CHAPTER VIICOOPERATION AND CONSISTENCY

Article 70Tasks of the Board

Official text

(1)The Board shall ensure the consistent application of this Regulation. To that end, the Board shall, on its own initiative or, where relevant, at the request of the Commission, in particular:

(a)monitor and ensure the correct application of this Regulation in the cases provided for in Articles 64 and 65 without prejudice to the tasks of national supervisory authorities;

(b)advise the Commission on any issue related to the protection of personal data in the Union, including on any proposed amendment of this Regulation;

(c)advise the Commission on the format and procedures for the exchange of information between controllers, processors and supervisory authorities for binding corporate rules;

(d)issue guidelines, recommendations, and best practices on procedures for erasing links, copies or replications of personal data from publicly available communication services as referred to in Article 17 (2);

(e)examine, on its own initiative, on request of one of its members or on request of the Commission, any question covering the application of this Regulation and issue guidelines, recommendations and best practices in order to encourage consistent application of this Regulation;

(f)issue guidelines, recommendations and best practices in accordance with point (e) of this paragraph for further specifying the criteria and conditions for decisions based on profiling pursuant to Article 22 (2);

(g)issue guidelines, recommendations and best practices in accordance with point (e) of this paragraph for establishing the personal data breaches and determining the undue delay referred to in Article 33 (1) and (2) and for the particular circumstances in which a controller or a processor is required to notify the personal data breach;

(h)issue guidelines, recommendations and best practices in accordance with point (e) of this paragraph as to the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of the natural persons referred to in Article 34 (1).

(i)issue guidelines, recommendations and best practices in accordance with point (e) of this paragraph for the purpose of further specifying the criteria and requirements for personal data transfers based on binding corporate rules adhered to by controllers and binding corporate rules adhered to by processors and on further necessary requirements to ensure the protection of personal data of the data subjects concerned referred to in Article 47;

(j)issue guidelines, recommendations and best practices in accordance with point (e) of this paragraph for the purpose of further specifying the criteria and requirements for the personal data transfers on the basis of Article 49 (1);

(k)draw up guidelines for supervisory authorities concerning the application of measures referred to in Article 58 (1),

(2)and (3) and the setting of administrative fines pursuant to Article 83;

(l)review the practical application of the guidelines, recommendations and best practices;

(m)issue guidelines, recommendations and best practices in accordance with point (e) of this paragraph for establishing common procedures for reporting by natural persons of infringements of this Regulation pursuant to Article 54 (2);

(n)encourage the drawing-up of codes of conduct and the establishment of data protection certification mechanisms and data protection seals and marks pursuant to Articles 40 and 42;

(o)approve the criteria of certification pursuant to Article 42 (5) and maintain a public register of certification mechanisms and data protection seals and marks pursuant to Article 42 (8) and of the certified controllers or processors established in third countries pursuant to Article 42 (7);

(p)approve the requirements referred to in Article 43 (3) with a view to the accreditation of certification bodies referred to in Article 43;

(q)provide the Commission with an opinion on the certification requirements referred to in Article 43 (8);

(r)provide the Commission with an opinion on the icons referred to in Article 12 (7);

(s)provide the Commission with an opinion for the assessment of the adequacy of the level of protection in a third country or international organisation, including for the assessment whether a third country, a territory or one or more specified sectors within that third country, or an international organisation no longer ensures an adequate level of protection. To that end, the Commission shall provide the Board with all necessary documentation, including correspondence with the government of the third country, with regard to that third country, territory or specified sector, or with the international organisation.

(t)issue opinions on draft decisions of supervisory authorities pursuant to the consistency mechanism referred to in Article 64 (1), on matters submitted pursuant to Article 64 (2) and to issue binding decisions pursuant to Article 65, including in cases referred to in Article 66;

(u)promote the cooperation and the effective bilateral and multilateral exchange of information and best practices between the supervisory authorities;

(v)promote common training programmes and facilitate personnel exchanges between the supervisory authorities and, where appropriate, with the supervisory authorities of third countries or with international organisations;

(w)promote the exchange of knowledge and documentation on data protection legislation and practice with data protection supervisory authorities worldwide.

(x)issue opinions on codes of conduct drawn up at Union level pursuant to Article 40 (9); and

(y)maintain a publicly accessible electronic register of decisions taken by supervisory authorities and courts on issues handled in the consistency mechanism.

(2)Where the Commission requests advice from the Board, it may indicate a time limit, taking into account the urgency of the matter.

(3)The Board shall forward its opinions, guidelines, recommendations, and best practices to the Commission and to the committee referred to in Article 93 and make them public.

(4)The Board shall, where appropriate, consult interested parties and give them the opportunity to comment within a reasonable period. The Board shall, without prejudice to Article 76, make the results of the consultation procedure publicly available.

Commentary

Article 70 is the EDPB’s functional mandate. Article 68 creates the Board, Article 69 protects its independence, and Article 70 explains what the Board must actually do to secure a coherent European data protection system.

Its central purpose can be stated simply:

The EDPB must help ensure that one GDPR is interpreted and applied consistently throughout the European Union, while national supervisory authorities remain responsible for ordinary investigations and enforcement.

