Print

Regulation 2018/1725

Regulation (EU) 2018/1725 lays down the data protection obligations for the EU institutions and bodies when they process personal data and develop new policies.

The Regulation repeals Regulation (EC) 45/2001, and, in line with GDPR, adopts a principle-based approach.

The new legal instrument ensures that EU institutions and bodies provide transparent and easily accessible information on how personal data is used, as well as foresee clear mechanisms for individuals to exercise their rights; it also reconfirms, clarifies and enhances the role of data protection officers within each EU institution and of the EDPS.

Filters

20
May
2020

EDPS’ comments on EASO’s draft internal rules concerning restrictions of certain rights of data subjects (Case 2020-0468)

These comments refer to EASO’s draft implementing rules concerning restrictions on certain rights of data subjects (pursuant to Article 25 of Regulation (EU) 2018/1725).

Available languages: English
8
May
2020

Monitoring and enforcing compliance with Regulation (EU) 2018/1725

The EDPS’ role is to ensure effective protection of people’s fundamental rights and freedoms against the (mis)use of technologies, in particular in relation to the processing of personal data by the EU institutions, bodies, offices and agencies (collectively ‘EUIs’). More specifically, under Article 57 of Regulation (EU) 2018/1725 on data protection for the EUIs, one of our main tasks is to ‘monitor and enforce the application of this Regulation’. This paper explains how we will act in that role, explaining both to individuals whose data EUIs process (the data subjects) and the EUIs themselves what they can expect from us as the supervisory authority for EUI’s processing of personal data and what we expect EUIs to do.

Available languages: English
8
May
2020

47th Virtual Meeting of the Data Protection Officers and the EDPS

47th Meeting of the Data Protection Officers of the EU institutions and the European Data Protection Supervisor, virtual meeting.

Agenda
Available languages: English
Public Communication
Available languages: English
Use of social media by EU institutions and bodies
Available languages: English
Monitoring social media - risks
Available languages: English
Use of social media - technical aspects mitigating measures, privacy friendly social networks
Available languages: English
Registers - best practices findings when inspecting
Available languages: English
Microsoft findings and recommendations
Available languages: English
Covid-19 and data protection
Available languages: English
2
Apr
2020

Report on remote inspection of publicly accessible registers under Article 31(5) of the Regulation

The EDPS has published guidance to EU institutions and bodies (“EUIs”) regarding the records of processing operations. The EDPS had previously clarified that making the register “publicly available” means publication on the internet. While initially May 2020, i.e. two years after the entry into force of the GDPR, had initially been announced by the EDPS as target date for implementation of this obligation, the EDPS noticed upon entry into force of Regulation 2018/1725, that the new Regulation contained no grace period regarding this obligation.

Report
Available languages: English
Second Interim Report
Available languages: English