For sale — contact mail@quant.rocks

🔮 What's Coming Next

Speculative editorial analysis on the most likely changes to EU data protection law in 2026–2028. Probabilities are our own assessment — not confirmed regulatory positions. Last updated 22 August 2026.

These predictions are speculative editorial analysis — not legal advice or confirmed regulatory positions.
SpeculativeAI + GDPR

LLM Training on Personal Data: Mass Enforcement Actions Expected

With the EDPB's July 2026 guidelines confirming that web scraping for AI training requires a lawful basis, and that AI models are not automatically "anonymous," DPAs are expected to launch coordinated enforcement against major LLM providers. OpenAI, Google DeepMind, Meta AI, and Anthropic all face open investigations across multiple EU jurisdictions. The key unresolved question: can legitimate interest (Article 6(1)(f)) ever justify training on billions of web pages containing personal data? The Italian Garante's 2023 ChatGPT ban foreshadowed a broader reckoning now reaching critical mass.

Likelihood of coordinated enforcement by mid-202785%
EDPB AI guidelines
SpeculativeAI + GDPR

Right to Erasure vs. AI Models: The "Unlearning" Crisis

GDPR's right to erasure (Article 17) creates an unsolved technical problem for LLMs: how do you delete personal data from a trained model? Current "machine unlearning" techniques are immature and unproven at scale. Regulators will likely require either (a) proof that personal data cannot be extracted from models, (b) periodic model retraining excluding erasure requests, or (c) effective output filtering. Expect binding guidance defining what "erasure" means in the context of neural networks — potentially requiring costly retraining cycles. Companies that cannot demonstrate compliance may face orders to suspend processing.

Likelihood of binding guidance by 202770%
EDPB documents
SpeculativeAI + GDPR

AI-Generated Content About Real People: Accuracy Obligations Under Fire

LLMs routinely generate false information about real individuals — "AI hallucinations" that violate GDPR's accuracy principle (Article 5(1)(d)). After the DPC opened its inquiry into X/Grok for generating non-consensual images of real people (Feb 2026), regulators are expected to establish that AI outputs containing personal data must meet the same accuracy standards as any other data processing. This could force providers to implement robust factual grounding, disable person-specific outputs, or face systematic fines. The intersection of deepfakes, synthetic media, and GDPR accuracy will be a defining enforcement battleground through 2027.

Likelihood of enforcement action by 202790%
DPC X/Grok inquiry
SpeculativeAI + GDPR

AI Decision-Making: Article 22 Becomes the Central Battleground

As AI systems increasingly make or heavily influence decisions about people — credit scoring, hiring, insurance pricing, content moderation — GDPR Article 22's prohibition on "solely automated" decisions is being tested. The NOYB class action against CRIF (Jun 2026) signals the start of systematic challenges to AI-driven decision-making. With the AI Act now requiring human oversight for high-risk systems, expect DPAs to issue coordinated enforcement requiring meaningful human review — not just rubber-stamping AI outputs. Companies using LLMs for customer-facing decisions without genuine human-in-the-loop processes face significant liability.

Likelihood of major ruling by 202780%
NOYB CRIF case
SpeculativeGeopolitics

US-EU Digital Decoupling: From Data Transfers to Digital Sovereignty

The Trump administration's systematic dismantling of US privacy safeguards — paralysing the PCLOB (Jan 2025), signalling hostility toward EU regulatory cooperation, and the Supreme Court's FTC independence ruling (Jun 2026) — has pushed the EU from "adequacy" thinking toward outright digital sovereignty. EU Member States are increasingly backing requirements that sensitive data remain on EU-based infrastructure. Major European institutions are migrating from US cloud providers. The political direction is clear: the era of frictionless US-EU data flows may be ending regardless of whether Schrems III succeeds formally.

Likelihood of EU cloud sovereignty mandates by 202865%
NOYB analysis
SpeculativeGeopolitics

US Retaliatory Measures Against EU Data Regulation

As the EU tightens requirements on US tech companies through GDPR, the AI Act, and the Digital Markets Act simultaneously, the US administration has signalled that EU digital regulation constitutes a trade barrier. Expect escalating tension: potential US trade measures targeting EU companies, political pressure to water down GDPR enforcement against American firms, and framing of EU privacy regulation as protectionism. The EU faces a difficult balancing act between maintaining fundamental rights standards and avoiding a full-scale transatlantic digital trade war.

