CHAPTER VIICOOPERATION AND CONSISTENCY

Article 76Confidentiality

Official text

(1)The discussions of the Board shall be confidential where the Board deems it necessary, as provided for in its rules of procedure.

(2)Access to documents submitted to members of the Board, experts and representatives of third parties shall be governed by Regulation (EC) No 1049/2001 of the European Parliament and of the Council¹.

¹ Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43).

Commentary

Article 76 regulates the boundary between confidentiality and transparency in the work of the European Data Protection Board, or EDPB. It recognises that the Board sometimes needs a protected space for candid regulatory deliberation and for safeguarding sensitive case information, but it does not permit the EDPB to operate as a permanently secret institution.

In the simplest terms:

EDPB discussions may be kept confidential where confidentiality is genuinely necessary. However, documents held by the EDPB remain subject to the EU’s public-access framework, including its rules, exceptions and remedies.

The Article contains two distinct legal regimes:

  1. Paragraph 1 concerns confidentiality of discussions.
  2. Paragraph 2 concerns public access to documents.

These questions overlap but must not be treated as identical. A confidential meeting does not automatically make every document connected with it permanently inaccessible. Equally, the existence of a public-access right does not mean that every internal draft, personal detail or ongoing enforcement document must be disclosed.


1. Why confidentiality is necessary

The EDPB handles matters that may include:

  • unresolved investigations;
  • personal data concerning complainants;
  • commercially sensitive information;
  • cybersecurity vulnerabilities;
  • allegations of GDPR infringements;
  • draft administrative fines;
  • internal disagreements among supervisory authorities;
  • proposed international-transfer arrangements;
  • foreign-government correspondence;
  • litigation strategy;
  • draft Article 65 binding decisions.

Immediate public disclosure of everything discussed could cause serious harm.

Illustration

Several supervisory authorities are considering whether a cloud provider’s security system contains an exploitable vulnerability. If the technical details are disclosed before the vulnerability is fixed, attackers may exploit it. Confidential discussion protects individuals whose data may otherwise be exposed. A different illustration A concerned authority alleges that a company unlawfully processed health data. The allegation remains contested and the controller has not yet been heard. Publishing the accusation as an established fact could:

  • damage the company’s reputation;
  • prejudice the investigation;
  • compromise the right to be heard;
  • mislead the public;
  • put pressure on decision-makers. Confidentiality can therefore protect both effective enforcement and procedural fairness.

2. Why transparency is equally necessary

The EDPB is an EU body with legal personality. It issues influential guidance and may adopt binding decisions that affect national supervisory authorities and, indirectly or directly, controllers, processors and complainants.

A body exercising such authority must remain publicly accountable.

Transparency allows the public to understand:

  • how the GDPR is interpreted;
  • what positions the EDPB adopts;
  • how national regulators cooperate;
  • how disputes are resolved;
  • whether the Board acts consistently;
  • whether its reasoning is legally sound.

Regulation 1049/2001 is based on the principle that openness encourages citizen participation, increases institutional legitimacy and accountability, and gives the fullest possible effect to public access subject to defined exceptions.

Illustration

The EDPB adopts a binding decision that requires a lead authority to find an additional infringement and reassess a substantial fine. The public has a legitimate interest in understanding:

  • which GDPR rules were applied;
  • why the EDPB disagreed with the lead authority;
  • how the objections were assessed;
  • what the binding outcome was. Article 76 should therefore be understood as balancing legitimate confidentiality with meaningful public scrutiny.

3. The two paragraphs regulate different objects

Article 76(1) speaks about“discussions of the Board.”

Article 76(2) speaks about“access to documents.”

A discussion may include:

  • oral interventions during a plenary;
  • debate within an expert subgroup;
  • exchanges concerning proposed amendments;
  • deliberation before a vote.

A document may include:

  • an agenda;
  • draft opinion;
  • written objection;
  • controller submission;
  • meeting note;
  • legal analysis;
  • email;
  • technical report;
  • adopted decision.

A discussion can be confidential even where the final document is public.

[!example] Illustration EDPB members debate a draft guideline behind closed doors. They disagree candidly about the correct interpretation. After voting, the final guideline is published. The internal discussion may remain confidential to preserve the deliberative process, while the adopted institutional position is transparent. The reverse may also occur. A meeting may discuss a publicly known subject, but one document submitted to it may contain protected personal or commercial information requiring redaction.

4. Article 76(1): Confidentiality is conditional

Paragraph 1 does not say:

“All Board discussions shall always be confidential.”

Instead, it provides that discussions“shall be confidential where the Board deems it necessary, as provided for in its rules of procedure.”,

The provision therefore contains three elements:

  1. the subject is a Board discussion;
  2. the Board considers confidentiality necessary;
  3. confidentiality is applied according to the Rules of Procedure.

This is a conditional confidentiality rule. It requires a connection between secrecy and necessity.


5. Is transparency automatically the rule for every discussion?

The supplied commentary states that Article 76 makes public deliberation the general rule and confidential discussion exceptional. That proposition needs qualification.

Article 76 does not expressly require:

  • every plenary meeting to be publicly broadcast;
  • publication of verbatim deliberations;
  • public access to expert-group debates;
  • disclosure of every individual member’s position;
  • open attendance at every EDPB meeting.

The Article says that discussions are confidential where necessary under the Rules of Procedure. It does not itself create an automatic legal right for the public to attend every discussion that has not been formally declared confidential.

The safer interpretation is:

Confidentiality must have a lawful and necessary basis, but the absence of a confidentiality designation does not automatically convert every internal deliberation into a public hearing.

Transparency may instead be achieved through:

  • publication of final opinions;
  • publication of binding decisions;
  • annual reports;
  • consultation documents;
  • public registers;
  • access-to-document requests;
  • reasoned explanations.

6. Meaning of “where the Board deems it necessary”

The Board receives a degree of judgment, but it does not receive unlimited discretion.

The necessity assessment should be based on objective considerations.

Likely considerations include whether disclosure would:

  • expose personal data;
  • prejudice an investigation;
  • undermine rights of defence;
  • reveal a security vulnerability;
  • disclose protected business information;
  • damage international relations;
  • interfere with effective decision-making;
  • reveal legally privileged material;
  • breach professional secrecy.

Illustration

The Board discusses a public consultation report on pseudonymisation after every submission has already been published. There may be little need to treat the entire discussion as confidential merely because confidentiality is convenient. By contrast, an Article 65 discussion concerns:

  • unresolved allegations;
  • confidential objections;
  • personal data;
  • draft corrective measures;
  • enforcement strategy. Confidentiality is much easier to justify.

6.1 Necessity is not merely usefulness

Confidentiality may make meetings more comfortable, but Article 76 asks whether it is necessary within the procedural framework.

The Board should not rely only on statements such as:

  • “we normally keep this secret”;
  • “disclosure may be inconvenient”;
  • “members prefer privacy”;
  • “the subject is controversial.”

A meaningful assessment should connect confidentiality to a protected interest.


7. Confidentiality under the Rules of Procedure

The GDPR leaves the detailed criteria to the EDPB’s Rules of Procedure.

The published Rules of Procedure include confidentiality provisions and identify the Board’s guiding principles, including independence, good administration, collegiality and transparency.

As reflected in the supplied material, the Rules treat discussions as confidential in particular where they concern:

  • a specific individual;
  • the consistency mechanism;
  • a topic the Board specifically decides should remain confidential;
  • international relations;
  • situations where disclosure would seriously undermine the institution’s decision-making process, unless an overriding public interest supports disclosure.

These categories require careful application.

7.1 Discussion concerning a specific individual

The category may involve:

  • complainants;
  • employees;
  • data subjects;
  • witnesses;
  • whistleblowers;
  • named representatives.

Illustration

The Board discusses a complaint containing a person’s psychiatric records. Public deliberation could itself cause a further privacy violation. Confidentiality is strongly justified.

7.2 Consistency-mechanism discussions

Article 64, 65 and 66 proceedings may contain:

  • draft national measures;
  • objections;
  • investigative evidence;
  • information about proposed fines;
  • controller submissions;
  • contested facts.

Confidentiality protects the process until the proper publication stage.

7.3 International relations

The Board may consider:

  • adequacy assessments;
  • foreign surveillance laws;
  • negotiations;
  • government correspondence;
  • international cooperation.

Premature disclosure could affect negotiations or diplomatic relations.

7.4 Protection of decision-making

Members need some capacity to:

  • explore provisional views;
  • disagree candidly;
  • propose compromise language;
  • reconsider earlier positions;
  • test legal arguments.

Immediate disclosure of every unfinished statement could make discussions rigid and strategic.


8. Confidentiality should be proportionate

The Board should consider whether complete secrecy is necessary or whether a narrower measure would suffice.

Possible alternatives include:

  • redaction;
  • anonymisation;
  • partial access;
  • confidentiality limited to one agenda item;
  • delayed disclosure;
  • release of a non-confidential summary;
  • publication after final adoption;
  • protection of annexes but not the main document.

Illustration

A 100-page report contains three pages describing a critical security vulnerability. It may be disproportionate to withhold the entire report if those three pages can be securely redacted.

[!example] Illustration An Article 65 decision contains a complainant’s name but otherwise explains a major legal issue affecting millions of people. Anonymising the complainant may reconcile privacy with public accountability. The narrower the restriction, the easier it is to justify as necessary.

9. Who decides that confidentiality is necessary?

Article 76 says that the Board deems confidentiality necessary.

The Chair may:

  • propose confidentiality;
  • manage classified agenda items;
  • direct the Secretariat;
  • apply the Rules operationally.

But the Chair should not claim an unlimited personal power to designate any subject confidential against the Board’s procedural framework.

Illustration

The Chair’s national authority is criticised in an Article 65 referral. The Chair cannot classify all material as confidential merely to avoid reputational embarrassment. The confidentiality decision must reflect:

  • the Rules of Procedure;
  • objective protected interests;
  • institutional rather than personal considerations. For routine categories already identified in the Rules, the Secretariat and Chair may apply established classifications. For unusual matters, a specific Board determination may be required.

10. Who is bound by confidentiality?

Depending on the context and applicable rules, confidentiality may bind:

  • EDPB members;
  • representatives;
  • the Chair and Deputy Chairs;
  • Secretariat staff;
  • invited experts;
  • observers;
  • third-party representatives;
  • translators;
  • technical staff;
  • persons receiving protected documents.

Illustration

A cybersecurity expert is invited to an expert subgroup and receives a confidential vulnerability report. The expert may use it for the authorised EDPB work but may not:

  • publish it;
  • provide it to a client;
  • use it for private commercial purposes;
  • disclose it to unauthorised persons. Before access is granted, external participants should understand:
  • the scope of confidentiality;
  • duration;
  • permitted use;
  • security arrangements;
  • consequences of unauthorised disclosure.

11. Duration of confidentiality

Article 76 does not specify that confidentiality lasts forever.

The justification may change over time.

Illustration

Internal discussion concerns an active security vulnerability. Confidentiality may be essential while the vulnerability is exploitable. After:

  • the vulnerability is fixed;
  • affected users are informed;
  • the investigation concludes;
  • the relevant decision is published. the justification for withholding some information may weaken. This does not mean every previously confidential document must automatically be released. A later access request requires an assessment under the applicable legal framework. The important principle is: Confidentiality should be reassessed where its factual justification was temporary.

Permanent secrecy should not result merely from an initial classification made during an urgent procedure.


12. Confidentiality and the right to be heard

Confidentiality cannot be used to eliminate the procedural rights of a person adversely affected by an EDPB decision.

An affected controller or processor may need sufficient information to answer:

  • objections;
  • evidence;
  • new allegations;
  • legal characterisations;
  • proposed corrective action.

Illustration

A concerned authority alleges that a platform processes health inferences unlawfully. The EDPB treats the objection as confidential and never tells the platform:

  • the substance of the allegation;
  • the evidence;
  • the legal basis. The Board then adopts a binding decision finding an Article 9 infringement. This would raise serious concerns about:
  • the right to be heard;
  • access to the file;
  • good administration;
  • effective judicial protection. Confidentiality may justify:
  • redacting third-party identities;
  • withholding security details;
  • protecting business secrets.

It does not ordinarily justify keeping the essence of an adverse case secret from the person affected by it.


13. Public access is not the same as party access

Two access questions must be separated.

Public access

A citizen or organisation asks to obtain an EDPB document under Regulation 1049/2001.

Procedural access

A controller, processor, complainant or authority seeks access because the document is relevant to its rights of defence or participation in a case.

A document may lawfully be withheld from the general public but still need to be disclosed to an affected party.

[!example] Illustration A technical annex contains commercially confidential information relevant to an Article 65 dispute. The public may receive only a redacted version. The controller directly affected may need fuller access, perhaps subject to confidentiality arrangements, to defend itself. Conversely, a document may be publicly available but not establish that a particular person has a special procedural right to intervene.

14. Article 76(2): Public access under Regulation 1049/2001

Paragraph 2 states that access to documents submitted to:

  • Board members;
  • experts;
  • third-party representatives

is governed by Regulation 1049/2001.

Regulation 1049/2001 establishes the EU public-access framework. It aims to give the fullest possible effect to public access while protecting specified public and private interests through defined exceptions.

The EDPB’s own public-access page states that eligible applicants have a right of access to EDPB documents held by the Board concerning matters within its responsibility, subject to exceptional refusal of all or part of a document under the Public Access Regulation.


15. Who may request EDPB documents?

Under the EU public-access framework, a right of access is available to:

  • EU citizens;
  • natural persons residing in a Member State;
  • legal persons with a registered office in a Member State.

Institutions may extend access more broadly under their practice.

The EDPB states that EU citizens and natural or legal persons residing or established in a Member State can request access to its documents.

Illustration

A journalist living in France may request:

  • an EDPB meeting document;
  • a consultation submission;
  • correspondence;
  • a draft where legally accessible;
  • a final decision. The applicant does not necessarily have to prove a personal interest in the document. Public access is a transparency right, not ordinary civil discovery.

16. What is a document?

Regulation 1049/2001 takes a broad approach to documents drawn up or received and held by an institution concerning matters within its responsibility. The access framework is intended to support wide transparency in EU administration.

Potential EDPB documents may include:

  • letters;
  • emails;
  • minutes;
  • agendas;
  • reports;
  • draft opinions;
  • legal memoranda;
  • presentations;
  • technical annexes;
  • Member State submissions;
  • consultation responses;
  • electronic records;
  • meeting notes.

The fact that information is stored electronically does not ordinarily remove it from the concept of a document.

Illustration

A substantive EDPB legal analysis exists only as an email circulated among members. It cannot automatically escape the access framework merely because it was not formatted as a formal memorandum. Whether it must be disclosed depends on:

  • whether it is held;
  • its content;
  • the procedural context;
  • applicable exceptions;
  • possible partial access.

17. Does Article 76(2) cover only documents received by the Board?

The supplied commentary argues that documents drawn up by the EDPB are excluded because Article 76(2) refers to documents “submitted to” members, experts and third-party representatives.

That interpretation is too narrow and inconsistent with the EDPB’s own public-access position.

The EDPB expressly states:

The right applies to all documents held by the EDPB concerning any matter relating to its responsibility.

Regulation 1049/2001 also describes a broad framework covering documents drawn up or received and held by the relevant institution.

Accordingly:

  • Article 76(2) expressly confirms access rules for submitted documents;
  • it should not be read as excluding every internally generated EDPB document;
  • final EDPB outputs are also subject to independent publication duties;
  • internal documents may still be withheld where an exception applies.

Illustration

The Secretariat drafts an internal legal note for an Article 65 dispute. The note is generated internally, not “submitted” by a national authority. That fact does not automatically place it outside every public-access rule. It may nevertheless be withheld because disclosure would undermine:

  • ongoing decision-making;
  • legal advice;
  • investigations;
  • rights of defence. The issue is governed by the applicable access rules and exceptions, not by a categorical claim that internally drafted documents are wholly excluded.

18. Public access is not automatic disclosure

Regulation 1049/2001 creates a right to request documents. It does not mean every requested document must be disclosed in full.

The EDPB may refuse or limit access where a recognised exception applies.

Possible protected interests include:

  • public security;
  • defence;
  • international relations;
  • financial, monetary or economic policy;
  • privacy and integrity of the individual;
  • commercial interests;
  • court proceedings;
  • legal advice;
  • inspections, investigations and audits;
  • institutional decision-making.

The EDPB confirms that in exceptional cases it may refuse disclosure of a document or part of it under the Public Access Regulation.


19. Privacy and personal data

EDPB documents frequently contain personal data.

Disclosure to the public may affect:

  • complainants;
  • witnesses;
  • employees;
  • authority staff;
  • company representatives;
  • experts;
  • data subjects.

The access framework and EU data protection rules must be applied together.

Illustration

A complaint file contains:

  • complainant’s name;
  • address;
  • health information;
  • signatures;
  • correspondence. The public interest in understanding the legal issue does not ordinarily require publication of the complainant’s full identity and medical details. The EDPB may provide:
  • an anonymised version;
  • a redacted summary;
  • partial access;
  • the legal analysis without identifying details. Transparency and privacy are complementary. Redaction can often give meaningful access while protecting individuals. The EDPS describes public access and data protection as fundamental and complementary rights that may require careful reconciliation where documents contain personal data.

20. Commercial interests

An Article 64 or 65 file may contain:

  • source code;
  • security architecture;
  • customer information;
  • pricing;
  • algorithms;
  • business strategy;
  • confidential contracts;
  • trade secrets.

Disclosure may undermine legitimate commercial interests.

Illustration

A company submits a detailed explanation of an anti-fraud model. The public may have a legitimate interest in knowing:

  • what categories of personal data are used;
  • the lawful basis;
  • how individuals are affected;
  • what safeguards exist. It may not be necessary to disclose:
  • source code;
  • exploit-sensitive logic;
  • confidential customer lists;
  • proprietary technical parameters. The Board should avoid both extremes:
  • publishing every confidential business detail;
  • allowing a broad trade-secret claim to conceal the entire legal basis of a regulatory decision.

21. Investigations and enforcement proceedings

Disclosure may undermine an ongoing investigation by:

  • revealing investigative strategy;
  • alerting targets;
  • enabling destruction of evidence;
  • influencing witnesses;
  • prejudging allegations;
  • exposing confidential cooperation.

[!example] Illustration Several authorities plan coordinated inspections of a controller’s establishments. A request seeks the inspection schedule and list of evidence to be seized. Disclosure before the inspections could defeat the investigation. The material may justifiably be withheld while the risk exists. After completion, the EDPB should not assume that the investigative exception applies permanently. The harm from disclosure should be reassessed in light of the current procedural stage.

22. Decision-making process

Institutions may protect internal deliberations where disclosure would seriously undermine decision-making, subject to the applicable public-interest test.

This protects the ability of members to:

  • test ideas;
  • reconsider positions;
  • propose compromise wording;
  • express provisional views;
  • debate freely.

Illustration

The EDPB is still drafting guidance on legitimate interests. Publication of every internal version might:

  • create public confusion about the Board’s position;
  • generate pressure based on provisional language;
  • discourage candid debate. Temporary withholding may be justified. Once the final guidance is adopted, the need to keep earlier drafts secret may weaken, although legal advice, personal data and other protected material may still require protection.

23. International relations

The EDPB may receive confidential correspondence from a third-country government during:

  • adequacy assessment;
  • transfer negotiations;
  • international cooperation;
  • analysis of surveillance law.

Illustration

A foreign government provides confidential operational information concerning access to European data. Premature disclosure may:

  • harm diplomatic relations;
  • reduce future cooperation;
  • compromise security methods;
  • misrepresent ongoing negotiations. International-relations confidentiality can therefore be legitimate. However, a general statement that “international relations are involved” should not automatically close the entire file. The institution should determine which portions actually require protection.

EDPB documents may include:

  • advice from legal services;
  • litigation strategy;
  • draft pleadings;
  • assessments of pending cases;
  • communications with external counsel.

Confidentiality may protect:

  • effective legal representation;
  • equality of arms;
  • privileged advice;
  • pending judicial proceedings.

[!example] Illustration A controller challenges an Article 65 decision before the General Court. The EDPB’s internal analysis of litigation weaknesses may be withheld to preserve the Board’s ability to defend itself. This does not permit withholding the adopted Article 65 decision or the public reasoning underlying it.

25. Partial access

A central principle of the public-access system is that where only part of a document is protected, the institution should consider disclosing the remainder.

Illustration

A twenty-page submission contains:

  • fifteen pages of legal argument;
  • two pages of personal data;
  • three pages describing a security vulnerability. The EDPB should consider disclosing the legal argument while redacting the protected sections. A blanket refusal may be excessive where meaningful partial access is possible. Partial access also supports legal certainty because it lets the public understand the regulatory issue without exposing sensitive material.

26. Overriding public interest

Some exceptions in Regulation 1049/2001 may be displaced by an overriding public interest in disclosure.

Potential public-interest considerations include:

  • exposure of serious institutional wrongdoing;
  • accountability for major enforcement decisions;
  • clarity regarding a systemic interpretation of fundamental rights;
  • evidence of improper external influence;
  • public-health implications;
  • significant risks affecting millions of people.

[!example] Illustration An internal document shows that a binding EDPB decision was materially altered following unlawful political pressure. The public interest in understanding a possible breach of EDPB independence may weigh strongly in favour of disclosure. Not every form of curiosity or commercial interest qualifies as an overriding public interest. The interest should be specific, genuine and significant.

27. Consultation with the document’s originator

Where the requested document originated with:

  • a national supervisory authority;
  • the Commission;
  • a third-country government;
  • a controller;
  • an expert;
  • another institution.

the EDPB may need to consult the originator before deciding on disclosure.

Illustration

A company submits a document marked “confidential.” The label does not automatically decide the public-access request. The EDPB should assess:

  • which information is actually protected;
  • how disclosure would cause harm;
  • whether partial access is possible;
  • whether a public interest outweighs the harm. The originator’s view is relevant, but the EDPB must make its own lawful decision under the access framework.

28. Procedure for requesting access

The EDPB provides a public-access route for requests under Regulation 1049/2001. The applicant should identify the requested document or category of documents with sufficient clarity.

A practical request may specify:

  • subject;
  • approximate date;
  • document type;
  • EDPB procedure;
  • relevant authority;
  • case or opinion number;
  • preferred format.

29. Remedies after refusal

An applicant who believes access has been unjustifiably refused is not left without a remedy.

The EDPB states that the applicant may:

  • complain to the European Ombudsman; or
  • bring an action before the Court of Justice of the European Union.

Under the Regulation 1049/2001 framework, the applicant will ordinarily first have access to an internal review or confirmatory process before external remedies, depending on the applicable procedural arrangement.

A refusal should explain:

  • the exception relied upon;
  • how disclosure would cause protected harm;
  • whether partial access was considered;
  • available remedies.

Illustration

The EDPB refuses access using only the sentence: “This document is confidential.” That may be inadequate where the applicant cannot understand:

  • which legal exception applies;
  • why the harm is reasonably foreseeable;
  • whether partial disclosure was possible;
  • how to challenge the refusal. A reasoned refusal is part of good administration.

30. Confidentiality does not defeat mandatory publication duties

Other GDPR provisions require publication of specified EDPB outputs.

Examples

include:

  • Article 64 opinions;
  • Article 65 binding decisions;
  • Article 70 guidelines, recommendations and best practices;
  • Article 71 annual reports;
  • Article 70 consultation results, subject to confidentiality. The EDPB also maintains an extensive public document collection containing guidelines, Article 64 opinions, binding decisions and other materials. Article 76 cannot be used to negate these publication obligations.

Illustration

The EDPB adopts an Article 65 binding decision involving confidential commercial material. The Board may:

  • redact protected material;
  • anonymise individuals;
  • delay publication until the Article 65 publication stage. It cannot simply declare the entire binding decision permanently secret if the GDPR requires publication. The duty is to reconcile publication with protected interests, not to choose one and ignore the other.

31. Confidential deliberations and transparency of reasons

Even where deliberations remain confidential, the final act must contain sufficient reasoning.

Illustration

The Board adopts a binding decision requiring a lead authority to find an additional infringement. It cannot justify the outcome by saying: “The reasons were discussed confidentially and cannot be disclosed.” The public and affected parties must understand the legal and factual basis of the adopted decision, subject to lawful redactions. Confidentiality may protect:

  • which member proposed an argument;
  • preliminary views;
  • compromise negotiations;
  • internal voting strategy. It should not deprive the final decision of intelligible reasons.

32. Voting records

Article 76 does not expressly require publication of how each EDPB member voted.

The Board may publish:

  • the numerical result;
  • whether the required majority was achieved;
  • the final adopted position.

Individual voting records may remain confidential under the applicable procedural and access rules.

Illustration

An Article 65 decision is adopted by the required majority. The public may know the numerical result but not which national authority voted each way. This protects members from improper pressure but may reduce political transparency. The legality of withholding a more detailed voting record may depend on:

  • document content;
  • procedural context;
  • decision-making exception;
  • whether disclosure would undermine future deliberations;
  • overriding public interest. The final institutional decision remains attributable to the EDPB as a body, regardless of each member’s vote.

33. Expert subgroup discussions

The EDPB’s work is often prepared in expert subgroups.

These may address:

  • technology;
  • enforcement;
  • cross-border cooperation;
  • international transfers;
  • financial matters;
  • strategic issues.

Although Article 76 refers to discussions of the Board, the Rules of Procedure extend confidentiality treatment to relevant expert-subgroup discussions.

[!example] Illustration An expert subgroup studies a serious vulnerability in a widely used encryption tool. The same rationale supporting confidentiality at plenary level applies at the preparatory stage. At the same time, an expert subgroup should not be used to avoid transparency permanently by making all substantive decisions informally before the plenary. The adopted Board position and reasons must remain visible through the proper outputs.

34. Third-party experts and representatives

Article 76(2) specifically refers to documents submitted to experts and representatives of third parties.

External participation may be necessary to understand:

  • technology;
  • market structure;
  • foreign law;
  • scientific processing;
  • security;
  • industry practice.

But expanding access increases risk.

Illustration

A technical consultant receives a confidential model-evaluation report. Appropriate controls may include:

  • confidentiality undertaking;
  • secure access;
  • prohibition on further disclosure;
  • deletion or return after use;
  • conflict-of-interest disclosure;
  • restricted downloading;
  • logging. The Board should not give sensitive material to a third party purely because the person is invited to one meeting. Access should be necessary for the assigned role.

35. Data minimisation in document circulation

Confidentiality risks can be reduced by limiting what is circulated in the first place.

Illustration

A dispute can be understood without disclosing:

  • complainant’s home address;
  • identity-document number;
  • unrelated medical history;
  • personal telephone number. Those details should be removed or restricted before circulation to:
  • all Board members;
  • external experts;
  • third-party representatives. Data minimisation supports both:
  • confidentiality;
  • effective decision-making. It also reduces the consequences of unauthorised disclosure.

36. Unauthorised leaks

Article 76 does not expressly prescribe a penalty for unauthorised disclosure.

Consequences may arise under:

  • EU staff law;
  • national disciplinary law;
  • professional secrecy rules;
  • contractual confidentiality;
  • criminal law where applicable;
  • data protection obligations;
  • institutional procedures.

Illustration

A participant leaks an unredacted controller submission containing:

  • trade secrets;
  • employee data;
  • technical vulnerabilities. Possible consequences may include:
  • disciplinary action;
  • removal from the proceeding;
  • damage claims;
  • security incident response;
  • data protection investigation;
  • criminal consequences under applicable law. The EDPB should also assess:
  • who received the information;
  • whether individuals are at risk;
  • whether breach notification is required under the applicable EU institutional data protection regime;
  • what containment steps are necessary.

37. Article 76 and professional secrecy under Article 54

Members and staff of national supervisory authorities are subject to professional-secrecy obligations under Article 54(2).

When they participate in the EDPB, those national obligations and Article 76 may operate together.

Illustration

A national authority receives confidential evidence during its investigation and transmits it into an Article 65 procedure. The evidence does not lose its protected status merely because it is shared with the EDPB. The receiving members and Secretariat must respect:

  • Article 76;
  • EDPB procedural rules;
  • applicable professional-secrecy obligations;
  • rights of defence;
  • access-to-document rules. Confidentiality follows the information through the lawful cooperation process, subject to the appropriate legal regime at each stage.

38. Recital 164 has only indirect relevance

Recital 164 concerns national rules protecting professional or equivalent secrecy when supervisory authorities exercise powers to access:

  • personal data;
  • controllers’ or processors’ premises.

It addresses the relationship between supervisory powers and matters such as:

  • legal professional privilege;
  • medical secrecy;
  • professional confidentiality;
  • other legally protected secrets.

It is not specifically a recital explaining Article 76.

Its relevance is indirect.

Illustration

A national supervisory authority lawfully obtains documents from a lawyer during an investigation. Some documents are protected by professional secrecy under applicable national and EU law. When the authority submits material to the EDPB, Article 76 governs EDPB confidentiality and document access, but it does not automatically extinguish the original professional-secrecy protection. The two rules operate at different stages:

  • Recital 164 concerns the authority’s acquisition of information;
  • Article 76 concerns EDPB discussion and access to documents.

39. A complete practical example

Assume that an Article 65 dispute concerns a multinational health platform.

The file contains:

  • complainants’ medical records;
  • source code;
  • security vulnerabilities;
  • objections from five authorities;
  • the lead authority’s draft fine;
  • legal submissions;
  • correspondence with a third-country government.

Stage 1: Classification

The Secretariat identifies:

  • personal data;
  • business secrets;
  • privileged material;
  • international-relations information;
  • security-sensitive annexes.

Stage 2: Circulation

Members receive the documents through a secure system.

External experts receive only the material necessary to assess the technical issue.

Stage 3: Confidential deliberation

The Board discusses:

  • whether objections qualify;
  • whether an Article 9 infringement exists;
  • whether the security measures were adequate;
  • appropriate corrective measures.

The discussion is confidential because it concerns:

  • individuals;
  • the consistency mechanism;
  • an ongoing enforcement matter;
  • sensitive technical information.

Stage 4: Hearing rights

The platform receives enough information to answer the allegations.

Complainants’ identities and unnecessary medical details are protected.

Stage 5: Adoption

The EDPB adopts a reasoned Article 65 decision.

Stage 6: National implementation

The lead authority adopts and notifies the final national decision.

Stage 7: Publication

The EDPB publishes a redacted version that explains:

  • the legal issues;
  • qualifying objections;
  • findings;
  • required national action.

It removes:

  • names of complainants;
  • exploit-sensitive information;
  • unnecessary trade secrets.

Stage 8: Public-access request

A researcher requests internal drafts and voting records.

The EDPB assesses each document under Regulation 1049/2001, considering:

  • decision-making protection;
  • personal data;
  • commercial interests;
  • partial access;
  • whether the process is complete;
  • overriding public interest.

This example shows that confidentiality is neither absolute secrecy nor automatic disclosure. It is a structured document-by-document and interest-by-interest assessment.


40. Important corrections and qualifications to the supplied commentary

Several points in the supplied commentary should be refined.

40.1 Article 76 does not clearly make every non-confidential Board discussion publicly accessible

It requires necessity for confidentiality, but it does not create an automatic right to attend or obtain a transcript of every other discussion.

40.2 Confidentiality is not necessarily limited to rare or exceptional cases

Major categories of EDPB work, especially Article 65 disputes, routinely involve legitimate confidentiality interests.

40.3 Article 76(2) should not be read as excluding all documents drafted internally

The EDPB states that access applies to all documents it holds concerning matters within its responsibility, subject to applicable exceptions.

40.4 Regulation 1049/2001 does not require automatic publication of everything

It establishes a right to request access, subject to exceptions, partial access, procedures and remedies.

40.5 Confidentiality of a discussion does not automatically determine access to every related document

Each document and protected interest requires proper assessment.

40.6 Public access and rights of defence are different

A document withheld from the public may still need to be disclosed to an affected party.

40.7 Final EDPB outputs remain subject to publication duties

Article 76 cannot be used to defeat Articles 64, 65, 70 and 71.

40.8 Recital 164 is not a dedicated Article 76 recital

It concerns professional secrecy when supervisory authorities exercise access powers and is relevant only by analogy or interaction.


Conclusion

Article 76 creates a structured balance between two important principles:

  • confidentiality needed for effective, fair and secure regulatory work;
  • transparency needed for accountability, legitimacy and public trust. Paragraph 1 permits confidential discussions where the EDPB considers confidentiality necessary under its Rules of Procedure. This may be justified where discussions concern:
  • identifiable individuals;
  • Article 64 to 66 consistency proceedings;
  • ongoing investigation;
  • security vulnerabilities;
  • commercial secrets;
  • international relations;
  • protected internal deliberation. But confidentiality must remain:
  • lawful;
  • necessary;
  • proportionate;
  • connected to a protected interest;
  • limited where partial transparency is possible. Paragraph 2 places access to EDPB documents within the EU public-access framework. Regulation 1049/2001 seeks broad access but allows refusal where disclosure would genuinely undermine protected public or private interests. The EDPB should consider:
  • full disclosure;
  • partial disclosure;
  • redaction;
  • anonymisation;
  • delayed access;
  • overriding public interest.

The Article does not permit the Board to hide its reasoning merely because its internal debate was confidential. Final opinions, binding decisions, guidelines and reports must be published where the GDPR requires, subject to lawful and proportionate protection of sensitive information.

The simplest summary is:

EDPB members need a protected space to deliberate honestly and handle sensitive evidence, but confidentiality cannot become a blanket shield against public accountability. The discussion may remain private where necessary, while the final legal position, reasoning and outcomes should be made transparent to the greatest extent the law permits.