Direkt zum Inhalt
ShareEmailLinkedInXWhatappsFacebook
feedback
Share

Targeted modifications of the GDPR: EDPB & EDPS welcome simplification of record keeping obligations and request further clarifications

1 Woche 5 Tage ago

Brussels, 9 July 2025 - The European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) issued today a Joint Opinion on the European Commission’s Proposal for a Regulation amending certain regulations, including the GDPR

The Proposal, part of the fourth simplification Omnibus, aims to simplify EU rules and reduce administrative burden, extending certain mitigating measures available for small and medium sized enterprises (SMEs) to small mid-cap enterprises (SMCs), and includes further simplification measures.  

The Proposal aims to modify Art.30 (5) GDPR, providing a derogation to the obligation to keep a record of data processing operations. Currently, this derogation only applies to enterprises and organisation under 250 employees, except in certain cases. Under the Proposal, the derogation would apply to an enterprise or organisation employing fewer than 750 people, unless the processing operation carried out is likely to result in a high risk to individuals’ rights and freedoms, within the meaning of Art.35 GDPR. 

In addition, the Proposal introduces a definition of SME and SMC in Art.4 GDPR and extends the scope of Art.40 (1) and 42 (1) GDPR to the SMCs, which refer to codes of conduct and certification. These tools are currently designed to help enterprises and organisations demonstrate compliance with the GDPR focusing on the specific needs of SMEs. 

Wojciech Wiewiórowski, EDPS, said: “We support the general objective of the Proposal to reduce the administrative burden for SMEs and SMCs as long as this does not lower the protection of individuals’ fundamental rights, in particular the rights to privacy and to the protection of personal data. To this end, we welcome that the proposed modifications to simplify and clarify the obligation to keep a record of processing are targeted and limited in nature, and do not affect the core principles and other obligations under the GDPR.”  

Anu Talus, EDPB Chair, said: “The EDPB supports the Proposal’s general objective to reduce the administrative burden for SMEs and SMCs and to ensure that, in practice, they can enjoy a derogation from the duty to keep records of processing activities. The current derogation did not always achieve its goal. At the same time, the record of processing activities is a useful tool to support compliance with other duties, such as the one of transparency or to give effect to data subject rights. The simplification will offer greater flexibility to SMEs and SMCs to choose the most appropriate method to be compliant.”

As regard the organisations being subject to the derogation, considering that the Proposal impacts legislation in other policy areas, the EDPB and the EDPS expect further clarifications on why the new threshold of enterprises or organisations employing fewer than 750 persons would be more appropriate under the GDPR, rather than the threshold of 500 employees initially considered. In addition, the new exemption in Art. 30 (5) refers to ‘enterprises employing fewer than 750 employees’ without referring to the newly introduced definitions of SME and SMC, which also includes financial criteria. In order to ensure that the exemption will benefit SMEs and SMCs, the EDPB and the EDPS’s Joint Opinion recommends referring to the newly introduced definitions of SME and SMC. 

The EDPB and EDPS also ask the co-legislators to clarify in the Proposal that the term ‘organisation’, falling within the scope of the proposed derogation under Art.30 (5) GDPR, does not include public authorities and bodies.  
 

EDPB

Targeted modifications of the GDPR: EDPB & EDPS welcome simplification of record keeping obligations and request further clarifications

1 Woche 5 Tage ago
Targeted modifications of the GDPR: EDPB & EDPS welcome simplification of record keeping obligations and request further clarifications julia Wed, 07/09/2025 - 12:39 Wed, 07/09/2025 - 12:00

EDPS and EDPB a Joint Opinion on the European Commission’s Proposal for a Regulation amending certain regulations, including the GDPR.

Read Press Release

Read Joint Opinion 

0
European Data Protection Supervisor

The Helsinki Statement on enhanced clarity, support and engagement

2 Wochen 4 Tage ago

A fundamental rights approach to innovation and competitiveness

Helsinki, 3 July 2025 – At a high-level meeting in Helsinki on 1–2 July 2025, the European Data Protection Board (EDPB) adopted a landmark Statement on enhanced clarity, support and engagement.