Likelihood of formal US trade dispute by 202845%
IAPP coverage
SpeculativeAI + GDPR

Mandatory DPIAs for All AI Systems Processing Personal Data

With the AI Act's risk-based framework now fully applicable, regulators are expected to clarify that virtually all AI systems processing personal data require Data Protection Impact Assessments (Article 35). The combination of systematic profiling, new technologies, and large-scale processing means most LLM deployments will trigger mandatory DPIAs. Organisations deploying AI chatbots, recommendation systems, or content moderation tools without documented DPIAs face enforcement. Expect standardised DPIA templates specifically designed for generative AI systems.

Likelihood of standardised AI DPIA templates by 202780%
EDPB guidance
SpeculativeePrivacy Regulation

ePrivacy Regulation Could Finally Be Adopted

The long-delayed ePrivacy Regulation — stalled since 2017 — faces further setbacks after EU Member States blocked the Commission's proposal to eliminate cookie banners in June 2026. The regulation would replace the Cookie Directive with stricter rules on electronic communications metadata, but disagreements over metadata retention and the cookie consent mechanism continue to delay progress.

Likelihood by end of 202745%
Legislative status
SpeculativeAI Act + GDPR

AI Act Full Application Triggers GDPR Enforcement Wave

The EU AI Act reaches full application in August 2026, and regulators are expected to launch coordinated enforcement actions targeting AI systems that process personal data without adequate safeguards. Expect clarification on how GDPR rights — especially Article 22 on automated decisions — apply to high-risk AI systems, with stronger requirements for human review, transparency, and DPIAs before deployment.

Likelihood by end of 202690%
EDPB guidance on Article 22
SpeculativeEnforcement Reform

DPA Cross-Border Enforcement Overhaul

The one-stop-shop mechanism has drawn sustained criticism — particularly the Irish DPC's handling of Big Tech cases. The European Commission published its GDPR evaluation in 2023, and a political agreement on additional procedural rules was reached in June 2025. The next phase is practical implementation, with likely follow-up guidance to accelerate cross-border enforcement and reduce bottlenecks at lead supervisory authorities.

Likelihood by end of 202655%
Commission evaluation (2023)
SpeculativeData Transfers

Schrems III: DPF Annulment and Collapse of US Data Flows

NOYB has now formally filed a lawsuit before the CJEU seeking annulment of the EU–US Data Privacy Framework. With the US Supreme Court eliminating FTC independence, the PCLOB paralysed, and the Trump administration openly hostile to EU oversight mechanisms, the legal foundations of the adequacy decision are severely weakened. The CJEU invalidated Safe Harbor in 2015 and Privacy Shield in 2020 — a third invalidation appears increasingly inevitable. SCCs and BCRs are also affected since transfer impact assessments relied on the same US oversight bodies. Companies should prepare contingency plans for a world without a valid US adequacy decision.

Likelihood of DPF invalidation by 202880%
NOYB lawsuit details
SpeculativeChildren's Data

Stricter Age Verification Requirements EU-Wide

Following Ireland's major fine against Meta over children's data (Instagram, 2022), and broader DSA enforcement, expect new EU-wide standards for age verification and parental consent mechanisms. The EDPB has signalled children's data as a top enforcement priority for 2025–2026. Coordinated enforcement actions across multiple DPAs are expected, potentially targeting social media platforms and gaming companies.

Likelihood of new guidance by end of 202685%
EDPB consent guidelines
SpeculativeEnforcement

First €2 Billion+ GDPR Fine

With Meta's €1.2B fine setting a record in 2023, and multiple open investigations into Big Tech advertising ecosystems, a fine crossing the €2 billion threshold is plausible before 2027. This would require a proven Article 83(5) violation — systematic and intentional processing in breach of fundamental GDPR principles — with a company large enough to support a fine of 4% of global annual turnover at this level.

Likelihood by end of 202740%
GDPR Enforcement Tracker
SpeculativeConsent Models

"Pay or Okay" Consent Models Ruled Invalid

Following NOYB's complaints against Meta and Schibsted over "Pay or Okay" consent walls — where users must pay for an ad-free experience or consent to tracking — regulators are expected to issue binding guidance declaring these models incompatible with freely given consent under GDPR Article 7. The EDPB has already expressed scepticism, and a definitive ruling could force publishers and platforms to find alternative business models.

Likelihood of binding ruling by 202770%
NOYB coverage