EDPB Digest

Every document the European Data Protection Board has published, 543 of them as of 19 September 2026 (532 on the documents listing and 11 that were still at consultation stage), with one takeaway each. For 117 documents the takeaway is written from the document itself: what it establishes, who it binds and what to do about it. For the remaining 426, which are approvals of binding corporate rules, accreditation requirements, national DPIA lists, certification criteria, institutional reports and the Board's own procedures, a one-line description says what the document is so it can be ruled in or out in a second.

Two limits, stated up front. The choice of which documents earned a written takeaway follows the topics of this site (privacy operations, the AI Act, assessment tools), not the document's importance in general. And a takeaway is a reading aid, not a substitute: every entry links to the EDPB page, and the document governs where the two differ. Dates are the publication dates shown in the EDPB listing. Documents still at consultation stage on that date (guidelines, recommendations and templates adopted for public consultation but not yet final) sit in their own group, Consultation versions, dated by their adoption for consultation and marked consultation; the final text may differ.

Filters and search run in your browser. Nothing you type is sent anywhere. Every entry links to the EDPB page it describes.

Jump to a type:

Guidelines46 documents, 29 written

Guidelines 02/2024 on Article 48 GDPR

05 June 2025Read from the documenttransferscontroller processor

A request from a third-country court or authority is not in itself a legal basis for processing nor a ground for transfer: the controller or processor needs an Article 6 basis and a Chapter V transfer tool. A mutual legal assistance treaty or similar agreement can supply both, as a legal obligation or public interest task under Article 6(1)(c) or (e) and as appropriate safeguards under Article 46(2)(a); without one, the organisation still needs an Article 6 basis and a Chapter V ground, which in practice is usually a narrowly read Article 49 derogation, since a foreign authority rarely signs Article 46 safeguards. Processors receiving such requests must inform the controller promptly. Version 2.0 was adopted 4 June 2025 after consultation on the December 2024 draft; version 2.1 makes minor corrections.

Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive

16 October 2024Read from the documentcookies trackingconsent

Article 5(3) of the ePrivacy Directive applies whenever information, personal or not, is stored on or accessed from terminal equipment connected to a public communications network, and the guidelines read each element broadly. URL and pixel tracking, tracking based on an IP address originating from the user's device, unique identifiers collected by client-side code, IoT device reporting and local processing whose results are transmitted all fall within scope, so they need consent or a strict necessity exemption whether or not a cookie is used. Version 2.0, adopted 7 October 2024 after public consultation, applies to any provider of online services; audit all client-side scripts and identifiers, not just cookies.

Guidelines 04/2022 on the calculation of administrative fines under the GDPR

24 May 2023Read from the documentenforcement

Supervisory authorities calculate GDPR fines in five steps: identify the processing operations and apply Article 83(3), set a starting point from the seriousness of the infringement (0 to 10 percent, 10 to 20 percent or 20 to 100 percent of the legal maximum) adjusted for the undertaking's turnover, weigh aggravating and mitigating circumstances, apply the legal maximum, and check that the result is effective, proportionate and dissuasive. The guidelines bind authorities in their own practice and apply to controllers and processors that are undertakings. Use the method to model exposure and to evidence the mitigating factors, such as cooperation and remedial action, that reduce the amount.

Guidelines 01/2022 on data subject rights - Right of access

17 April 2023Read from the documentrights

The right of access has three parts: confirmation that data are processed, access to the data themselves, and the Article 15 information on purposes, categories, recipients, retention, rights and safeguards. Controllers must provide a free first copy, in a commonly used electronic form where the request was made electronically unless the person asks otherwise, respond within one month extendable by two, may layer large volumes only if all layers are available at once, must interpret manifestly unfounded or excessive narrowly and prove it, and may limit only the data, not the accompanying information, to protect others' rights. Build the response procedure around these points, since the EDPB ran a coordinated enforcement action on the right of access in 2024, reported in January 2025.

Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority

17 April 2023Read from the documentgovernanceenforcementcontroller processor

The lead supervisory authority for cross-border processing is the authority of the main establishment: for a controller the place of central administration in the Union unless decisions on purposes and means are taken and implemented elsewhere, for a processor its central administration or, failing that, where the main processing takes place. Version 2.1 adds that main establishment attaches to a single controller and cannot be extended to joint controllers, each of which keeps its own. Forum shopping is not permitted, and a processor working for a controller is supervised by the controller's lead authority. The guidelines replace WP244 rev.01; document the main establishment analysis with objective evidence.

Guidelines 9/2022 on personal data breach notification under GDPR

04 April 2023Read from the documentbreachsecurity

Controllers notify a personal data breach to the competent supervisory authority without undue delay and where feasible within 72 hours of becoming aware, unless it is unlikely to result in a risk, and communicate to data subjects only where the risk is high; every breach, notified or not, is documented under Article 33(5). Version 2.0 changes one point from WP250 rev.01, which it replaces: a controller not established in the Union but subject to Article 3(2) does not benefit from the one-stop-shop and must notify every supervisory authority whose Member State has affected data subjects. Non-EU controllers should map notification routes per Member State in advance.

Guidelines 03/2022 on deceptive design patterns in social media platform interfaces: how to recognise and avoid them

24 February 2023Read from the documenttransparencyconsentcookies tracking

Interfaces that push users into unintended or harmful choices about their data breach the fairness principle in Article 5(1)(a), transparency in Article 12, data minimisation in Article 5(1)(c) and data protection by design in Article 25. The guidelines sort such patterns into six categories, overloading, skipping, stirring, obstructing, fickle and left in the dark, across registration, privacy notices, consent and settings, rights requests and account closure. They address social media providers, designers and DPOs, and version 2.0 renames dark patterns as deceptive design patterns. Use the categories as a review checklist for any consent or settings interface, since the EDPB applied the same reasoning in Binding Decision 2/2023.

Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR

24 February 2023Read from the documenttransfers

A transfer under Chapter V requires three cumulative conditions: the exporter is subject to the GDPR for the processing, it discloses or makes data available to a separate controller or processor, and that importer is in a third country, whether or not itself subject to the GDPR. Direct disclosure by the data subject and access by the same controller's own employee abroad are not transfers, but remote access by a separate entity, even display on a screen, is. Version 2.0 confirms Chapter V applies to importers caught by Article 3(2) and adds twelve illustrated examples. Map every third-country access path, including support and administration, against the three criteria.

Guidelines 07/2022 on certification as a tool for transfers

24 February 2023Description

Guidelines on certification as a transfer tool under Article 46(2)(f): what a certification scheme must contain for a third-country importer to rely on it. The first scheme was approved for this use in April 2026 (Europrivacy, Opinion 15/2026); certification, the covered processing and the binding commitments must together satisfy Article 46(2)(f).

Guidelines 01/2021 on Examples regarding Personal Data Breach Notification

03 January 2022Read from the documentbreachsecurity

Eighteen fictional but representative cases across six categories, ransomware, data exfiltration attacks, internal human risk, lost or stolen devices and paper, mispostal and social engineering, show how to assess risk and decide whether to notify the supervisory authority under Article 33 and communicate to data subjects under Article 34. Each case sets out the prior security measures expected, the risk assessment, mitigation and resulting obligations, and complements the general notification guidance now found in Guidelines 9/2022. The guidelines address controllers; use the cases to calibrate an incident triage procedure, remembering that any change in circumstances can change the risk level and the outcome.

Guidelines 10/2020 on restrictions under Article 23 GDPR

13 October 2021Description

Guidelines on Article 23: Member State laws restricting data subject rights must be necessary, proportionate, foreseeable and time-limited, and cannot suspend rights wholesale. Relevant to legislators and public bodies.

Guidelines 02/2021 on virtual voice assistants

07 July 2021Read from the documentconsentbiometricscookies tracking

Virtual voice assistants fall under Article 5(3) of the ePrivacy Directive as well as the GDPR: storing or accessing data on the device requires prior consent unless strictly necessary to perform a service the user requested, and processing for improvement, personalisation or profiling needs consent under Article 6(1)(a). Voice recordings can be biometric data under Article 9, data captured through accidental activation has no legal basis and must be deleted, and indefinite retention breaches storage limitation. The guidelines apply to VVA providers, designers, application developers, device manufacturers and integrators. Map the roles in your VVA ecosystem and build voice-based ways to exercise access and erasure.

Guidelines 07/2020 on the concepts of controller and processor in the GDPR

07 July 2021Read from the documentcontroller processorgovernance

Controller and processor are functional, autonomous concepts fixed by who actually determines the purposes and the essential means of processing (data types, retention, recipients, data subjects), not by contractual labels; non-essential means can be left to the processor. Joint controllership arises from common or converging decisions that are inextricably linked, and needs a transparent Article 26 arrangement. An Article 28 contract must be specific to the processing rather than restating the GDPR, and sub-processors require prior authorisation. The guidelines apply to controllers, processors and supervisory authorities across the EEA; version 2.1 of 20 September 2022 is the current text of this 7 July 2021 version.

Guidelines 8/2020 on the targeting of social media users

13 April 2021Read from the documentmarketingcontroller processorlawful basis

Social media providers and targeters are generally joint controllers for targeting: the targeter chooses the audience criteria and the message, the platform decides which data and criteria are available, so an Article 26 arrangement is required. Article 6(1)(b) cannot support online advertising; legitimate interests requires the three cumulative conditions, and consent is needed for tracking-based profiling and wherever Article 5(3) of the ePrivacy Directive applies to cookies. Telling users merely that data is used for advertising is not transparent enough, inferred special category data rarely benefits from an Article 9(2) exception, and targeting of vulnerable groups calls for a DPIA. Version 2.0 of 13 April 2021 is final.

Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications

09 March 2021Read from the documentconsentdpiasecurity

Most data processed in and around a connected vehicle is personal data, since it can be linked to the driver, owner or passengers, and Article 5(3) of the ePrivacy Directive applies to storing or accessing information on the vehicle, so consent is required unless the access is strictly necessary for a service the user requested. Location, biometric and offence-related data get special treatment: minimise location data, keep biometrics local and encrypted with a non-biometric alternative, and process offence-related data locally under the user's control. Manufacturers, service providers, insurers, dealers, fleet managers and telecom operators are addressed, with worked cases on pay-as-you-drive insurance, rental, eCall and accident research. Version 2.0 of 9 March 2021 is final; prefer local processing and run a DPIA.

Guidelines 4/2019 on Article 25 Data Protection by Design and by Default

20 October 2020Read from the documentgovernancesecurity

Article 25 obliges controllers to implement appropriate technical and organisational measures that embed each data protection principle effectively into processing, chosen with regard to the state of the art, cost, the nature, scope, context and purposes of processing and the risks, and to demonstrate effectiveness, for example through key performance indicators. By default only data necessary for each purpose may be processed, judged by amount, extent, storage period and accessibility. The obligation applies when the means are determined and throughout processing, including legacy systems, and processors and producers should support it. Version 2.0 of 20 October 2020 is final; failure to implement it affects fines under Article 83(4).

Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1)

07 July 2020Read from the documentrights

A data subject may ask a search engine provider to delist results returned for a search on their name on any of the six grounds in Article 17(1) GDPR, and the provider may refuse under the five exemptions in Article 17(3). Delisting removes the link from name-based results only; the content stays on the source website and the request does not erase it there. Search engine operators should test each request against the grounds and then the exemptions, and document the balancing. Part 1 covers the grounds and exemptions; criteria for handling complaints are announced as a later part.

Guidelines 05/2020 on consent under Regulation 2016/679

04 May 2020Read from the documentconsentcookies trackinglawful basis

Valid consent under Article 4(11) GDPR must be freely given, specific, informed and an unambiguous affirmative act: pre-ticked boxes, silence and scrolling do not count, and access to a service must not be made conditional on consent to cookies, so cookie walls fail the freely given test. The guidelines apply to every controller relying on Article 6(1)(a), with public authorities and employers warned that the imbalance of power usually rules consent out. Controllers should separate consent by purpose, keep records that show what was asked and when, and make withdrawal as easy as giving consent. The guidelines replace WP29 Guidelines WP259 rev.01.

Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak

21 April 2020Description

Guidelines on processing health data for Covid-19 research: consent under Articles 6(1)(a) and 9(2)(a) can be the legal basis but must not be confused with the ethical consent to take part in a study, other research bases and Article 89 safeguards apply, and transfers may use Article 49 derogations in the emergency. Historical; the general points are in the 2026 scientific research guidelines.

Guidelines 3/2019 on processing of personal data through video devices

30 January 2020Read from the documentbiometricslawful basisdpia

Video surveillance falls under the GDPR whenever identifiable people are captured, and the household exemption does not cover a camera that films public space or an area open to an indefinite number of people. Public and private controllers must ground each camera in a lawful basis, usually legitimate interest backed by real and present threats or, for public bodies, a public-interest task, since Article 6(1)(f) is closed to authorities performing their tasks; consent cannot be inferred from entering a monitored area, and facial recognition that identifies people is biometric processing needing an Article 9(2) exception. Practitioners should post a layered notice at the entrance, keep retention to a few days unless longer is justified, and run a DPIA for large-scale systematic monitoring of publicly accessible areas.

Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) - version adopted after public consultation

12 November 2019Read from the documentgovernance

Article 3 GDPR is applied processing activity by processing activity, not to an organisation. Under Article 3(1) it reaches any processing carried out in the context of the activities of an EU establishment, wherever the processing happens, and a single employee with stable arrangements can be enough. Under Article 3(2) it reaches controllers and processors outside the EU that offer goods or services to people in the Union or monitor their behaviour, with mere website accessibility insufficient; those entities must generally appoint an Article 27 representative, who cannot be the DPO. Practitioners should map each processing activity against both criteria and name the representative in privacy notices.

Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects

16 October 2019Read from the documentlawful basismarketing

Article 6(1)(b) GDPR covers only processing that is objectively necessary to perform the contract with the data subject: writing a processing operation into the terms does not make it necessary, and a less intrusive way of delivering the service defeats the basis. For online service providers the guidelines rule out contractual necessity for behavioural advertising and service improvement metrics, treat fraud prevention as likely to exceed it, and allow personalisation only where it is integral to the service the user signed up for. Controllers should test each purpose separately against the contract, move purposes that fail to legitimate interests or consent, and record the assessment.

Automated decision-making and profiling

25 May 2018Read from the documentairights

Article 22(1) GDPR is a general prohibition on decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect a person; it lifts only where the decision is necessary for a contract, authorised by Union or Member State law, or based on explicit consent. Under the contract and consent exceptions the controller must provide human intervention that is meaningful rather than a token gesture, let the person express their view and contest the decision (for the legal-authorisation exception the law itself must lay down the safeguards), and explain the rationale and criteria in simple terms. Controllers should map each scoring or eligibility decision against Article 22 and run a DPIA where it applies.

Data Protection Officer

25 May 2018Read from the documentgovernance

A DPO is mandatory for every public authority or body except courts acting judicially, and for any organisation whose core activities involve large-scale regular and systematic monitoring of data subjects or large-scale processing of special category or criminal conviction data. The DPO must have expert knowledge of data protection law, may not be instructed on how to perform the tasks or be dismissed or penalised for doing them, reports to the highest management level and cannot hold a role that decides the purposes and means of processing. A voluntary DPO carries the same obligations, and a group may share one DPO who is easily accessible from each establishment.

Data Protection impact assessments High risk processing

25 May 2018Read from the documentdpia

A DPIA is required where processing is likely to result in a high risk, and the guidelines give nine indicators: evaluation or scoring, automated decisions with legal or similar effect, systematic monitoring, sensitive or highly personal data, large scale, matching or combining datasets, vulnerable data subjects, innovative use of technology, and processing that prevents people exercising a right or using a service. As a rule of thumb, processing meeting two of the nine criteria calls for a DPIA, and a decision not to do one should be documented. Residual high risk must go to the supervisory authority for prior consultation, and the assessment is reviewed as processing changes.

Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679

25 May 2018Read from the documenttransfers

Article 49 derogations are exceptions to be interpreted restrictively so that the exception does not become the rule: an exporter must first look for an adequacy decision under Article 45, then appropriate safeguards under Article 46, and only then a derogation. Most derogations cover only occasional, non-repetitive transfers, so a systematic flow within a stable business relationship cannot rest on them, and the compelling legitimate interests ground is a last resort limited to non-repetitive transfers of a limited number of data subjects, with safeguards and notification to the supervisory authority. Exporters should document why Articles 45 and 46 were unavailable before relying on a derogation.

Guidelines for identifying a controller or processor's lead supervisory authority, WP244 rev.01

25 May 2018Read from the documentsupersededgovernanceenforcement

The one-stop-shop gives a controller or processor engaged in cross-border processing a single lead supervisory authority, the one for its main establishment: normally the place of central administration in the EU, unless decisions on the purposes and means are taken and implemented elsewhere. The GDPR does not permit forum shopping; a supervisory authority may rebut a claimed main establishment and require evidence of where decisions are actually taken, and a controller with no EU establishment gets no lead authority at all. Processors follow the controller's lead authority for the processing concerned. EDPB Guidelines 8/2022, version 2.0 adopted 28 March 2023, replaced them.

Guidelines on Personal data breach notification under Regulation 2016/679, WP250 rev.01

25 May 2018Read from the documentsupersededbreachsecurity

A personal data breach can affect the confidentiality, integrity or availability of personal data, and not every security incident is one. A controller is aware once it has a reasonable degree of certainty that personal data have been compromised; it then has 72 hours where feasible to notify the supervisory authority unless the breach is unlikely to result in a risk, may notify in phases, and must communicate to data subjects without undue delay for high-risk breaches. Processors must notify the controller without undue delay, and every breach, notified or not, must be documented. The guidelines were replaced by EDPB Guidelines 9/2022, version 2.0 adopted 28 March 2023.

Guidelines on the right to data portability under Regulation 2016/679, WP242 rev.01

25 May 2018Read from the documentrights

The right to data portability under Article 20 GDPR lets a person obtain, and move to another controller, the personal data they gave to a controller, provided the processing runs on consent or contract and by automated means. 'Provided' data includes what the person typed in and what the controller observed from their activity; profiles and other inferred data are outside the right. The format must be structured, commonly used and machine-readable, the export free and unobstructed, and the receiving controller needs its own lawful basis for third-party data. Practitioners should confirm the lawful basis of each data set before deciding what is in scope.

Right to data portability

25 May 2018Read from the documentrights

Article 20 GDPR gives a data subject the right to receive the personal data they provided to a controller in a structured, commonly used and machine-readable format, and to have it transmitted directly to another controller where technically feasible. The right applies only where processing rests on consent or contract and is carried out by automated means; it covers data actively supplied and data observed from the person's use of the service, but not data the controller has inferred or derived. Exercising it triggers no erasure and must be free and unhindered. Controllers should map the data sets in scope and build an export path in advance.

Transparency

25 May 2018Read from the documenttransparency

Transparency under Articles 12 to 14 GDPR means information that is concise, transparent, intelligible and easily accessible, in clear and plain language: the reader should not have to seek it out, and qualifiers such as 'may', 'might', 'some' or 'often' should be avoided because they leave the reader unsure what actually happens. The obligation applies to every controller regardless of lawful basis and across the whole processing life cycle; Article 13 information is due when the data are obtained, Article 14 information within a month and earlier if the data are disclosed to a recipient. Layered online notices should put purposes, controller identity and rights in the first layer, and material changes must be actively communicated.

Article 29 Working Party - Guidelines on transparency under Regulation 2016/679

11 April 2018Read from the documenttransparency

Information given to data subjects under Articles 13 and 14 GDPR must be concise, transparent, intelligible and easily accessible, in clear and plain language that an average member of the intended audience understands; layered privacy statements online should put the highest-impact processing, purposes, controller identity and rights up front. Timing is fixed: at collection under Article 13, within one month under Article 14 and before any disclosure to a recipient. A material change to a notice, such as a new purpose, must be actively communicated; expecting people to check for updates is unfair. Every controller should audit its notices against these tests, whatever the lawful basis.

Recommendations7 documents, 4 written

Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)

20 June 2023Read from the documenttransfersgovernance

A single standard application form and a referential of mandatory elements now govern approval of controller binding corporate rules under Article 47, replacing WP256 rev.01 and WP264. The recommendations apply to any group applying for BCR-C and to every existing BCR-C holder, who must align their rules as part of the 2024 annual update, generally without a new approval. Applicants submit one copy to the presumptive BCR lead covering structure, data flows, binding mechanism, training, audit and the DPO network, and map each element of the referential to the BCR text before filing.

Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data

18 June 2021Read from the documenttransfers

Data exporters must follow a six-step roadmap after Schrems II: know your transfers, identify the transfer tool, assess whether third-country law or practice undermines it, adopt supplementary measures where needed, complete procedural steps and re-evaluate at appropriate intervals. The assessment must rest on relevant, objective, reliable, verifiable and publicly available or otherwise accessible information; the absence of prior access requests is never decisive on its own. Annex 2 gives technical, contractual and organisational measures, with encryption and pseudonymisation under keys the importer cannot reach, and split or multi-party processing, as the effective technical use cases. Version 2.0 of 18 June 2021 is final and applies to controllers and processors acting as exporters, who should document every step as the transfer impact assessment.

Recommendations 02/2021 on the legal basis for the storage of credit card data for the sole purpose of facilitating further online transactions

19 May 2021Read from the documentlawful basisconsent

Storing a customer's credit card data after a purchase, solely to make later purchases easier, can rest only on consent under Article 6(1)(a) GDPR. Contract performance does not apply because the transaction is complete, legal obligation is irrelevant, and legitimate interests fails the balancing test given the sensitivity of financial data and the customer's reasonable expectations. Consent must come from a clear affirmative act such as an unticked box, separately from the terms of service and never as a precondition of the purchase, and withdrawal must lead to deletion. Addressed to online goods and service providers in the EEA; apply it to every checkout that offers to remember a card.

Recommendations 02/2020 on the European Essential Guarantees for surveillance measures

10 November 2020Read from the documenttransfers

Four European Essential Guarantees define when third-country surveillance access to transferred data is compatible with EU fundamental rights: processing based on clear, precise and accessible rules; necessity and proportionality, with no generalised and indiscriminate access; an independent oversight mechanism with binding powers; and effective remedies before an independent body, including notification once it no longer jeopardises an investigation. Adopted on 10 November 2020, they update the WP29 working document WP237 of 2016 in light of Schrems II and ECtHR case law. Exporters apply them in step 3 of Recommendations 01/2020, and the Commission applies them in adequacy assessments under Article 45.

Consultation versions11 documents, 10 written

Guidelines 02/2026 on anonymisation (version for public consultation)

08 July 2026Read from the documentconsultation

Data is anonymous only when it no longer relates to an identified or identifiable person for the entity holding it, judged by content, purpose and effect; the test has three limbs, none of which may be met: no singling out of a record, no linking of records about the same person, and no inference of an attribute. The guidelines, which fold in the Court of Justice's September 2025 ruling in EDPS v SRB, allow a contextual assessment (what the actual recipients and reasonably likely third parties can do) or a simplified one applied uniformly. Consultation runs to 30 October 2026; treat every 'anonymised' export, training set or statistic against the three limbs now, and keep the assessment on file, since this is the standard supervisory authorities will apply once the text is final.

Guidelines 03/2026 on web scraping in the context of generative AI (version for public consultation)

08 July 2026Read from the documentconsultation

Scraping the web for personal data to train or ground a generative AI model is processing under the GDPR from the moment of collection, so the scraper needs a legal basis (in practice legitimate interests under the three-step test), purpose limitation and transparency, with the Article 14(5)(b) relief from individual notice only where informing people is impossible or disproportionate and public information is given instead. Controllers should scrape from reliable sources, respect machine-readable opt-outs, record timestamps and provenance, filter and validate data before training, and treat special category data as prohibited unless an Article 9(2) exception applies alongside the Article 6 basis. Consultation runs to 30 October 2026; read it with Opinion 28/2024 on AI models.

Template for personal data breach notification (version for public consultation)

10 June 2026Read from the documentconsultation

A common EU template for notifying personal data breaches to supervisory authorities under Article 33, built for implementation in each authority's online tool: conditional sections that appear only when relevant, predefined answer values and tooltips, covering the nature of the breach, categories and numbers of people and records, likely consequences, measures taken, timing and reasons for any delay, and cross-border elements. Consultation ran 10 June to 5 August 2026; the Board will decide the timetable for authorities to adopt it. Map the incident intake form to its fields now so a notification can be assembled from the record rather than rewritten under the 72-hour clock.

Guidelines 1/2026 on processing of personal data for scientific research purposes (version for public consultation)

15 April 2026Read from the documentconsultation

Six indicators decide whether an activity is scientific research (methodical approach, ethical standards, verifiability, independence, societal objective, scientific merit); commercial research qualifies if it is genuinely scientific. Any Article 6 basis can carry it, with broad consent allowed for defined research areas under extra safeguards, public interest where law provides for it, and legitimate interests weighted in research's favour; special categories need an Article 9(2) condition such as (j) with a legal basis in Union or national law. Further processing for research is presumed compatible under Article 5(1)(b) but still needs its own lawful basis, storage may be extended only for identified projects or a defined research area, and Article 89(1) safeguards (anonymise or pseudonymise where the purpose allows, ethics review, secure environments, DPIA) condition the derogations from erasure, objection and information duties. Adopted 15 April 2026 for consultation to 25 June 2026.

Template for Data Protection Impact Assessment (version for public consultation)

14 April 2026Read from the documentconsultation

A harmonised DPIA report template with predefined fields and an explainer, adopted 14 April 2026 for consultation to 9 June 2026, meant to structure and evidence the Article 35 assessment: description of the processing, necessity and proportionality, risks to individuals, measures, residual risk and consultation of the DPO and of data subjects. Use is not mandatory; after consultation each supervisory authority will adopt it either as its sole standard or as a meta-template that national formats must map to. Compare the site's DPIA tool field by field once the final version is published, and expect authorities to ask for reports in this shape.

Recommendations 1/2026 on the Application for Approval and on the elements and principles to be found in Processor Binding Corporate Rules (Art. 47 GDPR) (version for public consultation)

15 January 2026Read from the documentconsultation

The application form, the elements and principles table and the background paper for processor binding corporate rules, replacing WP257 rev.01 and WP265: the same structure as Recommendations 1/2022 for controller BCRs, with the scope clarified (transfers from the processor to its own sub-processor members, not direct transfers from an external controller), full rather than summarised information to data subjects on their enforceable rights, a duty on importers to notify and, where grounds exist, challenge government access requests, and a reminder that approval does not assess supplementary measures, which each exporter still owes transfer by transfer. Adopted 15 January 2026 for consultation to 2 March 2026; groups with processor BCRs in progress should draft to the new table.

Recommendations 2/2025 on the legal basis for requiring the creation of user accounts on e-commerce websites (version for public consultation)

03 December 2025Read from the documentconsultation

Making a customer create an account before buying rarely passes the Article 6(1)(b) necessity test: a one-off purchase needs only the data to execute the sale, so the account is necessary only for genuine subscriptions with recurrent authenticated interactions or offers restricted to a verified closed group. Legitimate interests fail for fraud prevention, loyalty and order tracking because less intrusive means exist, and consent can only carry optional account benefits kept separate from checkout. Offering a guest checkout beside the account is the design that satisfies Article 25, and dormant account data must be deleted under storage limitation. Adopted 3 December 2025 for consultation to 12 February 2026; retailers should add a guest path now.

Guidelines 3/2025 on the interplay between the Digital Services Act and the GDPR (version for public consultation)

11 September 2025Read from the documentconsultation

The DSA's duties for intermediaries and platforms are performed under the GDPR, not outside it, and the DSA supplies no legal basis of its own: notice-and-action channels should let people report anonymously unless identification is needed, recommender systems on very large platforms must offer a non-profiling option under which no profile is built for future recommendations, targeted advertising may never use special category data and never target minors, and age assurance should avoid methods that identify users unambiguously such as government ID uploads. Supervisory authorities and Digital Services Coordinators cooperate on the overlap. Adopted for consultation 12 September to 31 October 2025; relevant to any marketplace, app or platform in scope of the DSA.

Guidelines 01/2025 on pseudonymisation (version for public consultation)

16 January 2025Read from the documentconsultation

Pseudonymised data stays personal data for everyone who could re-attribute it with the separately held additional information, so pseudonymisation is a safeguard, not an exit from the GDPR. It works within a defined pseudonymisation domain where the keys, lookup tables and original data are kept apart under technical and organisational measures, and within that domain it reduces the impact of a breach (Article 32), supports minimisation and confidentiality by design (Article 25), strengthens a legitimate interest balancing, and can serve as a supplementary measure for transfers where the additional information stays out of the third country's reach. Adopted 16 January 2025 for consultation to 14 March 2025; no final version had been published by September 2026.

Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR (version for public consultation)

08 October 2024Read from the documentconsultation

Legitimate interests carry processing only when three cumulative conditions are met: an interest that is lawful, clearly articulated and real and present rather than speculative; processing that is necessary, meaning the interest cannot reasonably be achieved just as effectively by less intrusive means; and a balancing in which the person's interests, the sensitivity of the data, the context, vulnerable groups, reasonable expectations (which do not depend only on what the privacy notice said) and mitigating measures beyond the legal minimum are weighed. After an objection the controller must show compelling legitimate grounds, a higher bar. Worked contexts cover fraud prevention, direct marketing, information security and children; public authorities cannot use the basis for their tasks. Adopted 8 October 2024 for consultation to 20 November 2024; no final version had been published by September 2026, and the March 2026 one-stop-shop case digest applies the same test.

Statements16 documents, 5 written

Statement 1/2025 on Age Assurance

12 February 2025Read from the documentchildrenbiometricslawful basis

Age assurance must respect ten principles, among them a risk-based assessment of proportionality, purpose limitation and data minimisation, effectiveness, lawfulness, fairness and transparency, data protection by design and by default, security and accountability. The statement applies to service providers and third parties involved in age assurance, and requires them to establish a lawful basis under Article 6, choose the least intrusive method and collect only the age attributes strictly necessary, for instance an over or under threshold signal rather than a date of birth. Map any age gate against the ten principles and record the proportionality assessment.

Statement 01/2022 on the announcement of an agreement in principle on a new Trans-Atlantic Data Privacy Framework

06 April 2022Read from the documenthistoricaltransfers

The political agreement in principle announced on 25 March 2022 was a positive first step but did not constitute a legal framework on which exporters could base transfers to the United States, so controllers and processors had to continue complying with the CJEU's Schrems II judgment of 16 July 2020. The EDPB announced it would examine whether US reforms limit national security collection to what is strictly necessary and proportionate, whether the redress mechanism gives an effective remedy with binding decisions, and whether judicial review of that body exists. The statement was overtaken by Opinion 5/2023 and by the EU-US Data Privacy Framework adequacy decision of 10 July 2023.

Statement 04/2021 on international agreements including transfers

13 April 2021Read from the documenttransfersgovernance

Member States and Union bodies should review international agreements involving transfers of personal data that were concluded before 24 May 2016 (GDPR) or 6 May 2016 (LED), in fields such as taxation, social security, mutual legal assistance and police cooperation, and align them with Chapter V GDPR, the LED and the Schrems II judgment of 16 July 2020. The statement points to Guidelines 2/2020 on legally binding instruments between public authorities for the safeguards required, and offers the assistance of the national supervisory authorities. Public-sector practitioners should inventory such agreements and check that each carries enforceable rights and effective remedies.

Statement on the Court of Justice of the European Union Judgment in Case C-311/18 - Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

17 July 2020Read from the documenthistoricaltransfers

The Court's invalidation of the Privacy Shield in Case C-311/18 is welcomed as confirming that a level of protection essentially equivalent to the GDPR is required for every transfer. Standard contractual clauses remain valid, but exporter and importer must assess in advance whether the destination country's law allows that level of protection and, where it does not, add safeguards or suspend the transfer or terminate the clauses; supervisory authorities can suspend transfers where no alternative protection exists. Issued on 17 July 2020 as the first EDPB reaction, it calls for a complete EU-US framework and promises further guidance, which followed as the FAQ of 24 July 2020 and Recommendations 01/2020.

Statement on privacy implications of mergers

19 February 2020Description

Statement that mergers of data-rich companies raise data protection issues and that authorities should be consulted in merger control. Policy position.

Statement 2/2019 on the use of personal data in the course of political campaigns

13 March 2019Read from the documenthistoricalmarketinglawful basis

Ahead of the 2019 European Parliament elections the Board set out how the GDPR applies to political parties, coalitions and candidates that profile and target voters. Political opinions are special category data whose processing is prohibited unless a narrow condition such as explicit consent applies; data people have made public stays subject to the transparency, purpose and lawfulness rules; and profiling tied to targeted campaign messaging can produce similarly significant effects, so it is in principle lawful only with valid explicit consent, and voters must be told why they receive a message. Campaign data teams should treat voter profiling as needing explicit consent and explain targeting to recipients.

Opinions of the Board (Article 64)257 documents, 5 written

Opinion 15/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal to be used as tool for transfers pursuant to Articles 42 and 46 GDPR

16 April 2026Description

Opinion under Articles 42(5) and 46(2)(f) approving the Europrivacy certification criteria as a European Data Protection Seal usable as a tool for transfers to third countries, the first certification approved for that purpose (April 2026). Relevant to exporters considering certification instead of standard contractual clauses, and to importers seeking it.

Opinion 13/2026 on the draft decision of the Office of the Data Protection Ombudsman (FI SA) regarding the approval of the requirement for accreditation of a certification body pursuant to Article 43(3) GDPR

15 April 2026Description

Opinion on the draft accreditation requirements for certification bodies submitted by the FI supervisory authority under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models

18 December 2024Read from the documentailawful basis

AI models trained on personal data are not anonymous in all cases; anonymity requires that the likelihood of extracting personal data from the model, directly or through queries, is insignificant, assessed case by case and documented. Legitimate interest can ground development and deployment only where the three-step test is met: a real and lawful interest, necessity with no less intrusive alternative, and a balancing that weighs data subjects' reasonable expectations and mitigating measures. Unlawful processing in development can affect later deployment unless the model is properly anonymised, and a deploying controller must assess how the model was built. Document anonymity testing and the legitimate interest assessment for every model.

Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)

09 October 2024Read from the documentcontroller processortransfersgovernance

Controllers must have the name, address and contact person of every processor and sub-processor in the chain readily available at all times, and must verify that each provides sufficient guarantees, with the extent of verification scaling with the risk of the processing. Processors must flow identical obligations down to sub-processors, but the controller need not systematically review sub-processing contracts; it decides case by case whether doing so is needed for accountability. The controller remains responsible for transfers made by processors and sub-processors and needs the transfer mapping and legal grounds documented. Requested by the Danish supervisory authority; use it to rebuild sub-processor inventories and due diligence.

Opinion 10/2024 on the draft decision of the competent supervisory authority of Sweden regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

03 June 2024Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Sweden under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 11/2024 on the use of facial recognition to streamline airport passengers' flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR)

24 May 2024Read from the documentbiometricssecurity

Facial recognition to speed passengers through airport checkpoints is compatible with Articles 5(1)(e), 5(1)(f), 25 and 32 GDPR only where the biometric template stays under the passenger's control: stored solely on the passenger's device, or stored centrally at the airport encrypted with a key held only by the passenger. Central databases under airport operator control and cloud storage under airline control cannot satisfy data protection by design and breach the security and storage limitation requirements. Requested by the French supervisory authority and adopted 23 May 2024, it guides airport operators, airlines and their authorities; any biometric passenger flow project must be built around on-device storage or passenger-held keys.

Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms

17 April 2024Read from the documentconsentcookies trackingmarketing

Large online platforms that offer users only a choice between consenting to behavioural advertising or paying a fee will, in most cases, not obtain valid consent. Consent must be freely given, so platforms should offer a further free alternative without behavioural advertising, for instance contextual advertising using minimal personal data, and must assess detriment, lock-in effects, the power imbalance flowing from market position and whether any fee is appropriate; the controller bears the burden of demonstrating all of this. Requested by the Dutch, Norwegian and Hamburg authorities and adopted 17 April 2024, with a corrigendum in October 2024, it addresses large online platforms only.

Opinion 37/2023 on the draft decision of the competent supervisory authority of Luxemburg regarding the approval of the requirements for accreditation of a certification body pursuant to Art. 43.3

21 December 2023Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Luxemburg under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 38/2023 on the draft decision of the competent supervisory authority of Slovenian regarding the approval of the requirements for accreditation of a certification body pursuant to Art. 43.3

21 December 2023Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Slovenian under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 19/2023 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the American Express Global Business Travel Group

16 November 2023Description

Favourable opinion on the draft decision of the Dutch authority approving the controller binding corporate rules of American Express Global Business Travel Group under Article 64(1)(f); the authority gives the final approval. Matters only to organisations transferring personal data to or within that group.

Opinion 11/2023 on the draft decision of the competent supervisory authority of Sweden regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

11 July 2023Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Sweden under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 12/2023 on the draft decision of the competent supervisory authority of Cyprus regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

11 July 2023Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Cyprus under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 13/2023 on the draft decision of the competent supervisory authority of Croatia regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

11 July 2023Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Croatia under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 02/2023 on the draft decision of the competent supervisory authority of Latvia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR

17 February 2023Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Latvia under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 03/2023 on the draft decision of the competent supervisory authority of Romania regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

17 February 2023Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Romania under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 1/2023 on the draft decision of the competent supervisory authority of Croatia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR

17 February 2023Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Croatia under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 4/2023 on the draft decision of the competent supervisory authority of Malta regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

17 February 2023Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Malta under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 26/2022 on the draft decision of the Data Protection Authority of Bavaria for the Private Sector regarding the Controller Binding Corporate Rules of the Munich Re Reinsurance Group

30 September 2022Description

Favourable opinion on the draft decision of the national authority approving the controller binding corporate rules of Munich Re Reinsurance Group under Article 64(1)(f); the authority gives the final approval. Matters only to organisations transferring personal data to or within that group.

Opinion 11/2022 on the draft decision of the competent supervisory authority of Poland regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

04 July 2022Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Poland under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 12/2022 on the draft decision of the competent supervisory authority of France regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

04 July 2022Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of France under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 13/2022 on the draft decision of the competent supervisory authority of Bulgaria regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

04 July 2022Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Bulgaria under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 14/2022 on the draft decision of the competent supervisory authority of Bulgaria regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

04 July 2022Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Bulgaria under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 15/2022 on the draft decision of the competent supervisory authority of Luxembourg regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

04 July 2022Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Luxembourg under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 16/2022 on the draft decision of the competent supervisory authority of Slovenia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

04 July 2022Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Slovenia under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 35/2021 on the draft decision of the competent supervisory authority of Belgium regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

30 November 2021Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Belgium under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 36/2021 on the draft decision of the competent supervisory authority of Norway regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

30 November 2021Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Norway under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 37/2021 on the draft decision of the competent supervisory authority of Malta regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

30 November 2021Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Malta under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 38/2021 on the draft decision of the competent supervisory authority of Latvia regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

20 November 2021Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Latvia under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 26/2021 on the draft decision of the Supervisory Authority of North Rhine-Westphalia (Germany) regarding the Controller Binding Corporate Rules of the Internet Initiative Japan Group

05 August 2021Description

Favourable opinion on the draft decision of the national authority approving the controller binding corporate rules of Internet Initiative Japan Group under Article 64(1)(f); the authority gives the final approval. Matters only to organisations transferring personal data to or within that group.

Opinion 27/2021 on the draft decision of the Supervisory Authority of North Rhine-Westphalia (Germany) regarding the Processor Binding Corporate Rules of the Internet Initiative Japan Group

05 August 2021Description

Favourable opinion on the draft decision of the national authority approving the processor binding corporate rules of Internet Initiative Japan Group under Article 64(1)(f); the authority gives the final approval. Matters only to organisations transferring personal data to or within that group.

Opinion 23/2021 on the draft decision of the competent supervisory authority of Czech Republic regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

20 July 2021Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Czech Republic under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 24/2021 on the draft decision of the competent supervisory authority of Slovakia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

20 July 2021Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Slovakia under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 25/2021 on the draft decision of the competent supervisory authority of Lithuania regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

20 July 2021Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Lithuania under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 19/2021 on the draft decision of the competent supervisory authority of Hungary regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

01 June 2021Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Hungary under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 10/2021 on the draft decision of the competent supervisory authority of Hungary regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

23 March 2021Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Hungary under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 11/2021 on the draft decision of the competent supervisory authority of Norway regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

23 March 2021Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Norway under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 12/2021 on the draft decision of the competent supervisory authority of Portugal regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

23 March 2021Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Portugal under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 13/2021 on the draft decision of the competent supervisory authority of Romania regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

23 March 2021Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Romania under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 26/2020 on the draft decision of the competent supervisory authority of Denmark regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

07 December 2020Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Denmark under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 30/2020 on the draft decision of the competent supervisory authority of Austria regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

07 December 2020Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Austria under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 31/2020 on the draft decision of the competent supervisory authority of Poland regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

07 December 2020Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Poland under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 19/2020 on the draft decision of the competent supervisory authority of Denmark regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

15 August 2020Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Denmark under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 21/2020 on the draft decision of the competent supervisory authority of the Netherlands regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

15 August 2020Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Netherlands under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 22/2020 on the draft decision of the competent supervisory authority of Greece regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

15 August 2020Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Greece under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 23/2020 on the draft decision of the competent supervisory authority of Italy regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

15 August 2020Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Italy under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 18/2020 on the draft decision of the competent supervisory authority of the Netherlands regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

23 July 2020Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Netherlands under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 20/2020 on the draft decision of the competent supervisory authority of Greece regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

23 July 2020Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Greece under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 10/2020 on the draft decision of the competent supervisory authorities of Germany regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

25 May 2020Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Germany under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 11/2020 on the draft decision of the competent supervisory authority of Ireland regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

25 May 2020Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Ireland under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 12/2020 on the draft decision of the competent supervisory authority of Finland regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

25 May 2020Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Finland under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 13/2020 on the the draft decision of the competent supervisory authority of Italy regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

25 May 2020Description

Opinion on the draft accreditation requirements for code of conduct monitoring bodies submitted by the supervisory authority of Italy under Article 41(3), checked against Guidelines 1/2019; the authority adopts the final requirements. For code owners and would-be monitoring bodies in that country.

Opinion 14/2020 on the draft decision of the competent supervisory authority of Ireland regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

25 May 2020Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Ireland under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 15/2020 on the draft decision of the competent supervisory authorities of Germany regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

25 May 2020Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Germany under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 16/2020 on the draft decision of the competent supervisory authority of the Czech Republic regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

25 May 2020Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Czech Republic under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 4/2020 on the draft decision of the competent supervisory authority of the United Kingdom regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 GDPR

31 January 2020Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of United Kingdom under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 5/2020 on the draft decision of the competent supervisory authority of Luxembourg regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 GDPR

31 January 2020Description

Opinion on the draft accreditation requirements for certification bodies submitted by the supervisory authority of Luxembourg under Article 43(3), checked against Guidelines 4/2018; the authority adopts the final requirements. For certification bodies seeking accreditation in that country.

Opinion 6/2020 on the draft decision of the Spanish Supervisory Authority regarding the Controller Binding Corporate Rules of Fujikura Automotive Europe Group (FAE Group)

29 January 2020Description

Favourable opinion on the draft decision of the Spanish authority approving the controller binding corporate rules of Fujikura Automotive Europe Group (FAE Group) under Article 64(1)(f); the authority gives the final approval. Matters only to organisations transferring personal data to or within that group.

Opinion 5/2019 on the interplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities

12 March 2019Read from the documentcookies trackingenforcement

Processing such as the placing of cookies can fall under both the ePrivacy Directive and the GDPR simultaneously; where the ePrivacy Directive contains a specific rule it takes precedence as lex specialis, and everything it does not specifically govern remains subject to the GDPR. A data protection authority keeps its full GDPR competence over such processing, but it can enforce the ePrivacy rules themselves only where national law makes it the competent body, and any GDPR decision must rest on GDPR grounds, with ePrivacy breaches usable as factual elements. Practitioners should expect DPAs to weigh cookie consent failures when assessing GDPR lawfulness.

Opinion 7/2019 on the draft list of the competent supervisory authority of Iceland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

12 March 2019Description

Reviews the draft national list from the supervisory authority of Iceland of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 01/2019 on the draft list of the competent supervisory authority of the Principality of Liechtenstein regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

23 January 2019Description

Reviews the draft national list from the supervisory authority of Principality of Liechtenstein of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 2/2019 on the draft list of the competent supervisory authority of Norway regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

23 January 2019Description

Reviews the draft national list from the supervisory authority of Norway of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 24/2018 on the draft list of the competent supervisory authority of Denmark regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

04 December 2018Description

Reviews the draft national list from the supervisory authority of Denmark of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 25/2018 on the draft list of the competent supervisory authority of Croatia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

04 December 2018Description

Reviews the draft national list from the supervisory authority of Croatia of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 26/2018 on the draft list of the competent supervisory authority of Luxembourg regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

04 December 2018Description

Reviews the draft national list from the supervisory authority of Luxembourg of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 27/2018 on the draft list of the competent supervisory authority of Slovenia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

04 December 2018Description

Reviews the draft national list from the supervisory authority of Slovenia of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 1/2018 on the draft list of the competent supervisory authority of Austria regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Austria of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 10/2018 on the draft list of the competent supervisory authority of Hungary regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Hungary of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 11/2018 on the draft list of the competent supervisory authority of Ireland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Ireland of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 13/2018 on the draft list of the competent supervisory authority of Lithuania regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Lithuania of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 14/2018 on the draft list of the competent supervisory authority of Latvia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Latvia of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 16/2018 on the draft list of the competent supervisory authority of the Netherlands regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Netherlands of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 17/2018 on the draft list of the competent supervisory authority of Poland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Poland of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 18/2018 on the draft list of the competent supervisory authority of Portugal regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Portugal of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 19/2018 on the draft list of the competent supervisory authority of Romania regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Romania of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 2/2018 on the draft list of the competent supervisory authority of Belgium regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Belgium of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 20/2018 on the draft list of the competent supervisory authority of Sweden regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Sweden of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 21/2018 on the draft list of the competent supervisory authority of Slovakia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Slovakia of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 22/2018 on the draft list of the competent supervisory authority of the United Kingdom regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of United Kingdom of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 3/2018 on the draft list of the competent supervisory authority of Bulgaria regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Bulgaria of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 4/2018 on the draft list of the competent supervisory authority of Czech Republic regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Czech Republic of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 5/2018 on the draft list of the competent supervisory authorities of Germany regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Germany of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 6/2018 on the draft list of the competent supervisory authority of Estonia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Estonia of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 7/2018 on the draft list of the competent supervisory authority of Greece regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Greece of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 8/2018 on the draft list of the competent supervisory authority of Finland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of Finland of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Opinion 9/2018 on the draft list of the competent supervisory authority of France regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

03 October 2018Description

Reviews the draft national list from the supervisory authority of France of processing operations requiring a DPIA under Article 35(4), asking for alignment with the nine WP248 criteria so national lists stay consistent. Check the final national list if you operate there.

