Personal data after GDPR: new legal challenges

Barbashyn Law Team Serhiу Barbashyn — Attorney-at-Law, Managing Partner at Barbashyn Law Firm | Andriу Barbashyn — Acting Head of the IT Law Department at Barbashyn Law Firm, USF Expert
29 July, 2026 5 minutes read
29 July, 2026 5 minutes read

More than eight years have passed since the GDPR came into force, yet the Regulation remains the key international legal instrument in the field of personal data protection. Its provisions are essential not only for the countries of the European Union but also for international businesses operating across different parts of the world.

This is evidenced by enforcement practice: in 2025 alone, EU regulatory authorities imposed GDPR-related fines totaling more than €1.15 billion.

In this article, we examine the key challenges in applying the GDPR to personal data, artificial intelligence, cookies and targeted advertising, cross-border data transfers, and the processing of biometric and other sensitive information.

Expansion of the concept of personal data

The modern interpretation of personal data has long extended beyond traditional information such as a name, phone number, or email address. The GDPR is based on the principle that personal data includes any information that directly or indirectly allows an individual to be identified.

Today, this category may include IP addresses, cookies, geolocation data, device identifiers, app usage history, biometric information, and digital user profiles. In many cases, it is the combination of such data that makes it possible to identify an individual, even if each individual element alone is not sufficient for this purpose.

A significant influence on the development of the modern approach to interpreting the concept of personal data was the case against Germany, in which it was established that a dynamic IP address may also constitute personal data if there is a legal means of identifying the user through additional information.

Moreover, this approach is supported by the case law of the European Union. In particular, pseudonymised data do not cease to be personal data if an individual can be identified using “reasonable means.” Therefore, the key criterion is not the method of storing the data or how it is classified, but whether it can be linked to a specific individual.

In practice, this also means that the use of web analytics, personalisation services, or advertising technologies almost always involves the processing of personal data. Therefore, it is important to analyse not individual datasets in isolation, but the entire digital footprint of an individual generated through their activities on websites, mobile applications, and online services.

Artificial Intelligence and Automated Decision-Making

The rapid growth of artificial intelligence has fundamentally changed the way personal data is handled. Today, personal data is increasingly used to train AI models, automate candidate screening, assess creditworthiness, personalise advertising, and determine pricing.

At the same time, the use of AI does not exempt organisations from GDPR requirements. On the contrary, the greater the autonomy of an algorithm, the more attention must be paid to compliance with the fundamental principles of personal data protection.

In particular, companies should pay attention to the following aspects:

  • Lawfulness of processing — the use of personal data to train or improve AI models must always have an appropriate legal basis and be consistent with the purpose for which the data was originally collected. For example, in 2025, the Italian regulator fined an AI chatbot developer €5 million for lacking an appropriate legal basis for processing users’ personal data;
  • Transparency — individuals should be informed when AI is used in decision-making and understand how their personal data is processed. For example, a candidate who receives an automated rejection should know that their CV was assessed by an AI system rather than solely by a recruiter;
  • Right to challenge — automated decisions should not be final where they produce legal or similarly significant effects on an individual. For example, if a person is denied a loan, they should be able to request a review of the decision by an authorised bank employee rather than simply undergo another automated assessment by the algorithm. Moreover, 84% of Europeans believe that the use of artificial intelligence requires appropriate regulation to protect privacy and ensure transparency.

The quality of the data used to train AI models also deserves particular attention. Incomplete, inaccurate, or biased data may lead to discriminatory outcomes and create legal risks for companies. Therefore, the implementation of AI should be accompanied by proper personal data governance and compliance with GDPR requirements.

Cookies, Targeted Advertising, and the Challenge of Genuine Consent

Cookies are no longer merely a technical tool used to operate websites. Today, they are one of the key mechanisms for collecting data about user behaviour, enabling companies to create detailed digital profiles and deliver personalised advertising.

At the same time, practice shows that formal consent does not always mean that consent has been given freely. Increasingly, users agree to the processing of their data not because they genuinely want to, but because they have no real alternative or because the opt-out mechanism is unnecessarily complicated.

For businesses, this means that even formally obtained consent may be deemed invalid if it does not meet the GDPR requirements for being freely given and informed. A notable example is the decision by CNIL, which in 2025 fined Google €325 million, including for placing cookies during the creation of Google accounts without obtaining valid user consent.

Therefore, when assessing whether consent is valid, particular attention should be paid to the following aspects:

  • Freedom of choice — consent must be the result of a freely made decision, rather than the result of pressure or a lack of alternatives. For example, the “pay or consent” model has sparked debate, as users are effectively required either to agree to the use of their data for targeted advertising or to pay for access to the service;
  • Clarity of the consent mechanism — users should be able to accept or reject non-essential cookies with equal ease. For example, if the “Accept all” button is prominently displayed while the option to reject cookies is hidden behind several layers of settings, such consent can hardly be considered fully informed;
  • Specificity of purpose — users should understand exactly why their data is being collected and how it will be used. For example, consent to the use of cookies necessary for the operation of a website does not automatically constitute consent to creating a behavioural profile or using the data for personalised advertising.