Article 70 gives the Board several different kinds of functions. It acts as:

  • a consistency body;
  • a dispute-resolution body;
  • an interpretive guidance body;
  • an adviser to the European Commission;
  • a promoter of supervisory cooperation;
  • a coordinator of training and international regulatory exchange;
  • a contributor to codes of conduct and certification;
  • a keeper of public consistency records.

These functions do not all have the same legal effect. An Article 65 binding decision is legally different from an ordinary guideline, an Article 64 opinion, a recommendation, a best-practice document or general advice to the Commission. Understanding those distinctions is essential.


1. The overriding duty: consistent application of the GDPR

Article 70 begins by stating that the Board“shall ensure the consistent application” of the GDPR.

This is the organising principle for everything that follows.

Consistency means that common GDPR concepts should not be interpreted in materially contradictory ways across Member States without a legally justified reason. It does not mean that every case must have exactly the same result.

Illustration

Suppose two organisations suffer data breaches. The first breach:

  • exposes medical records;
  • affects one million people;
  • remains undetected for six months;
  • creates a serious risk of discrimination and fraud. The second breach:
  • concerns ten business email addresses;
  • is contained within minutes;
  • creates minimal risk. Consistency does not require both organisations to receive the same corrective measure or fine. The cases are materially different. Consistency instead requires authorities to use the same legal principles when assessing:
  • breach severity;
  • risk;
  • delay;
  • mitigation;
  • affected data;
  • notification duties;
  • appropriate corrective action.

Article 70 therefore promotes coherent legal standards, not mechanical uniformity.


2. “Shall ensure” does not make the EDPB a universal European regulator

The wording “shall ensure” is strong, but it must be read with the institutional structure of the GDPR.

National supervisory authorities remain responsible for:

  • receiving complaints;
  • conducting investigations;
  • carrying out audits;
  • exercising Article 58 powers;
  • imposing fines;
  • adopting national decisions;
  • defending those decisions in national courts.

The EDPB does not ordinarily investigate every alleged infringement or issue every GDPR fine.

Article 70(1)(a) expressly says that the Board’s consistency role is without prejudice to the tasks of national supervisory authorities.

Illustration

A restaurant keeps customer reservation details for an excessive period. The national supervisory authority may investigate and order deletion. The EDPB would not normally become the first-instance regulator merely because the dispute involves the GDPR. The EDPB may become relevant if:

  • the processing is cross-border;
  • national authorities disagree;
  • a relevant and reasoned objection is raised;
  • a wider interpretive question emerges;
  • the matter enters the Article 64 or Article 65 consistency mechanism. The EDPB is therefore a European consistency and coordination body, not a substitute for every national authority.

3. “In particular” makes Article 70(1) broad but not unlimited

Article 70 says the Board shall perform the listed tasks“in particular.”

This indicates that the list is extensive but not necessarily closed. The Board may carry out closely related activities reasonably necessary to achieve consistent GDPR application.

However, “in particular” does not give the Board unlimited power.

Every EDPB activity must remain connected to:

  • the GDPR;
  • another relevant EU data protection instrument;
  • the Board’s statutory functions;
  • consistent application;
  • cooperation among supervisory authorities.

Illustration

The Board may create a practical template to help authorities analyse cross-border complaints. That supports Article 70’s cooperation and consistency objectives. It could not use Article 70 to:

  • legislate a new criminal offence;
  • impose a tax;
  • amend the GDPR;
  • regulate an unrelated environmental issue;
  • give itself investigative powers not provided by EU law. Article 70 gives functional flexibility, not general legislative competence.

4. Article 70(1)(a): Monitoring Articles 64 and 65

Point (a) requires the Board to monitor and ensure correct GDPR application in the cases covered by:

  • Article 64 opinions; and
  • Article 65 binding dispute resolution.

4.1 Article 64 matters

Article 64 requires or permits EDPB opinions on matters such as:

  • lists of processing operations requiring DPIAs;
  • transnational codes of conduct;
  • accreditation requirements;
  • standard data protection clauses;
  • bespoke transfer clauses;
  • binding corporate rules;
  • matters of general application;
  • matters affecting more than one Member State.

The EDPB reviews the proposed measure before the competent supervisory authority adopts its final decision.

Illustration

A national authority proposes standard controller-processor clauses. The EDPB examines whether they properly address:

  • documented instructions;
  • confidentiality;
  • subprocessors;
  • security;
  • assistance with rights;
  • breach support;
  • deletion or return;
  • audit rights. The EDPB does not become the contracting party. It ensures that the proposed national clauses reflect a consistent interpretation of Article 28.

4.2 Article 65 matters

Article 65 applies where:

  • a lead authority does not follow a relevant and reasoned objection;
  • authorities disagree over the main establishment;
  • a required Article 64 opinion was not requested or followed.

The Board then adopts a binding decision.

[!example] Illustration A lead authority finds only a transparency violation. Another authority argues that the controller also lacked a legal basis and that the proposed corrective action is inadequate. If the objection satisfies Article 4(24) and consensus cannot be reached, the EDPB resolves the defined disagreement under Article 65. Point (a) does not permit the EDPB to absorb every national case. Its role is confined to the consistency routes established by the GDPR.

5. Article 70(1)(b): Advising the Commission

The Board must advise the Commission on any question concerning personal data protection in the Union, including proposed amendments to the GDPR.

