WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Europe

European Union Privacy & Data Protection Laws

Every regime below can apply to a business handling European Union residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

Applies to any organization established in the EU (regardless of where processing actually happens), OR to a non-EU organization that either offers goods/services to people in the EU (paid or free) or monitors their behavior (analytics, ad targeting, profiling) — no revenue or headcount threshold triggers or excuses this. Nonprofits and public authorities are generally covered, not exempt (unlike most US comprehensive laws). A narrow exemption from Article 30 record-keeping exists for organizations under 250 employees, but only for that specific paperwork duty — it doesn't exempt them from GDPR's substantive rules.

Regulation (EU) 2016/679, Art. 3Read regulation →

Sector-Specific Law · 3

July 31, 2002 (as amended from May 25, 2011); applied through national implementing laws
Directive on privacy and electronic communications (ePrivacy Directive)
ePrivacy Directive

The legal basis for cookie banners, and a genuinely separate regime from the GDPR that businesses routinely fold into it by mistake. Art. 5(3) requires prior informed consent before storing information on, or gaining access to information already stored on, a user's terminal equipment, exempting only what is strictly necessary to provide a service the user requested — and it is technology-neutral, so local storage, pixels, SDK identifiers, and device fingerprinting are all in scope, not just HTTP cookies. Two consequences follow. First, legitimate interest is not available here: consent under Art. 5(3) means GDPR-standard consent, and pre-ticked boxes do not qualify (Planet49, C-673/17). Second, because it is a DIRECTIVE, the operative text is 27 national implementing laws with real variation in enforcement posture and in the treatment of analytics cookies, and it is enforced in several member states by a telecoms or consumer regulator rather than the data protection authority. Art. 13 separately governs unsolicited direct marketing by email, SMS, and automated calling. The long-pending ePrivacy Regulation intended to replace this Directive was withdrawn rather than adopted; the Directive remains in force.

Directive 2002/58/EC, Arts. 5(3) and 13, as amended by Directive 2009/136/ECRead regulation →
January 17, 2025 (date of application, following a two-year implementation period)
Digital Operational Resilience Act
DORA

DORA is a directly applicable Regulation covering a closed list of EU financial entities set out in Art. 2 — credit institutions, payment and electronic money institutions, investment firms, insurers and intermediaries, crypto-asset service providers, trading venues, fund managers and more — plus ICT third-party providers designated critical by the European Supervisory Authorities. It imposes an ICT risk management framework, a classified ICT-incident reporting pipeline to competent authorities, digital operational resilience testing (including threat-led penetration testing for larger entities), and a register of information on all ICT third-party contractual arrangements, with prescribed contractual terms for those contracts. Two points that catch non-financial businesses out: DORA reaches ICT vendors indirectly through those mandated contract terms even when they are not themselves designated critical, and its incident reporting is separate from and additional to GDPR Art. 33 — an incident can trigger both pipelines on different clocks to different regulators.

Regulation (EU) 2022/2554Read regulation →
October 18, 2024 (repeal of the original NIS Directive); binding through national transposing laws, several of which landed late
Directive on measures for a high common level of cybersecurity across the Union (NIS2)
NIS2 Directive

NIS2 requires 'essential' and 'important' entities across roughly eighteen sectors (Annexes I and II) to adopt baseline cybersecurity risk-management measures, report significant incidents on a three-step clock — a 24-hour early warning, a 72-hour notification, and a final report within one month — and hold management bodies personally accountable for cybersecurity oversight. Scope is generally size-capped at medium and large entities, with size-independent categories for certain providers. Two caveats matter for anyone reading this page. First, it is a Directive: the binding text is each member state's transposing law, and most states missed the October 17, 2024 deadline, prompting Commission infringement proceedings — so the operative rules and their commencement dates differ by country and should be checked per member state rather than assumed uniform. Second, this atlas's questionnaire can only detect two of NIS2's sectors (health, and banking/financial market infrastructure), so a non-match here is not a determination that NIS2 does not apply to you — check Annexes I and II directly, particularly if you are a cloud, managed service, data centre, online marketplace, or search provider.

Directive (EU) 2022/2555; national transposing laws (transposition deadline October 17, 2024)Read regulation →

Children & Minors Protections · 1

May 25, 2018 (GDPR Art. 8); DSA Art. 28 applicable from February 17, 2024
General Data Protection Regulation — conditions applicable to a child's consent for information society services
GDPR Art. 8

Where an online service offered directly to a child relies on CONSENT as its lawful basis, Art. 8 makes that consent valid only from age 16 — below that, it must be given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify that, taking available technology into account. The trap for a business treating 'the EU' as one jurisdiction is Art. 8(1)'s second sentence: member states may set a lower age, not below 13, and many have, so the operative threshold is 13, 14, 15, or 16 depending on the country — there is no single EU age of digital consent. Art. 8 also only governs consent; it does not authorise processing a child's data on another lawful basis without further care. Separately, DSA Art. 28 requires providers of online platforms accessible to minors to put appropriate privacy, safety, and security measures in place and prohibits advertising based on profiling where the provider is aware with reasonable certainty that the user is a minor.

Regulation (EU) 2016/679, Art. 8; Regulation (EU) 2022/2065 (Digital Services Act), Art. 28Read regulation →

Cross-Border Data Transfer · 1

Chapter V's governing principle (Art. 44) is that the level of protection the GDPR guarantees must not be undermined by moving data out of the EEA. Transfers are lawful where the destination has a European Commission adequacy decision (Art. 45); failing that, on an appropriate safeguard (Art. 46) — most commonly the 2021 Standard Contractual Clauses, or binding corporate rules under Art. 47; failing that, on one of the narrow Art. 49 derogations, which the EDPB reads as exceptional and unsuitable for repeated or systematic transfers. The Art. 46 route is not a paperwork exercise: after Schrems II (C-311/18), the exporter must also assess whether the destination's law and practice actually deliver essentially equivalent protection, and add supplementary measures where they do not — the transfer impact assessment. Onward transfers by your processor count, and so does remote ACCESS from a third country, which is where most businesses under-scope the analysis.

Regulation (EU) 2016/679, Arts. 44-49Read regulation →

Data Security & Breach Notification · 1

Art. 33 requires notifying the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to people's rights and freedoms; a late notification must carry reasons for the delay. Art. 34 separately requires telling affected individuals without undue delay where the breach is likely to result in a HIGH risk to them — the two thresholds are different, and only the authority-facing one has a clock. Art. 32 is the standing obligation the other two hang off: security appropriate to the risk, judged against state of the art and cost. Two practical points a reviewer should confirm for a specific business: the 72 hours run from awareness that a breach has probably occurred, not from full technical certainty (EDPB Guidelines 9/2022), and the one-stop-shop only applies if you have a main establishment in the EU — a controller relying on an Art. 27 representative may have to notify each affected member state's authority separately.

Regulation (EU) 2016/679, Arts. 32, 33, 34Read regulation →

Other Europe jurisdictions