EDPB Guidelines 1/2026: What are “scientific research purposes” in the context of personal data processing?

1 Sep 2026

This policy brief — published as part of the GA4GH Health Data Sharing, Privacy, and Regulatory Forum — discusses the European Data Protection Board’s (EDPB) draft Guidelines and its understanding of “scientific research purposes” when processing personal data, in relation to existing European data regulations.

DNA strand with other scientific graphics in the background

By Mikel Recuero, University of the Basque Country

This policy brief focuses on discerning what the European Data Protection Board’s (EDPB) draft Guidelines understand by “scientific research purposes” in the context of the processing of personal data. Furthermore, we briefly refer to the complex legal interplay between these Guidelines, the EU’s General Data Protection Regulation’s (GDPR) underlying approach, and the Regulation 2025/327 on the European Health Data Space (EHDS).

The GDPR contains a set of provisions specifically applicable to the processing of personal data for scientific research purposes. These provisions include inter alia, adaptations in the application of some basic data protection principles (such as purpose or storage limitations), exceptions to some data subjects’ rights (such as right to erasure), a possibility of granting broad consent (Recital 33), or even a specific condition for the processing of special categories of personal data when the processing is necessary for the pursuit of scientific research (Article 9(2)(j)). The provisions aim to strike a fair balance between the fundamental right to data protection and other fundamental rights and interests, including the freedom of the arts and sciences (Art. 13 of the EU Charter of Fundamental Rights), the broader societal and public interest in scientific advancement (Recital 157 GDPR), and even, as some authors argue, the international human right to science¹. To this end, a trade-off is introduced via the adoption of appropriate safeguards pursuant to Article 89(1) GDPR.

Accordingly, data controllers may have access to this “privileged” regime under the GDPR, provided that they can substantiate and demonstrate that the purpose of their personal data processing is to carry out scientific research. However, despite the important role given to scientific research in the Regulation, orientations and guidance have been rather limited. 

On 15 April 2026, the European Data Protection Board (EDPB) adopted the Guidelines 1/2026 on processing of personal data for scientific research purposes. These Guidelines provide the genomics and health community with a valuable resource and referential point, but they also give rise to a number of issues and lead to complex legal interactions. 

Determining when processing is undertaken for scientific research purposes

In an attempt to shed some light, while conceding there is no universally agreed definition, the EDPB builds on the concise notes set out in the GDPR’s recitals 157 and 159 to further develop six key-indicative factors for determining whether processing of personal data is motivated by scientific research purposes. These factors function as a cumulative rebuttable presumption: where all are satisfied, the controller may presume that the processing constitutes scientific research within the meaning of the GDPR, and no further justification is required. Nevertheless, where one or more factors are absent, the presumption does not automatically operate but the burden shifts to the controller, who must be able to justify and document why the processing should nonetheless be regarded as scientific research. 

According to the EDPB, the six key-indicative factors of the test are as follows:

  • Methodological and systematic approach. Research activities are conducted following a methodological and systematic approach consistent with the relevant field, whether through a comprehensive research plan with testable hypotheses or, for exploratory work, at minimum a clearly stated objective.
  • Adherence to ethical standards. Research activities comply with the ethical standards of the relevant discipline, encompassing respect for human autonomy, informed consent to participate in research, transparency, accountability, and oversight.
  • Verifiability and transparency. Research activities aim to achieve verifiable results and are open to scrutiny (e.g. through peer review and publication) while acknowledging legitimate limitations such as protection of intellectual property and trade secrets.
  • Autonomy and independence. Research activities are conducted free from undue external or internal pressures, with the research team retaining freedom over research questions, methods, theories, and publication or dissemination channels. In addition, researchers hold academic qualifications (e.g. a PhD) or demonstrated scientific credentials in the relevant field, or work under the supervision of qualified researchers.
  • Objectives of the research. Research activities contribute to the growth of society’s general knowledge and wellbeing, though this does not preclude the concurrent pursuit of commercial interests.
  • Potential to contribute to existing scientific knowledge. Research activities are scientifically meritorious, meaning they have the potential to advance existing knowledge or apply it in novel ways, ideally subject to independent expert assessment.

In operational terms, this means data controllers will need to conduct a self-assessment against the above-described six factors before processing personal data. It follows that the rationale behind this test is not to confer the status of genuine scientific research to certain projects, hypotheses, or research endeavours, but merely to delineate which personal data processing activities that are motivated by such purposes are eligible for greater regulatory flexibility. 

How is this consistent with the current approach and letter of the GDPR?

It is worth considering to what extent the EDPB’s position sits comfortably with the current wording of the GDPR and, notably, with the European Commission’s declared goal of fostering research and innovation in the EU². The GDPR deliberately refrains from defining scientific research in a restrictive manner: recital 159 states that scientific research shall be interpreted in a “broad manner.” However, the EDPB’s six-factor test introduces a degree of normative specificity that sits uncomfortably with this legislative choice. 

One particular point of criticism has been the EDPB’s excessive focus on academic and institutional research, leading to a situation where science is almost equated with established institutional habits or practices of academia. The autonomy and independence factor introduces a requirement for academic qualifications or credentials (e.g. holding a PhD), which risks excluding legitimate research carried out by skilled professionals in industry settings who may lack formal academic titles, and could exclude activities carried out by start-ups, SMEs, or citizen-science initiatives that are not run by professional scientists. Furthermore, applying all these factors together would appear to narrow down the scope of what constitutes scientific research beyond what the GDPR originally intended. As a result, novel, interdisciplinary research that does not yet exhibit all the hallmarks of mature research endeavours could be excluded from the privileged regime; thereby impacting not only the original scope of the GDPR, but also the essence of freedom of science. 

