What Changed
- The EDPB called for European Commission legislation enabling regulators in adjacent fields to share confidential enforcement information.
- DPAs discussed practical mechanisms to pool resources, conduct joint operations, and support lead supervisory authorities amidst rising AI-related complaints.
- The Board committed to holding enforcement procedure workshops in the context of implementing the upcoming Procedural Regulation.
The European Data Protection Board (EDPB) has urged the European Commission to propose a clear legal basis enabling cross-regulatory information sharing. The position was stated at a high-level meeting in Dublin on 16 and 17 July 2026. This development affects digital regulators, Data Protection Authorities (DPAs), and organizations operating across adjacent regulatory sectors within the European Union.
According to the Board, the evolving regulatory environment demands effective cooperation between regulators operating under adjacent areas of EU law. Establishing a statutory legal basis would permit regulators to exchange relevant information, including confidential enforcement details. EDPB Chair Anu Talus noted that first-hand experience with digital regulators at national and EU levels underscores the need for stronger legislation to remove cooperation barriers, enhance cross-regulatory coherence, and improve enforcement outcomes.
The EDPB also addressed operational challenges confronting DPAs, specifically a sharp increase in the number and complexity of complaints linked to the expanded use of artificial intelligence (AI). To mitigate resource constraints and ensure efficient enforcement of the General Data Protection Regulation (GDPR), the Board discussed practical solutions and resource-pooling strategies. These include enabling complaint-receiving authorities to support lead supervisory authorities with resources, increasing the use of joint operations, and hosting workshops on national enforcement practices ahead of the upcoming Procedural Regulation. Des Hogan, Chairperson and Commissioner for Data Protection in Ireland, stated that information sharing and joint operations will assist DPAs in pooling resources, protecting individuals, and providing regulatory clarity for industry.
Furthermore, the EDPB reviewed progress under the 2025 Helsinki Statement on enhanced clarity, support, and engagement, reiterating its commitment to expanding dialogue across the broader data protection ecosystem. The news release also noted recent regulatory actions, including a 403,000,000 EUR fine issued by the Irish Data Protection Commission against Google concerning location data processing, and a 100,000 EUR fine by the Spanish DPA against Securitas Direct related to data subject rights.
Who May Be Affected
EU digital regulators, Data Protection Authorities, and businesses operating in adjacent regulated digital markets across the EU.
Cross-Border Context
The call concerns EU-wide regulatory coordination, joint operations, and information exchange affecting cross-border enforcement across EU Member States.
What to check next
- Legislative proposals or consultations issued by the European Commission regarding cross-regulatory information sharing.
- Developments and official text regarding the upcoming GDPR Procedural Regulation.
This article provides general information and does not constitute legal advice. Consult the official text and obtain advice appropriate to your circumstances where needed.
Prepared automatically with AI assistance from the official sources linked on this page. Translations and explanations do not replace the official text.