Index/Organizations/European Data Protection Board

European Data Protection Board

Body of the European Union ensure that data privacy laws are consistently applied in the EU countries

Fact-Checks

20 results
Dec 16, 2025
Most Viewed

What exactly is proposed in the revised "chat control" proposal from dec. 2025?

The revised “Chat Control” (CSAR) proposal in late 2025 removes the Council’s earlier explicit requirement for mandatory, universal scanning of encrypted private communications but keeps obligations a...

Dec 17, 2025
Most Viewed

eu chat control

EU governments have negotiated a contentious package known as the Child Sexual Abuse Regulation (nicknamed “Chat Control”) that aims to curb online child sexual abuse material (CSAM) but has been repe...

Dec 10, 2025
Most Viewed

What is the legal basis and timeline for EES rollout across the EU (including 2024 implementation milestones)?

The legal basis for the Entry/Exit System (EES) is Regulation (EU) 2017/2226, adopted in November 2017 and in force since December 2017; eu‑LISA is responsible for development and operation . After re...

Nov 28, 2025

Brazil's LGPD recent changes

Brazil’s General Personal Data Protection Law (LGPD) remains the country’s cornerstone data-privacy framework, aligned in many respects with the EU’s GDPR and enforced by the National Data Protection ...

Nov 6, 2025

What are the EU's regulations on biometric data collection for travelers?

The EU’s biometric rules for travellers center on the Entry/Exit System (EES), which mandates collection of facial images and fingerprints from non‑EU short‑stay visitors and started phased operations...

Dec 8, 2025

Which countries legally require facial recognition for international arrivals and can travelers refuse?

Several countries use facial recognition at international borders; the U.S., China and many European states deploy it at airports for arrivals and departures, and some places require it for certain cl...

Nov 9, 2025

What rights do travelers have under EU law regarding biometric data retention and deletion?

Travelers dealing with EU biometric checks face a mix of specific system rules and broader data-protection rights: the Entry/Exit System (EES) will collect fingerprints and facial images and store the...

Jan 16, 2026

What specific data retention obligations do UK and EU age‑verification laws impose on platforms like OnlyFans?

UK and EU age‑verification rules do not mandate a single retention schedule but consistently require strict data‑minimisation, purpose limitation and avoidance of unnecessary storage: platforms must d...

Nov 10, 2025

What privacy protections exist under GDPR for non-EU visitors in EES?

GDPR protections apply to non-EU visitors whose personal data is processed in the EU when organizations “offer goods or services” to them or “monitor” their behaviour; the EU Entry/Exit System (EES) c...

Jan 18, 2026

Will the eu look at individuals data in its investigation

The European Data Protection Board (EDPB) has nominated "transparency and information obligations" under Articles 12–14 GDPR as the topic for its 2026 coordinated enforcement action, and national data...

Jan 2, 2026

How do countries with no explicit-content laws handle child protection and age verification?

Countries that lack specific "explicit-content" statutes generally rely on a patchwork of existing laws, industry codes, and regulator guidance to protect children online, while pressing platforms to ...

Jan 1, 2026

How do recent CJEU rulings affect Schengen entry/exit systems and passenger name record (PNR) data sharing?

The Court of Justice of the European Union (CJEU) upheld the validity of the EU PNR Directive but substantially narrowed how member states may process Passenger Name Record (PNR) data: broad, undiffer...

Dec 17, 2025

Do you think chat control 2.0 will have retroactive scanning or is it too risky?

Available reporting shows the EU’s latest “Chat Control 2.0” effort dropped an explicit duty to break end‑to‑end encryption and mandatory on‑device scanning, but it preserves mechanisms that critics s...

Nov 28, 2025

How can Brazilian citizens view, correct, or revoke consent for data used in their digital ID?

Brazil’s General Data Protection Law (LGPD) gives data subjects rights to access, correct and withdraw consent, and the national digital ID is governed by government programs (gov.br, Serpro/QuarkID) ...

Nov 28, 2025

How does brazilian law regulate data sharing and consent for the digital id?

Brazil’s digital identity and data-sharing landscape is governed principally by the General Data Protection Law (LGPD), which requires a lawful legal basis (including consent) for processing personal ...

Nov 28, 2025

how does brazil's digital id protect user privacy and data security?

Brazil’s digital-ID program combines a centralized National Civil Identification (ICN/DNI) and the gov.br account tiers with mandatory and optional biometric checks, and recent moves to use blockchain...

Nov 27, 2025

How do data protection authorities in EU member states handle individual requests to refuse or delete EES data?

Data protection authorities (DPAs) in EU member states handle individual requests about Entry/Exit System (EES) data through existing GDPR pathways: individuals may request access, rectification or de...

Nov 26, 2025

How does the EU's GDPR classify and restrict processing of biometric data for travel purposes?

GDPR treats biometric data as a special category of personal data and therefore places stricter limits on its processing — lawful grounds are narrow (explicit consent or specific public-interest bases...

Nov 24, 2025

What complaint or appeal channels exist for travelers who believe EES processing violates their privacy rights?

Travelers who believe the EU Entry/Exit System (EES) violates their privacy can use the EU data-protection framework: file complaints with national Data Protection Authorities (DPAs), seek remedies th...

Nov 17, 2025

How has the European Data Protection Supervisor (EDPS) advised on consent vs legal basis for EES processing in 2023-2025?

The EDPS between 2023–2025 consistently stressed that processing by EU institutions must rest on a clear GDPR legal basis and that consent has limits — it can be appropriate in some cases (e.g., short...