TL;DR for the DPO
On March 19, 2026, the EDPB launched the 2026 Coordinated Enforcement Action on GDPR transparency (Arts. 12-14). 25 European DPAs, including the Italian Garante, are verifying privacy notices across various sectors. Risk for DPOs: findings on incomplete, outdated or unclear notices. Priority: privacy notice audit by Q3 2026, with focus on specific purposes, legal bases, recipients, non-EU transfers, retention periods.
What is CEF 2026
The Coordinated Enforcement Framework (CEF) was introduced by the EDPB in 2020 to harmonize GDPR enforcement at EU level. Each year, the EDPB selects a specific topic and national DPAs conduct parallel verifications, sharing methodologies and findings. Past topics:
- 2023 - Cloud services in the public sector
- 2024 - Designation and role of DPOs
- 2025 - Implementation of the right of access (Art. 15)
- 2025 (parallel) - Right to be forgotten (Art. 17)
- 2026 - Transparency and information obligations (Arts. 12-14)
What DPAs will examine
Participating DPAs are verifying whether controllers' privacy notices meet the transparency requirements of Art. 12 GDPR (concise, transparent, intelligible, accessible form, plain and clear language) and completeness of Arts. 13-14. In particular:
- Clear and accessible identity and contact details of controller and DPO
- Specific purposes (not generic statements like 'to provide the service')
- Legal basis indicated for EACH processing purpose, not cumulatively
- Recipients identified precisely, or at least categories of recipients
- Non-EU transfers explicitly indicated, with mention of safeguards (SCCs, adequacy decision, etc.) and link to documentation
- Retention period for each data category, or criteria to determine it
- Data subject rights with operational instructions on how to exercise them
- Right to lodge a complaint with the supervisory authority
Critical issue: recipients
In recent enforcement, several DPAs have taken the position that controllers must EXPLICITLY identify EACH third country to which they transfer data. The generic 'recipients in the European Union and/or adequate third countries' is no longer sufficient. The French CNIL, the Spanish AEPD and the Italian Garante have penalized controllers for this gap in 2025. Expect more rigor in 2026.
What it means operationally for the DPO
DPOs of EU controllers should plan a full audit of privacy notices by Q3 2026. Priority should be given to controllers with high-risk characteristics:
- Controllers processing special categories of data (Art. 9) or children's data
- Controllers with structured non-EU transfers (cloud, SaaS, international B2B services)
- Public sector controllers (the EDPB had already focused on the public sector in 2023)
- Controllers with direct marketing, profiling, automated decisions
- Controllers who have updated their business model in the last 24 months without updating the privacy notice
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free