European Union · Regulation (EU) 2018/1725

The GDPR that applies to the institutions themselves

For EU institutions, bodies, offices, and agencies — AccessPoint runs the Articles 17–20 data subject rights on the one-month clock, Article 25 restrictions grounded in internal rules, 72-hour EDPS breach notification, and Article 39 data protection impact assessments.

European Union — Institutions (2018/1725) at a glance

Rights deadline
One month, extendable by two further months where justified by complexity or volume
Restrictions
Art. 25 — available only where internal rules provide for them
Breach
72 hours to the EDPS; communication to data subjects where the risk is high
DPIA
Art. 39, before processing likely to result in a high risk
Oversight
European Data Protection Supervisor
Languages
English, French

Built for European Union — Institutions (2018/1725)

One platform for the whole access-and-privacy mandate, pre-configured for this regime and running in your own Microsoft 365 tenant.

Articles 17–20 rights

Access, rectification, erasure, and restriction run on the one-month clock with the two-month extension where complexity or volume justifies it, and the justification recorded rather than assumed.

Article 25 restrictions

An institution may restrict rights only where it has adopted internal rules providing for it. AccessPoint links each restriction to the internal rule relied on, so a restriction is traceable to its legal basis instead of asserted.

72-hour EDPS notification

Log a personal data breach, assess the risk, and work the notification to the EDPS and, where the risk is high, communication to the data subjects — on a live checklist against the clock.

Article 39 DPIAs

Run data protection impact assessments as full cases before high-risk processing begins, with risks, mitigations, DPO involvement, and a dated sign-off.

The DPO in the workflow

The Regulation gives the data protection officer a defined role. Route assessments, restrictions, and breach decisions through the DPO as a tracked step with a recorded opinion.

In your own tenant

Personal data stays inside the institution's own Microsoft 365 and Azure tenant, under its own controls — no third-party cloud and no vendor access.

Two regimes, one institution

An EU body owes documents under 1049/2001 and personal data under 2018/1725 — often on the same file.

The two obligations arrive together far more often than either regime's guidance suggests. A request for documents under Regulation 1049/2001 turns up personal data that must be assessed before release; a subject access request under 2018/1725 turns up documents whose disclosure is governed by the access regime. Institutions running the two in separate systems end up making inconsistent decisions about the same material, and discovering it when a complaint reaches the Ombudsman or the EDPS. AccessPoint runs both packs in one tenant on one audit ledger, so the same document assessed twice is assessed consistently — and the record shows it was.

One ledger, both regimes Access and data protection decisions on the same record.
The one-month clock Computed with its extension justified, not assumed.
Restrictions traced Each Art. 25 restriction linked to its internal rule.

Configured out of the box

Installing the eu-edps-1725 jurisdiction pack seeds your tenant with everything this regime needs — a starting point you can adjust, not a lock-in.

Related guide: FOI Workflow Quick Check
  • Regulation (EU) 2018/1725 as the legal-authority spine
  • The Articles 17–20 rights on the one-month clock with the two-month extension and its justification
  • Article 25 restrictions linked to the institution's adopted internal rules
  • 72-hour EDPS breach notification and high-risk communication to data subjects
  • Article 39 data protection impact assessments with DPO involvement and sign-off
  • Records of processing operations and the DPO's register
  • EDPS complaint and investigation tracking with grounds and outcomes
  • Bilingual correspondence templates carrying the Regulation's wording

European Union — Institutions (2018/1725) Questions

How does 2018/1725 differ from the GDPR?

It is the equivalent regime for the EU's own institutions, bodies, offices, and agencies rather than for controllers in the member states. The structure closely tracks the GDPR, but the supervisory authority is the EDPS, restrictions on rights operate through Article 25 internal rules rather than member-state law, and the surrounding obligations are framed for Union administration.

Can we run it alongside the institutions access regime?

Yes, and most institutions should. AccessPoint ships a separate pack for public access to documents under Regulation 1049/2001, and the two run in one tenant on one audit ledger — which is what keeps decisions about the same document consistent across the two regimes.

How are Article 25 restrictions handled?

Each restriction is linked to the internal rule the institution has adopted to provide for it, and the reason is recorded against the specific information restricted. Because Article 25 makes the internal rule a precondition, tying the two together in the record is what makes a restriction defensible before the EDPS.

Where does personal data reside?

Entirely within the institution's own Microsoft 365 and Azure tenant, in the region you choose. Requests, records, assessments, and audit history never leave your control — no third-party cloud and no vendor access.

Run Regulation 2018/1725 in Your Own Tenant

Try AccessPoint free for 30 days, configured for EU institutions. No credit card required.

Start Free Trial