GDPR Procedural Regulation (Regulation (EU) 2025/2518)
Harmonised procedural rules for cross-border GDPR enforcement: admissibility of complaints, cooperation deadlines between lead and concerned authorities, and rights of the parties. In force 1 January 2026, applies from 2 April 2027.
| Jurisdiction | European Union |
|---|---|
| Category | Privacy & Data Protection |
| Status | Upcoming |
| Effective date | |
| Latest development |
Analysis
Regulation (EU) 2025/2518 (GDPR Procedural Regulation) introduces harmonised procedural rules for how supervisory authorities handle cross‑border GDPR enforcement, with common complaint admissibility criteria, binding cooperation deadlines, and clarified rights of parties in investigations.Regulation (EU) 2025/2518 – consolidated textNew EU Regulation harmonises cross-border enforcementEU Parliament Think Tank brief777953) It entered into force on 1 January 2026 and applies from 2 April 2027 to new cross‑border cases.Regulation (EU) 2025/2518 – consolidated textWhat to expect with the new GDPR Procedural RegulationGDPR Procedural Regulation: New Enforcement Rules
Key Requirements
1. Harmonised complaint admissibility and standardised complaint form
- Supervisory authorities must apply a single, EU‑wide standard for evaluating the admissibility of cross‑border GDPR complaints. The regulation establishes “common admissibility standards for complaints” so that individuals’ complaints are assessed consistently across Member States.Adoption of Provisional GDPR Procedural RegulationEU Parliament Think Tank brief777953)Regulation (EU) 2025/2518 – consolidated text
- Complaints must contain harmonised minimum information, and authorities use a standardised complaint form. The Regulation introduces a standardised complaint form and harmonised information requirements to help authorities act faster and more consistently.EU reaches agreement to streamline cross-border GDPR enforcementRegulation (EU) 2025/2518 – consolidated textRegulation (EU) 2025/2518 overview (Streamlex)
- Incomplete complaints must be declared inadmissible within short deadlines, with reasons. Analyses of the Regulation describe that an authority finding a complaint incomplete must declare it inadmissible promptly (e.g., within a two‑week period) and give reasons, reflecting the binding procedural discipline introduced for complaint handling.GDPR Procedural Regulation: New Enforcement RulesAdoption of Provisional GDPR Procedural RegulationEU Parliament Think Tank brief777953)
2. Binding deadlines for cross‑border investigations and cooperation
- Lead supervisory authorities (LSAs) must complete investigations in most cross‑border cases within 15 months, extendable by 12 months for complex cases. The Regulation introduces mandatory deadlines: a 15‑month deadline for completion of investigations in cross‑border cases, with a possible 12‑month extension in particularly complex matters.EU reaches agreement to streamline cross-border GDPR enforcementAdoption of Provisional GDPR Procedural RegulationNew EU Regulation harmonises cross-border enforcement
- Simplified cooperation procedures must be completed within 12 months. For less complex cross‑border cases, a simplified cooperation procedure is created with a 12‑month investigation deadline, aimed at quicker resolution.EU reaches agreement to streamline cross-border GDPR enforcementAdoption of Provisional GDPR Procedural RegulationNew EU Regulation harmonises cross-border enforcement
- Cooperation timelines between LSA and concerned supervisory authorities (CSAs) are harmonised and binding. The Regulation lays down additional rules on cooperation between authorities under the GDPR one‑stop‑shop system, harmonising procedural steps and time limits for CSAs to comment and object to draft decisions.Regulation (EU) 2025/2518 – consolidated textCooperation between authorities – EDPBNewly proposed GDPR procedural rules – EP briefing757612_EN.pdf)
3. Early resolution and simplified cooperation mechanisms
- Early resolution mechanism for complaints where infringements are already remedied and no objections remain. The Regulation introduces an early‑resolution mechanism allowing supervisory authorities to close complaints swiftly if the infringement has been remedied and no objections remain among authorities.Adoption of Provisional GDPR Procedural RegulationNew EU Regulation harmonises cross-border enforcementEU Parliament Think Tank brief777953)
- Simplified cooperation track for less complex cross‑border cases. The Regulation also provides a simple cooperation procedure for less complex cases, with streamlined steps and shorter deadlines.EU Parliament Think Tank brief777953)Adoption of Provisional GDPR Procedural RegulationNew GDPR procedural rules for cross-border cases – EP ATAG777953_EN.pdf)
4. Enhanced rights of complainants and organisations (“parties’ rights”)
- Parties gain clearer rights to be heard and to access preliminary findings before a final decision. The Regulation ensures both complainants and organisations under investigation are heard through access to preliminary findings, supporting more transparent procedures.Adoption of Provisional GDPR Procedural RegulationEU reaches agreement to streamline cross-border GDPR enforcementNew GDPR procedural rules for cross-border cases – EP ATAG777953_EN.pdf)
- Formal defence rights for businesses under investigation are clarified and harmonised. Commentary on the Regulation emphasises that it formalises defence rights for businesses, including rights to respond to preliminary findings and draft decisions under consistent rules across the EU.GDPR Procedural Regulation: New Enforcement RulesWhat to expect with the new GDPR Procedural RegulationRegulation (EU) 2025/2518 overview (Streamlex)
- Procedural regulation only: material GDPR obligations and fine levels remain unchanged. Analyses emphasise that this is a procedural regulation: it does not change substantive GDPR obligations (e.g., legal bases, data subject rights, Article 83 fines), but governs how authorities enforce those obligations in cross‑border cases.GDPR Procedural Regulation: New Enforcement RulesEU Parliament Think Tank brief777953)Regulation (EU) 2025/2518 overview (Streamlex)
Compliance Challenges
1. Managing stricter investigation timelines and coordination
- Challenge: Meeting 15‑month and 12‑month deadlines while handling complex, multi‑jurisdictional investigations. The introduction of binding deadlines (15 months plus possible 12‑month extension; 12 months for simplified cooperation) compresses investigation timelines, requiring more efficient internal processes and coordination.EU reaches agreement to streamline cross-border GDPR enforcementAdoption of Provisional GDPR Procedural RegulationNew EU Regulation harmonises cross-border enforcement
- Real example – historic delays in cross‑border GDPR cases motivating this reform. EU Parliament analyses note that cross‑border GDPR enforcement has been slow and uneven, with significant delays and divergent practices across authorities, prompting the need for harmonised procedural rules.EU Parliament Think Tank brief777953)Newly proposed GDPR procedural rules – EP briefing757612_EN.pdf)GDPR Cooperation and Enforcement – EDPB
2. Adapting to harmonised complaint admissibility and intake requirements
- Challenge: Adjusting internal complaint‑handling processes to EU‑wide admissibility criteria and standard forms. Organisations must ensure their customer support, legal, and privacy teams can process and respond to standardised complaint information and anticipate the admissibility criteria applied by supervisory authorities.EU reaches agreement to streamline cross-border GDPR enforcementRegulation (EU) 2025/2518 – consolidated textRegulation (EU) 2025/2518 overview (Streamlex)
- Example: Organisations facing more structured complaints that must be addressed comprehensively. Commentary notes that harmonised complaint information will allow authorities to act faster and more consistently, which likely results in more structured and complete complaints reaching organisations, increasing the need for robust investigation and response workflows.Regulation (EU) 2025/2518 | overview articleEU reaches agreement to streamline cross-border GDPR enforcementWhat to expect with the new GDPR Procedural Regulation
3. Ensuring effective defence rights and procedural engagement
- Challenge: Coordinating internal and external counsel to respond to preliminary findings within tight deadlines. The Regulation’s requirement that parties be heard and respond to preliminary findings before final decisions means organisations must have rapid, coordinated processes to review draft findings and submit reasoned responses.Adoption of Provisional GDPR Procedural RegulationGDPR Procedural Regulation: New Enforcement RulesWhat to expect with the new GDPR Procedural Regulation
- Real example – large tech platforms facing complex cross‑border investigations under the one‑stop‑shop. Existing EDPB materials highlight that under the one‑stop‑shop system, large controllers can be subject to complex, multi‑authority investigations, necessitating significant procedural organisation and coordination.Cooperation between authorities – EDPBGDPR Cooperation and Enforcement – EDPBNewly proposed GDPR procedural rules – EP briefing757612_EN.pdf)
4. Handling early resolution and simplified cooperation responsibly
- Challenge: Strategically using early resolution without under‑documenting remediation. Early resolution is possible when infringements are remedied and no objections remain, but organisations must document remediation comprehensively to support closure while avoiding superficial fixes.Adoption of Provisional GDPR Procedural RegulationNew EU Regulation harmonises cross-border enforcementNew GDPR procedural rules for cross-border cases – EP ATAG777953_EN.pdf)
- Example: Authorities closing cases where controllers have already implemented corrective measures. Descriptions of
Recent developments
- — Analysis of the GDPR Procedural Regulation explains that Regulation (EU) 2025/2518 introduces detailed procedural rules for GDPR enforcement, including clearer complaint handling standards and cross‑border cooperation requirements, and notes that the Regulation will apply from 2027-04-02 for new cases.[4] (source)
- — Industry commentary outlines what organisations should expect under the GDPR Procedural Regulation, emphasizing that the new rules will apply to complaints lodged after 2027-04-02 and will significantly affect handling of cross‑border processing complaints, timelines, and complainant participation.[8] (source)
- — Consolidated text confirms Regulation (EU) 2025/2518 entered into force on 2026-01-01 and clarifies that it lays down additional procedural rules for enforcement of GDPR, with applicability deferred to 2027-04-02, giving organisations a transition period to adapt enforcement workflows.[2] (source)
- — European Parliament’s legislative train reports that Regulation (EU) 2025/2518 (GDPR Procedural Regulation) has been adopted and published in the Official Journal on 2025-12-12, confirming its role in further specifying procedural rules for GDPR enforcement and highlighting its objective of faster, more effective cross‑border enforcement.[1] (source)
- — News overview describes Regulation (EU) 2025/2518 as the GDPR Enforcement Rules Regulation, detailing that it establishes additional procedural rules for complaint-based and ex officio investigations in cross‑border processing and for dispute resolution before the EDPB, signalling stricter and more structured enforcement processes.[12] (source)
- — EDPB’s annual report highlights Regulation (EU) 2025/2518 as a key measure to harmonise and streamline cross‑border GDPR enforcement, indicating supervisory authorities are preparing guidance and cooperation mechanisms to implement the new procedural framework.[9] (source)
- — Law firm commentary notes that Regulation (EU) 2025/2518 has now entered into force and will apply to GDPR enforcement actions opened after 2027-04-02, introducing harmonised admissibility requirements, early resolution options, strict 12‑ and 15‑month deadlines for cases, and enhanced cooperation and access rights between DPAs and parties.[6] (source)
- — Analysis of the EU’s 2025 Digital Omnibus package situates Regulation (EU) 2025/2518 within a broader set of GDPR‑related updates, noting complementary changes such as a proposed “single entry point” for breach notifications and indicating that regulators are moving towards more centralized and streamlined enforcement mechanisms.[11] (source)
- — Client alert describes the GDPR Procedural Regulation as “a new chapter in GDPR enforcement,” stressing that although it entered into force on 2026-01-01 it will only apply from 2027-04-02, and comments that businesses should begin reviewing complaint-handling and investigation processes in light of the new timelines and procedural safeguards.[5] (source)
- — Update from Gibson Dunn reports the publication of Regulation (EU) 2025/2518 and explains that it aims to improve cooperation between supervisory authorities and accelerate complaint handling in cross‑border GDPR cases, with a 20‑day entry into force period and application 15 months thereafter, impacting enforcement strategy for large multinationals.[10] (source)
Related regulations
- EU AI Act - Annex III High-Risk System Requirements (2 Dec 2027) — European Union, Upcoming, effective 2027-12-02
- EU Data Act — European Union, Phased, effective 2025-09-12
- EU Cyber Resilience Act (CRA) — European Union, Phased, effective 2027-12-11
- EU AI Act - GPAI Model Obligations (2 Aug 2025) and Enforcement (2 Aug 2026) — European Union, Active, effective 2025-08-02
- EU Digital Omnibus on AI (Regulation (EU) 2026/1744) — European Union, Active, effective 2026-07-27
- EU AI Act - Synthetic Media Transparency and New Prohibitions (2 Dec 2026) — European Union, Upcoming, effective 2026-12-02
- EU AI Act - Annex I High-Risk Systems (2 Aug 2028) — European Union, Upcoming, effective 2028-08-02
- EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026) — European Union, Active, effective 2026-09-11
Put it into practice
- Generate the policy: GDPR policy generator (generatepolicy.com)
- Buy the policy pack: GDPR Complete Bundle (cyberpolicy.shop)
- Build it yourself: GDPR & DPIA Compliance Workbook (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates