ECschema gdpri-v2trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC
Last updated · 10 categories · 54
claims · 55 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
54Claimsbaseline..claims[]
82Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
No red categories; 8 sub-modules are flagged red.
Jurisdiction brief
Standing brief, as of 14 September 2026.
Lead Signal
Ecuador's data-protection regulator is moving rapidly from foundational statute to detailed operational rulemaking. The Superintendencia de Protección de Datos Personales, constituted under the Ley Orgánica de Protección de Datos Personales (published in the Official Gazette Supplement 459 on 26 May 2021) as an independent regulator with sanctioning powers under LOPDP Article 76, issued a resolution in February 2026 introducing a quantitative 'Método Técnico de Gran Escala' to determine when personal-data processing counts as large-scale, triggering heightened statutory obligations. This is a confirmed, in-force change that gives controllers and processors, for the first time, an objective threshold test rather than a qualitative judgment call for one of the LOPDP's most consequential compliance triggers.
The same period saw the SPDP move on two further fronts simultaneously: an AI-focused General Norm, Resolución SPDP-SPD-2026-0009-R of 12 February 2026, now requires organisations to clearly inform data subjects when their personal data is processed via AI systems and to conduct risk or impact assessments before deploying AI systems that process personal data. Taken together with the large-scale-processing threshold issued the same month, this signals a regulator moving on multiple compliance fronts at once rather than sequencing its rulemaking programme one topic at a time.
Other Developments
A draft biometric-data norm is circulating for consultation. The SPDP has circulated a draft General Norm on biometric-data processing that would further specify obligations for facial, fingerprint, and other unique-identifier data. This remains at draft stage and is not yet finalised, so controllers processing biometric data should treat the draft as a strong signal of where obligations are heading rather than as a current binding requirement.
A breach-notification procedure is also pending formalisation. The SPDP circulated a draft resolution, referred to in its own filing as PR_vulneraciones, in May 2026, proposing to formalise breach-notification procedure and timelines for controllers and processors. Like the biometric norm, this is a horizon item rather than an in-force obligation as of this cycle, and its finalisation is expected within the coming two quarters based on the consultation stage it currently occupies.
The SPDP's enforcement posture rests on a confirmed sanctioning power that the institution is still operationally maturing. SPDP is constituted as a control body with sanctioning power under LOPDP Article 76, a confirmed and in-force authority. At the same time, the SPDP's own organisational statute was still being formalised through further SPDP resolutions as of mid-2025, indicating that institutional capacity-building has been running in parallel with, rather than fully ahead of, the substantive rulemaking programme described above.
Cross-Monitor Connections
The AI-transparency and AI-risk-assessment obligations introduced by Resolución SPDP-SPD-2026-0009-R sit adjacent to the artificial-intelligence monitor's own coverage of algorithmic governance; readers tracking Ecuador's broader AI-regulatory posture should consult artificial-intelligence's Ecuador coverage for that dimension rather than expecting this monitor to analyse AI governance beyond its data-protection-specific transparency and risk-assessment angle. No financial-integrity, world-payments, or advennt cross-references were identified as directly relevant to this cycle's data-protection developments.
Outlook
Two items sit on a defined near-term horizon: the SPDP's draft breach-notification resolution and its draft biometric-data norm are both expected to reach finalisation around the fourth quarter of 2026, based on their current consultation stage. Their finalisation would convert two of this cycle's most consequential draft instruments into binding obligations, meaningfully expanding the controller/processor compliance surface beyond what is already in force through the large-scale-processing threshold and the AI-transparency norm.
trust tier: ai_unverified
Standing brief, as of 14 September 2026.
Regulatory Status
Ecuador's data-protection framework, anchored in the Ley Orgánica de Protección de Datos Personales (26 May 2021) and enforced by the independent Superintendencia de Protección de Datos Personales under LOPDP Article 76 sanctioning power, tightened substantially this cycle. A February 2026 SPDP resolution introduced a quantitative large-scale-processing threshold, the 'Método Técnico de Gran Escala'. The same month, Resolución SPDP-SPD-2026-0009-R introduced AI-specific transparency and pre-deployment risk-assessment obligations. Two further instruments remain at draft stage: a biometric-data General Norm and a breach-notification procedure (PR_vulneraciones), both expected to finalise around Q4 2026. The SPDP's own institutional organisational statute was still being formalised as of mid-2025, suggesting the regulator's operational capacity is maturing in parallel with its rapidly expanding substantive rulebook.
Outlook
Finalisation of the draft biometric-data and breach-notification norms, both expected around Q4 2026, represents the clearest near-term change to Ecuador's data-protection compliance surface. Organisations processing biometric data or lacking a formalised breach-response timeline should treat the current drafts as directional guidance ahead of that finalisation.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Comprehensive, actively enforced, single-instrument regime with a fully operational independent supervisor; only source of amber risk is the pending Digital Omnibus reform tracked in enforcement_and_redress.recent_developments_180d.
Traffic-light rationale — GreenComprehensive, actively enforced, single-instrument regime with a fully operational independent supervisor; only source of amber risk is the pending Digital Omnibus reform tracked in enforcement_and_redress.recent_developments_180d.
Sub-modules (5)
Regulator And AuthorityGreen
The EDPS is the independent supervisory authority responsible for monitoring and enforcing EUDPR compliance across ~80 EU institutions, bodies, offices and agencies; Wojciech Wiewiórowski holds the post.
Claims (1):
The European Data Protection Supervisor (EDPS) is the independent supervisory authority responsible for monitoring the processing of personal data by EU institutions and bodies, advising on policies/legislation affecting privacy, and cooperating with other supervisory authorities.
Act And InstrumentsGreen
Core instrument is Regulation (EU) 2018/1725, supplemented by Commission Decision (EU) 2020/969 (DPO/restrictions implementing rules) and the EDPS Rules of Procedure.
Claims (1):
Regulation (EU) 2018/1725 lays down the data protection obligations for the EU institutions and bodies when they process personal data and repeals Regulation (EC) 45/2001, adopting a principle-based approach in line with the GDPR.
Material ScopeGreen
EUDPR governs processing of personal data by Union institutions and bodies, including administrative processing by Europol/EPPO for staff matters; operational law-enforcement data of Europol/EPPO is carved out to their own founding legal acts, and a specific EUDPR chapter aligned with the Law Enforcement Directive applies to EU bodies processing operational data (e.g. Eurojust).
Claims (1):
The processing of operational personal data by Europol and the European Public Prosecutor's Office is excluded from the scope of the EUDPR and instead governed by specific provisions in their founding legal acts, though their administrative processing of personal data (e.g. staff management) is subject to the Regulation.
Territorial ScopeAmber
EUDPR has no GDPR-style extraterritorial reach over non-EU private controllers; it applies to Union institutions and bodies as controllers regardless of where their processing physically occurs. This is a structurally different scope concept than GDPR Art 3, and should not be conflated with it.
