights over personal data and imposes global compliance obligations.
Bruegel costed the EU cloud law's public-sector migration, driven by GDPR's incompatibility with the US CLOUD Act, at up to EUR 86 billion on 11 June 2026, a sum dwarfing the rest of the sovereignty budget.
Last refreshed: 4 August 2026 · Appears in 1 active topic
Is the GDPR strong enough to prevent US intelligence services accessing EU citizen data?
Timeline for GDPR
Mentioned in: AI Act fines land on a stale register
European Tech SovereigntyMentioned in: Omnibus widens the AI Office's reach
European Tech SovereigntyMentioned in: A Spanish court opens the algorithm
AI: Jobs, Power & MoneyMentioned in: Germany names the AI Act's enforcers
AI: Jobs, Power & MoneyMentioned in: Brussels stalls its own AI-label code
Media's AI PivotBackground
The General Data Protection Regulation (Regulation EU 2016/679) is the EU's foundational data-protection law, in force since 25 May 2018. It gives EU residents rights of access, erasure, portability and objection over their personal data, and binds any organisation processing that data regardless of where it is based, with maximum fines of the greater of EUR20 million or 4% of global annual turnover.
GDPR replaced the 1995 Data Protection Directive, introducing privacy by design, mandatory 72-hour breach notification, and impact assessments for high-risk processing. The European Data Protection Board coordinates enforcement across national authorities including France's CNIL, Germany's BfDI and Ireland's DPC, the last of which handles most cases against US tech firms headquartered in the bloc.
Its influence extends beyond the EU: the UK retained its principles as UK GDPR after Brexit, and it shaped similar laws in Brazil, California, Japan and South Korea.
Its CLOUD Act clash costs billions
GDPR's structural incompatibility with US CLOUD Act jurisdiction underpins Brussels' push to migrate public-sector data away from US-headquartered cloud providers. Bruegel costed that migration, required under the EU's cloud law, at up to EUR 86 billion on 11 June 2026, using the Commission's own impact assessment, and called the assessment's 5% price-premium assumption unrealistic .
The figure dwarfs the rest of the sovereignty budget: the same-month AI Gigafactories call, EUR 4.12 billion, and Open Source Strategy, EUR 2 billion, together total under a tenth of it, making GDPR-driven cloud sovereignty the single largest cost line in the EU's technology-independence programme.