Skip to main content

EDPB adopts statement on DPAs role in AI Act framework, EU-U.S. Data Privacy Framework FAQ and new European Data Protection Seal

5 days 4 hours ago

Brussels, 17 July - During its latest plenary, the European Data Protection Board (EDPB) adopted a statement on the Data Protection Authorities’ (DPAs) role in the Artificial Intelligence Act (AI Act) framework.

According to the EDPB, DPAs already have experience and expertise when dealing with the impact of AI on fundamental rights, in particular the right to protection of personal data, and should therefore be designated as Market Surveillance Authorities (MSAs) in a number of cases. This would ensure better coordination among different regulatory authorities, enhance legal certainty for all stakeholders and strengthen the supervision and enforcement of both the AI Act and EU data protection law.

According to the AI Act, Members States shall appoint MSAs at national level before 2 August 2025, for the purpose of supervising the application and implementation of the AI Act.

In its statement, the EDPB recommends that:

  • As already indicated in the AI Act, DPAs should be designated as MSAs for high-risk AI systems used for law enforcement, border management, administration of justice and democratic processes;
  • Member States should consider appointing DPAs as MSAs also for other high-risk AI systems, taking account of the views of the national DPA, particularly where those high-risk AI systems are in sectors likely to impact natural persons rights and freedoms with regard to the processing of personal data;
  • DPAs, where appointed as MSAs, should be designated as the single points of contact for the public and counterparts at Member State and EU levels;
  • Clear procedures should be established for cooperation between MSAs and the other regulatory authorities which are tasked with the supervision of AI systems, including DPAs. In addition, appropriate cooperation should be established between the EU AI Office and the DPAs/EDPB.

EDPB Deputy Chair Irene Loizidou Nicolaidou said: “DPAs should play a prominent role in enforcing the AI Act as most AI systems involve processing of personal data. I strongly believe that DPAs are suitable for this role because of their full independence and deep understanding of the risks of AI for fundamental rights, based on their existing experience.”

Next, the Board adopted two Frequently Asked Questions (FAQ) documents concerning the EU-U.S. Data Privacy Framework (DPF), aimed at providing more clarification on the functioning of the DPF.

The FAQ for individuals provides information on the functioning of the DPF: how to benefit from it, how to lodge a complaint and how this complaint will be handled.

Likewise, the FAQ for businesses explains which U.S. companies are eligible to join the DPF: what to do before transferring personal data to a company in the U.S. which is DPF-certified, and where to find further guidance.

Finally, the EDPB adopted an opinion approving the EuroPriSe Criteria Catalogue for  the  certification of processing activities by processors, resulting in a European Data Protection Seal.* European Data Protection Seals serve as important tools contributing to GDPR compliance.

In September 2022, the EDPB had adopted an opinion on the EuroPriSe certification criteria, enabling their recognition in Germany as certification criteria for processing operations by processors. Following an update of the scheme, this new opinion approves the criteria as being applicable in the whole EU/EEA, and as a European Data Protection Seal.

GDPR certification contributes to the demonstration of compliance efforts and to increased transparency and trust. It allows for better assessment of the degree of protection offered by products, services, processes or systems used by organisations that process personal data.

Note to editors:

*The EuroPrise European Data Protection Seal will be added to the register of certification mechanisms and data protection seals in accordance with Article 42(8) GDPR.

The opinion on the approval of the EuroPriSe certification scheme as European Data Protection Seal, adopted during the EDPB Plenary, is subject to the necessary legal, linguistic and formatting checks and will be made available on the EDPB website once it has been completed.


Coordinated Supervision Committee appoints new coordinator

2 weeks 6 days ago

The Coordinated Supervision Committee (CSC) elected Fanny Coudert from the European Data Protection Supervisor (EDPS) as its new coordinator for a term of two years. Ms. Coudert succeeds former coordinator Clara Guerra from the Portuguese Data Protection Authority (DPA).

Fanny Coudert will lead the work of the Committee with the support of Deputy Coordinators Sebastian Hümmeler from the Federal German DPA and Matej Sironic from the Slovenian DPA.

EDPB Chair Anu Talus said: “I would like to thank outgoing CSC coordinator Clara Guerra for her valuable work in the past years, which helped the CSC grow and expand. Today, the CSC ensures that the supervision of 5 bodies, agencies and systems  is seamlessly coordinated by its members. This work is crucial for an EU without internal borders.” 
I would also like to welcome Fanny Coudert and I look forward to working with her. I am confident that her expertise can contribute positively and significantly to the expanding workload of the CSC.”

