Dublin: The European Data Protection Board’s publication marking ten years of the General Data Protection Regulation arrives at a moment when the regulatory architecture it oversees is under pressure the original 2016 text did not anticipate. Cumulative fines across the European Economic Area have crossed seven point one billion euros since application began in May 2018, with roughly one point one five billion levied in 2025 alone, and the docket of cross-border cases that pass through the one-stop-shop mechanism has grown to a volume that has stretched the Irish Data Protection Commission to the centre of disputes far beyond its administrative footprint. The anniversary stocktake is therefore not a victory lap but a methodical accounting of a system being asked to do more than its founders intended.
The headline numbers conceal a more uneven story. The thirty-one national authorities that sit on the Board created 414 new cross-border cases in 2025 and triggered 1,299 procedures under the one-stop-shop framework, but half of all cross-border decisions adopted between 2018 and 2025 originated with three authorities, the Irish DPC, the French CNIL, and Germany’s federated supervisors, while a longer tail of national regulators in smaller member states issued fewer than fifteen decisions each over the same period. The asymmetry has accreted political weight because the largest American platforms maintain European headquarters in Dublin, Luxembourg, and Amsterdam, concentrating regulatory exposure in jurisdictions whose enforcement capacity has been repeatedly tested by the European Parliament’s civil liberties committee. The Board quietly concedes that average time to closure for one-stop-shop cases involving more than one supervisory authority remains above two years, a figure the Board has been promising to compress since at least the consistency mechanism reforms of 2021.
The substantive ground covered by the anniversary text tracks the issues that have crystallised since application began. Children’s data protection has moved from a marginal concern in the 2016 regulation to a sector where dedicated guidance, age-assurance work and coordinated action plans have generated more than two hundred enforcement actions across member states between 2023 and 2025. Health data sharing has been brought inside the European Health Data Space framework that entered application earlier this year, partially absorbing the cross-border treatment scenarios that the original regulation handled awkwardly. International transfers, the area where the Schrems II judgment forced wholesale recontracting in 2020, now operate under the EU-US Data Privacy Framework agreed in 2023 and the equivalent UK arrangement, both of which face standing legal challenges in the Court of Justice that the Board acknowledges remain unresolved.
Regulation 2025/2518, the procedural reform that entered into force on 1 January and will become applicable from 2 April 2027, sits at the centre of the next decade. The instrument harmonises the administrative procedures for cross-border complaints in a way that the Article 60 cooperation mechanism never managed, with deadlines, complainant rights and lead-authority duties codified in directly applicable terms rather than left to national procedural law. The Board’s report treats it as the most consequential structural change to the system since application, although the lag before the rules bite means the next eighteen months will continue to operate under the older choreography that has produced the slow closures the report measures.
The political backdrop is more delicate than the Board’s measured prose suggests. The Commission’s Digital Omnibus proposal, tabled in the closing months of 2025 and now working its way through interinstitutional discussion, is the first serious attempt to reopen the GDPR text rather than supplement it with sectoral instruments. The proposed changes target SME obligations, documentation requirements, and the breach-notification thresholds that have produced what corporate counsel call alert fatigue across compliance functions. The Board has been careful in its public communications to distinguish between simplification it can support and dilution it cannot, and the anniversary report places those red lines at the data-minimisation principle, the rights of access and erasure, and the cross-border enforcement architecture itself.
Beneath the institutional language sits a structural question the next decade will have to answer. The GDPR was drafted as a horizontal regulation premised on a relatively narrow set of digital business models. The Artificial Intelligence Act, the Data Act, the Digital Services Act and the Digital Markets Act now sit alongside it, each with its own supervisory architecture and overlapping definitions of personal data, automated decision-making, and platform responsibility. The anniversary text proposes that the Board’s coordinating role with the AI Office, the European Board for Digital Services and national competent authorities be formalised through joint guidelines rather than informal liaison. Whether that proposal survives the omnibus negotiations is the question that will determine, more than any single enforcement headline, the shape of European data protection at the regulation’s fifteenth anniversary.




