On August 17, 2026, the European Commission opened a call for evidence on the application and functioning of Directive (EU) 2016/680, the Law Enforcement Directive (LED), across the European Union. Feedback runs until September 28, 2026 (midnight Brussels time). The planned output is a Commission Communication reporting how Member States have implemented and applied the LED eight years after it entered into application, with adoption targeted for the third quarter of 2026.
This is not a new binding obligation. It is the statutory evaluation window that can set the agenda for later reform of police and criminal-justice personal-data rules, cross-border sharing practices, and the compliance machinery competent authorities and their processors actually run.
What exactly is the Commission evaluating, and what is not yet on the table?
The initiative covers EU rules that regulate personal-data processing by law enforcement and criminal justice authorities for prevention, investigation, detection, or prosecution of criminal offences, and related judicial activities. The Commission asks how those rules have been transposed and used in practice, and whether they still deliver both a high level of protection and workable EU-wide data sharing.
The act type is a Communication, reference Ares(2026)7936373 on the Have Your Say dossier. No amending directive or regulation is proposed in this step. Stakeholders should treat the call as the evidence base for a forthcoming evaluation report, not as a draft legal text. Continuous, per-jurisdiction real-time monitoring surfaces this kind of Commission consultation the moment the portal opens, before the feedback window closes.
The LED itself remains the binding baseline: Directive (EU) 2016/680 still governs competent authorities and entities processing on their behalf for law-enforcement purposes, in parallel with the GDPR for other processing.
Who should respond by September 28, 2026?
Priority respondents are data protection officers and governance leads inside police, prosecution, and criminal-court authorities, plus private processors and technology vendors that design, host, or operate law-enforcement case-management, biometrics, analytics, or cross-border exchange systems for those authorities.
Member State supervisory authorities with LED competence, criminal-justice data-sharing hubs, and EU-level justice and home-affairs stakeholders also have a direct interest: the Communication will record how harmonised (or fragmented) national practice looks eight years on. Commercial actors that only process under the GDPR for commercial purposes are out of the LED's core scope, but vendors selling into competent authorities should still track whether the evaluation flags gaps that later become legislative proposals.
What should compliance teams do before the deadline?
Map every processing activity that relies on national LED transposition, including joint controllers, processors, and cross-border transfers or exchanges with other Member State authorities. Document where national practice diverges from the directive's expectations on purpose limitation, data quality, retention, logging, and data-subject rights adapted to the law-enforcement context.
File concrete, evidence-backed feedback on the Commission portal before September 28, 2026: operational friction in cross-border sharing, uneven transposition, or protection gaps that create legal risk for authorities and their vendors. Align internal briefing packs so privacy, legal, and product teams share one narrative of LED exposure before the Communication lands in Q3 2026.
| Milestone | Date / window | What it means for practitioners |
|---|---|---|
| Call for evidence opens | August 17, 2026 | Stakeholder input window starts on Have Your Say initiative 18372 |
| Feedback closes | September 28, 2026 (midnight Brussels) | Last day to lodge evidence that can shape the evaluation report |
| Commission adoption (planned) | Third quarter 2026 | Communication on LED application; watch for follow-on reform signals |
How does this sit next to GDPR and the Digital Omnibus track?
The LED is the specialised regime for criminal-law personal data; the GDPR covers other personal-data processing. Controllers that wear both hats (for example, a ministry that runs administrative GDPR processing and LED operational systems) must keep the two regimes distinct in policies, DPIAs, and vendor contracts.
This evaluation is separate from the Digital Omnibus data strand that targets GDPR, ePrivacy, NIS2, DORA, and Data Act simplification. Do not fold LED comments into Omnibus cookie or GDPR burden narratives: the Commission has opened a distinct dossier for law-enforcement data protection, and feedback on initiative 18372 should stay on LED transposition, operational sharing, and protection outcomes.
Take advantage of this real-time watch
Next steps: confirm whether your organisation processes under national LED rules or as a processor for a competent authority; calendar the September 28, 2026 close; and brief counsel and product owners on gaps you want the Communication to record. Obsidian keeps the LED evaluation and any later reform signals on the same monitored thread so teams act on the portal date, not on secondary coverage.