Editor's note:

The Coordinated Supervision Committee ensures the coordinated supervision of the large EU Information Systems and of EU bodies, offices and agencies in accordance with Article 62 of Regulation 2018/1725 or with the EU legal act establishing the large scale IT system or EU body, office or agency. The Committee was created within the framework of the European Data Protection Board (EDPB) and brings together the EU supervisory authorities (SAs) and the European Data Protection Supervisor (EDPS), as well as the supervisory authorities of the Non-EU Schengen Member States, when foreseen under EU law.

The CSC currently covers the Internal Market Information system (IMI), Eurojust, the European Public Prosecutor’s Office (EPPO), Europol and the Schengen Information System (SIS). Gradually, the Committee will also cover other IT systems, bodies, offices and agencies in the fields of Border, Asylum and Migration (EES, Eurodac, ETIAS, VIS, and their interoperability), Police and Justice Cooperation (ECRIS-TCN) and the next generation Prüm. 
You can find more information on the Committee here.

About the CSC Coordinator and Deputy Coordinators mandates:

The Coordinator and the Deputy Coordinators are designated for a term of two years starting from the date of their respective elections and they may be re-elected once for a further two years.
Deputy Coordinator Sebastian Hümmeler was re-elected for the second time on 29 November 2023 and Deputy Coordinator Matej Sironic was elected on 10 April 2024.



Zdravko Vukić elected new Deputy Chair of the European Data Protection Board

1 month ago

Brussels, 19 June - During its latest plenary, the Members of the European Data Protection Board (EDPB) elected Zdravko Vukić, Director of the Croatian Personal Data Protection Agency, as Deputy Chair. Vukić replaces Aleid Wolfsen (Chair of the Dutch Data Protection Authority), who has reached the end of his five-year mandate as EDPB Deputy Chair.
Over the coming years, Zdravko Vukić, together with fellow Deputy Chair Irene Loizidou Nikolaidou, will work closely together with EDPB Chair Anu Talus to ensure the consistent application of EU data protection rules and to promote effective cooperation among data protection authorities throughout the European Economic Area (EEA).

EDPB Deputy Chair Zdravko Vukić said:

“I am honoured and thankful to be elected EDPB Deputy Chair. The EDPB is a prominent and influential EU decision-making body, which plays a key role in shaping a digital society that is in line with EU common values.

All EDPB Members work together closely to raise awareness of GDPR at both national and EU levels, to empower individuals to exercise their rights and help companies, including small businesses, understand their compliance obligations.

In the years to come, I will make it my responsibility as Deputy Chair to continue pursuing these objectives and I will be committed to enhancing enforcement cooperation to address emerging challenges with innovative approaches and tools.

In order to deliver these results, we have to ensure that the DPAs and the EDPB Secretariat, serving as crucial link between authorities, are adequately staffed. As Deputy Chair, I will devote special attention and time to this crucial aspect too.”

EDPB Chair Anu Talus said:

“I would like to thank outgoing Deputy Chair Aleid Wolfsen for his commitment and contribution over the past years, which helped us as a Board to grow together and achieve excellent results.

I also look forward to working with Deputy Chair Zdravko Vukić to face the challenge of the increasing number of tasks of the EDPB.”

While it is already common practice for the EDPB to hold a public consultation after the adoption of the first version of guidelines, the Board decided it may also consult stakeholders prior to the preparation of guidelines on a case-by-case basis.
This prior consultation will enable the EDPB to take on stakeholders’ comments, questions and practical examples during the initial drafting period.


Facial recognition at airports: individuals should have maximum control over biometric data

1 month 4 weeks ago

Brussels, 24 May - During its latest plenary, the EDPB adopted an Opinion on the use of facial recognition technologies by airport operators and airline companies to streamline the passenger flow at airports*. This Article 64(2) Opinion, following a request from the French Data Protection Authority, addresses a matter of general application and produces effects in more than one Member State.

EDPB Chair Anu Talus said: “More and more airport operators and airline companies around the world are piloting facial recognition systems allowing passengers to go more easily through the various checkpoints. It is important to be aware that biometric data are particularly sensitive and that their processing can create significant risks for individuals. Facial recognition technology can lead to false negatives, bias and discrimination. Misuse of biometric data can also have grave consequences, such as identity fraud or impersonation. Therefore, we urge airline companies and airport operators to opt for less intrusive ways to streamline passenger flows, when possible. In the view of the EDPB, individuals should have maximum control over their own biometric data.”