Binding decisions (Article 65)12 documents, 7 written

Urgent Binding Decision 01/2023 requested by the Norwegian SA for the ordering of final measures regarding Meta Platforms Ireland Ltd (Art. 66(2) GDPR)

27 October 2023Read from the documentlawful basismarketingenforcement

Meta Platforms Ireland infringed Article 6(1) GDPR by continuing to process personal data for behavioural advertising on Facebook and Instagram under Article 6(1)(b) after the Irish SA's decisions of 31 December 2022, and by switching to Article 6(1)(f) on 5 April 2023 without a valid legal basis. The EDPB instructed the Irish SA to order Meta to cease that processing across the EEA, extending the Norwegian SA's provisional ban of 14 July 2023. For any controller, neither contract nor legitimate interest carries behavioural advertising built on observed behaviour, location and ad interactions; consent is the basis to design for.

Binding Decision 2/2023 on the dispute submitted by the Irish SA regarding TikTok Technology Limited (Art. 65 GDPR)

02 August 2023Read from the documentchildrendpiaenforcement

TikTok's public-by-default settings for users aged 13 to 17 between 31 July and 31 December 2020 infringed Articles 25(1), 25(2), 5(1)(c), 24(1), 13(1)(e) and 12(1) GDPR, and the EDPB additionally instructed the Irish SA to find an infringement of the fairness principle in Article 5(1)(a) because the registration and video-posting pop-ups nudged children towards public accounts. The decision binds the Irish SA and the objecting authorities and is the EDPB's clearest statement that deceptive interface design is unfair processing. Audit defaults and consent flows for child users, and expect fairness, not only transparency, to be assessed.

Binding Decision 1/2023 on the dispute submitted by the Irish SA on data transfers by Meta Platforms Ireland Limited for its Facebook service (Art. 65 GDPR)

13 April 2023Read from the documenttransfersenforcement

Meta Platforms Ireland infringed Article 46(1) GDPR by transferring EU/EEA Facebook user data to the United States on standard contractual clauses that could not compensate for the deficiencies in US law identified by the CJEU. The EDPB instructed the Irish SA to add an administrative fine to the proposed suspension order and to order Meta to bring processing into compliance, including ceasing unlawful processing of the transferred data, in an inquiry opened on 28 August 2020. The decision binds the Irish SA and shows that a transfer impact assessment concluding that supplementary measures are ineffective must lead to suspension, not continued transfer.

Binding Decision 3/2022 on the dispute submitted by the Irish SA on Meta Platforms Ireland Limited and its Facebook service (Art. 65 GDPR)

05 December 2022Read from the documentlawful basismarketingenforcement

Meta Platforms Ireland cannot rely on Article 6(1)(b) GDPR for behavioural advertising on Facebook, because such advertising is objectively not necessary for the performance of the contract and users cannot be taken to expect it from a brief mention in the terms. The EDPB also confirmed infringements of Articles 12 and 13 for unclear information on processing operations and legal bases, found the accept-or-leave choice unfair under Article 5(1)(a), instructed the Irish SA to impose a fine and required compliance within three months of the final decision. Adopted on 5 December 2022, the decision sets the position later enforced EEA-wide in Urgent Binding Decision 01/2023.

Binding Decision 4/2022 on the dispute submitted by the Irish SA on Meta Platforms Ireland Limited and its Instagram service (Art. 65 GDPR)

05 December 2022Read from the documentlawful basismarketingenforcement

Meta Platforms Ireland cannot rely on Article 6(1)(b) GDPR for behavioural advertising on Instagram: the processing is not a core part of the contract, is objectively unnecessary for its performance and falls outside users' reasonable expectations under the Terms of Use. The EDPB upheld infringements of Articles 5(1)(a), 12(1) and 13(1)(c) for failing to give meaningful information on processing operations and legal bases, found the binary accept-or-delete choice unfair, instructed the Irish SA to impose a fine and set a three-month compliance deadline. Adopted on 5 December 2022, it mirrors Binding Decision 3/2022 on Facebook, and both were extended EEA-wide by Urgent Binding Decision 01/2023.

Binding Decision 5/2022 on the dispute submitted by the Irish SA regarding WhatsApp Ireland Limited (Art. 65 GDPR)

05 December 2022Read from the documentlawful basistransparencyenforcement

WhatsApp Ireland cannot rely on Article 6(1)(b) GDPR to process personal data for service improvement and security features, because processing must be objectively necessary and integral to the contracted service, judged from both the controller's and a reasonable user's perspective, and a controller cannot pick a basis that serves its commercial interests at the expense of data subject protection. The EDPB instructed the Irish SA to record the Article 6(1) infringement, to increase the administrative fine beyond its draft, and to order the privacy policy into compliance with Articles 12(1) and 13(1)(c). Any controller citing contract for improvement or analytics processing should re-evaluate that basis.

Binding Decision 2/2022 on the dispute arisen on the draft decision of the Irish Supervisory Authority regarding Meta Platforms Ireland Limited (Instagram) under Article 65(1)(a) GDPR

28 July 2022Description

Article 65 decision in the Irish authority's Meta (Instagram) inquiry into children's data: contact details of child users with business accounts were published by default and children's accounts were public by default, breaching Articles 5(1)(c), 6(1), 12(1), 24, 25 and 35 among others; the Board directed a higher fine (EUR 405 million in the final decision). Enforcement history; the substantive points on default settings and children are in the Article 25 guidance and Guidelines 05/2020.

Binding decision 1/2021 on the dispute arisen on the draft decision of the Irish Supervisory Authority regarding WhatsApp Ireland under Article 65(1)(a) GDPR

28 July 2021Read from the documenthistoricaltransparencyenforcement

WhatsApp Ireland's privacy notices infringed the transparency duties in Articles 12 to 14 GDPR, and the EDPB, resolving objections from several supervisory authorities, instructed the Irish Data Protection Commission to add an infringement of Article 13(1)(d) because legitimate interests were not tied to specific processing operations, to treat the output of the lossy hashing of non-users' phone numbers as pseudonymised personal data within Article 14, and to reassess the fine upwards from the 30–50 million euro range in its draft. The decision binds the Irish authority and WhatsApp Ireland. Read it as the benchmark for how granular a legitimate-interests description and a non-user notice must be.

Legislative opinions20 documents, 7 written

EDPB-EDPS Joint Opinion 4/2026 on the Proposal for a Cybersecurity Act 2 and the Proposal on amendments to the NIS 2 Directive

19 March 2026Read from the documentsecuritybreach

The EDPB and EDPS back a single entry point for notifying personal data breaches alongside NIS 2 incident reports, support classifying European Digital Identity and Business Wallet providers as essential entities, and welcome supply chain measures aimed at non-technical risks. They ask legislators to spell out any large-scale personal data processing by ENISA in the basic act, to require EDPB consultation before certification schemes on security of processing are adopted, to keep certification controls configurable so they respect data minimisation, and to define safeguards for mandatory ransomware payment reporting. NIS 2 operators should plan for combined incident and breach reporting.

EDPB-EDPS Joint opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (Digital Omnibus)

11 February 2026Read from the documentbreachaicookies tracking

The EDPB and EDPS reject the narrowed definition of personal data in Article 4(1) and the new Article 41a on pseudonymisation, insist Article 22 stays a prohibition in principle on solely automated decisions, and accept legitimate interest for AI only with a mandatory three-step test, an unconditional right to object and enhanced transparency. They support raising the breach notification threshold to breaches likely to result in high risk, extending the deadline from 72 to 96 hours, the six-month bar on repeat consent requests and machine-readable consent signals, but warn that splitting the terminal equipment rules between the GDPR (personal data) and the ePrivacy Directive (other data) creates legal uncertainty and must not lower protection, and want the EDPB rather than the Commission to own DPIA lists and breach templates. Current GDPR obligations stand while negotiation continues.

EDPB-EDPS Joint opinion 1/2026 on the Proposal for a Regulation as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

21 January 2026Read from the documentaigovernance

The EDPB and EDPS accept that postponing high-risk AI obligations from 2 August 2026 to 2 December 2027 (Annex III) and from 2 August 2027 to 2 August 2028 (Annex I) has partly objective causes but ask legislators to keep the current dates for transparency duties, retain AI literacy obligations for providers and deployers, and keep registration of Annex III systems that providers self-exempt. They support bias detection with special category data in all AI systems only under strict necessity, with data protection authorities kept as primary supervisors, involved in EU-level sandboxes and unhindered by market surveillance single points of contact. Providers should not treat the delay as settled.

EDPB-EDPS Joint Opinion 01/2025 on the Proposal for a Regulation on simplification measures for SMEs and SMCs, in particular the record-keeping obligation under Art. 30(5) GDPR

09 July 2025Read from the documentgovernancecontroller processor

The Commission's proposal of 21 May 2025 would raise the Article 30(5) record-keeping exemption from fewer than 250 employees to fewer than 750, drop the trigger for special category and criminal data, and keep records only for processing likely to result in high risk, covering an estimated 38,000 SMCs. The EDPB and EDPS accept the aim, note the missing fundamental rights assessment and ask for recitals confirming that records are needed only for the high-risk activities themselves, that Article 9(2)(b) employment processing is in principle not high risk, that the threshold follows the formal SME and SMC definitions, and that public authorities stay excluded. Until adoption, the 250-employee rule applies.

EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)

18 June 2021Read from the documenthistoricalaibiometrics

The EDPB and EDPS welcome the risk-based approach of the AI Act proposal but call for a general ban on any use of AI for automated recognition of human features in publicly accessible spaces, a ban on social scoring by private as well as public actors, and a prohibition on inferring emotions except in narrowly regulated cases. They ask that GDPR compliance be a precondition for placing systems on the market and that data protection authorities be the national supervisory authorities. Addressed to the co-legislators in June 2021, it is a historical position; read it alongside the adopted AI Act to see which asks were taken up.

EDPB-EDPS Joint Opinion 04/2021 on the Proposal for a Regulation of the European Parliament and of the Council on a framework for the issuance, verification and acceptance of interoperable certificates on vaccination, testing and recovery

31 March 2021Description

Joint opinion on the proposed Regulation for interoperable COVID-19 vaccination, test and recovery certificates (the Digital Green Certificate): no central EU database, purpose limited to free movement, and a sunset once the pandemic ends. Historical.

EDPB-EDPS Joint Opinion 1/2021 on standard contractual clauses between controllers and processors

14 January 2021Read from the documenthistoricalcontroller processor

The Commission's draft standard contractual clauses for Article 28 contracts are welcomed as a strong accountability tool, subject to amendments: the scope must state clearly whether the clauses apply to processors outside the EU and how they interact with Chapter V transfer clauses, the docking clause needs a procedure for new parties, the controller and not the processor must choose the auditor, cost allocation should be deleted, and the annexes must set out each party's responsibilities with absolute clarity. Addressed to the Commission in January 2021 before it adopted the clauses. When drafting a processing agreement on the Commission's clauses, give these points the most care.

EDPB-EDPS Joint Opinion 2/2021 on standard contractual clauses for the transfer of personal data to third countries

14 January 2021Read from the documenthistoricaltransfers

The draft Article 46 SCCs reinforce protection for data subjects through four modules, a docking clause and clauses on third-country law and government access requests, but the EDPB and EDPS require changes: the assessment of third-country law must rest on objective factors rather than the likelihood of access or the absence of past requests, notification of access requests must precede any response, the processor-to-processor module needs the full Article 28 obligations, and importers already subject to the GDPR under Article 3(2) should be excluded. The SCCs must be used with Recommendations 01/2020 on supplementary measures. Addressed to the Commission in January 2021; the transfer impact assessment stays with the exporter.