The Statement outlines new initiatives to make GDPR compliance easier, in particular for micro, small and medium organisations, strengthen consistency and boost cross-regulatory cooperation. 

EDPB Chair Anu Talus said: “The EDPB aims to ensure that compliance with the GDPR can be more easily achieved. By placing fundamental rights into the core of their digital transformation, organisations can ensure that technological advancements and the respect for European values go hand in hand, ultimately building a stronger and more resilient digital economy.”

Across its efforts, the EDPB will strengthen its dialogue with stakeholders, holding proactive and early engagement to identify areas where further support and clarification is required, and providing the opportunity for stakeholders to flag possible inconsistencies and give feedback. The EDPB will publicly report on the main outcomes of the public consultations. 

The EDPB will launch a series of direct and practical resources to simplify GDPR application.

EDPB Chair Anu Talus said: “The EDPB is committed to helping organisations in achieving GDPR compliance with greater ease and efficiency. Through timely and concise guidance and ready-to-use tools, like a common data breach notification template, checklists, how-tos and FAQs, we will continue to make GDPR alignment achievable and accessible for all.”

Among the measures agreed upon to ensure consistent GDPR interpretation and enforcement across Europe, EDPB Members will make continuous efforts to align national and EDPB guidance. They will also develop common practices, methods, tools and common actions review guidelines to ensure their real-world effectiveness. The EDPB will also publish positions by DPAs on priority issues to help organisations understand and act on regulatory expectations.

The EDPB recognises the growing complexity of the digital regulatory landscape and has renewed its commitment to fostering structured cooperation with non-data protection regulators to address legal and practical challenges in cross-sectoral cases.
 

EDPB

Collaboration & Consistent efforts: two cornerstones for data protection in EU institutions

2 Wochen 5 Tage ago
Collaboration & Consistent efforts: two cornerstones for data protection in EU institutions miriam Wed, 07/02/2025 - 15:56 Wed, 07/02/2025 - 12:00

The EDPS - Data Protection Network meeting meets twice a year to discuss data protection priorities and practices in the digital world. 

Read Blogpost by EDPS Secretary General Leonardo Cervera Navas. 

0
European Data Protection Supervisor

New TechDispatch Talks are out!

2 Wochen 6 Tage ago
New TechDispatch Talks are out! miriam Tue, 07/01/2025 - 12:48 Thu, 07/03/2025 - 12:00

EDPS presents a brand new episode of TechDispatch Talks, a series to help you understand new and emerging technologies, their opportunities but also privacy challenges. Now you can watch it or have a listen!

0
European Data Protection Supervisor

Newsletter #115

3 Wochen 3 Tage ago
Newsletter #115 miriam Fri, 06/27/2025 - 16:04 Wed, 07/02/2025 - 12:00

30 days of preserving privacy and data protection, what does that look like? Read our newsletter to find out. 

1 Read it now
European Data Protection Supervisor

TechDispatch - Federated Learning

1 Monat 1 Woche ago
TechDispatch - Federated Learning francesco Tue, 06/10/2025 - 09:39 Tue, 06/10/2025 - 12:00

The EDPS TechDispatch provides factual descriptions of a new technology and its implication for personal data protection. Learn more about Federated Learning in this new edition.

1 Read here
European Data Protection Supervisor

EDPB publishes final version of guidelines on data transfers to third country authorities and SPE training material on AI and data protection

1 Monat 2 Wochen ago

Brussels, 05 June - During its latest plenary, the European Data Protection Board (EDPB) adopted the final version of its guidelines on Art.48 GDPR about data transfers to third country authorities, after public consultation. In addition, the Board presented two new Support Pool of Experts (SPE) projects providing training material on artificial intelligence and data protection. Finally, the Board discussed the European Commission’s request for a joint EDPB-EDPS opinion on the draft proposal on the simplification of record-keeping obligation under the GDPR. 

Data transfers to third country authorities 

Following public consultation, the EDPB has adopted the final version of the guidelines on data transfers to third country authorities. In its guidelines, the EDPB zooms in on Art. 48 GDPR and clarifies how organisations can best assess under which conditions they can lawfully respond to requests for a transfer of personal data from third country authorities (i.e. authorities from non-European countries).

