GDPR guidelines
Guidelines from the EDPB and the Dutch Data Protection Authority
Guidelines are not law, but supervisory authorities assess against them. Per guideline: what it covers, whether it is adopted or still under consultation, and what it means in practice. Only guidelines read on edpb.europa.eu or autoriteitpersoonsgegevens.nl.
Reference date of this layer: 15 September 2026. Every item was checked against its source; the date per item is shown. Anything after the reference date is not yet here.
- under consultationEuropean Data Protection Board (EDPB)Guidelines 02/2026, versie 1.0
Guidelines 02/2026 on Anonymisation
Version 1.0 was adopted on 7 July 2026 for public consultation. Comments can be submitted until 30 October 2026 (23:59 CET) via the EDPB site. The guidelines update Opinion 05/2014 of the Article 29 Working Party and refine its criteria. They build on the EDPS v SRB judgment (C-413/23 P): whether data are anonymous is assessed from the perspective of each relevant entity and the means that entity is reasonably likely to use. Data count as anonymous if they pass three criteria: No Record Isolation, No Linkage and No Inference. The test can be applied in two ways: contextually (per entity, based on its capabilities) or in a simplified way (without that distinction, and therefore stricter).
What this means: If you want to treat training data, statistics or AI output as anonymous, you must be able to show that the three criteria are met. You can do that in the simplified way, or contextually per receiving entity. The same dataset can be anonymous for one entity and personal data for another. An earlier assessment under Opinion 05/2014 does not need to be redone, but periodic reassessment is good practice. Until the final version this is a draft; comments can be submitted until 30 October 2026.
- under consultationEuropean Data Protection Board (EDPB)Guidelines 03/2026, versie 1.0
Guidelines 03/2026 on web scraping in the context of generative AI
Version 1.0 was adopted on 7 July 2026 for public consultation; comments can be submitted until 30 October 2026 (23:59 CET). The guidelines cover private entities scraping data from websites to train generative AI, either themselves or through a contracted party. They address roles (controller or processor), purpose limitation, transparency (including the Article 14(5)(b) disproportionate effort exception), data minimisation, accuracy, legitimate interest as legal basis with the balancing test and mitigating measures, and special categories of data, where the GC and Others ruling (C-136/17) can be relevant for incidental collection.
What this means: If you scrape web data for AI yourself on the basis of legitimate interest, you must be able to demonstrate the balancing test, and it helps to exclude sources and data types you do not need, skip websites that refuse scraping and give people a way to object in advance. If you use an already scraped dataset, you as controller assess whether it can lawfully be used and must meet the accountability principle. You must actively try to keep out special category data. It is still a draft; the final text may differ.
- finalEuropean Data Protection Board (EDPB)Guidelines 02/2025, versie 2.0
Guidelines 02/2025 on processing of personal data through blockchain technologies
Final version 2.0 was adopted on 7 July 2026 after the 2025 consultation (version 1.1, adopted on 8 April 2025, feedback until 9 June 2025). The EDPB explains how blockchains work, which architectures exist and what that means for roles, legal bases, retention and the right to erasure. The recommendation is not to store directly identifiable personal data on chain but off chain, using encryption, hashing or cryptographic commitments, and to favour permissioned blockchains.
What this means: If you use blockchain with personal data, assess in advance whether a DPIA is mandatory (likely high risk) and justify in it why blockchain is necessary and proportionate. Design the architecture so that erasure, rectification and objection can be given effect. Establish on the facts who is controller or processor in the network and keep personal data off chain as much as possible.
- under consultationAutoriteit Persoonsgegevens (AP)Conceptlijst DPIA-uitzonderingen, consultatie AP (artikel 35 lid 5 AVG)
Consultation on the draft list of processing operations for which no DPIA is required (Dutch DPA)
On 24 June 2026 the Dutch DPA published a draft list of types of processing for which no DPIA is needed, mainly aimed at SMEs and self employed entrepreneurs. Comments were possible until 10 August 2026; the consultation is closed. The DPA will publish a summary of the responses, submit the revised list to the EDPB and adopt the final list after that opinion, after which it will be published in the Government Gazette and on the DPA website and take effect.
