The EU's General Data Protection Regulation, effective 2018, doesn't explicitly mandate HTTPS by name — but its broader requirement for "appropriate technical measures" to protect personal data in transit was widely interpreted by legal and security guidance as effectively requiring encrypted connections for any site collecting personal data from EU residents.
The practical effect
Combined with the browser-level pressure already building from Chrome's "Not Secure" warnings around the same period, GDPR gave European organizations an additional, compliance-driven reason to prioritize HTTPS migration that had previously been treated as a lower-priority technical task rather than a legal consideration.
What GDPR's actual text says about encryption specifically
GDPR's Article 32 requires appropriate technical and organisational measures to ensure a level of security appropriate to the risk, explicitly naming encryption as an example of such a measure — while this stops short of a specific, unambiguous HTTPS mandate, the practical legal and compliance guidance that followed consistently interpreted this as requiring encrypted transmission of personal data in essentially all realistic circumstances.
How this compares to more explicit legal mandates elsewhere
Some other jurisdictions have since gone further than GDPR's general appropriate measures language, with certain sector-specific regulations, particularly around healthcare and financial data, explicitly naming HTTPS or TLS as a required control rather than leaving the specific mechanism open to interpretation.
How GDPR's extraterritorial reach affected non-EU sites
GDPR's requirements apply to any organization processing personal data of EU residents regardless of where the organization itself is based, meaning the regulation's practical influence on HTTPS adoption extended well beyond EU-based businesses to any global site with EU visitors — a significant factor in GDPR's outsized influence on general, worldwide security practice beyond its formal EU jurisdiction.
Specific enforcement actions that referenced inadequate encryption
While GDPR enforcement actions rarely cite missing HTTPS as the sole violation, several published enforcement decisions and regulatory guidance documents from EU data protection authorities have referenced inadequate transport encryption as one contributing factor in broader findings of inadequate technical security measures, reinforcing the practical legal expectation even without an explicit standalone HTTPS mandate.
Whether similar regulation exists outside the EU with comparable effect
Several other jurisdictions have since introduced broadly comparable data-protection frameworks partly modeled on GDPR, including California's CCPA and various national laws elsewhere, generally carrying similar general security-measure language that legal guidance has again interpreted as expecting encrypted transmission of personal data.
Why GDPR's indirect influence is arguably more significant than any explicit technical mandate would have been
GDPR's deliberately general appropriate measures language, rather than a specific prescriptive HTTPS requirement, arguably had broader practical influence than a narrow technical mandate might have, since it pushed organizations to think about encryption as part of a holistic risk-based compliance obligation rather than a narrow checkbox — encouraging broader security investment beyond HTTPS alone as a side effect of the general framing.
A closing thought on regulation as an indirect but genuine adoption driver
GDPR's HTTPS-adjacent influence is a useful reminder that not every significant driver of security adoption is itself explicitly security-focused legislation — broader privacy and data-protection regulation can meaningfully shape technical security practice as a secondary effect, sometimes as powerfully as security-specific rules would have.
GDPR's indirect influence on HTTPS adoption shows how broad privacy regulation can shape technical practice as powerfully as security-specific rules.