Who interprets the GDPR? EDPB (soft) law and the case for reform

The European Data Protection Board (EDPB) can adopt various legal instruments, including Guidelines and Opinions, that are formally non-binding. Yet if supervisory authorities rarely (if ever) depart from them, controllers and processors structure their compliance efforts around them, and data subjects rely upon them in complaints and litigation, perhaps that formal status deserves a second look.

The need to re-visit EDPB legal instruments is strengthened by the role that the European Commission implementing acts have started to play in specifying how certain data protection notions are meant to work. While the Commission’s implementing acts and the EDPB’s Guidelines and Opinions seek consistency, they appear to differ today in terms of formal legal status, procedural safeguards and judicial review.

Even among EDPB instruments, case law suggests a different treatment of Opinions versus Binding Decisions purely based on formal status, without taking practical effects into account. The result is a system in which instruments that are equally capable of significantly influencing the interpretation and application of the GDPR may nonetheless escape direct review depending on how they have formally been adopted.

The Digital Omnibus proposal regarding the GDPR has further illustrated the issue of competence for interpretation of the GDPR, through a tug-of-war between the EDPB and the Commission with significant institutional consequences.

The result? A situation in which reform is needed due to significant questions of legal certainty, accountability and effective judicial protection.

The aim of this article (also available in PDF) is to explain these points, including proposals for reform. It is meant as a critical yet constructive piece on the EDPB’s use of legal instruments.


Under Articles 51-58 GDPR, national supervisory authorities are entrusted with primary responsibility for the enforcement of the GDPR, including investigative powers and the adoption of corrective measures in individual cases.

At EU level, Article 70 GDPR establishes the EDPB as the central body responsible for ensuring the consistent application of the GDPR across the EU.

To this end, it empowers the EDPB to adopt a wide range of instruments, falling within two categories:

  • Theoretically non-binding interpretative instruments, including guidelines, recommendations, best practices and opinions (Articles 70 and 64 GDPR);
  • Formally binding decisions, adopted under Article 65 GDPR in the context of dispute resolution between supervisory authorities.

Why do I list Guidelines and Opinions as “theoretically” non-binding? From a strict statutory sense, Guidelines and Opinions of the EDPB are not formally recognised as “binding” under the GDPR.

However, their impact is significantly stronger in practice.

First, they are de facto binding on supervisory authorities:

  • Such legal instruments represent the outcome of a negotiation among supervisory authorities, each of whom takes part in the adoption process and has had its say. They are not the view of just one authority but a collective position, such that no supervisory authority is likely to disown it publicly (likely at great reputational and institutional risk);
  • Even if one wished to do so, supervisory authorities are required under the GDPR to “cooperate with each other” in order to “contribute to the consistent application of this Regulation throughout the [EU]” (Article 63 GDPR), such that any deviation could be viewed as a breach of the collaboration duty;
  • Moreover, any deviation by a supervisory authority from an EDPB position is likely to trigger escalation, including referral to the EDPB and ultimately a Binding Decision under Article 65 GDPR – and failure by the EDPB Chair to start the process could even be seen to be a violation of the EDPB’s own core obligation to “ensure the consistent application of this Regulation” (Art. 70(1) GDPR); [In the case of EDPB Opinions, the process is foreseen already under Article 65(1)(c) GDPR. In the case of EDPB Guidelines, the process is slightly longer, as it requires first an EDPB Opinion, but the trigger for this can be a simple request by the EDPB Chair, the Commission or any supervisory authority under Article 64(2) GDPR.]
  • Reinforcing this impact, the EDPB launched on 24 June 2026 a hotline to report inconsistencies in the application of the GDPR, which allows stakeholders to “report alleged divergences between national positions, as well as between national positions and those of the EDPB”.

It is worth noting that there are remarkably few (if any) published examples of supervisory authorities deviating from EDPB Guidelines or Opinions, and there is now an explicit call by the EDPB to report any divergences “between national positions and those of the EDPB” – suggesting that even if there were any, they would be led to disappear.

Next, data subjects attribute to them a form of binding nature vis-à-vis controllers and processors, as they frequently rely on such instruments for complaints or judicial proceedings.

Finally, as regards controllers and processors themselves, a choice to ignore or deviate from any such legal instrument is automatically a risky one, given the impact that these instruments have on supervisory authorities. Moreover, once Guidelines or an Opinion have been published, taking a diverging view of what the GDPR actually requires for compliance will likely be viewed as negligence or even a wilful infringement of the GDPR – with the risk that fines are then considered an appropriate sanction [see Court of Justice of the European Union, (CJEU), 5 December 2023, Deutsche Wohnen, C-807/21, EU:C:2023:950, paragraphs 61 & following]. In other words, controllers and processors must take these instruments into account in their compliance strategies, given their role in shaping enforcement and complaints.

These instruments therefore exert a form of “de facto binding force”, limiting the freedom both of supervisory authorities and of controllers and processors even in the absence of a formal recognition of any binding nature. Their authority extends to the courts, as for instance Advocates General at the EU Court of Justice have sometimes quoted such EDPB guidance in support of their reasoning.

[This has sometimes created circular quotations. For instance, in the EDPB’s binding decisions regarding three Irish DPC cases involving Meta Platforms Ireland and WhatsApp Limited Ireland, the EDPB quoted the Opinion of 20 September 2022 of Advocate General Rantos in the context of case C-252/21 regarding the issue of “contract” as a legal ground. Yet the passage quoted appears to rely only on the EDPB’s Online Services Guidelines, not any relevant CJEU case law. In other words, by quoting this passage of the Advocate General’s Opinion, the EDPB was indirectly quoting its own Online Services Guidelines 2/2019 of 8 October 2019.]

This situation leads to a progressive blurring between soft law and hard law:

  • On the one hand, EDPB Guidelines and Opinions are formally non-binding and lack the procedural safeguards typically associated with EU rule-making and administrative decisions (e.g. full judicial review);
  • On the other hand, supervisory authorities are highly, even extremely unlikely to depart from the position set out by the EDPB.

An often repeated claim is that this is not an issue, as there is the possibility of review of any decision based on such EDPB instruments. Yet this possibility does not aid with legal certainty, effective judicial protection or even the consistency that the EDPB is supposed to ensure in accordance with Article 70 GDPR.

This is because any such review of a decision based on an EDPB instrument will by nature necessarily be national in scope (as review takes place at national level, based on the appellate process for that specific supervisory authority). Should the appellate court take another view than that set out in the EDPB instrument, the EDPB instrument’s validity will remain unaffected. The possibility to review the national decision and in that context challenge the vision set out in an EDPB instrument such as Guidelines or Opinions therefore risks creating more national inconsistencies in applying the GDPR, not less.

In other words, acknowledge the de facto binding nature of EDPB Guidelines and Opinions, and allowing judicial review thereof directly, enables greater consistency in the application of the GDPR and improves legal certainty.


III. Case law so far on EDPB instruments

Recent case law suggests that a judicial recognition of this de facto binding force is possible, with a trend towards increased accountability of the EDPB – though there appear to be fault lines between how the EU General Court and the EU Court of Justice (which sits higher than the General Court) view the issue.

The General Court so far has been dismissive of the legal value of even EDPB Opinions based on Article 64 of the GDPR.

In case T-319/24, Meta v EDPB, the General Court was led to examine a challenge to the “Consent or Pay” Opinion 8/2024 of 17 April 2024.

In its Order of 29 April 2025, the General Court dismissed Meta’s challenge to Opinion 8/2024, holding that the Opinion did not produce binding legal effects and was therefore not challengeable under Article 263 TFEU. It even stated that EDPB Opinions are “opinions to which no special authority is attached” [EU General Court, Order of 29 April 2025, Meta Platforms Ireland v European Data Protection Board, T-319/24, EU:T:2025:435, para. 28].

The reasoning of the General Court appears to be extremely formalistic though, and removed from the way in which Opinions work in practice:

  • Its finding that “[i]t cannot therefore be inferred from the wording of the contested opinion that it is intended in itself to produce binding legal effects” (para. 24) gives authorities a free pass if they use careful wording even though the effect in practice is binding.
  • The General Court rightly points out that from a statutory perspective, an EDPB Opinion can be the prelude to an EDPB Binding Decision: “the opinion adopted under Article 64(2) of Regulation 2016/679, like the contested opinion, is not in the nature of an act which is in itself binding, since it is only by means of a subsequent binding decision of the EDPB that the guidelines contained in that opinion may, having regard to the EDPB’s powers, where appropriate, later become instructions of mandatory application by the supervisory authorities” (para. 29). Yet if there is no need for a Binding Decision because supervisory authorities choose in practice to follow the EDPB Opinion (for instance, to avoid the process of discussion and adoption of a Binding Decision), there is a de facto binding nature.

