TL;DR for the DPO
Two things to take away. First: authorities are building channels to share information with regulators in adjacent fields, so an investigation started elsewhere can land on your DPA's desk. Second: proceedings stay long because resources are short, and that is not a good reason to relax - joint operations exist precisely to compensate.
What the Board asked for
At the high-level meeting held in Dublin on 16 and 17 July 2026, the EDPB called on the European Commission to propose a legal basis for cross-regulatory information sharing, including confidential information relevant to enforcement within each regulator's area of competence. Chair Anu Talus linked the request to first-hand experience of cooperating with other EU digital regulators at national and EU level: stronger legislation is needed to remove barriers and improve enforcement outcomes and cross-regulatory coherence.
The problem said out loud: complaints grow, resources do not
The Board recalled the significant progress on cross-border enforcement, also mentioned in the second European Commission report on the GDPR. At the same time authorities face a considerable rise in the number and complexity of complaints, among others as a result of the increased use of AI, placing additional strain on already stretched resources and limiting their ability to perform all their tasks under the Regulation. Authorities underlined the need for practical and, where necessary, legislative solutions, especially in cases where a large number of people is affected.
The solutions on the table
- Greater use of joint operations between authorities, to pool resources
- The possibility for complaint-receiving authorities to make resources available to lead supervisory authorities, where useful
- A series of workshops on enforcement procedures and on exchanging information about national practices, also in the context of the upcoming Procedural Regulation
- A broader dialogue with other actors in the ecosystem, because consistency also depends on national legislation and case law, which the EDPB does not govern
What changes for the DPO
- If a client is also subject to other regulators (competition, digital services, finance, AI), treat the documentation as potentially shared between authorities: consistency between what you tell one and the other becomes an issue
- In cross-border cases, expect longer but more coordinated investigations: more authorities looking at the same file, not fewer
- The Procedural Regulation will codify practices many authorities already apply: if you have an internal procedure for replying to the authority, now is the time to write it properly
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free