Cleo
CompanyLegal Data
Request a demo
Anaelle GuezNaomie Halioua
Request a demo
Cleo

AI-powered regulatory intelligence.

contact@cleolabs.co

Solutions

  • Product Compliance

Company

  • About
  • Research
  • Blog
  • Compliance Guides

Jurisdictions

  • 🇪🇺 European Union
  • 🇫🇷 France
  • 🇩🇪 Germany
  • 🇬🇧 United Kingdom
  • 🇺🇸 United States

Legal

  • Privacy
  • Terms
  • Security

Events

  • VivaTech ParisJun 11–14, 2026

© 2026 Cleo Labs. All rights reserved.

GDPREU DataSOC 2 Type IIISO 27001
🇪🇺European Union

GDPR compliance in the EU

The GDPR is directly applicable across all 27 EU member states since May 2018. It harmonizes data protection rules while allowing member states to specify certain provisions through national law.

Start free scan
Anaelle GuezNaomie Halioua
or book a call

Enforcement authority

European Data Protection Board (EDPB) coordinates; each member state has a national DPA

Maximum sanctions

Up to EUR 20 million or 4% of global annual turnover. Over EUR 4.5 billion in fines issued since 2018 across the EU.

Key obligations

What GDPR requires from organizations operating in the EU.

Appoint a Data Protection Officer (DPO) for public authorities and large-scale processing
Maintain Records of Processing Activities (ROPA) under Article 30
Conduct Data Protection Impact Assessments for high-risk processing
Implement data breach notification to supervisory authority within 72 hours
Ensure valid legal basis under Article 6 for all personal data processing

Local context in the EU

The EDPB issues binding decisions on cross-border cases. Ireland, Luxembourg, and France handle the largest volume of cross-border complaints due to tech company headquarters locations.

GDPR by industry in the EU

Retail & Consumer GoodsHealthTechInsuranceEnergy & UtilitiesCosmetics & Personal CareElectronics & Connected Devices

Frequently asked questions

How does GDPR apply in the EU?

The GDPR is directly applicable across all 27 EU member states since May 2018. It harmonizes data protection rules while allowing member states to specify certain provisions through national law.

Who enforces GDPR in the EU?

European Data Protection Board (EDPB) coordinates; each member state has a national DPA

What are the penalties for GDPR non-compliance?

Up to EUR 20 million or 4% of global annual turnover. Over EUR 4.5 billion in fines issued since 2018 across the EU.

Read our complete GDPR compliance guide

GDPR in other jurisdictions

🇫🇷France🇩🇪Germany🇬🇧United Kingdom🇺🇸United States🇧🇷Brazil🇦🇺Australia🇮🇳India

Check your GDPR compliance now

Start free scan to see your risk score and applicable obligations.

Start free scan
Anaelle GuezNaomie Halioua
or book a call