This function permits the Commission to obtain specialist, independent advice from the collective body of European data protection authorities.

Potential subjects include:

  • proposed EU legislation;
  • new technologies;
  • artificial intelligence;
  • digital identity;
  • health-data systems;
  • online advertising;
  • cybersecurity laws;
  • international transfers;
  • changes to GDPR enforcement procedures.

Illustration

The Commission proposes legislation requiring online services to verify every user’s identity. The EDPB could advise on:

  • necessity;
  • proportionality;
  • data minimisation;
  • risks to anonymity;
  • retention;
  • security;
  • children;
  • safeguards against function creep. The EDPB’s advice does not replace the legislative process. Parliament and the Council remain the EU legislators. The Commission remains responsible for its legislative proposal.

5.1 Independence of the advice

Article 69 means that the Commission may ask the question but cannot dictate the answer.

A Commission request saying:

“Please analyse the data protection impact of this proposal”

is proper.

A request saying:

“Please issue a favourable opinion stating that this proposal fully complies with the GDPR”

would attempt to control the Board’s independent assessment.

Article 70 authorises advice, not executive instruction.


6. Article 70(1)(c): Information exchange for binding corporate rules

Point (c) requires the Board to advise the Commission on formats and procedures for exchanging information among:

  • controllers;
  • processors;
  • supervisory authorities

in connection with binding corporate rules, or BCRs.

BCRs are internal rules used by multinational groups to support international transfers of personal data.

An application may involve:

  • many corporate entities;
  • several EEA establishments;
  • multiple supervisory authorities;
  • controller and processor activities;
  • transfers to numerous third countries;
  • complex liability and audit structures.

Standardised communication can reduce:

  • repeated requests;
  • conflicting information;
  • inconsistent application forms;
  • uncertainty about the competent authority;
  • delays in approval.

Illustration

A multinational group applies for controller BCRs. A standard procedure may specify:

  • group structure;
  • entities covered;
  • categories of data;
  • transfer destinations;
  • enforceability;
  • rights mechanisms;
  • complaint handling;
  • government-access procedures;
  • audit arrangements;
  • responsible supervisory authority. Point (c) concerns the procedure and format for information exchange. The substantive criteria for valid BCRs arise primarily from Article 47 and the Board’s broader guidance functions.

7. Article 70(1)(d): Erasing links, copies and replications

Point (d) requires guidance on procedures under Article 17(2).

Article 17(2) addresses situations where a controller has made personal data public and must erase it. Taking account of available technology and implementation cost, the controller must take reasonable steps to inform controllers processing that data that the individual requested erasure of links, copies or replications.

This is more complex than deleting one record from one database.

Illustration

A person’s private medical information is unlawfully published on a public website. The information is then:

  • indexed by search engines;
  • copied by archive services;
  • reposted on social media;
  • stored in content-delivery caches;
  • scraped into third-party databases. The original publisher may delete the webpage, but copies may remain accessible elsewhere. EDPB guidance can explain issues such as:
  • which downstream controllers must be contacted;
  • what constitutes a reasonable step;
  • how technology and cost should be considered;
  • how to document notifications;
  • when links should be removed;
  • how to handle replicas and cached copies. Article 17(2) does not impose an absolute duty to guarantee deletion from the entire internet. It requires reasonable steps in light of relevant circumstances. Guidance helps prevent authorities from applying radically different standards.

8. Article 70(1)(e): General guidance power

Point (e) is the Board’s broad interpretive power.

The EDPB may examine any question concerning GDPR application:

  • on its own initiative;
  • at the request of one of its members;
  • at the request of the Commission.

It may then issue:

  • guidelines;
  • recommendations;
  • best practices.

This provision supports guidance on issues not expressly listed elsewhere.

Examples

include:

  • legitimate interests;
  • controller and processor concepts;
  • targeted advertising;
  • connected vehicles;
  • blockchain;
  • pseudonymisation;
  • data protection by design;
  • children’s data;
  • scientific research;
  • facial recognition;
  • generative AI. The EDPB maintains a large public collection of guidelines, opinions, binding decisions and other materials directed at consistent European application.

8.1 Guidelines are not legislation

The EDPB may interpret the GDPR, but it cannot rewrite it.

Illustration

The GDPR says that consent must be freely given, specific, informed and unambiguous. The EDPB may explain:

  • when a power imbalance undermines choice;
  • how withdrawal should work;
  • why pre-ticked boxes are invalid;
  • how consent should be documented. It cannot create a new legal basis requiring consent for every processing operation, because Article 6 recognises several lawful bases.

Although guidelines are generally classified as soft law, they have significant practical importance.

They may influence:

  • supervisory investigations;
  • compliance programmes;
  • court interpretation;
  • DPIAs;
  • legal advice;
  • audit expectations;
  • enforcement priorities.

A controller should not treat EDPB guidance as irrelevant merely because it is not an Article 65 binding decision.

At the same time, authorities and courts must apply the GDPR itself. If a guideline conflicts with the Regulation or binding CJEU case law, the higher legal rule prevails.


9. Article 70(1)(f): Profiling and automated decisions

Point (f) requires guidance concerning the criteria and conditions for decisions based on profiling under Article 22(2).

Article 22 is often misunderstood. It concerns decisions:

  • based solely on automated processing, including profiling;
  • that produce legal effects or similarly significantly affect a person.

