European Union and EEA

EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes

60 controls. 3 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

60 controls 3 frameworks share controls with it European Union and EEA verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
RDCOC-ADH-01Adherence Procedures0
RDCOC-ANO-01Anonymisation Criteria1
RDCOC-APP-01Supervisory Authority / EDPB Approval0
RDCOC-AUD-01Audits and Compliance Reviews0
RDCOC-BRE-01Breach Notification Procedures1
RDCOC-COM-01Complaint Handling1
RDCOC-CON-01Consent and Broad Consent1
RDCOC-DPI-01Data Protection Impact Assessments1
RDCOC-GOV-01Code Owner and Governance0
RDCOC-LAW-01Lawful Basis for Research1
RDCOC-MON-01Accredited Monitoring Body0
RDCOC-PRO-01Processor Engagements1
RDCOC-PSE-01Pseudonymisation Standards1
RDCOC-RET-01Retention and Archival1
RDCOC-REV-01Periodic Review and Update0
RDCOC-RIG-01Data Subject Rights and Information in Research1
RDCOC-SAN-01Sanctions and Suspension0
RDCOC-SCO-01Scope of Processing Activities1
RDCOC-TRA-01International Data Transfers1
RDCOC-TRN-01Training and Awareness1
2.12.1 Substantiate that processing is for scientific research purposes against the six key-indicative factors0
2.2-2.32.2-2.3 Research data infrastructures and ancillary operations assessed against the same factors0
3.1.13.1.1 Further processing for research is presumed compatible, but lawfulness, the Article 9 derogation and Member State limits are assessed anew0
3.1.23.1.2 Providing personal data to another controller for its research: no compatibility test, both controllers comply in full0
3.23.2 Storage limitation: determine and communicate the period before processing, store for specified future research only, review necessity and format0
4.1.14.1.1 Consent must be freely given: vulnerable participants, patients' capacity, no conditioning of care, and remuneration assessed0
4.1.24.1.2 Choose broad or dynamic consent before processing, document the choice, define the research area, keep projects within it0
4.1.2.14.1.2.1 Broad consent safeguards: detailed and continuing information, use and access controls, time limits, an oversight body, a choice tool0
4.1.34.1.3 Distinguish consent to participate in research from GDPR consent, and keep the two requests distinguishable0
4.24.2 Public interest as a legal basis needs a Union or Member State law meeting necessity and proportionality, open to private entities the law covers0
4.34.3 Legitimate interest: significant weight for research, reasonable expectations, and safeguards folded into the balancing test0
4.44.4 Special categories: determine the Article 9(2) derogation, treat inferred and collatable data as special, DPIA at large scale, Member State conditions0
4.4.24.4.2 Data manifestly made public: a high threshold requiring the data subject's own explicit, affirmative choice in context0
4.4.34.4.3 Derogations in Union or Member State law: show the law applies and implement its suitable and specific measures, adding safeguards where the law did not anticipate the risks0
5.15.1 Give data subjects a way to stay informed over long research: voluntary contact details, choice of channel, a webpage or application0
5.25.2 Information at collection, layered where appropriate; a controller without the data or contact must still inform and answer access requests through its processor or co-controll0
5.35.3 Inform before further processing for research with time to react, never knowingly delete contact details, make reasonable efforts to reach data subjects and inform indirectly w0
5.45.4 Receiving controllers inform under Article 14, including for data they generate; cooperate with providers and intermediaries; tell pseudonymised-data subjects how to exercise r0
5.4.25.4.2 Impossibility, disproportionate effort and research-impairing individual information: exemptions that still require public information and safeguards, especially for covert r0
5.55.5 Inform data subjects of changes that make earlier information obsolete, in time to act; which changes count and which do not0
6.16.1 Determine the restrictions and derogations of rights in Union or Member State law, and the additional rights, and inform data subjects of them0
6.26.2 Erasure requests: test the Article 17(1) grounds, then the Article 17(3)(d) exception restrictively and case by case, and warn of it in advance0
6.36.3 Objections: the controller bears the burden of compelling grounds; under Article 21(6) necessity for a public-interest task is strict, verified at the time of the request, and 0
7.17.1 Attribute controllership functionally, document the allocation, and recognise the sponsor or protocol author as controller even without handling identifiable data0
7.27.2 Processors act within the controller's instructions and become controllers, with the liability that follows, where they decide purposes or essential means0
7.37.3 Joint controllers: joint determination of the protocol, an Article 26 arrangement reflecting differing responsibilities and made available to data subjects, processors engaged 0
8.18.1 Article 89(1) safeguards assessed on nature, scope, context, purposes and risks, in addition to the GDPR's general measures, and reassessed on further processing0
8.28.2 Start with a risk analysis or DPIA that looks beyond privacy to other fundamental rights, health findings, re-identification, publication and vulnerable or related persons0
8.38.3 Anonymise where the purposes allow, otherwise pseudonymise, identify directly only where strictly necessary; decide the format at planning, keep methods state of the art and ve0
8.48.4 Genetic and biometric data: particular caution, restrictive purposes, pseudonymisation, ethical approval, federated storage with secure access, role-based controls, and communi0
8.58.5 Select further safeguards fitted to the research method from the EDPB's menu: oversight governance, enhanced transparency, consent as a safeguard, strict purpose limits, PETs, 0
ART40Article 40 codes of conduct for research: the mechanism and the sector codes held (EDPB Guidelines 1/2019 and 04/2021; Farmaindustria, EUCROF, GEANT, CSA)0
GLEDPB Guidelines 1/2026: what they are, what is held and their status; the framework renamed from an Article 40 code that does not exist0
INFOSection 5: obligations to inform0
LAWSection 4: lawfulness, consent, public interest, legitimate interest and special categories0
PRINSection 3: purpose limitation and storage limitation0
RIGHTSSection 6: data subjects' rights0
ROLESSection 7: attribution of responsibility0
SAFESection 8: appropriate safeguards under Article 89(1)0
SCOPESection 2: the concept of processing for scientific research purposes0

Tell me when EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition