EDPB Guidelines on Scientific Research: Consultation Has Closed!

On 15 April 2026, the European Data Protection Board (EDPB) published its Draft Guidelines (1/2026) on the processing of personal data for scientific research purposes. The public consultation has now closed, and the EDPB will consider the feedback received before adopting the final version.

For universities, hospitals, pharmaceutical and biotechnology companies, research institutes, technology businesses, public authorities and public-private research consortia, these Draft Guidelines are an important development. GDPR contains several provisions designed to facilitate scientific research — but this flexibility is conditional: organisations must demonstrate that their activities are genuinely scientific and implement appropriate safeguards to protect the rights and freedoms of research participants.

So now that the consultation has ended: what should organisations expect, and what should they do?

Why These Guidelines Matter

Scientific research increasingly relies on collecting, reusing and retaining personal data, including health and genetic data, public or administrative records, and large datasets used in AI research.

GDPR recognises the societal value of such processing and already provides certain research-specific flexibilities, including:

  • a presumption that further processing for scientific research is compatible with the original purpose;
  • longer retention of personal data for research purposes; and
  • the possibility of relying on broad consent in certain circumstances.

These provisions do not, however, create a general exemption from GDPR. The Draft Guidelines explain how the research provisions should apply throughout the entire lifecycle of a project — from initial design and selection of a legal basis, to transparency, data sharing, storage, publication of results, and handling data subject requests.

First Things First: Is the Activity Genuinely Scientific?

An organisation cannot benefit from GDPR's research provisions simply by describing an activity as "research", "innovation" or "R&D". The processing must genuinely be motivated by scientific research purposes.

To assess this, the EDPB identifies six key indicative factors:

  1. A methodical and systematic approach
  2. Adherence to relevant ethical standards
  3. Verifiability and transparency
  4. Autonomy and independence
  5. An objective of contributing to society's general knowledge and wellbeing
  6. The potential to contribute to existing scientific knowledge or apply it in a novel way

Where all factors are present, the activity may be presumed to constitute scientific research. If some factors are absent, controllers must justify and demonstrate why the activity should nevertheless qualify.

Scientific research is not limited to universities, public authorities or non-profit organisations — commercial organisations may also conduct it, and a project does not lose its scientific character merely because its results are later commercialised. Purely internal commercial analytics, however, are unlikely to qualify. The Draft Guidelines illustrate this with a retailer analysing customer behaviour solely to improve its marketing strategy: the analysis is not intended to produce independently verifiable results or contribute to wider scientific knowledge, and therefore does not qualify.

The Presumption of Compatibility: Is It a Free Pass?

Where personal data was initially collected for another purpose and is later processed for scientific research, the further processing is presumed to be compatible with the original purpose. This is potentially very useful for organisations wishing to reuse existing datasets — for example, a hospital using data originally collected during patient treatment for a later research project.

Because of this presumption, controllers do not normally have to carry out the standard compatibility assessment under Art. 6(4) GDPR. This does not, however, mean the further processing is automatically lawful. Organisations must still:

  • identify a valid legal basis under Art. 6 GDPR;
  • identify an Art. 9 GDPR condition where sensitive data is involved;
  • comply with transparency and accountability requirements; and
  • implement safeguards under Art. 89(1) GDPR.

The presumption of compatibility concerns purpose limitation only. It is not, by itself, a legal basis, and does not legitimise an otherwise unlawful disclosure or reuse of data.

Broad Consent Can Be Useful, But It Has Limits

Scientific research presents a practical difficulty: researchers may know the general area of research when personal data is collected, but not the precise projects, hypotheses or methods that will arise later. The Draft Guidelines recognise that, in certain circumstances, consent may cover a defined area of research rather than one fully specified project — commonly referred to as "broad consent".

Broad consent should not be treated as unlimited consent for any possible future use. The relevant research area must still be described meaningfully, and the broader the consent, the stronger the accompanying safeguards should be, such as:

  • independent ethical review;
  • enhanced and ongoing transparency;
  • strict access/use conditions;
  • limits on the duration of consent; and
  • the opportunity to consent separately to different research areas.

The Draft Guidelines also discuss "dynamic consent": participants are contacted as new projects or stages arise, and can make additional choices through, for example, a digital portal or privacy dashboard.

Ethical Consent and GDPR Consent Are Not the Same

Organisations should clearly distinguish between consent to participate in a research project under ethical, medical or sector-specific requirements, and consent under GDPR as a legal basis for processing personal data.

A person may provide ethical consent to participate in a clinical trial, while the processing of their personal data is in fact based on a legal obligation or a task carried out in the public interest. A signed participation form therefore doesn't necessarily meet all GDPR requirements for valid consent. This distinction should be reflected in consent forms, participant information sheets, privacy notices and internal documentation — the EDPB's factsheet specifically recommends keeping ethical participation consent and GDPR consent strictly separate.

Consent Is Not Always the Most Appropriate Legal Basis

Consent may appear to be the most participant-friendly option, but it may not be valid where there is a significant power imbalance or the participants are vulnerable — for example, where research concerns patients, children or employees.

