All news
EDPB / EDPS May 20, 2026 9 min

EDPB CEF 2026: 25 European DPAs verify transparency of privacy notices

Coordinated Enforcement Action launched March 19, 2026: focus on GDPR Arts. 12-14. Operational implications for EU DPOs

TL;DR for the DPO

On March 19, 2026, the EDPB launched the 2026 Coordinated Enforcement Action on GDPR transparency (Arts. 12-14). 25 European DPAs, including the Italian Garante, are verifying privacy notices across various sectors. Risk for DPOs: findings on incomplete, outdated or unclear notices. Priority: privacy notice audit by Q3 2026, with focus on specific purposes, legal bases, recipients, non-EU transfers, retention periods.

What is CEF 2026

The Coordinated Enforcement Framework (CEF) was introduced by the EDPB in 2020 to harmonize GDPR enforcement at EU level. Each year, the EDPB selects a specific topic and national DPAs conduct parallel verifications, sharing methodologies and findings. Past topics:

  • 2023 - Cloud services in the public sector
  • 2024 - Designation and role of DPOs
  • 2025 - Implementation of the right of access (Art. 15)
  • 2025 (parallel) - Right to be forgotten (Art. 17)
  • 2026 - Transparency and information obligations (Arts. 12-14)
25
Participating DPAs
12-14
GDPR articles under review

What DPAs will examine

Participating DPAs are verifying whether controllers' privacy notices meet the transparency requirements of Art. 12 GDPR (concise, transparent, intelligible, accessible form, plain and clear language) and completeness of Arts. 13-14. In particular:

  • Clear and accessible identity and contact details of controller and DPO
  • Specific purposes (not generic statements like 'to provide the service')
  • Legal basis indicated for EACH processing purpose, not cumulatively
  • Recipients identified precisely, or at least categories of recipients
  • Non-EU transfers explicitly indicated, with mention of safeguards (SCCs, adequacy decision, etc.) and link to documentation
  • Retention period for each data category, or criteria to determine it
  • Data subject rights with operational instructions on how to exercise them
  • Right to lodge a complaint with the supervisory authority

Critical issue: recipients

In recent enforcement, several DPAs have taken the position that controllers must EXPLICITLY identify EACH third country to which they transfer data. The generic 'recipients in the European Union and/or adequate third countries' is no longer sufficient. The French CNIL, the Spanish AEPD and the Italian Garante have penalized controllers for this gap in 2025. Expect more rigor in 2026.

What it means operationally for the DPO

DPOs of EU controllers should plan a full audit of privacy notices by Q3 2026. Priority should be given to controllers with high-risk characteristics:

  • Controllers processing special categories of data (Art. 9) or children's data
  • Controllers with structured non-EU transfers (cloud, SaaS, international B2B services)
  • Public sector controllers (the EDPB had already focused on the public sector in 2023)
  • Controllers with direct marketing, profiling, automated decisions
  • Controllers who have updated their business model in the last 24 months without updating the privacy notice
Official source:EDPB - CEF 2026 launch

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

EDPB / EDPS
12-14gli articoli sotto esame

In 2026 every European authority is looking at the same thing: privacy notices

Each year the EDPB picks a topic and every national authority checks it together, in the same period, through questionnaires and inspections. For 2026 the topic is transparency: how controllers tell people what happens to their data. In scope are Article 13, where data comes from the data subject, and Article 14, where it comes from elsewhere. The Czech authority has already written the theme into its inspection plan.

Aug 10, 2026New 6 min
EDPB / EDPS
28 agotermine per candidarsi

Competition and data protection: the EDPB opens the table, and there is a deadline

After the DSA and before the DMA and the AI Act, the fourth piece of the European regulatory mosaic concerns the relationship between competition and data protection. This is not theoretical: it touches data as a market asset, mergers, and the position of those who process data because they dominate a market. The EDPB and the Commission are asking for input before they write, and this time the deadline is close.

Jul 30, 2026New 6 min
EDPB / EDPS
10 lug 2027quando si potra' condividere

Anti-money laundering and privacy: the EDPB and AMLA write the sharing rules together

On 1 July 2026 the EDPB and the European Anti-Money Laundering Authority announced joint guidelines on a question neither could solve alone: how banks, professionals and authorities can share information about suspicions without building unchecked lists of suspects. The possibility applies from 10 July 2027 and the public consultation is expected in the first half of that year. Anyone advising obliged entities has a year to prepare.

Jul 01, 2026New 6 min