Aristotelis Zervos
Aristotelis Zervos, Editorial Director at 2B Advice, combines legal and journalistic expertise in Data protection, IT-Compliance and AI regulation.
The European Data Protection Board (EDPB) has assessed compliance with the Transparency- and Duty to inform as the next EU-wide audit priority for 2026. Specifically, the data protection authorities of the EU member states are to jointly investigate whether companies and public bodies are complying with their legal obligations under Articles 12, 13, and 14. GDPR properly comply. Specifically, this means: Whether affected Individuals are adequately informed about when and how their personal data is processed.
Koordiniertes Vorgehen (CEF) der Datenschutzbehörden
The joint action by the supervisory authorities is taking place within the framework of the Coordinated Enforcement Framework (CEF), which was established by the EDPB. The aim of the CEF is to strengthen cooperation between national data protection authorities and to ensure uniform enforcement of the GDPR in Europe. Participation is voluntary. The participating supervisory authorities focus on the same priority topic at the same time and conduct investigations in their respective countries. The results are then compiled in a joint report at EU level, best practices are identified, and weaknesses in the implementation of the requirements are highlighted. If necessary, recommendations or further enforcement measures follow.
The 2026 Specialization Exam „Transparency- and Duty to inform“ ist bereits die fünfte gemeinsame Aktion. In den vergangenen Jahren hat der EDSA koordinierte Prüfungen unter anderem zu folgenden Themen durchgeführt:
- 2023: Appointment and duties of data protection officers
- 2024: Implementation of the right to information by Responsible persons (Art. 15) GDPR)
- 2025: Right to Deletion (Art. 17 GDPR)
The choice of the new focus is in line with the EDSA's longer-term strategy, which aims to achieve more consistent and coordinated enforcement of the GDPR aims at.
Was bedeutet das konkret für Unternehmen?
Die Aufsichtsbehörden werden voraussichtlich standardisierte Fragebögen einsetzen, um bei vielen Organisationen den Stand der Transparenzmaßnahmen abzufragen. Anschließend können sie je nach Land entweder breite Stichproben durchführen oder gezielt förmliche Prüfungsverfahren bei einzelnen Verantwortlichen einleiten. In jedem Fall ist damit zu rechnen, dass Datenschutzerklärungen und ähnliche Dokumentationen angefordert und auf ihre Konformität geprüft werden. Bei festgestellten Verstößen stehen den Behörden weitere Schritte bis hin zu Sanktionen offen.
Violations of transparency requirements are also not „minor formalities“: they affect core principles of GDPR.
At the same time, the campaign offers an opportunity: Anyone who Transparency Convincingly implementing this strengthens trust and reduces complaints, inquiries, and legal risks.
Reading tip: Datenschutzbehörden prüfen KI-Einsatz! Diese 7 Fragen müssen Unternehmen jetzt beantworten
Weaknesses from Articles 12, 13, and 14 of the GDPR in practice
Aus Sicht der Praxis werden Aufsichtsbehörden voraussichtlich vor allem auf folgende „klassische Schwachstellen“ achten:
- Klarheit und Verständlichkeit:
Sind die Datenschutzhinweise in einer für die Zielgruppe nachvollziehbaren Sprache verfasst? Verstecken sich wichtige Details im „Kleingedruckten“ bzw. in juristischem Fachjargon? - Vollständigkeit der Angaben:
If all of the information specified in Articles 13 and 14 GDPR prescribed information, such as the purposes of the Processingwhich Legal basis, alle Empfänger (bzw. Kategorien von Empfängern), Speicherfristen und die Rechte der Betroffenen? Fehlen keine relevanten Details? Information on indirect data collection:
If personal data not collected directly from the data subject, but rather from third parties or publicly available sources: If the subsequent information is provided in accordance with Art. 14 GDPR in a timely manner and in an appropriate form? Are processes in place to ensure that such Duty to inform auch bei Daten aus externen Quellen zu erfüllen?- Internal data protection information:
Are not only customers and users, but also employees adequately informed about the Processing of their data? Companies should make sure to keep internal data protection notices (e.g. for employees) up to date, as the supervisory authorities will probably not only examine publicly accessible statements, such as the privacy policy on the website. - Language and structure:
Is the language understandable and the presentation clear? Especially when dealing with complex issues (such as the use of Cookies, Tracking-tools or data transfers to third countries), the information should be presented in a way that provides an overview understandable to the general public.
Three practical quick checks to help you prepare
Quick Check 1: Data protection information in practice
Systematically compare the privacy notices with the VVT und den tatsächlichen Datenflüssen ab: Zwecke, Legal basis, Empfänger, Tools, Speicherfristen.
Quick Check 2: Art. 14 GDPR in view
Identifizieren Sie Prozesse, in denen Daten nicht direkt bei Betroffenen erhoben werden (z. B. Lead-Listen, Konzernweitergaben, Dienstleisterdaten). Prüfen Sie, ob und wie die Informationspflicht erfüllt wird oder ob Ausnahmen dokumentiert begründet sind.
Quick Check 3: Verständlichkeit testen
Have non-lawyers in the company (e.g., sales, HR) read the information. If the content is not understood, this is a strong indication that there is room for improvement and a good reality check for Art. 12. GDPR.
Fazit zum EDSA-Prüfschwerpunkt 2026
With the election of Transparency and Duty to inform As its EU-wide audit priority for 2026, the EDSA is setting a clear focus: privacy notices will be reviewed in terms of both content and structure. It is therefore worthwhile for companies to take a targeted „Transparency-Audit“. Especially where data flows are complex (Tracking, platforms, international service providers, group-wide processes). Those who refine their approach now will not only strengthen Compliance, but also trust and efficiency in dealing with data subject rights.
Benötigen Sie Unterstützung bei der Beantwortung eines behördlichen Informationsersuchens oder bei einer konkreten Prüfaktion? Unsere Datenschutzexperten prüfen das Schreiben der für Sie zuständigen Datenschutzbehörde, erstellen die notwendigen Unterlagen und unterstützen Sie bei allen regulatorischen Anforderungen. Kontaktieren Sie uns für eine unverbindliche Erstberatung.
Source: Coordinated Enforcement Framework: EDPB selects topic for 2026
Aristotelis Zervos is Editorial Director at 2B Advice, a lawyer and journalist with profound expertise in data protection, GDPR, IT-Compliance and AI governance. He regularly publishes in-depth articles on AI regulation, GDPR-Compliance and risk management. You can learn more about him on his Author profile page.





