On 24 May 2026, the European Union marked ten years since the publication of the General Data Protection Regulation.

The GDPR has reshaped the protection of personal data in Europe by giving individuals stronger rights and greater control over their personal information. Citizens now have the right to know how their data is used, to access it, request its correction or deletion, and withdraw consent at any time.

At the same time, the GDPR has imposed clear obligations on organisations and has become a global reference point for privacy and data protection legislation.

Together with the Digital Services Act, the Digital Markets Act and the AI Act, the GDPR forms part of the EU’s broader effort to protect individuals in the digital environment and ensure that technological progress respects fundamental rights.

Share this article