Article 22(2) permits such decisions in limited situations, including where:

  • necessary for a contract;
  • authorised by law with safeguards;
  • based on explicit consent.

Illustration

A recruitment system automatically rejects an applicant without human involvement. The EDPB may guide authorities on:

  • whether the decision is solely automated;
  • whether rejection significantly affects the person;
  • whether human review is genuine or superficial;
  • whether automation is genuinely necessary for the contract;
  • whether explicit consent is valid;
  • what safeguards Article 22(3) requires;
  • how meaningful information about logic should be provided. A human clicking “approve” after blindly accepting an algorithmic output may not amount to meaningful human involvement. Point (f) therefore helps distinguish genuine assisted decision-making from nominal human review designed to avoid Article 22.

10. Article 70(1)(g): Establishing and notifying personal data breaches

Point (g) concerns guidance on:

  • determining when a personal data breach exists;
  • interpreting “undue delay”;
  • identifying when controllers must notify authorities;
  • clarifying processor-to-controller notification.

A personal data breach includes a breach of security leading to accidental or unlawful:

  • destruction;
  • loss;
  • alteration;
  • unauthorised disclosure;
  • access.

It is broader than a cyberattack.

Illustrations

  • A laptop containing unencrypted employee records is stolen.
  • An email containing medical data is sent to the wrong recipient.
  • A database is corrupted and no backup exists.
  • A staff member accesses customer information without authorisation.
  • Ransomware makes data unavailable. Each may be a personal data breach.

10.1 The 72-hour rule

Article 33 requires a controller to notify the supervisory authority, where the notification threshold is met, without undue delay and, where feasible, within 72 hours after becoming aware.

Guidance may explain:

  • when awareness occurs;
  • what preliminary facts are enough;
  • whether notice may be phased;
  • how weekends affect operations;
  • what reasons should be given for delay.

Illustration

A security alert appears on Friday. The controller confirms on Saturday that personal data were accessed. The organisation cannot automatically wait until Monday because its privacy office is closed. The statutory period does not pause for internal convenience.

10.2 Processor notification

A processor must notify the controller without undue delay after becoming aware of the breach.

The processor should not delay simply because it has not completed its full forensic investigation. It can provide initial information and supplement it later.


11. Article 70(1)(h): High-risk breaches and communication to individuals

Point (h) concerns the Article 34 threshold.

Article 33 asks whether the breach is likely to create a risk. Article 34 applies where it is likely to result in a high risk to individuals’ rights and freedoms.

A high-risk assessment may consider:

  • sensitivity;
  • identifiability;
  • number of people;
  • vulnerability;
  • ease of misuse;
  • encryption;
  • consequences;
  • duration;
  • containment.

Illustration

A breach exposes names and public business telephone numbers. Risk may be limited. A breach exposes:

  • passwords;
  • psychiatric diagnoses;
  • precise locations;
  • financial data;
  • identity documents. High risk is much more likely. Guidance promotes consistency in deciding:
  • when individuals must be informed;
  • how quickly they must be informed;
  • what communication must contain;
  • whether technical protection makes the data unintelligible;
  • whether later measures removed the high risk.

12. Article 70(1)(i): Binding corporate rules

Point (i) requires guidance on criteria and requirements for controller and processor BCRs.

BCR guidance may address:

  • legally binding effect;
  • scope;
  • third-party beneficiary rights;
  • liability;
  • complaint mechanisms;
  • audits;
  • training;
  • international-transfer safeguards;
  • onward transfers;
  • government-access requests;
  • cooperation with authorities.

Illustration

A global group claims its BCRs are binding because they appear in an internal handbook. The EDPB may require evidence that:

  • every covered group entity is legally bound;
  • employees and entities must comply;
  • individuals can enforce relevant rights;
  • an EEA entity accepts responsibility;
  • effective remedies exist. An aspirational corporate policy is not enough. Approval of BCRs does not approve every processing operation conducted by the group. The organisation must still comply with:
  • purpose limitation;
  • lawfulness;
  • transparency;
  • rights;
  • security;
  • data minimisation.

13. Article 70(1)(j): Article 49 transfer derogations

Point (j) concerns the derogations for specific situations under Article 49(1).

These include transfers based on:

  • explicit consent after information about risks;
  • necessity for a contract;
  • important public-interest reasons;
  • legal claims;
  • vital interests;
  • certain public registers;
  • limited compelling legitimate interests under strict conditions.

These derogations are not supposed to become a convenient substitute for appropriate Article 46 safeguards in regular, structural transfers.

Illustration

A company transfers its full European customer database to a third country every day and relies on contractual necessity. The EDPB may explain that a derogation for necessary contractual transfers should be interpreted narrowly. Some transfer may be objectively necessary to perform a particular booking, but continuous bulk transfer for general analytics may not be. Guidance distinguishes:

  • occasional exceptional transfers;
  • regular business architecture that should use stable safeguards.

14. Article 70(1)(k): Supervisory powers and fines

Point (k) requires guidelines for supervisory authorities concerning:

  • investigative powers under Article 58(1);
  • corrective powers under Article 58(2);
  • authorisation and advisory powers under Article 58(3);
  • administrative fines under Article 83.

This function is essential because national enforcement traditions differ.

14.1 Investigative powers

Guidance may help authorities use:

  • information orders;
  • data protection audits;
  • access to data and information;
  • access to premises and equipment.

14.2 Corrective powers

Guidance may address:

  • warnings;
  • reprimands;
  • compliance orders;
  • rectification;
  • erasure;
  • processing restrictions;
  • bans;
  • suspension of transfers;
  • fines.

Illustration

Two authorities find similar three-year unlawful retention practices. One imposes only a warning. The other imposes a major fine and erasure order. Different outcomes may be justified by:

  • prior violations;
  • cooperation;
  • scale;
  • sensitivity;
  • intention;
  • remedial conduct. Point (k) seeks coherent criteria, not identical punishment regardless of circumstances.

14.3 Fine guidelines cannot replace Article 83

The EDPB may develop methodologies for:

  • seriousness;
  • turnover;
  • aggravating factors;
  • mitigating factors;
  • effectiveness;
  • proportionality;
  • deterrence.

It cannot change the statutory maximums or invent new finable conduct.


15. Article 70(1)(l): Reviewing practical application

Point (l) requires the Board to review the practical application of guidance referred to in points (e) and (f).

This is a quality-control obligation.

Guidance may become outdated because of:

  • new CJEU judgments;
  • technological change;
  • enforcement experience;
  • stakeholder feedback;
  • new EU legislation;
  • unexpected implementation problems.

Illustration

The EDPB issues profiling guidance in 2018. By 2026:

  • generative AI has changed how profiles are created;
  • human review is increasingly automated;
  • new case law clarifies Article 22;
  • national authorities report inconsistent interpretations. The Board should assess whether to revise its guidance.

15.1 The textual limitation

Point (l) expressly mentions guidance under points (e) and (f). Some commentators view this as an editorially narrow cross-reference and argue that practical review logically applies more broadly.

That may be sensible as good administration, but the legal text should not be silently rewritten. The precise mandatory obligation names points (e) and (f). The EDPB may nevertheless review other guidance under:

  • its general consistency mandate;
  • its own-initiative power;
  • the need to keep advice accurate.

Thus:

  • broad review is good practice and may be functionally necessary;
  • the express wording of point (l) remains narrower.

16. Article 70(1)(m): Common infringement-reporting procedures

Point (m) requires guidance for common procedures through which natural persons can report GDPR infringements under Article 54(2).

This may involve:

  • complaints;
  • confidential reports;
  • employee reports;
  • whistleblower-type disclosures;
  • referrals;
  • evidence submissions.

Illustration

An employee discovers that a company secretly sells patient information. A common reporting procedure may clarify:

  • which authority to contact;
  • information to include;
  • confidentiality;
  • secure document transmission;
  • identity protection;
  • acknowledgment;
  • distinction between a complaint and an infringement report;
  • transfer to the competent authority. This task does not create a complete EU whistleblower code by itself. It promotes accessible and consistent reporting routes within the supervisory system.

17. Article 70(1)(n): Codes of conduct and certification

Point (n) requires the Board to encourage:

  • codes of conduct under Article 40;
  • certification mechanisms;
  • seals;
  • marks under Article 42.

17.1 Codes of conduct

A code of conduct can translate broad GDPR obligations into sector-specific rules.

Illustration

A hotel-sector code may cover:

  • guest identification;
  • reservation data;
  • loyalty programmes;
  • CCTV;
  • marketing;
  • payment information;
  • retention;
  • rights handling. A code cannot reduce GDPR protection. It may explain compliance, promote accountability and provide monitoring arrangements.

17.2 Certification

Certification can provide structured assurance concerning particular processing operations.

However, certification:

  • does not reduce the controller’s responsibility;
  • does not guarantee complete GDPR compliance;
  • does not prevent supervisory investigation;
  • is time-limited and reviewable.

Illustration

A cloud provider holds a GDPR certification for one hosting service. The certification does not automatically cover:

  • every service;
  • every subprocessor;
  • every international transfer;
  • the customer’s own unlawful instructions. The scope of certification must be read carefully.

18. Article 70(1)(o): Accreditation and the textual inconsistency

Point (o) states that the EDPB shall:

  • carry out accreditation of certification bodies and periodic review under Article 43;
  • maintain a public register of accredited bodies;
  • maintain a register of accredited third-country controllers or processors under Article 42(7).

This wording is difficult because Article 43(1) largely assigns accreditation to:

  • the competent national supervisory authority; or
  • the national accreditation body.

EDPB guidance on accreditation discusses the roles of Member States, national accreditation bodies and supervisory authorities.

The conflict should not be solved by simply pretending that point (o) does not exist. Nor should it be read as transferring every national accreditation decision to the EDPB.

A coherent interpretation is that the EDPB’s role is European and consistency-oriented, especially regarding:

  • common accreditation expectations;
  • European data protection seals;
  • registers;
  • third-country certification;
  • consistency review;
  • criteria with cross-border significance.

[!example] Illustration A national certification body seeks domestic accreditation. The ordinary accreditation may be performed under Article 43 by the competent national actor. Where certification is intended to operate as a European Data Protection Seal or involves European-level criteria, the EDPB has a stronger approval and coordination role. The exact division must be interpreted across Articles 42, 43, 64 and 70 rather than by isolating point (o).

