EDPB Adopts a Harmonised DPIA Template: What Changes for Practitioners

EDPB Adopts a Harmonised DPIA Template: What Changes for Practitioners

The EDPB has published a harmonised DPIA template, now open for public consultation until 9 June 2026. The template introduces a clear methodological distinction between risks inherent in the processing design and risks arising from non-default events. An analysis of its structure and implications for practitioners.

14 April 2026 · 9 min · NicFab
European AI Continent Action Plan: critical analysis one year on

AI Continent Action Plan: the Real Test Remains Trustworthy AI

The European Commission celebrates the milestones of the AI Continent Action Plan. But beyond the AI Factory numbers, the credibility of the European model depends on making the Trustworthy AI pillar truly operational.

10 April 2026 · 6 min · NicFab
Data Protection Day 2026 - 45 Years of Convention 108

Data Protection Day 2026: 45 Years of Convention 108 and the Challenge of Staying Vigilant

On 28 January 2026, we celebrate Data Protection Day, the anniversary of Convention 108. Between GDPR revision proposals, simplification measures, and new technologies, personal data protection requires constant vigilance. An analysis of current challenges supported by empirical data and institutional sources.

28 January 2026 · 12 min · NicFab
DMA GDPR Guidelines Consultation

Public Consultation on Joint Guidelines on the Interplay between DMA and GDPR

Public consultation open until 4 December 2025 on guidelines regulating the interplay between Digital Markets Act and GDPR

9 October 2025 · 4 min · NicFab
EDPB-EDPS Joint Opinion 01/2025 on SME Record-Keeping Simplification

EDPB-EDPS Joint Opinion 01/2025 on SME Record-Keeping Simplification

🚨 NEW EDPB-EDPS Joint Opinion on SME Record-Keeping Simplification On 9 July 2025, the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) released their Joint Opinion 01/2025 on the proposed regulation to simplify record-keeping obligations for small and medium-sized enterprises (SMEs) and small mid-cap companies (SMCs). 🎯 Key Highlights: Extended threshold: The proposal would raise the employee threshold from 250 to 750 employees for record-keeping exemptions under Art. 30(5) GDPR Broader scope: SMCs (small mid-cap companies) would also benefit from simplified obligations Risk-based approach maintained: High-risk processing activities would still require full compliance regardless of company size Administrative burden reduction: Aims to provide greater flexibility for smaller organizations while maintaining data protection standards 💡 EDPB-EDPS Position: The authorities express preliminary support for this targeted simplification initiative, welcoming the risk-based approach that ensures fundamental rights protection remains intact. However, they’ve requested further clarification on the new 750-employee threshold and recommend better alignment with the newly introduced SME/SMC definitions. ...

10 July 2025 · 1 min · NicFab
Main EDPB Documents (updated on 12/1/2023)

Main EDPB Documents (updated on 12/1/2023)

List of the key adopted and published documents by the European Data Protection Board - EDPB

12 January 2023 · 33 min · NicFab