In a rapidly evolving digital age, the European Union has frequently been to forefront of data protection and cybersecurity regulation, often bringing it into direct conflict with US tech tycoons. In 2025 and beyond, several key trends and regulatory developments are shaping the data security landscape across the EU.
EU Data Security
Recent years have seen a significant increase in cyber threats and data breaches across Europe. According to the European Union Agency for Cybersecurity (ENISA), cyber-attacks in the EU increased by 57% in 2023 compared to the previous year
This surge in malicious activity has prompted both public and private sectors to bolster their cybersecurity measures. The cost of data breaches continues to rise, with the average total cost of a breach in Europe reaching €4.88 million in 2024, a 10% increase from 2023. Healthcare remains the most expensive industry for data breaches, with an average cost of €9.77 million per incident
General Data Protection Regulation (GDPR)
GDPR remains the cornerstone of data protection in the EU. Since its implementation in 2018, it has significantly impacted how organisations handle personal data. Recent statistics highlight its ongoing importance; over 144,000 queries and complaints and 89,000 data breaches were logged by EEA Supervisory Authorities in the first year of GDPR implementation and as of 2024, fines for GDPR violations have exceeded €4.2 billion. 66% of EU citizens are aware of the GDPR, with 36% well-informed about its implications.
Network and Information Security Directive 2 (NIS2)
The NIS2 Directive, which came into effect on October 17, 2024, expands the scope of cybersecurity regulation to a wider group of “essential entities” across various sectors.
It introduces stricter cybersecurity risk management requirements and reporting obligations, aiming to enhance the overall resilience of the EU’s digital infrastructure.
Cyber Resilience Act (CRA)
Also adopted in 2024, the CRA introduces EU-wide cybersecurity requirements for hardware and software products.
It aims to ensure that products with digital elements are secure throughout their lifecycle and supply chain. The regulation will apply 36 months after its entry into force, with some provisions taking effect earlier
Emerging Trends
The intersection of AI and data protection is becoming increasingly important. In December 2024, the European Data Protection Board (EDPB) adopted Opinion 28/2024, addressing data protection aspects related to AI models.
The EU AI Act, passed in 2024, introduces risk-based regulations for AI systems, with potential fines of up to €35 million or 7% of global turnover for severe breaches.
The EU is also intensifying its efforts to improve cybersecurity across member states. The European Cyber Resilience Act, expected to be fully implemented by 2025, will introduce new cybersecurity obligations for providers of hardware and software products containing digital elements.
Data Sovereignty and Cross-Border Transfers
Following the Schrems II ruling in 2020, which deemed the EU-US Privacy Shield invalid, the EU has been working on new mechanisms for international data transfers. The EU-US Data Privacy Framework, adopted in July 2023, aims to facilitate personal data transfers to participating US entities.
Enforcement and Cooperation
The EU is strengthening cooperation between national data protection authorities to enhance GDPR enforcement. In June 2024, the Council agreed on a position to improve cooperation in cross-border cases, aiming to speed up complaint handling and investigations.
Industry experts and policymakers have weighed in on the evolving data security landscape in the EU: “Data protection is a key fundamental right and the GDPR is the EU’s most powerful tool to safeguard it. Now the EU is taking an important step to make enforcement of this law more efficient,” stated Paul Van Tigchelt, Minister of Justice.
Tim Golden, Founder & CEO at Compliance Risk, commented on the need for unified regulation: “The U.S. is long overdue for a single, comprehensive data privacy rule. We could learn a lot from the EU’s GDPR”
Andrea Jelinek, Chair of the EDPB, reflected on the first year of GDPR implementation: “It has been a challenging first year, but we have reached the goals that we set out to achieve, and we intend to keep up both the work and the pace”
Future Challenges
Despite significant progress, the EU faces several challenges in maintaining robust data security:
- Balancing innovation with data protection, particularly in emerging technologies like AI and IoT.
- Harmonising the growing number of data-related regulations to ensure consistency and avoid conflicts.
- Addressing the shortage of cybersecurity professionals, with 363,000 unfilled positions reported in 2023.
- Adapting to evolving cyber threats, including the potential misuse of AI in cyber attacks.
- The return of Donald Trump as US President and his aggressive approach to European policies on everything from tech to trade, will present its own challenges. Allied to that, his close relationship with tech billionaire Elon Musk, who has embarked on a campaign to openly destabilise centrist EU governments, and the UK administration, makes this a hybrid threat. Meta CEO Mark Zuckerberg has also crossed the Rubicon to side with Trump, dismantling US factchecking for Facebook, Threads and Instagram. While such checks remain in the EU, there will undoubtedly be moves to weaken any sort of restrictions on what some call free speech, but what could often also be called disinformation.
The EU is likely to continue refining its regulatory approach to data security. The European Commission’s 2024 report on the state of cybersecurity in the Union aims to provide policymakers with an evidence-based overview of the cybersecurity landscape and capabilities at EU, national, and societal levels.
As Ursula von der Leyen, European Commission President, said in her 2021 State of the Union address: “If everything is connected, everything can be hacked. Given that resources are scarce, we have to bundle our forces. This is why we need a European Cyber Defence Policy, including legislation setting common standards under a new European Cyber Resilience Act.”
The EU’s approach to data security continues to evolve, as do the threats to it, driven by technological advancements and the need for harmonised regulation across member states. As the digital landscape becomes increasingly complex, the EU’s regulatory framework aims to strike a balance between fostering innovation and protecting the fundamental rights of its citizens. Technology organisations operating within the EU must remain vigilant and adaptable to navigate this dynamic regulatory environment successfully, while the EU faces its own challenges to reinforce digital accountability and responsibility in an increasingly unstable world.