In reality, compliance with an Opinion to avoid a Binding Decision is tantamount to compliance with a Binding Decision, and an overly formalistic approach is then legal fiction.

In other words, while the General Court seems to consider that Opinions are not authoritative, this is not borne out in practice, and case law not recognising this is detached from reality.

An appeal against the Order in case T-319/24 is pending before the Court of Justice, and it remains to be seen whether it will follow the General Court’s reasoning.

III.2. Court of Justice: WhatsApp Binding Decision

The approach taken by the Court of Justice (CJEU) so far does not appear to be aligned with the General Court’s approach.

In a Grand Chamber judgment of 10 February 2026, on an appeal against another General Court judgment but this time regarding an EDPB Binding Decision, the CJEU held that where an EDPB act is “expressing the definitive position of [an EU body] on the points to be decided by it” and if it is “intended to produce legal effects vis-à-vis third parties” (para. 76), the intermediary nature of the act in question (i.e. that a national decision has to follow) does not change the possibility to challenge it. [CJEU, 10 February 2026, WhatsApp Ireland v European Data Protection Board, C-97/23 P, EU:C:2026:81]

The case concerned an EDPB Binding Decision requiring the Irish Data Protection Commission (DPC) to adopt a stricter position than initially envisaged.

The CJEU held for instance that this Binding Decision “definitively determines, within the meaning of that case-law, the position of the competent EU body, namely the EDPB, and deals exhaustively with all the issues which that body is required to resolve” (para. 72).

The fact that a Binding Decision is “intended to produce legal effects vis-à-vis third parties” is “apparent from the very wording of Article 65(1)(a) and (2) of the GDPR and Article 68(1) of the GDPR”, according to the CJEU, because “[p]ursuant to Article 65(6) of the GDPR, the lead supervisory authority must adopt its final decision on the basis of the decision of the EDPB” (para. 71).

In other words, what matters is not who is the addressee of the act in question (a supervisory authority or a controller), but whether it leaves no real discretion and thereby alters the legal situation of the controller. In the case at hand, WhatsApp was directly affected because the EDPB Binding Decision effectively predetermined the outcome of the national enforcement procedure.

III.3. Consequences for Opinions and Guidelines

The CJEU’s WhatsApp judgment suggests that the distinction between EDPB instruments cannot rest solely on their formal label, and that what matters is a practical assessment of whether (i) an act is going to decide the position of the EDPB and whether (ii) this leaves any discretion for controllers and processors.

While it remains to be seen what the CJEU decides in the Consent or Pay Opinion appeal, this position suggests at least greater accountability, and at least the potential for Opinions to be recognised as de facto binding.

It raises a key question, though, namely whether the current statutory framework is still appropriate and whether it should evolve.


IV. European Commission implementing acts

Before examining what EDPB instruments could look like – and whether the EDPB’s current approach and Art. 70 GDPR itself are an appropriate framework – it is worthwhile examining another form of interpretative instrument, namely implementing acts of the European Commission.

Under Article 291 of the Treaty on the Functioning of the European Union, the Commission may adopt implementing acts where uniform conditions are needed for implementing legally binding EU acts. Implementing acts are themselves legally binding, provided the Commission acts within the limits of the empowerment given by the legislator.

The power to adopt implementing acts is not a blank cheque. They produce a single legal standard, and must as a result stay within the bounds set by the EU legal instrument foreseeing this power. For instance, they cannot be used to amend essential elements of legislation, nor are they a substitute for the process of adopting laws where more appropriate.

Where the legislature has given the Commission a suitable mandate, implementing acts can provide binding, reviewable, EU-wide rules.

The Digital Markets Act (DMA) illustrates the Commission’s powers in this respect, as it grants the Commission the power to adopt decisions further specifying the measures a gatekeeper (i.e. an undertaking meeting thresholds in terms of customer base and revenue in the EU) must take to comply with certain DMA obligations. Besides being the enforcer of the DMA, it is therefore also given a key role in turning general obligations into concrete compliance requirements.