What this means: Until final publication nothing changes: you still assess yourself whether a DPIA is needed. The draft covers professionals, self employed persons and employers with up to 250 employees in European Netherlands, for among others HR administration, customer data, website visits and solo healthcare providers, each under conditions. Once adopted you may skip the DPIA for those operations, but all other GDPR obligations and DPIA duties under other legislation continue to apply. Watch the Government Gazette and the DPA website for the final list.
Art. 35Autoriteit Persoonsgegevens, nieuwsbericht en consultatiedocumentchecked on 15 September 2026 - adoptedEuropean Data Protection Board (EDPB)EDPB Template for personal data breach notification v1.0
EDPB Template for personal data breach notification
At its June 2026 plenary the EDPB adopted a common data breach notification template (announced on 10 June 2026). The template is mainly meant for supervisory authorities to build into their IT systems. It asks for certain information only when needed, offers predefined values and recommended tooltips, and makes sure notifications contain the information Article 33 GDPR requires. The public consultation ran from 10 June to 5 August 2026 and is closed. After the consultation the EDPB will decide on the timeline for practical implementation by all supervisory authorities.
What this means: You can already set up your internal breach register around the fields of the template, so a future notification to the Dutch DPA goes faster. Until implementation the current DPA notification form continues to apply. Watch the EDPB and the Dutch DPA for the implementation decision.
- adoptedEuropean Data Protection Board (EDPB)Guidelines 1/2026, versie voor publieke consultatie
Guidelines 1/2026 on processing of personal data for scientific research purposes
Adopted on 15 April 2026 as a version for public consultation. The consultation ran from 16 April to 25 June 2026 and is closed. The guidelines give six key indicative factors to determine whether processing is scientific research within the meaning of the GDPR. Research that meets all six is presumed to be scientific research. If it does not, the controller must justify why it still qualifies. They also cover principles (purpose limitation, storage limitation), legal bases, information obligations, data subject rights, roles (controller, processor, joint controllers) and Article 89(1) safeguards. Examples include AI research. No final version was seen on 15 September 2026.
What this means: If you do research with personal data you must be able to substantiate that it is real scientific research before using the Article 89 relaxations. You record the legal basis, the safeguards and the division of roles with partners. Until the final version this remains a draft framework.
- under consultationEuropean Data Protection Board (EDPB)EDPB Template [2026] for DPIA, versie 1.0 met explainer (aangenomen 10 maart 2026 voor publieke consultatie)
EDPB Template for Data Protection Impact Assessment
On 10 March 2026 the EDPB adopted version 1.0 of a common DPIA template with an explainer for public consultation. It was published on 14 April 2026, in line with the Helsinki statement to make GDPR compliance easier and more consistent. The consultation ran from 14 April to 9 June 2026 and is closed. After finalisation all national supervisory authorities will take steps to adopt the template as their sole template or as a meta-template to which national templates align. Use is not mandatory. As of 15 September 2026 no final version has been published.
What this means: You can already compare your DPIA format with the EDPB template, so you can later align with what the Dutch DPA will use without rework. The template has a fixed structure: overview of the processing, systematic description, analysis (legal basis, minimisation, retention and measures), necessity and proportionality, risk assessment with an action plan, involvement of the DPO and data subjects, and conclusion. The final version and the date supervisory authorities will implement it are not yet known.
- under consultationAutoriteit PersoonsgegevensConsultatieversie Handhavingsbeleid AP, april 2026 (reacties tot en met 17 mei 2026)
Consultation on the Dutch DPA's enforcement policy (April 2026)
On 13 April 2026 the Dutch DPA put a draft enforcement policy out for consultation. It sets out the principles: a duty to act against ongoing breaches, effect oriented action, openness to talks on ending a breach, and keeping the offender, the DPO and the complainant informed. It also sets out the tools: reprimand, making a commitment binding (under the DSA only), a plain order, an order subject to a penalty payment and an order enforced by administrative action, withdrawal of GDPR certification, processing restriction and ban, administrative fine and closing letter. On top of that come formal preventive tools: a temporary restriction or ban during an investigation, a formal warning on intended processing, and an order to prevent repetition or a preventive order. The draft also covers settlement in dialogue with a fine reduction of up to 35 percent, and a 5 percent fine discount for each full half year past the decision deadline (capped at 5,000 euros per half year). Responses were accepted until 17 May 2026. The consultation is closed and the DPA will publish a summary of the responses.
