Skip to main content

IN EFFECT since May 25, 2018

Last verified against primary sources:

GDPR (General Data Protection Regulation)

EU · Effective May 25, 2018

EU/EEA data protection law: lawful basis, privacy notice, data-subject rights (access, deletion, portability), and opt-in consent for non-essential cookies. UK applies the equivalent UK GDPR.

Overview

In force and actively enforced since May 25, 2018. Cookie consent rules are unchanged (governed by the ePrivacy Directive); the EDPB has extended Article 5(3) to pixels and fingerprinting. A Digital Omnibus proposal (Nov 2025) may later move cookie rules into the GDPR (one-click reject, browser-level consent signals, low-risk exemptions) but is not yet law. Applies to any organization processing EU/EEA residents' data, regardless of size.

Official text: https://eur-lex.europa.eu/eli/reg/2016/679/oj

See where your app stands

SaaSalyst scans your website in 30 seconds across 118 business readiness checks: compliance signals, security headers, SEO, accessibility, and AI readiness.

Scan Your App