EDPB Guidelines
Guidelines and recommendations issued by the European Data Protection Board (EDPB), mapped to the GDPR articles they interpret.
- EDPB 203
EDPB- 203
- EDPB 2/2018Arts 44, 45, 46, 47, 49
Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679
Interpretation and application of the derogations for specific situations set out in Article 49 GDPR for international transfers of personal data in the absence of an adequacy decision or appropriate safeguards.
- EDPB 05/2021Arts 3, 44, 45, 46, 47, 48…
Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR
Clarifies when a processing activity qualifies as a transfer under Chapter V and how Article 3 (territorial scope) interacts with the transfer regime.
- EDPB 07/2022Arts 42, 43, 46
Guidelines 07/2022 on certification as a tool for transfers
Provides guidance on the use of certification under Article 42 GDPR as an appropriate safeguard for international transfers of personal data under Article 46(2)(f).
- EDPB 01/2021Arts 32, 33, 34
Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
Practice-oriented, case-based guidance illustrating breach notification obligations under Articles 33 and 34 GDPR, including risk assessment and mitigation measures.
- EDPB 04/2022Arts 83
Guidelines 04/2022 on the calculation of administrative fines under the GDPR
Harmonises the methodology used by supervisory authorities when calculating administrative fines under Article 83 GDPR.
- EDPB 02/2022Arts 56, 60, 61, 64, 65, 77…
Guidelines 02/2022 on the application of Article 60 GDPR
Explains how the lead supervisory authority and the supervisory authorities concerned cooperate under the one-stop-shop mechanism of Article 60 GDPR, covering the draft decision, relevant and reasoned objections, and the adoption and notification of final decisions.
- EDPB 08/2020Arts 4, 5, 6, 9, 13, 14…
Guidelines 08/2020 on the targeting of social media users
Addresses joint controllership between targeters and social media providers, applicable lawful bases, transparency and special category data when targeting users on social media platforms.
- EDPB 02/2021 (Rec.)Arts 5, 6, 7, 25, 32
Recommendations 02/2021 on the legal basis for the storage of credit card data for the sole purpose of facilitating further online transactions
Sets out that storing a customer's credit card data after a purchase, solely to make future online transactions easier, requires the data subject's consent under Article 6(1)(a) GDPR and cannot rely on contractual necessity or legitimate interests.
- EDPB 01/2023Arts 44, 45, 46, 49
Guidelines 01/2023 on Article 37 Law Enforcement Directive
Clarifies the conditions for transfers of personal data to third countries under Article 37 of the Law Enforcement Directive (EU) 2016/680, where transfers rely on appropriate safeguards in a legally binding instrument or on an assessment by the competent authority.
- EDPB 02/2021Arts 5, 6, 9, 13, 14, 25…
Guidelines 02/2021 on Virtual Voice Assistants
Identifies the most relevant compliance challenges for virtual voice assistants and recommends measures on lawful basis, transparency, data minimisation, and security.
- EDPB 01/2022Arts 12, 15
Guidelines 01/2022 on data subject rights - Right of access
Detailed guidance on the scope of the right of access, how controllers must respond to requests, permissible limitations, and the modalities of providing the information.
- EDPB 06/2022Arts 57, 60, 77
Guidelines 06/2022 on the practical implementation of amicable settlements
Guidance on the use of amicable settlements to resolve complaints under Article 77 GDPR within the one-stop-shop cooperation mechanism.
- EDPB 8/2022Arts 4, 56
Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority
Targeted update endorsing and refining WP29 guidelines on how to determine the lead supervisory authority of a controller or processor with cross-border processing.
- EDPB 01/2020Arts 44, 45, 46, 47, 48, 49
Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data
Post-Schrems II roadmap for exporters: a six-step methodology to map transfers, assess third-country law and adopt technical, contractual and organisational supplementary measures. Version 2.0, adopted 18 June 2021.
- EDPB 10/2020Arts 5, 12, 13, 14, 15, 16…
Guidelines 10/2020 on restrictions under Article 23 GDPR
Explains how Union or Member State law may restrict data subject rights and controller obligations under Article 23, including the necessity, proportionality and essence-of-rights test and the safeguards each restriction must contain. Version 2.1, adopted 13 October 2021.
- EDPB 04/2021Arts 40, 41, 44, 46
Guidelines 04/2021 on Codes of Conduct as tools for transfers
Sets out the requirements for approving a code of conduct as an appropriate safeguard for international transfers, including binding and enforceable commitments by non-EEA controllers and processors, and the role of the monitoring body. Version 2.0, adopted 22 February 2022.
- EDPB 01/2022 (BCR-C)Arts 46, 47
Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)
Updated application form and the mandatory elements and principles for Controller Binding Corporate Rules, aligned with Schrems II, covering binding effect, transparency, third-country legislation assessments and cooperation duties. Adopted 20 June 2023.
- EDPB 05/2022Arts 4, 5, 6, 9, 22, 35
Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement
Analyses the deployment of facial recognition by law enforcement under the Law Enforcement Directive and the Charter, addressing biometric data, strict necessity, legal basis and safeguards, with practical scenarios. Version 2.0, adopted 26 April 2023.
- EDPB 02/2023Arts 4, 6, 7
Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive
Clarifies which tracking techniques beyond cookies fall within Article 5(3) ePrivacy Directive — URL and pixel tracking, local processing, IoT reporting, unique identifiers — and how the consent requirement interacts with the GDPR. Version 2.0, adopted 7 October 2024.