On April 15, 2026, the European Data Protection Board (EDPB) adopted the Guidelines 1/2026 on processing of personal data for scientific research purposes for public consultation. They are aimed at those responsible in universities, hospitals, public research institutions, pharmaceutical companies and private research institutes.
The guidelines specify the research-specific provisions of the GDPR – in particular Art. 5(1)(b) and (e), Art. 9(2)(j), Art. 14(5)(b), Art. 17(3)(d), Art. 21(6) and Art. 89 GDPR – and contain a corresponding review grid. Certain topics are excluded, including the purpose compatibility test under Art. 6(4) GDPR outside the research context, automated individual decisions and the interaction with sector-specific EU and Member State law. The European Health Data Space and the Clinical Trials Regulation are only mentioned selectively.
Research concept
Only „genuine“ scientific research should benefit from the research privileges of the GDPR. According to recital 159, the term should be interpreted broadly, but „not be stretched beyond its common meaning“. To this end, the EDPB proposes six key factors (key-indicative factors), which must be examined cumulatively:
- Methodical and systematic approach: Research plan, hypothesis formation or – in the case of exploratory research – a clearly formulated objective.
- Compliance with ethical standards: Sector-specific ethics, consent to participate, transparency, accountability.
- Verifiability and transparency: Verifiable results, peer review, publication of results (subject to justified restrictions such as IP protection).
- Autonomy and independence: Research free from undue pressure; academic or scientific qualification of the researchers (PhD or proven expertise). Commercial implementation is not an obstacle to this.
- Aims of the research: Contribution to the general knowledge and well-being of society; commercial interests are not excluded.
- Scientific added value: Potential to expand existing knowledge or apply it in new ways.
If these factors are fulfilled, scientific research is presumed. If some are missing, the person responsible bears the burden of justification. Marketing analyses do not constitute research. Processing operations in the context of research data infrastructures (biobanks, register databases) as well as upstream activities such as contact data collection or pseudonymization can also fall under the research purpose, provided that the factors are mirrored accordingly.
Ease of use and storage
According to Art. 5(1)(b) GDPR, further processing for research purposes is deemed to be compatible with the original purposes compatible, which is why a purpose compatibility check in accordance with Art. 6(4) GDPR is not required. The purpose compatibility replaces the Legality check but not. The legal basis of the initial collection can often be continued, but not if the initial collection was based on consent or a legal obligation and the new processing exceeds the corresponding scope. If personal data is passed on between two controllers for research purposes, neither of the two controllers must carry out a compatibility check, but both must ensure a legal basis in accordance with Art. 6(1) GDPR or an exception in accordance with Art. 9(2) GDPR.
At the Storage According to Art. 5(1)(e) GDPR, personal data may also be retained beyond the fulfillment of the original purpose, provided that future research projects are sufficiently foreseeable. However, a generic „for research purposes“ is not sufficient; a limitation to a specific research area is required.
Legal bases: Consent, public and legitimate interest
Broad and dynamic consent
Where specific research purposes are not yet known at the time of data collection, „Broad Consent„, i.e. consent for a specific area of research. However, this requires protective measures, such as detailed, ongoing information for the persons concerned, e.g. via a newsletter, supervision and an ethical review. „Dynamic consent“ (i.e. consent obtained on a project-by-project or step-by-step basis) may be more suitable, particularly in the case of close and long-term contact between researchers and data subjects; combinations of broad and dynamic consent are also permissible.
The EDPB then requires the controller to check before each use of data in an individual project whether the project meets the legitimate expectations of those affected corresponds. If not, a new consent must be obtained. This additional expectation check is not set out in Recital 33 GDPR and in fact approximates broad consent to dynamic consent.
In clinical research, which healthcare and research at the same time a single consent is sufficient for linked purposes. If the purposes are not linked, separate consents are required. Consent should not be required for patients with severely impaired judgment.
Consent under the relevant research law does not necessarily meet the requirements of the GDPR for consent. Data controllers must therefore document consent under data protection law separately, ideally with clearly distinguishable consent forms or areas.
Public interest
A public interest as a legal basis can be based on also private research institutions if the relevant EU or member state law covers their activities (see recital 45 GDPR). A statutory research obligation is not required.
Legitimate interest
Scientific research, including of a commercial nature, may constitute a legitimate interest. The Research purpose generally has to weigh up the interests of. considerable weight. However, residual risks to the rights of data subjects must be mitigated in accordance with Art. 89(1) GDPR and taken into account when balancing interests.
