The regulation that makes every website ask you about cookies is a lot more than an annoying pop-up. It decides who may collect your data, how long they may keep it, and what it costs when they break the rules.
Personal data is anything someone can identify you by. Name and email, of course. But also where your phone is at seven every morning. From that alone you can tell where you live, where you work and who you visit after work.
The regulation says a few simple things. You need a lawful basis to collect. You have to say honestly what you do with the data. You don't keep more than you need, or longer than you need. And you have to be able to prove you do all of this, not just claim it.
An example from this autumn
On September 21, 2026 Ireland's Data Protection Commission fined Google €403 million over location data collected between May 25, 2018 and February 4, 2020. According to the decision, Google breached the lawfulness and fairness of processing, transparency, and the storage limit. The inquiry began in February 2020 after complaints from consumer organisations. The decision came six and a half years later.
Why this is an AI story
Models feed on data, and agents read your email and your calendar. Every time an AI product touches personal data of people in the EU, GDPR is in the room, next to the DSA and the EU AI Act. On the same day as the fine, the European Data Protection Board (EDPB) adopted its final guidelines on how GDPR and the DSA fit together.