Skip to content
Topic Actively litigated

Scientific Panel Independence

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

A specific topic is needed to address the independence and impartiality requirements that are critical for scientific panels to maintain credibility and objectivity in their advisory role.

71 linked items 2 Laws8 Case Law35 Guidance15 Enforcement8 News

Overview

19 sources · Jul 23, 2026

Legal Framework

The independence and impartiality of scientific advisory panels is anchored in several interlocking provisions. Under the DSA, Recital 92 establishes that verification by independent experts is a structural requirement for accountability of very large online platforms and very large search engines, mandating independent auditing of compliance obligations. Recital 59 extends the independence requirement to out-of-court dispute settlement bodies, specifying that independence must be ensured not only at the institutional level but also at the level of the natural persons entrusted with resolving disputes, including through explicit rules on conflicts of interest. These provisions reflect a layered design: institutional autonomy from the entities being assessed, coupled with individual-level safeguards against financial, professional, or relational conflicts that could compromise objective judgment.

The conflict-of-interest dimension is further informed by procurement principles articulated in Dutch case law, particularly Article 2.87(1)(e) jo. 1.10b of the Aanbestedingswet 2012, which mandates exclusion of contractors where a conflict of interest cannot be resolved. The underlying rationale is that advisory credibility depends on both structural separation and demonstrable absence of conflicting interests at the decision-making level.

Key Developments

The Gerechtshof Den Haag's June 2026 ruling in the RET/RMC matter (cases 200.361.266/01, 200.361.440/01, and 200.361.896/01) provides a concrete threshold for assessing conflict-of-interest claims. The court applied the Xafax framework, which establishes that contracts between contracting authorities and contractors can be challenged on appeal only where nullity arises under Article 3:40 BW — specifically, conflict with public order — and not merely on procurement-law grounds. The court examined whether an alleged prohibited state aid transaction (a share transfer at below-market price) created a conflict of interest warranting exclusion under Article 2.87(1)(e) Aw 2012, ultimately finding the evidence insufficient to establish that the transaction influenced the procurement procedure's pricing or outcome.

The court's reasoning establishes a materiality standard: a conflict of interest must be shown to have actually influenced, or created a real risk of influencing, the decision at issue. Speculative or unsubstantiated conflict claims do not meet this threshold. The burden rests on the party asserting the conflict to demonstrate a concrete nexus between the conflicting interest and the compromised process.

The EDPB's guidance on accreditation of certification bodies reinforces this standard at the EU level, requiring that certifying entities demonstrate structural and operational independence from the bodies they assess.

Practical Guidance

  • Establish written conflict-of-interest declarations for every panel member, covering direct and indirect financial interests, professional relationships, and prior engagements with the entity under review, consistent with the individual-level independence requirement articulated in DSA Recital 59.

  • Implement a documented screening procedure at the appointment stage that assesses whether any identified conflict creates a material risk of influence on the panel's advisory output, applying the materiality threshold from the Gerechtshof Den Haag RET/RMC ruling.

  • Maintain structural separation between the scientific panel and the entity being audited or assessed, ensuring that funding, staffing, and operational reporting lines do not create dependencies that would undermine the institutional independence required under DSA Recital 92.

  • Where a conflict is identified that cannot be mitigated through recusal or Chinese-wall procedures, exclude the affected member or entity entirely, consistent with the exclusion standard under Article 2.87(1)(e) jo. 1.10b Aw 2012 and the nullity principles of Article 3:40 BW.

  • Document the independence assessment process contemporaneously, including the rationale for any decision to retain a member despite an identified potential conflict, to create an evidentiary record that demonstrates compliance with the materiality standard if challenged.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 2
Art. 28(3) Notifying authorities shall be established, organised and operated in such a way that no conflict of interest arises with conformity assessment bodies… AI Act Art. 19(8) Member States shall ensure that any risk of conflict of interest concerning the designated cybersecurity experts is revealed to the other Member State… NIS2 rec 92 Recital 92 — independent compliance audits for very large online platforms DSA Oct 2022 rec 59 Recital 59 — certified out-of-court dispute settlement DSA Oct 2022
Case Law 8
¶277 That being so, it may be justified for a judge who has not recused him or herself and who is the subject of an application for recusal made by a party… Judgment of the Court (Grand Chamber) of 5 June 2023.#European Commission v Republic of Poland.#Failure of a Member State to fulfil obligations – Second subparagraph of Article 19(1) TEU – Article 47 of the Charter of Fundamental Rights of the European Union ‐ Rule of law – Effective legal protection in the fields covered by EU law – Independence of judges – Article 267 TFEU – Possibility of making a reference to the Court for a preliminary ruling – Primacy of EU law – Jurisdiction in relation t ¶149 In those circumstances, the applicant is incorrect in calling into question OLAF’s independence in suspecting the Commission of being subject to a con… Judgment of the General Court (Fourth Chamber) of 20 July 2016 (Extracts).#Athanassios Oikonomopoulos v European Commission.#Non-contractual liability — Damage caused by the Commission in the context of an OLAF investigation and by OLAF — Actions for damages — Action for a declaration that certain measures taken by OLAF were void and inadmissible for evidentiary purposes before the national authorities — Admissibility — Misuse of powers — Processing of personal data — Rights of the defence.#Case ¶11 Article 16 of Law 2/2011 stated as follows: ‘The President and the members of the board shall cease to perform their duties: (a) if they resign; (b) o… Judgment of the Court (Second Chamber) of 19 October 2016.#Xabier Ormaetxea Garai and Bernardo Lorenzo Almendros v Administración del Estado.#Request for a preliminary ruling from the Tribunal Supremo.#Reference for a preliminary ruling — Electronic communications networks and services — Directive 2002/21/EC — Article 3 — Impartiality and independence of national regulatory authorities — Institutional reform — Merger of national regulatory authority with other regulatory authorities — Dismissal ¶8 Since the Law of 1992 was silent as regards the duration or the ending of the Supervisor’s term in office, Law LIX of 1993 on the Parliamentary Commis… Judgment of the Court (Grand Chamber), 8 April 2014.#European Commission v Hungary.#Failure of a Member State to fulfil obligations — Directive 95/46/EC — Protection of individuals with regard to the processing of personal data and the free movement of such data — Article 28(1) — National supervisory authorities — Independence — National legislation prematurely bringing to an end the term served by the supervisory authority — Creation of a new supervisory authority and appointment of another per 288/12 Judgment of the Court (Grand Chamber), 8 April 2014.#European Commission v Hungary.#Failure of a Member State to fulfil obligations — Directive 95/46/EC — Protection of individuals with regard to the processing of personal data and the free movement of such data — Article 28(1) — National supervisory authorities — Independence — National legislation prematurely bringing to an end the term served by the supervisory authority — Creation of a new supervisory authority and appointment of another per Court of Justice of the European Union Apr 2014 424/15 Judgment of the Court (Second Chamber) of 19 October 2016.#Xabier Ormaetxea Garai and Bernardo Lorenzo Almendros v Administración del Estado.#Request for a preliminary ruling from the Tribunal Supremo.#Reference for a preliminary ruling — Electronic communications networks and services — Directive 2002/21/EC — Article 3 — Impartiality and independence of national regulatory authorities — Institutional reform — Merger of national regulatory authority with other regulatory authorities — Dismissal Court of Justice of the European Union Oct 2016 579/21 Judgment of the Court (First Chamber) of 22 June 2023.#Proceedings brought by J.M.#Request for a preliminary ruling from the Itä-Suomen hallinto-oikeus.#Reference for a preliminary ruling – Processing of personal data – Regulation (EU) 2016/679 – Articles 4 and 15 – Scope of the right of access to information referred to in Article 15 – Information contained in log data – Article 4 – Definition of ‘personal data’ – Definition of ‘recipients’ – Temporal application.#Case C-579/21. Court of Justice of the European Union Jun 2023 GDPRhub CJEU - C-288/12 - European Commission v Hungary GDPRhub Apr 2014 257/19 Judgment of the Court (Fifth Chamber) of 9 July 2020.#European Commission v Ireland.#Failure of a Member State to fulfil obligations — Principles governing the investigation of accidents in the maritime transport sector — Directive 2009/18/EC — Article 8(1) — Parties whose interests could conflict with the task entrusted to the investigative body — Members of the investigative body simultaneously performing other functions — Failure to provide for an independent investigative body.#Case C-257/19 Court of Justice of the European Union Jul 2020 Supreme Administrative Court of Finland Korkein hallinto-oikeus (Finland) - KHO:2021:125 Supreme Administrative Court of Finland Sep 2021 German Federal Administrative Court BVerwG - 6 C 1.24 German Federal Administrative Court Nov 2025 Municipal Civil Court in Zagreb OGS Zagreb - Pn-877/2023-29 Municipal Civil Court in Zagreb Jan 2026
Guidance 35
§19 In addition, a monitoring body in the EEA may subcontract its activities to an external entity outside the EEA, acting on its behalf, provided that su… Guidelines 04/2021 on Codes of Conduct as tools for transfers §28 Under i tem 5.2 of the Requirements, “ the certification body shall demonstrate to the accreditation body that it is independent in accordance with Ar… Opinion 13/2026 on the draft decision of the Office of the Data Protection Ombudsman (FI SA) regarding the approval of the requirement for accreditation of a certification body pursuant to Article 43(3) GDPR §23 With respect to section 4.2.3 of the SE SA’s accreditation requirements, the Board welcomes the explanations provided by the SE SA on how the impartia… Opinion 10/2024 on the draft decision of the competent supervisory authority of Sweden regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) §45 Regarding ‘general requirements for accreditation’, the Board recommends that the SE SA: 1) clarifies in the requirements clarify the terms “risk anal… Opinion 10/2024 on the draft decision of the competent supervisory authority of Sweden regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) 12023 on the draft decision of the competent Opinion 1/2023 on the draft decision of the competent supervisory authority of Croatia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR EDPB Feb 2023 92019 on the austrian data protection supervisory Opinion 9/2019 on the Austrian data protection supervisory authority draft accreditation requirements for a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2019 42018 on the accreditation of certification bodies under article 43 Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679) EDPB Dec 2018 032023 on the draft decision of the competent Opinion 03/2023 on the draft decision of the competent supervisory authority of Romania regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Feb 2023 162022 on the draft decision of the competent Opinion 16/2022 on the draft decision of the competent supervisory authority of Slovenia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2022 152022 on the draft decision of the competent Opinion 15/2022 on the draft decision of the competent supervisory authority of Luxembourg regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2022 232021 on the draft decision of the competent Opinion 23/2021 on the draft decision of the competent supervisory authority of Czech Republic regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2021 242021 on the draft decision of the competent Opinion 24/2021 on the draft decision of the competent supervisory authority of Slovakia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2021 102021 on the draft decision of the competent Opinion 10/2021 on the draft decision of the competent supervisory authority of Hungary regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Mar 2021 312020 on the draft decision of the competent Opinion 31/2020 on the draft decision of the competent supervisory authority of Poland regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Dec 2020 192020 on the draft decision of the competent Opinion 19/2020 on the draft decision of the competent supervisory authority of Denmark regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Aug 2020 182020 on the draft decision of the competent Opinion 18/2020 on the draft decision of the competent supervisory authority of the Netherlands regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2020 132020 on the the draft decision of the competent Opinion 13/2020 on the the draft decision of the competent supervisory authority of Italy regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB May 2020 112020 on the draft decision of the competent Opinion 11/2020 on the draft decision of the competent supervisory authority of Ireland regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB May 2020 112023 on the draft decision of the competent Opinion 11/2023 on the draft decision of the