Go back
Advisory Bulletin – August 2026 – Clarifying the Definition of Personal Data
Key Points
- Reflect the reality of European R&D. Scientific research is conducted by businesses as well as universities and research institutions. The definition must work for both.
- Read the definition as a whole. Individual elements qualify each other. Removing words because they could be interpreted broadly in isolation risks distorting the overall legal test.
- Avoid using a simplification proposal to introduce new restrictions. Article 4(38) should clarify when the GDPR’s scientific research framework applies, not make that threshold harder to satisfy.
- Stay faithful to Recital 159. The GDPR already takes a broad approach to scientific research, including technological development, applied research and privately funded research. The new definition should reflect that breadth.
Restore the Elements Needed for a Workable Definition
Privacy Next considers that three elements of the Commission approach should be restored to Article 4(38):
- Supporting innovation. Innovation is one of the principal reasons for clarifying the GDPR’s treatment of scientific research. Removing it from the definition is difficult to reconcile with the wider purpose of the Digital Omnibus. A recital is not an adequate substitute because supporting innovation is intended to form part of the legal concept itself.
- Furtherance of a commercial interest. Research does not cease to be scientific because it is commercially funded or may generate commercial value. Recital 159 already expressly recognises privately funded research. Much of Europe’s R&D investment depends on precisely this combination of scientific inquiry and commercial purpose.
- Applying existing knowledge in novel ways. Innovation does not always require entirely new knowledge. Testing, adapting or applying existing knowledge in new contexts is an important part of research and product development and should not be artificially excluded.
The concern that any of these elements could be interpreted too broadly when considered alone should not determine the definition. Legal definitions are applied as a whole. That is precisely why focusing on individual words for deletion is counterproductive. The cumulative elements provide the boundaries. Removing them one by one risks replacing a broad but controlled definition with a narrow and uncertain one.
Avoid Making “verifiable and transparent results” a Condition
Remove the proposed requirement that scientific research should produce verifiable and transparent results. It risks imposing unworkable conditions on how research must be conducted and how results are treated, directly restricting innovation.
- It adds complexity rather than certainty. What constitutes sufficiently “verifiable” or “transparent” results would itself require interpretation, creating a new legal test rather than clarifying an existing one.
- It could expose commercially sensitive research. R&D frequently generates trade secrets, intellectual property and confidential commercial information. Businesses should not face uncertainty over whether research must be disclosed or published to qualify under the GDPR.
- It misunderstands how research works. Research can be exploratory, inconclusive or unsuccessful. Its status as scientific research should not depend on the nature or dissemination of the eventual result.
- It risks putting European businesses at a competitive disadvantage. Companies deciding where to conduct data-intensive R&D need predictable rules and protection for commercially sensitive research. Additional EU-specific constraints would make Europe less, not more, attractive for innovation.
Conclusion
Privacy Next urges policymakers to reverse the narrowing of the proposed definition of scientific research under GDPR, restore the references to innovation, commercial interests and the application of existing knowledge, and remove the requirement for verifiable and transparent results. The definition must work as a whole and reflect the broad approach already established by Recital 159. The GDPR already provides safeguards for scientific research, including Article 89. Those safeguards should not be duplicated or expanded indirectly through the definition itself. Otherwise, a provision intended to clarify and simplify the GDPR risks restricting legitimate research, discouraging investment and creating a new obstacle to the very innovation and competitiveness the Digital Omnibus is intended to support.