One particular aspect of the DMA is noteworthy in this respect, as the combination of Articles 6(11) and 8(2) DMA mean that the Commission can specify how to make search query data anonymous. As described in Commission-EDPB Joint Guidelines on the DMA-GDPR interplay:

“Through an implementing act under Article 8(2) DMA, the Commission may specify legally binding measures on gatekeepers to ensure effective anonymisation and on the eligibility of third parties to receive data under Article 6(11) DMA. […] This may include the specification of technical measures that result in the alteration of the data to be provided, as well as administrative, organisational, and contractual measures to be adopted by the gatekeeper before sharing data under Article 6(11) DMA. […].” [Joint Guidelines of the European Commission and of the EDPB on the Interplay between the Digital Markets Act and the General Data Protection Regulation, version for public consultation, 9 October 2025, para. 188]

In practice, therefore, the Commission’s implementing act (the Alphabet-related one having been adopted on 16 July 2026) is a binding legal instrument setting out the conditions under which information ceases to be personal data, according to the Commission. It interprets the GDPR, but not in the form of mere guidance with an as-of-yet unclear legal authority.

A particularly interesting feature of this implementing act is that it is a clearly challengeable, binding piece of rule-making on the most fundamental of data protection concepts (what is personal data?), a topic that might normally be assumed to be squarely and solely within the EDPB’s remit.

While Commission implementing acts may appear to be procedurally a more complex legal instrument requiring more time, the Alphabet-related implementing act is a good illustration that the Commission can be significantly faster than the EDPB to adopt in-depth requirements: this detailed decision followed a process started officially on 27 January 2026, with an in-depth set of technical requirements already being published for public consultation on 16 April 2026. Only three months separated the public consultation launch and the adoption of the final decision.

Conversely, EDPB guidance is frequently the product of lengthy internal discussions, multiple drafting rounds and extensive consultation processes, such that the adoption of major Guidelines or Opinions can itself take considerable time, with often a year and a half between a first version for public consultation and a finalised set of Guidelines.


V. Digital Omnibus for GDPR: tug-of-war for competence

Further to the publication by the European Commission of its Digital Omnibus proposal regarding the GDPR (as well as the ePrivacy Directive and various other data-related EU laws), the issue of competence for adopting rules or guidance on data protection issues appears to have spilled into the realm of politics.

In its proposal, the Commission foresaw various situations in which the EDPB was to make a proposal for a certain approach or interpretation, and after review the Commission would be empowered to “adopt it by way of an implementing act”. [For instance, in relation to a “proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person” (proposed new Article 33(6) GDPR), a “proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment” (proposed new Article 35(6a) GDPR), etc.]

A proposal that is tied to the Commission’s competence under the DMA related to an implementing act “to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities” (proposed new Article 41a(1) GDPR). While this situation left the initiative to the Commission, the Digital Omnibus for GDPR proposal states that “[t]he Commission shall closely involve the EDPB in the preparations of [such] implementing acts”, with a requirement for the EDPB to “issue an opinion on the draft implementing acts within a deadline of 8 weeks as of the receipt of the draft from the Commission” (proposed new Article 41a(4) GDPR).

The proposal has not been welcomed by the EDPB or the European Data Protection Supervisor (EDPS), which issued a Joint Opinion 2/2026 in which they objected to this empowerment, arguing it could de facto affect the material scope of EU data protection law:

“The EDPB and the EDPS are concerned that the Proposal would allow for the further specification – by way of an implementing act – of the means and criteria that determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities. […] An implementing act as proposed could de facto affect the material scope of EU data protection law, effectively redefining the scope of when and for whom information is considered personal data. The EDPB and the EDPS consider that it should be the competence of supervisory authorities, under the control of the competent courts, to apply the definitions of the GDPR in an independent manner as guaranteed by Article 8(3) of the Charter and it is the competence of the EDPB to ensure consistent application on this matter.” [EDPB-EDPS Joint Opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (Digital Omnibus), 10 February 2026, para. 23.]

These concerns appear to be at odds with the EDPB’s own approach to rule-making, as its own assessments of the notions of “personal data”, pseudonymisation and anonymisation can just as easily be considered to have “de facto affect[ed] the material scope of EU data protection law” through their own interpretation of the law and of case law.

