Overslaan en naar de inhoud gaan
ShareEmailLinkedInXWhatappsFacebook
feedback
Share

Italian SA fines a company for post-sick leave questionnaires

4 maanden ago

Background information

  • Date of final decision: 10 July 2025
  • National case
  • Controller: Magna PT S.p.A.
    Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 6 (Lawfulness of processing),  Article 9 (Processing of special categories of personal data),  Article 13 (Information to be provided where personal data are collected from the data subject)
  • Decision: Administrative fine, Definitive ban on data processing
  • Key words: Administrative fine, Principles relating to processing of personal data, Transparency,
    Retention time, Lawfulness of processing, Employment

Summary of the Decision

Origin of the case  

A trade union report highlighted a widespread practice within an automotive company: after an absence due to illness, accident or hospitalisation, workers were interviewed and asked to complete a questionnaire. The document, completed by a direct supervisor, was then sent to the Human Resources Department, which, together with the supervisor and/or the competent doctor, assessed, on the basis of the company's representations, any initiatives to protect the health of workers, such as modifying the workstation or intervening in working relationships.


Key Findings 

During the investigation, the Italian Supervisory Authority (SA) found several infringements of the EU Regulation (GDPR), including the lack of clear and transparent information for employees and the lack of a legal basis for data processing, including health data. The Italian SA also found that workers' data were being stored in an irrelevant (absences from work) and disproportionate (up to ten years) manner, and that the data processing was not relevant for assessing the professional skills of the employees.

Decision

The Italian SA imposed a definitive ban on data processing and ordered the company to delete any data already collected and stored. The Italian SA also issued an administrative fine of 50 000 Euro.

For further information: Lavoro, il Garante privacy sanziona un’azienda per questionari post-malattia 
 

EDPB

The Italian Supervisory Authority fined a company 120 000 EUR for tracking five employees who drove company cars

4 maanden ago

Background information

  • Date of final decision: 27 November 2025
  • National case
  • Controller: Pioneer Hi-Bred Italia Sementi s.r.l.
    Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 6 (Lawfulness of processing),  Article 13 (Information to be provided where personal data are collected from the data subject),  Article 28 (Processor), Article 88
  • Decision: Administrative fine, Compliance order, Erasure order 
  • Key words:  Administrative fine, Principles relating to processing of personal data, Lawfulness of processing, Transparency,  Definition of controller, Employment

Summary of the Decision

Origin of the case  

Following a complaint, the Italian Supervisory Authority (SA), became aware that a company had installed a satellite tracking device on company vehicles assigned to its employees, which was able to detect their behavior (times, mileage, fuel consumption, and driving style), both during work and private trips. The data collected were used to assign a rating score and take any corrective action. Given the sensitivity of the matter raised, the Italian SA ordered an on-site inspection.

Key Findings

Inspections and subsequent checks revealed that the satellite device, installed at the request of the Swiss parent company, allowed for tracking of workers' activities without the safeguards provided by the Italian workers Charter (Regulations on the protection of the freedom and dignity of workers). Furthermore, the information provided to workers covered all the group's affiliated companies, including those based outside the EU, without clearly indicating the purposes of the processing, legal bases, or entities qualifying as data controllers, processors, and recipients.

The investigations also revealed that access to the information collected via the devices installed in company cars was also granted to staff from other companies in the group, without the appropriate authorization.

Decision

The Italian SA issued a fine of 120 000 EUR to the company as data processor. 
In determining the amount of the fine, the Italian SA took into account both the limited number of employees involved and the immediate suspension of the unlawful data processing, implemented by the company immediately after the complaint was filed. The Italian SA also ordered the deletion of data relating to employees' journeys, collected and used to assign driving behavior.

For further information: Garante privacy: no al controllo dello stile di guida dei lavoratori. Sanzione di 120mila euro a società che monitorava 5 dipendenti con auto aziendale 
 

EDPB

Imposition of fine on a telecommunications company for violations of data subject’s rights

4 maanden ago

Background information

  • Date of final decision: 11 February 2026
  • National case
  • Controller: Vodafone-Panafon S.A Hellenic Telecommunications Company
  • Legal Reference: Article 12: Transparent information, communication and modalities for the exercise of the rights of the data subject, Article 12.2: Facilitation of the exercise of the rights of the data subject, Article 12.3: Time limit for responding to a request, Article 12.4: Information to be provided where no action is taken on the request, Article 15: Right of access by the data subject, Article 18: Right to restriction of processing
  • Decision: Infringement of the GDPR; fine imposed; order to comply 
    Key words: Transparent information, communication and exercise of the rights of the data subject 

Summary of the Decision

Origin of the case

A complaint was submitted to the Greek SA against Vodafone-Panafon S.A Hellenic Telecommunications Company for

  1. violation of the right of access to recorded calls,
  2. violation of the right to restriction of processing,
  3. obstacles placed by the respondent during the exercise of the aforementioned right of access, and
  4. contradictory information regarding the procedure for satisfying the exercised right of access.

Key Findings

The Authority found that the respondent company infringed the provisions of Articles 12(1), (2), (3), (4), 15 and 18 of the GDPR pursuant to Articles 58(2)(i) and 83(5)(b) of the GDPR. 

Decision

The Greek SA imposed on the telecommunications company, an administrative fine of EUR 30.000 for violating Articles 12(1), (2), (3), (4), 15 and 18 of the GDPR. 
It also ordered, pursuant to Article 15(4)(b) of national Law 4624/2019, the respondent company to adopt appropriate technical and organisational measures to ensure the proper and timely examination of data subjects’ rights, including more effective training of its representatives, and to provide the Authority with relevant documentation within six months.


For further information: national decision in Greek Επιβολή προστίμου σε πάροχο υπηρεσιών τηλεπικοινωνίας  

EDPB

The Italian SA fined Poste Vita for data breach

4 maanden ago

Background information

  • Date of final decision: 10 July 2025
  • National case
  • Controller: Poste Vita s.p.a.
    Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 33 (Notification of a personal data breach to the supervisory authority)
  • Decision: Administrative fine
  • Key words: Administrative fine, Clients, Data security, Insurance, Personal data breach

Summary of the Decision

Origin of the case  

The investigation was initiated following a complaint from an insurance company (Poste Vita) customer who complained about the unlawful disclosure of personal data to an unauthorised third party who had then used it in legal proceedings. The data related to three life insurance policies held by the complainant.

Key Findings 

During the investigation, the Italian Supervisory Authority (SA) verified that the data breach had occurred due to a series of errors committed by the company's operators. They had responded to requests for information regarding the data subject's policies without first verifying that the email address from which the requests were sent matched the contact details provided by the customer. The requests came from two email addresses which, although they had the name and surname of the data subject, who had never provided any email address to the company, were in fact linked to third parties.

Decision

Noting that in the meantime the insurance company had implemented corporate procedures aimed at rigorously verifying the identity of the person concerned, the Italian SA imposed a fine of 80,000 EUR, without taking further measures.

For further information: Data breach, il Garante sanziona Poste Vita per 80mila euro

EDPB

The Italian SA imposed a 40 000 EUR fine on a company for violating the confidentiality of a employee's email account after the end of his employment

4 maanden ago

Background information

  • Date of final decision: 18 December 2025
  • National case
  • Controller: LTL S.p.A.
    Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject), Article 15 (Right to access by the data subject)
  • Decision:  Administrative fine,  Compliance order,  Erasure order or Add here your free text for the decision
  • Key words: Administrative fine, Principles relating to processing of personal data, Transparency,
    Right of access,  Employment, Data subject rights

Summary of the Decision

Origin of the case  

In a complaint submitted to the Italian Supervisory Authority (SA), an individual complained that, after receiving a disciplinary letter followed by dismissal, the company had denied him access to his company' email account, which remained active. Exercising his rights, the data subject asked the company to disable the email account, forward any messages received in the meantime to his personal email address, and activate an automatic reply informing any senders of his new email address. However, this request remained unfulfilled, even though it was formulated in compliance with the GDPR.


Key Findings 

During the investigation, the Italian SA found that the company not only continued to receive emails addressed to the employee, but also forwarded them to another company email account. This unlawful practice had been going on for about two months, exceeding the 30-day limit set by the company's internal rules.

Decision

The Italian SA fined the company 40 000 EUR.
In determining the amount of the fine, the SA took into account the type and duration of the violations, the failure to respond to the employee's request to exercise his rights, and the absence of previous violations of data protection regulations by the company.
The Authority therefore ordered the company to allow the employee access to his company email account and ordered its subsequent deletion, without prejudice to the retention of what was necessary for the protection of company's rights in court.

For further information: Garante: l’accesso alla email del lavoratore licenziato vìola la privacy
 

EDPB

EDPB and EDPS support strengthening EU’s cybersecurity and easing compliance while protecting individuals’ personal data

4 maanden 2 weken ago

Brussels, 19 March 2026 – The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have adopted a Joint Opinion on the European Commission’s proposal for a Cybersecurity Act 2 (CSA2) and the proposal on amendments to the Network and Information Security 2 (NIS2) Directive.

On 20 January 2026, the Commission published a cybersecurity package proposal to further strengthen cybersecurity in Europe while making compliance with cybersecurity laws easier for organisations. In their joint opinion, issued at the request of the Commission*, the EDPB and the EDPS address the proposed revision of the CSA and the targeted amendments to the NIS2 Directive.

“The relationship between data protection and cybersecurity is reciprocal and deeply interconnected. While cybersecurity supports the protection of personal data by limiting the risks of unwanted access, modification or unavailability of data, it is crucial to ensure that security controls are implemented in a way that does not undermine individuals’ fundamental rights and freedoms.”

EDPB Chair Anu Talus

“While maximizing the effectiveness of cybersecurity measures is vital, we must ensure that the processing of personal data remains limited to what is strictly necessary. We welcome the reinforced role of ENISA to promote digital resilience; our hope is that this new mandate fosters the synergies needed to create a robust ecosystem where security and privacy go hand in hand.”

European Data Protection Supervisor, Wojciech Wiewiórowski

Regarding the Proposal for the CSA2, the EDPB and the EDPS support the general objective to strengthen the role of the European Union Agency for Cybersecurity (ENISA) and to facilitate uptake of cybersecurity certification, as well as the objective to further address the various risks to ICT supply chains, including non-technical ones.

The proposal to provide further clarification on the way ENISA gives support to different stakeholders is well received. The EDPB and the EDPS specifically welcome that ENISA’s advice would be issued upon a prior request from the EDPB, thus ensuring a clear coordination and a clear division of responsibilities. They also suggest adding the EDPS as a possible requestor of advice from ENISA.

In the joint opinion, the EDPB and the EDPS recall that in case the Management Board of ENISA decides to adopt additional measures necessary for the application of the EU Data Protection Regulation, such decisions should be limited to very technical (practical) details related to the processing of personal data. The Proposal should also provide for a prior consultation with the EDPS before adoption of such rules.

The joint opinion welcomes the synergies that might arise from the cooperation between ENISA and other EU institutions and bodies, and also recommends adding an explicit reference to the EDPS as an EU body with which ENISA would cooperate.

While the objective of facilitating uptake of cybersecurity certification is welcome, the scope of the European Cybersecurity Certification Framework and its relationship with GDPR certification should be further clarified. To ensure consistency, ENISA should consult with the EDPB before adopting a certification scheme relating to the security of processing of personal data. Furthermore, certification schemes for products, services and processes that are likely to be used in data processing operations, should take into account security controls that can help to demonstrate the fulfilment of GDPR requirements, to the extent possible.

The EDPB and the EDPS recommend that the European Cybersecurity Skills Framework is not only limited to cybersecurity professionals, but also includes a general workforce profile.

In line with the recent EDPB-EDPS joint opinion on the Digital Omnibus Regulation Proposal, the EDPB and EDPS express their support for the establishment of a single-entry point for the notification of personal data breaches, as it would reduce the administrative burden for notifying organisations without affecting the level of protection for individuals.