Task force reports3 documents, 3 written

Report of the work undertaken by the ChatGPT Taskforce

24 May 2024Read from the documenthistoricalailawful basisenforcement

The taskforce, set up on 13 April 2023 to coordinate national investigations into OpenAI while it had no EU establishment, records preliminary common views: web scraping for training, pre-processing, training, prompts and outputs each need a lawful basis, with OpenAI relying on legitimate interests; terms of service cannot shift GDPR responsibility to users; transparency, accuracy of probabilistic output and data subject rights must be handled by design, and technical complexity does not excuse non-compliance. OpenAI established an EU presence on 15 February 2024, bringing future cross-border processing under the one-stop-shop. Read it as the authorities' checklist for any generative AI service; the views were preliminary as of 23 May 2024.

Report of the work undertaken by the supervisory authorities within the 101 Taskforce

19 April 2023Read from the documenthistoricaltransferscookies trackingcontroller processor

Supervisory authorities handling the 101 complaints filed on 17 August 2020 about Google Analytics and Facebook Business Tools agreed that transfers relying on the invalidated Privacy Shield after 16 July 2020 breached Chapter V, that standard contractual clauses need supplementary measures addressing the deficiencies the CJEU identified, that encryption fails where the importer holds the keys, that anonymisation after transfer is too late, and that a website operator choosing such a tool is a controller. By March 2023 eight authorities had issued decisions. Since 10 July 2023 the EU-US adequacy decision covers transfers to DPF-certified recipients, so the report now matters mainly for non-certified importers and for the controller analysis.

Report of the work undertaken by the Cookie Banner Taskforce

18 January 2023Read from the documentcookies trackingconsent

Supervisory authorities agreed a minimum common position on cookie banners: no reject option where consent is given means no valid consent, pre-ticked boxes are invalid, a reject option hidden as a low-prominence text link is not equivalent to the accept button, deceptive colours and contrast are assessed case by case with unreadable text manifestly non-compliant, cookies claimed as essential must be shown to be so, and withdrawal must be as easy as consent without mandating a specific icon. Where Article 5(3) ePrivacy is breached, subsequent GDPR processing cannot be compliant. The positions apply on top of national ePrivacy law; test each banner against them before relying on the consent.

Coordinated enforcement5 documents, 3 written

Coordinated Enforcement Action, implementation of the right to erasure by controllers

18 February 2026Read from the documentrightsenforcement

Across 32 supervisory authorities and 764 controllers surveyed, erasure compliance is mostly rated average and fails in seven recurring ways: missing internal procedures (flagged by 17 authorities), untrained staff, thin privacy notice information (13 authorities), blanket use of Article 17(3) exceptions without documented case-by-case assessment, retention periods set at the longest possible for everything, no method for erasure in back-ups, and anonymisation used as a substitute for deletion. Nine authorities opened or continued formal investigations. Controllers should adopt a written erasure procedure with owners and deadlines, a data deletion matrix cross-referencing data types and retention periods, a back-up erasure method, and documented reasoning for every refusal.

Coordinated Enforcement Action, implementation of the right of access by controllers

20 January 2025Read from the documentrightsenforcement

Thirty supervisory authorities examined how 1,185 controllers, from SMEs to large companies and public bodies, implement the right of access; two-thirds of participating authorities rated compliance as average to high, and larger organisations and those receiving more requests performed better. The report identifies recurring shortcomings: no documented internal procedure, inconsistent or excessive reading of the limitations, automatic reliance on exceptions, excessive formal requirements and identity checks, and limited awareness of Guidelines 01/2022. It closes with non-binding recommendations for controllers and authorities. Benchmark the access procedure against the challenges it lists and align it with Guidelines 01/2022.

Coordinated Enforcement Action, Designation and Position of Data Protection Officers

17 January 2024Read from the documentgovernance

The second coordinated enforcement action, run by 25 supervisory authorities across the EEA in 2023 with over 17,000 replies, finds that most DPOs report the skills, training, clearly defined tasks and independence that Articles 37 to 39 require, but identifies organisations that fail to designate a DPO where mandatory, under-resource the role, assign tasks not aligned with the GDPR or compromise independence through reporting lines. The report addresses supervisory authorities, controllers and processors, and signals awareness-raising and enforcement on these points. Check DPO designation, resourcing, reporting line and task list against the findings, and give the DPO time and budget to keep knowledge current.

Other guidance21 documents, 10 written

EU-U.S. Data Privacy Framework F.A.Q. for European businesses - version 2.0

23 January 2026Read from the documenttransferscontroller processor

Personal data may flow from the EEA to a US company without further safeguards only while that company holds an active certification on the Data Privacy Framework List kept by the US Department of Commerce, and only companies under FTC or Department of Transportation jurisdiction can self-certify. Exporters must check the list before each transfer, fall back on standard contractual clauses or binding corporate rules if certification lapses, confirm HR Data coverage and cooperation with EU authorities before sending employee data, and still sign an Article 28 agreement with any certified processor. Version 2.0, adopted 15 January 2026, replaces version 1.0 of July 2024.

EU-US Data Privacy Framework FAQ for European individuals - version 2.0

23 January 2026Read from the documenttransfersrights

Individuals whose data is transferred to a DPF-certified US company keep rights to notice, access, correction and deletion, and can check certification on the DPF List. Complaints go first to the company, which must respond within 45 days, then to any EEA data protection authority using the EDPB template form or to the company's independent recourse mechanism; HR Data complaints and opted-in companies go to the informal panel of EU authorities, other cases can be referred to the FTC, the Department of Commerce or the OACP. Controllers should mirror these routes in privacy notices. Version 2.0 replaces the July 2024 version.

EU-US Data Privacy Framework FAQ for European businesses

16 July 2024Read from the documentsupersededtransfers

Answers for businesses in the EU on the EU-US Data Privacy Framework: how transfers to certified US organisations work under the adequacy decision, what a European exporter must check before relying on it, and how the framework relates to other transfer tools. It is informational guidance for controllers and processors exporting data to the United States rather than a binding position, and it sits alongside the EDPB information note on transfers to the United States and the redress mechanism documents. This 16 July 2024 version has been superseded by the EU-U.S. Data Privacy Framework FAQ for European businesses, version 2.0.

EU-US Data Privacy Framework FAQ for European individuals

16 July 2024Read from the documentsupersededtransfersrights

Answers for individuals in the EU on the EU-US Data Privacy Framework: how transfers to the United States work under the adequacy decision of 10 July 2023, what rights individuals have and how to seek redress. It is informational guidance for individuals rather than a binding position, and it is useful to controllers drafting privacy notices or complaint responses for transfers to certified US organisations. This 16 July 2024 version has been superseded by the EU-U.S. Data Privacy Framework FAQ for European individuals, version 2.0.

Information Note on the Data Privacy Framework redress mechanism for national security purposes

24 April 2024Read from the documenttransfersrights

Individuals in the EU and EEA who believe their personal data transferred to the United States was unlawfully collected or processed by US national security authorities can complain through the Data Privacy Framework redress mechanism, starting with the US Office of the Director of National Intelligence's Civil Liberties Protection Officer. Complaints use the EDPB template complaint form for the CLPO, and the note sits alongside rules of procedure for the mechanism and for the informal panel of EU data protection authorities that handles them. Controllers relying on the DPF should reference the mechanism in their transfer documentation and privacy notices.

Information note on data transfers under the GDPR to the United States after the adoption of the adequacy decision on 10 July 2023

18 July 2023Read from the documenttransfers

From 10 July 2023 transfers to US organisations on the Data Privacy Framework List may rely on the adequacy decision without Article 46 tools or supplementary measures, while transfers to non-certified US recipients still need standard contractual clauses, binding corporate rules or another Article 46 safeguard. The note addresses controllers and processors exporting data and explains that individuals may complain to their national authority about US intelligence access without proving their data was collected. Check each US recipient against the DPF List, take the Commission's assessment into account in transfer impact assessments for non-certified recipients, and note the review cycle of one year then at least every four years.

One-Stop-Shop Leaflet

29 June 2021Description

Leaflet explaining the one-stop-shop mechanism to the public.

Information note on data transfers under the GDPR to the United Kingdom after the transition period - update 13/01/2021

13 January 2021Read from the documenthistoricaltransfers

From 1 January 2021 the UK is a third country, but under the EU-UK Trade and Cooperation Agreement transfers to UK entities are not treated as third-country transfers for an interim period ending no later than 30 June 2021, provided the UK data protection regime stays in place. Exporters should use the period to put Article 46 tools in place (standard contractual clauses, binding corporate rules, codes of conduct), consider supplementary measures, and update records and privacy notices; groups with the ICO as BCR lead authority need a new EEA lead. Addressed to GDPR controllers and processors; historical now that the interim period has ended and UK adequacy applies.

Information note on data transfers under the GDPR to the United Kingdom after the transition period

15 December 2020Read from the documentsupersededtransfers

With the transition period ending on 31 December 2020 and no adequacy decision in place, transfers of personal data to the UK fall under Chapter V GDPR from 1 January 2021: exporters need standard contractual clauses, binding corporate rules or another Article 46 safeguard, plus supplementary measures where Recommendations 01/2020 require them, and Article 49 derogations are exceptional and read restrictively. Controllers and processors must update records of processing and privacy notices, and groups with the ICO as BCR lead authority must appoint a new EEA lead. Superseded on 13 January 2021 by the updated information note reflecting the interim provision of the EU-UK Trade and Cooperation Agreement.

Article 65 FAQ

10 November 2020Description

Frequently asked questions on the Article 65 dispute resolution procedure. Procedure between authorities.

Frequently Asked Questions on the judgment of the Court of Justice of the European Union in Case C-311/18 - Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems

24 July 2020Read from the documenthistoricaltransfers

The judgment of 16 July 2020 invalidates the Privacy Shield with immediate effect and no grace period, while standard contractual clauses and binding corporate rules remain valid only where the exporter and importer have assessed, case by case, that the law of the destination country allows an essentially equivalent level of protection, adding supplementary measures where it does not. Article 49 derogations are available but cannot become the rule, and a controller that cannot suspend a transfer lacking safeguards must notify its supervisory authority. Addressed to controllers and processors exporting data. The guidance on supplementary measures it promised became Recommendations 01/2020, which now carries the operational detail.

EDPB Leaflet

28 March 2019Description

General leaflet introducing the Board.

Position Paper on the derogations from the obligation to maintain records of processing activities pursuant to Article 30(5) GDPR

19 April 2018Read from the documentgovernance

Article 30(5) GDPR exempts organisations with fewer than 250 employees from keeping records of processing activities, but the exemption falls away if the processing is likely to result in a risk to data subjects, is not occasional, or includes special category or criminal conviction data. The WP29 reads these three conditions as alternatives: any one of them alone triggers the record-keeping duty. The duty covers only the processing that meets a condition, so a small organisation that regularly processes employee data must record that processing while occasional, low-risk activities stay outside. Small organisations should treat core processing as non-occasional and keep a record rather than rely on headcount.

Support Pool of Experts reports22 documents, 13 written

One-Stop-Shop case digest on right to object and right to erasure

26 May 2026Read from the documentrightsenforcement

Supervisory authorities handling Article 17 and Article 21 complaints through the one-stop-shop look first at whether the controller made the right easy to exercise: 631 final decisions from 2018 to January 2026 (551 on erasure, 80 on objection) show the recurring failures are poor information on the right to object, cumbersome identity checks, internal delays, weak coordination with processors and handling errors. Most cases ended in reprimands, compliance or erasure orders or amicable settlement, with fines rare. Use the catalogue to test your own objection and erasure workflow, including marketing opt-outs and account deletion. An external SPE expert wrote it; the May 2026 update replaces the 2022 version.