Without examining their criticism of the effectiveness of the proposal (see paragraph 24 of their Joint Opinion 2/2026, alleging that there would not be greater legal certainty), their argument regarding competence is limited: “it should be the competence of supervisory authorities, under the control of the competent courts, to apply the definitions of the GDPR in an independent manner as guaranteed by Article 8(3) of the Charter and it is the competence of the EDPB to ensure consistent application on this matter”. Yet unless one recognises EDPB instruments as properly binding and challengeable, “consistent application” is not guaranteed, and national courts are by definition not members of the EDPB or under the EDPB’s supervision, raising further risks of national divergence and not “consistent application” unless a case eventually makes its way to the EU Court of Justice by way of a preliminary reference.

In other words, the Joint Opinion alleges concerns of (in)consistent application, yet does not explain why such concerns should be disregarded in relation to EDPB instruments.

In a footnote (number 35), the EDPB and EDPS compare the proposed Art. 41a GDPR implementing acts and the Art. 6(11) & 8(2) DMA implementing acts:

“35 […] The implementing acts adopted under Article 8(2) DMA are firmly different to the one proposed in Article 41a GDPR. While Article 8(2) DMA empowers the Commission as enforcer of the DMA to specify the measures that the gatekeeper concerned is to implement in order to effectively comply with the obligations laid down in the DMA, the proposed Article 41a GDPR allows the Commission to set out general means and criteria applicable to all controllers for assessing whether data resulting from pseudonymisation no longer constitutes personal data.”

The alleged distinction appears to boil down to the fact that the Commission is the “enforcer of the DMA”, while it is not for the GDPR. Yet the EDPB is not an enforcer of the GDPR either; only supervisory authorities have that power.

Further to the EDPB-EDPS Joint Opinion, both the European Parliament and the Council of the European Union appear poised to suggest amendments to the Digital Omnibus that would limit the Commission’s drafting freedom: the EDPB establishes the DPIA list, data breach notification template, etc., and the Commission “may” adopt, by means of an implementing act, the EDPB’s document.

In relation to the notion of “personal data” and pseudonymisation and anonymisation, the intervention of the Commission would not even be foreseen, with the EU Council foreseeing instead an obligation for the EDPB Chair to request an Art. 64(2) GDPR Opinion – and an obligation for the EDPB to issue such an Opinion – on the topic.

This approach raises questions from an accountability and challengeability perspective.

As mentioned above, Art. 64(2) GDPR Opinions are de facto binding upon supervisory authorities and have also significant legal consequences in practice for controllers and processors.

If one were to consider that Opinions are not challengeable (as the General Court has held), the Digital Omnibus in its form apparently contemplated by the EU Council would create a statutory obligation to adopt an unchallengeable legal instrument that would, due to its de facto binding nature and the content thereof, affect the material scope of EU data protection law, effectively redefining the scope of when and for whom information is considered personal data”, to use the words of the EDPB-EDPS Joint Opinion (emphasis mine).

Such a situation would ultimately only create greater legal uncertainty if unaccompanied by reform of the EDPB, or at least reform of the statutorily recognised authority of EDPB instruments.


VI. Solutions needed, reform required

The above points to several issues:

  • The EDPB wishes only supervisory authorities, as enforcers of the GDPR, to be competent for applying the GDPR’s definitions, and it wants to ensure “consistent application” of those definitions;
  • The General Court considers that the EDPB’s Opinions are not authoritative (never mind Guidelines), making such a “consistent application” illusory in theory;
  • Even if one were to follow the General Court’s position, there are disincentives for supervisory authorities to deviate from Opinion and Guidelines, as this creates the (direct or indirect) risk of a Binding Decision being taken against them by the EDPB;
  • Controllers and processors are, absent a judicial recognition that the de facto binding nature of Guidelines and Opinions makes them challengeable, left without any recourse at EU level to challenge any EDPB interpretation they find contrary to the GDPR, until and unless a supervisory authority investigates them and holds them accountable for taking another position and the appellate body or court decides to refer questions to the Court of Justice on the matter.

This is not conducive to legal certainty.

Different solutions are available, but they ultimately depend on what the EDPB is prepared to accept – and what the EU legislator’s wishes truly are, with the core question being whether the EDPB is meant to have an influence on GDPR enforcement, or only on the interpretation of the GDPR.

Interpretation and enforcement are closely related, but they are not the same. Enforcement involves investigating cases, exercising regulatory powers and ensuring compliance with the law. Interpretation involves explaining what the law means and how it should be applied across the EU. Each function requires different safeguards and different forms of accountability.

