Refine By
Clear all filter
About 91497 results for "*"
NEWS
The EDPB has published Guidelines 01/2025 on Pseudonymisation for public consultation. The guidelines clarify the legal definition of pseudonymisation under the EU's General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR), emphasising that pseudonymised data remains personal data. They outline pseudonymisation's role as a safeguard for implementing data protection principles, particularly in risk reduction, data minimisation, and ensuring appropriate security levels. The EDPB also addresses the impact of pseudonymisation on data subject rights and its potential use in data transfers to third countries. Such comments should be sent 28th February 2025 at the latest using the provided form.
NEWS
The European Data Protection Board (EDPB) has adopted a report summarising the outcome of the 2024 coordinated enforcement action under the Coordinated Enforcement Framework (CEF). The initiative, aimed at streamlining enforcement and cooperation among 30 Data Protection Authorities (DPAs) across Europe, focused on assessing controllers’ compliance with the right of access.
NEWS
The European Data Protection Board (EDPB) has selected compliance with transparency and information obligations under the EU General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) as the topic of its fifth coordinated enforcement action, which is set to launch in 2026. The action will focus on Articles 12, 13 and 14 of the EU GDPR, which require that individuals are informed when their personal data is being processed. Data Protection Authorities (DPAs) will participate on a voluntary basis in the coming weeks, with results aggregated and analysed to generate insights for targeted follow-up at both national and European levels. This action forms part of the Coordinated Enforcement Framework (CEF), established in October 2020. Previous coordinated actions have addressed the designation and role of Data Protection Officers (2024), and the implementation of the right of access by controllers (2025).
NEWS
The European Data Protection Board (EDPB) has signed a Joint Statement on AI-Generated Imagery and the Protection of Privacy, representing the united position of 61 authorities across the world coordinated by the Global Privacy Assembly's International Enforcement Cooperation Working Group. The statement addresses concerns about AI systems that generate realistic images and videos depicting identifiable individuals without their knowledge or consent, particularly highlighting risks of cyber-bullying and exploitation affecting children and other vulnerable groups. The co-signatories remind organisations developing and using AI content generation systems that these must comply with applicable data protection and privacy rules, outlining four fundamental principles: implementing robust safeguards, ensuring meaningful transparency, providing effective and accessible protection mechanisms, and addressing specific risks to children. The statement calls on organisations to engage proactively with regulators, implement robust safeguards from the outset, and ensure technological advancements do not compromise privacy, dignity, safety and other fundamental rights.
NEWS
The European Data Protection Board (EDPB) issued an opinion on 5 May 2025 supporting the European Commission's proposal to extend the UK's data protection adequacy decisions under Regulation (EU) 2016/679 (General Data Protection Regulation) and LED until 27 December 2025. The extension aims to accommodate the UK's ongoing Data (Use and Access) Bill legislative process, allowing time for assessment of the updated legal framework. The EDPB notes this is an exceptional, one-time extension to the current decisions that were set to expire on 27 June 2025.
NEWS
The European Data Protection Board (EDPB) has adopted a new document on 13 March 2025 updating procedures for approving Binding Corporate Rules (BCRs) under Regulation (EU) 2016/679 (General Data Protection Regulation). The document replaces Working Paper 263rev.01 and establishes a five-phase approval process: BCR Lead review, co-review, cooperation, BCR session and EDPB Opinion phases. The procedure aims to streamline cooperation between supervisory authorities while maintaining consistency in BCR assessments. Once approved by the BCR Lead authority, the rules provide appropriate safeguards for data transfers without requiring additional authorisations from other supervisory authorities.
NEWS
The European Data Protection Supervisor (EDPS) has adopted two documents aimed at strengthening the role and independence of data protection officers (DPOs) within EU institutions, bodies, offices and agencies (EUIs). On 18 December 2025, the EDPS issued Supervisory Guidance clarifying requirements relating to DPO designation, institutional positioning, independence guarantees and responsibilities within EUIs. On 16 January 2026, the EDPS adopted Decision 01/2026, establishing binding rules requiring EUIs to obtain prior EDPS consent before dismissing DPOs before the end of their term. The guidance sets out the EDPS’ interpretation of DPO roles, positions and tasks, while the decision creates a uniform procedural framework for dismissals. Both measures apply with immediate effect and must be reflected in EUIs’ internal practices and decision-making regarding the position and protection of DPOs.
