CHAPTER VIICOOPERATION AND CONSISTENCY

Article 71Reports

Official text

(1)The Board shall draw up an annual report regarding the protection of natural persons with regard to processing in the Union and, where relevant, in third countries and international organisations. The report shall be made public and be transmitted to the European Parliament, to the Council and to the Commission.

(2)The annual report shall include a review of the practical application of the guidelines, recommendations and best practices referred to in point (l) of Article 70 (1) as well as of the binding decisions referred to in Article 65.

Commentary

Article 71 is the EDPB’s principal annual accountability obligation. It requires the Board not merely to list what it did during the preceding year, but to report more broadly on the state of personal data protection, examine how its guidance and binding decisions operate in practice, publish the report, and deliver it directly to the EU’s main political institutions.

In the simplest terms:

Every year, the EDPB must explain what is happening in European data protection, what the Board has done, whether its work is producing practical results, and what problems still require attention.


1. The basic structure of Article 71

Article 71 contains two connected duties.

Paragraph 1: Prepare, publish and transmit an annual report

The EDPB must prepare an annual report concerning personal data protection:

  • within the Union;
  • in relevant third countries;
  • in relevant international organisations.

The report must:

  • be made public;
  • be sent to the European Parliament;
  • be sent to the Council;
  • be sent to the Commission.

Paragraph 2: Include practical review

The report must review:

  • the practical application of relevant EDPB guidelines, recommendations and best practices;
  • the practical application of Article 65 binding decisions.

The official Article 71 text confirms both the general reporting obligation and the specific requirement to review guidance and binding decisions.

These are mandatory obligations. The use of“shall” means that the EDPB must:

  1. prepare the report every year;
  2. publish it;
  3. transmit it to the named institutions;
  4. include the paragraph 2 review.

2. Why Article 71 is necessary

The EDPB exercises substantial European regulatory influence.

It may:

  • issue guidelines affecting entire industries;
  • advise the Commission on proposed legislation;
  • give opinions on international data transfers;
  • issue opinions on binding corporate rules;
  • resolve disputes among supervisory authorities;
  • adopt urgent binding decisions;
  • coordinate enforcement cooperation;
  • promote common regulatory practices.

Some EDPB decisions may materially influence whether a multinational controller:

  • is found to have infringed the GDPR;
  • must stop a processing operation;
  • must delete personal data;
  • faces a substantial administrative fine;
  • can rely on particular international-transfer arrangements.

An institution exercising such functions must be accountable.

Article 71 therefore supports four related principles:

  1. Transparency: The public can see what the EDPB has done.
  2. Accountability: The Board must explain how it has exercised its mandate.
  3. Institutional oversight: Parliament, Council and Commission can evaluate the European data protection system.
  4. Regulatory learning: The Board must consider whether its guidance and decisions work in practice.

Article 69 guarantees the Board’s independence. Article 71 supplies an important counterbalance:

Independence means that political institutions cannot tell the EDPB what conclusion to reach. Accountability means that the EDPB must explain what it has done and what results followed.


3. Article 71 is broader than a conventional activity report

A crucial feature of paragraph 1 is its wording. The report is to concern:

“the protection of natural persons with regard to processing”

It is not described simply as a report “on the Board’s activities.”

This indicates that the report should have two dimensions.

3.1 Institutional dimension

It may explain the EDPB’s work, such as:

  • guidance adopted;
  • opinions issued;
  • binding decisions made;
  • stakeholder consultations;
  • cooperation projects;
  • international work;
  • Secretariat activities;
  • litigation;
  • training and expert-support initiatives.

3.2 Substantive data protection dimension

It should also help readers understand:

  • major risks to individuals;
  • important technological developments;
  • enforcement trends;
  • recurring GDPR problems;
  • cross-border cooperation;
  • international-transfer developments;
  • emerging legal questions;
  • resource or procedural challenges.

The EDPB’s 2025 Annual Report follows this broad model. Its structure covers guidance, recommendations, legislative consultation, stakeholder engagement, enforcement support, cooperation, litigation, binding decisions, national cases and international activity.

Illustration

A weak report might say: “The EDPB held meetings, adopted documents and attended events.” A meaningful Article 71 report would explain:

  • which guidance was adopted;
  • why it was needed;
  • which enforcement problems emerged;
  • how supervisory authorities cooperated;
  • whether EDPB decisions were implemented;
  • which technological risks grew during the year;
  • what work remains outstanding. The second approach better serves Article 71’s purpose.

4. “Annual” means a recurring and regular obligation

The EDPB must draw up a report every year.

Article 71 does not expressly prescribe:

  • a particular reporting period;
  • a fixed publication date;
  • a deadline measured from the end of the year;
  • a mandatory report template.

In practice, EDPB annual reports generally cover a calendar year and are published during the following year. The 2025 Annual Report was published on 9 April 2026. Earlier reports are also available through the EDPB’s annual-report archive.

4.1 Timeliness matters

A report published many years after the period covered would lose much of its usefulness.

Illustration

A report covering 2025 and published in April 2026 can inform:

  • current legislative work;
  • enforcement planning;
  • supervisory budgets;
  • industry compliance;
  • public debate. If the same report were published in 2029, many of its observations would be outdated. Although Article 71 contains no explicit publication deadline, its transparency and accountability purpose implies that publication should occur within a reasonable period after the end of the reporting year.

5. “Protection of natural persons”

The report’s central subject is not:

  • administrative efficiency by itself;
  • market regulation by itself;
  • institutional activity for its own sake.

The focus is the protection of natural persons concerning the processing of personal data.

The report should therefore examine the human consequences of processing.

Relevant issues may include:

  • discriminatory automated decisions;
  • unlawful surveillance;
  • exposure of health information;
  • behavioural advertising;
  • identity fraud;
  • children’s privacy;
  • employee monitoring;
  • barriers to access and erasure rights;
  • misuse of biometric data;
  • insecure artificial intelligence systems;
  • international government access.

Illustration

A report says that authorities completed 500 investigations into AI systems. That number is useful, but incomplete. The report should ideally explain:

  • which rights were at risk;
  • what kinds of AI uses were examined;
  • whether individuals suffered significant effects;
  • which safeguards were required;
  • which legal uncertainties remain. Article 71 is ultimately about the effectiveness of data protection for people, not merely the volume of regulatory work.

6. Processing “in the Union”

The report must cover personal data processing in the Union.

This includes processing by:

  • private businesses;
  • public bodies;
  • employers;
  • technology providers;
  • healthcare institutions;
  • financial organisations;
  • schools;
  • platforms;
  • processors;
  • non-profit organisations.

It may cover both:

  • purely national processing;
  • cross-border processing.

The EDPB is not required to describe every national case. That would be practically impossible and would duplicate national supervisory reports under Article 59.

Instead, it may identify:

  • important trends;
  • representative cases;
  • systemic risks;
  • recurring infringements;
  • significant corrective measures;
  • cross-border developments.

Illustration

Several national authorities identify repeated failures to answer access requests. The EDPB’s report may aggregate these experiences and explain:

  • common causes;
  • affected sectors;
  • relevant guidance;
  • enforcement responses;
  • whether further European action is needed. This produces a European overview without replacing each authority’s Article 59 report.

7. Relationship between Article 59 and Article 71

Article 59 requires each national supervisory authority to prepare an annual report on its activities.

Article 71 requires the EDPB to prepare a European-level report on data protection.

The two obligations are related but different.

Article 59 national report

Focuses mainly on:

  • the national authority’s activities;
  • complaints;
  • investigations;
  • infringements;
  • corrective measures;
  • institutional capacity.

Article 71 EDPB report

Focuses on:

  • European data protection conditions;
  • EDPB outputs;
  • cross-border cooperation;
  • European guidance;
  • Article 65 decisions;
  • international and third-country developments;
  • practical implementation of European consistency work.

[!example] Illustration The French authority’s Article 59 report may explain French complaint statistics and enforcement actions. The EDPB’s Article 71 report may compare or consolidate data from several authorities and describe broader European trends. Article 71 does not replace Article 59, and Article 59 reports do not eliminate the need for an EDPB report.

8. Third countries and international organisations

The report must cover data protection in third countries and international organisations“where relevant.”

A third country is generally a country outside the EU or EEA data protection framework.

An international organisation is defined in Article 4(26) and may include treaty-based intergovernmental organisations and bodies established under international agreements.

Relevant issues may include:

  • adequacy decisions;
  • international transfers;
  • binding corporate rules;
  • standard contractual clauses;
  • foreign surveillance laws;
  • government-access requests;
  • international enforcement cooperation;
  • cross-border redress;
  • protection by international organisations;
  • onward transfers.

Illustration

A third country receives large volumes of European personal data under an adequacy decision. During the reporting year:

  • surveillance law changes;
  • judicial redress is restricted;
  • a new independent supervisory body is created;
  • enforcement practices develop. These matters may be relevant to the protection of European data subjects and should therefore be considered in the EDPB’s report.

9. “Where relevant” should not be interpreted too narrowly

The supplied commentary suggests that a third country is relevant only where it processes the data of EU individuals.

That is too narrow.

Third-country or international developments may be relevant because they:

  • affect international transfers;
  • shape adequacy assessments;
  • influence global privacy standards;
  • create enforcement partnerships;
  • affect processors serving European controllers;
  • influence technologies deployed in Europe;
  • provide comparative regulatory experience.

Illustration

A third country adopts an innovative law governing generative AI and personal data. Even if the immediate processing does not involve identifiable EU individuals, the development may still be relevant because:

  • the same AI provider operates in Europe;
  • the legal model may influence international standards;
  • European regulators may cooperate with that country;
  • the technology may later process EEA data. “Where relevant” gives the EDPB flexibility to focus on international developments that materially connect with its statutory mission. It does not restrict the report only to proven processing of EU residents’ data.

10. The report must be made public

Paragraph 1 requires public availability.

Publication is mandatory, not discretionary.

In practice, annual reports are published on the EDPB website, which maintains an archive of reports from 2018 onward.

Meaningful public availability should include:

  • free access;
  • stable links;
  • downloadable files;
  • searchable text;
  • accessible formatting;
  • archival retention;
  • intelligible structure.

Illustration

A report technically appears online but:

  • is available only for one week;
  • is hidden behind an inaccessible portal;
  • cannot be searched;
  • is an unreadable image scan. That may satisfy publication only in a formal sense, not the effective transparency purpose of Article 71.

10.1 Plain-language accessibility

A detailed annual report may be technical. An executive summary can help:

  • individuals;
  • journalists;
  • small organisations;
  • civil-society groups;
  • non-specialist policymakers.

The EDPB provides an executive summary alongside its 2025 Annual Report.

A summary should supplement rather than replace the full report.


11. Transmission to Parliament, Council and Commission

The report must also be transmitted to:

  • the European Parliament;
  • the Council of the European Union;
  • the European Commission.

This is more than general website publication.

Formal transmission ensures that the institutions responsible for:

  • legislation;
  • policy;
  • budgets;
  • Treaty enforcement;
  • international relations;
  • institutional oversight

receive the report directly.

The EDPB expressly states that it publishes its annual report and sends copies to Parliament, Council and Commission.


12. Purpose of transmission to Parliament

The European Parliament may use the report to examine:

  • whether the GDPR remains effective;
  • whether new legislation is needed;
  • whether individuals receive adequate protection;
  • whether cross-border enforcement operates properly;
  • whether supervisory authorities have sufficient resources;
  • whether EU digital laws interact coherently.

Parliament may:

  • hold hearings;
  • request explanations;
  • commission research;
  • debate legislative reform;
  • scrutinise institutional performance.

[!example] Illustration The report identifies repeated delays in cross-border cases because national procedures differ significantly. Parliament may consider whether additional procedural harmonisation is necessary. Parliament may question the EDPB about the problem. It cannot lawfully dictate the conclusion of an individual Article 65 dispute.

13. Purpose of transmission to the Council

The Council represents Member State governments in the EU legislative system.

The report may help it understand:

  • national enforcement trends;
  • regulatory cooperation;
  • implementation difficulties;
  • international-transfer issues;
  • need for legislative reform;
  • financial and institutional challenges.

Illustration

The EDPB reports that several supervisory authorities lack enough technical staff to investigate AI systems. Member States may consider:

  • national budgetary measures;
  • shared technical resources;
  • legislative support;
  • expert-exchange programmes. The report should inform governmental action without making the EDPB subordinate to national governments.

14. Purpose of transmission to the Commission

The Commission may use the report in connection with:

  • legislative proposals;
  • GDPR evaluation;
  • Treaty enforcement;
  • adequacy monitoring;
  • international negotiations;
  • digital-sector policy;
  • infringement proceedings.

The report itself does not automatically establish that a Member State has breached EU law.

15. Article 71 reporting and EDPB independence

The EDPB must transmit its report to political institutions but remains independent under Article 69.

The institutions may not:

  • rewrite the report;
  • prevent publication;
  • order removal of criticism;
  • dictate which enforcement issues are discussed;
  • require the EDPB to alter its legal conclusions.

[!example] Illustration The report criticises gaps in a Commission proposal or weaknesses in a Member State’s enforcement system. The Commission or Council may respond, dispute the analysis or propose reforms. They should not edit the EDPB’s report before publication. Transmission creates accountability, not hierarchical approval.

16. Article 71(2): Review of practical application

Paragraph 2 is more demanding than a mere list of EDPB documents.

It requires a review of practical application.

This asks:

  • Was the guidance used?
  • Was it understood?
  • Did authorities apply it consistently?
  • Did controllers and processors experience difficulties?
  • Did new cases reveal gaps?
  • Are revisions required?
  • Were binding decisions implemented?
  • Did they produce effective results?

Illustration

The EDPB adopted guidelines on legitimate interests. A meaningful practical review might examine:

  • whether national authorities applied the three-stage assessment consistently;
  • which sectors experienced uncertainty;
  • whether controllers correctly documented balancing tests;
  • whether CJEU case law requires revision;
  • whether additional examples are needed. A statement that “guidelines were published” would not amount to a full practical review.

17. The cross-reference to Article 70(1)(l)

Paragraph 2 refers to the guidelines, recommendations and best practices described in Article 70(1)(l).

Article 70(1)(l), in turn, requires the Board to review the practical application of guidance referred to in points (e) and (f).

This drafting structure is awkward.

Point (e) concerns the Board’s broad general-guidance power. Point (f) concerns profiling and automated decisions. Other points, including breach notification and international transfers, also require guidelines, but point (l) expressly names only points (e) and (f).

The safest legal interpretation is:

  • Article 71(2) expressly requires reporting on the practical review required by point (l);
  • this does not prevent the EDPB from reviewing other guidance;
  • the broader Article 71(1) mandate gives the Board room to discuss all important guidance;
  • the text should not simply be rewritten to say that every EDPB document is expressly included.

The supplied commentary incorrectly states that Article 71(2) requires a review of all statements, guidelines, recommendations and best practices published under Article 70(3). That is broader than the actual wording.


18. What “practical application” should involve

A serious review may use evidence such as:

  • surveys of supervisory authorities;
  • stakeholder consultations;
  • national decisions;
  • court judgments;
  • complaints;
  • enforcement statistics;
  • case digests;
  • DPO feedback;
  • audits;
  • sector studies;
  • recurring interpretive questions.

The 2024 Annual Report included stakeholder consultation, surveys concerning practical application of adopted guidance, cooperation, binding decisions and selected national enforcement cases.

Illustration

The EDPB’s breach guidance says that organisations should not delay notification while awaiting a complete forensic report. A practical review could examine:

  • whether organisations still delay;
  • why they delay;
  • how authorities calculate awareness;
  • whether phased notification works;
  • whether a common notification template would help. This turns reporting into regulatory learning.

19. Review of Article 65 binding decisions

The annual report must also review Article 65 binding decisions.

This should be distinguished from merely listing them.

A useful review may address:

  • number of disputes;
  • nature of objections;
  • GDPR provisions involved;
  • time taken;
  • EDPB conclusions;
  • final national implementation;
  • compliance measures;
  • litigation;
  • recurring institutional problems.

Illustration

The EDPB requires a lead authority to:

  • find an additional infringement;
  • revise a corrective order;
  • reassess the fine. The annual report should ideally explain whether:
  • the national final decision implemented those requirements;
  • the controller complied;
  • litigation followed;
  • the decision clarified a recurring legal issue. Article 65(5) already requires publication of binding decisions. Article 71(2) adds an evaluative layer: what happened in practice?

20. Binding decisions do not cover all enforcement

Most GDPR cases do not result in Article 65 decisions.