The subsequent use of collected data is another pressing issue. Information obtained through cookies is often shared with advertising platforms and analytics services. Therefore, it is particularly important to ensure transparency in such processing and inform users who has access to their data and for what purposes.

Cross-Border Data Transfers, Cloud Services, and Cyber Risks

The digitalisation of business has made it increasingly rare for personal data to remain within a single country. The use of cloud services, international platforms, and AI solutions means that information may be processed simultaneously across multiple jurisdictions, each of which has its own data protection requirements.

For this reason, cross-border transfers of personal data remain one of the most complex issues in the application of the GDPR. It is not enough for companies to know where their servers are physically located. It is equally important to understand who has access to the data, whether sub-processors are involved, and whether the legislation of the relevant country provides a level of protection equivalent to European standards.

An important reference point in this area was the CJEU’s decision in the Schrems II case, which invalidated the Privacy Shield mechanism for data transfers between the EU and the US. The Court effectively confirmed that the use of international services does not, in itself, guarantee adequate protection of personal data. Controllers must independently assess the risks associated with such transfers and implement additional safeguards where necessary.

Cyber incidents and personal data breaches remain another significant challenge. Transferring information to a cloud provider does not relieve a company of its responsibility to protect that data. Therefore, controllers must assess the risks associated with working with digital service providers, monitor data processing activities, and respond promptly to security breaches.

The practical significance of these requirements is demonstrated by a decision of the Irish regulator, which in 2025 fined TikTok €530 million for GDPR violations related to the transfer of EEA users’ personal data to China. This demonstrates that risks arise not only from where data is physically stored, but also from the possibility of accessing it from third countries.

Biometric and Sensitive Data: The Limits of Permissible Processing

Biometric and other sensitive personal data belong to the category of information associated with an elevated level of risk, as they are directly linked to an individual’s unique physiological or behavioural characteristics.

Their key feature is their permanence. Unlike passwords or other identifiers, such data cannot simply be “reissued” if compromised. This also means that the consequences of their unlawful use may be long-lasting and potentially irreversible.

In practice, biometric technologies have already been integrated into a wide range of digital services, particularly in the following areas:

  • user authentication on mobile devices (Face ID, fingerprints);
  • physical access control systems for employees accessing premises and information resources;
  • video surveillance with automated facial recognition;
  • medical and fitness applications that process users’ health data.

At the same time, the level of risk associated with such technologies largely depends on the context in which they are used.

The use of biometric data for individual user authentication, such as unlocking a device, involves a relatively limited intrusion into privacy. By contrast, its use in mass surveillance systems or for continuous monitoring of employees or visitors creates a significantly higher level of risk and requires stronger justification of the necessity and proportionality of such processing.

A practical example of this approach can be found in a decision by the UK regulator, which ordered a company to stop using facial recognition and fingerprint technologies to monitor employees’ working hours because the company failed to demonstrate that this particular method of processing was necessary and proportionate to achieve the intended purpose.

Another significant area of risk concerns the processing of health data, which by its nature belongs to the most sensitive categories of information. Such data includes information about an individual’s physical condition, medical examination results, psychological and emotional characteristics, and other aspects of their health, the disclosure of which may have serious implications for their privacy.

This risk is illustrated by a case in which a company developing software and digital services for doctors and other healthcare professionals was fined €800,000 for violations of requirements governing the processing of health data.

Therefore, when combined with other digital sources, such data can enable the creation of highly detailed individual profiles, significantly increasing the risks of unauthorised use, discrimination, and loss of control over one’s personal information.

Conclusion

Thus, the GDPR remains a key benchmark in the field of personal data protection, covering both traditional processing models and modern digital technologies, from algorithmic systems and cookie tracking to cloud services and biometrics.

For businesses, GDPR compliance means more than simply having a privacy policy, a cookie banner, or standard contractual clauses. It requires continuous oversight of the personal data lifecycle, a sound legal basis for processing, transparency in algorithmic decision-making, proper assessment of service providers and international data transfers, as well as the effective exercise of data subjects’ rights.

Moreover, in 2025 alone, the EDPB reviewed 764 companies to assess how they ensure the implementation of the right to erasure of personal data. Regulatory practice also demonstrates a gradual shift from reviewing formal documentation to assessing the actual effectiveness of internal procedures. Therefore, companies must not only document their compliance but also be prepared to demonstrate that the measures they have implemented actually work, are regularly reviewed, and are appropriate to the nature and risks of the specific processing activities.

Ultimately, effective GDPR compliance is an ongoing process that requires a combination of legal, technical, and organisational expertise, as well as a timely response to developments in technology, case law, and regulatory approaches.

Published in Yurydychna Praktyka

Link to the article

Share

We use cookies to improve the performance of the site and enhance your user experience.

More information can be found in our Privacy Notice