The EDPB explains that judgements or decisions from third country authorities cannot automatically be recognised or enforced in Europe. As a general rule, an international agreement may provide for both a legal basis and a ground for transfer. In case there is no international agreement, or if the agreement does not provide for an appropriate legal basis or safeguards, other legal bases or other grounds for transfer could be considered, in exceptional circumstances and on a case by case basis.

The modifications introduced in the updated guidelines do not change their orientation, but they aim to provide further clarifications on different aspects that were brought up in the consultation. For example, the updated guidelines address the situation where the recipient of a request is a processor. In addition, they provide additional details regarding the situation where a mother company in a third country receives a request from that third country authority and then requests the personal data from its subsidiary in Europe. 

 

Upskilling and reskilling on AI and data protection

During its June’s plenary, the EDPB also presented two new Support Pool of Experts (SPE) projects*: Law & Compliance in AI Security and Data Protection and Fundamentals of Secure AI Systems with Personal Data. The two projects, which have been launched at the request of the Hellenic Data Protection Authority (HDPA), provide training material on AI and data protection.

The report “Law & Compliance in AI Security & Data Protection” is addressed to professionals with a legal focus like data protection officers (DPO) or privacy professionals.

The second report, “Fundamentals of Secure AI Systems with Personal Data”, is oriented toward professionals with a technical focus like cybersecurity professionals, developers or deployers of high-risk AI systems.

The main aim of these projects is to address the critical shortage of skills on AI and data protection, which is seen as a key obstacle to the use of privacy-friendly AI. The training material will help equip professionals with essential competences in AI and data protection to create a more favourable environment for the enforcement of data protection legislation.

The Board decided to publish both documents as PDF files. Taking into account the very fast evolution of AI, the EDPB also decided to launch a new innovative initiative as a one-year pilot project consisting of a modifiable community version of the reports. The EDPB will start working with the authors of both reports to import them in its Git repository** to allow, in a near future, any external contributor, with an account on this platform and under the condition of the Creative Commons Attribution-ShareAlike license, to propose changes or add comments to the documents.

Simplification of record-keeping obligation under the GDPR ***

Finally, the Board discussed the European Commission's request for a joint opinion by the EDPB and the European Data Protection Supervisor (EDPS) on its proposal to simplify the record-keeping obligations of small and medium-sized enterprises (SMEs), small mid-caps (SMCs) and organisations with fewer than 750 employees, amounting to a targeted amendment of Art. 30(5) GDPR. The EDPB and EDPS will issue their joint opinion on this matter within eight weeks. 

 

Note to editors:

* The Support Pool of Experts (SPE) is an initiative included in the EDPB strategy 2024-2027 to help Data Protection Authorities (DPAs) increase their capacity to enforce by developing common tools and giving them access to a wide pool of experts.  

As part of the SPE programme, the EDPB may commission experts to provide reports and tools on specific topics. The views expressed in the deliverables are those of their authors and they do not necessarily reflect the official position of the EDPB.

** The reports will be available in the following months on the repository page.

***On 8 May 2025, the EDPB and the EDPS adopted a letter, addressed to the European Commission, to share preliminary views on the Commission’s proposal on the simplification of record-keeping obligation under the GDPR.

EDPB

Migration management: data protection is one of the last lines of defence for vulnerable individuals

1 Monat 3 Wochen ago
Migration management: data protection is one of the last lines of defence for vulnerable individuals julia Wed, 05/28/2025 - 10:41 Wed, 05/28/2025 - 12:00

The EDPS published on 28 May 2025 an Opinion on the Proposal for a Regulation establishing a common system for the return of third-country nationals staying illegally in the EU.

The objective of the Proposal is to ensure the effective return and re-admission of third-country nationals illegally staying in the EU by providing Member States with simplified and common rules.

Read Press Release and Opinion 

0
European Data Protection Supervisor

EDPS at CPDP 2025 - The world is watching

2 Monate ago
EDPS at CPDP 2025 - The world is watching ilucenfe Tue, 05/20/2025 - 15:06 Tue, 05/20/2025 - 12:00

CPDP is back! Discover the EDPS involvement in this year's Conference on Computers, Privacy and Data Protection, taking place on May 21-23 in Brussels.

The EDPS will organise two panels on Artificial Intelligence and Data Protection. EDPS' experts will also participate as speakers in other panels and the Supervisor will deliver the conference's closing remarks.

1 Learn more
European Data Protection Supervisor

Newsletter is out!

2 Monate 1 Woche ago
Newsletter is out! miriam Mon, 05/12/2025 - 11:52 Mon, 05/12/2025 - 12:00

In this issue, read about our trainees’ vision for Europe; our upcoming event on the future of data protection; current affairs on data protection law; our advice and tools for EU institutions, bodies, offices and agencies, and MORE! Read it here.

1 Read it now
European Data Protection Supervisor

Simplification of record-keeping obligation: EDPB and EDPS adopt letter to EU Commission

2 Monate 1 Woche ago
Simplification of record-keeping obligation: EDPB and EDPS adopt letter to EU Commission julia Thu, 05/08/2025 - 18:05 Thu, 05/08/2025 - 12:00

The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have adopted a letter, addressed to the European Commission, on the upcoming proposal on the simplification of record-keeping obligation under the GDPR, amounting to a targeted amendment of Art. 30(5) GDPR.

The joint letter replies to the letter sent by the European Commission to the EDPB and the EDPS on 6 May 2025 where the Commission explained how it intends to introduce specific modifications to the GDPR. The EDPB and EDPS understand that a formal consultation will take place after the publication of the proposed legislative change.

The EDPB and EDPS shared that, at this stage, they could express preliminary support to this targeted simplification initiative, bearing in mind that this would not affect the obligation of controllers and processors to comply with other GDPR obligations. Nevertheless, the EDPB and EDPS asked the Commission to better evaluate the impact on the organisation subject to this change, to assess whether the draft proposal ensure a proportionate and fair balance between the protection of personal data and the interests of organisations with less than 500 employees.

Full letter here

0 Full letter here
European Data Protection Supervisor

Blogpost: Celebrating Schuman Day – Young Voices Speak for Europe

2 Monate 1 Woche ago
Blogpost: Celebrating Schuman Day – Young Voices Speak for Europe miriam Thu, 05/08/2025 - 15:35 Fri, 05/09/2025 - 12:00

Every year at the EDPS, we celebrate Europe Day, the achievements and opportunities it made possible to Europeans. Honouring the legacy of those who advanced the European project is as important as looking ahead and listening to the generations that will shape its future. EDPS Supervisor has therefore asked them about how the EU has impacted their lives and what it means to be European today. 

Read on about what they had to say.

1 Read blogpost
European Data Protection Supervisor

Simplification of record-keeping obligation: EDPB and EDPS adopt letter to EU Commission

2 Monate 1 Woche ago

Brussels, 08 May - The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have adopted a letter, addressed to the European Commission, on the upcoming proposal on the simplification of record-keeping obligation under the GDPR, amounting to a targeted amendment of Art. 30(5) GDPR.

The joint letter replies to the letter sent by the European Commission to the EDPB and the EDPS on 6 May 2025 where the Commission explained how it intends to introduce specific modifications to the GDPR. The EDPB and EDPS understand that a formal consultation will take place after the publication of the proposed legislative change.  

The EDPB and EDPS shared that, at this stage, they could express preliminary support to this targeted simplification initiative, bearing in mind that this would not affect the obligation of controllers and processors to comply with other GDPR obligations. Nevertheless, the EDPB and EDPS asked the Commission to better evaluate the impact on the organisations subject to this change, to assess whether the draft proposal ensure a proportionate and fair balance between the protection of personal data and the interests of organisations with less than 500 employees.

EDPB-EDPS Letter on European Commission draft proposal on simplification of record-keeping under the GDPR

8 May 2025 Publication Type: Topics: English Download Simplification of record-keeping obligation: EDPB and EDPS adopt letter to EU Commission
EDPB

European Patent Organisation and extension of adequacy decisions for the UK: EDPB adopts opinions

2 Monate 2 Wochen ago

Brussels, 06 May - During its latest plenary, the European Data Protection Board (EDPB) adopted an opinion on the European Commission’s draft adequacy decision under the GDPR concerning the European Patent Organisation (EPO). In addition, the Board adopted an opinion on the European Commission’s proposal to extend the validity of the UK adequacy decisions under the GDPR and the Law Enforcement Directive (LED). Finally, the EDPB agreed to grant the status of observer to the Personal Data Protection Agency of Bosnia and Herzegovina.

