Overslaan en naar de inhoud gaan
ShareEmailLinkedInXWhatappsFacebook
feedback
Share

EDPB gives recommendations to make online shopping more respectful of users’ privacy, discusses the Digital Omnibus proposal and appoints new Deputy Chair

4 dagen 1 uur ago

Brussels, 4 December - During its latest plenary, the EDPB adopted recommendations on the legal basis for requiring the creation of user accounts on e-commerce websites. In addition, the Board had a preliminary discussion on the Digital Omnibus proposal and appointed the new EDPB Deputy Chair.

Internet users visit e-commerce websites for a variety of reasons, including making online purchases, taking advantage of promotions, or simply browsing products. When interacting with these websites, they may be asked to create an account, which can result in the collection and processing of personal data, as well as increased privacy and security risks.

The EDPB adopted recommendations to clarify when e-commerce websites can require their users to create an account.

As a general rule, users should have the option to engage with e-commerce websites, including the ability to make purchases, without creating an account. In such cases, the EDPB recommends that e-commerce websites offer a choice: either a 'guest' mode, allowing users make purchases without creating an account, or the option to voluntarily create an account. This approach minimises the collection and processing of personal data, and therefore aligns with the GDPR's principle of data protection by design and by default. 

However, mandatory account creation can be justified in a limited number of cases, including for example, offering a subscription service or providing access to exclusive offers.

The recommendations highlight the EDPB's efforts to promote pragmatic, user-friendly and privacy-protective practices in the e-commerce sector.

The recommendations are subject to public consultation, providing stakeholders with the opportunity to comment and provide feedback.

 

Preliminary discussion on the Digital Omnibus proposal

The EDPB had a preliminary discussion on the proposal for a Digital Omnibus, on which the EDPB and EDPS will issue a Joint Opinion.

In its Helsinki Statement, the EDPB made proposals in order to achieve enhanced clarity, support and engagement. The EDPB and the EDPS welcome the discussion on effective digital regulation and remain committed to finding solutions to make GDPR compliance easier, especially for small organisations.

The EDPB and the EDPS will focus on how the European Commission’s proposal will impact the fundamental rights of individuals and whether it will lead to simplification for organisations and more legal certainty.

While numerous points need to be analysed, at this stage, the EDPB and the EDPS can already underline that the proposed modification of the definition of personal data seems to go further than the recent CJEU case law, and beyond a targeted modification of the GDPR, which may risk to adversely affect the fundamental right to data protection.

The EDPB recalls its upcoming public stakeholder event on this topic on 12 December 2025 and underlines that the implementation of the CJEU case law through guidelines taking into account stakeholders' input ensures greater certainty.

 

Jelena Virant Burnik elected new Deputy Chair of the EDPB

At this week’s plenary, the members of the EDPB appointed Jelena Virant Burnik, Information Commissioner of the Republic of Slovenia, as new Deputy Chair of the Board.

“I am honoured to have been elected as Deputy Chair of the EDPB. I am pleased to have the opportunity to help strengthen the role of the EDPB as a central authority in EU data protection.  I am committed to fostering cooperation among national Data Protection Authorities and providing a forum for their open discussions that help align the understanding and enforcement of the GDPR provisions.

In the ever-developing landscape of digital regulation, the EDPB must remain a regulator that understands the complex interplay of legislation and contributes productively to the discussions at European level. “

EDPB Deputy Chair, Jelena Virant Burnik

“Over the past years, the landscape in which we operate has fundamentally shifted, reshaping the EDPB’s role in Europe’s digital future. In this dynamic environment, the new EDPB Deputy Chair faces exciting challenges ahead. I am confident that the EDPB will greatly benefit from her expertise and dedication.

I look forward to collaborating with Jelena Virant Burnik to advance the EDPB’s shared mission: fostering innovation while safeguarding individuals’ fundamental rights."

EDPB Chair, Anu Talus

Over the coming years, Jelena Virant Burnik, will work closely with EDPB Chair Anu Talus and fellow Deputy Chair Zdravko Vukić to ensure the consistent application of EU data protection rules and promote effective cooperation among Data Protection Authorities across Europe.

EDPB

Strengthening data protection worldwide: EDPB meets with the countries and organisation with an adequacy decision

5 dagen 1 uur ago

Brussels, 3 December - As part of its December’s plenary meeting, the European Data Protection Board (EDPB) held yesterday an online meeting with Commissioners and representatives of Data Protection Authorities (DPAs) from the countries and the organisation with an EU adequacy decision. This meeting marked the second of its kind, following the first gathering in October 2024.

An adequacy decision is a key-mechanism in EU data protection legislation which allows free flow of personal data from Europe to third countries or an international organisation offering an adequate level of data protection.* To date, the following countries and organisation benefit from this:  Andorra, Argentina, Canada, Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, United Kingdom, Uruguay, United States, and the European Patent Organisation. Data Protection Authorities from those countries and the European Patent Organisation are key partners for the EDPB, playing a key role in our joint efforts to strengthen data protection worldwide.

Strengthening multilateral cooperation

The Board organised a first meeting in October 2024 with Data Protection Authorities from the fifteen countries with an EU adequacy decision.

Following that meeting, the EDPB and the Data Protection Authorities from the countries and the organisation with an EU adequacy decision strengthened their cooperation by sharing information on some advisory works and gathering experiences on international data protection enforcement cooperation.

“Our first joint meeting in October 2024 paved the way for a stronger cooperation and valuable knowledge and experience sharing on data protection.

The high level of engagement shown in this second meeting by the EDPB and the Data Protection Authorities from the countries and the international organisation for which the EU adopted an adequacy decision is a clear sign of our commitment to continue working together in this shared direction.”

EDPB Chair, Anu Talus

Yesterday’s meeting was an opportunity for all participants to share views on past activities and updates on the next enforcement and advisory priorities.

 

Note to editors

The European Commission has the power to determine, on the basis of Art. 45 of Regulation (EU) 2016/679 whether a country outside the EU offers an adequate level of data protection.

