The GDPR Procedural Regulation, formally Regulation (EU) 2025/2518, standardises how European data protection authorities handle cross-border enforcement of the General Data Protection Regulation (GDPR). It entered into force on 1 January 2026 and applies to new cross-border cases from 2 April 2027, bringing binding investigation deadlines, a single EU-wide admissibility standard for complaints, and formal defence rights for businesses under investigation.
The regulation changes how enforcement runs. The substantive rules of the GDPR - what you may do with personal data, when you need consent, how fines are calculated - stay exactly as they are.
Key takeaways:
Regulation (EU) 2025/2518 was published in the Official Journal on 12 December 2025, entered into force on 1 January 2026, and applies to complaints lodged and investigations opened after 2 April 2027.
Lead authorities must submit a draft decision within 15 months of confirming competence in a cross-border case, extendable once by up to 12 months for complex investigations.
Complaints face one admissibility standard across all EU member states, and an authority that finds a complaint incomplete must declare it inadmissible within two weeks and give reasons.
Businesses under investigation gain a right to be heard on preliminary findings and access to the administrative file, with trade secrets and confidential material protected.
The regulation is procedural only: GDPR obligations, cookie consent rules, and Article 83 fine levels do not change.
What Is the GDPR Procedural Regulation?
The GDPR Procedural Regulation is an EU regulation that lays down additional procedural rules for enforcing the GDPR in cases concerning cross-border processing - situations where a company's data handling affects people in more than one member state. It runs to 37 articles and 68 recitals, and it slots into the GDPR's existing one-stop-shop mechanism rather than replacing it.
That mechanism was the problem it set out to fix. Under Article 60 of Regulation (EU) 2016/679, a single lead supervisory authority - normally the regulator where a company has its main EU establishment - handles cross-border cases in cooperation with the other authorities concerned. In practice, each authority ran its own national administrative procedure. A complaint admissible in one country could be rejected in another for a missing formality, the rights of complainants and companies depended on where the case happened to run, and headline investigations dragged on for years. Ireland's Data Protection Commission, lead authority for many large technology firms, became the most visible example - its enforcement record was shaped as much by procedural friction as by the merits of each case.
The European Commission proposed the fix on 4 July 2023 as COM(2023) 348. The European Data Protection Board (EDPB) and the European Data Protection Supervisor assessed the draft in their Joint Opinion 01/2023, welcoming the aim while proposing amendments. The European Parliament adopted its first-reading position on 21 October 2025, the Council followed on 17 November 2025, and the final act was signed on 26 November 2025 and published in the Official Journal on 12 December 2025.
When Does the GDPR Procedural Regulation Apply?
The regulation entered into force on 1 January 2026 and applies from 2 April 2027. The 15-month gap is deliberate: supervisory authorities need that time to build the case-management systems, translation workflows, and cooperation channels the new procedure assumes.
Transitional rules keep ongoing cases under the old regime. The new procedure covers complaints lodged after 2 April 2027 and investigations that authorities open on their own initiative after that date, while disputes referred to the EDPB under Article 65 of the GDPR follow the new rules only where the referral happens after the application date.
As of August 2026, that build-out is under way across national authorities. For businesses the practical effect is a countdown: any cross-border complaint filed from 2 April 2027 onwards runs on the new clock.
How Does Enforcement Change Compared to Today?
The shift is easiest to see side by side.
| Aspect | Under the GDPR alone | From 2 April 2027 |
|---|---|---|
| Complaint admissibility | National rules differ per member state | One EU-wide information standard; incomplete complaints declared inadmissible within two weeks, with reasons |
| Investigation deadline | None | Draft decision within 15 months of the lead authority confirming competence, extendable once by up to 12 months for complex cases |
| Straightforward cases | Same full procedure for everything | Simple cooperation procedure with a 12-month draft-decision deadline |
| Involving other authorities | Often only at the draft-decision stage | Summary of key issues shared within three months; comments within four weeks |
| Right to be heard | Varies by national law | Guaranteed on preliminary findings before an adverse decision |
| Access to the file | Varies by national law | Access to the administrative file, with trade secrets protected |
| Early resolution | No common mechanism | Complaints can close early where the infringement has ended and the complainant does not object within four weeks |
How Do Cross-Border Investigations Change?