Regarding the proposed amendments to the NIS2 Directive, the EDPB and the EDPS welcome the designation of European Digital Identity Wallets and European Business Wallets providers as 'essential entities'.

 

Note to editors:
* On 21 January 2026, the Commission formally consulted the EDPB and the EDPS and requested a joint opinion on the European Commission’s proposal for a CSA2 and the proposal on amendments to the NIS2 Directive in accordance with Art. 42(2) of Regulation (EU) 2018/1725.

EDPB

Europe Day 2026: let’s celebrate together

5 maanden ago

Brussels, 5 May – On 9 May each year, Europeans celebrate the anniversary of the Schuman Declaration, the key moment which led to the creation of the EU as we know it today. To mark this special occasion, the European institutions will open their doors to the public on 9 May 2026, and we would be delighted to welcome you.

Come and visit us

We invite you to our interactive booth to discover and enjoy the activities we have prepared together with the European Data Protection Supervisor (EDPS).

•    When:  9 May 2026, from 10:00 to 18:00 (CET)
•    Where: European Parliament (Rue Wiertz 60, Brussels)

You will find us on the ground floor, in the cybersecurity area.


Test your skills and discover more

During your visit, you will get the chance to enjoy fun activities tailored just for you. This includes a:

•    EU Survey Quiz to test your knowledge of EU institutions 
•    Roulette that will test your skills with fun data protection-related challenges

This year, we are also bringing along a new friend: our mascot “Eddy the beaver”. Do not hesitate to come and greet him and make sure to bring along the little ones.

We are looking forward to meeting you! 
 

EDPB

Marking 10 years of the GDPR: the evolution of the European data protection landscape

5 maanden 1 week ago

Brussels, 27 April – Today marks the 10th anniversary of the GDPR’s adoption, the first comprehensive data protection framework spanning an entire continent, establishing clear rights for individuals and obligations for organisations across Europe.

The moment that led to the creation of the EDPB

The GDPR led to the establishment of the European Data Protection Board (EDPB) on 25 May 2018, replacing the Article 29 Working Party that was previously in charge of dealing with issues relating to the protection of personal data.

The GDPR gave the Data Protection Authorities (DPAs) stronger enforcement powers and expanded the scope of their work from focusing mainly on national compliance complaints to routinely dealing with cross-border cases.

In the past 10 years, the 31 European DPAs comprising the EDPB have worked together to ensure the consistent enforcement of the GDPR and a harmonised data protection approach across Europe.  

A key role in an evolving digital landscape

Today, the GDPR is part of a broader and evolving European digital framework, alongside other digital laws such as the Digital Services Act, the Digital Markets Act, and the AI Act. In a world shaped by artificial intelligence, platform economies, and increasing data-driven innovation, the GDPR ensures that technological progress goes hand in hand with the protection of individuals’ fundamental rights.

An inspiration for the rest of the world

The impact of the GDPR has extended far beyond Europe’s borders, inspiring similar frameworks across the globe and contributing to a growing international recognition of privacy as a fundamental right.  

How the GDPR has shaped the data protection landscape: insights from Data Protection Authorities

Have you ever wondered what the data protection landscape looked like before the GDPR and how DPAs prepared for its entry into force? How has life for Europeans changed since its adoption? Watch the video for insights and testimonies from Data Protection Authorities which contributed to the shaping of the data protection landscape in Europe.
 

Sorry, your browser doesn't support embedded videos.

EDPB

Stakeholder event on competition and data protection

5 maanden 1 week ago

Brussels, 23 April – The EDPB is organising a remote stakeholder event in the context of its joint work with the European Commission on upcoming guidelines on the interplay between competition and data protection. 

The event is an opportunity for stakeholders to inform and support the ongoing work on this topic. It also reflects the EDPB’s commitment to stakeholder engagement and cross-regulatory cooperation, as outlined in the Helsinki statement and in the EDPB Strategy 2024-2027.

Join the event to have your say

This is your chance to contribute directly to a fast-evolving and highly relevant policy area. The EDPB will launch a call for expressions of interest to participate in the stakeholder event. Further details on the date and format will be published on the EDPB website.

EDPB

EDPB brings clarity to data processing for scientific research, speeds up the finalisation of the anonymisation guidelines and approves first European data protection seal as a tool for transfers

5 maanden 2 weken ago

Brussels, 16 April – During its latest plenary, the EDPB has adopted Guidelines on processing of personal data for scientific research purposes. In addition, the Board has created a team to speed up the finalisation of the guidelines on anonymisation. The EDPB has also adopted two opinions on the two sets of the Europrivacy certification criteria for approval as European Data Protection Seals, one of which to be used as a tool for transfers.

Many areas of scientific research rely on the processing of individuals’ personal data, and this has driven significant scientific breakthroughs that benefit society. The rise of new technologies, such as artificial intelligence, also contributes to scientific progress by enabling researchers to use and analyse data in innovative ways.

The main objective of the EDPB guidelines on scientific research is to provide more clarity for researchers and make GDPR compliance easier, while ensuring the protection of individuals’ fundamental rights.

“Scientific research can drive societal progress and improve our daily lives. 
Our guidelines facilitate innovative research by helping researchers to navigate the GDPR.

The EDPB is committed to supporting the scientific community and unlocking the full potential of scientific research in the EU while upholding data protection rights."

EDPB Chair, Anu Talus

In its guidelines, the Board provides clarifications on the concept of ‘scientific research’. To determine if the processing takes place for scientific research purposes in the meaning of the GDPR, the Board provides six key-indicative factors that should be considered, in addition to the nature, scope, context and purposes of processing. These are: 1) methodical and systematic approach, 2) adherence to ethical standard, 3) verifiability and transparency, 4) autonomy and independence, 5) objectives of the research, and 6) potential to contribute to existing scientific knowledge or apply existing knowledge in novel ways. If the research activities meet these six factors, they can be presumed to constitute scientific research. Otherwise, the controller should justify and be able to demonstrate why the activities should be considered scientific research, within the meaning of the GDPR.

