Legend: 🇪🇺 All done! | 🤖 Working on it | ☠️ Obsolete
2026
- EDPB Guidelines 2026-01 on processing of personal data for scientific research purposes
- EDPB Guidelines 2026-02 on Anonymisation
- EDPB Guidelines 2026-03 on web scraping in the context of generative AI
- 🤖 2026 on the Application for Approval and on the elements and principles to be found in Processor Binding Corporate Rules (Art. 47 GDPR)
2025
- EDPB Position Paper 2025-01 on Interplay between data protection and competition law
- EDPB Guidelines 2025-01 on Pseudonymisation
- EDPB Guidelines 2025-02 on processing of personal data through blockchain technologies — v1.1 (consultation)
- EDPB Guidelines 2025-02 on processing of personal data through blockchain technologies — v2.0 (final)
- AI-Complex Algorithms and effective Data Protection Supervision - Bias evaluation
- AI-Complex Algorithms and effective Data Protection Supervision - Effective implementation of data subjects’ rights
- EDPB Statement 2025-01 on Age Assurance
- EDPB Recommendations 2025-02 on the legal basis for requiring the creation of user accounts on e-commerce websites
- 🤖 2025 on the 2027 WADA World Anti-Doping Code
- 🤖 2025 on the interplay between the DSA and the GDPR
- 🤖 Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation
- 🤖 Coordinated Supervision Committee Report of Activities 2022-2024
2024
- EDPB Guidelines 2024-01 on processing of personal data based on Article 6(1)(f) GDPR
- EDPB Guidelines 2024-02 on Article 48 GDPR — v1 (consultation)
- EDPB Guidelines 2024-02 on Article 48 GDPR — v2 (final)
- EDPB Opinion 2024-04 on the notion of main establishment of a controller in the Union under Art. 4.16(a) GDPR
- 🤖 2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms
- 🤖 2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)
- EDPB Opinion 2024-28 on certain data protection aspects related to the processing of personal data in the context of AI models
2023
- 🤖 2023 on Article 37 Law Enforcement Directive
- EDPB Guidelines 2023-02 on Technical Scope of Art. 5(3) of ePrivacy Directive
2022
- EDPB Guidelines 2022-01 on data subject rights - Right of access
- 🤖 2022 on the application of Article 60 GDPR
- 🤖 2022 on Deceptive design patterns in social media platform interfaces - how to recognise and avoid them
- EDPB Guidelines 2022-04 on the calculation of administrative fines under the GDPR
- 🤖 2022 on the use of facial recognition technology in the area of law enforcement
- EDPB Guidelines 2022-06 on the practical implementation of amicable settlements
- 🤖 2022 on certification as a tool for transfers
- 🤖 2022 on identifying a controller or processor’s lead supervisory authority
- EDPB Guidelines 2022-09 on personal data breach notification under GDPR
- 🤖 2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)
- 🤖 2022 on personal data transfers to the Russian Federation
2021
- EDPB Guidelines 2021-01 on Examples regarding Personal Data Breach Notification
- 🤖 2021 on virtual voice assistants
- EDPB Guidelines 2021-03 on the application of Article 65(1)(a) GDPR
- 🤖 2021 on Codes of Conduct as tools for transfers
- EDPB Guidelines 2021-05 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR
- 🤖 2021 on the adequacy referential under the Law Enforcement Directive
- 🤖 2021 on the legal basis for the storage of credit card data for the sole purpose of facilitating further online transactions
2020
- 🤖 2020 on processing personal data in the context of connected vehicles and mobility related applications
- Guidelines 2/2020 on articles 46(2)(a) and 46(3)(b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies
- Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak
- Guidelines 04/2020 on the use of location data and contact tracing tools in the context of the COVID-19 outbreak
- EDPB Guidelines 2020-05 on consent under GDPR
- 🤖 2020 on the interplay of the Second Payment Services Directive and the GDPR
- EDPB Guidelines 2020-07 on the concepts of controller and processor in the GDPR
- EDPB Guidelines 2020-08 on the targeting of social media users
- Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679
- 🤖 2020 on restrictions under Article 23 GDPR
- Guidance on certification criteria assessment (Addendum to Guidelines 1/2018)
- 🤖 2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data
- Recommendations 02/2020 on the European Essential Guarantees for surveillance measures
2019
- 🤖 1725)
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default
- Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1)
- Guidelines 3/2019 on processing of personal data through video devices
- 🤖 2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects
- Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679
- 2019 on the interplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities
- 2019 on Article 25 Data Protection by Design and by Default
2018 & Before
- EDPB Guidelines 2018-02 on derogations of Article 49 under Regulation 2016-679
- 2018 on the territorial scope of the GDPR (Article 3) Version 2.1
- Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation
- Guidelines 1/2018 on certification and identifying certification criteria — Annex 2
- Guidelines 4/2018 on the accreditation of certification bodies under Article 43 GDPR
EDPB/EDPS Joint Opinions on EU Legislative Proposals
Art. 42 Regulation (EU) 2018/1725 — consultations on draft EU legislation, distinct from the GDPR-interpretive Guidelines above.