The biggest shift is time discipline. A lead authority must put a draft decision on the table within 15 months of confirming it is competent to handle a case, may extend once by up to 12 months if the investigation is genuinely complex, and has to involve the other authorities concerned within the first three months rather than at the end.
Binding Deadlines With a Complexity Valve
The 15-month clock starts when the lead authority confirms its competence and ends with a draft decision under Article 60(3) of the GDPR. An extension is allowed once, for no more than 12 months, and only on grounds of complexity - the authority must tell the other regulators the duration of and reasons for the extension at least four weeks before the original deadline expires. Cases handled under the simple cooperation procedure carry a tighter 12-month deadline.
Missing a deadline does not invalidate the eventual decision. It does count against the authority when a court assesses whether a complaint was handled in line with the complainant's right to an effective judicial remedy, which turns chronic delay from a grievance into a litigation risk for the regulator itself.
Cooperation Moves to the Front of the Case
Once the lead authority has formed a preliminary view, it must draft a summary of key issues and share it with the other supervisory authorities concerned within three months of confirming competence. Those authorities get four weeks to comment, and the lead authority then has four weeks to say whether and how it will take the comments on board. The aim is to surface disagreements early, when they are cheap to resolve, rather than at the draft-decision stage where they trigger formal dispute resolution before the EDPB.
For clear-cut cases there is a lighter track. The lead authority can propose the simple cooperation procedure within six weeks of confirming competence, and if no other authority objects within two weeks, the case proceeds without the summary-of-key-issues step.
What Do Complainants Get Under the New Rules?
A complaint lodged anywhere in the EU is judged against the same admissibility checklist, and a complainant whose complaint is heading for rejection gets the chance to respond first. The regulation also creates an early resolution route, so a grievance that has already been fixed can end without a multi-year procedure.
The admissibility change matters more than it sounds. Until now, a complaint accepted without question in one member state could fail in another over a formality. From April 2027 the required information is fixed EU-wide, and an authority that considers a complaint incomplete must declare it inadmissible within two weeks of receiving it and explain why.
Early resolution works on a simple mechanic. Where the authority considers that the alleged infringement has been brought to an end and the complaint is therefore devoid of purpose, it informs the complainant in plain language, and the complainant has four weeks to object. Silence closes the case; an objection sends it back into the normal procedure.
For website owners, the most likely entry point into all of this is a complaint about cookies or tracking. What to do when a cookie compliance complaint lands is worth rehearsing before the new procedure makes the timetable stricter.
What Rights Do Businesses Under Investigation Gain?
Companies gain the procedural rights that until now depended on which member state led the case: written preliminary findings, a genuine right to be heard before any adverse decision, and access to the administrative file, with trade secrets shielded from disclosure.
Before a lead authority can move towards a decision against you, it must set out its allegations in preliminary findings and give you the opportunity to respond. The final decision may only address infringements raised in those findings and may only rely on facts you had the chance to comment on. That single rule imports a defence-rights logic familiar from EU competition proceedings into GDPR enforcement.
Access to the file comes with confidentiality rules attached. Material counts as confidential where it contains trade secrets as defined in Directive (EU) 2016/943 or other information protected under EU or national law, and parties are expected to flag confidential content at the moment they submit it - a discipline worth building into how your legal and engineering teams answer regulator requests.
None of this softens outcomes. The two-tier structure and assessment criteria for penalties under Article 83 of the GDPR are untouched; the procedure around them simply becomes more predictable.
Does It Change Cookie Consent or Fine Levels?
No. The regulation adds no substantive obligations and removes none. Cookie consent requirements still come from the national laws transposing the ePrivacy Directive, working alongside the GDPR's consent standard, and fine ceilings stay at EUR 20 million or 4 percent of worldwide annual turnover, whichever is higher.