This does not offer a promising scenario for genomic and health data sharing collaborations, as public-private partnerships and consortium-based science are increasingly becoming the global standard, while AI is reconfiguring how and by whom scientific research is carried out.

Secondary use of personal electronic health data in the EHDS framework

At a first glance, it would appear that the EHDS sets a higher threshold, especially since access to personal electronic health data under its infrastructure would be subject to stronger protections and safeguards (including technical measures, secure processing environments, and governance mechanisms) than those provided for in the EDPB’s test. Yet, many research, development, and innovation activities may still not satisfy the EDPB’s requirements, which creates an actual risk of contradictory compliance obligations. 

The new EHDS Regulation is likely to transform the secondary use of electronic health data (both personal and non-personal) for scientific research purposes over the next decade. As for the secondary uses that are expressly permitted, Article 53(1)(e) of the EHDS refers specifically to “scientific research related to health or care sectors”. Recital 61 clarifies, in line with the GDPR, that “the notion of scientific research purposes should be interpreted in a broad manner”. In contrast to the GDPR, however, the EHDS does provide a greater level of detail in terms of what constitutes scientific research in the context of secondary uses. 

On the one hand, this far-reaching claim is followed by an illustrative list of purposes that would fall within the scope of permitted secondary use, including, in particular: “(i) development and innovation activities for products or services” and “(ii) training, testing and evaluation of algorithms, including in medical devices, in vitro diagnostic medical devices, AI systems and digital health applications.” On the other hand, the EHDS places a sectoral restraint on the fields in which research is conducted within the EHDS (“related to health or care sector”), while also imposing several conditions of general interest on the concerned research activities. In particular, the latter translates into an obligation, pursuant to Article 67(2)(c) of the EHDS to demonstrate to Health Data Access Bodies (HDABs) what the expected benefits are and to what extent they can contribute to society or to end users (i.e. patients, health professionals, and health administrators).

Consequently, tensions resulting from a strict application of the EDPB’s six-factor test and the EHDS framework for the secondary use of personal electronic health data deserve careful examination. 

 

Mikel Recuero is Privacy & Data Governance Counsel and postdoctoral researcher at the University of the Basque Country.

 

Footnotes

  1. Molnár-Gábor, F. Implementing the human right to science in the context of health-related data processing. Journal of Law and the Biosciences 11(1), 2024. DOI: 10.1093/jlb/lsae004
  2.  As expressed, in particular, through the adoption of the European Strategy on Research and Technology Infrastructures (COM/2025/497 final) and the Strategy for European Life Sciences (COM/2025/525 final). 

Further reading

  • Becker R., Dove. E. S. The EU GDPR and secondary use of health and genetic data for research support purposes. International Data Privacy Law, 16(2). DOI: 10.1093/idpl/ipag001
  • Bentzen H. In the Name of Scientific Advancement: How to Assess What Constitutes ‘Scientific Research’ in the GDPR to Protect Data Subjects and Democracy. In: Terzis G, Kloza D, Kużelewska E, Trottier D, eds. Disinformation and Digital Media as a Challenge for Democracy. European Integration and Democracy Series. Intersentia, 2020:341-366. DOI: 10.1017/9781839700422.020.
  • European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS). Joint Opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (Digital Omnibus). Adopted on 10 February 2026. https://www.edps.europa.eu/system/files/2026-02/edpb_edps_jointopinion_202602_digitalomnibus_en.pdf 
  • European Data Protection Board (EDPB). Guidelines 1/2026 on processing of personal data for scientific research purposes. Adopted on 15 April 2026. https://www.edpb.europa.eu/our-work-tools/documents/public-consultations/2026/guidelines-12026-processing-personal-data_en 
  • European Data Protection Supervisor (EDPS). Preliminary Opinion on data protection and scientific research. Adopted on 6 January 2020. https://www.edps.europa.eu/data-protection/our-work/publications/opinions/preliminary-opinion-data-protection-and-scientific_en 
  • Molnár-Gábor, F. Implementing the human right to science in the context of health-related data processing. Journal of Law and the Biosciences 11(1), 2024. DOI: 10.1093/jlb/lsae004
  • Slokenberga, S. Scientific research regime 2.0? Transformations of the research regime and the protection of the data subject that the proposed EHDS regulation promises to bring along. Technology and Regulation, 2022:135-147. DOI 10.71265/h27r4829

Relevant GDPR provisions

  • Recital 157 – Information from registries and scientific research.
  • Recital 159 – Processing for scientific research purposes.

Relevant EHDS provisions

  • Recital 61 – Concept and scope of scientific research.
  • Article 53(1)(e) – Scientific research related to health or care sectors.
  • Article 67(2)(c) – Detailed explanation of the expected benefits.

Latest News

DNA strand with other scientific graphics in the background
Policy Briefs
1 Sep 2026
EDPB Guidelines 1/2026: What are “scientific research purposes” in the context of personal data processing?
See more
Image of globe with numbers in front of it
Products in Action
4 Aug 2026
Greater Bay Area Bioinformatics Center leverages GA4GH standards to navigate data sovereignty and advance genomic research in China
See more
Products in Action
21 Jul 2026
GA4GH Product in Action: Individual-Centric Genomics Platform JPN
See more