CoE Framework Convention signatory
This content is for informational and educational purposes only and does not constitute legal advice.
On 14 April 2026, the European Data Protection Board opened a consultation on a template for data protection impact assessments under the General Data Protection Regulation (GDPR), until 9 June 2026. The template applies to controllers undertaking high-risk processing activities, including large-scale processing of special categories of personal data, systematic monitoring of publicly accessible areas, automated decision-making with legal or similarly significant effects on individuals, profiling, matching or combining datasets, and processing involving vulnerable data subjects. It requires controllers to document a systematic description of the processing activity covering data types, purposes, data flows, and supporting technical assets, and analyse lawfulness under Article 6 of the GDPR, including legitimate interests balancing tests where applicable. It also requires controllers to demonstrate compliance with data minimisation, retention, and data quality obligations and detail measures supporting data subjects' rights, data protection by design and by default, and security of processing. Controllers must further assess the necessity and proportionality of the processing, conduct an inherent risk assessment identifying threats arising both from deliberate design choices and from accidental or unlawful events, and develop an action plan setting out additional mitigating measures alongside a residual risk assessment. The template also requires documentation of the Data Protection Officer's advice and, where appropriate, the views of data subjects or their representatives, before concluding with a formal decision to approve, conditionally approve, reject, or refer the processing to the relevant supervisory authority.
On 14 April 2026, the European Commission opened a consultation on the draft implementing regulation laying down the minimum metadata elements and their characteristics to be provided by health data holders for dataset descriptions for the secondary use of electronic health data until 12 May 2026. The implementing regulation was issued in line with Article 77(1) of Regulation 2025/327 establishing the European Health Data Space. The draft implementing regulation requires health data holders to express minimum metadata elements using the definitions, structure, cardinalities, and controlled vocabularies set out in the HealthDCAT-AP. The minimum metadata elements, listed in Part B of the Annex, include access rights, applicable legislation, coding system, custodian, distribution, geographical coverage, health category, health data access body, identifier, provenance, temporal coverage, and variables. The HealthDCAT-AP builds on the general DCAT-Application Profile and is developed and maintained by the Commission to support the description of health datasets made available for the secondary use of electronic health data.
On 9 April 2026, the European Data Protection Board (EDPB) published its annual report 2025. The report covers the EDPB's activities during the year, including the adoption of guidelines on pseudonymisation, blockchain technologies, and the interplay between the General Data Protection Regulation (GDPR) and other digital legislation, including the Digital Services Act and Digital Markets Act. It also highlights opinions on adequacy decisions for the United Kingdom, Brazil, and the European Patent Organisation. The report includes enforcement actions of organisations across the European Economic Area, with enforcement data covering 30 jurisdictions and total fines of over EUR 1.14 billion issued by national data protection authorities during the year. It also documents progress under the Helsinki statement on enhanced clarity, support and engagement, the coordinated enforcement action on the right to erasure, and the work of the support pool of experts on Artificial Intelligence (AI) and data protection. It was also stated that the report will be followed by a series of deliverables in 2026, including a data protection impact assessment template, a common data breach notification template, and joint guidelines on the interplay between the AI Act and data protection law.
On 9 April 2026, the European Commission closes the consultation on the draft Implementing Regulation on detailed arrangements for the conduct of certain proceedings pursuant to the Artificial Intelligence Act. The draft stipulates that when the Commission adopts a decision requesting access, the provider must furnish all necessary elements in a timely and effective manner. This access may include application programming interfaces (APIs), internal access, source code, model weights, and the infrastructure used for hosting the model. The Commission may also require providers to disable logging measures that could track or record the Commission's access. The draft mandates that providers allow the Commission to inspect and modify system state interactions. Furthermore, the draft clarifies that the access granted should match the levels available to the provider's own employees. The Implementing Regulation is set to enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
On 9 April 2026, the European Commission closes the consultation on the draft Implementing Regulation on detailed arrangements for the conduct of certain proceedings pursuant to the Artificial Intelligence Act. The draft outlines the procedures for initiating and concluding proceedings against providers of general-purpose AI models. It also provides for the possibility of interim measures in urgent situations where risks to health or safety may arise. The draft sets out procedural safeguards, including the right of addressees to submit written observations on preliminary findings within a minimum period of 14 days. The draft further establishes rules on the identification and protection of business secrets, allowing non-confidential versions of documents to be disclosed to legal counsel and experts under specified conditions. It also sets limitation periods for enforcement, including a five-year period for the Commission to impose fines for infringements. In addition, the draft specifies requirements for digital communication with the Commission, including the use of qualified electronic signatures for submitted documents. It outlines criteria for assessing the independence of experts involved in evaluations, requiring that they have no shared ownership, governance, or contractual relationships with AI providers during the 12 months preceding the evaluation. Appointed experts must also commit to safeguarding the confidentiality, availability, and integrity of sensitive information and business secrets accessed during testing activities. The text indicates that experts should generally be selected through open and transparent procedures, while allowing the Commission to appoint members of the scientific panel established under Article 68 of the Artificial Intelligence Act directly. It also provides that such appointments may be made in accordance with the procedure set out in Article 167 of the EU Financial Regulation. The draft is expected to enter into force on the twentieth day following its publication in the Official Journal of the European Union.
On 8 April 2026, the European Union and Morocco announced the launch of a digital dialogue on strategic cooperation. It covers several areas, including the rollout of secure and trusted digital networks and artificial intelligence (AI) compute infrastructure, the exchange of practices related to AI ecosystems, collaboration between Moroccan AI research institutes and EU AI Factories, e-governance and digital public infrastructure partnerships, and support for start-ups. It also addresses interoperability between EU and Moroccan digital frameworks, including digital wallets. The dialogue is linked to Morocco's "Digital Morocco 2030" strategy and to commitments set out in the EU's Pact for the Mediterranean.
On 30 March 2026, the European Commission closes the consultation on the second draft Code of Practice on Transparency of AI-Generated Content. The Code of Practice addresses obligations under Article 50 of the AI Act for providers and deployers of AI systems generating content. It comprises two sections, one covering rules for marking and detection of AI-generated and manipulated content applicable to providers of generative AI systems under Article 50(2) and (5) AI Act, and another covering rules for labelling of deepfakes and AI-generated and manipulated published text applicable to deployers of AI systems under Article 50(4) and (5) AI Act. The second draft incorporates feedback from stakeholders. The transparency obligations under the AI Act become applicable on 2 August 2026.
Last updated: 02/08/2026