The Opinion analyses the compatibility of the processing with the storage limitation principle (Article 5(1)(e) GDPR), the integrity and confidentiality principle (Article 5(1)((f)) GDPR, data protection by design and default (Article 25 GDPR) and security of processing (Article 32 GPDR). Compliance with other GDPR provisions including regarding the lawfulness of the processing are not in scope of this Opinion.**

There is no uniform legal requirement in the EU for airport operators and airline companies to verify that the name on the passenger’s boarding pass matches the name on their identity document, and this may be subject to national laws. Therefore, where no verification of the passengers’ identity with an official identity document is required, no such verification with the use of biometrics should be performed, as this would result in an excessive processing of data.
In its Opinion, the EDPB considered the compliance of processing of passengers’ biometric data with four different types of storage solutions, ranging from ones that store the biometric data only in the hands of the individual to those which rely on centralised a storage architecture with different modalities. In all cases, only the biometric data of passengers who actively enrol and consent to participate should be processed.

The EDPB found that the only storage solutions which could be compatible with the integrity and confidentiality principle, data protection by design and default and security of processing, are the solutions whereby the biometric data is stored in the hands of the individual or in a central database but with the encryption key solely in their hands. These storage solutions, if implemented with a list of recommended minimum safeguards, are the only modalities which adequately counterbalance the intrusiveness of the processing by offering individuals the greatest control.

The EDPB found that the solutions based on the storage in a centralised database either within the airport or in the cloud, without the encryption keys in the hands of the individual, cannot be compatible with the requirements of data protection by design and default and, if the controller limits themselves to the measures described in the scenarios analysed, would not comply with the requirements of security of processing.

Regarding the principle of storage limitation, controllers need to ensure they have a sufficient justification for the envisaged retention period and limit it to what is necessary for the proposed purpose.

Next, a report was adopted by the DPAs on the work of the ChatGPT taskforce. This taskforce was created by the EDPB to promote cooperation between DPAs investigating the chatbot developed by OpenAI.

The report provides preliminary views on certain aspects discussed between DPAs and does not prejudge the analysis that will be made by each DPA in their respective, ongoing investigation***.

It analyses several aspects concerning common interpretation of the applicable GDPR provisions relevant for the various ongoing investigations, such as:

  • lawfulness of collecting training data (“web scraping”), as well as processing of data for input, output and training of ChatGPT.
  • fairness: ensuring compliance with the GDPR is a responsibility of OpenAI and not of the data subjects, even when individuals input personal data.
  • transparency and  data accuracy: the controller should provide proper information on the probabilistic nature of ChatGPT’s output and refer explicitly to  the fact that the generated text may be biased or made up.
  • The report points out that it is imperative that data subjects can exercise their rights effectively.

Taskforce members also developed a common questionnaire as a possible basis for their exchanges with Open AI, which is published as an annex to the report.

Furthermore, the EDPB decided to develop guidelines on Generative AI, focusing as a first step on data scraping in the context of AI training.

Finally, the EDPB adopted a statement on the Commission's "Financial data access and payments package" (which includes the proposals for the Regulation on the framework for Financial Data Access (FIDA), on the Payments Service Regulation (PSR) and on the Payment Services Directive 3 (PSD3)).
The EDPB takes note of the European Parliament’s reports on the FIDA and PSR proposals, but considers that, with regard to the prevention and detection of fraudulent transactions, additional data protection safeguards should be included in the transaction monitoring mechanism of the PSR Proposal. It is important to ensure that the level of interference with the fundamental right to the protection of personal data of persons concerned is necessary and proportionate to the objective of preventing payment fraud.


EDPB launches French and German versions of its Data Protection Guide for small business

2 months ago

The EDPB Data Protection Guide for small business is now available in French and German

The Guide provides practical information to SMEs about GDPR compliance and benefits in an accessible and easily understandable language.

The development of tools providing practical, easily understandable and accessible data protection guidance is key to reaching a non-expert audience and a strategic objective for the EDPB.

The EDPB Data Protection Guide for small business covers various aspects of the GDPR, from data protection basics, to data subject rights and measures to secure personal data. It contains videos, infographics, interactive flowcharts, and other practical materials to help SMEs on their way to become GDPR compliant

In the near future, the Guide will become available in 15 more European languages.