The EDPB, the successor to the Article 29 Working Party (in effect, a group of supervisory authorities), was created primarily to support cooperation and consistency between national supervisory authorities. Its structure reflects that purpose:

  • It features a small(ish) secretariat serving more as coordinator than as supervisor;
  • The persons holding the pen when starting work on EDPB Guidelines or Opinions appear to be representatives of supervisory authorities, not EDPB staff;
  • Anecdotal feedback provided to us by persons involved directly in the process suggests that this approach is often difficult to manage, as this drafting duty as part of international cooperation comes in addition to their typical work within their respective supervisory authority.

Yet the adoption process is not transparent. There is limited visibility as to how those positions are reached, whether competing views are even considered and the reasons for their rejection, how disagreements are resolved and which members vote in favour of or against a proposal.

Such arrangements may be entirely appropriate for a body whose primary purpose is to coordinate enforcement activities. The question is whether the same arrangements remain appropriate when the resulting positions increasingly shape the interpretation of the GDPR throughout the EU.

This question stems from the fact that while the de facto binding nature of EDPB Guidelines and Opinions may not have been fully anticipated by the EU legislator, it is a practical reality that causes legal uncertainty and raises questions of compliance with democratic processes in relation to rule-making (including the principle of judicial review of laws).

These questions can properly be addressed within the EDPB’s structure, or through a more in-depth reallocation of institutional responsibilities.

VI.1. Judicial recognition of challengeability

A first possible solution is not unforeseeable as regards EDPB Opinions, but may require further cases (and therefore a volunteer to push a case all the way to the Court of Justice) for EDPB Guidelines.

Essentially, if the Court of Justice were to recognise that both types of instruments are subject to judicial review and can therefore be challenged by controllers or processors, the issue might be largely resolved for the future.

VI.2. How EDPB internal reform could address these concerns

Yet judicial recognition of challengeability is not the only path, and an internal reform by the EDPB may be even more appropriate long term, also in terms of accessibility of the reform for the broader public (which is not limited to avid readers of Court of Justice judgments).

The EDPB could address these concerns already by more clearly distinguishing between its coordination and interpretative functions.

In practice, reform could take the form of a combination of various improvements to its interpretative function to properly take such concerns into account:

Duty to state reasons:

One core principle of good administration is the duty to state reasons, i.e. to explain any position. It is even part of Article 41 of the EU Charter of Fundamental Rights, on the right to good administration (Art. 41(2): “[The right to good administration] includes: […] (c) the obligation of the administration to give reasons for its decisions”).

Irrespective of whether the EDPB considers itself to be bound by the principles of good administration in relation to its Guidelines and Opinions, it has already emphasised in its Helsinki Statement of 3 July 2025 that it wished to “strengthen its dialogue with stakeholders, holding proactive and early engagement to identify specific areas where further support and clarification is required, and providing the opportunity for stakeholders to flag possible inconsistencies and give feedback”.

For the EDPB to be able to claim that it is engaging in a dialogue, though, it needs to not only request stakeholder input but also respond to such input – even if not at an individual level, every collective argument raised should be addressed.

Whether this is the case today is debatable, as changes to for instance EDPB Guidelines further to public consultation processes do not include justifications as to why a particular perspective is being dismissed, even if supported by a large number of comments.

Otherwise, if only the feedback supporting the EDPB’s assumed position or suggesting minor clarifications is properly addressed, stakeholder engagement is not a dialogue but a monologue by the EDPB.

Transparency in the decision-making process:

According to Article 76(1) of the GDPR, “[t]he discussions of the [EDPB] shall be confidential where the [EDPB] deems it necessary, as provided for in its rules of procedure”.

Those EDPB rules of procedure specifically consider as “confidential” all “discussions of the Board and of expert subgroups” that “concern the consistency mechanism” (Art. 33 of the EDPB rules of procedure, version 8). Yet the “consistency mechanism” to which the EDPB refers only covers Articles 63-67 GDPR, so not for instance the process for adoption of Guidelines (e.g. votes, but also the discussions leading thereto).

Even in relation to EDPB Opinions under Article 64(2) GDPR, it is unclear whether the systematic exclusion from transparency of all discussions – including votes – for adoption of an Opinion is even compatible with EU law or overreach going beyond the intent of the law.

