Skip to main content
Is Your GDPR Program Ready for the EDPB's Next Chapter?Privacy Regulations
5 min readFor Data Protection Officers

Is Your GDPR Program Ready for the EDPB's Next Chapter?

The European Data Protection Board (EDPB) is becoming increasingly central to your data protection strategy. With the EU's Digital Omnibus package proposing amendments to the GDPR and Anu Talus leading the EDPB through significant changes, it's time to evaluate your compliance framework before new guidance is issued.

This checklist will help you align your program with the EDPB's enforcement direction and prepare for regulatory shifts affecting rights requests, AI processing documentation, and coordination with supervisory authorities.

Prerequisites

Before starting this assessment, gather:

  • Your current GDPR compliance documentation (DPIAs, processing registers, lawful basis assessments)
  • Records of any supervisory authority correspondence from the past 24 months
  • Your AI and automated decision-making inventory (if you process personal data through algorithmic systems)
  • Documentation of any cross-border processing activities requiring cooperation between multiple supervisory authorities

If these materials aren't organized and accessible, prioritize getting them in order.

Checklist Items

1. Verify Your Consistency Mechanism Readiness

What to check: Review how your organization would respond if the EDPB issues binding decisions under Article 65 GDPR's consistency mechanism.

Action: Ensure you have a process to monitor EDPB binding decisions, translate them into operational requirements, and implement changes within 30 days.

Good looks like: You have a documented workflow assigning responsibility for EDPB decision monitoring, including legal review, and connecting to your change management process. Test this workflow annually with an EDPB guideline.

2. Document Your AI Processing Under GDPR Standards

What to check: If you use AI systems that process personal data, assess whether your documentation meets GDPR Article 22 requirements and aligns with EDPB guidance on automated decision-making.

Action: For each AI system, document the logic involved, the significance and envisaged consequences for data subjects, and whether human review is available. Update your Article 30 processing register to identify AI-driven processing separately.

Good looks like: A non-technical colleague can explain what the system decides, what data it uses, and how a data subject can request human review. Your legal team has confirmed this meets the "meaningful information" standard from EDPB Guidelines 3/2019.

3. Audit Your Cross-Border Processing Coordination

What to check: If you operate in multiple EU member states, review whether you've correctly identified your lead supervisory authority under Article 56 GDPR and whether your breach notification procedures account for EDPB coordination requirements.

Action: Map each processing activity to the supervisory authority with jurisdiction. For any processing affecting data subjects in multiple member states, document how you'd handle a situation requiring EDPB dispute resolution under Article 60 or 64.

Good looks like: You have a matrix showing which supervisory authority covers each processing activity, contact information for your lead authority's DPO liaison, and a 72-hour notification template including fields for cross-border impact assessment.

4. Prepare for Digital Omnibus Amendments

What to check: Review your compliance program's flexibility to absorb regulatory changes, particularly around Technical and Organisational Measures and accountability documentation.

Action: Identify which GDPR articles your current compliance program depends on most heavily (typically Articles 6, 13, 14, 15, 30, 32, 35). For each, document what operational changes you'd need if that article's requirements were modified. Don't wait for final text.

Good looks like: You have a risk register listing your five highest-impact GDPR dependencies and preliminary mitigation plans. Your legal counsel has reviewed the Digital Omnibus proposal and flagged articles requiring system changes, not just documentation updates.

5. Test Your EDPB Guidance Implementation Process

What to check: Assess how quickly your organization translates EDPB guidelines into operational practice.

Action: Pick the most recent EDPB guideline relevant to your processing (check edpb.europa.eu for adopted guidelines). Document how long it took to review it, assess impact, and implement necessary changes. If you haven't done this, do it now with any guideline from the past 12 months.

Good looks like: You completed review within two weeks of publication, impact assessment within 30 days, and implementation within 90 days. You have meeting notes showing cross-functional discussion between legal, engineering, and privacy teams.

6. Validate Your Supervisory Authority Escalation Path

What to check: Confirm you know when and how to escalate complex processing questions to your supervisory authority, particularly for high-risk processing requiring Prior Consultation under Article 36.

Action: Review your DPIA process. For any processing that scored as high-risk but where you didn't perform Prior Consultation, document why consultation wasn't required. Create a decision tree to determine when Article 36 applies.

Good looks like: You have written guidance explaining the Prior Consultation threshold, examples of processing that did and didn't require it, and contact information for your supervisory authority's consultation intake process. Your team can articulate the difference between informal guidance requests and formal Article 36 consultation.

7. Confirm Your Rights Request Process Reflects EDPB Standards

What to check: Review whether your data subject rights fulfillment process aligns with EDPB guidance on verification, fees, and response timelines.

Action: Audit your past 20 rights requests. Check: Did you verify identity appropriately? Did you respond within one month (or communicate an extension)? Did you document why any requests were refused? Compare your practices against EDPB Guidelines 01/2022 on data subject rights.

Good looks like: Your rights request log shows consistent response times, documented verification steps, and clear reasoning for any rejections. You can demonstrate that your verification process is proportionate to the sensitivity of data and the risk of disclosure to the wrong person.

Common Mistakes

  • Treating EDPB guidelines as optional. Guidelines aren't binding law, but supervisory authorities use them as enforcement standards. If your practices diverge from EDPB guidance, you need documented justification.
  • Ignoring binding decisions that don't mention your sector. Article 65 decisions establish precedent across all processing contexts. A binding decision about consent in adtech affects how you handle consent in HR systems.
  • Waiting for national Supervisory Authority guidance instead of consulting EDPB materials. Your supervisory authority interprets GDPR through the EDPB's lens. Start with EDPB guidance, then layer in national interpretation.
  • Assuming AI compliance is an IT problem. The EDPB's focus on automated decision-making means your legal and privacy teams need to understand your AI systems' logic, not just their technical architecture.
  • Missing the consistency mechanism's implications. If the EDPB issues a binding decision contradicting your current practice, you can't wait for your local supervisory authority to tell you to change. The decision applies across the EU immediately.

Next Steps

Schedule a quarterly EDPB monitoring review. Assign someone to track new guidelines, binding decisions, and statements from the Chair. The EDPB publishes its work program annually; use it to anticipate where guidance is coming.

If any checklist item revealed a gap, document it as a compliance risk with a remediation timeline. The EDPB's role in ensuring consistent GDPR application means that practices acceptable in one member state won't shield you if they conflict with EDPB guidance.

Finally, don't treat this checklist as a one-time exercise. The EDPB's priorities will shift as the Digital Omnibus package moves through the legislative process and as AI regulation matures. Your compliance program needs to shift with them.

You Might Also Like