The adoption of an adequacy decision involves: 1) a proposal from the European Commission; 2) an opinion of the European Data Protection Board; 3) approval from representatives of EU countries; 4) adoption of the decision by the European Commission.

EDPB

Support the EDPB’s work as an expert

1 week 3 dagen ago

Brussels, 28 November - The EDPB launched a call for expression of interest to establish a new reserve list for the Support Pool of Experts (SPE) programme. The objective is set up a reserve list of legal and technical experts.

The legal expertise sought includes a wide range of fields, such as data protection, policy monitoring, technology, cybersecurity, competition, healthcare, online intermediary services and content moderation.

As for the technical expertise, the relevant areas include IT auditing, website security, mobile OS and apps, Internet of Things, cloud-computing, behavioural advertising, anonymisation techniques, cryptology, artificial intelligence, User experience (UX) design, fintech, data science, social science (incl. economics, sociology, psychology), and development of applications and software.

Bring your expertise to the table

Don’t miss this opportunity to participate in this EDPB’s key strategic initiative. Your work will help Data Protection Authorities (DPAs) across Europe increase their capacity to supervise and enforce data protection rules and strengthen the protection of individuals’ fundamental rights.

In 2022, the EDPB issued a call for expression of interest, which led to the establishment of a first SPE reserve list. As this list is set to expire in February 2026, the EDPB is inviting experts who were included in this first SPE reserve list to submit their application in response to the new call for expression of interest.

The call will be open until August 2030.

Learn how to submit your application.

Apply now


Background

The SPE was developed as part of the EDPB Strategy 2021-2023 to help DPAs increase their enforcement capacity by developing common tools and giving them access to a wide pool of experts.  

The EDPB aims to carry out approximately ten projects per year with pre-eminent external experts in a given field.  Projects are coordinated either by individual DPAs or by the EDPB.

More information on the SPE and on completed project is available here
 

EDPB

Stakeholder event on anonymisation and pseudonymisation: express your interest

3 weken ago

Brussels, 17 November - The EDPB organises a remote event to collect  stakeholders’ input on anonymisation and pseudonymisation on implications of the judgement of the Court of Justice of the European Union (CJEU) in EDPS v Single Resolution Board (SRB). The event will take place on 12 December 2025 (time to be confirmed).

This will be an opportunity to inform and support the EDPB’s ongoing work on these topics as per its work programme 2024-2025 and it reflects the EDPB’s commitment to stakeholder engagement, as outlined in the recent Helsinki statement.  

Who can participate?

Individuals representing sector associations, organisations or NGOs and individual companies, law firms or academics are invited to express their interest to participate in this event (one participant per organisation). The EDPB encourages all organisations interested in this matter to delegate a representative with technical knowledge of these topics.

As a general rule, participants will be registered on a first-come first-served basis. Nonetheless, the EDPB reserves the right to give precedence to specific stakeholders among those who expressed their interest, based on their relevance to the topics of the event, and to ensure diversity of views and a balanced representation of areas of interest, as well as geographical balance.

How to take part?

You can find further information and the instructions on how to register (link not available).

The call will be closed as soon as a sufficiently high number of applicants is reached with a view to ensuring the participation of a maximum number of stakeholders.

If you have technical problems submitting the application, we invite you to refresh the page or open the form in a different browser. 

 

Update on 17/11/2025, 12:57 pm: The call is now closed.

Thank you to all those who expressed their interest in taking part in the EDPB stakeholder event on ‘anonymisation and pseudonymisation’. We will carefully review all applications and communicate the results of the process to those who applied in the coming weeks.
 

EDPB

Draft adequacy decision for Brazil: EDPB adopts opinion

1 maand ago

Brussels, 5 November - During its latest plenary, the EDPB adopted an opinion on the European Commission’s draft decision on the adequate level of protection of personal data in Brazil.* Once adopted, the decision will ensure that personal data can flow freely from Europe to Brazil and that individuals can retain control over their data.

In its opinion, requested by the Commission, the EDPB assesses whether the Brazilian data protection framework and the rules on government access to personal data transferred from Europe provide safeguards essentially equivalent to the ones in EU legislation. The Board positively notes the close alignment with EU legislation and the case law of the Court of Justice of the EU. The EDPB also examines whether the safeguards provided under the legal framework in Brazil are in place and effective.

“The EDPB welcomes the alignment between Brazil and Europe’s data protection frameworks. This is a pivotal moment that will strengthen legal certainty for organisations and competent authorities transferring personal data from Europe to Brazil.

We call on the European Commission to address a few remaining points to ensure the effective protection of individuals’ fundamental rights.”

EDPB Chair, Anu Talus


The EDPB also invites the Commission to provide further clarifications and monitor certain areas in relation to Data Protection Impact Assessments (DPIA), the limitations on transparency related to commercial and industrial secrecy, and the rules on onward transfers.

As a general rule, the Brazilian data protection law does not apply to data processed by Brazilian public authorities for the exclusive purposes of public safety, national defence, State security, or the investigation and prosecution of criminal offenses.

At the same time, the EDPB positively notes that the Brazilian data protection law partially applies to the processing of personal data in the context of criminal investigations and maintenance of public order, as interpreted by the Federal Supreme Court of Brazil in its case-law.

The Board invites the Commission to further specify the applicability of the Brazilian data protection law, as well as the Brazilian Data Protection Authority’s investigatory and corrective powers in relation to law enforcement authorities. Finally, the Board invites the Commission to further clarify the outline of Brazil’s concept of national security.

 

Note to editors:

* An adequacy decision is a key-mechanism in EU data protection legislation which allows the European Commission to determine whether a third country or an international organisation offers an adequate level of data protection. The European Commission has the power to determine, on the basis of Art. 45 of Regulation (EU) 2016/679 whether a country outside the EU offers an adequate level of data protection.

The adoption of an adequacy decision involves: 1) a proposal from the European Commission; 2) an opinion of the European Data Protection Board; 3) approval from representatives of EU countries; 4) adoption of the decision by the European Commission.

