And yet there isn't a single data law for the whole of the EU. Every country has enacted a law but none are the same. Fro example you can't have encrypted data in France unless you're willing for the government to have access to the keys. The British government is so concerned by this that in many of it's contracts with it's suppliers it actively bans them from holding any data outside the UK boarders and it isn't just the type of data you'd imagine like defence or security services stuff it is mundane stuff like TfL fine data etc. Capita found out this to their cost when they wanted to move large parts of their operations to Poland ( and indeed India ) only for the government to block it.
I was referring to the Cancer Research example which relates to personal identifiable information (PII) and sensitive personal identifiable information (SPII) which is EU wide: EU Data Protection Directive (EUDP)