Many are resolved through:

  • ordinary national enforcement;
  • Article 60 consensus;
  • voluntary compliance;
  • complaint resolution;
  • court proceedings.

Therefore, reporting on Article 65 decisions alone cannot provide a complete picture of European enforcement.

The EDPB may supplement the mandatory content with:

  • cooperation statistics;
  • national cases;
  • corrective measures;
  • coordinated enforcement;
  • major litigation;
  • expert-support initiatives.

The 2025 Annual Report includes enforcement-support activity, GDPR cooperation, binding decisions and a selection of national cases.


21. Naming public and private entities

Article 71 does not prescribe which organisations must be named.

The supplied commentary says public bodies should be openly named because they have no reasonable expectation of privacy. That statement is too categorical.

Public authorities do not enjoy personal privacy in the same way as natural persons, but naming may still involve:

  • ongoing investigations;
  • confidential security matters;
  • procedural fairness;
  • employee personal data;
  • legal restrictions;
  • national-secrecy concerns.

Private organisations may be named where:

  • the underlying decision is public;
  • naming is necessary for accountability;
  • the decision is final or appeal status is stated;
  • applicable confidentiality requirements permit it.

Illustration

A final published Article 65 case identifies a major platform. The annual report may refer to that case by name and explain its significance. An unfinished investigation based on disputed allegations should be handled more cautiously. The correct approach is contextual rather than:

  • always name public bodies;
  • never name private entities.

22. Confidentiality and public reporting

Article 71 must be read with Article 76, which protects confidential discussions and information.

The annual report should not disclose:

  • complainant identities without a lawful basis;
  • whistleblower information;
  • protected security vulnerabilities;
  • privileged legal advice;
  • confidential business information;
  • evidence from ongoing investigations;
  • protected internal deliberations.

But confidentiality should not become a blanket excuse for an empty report.

The Board may use:

  • aggregation;
  • anonymisation;
  • redaction;
  • delayed reporting;
  • thematic descriptions;
  • public versions of decisions.

[!example] Illustration A confidential investigation reveals a vulnerability in hospital software. The report may explain: “Authorities coordinated action concerning a serious vulnerability affecting healthcare systems.” It need not publish exploit details that would create further danger.

23. Recitals 91 and 100

The supplied material lists Recitals 91 and 100 as relevant, but their connection to Article 71 is indirect.

Recital 91

Recital 91 concerns when a DPIA is required for high-risk processing.

It may be relevant to the report if the EDPB discusses:

  • high-risk technologies;
  • large-scale monitoring;
  • biometric processing;
  • profiling;
  • DPIA guidance.

It is not a recital specifically interpreting the annual-report obligation.

Recital 100

Recital 100 concerns certification mechanisms, seals and marks.

It may be relevant where the annual report reviews:

  • certification activity;
  • codes of conduct;
  • accreditation;
  • accountability mechanisms.

Again, it does not directly explain Article 71.

Recital 139

Recital 139 is directly relevant because it describes the EDPB’s institutional role, independence and contribution to consistent GDPR application.

It supplies the most direct contextual basis for understanding why the Board must report publicly on its work.


24. A model structure for an Article 71 report

A strong annual report could contain the following sections.

Executive overview

Major developments, risks and priorities in plain language.

State of data protection in the Union

Major technological, legal and enforcement trends.

Guidance and recommendations

Documents adopted, practical use, stakeholder response and need for revision.

Consistency opinions

Article 64 opinions and national follow-up.

Binding decisions

Article 65 disputes, outcomes, implementation and litigation.

Urgent procedures

Article 66 requests and resulting measures.

Cross-border cooperation

Article 60 procedures, mutual assistance, joint operations and known challenges.

Supervisory enforcement

Selected national cases and recurring infringements.

International developments

Adequacy, transfers, global cooperation and relevant third-country developments.

Stakeholder consultation

Public consultations, major concerns and changes made following input.

Institutional capacity

Secretariat work, expert support, litigation and operational challenges.

Future priorities

Planned guidance, enforcement support and emerging risks.

Annexes

Lists of adopted documents, opinions, decisions and relevant statistics.

The GDPR does not prescribe this exact format. It illustrates how Article 71’s objectives can be met meaningfully.


25. Limits of annual-report statistics

Statistics can create an appearance of precision while concealing differences.

