# The EDPS Annual Report 2025: What It Tells DPOs About the Next Phase of EU Oversight

Canonical URL: https://xpertdpo.com/edps-annual-report-2025-dpo-ai-governance/

Content type: Article

Published: 2026-08-06T15:12:25+01:00

Updated: 2026-08-06T20:59:44+01:00

Author: Philipa Jane Farley, Head of Legal and Operations

Summary: The EDPS Annual Report 2025 shows DPOs how privacy supervision, AI oversight, cybersecurity and digital regulation are becoming one connected governance challenge.

## Article

*This article accompanies **Hour 1: Global Privacy Law Updates** in our full-day CPD programme on XpertAcademy. Completion of the full one-hour session, including the related learning materials, contributes to the one-hour CPD certificate issued for that session. [Access CPD Event A: Full-Day Regulatory Privacy Training](https://xpertacademy.com/cpd-event-a-regulatory/).*

 The European Data Protection Supervisor (EDPS) published its [Annual Report 2025](https://www.edps.europa.eu/data-protection/our-work/our-work-by-type/annual-reports_en) on 7 May 2026. It describes a year in which the EDPS moved from preparing for a wider digital mandate to putting that mandate into operation.

 That distinction matters. The report is not simply a record of data protection activity inside the EU institutions. It shows privacy supervision becoming more closely connected with artificial intelligence, cybersecurity, international transfers, large-scale information systems and the design of new EU law.

 For DPOs, compliance leaders and senior privacy operations teams outside the EU institutions, the EDPS is not usually their direct supervisory authority. Its work is nevertheless an important signal. EU institutions often encounter the same governance pressures as large organisations: cloud dependence, complex supply chains, AI adoption, sensitive data, cross-border processing and demands for rapid digital delivery.

### First, where does the EDPS fit?

 The EDPS is the independent data protection authority for the EU institutions, bodies, offices and agencies. Its supervisory framework is principally [Regulation (EU) 2018/1725](https://eur-lex.europa.eu/eli/reg/2018/1725/oj), rather than the GDPR regime that applies to most organisations in the Member States.

 It combines direct supervision of EU bodies with legislative advice, technology monitoring and cooperation with national authorities. That is different from the European Data Protection Board's role in supporting consistent application of the GDPR and Law Enforcement Directive across the EEA. Our [European privacy and AI governance map](https://xpertdpo.com/european-data-protection-ai-governance-institutions-guide/) sets out the institutional boundaries in more detail.

> The EDPS is not "the EU's DPA for everyone". Its importance lies in the combination of direct supervision, legislative advice and early visibility of emerging governance problems.

### AI supervision has become operational

 The most obvious development in the 2025 report is the expansion of the EDPS's AI work. The EDPS established a dedicated AI Unit, mapped AI use across EU institutions and launched a regulatory sandbox pilot to allow institutions to test systems with regulatory guidance.

 It also developed an AI Act Correspondents Network across EU institutions. This is a useful governance lesson in itself. New regulation cannot be implemented by a central policy team working in isolation. Organisations need named people close enough to business use cases to identify systems, surface changes and connect operational facts with central assurance.

 The EDPS is also the AI Act market surveillance authority for EU institutions. That role is separate from its data protection supervision. It means the same institution may need to consider an AI system through more than one legal lens, using distinct powers and tests. Our [practical EU AI Act timeline](https://xpertdpo.com/eu-ai-act-timeline-2026-practical-actions/) explains the current staged dates following the 2026 Omnibus amendments.

 For corporate privacy teams, the parallel is clear: a DPIA will not, by itself, discharge AI Act, product safety, employment, equality, consumer or sector-specific responsibilities. The evidence may overlap, but the legal questions and accountable owners are not identical. Our practical guide to [AI Act role mapping](https://xpertdpo.com/ai-act-role-mapping-provider-deployer-importer-and-distributor/) explains why the organisation's role must be established for each use case rather than assumed at enterprise level.

### Legislative advice is becoming a larger part of the picture

 The EDPS responded to a record 145 legislative consultations during 2025. Those consultations ranged from digital identity to proposed changes affecting the GDPR.

 The number is striking, but the more important point is structural. European digital regulation is no longer arriving as one self-contained instrument at a time. Privacy requirements now interact with AI rules, cyber-resilience measures, data-access regimes, platform regulation, law-enforcement systems and sectoral initiatives.

 That makes regulatory horizon-scanning harder. It also makes narrow legal ownership less effective. A DPO does not need to own every part of the EU Digital Rulebook, but the organisation needs a reliable way to identify where a proposal or new obligation changes personal-data processing, rights, accountability evidence or regulator engagement.

> The practical risk is no longer simply missing a new rule. It is implementing one regulatory requirement in a way that creates an unmanaged conflict somewhere else.

### Cloud accountability remains a live supervisory issue

 The report highlights the EDPS investigation into the European Commission's use of Microsoft 365. The matter is significant beyond the particular parties because it concerns familiar operational questions: controller instructions, processor terms, international transfers, onward processing, purpose limitation and whether contractual controls match the service actually used.

 Large cloud arrangements are rarely governed by the contract alone. Configuration, telemetry, support access, connected services, product changes and subcontracting can alter the factual processing environment. Good governance therefore requires a maintained evidence position, not a procurement-stage paper exercise.

 This is especially relevant as AI features are added to existing enterprise platforms. Organisations should be able to distinguish the service they originally approved from the capabilities now available, the data exposed to those capabilities and the supplier roles that follow. Our analysis of [cloud AI contracts, subprocessors and transfer evidence](https://xpertdpo.com/cloud-ai-contracts-subprocessors-and-transfer-evidence/) looks at that problem in more operational detail.

### Large-scale systems test whether governance works under pressure

 The EDPS also reported audits and oversight involving large-scale EU information systems and agencies including Europol, Frontex and Eurojust. These environments combine sensitive data, multiple participating authorities, access controls, operational urgency and potentially significant effects on individuals.

 Most organisations do not operate systems of that scale or sensitivity. The governance lesson still travels. Where data flows across teams, jurisdictions and technical platforms, accountability depends on more than a high-level statement of responsibility. It requires evidence of access, purpose, data quality, retention, human decision-making and escalation.

 This is the difference between a governance framework that describes how processing should work and an assurance record that shows what happened in practice. Privacy metrics should therefore be designed for audit resilience, not only monthly reporting.

### Cybersecurity and data protection are being connected more formally

 During 2025, the EDPS became a permanent member of the Inter-Institutional Cybersecurity Board. That reflects a wider shift in European governance: privacy and cybersecurity have separate legal foundations and objectives, but their operational evidence increasingly meets in the same systems, incidents and supplier chains.

 A mature organisation should preserve those distinctions while making cooperation routine. Security teams need to understand the personal-data and rights implications of an incident. Privacy teams need enough technical evidence to assess risk, notifications and remedial action. Both need clear ownership when an AI or cloud service changes the threat model.

 This does not mean merging every assessment into a single universal form. It means designing information flows so that material facts do not remain trapped within one assurance function.

### Foresight is becoming part of regulatory readiness

 The EDPS's technology monitoring considered agentic AI, AI companions and federated learning. These subjects are not included merely to make an annual report look forward-looking. They show the authority trying to understand governance questions before use becomes routine.

 Agentic systems can act across tools and data sources with less immediate human direction. AI companions can create unusually intimate and persistent data relationships. Federated learning may reduce some centralised data collection while introducing different questions about inference, model updates and participant control.

 For DPOs, the lesson is to make foresight proportionate and practical. Teams do not need speculative assessments of every emerging technology. They do need a route for identifying when a proposed capability changes autonomy, scale, sensitivity, observability or the effect on individuals. That trigger should lead to the right combination of technical review, DPIA, AI assessment, legal analysis and senior decision-making.

### What senior teams should take from the report

 The EDPS report supports six practical actions.

- Map AI use through accountable operational contacts, not a one-off survey.
- Revisit major cloud arrangements when services, features or subprocessors change.
- Connect privacy, AI, security, procurement and legal horizon-scanning.
- Preserve separate legal assessments while reusing verified evidence sensibly.
- Test whether governance records can reconstruct real decisions and system changes.
- Give emerging technology review a defined trigger, owner and escalation route.

 For in-house teams, this is less about adding another committee and more about making the existing control environment work across regulatory boundaries. Where capacity or specialist judgement is stretched, [XpertDPO's DPO support](https://xpertdpo.com/dpo-support/) can provide senior review while keeping accountability with the organisation.

### The XpertDPO view

 The EDPS Annual Report 2025 is a useful marker of where European digital governance is heading. Data protection remains a distinct legal discipline, but effective supervision increasingly requires regulators and organisations to understand AI, cloud architecture, cybersecurity, transfers and complex institutional systems together.

 That should not be read as a reason to collapse every obligation into "digital compliance". Doing so can obscure legal tests, statutory independence and ownership. The better response is coordinated governance with clear boundaries: shared facts, explicit roles, connected escalation and evidence that remains intelligible to each competent authority.

> Coordination should make accountability clearer. If it leaves everyone involved but nobody decisively responsible, it has produced the opposite result.

 The EDPS is operating in a particular institutional setting, but the report's central challenge is widely shared. Organisations are adopting technologies whose governance does not fit neatly within a single team. Senior privacy leaders should use that as a prompt to test whether their own structures can move from policy statements to operational truth.

### What This Means for CPD

 For Event A Hour 1, the practical learning is that an annual report should be read as evidence of regulatory direction, not simply as a record of activity. Learners should be able to identify which EDPS developments are directly relevant to EU institutions and which provide a wider governance signal for DPOs and compliance leaders.

 This article is intended to support the learning covered in Hour 1 of our XpertAcademy CPD programme. The relevant CPD certificate is issued for completion of the full one-hour session on XpertAcademy, rather than for reading this article on its own. [Return to CPD Event A: Full-Day Regulatory Privacy Training](https://xpertacademy.com/cpd-event-a-regulatory/).

### Sources

- EDPS, [Annual Report 2025: protecting people in a changing digital world](https://www.edps.europa.eu/data-protection/our-work/our-work-by-type/annual-reports_en)
- EDPS, [Annual Report 2025 press release](https://www.edps.europa.eu/press-publications/press-news/press-releases/2026/edpss-annual-report-2025-highlights-record-legislative-consultations-and-ai-transition-within-european-institutions_en)
- EDPS, [About the EDPS](https://www.edps.europa.eu/about/about-us_en)
- EDPS, [The EDPS and the Artificial Intelligence Act](https://www.edps.europa.eu/artificial-intelligence/artificial-intelligence-act_en)
- EUR-Lex, [Regulation (EU) 2018/1725](https://eur-lex.europa.eu/eli/reg/2018/1725/oj)

## General Information Only

This article is provided for general information and does not constitute legal, regulatory, or professional advice. Data protection obligations depend on the specific facts, context, and jurisdiction involved. You should not rely on this content as a substitute for advice tailored to your organisation.

If you would like support with a specific issue, please contact us: https://xpertdpo.com/contact/
