Regulatory Watch  /  European Union  /  Guidance
Moderate impactGuidancePublished

noyb releases ad‑hoc guidance on GDPR compliance for COVID‑19 data processing

noyb published an ad‑hoc paper outlining how the GDPR permits processing personal data to combat the coronavirus pandemic. The paper cites Articles 6(1)(d) and 9(2)(i) as legal bases and stresses the need for privacy‑by‑design, data minimisation and user control. It advises voluntary, locally stored and encrypted contact‑tracing solutions.

Why it matters: The guidance clarifies that GDPR does not need to be waived for epidemic response, but must be observed, shaping how health data can be used responsibly.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Data protection in times of coronavirus: not a question of if, but of how
noyb · primary source · Apr 9, 2020
Data protection in times of coronavirus: not a question of if, but of how
noyb · Apr 9, 2020
Details
JurisdictionEuropean Union
RegulatorEDPB
LawGeneral Data Protection Regulation
StatusPublished
PublishedApril 9, 2020
Effectivenot stated
Organisationsnoyb, Max Schrems
Topicsprivacy, data minimization, purpose limitation, security, cross border transfer, health
Datapersonal, sensitive, health