All news
EDPB / EDPS April 15, 2026 7 min

"We keep it for research purposes": the EDPB explains why that is not an answer

Guidelines 1/2026 on processing personal data for scientific research: 171 paragraphs on broad consent, Article 89 safeguards and — a point few expected — on your retention schedule

In short

Guidelines 1/2026 were adopted in draft on 15 April 2026: 67 pages, 171 paragraphs. They cover the notion of scientific research, legal bases, transparency, data subject rights and the safeguards under Article 89(1). Public consultation closed on 25 June 2026 and the final text will follow the revisions: what you read today is still a draft.

Broad consent exists, but it comes at a price

The knot the research community had been waiting on for years is broad consent: can you ask for consent to research that is not fully defined at the time of collection? The Board's answer is yes, subject to conditions. Consent may cover a clearly described research field, or identifiable expected outcomes, backed by appropriate safeguards. What does not hold up is consent to "research" in general: if the data subject is not told which area the study will move in, the consent is neither specific nor informed.

  • Describe the area, not the word: "paediatric oncology studies", not "scientific purposes"
  • Future processing must be reasonably foreseeable at the time of collection
  • Article 89(1) safeguards are not decoration: minimisation, pseudonymisation where feasible, separation between whoever holds the identifying data and whoever analyses it
  • Consent stays withdrawable: you need a procedure stating what happens to data already fed into an ongoing study
  • If the study changes field you go back to the data subject: broad consent is not perpetual consent

The line that ends up in the record

Here comes the part that matters to whoever fills in the Article 30 record and the retention schedule. The Board is explicit: storing personal data for a generic "scientific research purpose", without indicating the area, is not permissible. The controller must specify the potential research and support it with Article 89 safeguards. Translated into record language: "retained for research purposes" is not a retention period, it is an omission with an elegant formula in front of it.

The check to run on your clients' records

Look for lines where the retention period reads "as long as necessary for research purposes", "for statistical and research purposes" or similar. In most cases they cover archives nobody has opened in years. If there is no defined research area and no Article 89 safeguards, that line does not describe a period: it describes indefinite retention, and in an inspection it reads exactly that way.

What the document does not solve

  • It does not turn research into a legal basis: Article 89 is a safeguards regime, not a standalone lawfulness condition
  • It does not remove the compatibility assessment: the Article 5(1)(b) presumption is not automatic and must be documented
  • It does not touch national law: member state rules on research processing remain in place
  • It is not final: the consultation drew heavy comments from the life sciences sector and the text will change

In DPO Workspace

In the retention matrix, rules with no numeric period have their own type and can stay flagged as pending verification until the source is confirmed. That is the right place to park "for research purposes" lines while the final text is awaited, rather than leaving them written as if they were a period.

The document is long and not all of it serves the corporate DPO. But the broad consent paragraphs and the retention one are the kind of passage that, a year from now, will show up in an enforcement decision introduced by "as clarified by the Board".

Official source:EDPB - Guidelines 1/2026 on processing of personal data for scientific research purposesOfficial source:EDPB - Guidelines 1/2026 (testo integrale, PDF)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

EDPB / EDPS
12-14gli articoli sotto esame

In 2026 every European authority is looking at the same thing: privacy notices

Each year the EDPB picks a topic and every national authority checks it together, in the same period, through questionnaires and inspections. For 2026 the topic is transparency: how controllers tell people what happens to their data. In scope are Article 13, where data comes from the data subject, and Article 14, where it comes from elsewhere. The Czech authority has already written the theme into its inspection plan.

Aug 10, 2026New 6 min
EDPB / EDPS
28 agotermine per candidarsi

Competition and data protection: the EDPB opens the table, and there is a deadline

After the DSA and before the DMA and the AI Act, the fourth piece of the European regulatory mosaic concerns the relationship between competition and data protection. This is not theoretical: it touches data as a market asset, mergers, and the position of those who process data because they dominate a market. The EDPB and the Commission are asking for input before they write, and this time the deadline is close.

Jul 30, 2026New 6 min
EDPB / EDPS
10 lug 2027quando si potra' condividere

Anti-money laundering and privacy: the EDPB and AMLA write the sharing rules together

On 1 July 2026 the EDPB and the European Anti-Money Laundering Authority announced joint guidelines on a question neither could solve alone: how banks, professionals and authorities can share information about suspicions without building unchecked lists of suspects. The possibility applies from 10 July 2027 and the public consultation is expected in the first half of that year. Anyone advising obliged entities has a year to prepare.

Jul 01, 2026New 6 min