Changes between two versions
What changed between the draft committee report and the plenary report
From · draft committee report· 9 Nov 2023
on the proposal for a regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679
To · plenary report· 20 Feb 2024
on the proposal for a regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679
AI:What changed, in short
The versions differ mainly in substance: the new text adds detailed procedural rules on complaints, investigations, cooperation, and judicial remedies.1345 It introduces a nine-month deadline for draft decisions, with extensions, and a three-month deadline for non-contentious cases.4053 It strengthens the role of the Board in resolving procedural disputes and allows parties to seek judicial remedies against supervisory authorities.8687 It adds detailed rules on amicable settlements, ex officio procedures, and cooperation with other authorities.424357 The other changes are formal or wording: renumbering, typo fixes, and updates to cross-references.2141718
74 changes of substance · 26 formal · 0 of wording only · 2 smaller changes not described
Written by AI from the two texts only · read the changes before relying on it · 4 Sept 2026 · Report a problem
+127 added · −258 removed · 42 changed paragraphs, packaging included.
Part 10 of 10: EXPLANATORY STATEMENT
EXPLANATORY STATEMENT
13 unchanged paragraphs
Short Justification
Background
The General Data Protection Regulation seeks to harmonise the protection of fundamental rights and freedoms of natural persons in respect of processing of their data and to ensure the free flow of personal data between Member States. The Parliament has in the past expressed concerns with regard to “the uneven and sometimes non-existent enforcement of the GDPR by national [Data Protection Authorities] DPAs”. It underlined that lengthy procedures can produce an “adverse effect on effective enforcement and on citizens’ trust”, and, in particular for cross-border complaints, has suggested to establish “a common administrative procedure to handle complaints” to strengthen enforcement. The Commission proposal at hand for a GDPR Enforcement Procedures Regulation (GDPR-EPR) suggests to facilitate in particular cross-border cases. It also takes up demands of national DPAs to clarify and streamline cross-border procedures, as spelled out in the European Data Protection Board’s "Vienna Statement" from April 2022, the EDPB "Wish List" from October 2022, the European Data Protection Supervisor’s (EDPS) contribution from April 2023, and the EDPB-EDPS joint opinion on the Commission proposal from September 2023.
The Rapporteur’s Position
- The national procedural laws should continue to apply insofar as they are not in conflict with the GDPR-EPR, thereby ensuring more detailed rules such as on oral hearings continue to be valid, while national procedural standards are not lowered.
- The report consolidates and expands on the provisions on general procedural rules in a new Section 2 in Chapter I in order for the right to be heard, translations, confidentiality, and the sincere cooperation of authorities to always apply, not only in the case of complaints or for dispute resolution among authorities.
- The right to be heard is streamlined following Article 42(1) of the Charter on good administration, and applies to all parties of a case equally.
- A joint case file is introduced, containing all information relating to a case, and making them accessible to all parties and supervisory authorities, thus avoiding a back and forth of documents and ensuring all parties and authorities have the same, most current information, while internal deliberations of authorities and confidential information remain protected.
- In case new information or infringements are revealed over the course of an investigation, the scope of a case can be expanded.
- Amicable settlements are limited to cases of data subject rights, requiring the explicit agreement of the complainant, while not preventing ex-officio investigations of a supervisory authority for larger scale infringements of the GDPR.
- Deadlines and the respective roles and duties of a lead authority and other supervisory authorities are clarified, in particular with regard to procedures to draft a decision, to reach consensus, or to resolve disputes, including procedural determinations by the EDPB.
- A right to judicial remedies in case a competent supervisory authority does not act is introduced.
- The transition period of one year should allow for the necessary changes to the Internal Market Information System used by the authorities, and the Rules of Procedure of the Board, as well as possible amendments of national laws.