Refine By
Clear all filter
About 91497 results for "*"
NEWS
The European Data Protection Board (EDPB) has adopted its 2024–27 strategy during its April 2024 plenary session, which sets out its priorities for the next four years. The EDPB’s priorities are sectioned into four pillars including enhancing harmonisation and promoting compliance, reinforcing a common enforcement culture and effective cooperation, safeguarding data protection in the developing digital and cross-regulatory landscape, and contributing to the global dialogue on data protection. In addition, regarding the EU-US Data Privacy Framework (DPF), the EDPB adopted Rules of Procedure, a public information note and template complaint forms to facilitate the implementation of the redress mechanisms under the DPF. The EDPB documents relate to two DPF redress mechanisms created to handle complaints by EU individuals. The redress mechanisms deal with only complaints relating to their respective competence such as, national security or commercial purposes and only for data transmitted after 10 July 2023.
NEWS
The European Data Protection Board (EDPB) has adopted a statement on the Data Protection Authorities’ (DPAs) role in the EU AI Act framework, on 17 July 2024. According to the EU AI Act, Members States shall appoint Market Surveillance Authorities (MSAs) at national level before 2 August 2025, to supervise the application and implementation of the EU AI Act.
NEWS
The European Data Protection Board (EDPB) has adopted a template for Data Protection Impact Assessments (DPIAs) as part of its efforts to make compliance with Regulation (EU) 2016/679 (General Data Protection Regulation (GDPR)) easier and enhance consistency across Europe. The template is intended to support organisations in structuring, harmonising and evidencing their DPIA reporting processes, and is accompanied by an explainer document aimed at aiding its practical use. The template is open for public consultation until 9 June 2026.
NEWS
The European Data Protection Board (EDPB) has clarified the notion of a controller’s ‘main establishment’ in the EU, in particular for cases where decisions regarding the processing are taken outside of it. This clarification took place via the adoption of an ‘Opinion on the notion of main establishment and on the criteria for the application of the One-Stop-Shop mechanism’. In this Opinion, the EDPB considers that a controller’s ‘place of central administration’ in the EU can be considered as a main establishment under Article 4(16)(a) of the EU General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR), only if it takes the decisions on the purposes and means of the processing of personal data and if it has the power to have such decisions implemented. The EDPB further explains that the One-Stop-Shop mechanism can only apply if there is evidence that one of the establishments of the controller in the EU takes decisions on the purposes and means for the relevant processing operations and has the power to have these decisions implemented. This means that, when the decisions on the purposes and means of the processing are taken outside of the EU, there should be no main establishment of the controller in the EU, and therefore the One-Stop-Shop should not apply.
NEWS
The European Data Protection Board (EDPB) has adopted final guidelines clarifying Article 48 of Regulation (EU) 2016/679 (General Data Protection Regulation (GDPR)) regarding data transfers to third country authorities. The guidelines establish that judgements from non-European authorities cannot automatically be enforced in Europe, requiring either an international agreement providing legal basis and transfer grounds, or consideration of alternative legal bases in exceptional circumstances. The updated guidelines include new clarifications on processor obligations and parent company-subsidiary data transfer scenarios. The EDPB has also launched two Support Pool of Experts training initiatives addressing artificial intelligence compliance and data protection requirements.
NEWS
The European Data Protection Board (EDPB) has adopted final guidelines clarifying the application of Article 48 of Regulation (EU) 2016/679 (General Data Protection Regulation (GDPR)) regarding data transfers to non-European authorities. The guidelines establish that third country authority decisions require international agreements for automatic recognition in Europe. Where no such agreements exist, alternative legal bases may be considered in exceptional circumstances. The guidelines include new provisions addressing processor-specific scenarios and parent-subsidiary data transfer requests where the parent company is located in a third country.
NEWS
The European Data Protection Board (EDPB) has adopted guidelines on anonymisation and on web scraping in the context of generative artificial intelligence (AI). The anonymisation guidelines, which draw on CJEU ruling C‑413/23 P, introduce a three-criteria test—no record isolation, no linkage and no inference. They offer two assessment approaches: a contextual approach and a simplified approach. The web scraping guidelines address EU General Data Protection Regulation compliance in relation to legal bases, the purpose limitation and transparency principles and the handling of special category data. Specifically, the guidelines clarify that a lawful basis under Article 6 and an exception under Article 9(2) are required when processing special category data. These guidelines, together with the final version of its blockchain guidelines, are open for public consultation until 30 October 2026.
NEWS
The European Data Protection Board (EDPB) has adopted an opinion on the European Commission’s draft adequacy decision on the level of protection of personal data in Brazil. The opinion, requested by the Commission, assesses whether Brazil’s data protection framework and its rules on government access to personal data transferred from the EU provide safeguards equivalent to those under EU law. The EDPB notes the strong alignment between Brazil’s framework and EU legislation, as well as case law of the Court of Justice of the European Union. However, it invites the Commission to provide further clarifications and monitor certain areas, including Data Protection Impact Assessments, limitations on transparency related to commercial and industrial secrecy and rules on onward transfers. The EDPB also requests the Commission to clarify the scope of applicability of Brazilian data protection law, the investigatory and corrective powers of the Brazilian Data Protection Authority in relation to law enforcement authorities and Brazil’s concept of national security.
NEWS
The European Data Protection Board (EDPB) has adopted an opinion on certain obligations following from the reliance on processors and sub-processors, in light of a request by the Danish Data Protection Authority under Article 64(2) of the EU General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR). Opinion 22/2024 addresses eight questions on the interpretation of certain duties of controllers where they rely on processors and sub-processors, and also considers the wording of controller-processor contracts.
NEWS
The European Data Protection Board (EDPB) has adopted an opinion on the European Commission's draft adequacy decision for the European Patent Organisation (EPO), marking the first such decision for an international organisation under Regulation (EU) 2016/679 (General Data Protection Regulation) Article 45. The EDPB notes that EPO's data protection framework aligns with EU standards but calls for clarification on oversight mechanisms, particularly regarding the Data Protection Board's binding powers in complaints handling. The opinion also addresses EPO's handling of government access requests. Additionally, the EDPB approved a 6-month extension of UK adequacy decisions until 27 December 2025, allowing time to evaluate pending UK data protection reforms.
NEWS
The European Data Protection Board (EDPB) has adopted Opinions 26/2025 and 27/2025 on the European Commission’s draft decisions to extend the validity of the UK adequacy decisions under the General Data Protection Regulation (Regulation (EU) 2016/679) and the Law Enforcement Directive (Directive (EU) 2016/680) until December 2031. The Board has welcomed the continued alignment between UK and EU data protection frameworks but has urged the Commission to closely monitor UK developments that may affect the level of protection, including recent legislative changes to the Data (Use and Access) Act 2025 and the structure of the Information Commissioner’s Office (ICO).
NEWS
The European Data Protection Board (EDPB) has adopted recommendations on the 2027 World Anti-Doping Agency (WADA) World Anti-Doping Code. The EDPB's recommendations aim to assess the compatibility of the WADA Code and International Standards with Regulation (EU) 2016/679 (EU General Data Protection Regulation (EU GDPR)). Key focus areas include ensuring appropriate legal bases for data processing, purpose limitation, and effective communication of data rights to individuals. The EDPB emphasises that EU Member States must ensure their national anti-doping measures align with the EU GDPR, and that National Anti-Doping Organisations are responsible for EU GDPR-compliant data processing as controllers.