Meeting in Dublin on 16 and 17 July 2026, Europe’s data protection authorities put a clear request to the European Commission: give the Union a legal basis that lets authorities with different remits share information, including confidential information, in order to enforce their respective rules. The request, made by the European Data Protection Board (EDPB) at the close of its high-level meeting, springs from a practical observation: supervising digital phenomena that touch data protection, artificial intelligence, digital services and competition all at once is today hampered by the absence of clear rules on information sharing between regulators.
What the EDPB is asking for, and why
The call rests on the growing need for effective cooperation between authorities operating in adjacent areas of Union law. The same companies are now subject, on a single product or service, to the GDPR, the AI Act, the digital services rules and competition law; yet the authorities supervising each of these bodies of law have no clear footing on which to exchange what they learn, still less information covered by confidentiality. The EDPB therefore asks the Commission to propose a dedicated legal basis enabling the exchange of information relevant to enforcement within each authority’s remit. First-hand experience of working with other digital regulators, at national and EU level, has made clear that without legislation the cooperation stays exposed to barriers that weaken supervisory outcomes. This is not the Board’s first move on the legislative plane: on reform projects such as the Digital Omnibus, the EDPB and the EDPS have already set out their positions.
GDPR enforcement under strain
The second strand of the Dublin discussion concerns the resilience of enforcement. The EDPB recalls the progress on cross-border enforcement noted in the Commission’s second report on the application of the GDPR, while flagging at the same time a marked rise in the number and complexity of complaints, driven in part by the spread of artificial intelligence, which weighs on already stretched resources. Hence the search for practical and, where needed, legislative solutions: pooling resources between authorities, with the possibility for those receiving a complaint to make resources available to the lead authority; a series of workshops on enforcement procedures; wider use of joint operations. Against this backdrop sits Regulation (EU) 2025/2518, which lays down additional procedural rules for enforcing the GDPR in cross-border cases, codifies many practices the authorities already follow and will apply from 2 April 2027.
From principle to practice: the understanding with the anti-money-laundering authority
That information sharing has become concrete ground, and not merely an aspiration, is shown by the initiative the EDPB has launched with the European Anti-Money Laundering Authority (AMLA). The two bodies will develop joint guidelines on how to build partnerships for sharing information in the fight against financial crime without sacrificing data protection. The reference is to Article 75 of the Anti-Money Laundering Regulation, which lets obliged entities and public authorities exchange information within defined limits, a possibility that will apply from 10 July 2027. Because that exchange involves processing personal data, data protection safeguards become part of the design; the guidelines, preceded by an event to gather input and by a public consultation planned for the first half of 2027, will set out in operational terms how investigative effectiveness and the protection of the individual can sit together.
It remains to be seen whether the Commission will take up the invitation with a standalone measure or leave cross-regulatory cooperation resting on fragmentary foundations. For now the direction is set: data protection authorities are not asking for new powers, but for the tools to exercise those they already have, in an ecosystem where the boundaries between regulated fields are thinning. For companies the signal is concrete, because information shared with one authority may reach another more readily, and coherence across different supervisors will become a compliance criterion, not merely the authorities’ problem.




