Key Points

  • Reflect the reality of European R&D. Scientific research is conducted by businesses as well as universities and research institutions. The definition must work for both.
  • Read the definition as a whole. Individual elements qualify each other. Removing words because they could be interpreted broadly in isolation risks distorting the overall legal test.
  • Avoid using a simplification proposal to introduce new restrictions. Article 4(38) should clarify when the GDPR’s scientific research framework applies, not make that threshold harder to satisfy.
  • Stay faithful to Recital 159. The GDPR already takes a broad approach to scientific research, including technological development, applied research and privately funded research. The new definition should reflect that breadth.

Restore the Elements Needed for a Workable Definition

Privacy Next considers that three elements of the Commission approach should be restored to Article 4(38):

  • Supporting innovation. Innovation is one of the principal reasons for clarifying the GDPR’s treatment of scientific research. Removing it from the definition is difficult to reconcile with the wider purpose of the Digital Omnibus. A recital is not an adequate substitute because supporting innovation is intended to form part of the legal concept itself.
  • Furtherance of a commercial interest. Research does not cease to be scientific because it is commercially funded or may generate commercial value. Recital 159 already expressly recognises privately funded research. Much of Europe’s R&D investment depends on precisely this combination of scientific inquiry and commercial purpose.
  • Applying existing knowledge in novel ways. Innovation does not always require entirely new knowledge. Testing, adapting or applying existing knowledge in new contexts is an important part of research and product development and should not be artificially excluded.

The concern that any of these elements could be interpreted too broadly when considered alone should not determine the definition. Legal definitions are applied as a whole. That is precisely why focusing on individual words for deletion is counterproductive. The cumulative elements provide the boundaries. Removing them one by one risks replacing a broad but controlled definition with a narrow and uncertain one.

Avoid Making “verifiable and transparent results” a Condition

Remove the proposed requirement that scientific research should produce verifiable and transparent results. It risks imposing unworkable conditions on how research must be conducted and how results are treated, directly restricting innovation.

  • It adds complexity rather than certainty. What constitutes sufficiently “verifiable” or “transparent” results would itself require interpretation, creating a new legal test rather than clarifying an existing one.
  • It could expose commercially sensitive research. R&D frequently generates trade secrets, intellectual property and confidential commercial information. Businesses should not face uncertainty over whether research must be disclosed or published to qualify under the GDPR.
  • It misunderstands how research works. Research can be exploratory, inconclusive or unsuccessful. Its status as scientific research should not depend on the nature or dissemination of the eventual result.
  • It risks putting European businesses at a competitive disadvantage. Companies deciding where to conduct data-intensive R&D need predictable rules and protection for commercially sensitive research. Additional EU-specific constraints would make Europe less, not more, attractive for innovation.

Conclusion

Privacy Next urges policymakers to reverse the narrowing of the proposed definition of scientific research under GDPR, restore the references to innovation, commercial interests and the application of existing knowledge, and remove the requirement for verifiable and transparent results. The definition must work as a whole and reflect the broad approach already established by Recital 159. The GDPR already provides safeguards for scientific research, including Article 89. Those safeguards should not be duplicated or expanded indirectly through the definition itself. Otherwise, a provision intended to clarify and simplify the GDPR risks restricting legitimate research, discouraging investment and creating a new obstacle to the very innovation and competitiveness the Digital Omnibus is intended to support.

In preparation for a revision of the Eurojust Regulation, the Commission undertook a call for evidence and public consultation to gather a diverse range of views on how the EU can improve Eurojust’s ability to address serious cross-border crime. The initiative for a revision of the Eurojust Regulation aims to enhance security by increasing Eurojust’s support to national authorities in combating serious and organised crime, which is expected to reduce economic harm, promote stability, and foster growth in the EU. Strengthened efforts against crimes such as drug trafficking, human trafficking, and cybercrime are anticipated to yield social benefits, including improved public safety, health, and online security.  Additionally, the initiative seeks to bolster fundamental rights by ensuring citizen security, improving victims’ access to justice, and safeguarding suspects’ rights. ​ While enhanced information exchange is essential for addressing cross-border crime, the impact on personal data protection must be recognised and appropriate safeguards must be in place. The revision of the Eurojust Regulation seeks to provide Eurojust with a framework to respond faster and more effectively to organised crime and further enhance the security of society.

On 16 April 2026, the EDPB adopted Guidelines 1/2026 on the processing of personal data for scientific research purposes and called for feedback on the Guidelines. There is no question that there is a need for greater clarity on when GDPR applies to scientific research. However, the present Guidelines were developed before the legislative debate surrounding the Digital Omnibus and the future scope of scientific research has reached a conclusion. In its feedback to the EDPB, Privacy Next asserts that the present Guidelines should be withdrawn and reconsidered once the co-legislators have concluded the Digital Omnibus negotiations. The role of the regulator is to apply agreed laws within an established mandate, not to pre-empt the legislative process.

The EU’s Digital Fitness Check is the second stage of the European Commission’s digital simplification agenda, following the targeted regulatory adjustments proposed under the Digital Omnibus. The fitness check was designed as a broad, evidence‑gathering exercise to assess whether the EU’s digital rulebook remains effective, proportionate and fit for the future. The call for evidence and consultation sought the views of stakeholders to examine the cumulative impact of the EU’s digital rules businesses, people, and public authorities, The process had a deliberately tactical focus, inviting stakeholders to share practical experiences with overlaps, inconsistencies and synergies between the rules, and to provide evidence on regulatory burdens and real‑world effects. It is hoped that the consultative process will provide an evidence-based assessment of the EU’s digital rules to determine how well they support EU competitiveness while safeguarding values and fundamental rights.

Privacy Next provided a response to the European Commission’s call for feedback on the Digital Omnibus proposal for a regulation – COM(2025)836. The Digital Omnibus proposal comes at a time when the regional organisation and its Member States are pursuing a range of policy priorities – competitiveness, simplification, better enforcement, increased cooperation, and more efficiency are all identified as necessary matters to address. Privacy Next is of the view that these are not mutually exclusive choices in the process of legislative reform. The data governance framework has been built recognising the need to adapt to the technical and social developments in society while maintaining sufficient safeguards for the protection of personal data. Both objectives must be pursued to ensure the effective functioning of the EU’s Single/internal market.

The feedback submitted by Privacy Next raised the following key points:

  • GDPR has expanded into a “law of everything,” overextending its scope and weakening the data protection framework
  • Supervisory authorities are overwhelmed by individual complaints, undermining enforcement, consistency, and public guidance on GDPR implementation.
  • An overemphasis on individual data protection claims has sidelined GDPR’s equally important objective of enabling the free movement of personal data.
  • A recalibration of GDPR priorities is needed to better balance fundamental rights, economic competitiveness, and administrative feasibility.