19. Article 70(1)(p): Requirements for accreditation

Point (p) requires the Board to specify the Article 43(3) requirements used to accredit certification bodies.

Relevant requirements may include:

  • independence;
  • expertise;
  • impartiality;
  • conflicts of interest;
  • complaints procedures;
  • evaluation methods;
  • audit competence;
  • confidentiality;
  • withdrawal and suspension procedures.

Illustration

A certification body also sells GDPR consultancy to the organisations it certifies. The accreditation requirements should address the risk that it:

  1. designs the compliance programme;
  2. evaluates its own work;
  3. grants the certificate;
  4. earns repeat fees from the certified client.

Guidance may require organisational separation and conflict controls.

The EDPB’s accreditation guidance discusses general and additional accreditation requirements under Article 43.


20. Article 70(1)(q): Opinion on certification requirements

Point (q) requires the Board to advise the Commission on certification requirements under Article 43(8).

The Commission may adopt delegated acts specifying requirements to be taken into account for certification mechanisms.

The EDPB contributes specialist data protection expertise.

Illustration

The Commission proposes technical requirements for certification of AI-based identity systems. The EDPB may advise on whether the requirements adequately cover:

  • biometric data;
  • bias;
  • access controls;
  • human oversight;
  • retention;
  • accuracy;
  • model updates;
  • incident handling. The EDPB gives an opinion. The Commission remains responsible for exercising its delegated power lawfully.

21. Article 70(1)(r): Standardised icons

Article 12(7) allows information to be presented with standardised icons to provide a visible, intelligible and meaningful overview of intended processing.

Point (r) requires the EDPB to advise the Commission on these icons.

Illustration

A location icon might indicate that precise location data are collected. That icon would be misleading unless users can understand:

  • whether collection is continuous;
  • the purpose;
  • recipients;
  • retention;
  • whether location is required. Icons should supplement privacy information, not replace it. Poorly designed icons may create false confidence or manipulate users. The EDPB’s role is to help ensure that icons support genuine transparency.

22. Article 70(1)(s): Adequacy assessments

Point (s) requires the Board to advise the Commission when assessing whether a third country, territory, sector or international organisation provides an adequate level of protection.

It also applies when considering whether adequacy no longer exists.

The Commission must provide the EDPB with necessary documentation, including correspondence with the relevant government or international organisation.

Relevant issues may include:

  • data protection principles;
  • independent supervision;
  • individual remedies;
  • judicial protection;
  • government access;
  • surveillance;
  • onward transfers;
  • international commitments;
  • practical enforcement.

[!example] Illustration A third country has a modern privacy statute but permits intelligence agencies to obtain all transferred communications without effective judicial review. Formal statutory rights alone may not demonstrate adequacy. The EDPB examines whether protection is essentially equivalent in substance and practice, not whether the third country has copied the GDPR word for word. The EDPB’s opinion is important but the Commission adopts the adequacy decision. The EU Courts retain judicial review.

23. Article 70(1)(t): Opinions and binding decisions

Point (t) brings together the Board’s formal consistency outputs.

The Board must:

  • issue Article 64(1) opinions on specified draft decisions;
  • issue Article 64(2) opinions on general or multi-state matters;
  • adopt Article 65 binding decisions;
  • adopt relevant Article 66 urgent opinions or decisions.

These instruments differ.

Article 64 opinion

Preventive consistency review or general European guidance.

Article 65 binding decision

Binding resolution of a defined dispute among supervisory authorities.

Article 66 urgent decision

Emergency European intervention where ordinary procedures are too slow.

[!example] Illustration A national authority proposes BCR approval. The EDPB gives an Article 64 opinion. A lead authority rejects Germany’s relevant and reasoned objection. The EDPB adopts an Article 65 binding decision. A local authority imposes an urgent three-month territorial ban and requests final EEA-wide action. The EDPB considers an Article 66 urgent decision. Point (t) does not enlarge the Board’s power beyond Articles 64 to 66. It confirms these functions within its task list.

24. Article 70(1)(u): Cooperation and best-practice exchange

Point (u) requires the Board to promote:

  • cooperation;
  • bilateral information exchange;
  • multilateral information exchange;
  • sharing of best practices.

This may include:

  • common investigation methods;
  • technical expertise;
  • enforcement strategies;
  • case-handling templates;
  • coordinated actions;
  • secure communication channels;
  • enforcement case digests.

Illustration

Several authorities investigate dark patterns. Through the EDPB, they can share:

  • interface-testing methods;
  • evidence standards;
  • user-research approaches;
  • legal analyses;
  • corrective options. They must still protect:
  • confidential material;
  • rights of defence;
  • complainant identities;
  • ongoing investigations.

25. Article 70(1)(v): Training and personnel exchanges

Point (v) requires the Board to promote common training and facilitate staff exchanges among:

  • EEA supervisory authorities;
  • appropriate third-country supervisory authorities;
  • international organisations.

Training may cover:

  • digital forensics;
  • AI;
  • cybersecurity;
  • administrative procedure;
  • fine calculation;
  • international transfers;
  • joint inspections;
  • children’s privacy.

Illustration

A smaller supervisory authority lacks machine-learning expertise. A temporary staff exchange with another authority can help it investigate:

  • model training;
  • inferential profiling;
  • re-identification;
  • automated decisions. Personnel exchanges build not only expertise but also common enforcement culture. Third-country exchanges require careful handling of:
  • confidentiality;
  • international-transfer rules;
  • access to live case files;
  • conflicts of interest;
  • legal authority.

26. Article 70(1)(w): Global exchange

Point (w) requires the EDPB to promote exchange of knowledge and documentation with supervisory authorities worldwide.

This may include:

  • legislation;
  • guidance;
  • enforcement practice;
  • technical research;
  • breach trends;
  • cross-border investigation methods.

Illustration

A connected-device company operates in Europe, Asia and South America. European and foreign authorities may exchange general knowledge about:

  • security vulnerabilities;
  • common processing;
  • children’s risks;
  • enforcement approaches. Point (w) does not itself authorise unrestricted disclosure of confidential case files or personal data. Any actual transfer of information must have an appropriate legal basis and safeguards.

27. Article 70(1)(x): Union-level codes of conduct

Point (x) requires EDPB opinions on codes of conduct drawn up at Union level under Article 40(9).

A Union-level code may apply across several Member States and could become a European accountability instrument.

Illustration

A European financial-services association develops a code covering:

  • fraud detection;
  • automated scoring;
  • data sharing;
  • retention;
  • rights;
  • security. The EDPB assesses whether the code:
  • complies with the GDPR;
  • contains adequate safeguards;
  • provides credible monitoring;
  • prevents conflicting national interpretations. An EDPB opinion does not turn the code into legislation. Participating entities remain directly responsible for GDPR compliance.

28. Article 70(1)(y): Public electronic register

Point (y) requires a publicly accessible register of decisions by supervisory authorities and courts concerning issues handled through the consistency mechanism.

The register promotes:

  • transparency;
  • accountability;
  • legal certainty;
  • comparable enforcement;
  • understanding of how EDPB outcomes are implemented.

Illustration

The EDPB adopts a binding decision requiring a lead authority to amend its proposed findings and fine. The register can connect:

  • EDPB decision;
  • final supervisory decision;
  • relevant court decision. This allows the public to see not only what the EDPB required, but also what happened nationally afterward. The EDPB currently publishes opinions, binding decisions and related documents through its public document and consistency systems. Publication must still protect:
  • personal data;
  • complainants;
  • privileged information;
  • trade secrets;
  • security details.

29. Article 70(2): Commission time limits

When the Commission requests advice, it may indicate a deadline that takes account of urgency.

The provision gives the Commission power to identify when advice is needed. It does not expressly say that every stated deadline is absolutely binding regardless of feasibility.

A sound interpretation is that the Board must make serious efforts to comply, while preserving:

  • independence;
  • adequate analysis;
  • consultation where appropriate;
  • procedural fairness;
  • quality.

Illustration

The Commission requests a complex adequacy opinion in forty-eight hours, involving thousands of pages of foreign surveillance law. Blind compliance could produce unreliable advice. The EDPB should:

  • assess the urgency;
  • explain what can realistically be completed;
  • request essential documentation;
  • provide interim observations if useful;
  • state when a reliable final opinion can be given. The Commission may set the requested timeframe. It may not use an impossible deadline to control the Board’s substantive answer.

30. Article 70(3): Forwarding and publication

The Board must send its:

  • opinions;
  • guidelines;
  • recommendations;
  • best practices

to:

  • the Commission;
  • the Article 93 committee.

It must also make them public.

Publication supports:

  • transparency;
  • consistent compliance;
  • judicial scrutiny;
  • national enforcement;
  • stakeholder understanding.

Article 65 decisions have more specific publication rules that coordinate publication with the final national decision.

Article 70(3) does not necessarily require publication of:

  • confidential drafts;
  • internal deliberations;
  • protected case materials.

The duty concerns the adopted outputs.


31. Article 70(4): Consultation of interested parties

Where appropriate, the Board must consult interested parties and allow comments within a reasonable period.

Interested parties may include:

  • businesses;
  • trade associations;
  • consumer groups;
  • civil society;
  • academics;
  • DPOs;
  • technical experts;
  • public authorities;
  • individuals;
  • professional organisations.

The EDPB operates a public consultation process and publishes consultation opportunities, feedback periods and related privacy information.

31.1 Meaning of “where appropriate”

Consultation may be appropriate where guidance:

  • has broad effects;
  • concerns novel technology;
  • changes an established interpretation;
  • imposes significant practical expectations;
  • benefits from technical evidence.

It may be inappropriate or impossible where:

  • urgent action is required;
  • the matter concerns a confidential Article 65 dispute;
  • consultation would expose sensitive evidence;
  • the Board is applying settled law narrowly.

31.2 Reasonable period

A reasonable period depends on:

  • complexity;
  • urgency;
  • affected sectors;
  • document length;
  • multilingual needs;
  • consultation purpose.

Illustration

A 100-page technical guideline is published for five working days during a holiday period. That may not provide a meaningful opportunity to comment. A shorter period may be justified for a narrowly focused urgent document.

31.3 Consultation does not transfer decision-making power

Stakeholders can:

  • identify errors;
  • present evidence;
  • explain practical consequences;
  • propose clearer wording.

They cannot veto the final guidance.

The EDPB must assess comments independently and remain faithful to the GDPR.