2026
- 2026 on the Digital Omnibus on AI
- EDPB-EDPS Joint Opinion 2026-02 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (Digital Omnibus)
- 2026 on the European Biotech Act proposal
- 2026 on the Cybersecurity Act 2 and NIS2 Directive amendments
2025
2023
2022
- 2022 on the Data Act proposal
- 2022 on the European Health Data Space proposal
- 2022 on the Child Sexual Abuse (CSAM) Regulation proposal
2021
- 2021 on standard contractual clauses between controllers and processors
- 2021 on standard contractual clauses for the transfer of personal data to third countries
- 2021 on the Data Governance Act proposal
- 2021 on the EU Digital COVID Certificate
- 2021 on the Artificial Intelligence Act proposal
(No joint opinion identified for 2024.)
EDPB Opinions under Article 70(1)(s) GDPR (Adequacy Decisions)
Opinions to the European Commission on draft adequacy findings for third countries, distinct from the GDPR-interpretive Guidelines above.
2025
- 2025 on the extension of UK adequacy (GDPR and LED)
- 2025 on adequacy of the European Patent Organisation
- 2025 on UK adequacy renewal under the GDPR
- 2025 on UK adequacy renewal under the LED
- 2025 on adequacy of Brazil
2023
2021
- 2021 on UK adequacy under the GDPR
- 2021 on UK adequacy under the LED
- 2021 on the Tobacco Traceability System
- 2021 on adequacy of the Republic of Korea
(No dedicated Art. 70 opinion identified for 2022 or 2024 — the January 2024 review of 11 legacy adequacy decisions was handled via an EDPB letter, not a numbered opinion.)
Pre-GDPR — Endorsed by EDPB
- WORKING PARTY 29 POSITION PAPER on the derogations from the obligation to maintain records of processing activities pursuant to Article 30(5) GDPR
- EDPB Guidelines on the right to data portability - WP242 rev.01
- Guidelines on Data Protection Officers (‘DPOs’) (wp243rev.01)
- Guidelines for identifying a controller or processor’s lead supervisory authority wp244
- 679, WP250 rev.01
- 679 wp251
- EDPB Guidelines on transparency under Regulation 2016-679, WP260 rev.01
- 679 WP248
- EDPB Guidelines on Consent under GDPR WP259 —
superseded bysee EDPB Guidelines 2020-05 on consent under GDPR (kept for reference) Guidelines for identifying a controller or processor’s lead supervisory authority, WP244 rev.01— superseded by 2022 on identifying a controller or processor’s lead supervisory authorityRecommendation on the Standard Application for Approval of Controller Binding Corporate Rules, WP 264— superseded by 2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)
- Guidelines on DPIA and determining whether processing is “likely to result in a high risk”, WP248 rev.01
- Working Document Setting Forth a Co-Operation Procedure for the approval of “Binding Corporate Rules”, WP 263 rev.01
- Recommendation on the Standard Application form for Approval of Processor Binding Corporate Rules, WP 265
Working Document setting up a table with the elements and principles to be found in Binding Corporate Rules, WP 256 rev.01— superseded by 2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)- Working Document setting up a table with the elements and principles to be found in Processor Binding Corporate Rules, WP 257 rev.01
- Adequacy Referential, WP 254 rev.01
- Guidelines on the application and setting of administrative fines for the purposes of Regulation 2016/679, WP 253
Pre-GDPR — Not Endorsed by EDPB
- 2017 on processing personal data in the context of Cooperative Intelligent Transport Systems (C-ITS) - wp252
- 2012 on Cloud Computing
- 2017 on data processing at work - wp249
- 2012 on Cookie Consent Exemption
Other Resources
- List of all EDPB Guidelines Flowcharts
- 🇫🇷 CNIL Guidelines — French CNIL guidelines, délibérations and recommandations