Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

The European Data Protection Board Releases New Guidelines on the Processing of Personal Data for Scientific Research

By David Peloquin, Edward Machin & Lauren Aurelius on April 24, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

For almost a decade, the scientific research provisions of the General Data Protection Regulation (GDPR) have lacked authoritative, European Union (EU)-wide interpretation, leaving sponsors of clinical trials and research institutions alike to navigate a patchwork of national implementing laws. A 2019 study commissioned by the European Data Protection Board (EDPB) — the body comprising EU national data protection authorities — confirmed significant divergence among EU Member States, and interim guidance published in 2021 by the EDPB highlighted — but left unresolved — several key GDPR compliance issues facing organisations in the life sciences industry. In the years since, the COVID-19 pandemic and the United Kingdom’s post-Brexit departure from the EU framework have only sharpened the need for more specific guidance. Ropes & Gray attorneys co-authored an article published in Science magazine in October 2020 that provided a summary of the complexity in this space and potential solutions.

The adoption of Guidelines 1/2026 by the EDPB on 15 April 2026 represents the most meaningful step to date towards regulatory clarity for the global research enterprise. The Guidelines, which are open for public consultation until 25 June 2026, address, among other things, the definition of “scientific research”, the legal bases for processing sensitive personal data (including broad consent and the public interest and legitimate interest pathways), and transparency obligations and appropriate safeguards under Article 89(1) of the GDPR. The EDPB has simultaneously announced a dedicated “sprint team” to finalise related guidelines on anonymisation by the summer. Given the GDPR’s broad extra-territorial jurisdiction, the Guidelines will have major implications for research organisations both within and outside the EU.

To read the full Ropes & Gray alert, click here.

Photo of David Peloquin David Peloquin
Read more about David PeloquinEmail
Photo of Edward Machin Edward Machin
Read more about Edward MachinEmail
Photo of Lauren Aurelius Lauren Aurelius
Read more about Lauren AureliusEmail
  • Posted in:
    Privacy and Cybersecurity, Technology and AI
  • Blog:
    RopesDataPhiles
  • Organization:
    Ropes & Gray
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo