If you’ve ever wondered why most large GDPR fines come out of Ireland or Luxembourg — even when the company in question annoyed users in twenty other countries — the answer involves the EDPB. If you’ve seen “EDPB” mentioned in news about a Meta or Amazon fine, in a privacy policy, or in a letter from your own national data-protection authority (a DPA), this is a profile of the body. Every fact is sourced.
Quick facts
- Full name: European Data Protection Board (EDPB)
- Established: 25 May 2018, by Article 68 of the GDPR
- Predecessor: the Article 29 Working Party (late 1990s–2018), which operated under the old Data Protection Directive 95/46/EC
- Legal status: independent EU body with legal personality
- Membership: the heads of all national supervisory authorities (DPAs) of the European Economic Area + the European Data Protection Supervisor (EDPS)
- Chair: Anu Talus, head of the Finnish DPA — elected 25 May 2023 for a five-year term
- Deputy Chairs: Zdravko Vukić (Croatian DPA, elected 19 June 2024 — replaced Aleid Wolfsen) and Jelena Virant Burnik (Slovenian DPA, elected 4 December 2025 — replaced Irene Loizidou Nikolaidou, who had vacated the role after stepping down as Cyprus Commissioner)
- Term: five years, renewable once (Article 73 GDPR)
- Headquarters: Brussels (Secretariat provided by the EDPS)
- Website: edpb.europa.eu
What “EDPB” actually stands for
EDPB stands for European Data Protection Board. It is the EU-level body that coordinates the work of all 30 national data protection authorities (DPAs — the per-country regulators that enforce GDPR; in France it’s CNIL, in Italy it’s Garante, in Estonia it’s AKI, in Finland it’s Tietosuojavaltuutettu, etc.) of the European Economic Area — the 27 EU Member States plus Iceland, Liechtenstein and Norway — and ensures that GDPR is applied consistently across borders.
It is not itself a national regulator. It does not investigate complaints from individuals, does not run audits of companies, and (with one important exception — see below) does not issue fines. The fines you read about — €390 million against Meta, €746 million against Amazon (later annulled in full by Luxembourg’s Cour administrative — the country’s appeal-level administrative court — on 12 March 2026 and remitted back to the CNPD), €290 million against Uber — are issued by national DPAs (Ireland’s DPC, Luxembourg’s CNPD, the Dutch AP). The EDPB sits one layer above them: it breaks ties when DPAs disagree, issues common GDPR guidelines that all 30 follow, and represents the EU position in international privacy matters.
What EDPB actually does
The EDPB’s tasks are listed in Article 70 GDPR. The practical headline functions:
1. Issue guidelines and recommendations
The EDPB publishes interpretive guidelines on how GDPR applies to specific situations: cookies, international data transfers after the Schrems II ruling (the 2020 CJEU judgment that struck down the EU–US Privacy Shield and tightened the rules for sending personal data to the US), dark patterns in cookie banners, AI training data, biometric data in workplaces, the role of Data Protection Officers (DPOs — internal compliance leads that GDPR requires for many organisations), and so on. These are not binding statutes, but every DPA across the EEA references them — so in practice they shape compliance expectations across 30 jurisdictions.
2. Run the consistency mechanism
When a national DPA wants to take a major regulatory action with cross-border effect — approving an industry code of conduct (a sector-specific compliance standard that companies can adopt voluntarily), accrediting a certification body (an independent organisation that audits companies for GDPR compliance), or deciding on standard contractual clauses (template contracts the EU pre-approves for moving personal data across borders) — the EDPB issues an opinion to ensure consistency before the national DPA acts.
3. Take binding decisions in cross-border disputes
This is the EDPB’s hardest power. Under Article 65 GDPR, if national DPAs cannot agree on the outcome of a cross-border case — typically when the lead supervisory authority (where the controller is headquartered) takes a softer line than other concerned DPAs want — the EDPB takes a binding decision that overrides the disagreement.
This is how the very large fines against Meta, WhatsApp and TikTok ended up at the levels they did: the Irish DPC initially proposed lower fines, other concerned DPAs objected, the EDPB stepped in via Article 65, and the final fine was significantly higher than what Ireland alone would have imposed.
4. Represent the EU on data protection internationally
The EDPB issues opinions on adequacy decisions — formal Commission rulings that a non-EU country has a strong enough data-protection regime to receive personal data from the EU without extra safeguards. The current most-discussed example is the EU–US Data Privacy Framework (the post-Schrems II replacement that, again, allows personal data to flow from the EU to the US under certain conditions). The EDPB also engages with non-EU regulators and signs joint declarations with bodies such as the Global Privacy Assembly (a network of about 130 data-protection regulators worldwide).
The one-stop-shop mechanism
The “one-stop-shop” is the EDPB’s most-cited feature in practice — and the most misunderstood. Here is how it works.
The problem it solves. A pan-EU company (say, Meta) has users in all 27 Member States. Without a coordination rule, theoretically each of the 27 national DPAs could investigate, demand documents and impose fines for the same conduct. That would be unworkable.
The mechanism. Article 56 GDPR designates a lead supervisory authority (LSA) for any controller with cross-border processing — typically the DPA of the country where the company has its “main establishment” (its EU HQ). All cross-border complaints route to the LSA. Other DPAs whose residents are affected become concerned supervisory authorities (CSAs) and have a say in the case, but the LSA drives the investigation.
Where EDPB comes in. When the LSA prepares a draft decision, all CSAs review it. If any CSA raises a “relevant and reasoned objection” and the LSA does not agree, the dispute lands at the EDPB, which takes a binding decision under Article 65 GDPR. That binding decision tells the LSA what to do — including, often, to raise the fine.
Why it matters. This is why most large GDPR enforcement against US tech companies happens through the Irish DPC (Meta, Google, Apple, TikTok, X are all headquartered in Ireland for EU purposes) and the Luxembourg CNPD (Amazon). It is also why those fines are sometimes announced with phrases like “following the EDPB’s binding decision under Article 65” — that language signals other DPAs disagreed with the LSA and EDPB sided against the LSA.
Composition and how decisions are made
The EDPB consists of:
- one representative from each national DPA of the 27 EU Member States,
- representatives from the EEA states (Iceland, Liechtenstein, Norway),
- the European Data Protection Supervisor (EDPS) — a separate body that supervises EU institutions themselves.
Decisions are taken by simple majority, except for binding decisions under Article 65 GDPR (the cross-border tie-breaks), which require a two-thirds majority in most cases and a simple majority on second reading.
The Board meets in plenary roughly once a month in Brussels.
Leadership
The Chair is elected by the Board members from among themselves for a five-year term, renewable once (Article 73 GDPR).
- Chair: Anu Talus — Data Protection Ombudsman of Finland (since 1 November 2020). Elected EDPB Chair on 25 May 2023, replacing Andrea Jelinek of Austria at the end of Jelinek’s single five-year term (2018–2023). Talus was elected in a two-round secret ballot, with 19 of 27 votes.
- Deputy Chair: Zdravko Vukić — Director of the Croatian Personal Data Protection Agency. Elected on 19 June 2024, replacing Aleid Wolfsen (Netherlands) at the end of his five-year term.
- Deputy Chair: Jelena Virant Burnik — Information Commissioner of Slovenia. Elected on 4 December 2025, replacing Irene Loizidou Nikolaidou, who had vacated the EDPB role after the end of her national mandate as Cyprus Commissioner for Personal Data Protection.
The Chair sets the agenda, represents the Board externally, and chairs plenary meetings. Day-to-day operational support is provided by the Secretariat in Brussels, run by the EDPS.
EDPB vs EDPS — not the same thing
The two are constantly confused. The clean distinction:
- EDPB (European Data Protection Board) — coordinates national DPAs across the EEA. The body this profile is about.
- EDPS (European Data Protection Supervisor) — supervises EU institutions themselves (Commission, Parliament, Council, agencies) when they process personal data. Headed on an interim basis by Wojciech Wiewiórowski, whose five-year term expired on 5 December 2024 — he continues in office while the Council and Parliament finalise the appointment of a successor.
EDPS provides the Secretariat for the EDPB. EDPS is also a member of EDPB. But they have separate legal mandates: EDPB watches private companies and Member States via the national DPAs; EDPS watches Brussels itself.
The Article 29 Working Party (predecessor)
Before GDPR, the EU’s data protection coordination body was the Article 29 Working Party — established under Article 29 of Directive 95/46/EC. It operated from the late 1990s until 25 May 2018, when GDPR replaced the Directive and the Working Party was succeeded by the EDPB.
Practical relevance for compliance work: many WP29 opinions and guidelines remain conceptually valid and were either expressly endorsed or re-issued by EDPB. Old “WP” reference numbers still appear in some legal texts.
What this means for you
If you’re a privacy / compliance professional at an EU-active company: the EDPB’s guidelines are the baseline expectation that every DPA you might encounter will share. When a guideline drops on cookies, dark patterns, AI training data, or international transfers — that’s the new floor. Read them when they’re published, not when a DPA quotes one back at you.
If your company has its EU headquarters in Ireland, Luxembourg, the Netherlands, or another small “main establishment” jurisdiction: the LSA / one-stop-shop mechanism is the most consequential thing about you. Your “home” DPA leads investigations, but other DPAs can object — and if they do, the final fine can be set by the EDPB, often higher than the home DPA proposed. Plan compliance assuming the worst-case outcome runs through Brussels, not through Dublin alone.
If you’re a journalist, researcher, or interested citizen: when you see “following the EDPB’s binding decision under Article 65” in a fine announcement, that’s a tell — it means national DPAs disagreed and the EU-level body had to step in. That’s where the most politically interesting fights happen.
TL;DR
The EDPB is the EU-level body that holds the GDPR’s enforcement system together. It does not investigate companies or issue most fines — that is the national DPAs’ job. What it does: writes guidelines that 30 jurisdictions follow, runs the consistency mechanism so that DPAs do not contradict each other, and resolves cross-border disputes via binding decisions. The reason large GDPR fines against US tech companies tend to come from Ireland or Luxembourg, often noticeably higher than those DPAs initially proposed, is the EDPB’s Article 65 binding decisions. Chair since May 2023: Anu Talus.
Sources
- GDPR Articles 68–76 (EUR-Lex) — establishment, tasks, composition, decision-making
- EDPB official “About” page
- EDPB on the Article 29 Working Party legacy
- EDPB news: Anu Talus elected Chair, 25 May 2023
- EDPB news: Zdravko Vukić elected Deputy Chair, 2024
- EDPB plenary 4 December 2025: Jelena Virant Burnik elected Deputy Chair
- EDPB Board page (current composition)
- EDPB Members page
- edpb.europa.eu — official site
- edps.europa.eu — separate body, often confused with EDPB