EDPB Adopts Scientific Research Data Processing Guidelines
Summary
The EDPB adopted Guidelines on processing personal data for scientific research purposes, providing six indicative factors to determine if processing qualifies as scientific research under GDPR, and clarifying purpose compatibility, broad consent, and limitations on data subject rights. The Board also created a dedicated sprint team to accelerate finalisation of the upcoming anonymisation guidelines by summer. Two Europrivacy certification opinions were also adopted, including the first European Data Protection Seal approved as a transfer tool under Articles 42 and 46 GDPR. The scientific research guidelines are open for public consultation until 25 June 2026.
Research institutions, universities, hospitals, and biotech companies conducting scientific research should review their data processing procedures against the six indicative factors provided in the EDPB guidelines to confirm their activities qualify as scientific research under GDPR. Where broad consent is relied upon, additional safeguards must be implemented to compensate for the lack of full purpose specification at the time of data collection.
About this source
GovPing monitors EDPB EU News for new data privacy & cybersecurity regulatory changes. Every update since tracking began is archived, classified, and available as free RSS or email alerts — 2 changes logged to date.
What changed
The EDPB adopted Guidelines on processing personal data for scientific research purposes, providing six indicative factors (methodical approach, ethical standards, verifiability, autonomy, research objectives, contribution to scientific knowledge) to determine if processing qualifies as scientific research under GDPR. The guidelines clarify that further processing for scientific research is presumed compatible with the initial purpose, permit broad and dynamic consent where purposes are not fully known at collection, and explain when rights to erasure and objection may be limited. The Board also adopted two Europrivacy certification opinions, including the first seal approved as a transfer tool.
Research institutions, universities, hospitals, and biotech companies relying on GDPR Article 89 safeguards for scientific research can use these guidelines as a compliance reference. Controllers must still ensure a suitable legal basis exists for initial processing and document how responsibilities are allocated among joint controllers, processors, and other entities involved in the research.
Archived snapshot
Apr 22, 2026GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.
Brussels, 16 April – During its latest plenary, the EDPB has adopted Guidelines on processing of personal data for scientific research purposes. In addition, the Board has created a team to speed up the finalisation of the guidelines on anonymisation. The EDPB has also adopted two opinions on the two sets of the Europrivacy certification criteria for approval as European Data Protection Seals, one of which to be used as a tool for transfers.
Many areas of scientific research rely on the processing of individuals’ personal data, and this has driven significant scientific breakthroughs that benefit society. The rise of new technologies, such as artificial intelligence, also contributes to scientific progress by enabling researchers to use and analyse data in innovative ways.
The main objective of the EDPB guidelines on scientific research is to provide more clarity for researchers and make GDPR compliance easier, while ensuring the protection of individuals’ fundamental rights.
“Scientific research can drive societal progress and improve our daily lives.
Our guidelines facilitate innovative research by helping researchers to navigate the GDPR.The EDPB is committed to supporting the scientific community and unlocking the full potential of scientific research in the EU while upholding data protection rights."
EDPB Chair, Anu Talus
In its guidelines, the Board provides clarifications on the concept of ‘scientific research’. To determine if the processing takes place for scientific research purposes in the meaning of the GDPR, the Board provides six key-indicative factors that should be considered, in addition to the nature, scope, context and purposes of processing. These are: 1) methodical and systematic approach, 2) adherence to ethical standard, 3) verifiability and transparency, 4) autonomy and independence, 5) objectives of the research, and 6) potential to contribute to existing scientific knowledge or apply existing knowledge in novel ways. If the research activities meet these six factors, they can be presumed to constitute scientific research. Otherwise, the controller should justify and be able to demonstrate why the activities should be considered scientific research, within the meaning of the GDPR.
Further processing for scientific research purposes is presumed to be compatible with the initial purpose for collecting individuals’ personal data. Therefore, controllers are not obliged to do the purpose compatibility test under the GDPR to determine if the new processing is compatible with the original purpose of collection. However, controllers must still make sure that the legal basis of the initial processing is also suitable for the further processing of personal data for scientific research purposes.
Controllers can rely on “broad consent” where the purposes of research are not fully known at the time of collecting the personal data. In this case, researchers should respect ethical standards for scientific research and put additional safeguards in place to compensate for the lack of purpose specification. Controllers can also ask individuals to consent to different individual research projects separately, as soon as the purposes of those projects become known (dynamic consent). A combination of both broad and dynamic consent is also possible.
In addition, the EDPB clarifies rights of individuals when their personal data are processed for scientific purposes. This includes the rights to erasure and object for which limitations may apply when personal data are processed for scientific research purposes. The Board provides examples to explain when the right to erasure can be considered likely to render impossible or seriously impair the objective of conducting scientific research. The EDPB also explains when controllers may reject an individuals’ objection to the processing of their personal data for scientific research purposes. This can be the case when processing is necessary for the performance of a task carried out for reasons of public interest.
The Board recalls that when several entities are involved in the processing of personal data for scientific research purposes, it is necessary to assess and document how responsibilities are allocated among the entities. In this regard, the Guidelines provide useful examples to clarify in which situations entities can qualify as controller, joint controllers or processor.
Finally, the Board explains how controllers can assess the appropriate technical and organisational measures, such as anonymisation or pseudonymisation, when processing personal data for scientific research purposes. The EDPB provides examples of other safeguards that could be implemented depending on the risks posed by the research activities carried out. These include independent or ethical oversight, secure processing environments, privacy enhancing technologies, protective measures for publication of research results, confidentiality arrangements, and conditions for further use.
The guidelines will be subject to public consultation until 25 June, providing stakeholders with the opportunity to comment and provide feedback.
A “sprint team” to finalise the work on anonymisation
To speed up the finalisation of the upcoming guidelines on anonymisation, the Board created a dedicated "sprint team" that will complete the work by the summer.
Europrivacy opinions
The EDPB adopted an Opinion approving the updated set of Europrivacy certification criteria as European Data Protection Seal * pursuant to Art. 42 (5) GDPR. The Board had first approved the Europrivacy certification criteria on 10 October 2022 as the first European Data Protection Seal through the EDPB Opinion 28/2022. The scope of the Europrivacy certification scheme has been extended to include controllers and processors established outside Europe who are subject to Art. 3(2) GDPR, either because they provide goods or services to individuals in Europe or because they monitor their behaviour.
In addition, for the first time, the Board adopted an Opinion recognising the Europrivacy certification criteria as European Data Protection Seal to be used as a tool for transfers in accordance with Art. 42 and 46 GDPR. Data importers outside Europe who are not subject to the GDPR can now apply to the Europrivacy certification scheme for the transfers of data they receive. This certification will facilitate the fulfillment of the obligation of the controllers and processors in Europe to demonstrate that they provide appropriate safeguards for personal data transfers to third countries or international organisations.
These approvals bring further light on the GDPR certification mechanisms, confirming their key role as GDPR compliance tool.
Note to editors
*The European Data Protection Seal is a GDPR-certification mechanism recognised all over Europe. The Seal must satisfy specific criteria approved by the EDPB and must be granted by a certification body accredited under Art. 43 GDPR to prove compliance with GDPR standards.
Mentioned entities
Related changes
Get daily alerts for EDPB EU News
Daily digest delivered to your inbox.
Free. Unsubscribe anytime.
About this page
Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission
Source document text, dates, docket IDs, and authority are extracted directly from EDPB.
The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.
Classification
Who this affects
Taxonomy
Browse Categories
Get alerts for this source
We'll email you when EDPB EU News publishes new changes.
Subscribed!
Optional. Filters your digest to exactly the updates that matter to you.