EDPB

Help make GDPR compliance easy for organisations: what templates would be helpful for you? Provide your feedback

1 maand ago

Brussels, 5 November - The European Data Protection Board (EDPB) is taking an important step towards facilitating GDPR compliance for organisations by developing a series of ready-to-use templates. This initiative, announced following the Helsinki Statement on enhanced clarity, support, and engagement, aims to provide practical tools that organisations can readily implement to meet their data protection obligations.

To ensure these templates address the needs of organisations, the EDPB has launched a public consultation inviting stakeholders to share their suggestions. The consultation specifically seeks feedback on which types of templates would be most beneficial (for example, a template for privacy notices or a template for records of processing activities).

The EDPB will already work on templates for key GDPR requirements such as Data Protection Impact Assessments (DPIAs) and data breach notifications.

Contributions can be submitted here until 3 December 2025.

The EDPB encourages all interested parties to take part in this consultation and help create practical resources that make GDPR compliance more straightforward and accessible for everyone.

EDPB

Draft UK adequacy decisions: EDPB adopts opinions

1 maand 2 weken ago

Brussels, 20 October - During its latest plenary, the EDPB adopted two opinions on the European Commission’s draft decisions on the extension of the validity of the UK adequacy decisions under the General Data Protection Regulation (GDPR) and the Law Enforcement Directive (LED) until December 2031.*

The EDPB opinions, requested by the Commission as per Art. 70(1) (s) GDPR and Art. 51(1) (g) LED, address the proposed six-year extension of the two UK adequacy decisions which are set to expire in December 2025.

The extension of the validity of the UK adequacy decisions will allow organisations and competent authorities based in Europe to continue transferring data to UK-based organisations and authorities without implementing additional guarantees.**

“The EDPB welcomes the continuing alignment between the UK and Europe’s data protection framework, despite the recent changes in the UK legal framework.

I call on the European Commission to address the points highlighted by the Board and to ensure an effective monitoring once the decisions are adopted. This will increase the robustness of UK’s adequacy and ensure more legal certainty for organisations and competent authorities transferring personal data from Europe to the UK.”

EDPB Chair, Anu Talus

About the GDPR opinion

According to the Board, most of the changes introduced to the UK’s data protection framework aim to clarify and facilitate compliance with the law.

Some aspects of the draft decision could be further clarified.

The EDPB invites the European Commission to further analyse and monitor the changes to the Retained EU Law (Revocation and Reform) Act 2023, also known as REUL Act, in particular the removal of the principle of primacy of EU law and the removal of the direct application of the principles of EU law.

The EDPB notes that the Secretary of State has been granted new powers to introduce changes to the new data protection framework, via secondary regulations which require less Parliamentary scrutiny. This is the case for international transfers, automated decision-making, and the governance of the Information Commissioner’s Office (ICO). The EDPB invites the Commission to address possible risks of divergence by highlighting, in the final adequacy decision, the areas which they intend to carefully monitor.

The EDPB also encourages the Commission to further elaborate its assessment and monitor the rules on transfers from the UK to third countries. The new adequacy test, introduced by the Data (Use and Access) Act 2025, requires the level of protection of the third country to be not materially lower than the one provided for data subjects by the UK framework, but this test does not refer to the risk of government access, the existence of redress for individuals and the need for an independent supervisory authority.

The Commission should also further assess and monitor the purported use by the UK Government of Technical Capability Notices (“TCN”) requiring companies to circumvent encryption, as this would create systemic vulnerabilities and pose a risk to the integrity and confidentiality of electronic communications.

Finally, the EDPB calls on the Commission to further assess and monitor the changes to the structure of the ICO and the exercise of its corrective powers. In this context, the EDPB positively notes the transparency policy of the ICO and the availability of the statistical and analytical data of its enforcement activities.

The new adequacy decisions will add to the 2021 decisions, which will continue to apply to areas not covered in the 2025 draft decisions. The EDPB builds on its 2021 opinions (14/2021 and 15/2021). In particular, the close alignment between the GDPR framework and the UK legal framework on key provisions, highlighted in 2021, continues to hold true today (including, for example, transparency, data subject rights, and special categories of data).

About the LED opinion

The EDPB welcomes the continuous alignment between the data protection framework in Europe and the UK, and encourages the Commission to complement its assessment on aspects relating to national security exemptions. Such exemptions may waive most data protection principles and some international transfer rules for law enforcement authorities, and also limit ICO’s enforcement and inspection powers.

The EDPB invites the Commission to analyse the UK’s rules on transfers of personal data to third countries, in particular the new adequacy test, in the same way as in the GDPR opinion.

The Board also points out the more permissive approach for automated decision making and the new powers conferred to the Secretary of State in this matter. It recalls the importance of meaningful human review and urges the Commission to clarify and monitor possible exemptions from individuals’ right to obtain human intervention.

Finally, the EDPB acknowledges that the system of oversight of criminal law enforcement agencies as well as the redress mechanisms remain largely unchanged, and it reiterates the need for the Commission to closely monitor the application of corrective powers and remedies for individuals in the UK data protection framework.

 

Note to editors:

* On 22 July 2025, the European Commission issued two draft amending implementing decisions on the adequate protection of personal data by the United Kingdom pursuant to Article 45(3) GDPR and Article 36(3) LED. These draft decisions aim at extending the validity of the previous adequacy decisions adopted on 28 June 2021.
In May 2025, the Commission adopted a decision to extend the validity of the UK adequacy decision for six more months, from June until December 2025. The EDPB adopted an opinion on this extension in May 2025.

** An adequacy decision is a key-mechanism in EU data protection legislation which allows the European Commission to determine whether a third country or an international organisation offers an adequate level of data protection. The European Commission has the power to determine, on the basis of Art. 45 of Regulation (EU) 2016/679 whether a country outside the EU offers an adequate level of data protection.

The adoption of an adequacy decision involves: 1) a proposal from the European Commission; 2) an opinion of the European Data Protection Board; 3) an approval from representatives of EU countries; 4) the adoption of the decision by the European Commission.

EDPB

Coordinated Enforcement Framework: EDPB selects topic for 2026

1 maand 3 weken ago

Brussels, 14 October - During its October plenary, the European Data Protection Board (EDPB) picked the topic for its fifth coordinated enforcement action, which will concern compliance with the obligations of transparency and information under the General Data Protection Regulation (GDPR).  The GDPR ensures that individuals are informed when their data is being processed (under Art. 12, 13 and 14). This right to be informed is a core element of transparency and ensures that individuals have more control over their data.

In a coordinated action, the EDPB prioritises a certain topic for Data Protection Authorities (DPAs) to work on at national level. The results of these national actions are then aggregated and analysed to generate deeper insight into the topic and allowing for targeted follow-up at both national and European level if needed.

Participating DPAs will join this new action on a voluntary basis in the coming weeks and the action itself will be launched over the course of 2026.

CEF achievements so far

In recent years, the EDPB has carried out various coordinated actions on different topics, publishing reports on their results. Specifically:

Earlier this year, the EDPB has launched a coordinated action on the right to erasure or the “right to be forgotten” (Art.17 GDPR). The report on the outcome of this action will be adopted in the coming months.

Background

This new coordinated action follows the EDPB’s decision to set up a Coordinated Enforcement Framework (CEF) in October 2020. The CEF is a key action of the EDPB under its 2024-2027 Strategy, together with the creation of a Support Pool of Experts (SPE). The two initiatives aim to streamline enforcement and cooperation among DPAs.
 

EDPB

Strengthening Schengen security and preventing irregular migration: EU Entry Exit System enters into operation

1 maand 4 weken ago

Brussels, 10 October -   On the occasion of the upcoming entry into operation of the EU Entry Exit System (EES) on 12 October 2025, the Coordinated Supervision Committee (CSC) will include the EES system under its scope. This system registers non-Schengen nationals travelling with a short stay visa or travellers who are visa exempt. The EES is a large scale IT systems developed by the EU to prevent irregular migration and enhance security in the Schengen area.

 

How it works 

The EES gradually replaces passport stamping at the external borders of the Schengen area, with the aim of making the border process more efficient. The system records which travellers from third countries, with or without a visa, enter and exit the Schengen area. 

The implementation of the EES will happen gradually.  European countries will have the option to progressively start using this system over a period of six months, starting with the registration of third country nationals at 10% of border crossings. By the end of the six months period, European countries should reach full registration of all individuals.

Processing of individuals’ personal data by the EES

The EES records personal data from travel documents such as name, date of birth, and place of birth. It also registers the dates of entry and exit of travellers, as well as biometric data such as a facial images and fingerprints. Given the sensitivity of the personal data processed by this system, it is crucial to ensure individuals can effectively exercise their rights and the processing of personal data is supervised.

 

Ensuring data subject rights

The protection of personal data is a fundamental right, which also applies to EES data processing. 
The EES regulation ensures that travellers must be properly informed about their rights regarding the processing of their personal data in the EES, and how to exercise these rights. Authorities processing personal data in the EES, such as border guards, migration services, and under certain conditions, law enforcement authorities must ensure that individuals can easily request access to their data, as well as rectification, completion, erasure and restriction.

 

Supervision of the data processing in the EES

With the upcoming entry into operation of the EES, the CSC will also focus its supervision, at both European and at national level, on the processing of personal data in the EES.


More information on the CSC supervision of the EES will be published on the CSC members’ websites.

 

Background

The CSC consists of European national Data Protection Authorities and the EDPS, which together ensure coordinated supervision of large scale IT systems, and of EU bodies, offices and agencies falling under its scope. These also include the Schengen information system (SIS), the Visa information system (VIS), Eurodac, and two new systems entering into operation at a later date: the European Travel Information and Authorisation System (ETIAS) and the European Criminal Records Information System on non EU-nationals (ECRIS-TCN).
The CSC enjoys an autonomous functioning and positioning and it adopts its own rules of procedure and working methods. The Committee was established within the framework of the EDPB.
 

EDPB

Anonymisation and pseudonymisation: take part in the stakeholder event

1 maand 4 weken ago

Brussels, 9 October - The EDPB is organising a remote stakeholder event to collect stakeholders’ input on anonymisation and pseudonymisation following the clarification on the scope of the concept of personal data provided by the Court of Justice of the European Union (CJEU) in its judgement in EDPS v Single Resolution Board (SRB). The event will take place by the end of the year.
The event will inform and support the EDPB’s ongoing work on these topics as per its work programme 2024-2025 and it reflects the EDPB’s commitment to stakeholder engagement, as outlined in the recent Helsinki statement.  

Do you wish to participate to have your say? 

The EDPB will launch a call for expression of interest to participate in the stakeholder event in the following weeks. 
More details about the date and format will follow soon on the EDPB website.

EDPB

DMA and GDPR: EDPB and European Commission endorse joint guidelines to clarify common touchpoints

1 maand 4 weken ago

Brussels, 09 October - The European Data Protection Board (EDPB) and the European Commission endorsed joint guidelines on the interplay between the Digital Markets Act (DMA) and the General Data Protection Regulation (GDPR). These are the first joint guidelines by the Board and the European Commission.

In line with its 2024-2027 Strategy and the recent Helsinki Statement’s objectives to make GDPR compliance easier and strengthen consistency, the EDPB has cooperated with the European Commission, each within their respective mandates, to facilitate the coherent application of the DMA*and GDPR and to increase legal certainty for gatekeepers, business users, beneficiaries and individuals.

EDPB Chair Anu Talus said:  “These joint guidelines are the result of a fruitful cooperation between the EDPB and the European Commission. This is the first time that the EDPB and the European Commission prepare guidelines jointly. This approach maximises usefulness of the guidance by simplifying compliance for businesses and bringing enhanced legal certainty to them. 

The guidelines will help gatekeepers, business users and individuals to better understand their obligations and rights under the DMA, and ensure a consistent, effective and complementary application of the DMA and EU data protection law.”

How the DMA and the GDPR interact

The DMA and the GDPR both protect individuals in the digital landscape, but their goals are complementary as they address interconnected challenges: individual rights and privacy in case of the GDPR and fairness and contestability of digital markets under the DMA.   

Several activities regulated by the DMA entail the processing of personal data by gatekeepers and, in several provisions, the DMA explicitly refers to definitions and concepts included in the GDPR. The joint guidelines clarify how gatekeepers can implement these DMA provisions in accordance with EU data protection law. For example, the EDPB and the Commission specify which elements gatekeepers should consider in order to comply with the requirements of specific choice and valid consent under Art. 5(2) DMA and the GDPR, and thus to lawfully combine or cross-use personal data in core platform services.

The EDPB and the Commission also address other provisions including those related to the distribution of third party apps and stores, data portability, data access requests and interoperability of messaging services.

 

Next steps

The Board and the Commission have just launched a joint public consultation on the first version of the guidelines which will be open until 4 December 2025.  This will be an opportunity for stakeholders to comment and provide feedback.

All submissions will be published on the DMA website to which a link will be included on the EDPB website, after the consultation period has closed.

The final text, incorporating input received during the consultation, will be prepared jointly by the Board and the Commission, and will be adopted by the EDPB and European Commission.

 

More guidelines on the way

Following these first joint guidelines with the Commission, further work is underway to clarify the new cross-regulatory landscape and maintain coherent and consistent safeguards for the protection of personal data. In this regard, the EDPB is working with the Commission, specifically with the AI Office, on joint guidelines on the interplay between the AI Act and EU data protection laws.

Note to editors:
The Digital Markets Act is one of the first regulatory tools that aims to tackle unfair practices of gatekeepers in digital markets. Gatekeepers are large digital platforms providing core platform services, such as online search engines, app stores, and messenger services. The main objective of the DMA is to make the markets in the digital sector fairer and more contestable. 
 

EDPB

Interplay between the DSA and the GDPR: EDPB adopts guidelines

2 maanden 3 weken ago

Brussels, 12 September - During its September plenary meeting, the European Data Protection Board (EDPB) has adopted guidelines on the interplay between the Digital Services Act (DSA) and the General Data Protection Regulation (GDPR). These are the first set of EDPB guidelines on the interplay between the GDPR and the EU’s recently adopted digital laws.

The DSA aims to complement the rules of the GDPR to ensure the highest level of protection of fundamental rights in the digital space. Its main goal is to create a safer online environment in which the fundamental rights of all users, including the right to freedom of expression, are protected. It applies to online intermediary services, such as search engines and platforms.

Several provisions included in the DSA entail the processing of personal data by intermediary service providers. The EDPB guidelines contribute to the consistent application of the DSA and of the GDPR, insofar as some provisions of the DSA concern the processing of personal data by intermediary service providers and include references to GDPR concepts and definitions.

While it is up to the competent authorities under the DSA - with the support of the European Board for Digital Services and EU courts - to interpret the DSA, there are a number of provisions which relate to the GDPR.

These include:

  • notice-and-action systems that help individuals or entities report illegal content
  • recommender systems used by online platforms to automatically present specific content to the users of the platform with a certain relative order or prominence
  • the provisions to ensure a high level of privacy, safety, and security of minors and prohibiting that profile-based advertising using their data is presented to them
  • transparency of advertising by online platforms
  • prohibition of profiling-based advertising using special categories of data 

The EDPB guidelines help to understand how the GDPR should be applied in the context of DSA obligations.

The EDPB also provides practical guidance relating to the cross-regulatory cooperation between authorities to coordinate enforcement which will provide more legal certainty for intermediary service providers and ultimately to protect the rights and freedoms of individuals.

The guidelines will be subject to public consultation, providing stakeholders with the opportunity to comment and provide feedback.

EDPB Chair Anu Talus said: “By clarifying the interplay between the DSA and the GDPR, these guidelines mark a significant step towards ensuring a coherent and effective EU digital rulebook, and they will help uphold the fundamental rights and freedoms of individuals.

I hope that stakeholders, including the competent authorities under the DSA, will make the most of the opportunity to contribute to the public consultation".

More work in the pipeline

Following these first guidelines on the interplay between the GDPR and the DSA, further work is underway with other regulators to clarify the new cross-regulatory landscape and maintain coherent and consistent safeguards for the protection of personal data. In this regard, the EDPB is working on joint guidelines with the European Commission on the interplay between the Digital Markets Act (DMA) and the GDPR, as well as on joint guidelines on the interplay between the AI Act and EU data protection laws.
 

EDPB

Targeted modifications of the GDPR: EDPB & EDPS welcome simplification of record keeping obligations and request further clarifications

4 maanden 4 weken ago

Brussels, 9 July 2025 - The European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) issued today a Joint Opinion on the European Commission’s Proposal for a Regulation amending certain regulations, including the GDPR

The Proposal, part of the fourth simplification Omnibus, aims to simplify EU rules and reduce administrative burden, extending certain mitigating measures available for small and medium sized enterprises (SMEs) to small mid-cap enterprises (SMCs), and includes further simplification measures.  

The Proposal aims to modify Art.30 (5) GDPR, providing a derogation to the obligation to keep a record of data processing operations. Currently, this derogation only applies to enterprises and organisation under 250 employees, except in certain cases. Under the Proposal, the derogation would apply to an enterprise or organisation employing fewer than 750 people, unless the processing operation carried out is likely to result in a high risk to individuals’ rights and freedoms, within the meaning of Art.35 GDPR. 

In addition, the Proposal introduces a definition of SME and SMC in Art.4 GDPR and extends the scope of Art.40 (1) and 42 (1) GDPR to the SMCs, which refer to codes of conduct and certification. These tools are currently designed to help enterprises and organisations demonstrate compliance with the GDPR focusing on the specific needs of SMEs. 

Wojciech Wiewiórowski, EDPS, said: “We support the general objective of the Proposal to reduce the administrative burden for SMEs and SMCs as long as this does not lower the protection of individuals’ fundamental rights, in particular the rights to privacy and to the protection of personal data. To this end, we welcome that the proposed modifications to simplify and clarify the obligation to keep a record of processing are targeted and limited in nature, and do not affect the core principles and other obligations under the GDPR.”  