31.4 Publication of consultation results

The Board must make consultation results available, subject to Article 76 confidentiality.

This need not mean publishing every submission without redaction. The Board may publish:

  • submissions;
  • summaries;
  • response reports;
  • revised guidance;
  • explanation of major changes.

Personal data, trade secrets and legitimately confidential information may require protection.


32. Soft law and democratic legitimacy

A major grey area concerns the practical power of EDPB guidance.

Guidelines are not ordinarily legislation, but controllers, auditors and authorities often treat them as authoritative.

That creates two risks.

Risk 1: Guidance may effectively create new rules

The Board may appear to impose duties not found in the GDPR.

Risk 2: Guidance may have major effects without ordinary legislative safeguards

Unlike legislation, guidance is not adopted jointly by Parliament and Council.

The safeguards are:

  • a clear statutory basis in Article 70;
  • public consultation where appropriate;
  • publication;
  • reasoned interpretation;
  • independence;
  • judicial consideration;
  • possibility of later review;
  • supremacy of the GDPR and CJEU case law.

33. Does Article 70 directly bind controllers?

Article 70 is primarily addressed to the EDPB. It does not itself impose a direct operational duty on every controller to follow every EDPB document.

Nevertheless, EDPB outputs matter.

A controller should determine:

  • whether guidance applies;
  • whether national authorities follow it;
  • whether CJEU case law supports it;
  • whether compliance controls need changes;
  • whether departure can be justified.

Illustration

A controller departs from EDPB breach guidance based on a materially different factual situation. It should document:

  • why the guidance is distinguishable;
  • supporting law;
  • risk assessment;
  • decision-making. Simply saying “guidance is not binding” may not satisfy accountability if the controller ignored a well-reasoned common European interpretation. Binding Article 65 or 66 decisions have a different legal character and must be treated accordingly.

34. Key corrections to the supplied commentary

Several issues in the supplied commentary require refinement.

34.1 Article 70(1)(e) permits a request by one of the Board’s members, not a “member of the Commission”

The correct categories are:

  • the EDPB on its own initiative;
  • an EDPB member;
  • the Commission.

34.2 Article 70(1)(t) covers urgent opinions as well as urgent binding decisions

Article 66 allows both forms depending on the request and circumstances.

34.3 Point (l) should not simply be rewritten

The express text refers to points (e) and (f). Broader practical review is sensible, but describing the text as a confirmed editorial error goes beyond what the legislation itself establishes.

34.4 Point (o), not point (n), contains the accreditation language

Point (n) concerns encouragement of codes and certification. Point (o) deals with accreditation, review and registers.

34.5 The certification inconsistency cannot be resolved merely by deleting the EDPB’s role

Articles 42, 43, 64 and 70 must be read together. National bodies perform much accreditation, while the EDPB supports consistency and European-level mechanisms.

34.6 EDPB guidance is influential but not equivalent to legislation

Its legal weight depends on the instrument, statutory basis, reasoning and context.

34.7 Consultation may occur before or after initial adoption

Common practice is to adopt draft guidelines for public consultation and later adopt a final version. Describing that draft consultation as “ex post” can be confusing because consultation still occurs before final adoption.


35. A practical way to understand Article 70

Article 70 divides the EDPB’s work into five broad functions.

First: deciding and reviewing European consistency matters

Points (a) and (t) concern Articles 64 to 66.

Second: interpreting the GDPR

Points (d) to (m) cover guidelines, recommendations and best practices.

Third: advising the Commission

Points (b), (c), (q), (r) and (s) concern legislation, formats, certification, icons and adequacy.

Fourth: building accountability systems

Points (n) to (q) and (x) concern codes, certification, accreditation and seals.

Fifth: strengthening enforcement cooperation

Points (u), (v), (w) and (y) concern information exchange, training, global cooperation and public registers.

The categories overlap, but they show that the EDPB’s role is much broader than deciding disputes.


Conclusion

Article 70 is the operational charter of the European Data Protection Board. Its overriding mission is to ensure that the GDPR functions as one European legal framework rather than a collection of incompatible national interpretations. The Board performs that mission by:

  • reviewing important national draft measures;
  • resolving disputes among supervisory authorities;
  • issuing guidelines and best practices;
  • advising the Commission;
  • clarifying profiling and breach rules;
  • supporting international-transfer mechanisms;
  • promoting consistent fines and corrective powers;
  • encouraging codes and certification;
  • strengthening cooperation and training;
  • consulting stakeholders;
  • publishing its work;
  • maintaining consistency records. The EDPB’s functions vary in legal effect.
  • Guidelines and recommendations are influential interpretive instruments.
  • Article 64 opinions are formal consistency opinions.
  • Article 65 decisions are binding on the authorities concerned.
  • Article 66 decisions provide urgent European intervention.
  • Advice to the Commission informs legislation and policy but does not replace the Commission’s or legislature’s decision. The Board must remain independent, but it must also be transparent, consultative and accountable. It cannot use consistency as a reason to erase legitimate factual differences or national rules permitted by the GDPR. Nor can it use guidance to become a substitute legislature. The simplest summary is:

National authorities enforce the GDPR in individual cases. The EDPB supplies the common European interpretation, resolves defined cross-border disagreements, advises on European data protection policy and helps national regulators work as one coherent enforcement network.