The European Data Protection Board

The European Data Protection Board (EDPB) is a European Union’s independent body whose purpose is to ensure consistent application of the General Data Protection Regulation (GDPR) and to promote cooperation among the EU’s data protection authorities.

The EDPB comprises representatives of the EU national data protection authorities (national Supervisory Authorities) and the European Data Protection Supervisor (EDPS).

The EDPB tasks are:

  • issuing guidelines and recommendations,
  • identifying best practices related to the interpretation and application of GDPR,
  • advising the European Commission on matters related to the protection of personal data in the European Economic Area (EEA),
  • adopting opinions to ensure the consistency of application of GDPR by the national supervisory authorities, in particular on decisions having cross-border effects.

Additionally, the EDPB resolves disputes between the federal authorities cooperating on enforcement, encouraging the development of codes of conduct and establishing certification mechanisms in the field of data protection. EDPB’s aim is to promote cooperation and effective exchange of information and good practices among national supervisory authorities.

Read more about data privacy and data protection on the Piwik PRO blog: Data privacy.


  • HIPAA-compliant analytics for healthcare systems: How hospital marketing teams can measure what matters

    Patients now research symptoms, compare providers, and book appointments entirely online before ever contacting a hospital. Healthcare marketers need to adapt to digital-first patient journeys, run campaigns for numerous service lines, manage hospital marketing analytics across multiple locations, and prove ROI to administrators. For nonprofit hospitals, the picture is broader still — donation tracking is…

  • Privacy by design in practice: How “just enough” data beats “just in case” collection

    While collecting more data “just in case” feels safer, according to Matt Gershoff, it’s also one of the biggest sources of unnecessary compliance risk, analytical noise, and wasted organizational resources in the analytics industry today. His approach of “just enough” data collection is more intentional, more aligned with privacy regulation, and often more analytically effective.