Anu Talus, EDPB Chair, said: “The EDPB supports the Proposal’s general objective to reduce the administrative burden for SMEs and SMCs and to ensure that, in practice, they can enjoy a derogation from the duty to keep records of processing activities. The current derogation did not always achieve its goal. At the same time, the record of processing activities is a useful tool to support compliance with other duties, such as the one of transparency or to give effect to data subject rights. The simplification will offer greater flexibility to SMEs and SMCs to choose the most appropriate method to be compliant.”

As regard the organisations being subject to the derogation, considering that the Proposal impacts legislation in other policy areas, the EDPB and the EDPS expect further clarifications on why the new threshold of enterprises or organisations employing fewer than 750 persons would be more appropriate under the GDPR, rather than the threshold of 500 employees initially considered. In addition, the new exemption in Art. 30 (5) refers to ‘enterprises employing fewer than 750 employees’ without referring to the newly introduced definitions of SME and SMC, which also includes financial criteria. In order to ensure that the exemption will benefit SMEs and SMCs, the EDPB and the EDPS’s Joint Opinion recommends referring to the newly introduced definitions of SME and SMC. 

The EDPB and EDPS also ask the co-legislators to clarify in the Proposal that the term ‘organisation’, falling within the scope of the proposed derogation under Art.30 (5) GDPR, does not include public authorities and bodies.  
 

EDPB

The Helsinki Statement on enhanced clarity, support and engagement

5 maanden ago

A fundamental rights approach to innovation and competitiveness

Helsinki, 3 July 2025 – At a high-level meeting in Helsinki on 1–2 July 2025, the European Data Protection Board (EDPB) adopted a landmark Statement on enhanced clarity, support and engagement.

The Statement outlines new initiatives to make GDPR compliance easier, in particular for micro, small and medium organisations, strengthen consistency and boost cross-regulatory cooperation. 

EDPB Chair Anu Talus said: “The EDPB aims to ensure that compliance with the GDPR can be more easily achieved. By placing fundamental rights into the core of their digital transformation, organisations can ensure that technological advancements and the respect for European values go hand in hand, ultimately building a stronger and more resilient digital economy.”

Across its efforts, the EDPB will strengthen its dialogue with stakeholders, holding proactive and early engagement to identify areas where further support and clarification is required, and providing the opportunity for stakeholders to flag possible inconsistencies and give feedback. The EDPB will publicly report on the main outcomes of the public consultations. 

The EDPB will launch a series of direct and practical resources to simplify GDPR application.

EDPB Chair Anu Talus said: “The EDPB is committed to helping organisations in achieving GDPR compliance with greater ease and efficiency. Through timely and concise guidance and ready-to-use tools, like a common data breach notification template, checklists, how-tos and FAQs, we will continue to make GDPR alignment achievable and accessible for all.”

Among the measures agreed upon to ensure consistent GDPR interpretation and enforcement across Europe, EDPB Members will make continuous efforts to align national and EDPB guidance. They will also develop common practices, methods, tools and common actions review guidelines to ensure their real-world effectiveness. The EDPB will also publish positions by DPAs on priority issues to help organisations understand and act on regulatory expectations.

The EDPB recognises the growing complexity of the digital regulatory landscape and has renewed its commitment to fostering structured cooperation with non-data protection regulators to address legal and practical challenges in cross-sectoral cases.
 

EDPB

EDPB publishes final version of guidelines on data transfers to third country authorities and SPE training material on AI and data protection

6 maanden ago

Brussels, 05 June - During its latest plenary, the European Data Protection Board (EDPB) adopted the final version of its guidelines on Art.48 GDPR about data transfers to third country authorities, after public consultation. In addition, the Board presented two new Support Pool of Experts (SPE) projects providing training material on artificial intelligence and data protection. Finally, the Board discussed the European Commission’s request for a joint EDPB-EDPS opinion on the draft proposal on the simplification of record-keeping obligation under the GDPR. 

Data transfers to third country authorities 

Following public consultation, the EDPB has adopted the final version of the guidelines on data transfers to third country authorities. In its guidelines, the EDPB zooms in on Art. 48 GDPR and clarifies how organisations can best assess under which conditions they can lawfully respond to requests for a transfer of personal data from third country authorities (i.e. authorities from non-European countries).

The EDPB explains that judgements or decisions from third country authorities cannot automatically be recognised or enforced in Europe. As a general rule, an international agreement may provide for both a legal basis and a ground for transfer. In case there is no international agreement, or if the agreement does not provide for an appropriate legal basis or safeguards, other legal bases or other grounds for transfer could be considered, in exceptional circumstances and on a case by case basis.

The modifications introduced in the updated guidelines do not change their orientation, but they aim to provide further clarifications on different aspects that were brought up in the consultation. For example, the updated guidelines address the situation where the recipient of a request is a processor. In addition, they provide additional details regarding the situation where a mother company in a third country receives a request from that third country authority and then requests the personal data from its subsidiary in Europe. 

 

Upskilling and reskilling on AI and data protection

During its June’s plenary, the EDPB also presented two new Support Pool of Experts (SPE) projects*: Law & Compliance in AI Security and Data Protection and Fundamentals of Secure AI Systems with Personal Data. The two projects, which have been launched at the request of the Hellenic Data Protection Authority (HDPA), provide training material on AI and data protection.

The report “Law & Compliance in AI Security & Data Protection” is addressed to professionals with a legal focus like data protection officers (DPO) or privacy professionals.

The second report, “Fundamentals of Secure AI Systems with Personal Data”, is oriented toward professionals with a technical focus like cybersecurity professionals, developers or deployers of high-risk AI systems.

The main aim of these projects is to address the critical shortage of skills on AI and data protection, which is seen as a key obstacle to the use of privacy-friendly AI. The training material will help equip professionals with essential competences in AI and data protection to create a more favourable environment for the enforcement of data protection legislation.

The Board decided to publish both documents as PDF files. Taking into account the very fast evolution of AI, the EDPB also decided to launch a new innovative initiative as a one-year pilot project consisting of a modifiable community version of the reports. The EDPB will start working with the authors of both reports to import them in its Git repository** to allow, in a near future, any external contributor, with an account on this platform and under the condition of the Creative Commons Attribution-ShareAlike license, to propose changes or add comments to the documents.