Regulator Registration And FilingGreen
Each EUI must designate a DPO who is registered with the EDPS after designation; EUIs must also maintain a Record of Processing Activities (ROPA) under Art 31, made publicly accessible via a central register where feasible.
Claims (1):
After designation, the data protection officer of a Union institution or body shall be registered with the European Data Protection Supervisor by the institution or body which designated him or her.
Category narrative90 words
JID=EC covers the data-protection regime applicable to the EU institutions, bodies, offices and agencies (EUIs) themselves — i.e. the European Commission, Parliament, Council, agencies, EU IT-systems bodies, etc. — as controllers, NOT the GDPR regime applicable to private/public-sector controllers inside EU Member States (that is the domain of the 27 MS JIDs). The operative instrument is Regulation (EU) 2018/1725 (the 'EUDPR'), which replaced Regulation (EC) 45/2001 and mirrors the GDPR's principle-based architecture but is a distinct, self-contained legal instrument with its own supervisory authority, the European Data Protection Supervisor (EDPS).
no periodic updates on record for this sub-brief
Sources and claims (4)
ConfirmedEDPS — The European Data Protection Supervisor (EDPS) is the independent supervisory authority responsible for monitoring the processing of personal data by EU institutions and bodies, advising on policies/legislation affecting privacy, and cooperating with other supervisory authorities.observed
ConfirmedEDPS — Regulation (EU) 2018/1725 lays down the data protection obligations for the EU institutions and bodies when they process personal data and repeals Regulation (EC) 45/2001, adopting a principle-based approach in line with the GDPR.observed
ConfirmedPublications Office of the EU — The processing of operational personal data by Europol and the European Public Prosecutor's Office is excluded from the scope of the EUDPR and instead governed by specific provisions in their founding legal acts, though their administrative processing of personal data (e.g. staff management) is subject to the Regulation.observed
ConfirmedPublications Office of the EU — After designation, the data protection officer of a Union institution or body shall be registered with the European Data Protection Supervisor by the institution or body which designated him or her.observed
Traffic-light rationale — GreenSubstantively aligned with GDPR; anonymisation/pseudonymisation boundary is an active area of guidance development, not a gap.
Sub-modules (4)
Lawful BasesGreen
Art 5 EUDPR sets the enumerated lawful bases for EUI processing (consent, contract, legal obligation, vital interests, public-interest task/official authority) as the EUI-context analogue of GDPR Art 6.
Claims (1):
Article 5 of Regulation (EU) 2018/1725 sets out the lawfulness-of-processing principle governing which legal bases a Union institution or body may rely upon, mirroring the structure of GDPR Article 6.
Consent ThresholdsGreen
Art 7 requires consent to be freely given, specific, informed and unambiguous, demonstrable by the controller, and withdrawable as easily as it was given.
Claims (1):
Where processing is based on consent, the controller must be able to demonstrate that the data subject consented, and withdrawal of consent must be as easy as giving it, without affecting the lawfulness of prior processing.
Special CategoriesGreen
Art 10 restricts processing of special-category data (ethnic/racial origin, political opinions, religious/philosophical beliefs, trade-union membership, genetic data, biometric data for unique identification, health data, sex life/orientation), with Art 11 governing criminal-conviction data.
Claims (1):
Article 10 of the EUDPR restricts processing of data revealing racial/ethnic origin, political opinions, religious/philosophical beliefs, trade-union membership, genetic data, biometric data for unique identification, health data, or data on sex life/sexual orientation, subject to enumerated exceptions.
Pseudonymisation And AnonymisationGreen
The EDPB, sitting alongside the EDPS's own guidance function, adopted guidelines on anonymisation in July 2026 clarifying the notion of anonymous data in light of CJEU case-law directly involving an EUI (EDPS v SRB), of direct relevance to EUI compliance practice.
Claims (1):
On 8 July 2026, the EDPB adopted guidelines on anonymisation and on web scraping in the context of generative AI, bringing clarity to the notion of anonymous data, taking into account the CJEU ruling in Case C-413/23 P EDPS v SRB of 4 September 2025.
Category narrative52 words
EUDPR Chapter II mirrors GDPR Arts 5-11: lawfulness of processing (Art 5), conditions for consent (Art 7), special categories (Art 10), and criminal-conviction data (Art 11). Recent EDPB/EDPS guidance (July 2026) on anonymisation clarifies the boundary between personal and anonymous data post-CJEU C-413/23 P EDPS v SRB, directly relevant to EUI processing.
no periodic updates on record for this sub-brief
Sources and claims (4)
ConfirmedEDPS — Article 5 of Regulation (EU) 2018/1725 sets out the lawfulness-of-processing principle governing which legal bases a Union institution or body may rely upon, mirroring the structure of GDPR Article 6.observed
ConfirmedPublications Office of the EU — Where processing is based on consent, the controller must be able to demonstrate that the data subject consented, and withdrawal of consent must be as easy as giving it, without affecting the lawfulness of prior processing.observed
ConfirmedPublications Office of the EU — Article 10 of the EUDPR restricts processing of data revealing racial/ethnic origin, political opinions, religious/philosophical beliefs, trade-union membership, genetic data, biometric data for unique identification, health data, or data on sex life/sexual orientation, subject to enumerated exceptions.observed
ConfirmedEDPB — On 8 July 2026, the EDPB adopted guidelines on anonymisation and on web scraping in the context of generative AI, bringing clarity to the notion of anonymous data, taking into account the CJEU ruling in Case C-413/23 P EDPS v SRB of 4 September 2025.observed
Rights framework is comprehensive and actively supervised; some rights may be restricted under Art 25 internal-rules mechanism for specified public-interest grounds (investigations, security), which is a lawful derogation, not a gap.
Primary frameworkRegulation (EU) 2018/1725, Arts 14-25
Traffic-light rationale — GreenRights framework is comprehensive and actively supervised; some rights may be restricted under Art 25 internal-rules mechanism for specified public-interest grounds (investigations, security), which is a lawful derogation, not a gap.
Sub-modules (5)
Access RightGreen
Art 17 grants the right of access, exercisable without unnecessary constraints, free of charge; the EDPS ran a Coordinated Enforcement Action reviewing EUI right-of-access practice in 2024.
Claims (1):
The right of access under EUDPR allows a data subject to obtain confirmation that data concerning him or her are processed, the purposes of processing, and the logic involved in automated decisions, exercisable without unnecessary constraints, at any time, free of charge.
Rectification And ErasureGreen
Art 18 grants rectification of inaccurate data; Art 19 grants erasure ('right to be forgotten') on enumerated grounds; the EDPS ran a Coordinated Enforcement Action on the right to erasure in 2025.
Claims (2):
The data subject has the right to obtain from the controller rectification of inaccurate personal data without undue delay, including completion of incomplete data by supplementary statement.
The right to erasure is enshrined in Article 19 of the EUDPR for EUIs, with similarities to Article 17 GDPR for EU/EEA countries; the EDPS conducted a fourth Coordinated Enforcement Action fact-finding exercise on EUI compliance with the right to erasure in 2025.
Restriction And ObjectionGreen
Art 20 grants restriction of processing; Art 23 grants the right to object on grounds relating to the data subject's particular situation; both may be restricted under the Art 25 internal-rules mechanism.
Claims (1):
The EDPS may order the rectification or erasure of personal data or restriction of processing pursuant to Articles 18, 19 and 20 of the EUDPR, and notify such actions to recipients to whom the data have been disclosed.
Data PortabilityGreen
Art 22 grants the right to receive personal data in a structured, machine-readable format and to transmit it to another controller.
Claims (1):
Under Article 22, the data subject has the right to receive personal data concerning him or her in a structured, commonly used, machine-readable format and to transmit it to another controller without hindrance.
Deadlines And Response WindowsGreen
Controllers must respond to data-subject requests without undue delay and in any event within one month of receipt, extendable by two further months where necessary, with reasons communicated to the data subject.
Claims (1):
The data controller must respond to a data subject's request for access to their personal data without undue delay and in any event within one month from receipt, which may be extended by two further months where necessary.
Category narrative47 words
EUDPR Arts 14-24 grant EUI data subjects rights of information, access, rectification, erasure, restriction, portability and objection, with a general one-month response deadline (extendable by two months). The EDPS actively supervises these rights via Coordinated Enforcement Framework participation (2024 access review, 2025 erasure review, 2026 transparency review).
Sources and claims (6)
ConfirmedEDPS — The right of access under EUDPR allows a data subject to obtain confirmation that data concerning him or her are processed, the purposes of processing, and the logic involved in automated decisions, exercisable without unnecessary constraints, at any time, free of charge.observed
ConfirmedPublications Office of the EU — The data subject has the right to obtain from the controller rectification of inaccurate personal data without undue delay, including completion of incomplete data by supplementary statement.observed
ConfirmedEDPS — The right to erasure is enshrined in Article 19 of the EUDPR for EUIs, with similarities to Article 17 GDPR for EU/EEA countries; the EDPS conducted a fourth Coordinated Enforcement Action fact-finding exercise on EUI compliance with the right to erasure in 2025.observed
ConfirmedEDPS — The EDPS may order the rectification or erasure of personal data or restriction of processing pursuant to Articles 18, 19 and 20 of the EUDPR, and notify such actions to recipients to whom the data have been disclosed.observed
ConfirmedPublications Office of the EU — Under Article 22, the data subject has the right to receive personal data concerning him or her in a structured, commonly used, machine-readable format and to transmit it to another controller without hindrance.observed
ConfirmedEDPS — The data controller must respond to a data subject's request for access to their personal data without undue delay and in any event within one month from receipt, which may be extended by two further months where necessary.observed
Fully codified and actively supervised (breach-notification web-portal, DPIA lists, DPO dismissal-consent rules updated January 2026); no material gaps identified.
Primary frameworkRegulation (EU) 2018/1725, Chapters III-IV
Traffic-light rationale — GreenFully codified and actively supervised (breach-notification web-portal, DPIA lists, DPO dismissal-consent rules updated January 2026); no material gaps identified.
Sub-modules (7)
Accountability And DpiaGreen
Art 39(1) requires a DPIA where processing is likely to result in a high risk to rights and freedoms; the EDPS has adopted binding, non-exhaustive DPIA-trigger lists under Art 39(4)/(5).
Claims (1):
Article 39(1) of Regulation (EU) 2018/1725 requires a DPIA when the processing activity is likely to result in a high risk to the rights and freedoms of natural persons, with Article 39(3) providing a non-exhaustive illustrative list.
Dpo RequirementsGreen
DPO designation is compulsory for every EUI; the DPO may only be dismissed with the EDPS's prior consent, with detailed procedural Rules adopted by EDPS Decision 01/2026 (16 January 2026), entering into force early 2026.
Claims (2):
EU institutions, bodies, offices and agencies are required to designate a Data Protection Officer, and the Regulation establishes that a DPO may not be dismissed or penalised by the controller for performing their tasks without the EDPS's prior consent.
EDPS Decision 01/2026 of 16 January 2026 establishes detailed procedural rules on the requirement of prior EDPS consent for the dismissal of DPOs, requiring EUIs to submit a complete dismissal request with supporting documentation before any intended dismissal.
Ropa RequirementsGreen
Art 31 requires each controller to maintain a record of processing activities, in writing (including electronic form), centrally registered and made publicly accessible unless disproportionate given EUI size.
Claims (1):
Each controller shall maintain a record of processing activities under its responsibility in writing, including electronic form, and Union institutions and bodies shall keep their records in a central, publicly accessible register unless inappropriate given their size.
Joint Controller ArrangementsGreen
Art 28 governs joint-controller arrangements between Union institutions/bodies; infringement of Art 28 is expressly fineable under Art 66.
Claims (1):
Article 28 (joint controllers) of the EUDPR is among the provisions for which infringement can be sanctioned with an administrative fine under Article 66.
Security MeasuresGreen
Art 33 requires appropriate technical and organisational security-of-processing measures; infringement is expressly fineable under Art 66(2)/(3).
Claims (1):
Article 33 (security of processing) is expressly listed among the infringements for which fining is set out under Article 66 of the EUDPR.
Breach NotificationGreen
EUIs must notify the EDPS of a personal-data breach presenting a risk to rights and freedoms within 72 hours of becoming aware, where feasible, and notify affected individuals without undue delay where the breach is likely to result in high risk; a dedicated encrypted-notification web form is maintained.
Claims (1):
The EUDPR introduces a duty on all EU institutions and bodies to report certain types of personal-data breach to the EDPS within 72 hours of becoming aware of the breach, where feasible, and to inform affected individuals without undue delay if the breach is likely to result in high risk.
Retention And DisposalGreen
EUDPR's storage-limitation principle requires that personal data be kept in identifiable form no longer than necessary for the purposes for which it is processed.
Claims (1):
Personal data processed under the EUDPR must be kept in a form permitting identification of data subjects for no longer than is necessary for the purposes for which the data are processed.