competent supervisory authority of Sweden regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2023 022023 on the draft decision of the competent Opinion 02/2023 on the draft decision of the competent supervisory authority of Latvia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR EDPB Feb 2023 142022 on the draft decision of the competent Opinion 14/2022 on the draft decision of the competent supervisory authority of Bulgaria regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2022 372021 on the draft decision of the competent Opinion 37/2021 on the draft decision of the competent supervisory authority of Malta regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Nov 2021 202020 on the draft decision of the competent Opinion 20/2020 on the draft decision of the competent supervisory authority of Greece regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2020 122020 on the draft decision of the competent Opinion 12/2020 on the draft decision of the competent supervisory authority of Finland regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB May 2020 Show 15 more →
Enforcement 15
DSB (Austria) Austrian DSB rules 360-degree feedback unlawful without specific works agreement DSB (Austria) Mar 2026 Austrian Data Protection Authority (dsb) Company: Lack of appointment of data protection officer Austrian Data Protection Authority (dsb) Oct 2024 APD/GBA (Belgium) Belgian DPA finds cookie banner without reject-all button and unequal withdrawal violates APD/GBA (Belgium) Oct 2024 Croatian Data Protection Authority (azop) Bedrijf: Onvoldoende juridische basis voor de verwerking van gegevens. Croatian Data Protection Authority (azop) Mar 2025 NL Estonian Data Protection Authority (AKI) Asper Biogene OÜ: Insufficient technical and organisational measures to ensure information security Estonian Data Protection Authority (AKI) Jan 2025 Croatian Data Protection Authority (azop) Company: Insufficient legal basis for data processing Croatian Data Protection Authority (azop) Mar 2025 Persónuvernd (Iceland) Persónuvernd (Iceland) - 2020061979 Persónuvernd (Iceland) Jun 2022 Croatian Data Protection Authority (azop) Hotel: Insufficient legal basis for data processing Croatian Data Protection Authority (azop) Sep 2023 Belgian Data Protection Authority (APD) Proximus SA: Insufficient involvement of data protection officer Belgian Data Protection Authority (APD) Apr 2020 Garante per la protezione dei dati personali (Italy) Garante per la protezione dei dati personali (Italy) - 9794895 Garante per la protezione dei dati personali (Italy) Jun 2022 Data Protection Authority of Berlin Clinic: Insufficient involvement of data protection officer Data Protection Authority of Berlin Jan 2021 Belgian Data Protection Authority (APD) Bank: Insufficient involvement of data protection officer Belgian Data Protection Authority (APD) Dec 2021 Data Protection Authority of Berlin Company: Insufficient involvement of data protection officer Data Protection Authority of Berlin Sep 2022 Italian Data Protection Authority (Garante) Conservatorio di Musica S. Cecilia di Roma: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) Nov 2022 Italian Data Protection Authority (Garante) Policoro municipality: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Aug 2022
News 8
GDPRhub De IJslandse toezichthouder heeft geoordeeld dat er sprake is van een belangenconflict wanneer een Functionaris Gegevensbescherming (FG) tegelijkertijd ook de hoofdjurist van een bedrijf is. GDPRhub Sep 2022 NL IAPP Can the roles of DPO and whistleblowing officer be merged? IAPP Mar 2023 GDPRhub Het Italiaanse bedrijf SA heeft juridische stappen ondernomen tegen een gemeente vanwege het gebruik van haar videosurveillance systeem en omdat het haar Functionaris Gegevensbescherming (FG) heeft aangesteld om de gemeente in een rechtszaak te vertegenwoordigen. GDPRhub Sep 2022 NL IAPP Berlin DPA imposes 525K euro fine over DPO violation IAPP Sep 2022 NL EU Court Expert EU-Hof: gegevens waaruit indirect de seksuele geaardheid van een persoon kan worden afgeleid vormen gevoelige gegevens in de zin van de AVG NL EU Court Expert Aug 2022 IAPP Kunnen organisaties efficiëntieverbeteringen realiseren door de functies van Data Protection Officer (DPO) en klokkenluider te combineren? IAPP Apr 2023 NL IAPP Berlijn, DPA: Boete van 525.000 euro opgelegd vanwege schending van de DPO-regels. IAPP Sep 2022 NL White Label Consultancy Data Protection Officer or Chief Privacy Officer?The rise of the Data Protection Officer White Label Consultancy Jan 2022
Literature 3
Journal of Computer Science and Technology Studies Event-Driven Compliance: Reconciling Privacy Regulation with Real-Time Advertising Infrastructure Journal of Computer Science and Technology Studies Nov 2025 Frontiers in Education The AI Act and the future of STEM education in Europe: rethinking pedagogy, assessment, and teacher agency Frontiers in Education Jul 2026 Journal of Ethics and Emerging Technologies The Magician’s Eye Journal of Ethics and Emerging Technologies Jul 2026