Simplification of record-keeping obligation under the GDPR ***

Finally, the Board discussed the European Commission's request for a joint opinion by the EDPB and the European Data Protection Supervisor (EDPS) on its proposal to simplify the record-keeping obligations of small and medium-sized enterprises (SMEs), small mid-caps (SMCs) and organisations with fewer than 750 employees, amounting to a targeted amendment of Art. 30(5) GDPR. The EDPB and EDPS will issue their joint opinion on this matter within eight weeks. 

 

Note to editors:

* The Support Pool of Experts (SPE) is an initiative included in the EDPB strategy 2024-2027 to help Data Protection Authorities (DPAs) increase their capacity to enforce by developing common tools and giving them access to a wide pool of experts.  

As part of the SPE programme, the EDPB may commission experts to provide reports and tools on specific topics. The views expressed in the deliverables are those of their authors and they do not necessarily reflect the official position of the EDPB.

** The reports will be available in the following months on the repository page.

***On 8 May 2025, the EDPB and the EDPS adopted a letter, addressed to the European Commission, to share preliminary views on the Commission’s proposal on the simplification of record-keeping obligation under the GDPR.

EDPB

Simplification of record-keeping obligation: EDPB and EDPS adopt letter to EU Commission

7 maanden ago

Brussels, 08 May - The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have adopted a letter, addressed to the European Commission, on the upcoming proposal on the simplification of record-keeping obligation under the GDPR, amounting to a targeted amendment of Art. 30(5) GDPR.

The joint letter replies to the letter sent by the European Commission to the EDPB and the EDPS on 6 May 2025 where the Commission explained how it intends to introduce specific modifications to the GDPR. The EDPB and EDPS understand that a formal consultation will take place after the publication of the proposed legislative change.  

The EDPB and EDPS shared that, at this stage, they could express preliminary support to this targeted simplification initiative, bearing in mind that this would not affect the obligation of controllers and processors to comply with other GDPR obligations. Nevertheless, the EDPB and EDPS asked the Commission to better evaluate the impact on the organisations subject to this change, to assess whether the draft proposal ensure a proportionate and fair balance between the protection of personal data and the interests of organisations with less than 500 employees.

EDPB-EDPS Letter on European Commission draft proposal on simplification of record-keeping under the GDPR

8 May 2025 Publication Type: Topics: English Download Simplification of record-keeping obligation: EDPB and EDPS adopt letter to EU Commission
EDPB

European Patent Organisation and extension of adequacy decisions for the UK: EDPB adopts opinions

7 maanden ago

Brussels, 06 May - During its latest plenary, the European Data Protection Board (EDPB) adopted an opinion on the European Commission’s draft adequacy decision under the GDPR concerning the European Patent Organisation (EPO). In addition, the Board adopted an opinion on the European Commission’s proposal to extend the validity of the UK adequacy decisions under the GDPR and the Law Enforcement Directive (LED). Finally, the EDPB agreed to grant the status of observer to the Personal Data Protection Agency of Bosnia and Herzegovina.

 

Adequate protection of personal data by the EPO

At the European Commission’s request, the Board adopted an opinion on the Commission’s draft adequacy decision regarding the European Patent Organisation (EPO). Once formally adopted by the Commission, this will be the first adequacy decision concerning an international organisation and not a country or a region.
An adequacy decision is a key-mechanism in EU data protection legislation which allows the European Commission to determine whether a third country or an international organisation offers an adequate level of data protection. The effect of such a decision is that personal data can flow freely from Europe to that third country or international organisation.

EDPB Chair, Anu Talus, said: “The EDPB welcomes the Commission’s initiative to work on the first adequacy decision concerning an international organisation. This decision shows how the legal framework of such organisations can be recognised as ensuring an adequate level of protection on the basis of Art.45 GDPR.

The EDPB underlines the importance of ongoing dialogue between the Commission and international organisations, with a view to developing this category of adequacy decisions in addition to those relating to third countries.”

In its opinion, the Board positively notes that the EPO data protection framework is largely aligned with the European Union data protection framework, including on data protection rights and principles.

This shows that the GDPR and, in particular, its transfer provisions, can facilitate safe data flows from Europe to international organisations, while taking into account their status.

 

Six-month extension of the UK adequacy decisions

The EDPB opinion, requested by the European Commission, addresses the proposed extension of the two UK adequacy decisions under the GDPR and the LED, which are set to expire on 27 June 2025.

The opinion only concerns the proposed 6-month extension of these adequacy decisions and does not address the level of protection for personal data afforded in the UK, which will be examined by the EDPB following the Commission’s assessment, and if the renewal of the UK adequacy decisions is proposed.

Since the UK‘s data protection reform is still pending in the UK parliament, the EDPB recognises the need for a technical and time-limited extension of the adequacy decisions until 27 December 2025.This will give the European Commission sufficient time to evaluate the updated UK legal framework once it has been adopted.  

The EDPB stresses that this extension is exceptional and is due to the ongoing legislative developments in the UK. It should not, in principle, be further prolonged.

The Board recalls the validity of its opinions 14/2021 and 15/2021 on the two UK adequacy decisions, adopted in April 2021, and invites the European Commission to take them into account in its future assessments. 
The Board also recalls the Commission’s obligation to monitor all relevant developments in the UK during the extension period.

 

New observer to the EDPB’s activities

Finally, EDPB members agreed to grant observer status to the EDPB’s activities to the Bosnia and Herzegovina Data Protection Authority, in line with Art. 8 EDPB Rules of Procedure.
 

EDPB

Europe Day 2025: come and visit us!

7 maanden ago

Every year, on 9 May, people across Europe celebrate the anniversary of the Schuman Declaration, which was a milestone to bring peace and solidarity in Europe. This year is particularly special as it marks the 75th anniversary of this historic moment.

Let’s celebrate together

To celebrate this occasion, the EDPB takes part in the EU Open Day, with an interactive stand hosted by volunteers from the EDPB Secretariat and national Data Protection Authorities (DPAs). Come and visit us to learn more about data protection and the EDPB’s activities.

