Refine By
Clear all filter
About 91497 results for "*"
NEWS
The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have adopted a joint opinion on the European Commission's proposal for an EU Biotech Act, which seeks to strengthen the EU's biotechnology and biomanufacturing sectors by streamlining regulatory frameworks and updating the rules governing clinical trials. While supporting the proposal's aim of establishing a single legal basis for personal data processing by sponsors and investigators, the EDPB and EDPS emphasise that the sensitive nature of health and genetic data processed in clinical trials requires a high level of protection. The joint opinion makes several recommendations, including: (1) clarifying whether actors involved in clinical trials act as sole or joint data controllers; (2) limiting the mandatory 25-year minimum retention period to clinical trial master files rather than all personal data processed during a trial; (3) specifying the purposes and safeguards for any further processing of trial data; (4) ensuring coherence with obligations under the EU AI Act; (5) requiring pseudonymisation where it is not necessary to process directly identifiable personal data and (6) providing a legal basis for personal data processing in regulatory sandboxes.
NEWS
The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have adopted Joint Opinion 4/2026 assessing the European Commission’s proposals for a revised EU Cybersecurity Act and amendments to the EU NIS 2 Directive (NIS2), following a formal consultation. They supported the overall objectives of strengthening the European Union Agency for Cybersecurity’s (ENISA’s) role, reviving the European cybersecurity certification framework, simplifying compliance, and addressing  information and communication technology (ICT) supply chain risks, while underlining that cybersecurity measures must remain necessary and proportionate to avoid undue interference with privacy and data protection. They welcomed improved cooperation mechanisms and a single-entry point for incident and personal data breach reporting. They recommended safeguards where ENISA processes personal data, including clear legislative limits and prior EDPS consultation, extending the European Cybersecurity Skills Framework to the general workforce, clarifying links with EU General Data Protection Regulation certification, supporting ICT supply chain measures and the designation of digital identity and business wallet providers as essential entities, and ensuring safeguards for ransomware reporting.
NEWS
The European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) have adopted a Joint Opinion on the European Commission's Digital Omnibus on AI proposal, which seeks to simplify AI Act implementation. The data protection authorities support streamlining but express concerns that proposed changes could undermine fundamental rights protection. Key concerns include the extension of special category personal data processing (such as ethnicity or health data) for bias detection and correction to all AI system providers and deployers, which they recommend should be limited to circumscribed situations where bias risks are sufficiently serious. The EDPB and EDPS oppose the proposed deletion of registration obligations for AI systems categorised as high-risk, even when providers deem them non-high risk, stating this would significantly undermine accountability. They also express concerns about proposed postponement of core provisions for high-risk AI systems and recommend maintaining the original timeline where possible. The opinion supports EU-level AI regulatory sandboxes but calls for direct involvement of Data Protection Authorities in supervision and clarification of the AI Office's supervisory role to avoid overlap with EDPS supervision of Union institutions.
NEWS
The European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) released a Joint Opinion on 9 July 2025 regarding the European Commission's proposed GDPR amendments. The proposal would extend the record-keeping derogation under Article 30(5) to organisations with fewer than 750 employees, up from the current 250-employee threshold. The amendments also introduce formal definitions for Small and Medium-sized Enterprises (SMEs) and Small Mid-cap Companies (SMCs) in Article 4, while extending codes of conduct and certification provisions to SMCs. The regulators requested clarification on the 750-employee threshold and emphasised that public authorities should remain excluded from the derogation.
NEWS
The European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) have issued a joint letter in response to the European Commission’s 6 May 2025 correspondence on a draft proposal to amend Article 30(5), Regulation (EU) 2016/679 (General data protection regulation(GDPR)). The draft—still in its early stages and not yet formally published—suggests extending the existing record-keeping derogation to cover organisations with fewer than 500 employees (including certain SMEs, SMCs, and non-profits), tightening the risk threshold from 'likely risk' to 'likely high risk,' removing the occasional processing exception, and clarifying that processing special categories of data for employment-related legal obligations would not trigger a record-keeping duty.
