EDPS and EU data protection officers focus on AI, cybersecurity and compliance

Data protection priorities for EU institutions include AI risk management, website compliance and data breaches.

EDPS-DPO network meeting in Brussels on data protection priorities, AI governance, cybersecurity and DPIAs

The European Data Protection Supervisor (EDPS) and data protection officers (DPOs) from EU institutions, bodies, offices and agencies met in Brussels on 18 June to discuss emerging data protection priorities and compliance challenges.

The 58th meeting of the EDPS-DPO network was hosted by the Executive Agencies of the European Commission. The meeting brought together DPOs from across the EU administration at a time of significant regulatory and technological change.

European Data Protection Supervisor Wojciech Wiewiórowski opened the meeting by emphasising the importance of safeguarding DPO independence in practice. He pointed to recent EDPS action, guidance, and procedures intended to safeguard the role of DPOs across EU institutions.

Wiewiórowski also reviewed key developments from 2025, including the closure of the EDPS investigation into the European Commission’s use of Microsoft 365, a rise in complaints, and the growing impact of AI-generated submissions. He noted that regulatory simplification should reduce unnecessary administrative burdens without undermining fundamental rights protections.

Thomas Zerdick, Head of the EDPS Supervision and Enforcement Unit, introduced a follow-up tracker designed to maintain continuity between EDPS-DPO meetings. The first tracker focused on EDPS supervisory guidance on the role of DPOs in EU institutions and the EDPS decision on prior consent to DPO dismissal.

Zerdick also presented recent developments in supervision and enforcement, including complaint handling, compliance issues affecting several EU institutions, and practical guidance on international transfers and data protection impact assessments. The update also covered work linked to the Area of Freedom, Security and Justice, including audits, opinions, and preparations for upcoming systems.

Luis Velasco, Head of the EDPS Technology and Privacy Unit, outlined initiatives to help EU institutions meet compliance requirements for automated systems and AI. He announced that an updated version of the EDPS guidance on risk management for AI systems is expected to be published later this summer.

Velasco also referred to a practical checklist on human intervention, intended to help organisations establish effective safeguards for automated systems. He warned that cyberattacks targeting EU institutions pose a growing threat and pose serious risks to individuals’ personal data.

The discussion also addressed the response to a personal data breach. Velasco stressed that individuals affected by a personal data breach should be informed without undue delay when a breach is likely to pose a high risk to their rights and freedoms.

A practical workshop focused on developing a common data protection impact assessment template under the EU Data Protection Regulation. Participants tested a draft template through a case study and discussed issues, including necessity, proportionality, and risk assessment.

The afternoon sessions included a discussion of the 2024 data breach at the European Agency for Law Enforcement Training. The CEPOL DPO and the EDPS Data Breach Notification Team shared lessons with the wider DPO community, highlighting that major data breaches create organisational and human challenges as well as compliance obligations.

The meeting also included a session on privacy and data protection case law, presented by Zerdick. The session focused on the EDPS’s interpretation of recent judgments and their practical implications for supervisory work and controllers.

Participants also received an update on the EDPS Website Compliance Awareness Campaign. Following pilot phases in 2024 and 2025, the Technology and Privacy Unit presented preliminary findings from the first wave of the campaign’s second phase, which involved automated scans of public-facing websites of EU institutions.

The EDPS said the meeting demonstrated the value of bringing together the EU’s DPO community to address shared challenges, exchange practical experience and strengthen compliance across institutions. The discussions focused on practical cooperation, support for compliance, and stronger data protection safeguards across the EU administration.

Why does it matter?

The meeting highlights how data protection within EU institutions is evolving beyond traditional compliance issues toward broader challenges involving AI governance, cybersecurity, automated decision-making and digital service oversight. As public administrations increasingly adopt AI-enabled systems and process larger volumes of personal data, data protection officers are playing a more strategic role in managing operational and regulatory risks.

The discussions also illustrate a growing emphasis on practical implementation. Common templates, coordinated guidance and shared lessons from data breaches can help institutions apply data protection rules more consistently across the EU administration. This is particularly important as regulators seek to align privacy requirements with emerging frameworks governing AI, cybersecurity and digital public services.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!