You will find the EDPB and EDPS stands at the European Commission’s headquarters - the Berlaymont building - Village 1 “A Democratic Union”, on Saturday 10 May from 10:00 to 18:00. 

Do you want to learn more about privacy and data protection — and test your knowledge?
Come visit us for fun activities and quizzes designed just for you!

Further information about Europe Day 2025
 

EDPB

EDPB annual report 2024: protecting personal data in a changing landscape

7 maanden 2 weken ago

Brussels, 23 April - The European Data Protection Board (EDPB) has published its 2024 Annual Report. The report provides an overview of the EDPB work carried out in 2024 and reflects on important milestones, such as the adoption of the 2024-2027 strategy, the increase in Art. 64(2) consistency opinions and the continued efforts to provide guidance and legal advice.

EDPB Chair Anu Talus said: “As I look back on the work carried out over the past year, I am proud to present our achievements. In 2024, we reaffirmed our commitment to safeguarding individuals’ fundamental rights to privacy and data protection in a fast-changing digital landscape.

We adopted a new strategy and continued to play a central role in providing guidance and ensuring a consistent application of the General Data Protection Regulation (GDPR) across Europe. To support understanding and implementation of data protection rights and duties, we expanded our outreach activities by devoting special attention to businesses and non-expert individuals. In addition, we acquired new roles in the framework of the new digital legislations.”

A new EDPB strategy

The EDPB strategy 2024-2027 outlines key priorities and actions to strengthen and modernise data protection across Europe, ensure consistent enforcement of the GDPR, and address emerging challenges, including cross-regulatory cooperation. The strategy also helps strengthen the EDPB’s global presence by engaging with global partners and representing the EU data protection model in key international fora.

 

EDPB’s central role in providing guidance and legal advice

The number of consistency opinions adopted under Art. 64(2) GDPR significantly increased. In 2024, the Board adopted eight Art. 64 (2) GDPR opinions, including on ‘Consent or Pay’ models used by large online platforms, the use of facial recognition at airports, and the use of personal data to train AI models. These opinions address a matter of general application and ensure consistency prior to enforcement.

The EDPB actively participated in legislative discussions by issuing statements highlighting data protection considerations and impacts. For example, the Board adopted statements on the draft procedural regulation for GDPR enforcement, and on the DPAs role in the AI Act framework.

The EDPB has also expanded its general guidance to help organisations achieve and maintain GDPR compliance. To this end, the Board adopted four new guidelines in 2024, such as the guidelines on legitimate interest and on data transfers to third country authorities.

 

Proactive engagement with stakeholders

In 2024, the EDPB continued to engage with stakeholders to foster open dialogue and mutual understanding between regulators, industry representatives, civil society organisations, and academic institutions.  To collect relevant insights from organisations that have expertise on data protection-related topics, the Board launched public consultations on its adopted guidelines and organised two stakeholder events, related to the upcoming guidelines on “Consent or Pay” models and to the preparation of the Opinion on AI models.

 

Contributing to cross-regulatory cooperation

New digital legislations, including the Digital Markets Act (DMA), the Digital Services Act (DSA), the AI Act, the Data Governance Act (DGA) and the Data Act, build on GDPR. To ensure consistency of application between the GDPR and these acts, the EDPB actively contributed to cross-regulatory cooperation by engaging with European and international partners, including the EU AI Office and the high-level group on the DMA.

 

Making the GDPR understandable and practical for all

Finally, the EDPB continued its efforts to provide information on the GDPR to a broader and non-expert audience by presenting it in a clear and non-technical language. To this end, the EDPB made the Data Protection Guide for Small Business available in 18 languages. In addition, the Board has launched a series of summaries of EDPB guidelines to help non-expert individuals and organisations identify in an easier way the most important points to consider. 
 

EDPB Annual Report 2024

23 April 2025 Publication Type: English Download file 1 Bulgarian Czech Danish German Greek English Spanish Estonian Finnish French Croatian Hungarian Italian Lithuanian Latvian Dutch Polish Portuguese Romanian Slovak Slovenian Swedish Download file 2 EDPB annual report 2024: protecting personal data in a changing landscape
EDPB

EDPB adopts guidelines on processing personal data through blockchains and is ready to cooperate with AI office on guidelines on AI Act and EU data protection law

7 maanden 3 weken ago

Brussels, 14 April - During its April 2025 plenary, the European Data Protection Board (EDPB) has adopted guidelines on processing of personal data through blockchain technologies.  A blockchain is a distributed digital ledger system that can confirm transactions  and  establish  who  owned  a  digital  asset  (such  as cryptocurrency)  at  a  given  time. Blockchains can also support the secure handling and transfer of data, ensuring its integrity and traceability.

As the use of blockchain technologies is expanding, the Board considers it important to help organisations using these technologies to comply with the GDPR. 
In its guidelines, the EDPB explains how blockchains work, assessing the different possible architectures and their implications for the processing of personal data.

The guidelines highlight the importance of implementing technical and organisational measures at the earliest stages of the design of the processing. The EDPB also clarifies that the roles and responsibilities of the different actors in a blockchain-related processing of personal data should be assessed during the design of the processing.
In addition, organisations should carry out a Data Protection Impact Assessment (DPIA) before processing personal data through blockchain technologies, where the processing is likely to result in a high risk to the rights and freedoms of individuals.

According to the Board, organisations should also ensure the highest protection of individuals’ personal data during the processing so that they are not made accessible to an indefinite number of persons by default.

The guidelines provide examples of different techniques for data minimisation, as well as for handling and storing personal data. As a general rule, storing personal data in a blockchain should be avoided if this conflicts with data protection principles.

Finally, the Board highlights the importance of the rights of individuals especially regarding transparency, rectification and erasure of personal data. 

The guidelines will be subject to public consultation until 9 June 2025, providing stakeholders with the opportunity to comment.

During its latest plenary, the EDPB also decided to closely cooperate with the AI Office in relation to the drafting of the guidelines on the interplay between the AI Act and EU data protection legislation.
 

EDPB