---
title: "\U0001F1EA\U0001F1FA EDPB Guidelines"
icon: "\U0001F1EA\U0001F1FA"
notion_url: 'https://www.notion.so/156ec4618823806ca65bf2bfeb02087e'
tags:
  - GDPR
  - EDPB
  - data-protection
modified: null
---

> [[List of all EDPB Guidelines Flowcharts]] · [[🇫🇷 CNIL Guidelines]]

**Legend**: 🇪🇺 All done! | 🤖 Working on it | ☠️ Obsolete

## 2026

- [[EDPB Guidelines 2026-01 on processing of personal data for scientific research purposes]]
- [[EDPB Guidelines 2026-02 on Anonymisation]]
- [[EDPB Guidelines 2026-03 on web scraping in the context of generative AI]]
- 🤖 [[Recommendations 1/2026 on the Application for Approval and on the elements and principles to be found in Processor Binding Corporate Rules (Art. 47 GDPR)]]

## 2025

- [[EDPB Position Paper 2025-01 on Interplay between data protection and competition law]]
- [[SiteMap/Guidelines/EDPB Guidelines/EDPB Guidelines 2025-01 on Pseudonymisation]]
- [[EDPB Guidelines 2025-02 on processing of personal data through blockchain technologies (v1.1)|EDPB Guidelines 2025-02 on processing of personal data through blockchain technologies — v1.1 (consultation)]]
- [[EDPB Guidelines 2025-02 on processing of personal data through blockchain technologies (v2.0)|EDPB Guidelines 2025-02 on processing of personal data through blockchain technologies — v2.0 (final)]]
- [[SiteMap/Guidelines/EDPB Guidelines/AI-Complex Algorithms and effective Data Protection Supervision - Bias evaluation]]
- [[SiteMap/Guidelines/EDPB Guidelines/AI-Complex Algorithms and effective Data Protection Supervision - Effective implementation of data subjects’ rights]]
- [[SiteMap/Guidelines/EDPB Guidelines/EDPB Statement 2025-01 on Age Assurance]]
- [[EDPB Recommendations 2025-02 on the legal basis for requiring the creation of user accounts on e-commerce websites]]
- 🤖 [[Recommendations 1/2025 on the 2027 WADA World Anti-Doping Code]]
- 🤖 [[Guidelines 3/2025 on the interplay between the DSA and the GDPR]]
- 🤖 [[Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation]]
- 🤖 [[Coordinated Supervision Committee Report of Activities 2022-2024]]

## 2024

- [[SiteMap/Guidelines/EDPB Guidelines/EDPB Guidelines 2024-01 on processing of personal data based on Article 6(1)(f) GDPR]]
- [[EDPB Guidelines 2024-02 on Article 48 GDPR (v1 - consultation)|EDPB Guidelines 2024-02 on Article 48 GDPR — v1 (consultation)]]
- [[EDPB Guidelines 2024-02 on Article 48 GDPR (v2 - final)|EDPB Guidelines 2024-02 on Article 48 GDPR — v2 (final)]]
- [[EDPB Opinion 2024-04 on the notion of main establishment of a controller in the Union under Art. 4.16(a) GDPR]]
- 🤖 [[Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms]]
- 🤖 [[Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)]]
- [[EDPB Opinion 2024-28 on certain data protection aspects related to the processing of personal data in the context of AI models]]

## 2023

- 🤖 [[Guidelines 01/2023 on Article 37 Law Enforcement Directive]]
- [[EDPB Guidelines 2023-02 on Technical Scope of Art. 5(3) of ePrivacy Directive]]

## 2022

- [[EDPB Guidelines 2022-01 on data subject rights - Right of access]]
- 🤖 [[Guidelines 02/2022 on the application of Article 60 GDPR]]
- 🤖 [[Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces - how to recognise and avoid them]]
- [[EDPB Guidelines 2022-04 on the calculation of administrative fines under the GDPR]]
- 🤖 [[Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement]]
- [[EDPB Guidelines 2022-06 on the practical implementation of amicable settlements]]
- 🤖 [[Guidelines 07/2022 on certification as a tool for transfers]]
- 🤖 [[Guidelines 08/2022 on identifying a controller or processor's lead supervisory authority]]
- [[EDPB Guidelines 2022-09 on personal data breach notification under GDPR]]
- 🤖 [[Recommendations 01/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)]]
- 🤖 [[Statement 02/2022 on personal data transfers to the Russian Federation]]

## 2021

- [[SiteMap/Guidelines/EDPB Guidelines/EDPB Guidelines 2021-01 on Examples regarding Personal Data Breach Notification]]
- 🤖 [[Guidelines 02/2021 on virtual voice assistants]]
- [[EDPB Guidelines 2021-03 on the application of Article 65(1)(a) GDPR]]
- 🤖 [[Guidelines 04/2021 on Codes of Conduct as tools for transfers]]
- [[EDPB Guidelines 2021-05 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR]]
- 🤖 [[Recommendations 01/2021 on the adequacy referential under the Law Enforcement Directive]]
- 🤖 [[Recommendations 02/2021 on the legal basis for the storage of credit card data for the sole purpose of facilitating further online transactions]]

## 2020

- 🤖 [[Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications]]
- [**Guidelines 2/2020 on articles 46(2)(a) and 46(3)(b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies**](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-22020-articles-46-2-and-46-3-b-regulation_en)
- [**Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak**](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-032020-processing-data-concerning-health-purpose_en)
- [**Guidelines 04/2020 on the use of location data and contact tracing tools in the context of the COVID-19 outbreak**](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-042020-use-location-data-and-contact-tracing_en)
- [[EDPB Guidelines 2020-05 on consent under GDPR]]
- 🤖 [[Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR]]
- [[EDPB Guidelines 2020-07 on the concepts of controller and processor in the GDPR]]
- [[EDPB Guidelines 2020-08 on the targeting of social media users]]
- [**Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679**](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-092020-relevant-and-reasoned-objection-under_en)
- 🤖 [[Guidelines 10/2020 on restrictions under Article 23 GDPR]]
- [**Guidance on certification criteria assessment (Addendum to Guidelines 1/2018)**](https://www.edpb.europa.eu/our-work-tools/documents/public-consultations/2021/guidance-certification-criteria-assessment_en)
- 🤖 [[Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data]]
- [**Recommendations 02/2020 on the European Essential Guarantees for surveillance measures**](https://www.edpb.europa.eu/our-work-tools/our-documents/recommendations/recommendations-022020-european-essential-guarantees_en)

## 2019

- 🤖 [[Recommendation 01/2019 on the draft list of the European Data Protection Supervisor regarding the processing operations subject to the requirement of a data protection impact assessment (Article 39.4 of Regulation (EU) 2018/1725)]]
- [**Guidelines 4/2019 on Article 25 Data Protection by Design and by Default**](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-42019-article-25-data-protection-design-and_en)
- [**Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1)**](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-52019-criteria-right-be-forgotten-search-engines_en)
- [**Guidelines 3/2019 on processing of personal data through video devices**](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-32019-processing-personal-data-through-video_en)
- 🤖 [[Guidelines 02/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects]]
- [**Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679**](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-12019-codes-conduct-and-monitoring-bodies-0_en)
- [[Opinion 05/2019 on the interplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities]]
- [[Guidelines 04/2019 on Article 25 Data Protection by Design and by Default]]

## 2018 & Before

- [[EDPB Guidelines 2018-02 on derogations of Article 49 under Regulation 2016-679]]
- [[2018 on the territorial scope of the GDPR (Article 3) Version 2.1]]
- [**Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation**](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-12018-certification-and-identifying_en)
- [**Guidelines 1/2018 on certification and identifying certification criteria — Annex 2**](https://www.edpb.europa.eu/our-work-tools/documents/public-consultations/2019/guidelines-12018-certification-and-identifying_en)
- [**Guidelines 4/2018 on the accreditation of certification bodies under Article 43 GDPR**](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-42018-accreditation-certification-bodies-under_en)

## EDPB/EDPS Joint Opinions on EU Legislative Proposals

*Art. 42 Regulation (EU) 2018/1725 — consultations on draft EU legislation, distinct from the GDPR-interpretive Guidelines above.*

### 2026

- [[EDPB-EDPS Joint Opinion 1/2026 on the Digital Omnibus on AI]]
- [[EDPB-EDPS Joint Opinion 2026-02 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (Digital Omnibus)]]
- [[EDPB-EDPS Joint Opinion 3/2026 on the European Biotech Act proposal]]
- [[EDPB-EDPS Joint Opinion 4/2026 on the Cybersecurity Act 2 and NIS2 Directive amendments]]

### 2025

- [[EDPB-EDPS Joint Opinion 1/2025 on SME/SMC simplification (Article 30(5) GDPR record-keeping)]]

### 2023

- [[EDPB-EDPS Joint Opinion 1/2023 on procedural rules relating to GDPR enforcement]]
- [[EDPB-EDPS Joint Opinion 2/2023 on the Digital Euro Regulation proposal]]

### 2022

- [[EDPB-EDPS Joint Opinion 2/2022 on the Data Act proposal]]
- [[EDPB-EDPS Joint Opinion 3/2022 on the European Health Data Space proposal]]
- [[EDPB-EDPS Joint Opinion 4/2022 on the Child Sexual Abuse (CSAM) Regulation proposal]]

### 2021

- [[EDPB-EDPS Joint Opinion 1/2021 on standard contractual clauses between controllers and processors]]
- [[EDPB-EDPS Joint Opinion 2/2021 on standard contractual clauses for the transfer of personal data to third countries]]
- [[EDPB-EDPS Joint Opinion 3/2021 on the Data Governance Act proposal]]
- [[EDPB-EDPS Joint Opinion 4/2021 on the EU Digital COVID Certificate]]
- [[EDPB-EDPS Joint Opinion 5/2021 on the Artificial Intelligence Act proposal]]

*(No joint opinion identified for 2024.)*

## EDPB Opinions under Article 70(1)(s) GDPR (Adequacy Decisions)

*Opinions to the European Commission on draft adequacy findings for third countries, distinct from the GDPR-interpretive Guidelines above.*

### 2025

- [[Opinion 06/2025 on the extension of UK adequacy (GDPR and LED)]]
- [[Opinion 07/2025 on adequacy of the European Patent Organisation]]
- [[Opinion 26/2025 on UK adequacy renewal under the GDPR]]
- [[Opinion 27/2025 on UK adequacy renewal under the LED]]
- [[Opinion 28/2025 on adequacy of Brazil]]

### 2023

- [[Opinion 5/2023 on the EU-US Data Privacy Framework]]

### 2021

- [[Opinion 14/2021 on UK adequacy under the GDPR]]
- [[Opinion 15/2021 on UK adequacy under the LED]]
- [[Opinion 20/2021 on the Tobacco Traceability System]]
- [[Opinion 32/2021 on adequacy of the Republic of Korea]]

*(No dedicated Art. 70 opinion identified for 2022 or 2024 — the January 2024 review of 11 legacy adequacy decisions was handled via an EDPB letter, not a numbered opinion.)*

## Pre-GDPR — Endorsed by EDPB

- [[WORKING PARTY 29 POSITION PAPER on the derogations from the obligation to maintain records of processing activities pursuant to Article 30(5) GDPR]]
- [[EDPB Guidelines on the right to data portability - WP242 rev.01]]
- [[Guidelines on Data Protection Officers ('DPOs') (wp243rev.01)]]
- [[Guidelines for identifying a controller or processor's lead supervisory authority wp244]]
- [[Guidelines on Personal data breach notification under Regulation 2016/679, WP250 rev.01]]
- [[Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679 wp251]]
- [[EDPB Guidelines on transparency under Regulation 2016-679, WP260 rev.01]]
- [[Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is "likely to result in a high risk" for the purposes of Regulation 2016/679 WP248]]
- [[EDPB Guidelines on Consent under GDPR WP259]] — ~~superseded by~~ see [[EDPB Guidelines 2020-05 on consent under GDPR]] (kept for reference)
- ~~**Guidelines for identifying a controller or processor's lead supervisory authority, WP244 rev.01**~~ — superseded by [[Guidelines 08/2022 on identifying a controller or processor's lead supervisory authority]]
- ~~**Recommendation on the Standard Application for Approval of Controller Binding Corporate Rules, WP 264**~~ — superseded by [[Recommendations 01/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)]]

1. [**Guidelines on DPIA and determining whether processing is "likely to result in a high risk", WP248 rev.01**](http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=611236)
2. [**Working Document Setting Forth a Co-Operation Procedure for the approval of "Binding Corporate Rules", WP 263 rev.01**](http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=623056)
3. [**Recommendation on the Standard Application form for Approval of Processor Binding Corporate Rules, WP 265**](http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=623848)
4. ~~**Working Document setting up a table with the elements and principles to be found in Binding Corporate Rules, WP 256 rev.01**~~ — superseded by [[Recommendations 01/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)]]
5. [**Working Document setting up a table with the elements and principles to be found in Processor Binding Corporate Rules, WP 257 rev.01**](http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=614110)
6. [**Adequacy Referential, WP 254 rev.01**](http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=614108)
7. [**Guidelines on the application and setting of administrative fines for the purposes of Regulation 2016/679, WP 253**](http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=611237)

## Pre-GDPR — *Not* Endorsed by EDPB

- [[Opinion 03/2017 on processing personal data in the context of Cooperative Intelligent Transport Systems (C-ITS) - wp252]]
- [[Opinion 05/2012 on Cloud Computing]]
- [[Opinion 02/2017 on data processing at work - wp249]]
- [[Opinion 04/2012 on Cookie Consent Exemption]]

## Other Resources

- [[List of all EDPB Guidelines Flowcharts]]
- [[🇫🇷 CNIL Guidelines]] — French CNIL guidelines, délibérations and recommandations
