Back to Frameworks

EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes

European Union and EEA
vGuidelines 1/2026, version for public consultation adopted 15 April 2026
7 domains
31 controls

Represents the GDPR Article 40 code-of-conduct mechanism applied to the scientific-research sector. There is no single EDPB-approved transnational research code; the controls capture what such a code must contain under GDPR Articles 40 (codes of conduct), 41 (accredited monitoring bodies) and 89 (safeguards and derogations for scientific research), informed by EDPB guidance. Sectoral codes exist (e.g. clinical-research and biobanking codes).

Verified

EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes is a compliance framework from European Union and EEA with 7 domains and 31 controls that map to 3 other frameworks. The largest domains are Section 4: lawfulness, consent, public interest, legitimate interest and special categories – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes (9 controls), Section 5: obligations to inform – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes (6 controls), Section 8: appropriate safeguards under Article 89(1) – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes (5 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykControl text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Section 2: the concept of processing for scientific research purposes – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes

2 controls
Controls in the Section 2: the concept of processing for scientific research purposes – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes domain of EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes2 controls
CodeTitle
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::2.12.1 Substantiate that processing is for scientific research purposes against the six key-indicative factors
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::2.2-2.32.2-2.3 Research data infrastructures and ancillary operations assessed against the same factors

Section 3: purpose limitation and storage limitation – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes

3 controls
Controls in the Section 3: purpose limitation and storage limitation – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes domain of EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes3 controls
CodeTitle
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::3.1.13.1.1 Further processing for research is presumed compatible, but lawfulness, the Article 9 derogation and Member State limits are assessed anew
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::3.1.23.1.2 Providing personal data to another controller for its research: no compatibility test, both controllers comply in full
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::3.23.2 Storage limitation: determine and communicate the period before processing, store for specified future research only, review necessity and format

Section 4: lawfulness, consent, public interest, legitimate interest and special categories – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes

9 controls
Controls in the Section 4: lawfulness, consent, public interest, legitimate interest and special categories – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes domain of EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes9 controls
CodeTitle
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.1.14.1.1 Consent must be freely given: vulnerable participants, patients' capacity, no conditioning of care, and remuneration assessed
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.1.24.1.2 Choose broad or dynamic consent before processing, document the choice, define the research area, keep projects within it
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.1.2.14.1.2.1 Broad consent safeguards: detailed and continuing information, use and access controls, time limits, an oversight body, a choice tool
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.1.34.1.3 Distinguish consent to participate in research from GDPR consent, and keep the two requests distinguishable
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.24.2 Public interest as a legal basis needs a Union or Member State law meeting necessity and proportionality, open to private entities the law covers
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.34.3 Legitimate interest: significant weight for research, reasonable expectations, and safeguards folded into the balancing test
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.44.4 Special categories: determine the Article 9(2) derogation, treat inferred and collatable data as special, DPIA at large scale, Member State conditions
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.4.24.4.2 Data manifestly made public: a high threshold requiring the data subject's own explicit, affirmative choice in context
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::4.4.34.4.3 Derogations in Union or Member State law: show the law applies and implement its suitable and specific measures, adding safeguards where the law did not anticipate the risks

Section 5: obligations to inform – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes

6 controls
Controls in the Section 5: obligations to inform – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes domain of EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes6 controls
CodeTitle
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::5.15.1 Give data subjects a way to stay informed over long research: voluntary contact details, choice of channel, a webpage or application
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::5.25.2 Information at collection, layered where appropriate; a controller without the data or contact must still inform and answer access requests through its processor or co-controller
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::5.35.3 Inform before further processing for research with time to react, never knowingly delete contact details, make reasonable efforts to reach data subjects and inform indirectly where they fail
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::5.45.4 Receiving controllers inform under Article 14, including for data they generate; cooperate with providers and intermediaries; tell pseudonymised-data subjects how to exercise rights; read Article 14(5) restrictively
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::5.4.25.4.2 Impossibility, disproportionate effort and research-impairing individual information: exemptions that still require public information and safeguards, especially for covert research
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::5.55.5 Inform data subjects of changes that make earlier information obsolete, in time to act; which changes count and which do not