Two distinctions save confusion here. Cross-border processing, the trigger for this regulation, means processing that affects people in several member states or spans establishments in more than one country; it is a different concept from cross-border data transfers to countries outside the EU, which follow Chapter V of the GDPR. And the regulation is an EU instrument, so it does not apply in the UK, where UK GDPR enforcement by the Information Commissioner's Office follows its own procedure.
What does change is exposure timing. If your cookie consent setup fires trackers before consent, a cross-border complaint filed from April 2027 enters a system built to reach a draft decision within 15 months instead of drifting for five years.
How Is This Different From the Digital Omnibus?
They are separate tracks. The Procedural Regulation is adopted law that changes how the GDPR is enforced. The Digital Omnibus is a Commission proposal from 19 November 2025 that would change what the GDPR requires - definitions, breach reporting, and the way cookie consent is regulated.
Their status could hardly differ more. The Omnibus package's artificial intelligence half was signed on 8 July 2026 and amends the AI Act. The data half, the part touching the GDPR and the ePrivacy Directive, remained under negotiation in the Council through the summer of 2026 after member states failed to agree a common position in June and the file passed to the Irish presidency. Plan around the Procedural Regulation as settled law, and treat the Omnibus's GDPR changes as a moving target.
How Should You Prepare Before April 2027?
Preparation is mostly documentation discipline. A procedure with fixed clocks rewards companies that can produce evidence quickly: which regulator would lead your case, what you process across borders, and proof of the consent you collected.
Map your lead authority. Your main EU establishment determines which regulator takes the lead in a cross-border case, so know the answer before a complaint decides it for you.
Keep your records of processing activities current. They are the first document an investigator reads and the fastest way to show the true cross-border scope of what you do.
Preserve consent evidence. A faster procedure leaves less time to reconstruct history, and timestamped logs answer the most common allegation - trackers firing before consent - in minutes. A consent management platform that stores proof of each choice gives you that trail; Kukie.io keeps a per-visitor consent log you can export when a regulator asks.
Rehearse complaint intake. Route privacy complaints to someone who can assess and act within days, because early resolution only helps businesses that fix problems before an authority formalises the case.
Frequently Asked Questions
When does the GDPR Procedural Regulation start to apply?
It entered into force on 1 January 2026 but applies from 2 April 2027. It covers complaints lodged and own-initiative investigations opened after that date, so cases already running continue under existing national procedures.
Does the GDPR Procedural Regulation change GDPR fines?
No. The fine ceilings and assessment criteria in Article 83 of the GDPR are unchanged. The regulation standardises the procedure that leads to a decision, including deadlines, cooperation steps, and defence rights.
Does the new regulation apply to purely national GDPR cases?
No. It applies only to cases concerning cross-border processing, where a lead supervisory authority cooperates with authorities in other member states. Purely domestic investigations stay entirely under national procedural law.
What happens to GDPR investigations already open before 2 April 2027?
They continue under the current rules. The new procedure applies to complaints lodged after 2 April 2027 and to investigations that authorities open on their own initiative after that date.
Is the GDPR Procedural Regulation the same as the Digital Omnibus?
No. The Procedural Regulation is adopted law that governs enforcement procedure. The Digital Omnibus is a separate legislative proposal to amend the substance of the GDPR, and its data protection provisions were still under negotiation in the Council as of mid 2026.
What deadlines do supervisory authorities face under Regulation (EU) 2025/2518?
A lead authority must share a summary of key issues within three months of confirming competence and submit a draft decision within 15 months, or within 12 months under the simple cooperation procedure. One extension of up to 12 months is allowed for complex cases.
Get Your Consent Evidence in Order
If a cross-border complaint about your cookies arrived tomorrow, the real question is whether you could prove what visitors consented to and when. Kukie.io scans your site, categorises the cookies it finds, and records each visitor's consent choice so the evidence exists before anyone asks for it.