Key findings (1)
— source on file
Category narrative52 words
EUDPR Chapter IV imposes accountability (Art 4(2)), DPIA obligations (Art 39), mandatory DPO designation with EDPS-consent-gated dismissal (Art 44, reinforced by EDPS Decision 01/2026), ROPA (Art 31), joint-controller (Art 28) and processor (Art 29) rules, security-of-processing duties (Art 33), 72-hour breach notification to the EDPS (Art 34-35), and storage-limitation/retention principles (Art 4(1)(e)).
no periodic updates on record for this sub-brief
Sources and claims (8)
ConfirmedEDPB — Article 39(1) of Regulation (EU) 2018/1725 requires a DPIA when the processing activity is likely to result in a high risk to the rights and freedoms of natural persons, with Article 39(3) providing a non-exhaustive illustrative list.observed
ConfirmedOfficial Journal of the EU — EU institutions, bodies, offices and agencies are required to designate a Data Protection Officer, and the Regulation establishes that a DPO may not be dismissed or penalised by the controller for performing their tasks without the EDPS's prior consent.observed
ConfirmedOfficial Journal of the EU — EDPS Decision 01/2026 of 16 January 2026 establishes detailed procedural rules on the requirement of prior EDPS consent for the dismissal of DPOs, requiring EUIs to submit a complete dismissal request with supporting documentation before any intended dismissal.observed
ConfirmedEDPS — Each controller shall maintain a record of processing activities under its responsibility in writing, including electronic form, and Union institutions and bodies shall keep their records in a central, publicly accessible register unless inappropriate given their size.observed
ConfirmedEDPS — Article 28 (joint controllers) of the EUDPR is among the provisions for which infringement can be sanctioned with an administrative fine under Article 66.observed
ConfirmedEDPS — Article 33 (security of processing) is expressly listed among the infringements for which fining is set out under Article 66 of the EUDPR.observed
ConfirmedEDPS — The EUDPR introduces a duty on all EU institutions and bodies to report certain types of personal-data breach to the EDPS within 72 hours of becoming aware of the breach, where feasible, and to inform affected individuals without undue delay if the breach is likely to result in high risk.observed
ConfirmedPublications Office of the EU — Personal data processed under the EUDPR must be kept in a form permitting identification of data subjects for no longer than is necessary for the purposes for which the data are processed.observed
Framework is complete, but EUDPR itself does not generate adequacy decisions (it relies on GDPR Art 45(3)/LED Art 36(3) decisions) — a structural cross-reference rather than a gap, tracked here as amber for interoperability clarity.
Primary frameworkRegulation (EU) 2018/1725, Arts 46-50
Traffic-light rationale — AmberFramework is complete, but EUDPR itself does not generate adequacy decisions (it relies on GDPR Art 45(3)/LED Art 36(3) decisions) — a structural cross-reference rather than a gap, tracked here as amber for interoperability clarity.
Sub-modules (6)
Transfer MechanismsGreen
In the absence of a GDPR/LED adequacy decision or Art 48 safeguards, an EUI transfer to a third country/international organisation may only occur on enumerated conditions; Art 49 additionally provides that third-country judicial/administrative orders demanding disclosure are enforceable only if based on an international agreement (e.g. MLAT).
Claims (1):
Any judgment of a court or tribunal, or decision of an administrative authority, of a third country requiring a controller or processor to transfer or disclose personal data may only be recognised or enforceable if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union.
Adequacy ReceivedRed
EUDPR does not itself operate an 'adequacy received' concept analogous to a Member State's inbound recognition; EUIs instead rely on the same GDPR/LED adequacy-decision architecture as Member States.
Adequacy GrantedAmber
Adequacy decisions relevant to EUI transfers are granted under GDPR Art 45(3)/LED Art 36(3), not under EUDPR itself; EUDPR Art 47 simply cross-references those decisions for EUI use.
Claims (1):
In the absence of an adequacy decision pursuant to Article 45(3) of the GDPR or Article 36(3) of the Law Enforcement Directive, or of appropriate Article 48 safeguards, an EUI transfer to a third country or international organisation may take place only under enumerated conditions.
Sccs And BcrsGreen
Art 48 allows the Commission or the EDPS to lay down standard contractual clauses for EUI transfers, including clauses that may build on certifications granted under GDPR Art 42; pre-GDPR-era SCCs/BCRs must be adapted to EUDPR requirements before continued use.
Claims (1):
The European Data Protection Supervisor may adopt standard contractual clauses for EUI international-transfer purposes, and pre-existing SCCs/BCRs adopted under the old Directive 95/46 remain valid but must be adapted to Regulation (EU) 2018/1725 before continued use.
Transfer Impact AssessmentAmber
No standalone EUDPR provision names a formal 'transfer impact assessment' step distinct from the Art 46-48 safeguards analysis; EDPS opinion practice (e.g. its September 2025 Opinion on an EU-US framework agreement for security-screening data exchange) functions as the practical equivalent for high-profile international agreements.
Claims (1):
On 17 September 2025, the EDPS issued an Opinion on the negotiating mandate for a framework agreement between the EU and the United States on the exchange of information for security screenings and identity verifications, functioning as a de facto transfer-risk assessment for a major international data-sharing instrument.
Data LocalisationGreen
EUDPR imposes no blanket data-localisation mandate; instead it relies on the Art 46-50 transfer-safeguard cascade and the Art 49 restriction on recognising third-country compulsion orders absent an international agreement.
Claims (1):
Transmissions of personal data to recipients established in the Union other than Union institutions and bodies are subject to additional safeguard conditions under the EUDPR, distinct from the stricter third-country transfer regime of Articles 46-50.
Category narrative50 words
EUDPR Chapter V (Arts 46-50) governs transfers by EUIs to third countries/international organisations: a general principle (Art 46), transfers on the basis of GDPR/LED adequacy decisions (Art 47), appropriate safeguards including EDPS-adopted SCCs (Art 48), non-recognition of third-country judgments absent an international agreement (Art 49), and narrowly-construed derogations (Art 50).
Sources and claims (5)
ConfirmedPublications Office of the EU — Any judgment of a court or tribunal, or decision of an administrative authority, of a third country requiring a controller or processor to transfer or disclose personal data may only be recognised or enforceable if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union.observed
ConfirmedPublications Office of the EU — In the absence of an adequacy decision pursuant to Article 45(3) of the GDPR or Article 36(3) of the Law Enforcement Directive, or of appropriate Article 48 safeguards, an EUI transfer to a third country or international organisation may take place only under enumerated conditions.observed
ConfirmedEDPS — The European Data Protection Supervisor may adopt standard contractual clauses for EUI international-transfer purposes, and pre-existing SCCs/BCRs adopted under the old Directive 95/46 remain valid but must be adapted to Regulation (EU) 2018/1725 before continued use.observed
ProbableEDPS — On 17 September 2025, the EDPS issued an Opinion on the negotiating mandate for a framework agreement between the EU and the United States on the exchange of information for security screenings and identity verifications, functioning as a de facto transfer-risk assessment for a major international data-sharing instrument.observed
ProbablePublications Office of the EU — Transmissions of personal data to recipients established in the Union other than Union institutions and bodies are subject to additional safeguard conditions under the EUDPR, distinct from the stricter third-country transfer regime of Articles 46-50.observed
Sectoral overlays are well-documented for financial-supervision and health agencies; credit-scoring and education have no dedicated EUI sub-regime, which is expected given the nature of Union institutions rather than a compliance gap.
