Data Protection
The General Data Protection Regulation (GDPR), a major overhaul of data protection legislation in the EU, was formally adopted on 27 April 2016, with the new rules in place since 25 May 2018. The GDPR unifies data protection throughout the EU as it does not require any enabling legislation to be passed by Member States.
The GDPR significantly expands the scope of EU privacy legislation, applying also to organisations from outside the EU who process EU residents’ data. Consent requirements for collecting and processing data are strengthened, complemented by a right to erasure. Non-compliance with the regulations can result in heavy fines of up to 4 percent of the annual turnover of the organisation found to be in breach.
Originally, the regulation provided certain exemptions for research activities, based on a relatively broad definition of “research”:
- Article 6(1)(f): in certain circumstances, personal data may be used for research purposes without the person’s consent.
- Article 6(4): some restrictions on processing sensitive data categories do not apply to e.g. scientific or health research.
- Article 89: given appropriate safeguards researchers may even override a person’s objection to processing of his data or requests for erasure.
The Digital Omnibus package proposed in November 2025 (see more information on the Digital Omnibus here) introduces targeted amendments to the provisions on research. In particular, it proposes a definition of “scientific research” aimed at addressing existing uncertainties regarding the conditions under which research activities may be conducted. The ESR welcomes this clarification, while noting that the proposed definition could be further refined to better reflect the principles of independence, transparency, and verifiability. The ESR also supports the clarification that further processing of personal data for scientific research purposes is compatible with the initial purpose of processing and that scientific research may constitute a legitimate interest. These changes could help reduce existing barriers to the reuse of personal data for scientific research, while ensuring that appropriate safeguards, including those under Article 89(1), remain in place. (see ESR response to the EU Digital Omnibus on Data, Cybersecurity and Privacy Consultation).
While the legislative process on the Digital Omnibus is ongoing, the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have raised concerns about several elements of the proposed amendments in a joint opinion, warning that they could risk weakening the level of data protection rather than achieving the intended simplification. In parallel, the EDPB published draft Guidelines 1/2026 in April 2026, providing detailed guidance on the application of the GDPR to scientific research.
The ESR will keep monitoring the developments around the Digital Omnibus on Data, Cybersecurity and Privacy, in order to ensure that legal certainty, traceability and transparency of data are not undermined in favour of a simplified framework.
For more information, please visit the following links:
- General Data Protection Regulation (GDPR)
- European Commission on Data Protection
- EC Proposal for a Digital Omnibus on Data, Cybersecurity and Privacy
- ESR response to the EU Digital Omnibus on Data, Cybersecurity and Privacy Consultation
- EDPB/EDPS Joint Opinion on as regards the simplification of the digital legislative framework (Digital Omnibus)
- EDPB draft Guidelines on processing personal data for scientific research purposes