Further processing for scientific research purposes is presumed to be compatible with the initial purpose for collecting individuals’ personal data. Therefore, controllers are not obliged to do the purpose compatibility test under the GDPR to determine if the new processing is compatible with the original purpose of collection. However, controllers must still make sure that the legal basis of the initial processing is also suitable for the further processing of personal data for scientific research purposes.

Controllers can rely on “broad consent” where the purposes of research are not fully known at the time of collecting the personal data. In this case, researchers should respect ethical standards for scientific research and put additional safeguards in place to compensate for the lack of purpose specification. Controllers can also ask individuals to consent to different individual research projects separately, as soon as the purposes of those projects become known (dynamic consent). A combination of both broad and dynamic consent is also possible.

In addition, the EDPB clarifies rights of individuals when their personal data are processed for scientific purposes. This includes the rights to erasure and object for which limitations may apply when personal data are processed for scientific research purposes. The Board provides examples to explain when the right to erasure can be considered likely to render impossible or seriously impair the objective of conducting scientific research. The EDPB also explains when controllers may reject an individuals’ objection to the processing of their personal data for scientific research purposes. This can be the case when processing is necessary for the performance of a task carried out for reasons of public interest.

The Board recalls that when several entities are involved in the processing of personal data for scientific research purposes, it is necessary to assess and document how responsibilities are allocated among the entities. In this regard, the Guidelines provide useful examples to clarify in which situations entities can qualify as controller, joint controllers or processor.

Finally, the Board explains how controllers can assess the appropriate technical and organisational measures, such as anonymisation or pseudonymisation, when processing personal data for scientific research purposes. The EDPB provides examples of other safeguards that could be implemented depending on the risks posed by the research activities carried out. These include independent or ethical oversight, secure processing environments, privacy enhancing technologies, protective measures for publication of research results, confidentiality arrangements, and conditions for further use.

The guidelines will be subject to public consultation until 25 June, providing stakeholders with the opportunity to comment and provide feedback.

A “sprint team” to finalise the work on anonymisation

To speed up the finalisation of the upcoming guidelines on anonymisation, the Board created a dedicated "sprint team" that will complete the work by the summer.

Europrivacy opinions

The EDPB adopted an Opinion approving the updated set of Europrivacy certification criteria as European Data Protection Seal* pursuant to Art. 42 (5) GDPR. The Board had first approved the Europrivacy certification criteria on 10 October 2022 as the first European Data Protection Seal through the EDPB Opinion 28/2022. The scope of the Europrivacy certification scheme has been extended to include controllers and processors established outside Europe who are subject to Art. 3(2) GDPR, either because they provide goods or services to individuals in Europe or because they monitor their behaviour.

In addition, for the first time, the Board adopted an Opinion recognising the Europrivacy certification criteria as European Data Protection Seal to be used as a tool for transfers in accordance with Art. 42 and 46 GDPR.  Data importers outside Europe who are not subject to the GDPR can now apply to the Europrivacy certification scheme for the transfers of data they receive. This certification will facilitate the fulfillment of the obligation of the controllers and processors in Europe to demonstrate that they provide appropriate safeguards for personal data transfers to third countries or international organisations.

These approvals bring further light on the GDPR certification mechanisms, confirming their key role as GDPR compliance tool.

 

Note to editors

*The European Data Protection Seal is a GDPR-certification mechanism recognised all over Europe. The Seal must satisfy specific criteria approved by the EDPB and must be granted by a certification body accredited under Art. 43 GDPR to prove compliance with GDPR standards. 
 

EDPB

Enhancing compliance and consistency: EDPB adopts DPIA template

5 maanden 3 weken ago

Brussels, 14 April - In line with the EDPB’s Helsinki Statement to make GDPR compliance easier and strengthen consistency across Europe, the EDPB has adopted a template for Data Protection Impact Assessments (DPIA). The template will help organisations structure, harmonise and evidence their DPIA reporting processes. The template is complemented by an explainer document providing concise explanations for completing this template effectively, by breaking down key concepts in a simple language and addressing possible questions and knowledge gaps controllers might have.

A DPIA is a process required in situations where the processing is likely to result in a high risk, to describe how personal data will be processed, assess whether the processing is necessary and appropriate, and identify and reduce risks to individuals’ rights and freedoms. The EDPB template has been conceived to support organisations step by step in this process while filling the template.

Controllers can conduct their risk analysis and management processes as they prefer, using the DPIA methodology of their choice. While it is not mandatory for organisations to use the EDPB template, it allows them to benefit from predefined fields that prompt complete and structured responses. This will help ensure that all necessary information is captured accurately while minimising the risk of errors and saving time.

The template will be subject to public consultation until 9 June, providing stakeholders with the opportunity to comment and provide feedback. Following the public consultation, all Data Protection Authorities will initiate the necessary steps to adopt this template either as their sole standard or as a ‘meta-template’ to which national-specific templates will align. In the meantime, organisations are encouraged to use this template and to provide feedback in the context of the public consultation.

EDPB

EDPB annual report 2025: supporting stakeholders through guidance and dialogue

5 maanden 3 weken ago

Brussels, 09 April - The European Data Protection Board (EDPB) has published its 2025 Annual Report. The report provides an overview of the EDPB work carried out in 2025 and reflects on important milestones, such as the adoption of the Helsinki Statement on Enhanced Clarity, Support, and Engagement.

“In 2025, we saw the data protection landscape change significantly. The rapid expansion of the EU’s digital regulatory framework has added complexity to the data protection ecosystem. To help organisations navigate this complexity and support compliance, the EDPB focused on enhancing legal certainty, making compliance more achievable in practice, and strengthening cooperation, both among Data Protection Authorities and with other regulators. 

We also prioritised meaningful dialogue with stakeholders to ensure our work reflected real-world needs.

Our achievements support economic growth while continuing to protect individuals’ fundamental rights to privacy and data protection.”

EDPB Chair, Anu Talus

 

The Helsinki’s statement initiatives leading the way

In 2025, the EDPB worked actively to address the demand for regulatory simplification to support innovation and economic growth, while ensuring the protection of individuals’ personal data. 