Primary frameworkRegulation (EU) 2018/1725, Art 25 (sector/agency-specific restriction decisions)
Traffic-light rationale — GreenSectoral overlays are well-documented for financial-supervision and health agencies; credit-scoring and education have no dedicated EUI sub-regime, which is expected given the nature of Union institutions rather than a compliance gap.
Sub-modules (7)
Financial Sector OverlayGreen
EU financial-supervision agencies such as ESMA and EIOPA, as EUIs, have each adopted EDPS-consulted internal-rules decisions under Art 25 restricting certain data-subject rights (e.g. right of access, rectification, erasure) in the context of supervisory investigations/inquiries.
Claims (1):
ESMA, following Article 25 of Regulation (EU) 2018/1725 and after an EDPS opinion, adopted internal rules permitting it to restrict data-subject rights of access, rectification, erasure and restriction of processing in the context of its investigations or inquiries.
Health Sector OverlayGreen
EDPS Decision 46/2026 authorised a Model Administrative Arrangement for transfers of personal data from the European Medicines Agency (EMA) to the Council of Europe's Directorate for the Quality of Medicines & HealthCare for a sampling/testing cooperation programme.
Claims (1):
EDPS Decision 46/2026 authorises the use of an administrative arrangement based on the EDPS Model Administrative Arrangement for transfers of personal data from the European Medicines Agency to the Council of Europe's EDQM, pursuant to Article 48(3)(b) of the EUDPR, in the context of a medicines sampling and testing cooperation.
Telecoms And EprivacyAmber
EUDPR Art 36 (confidentiality of communications) sits alongside the ePrivacy Directive 2002/58/EC, which the EDPS notes 'is due to be repealed'; the pending Digital Omnibus proposal would further amend the ePrivacy Directive alongside the GDPR and EUDPR.
Claims (1):
The ePrivacy Directive 2002/58/EC provides additional data-protection rules for telecommunications networks and internet services alongside the EUDPR, and is due to be repealed/amended as part of the Digital Omnibus proposal.
Employment DataAmber
EDPS supervisory activity covers EUI staff-management processing, including a reprimand of EPSO (EU Personnel Selection Office) over remote-testing practices, and active monitoring of AI use in recruitment/HR processes across EUIs.
Claims (1):
The EDPS's February 2025 Newsletter reports an EDPS reprimand issued to EPSO (the EU Personnel Selection Office) concerning its data-processing practices, alongside continued monitoring of AI use in EUI recruitment.
Credit And ScoringRed
No distinct EUI credit-scoring sub-regime was identified; EUIs are not consumer-credit actors in the way private financial institutions are.
No distinct statutory EUI education-sector sub-regime was identified beyond general EUDPR principles; EDPS public engagement on AI-in-education is awareness-raising rather than a binding sectoral overlay.
Absence provenance: unavailable. Searched: EDPS education sector data protection EUI, EUDPR school data processing.
InsuranceGreen
EIOPA, as an EUI insurance/pensions supervisory agency, operates under an EDPS-consulted Art 25 internal-rules decision restricting data-subject rights in the context of its supervisory investigations.
Claims (1):
EIOPA adopted a Decision, following Article 25 of Regulation (EU) 2018/1725 and after consulting the EDPS, laying down rules restricting data-subject rights (access, rectification, erasure, restriction) in the framework of its supervisory procedures.
Category narrative91 words
Because JID=EC covers the Union institutions themselves, 'sectors' map onto specific EUIs/agencies rather than private industry: EU financial-supervision agencies (ESMA, EIOPA, EBA) apply EUDPR with Art 25 internal-rules restrictions for their supervisory investigations; health-related EUIs (EMA, ECDC) process personal data under EUDPR with EDPS-authorised inter-agency transfer arrangements; ePrivacy/telecoms confidentiality rules for EUI electronic communications sit alongside EUDPR Art 36; and EUI employment/recruitment processing (including EPSO testing and AI-in-hiring) is an active EDPS supervisory focus. Credit-scoring, education, and insurance are not distinct statutory sub-regimes for EUIs beyond EIOPA's Art 25 restriction decisions.
Sources and claims (5)
ConfirmedOfficial Journal of the EU — ESMA, following Article 25 of Regulation (EU) 2018/1725 and after an EDPS opinion, adopted internal rules permitting it to restrict data-subject rights of access, rectification, erasure and restriction of processing in the context of its investigations or inquiries.observed
ConfirmedEDPS — EDPS Decision 46/2026 authorises the use of an administrative arrangement based on the EDPS Model Administrative Arrangement for transfers of personal data from the European Medicines Agency to the Council of Europe's EDQM, pursuant to Article 48(3)(b) of the EUDPR, in the context of a medicines sampling and testing cooperation.observed
ConfirmedEDPS — The ePrivacy Directive 2002/58/EC provides additional data-protection rules for telecommunications networks and internet services alongside the EUDPR, and is due to be repealed/amended as part of the Digital Omnibus proposal.observed
ProbableEDPS — The EDPS's February 2025 Newsletter reports an EDPS reprimand issued to EPSO (the EU Personnel Selection Office) concerning its data-processing practices, alongside continued monitoring of AI use in EUI recruitment.observed
ConfirmedOfficial Journal of the EU — EIOPA adopted a Decision, following Article 25 of Regulation (EU) 2018/1725 and after consulting the EDPS, laying down rules restricting data-subject rights (access, rectification, erasure, restriction) in the framework of its supervisory procedures.observed
Core cookie/consent-signal policy is in active reform (Digital Omnibus); several sub-modules are genuinely inapplicable to the EUI-controller context rather than gaps.
Primary frameworkDirective 2002/58/EC (ePrivacy) read with Regulation (EU) 2018/1725, Art 36
Traffic-light rationale — AmberCore cookie/consent-signal policy is in active reform (Digital Omnibus); several sub-modules are genuinely inapplicable to the EUI-controller context rather than gaps.
Sub-modules (6)
Cookies And TrackersAmber
EUI web services are subject to the ePrivacy Directive alongside EUDPR; the Digital Omnibus proposal targets ePrivacy amendments addressing cookie-banner consent fatigue.
Claims (1):
The ePrivacy Directive 2002/58/EC provides additional data-protection rules for telecommunications networks and internet services and is targeted for amendment by the Digital Omnibus proposal alongside the GDPR and EUDPR.
Dark PatternsRed
No EUI-specific dark-pattern prohibition distinct from general GDPR/DSA-level discourse was identified for the EC/EUDPR context.
The Digital Omnibus proposal introduces requirements on automated, machine-readable indications of individuals' choices regarding data processing, which the EDPB/EDPS jointly support as a solution to consent fatigue.
Claims (1):
The EDPB and the EDPS strongly support the Digital Omnibus's objective of addressing consent fatigue and cookie-banner proliferation via automated, machine-readable indications of individuals' processing choices.