NEWS
The European Data Protection Supervisor (EDPS) has issued Opinion 17/2026 on the European Commission’s proposal to amend Regulation (EU) 2018/1725 to streamline and align data protection rules for the processing of operational personal data by EU Justice and Home Affairs agencies and bodies, including Europol, Eurojust, the European Public Prosecutor’s Office and, to a limited extent, European Border and Coast Guard Agency. The EDPS welcomes the proposed changes but calls for further safeguards to ensure effective supervision and enforcement, particularly because of the sensitive and complex nature of personal data processing in criminal justice and law enforcement. It recommends clarifying its powers to issue binding compliance orders and adopt interim protective measures in urgent cases, strengthening cooperation with national data protection authorities and ensuring that existing agreements allowing Europol and Eurojust to exchange operational personal data with third countries fully comply with current EU data protection law. The EDPS also calls for additional human and financial resources in light of its expanding responsibilities and the increased data-processing capabilities of EU Justice and Home Affairs agencies.
NEWS
The European Data Protection Supervisor (EDPS) has found that the European Commission's use of Microsoft 365 has infringed multiple provisions of Regulation (EU) 2018/1725, the EU’s data protection law for EU institutions, bodies, offices and agencies and those on transfers of personal data outside the EU/EEA. The EDPS has now issued corrective measures and ordered the Commission to suspend all data flows as a result of its use of Microsoft 365 to Microsoft and to its affiliates and sub-processors located in countries outside the EU/EEA not covered by an adequacy decision, and has also ordered the Commission to ensure the processing operations from its use of Microsoft 365 comply with Regulation (EU) 2018/1725. The Commission must demonstrate compliance with the EDPS' orders by 9 December 2024.
NEWS
The European Data Protection Supervisor (EDPS) has published an Opinion on the European Commission’s Proposal for a Regulation establishing a common system for the return of third-country nationals staying illegally in the European Union. The EDPS, led by Wojciech Wiewiórowski, was appointed by joint decision of the European Parliament and the Council to provide independent oversight of personal data processing by EU institutions and bodies.
NEWS
The European Data Protection Supervisor (EDPS) has published guidance to assist EU institutions, bodies, offices and agencies in identifying and mitigating data protection risks linked to artificial intelligence (AI) systems under Regulation (EU) 2018/1725. The Guidance for Risk Management of Artificial Intelligence systems outlines a framework aligned with ISO 31000:2018 for assessing and treating risks throughout the AI lifecycle. It emphasises technical mitigation of risks to fairness, accuracy, data minimisation, security and data subject rights, offering detailed measures to prevent bias, ensure interpretability and protect personal data. The document complements existing EDPS orientations on generative AI and data protection impact assessments, aiming to foster accountability and lawful AI deployment by EU controllers.
NEWS
The European Data Protection Supervisor (EDPS) has issued Opinion 7/2026 on the European Commission's proposal to extend Regulation (EU) 2021/1232, which governs interim data processing rules for combating child sexual abuse material (CSAM) online. The proposed extension would continue the temporary framework from its current expiry date of 3 April 2026 until 3 April 2028, allowing providers to take voluntary measures to combat CSAM while inter-institutional negotiations continue on longer-term legislation. The EDPS recommends specific amendments to ensure greater legal certainty regarding lawfulness of processing under Regulation 2016/679 (GDPR) and calls for effective safeguards against general and indiscriminate scanning in line with necessity and proportionality principles. The opinion references previous EDPS positions from 2020 and 2024, and a 2022 joint opinion with the European Data Protection Board (EDPB), reiterating that content detection solutions must be targeted and carefully consider privacy rights of all users.