In the case of medical research (e.g. clinical studies), Art. 6(1)(f) GDPR alone is not sufficient; an exception under Art. 9(2) GDPR is also required.
Personal data requiring special protection
For special categories of personal data, explicit consent (Art. 9(2)(a)), data manifestly made public (Art. 9(2)(e)) and national research privileges (Art. 9(2)(j)) are possible legal bases. The hurdle for manifestly making data public is high; data in social media is only covered if the data subject has made the data publicly accessible through a clear action. This is more likely to be the case for active users (influencers, bloggers) than for third-party posts.
When processing special categories on a large scale, a data protection impact assessment must be carried out.
Information requirements
In the case of long-term research, the data controller should actively offer the data subjects contact channels (e‑mail, letter, telephone) and inform them, for example, about a Privacy dashboard or a website keep informed. If the risk profile, group of recipients, retention period or legal basis change significantly, the data subjects must be informed prior to implementation.
If a controller wishes to process personal data that was originally for another purpose collected are later processed for research purposes, they must inform the data subjects in accordance with Art. 13(3) GDPR. Anyone who knowingly deletes contact data even though they plan to use it for research purposes at a later date is violating the principle of transparency.
If, in the course of a research project New personal data generated (e.g. diagnoses, derived pseudonyms, classifications), these are not considered to be collected directly from the data subject; Art. 14 GDPR applies.
The Exceptions according to Art. 14(5) GDPR when obtaining personal data via third parties must be interpreted restrictively:
- The exception in the case of disproportionate effort is relevant in research (outdated contact data, large databases over 10 years, inaccessible populations). However, those responsible must then provide indirect information (website, display in hospitals/schools, media, patient organizations).
- „Covert research“ (the information thwarts the research objectives) should only take place if it is clearly necessary („strictly necessary“) and only with additional guarantees such as an ethics review.
Rights of data subjects: erasure and objection
The exception to the right to erasure under Art. 17(3)(d) GDPR only applies if the erasure is likely to undermine the research objectives. make it impossible or seriously restrict would. This will rarely be the case for large data sets with many data subjects; for small cohorts or longitudinal studies this is more likely. If a data subject withdraws their consent, the data must be deleted in accordance with Art. 17(1)(b) GDPR, unless there is another legal basis for continued storage.
In the event of an objection, the controller may continue the processing if it is necessary for a task in the public interest is necessary. The EDPB extends this to Art. 6(1)(f) if the legitimate interest coincides with a public interest. However, the particular circumstances of the data subject must be taken into account (e.g. a rare disease with a high risk of re-identification).
Those responsible must also check whether Member State law in accordance with Art. 89(2) GDPR restricts data subjects’ rights for research purposes; corresponding deviations must be disclosed to the data subjects.
Distribution of roles with several actors
The qualification as controller, joint controller or processor must be determined functionally and documented on a case-by-case basis. The EDPB specifies as follows:
- Anyone who participates in the creation of a research protocol and determines the purposes and essential means is regularly the controller, even if they do not process any data themselves (e.g. the Sponsor a clinical study).
- Pure research funding or consulting (e.g. through a Ethics Committee) is not sufficient for responsibility.
- Processors are, for example, contract research organizations (CROs), provided that they only act in accordance with instructions.
- At joint responsibility the responsibilities must be contractually regulated and the data subjects must be informed accordingly (Art. 26 GDPR). It may be the case that several controllers rely on different legal bases.
Appropriate safeguards pursuant to Art. 89(1) GDPR
According to the EDPB, Art. 89(1) GDPR establishes an independent obligation in addition to the general obligations under Art. 5, 24, 25 and 32 GDPR:
- Anonymization before pseudonymization: If research purposes can be achieved with anonymous data, personal data must be anonymized. The anonymization process itself can be based on the same legal basis as the upstream operations.
- Pseudonymization according to the state of the art; re-identification risks for data set combinations must be continuously monitored.
- Additional guarantees such as secure processing environments, federated databases, privacy enhancing technologies (homomorphic encryption, synthetic data), contractual prohibitions on re-identification, ethics oversight, codes of conduct in accordance with Art. 40 GDPR and certifications in accordance with Art. 42 GDPR.
- Special care should be taken with genetic and biometric data because genetic profiles are only anonymous in exceptional cases, family members are also affected and the risks are lifelong.