Clean Rooms And DcrRed
No clean-room/data-collaboration-room regime specific to EUIs was identified.
Absence provenance: unavailable. Searched: EDPS clean room data collaboration EUI.
Cross Context AdvertisingAmber
EDPS newsletter reporting references an EDPS review of whether the European Commission organised a micro-targeting campaign on a social-media platform (X), indicating active EDPS scrutiny of EUI targeted-communication practices.
Claims (1):
EDPS newsletter reporting flags scrutiny of whether the European Commission organised a micro-targeting campaign on the social-media platform X, indicating active EDPS review of EUI targeted-communications practices.
Direct MarketingRed
EUIs, as public bodies, are not typically direct-marketing actors; no dedicated EUDPR direct-marketing consent/suppression regime was identified.
Absence provenance: unavailable. Searched: EUDPR direct marketing consent EUI.
Category narrative65 words
EUIs are public-sector controllers, not commercial adtech operators, so several sub-modules (dark patterns, clean rooms/DCR, direct marketing) have no dedicated EUDPR content; however, EUI websites/communications fall under Art 36 confidentiality-of-communications and the ePrivacy Directive, and the EDPS has itself investigated an EUI's own targeted-communication practices (a European Commission social-media micro-targeting campaign). The pending Digital Omnibus proposes EU-wide automated consent-signal mechanisms relevant to cookie/tracker consent generally.
Sources and claims (3)
ConfirmedEDPS — The ePrivacy Directive 2002/58/EC provides additional data-protection rules for telecommunications networks and internet services and is targeted for amendment by the Digital Omnibus proposal alongside the GDPR and EUDPR.observed
ConfirmedEDPB — The EDPB and the EDPS strongly support the Digital Omnibus's objective of addressing consent fatigue and cookie-banner proliferation via automated, machine-readable indications of individuals' processing choices.observed
UncertainEDPS — EDPS newsletter reporting flags scrutiny of whether the European Commission organised a micro-targeting campaign on the social-media platform X, indicating active EDPS review of EUI targeted-communications practices.observed
Mature, actively-resourced supervisory framework (dedicated EDPS AI Unit since Oct 2024, published AI Compass 2026-2027); amber risk only from the pending Digital Omnibus on AI timeline changes.
Primary frameworkRegulation (EU) 2018/1725, Art 24; Regulation (EU) 2024/1689 (AI Act) as applied to EUIs
Traffic-light rationale — GreenMature, actively-resourced supervisory framework (dedicated EDPS AI Unit since Oct 2024, published AI Compass 2026-2027); amber risk only from the pending Digital Omnibus on AI timeline changes.
Sub-modules (6)
Profiling RestrictionsGreen
Art 24 restricts automated individual decision-making including profiling, and decisions may not be based on special-category data save under narrow exceptions with safeguards.
Claims (1):
Automated individual decisions under Article 24 of the EUDPR shall not be based on special categories of personal data referred to in Article 10(1), unless narrow exceptions apply with suitable safeguards for the data subject's rights, freedoms and legitimate interests.
Automated Decision Making TransparencyGreen
The right of access under Art 17 extends to information on the logic involved in any automated decision-making process concerning the data subject.
Claims (1):
The right of access allows a data subject to obtain from the controller confirmation of processing, the purposes, and the logic involved in any automated decision process concerning him or her.
Ai Risk AssessmentsGreen
The EDPS published its 'Compass' for its AI Act role (17 March 2026), identifying over 100 AI systems deployed or under development across EUIs and setting four strategic supervisory pillars for 2026-2027.
Claims (1):
The EDPS's mapping exercise for its AI Act role identified more than one hundred AI systems currently deployed or under development across EUIs, with the highest concentration of high-risk use cases in the Area of Freedom, Security and Justice and in employment/recruitment.
Biometric RegimeGreen
Article 43(1) of the AI Act designates the EDPS as the notified body for conformity assessment of high-risk AI systems of EUIs in the areas of remote biometric identification, biometric categorisation, and emotion recognition.
Claims (1):
Article 43(1) of the AI Act designates the EDPS as a notified body in charge of conformity assessment for high-risk AI systems of EUIs in the areas of remote biometric identification, biometric categorisation and emotion recognition under Annex III(1) of the AI Act.
Genetic DataGreen
Genetic data is enumerated among the EUDPR special categories under Art 10, subject to the same restrictive processing conditions as other sensitive categories.
Claims (1):
Genetic data is enumerated as a special category of personal data under Article 10 of the EUDPR, subject to restrictive processing conditions.
State Surveillance CarveoutsAmber
Art 25 permits EUIs to restrict data-subject rights (Arts 14-22, 35-36) where necessary and proportionate to safeguard enumerated public-interest objectives (including security and defence), subject to publication of the restricting legal act/internal rule in the Official Journal and EDPS consultation.
Claims (1):
Legal acts adopted on the basis of the Treaties, or internal rules on the operation of Union institutions and bodies, may restrict Articles 14-22, 35-36 EUDPR where the restriction respects the essence of fundamental rights and is a necessary and proportionate measure in a democratic society, and such restrictions must be clear, precise, published in the Official Journal, and adopted at the highest management level.
Category narrative67 words
EUDPR Art 24 (automated individual decision-making including profiling) is the EUI-context analogue of GDPR Art 22. Since 2024 the EDPS additionally holds a sui generis role under the AI Act (Regulation (EU) 2024/1689) as the competent supervisory/market-surveillance authority and notified body for EUI AI systems, including biometric high-risk systems (remote biometric identification, categorisation, emotion recognition). Art 25 permits national-security/defence-adjacent restrictions on data-subject rights via published internal rules.
no periodic updates on record for this sub-brief
Sources and claims (6)
ConfirmedPublications Office of the EU — Automated individual decisions under Article 24 of the EUDPR shall not be based on special categories of personal data referred to in Article 10(1), unless narrow exceptions apply with suitable safeguards for the data subject's rights, freedoms and legitimate interests.observed
ConfirmedEDPS — The right of access allows a data subject to obtain from the controller confirmation of processing, the purposes, and the logic involved in any automated decision process concerning him or her.observed
ConfirmedEDPS — The EDPS's mapping exercise for its AI Act role identified more than one hundred AI systems currently deployed or under development across EUIs, with the highest concentration of high-risk use cases in the Area of Freedom, Security and Justice and in employment/recruitment.observed
ConfirmedEDPS — Article 43(1) of the AI Act designates the EDPS as a notified body in charge of conformity assessment for high-risk AI systems of EUIs in the areas of remote biometric identification, biometric categorisation and emotion recognition under Annex III(1) of the AI Act.observed
ConfirmedEDPB — Genetic data is enumerated as a special category of personal data under Article 10 of the EUDPR, subject to restrictive processing conditions.observed
ConfirmedPublications Office of the EU — Legal acts adopted on the basis of the Treaties, or internal rules on the operation of Union institutions and bodies, may restrict Articles 14-22, 35-36 EUDPR where the restriction respects the essence of fundamental rights and is a necessary and proportionate measure in a democratic society, and such restrictions must be clear, precise, published in the Official Journal, and adopted at the highest management level.observed
Core child-consent rule is codified and confirmed, but education-settings and dependent-adults sub-modules have no dedicated EUI content, and minor-specific profiling bans are inferred rather than explicit.
Traffic-light rationale — AmberCore child-consent rule is codified and confirmed, but education-settings and dependent-adults sub-modules have no dedicated EUI content, and minor-specific profiling bans are inferred rather than explicit.
Sub-modules (5)
Age VerificationGreen
Where consent is the legal basis, EUDPR Art 8(1) deems processing of a child's data lawful where the child is at least 13 years old in the context of an offer of information-society services directly to the child.
Claims (1):
Where point (d) of Article 5(1) of the EUDPR applies, in relation to the offer of information society services directly to a child, the processing of a child's personal data is lawful where the child is at least 13 years old.
Parental ConsentGreen
Below age 13, EUDPR Art 8 requires the holder of parental responsibility to give or authorise consent, and the controller must make reasonable efforts to verify this, taking available technology into account.
Claims (1):
Where a child is below the age of 13, EUDPR processing of the child's information-society-service data is lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify this, taking into consideration available technology.
Minor Profiling BansAmber
No EUDPR provision creates a categorical profiling ban specific to minors beyond the general Art 24(4) restriction on special-category-based automated decisions; the EDPS has engaged in public conferences on children's digital rights (e.g. its 'From Cradle to Cloud' event) but this is soft-law engagement, not a binding minor-specific profiling prohibition.
Claims (1):
On 4 July 2025, the EDPS and EDPB Trainees organised the 'From Cradle to Cloud: Surveillance and Digitalisation around Childhood' conference to foster discussion on the digital rights of children and minors, reflecting active but non-binding EDPS engagement on minors' data protection.
Education SettingsRed
No dedicated EUI education-settings sub-regime under EUDPR was identified.
Absence provenance: unavailable. Searched: EDPS education settings children EUI data protection, EUDPR school-specific provisions.
Dependent AdultsRed
No dedicated EUDPR provision addressing dependent/vulnerable adults distinct from general data-subject rights was identified.
Article 8 of the EUDPR is the EUI-context analogue of GDPR Art 8, setting the age threshold for a child's own consent to information-society services at 13 (with parental-responsibility-holder consent required below that age) — notably EUDPR sets a fixed 13-year floor rather than the GDPR's Member-State-adjustable 13-16 range. Dedicated EUI education-settings and dependent-adults sub-regimes were not identified.
Sources and claims (3)
ConfirmedPublications Office of the EU — Where point (d) of Article 5(1) of the EUDPR applies, in relation to the offer of information society services directly to a child, the processing of a child's personal data is lawful where the child is at least 13 years old.observed
ConfirmedPublications Office of the EU — Where a child is below the age of 13, EUDPR processing of the child's information-society-service data is lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify this, taking into consideration available technology.observed
ProbableEDPS — On 4 July 2025, the EDPS and EDPB Trainees organised the 'From Cradle to Cloud: Surveillance and Digitalisation around Childhood' conference to foster discussion on the digital rights of children and minors, reflecting active but non-binding EDPS engagement on minors' data protection.observed
EDPS enforcement toolkit is active and demonstrably used against major EUIs (including the European Commission itself); amber-adjacent risk stems only from pending Digital Omnibus changes to underlying substantive rules, not from an enforcement capacity gap.
Primary frameworkRegulation (EU) 2018/1725, Arts 58, 65-66, 86
Traffic-light rationale — GreenEDPS enforcement toolkit is active and demonstrably used against major EUIs (including the European Commission itself); amber-adjacent risk stems only from pending Digital Omnibus changes to underlying substantive rules, not from an enforcement capacity gap.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
Art 58 confers the EDPS a wide range of investigative, corrective (including data-flow-suspension), and authorisation/advisory powers; Art 66 allows the EDPS to impose administrative fines on a Union institution or body for non-compliance with specified EDPS orders, with the CJEU holding unlimited jurisdiction to cancel, reduce or increase such fines.
Claims (2):
Article 58 of Regulation (EU) 2018/1725 confers the EDPS a wide range of investigative powers including risk-based compliance audits, and corrective powers including ordering rectification/erasure/restriction, imposing administrative fines under Article 66 for non-compliance with EDPS orders, and ordering suspension of data flows to a recipient in a Member State, third country, or international organisation.
The Court of Justice of the European Union has unlimited jurisdiction to review administrative fines imposed by the EDPS under Article 66, and may cancel, reduce or increase those fines within the limits of that Article.
Enforcement Activity IndexGreen
Following EDPS enforcement proceedings and a March 2024 Decision identifying infringements and imposing corrective measures, the European Commission demonstrated compliance with the EUDPR regarding its use of Microsoft 365 by December 2024; the EDPS separately reprimanded Frontex in January 2025 for unlawful data-sharing with Europol, and reprimanded EPSO over remote-testing practices.
Claims (2):
Following enforcement proceedings by the EDPS, the European Commission demonstrated compliance with Regulation (EU) 2018/1725 in relation to its use of Microsoft 365, following the EDPS's Decision of 8 March 2024 which had identified infringements and imposed corrective measures, with compliance confirmed by 9 December 2024.
On 8 January 2025, the EDPS issued a reprimand to Frontex for infringing Regulation (EU) 2019/1896 by systematically sharing personal data of suspects of cross-border crime with Europol without assessing whether such sharing was strictly necessary, following an EDPS audit opened in October 2022.
Regulator Funding And CapacityGreen
The Union budgetary authority is required to ensure the EDPS is provided with the human and financial resources necessary for the performance of its tasks, with a separate budgetary heading; the EDPS also established a dedicated AI Unit in October 2024 to operationalise its expanded AI Act mandate.
Claims (1):
The budgetary authority shall ensure that the EDPS is provided with the human and financial resources necessary for the performance of its tasks, with the EDPS budget shown in a separate budgetary heading of the Union's general budget.
Collective Redress And Class ActionsAmber
The EUDPR permits a data subject to mandate a not-for-profit organisation to lodge a complaint with the EDPS on their behalf, functioning as a limited representative-action mechanism.
Claims (1):
The EUDPR permits a data subject to mandate a not-for-profit organisation to lodge a complaint with the EDPS on the data subject's behalf.
Private Right Of ActionGreen
Any person who has suffered material or non-material damage as a result of an EUDPR infringement has the right to receive compensation from the responsible Union institution or body, subject to Treaty conditions, alongside the right to a judicial remedy before the CJEU.
Claims (1):
Any person who has suffered material or non-material damage as a result of an infringement of the EUDPR has the right to receive compensation from the responsible Union institution or body, subject to the conditions provided for in the Treaties.
