Skip to main content
EDPB Chair Anu Talus on Enforcement PrioritiesLaws and Regulations
4 min readFor Privacy Officers

EDPB Chair Anu Talus on Enforcement Priorities

The European Data Protection Board (EDPB) is at the heart of a regulatory system under pressure. When Anu Talus became chair in May 2023, she took on the task of ensuring consistent GDPR enforcement across 27 member states, even as AI technologies change how personal data is processed. With the EU Digital Omnibus package proposing amendments to the GDPR, the EDPB faces a critical challenge: can it adapt its guidance quickly enough to keep up with technological advances?

This post explores how the EDPB is addressing this challenge, based on Chair Talus's recent interview with the IAPP during the week the Digital Omnibus was released.

The Challenge

The EDPB's core mandate since 2018 is to ensure consistent GDPR application, provide guidance, adopt findings for uniform implementation, advise the European Commission, and encourage cooperation among Data Protection Authorities (DPAs). However, the environment has changed. AI systems now process personal data in ways the original GDPR drafters didn't foresee. Member state DPAs interpret the same regulation differently, and the European Commission is considering amendments through the Digital Omnibus package.

Your organization feels these effects. When the EDPB issues guidance that one DPA enforces strictly while another is more lenient, you're left building compliance programs for the strictest interpretation. When AI vendors claim compliance with GDPR amid regulatory uncertainty, you must decide whether to deploy their systems. The EDPB's coordination affects your risk exposure directly.

The Environment and Constraints

The EDPB operates under constraints that limit its capabilities. It lacks direct enforcement authority and can't compel a member state DPA to interpret guidance uniformly. It relies on cooperation among authorities with different legal traditions, resources, and political pressures.

The timing of the Digital Omnibus adds complexity. Proposing GDPR amendments while the regulation is still being interpreted creates uncertainty. Organizations are unsure whether to prepare for the current framework or the amended one. The EDPB must issue guidance on existing regulations while the Commission considers changes.

AI introduces technical challenges that the GDPR's principles-based approach struggles to address. Article 22's restrictions on automated decision-making were written before large language models. Article 5's data minimization principle doesn't fit neatly with training datasets that require massive data amounts. The EDPB needs to provide guidance that's specific yet flexible as AI evolves.

The Approach Taken

Chair Talus's interview outlines a strategy focused on maintaining the EDPB's coordination role while adapting to new realities. Instead of rewriting guidance for every AI development, the EDPB emphasizes cooperation among DPAs to ensure consistent interpretations.

This approach acknowledges a practical reality: the EDPB can't move faster than technology or the political process around the Digital Omnibus. However, it can ensure that when DPAs face similar AI-related compliance questions, they coordinate their responses.

For your team, the most reliable compliance signal isn't necessarily the latest EDPB guidance document. It's the enforcement actions and consistent interpretations emerging across jurisdictions. When you see these patterns, it's the EDPB's coordination function at work.

Results and Observable Patterns

The interview took place during what Chair Talus called "an especially significant week in EU data protection," coinciding with the Digital Omnibus release. The EDPB's ability to maintain guidance and coordination through uncertainty shows resilience but doesn't resolve the underlying challenge.

We lack metrics on how effectively the EDPB has harmonized AI-related enforcement across member states because that harmonization is still developing. However, the EDPB continues to function as the coordination body it was designed to be, even as the regulatory framework shifts.

For organizations implementing AI systems that process personal data, this creates a specific compliance posture: you're building programs in a regulatory environment where rules are clarified through enforcement and guidance simultaneously. The EDPB's coordination role means these clarifications should converge over time, but "over time" may be longer than your deployment timeline.

What Could Be Done Differently

The EDPB's structural constraint isn't something leadership can change easily. The board was designed as a coordination body, not a unified enforcement authority, reflecting the EU's political reality.

Faster, more specific guidance on AI systems could accelerate clarity. The EDPB could prioritize issuing opinions on specific AI use cases rather than waiting for comprehensive frameworks. A rapid-response approach to emerging AI compliance questions would provide clearer signals about enforcement directions.

The timing challenge with the Digital Omnibus is harder to address. The EDPB can't control the Commission's legislative timeline. However, it could offer transitional guidance on handling compliance when amendments are proposed but not yet adopted.

Takeaways for Your Team

First, treat EDPB guidance as a floor, not a ceiling. If you're operating across multiple EU member states, build your compliance program for the strictest DPA interpretation you're likely to face, not the most permissive EDPB guidance.

Second, monitor DPA enforcement patterns, not just EDPB publications. Coordinated enforcement actions or consistent interpretations across jurisdictions are stronger signals of where compliance expectations are settling than any single guidance document.

Third, don't wait for complete regulatory clarity on AI before making deployment decisions. The EDPB's coordination function will take time to produce harmonized guidance. Build your AI governance framework around GDPR's core principles, document your compliance reasoning, and be ready to adjust as enforcement patterns emerge.

Fourth, pay attention to the Digital Omnibus process. The proposed amendments could significantly change your compliance obligations. Track which amendments the Council and Parliament prioritize, as these indicate where regulatory pressure is building.

The EDPB's challenge is your challenge: maintaining compliance in a regulatory environment adapting to technology in real time. Chair Talus's approach emphasizes coordination and consistency. Your approach should emphasize documentation and flexibility. When the guidance catches up to the technology, you need evidence that your compliance decisions were reasonable given what was known at the time.

You Might Also Like