CoE Framework Convention signatory
This content is for informational and educational purposes only and does not constitute legal advice.
On 14 April 2026, the European Data Protection Board opened a consultation on a template for data protection impact assessments under the General Data Protection Regulation (GDPR), until 9 June 2026. The template applies to controllers undertaking high-risk processing activities, including large-scale processing of special categories of personal data, systematic monitoring of publicly accessible areas, automated decision-making with legal or similarly significant effects on individuals, profiling, matching or combining datasets, and processing involving vulnerable data subjects. It requires controllers to document a systematic description of the processing activity covering data types, purposes, data flows, and supporting technical assets, and analyse lawfulness under Article 6 of the GDPR, including legitimate interests balancing tests where applicable. It also requires controllers to demonstrate compliance with data minimisation, retention, and data quality obligations and detail measures supporting data subjects' rights, data protection by design and by default, and security of processing. Controllers must further assess the necessity and proportionality of the processing, conduct an inherent risk assessment identifying threats arising both from deliberate design choices and from accidental or unlawful events, and develop an action plan setting out additional mitigating measures alongside a residual risk assessment. The template also requires documentation of the Data Protection Officer's advice and, where appropriate, the views of data subjects or their representatives, before concluding with a formal decision to approve, conditionally approve, reject, or refer the processing to the relevant supervisory authority.
On 14 April 2026, the European Commission opened a consultation on the draft implementing regulation laying down the minimum metadata elements and their characteristics to be provided by health data holders for dataset descriptions for the secondary use of electronic health data until 12 May 2026. The implementing regulation was issued in line with Article 77(1) of Regulation 2025/327 establishing the European Health Data Space. The draft implementing regulation requires health data holders to express minimum metadata elements using the definitions, structure, cardinalities, and controlled vocabularies set out in the HealthDCAT-AP. The minimum metadata elements, listed in Part B of the Annex, include access rights, applicable legislation, coding system, custodian, distribution, geographical coverage, health category, health data access body, identifier, provenance, temporal coverage, and variables. The HealthDCAT-AP builds on the general DCAT-Application Profile and is developed and maintained by the Commission to support the description of health datasets made available for the secondary use of electronic health data.
On 9 April 2026, the European Data Protection Board (EDPB) published its annual report 2025. The report covers the EDPB's activities during the year, including the adoption of guidelines on pseudonymisation, blockchain technologies, and the interplay between the General Data Protection Regulation (GDPR) and other digital legislation, including the Digital Services Act and Digital Markets Act. It also highlights opinions on adequacy decisions for the United Kingdom, Brazil, and the European Patent Organisation. The report includes enforcement actions of organisations across the European Economic Area, with enforcement data covering 30 jurisdictions and total fines of over EUR 1.14 billion issued by national data protection authorities during the year. It also documents progress under the Helsinki statement on enhanced clarity, support and engagement, the coordinated enforcement action on the right to erasure, and the work of the support pool of experts on Artificial Intelligence (AI) and data protection. It was also stated that the report will be followed by a series of deliverables in 2026, including a data protection impact assessment template, a common data breach notification template, and joint guidelines on the interplay between the AI Act and data protection law.
On 9 April 2026, the European Commission closes the consultation on the draft Implementing Regulation on detailed arrangements for the conduct of certain proceedings pursuant to the Artificial Intelligence Act. The draft stipulates that when the Commission adopts a decision requesting access, the provider must furnish all necessary elements in a timely and effective manner. This access may include application programming interfaces (APIs), internal access, source code, model weights, and the infrastructure used for hosting the model. The Commission may also require providers to disable logging measures that could track or record the Commission's access. The draft mandates that providers allow the Commission to inspect and modify system state interactions. Furthermore, the draft clarifies that the access granted should match the levels available to the provider's own employees. The Implementing Regulation is set to enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
Last updated: 17/09/2026