Cuatrecasas, Gonçalves Pereira SLP

10/01/2025 | Press release | Distributed by Public on 10/01/2025 08:39

EDPB adopts guidelines on the interplay between the DSA and the GDPR

2025-10-01T16:14:00
European Union

The European Data Protection Board adopts first guidelines on the interplay between the DSA and the GDPR

View document
October 1, 2025
  • Catarina Castanheira Lopes
  • Pablo Tena
  • Helena Borges da Costa
  • Technology and Telecommunications
  • Intellectual and Industrial Property

Don't miss our content

Subscribe

KEY ASPECTS

  • Simultaneous compliance with the DSA and the GDPR is essential for intermediary service providers, requiring that the processing of personal data observes the principles of lawfulness, minimization and transparency.
  • The obligation to carry out a Data Protection Impact Assessment (DPIA) applies in high-risk situations, such as voluntary investigations or in the management of complaints.
  • Transparency in recommendation systems implies the provision of options not based on profiling and the limitation of the time it takes to retain users' choices to what is strictly necessary.
  • Systemic risk management and mitigation, especially for Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs), require the implementation of measures that are proportionate and compatible with the requirements of the GDPR.
View document
October 1, 2025
  • Catarina Castanheira Lopes
  • Pablo Tena
  • Helena Borges da Costa
  • Technology and Telecommunications
  • Intellectual and Industrial Property

Don't miss our content

Subscribe
Cuatrecasas, Gonçalves Pereira SLP published this content on October 01, 2025, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on October 01, 2025 at 14:40 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]