Notes from the IAPP Europe: GDPR anniversary, 2025 annual reports and looking ahead
The IAPP's European gathering marked the anniversary of GDPR and reviewed 2025 annual reports from data protection authorities, while looking at what the near-term regulatory landscape holds for privacy professionals across the region.
Why this matters: GDPR is old enough now that the gap between what it promised and what it delivered is visible. Anniversary moments like this are useful not for celebration but for honest accounting. Enforcement has been uneven, big tech fines have moved slowly through appeals, and smaller organizations still struggle with compliance basics. What regulators say publicly at events like this shapes what companies prioritize next. If you work in privacy, the signals coming out of these meetings are worth tracking.
Who should care: Lawyers · Privacy officers · AI governance
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.