NEWS
The European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) have published a joint opinion opposing key aspects of the European Commission's Digital Omnibus proposal, which aims to simplify EU digital legislation including the General Data Protection Regulation (Regulation (EU) 2016/679 (GDPR)). The regulators strongly urge co-legislators not to adopt proposed changes to the definition of personal data, stating these would significantly narrow the concept and go beyond Court of Justice of the European Union jurisprudence. They also oppose empowering the Commission to determine through implementing acts what constitutes personal data after pseudonymisation. The opinion, adopted on 10 February 2026, supports certain proposals including increased data breach notification thresholds from likely risk to high risk, extended notification deadlines from 72 to 96 hours, and new biometric authentication exceptions where verification means remain under individual control. The regulators welcome ePrivacy Directive changes addressing consent fatigue and cookie banner proliferation but raise concerns about separate regimes for personal and non-personal data. The opinion also addresses artificial intelligence provisions, automated decision-making rules, and integration of the Data Governance Act into the Data Act.
NEWS
The European Data Protection Board (EDPB) has announced that the Coordinated Supervision Committee (CSC) will supervise the EU Entry Exit System (EES), which has entered operation. The system registers non-Schengen nationals with short-stay visas or visa-exempt travellers, gradually replacing passport stamping at external Schengen borders. Implementation occurs over six months, starting with 10% of border crossings. The EES processes personal data including biometric information such as facial images and fingerprints, requiring coordinated data protection supervision at European and national levels.
NEWS
The European Data Protection Board (EDPB) and the EU Anti-Money Laundering Authority (AMLA) have announced that they will jointly develop Guidelines on partnerships for information sharing to clarify how organisations can share information to combat money laundering and terrorist financing while complying with data protection requirements. The Guidelines will explain how the information-sharing framework under Article 75 of the EU Anti-Money Laundering Regulation (AMLR) can be implemented in practice, enabling companies and professionals subject to anti-money laundering rules to share information with one another and with public authorities within the limits set out in Article 75 of the AMLR. The new information-sharing provisions will apply from 10 July 2027. The Guidelines will provide practical direction on establishing partnerships that support effective information sharing while ensuring the protection of personal data, giving greater clarity to companies, supervisors, Financial Intelligence Units and data protection authorities. A joint drafting team comprising members of the EDPB and AMLA will lead the work. The EDPB and AMLA will also engage with industry and other stakeholders by holding a stakeholder event later in 2026 to gather early views on areas requiring clarification and plan to launch a public consultation on the draft Guidelines in the first half of 2027. Further details on the scope and content of the Guidelines will be published as the work progresses.
NEWS
The European Data Protection Board (EDPB) has released its annual report for 2024 on 23 April 2025, detailing significant legal developments in EU data protection. The report outlines eight major Art. 64(2) Regulation (EU) 2016/679 (General Data Protection Board (GDPR)) opinions, including new guidance on AI models and 'Consent or Pay' practices. The EDPB adopted four new guidelines, including rules on Article 48 GDPR international transfers. DPAs across the EU issued €1.2bn in fines, while the EDPB expanded its regulatory scope through a new cooperation agreement with PEReN and enhanced supervision of EU IT systems.
NEWS
The European Data Protection Board (EDPB) has approved the certification criteria for the EU Data Protection Seal, a mechanism to certify compliance with EU General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) in data processing operations, including transfers to third countries. This seal helps establish appropriate safeguards for data transfers, offering a uniform standard of assurance across the EU. It also specifies the roles of supervisory authorities, accreditation bodies, and certification bodies in maintaining consistent application of GDPR rules
NEWS
MLex: The EU's new Artificial Intelligence (AI) Act carries tougher maximum fines than the EU's landmark General Data Protection Regulation (EU GDPR), but that doesn't indicate that European lawmakers view data protection harms to be less serious than harms caused by AI, the chair of the European Data Protection Board (EDPB) said 9 May 2024.
NEWS
The European Data Protection Board (EDPB) has adopted guidelines for a consultation on when national data protection authorities should impose administrative fines under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR), alongside or instead of other corrective measures. The guidelines set out a five-step methodology requiring authorities to establish that an infringement is finable, identify the liable party, assess intention or negligence, consider aggravating and mitigating factors, and determine whether a fine would be effective, proportionate and dissuasive. They explain the relationship between fines and measures such as warnings, reprimands, orders, processing limitations or bans, and withdrawal of certification, and include 14 practical examples. The EDPB has also adopted the final guidelines on the interaction between the EU Digital Services Act and the EU GDPR, following consultation, to support consistent application where intermediary services process personal data. The consultation closes on 13 November 2026.