Illustration

Authority A closes 10,000 complaints. Authority B closes 1,000. Authority A may appear more effective. But Authority A may have closed many simple or inadmissible cases, while Authority B completed complex investigations affecting millions of people. The EDPB should therefore combine:

  • quantitative information;
  • methodological explanations;
  • qualitative case analysis. Useful definitions include:
  • what counts as a complaint;
  • when a file is considered closed;
  • whether figures include inadmissible matters;
  • whether fines are imposed, final or paid;
  • whether decisions remain under appeal;
  • whether statistics cover the same period. Without methodological clarity, European comparison may mislead.

26. Reporting on weaknesses and failures

An annual report should not function only as an institutional success brochure.

Meaningful accountability may require discussion of:

  • delayed guidance;
  • unresolved cooperation difficulties;
  • procedural backlogs;
  • litigation losses;
  • inconsistent national practice;
  • resource shortages;
  • implementation gaps;
  • incomplete follow-up to binding decisions.

Illustration

The EDPB planned to adopt guidance on children’s AI systems but did not complete it because of technical complexity and limited resources. A candid report may explain:

  • why the work was delayed;
  • what interim measures were taken;
  • when completion is expected;
  • which risks remain. Transparency about difficulty can strengthen institutional credibility.

27. The report is not itself binding law

The Article 71 report may contain:

  • summaries;
  • institutional observations;
  • enforcement trends;
  • policy concerns;
  • forecasts;
  • interpretations.

The report itself is not automatically equivalent to:

  • a GDPR provision;
  • an Article 65 binding decision;
  • a final supervisory order;
  • a CJEU judgment;
  • an Article 64 opinion.

Illustration

The report states that authorities observed increased concern about biometric monitoring. That does not itself create a new legal ban on all biometric processing. Controllers should examine:

  • the underlying GDPR provisions;
  • EDPB guidance;
  • relevant decisions;
  • national law;
  • case-specific facts. The report is an important accountability and interpretive resource, not a substitute legislative act.

28. Key corrections to the supplied commentary

Several aspects require refinement.

First, the report is broader than an activity summary

This part of the supplied commentary is correct. Article 71 concerns the overall protection of individuals, not merely the Board’s meetings and publications.

Second, third-country relevance is not limited to processing of EU individuals

International developments may be relevant for transfers, adequacy, enforcement cooperation or emerging global standards.

Third, the report does not itself establish Member State liability

The Commission may use the report as evidence or institutional input, but it independently decides whether to bring infringement proceedings.

Fourth, public bodies need not invariably be named

Confidentiality, security, procedural fairness and pending investigations may justify withholding or delaying identification.

Fifth, Article 71(2) does not expressly require review of every Article 70(3) publication

It refers to the practical review under Article 70(1)(l) and Article 65 binding decisions.

Sixth, “review” means more than an overview

It should examine use, implementation, effects, difficulties and the need for revision.

Seventh, Recitals 91 and 100 are contextual, not dedicated Article 71 recitals

Their direct subject matters are DPIAs and certification.


Conclusion

Article 71 transforms the EDPB’s work into a recurring cycle of:

  1. action;
  2. publication;
  3. practical evaluation;
  4. institutional accountability;
  5. future improvement.

Every year, the Board must report on personal data protection in the Union and, where relevant, in third countries and international organisations. It must make that report public and transmit it to Parliament, Council and Commission.

The report must do more than catalogue documents. It must review whether:

  • EDPB guidance is being used;
  • recommendations work in practice;
  • authorities apply common standards consistently;
  • Article 65 binding decisions are implemented;
  • enforcement gaps remain;
  • further guidance or legislative action is needed.

The report serves several audiences:

  • individuals learn about risks and rights;
  • controllers and processors identify compliance trends;
  • DPOs obtain practical information;
  • supervisory authorities compare approaches;
  • Parliament and Council assess legal and institutional needs;
  • the Commission receives evidence for policy, adequacy and Treaty enforcement;
  • courts and researchers gain a record of European data protection development.

The essential distinction is:

Article 59 requires each national authority to account for its national activities. Article 71 requires the EDPB to provide the broader European picture and evaluate whether the European consistency system is working.

In the simplest terms:

The EDPB must not only explain what it published and decided. It must also ask whether those publications and decisions made data protection more effective in practice.