Section 6: data subjects' rights – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes

3 controls
Controls in the Section 6: data subjects' rights – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes domain of EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes3 controls
CodeTitle
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::6.16.1 Determine the restrictions and derogations of rights in Union or Member State law, and the additional rights, and inform data subjects of them
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::6.26.2 Erasure requests: test the Article 17(1) grounds, then the Article 17(3)(d) exception restrictively and case by case, and warn of it in advance
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::6.36.3 Objections: the controller bears the burden of compelling grounds; under Article 21(6) necessity for a public-interest task is strict, verified at the time of the request, and the particular situation is heard

Section 7: attribution of responsibility – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes

3 controls
Controls in the Section 7: attribution of responsibility – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes domain of EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes3 controls
CodeTitle
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::7.17.1 Attribute controllership functionally, document the allocation, and recognise the sponsor or protocol author as controller even without handling identifiable data
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::7.27.2 Processors act within the controller's instructions and become controllers, with the liability that follows, where they decide purposes or essential means
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::7.37.3 Joint controllers: joint determination of the protocol, an Article 26 arrangement reflecting differing responsibilities and made available to data subjects, processors engaged on agreed terms

Section 8: appropriate safeguards under Article 89(1) – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes

5 controls
Controls in the Section 8: appropriate safeguards under Article 89(1) – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes domain of EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes5 controls
CodeTitle
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::8.18.1 Article 89(1) safeguards assessed on nature, scope, context, purposes and risks, in addition to the GDPR's general measures, and reassessed on further processing
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::8.28.2 Start with a risk analysis or DPIA that looks beyond privacy to other fundamental rights, health findings, re-identification, publication and vulnerable or related persons
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::8.38.3 Anonymise where the purposes allow, otherwise pseudonymise, identify directly only where strictly necessary; decide the format at planning, keep methods state of the art and verified, bind recipients contractually and tell data subjects how identifiable they remain
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::8.48.4 Genetic and biometric data: particular caution, restrictive purposes, pseudonymisation, ethical approval, federated storage with secure access, role-based controls, and community information for isolated populations
edpb-guidelines-1-2026-on-processing-of-personal-data-for-scientific-research-purposes::8.58.5 Select further safeguards fitted to the research method from the EDPB's menu: oversight governance, enhanced transparency, consent as a safeguard, strict purpose limits, PETs, secure environments, sharing rules, re-identification penalties, qualifications, training, publication protection, confidentiality

Your Compliance Coverage

If you comply with EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes, you already cover:

Maps to 3 other frameworks

51 total controls
GDPR
11 source controls mapped|11 target controls covered
22%
ISO 13485:2016
1 source controls mapped|1 target controls covered
2%
ISO 37001:2016
1 source controls mapped|1 target controls covered
2%

Coverage is not the same as your position

This page shows what EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes and who does it apply to?

EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes is a compliance framework from European Union and EEA with 7 domains and 31 controls. Represents the GDPR Article 40 code-of-conduct mechanism applied to the scientific-research sector. There is no single EDPB-approved transnational research code; the controls capture what such a code must contain under GDPR Articles 40 (codes of conduct), 41 (accredited monitoring bodies) and 89 (safeguards and derogations for scientific research), informed by EDPB guidance. Sectoral codes exist (e.g. clinical-research and biobanking codes). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes actually require?

EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes has 31 controls organised across 7 domains. The largest domains are Section 4: lawfulness, consent, public interest, legitimate interest and special categories – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes (9 controls), Section 5: obligations to inform – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes (6 controls), Section 8: appropriate safeguards under Article 89(1) – EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes do I already cover?

EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes maps to 3 other compliance frameworks. The top mapping partners are GDPR (22% coverage), ISO 13485:2016 (2% coverage), ISO 37001:2016 (2% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes?

Start your EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 31 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 703 frameworks.

Get Started Free →

Free forever — no credit card required