Europol, Eurojust, the European Public Prosecutor’s Office (EPPO) and Frontex all process highly sensitive personal data in the course of investigating and prosecuting serious crime — data on suspects, convicted persons, victims and witnesses. Yet for years, each of these bodies has operated under a different data protection regime, with different rules on record-keeping, different duties for their Data Protection Officers, and different supervisory powers for the European Data Protection Supervisor (EDPS).
The European Commission has now proposed to change that. A new proposal (COM(2026) 314, procedure 2026/0173/COD) would amend Regulation (EU) 2018/1725 — the EU’s own institutional data protection rulebook, often described as the “GDPR for EU institutions” — to bring all four agencies under a single, coherent set of rules for the personal data they process in their law-enforcement and judicial work. The proposal is still at an early stage: it has just been transmitted to national parliaments, and negotiations in the European Parliament and the Council have not yet started.
A fragmented framework
Regulation (EU) 2018/1725 already contains a dedicated chapter — Chapter IX — governing what it calls “operational personal data”: data processed by EU justice and home affairs bodies in the course of police cooperation and judicial cooperation in criminal matters. In practice, however, that chapter has never applied evenly. The EPPO’s founding act predates the EUDPR and set up its own, separate data protection regime. Frontex is covered only to a limited extent. And Chapter IX itself is silent on several matters that are standard in general data protection law, such as the role of the Data Protection Officer, the duty to keep records of processing activities, or how supervisory authorities should cooperate with one another.
The Commission acknowledged these gaps in its first application report on the EUDPR back in 2022, and this proposal is the legislative follow-up. According to the Commission, an impact assessment was not considered necessary, given the limited and technical nature of the changes and the fact that the affected agencies are already subject to their own dedicated evaluations.
What the proposal changes
Bringing the EPPO under a common regime. For the first time, the EPPO would be integrated into the EUDPR framework rather than relying entirely on its own, separate rules. The EPPO would keep the specific provisions that reflect its unique status as the Union’s independent prosecution office, but the general data protection rules applicable to its operational work would align with those governing Europol and Eurojust.
One Data Protection Officer, one set of duties. The proposal consolidates the tasks of the Data Protection Officer so that a single role covers both administrative and operational personal data, rather than leaving gaps to be filled — inconsistently — by each agency’s own founding act.
A new record-keeping obligation. A new Article 87a introduces, for the first time, a duty for these bodies to maintain a record of all categories of processing of operational personal data — covering purposes, categories of data subjects and data, recipients (including private parties and third countries), retention periods, and security measures. This is, in effect, the law-enforcement equivalent of the “records of processing activities” that GDPR-covered organisations have had to maintain since 2018.
A single toolkit for the EDPS. Currently, the EDPS’s supervisory powers over Europol, Eurojust and the EPPO are each set out — differently — in their respective founding acts, and Frontex’s founding act does not address EDPS supervision of operational data processing at all. The proposal removes these agency-specific provisions and gives the EDPS one harmonised set of powers, modelled on the powers introduced in the 2022 reform of the Europol Regulation: the ability to order compliance, to suspend data flows, and to impose administrative fines.
Who is affected
The proposal’s direct addressees are the four agencies themselves, as controllers, and their Data Protection Officers, who will need to adapt to a more explicit and more demanding accountability framework — particularly the new record-keeping duty. National authorities that supply data to these agencies are also affected, since they gain a clearer, harmonised set of rules for how their data will be handled downstream. And, ultimately, the individuals whose data these agencies process — suspects, convicted persons, victims and witnesses — stand to benefit from more consistent safeguards and clearer avenues for oversight, regardless of which EU agency happens to be handling their case.
Where the proposal stands
As a Commission proposal, this text is only the starting point of the EU’s ordinary legislative procedure. No general application date has been set beyond the standard entry into force twenty days after publication in the Official Journal — and the provisions specifically affecting the EPPO will not apply until the still-pending revision of the EPPO’s own founding Regulation enters into application, creating a dependency between two separate legislative files. The Commission has also indicated that a further evaluation of the EUDPR as a whole is envisaged for 2027, suggesting this reform is one step in a longer process of consolidation.
Plus Ethics’s perspective
We welcome the direction of travel here: fragmented, agency-specific data protection regimes make compliance harder to audit and oversight harder to exercise consistently. A single rulebook, with a genuine record-keeping obligation and a unified EDPS toolkit, is a meaningful step toward the kind of accountability that private-sector controllers have had to build under the GDPR for years. At the same time, “one rulebook” also means one reference point that anyone working with these agencies — as a data subject, a national authority, or a private-sector recipient of a data request — now needs to understand well.
This article is provided for informational purposes and does not constitute individualised legal advice. The proposal discussed remains subject to negotiation in the European Parliament and the Council and may change materially before adoption.
Source: https://eur-lex.europa.eu/
