This Practice Note tracks key developments in relation to the European Commission’s reforms to the procedure for enforcement of the EU’s General Data Protection Regulation (EU) 2016/679 (EU GDPR) in cross-border cases. The reform takes place via Regulation (EU) 2025/2518 (the Procedural Regulation). This tracker summarises legislative and regulatory developments in addition to letters, opinions, responses, recommendations and advice issued by EU institutions, bodies, associations, offices and agencies. Note that the Procedural Regulation (reform to procedure in cross-border cases) is separate from the proposals for simplification of record-keeping rules and other ‘Digital Omnibus’ package changes to the EU GDPR—for more on that score, see instead Practice Notes: EU 2024–2029 simplification agenda—tracker and EU Digital Omnibus—tracker. Background to the proposal for EU GDPR procedural rules Under the EU GDPR, independent national data protection authorities, also known as supervisory authorities (SAs), have been tasked with its enforcement and are expected to co-operate and adopt shared decisions under the ‘one-stop-shop’ mechanism. Ultimately, this ‘one-stop-shop’ mechanism allows operators to deal with a single SA in cross-border data protection cases, while