Article content
In briefShow moreShow lessThe guidelines discussed what may qualify as scientific research, legal bases, purpose compatibility and special-category data safeguards.
- The guidelines discussed what may qualify as scientific research, legal bases, purpose compatibility and special-category data safeguards.
- They also addressed transparency, data-subject rights and security measures in AI-enabled research.
- They were consultation guidelines interpreting the existing GDPR, not a GDPR amendment.
The EDPB opened a consultation on guidelines for processing personal data in scientific research. The objective was to clarify how the GDPR should be understood when research projects use personal data over time, across institutions or in technically complex environments. The guidelines remained under consultation.
A foundational issue was what qualifies as scientific research. Classification matters because the research framework can affect assessments of purpose, legal basis, further use and certain rights. A project’s actual purpose and method therefore needed to be documented rather than asserted through a research label alone.
The EDPB also addressed legal bases and purpose limitation. Organisations must be able to explain why processing is lawful, how the purpose is specified and whether later use is compatible with the original purpose. This requires alignment between the project description, data sources, access model and planned analysis.
Special-category personal data received specific attention. Researchers and controllers must identify which information falls within those categories, determine what additional condition is required and apply technical and organisational measures that reduce risk. Access should be limited by role and genuine need.
The guidelines further discussed transparency and data-subject rights. Information provided to affected people must reflect the research context without practical difficulty automatically removing the relevant obligations. Where rights are restricted or deferred, the legal basis and safeguards must be explainable and documented.
AI-enabled research can increase the value of datasets while making purpose, model use and risk harder to delimit. Projects should therefore assess training data, model access, re-identification, leakage and control over further use. Security needs to be built into the full research lifecycle, not added only at the storage stage.
For Norway, this was guidance on the existing GDPR, relevant through the EEA. The consultation did not amend the GDPR or replace national research rules, sector-specific requirements or ethical standards. Norwegian organisations could use the draft as an input to assessments, but needed to await the final version and continue applying current law.
Sources
European Data Protection Board: “Clarity on data processing for scientific research,” 16 April 2026.
European Data Protection Board: “Guidelines 1/2026 on scientific research,” 15 April 2026.
For discussion
How can the research organisation document the connection between project purpose, legal basis, AI use, access controls and security safeguards?


