Torri-caveau di vetro collegate da ponti di luce ambra che trasportano dati, con un ponte centrale incompiuto: lo scambio di informazioni tra autorita' di regolazione

Immagine creata con IAAI-generated image

Making regulators talk to one another: the EDPB calls for a legal basis to share information

Meeting in Dublin on 16 and 17 July 2026, Europe’s data protection authorities put a clear request to the European Commission: give the Union a legal basis that lets authorities with different remits share information, including confidential information, in order to enforce their respective rules. The request, made by the European Data Protection Board (EDPB) at the close of its high-level meeting, springs from a practical observation: supervising digital phenomena that touch data protection, artificial intelligence, digital services and competition all at once is today hampered by the absence of clear rules on information sharing between regulators.

What the EDPB is asking for, and why

The call rests on the growing need for effective cooperation between authorities operating in adjacent areas of Union law. The same companies are now subject, on a single product or service, to the GDPR, the AI Act, the digital services rules and competition law; yet the authorities supervising each of these bodies of law have no clear footing on which to exchange what they learn, still less information covered by confidentiality. The EDPB therefore asks the Commission to propose a dedicated legal basis enabling the exchange of information relevant to enforcement within each authority’s remit. First-hand experience of working with other digital regulators, at national and EU level, has made clear that without legislation the cooperation stays exposed to barriers that weaken supervisory outcomes. This is not the Board’s first move on the legislative plane: on reform projects such as the Digital Omnibus, the EDPB and the EDPS have already set out their positions.

GDPR enforcement under strain

The second strand of the Dublin discussion concerns the resilience of enforcement. The EDPB recalls the progress on cross-border enforcement noted in the Commission’s second report on the application of the GDPR, while flagging at the same time a marked rise in the number and complexity of complaints, driven in part by the spread of artificial intelligence, which weighs on already stretched resources. Hence the search for practical and, where needed, legislative solutions: pooling resources between authorities, with the possibility for those receiving a complaint to make resources available to the lead authority; a series of workshops on enforcement procedures; wider use of joint operations. Against this backdrop sits Regulation (EU) 2025/2518, which lays down additional procedural rules for enforcing the GDPR in cross-border cases, codifies many practices the authorities already follow and will apply from 2 April 2027.

From principle to practice: the understanding with the anti-money-laundering authority

That information sharing has become concrete ground, and not merely an aspiration, is shown by the initiative the EDPB has launched with the European Anti-Money Laundering Authority (AMLA). The two bodies will develop joint guidelines on how to build partnerships for sharing information in the fight against financial crime without sacrificing data protection. The reference is to Article 75 of the Anti-Money Laundering Regulation, which lets obliged entities and public authorities exchange information within defined limits, a possibility that will apply from 10 July 2027. Because that exchange involves processing personal data, data protection safeguards become part of the design; the guidelines, preceded by an event to gather input and by a public consultation planned for the first half of 2027, will set out in operational terms how investigative effectiveness and the protection of the individual can sit together.

It remains to be seen whether the Commission will take up the invitation with a standalone measure or leave cross-regulatory cooperation resting on fragmentary foundations. For now the direction is set: data protection authorities are not asking for new powers, but for the tools to exercise those they already have, in an ecosystem where the boundaries between regulated fields are thinning. For companies the signal is concrete, because information shared with one authority may reach another more readily, and coherence across different supervisors will become a compliance criterion, not merely the authorities’ problem.


AI AnthropoCosmic In evidenzaAI AnthropoCosmicCall for Paper aperta fino al 15 settembre 2026. Un progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicCall for Paper open until 15 September 2026. An international project for an AI at the service of humanity, the environment and the cosmos. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article