Source: EDPB
The European Data Protection Board (EDPB) has adopted its work programme for 2026-2027, with a clear focus on making GDPR compliance simpler for organisations. The announcement was published on 13 February 2026 on the official EDPB website.
According to the EDPB, easing compliance is a top priority for the coming two years. A key part of this plan is the development of ready-to-use templates that organisations can use to meet their GDPR obligations.
The EDPB says it will develop templates for:
These are in addition to templates for data breach notifications and data protection impact assessments, which the EDPB had already announced previously.
The idea is straightforward: instead of building these documents from scratch, organisations will eventually be able to work from a standardised starting point provided by the EDPB itself.
According to the EDPB, the work programme builds on commitments made in the Helsinki Statement, which focused on making GDPR compliance easier, strengthening consistency and improving cooperation across regulatory areas. Simplifying compliance for organisations is described as a central goal of the EDPB's broader strategy for 2024-2027.
No specific deadlines for delivering the templates have been stated at this point.
If you are still working on getting your privacy policy, processing records or legitimate interest assessments in order, these upcoming templates could make that process more manageable. In the meantime, it is worth reviewing what you already have in place using our GDPR compliance checklist and checking whether your privacy policy meets current requirements. The EDPB's direction of travel is clear: GDPR compliance should be achievable for organisations of all sizes, and practical tools are on the way to help with that.
Free website scan covering GDPR, copyright, accessibility, security, and more.
Start free checkA large Belgian tech company received a total fine of 176,000 euro from the Belgian Data Protection Authority for failing to timely delete the mailbox of a former female employee.
Dutch legal blog Ius Mentis explains that GDPR makes it legally impossible to obtain valid consent for personal data use through terms of service or general conditions, and that Article 7(2) GDPR…
On 19 March 2026, the CJEU ruled in Case C-526/24 (Brillen Rottler) that a data subject's first DSAR can be refused as 'excessive' under Article 12(5) GDPR if the controller can demonstrate abusive…