One-Stop-Shop case digest on the legal basis of "legitimate interest"

26 March 2026Read from the documentlawful basisenforcement

Supervisory authorities applying the Article 6(1)(f) three-step test in 67 decisions between December 2018 and June 2025 (62 one-stop-shop decisions and 5 EDPB binding decisions) accepted commercial interests only when stated precisely, rejected most cases at the necessity stage where a less intrusive design existed, and read data subjects' interests and reasonable expectations broadly. The common infringements were no documented assessment before processing began, vague interests such as measuring content performance, excessive retention, and transparency gaps that stopped people objecting. Controllers relying on legitimate interest should write the assessment first, name the interest specifically and disclose it. An external SPE expert wrote the digest, which builds on Guidelines 1/2024.

Data brokers market study

04 March 2026Read from the documentmarketingtransparencylawful basis

Data brokers collect personal data from many public and private sources, aggregate it into profiles and monetise it, usually without meaningful control by the individual, and activity codes do not find them: keyword searches identified over 40 brokers and providers operating in Belgium. The study, commissioned by the Belgian supervisory authority through the SPE programme and written by an external expert, sorts them into eight types, rating personal data brokers, data pools and cleanrooms, AI platforms built on personal data and user-controlled brokers as high risk. Controllers buying enriched or third-party data should check their suppliers' sources and legal basis.

Fundamentals of Secure AI Systems with Personal Data

05 June 2025Read from the documentaisecurity

Security, data science and governance teams running AI systems on personal data get shared vocabulary and lifecycle controls from this five-module open-source training (CC BY-SA 4.0): terminology and the AI lifecycle, GDPR principles and AI Act risk tiers mapped onto AI risks, secure MLOps and secure processing environments, deployment, monitoring and decommissioning, and audit checklists with worked use cases. It maps seven AI risk domains against the ten privacy risks in ISO/IEC 29134:2023. An external SPE expert wrote it, completed December 2024 and updated April 2025, and it carries no official EDPB position. Use it as a curriculum and a source of AI/ML audit questions.

Law & Compliance in AI Security & Data Protection

05 June 2025Read from the documentaigovernance

Data protection officers can map GDPR and AI Act obligations onto each stage of an AI system's life with this roughly 15-hour self-study module, commissioned through the SPE programme and completed by an external expert in December 2024, in three parts: fundamental AI and cybersecurity concepts, the lifecycle from inception to discontinuation, and advanced topics including fairness, accountability, transparency, privacy-enhancing technologies and large language models. Three hypothetical case studies (a university, a children's toy start-up and a hospital) show how the two regimes interact. It states the author's views, not the EDPB's. Use it to train a DPO team before an AI risk assessment programme.

AI Privacy Risks & Mitigations Large Language Models (LLMs)

10 April 2025Read from the documentaidpia

Large language model systems carry privacy and data protection risks at every stage of their lifecycle, and the report sets out a risk management methodology to identify, assess and mitigate them, worked through three use cases: a customer service virtual assistant, a student progress monitoring system and a travel and schedule management assistant. It was prepared by an external expert under the Support Pool of Experts programme and does not reflect an official EDPB position. Use it as a structured template for an LLM risk assessment or DPIA, and expect supervisory authorities to have read it.

AI: Complex Algorithms and effective Data Protection Supervision

23 January 2025Read from the documentairightsenforcement

Two reports produced for the German Federal Data Protection Authority under the Support Pool of Experts programme address how supervisory authorities can evaluate algorithmic bias with available tools and how data subjects' rights can be effectively implemented in AI systems. They are written for supervisory staff, express the external author's views rather than an EDPB position, and indicate what an authority may examine in an AI investigation. Controllers deploying AI systems can use the bias evaluation methods and the rights implementation material to prepare for supervisory scrutiny.

One-Stop-Shop case digest on right of access

16 January 2025Read from the documentrightsenforcement

Of 185 final one-stop-shop decisions reviewed, 52 are analysed to show how supervisory authorities apply Article 15 in practice: activity logs tied to unique identifiers are personal data, an impersonating profile is the impersonated person's data, a copy must reflect the data held at the time of the request, identity verification must be proportionate and demanding official documents exceeds necessity where alternatives suffice, and the one month deadline is often missed through unclear procedures. It was prepared by an external expert under the Support Pool of Experts programme and complements Guidelines 01/2022. Use it as a worked-example library when handling contested access requests.

AI Auditing

27 June 2024Read from the documentaigovernancetransparency

Three deliverables prepared for the Spanish DPA under the Support Pool of Experts programme map, develop and pilot tools for evaluating the GDPR compliance of AI systems: a checklist for auditing algorithms, a proposal for Algo-scores and a proposal for AI leaflets as a transparency device. They express the external author's views and not an EDPB position, and are aimed at supervisory authorities inspecting AI systems as well as controllers assessing their own safeguards in the context of the AI Act. Use the checklist as a starting structure for internal AI audits and the leaflet format for user-facing transparency.

AI Risks: Optical Character Recognition and Named Entity Recognition

27 June 2024Read from the documentaidpia

Optical character recognition and named entity recognition carry specific data protection risks across procurement, development and deployment, and two reports prepared for the EDPS under the Support Pool of Experts programme list those risks with possible mitigations for each phase. They are the external author's views, not an EDPB position, and are written both for controllers assessing risk and for authorities checking the validity of those assessments during investigations. Use the risk catalogues when running a DPIA on document digitisation, redaction or entity extraction pipelines.

Data Protection Officer training

27 June 2024Read from the documentgovernance

Training material for data protection officers, produced for the Croatian DPA under the Support Pool of Experts programme, comes in three modules: a general module, a health sector module aimed at hospitals and an educational sector module, each with Q&As for practitioners. The material is in Croatian, was completed in December 2023, and expresses the external author's views rather than an EDPB position. It is relevant to organisations designing DPO training or role-based curricula for public health and education, and to Croatian-speaking DPOs directly.

Standardised Messenger Audit

27 June 2024Description

Expert methodology for auditing messaging services against data protection requirements, for supervisory authorities.

EDPB website auditing tool

29 January 2024Read from the documentcookies trackingenforcement

A free and open source tool, licensed under EUPL 1.2, lets legal and technical auditors prepare, complete and evaluate a compliance audit of a website by visiting it, and controllers and processors can run it against their own sites. It was prepared by external contractors under the Support Pool of Experts programme, is available in English and French with machine-translated German, Italian and Spanish versions, and the current release adds import and export of analyses, search, database management and full-page screenshots. Use it as the same lens a supervisory authority may apply when checking cookies, trackers and third-party requests.

One-Stop-Shop case digest on Security of Processing and Data Breach Notification

18 January 2024Read from the documentbreachsecurityenforcement

Ninety final one-stop-shop decisions adopted between January 2019 and June 2023 show how supervisory authorities apply Articles 32, 33 and 34: a breach occurring does not by itself prove that security measures were inappropriate, and authorities assess encryption, access controls, password policies and logging case by case across external attacks, weak internal practices and human error. Each notifiable breach (Article 33(1): any breach unless it is unlikely to result in a risk) must be notified separately with enough detail for the authority to verify compliance, and the risk assessment decides whether affected individuals must be informed. Prepared by an external expert under the Support Pool of Experts programme; use it to calibrate breach severity and notification decisions against decided cases.

Adequacy opinions10 documents, 10 written

Opinion 28/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by Brazil

04 November 2025Read from the documenttransfers

Brazil's LGPD is closely aligned with the GDPR and the ANPD, made a regulatory agency on 15 September 2025 with over 200 new posts and fines of up to 2% of revenue, is effective, so the EDPB supports the draft adequacy decision while asking the Commission to clarify and monitor whether the LGPD covers criminal law enforcement, the absence of an explicit high-risk DPIA duty, the commercial secrecy limit on transparency, the onward transfer exceptions in Article 33 LGPD, the breadth of national security and the 48-agency SISBIN intelligence system, and the National Council's influence over the ANPD. The Commission adopted the adequacy decision on 26 January 2026 (Decision (EU) 2026/179); exporters may rely on it within its scope, with four-yearly reviews.

Opinion 26/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the United Kingdom

16 October 2025Read from the documenttransfers

The UK framework as amended by the Data (Use and Access) Act 2025 remains aligned with the EU regime, so the EDPB supports renewing GDPR adequacy until December 2031. It asks the Commission to monitor the Secretary of State's powers to change the rules by secondary legislation, the ICO's new board structure and complaint triage, the recognised legitimate interests basis for disclosures to public authorities, the onward transfer test of protection not materially lower, relaxed automated decision-making rules, wider national security exemptions, technical capability notices affecting end-to-end encryption, bulk personal dataset authorisations and the immigration exemption. Exporters to the UK may keep relying on adequacy but should watch those points.

Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom

16 October 2025Read from the documenttransfersenforcement

The EDPB supports extending the UK's Law Enforcement Directive adequacy for six years to 27 December 2031, reviewed within four years, while flagging that the Data (Use and Access) Act replaces the onward transfer test with a standard of protection not materially lower and drops factors such as national security rules, loosens automated decision-making with an exemption for avoiding obstruction of investigations, removes the duty to log justifications, widens national security exemptions under section 88, and gives the Secretary of State appointment powers over the restructured ICO. It asks the Commission to justify adequacy on each point. Law enforcement authorities exchanging data with UK counterparts may continue.

Opinion 06/2025 regarding the extension of the European Commission Implementing Decisions under the GDPR and the LED on the adequate protection of personal data in the United Kingdom

06 May 2025Read from the documentsupersededtransfers

The EDPB accepted a technical, time-limited six-month extension of the UK GDPR and LED adequacy decisions from 27 June 2025 to 27 December 2025, because the Data (Use and Access) Bill introduced on 23 October 2024 was not expected to pass before late spring and the amended framework could not be assessed in time. It stated that the extension was exceptional and should not in principle be prolonged again, and asked the Commission to monitor UK developments closely during the period. The extension has expired; the renewal is covered by Opinions 26/2025 and 27/2025 of 16 October 2025 on the draft decisions running to December 2031.

Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation

06 May 2025Read from the documenttransfers

The European Patent Organisation's Data Protection Rules of 30 June 2021, overseen by a Data Protection Officer and a Data Protection Board, resemble the EU framework closely enough for the EDPB to support the draft adequacy decision, adopted 5 May 2025, subject to clarifications: that the European Patent Office stays ultimately responsible despite delegated controllers, that onward transmissions to public authorities and non-EEA contracting states keep the protection level, that the Data Protection Board's complaint decisions become binding, and that the President's discretion to waive immunity for law enforcement requests is bounded. The Commission adopted the decision on 15 July 2025 (Decision (EU) 2025/1382); firms sending personal data to the EPO may rely on it within its scope, with four-yearly reviews.

Opinion 5/2023 on the European Commission Draft Implementing Decision on the adequate protection of personal data under the EU-US Data Privacy Framework

28 February 2023Read from the documenthistoricaltransfers

The EDPB welcomed that Executive Order 14086 introduces necessity and proportionality into US signals intelligence, binds the entire intelligence community and creates the Data Protection Review Court, while raising concerns about temporary bulk collection without prior independent authorisation, onward transfers, the standard non-appealable response of the redress court and the absence of specific rules on automated decision-making. It recommended that the Commission make adequacy conditional on the updated intelligence policies and procedures and closely monitor the redress mechanism. The Commission adopted the adequacy decision on 10 July 2023, so the opinion now serves as the reference for the review points.

Opinion 32/2021 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data in the Republic of Korea

24 September 2021Read from the documenthistoricaltransfers

Korea's Personal Information Protection Act offers protection with numerous similarities to the GDPR, but the EDPB conditions its support on clarifications: the binding force of PIPC Notification No. 2021-1, the exemption of pseudonymised data from access, rectification and erasure rights, the lack of a general right to withdraw consent, onward transfers that rest on consent without disclosure of third-country risks, and unclear rules on government access and intelligence sharing. The opinion is addressed to the European Commission, which subsequently adopted the adequacy decision. Exporters relying on that decision should note the points the EDPB asked the Commission to monitor.

Opinion 14/2021 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data in the United Kingdom

13 April 2021Read from the documenthistoricaltransfers

UK data protection law shows strong convergence with the GDPR on core principles, but the EDPB flags points the Commission must resolve or monitor: the broadly formulated immigration exemption, the UK's power to recognise third countries as adequate and its agreement with the US under the CLOUD Act, the absence of an Article 48 equivalent, bulk interception where selectors have not been examined by oversight bodies, and intelligence sharing under national security exemptions. The four-year sunset clause is welcomed as the safeguard against divergence. Addressed to the Commission, which adopted the decision; exporters to the UK should track the renewal and the areas listed for monitoring.

Opinion 15/2021 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data in the United Kingdom

13 April 2021Read from the documenthistoricaltransfersother

The UK Data Protection Act 2018 provides, in principle, a level of protection for law enforcement data essentially equivalent to the Law Enforcement Directive, with alignment on lawfulness, purpose limitation, data quality, special categories and automated decisions. The EDPB asks the Commission to address onward transfers based on UK-only adequacy findings, national security access including certificates that restrict data protection duties, the independence of judicial commissioners, and the effect of the UK-US CLOUD Act agreement, and it welcomes the four-year sunset clause. Addressed to the Commission on 13 April 2021; relevant to competent authorities sharing data with UK law enforcement bodies rather than to private controllers.

Opinion 28/2018 regarding the European Commission Draft Implementing Decision on the adequate protection of personal data in Japan

05 December 2018Read from the documenthistoricaltransfers

The Board welcomed the Supplementary Rules that Japan adopted to bridge gaps with the GDPR and called them essential to adequacy, but asked the Commission to resolve remaining concerns before finalising the decision: consent withdrawal treated as merely desirable, onward transfers losing the Supplementary Rule protections, record-keeping on data origin limited to three years, insufficient evidence that government access is essentially equivalent, and no general rules on automated decisions. It recommended review every two years rather than four and monitoring of the binding force of the PPC Guidelines. Exporters relying on the Japan adequacy decision should read it for the limits of the finding, notably on onward transfers.

Reports, statements and letters53 documents, 6 written

EDPB Annual Report 2025

09 April 2026Description

The Board's annual report for 2025: guidelines adopted, opinions and binding decisions issued, cooperation and enforcement figures. Background only.

Report on stakeholder event on processing of personal data to target or deliver political advertisements

27 March 2026Read from the documenthistoricalmarketingconsentcontroller processor

Stakeholders consulted online on 27 March 2026 (232 participants from platforms, ad tech, civil society, academia, public authorities and political entities) told the EDPB that the political advertising regulation (TTPA) leaves the definition of political advertising, the line between targeting and delivery, explicit consent and age verification unclear, that several platforms have stopped offering political advertising, and that platforms often misdescribe themselves as processors when they act as controllers. The report records those views for the EDPB's forthcoming TTPA guidelines and binds nobody. Publishers, platforms and campaigners should track the guidelines and settle controller roles in their advertising supply chain now.

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

18 February 2026Read from the documenthistoricalothercontroller processor

Stakeholders at the EDPB's remote event on 12 December 2025 (115 participants, mostly business associations, law firms, academia and NGOs) asked for a concrete, practical methodology for judging identifiability after the Court of Justice's ruling, especially for SMEs, and disagreed on whose perspective decides whether data is personal in controller-processor relationships and after transmission to third parties, third countries or the public. The report feeds the pseudonymisation Guidelines 01/2025 and the forthcoming anonymisation guidelines and binds nobody. Organisations relying on pseudonymised data sharing should document the re-identification risk assessment from the recipient's perspective and the legal, organisational and technical measures that support it.

EDPB Report on the public consultation on helpful templates for organisations to facilitate their GDPR compliance

12 February 2026Read from the documentgovernancelawful basistransparency

Of 82 written contributions received between 5 November and 3 December 2025 (71 from the EU and EEA, 11 from third countries), respondents most often asked for EU-level templates for records of processing activities, DPIAs, legitimate interest assessments, privacy notices, transfer impact assessments, processing agreements, breach notification forms and privacy risk assessments. The EDPB commits in its 2026–2027 work programme to produce three: a legitimate interest assessment, a record of processing activities and a privacy notice, harmonised with existing national templates, with more if time allows. Organisations, especially SMEs, should plan to align their internal forms with these once published rather than build new ones now.

EDPB Work Programme 2026-2027

12 February 2026Read from the documentgovernancetransparency

The EDPB's 2026–2027 programme, adopted 11 February 2026, lists guidelines to expect on anonymisation, pseudonymisation, legitimate interest assessment, children's data, consent or pay models, scientific research, generative AI data scraping, telemetry data and blockchain, EU templates for breach notifications, DPIAs, legitimate interest assessments, records of processing and privacy notices, updated DPO guidelines, guidelines on administrative fines, and joint guidance on the interplay of the GDPR with the AI Act, DMA, DSA, political advertising and AML rules. The 2026 coordinated enforcement action targets transparency obligations under Articles 12–14. Practitioners should map pending guidance against open policy decisions and prepare transparency notices for the 2026 sweep.

EDPB Annual Report 2024

23 April 2025Description

The Board's annual report for 2024: guidelines adopted, opinions and binding decisions issued, cooperation and enforcement figures. Background only.

EDPB Work Programme 2024-2025

09 October 2024Description

The Board's work programme for 2024-2025: the guidelines, templates and coordinated actions it planned for the period. Background for what was coming.

Statement 3/2024 on data protection authorities' role in the Artificial Intelligence Act framework

16 July 2024Read from the documentaigovernanceenforcement

Member States should designate data protection authorities as market surveillance authorities under the AI Act, in particular for the high-risk systems named in Article 74(8) covering law enforcement, border management and democratic processes, and should consider doing so for the other Annex III high-risk systems likely to affect individuals' rights, with the DPA as single point of contact. Addressed to Member States, the Commission and the AI Office, the statement notes that no clear coordination yet exists between the AI Office and DPAs on general-purpose AI models and calls for cooperation and additional resources. Track which authority your Member State designates for AI Act supervision.

EDPB Annual Report 2023

23 April 2024Description

The Board's annual report for 2023: guidelines adopted, opinions and binding decisions issued, cooperation and enforcement figures. Background only.

EDPB Strategy 2024-2027

18 April 2024Description

The Board's strategy for 2024-2027: its priorities for harmonisation, enforcement and engagement. Institutional.

EDPB Annual Report 2022

17 April 2023Description

The Board's annual report for 2022: guidelines adopted, opinions and binding decisions issued, cooperation and enforcement figures. Background only.

EDPB Work Programme 2023-2024

22 February 2023Description

The Board's work programme for 2023-2024: the guidelines, templates and coordinated actions it planned for the period. Background for what was coming.

EDPB Annual Report 2021

12 May 2022Description

The Board's annual report for 2021: guidelines adopted, opinions and binding decisions issued, cooperation and enforcement figures. Background only.

EDPB Annual Report 2020

02 June 2021Description

The Board's annual report for 2020: guidelines adopted, opinions and binding decisions issued, cooperation and enforcement figures. Background only.

EDPB Work Programme 2021-2022

16 March 2021Description

The Board's work programme for 2021-2022: the guidelines, templates and coordinated actions it planned for the period. Background for what was coming.

Statement 03/2021 on the ePrivacy Regulation

09 March 2021Read from the documenthistoricalcookies trackingother

The Council's negotiating mandate of 10 February 2021 on the ePrivacy Regulation risks lowering protection below the current Directive: the EDPB rejects general and indiscriminate retention of traffic and location data, calls for an explicit prohibition of cookie walls with a fair alternative, opposes further processing of metadata on a compatibility test, finds the exceptions in Articles 6, 6b and 6c too broad, and insists that data protection authorities enforce the Regulation within the GDPR cooperation mechanisms. Addressed to the co-legislators. The position is historical, but it records the EDPB's standing view on cookie walls and on metadata retention.

EDPB Strategy 2021-2023

15 December 2020Description

The Board's strategy for 2021-2023: its priorities for harmonisation, enforcement and engagement. Institutional.

EDPB Annual Report 2019

18 May 2020Description

The Board's annual report for 2019: guidelines adopted, opinions and binding decisions issued, cooperation and enforcement figures. Background only.

EDPB response to Hoda letter

21 February 2020Description

Reply to correspondence from Hoda S.r.l., an Italian company, on the handling of a request for an opinion that the Italian authority had withdrawn, pointing the company to the general stakeholder channels. Correspondence.

EDPB Annual Report 2018

16 July 2019Description

The Board's annual report for 2018: guidelines adopted, opinions and binding decisions issued, cooperation and enforcement figures. Background only.

Statement 3/2019 on an ePrivacy regulation

13 March 2019Description

Statement urging the co-legislators to adopt the ePrivacy Regulation. The Commission announced the withdrawal of the proposal in February 2025 and formally withdrew it in October 2025 (OJ C/2025/5423).

EDPB Work Programme 2019-2020

12 February 2019Description

The Board's work programme for 2019-2020: the guidelines, templates and coordinated actions it planned for the period. Background for what was coming.

Other policy documents8 documents, 1 written

EDPB Comments on the European Commission's draft measures in the specification proceedings concerning Alphabet's compliance with Article 6(11) Digital Markets Act

05 May 2026Description

Comments to the Commission on the draft measures specifying Alphabet's obligation under Article 6(11) DMA to share search ranking, query, click and view data with competing search engines, including relevant AI services: the EDPB asks for effective anonymisation of the shared data and safeguards against re-identification. Gatekeeper platforms only.

Position paper on Interplay between data protection and competition law

17 January 2025Read from the documentgovernanceenforcement

Data protection and competition law pursue distinct objectives but both protect the individual, as data subject and as consumer, and personal data is central to digital business models, so the two sets of authorities must coordinate. Following the CJEU judgment in Meta v Bundeskartellamt, a competition authority assessing abuse of dominance may need to examine GDPR compliance but cannot replace the competent data protection authority, and the principle of sincere cooperation makes cooperation mandatory in some cases. The paper recommends dedicated coordination teams, cooperation protocols with deadlines and information-sharing rules, and joint sector inquiries. Expect data-sharing and default-setting practices of dominant firms to be reviewed by both regulators.

Internal procedure43 documents, 0 written

Rules of Procedure - version 8

06 April 2022Description

Rules of procedure of the Board. Governs how the Board itself works: no obligation on controllers or processors.

Rules of Procedure - version 7

08 October 2020Description

Rules of procedure of the Board. Governs how the Board itself works: no obligation on controllers or processors.

EDPB Guidance on its Plenary Minutes

14 September 2020Description

Internal procedural guidance of the Board. Governs how the Board itself works: no obligation on controllers or processors.

Rules of Procedure - version 6

31 January 2020Description

Rules of procedure of the Board. Governs how the Board itself works: no obligation on controllers or processors.

CSC Rules of Procedure

03 December 2019Description

Rules of procedure of the Board. Governs how the Board itself works: no obligation on controllers or processors.

Rules of Procedure - version 5

02 December 2019Description

Rules of procedure of the Board. Governs how the Board itself works: no obligation on controllers or processors.

Rules of Procedure - version 4

12 November 2019Description

Rules of procedure of the Board. Governs how the Board itself works: no obligation on controllers or processors.

Rules of Procedure - version 3

10 September 2019Description

Rules of procedure of the Board. Governs how the Board itself works: no obligation on controllers or processors.

Rules of Procedure - version 2

23 November 2018Description

Rules of procedure of the Board. Governs how the Board itself works: no obligation on controllers or processors.

Memorandum of Understanding

25 May 2018Description

Memorandum of Understanding of the Board. Governs how the Board itself works: no obligation on controllers or processors.

Rules of Procedure - version 1

25 May 2018Description

Rules of procedure of the Board. Governs how the Board itself works: no obligation on controllers or processors.

Sources: every entry links to its page on the EDPB website, which is the source for the title, date and document. The inventory CSV and the printable digest in the site's outputs folder list all 543 with a numbered source. Snapshot 19 September 2026.