GDPR & AI Act updates: key takeaways from April 2026
April 2026 marks a busy month for compliance: the EDPB launches a coordinated action on processing transparency and adopts a harmonized DPIA model, the CNIL publishes its 2026 audit priorities and a final recommendation on tracking pixels in emails, Google deploys end-to-end encryption on Gmail under certain conditions, and the CJEU clarifies the limits of abusive access requests. Here are the key takeaways.

April 2026 marks a busy month for compliance: the EDPB launches a coordinated action on processing transparency and adopts a harmonized DPIA model, the CNIL publishes its 2026 audit priorities and a final recommendation on tracking pixels in emails, Google deploys end-to-end encryption on Gmail under certain conditions, and the CJEU clarifies the limits of abusive access requests. Here's the GDPR news from April 2026 you won't want to miss.
EDPB coordinated action on processing transparency
In April 2026, the European Data Protection Board (EDPB) launched a coordinated enforcement mechanism (CEF 2026) focused on GDPR processing transparency.
The objective: to examine how organizations actually inform individuals about the use of their data, and to detect overly frequent areas of opacity in information notices and privacy policies.
This action brings together 25 national data protection authorities who are pooling their findings to produce a common report by the end of the year. This sends a strong signal to organizations that still neglect the quality of their GDPR information obligations.
Harmonized DPIA model: the EDPB standardizes DPIAs
In line with this harmonization effort, the EDPB has adopted a European template for Data Protection Impact Assessments (DPIAs).
This standardized template aims to facilitate the structuring of DPIAs and strengthen the consistency of risk assessments among Member States. This is a significant step forward for DPOs and compliance teams who manage sensitive or high-risk processing operations, as they can now rely on a common, European-wide recognized framework.
CNIL: 2026 inspection priorities and enhanced support
The CNIL has detailed its priority areas for inspection in 2026, with a focus on:
- recruitment practices
- electoral data processing
- sports federations
These themes will guide several hundred audits and inspections planned for this year. Concerned organizations would be well-advised to anticipate these inspections by auditing their data processing operations in these areas.
In parallel, the CNIL's 2026 work program strengthens support for public and private stakeholders in their compliance with the GDPR and the AI Act (AIA), through dedicated resources and educational initiatives.
Tracking pixels in Emails: tThe CNIL's final recommendation
In April, the CNIL published a final recommendation on the use of tracking pixels in emails. This document clarifies two essential points:
- the applicable rules regarding information obligations stipulated by the GDPR
- the conditions under which prior consent is required for these tracking mechanisms
This recommendation serves as a new practical guideline for all organizations that send electronic communications incorporating recipient engagement metrics (open rates, clicks, etc.).
Email encryption on Gmail: a real step forward, but with conditions
Google recently rolled out end-to-end encryption options for Gmail mobile, marking a step forward for communication protection. However, this encryption remains subject to strict technical conditions, and its adoption is still limited at this stage.
This is a point of attention for privacy officers, who will need to adapt their internal policies and user explanations regarding the actual guarantees offered by this tool.
Digital Omnibus: the debate on GDPR fragmentation
While Europe's data economy is worth hundreds of billions of euros, voices are being raised against certain reforms perceived as weakening fundamental GDPR safeguards. The debate surrounding the Digital Omnibus illustrates the persistent tensions between regulatory simplification and the protection of fundamental data subject rights.
A matter to watch closely for data protection professionals, whose practices could be impacted depending on the outcome of these negotiations.
CJEU: when an access request becomes abusive
A recent decision by the Court of Justice of the European Union (CJEU) sheds important light on the management of GDPR access requests: a request can be deemed excessive or abusive if its purpose is not the protection of personal data, but rather a strategic exploitation of the regulatory framework.
A new area to watch for DPOs, who now have legal precedent to handle this type of request.
To learn more about these topics, find our analyses and resources on the Adequacy blog.
FAQ - GDPR news from April 2026
What is the EDPB's 2026 CEF?
The 2026 CEF (Coordinated Enforcement Framework) is a coordinated action launched by the EDPB, bringing together 25 national data protection authorities. Its objective is to examine the transparency of GDPR processing, particularly the quality of information notices and privacy policies.
What is a harmonized DPIA template adopted by the EDPB?
It is a standardized European template for conducting Data Protection Impact Assessments (DPIA). It aims to standardize the structure of risk assessments among EU Member States and facilitate the work of DPOs.
What are the CNIL's audit priorities for 2026?
In 2026, the CNIL has targeted recruitment practices, electoral data processing, and sports federations. These areas guide several hundred audits and inspections planned for this year.
Are tracking pixels in emails allowed by the GDPR?
According to the CNIL's final recommendation published in April 2026, the use of tracking pixels in emails is governed by the GDPR and requires compliance with information obligations, as well as, in some cases, obtaining prior consent from recipients.
Can a GDPR access request be refused?
Yes. The CJEU has confirmed that an access request can be deemed excessive or abusive if its purpose is not the protection of personal data but rather a strategic exploitation of the GDPR. DPOs can then refuse or charge for processing such requests.
What is the Digital Omnibus in relation to GDPR?
The Digital Omnibus is a European legislative project aimed at simplifying certain regulatory obligations. It is the subject of debate between proponents of simplification and defenders of fundamental rights, with some believing it could weaken essential GDPR safeguards.

%20RGPD%20efficace%20.png)
