EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes
Represents the GDPR Article 40 code-of-conduct mechanism applied to the scientific-research sector. There is no single EDPB-approved transnational research code; the controls capture what such a code must contain under GDPR Articles 40 (codes of conduct), 41 (accredited monitoring bodies) and 89 (safeguards and derogations for scientific research), informed by EDPB guidance. Sectoral codes exist (e.g. clinical-research and biobanking codes).
EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes is a compliance framework from European Union and EEA with 7 domains and 31 controls that map to 3 other frameworks. The largest domains are Section 4: lawfulness, consent, public interest, legitimate interest and special categories – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes (9 controls), Section 5: obligations to inform – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes (6 controls), Section 8: appropriate safeguards under Article 89(1) – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes (5 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Section 2: the concept of processing for scientific research purposes – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes
| Code | Title |
|---|---|
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::2.1 | 2.1 Substantiate that processing is for scientific research purposes against the six key-indicative factors |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::2.2-2.3 | 2.2-2.3 Research data infrastructures and ancillary operations assessed against the same factors |
Section 3: purpose limitation and storage limitation – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes
| Code | Title |
|---|---|
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::3.1.1 | 3.1.1 Further processing for research is presumed compatible, but lawfulness, the Article 9 derogation and Member State limits are assessed anew |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::3.1.2 | 3.1.2 Providing personal data to another controller for its research: no compatibility test, both controllers comply in full |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::3.2 | 3.2 Storage limitation: determine and communicate the period before processing, store for specified future research only, review necessity and format |
Section 4: lawfulness, consent, public interest, legitimate interest and special categories – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes
| Code | Title |
|---|---|
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.1.1 | 4.1.1 Consent must be freely given: vulnerable participants, patients' capacity, no conditioning of care, and remuneration assessed |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.1.2 | 4.1.2 Choose broad or dynamic consent before processing, document the choice, define the research area, keep projects within it |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.1.2.1 | 4.1.2.1 Broad consent safeguards: detailed and continuing information, use and access controls, time limits, an oversight body, a choice tool |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.1.3 | 4.1.3 Distinguish consent to participate in research from GDPR consent, and keep the two requests distinguishable |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.2 | 4.2 Public interest as a legal basis needs a Union or Member State law meeting necessity and proportionality, open to private entities the law covers |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.3 | 4.3 Legitimate interest: significant weight for research, reasonable expectations, and safeguards folded into the balancing test |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.4 | 4.4 Special categories: determine the Article 9(2) derogation, treat inferred and collatable data as special, DPIA at large scale, Member State conditions |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.4.2 | 4.4.2 Data manifestly made public: a high threshold requiring the data subject's own explicit, affirmative choice in context |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.4.3 | 4.4.3 Derogations in Union or Member State law: show the law applies and implement its suitable and specific measures, adding safeguards where the law did not anticipate the risks |
Section 5: obligations to inform – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes
| Code | Title |
|---|---|
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::5.1 | 5.1 Give data subjects a way to stay informed over long research: voluntary contact details, choice of channel, a webpage or application |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::5.2 | 5.2 Information at collection, layered where appropriate; a controller without the data or contact must still inform and answer access requests through its processor or co-controller |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::5.3 | 5.3 Inform before further processing for research with time to react, never knowingly delete contact details, make reasonable efforts to reach data subjects and inform indirectly where they fail |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::5.4 | 5.4 Receiving controllers inform under Article 14, including for data they generate; cooperate with providers and intermediaries; tell pseudonymised-data subjects how to exercise rights; read Article 14(5) restrictively |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::5.4.2 | 5.4.2 Impossibility, disproportionate effort and research-impairing individual information: exemptions that still require public information and safeguards, especially for covert research |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::5.5 | 5.5 Inform data subjects of changes that make earlier information obsolete, in time to act; which changes count and which do not |
Section 6: data subjects' rights – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes
| Code | Title |
|---|---|
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::6.1 | 6.1 Determine the restrictions and derogations of rights in Union or Member State law, and the additional rights, and inform data subjects of them |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::6.2 | 6.2 Erasure requests: test the Article 17(1) grounds, then the Article 17(3)(d) exception restrictively and case by case, and warn of it in advance |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::6.3 | 6.3 Objections: the controller bears the burden of compelling grounds; under Article 21(6) necessity for a public-interest task is strict, verified at the time of the request, and the particular situation is heard |
Section 7: attribution of responsibility – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes
| Code | Title |
|---|---|
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::7.1 | 7.1 Attribute controllership functionally, document the allocation, and recognise the sponsor or protocol author as controller even without handling identifiable data |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::7.2 | 7.2 Processors act within the controller's instructions and become controllers, with the liability that follows, where they decide purposes or essential means |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::7.3 | 7.3 Joint controllers: joint determination of the protocol, an Article 26 arrangement reflecting differing responsibilities and made available to data subjects, processors engaged on agreed terms |
Section 8: appropriate safeguards under Article 89(1) – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes
| Code | Title |
|---|---|
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::8.1 | 8.1 Article 89(1) safeguards assessed on nature, scope, context, purposes and risks, in addition to the GDPR's general measures, and reassessed on further processing |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::8.2 | 8.2 Start with a risk analysis or DPIA that looks beyond privacy to other fundamental rights, health findings, re-identification, publication and vulnerable or related persons |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::8.3 | 8.3 Anonymise where the purposes allow, otherwise pseudonymise, identify directly only where strictly necessary; decide the format at planning, keep methods state of the art and verified, bind recipients contractually and tell data subjects how identifiable they remain |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::8.4 | 8.4 Genetic and biometric data: particular caution, restrictive purposes, pseudonymisation, ethical approval, federated storage with secure access, role-based controls, and community information for isolated populations |
| edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::8.5 | 8.5 Select further safeguards fitted to the research method from the EDPB's menu: oversight governance, enhanced transparency, consent as a safeguard, strict purpose limits, PETs, secure environments, sharing rules, re-identification penalties, qualifications, training, publication protection, confidentiality |
Your Compliance Coverage
If you comply with EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes, you already cover:
Maps to 3 other frameworks
Coverage is not the same as your position
This page shows what EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes and who does it apply to?
EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes is a compliance framework from European Union and EEA with 7 domains and 31 controls. Represents the GDPR Article 40 code-of-conduct mechanism applied to the scientific-research sector. There is no single EDPB-approved transnational research code; the controls capture what such a code must contain under GDPR Articles 40 (codes of conduct), 41 (accredited monitoring bodies) and 89 (safeguards and derogations for scientific research), informed by EDPB guidance. Sectoral codes exist (e.g. clinical-research and biobanking codes). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes actually require?
EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes has 31 controls organised across 7 domains. The largest domains are Section 4: lawfulness, consent, public interest, legitimate interest and special categories – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes (9 controls), Section 5: obligations to inform – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes (6 controls), Section 8: appropriate safeguards under Article 89(1) – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes do I already cover?
EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes maps to 3 other compliance frameworks. The top mapping partners are GDPR (22% coverage), ISO 13485:2016 (2% coverage), ISO 37001:2016 (2% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes?
Start your EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 31 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 703 frameworks.
Get Started Free →Free forever — no credit card required