The European Data Protection Board (EDPB) is seeking a formal legal basis to facilitate the exchange of information between different national regulatory authorities, according to reports from the French data protection agency, CNIL. This move aims to resolve legal uncertainties that currently hinder the seamless sharing of data between regulators when investigating cross-border privacy violations under the General Data Protection Regulation (GDPR).
The request centers on the need for a standardized framework that allows regulators to share evidence and investigative findings without risking legal challenges regarding the validity of the data transfer. Under current protocols, the absence of a dedicated legal mandate for such exchanges can lead to procedural delays or the potential inadmissibility of evidence in court, according to CNIL documentation.
This initiative reflects a broader effort to strengthen the “one-stop-shop” mechanism, which is designed to allow companies operating across the EU to deal with a single lead supervisory authority. However, the effectiveness of this system depends on the ability of that lead authority to coordinate efficiently with “concerned” supervisory authorities in other member states.
The Legal Gap in Regulatory Information Sharing
The core of the issue lies in the tension between the necessity of regulatory cooperation and the strict privacy protections mandated by the General Data Protection Regulation (GDPR). While the GDPR encourages cooperation between supervisory authorities, it does not explicitly detail every legal mechanism required for the transfer of sensitive investigative files between different national jurisdictions.
According to CNIL, the EDPB has identified that relying on general cooperation clauses may not be sufficient to withstand judicial scrutiny in all member states. If a national court determines that information was shared between regulators without a specific legal basis, it could potentially invalidate the resulting fines or sanctions. This creates a systemic risk for the enforcement of EU-wide data laws.
The EDPB is therefore pushing for a more robust legal foundation—potentially through updated guidelines or a formal recommendation—that clearly defines the conditions, limits, and legal justifications for sharing information. This would ensure that when the CNIL in France shares data with the Data Protection Commission (DPC) in Ireland or the BfDI in Germany, the process is legally bulletproof.
Impact on Cross-Border GDPR Enforcement
The push for a legal basis for information sharing directly affects how “Big Tech” companies are regulated within the European Union. Most major technology firms have their European headquarters in Ireland, making the Irish DPC the lead supervisor for a vast number of cases. For the system to work, the DPC must be able to receive and integrate evidence from other national regulators who may have identified local breaches.
Without a clear legal mandate, the exchange of “administrative documents” or “investigative dossiers” can become a bottleneck. This legal uncertainty can lead to prolonged investigation timelines and inconsistent application of penalties across different member states. By establishing a firm legal basis, the EDPB intends to accelerate the resolution of disputes between regulators and shorten the time it takes to reach a final decision on major cases.
This development is closely tied to the EDPB’s ongoing efforts to harmonize the application of the GDPR. The board, which consists of the heads of the national data protection authorities of the EU member states and the European Data Protection Supervisor, acts as the final arbiter in cases where national regulators disagree on how to interpret the law.
Challenges for National Regulators and the CNIL
For agencies like the CNIL, the lack of a clear legal framework for data sharing creates a precarious balance. The CNIL must ensure that its own investigative methods are compliant with French law while simultaneously collaborating with partners whose legal requirements may differ. The risk of “procedural irregularity” is a primary concern for the French regulator.
The EDPB’s goal is to move away from ad-hoc agreements between individual regulators and toward a systemic, EU-wide legal standard. This would likely involve specifying what types of data can be shared, the purpose of the sharing, and the safeguards in place to protect the rights of the data subjects involved in the investigations.
Industry analysts suggest that a more streamlined information-sharing process will likely result in more frequent and higher-value coordinated raids or audits, as regulators will be able to pool their intelligence more effectively without fear of legal reprisal from the companies being investigated.
Timeline for Regulatory Alignment
The EDPB typically addresses these structural issues through the adoption of guidelines or binding decisions. Once a consensus is reached among the member states’ representatives, the resulting framework becomes the standard for all supervisory authorities across the Union.
The next phase of this process involves the drafting of specific criteria for the “legal basis” requested. This will likely include a review of existing national laws in each member state to identify where the gaps are most prominent and how a centralized EDPB recommendation can bridge those divides.
The outcome of these deliberations will be reflected in future EDPB plenary sessions and official guidelines published on the European Data Protection Board’s official portal. These updates will dictate how national regulators handle the transmission of evidence and the coordination of sanctions moving forward.
For further updates on EU regulatory shifts, readers can monitor the official filings and press releases from the CNIL and the EDPB. Share this report with your network to discuss how these legal shifts may impact corporate data compliance in Europe.
Worth a look