Recent Developments 180DAmber
Within the last 180 days: the EDPB/EDPS adopted Joint Opinion 2/2026 on the Digital Omnibus Regulation proposal (Feb 2026) and a Joint Opinion on the 'Digital Omnibus on AI' (Jan 2026); the EDPS published its AI Act 'Compass' for 2026-2027 (17 March 2026); the EDPB launched its 2026 Coordinated Enforcement Framework action on transparency/information obligations (19 March 2026); the EDPS/BfDI/BayLfD held a high-level Digital Omnibus debate (8 June 2026); the EDPB adopted anonymisation and generative-AI web-scraping guidelines (8 July 2026); and the EDPB, meeting in Dublin, called for a clearer legal basis for cross-regulatory information sharing among regulators (16-17 July 2026).
Claims (3):
The EDPB and EDPS adopted a Joint Opinion on the Digital Omnibus Regulation proposal, which amends Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and several directives, following the Commission's formal consultation under Article 42(2) EUDPR on 25 November 2025.
The EDPB launched its 2026 Coordinated Enforcement Framework action on 19 March 2026, shifting focus from the 2025 right-to-erasure action to compliance with transparency and information obligations under Articles 12-14 GDPR, with 25 DPAs participating during 2026.
At a high-level meeting in Dublin on 16-17 July 2026, the EDPB called for a clear legal basis for the sharing of information among regulators with different competences, and discussed expanding cooperation to support consistent GDPR application.
Category narrative116 words
The EDPS has a full investigative/corrective/authorisation power toolkit under Art 58 (audits, orders, suspension of data flows, administrative fines under Art 66 for non-compliance with EDPS orders), with Art 65 giving affected individuals a right to compensation and Art 66(3) giving the Court of Justice unlimited jurisdiction to review fines. Enforcement activity in the trailing ~24 months includes the Commission Microsoft 365 decision (March 2024, compliance confirmed December 2024), the Frontex reprimand (January 2025), an EPSO reprimand, and ongoing own-initiative investigations (EU Parliament Wi-Fi, Europol's 'big data challenge'). Article 86 preserves a representative-complaint mechanism via not-for-profit organisations. Recent 180-day developments (Feb-Aug 2026) are dominated by the Digital Omnibus reform process and the EDPS's AI Act 'Compass'.
no periodic updates on record for this sub-brief
Sources and claims (10)
ConfirmedEDPS — Article 58 of Regulation (EU) 2018/1725 confers the EDPS a wide range of investigative powers including risk-based compliance audits, and corrective powers including ordering rectification/erasure/restriction, imposing administrative fines under Article 66 for non-compliance with EDPS orders, and ordering suspension of data flows to a recipient in a Member State, third country, or international organisation.observed
ConfirmedPublications Office of the EU — The Court of Justice of the European Union has unlimited jurisdiction to review administrative fines imposed by the EDPS under Article 66, and may cancel, reduce or increase those fines within the limits of that Article.observed
ConfirmedEDPS — Following enforcement proceedings by the EDPS, the European Commission demonstrated compliance with Regulation (EU) 2018/1725 in relation to its use of Microsoft 365, following the EDPS's Decision of 8 March 2024 which had identified infringements and imposed corrective measures, with compliance confirmed by 9 December 2024.observed
ConfirmedEDPS — On 8 January 2025, the EDPS issued a reprimand to Frontex for infringing Regulation (EU) 2019/1896 by systematically sharing personal data of suspects of cross-border crime with Europol without assessing whether such sharing was strictly necessary, following an EDPS audit opened in October 2022.observed
ConfirmedPublications Office of the EU — The budgetary authority shall ensure that the EDPS is provided with the human and financial resources necessary for the performance of its tasks, with the EDPS budget shown in a separate budgetary heading of the Union's general budget.observed
ConfirmedPublications Office of the EU — The EUDPR permits a data subject to mandate a not-for-profit organisation to lodge a complaint with the EDPS on the data subject's behalf.observed
ConfirmedPublications Office of the EU — Any person who has suffered material or non-material damage as a result of an infringement of the EUDPR has the right to receive compensation from the responsible Union institution or body, subject to the conditions provided for in the Treaties.observed
ConfirmedEDPS — The EDPB and EDPS adopted a Joint Opinion on the Digital Omnibus Regulation proposal, which amends Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and several directives, following the Commission's formal consultation under Article 42(2) EUDPR on 25 November 2025.observed
ConfirmedEDPB — The EDPB launched its 2026 Coordinated Enforcement Framework action on 19 March 2026, shifting focus from the 2025 right-to-erasure action to compliance with transparency and information obligations under Articles 12-14 GDPR, with 25 DPAs participating during 2026.observed
ConfirmedEDPB — At a high-level meeting in Dublin on 16-17 July 2026, the EDPB called for a clear legal basis for the sharing of information among regulators with different competences, and discussed expanding cooperation to support consistent GDPR application.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
No failing checks.
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
93.88
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Ecuador
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 54 claim(s) (54 category placement(s)), 55 source(s) in the cumulative register.
Regulator/framework, lawful-processing, data-subject-rights, controller/processor-duties, and enforcement/redress modules rest on T1 primary-source coverage (EUR-Lex consolidated EUDPR text, EDPS official guidance/decisions, EDPB official news/PDF publications). Cross-border/adequacy is T1-grounded for the transfer-mechanism cascade (Arts 46-50) but structurally amber because EUDPR cross-references GDPR/LED adequacy decisions rather than issuing its own. Sectoral_watch and children_and_vulnerable_groups modules are T1-grounded where EUI-specific sub-regimes exist (ESMA/EIOPA Art 25 decisions, EUDPR Art 8 child-consent threshold) but carry explicit absent_field_provenance for sub-modules with no EUI-specific counterpart (credit scoring, education, dependent adults) since EUIs are public administration bodies, not commercial/consumer-facing actors in those senses. Adtech_and_commercial_privacy relies partly on T3 (IAPP) commentary for Digital Omnibus context alongside T1 EDPB/EDPS joint opinions. Algorithmic/biometric/surveillance module is strongly T1-grounded via the EDPS's own AI Act Compass and Opinion 44/2023.
Unresolved questions (4):
Final adopted text and entry-into-force date of the Digital Omnibus Regulation (including its EUDPR amendments) remain pending trilogue outcome as of August 2026.
Whether the Digital Omnibus on AI's proposed high-risk timeline extension (capped at December 2027) will alter the EDPS's AI Act market-surveillance/notified-body workload projections set out in its 2026-2027 Compass.
Precise current headcount/budget figures for the EDPS (as opposed to qualitative resource-adequacy statements) were not located in the sources reviewed.
Whether any EUI-specific dependent-adults or education-settings internal rules exist at individual-agency level (as opposed to Union-wide EUDPR text) was not confirmed and may require agency-by-agency review.