 

Adequate protection of personal data by the EPO

At the European Commission’s request, the Board adopted an opinion on the Commission’s draft adequacy decision regarding the European Patent Organisation (EPO). Once formally adopted by the Commission, this will be the first adequacy decision concerning an international organisation and not a country or a region.
An adequacy decision is a key-mechanism in EU data protection legislation which allows the European Commission to determine whether a third country or an international organisation offers an adequate level of data protection. The effect of such a decision is that personal data can flow freely from Europe to that third country or international organisation.

EDPB Chair, Anu Talus, said: “The EDPB welcomes the Commission’s initiative to work on the first adequacy decision concerning an international organisation. This decision shows how the legal framework of such organisations can be recognised as ensuring an adequate level of protection on the basis of Art.45 GDPR.

The EDPB underlines the importance of ongoing dialogue between the Commission and international organisations, with a view to developing this category of adequacy decisions in addition to those relating to third countries.”

In its opinion, the Board positively notes that the EPO data protection framework is largely aligned with the European Union data protection framework, including on data protection rights and principles.

This shows that the GDPR and, in particular, its transfer provisions, can facilitate safe data flows from Europe to international organisations, while taking into account their status.

 

Six-month extension of the UK adequacy decisions

The EDPB opinion, requested by the European Commission, addresses the proposed extension of the two UK adequacy decisions under the GDPR and the LED, which are set to expire on 27 June 2025.

The opinion only concerns the proposed 6-month extension of these adequacy decisions and does not address the level of protection for personal data afforded in the UK, which will be examined by the EDPB following the Commission’s assessment, and if the renewal of the UK adequacy decisions is proposed.

Since the UK‘s data protection reform is still pending in the UK parliament, the EDPB recognises the need for a technical and time-limited extension of the adequacy decisions until 27 December 2025.This will give the European Commission sufficient time to evaluate the updated UK legal framework once it has been adopted.  

The EDPB stresses that this extension is exceptional and is due to the ongoing legislative developments in the UK. It should not, in principle, be further prolonged.

The Board recalls the validity of its opinions 14/2021 and 15/2021 on the two UK adequacy decisions, adopted in April 2021, and invites the European Commission to take them into account in its future assessments. 
The Board also recalls the Commission’s obligation to monitor all relevant developments in the UK during the extension period.

 

New observer to the EDPB’s activities

Finally, EDPB members agreed to grant observer status to the EDPB’s activities to the Bosnia and Herzegovina Data Protection Authority, in line with Art. 8 EDPB Rules of Procedure.
 

EDPB

Europe Day 2025: come and visit us!

2 Monate 2 Wochen ago

Every year, on 9 May, people across Europe celebrate the anniversary of the Schuman Declaration, which was a milestone to bring peace and solidarity in Europe. This year is particularly special as it marks the 75th anniversary of this historic moment.

Let’s celebrate together

To celebrate this occasion, the EDPB takes part in the EU Open Day, with an interactive stand hosted by volunteers from the EDPB Secretariat and national Data Protection Authorities (DPAs). Come and visit us to learn more about data protection and the EDPB’s activities.

You will find the EDPB and EDPS stands at the European Commission’s headquarters - the Berlaymont building - Village 1 “A Democratic Union”, on Saturday 10 May from 10:00 to 18:00. 

Do you want to learn more about privacy and data protection — and test your knowledge?
Come visit us for fun activities and quizzes designed just for you!

Further information about Europe Day 2025
 

EDPB

Visit Europe in one day

2 Monate 3 Wochen ago
Visit Europe in one day ilucenfe Thu, 04/24/2025 - 16:24 Mon, 04/28/2025 - 12:00

To celebrate Europe Day, the European institutions are opening their doors to the public on 10 May 2025! Come visit us to discover the engaging activities the EDPS and EDPB have prepared for you. Stop by the EDPS on EU Open Day!

Learn more. 

0 Learn more
European Data Protection Supervisor