GDPR Procedural Regulation published; new cross-border enforcement rules apply from April 2027

December 12, 2025

About: GDPR

#program-changes #enforcement

On December 12, 2025, the European Union published Regulation (EU) 2025/2518, the GDPR Procedural Regulation, in the Official Journal. Adopted by the Parliament and Council on November 26, 2025, it entered into force on January 1, 2026 and applies from April 2, 2027 to cross-border complaints lodged and investigations opened on or after that date. It is the first EU law to change how GDPR is enforced since the regulation took effect in 2018; the GDPR text itself is unchanged.

This item was added to the change feed when the GDPR page launched on this site, so followers can see the kind of legislative change a subscription covers. It is not a new announcement.

What changed

GDPR’s one-stop-shop was meant to let one lead supervisory authority handle a company’s cross-border processing while consulting the others. In practice, national procedures differed so much that large cases took years and complainants and companies got different treatment depending on where the case sat. The Procedural Regulation lays a common layer over the national rules for cross-border cases:

  • Harmonized complaint handling. A common form and admissibility rules for cross-border complaints, and an early-resolution route when the organization has already fixed the issue.
  • A cooperation file and simplified procedure. Lead and concerned authorities work from a shared file in a common electronic tool, with a lighter “simple cooperation procedure” for straightforward cases.
  • Deadlines. Most investigations are to conclude within 15 months, extendable for complex matters, and simplified cases within about 12 months. Dispute resolution at the EDPB gets its own timelines.
  • Rights for the organization under investigation. A right to be heard on preliminary findings before a draft decision, and access to the administrative file, at set points in the procedure.
  • Rights for complainants, including being heard before a complaint is rejected.

Purely domestic complaints and investigations are outside the regulation; national procedure continues to govern them. Cases already open on April 2, 2027 stay under the old rules.

Why it matters

For organizations processing EU personal data across borders, enforcement will be faster and more predictable, and the procedural rights are a genuine gain. The trade-off is that authorities will ask for your evidence pack, records of processing, impact assessments, lawful-basis documentation, and vendor agreements, earlier and against a clock. A program that exists on paper but cannot produce documents in weeks will feel the difference.

What to do now

  1. Read the regulation, especially Chapters III and IV on cooperation and the rights of parties under investigation.
  2. Check that your record of processing, DPIAs, legitimate-interest assessments, and processor agreements are current and retrievable; they are what an investigation will request first.
  3. Confirm who your lead supervisory authority is (main establishment) or, if you have no EU establishment, which authorities your customers’ complaints would land with.
  4. See the GDPR page for who enforces the regulation, what it requires, and how compliance is demonstrated.
  5. Follow GDPR on this site for the April 2027 application date, EDPB guidance on the new procedure, and the Digital Omnibus negotiations.

#program-changes#enforcement

← Back to news