The Draft Guidelines point to other legal bases that may be relevant. Private organisations may potentially rely on the "public interest" basis where their research is covered by an appropriate Union or Member State law. "Legitimate interests" may also be available, including for commercially funded research, although a balancing test remains mandatory.

In short: there is no universal legal basis for scientific research. The appropriate basis must be assessed project by project.

Sensitive Data Requires Particular Care

Research projects frequently involve health, biometric or other sensitive data. In such cases, an Art. 6 GDPR legal basis is not enough — organisations must also identify a condition under Art. 9(2) GDPR.

The scientific research condition under Art. 9(2)(j) generally cannot be relied on in isolation: the processing must be based on Union or Member State law providing proportionate and suitable safeguards. This means organisations conducting multinational research may need to consider different national rules in each relevant jurisdiction. Where no statutory condition applies, explicit consent may sometimes be available.

Transparency Is an Ongoing Obligation

A privacy notice provided at the start of a long-term research project may not remain sufficient throughout its lifecycle. Where personal data is processed over extended periods, organisations should maintain transparency and inform participants of material changes — for example through dedicated research websites, privacy dashboards, participant portals, newsletters, patient organisations, or other communication channels.

Exceptions for impossible or disproportionate notification must be interpreted restrictively. Even where individual notice is genuinely impossible or disproportionately burdensome, organisations should consider alternative transparency measures, such as publishing information online or communicating through relevant associations.

Data Subject Rights Do Not Automatically Disappear

GDPR permits certain limitations on data subject rights in the context of scientific research, but these limitations are narrow and must be assessed case by case. An erasure request, for example, may be rejected where deletion would be likely to render the research impossible or seriously impair its objectives.

This requires more than showing that deletion would be inconvenient, costly or methodologically undesirable — the controller must demonstrate a serious impact on the research and show that appropriate safeguards have been implemented. Research organisations should avoid adopting blanket policies stating that erasure, or other data subject rights, simply do not apply to research data.

Pseudonymised Data Is Still Personal Data

The Draft Guidelines reinforce the distinction between anonymisation and pseudonymisation. Pseudonymised data remains personal data and continues to fall within GDPR — organisations should never describe pseudonymised datasets as "anonymous" in privacy notices, research protocols or data sharing agreements.

Where research purposes can be fulfilled using anonymous data, anonymisation should be preferred. Where identifiers remain necessary, the data should generally be pseudonymised. Directly identifiable data should be used only where strictly necessary and proportionate — an assessment to be made during project design, as part of a risk analysis or, where required, a data protection impact assessment.

Research Partnerships Need Clear Allocation of Roles

Scientific research often involves several organisations — universities, hospitals, sponsors, laboratories, technology providers. These parties must transparently allocate their respective GDPR responsibilities, e.g. controller, processor, or joint controllers.

This assessment should not be postponed until the final stages of contractual negotiations: the allocation of roles affects several other compliance matters, including the legal basis, privacy notices and security obligations. The Draft Guidelines emphasise that responsibilities must be assessed and documented early.

What Should Organisations Do Now?

Although the consultation has closed and the Draft Guidelines may still change, organisations do not need to wait for the final version before reviewing their practices:

  • Map relevant research projects — identify projects currently relying (or intending to rely) on GDPR's scientific research provisions.
  • Document the scientific nature of the activity — assess each project against the six indicative factors and explain any factors not fully satisfied.
  • Review legal bases separately — confirm the Art. 6 GDPR basis and, where necessary, the relevant Art. 9 condition.
  • Review consent materials — distinguish GDPR consent from ethical participation consent, and assess whether broad or dynamic consent is appropriate.
  • Assess data formats and safeguards — determine whether directly identifiable data is necessary, or whether anonymised or pseudonymised data can be used.
  • Update transparency arrangements — ensure participants can remain informed throughout long-term or evolving projects.
  • Clarify organisational roles — document controller, joint-controller and processor responsibilities before processing begins.
  • Prepare for data subject requests — develop procedures for assessing requests such as erasure or objection individually, rather than rejecting them automatically.

What's Next?

The EDPB will now review the consultation responses and may amend the Draft Guidelines before adopting a final version. The final text may provide further clarification or adjust some positions taken in the consultation draft. The central message, however, is unlikely to change: GDPR is intended to facilitate responsible scientific research, but its research-specific flexibility depends on accountability, necessity and appropriate safeguards.

Organisations should treat the Draft Guidelines as a practical compliance benchmark now, rather than a reason to delay action until the final version is published. And one thing should be clear: the Draft Guidelines do not create a GDPR-free zone for researchers. Instead, they provide a clearer framework for conducting ambitious, data-driven research while protecting the individuals whose data makes that research possible.

Have questions about how the EDPB's Draft Guidelines may affect your scientific research projects? Reach out to us for a tailored assessment.

Fatih Yavuzer Legal Manager

Do you want to know more?

Do you have any questions about the above or are you looking for strategic Legal advice? Contact Considerati, we offer specialised advice and tailored support.

Our services orContact