The GDPR was only the beginning of Europe’s approach to data. A new generation of rules — on data sharing, digital services, and AI — is building on it, and together they signal where privacy regulation is heading: broader, more connected, and more demanding.
From one law to an ecosystem
The Data Act, the Data Governance Act, the Digital Services Act, and the AI Act all interact with the GDPR rather than replace it. Privacy is no longer a single compliance silo; it is woven through how organisations handle data, platforms, and automated decisions.
Themes to watch
Three directions stand out: greater individual control over data, stricter rules on automated decision-making, and rising expectations around transparency. Regulators increasingly want to see not just policies, but evidence that those policies work in practice.
How to prepare
The companies that will cope best are treating privacy as a capability, not a checkbox — investing in clean data maps, clear accountability, and processes that can flex as new rules arrive. The specifics will keep changing; the underlying discipline will not.
Privacy is becoming a marker of trust and a competitive differentiator. Building that discipline now is far easier than retrofitting it under deadline pressure later.