IN EFFECT since May 25, 2018
Last verified against primary sources:
GDPR (General Data Protection Regulation)
EU · Effective May 25, 2018
EU/EEA data protection law: lawful basis, privacy notice, data-subject rights (access, deletion, portability), and opt-in consent for non-essential cookies. UK applies the equivalent UK GDPR.
Overview
In force and actively enforced since May 25, 2018. Cookie consent rules are unchanged (governed by the ePrivacy Directive); the EDPB has extended Article 5(3) to pixels and fingerprinting. A Digital Omnibus proposal (Nov 2025) may later move cookie rules into the GDPR (one-click reject, browser-level consent signals, low-risk exemptions) but is not yet law. Applies to any organization processing EU/EEA residents' data, regardless of size.
Official text: https://eur-lex.europa.eu/eli/reg/2016/679/oj
See where your app stands
SaaSalyst scans your website in 30 seconds across 118 business readiness checks: compliance signals, security headers, SEO, accessibility, and AI readiness.
Scan Your App