All news
EDPB / EDPS August 10, 2026 6 min

In 2026 every European authority is looking at the same thing: privacy notices

The EDPB's annual coordinated action for 2026 targets transparency and the information duties of Articles 12, 13 and 14. This is not a national initiative: it runs simultaneously across Europe

TL;DR for the DPO

The privacy notice is the document everyone has and almost nobody re-reads. In 2026 it is the document every European authority will be looking at, at the same time. If you carry a client portfolio, this is the year to re-read all of them - and not in September.

How the coordinated action works

Since 2022 the EDPB has picked one topic a year and national authorities check it in parallel: some send questionnaires, some open formal inspections, some start proceedings. The findings feed a European report that becomes the interpretive reference for the years that follow. Previous editions covered the role of the DPO, the right of access and erasure. 2026 is transparency.

The practical consequence is that you do not need to be in the spotlight to end up in the sample: authorities pick controllers of every size, and for many the first news arrives as a questionnaire with a deadline.

What they actually look at

Article 12 does not require the notice to exist: it requires it to be concise, transparent, intelligible, easily accessible and in clear and plain language. That is five adjectives, and each one is a possible finding. A complete but unreadable notice breaches Article 12 just as an incomplete one breaches Article 13.

Article 14 is the real weak spot

Where data does not come from the data subject but from another source - a purchased list, a customer base inherited through an acquisition, a supplier passing records on - the notice is still due, must be given within a month, and must state WHERE the data came from. In practice it is the most neglected obligation of all, because nobody has a process that triggers when data enters through an indirect channel.

The questions to ask about each client

  • Is the notice current for what the client does TODAY, or does it describe the company of three years ago?
  • Do the purposes and legal bases match those written in the Article 30 records? The two diverge more often than people think, and authorities compare them.
  • Where data arrives from third parties, is there an Article 14 notice, and does anyone actually send it within the month?
  • Are retention periods stated with a criterion, or with 'for as long as necessary', which informs nobody?
  • Is the notice reachable in under two clicks from the point where data is collected?

What to do now, in practice

1) Inventory every client's notice with the date of its last review: anything older than two years is the backlog to clear first. 2) For each client, cross-check the purposes in the notice against the Article 30 records and note the divergences - it is the first check an authority runs, because it costs nothing. 3) Hunt for indirect data flows: lists, partners, acquisitions, suppliers passing records. Each one requires an Article 14 notice stating the source. 4) Put the notice review in this year's plan with a date, not as an ongoing activity: ongoing activities never happen.

Official source:Czech Data Protection Authority - Inspection Plan for 2026Official source:European Data Protection Board - Coordinated Enforcement Framework

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

EDPB / EDPS
28 agotermine per candidarsi

Competition and data protection: the EDPB opens the table, and there is a deadline

After the DSA and before the DMA and the AI Act, the fourth piece of the European regulatory mosaic concerns the relationship between competition and data protection. This is not theoretical: it touches data as a market asset, mergers, and the position of those who process data because they dominate a market. The EDPB and the Commission are asking for input before they write, and this time the deadline is close.

Jul 30, 2026New 6 min
EDPB / EDPS
10 lug 2027quando si potra' condividere

Anti-money laundering and privacy: the EDPB and AMLA write the sharing rules together

On 1 July 2026 the EDPB and the European Anti-Money Laundering Authority announced joint guidelines on a question neither could solve alone: how banks, professionals and authorities can share information about suspicions without building unchecked lists of suspects. The possibility applies from 10 July 2027 and the public consultation is expected in the first half of that year. Anyone advising obliged entities has a year to prepare.

Jul 01, 2026New 6 min
EDPB / EDPS
16-17luglio 2026

EDPB from Dublin: a legal basis is needed so authorities can share information across regulatory fields

The number and complexity of complaints are rising, partly because of increased use of AI, and authorities say openly that resources are not enough. The solutions on the table: joint operations, pooling resources between authorities, and the upcoming Procedural Regulation.

Jul 17, 2026New 6 min