With this in mind, the Board adopted the Helsinki Statement on Enhanced Clarity, Support, and Engagement, which outlines new initiatives to make GDPR compliance easier, strengthen consistency, enhance the dialogue and improve transparency with stakeholders and boost cross-regulatory cooperation.  

For example, the Board launched a public consultation to ask organisations which templates would be most useful, organised several stakeholder events to consult organisations on upcoming guidelines and systematically published reports on stakeholder input. 

 

Easing compliance for organisations and providing legal advice

In the context of ongoing discussions on regulatory simplification at EU level, the EDPB actively contributed to legislative initiatives aimed at reducing administrative burden and streamlining requirements. The Board adopted a joint opinion with the European Data Protection Supervisor (EDPS) on the Commission’s Proposal for a Regulation amending certain regulations, including the GDPR. 

In addition, the Board held important discussions on this matter during plenary meetings, which subsequently informed the  EPDB/EDPS joint opinions on the Commission’s proposals on the Digital Omnibus and on the Digital Omnibus on AI adopted at the beginning of 2026.

The Board also delivered five adequacy-related opinions concerning United Kingdom, Brazil and the European Patent Organisation (EPO). 

In addition, the Board adopted Recommendations on the legal basis for requiring the creation of user accounts on e-commerce websites, and Recommendations on the 2027 WADA World Anti-Doping Code upon request from the Commission.

 

Strengthening cross-regulatory cooperation

Cross-regulatory cooperation was a key focus for the EDPB last year. The EDPB worked together with the European Commission to clarify how data protection and digital laws interact and to address legal and practical challenges in cross-sectoral cases.

In 2025, the EDPB adopted its first set of joint guidelines with the Commission on the interplay between the Digital Markets Act (DMA) and the GDPR. The Board also worked with the Commission on joint guidelines on the interplay between the AI act and EU data protection laws for adoption in 2026. 

In addition, the EDPB adopted guidelines on the interplay between the Digital Services Act (DSA) and the GDPR.

 

Placing stakeholders at the heart of the EDPB work

In 2025, a public consultation was launched on the joint guidelines with the Commission on the DMA and the GDPR. The Board has also organised public consultations on the EDPB guidelines on DSA and GDPR, blockchain technologies, pseudonymisation and on the recommendations on the legal basis for requiring the creation of user accounts on e-commerce websites.

In addition, in line with the Helsinki statement’s objectives to make GDPR compliance easier, the EDPB organised a public consultation to understand which templates organisations consider would be most useful for them (e.g. privacy notice template, record of processing activities template, etc.).

In December 2025, a stakeholder event on anonymisation and pseudonymisation took place, which was followed by a  report on the input collected during the event. 

 

Promoting high standards of data protection worldwide

In line with its Strategy 2024-2027, the EDPB continued to engage with the international community to promote a high level of data protection and to ensure effective protection of personal data beyond EU borders. To this end, the Board participated in international fora such as the G7 Data Protection Authorities Roundtable and the Global Privacy Assembly.

In December 2025, the EDPB also held online the second meeting with Commissioners and representatives of Data Protection Authorities (DPAs) from the countries and the organisation with an EU adequacy decision.

 

Providing guidance and ensuring consistency 

In 2025, three new set of guidelines focusing on pseudonymisation, blockchains technologies and on the DSA and the GDPR, and guidelines following public consultation on data transfers to third country authorities were adopted. 

29 Art. 64(1) GDPR opinions were adopted, reflecting the Board’s continued commitment to promoting harmonisation.

 

Supporting consistent and effective enforcement 

Strengthening cooperation among DPAs was another key priority in 2025. This took place through multiple instruments aimed at facilitating joint actions and knowledge-sharing, including the Coordinated Enforcement Framework (CEF), the Support Pool of Experts (SPE) and dedicated taskforces. 

The Board contributed to improving cross-border cooperation, supporting DPAs in handling complex cases and ensuring alignment in enforcement practices. In 2025, 414 cross-border cases were created in the EDPB’s case register, and 1299 procedures related to the One-Stop-Shop (Art. 60 GDPR) were triggered, out of which 572 let to final decisions.

Finally, at national level DPAs issued a total of €1,15 bn worth in fines.

 

EDPB

EDPB conference on cross-regulatory cooperation: what we learned

6 maanden 1 week ago

Brussels, 23 March - On 17 March 2026, the EDPB conference “Cross-regulatory interplay and cooperation in the EU: a data protection perspective” took place in Brussels. The event showcased high-level discussions, featuring contributions from representatives of key EU institutions, European Data Protection Authorities, academia and industry. 

Key takeaways from the panel discussions

Throughout the day, three panels were held, focusing on 1) data protection and competition, 2) the Digital Markets Act (DMA) and the GDPR, and 3) the Digital Services Act (DSA) and the GDPR. 

During the first panel, speakers emphasised the critical need for cooperation between regulatory bodies in the fields of data protection and competition and shared views on what regulators in the two fields can learn from each other, especially in the aftermath of the Bundeskartellamt ruling. A speaker emphasized that regulators should align their approaches and recognize synergies between the two fields, such as protecting consumers and data subjects. Others pointed out that fixing harm to end users does not always solve competition issues, and that data protection should be considered in competition analysis only when relevant, on a case-by-case basis. Panellists also highlighted the need to cooperate not just on individual cases, but on broader concepts and legal principles.  In this context, the EDPB has recently agreed to develop joint guidelines with the European Commission to address the interplay between competition law and data protection.

