[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-253054-105":53,"doc-detail-253054-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","omnibus-survey-report-march-2026-cedpo-questionnaire-analysis","Omnibus Survey Report - March 2026 - CEDPO Questionnaire Analysis","","Omnibus Survey Report (March 2026) analyzes the CEDPO questionnaire and compiles a series of policy proposals addressing the interpretation and practical application of GDPR concepts. The report covers clarification of personal data definitions, harmonized terminology across EU digital laws, and adjusted rules for incident reporting, breach notification timing, and transitional security regimes. It also outlines approaches for reuse of personal data, AI-related legal grounds and categories, and strengthened criteria for rights management, including templates and uniform high-risk circumstances.",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":51,"@type":70,"position":76},"https://docshare.wps.com/template/general/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/omnibus-survey-report-march-2026-cedpo-questionnaire-analysis/253054/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/omnibus-survey-report-march-2026-cedpo-questionnaire-analysis/253054.png","ImageObject",442,249,{"name":88,"@type":89},"Dipper","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/pdf","2026-09-20","2026-09-13",true,{"@type":98,"interactionType":99,"userInteractionCount":79},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"What is the scope of the Omnibus Survey Report in March 2026?","Question",{"text":108,"@type":109},"It presents an analysis of the CEDPO questionnaire, focusing on proposed clarifications and updates related to GDPR concepts, EU digital-law terminology, and operational requirements.","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"Which topics are covered under incident reporting and data breach notifications?",{"text":113,"@type":109},"The report proposes a single-entry point with a common incident-reporting template, changes to notification timing, limits on mandatory reporting to DPAs, and a transitional regime for security-breach notifications.",{"name":115,"@type":106,"acceptedAnswer":116},"How does the report address AI and personal data?",{"text":117,"@type":109},"It includes proposals allowing specific conditions for special-category data and legitimate interest as a legal ground in AI development and operation, plus guidance on biometric data use for identity verification under data-subject control.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},253054,1789264089,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":50,"category_name":51,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":79,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":135,"language":136,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":61,"update_tm":125,"read_time":140},1374404997633,"https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd","Bonn, Bucharest, Dublin, Lisbon, Luxembourg, Madrid, Milan, Paris, The Hague, Vienna, Warsaw  \nOmnibus Survey Report  \nAnalysis of the CEDPO Questionnaire on Omnibus  \nIV and VII  \nMarch 2026  \nContact information:  \n[https://cedpo.eu](https://cedpo.eu)  \n[info@cedpo.eu](info@cedpo.eu)  \nContents  \nIntroduction .................................................................................................................4  \nResults Analysis ...........................................................................................................8  \nQuestion 1: Proposal to clarify the definition of personal data based on the definition presented in the CJEU ruling (C-413/23 P EDPS v SRB) ................................................................................................8  \nQuestion 2: Proposal to empower the Commission with the authority to adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities................................................................................... 10  \nQuestion 3: Proposal to use uniform definitions in different EU digital laws for ‘terminal equipment’,‘electronic communications networks’, ‘web browser’, ‘media service’, ‘media service provider’, ‘online interface’....................................................................................................................................... 12  \nQuestion 4: Proposal for a definition of “scientific research” specifying that “research may also aim to further a commercial interest”........................................................................................................ 13  \nQuestion 5: Proposal to facilitate the possibility to reuse personal data for archiving, scientific or historical research or statistical purposes by considering It automatically compatible with the initial purposes, and without it having to pass the compatibility test of article 6(4) GDPR.............................15  \nQuestion 6: Proposal to have a single-entry point and a common template for all incident reporting, not just under the GDPR but also for DORA, NIS2, eIDAS, CER...............................................................17  \nQuestion 7: Proposal to increase the notification period for data breaches to 96 hours (instead of 72  \nhours) ........................................................................................................................................... 18  \nQuestion 8: Proposal to limit the necessity to report personal data breach to DPAs to cases where it can result in a high risk to data subjects.................................................................................................20  \nQuestion 9: Establish a transitional regime for security breach notifications, maintaining direct reporting to supervisory authorities until the NIS2 Directive's single point of entry is operational, thereby ensuring continuous reporting............................................................................................21  \nQuestion 10: Proposal to mandate the EDPB to develop a common breach notification template and a single list of high-risk circumstances, to be adopted by the Commission via implementing acts, to harmonize EU-wide criteria and procedures....................................................................................22  \nQuestion 11: Proposal to allow the exceptional use of special categories of data in the context of the development and operation of an AI system or an AI model where appropriate safeguards are in place......................................................................................................................................................24  \nQuestion 12: Proposal to allow legitimate interest as a legal ground in the context of AI development and operation, as well as AI models, with appropriate measures and safeguards for the rights and freedom","cbCaiugBGGJkQ98B","https://ap.wps.com/l/cbCaiugBGGJkQ98B","pdf",1265056,55,"English","# Introduction\n# Results Analysis\n## Question 1-5\n## Question 6-10\n## Question 11-15\n## Question 16-19","[{\"question\":\"What is the scope of the Omnibus Survey Report in March 2026?\",\"answer\":\"It presents an analysis of the CEDPO questionnaire, focusing on proposed clarifications and updates related to GDPR concepts, EU digital-law terminology, and operational requirements.\"},{\"question\":\"Which topics are covered under incident reporting and data breach notifications?\",\"answer\":\"The report proposes a single-entry point with a common incident-reporting template, changes to notification timing, limits on mandatory reporting to DPAs, and a transitional regime for security-breach notifications.\"},{\"question\":\"How does the report address AI and personal data?\",\"answer\":\"It includes proposals allowing specific conditions for special-category data and legitimate interest as a legal ground in AI development and operation, plus guidance on biometric data use for identity verification under data-subject control.\"}]","Omnibus Survey Report - March 2026 - CEDPO Questionnaire Analysis | PDF",19]