Skip to main content
Category: Compliance and Monitoring

Article 29 Working Party

Also known as: WP29, Art. 29 WP, Article 29 Data Protection Working Party, Working Party on the Protection of Individuals with regard to the Processing of Personal Data
Simply put

The Article 29 Working Party was a European-level advisory body that provided guidance on privacy and the protection of personal data. It was established under an earlier EU data protection law and issued opinions and guidance documents to help shape a consistent approach across the EU. It has since been replaced by the European Data Protection Board.

Formal definition

The Article 29 Working Party (WP29), formally the Working Party on the Protection of Individuals with regard to the Processing of Personal Data, was an independent EU advisory body established under Article 29 of Directive 95/46/EC. It functioned in an advisory capacity, issuing opinions, guidance, and interpretive materials on data protection matters rather than exercising direct enforcement or binding regulatory power. It was active from 1997 to 2018 and was replaced by the European Data Protection Board (EDPB); note that this entry does not cover the scope of the EDPB's expanded powers, the specific mandate provisions of Directive 95/46/EC, or how WP29 guidance is treated under the current GDPR framework.

Why it matters

The Article 29 Working Party matters primarily because its interpretive legacy did not disappear when the body itself ceased to exist. Although WP29 was an advisory body without direct enforcement power, its opinions and guidance shaped how data protection concepts were understood across EU Member States during the Directive 95/46/EC era, and practitioners still encounter references to its output when tracing the development of current interpretive positions. Understanding what WP29 was, and what it was not, helps compliance and legal professionals avoid treating its historical guidance as if it carried the same status as a binding regulatory instrument.

The distinction between advisory and enforcement roles is important to preserve. WP29 issued opinions and interpretive materials rather than exercising direct enforcement or binding regulatory power, which means its documents functioned as persuasive guidance rather than legally binding rules. Professionals who rely on archived WP29 materials should be careful not to overstate their authority and should verify how any particular position is treated under the current framework, since this entry does not address how WP29 guidance is carried forward or reconsidered under the GDPR.

WP29 was active from 1997 to 2018 and was replaced by the European Data Protection Board. Anyone reviewing older data protection documentation, guidance references, or interpretive materials will benefit from recognizing this transition, so that they can distinguish legacy WP29 output from materials issued by its successor body. This entry does not cover the scope of the EDPB's expanded powers or the specific mandate provisions of Directive 95/46/EC.

Who it's relevant to

Data protection officers and privacy leads
DPOs and privacy leads frequently encounter references to WP29 opinions when researching the historical development of interpretive positions. Recognizing that these were advisory materials, not binding rules, and that WP29 was replaced by the EDPB in 2018, helps them scope the authority of any legacy guidance they cite and verify current treatment separately.
Legal and compliance professionals
Lawyers and compliance staff reviewing older data protection documentation or building interpretive arguments benefit from understanding WP29's advisory role under Directive 95/46/EC. This context helps them avoid overstating the status of archived opinions and prompts confirmation of how positions are treated under the current framework, which this entry does not cover.
Researchers and policy analysts
Those studying the evolution of EU data protection governance can use the WP29 archive of materials issued between 1997 and 2018 as a historical record of interpretive thinking, while noting the transition to the European Data Protection Board as its successor body.

Inside WP29

Advisory body composition
The Article 29 Working Party was an independent advisory group made up of representatives from the data protection authorities of EU member states, together with a representative of the European Data Protection Supervisor and the European Commission. It operated under the framework of the predecessor EU data protection regime rather than the current one.
Guidance and opinions
The body issued opinions, working documents, and guidance interpreting data protection concepts. These outputs were advisory in nature and were intended to promote consistent interpretation across member states, but they did not themselves carry the force of binding law.
Successor relationship
The Article 29 Working Party was succeeded by the European Data Protection Board (EDPB) when the current EU data protection framework took effect. Some of its guidance was subsequently endorsed or adopted by the EDPB, while other material was superseded.
Scope of subject matter
Its work addressed interpretation of data protection principles and concepts within the EU context. It did not govern the UK regime as it now stands independently, nor US frameworks such as the CCPA and CPRA or HIPAA, which are separate instruments with different treatment.

Common questions

Answers to the questions practitioners most commonly ask about WP29.

Is the Article 29 Working Party the same body as the European Data Protection Board?
No. The Article 29 Working Party was an advisory body established under the earlier EU Data Protection Directive and was made up of representatives from national data protection authorities. It ceased operating and was succeeded by the European Data Protection Board (EDPB) when the EU GDPR became applicable. While there is institutional continuity in purpose, they are distinct bodies with different legal foundations, and conflating them can lead to citing an instrument under the wrong framework. This answer does not address the specific competences or procedures of either body.
Are the opinions and guidance issued by the Article 29 Working Party legally binding?
Generally, the Article 29 Working Party's output took the form of opinions, working documents, and guidance that were advisory rather than legally binding in themselves. They were influential in interpreting the earlier EU data protection regime, but they did not carry the force of law in the way a regulation or a national statute does. Whether any particular guidance remains relevant under the current framework depends on whether it has been endorsed or superseded, and this entry does not assess the current status of individual documents.
How should we treat older Article 29 Working Party guidance when building current compliance documentation?
As a practical matter, teams typically check whether a given Working Party document has been endorsed, replaced, or withdrawn by the successor body before relying on it, since guidance developed under the earlier framework may not fully reflect the current regime. Where guidance has been carried forward or re-adopted, it can inform interpretation, but you should confirm its current status rather than assume continued applicability. This entry does not catalogue which documents remain in force.
Can we cite Article 29 Working Party opinions in a data protection impact assessment?
You can reference such opinions as interpretive background where they remain relevant, but they should be treated as advisory context rather than as authoritative legal requirements. It is generally advisable to pair any such reference with the current applicable legal instrument and any endorsing guidance from the successor body, and to note that a DPIA is not mandatory in all circumstances. This answer does not determine when a DPIA is required.
Does relying on historical Working Party guidance demonstrate accountability under current governance frameworks?
Not on its own. Accountability generally requires demonstrable evidence that your processing and controls meet current obligations, not merely a citation to advisory guidance. Referencing interpretive material can support the reasoning behind a decision, but it does not substitute for documented assessments, records, and controls tied to the applicable current framework. This entry does not specify the evidence required for any particular accountability obligation.
How do we decide whether Article 29 Working Party material or successor guidance applies to a given interpretation question?
In most cases the practical approach is to start from the currently applicable legal instrument and its authoritative interpretive guidance, then treat earlier Working Party material as historical context that may or may not have been carried forward. Where the successor body has issued updated guidance on the same topic, that generally takes precedence. This entry does not resolve conflicts between specific documents or address jurisdiction-specific differences in how such guidance is weighed.

Common misconceptions

Article 29 Working Party guidance is current, binding EU law.
The Working Party was an advisory body whose outputs were interpretive rather than legally binding. It has been succeeded by the European Data Protection Board, and practitioners should generally check whether a given piece of guidance was carried over, endorsed, or superseded by the successor body before relying on it.
The Article 29 Working Party and the European Data Protection Board are the same entity.
They are distinct bodies operating under different frameworks. The Working Party functioned under the predecessor EU regime, while the EDPB operates under the current one. Conflating them can lead to citing outdated guidance as if it reflects the present legal position.
Article 29 Working Party opinions apply uniformly across all jurisdictions, including the UK and the US.
Its remit was the EU data protection context. The UK regime now stands independently, and US frameworks such as the CCPA and CPRA and HIPAA are separate instruments. Treatment of any given concept typically differs across these regimes and should not be assumed to be interchangeable.

Best practices

When referencing Article 29 Working Party material, verify whether it has been endorsed, replaced, or withdrawn by the European Data Protection Board before relying on it as current interpretive guidance.
Treat Working Party opinions as advisory interpretation rather than binding legal authority, and pair them with the operative legal instrument when documenting a compliance position.
Scope any reliance on Working Party guidance to the EU context, and do not assume it governs the UK regime or US frameworks such as the CCPA and CPRA or HIPAA without separate analysis.
Maintain demonstrable evidence of which guidance version informed a given decision, since accountability under governance frameworks requires more than stated intent.
Cross-check successor EDPB outputs for the same topic, as the successor body may have refined or superseded earlier positions.
Avoid citing specific article numbers, dates, or figures from Working Party materials unless you can substantiate the exact reference, and describe the concept instead where certainty is lacking.