The discussions in the second panel centred on the joint guidelines on the DMA and the GDPR, which were developed by the European Commission and the EDPB and recently underwent public consultation. The joint guidelines are an unprecedented work and a good example of regulatory cooperation paving the way for further examples ahead, in line with the EDPB Strategy 2024-2027 and Helsinki Statement’s objectives to strengthen cross-regulatory cooperation. A crucial goal of the guidelines is the development of a coherent and compatible interpretation of the DMA and the GDPR while respecting the regulatory competences. It was emphasised that these guidelines help break silos, strengthen consistency, and provide further clarity and legal certainty. All of this contributes to easier compliance, which is valued by stakeholders and increases trust. At the same time, certain speakers suggested improvements to the final version of the guidelines, bearing in mind the DMA should not be given primacy over the GDPR and that the measures companies have to comply with should be proportionate.  Other examples of cooperation in this domain were also mentioned, such as the participation in the High Level Group for the Digital Markets Act and specific instances of cooperation on concrete cases. 

The last panel of the day explored how the Digital Services Act (DSA) and the GDPR interact. Panellists provided the example of the protection of minors: age verification should be effective yet fully in line with data protection legislation.  They highlighted the growing need for strong coordination between the two frameworks, including the role of the European Board for Digital Services and other ways for the Commission and the EDPB to work together. A speaker also underlined the challenges and ongoing work on cross-regulatory cooperation from the perspective of a national authority. Another speaker urged regulators to work on building a fully coherent interpretation of the two frameworks and more globally of the digital legislation. Panellists also stressed that emerging technologies such as artificial intelligence are reshaping online ecosystems and, as a result, the role of the DSA and the GDPR.  The panel concluded with a clear message: online safety under the DSA and the lawful processing of personal data are two sides of the same coin, both calling for the DSA and the GDPR to be read coherently. 

Highlights from the keynote speeches

The event also featured the participation of the Executive Vice-President of the European Commission for Technological Sovereignty, Security, and Democracy Henna Virkkunen and the European Parliament’s LIBE Committee Chair Javier Zarzalejos. 

Vice President Virkkunen welcomed the EDPB’s commitment to clarity, support and engagement in its Helsinki statement, aiming to ensure the work of the EDPB is clear, practical and consistent with the policy choice to protect individuals. EVP Virkkunen underlined the Commission’s commitment to seamless cooperation between different frameworks, mentioning several examples of successful cooperation, and highlighted that the Commission and the EDPB have heard the stakeholders’ call to provide support to compliance through stronger cooperation among regulators.  

LIBE Chair Zarzalejos underlined that close cross-regulatory cooperation is essential to ensure consistency, to maximise the effectiveness of enforcement efforts and to ensure trust. Chair Zarzalejos highlighted the intersections between data protection law on the one hand, and, on the other hand, competition law, the DMA, and the DSA, emphasizing the interconnected challenges for policymakers and businesses. He ended his speech with a call in favour of EU digital sovereignty.

A forward-looking approach

EDPB Chair Anu Talus closed the conference by reiterating that the EDPB and European Data Protection Authorities are committed to continue supporting stakeholders in navigating the new cross-regulatory landscape.

The EDPB will continue working with the Commission on joint guidelines on the interplay between the AI Act and the GDPR, as well as on the final version of the joint guidelines on the interplay between the DMA and the GDPR. Moreover, work will start on the recently announced Joint Guidelines on the interplay between data protection and competition law. 

In this process, stakeholders play a key role and, as stated in the Helsinki statement, the EDPB remains fully committed to further strengthening the dialogue with them.

Cross-regulatory cooperation is the future: speakers weigh in

During the conference, we took the opportunity to ask several speakers about the importance of cross-regulatory cooperation and how they see the role of Data Protection Authorities evolving in the years to come. Watch the video to hear what they have to say.

Sorry, your browser doesn't support embedded videos.

 

 

EDPB

EDPB and EDPS support strengthening EU’s cybersecurity and easing compliance while protecting individuals’ personal data

6 maanden 2 weken ago

Brussels, 19 March 2026 – The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have adopted a Joint Opinion on the European Commission’s proposal for a Cybersecurity Act 2 (CSA2) and the proposal on amendments to the Network and Information Security 2 (NIS2) Directive.

On 20 January 2026, the Commission published a cybersecurity package proposal to further strengthen cybersecurity in Europe while making compliance with cybersecurity laws easier for organisations. In their joint opinion, issued at the request of the Commission*, the EDPB and the EDPS address the proposed revision of the CSA and the targeted amendments to the NIS2 Directive.

“The relationship between data protection and cybersecurity is reciprocal and deeply interconnected. While cybersecurity supports the protection of personal data by limiting the risks of unwanted access, modification or unavailability of data, it is crucial to ensure that security controls are implemented in a way that does not undermine individuals’ fundamental rights and freedoms.”

EDPB Chair Anu Talus

“While maximizing the effectiveness of cybersecurity measures is vital, we must ensure that the processing of personal data remains limited to what is strictly necessary. We welcome the reinforced role of ENISA to promote digital resilience; our hope is that this new mandate fosters the synergies needed to create a robust ecosystem where security and privacy go hand in hand.”

European Data Protection Supervisor, Wojciech Wiewiórowski

Regarding the Proposal for the CSA2, the EDPB and the EDPS support the general objective to strengthen the role of the European Union Agency for Cybersecurity (ENISA) and to facilitate uptake of cybersecurity certification, as well as the objective to further address the various risks to ICT supply chains, including non-technical ones.

The proposal to provide further clarification on the way ENISA gives support to different stakeholders is well received. The EDPB and the EDPS specifically welcome that ENISA’s advice would be issued upon a prior request from the EDPB, thus ensuring a clear coordination and a clear division of responsibilities. They also suggest adding the EDPS as a possible requestor of advice from ENISA.

In the joint opinion, the EDPB and the EDPS recall that in case the Management Board of ENISA decides to adopt additional measures necessary for the application of the EU Data Protection Regulation, such decisions should be limited to very technical (practical) details related to the processing of personal data. The Proposal should also provide for a prior consultation with the EDPS before adoption of such rules.

The joint opinion welcomes the synergies that might arise from the cooperation between ENISA and other EU institutions and bodies, and also recommends adding an explicit reference to the EDPS as an EU body with which ENISA would cooperate.

While the objective of facilitating uptake of cybersecurity certification is welcome, the scope of the European Cybersecurity Certification Framework and its relationship with GDPR certification should be further clarified. To ensure consistency, ENISA should consult with the EDPB before adopting a certification scheme relating to the security of processing of personal data. Furthermore, certification schemes for products, services and processes that are likely to be used in data processing operations, should take into account security controls that can help to demonstrate the fulfilment of GDPR requirements, to the extent possible.

The EDPB and the EDPS recommend that the European Cybersecurity Skills Framework is not only limited to cybersecurity professionals, but also includes a general workforce profile.

In line with the recent EDPB-EDPS joint opinion on the Digital Omnibus Regulation Proposal, the EDPB and EDPS express their support for the establishment of a single-entry point for the notification of personal data breaches, as it would reduce the administrative burden for notifying organisations without affecting the level of protection for individuals.

Regarding the proposed amendments to the NIS2 Directive, the EDPB and the EDPS welcome the designation of European Digital Identity Wallets and European Business Wallets providers as 'essential entities'.

 

Note to editors:
* On 21 January 2026, the Commission formally consulted the EDPB and the EDPS and requested a joint opinion on the European Commission’s proposal for a CSA2 and the proposal on amendments to the NIS2 Directive in accordance with Art. 42(2) of Regulation (EU) 2018/1725.

EDPB

CEF 2026: EDPB launches coordinated enforcement action on transparency and information obligations under the GDPR

6 maanden 2 weken ago

Brussels, 19 March - The EDPB has launched its Coordinated Enforcement Framework (CEF) action for 2026*. Following a year-long coordinated action on the right to erasure in 2025, the CEF's focus this year will shift to compliance with the obligations of transparency and information under the GDPR.

The GDPR ensures that individuals are informed when their data is being processed (under Art. 12, 13 and 14). This right to be informed is a core element of transparency and ensures that individuals have more control over their data.

Next steps

During 2026, 25 Data Protection Authorities (DPAs) across Europe will take part in this initiative. They will look closely to assess the compliance of controllers with their transparency obligations under the GDPR.

Participating DPAs will soon contact controllers from different sectors across Europe, either through enforcement actions or fact-finding exercises. In the latter case, they might also decide to undertake additional follow-up actions if needed.

During the second half of the year, participating DPAs will share and discuss their findings together, with a view to aggregate the results of their national actions and generate deeper insight into the topic. A consolidated report will then be drafted and submitted for adoption by the EDPB, allowing for targeted follow-ups on both national and EU levels.

Background

The CEF is a key action of the EDPB under its 2024-2027 Strategy, aimed at streamlining enforcement and cooperation among DPAs.

In 2023, the EDPB published the report on its first coordinated action on the use of cloud-based services by the public sector.

In 2024, the EDPB also published the report on the outcome of the second coordinated action on the designation and position of Data Protection Officers.

In 2025, the EDPB issued the report on its third coordination action on the implementation of the right of access.

In 2026, the EDPB has adopted a report on its Coordinated Enforcement Framework (CEF) action on the right to be forgotten (Art.17 GDPR).

 

Note to editors:
*The Board selected this topic during its October 2025 plenary.

For further information:

EDPB

EDPB and EDPS support harmonisation of clinical trials under European Biotech Act, but call for specific safeguards for sensitive health data

6 maanden 3 weken ago

Brussels, 12 March 2026 – The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have adopted a Joint Opinion on the European Commission’s Proposal for a European Biotech Act. The Proposal aims to strengthen Europe’s biotechnology and biomanufacturing sectors, particularly in the area of health, by streamlining the regulatory framework and updating the rules for clinical trials.

The EDPB and the EDPS support the Proposal’s objective of fostering the EU’s competitiveness and addressing existing fragmentation in the application of the Clinical Trials Regulation (CTR). In particular, they welcome the aim to establish a single legal basis for the processing of personal data by sponsors and investigators, which will significantly improve legal clarity across Europe.

At the same time, the EDPB and the EDPS underline that the sensitivity of health and genetic data processed in the context of clinical trials requires a high standard of protection. The Joint Opinion provides several recommendations to ensure that the proposed simplifications do not lower the level of protection for clinical trial participants.

Key recommendations include:

  • Clarifying controller roles: The Proposal should specify whether the actors involved in funding and conducting clinical trials act as sole or joint data controllers, to ensure a clear allocation of responsibilities.
  • Limiting data retention: The mandatory 25-year minimum retention period should expressly apply only to the clinical trial master file, rather than to all personal data processed during a trial.
  • Further processing for other clinical trials or for scientific research: As the Proposal aims to provide a legal basis under Union law for the further processing of trial data by the same controller, the Biotech Act should clearly define the purposes, as well as specific safeguards for such processing.
  • Coherence with the AI Act: While promoting the use of AI in biotechnology, the Biotech Act should ensure that obligations for sponsors complement the existing requirements under the AI Act to ensure a consistent regulatory environment.
  • Appropriate technical and organisational measures: The CTR should explicitly require the use of pseudonymisation whenever it is not necessary to process directly identifiable personal data.
  • Regulatory sandboxes: If needed, the Commission's implementing acts regarding sandboxes in the specific context of clinical trials should provide for the legal basis for the processing of personal data, as well as for the derogation under Art. 9(2) for the processing of sensitive data; regarding other sandboxes, the processing of personal data should always be based on a legal basis under the GDPR. 


“Europe’s ambition to lead in medical innovation must go hand in hand with trust. Our opinion makes recommendations to the co-legislators aiming to ensure that the pursuit of new treatments respects the fundamental rights of individuals. This will help build a framework that protects clinical trial participants and will ensure further legal certainty for researchers.”
EDPB Chair, Anu Talus

“A competitive biotechnology sector in Europe requires a predictable and harmonised legal environment. We welcome the Proposal’s move towards a single legal basis for clinical trials, which will facilitate GDPR compliance and strengthen consistency across the Union. However, this harmonisation must be accompanied by strong safeguards, including a clear definition of the roles and responsibilities of all actors involved to ensure trust and accountability in scientific research.”
European Data Protection Supervisor, Wojciech Wiewiórowski
 

EDPB

Stakeholder event on political advertising: agenda available now

6 maanden 4 weken ago

Brussels, 6 March - The EDPB organises a remote event to collect stakeholders’ input on its Guidelines on the processing of personal data to target or deliver political advertisements under the regulation on the transparency and targeting of political advertising, on 27 March 2026.