What this means: A party that admits a GDPR breach, waives objection and appeal, agrees to publication of the fine decision and compensates data subjects can settle the procedure in dialogue. The fine is then reduced by up to 35 percent. There is no right to such a settlement. A binding commitment instead of a fine or penalty order is only available under the DSA, not the GDPR. Keep your DPO involved, since the DPA sends the DPO copies of key documents. Also expect more than fines, such as a temporary processing ban during an investigation or a preventive order. The policy has not yet been finalised.
Art. 58Art. 83Autoriteit Persoonsgegevens, Consultatie handhavingsbeleid AP (met consultatieversie PDF)checked on 15 September 2026 - finalEuropees Economisch en Sociaal ComitéEESC-2025-03929 (CELEX 52025AE3929, PB C, C/2026/3225)
European Economic and Social Committee adopts opinion on the Digital Omnibus
On 18 March 2026, at plenary session 604, the EESC unanimously (194 for, 0 against, 0 abstentions) adopted a single opinion on both Digital Omnibus proposals: COM(2025) 837 (including amendments to the GDPR) and COM(2025) 836 (Digital Omnibus on AI). Rapporteur was Heiko Willems, co-rapporteur Angelo Pagliara. The opinion was published in the Official Journal on 2 July 2026 (C/2026/3225). It is an advisory step in ordinary legislative procedure 2025/0360(COD), which is still ongoing.
What this means: No direct consequence for you. The opinion is not binding and the GDPR remains unchanged until the proposal is adopted.
EUR-Lex, EESC-advies CELEX 52025AE3929 en procedurepagina 2025/0360(COD)checked on 15 September 2026 - finalEuropese Centrale BankCON/2026/9 (CELEX 52026AB0009)
European Central Bank issues opinion on the Digital Omnibus
On 10 March 2026, at the request of the European Parliament (9 December 2025), the ECB issued an opinion on the Digital Omnibus proposal COM(2025)837. The ECB broadly supports the proposal. It asks for a clearer definition of 'public emergency' for access to private data. It also wants joint controllers to be able to submit a single breach notification through the new single entry point. Finally, it opposes bringing DORA incident reporting into that single entry point.
What this means: This opinion has no direct legal consequence for controllers or processors. It is a non-binding step in the legislative procedure. The ECB proposal for a single joint breach notification by joint controllers may still shape the final text.
EUR-Lex, ECB-advies CON/2026/9 (CELEX 52026AB0009)checked on 15 September 2026 - finalEuropean Data Protection Board en European Data Protection SupervisorEDPB-EDPS Joint Opinion 2/2026 (over COM(2025) 837)
EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus
The Joint Opinion was adopted on 10 February 2026 and published on 11 February 2026. The EDPB and EDPS support simplification but strongly urge the co-legislators not to adopt the change to the definition of personal data. They also consider that an implementing act should not determine when pseudonymised data is no longer personal data. They welcome the research definition, the exception for biometric authentication under the individual's sole control, the higher breach notification threshold and longer deadline, and common templates and DPIA lists, provided the EDPB prepares and approves them itself. They consider a specific provision on legitimate interest for AI (Article 88c) unnecessary. They want to keep the Article 22 prohibition in principle and want abuse of the right of access tied to abusive intent. On cookies they strongly support the aim and suggest an exception for contextual advertising.
What this means: The opinion is not binding, but it carries significant weight in the legislative negotiations. Expect the definition change and the Article 22 relaxation to be uncertain, while the breach and DPIA simplifications have the supervisors' support. Your current obligations are unchanged.
- finalAutoriteit PersoonsgegevensPosition paper AP: Omnibus Digitaal en Omnibus AI (januari 2026)
Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
The AP supports simplification but finds that the omnibus proposals do not strike the right balance with protection, and calls on the legislator to look at them critically. It wants the definition of personal data kept as it is, since uncertainty weakens both protection and supervision. Less transparency and accountability means less effective supervision: the AP wants to keep the current threshold for notifying data breaches. The AI literacy obligation should stay with organisations. Many proposals, such as limiting the right of access for excessive requests and explicitly naming legitimate interest for AI, are in the AP's view so vaguely worded that they do not solve the problems. Positive elements include EU level templates for DPIAs and breach notifications and harmonised cookie rules. The AP announces a joint analysis with the other European data protection authorities.
What this means: This is the position of your Dutch supervisory authority, not a new rule. The proposals have not been adopted, so the current GDPR still applies: notify data breaches under the current threshold, handle access requests under the current rules and still carry out your own balancing test when relying on legitimate interest for AI. Expect a strict stance from the AP if the definition of personal data or the notification duty is relaxed after all.
- adoptedEuropean Data Protection Board (EDPB)Guidelines 01/2025, versie voor publieke consultatie
Guidelines 01/2025 on Pseudonymisation
The EDPB explains what pseudonymisation is, that pseudonymised data remain personal data and how pseudonymisation helps with security, data protection by design and the balancing test for legitimate interest. The annex contains ten worked examples. Adopted on 16 January 2025 as a version for consultation (consultation from 17 January to 14 March 2025). On 15 September 2026 the EDPB site shows no final version.
What this means: You must keep the key or additional information separately and securely and record who can access it. Pseudonymisation is a measure you can rely on in a DPIA and a balancing test, but the GDPR continues to apply in full. In processing agreements you can agree that the processor only receives pseudonymised data.
- finalEuropean Data Protection Board (EDPB)Opinion 28/2024 (artikel 64 lid 2 AVG)
Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
At the request of the Irish supervisory authority the EDPB answers three questions: when an AI model is anonymous, whether legitimate interest can be a legal basis for developing and using AI models, and what the consequences are when a model was developed with unlawfully processed personal data. Anonymity must be assessed case by case; the likelihood of extracting personal data from the model or obtaining it through queries must be insignificant. On legitimate interest the opinion builds on Guidelines 1/2024 and recalls the three step test. The opinion was adopted on 17 December 2024 and published on 18 December 2024.
What this means: If you develop or buy an AI model you must be able to show documentation about the training data, the legal basis and the measures against extraction of personal data. Relying on legitimate interest requires a documented balancing test for both training and deployment. When buying a third party model you must carry out an appropriate assessment of whether it was lawfully developed.
- adoptedEuropean Data Protection Board (EDPB)Guidelines 1/2024, versie 1.0 (consultatie 10/2024)
Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR (legitimate interest)
The EDPB describes three cumulative conditions for relying on legitimate interest: a lawful, clearly articulated and present interest, necessity of the processing, and a balancing test in which the data subject's rights do not override that interest. The controller must assess and document this before processing starts. The text takes account of CJEU judgment C-621/22 (KNLTB, 4 October 2024) and covers fraud prevention, direct marketing and network and information security. Version 1.0 was adopted on 8 October 2024 for public consultation, which ran from 9 October to 20 November 2024. As of 15 September 2026 the EDPB has published only version 1.0; there is no final version yet.
What this means: You document a balancing test (LIA) per processing operation before you start and can demonstrate it. You review the test when the purpose or scope of the processing changes, and you inform data subjects of the interest pursued. For direct marketing, objecting must always be easy and free of charge (Article 21(2)) and an objection always wins. For other processing, such as fraud prevention, the general right to object of Article 21(1) applies, and you must show compelling legitimate grounds to continue.
- finalEuropean Data Protection Board (EDPB)Guidelines 9/2022, versie 2.0
Guidelines 9/2022 on personal data breach notification under GDPR
These guidelines are a slightly updated version of WP250 rev.01 of the Article 29 Working Party. References to WP250 are now to be read as references to Guidelines 9/2022. They describe when a breach must be notified, the 72 hour deadline and communication to data subjects. Version 1.0 was adopted on 10 October 2022 for a targeted consultation. Version 2.0, adopted on 28 March 2023 and published on 4 April 2023, clarifies the following: merely having a representative in the EU does not trigger the one-stop-shop. A controller not established in the EU must therefore notify every supervisory authority of a Member State where affected data subjects reside.
What this means: You must have a procedure to detect, assess and notify a breach within 72 hours of becoming aware of it. Processors must inform you without undue delay; put that in the processing agreement. If a high risk is likely you also inform the data subjects themselves. If you are not established in the EU, do not rely on a single lead authority: notify every relevant national supervisory authority.
- finalEuropean Data Protection Board (EDPB)Guidelines 05/2021, versie 2.0
Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR
The EDPB explains when there is a transfer under Chapter V, using three cumulative criteria: a controller or processor is subject to the GDPR for the processing, makes personal data available to another controller or processor, and that importer is in a third country or is an international organisation. Direct disclosure by a data subject is not a transfer. Version 2.0 was adopted on 14 February 2023 after public consultation and is final; version 1.0 dates from 18 November 2021.
What this means: You first determine whether a data flow is a transfer before using standard contractual clauses or a TIA. Disclosure within a group, for example from an EU subsidiary to a parent company outside the EEA, also counts as a transfer. Remote access by a processor in a third country is a transfer, but an own employee logging in remotely during a business trip is not, because the data stay within the same controller.
- finalEuropean Data Protection Board (EDPB)Guidelines 01/2021 (version 2.0)
Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
These guidelines give eighteen practical examples of data breaches, such as ransomware, data exfiltration by attackers, internal human error, lost or stolen devices and misdirected mail. For each example they state whether you must notify the supervisory authority, whether you must inform data subjects and which measures are appropriate. The EDPB adopted version 2.0 after public consultation on 14 December 2021 and published it on 3 January 2022.
What this means: You can compare your own breach with the examples to decide whether you must notify within 72 hours. You must record every breach internally, even when you do not notify. The examples show which precautions, such as encryption and backups, can avoid a notification.
- finalEuropean Data Protection Board (EDPB)Guidelines 07/2020, versie 2.0 (aangenomen 7 juli 2021), huidige versie 2.1 (20 september 2022, kleine correcties)
Guidelines 07/2020 on the concepts of controller and processor in the GDPR
The EDPB explains how to determine who is controller, joint controller or processor, and what a processing agreement must contain. The guidelines replace WP169 and also address sub-processors and instructions. Final version 2.0 was adopted after public consultation on 7 July 2021. Version 2.1 of 20 September 2022 contains only minor corrections.
What this means: You determine the role by who decides the purposes and means, not by what the contract says. A processing agreement must not merely restate the GDPR but must fill in the elements of Article 28(3) concretely. For joint controllership you must make an arrangement under Article 26 and make its essence available to data subjects, for example in the privacy notice or on request.
Art. 4Art. 26Art. 28Art. 29EDPB guideline page and final PDF (version 2.1)checked on 15 September 2026 - finalEuropean Data Protection Board (EDPB)Recommendations 01/2020, versie 2.0
Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data
After the Schrems II judgment the EDPB describes in six steps how to assess a transfer to a third country: map transfers, choose a tool, assess the law and practice of the third country, choose supplementary measures, take formal steps and re-assess periodically. Version 2.0 adopted on 18 June 2021, final.
What this means: For transfers outside the EEA based on an Article 46 tool (such as standard contractual clauses or BCRs) you must assess and document whether the law and practice of the third country undermine the protection; in practice this is called a Transfer Impact Assessment. If the country does not offer enough protection, you choose supplementary measures, such as encryption with the key kept under your control in the EEA, or you stop the transfer. You repeat the assessment when the law or practice changes.
- finalEuropean Data Protection Board (EDPB)Guidelines 4/2019, versie 2.0
Guidelines 4/2019 on Article 25 Data Protection by Design and by Default
The EDPB explains what data protection by design and by default mean in practice: technical and organisational measures that build in the Article 5 principles. The text gives examples per principle. Version 2.0 was adopted on 20 October 2020 after consultation and is final.
What this means: You must decide at the design stage how you safeguard the principles and be able to demonstrate it. Default settings must process as little data as possible. When buying software it is wise to ask the supplier how it supports this, because you remain responsible as controller.
- finalEuropean Data Protection Board (EDPB)Guidelines 05/2020 (version 1.1)
Guidelines 05/2020 on consent under Regulation 2016/679
These guidelines are a slightly updated version of the WP29 guidelines on consent (WP259 rev.01); references to WP259 are now read as references to this document. They explain when consent is valid: freely given, specific, informed and unambiguous. Only the passages on cookie walls and on scrolling were revised: making access conditional on consent to cookies (cookie wall) does not produce free consent, and scrolling or swiping is not an unambiguous indication of consent. Adopted on 4 May 2020; version 1.1 of 13 May 2020 only contains formatting corrections.
What this means: You may not make access to a service conditional on consent to processing that is not necessary for that service (Article 7(4)), and cookie walls are not allowed. A competitor offering a similar service without consent does not make your consent freely given. You must ask consent per purpose, be able to demonstrate it and make withdrawal as easy as giving it. Pre-ticked boxes, silence and scrolling do not count as consent.
- in forceAutoriteit Persoonsgegevens (AP)Staatscourant 2019, nr. 64418
Decision on the list of processing operations for which a DPIA is mandatory (Dutch DPA)
Under Article 35(4) GDPR, read with Article 57(1)(k), the Dutch DPA adopted a list of 17 types of processing for which you must carry out a DPIA in advance, such as covert investigation, blacklists, fraud prevention, credit scores, financial situation, genetic data, health data, cooperation partnerships, camera surveillance, employee monitoring, location data, communication data, internet of things, profiling, observing and influencing behaviour and biometric data. Through the consistency mechanism with the EDPB, biometrics was added. The decision was signed on 19 November 2019 and published in the Government Gazette of 27 November 2019. The list is not exhaustive: if your processing is not on it, a DPIA may still be required when the processing is likely to result in a high risk.
What this means: If your processing is on the list, the starting point is that you carry out a DPIA before you begin processing. Each category states which criteria from the EDPB guidelines (WP248 rev.01) the Dutch DPA took into account, which helps you substantiate your assessment. If the processing is not on the list, you assess yourself using the nine criteria of WP248 rev.01 whether a high risk is likely.
Art. 35Art. 57Art. 63Autoriteit Persoonsgegevens, documentpagina met Staatscourant PDF (stcrt-2019-64418)checked on 15 September 2026 - finalArticle 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)WP248 rev.01 (Endorsement 1/2018)
Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is likely to result in a high risk
These guidelines of the former Article 29 Working Party explain when a DPIA is required. They list nine criteria for high risk, such as scoring, systematic monitoring, sensitive data, large scale and new technology. In most cases processing that meets two criteria requires a DPIA. The EDPB endorsed the text on 25 May 2018 (Endorsement 1/2018); it was adopted on 4 April 2017 and last revised on 4 October 2017.
What this means: You test every new processing operation against the nine criteria. If criteria are met but you do not carry out a DPIA, you justify and document the reasons. A DPIA must contain the minimum content of Article 35(7): description, necessity, risks and measures. If a high residual risk remains you must consult the supervisory authority first (Article 36(1)).
- finalArticle 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)WP260 rev.01 (Endorsement 1/2018)
Guidelines on transparency under Regulation 2016/679
These guidelines describe how to inform data subjects: in plain language, easy to find and on time. They contain a table with all mandatory elements of a privacy notice and advice on layered information. First adopted on 29 November 2017, last revised on 11 April 2018 and endorsed by the EDPB on 25 May 2018.
What this means: Your privacy notice must contain all elements of Articles 13 and 14 and be written in plain language. For data not obtained from the data subject you must inform within a reasonable period and at the latest within one month, or earlier at first communication or disclosure to another recipient. If you change purposes you must inform again in advance.
- finalArticle 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)WP251 rev.01 (Endorsement 1/2018)
Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679
These guidelines explain what profiling is and when the Article 22 prohibition applies. That prohibition covers decisions taken solely by automated means that have legal effects or similarly significant effects. The guidelines describe the exceptions, the safeguards and the duty to inform about the underlying logic. They were adopted on 3 October 2017 and last revised on 6 February 2018. The EDPB endorsed them on 25 May 2018 (Endorsement 1/2018).
What this means: If you use an algorithm or AI to make decisions about people, you must check whether a human is really involved. Without that involvement the prohibition applies. This is different if an exception applies and you provide safeguards, such as the right to review by a human. You must explain the logic behind the decision and its consequences.