Menu
Browse

European Data Protection Board

Aliases: 2 aliases
Primary URL Location Industry
edpb[.]europa[.]eu
Country Belgium
Telecommunications Icon
Telecommunications
Profile

The European Data Protection Board (EDP) is an independent EU body tasked with ensuring the consistent application of the General Data Protection Regulation across the European Union and the European Economic Area. It provides guidance, issues guidelines and recommendations, and adopts binding decisions in cases of disputes between national supervisory authorities. The board also promotes cooperation among data protection authorities and contributes to the development of a coherent data protection framework for individuals and organisations. Its work supports both regulators and businesses seeking clarity on compliance obligations.

The EDP is headquartered in Brussels, Belgium, where it convenes its plenary meetings and maintains its secretariat. It brings together the heads of the data protection authorities of each of the twenty‑seven EU member states together with the European Data Protection Supervisor, forming a collegial body of twenty‑eight members. This composition gives the board a pan‑European reach and enables it to reflect diverse national perspectives while acting as a single EU‑wide authority. The secretariat, staffed by officials seconded from national authorities and EU institutions, supports the board’s operational activities.

Unlike sector‑specific regulators, the EDP’s mandate is exclusively focused on data protection and privacy, allowing it to develop deep expertise in the interpretation and enforcement of the GDPR. Its ability to adopt legally binding decisions in cross‑border cases distinguishes it from advisory bodies that can only issue non‑binding opinions. The board also plays a key role in fostering consistency through the consistency mechanism, which supervisory authorities can invoke to seek a uniform interpretation of the regulation. These attributes position the EDP as the central reference point for data protection law within the EU.

The EDP is established directly by the GDPR and operates as an independent institution without a parent company or shareholder structure; its accountability lies with the European Parliament, the Council of the European Union, and the European Court of Justice. In August 2020, the organisation was among several European ISPs that experienced a coordinated distributed denial‑of‑service attack targeting DNS infrastructure, which employed DNS amplification and LDAP techniques and peaked at approximately 300 Gbit/s, causing temporary service disruptions that were mitigated within a day. Dutch authorities later noted associated extortion demands involving Bitcoin, although no definitive attribution of the attack was ever established.

Incidents
Linked incidents available to members
1 incident