Changes between two versions
What changed between the draft committee report and the plenary report
From · draft committee report· 17 Dec 2024
on discharge in respect of the implementation of the general budget of the European Union for the financial year 2023, Section IX – European Data Protection Supervisor
To · plenary report· 1 Apr 2025
on discharge in respect of the implementation of the general budget of the European Union for the financial year 2023, Section IX – European Data Protection Supervisor
AI:What changed, in short
Adds calls for the EDPS to avoid inadmissible legal actions, cooperate with institutions, and finalise investigations on time.91214 Adds concerns about mission costs and transparency, urging assessment and use of video-conferencing.10 Adds calls for gender parity, geographical balance, and mandatory ethics training in HR section.1617 Adds calls for transparency on conflicts of interest, Transparency Register membership, and cybersecurity reporting.19212324 Adds calls for EMAS adoption and cooperation on fraud detection, plus notes on OLAF and minors' data.18222728
16 changes of substance · 2 formal · 10 of wording only
Written by AI from the two texts only · read the changes before relying on it · 4 Sept 2026 · Report a problem
+18 added · −8 removed · 20 changed paragraphs, packaging included.
Part 3 of 3: Paragraphs 82–110
Change 20
Changed:32.38. Notes with satisfaction from the Questionnaire that no cases of conflicts of interest, whistleblowing or fraud were reported in the EDPS in 2023; notes that the EDPS has set up a framework to prevent conflicts of interest at the level of senior management and staff through codes of conduct, awareness raising and declarations of absence of conflicts of interest and confidentiality; notes that, in addition to the mandatory introduction to the ethical framework of the EDPS for all new members of staff, new members of staff are also introduced to the EDPS’ anti-fraud strategy;
39. Notes from the Questionnaire that the EDPS has internal rules on whistleblowing, which define safe routes and channels through which staff may raise concerns about fraud, corruption or any other serious wrongdoing, without prejudice to the confidentiality of the identity of the whistleblower and of the information reported; notes that, so far, there has never been a whistleblowing case reported to the EDPS;
Change 21
Added:40. Urges the EDPS to publicly disclose any recusals due to conflicts of interest in its enforcement decisions, ensuring full transparency in regulatory oversight and decision-making;
4 unchanged paragraphs
Digitalisation, cybersecurity and data protection
41. Notes from the Questionnaire that the 2023 budget for IT equipment and projects was 9,5 % lower compared to 2022; notes that that decrease was primarily because no new IT feasibility studies were being commissioned in 2023, as opposed to 2022 where such studies represented a substantial portion of the IT budget; notes further that other cost elements remain relatively stable between the two years, including general IT services and maintenance;
42. Notes from the Follow-up Report and the Questionnaire the conclusions of the IT feasibility study carried out in 2022, whereby there are gaps between what the IT tools and services provided by the Commission and Parliament can offer and the specific needs of the EDPS; notes that those gaps should be addressed by developing in-house capabilities and applications for which a minimum of five IT staff and partial outsourcing EDPS was deemed necessary; regrets that, due to budgetary constraints, implementation of the recommendations of the study remained on hold; calls on the EDPS to consider a step-by-step approach by starting with those recommendations and projects that would require fewer resources;
43. Commends the progress made in 2023 by the EDPS in digitalising its workflows and processes, with the introduction of ARES, the qualified digital signature (e-IDAS) and a collaborative platform (Nextcloud) for drafting documents and video-conferencing, as well as updates to the tool (Website Evidence Collector) that automates the collection of personal data processing on websites of data controllers and processors, the adoption of the acceptance environment of EU Send Web, a service/channel to exchange sensitive non-classified information with other EUIBAs and further progress made towards implementing services that cannot be outsourced, such as the form and the electronic workflow to manage data breach notifications; notes nevertheless issues with regard to the use and maintenance of the e-procurement system;
Change 22
Added:44. Welcomes the EDPS's focus on ensuring that external contractors meet the necessary moral and ethical standards expected of all Union institutions, bodies, offices and agencies, particularly in light of the previous use of external companies by EDPS that, according to Yale University's ranking, continue to operate in Russia;
45. Acknowledges that the EDPS successfully relies on many of the administrative systems used by the Commission, particularly in the field of HR and business administration processes, as well as on some of Parliament’s services, including the provision of laptops, network infrastructure and video-conferencing; commends the fact that the project to improve the quality and performance of the computers provided to EDPS staff, in collaboration with Parliament, with a view to the generalisation of hybrid work, has been completed;
Change 23
Changed:38.46. Acknowledges the leading role of EDPS in enhancing the cybersecurity preparedness of the Union institutions, while working closely with bodies such as European Union Agency for Cybersecurity (ENISA) and cybersecurity hubs such as CERT-EU; urges it to develop a structured audit framework for cybersecurity risks within Union bodies; notes that, in 2023, the EDPS continued to improve its readiness to protect personal data and sensitive information against cyber-attacks in view of the rapidly changing cybersecurity threat landscape; commends in that context the EDPS for reviewing its security policies and methodologies in preparation for the impact of the Cybersecurity Regulation (Regulation (EU, Euratom) 2023/2841); notes from the Questionnaire that the EDPS introduced a request for two additional full-time equivalents to cover cybersecurity infrastructure in connection with EDPS’s obligations under that Regulation as well as the EDPS’ role as a member of the Interinstitutional Cybersecurity Board (IICB); notes further with appreciation that the EPDS upgraded its Information Security Policy and the EDPS Acceptable Use Policy to address specific cybersecurity threats in relation to teleworking, use of personal mobile devices and banning of dangerous applications (TikTok); notes that the EDPS did not encounter any cyber-attacks in 2023; calls for annual public reporting on detected threats, response measures, and institutional cyber resilience;
Change 24
Changed:39.47. Commends the EDPS for updating cybersecurity training for all staff and revamping the security training model for newcomers; appreciates that the EPDS has been proactive in raising awareness about cyber security risks, for instance by preparing fact sheets, conducting surveys with EUIBAs and running awareness campaigns; encourages the EDPS to ensure that staff receives compulsory training on the safe and ethical use of AI tools to enhance their understanding and mitigate potential risks;
Buildings
Change 25
Changed:40.48. Notes that,that in 2023, as in 2022, the EDPS and EDPB were the sole tenants of Parliament’s building where they were located, following the move of the Ombudsman at the end of 2021 and that by renting their premises from the Parliament rather than the private market the EDPS intends to keep the rental and maintenance costs at a reasonable level; notes that the EDPS had to request an additional EUR 81 856,84 for paying rental costs to Parliament, given that the indexation rate was 8,82 % and thus higher than the 2 % ceiling for administrative expenditures;
49. Notes that, in terms of accessibility of its building, the EDPS relies on the decisions taken and implemented by Parliament, as part of their building policy; notes from the Follow-up Report that the EDPS employs staff with physical impairments due to serious illness; welcomes the commitment of the EDPS to explore the possibilities of hiring trainees with reduced mobility or disabilities;
Environment and sustainability
Change 26
Changed:42.50. Notes that the EDPS has not joined the Eco-Management and Audit Scheme (EMAS) but has implemented several measures to reduce its environmental footprint, such as regulating the temperature automatically and centrally, turning lights off automatically when there is no movement in the room, purchasing eco-friendly products and services and automating the workflows with the introduction of ARES; notes from the Follow-up Report that according to the information received by Parliament’s Directorate-General for Infrastructure and Logistics, responsible for the management of the building rented by the EDPS, solar panels are installed on that building; asks the EDPS to inform the discharge authority to report on the share (%) of the solar-panel produced electricity in the EDPS’ total energy consumption needs per year; calls further on the EDPS to inform the discharge authority of any new developments regarding the EMAS certification process;
51. Notes that the EPDS has not assessed its carbon footprint in 2023; welcomes, however, that the EDPS continues to apply measures that reduce the carbon footprint by reducing the travel of journey to the office through teleworking possibilities, reimbursing 50 % of staff’s monthly/annual subscriptions for the use of public transport, encouraging the staff to favour videoconferencing and train travel for short distances, managing the cycle for invoices electronically and achieving an entirely paperless selection procedure and appraisal exercise as regards HR;
Change 27
Added:52. Urges the EDPS to adopt the EMAS to systematically monitor and improve its environmental footprint, particularly in terms of energy consumption, waste reduction, and sustainable office policies;
4 unchanged paragraphs
53. Notes that the EDPS addresses sustainability-related risks (such as environmental, social and governance risks) in a comprehensive way through an annual risk assessment exercise; welcomes in that context that the EDPS adopted its new risk management process in 2023, which should help the EDPS to target and better analyse those risks and consequently better calibrate mitigating actions;
Interinstitutional cooperation
54. Welcomes the budgetary and administrative savings achieved by the EDPS through inter-institutional cooperation, particularly the conclusion of service-level agreements with Parliament for the rental of its premises and the use of IT system applications, hardware supplies and maintenance and with the Commission for HR and business administration processes, as well as through participation in large interinstitutional framework contracts in areas such as IT consultancy, interim services and office supplies; commends in addition the EDPS for maintaining a structured cooperation with the Ombudsman, the Agency for Fundamental Rights and CERT-EU through memorandums of understanding;
55. Notes that the EDPS participates in meetings of various interinstitutional bodies; welcomes in this context the participation of the EPDS in meetings of the Heads of Administration and the Interinstitutional Online Communication Committee, led by Parliament’s Directorate-General for Communication; acknowledges that interinstitutional cooperation with EDPS, in his supervisory role, is of key importance for the other Union institutions to enhance their level of compliance with the data protection legal framework;
Change 28
Added:56. Calls for closer cooperation between the EDPS, the Court of Auditors, OLAF, and the European Public Prosecutor’s Office (EPPO) to develop common protocols for fraud detection in digital data and financial transactions within EU institutions; stresses the need for joint audits on AI-based fraud risks;
6 unchanged paragraphs
57. Welcomes the pivotal role played by the EDPS in 2023 in the coordination of the Data Protection Authorities of the Member States (DPAs) to promote consistent data protection across the Union; notes that the EDPS joined 26 DPAs in a coordinated enforcement action on the role and tasks of data protection officers (DPOs), assessing their compliance with Regulation (EU) 2018/1725; notes the continued active involvement of the EPDS in the Coordinated Supervision Committee (CSC) within the area of FSJ addressing issues such as handling complaints against Europol and enhancing cooperation processes; appreciates furthermore all the other steps taken to improve cooperation between the EDPS and the DPAs such as the conduction of a joint Europol inspection with national authorities (Poland and Lithuania) and the participation in the coordinated supervisory action on processing minors' data in Europol systems, the participation in an operational visit to the European Delegated Prosecutor’s office in Lisbon under a Working Arrangement with Portugal's DPA and the coordination of an onsite inspection in Lesvos with Greece’s DPA to verify data collection practices during Joint Operations by Frontex; acknowledges that those interinstitutional engagements help the EDPS align with best practices of Union institutions and benefit from the exchange of information with peer departments;
Communication
58. Notes that the budget for public communication and promotional activities in 2023 amounted to EUR 468 000, which represented an increase of 54 % compared to 2022;
59. Notes with satisfaction that the EDPS organised several communication events online as well as in person in 2023, aimed at raising awareness of EDPS’ role and mission among a wider public and the importance of respecting Union data protection rules, such as Data Protection Day, the EDPS Trainees’ conference (twice a year), the EDPS Seminar on the essence of the fundamental rights to privacy and data protection, and other international events;
60. Notes that the EDPS communicates online via its website and its social media accounts on X (ex-twitter) (29 400 followers), LinkedIn (71 000 followers), YouTube (2 900 followers), EU-Voice (5 900 followers) and EU-Video (750 followers);
61. Notes that the pilot project of the platforms EU Voice and EU Video (free and open-source social media networks, privacy-oriented and based on Mastodon and PeerTube software) continued in 2023; welcomes in that context the EDPS’ contribution to the Union's strategy on data and digital sovereignty in order to promote the Union's independence in the digital world and compliance with the data protection legal framework.