What Was the Article 29 Working Party?
The Article 29 Working Party (WP29) shaped EU data protection law for over two decades. Learn what it was, how it worked, why it was replaced by the EDPB under the GDPR, and why its influential opinions and guidelines remain relevant to understanding European data protection law today.
Key Points: (1) WP29 was the EU’s independent data protection advisory body under Directive 95/46/EC. (2) It brought together national DPAs, the EDPS and European Commission. (3) It issued influential opinions, guidelines and recommendations on data protection law. (4) It was replaced by the EDPB on May 25, 2018, when the GDPR became applicable. (5) Many WP29 guidelines remain relevant because they were endorsed by the EDPB.
The Article 29 Working Party (Art. 29 WP or WP29)—formally known as the Working Party on the Protection of Individuals with regard to the Processing of Personal Data—was the European Union’s independent advisory body on data protection under the Data Protection Directive (Directive 95/46/EC).
The Working Party took its familiar name from Article 29 of the Data Protection Directive, which established the body and set out its composition. It began its work in 1996 and became one of the most influential institutions in the development and interpretation of European data protection law before the adoption of the GDPR.
WP29 was replaced by the European Data Protection Board (EDPB) on 25 May 2018 in accordance with the GDPR (Regulation (EU) 2016/679)
When researching a GDPR issue, it is therefore common to encounter documents identified by references such as “WP29,” “Article 29 Working Party,” “Article 29 WP,” or a numbered “WP” document.
Practical research tip: When relying on an Article 29 Working Party document today, check whether the EDPB endorsed it and whether the EDPB has subsequently updated, supplemented or replaced the guidance.
What Did the Article 29 Working Party Do?
The Article 29 Working Party played an important role in promoting a consistent interpretation of European data protection law. Among other things, it:
- provided expert advice on data protection matters;
- promoted consistent application of the Data Protection Directive across the EU;
- issued opinions on European legislative and regulatory proposals affecting the protection of personal data;
- adopted opinions, recommendations, working documents and guidelines interpreting important data protection concepts; and
- provided guidance to regulators, organizations and the public on issues involving the processing of personal data.
Over more than two decades, WP29 addressed subjects that remain central to data protection compliance today, including consent, transparency, data controllers and processors, data protection officers, data breach notification, profiling, international data transfers, legitimate interests and data protection impact assessments.
Why Does WP29 Still Matter Under the GDPR?
The Article 29 Working Party ceased to exist when the GDPR became applicable on May 25, 2018. It was replaced by the European Data Protection Board (EDPB), established under Articles 68–76 GDPR.
The transition, however, did not make WP29's work irrelevant.
Many of the Working Party's most important guidelines were endorsed by the EDPB after the GDPR became applicable, and some have subsequently been revised, supplemented or replaced by EDPB guidance. As a result, WP29 documents continue to appear frequently in regulatory guidance, academic commentary, compliance materials and discussions of European data protection law.
Specifically, during its first plenary meeting the EDPB endorsed the GDPR related WP29 Guidelines:
- Guidelines on consent under Regulation 2016/679, WP259 rev.01
superseded by Guidelines 05/2020 on consent under Regulation 2016/679 - Guidelines on transparency under Regulation 2016/679, WP260 rev.01
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679, WP251rev.01
- Guidelines on Personal data breach notification under Regulation 2016/679, WP250 rev.01 superseded by Guidelines 9/2022 on personal data breach notification under GDPR
- Guidelines on the right to data portability under Regulation 2016/679, WP242 rev.01
- Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is "likely to result in a high risk" for the purposes of Regulation 2016/679, WP248 rev.01
- Guidelines on Data Protection Officers ('DPO'), WP243 rev.01
- Guidelines for identifying a controller or processor's lead supervisory authority, WP244 rev.01 superseded by Guidelines 8/2022 on identifying a controller or processor’s lead supervisory authority
- Position Paper on the derogations from the obligation to maintain records of processing activities pursuant to Article 30(5) GDPR
- Working Document Setting Forth a Co-Operation Procedure for the approval of “Binding Corporate Rules” for controllers and processors under the GDPR, WP 263 rev.01 superseded by EDPB Document Setting Forth a Co-Operation procedure for the approval of Binding Corporate Rules for controllers and processors
- Recommendation on the Standard Application for Approval of Controller Binding Corporate Rules for the Transfer of Personal Data, WP 264 superseded by Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)
- Recommendation on the Standard Application form for Approval of Processor Binding Corporate Rules for the Transfer of Personal Data, WP 265
- Working Document setting up a table with the elements and principles to be found in Binding Corporate Rules, WP 256 rev.01 superseded by Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)
- Working Document setting up a table with the elements and principles to be found in Processor Binding Corporate Rules, WP 257 rev.01
- Adequacy Referential, WP 254 rev.01
- Guidelines on the application and setting of administrative fines for the purposes of the Regulation 2016/679, WP 253
From WP29 to the EDPB
The change from the Article 29 Working Party to the European Data Protection Board reflected a broader transformation in EU data protection law.
Understanding WP29 is important not merely as a matter of history. Its opinions and guidelines helped develop many of the interpretations and compliance concepts that continue to shape the GDPR framework today.
WP29 operated principally as an independent advisory body under the Data Protection Directive. The GDPR gave its successor a stronger institutional position. The EDPB is an independent EU body with legal personality and plays a central role in ensuring the consistent application of the GDPR across the European Economic Area.
