New EDPB draft guidelines on scientific research under the EU GDPR
The question
In what circumstances can businesses lawfully process personal data for the purposes of scientific research under the EU General Data Protection Regulation (GDPR)?
The key takeaway
The European Data Protection Board (EDPB) has published draft guidelines on the processing of personal data for scientific research purposes. To provide greater clarity for researchers and support GDPR compliance, the draft guidelines identify six key indicative factors for determining what constitutes “scientific research” for these purposes, while seeking to balance research objectives with the protection of individuals’ fundamental rights.
The background
On 16 April 2026, the EDPB released the draft guidelines for public consultation. The consultation was open until 25 June 2026, providing stakeholders with the opportunity to comment and provide feedback. The Board has not yet announced a final version or indicated when this may be available.
The development
To determine whether data processing takes place for scientific research purposes, the EDPB guidelines advise controllers to consider six key indicative factors:
- the presence of a methodical and systematic approach to the processing
- adherence to an ethical standard
- verifiability and transparency (ie can the results of the activity be verified and is the research conduct open for criticism)
- autonomy and independence (ie are the activities conducted independently of the prejudices of the scientific community and pressures of external parties)
- objectives of the research, and
- the potential to contribute to existing scientific knowledge or apply existing knowledge in novel ways.
Where an activity meets all six factors, it can be presumed to constitute scientific research, whereas a controller whose activities do not meet every factor should be prepared to justify and demonstrate why the activities nonetheless qualify as scientific research within the meaning of the GDPR.
Further processing of data already held for the purpose of scientific research is presumed to be compatible with the original purpose, exempting controllers from the purpose compatibility test. In such circumstances, the controller must evaluate that the legal basis of the initial processing is suitable for the further processing activity. The guidelines also permit “broad” and “dynamic” consent where research purposes are not fully known at collection, if the ethical standards for scientific research are upheld and safeguards are implemented.
Individuals have data subject rights in relation to data that is processed for these purposes, including the right to request erasure of their personal data and to object to data processing for scientific purpose. The guidelines set out limitations of these rights, for example where the right to erasure may render impossible or seriously impair the objective of conducting scientific research or where there is a public interest in conducting the scientific research.
Why is this important?
The EDPB has provided greater legal certainty for organisations whose data processing activities may fall within the scope of scientific research, particularly in sectors such as AI and technology where research and commercial development often overlap. The draft guidelines set out clear criteria for what constitutes scientific research under the GDPR and clarify the scope of the regulation’s research-specific provisions, such as the presumption of purpose compatibility and broad consent. Organisations whose processing activities comply with the six factors may benefit from reduced compliance requirements, while those whose activities fall outside the definition will need to rely on standard frameworks to establish compliance. This includes conducting full purpose compatibility assessments for any further processing. The guidelines underscore the importance of assessing whether activities genuinely satisfy the EDPB’s criteria, and of documenting that assessment accordingly.
Any practical tips?
Organisations should consider:
- mapping their processing activities against the six indicative factors and documenting the analysis, for example if this is queried by the regulator
- verifying that the original legal basis supports any further processing for research purposes
- clearly delineating scientific research from commercial product development, where both co-exist
- implementing appropriate safeguards, such as pseudonymisation, secure processing environments, and ethical oversight
- establishing clear role allocations and agreements where multiple entities are involved, and
- monitoring any changes in the final adopted version (noting the guidelines remain in draft form).
While these are EU guidelines, they are still relevant to organisations subject to the UK GDPR and not caught by the EU legislation, as an indicator of the direction of regulatory travel.
Autumn 2026
Stay connected and subscribe to our latest insights and views
Subscribe Here