A run of EU data protection rulings this summer has strengthened the hand of ordinary complainants, capped by a Grand Chamber judgment from the Court of Justice on 14 July 2026. Together the decisions clarify how far national watchdogs must go when citizens invoke the General Data Protection Regulation.
The through-line is enforcement. Eight years after the GDPR took effect, the disputes reaching Luxembourg are less about what the law says than about whether regulators and courts must actually act on it.
## What the EU data protection rulings change
In a June decision, the Court confirmed that processing of personal data can rest on more than one legal ground under Article 6(1) of the GDPR at the same time, provided each ground’s conditions are met. The reading gives companies clarity but does not loosen the underlying duties.
More striking for individuals, the Court held that a supervisory authority cannot reject a GDPR complaint simply because court proceedings on the same matter are already pending. Regulators must engage with complaints on their merits rather than defer to parallel litigation.
## Why complaint rights matter
For years, campaigners argued that data protection authorities used procedural reasons to sidestep difficult cases. The latest EU data protection jurisprudence narrows that room to manoeuvre.
The practical effect is that a person who files a complaint is entitled to a substantive response. That raises the workload on national regulators, several of which already report backlogs stretching well beyond the GDPR’s own timelines.
## Generative AI enters the frame
The pressure is not only judicial. On 7 July 2026, the European Data Protection Board published draft guidelines on web scraping for generative AI, addressing how developers may, or may not, harvest personal data to train models.
The guidance signals where the next enforcement battles lie:
– The legal basis for scraping public data at scale.
– Transparency toward people whose data is swept up.
– Rights to object and to erasure once a model is trained.
## A transatlantic complication
Data protection also collided with foreign politics this month. Privacy advocates urged the EU to reconsider its data-transfer arrangement with the United States after a US Supreme Court ruling raised doubts about the independence of the Federal Trade Commission, a regulator the transfer framework relies on.
If the FTC no longer qualifies as an independent authority in EU eyes, the legal footing for transatlantic data flows could weaken, reviving uncertainty that businesses hoped had been settled.
## What happens next
Expect the Commission and the EDPB to translate these rulings into sharper guidance, while national authorities absorb the message that complaints cannot be waved away. For citizens, the summer’s EU data protection decisions add up to a simple shift: the regulation’s promises are becoming harder for institutions to ignore.
This is a developing area, and further judgments are expected before year-end as the courts work through a crowded docket of privacy cases. Consumer groups have welcomed the trend, arguing that a right without a remedy is no right at all, while some regulators quietly warn that resources have not kept pace with the caseload the courts now expect them to shoulder.