Europe Day 2024

2 months 3 weeks ago

Europe Day commemorates the signing of the Schuman Declaration, to celebrate peace and solidarity in Europe. Every year, the EDPB takes part in Europe Day, with an interactive stand manned by volunteers from the EDPB Secretariat and national DPAs, to raise awareness of data protection and to provide information about the EDPB’s activities

This year, the EU institutions open their doors to the public in Brussels, Luxembourg and Strasbourg on Saturday 4 May. In Brussels, Europe Day will take place at the European Commission’s headquarters - the Berlaymont building - from 10:00 to 18:00.

EDPB and EDPS will welcome you in the village “Our strong digital Europe”, showcasing a variety of fun activities to help you learn more about privacy and data protection.

Further information about Europe Day 2024


EDPB Annual Report 2023: Safeguarding individuals’ digital rights

2 months 4 weeks ago

The EDPB has launched its 2023 Annual Report. The report provides an overview of the work carried out by the EDPB in the previous year and reflects on important milestones, such as the election of Anu Talus as EDPB Chair; the adoption of two binding decisions and one urgent binding decision providing important common interpretations of data protection law and key legal principles that will shape the digital landscape; and the launch of the EDPB’s first outreach project for a general audience: the EDPB Data Protection Guide for small business. In addition, it includes examples of enforcement by data protection authorities (DPAs) at national level. 

EDPB Chair, Anu Talus said: “Looking back at the work carried out in the last year, I am proud to present this annual report. 2023 was another transformative year at the EDPB, full of notable achievements. We have built an impressive compendium of guidelines, created new cooperation methods for the DPAs, and adopted significant binding decisions which will help shape digital services. We also worked hard to raise awareness of the GDPR at the European and international level, so that individuals know their rights and exercise them, and that companies, even small ones, can understand how to comply with their legal duties.”


EDPB sets out priorities for 2024-2027 and clarifies implementation DPF redress mechanisms

3 months ago

Brussels, 18 April - During its latest plenary, the EDPB adopted its strategy for 2024-2027. The strategy sets out the EDPB’s priorities, grouped around four pillars, as well as key actions per pillar to help achieve these objectives. These four pillars are:

  • Pillar 1 – Enhancing harmonisation and promoting compliance  
  • Pillar 2 – Reinforcing a common enforcement culture and effective cooperation      
  • Pillar 3 – Safeguarding data protection in the developing digital and cross-regulatory landscape      
  • Pillar 4 – Contributing to the global dialogue on data protection

EDPB Chair Anu Talus said: “The new strategy takes the existing vision in a new direction in order to respond to the data protection needs of today, and the ever evolving digital landscape. The strategy is the result of a collaborative effort, involving all EU data protection authorities (DPAs) and sets out common priorities for the years to come. ”

In the next four years, the EDPB will continue to promote compliance with data protection law by developing clear, concise and practical guidance on important topics, and by developing materials for a wider audience. In addition, enforcement cooperation will remain an important priority for the EDPB. The Board will continue building on the vision set out in its so-called Vienna Statement, and further develop EDPB initiatives in this area, such as the coordinated enforcement actions.

A new aspect of the strategy is the focus on the interplay with the new regulatory digital framework. New digital laws, such as the DMA or the DSA, have an impact on data protection and privacy. The EDPB will work to enhance cooperation with other regulatory authorities, with a view to embedding the right to data protection in the overall regulatory architecture. Furthermore, the EDPB will continue to pay special attention to challenges raised by new technologies, such as AI.

The strategy will be complemented by two work programmes, which will contain details about its implementation.

In addition, regarding the EU-US Data Privacy Framework (DPF), the EDPB adopted Rules of Procedure, a public information note and template complaint forms to facilitate the implementation of the redress mechanisms under the DPF.

The EDPB documents relate to two DPF redress mechanisms created to handle complaints by EU individuals. The redress mechanisms deal only with complaints concerning their respective competence - national security or commercial purposes - and only for data transmitted after 10 July 2023.


EDPB: ‘Consent or Pay’ models should offer real choice

3 months ago

Brussels, 17 April - During its latest plenary, the EDPB adopted an Opinion following an Art. 64(2) GDPR request by the Dutch, Norwegian & Hamburg Data Protection Authorities (DPA). The Opinion addresses the validity of consent to process personal data for the purposes of behavioural advertising in the context of ‘consent or pay’ models deployed by large online platforms

EDPB Chair Anu Talus said: “Online platforms should give users a real choice when employing ‘consent or pay’ models. The models we have today usually require individuals to either give away all their data or to pay. As a result most users consent to the processing in order to use a service, and they do not understand the full implications of their choices.”

As regards ‘consent or pay’ models implemented by large online platforms, the EDPB considers that, in most cases, it will not be possible for them to comply with the requirements for valid consent, if they confront users only with a choice between consenting to processing of personal data for behavioural advertising purposes and paying a fee.

The EDPB considers that offering only a paid alternative to services which involve the processing of personal data for behavioural advertising purposes should not be the default way forward for controllers. When developing alternatives, large online platforms should consider providing individuals with an ‘equivalent alternative’ that does not entail the payment of a fee. If controllers do opt to charge a fee for access to the ‘equivalent alternative’, they should give significant consideration to offering an additional alternative. This free alternative should be without behavioural advertising, e.g. with a form of advertising involving the processing of less or no personal data. This is a particularly important factor in the assessment of valid consent under the GDPR.

The EDPB stresses that obtaining consent does not absolve the controller from adhering to all the principles outlined in Art. 5 GDPR, such as purpose limitation, data minimisation and fairness. In addition, large online platforms should also consider compliance with the principles of necessity and proportionality, and they are responsible for demonstrating that their processing is generally in line with the GDPR. 

As regards the need for consent to be free, the following criteria should be taken into account: conditionality, detriment, imbalance of power and granularity. For instance, the EDPB points out that any fee charged cannot make individuals feel compelled to consent. Controllers should assess, on a case-by-case basis, both whether a fee is appropriate at all and what amount is appropriate in the given circumstances. Large online platforms should also consider whether the decision not to consent may lead the individual to suffer negative consequences, such as exclusion from a prominent service, lack of access to professional networks, or risk of losing content or connections.  The EDPB notes that negative consequences are likely to occur when large online platforms use a ‘consent or pay’ model to obtain consent for the processing.

Controllers also need to evaluate, on a case-by-case basis, whether there is an imbalance of power between the individual and the controller. The factors to be assessed include the position of the large online platforms in the market, the extent to which the individual relies on the service and the main audience of the service. 

Furthermore, the EDPB provides elements to assess the criteria of informed, specific and unambiguous consent that large online platforms should take into account when implementing ‘consent or pay’ models.

EDPB Chair, Anu Talus added: “Controllers should take care at all times to avoid transforming the fundamental right to data protection into a feature that individuals have to pay to enjoy. Individuals should be made fully aware of the value and the consequences of their choices.” 

In addition to this Art. 64(2) Opinion, the EDPB will also develop guidelines on ‘consent or pay’ models with a broader scope and will engage with stakeholders on these upcoming guidelines.


CSC elects 2nd Deputy Coordinator

3 months 1 week ago

The Coordinated Supervision Committee (CSC) has elected Matej Sironic from the Slovenian Data Protection Authority (DPA) as its Deputy Coordinator for a term of two years. Sironic will be the second Deputy Coordinator, and will work along with Sebastian Hümmeler from the Federal German DPA. A second Deputy was elected in order to keep up with the CSC’s expanding mandate. Together with CSC Coordinator, Clara Guerra, they will lead the work of the Committee.

The CSC ensures the coordinated supervision of the large EU Information Systems and of EU bodies, offices and agencies in accordance with Article 62 of Regulation 2018/1725 or with the EU legal act establishing the large scale IT system or EU body, office or agency. It was created within the framework of the European Data Protection Board (EDPB) and brings together the EU data protection authorities (DPAs) and the European Data Protection Supervisor (EDPS), as well as the data protection authorities of the Non-EU Schengen Member States, when foreseen under EU law.

The CSC currently covers the Internal Market Information system (IMI), Eurojust, the European Public Prosecutor’s Office (EPPO), Europol and the Schengen Information System (SIS). Gradually, the Committee will also cover other IT systems, bodies, offices and agencies in the fields of Border, Asylum and Migration (EES, Eurodac, ETIAS, VIS, and their interoperability), Police and Justice Cooperation (ECRIS-TCN) and the next generation Prüm. You can find more information on the Committee here 

During its March meeting, the CSC also adopted recommendations for IMI actors on their data protection transparency obligations towards individuals. The recommendations aim to assist the IMI competent authorities in Member States, as data controllers, to better comply with their legal obligations. The recommendations will be disseminated to the national IMI coordinators by the relevant national DPAs. 

1 hour 26 minutes ago
Subscribe to EDPB feed