Yet greater transparency – both in relation to Guidelines and in relation to Opinions – can help increase legal certainty by increasing confidence that different perspectives are taken into account.

Binding nature and legal review:

Finally, the EDPB could acknowledge the practical effects of its Guidelines and Opinions, and not maintain the legal fiction publicised by the EU General Court according to which even Opinions are devoid of any particular authority.

It could accept the risk that this represents in terms of challengeability in the name of greater effectiveness of the law, as challengeability at EU level allows greater legal consistency across the EU without the risk of diverging national case law. The risk of EU-level litigation before the General Court and eventually before the Court of Justice is short-lived compared to the risk of protracted national proceedings in various Member States taking different turns before finally making their way (if at all) to the Court of Justice.

Reform as a statutory duty:

If anything, one could consider it to be the statutory obligation of the EDPB and of supervisory authorities to bring about such reforms: compared to the current approach (which fosters inconsistencies and legal uncertainty), this approach is more compatible with the statutory duties of both the EDPB (under Art. 70(1) GDPR) and supervisory authorities individually (under Art. 63 GDPR) to respectively ensure or contribute to “the consistent application” of the GDPR.

Such reforms would not diminish the EDPB’s role. On the contrary, they would strengthen the legitimacy of its interpretative function while preserving its essential role in ensuring cooperation and consistency.

VI.3. A greater role for the European Commission

If courts fail to recognise the challengeability of EDPB instruments, and if the EDPB is unable or unwilling to develop a clearer separation between enforcement coordination and GDPR interpretation, the question naturally arises whether that interpretative function should remain with the EDPB.

In that situation, and given the Commission’s own role in adopting implementing acts on anonymisation already under the DMA, a greater role for the Commission for all data protection interpretation issues may become the more sustainable long-term solution.

Different factors may anecdotally play a role in this respect:

  • The Commission already has longstanding experience in taking decisions with an impact on the way in which EU-wide rules are to be understood or implemented;
  • The Commission has, notably through its experience in competition law, already had to deal with a wide range of questions regarding the principles of EU administrative law, and it has more resources at its disposal to prepare decisions in a way as to limit the risk of a challenge on those aspects;
  • The legal nature of implementing acts (notably as regards their binding nature and challengeability) is already properly understood, such that litigation on that very nature is less likely than in the event of an EDPB instrument.

Transferring the interpretative function of the GDPR from the EDPB to the Commission, always under the control of the Court of Justice through the possibility of judicial review, would address the concerns of legal certainty and of the rights of defence, as well as help manage broader concerns regarding compliance with the principles of good administration.

Such a transfer cannot happen without legislative intervention, though, as an implementing act requires an appropriate legal justification that the GDPR does not currently foresee.

Under such an approach:

  • the EDPB would focus primarily on cooperation and enforcement coordination;
  • the Commission would exercise implementing or standard-setting powers where expressly conferred by the EU legislator; and
  • the Court of Justice would retain ultimate authority over the interpretation of EU law.

VI.4. Reform to help achieve consistency

In conclusion, true consistency in the interpretation and application of the GDPR comes from positions that can be viewed as both legally sound and workable in practice, with the possibility for anyone whose legal situation is impacted to challenge those positions. The impact of interpretative instruments on controllers and processors cannot be underestimated or ignored, and some degree of reform is required going forward.

At a minimum, this is achievable through a recognition of the challengeability of EDPB Guidelines and Opinions. A more far-reaching reform could involve institutional separation of GDPR interpretation and GDPR enforcement. [Other ideas have already been floated in relation to EDPB reform – see for instance Dr M.R. (Mark) Leiser‘s article on “Recalibrating the EDPB and the EDPS Under a Duty to Cooperate An Institutional Case for Cooperative Digital Administration“.]

Either way, some changes are needed to ensure that the data protection framework can evolve in a manner that is consistent with the fundamental principles of law. De facto binding legal instruments are not the way forward, greater legal certainty is instead.

The ball is now in the court of three distinct actors: the Court of Justice, the EDPB itself, and the Commission as holder of EU legislative initiative. If the EDPB does not reform its own administrative practices first, it may soon find that the EU legislators or the courts have taken that choice out of its hands.

🫖

Did this analysis get you thinking? Reach out!

DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!

Get in touch ↗   Let's connect on LinkedIn ↗