The agenda is available below

This will be an opportunity to inform and support the EDPB’s ongoing work on this topic as per its work programme 2024-2025 and it reflects the EDPB’s commitment to stakeholder engagement, as outlined in the recent Helsinki statement. 

Find out more: discussion paper.

EDPB

Conference on cross-regulatory cooperation in the EU (17 March) - Programme available now

7 maanden ago

The conference "Cross- regulatory interplay and cooperation in the EU: a data protection perspective” takes place on 17 March 2026 from 9.15 to 15.30. 
This event will offer a high-level overview of the EDPB’s work in the EU’s cross-regulatory landscape, focusing in particular on how regulatory frameworks interact and how cooperation between authorities is ensured.

Registration is now closed, but the event will be livestreamed on our website.

Access the EDPB conference livestream

EDPB

AI-generated imagery and protection of privacy: EDPB supports joint Global Privacy Assembly’s statement

7 maanden 1 week ago

Brussels, 23 February - EDPB Chair Anu Talus has signed a Joint Statement on AI-Generated Imagery and the Protection of Privacy on behalf of the EDPB. The statement, coordinated by the Global Privacy Assembly's (GPA) International Enforcement Cooperation Working Group (IEWG), represents the united position of 61 authorities across the world. This reflects the Board’s commitment to contributing to the global dialogue on data protection as outlined in the fourth pillar of its  work programme 2026-2027.

The statement addresses serious concerns about AI systems that generate realistic images and videos depicting identifiable individuals without their knowledge or consent. Whilst AI has the potential to bring numerous benefits for individuals and society, recent developments - particularly AI image and video generation integrated into widely accessible social media platforms - have enabled the creation of non-consensual intimate imagery, defamatory depictions, and other harmful content featuring real individuals. The co-signatories are especially concerned about potential harms to children and other vulnerable groups, such as cyber-bullying and/or exploitation.

Expectations for organisations

The co-signatories remind organisations developing and using AI content generation systems that these systems must be developed and used in compliance with applicable legal frameworks, including data protection and privacy rules.  

Although specific legal requirements vary by jurisdiction, fundamental principles should guide all organisations developing and using AI content generation systems. These principles include: 

  1. implementing robust safeguards,
  2. ensuring meaningful transparency,
  3. providing effective and accessible mechanisms to protect individuals, and
  4. addressing specific risks to children.

Joining forces to address a global risk

The harms arising from the non-consensual generation of intimate, defamatory, or otherwise harmful content depicting real individuals are significant and warrant urgent regulatory attention. The co-signatories are committed to addressing this global risk and will join efforts. To achieve this, the co-signatories aim to share information on their approaches to addressing these concerns.

Finally, the co-signatories call on organisations to engage proactively with regulators, implement robust safeguards from the outset, and ensure that technological advancements do not come at the expense of privacy, dignity, safety, and other fundamental rights - particularly for the most vulnerable members of our global society.
 

EDPB

EDPB identifies challenges hindering the full implementation of the right to erasure

7 maanden 2 weken ago

Brussels, 18 February - The European Data Protection Board (EDPB) has adopted a report on its Coordinated Enforcement Framework (CEF) action on the right to be forgotten (Art.17 GDPR).  The Board selected this topic as it is one of the most frequently exercised GDPR rights and one about which DPAs frequently receive complaints from individuals.

The main objectives of this coordinated action are to ensure that the right to erasure is effectively exercised by individuals in Europe and understand how controllers comply with this right in practice. In addition, the EDPB identified good practices and the most important related challenges, with the aim of providing further guidance on this topic. 

Throughout 2025, 32 DPAs across Europe took part in this initiative. More specifically, 9 DPAs have initiated new formal investigations or have continued ongoing ones, and 23 DPAs carried out a fact-finding exercise. A total of 764 controllers across Europe responded to the action, ranging from small and medium-sized enterprises (SMEs) to big companies active in many different industries and fields, as well as various types of public entities.

The results of these national actions have been aggregated and analysed together allowing for targeted follow-up on both national and EU level.

 

Areas of improvement and main challenges

The report lists the issues that were identified, along with a series of recommendations addressed to controllers, to help them implement the right to erasure.

Seven recurring main challenges were identified by DPAs. The results confirmed some of the findings of the 2024 coordinated action on the right of access, for example when it comes to the lack of appropriate internal procedures to handle requests, or the lack of sufficient information provided to individuals. In addition, participating DPAs reported specific findings related to the reliance by some controllers on inefficient anonymisation techniques to handle erasure requests as an alternative to deletion. DPAs also noted inconsistent practices, and the difficulties faced by controllers regarding the determination of retention periods and the deletion of personal data in the context of back-ups.

In addition, as the right to erasure is not an absolute right, some controllers face difficulties in assessing and applying the conditions for the exercise of this right, including in carrying out the different balancing tests between the right to erasure and other rights and freedoms.

 

Follow-up to help organisations comply 

Extensive guidance, documents and templates exist at national level to help controllers comply with the right of erasure and help individuals exercise this right. In line with the Helsinki Statement’s objectives of making GDPR compliance easier and ensuring consistent interpretation and enforcement across Europe, the extensive guidance and templates already available at national level will be leveraged at EDPB level where appropriate.

 

Background and next steps

The CEF is a key action of the EDPB under its 2024-2027 Strategy, aimed at streamlining enforcement and cooperation among DPAs. 

In 2023, the EDPB published the report on its first coordinated action on the use of cloud-based services by the public sector.

In 2024, the EDPB also published the report on the outcome of the second coordinated action on the designation and position of Data Protection Officers.

In 2025, the EDPB issued the report on its third coordination action on the implementation of the right of access.

The CEF 2026 action will be on the obligations of transparency and information under the GDPR.

 

For further information:

EDPB