Aristotelis Zervos
Aristotelis Zervos, Editorial Director at 2B Advice, combines legal and journalistic expertise in Data protection, IT-Compliance and AI regulation.
The European Data Protection Board (EDPB) has assessed compliance with the Transparency- and Duty to inform as the next EU-wide audit priority for 2026. Specifically, the data protection authorities of the EU member states are to jointly investigate whether companies and public bodies are complying with their legal obligations under Articles 12, 13, and 14. GDPR properly comply. Specifically, this means: Whether affected Individuals are adequately informed about when and how their personal data is processed.
Coordinated Approach (CEF) by Data Protection Authorities
The joint action by the supervisory authorities is taking place within the framework of the Coordinated Enforcement Framework (CEF), which was established by the EDPB. The aim of the CEF is to strengthen cooperation between national data protection authorities and to ensure uniform enforcement of the GDPR in Europe. Participation is voluntary. The participating supervisory authorities focus on the same priority topic at the same time and conduct investigations in their respective countries. The results are then compiled in a joint report at EU level, best practices are identified, and weaknesses in the implementation of the requirements are highlighted. If necessary, recommendations or further enforcement measures follow.
The 2026 Specialization Exam „Transparency- and Duty to inform“This is already the fifth joint initiative. In recent years, the EDSA has conducted coordinated audits on the following topics, among others:
- 2023: Appointment and duties of data protection officers
- 2024: Implementation of the right to information by Responsible persons (Art. 15) GDPR)
- 2025: Right to Deletion (Art. 17 GDPR)
The choice of the new focus is in line with the EDSA's longer-term strategy, which aims to achieve more consistent and coordinated enforcement of the GDPR aims at.
What does this mean specifically for companies?
Regulatory authorities are expected to use standardized questionnaires to assess the status of transparency measures at many organizations. Depending on the country, they may then either conduct broad-based sampling or initiate targeted formal investigation procedures against individual data controllers. In any case, it is to be expected that privacy policies and similar documentation will be requested and reviewed for compliance. If violations are identified, the authorities have the option to take further steps, including the imposition of sanctions.
Violations of transparency requirements are also not „minor formalities“: they affect core principles of GDPR.
At the same time, the campaign offers an opportunity: Anyone who Transparency Convincingly implementing this strengthens trust and reduces complaints, inquiries, and legal risks.
Reading tip: Data Protection Authorities Are Scrutinizing the Use of AI! Companies Must Answer These 7 Questions Now
Weaknesses from Articles 12, 13, and 14 of the GDPR in practice
From a practical standpoint, regulatory authorities are likely to focus primarily on the following „classic vulnerabilities“:
- Clarity and Comprehensibility:
Is the privacy policy written in language that the target audience can understand? Are important details hidden in the „fine print“ or in legal jargon? - Completeness of the Information:
If all of the information specified in Articles 13 and 14 GDPR prescribed information, such as the purposes of the Processingwhich Legal basis, all recipients (or categories of recipients), retention periods, and the rights of the data subjects? Are there any relevant details missing? Information on indirect data collection:
If personal data not collected directly from the data subject, but rather from third parties or publicly available sources: If the subsequent information is provided in accordance with Art. 14 GDPR in a timely manner and in an appropriate form? Are processes in place to ensure that such Duty to inform ...even when the data comes from external sources?- Internal data protection information:
Are not only customers and users, but also employees adequately informed about the Processing of their data? Companies should make sure to keep internal data protection notices (e.g. for employees) up to date, as the supervisory authorities will probably not only examine publicly accessible statements, such as the privacy policy on the website. - Language and structure:
Is the language understandable and the presentation clear? Especially when dealing with complex issues (such as the use of Cookies, Tracking-tools or data transfers to third countries), the information should be presented in a way that provides an overview understandable to the general public.
Three practical quick checks to help you prepare
Quick Check 1: Data protection information in practice
Systematically compare the privacy notices with the VVT and the actual data flows: Purposes, Legal basis, Recipients, Tools, Retention Periods.
Quick Check 2: Art. 14 GDPR in view
Identify processes in which data is not collected directly from data subjects (e.g., lead lists, group-wide data transfers, service provider data). Verify whether and how the obligation to provide information is being fulfilled, or whether any exceptions are documented and justified.
Quick Check 3: Test for Clarity
Have non-lawyers in the company (e.g., sales, HR) read the information. If the content is not understood, this is a strong indication that there is room for improvement and a good reality check for Art. 12. GDPR.
Conclusion on the EDSA Audit Focus Area for 2026
With the election of Transparency and Duty to inform As its EU-wide audit priority for 2026, the EDSA is setting a clear focus: privacy notices will be reviewed in terms of both content and structure. It is therefore worthwhile for companies to take a targeted „Transparency-Audit“. Especially where data flows are complex (Tracking, platforms, international service providers, group-wide processes). Those who refine their approach now will not only strengthen Compliance, but also trust and efficiency in dealing with data subject rights.
Do you need assistance in responding to a request for information from a regulatory authority or in connection with a specific audit? Our data protection experts will review the letter from your applicable data protection authority, prepare the necessary documentation, and assist you with all regulatory requirements. Contact us for a no-obligation initial consultation.
Source: Coordinated Enforcement Framework: EDPB selects topic for 2026
Aristotelis Zervos is Editorial Director at 2B Advice, a lawyer and journalist with profound expertise in data protection, GDPR, IT-Compliance and AI governance. He regularly publishes in-depth articles on AI regulation, GDPR-Compliance and risk management. You can learn more about him on his Author profile page.





