Skip to content
EU Parl Watch

amendment list, 27 July 2026

Amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557 as regards the simplification of the digital legislative framework, and repealing Regulations (EU) 2018/1807, (EU) 2019/1150, (EU) 2022/868, and Directive (EU) 2019/1024 (Digital Omnibus)

Document CJ72-AM-790968 · (COM(2025)0837 – 2025/0360(COD))

Committee on Industry, Research and Energy Committee on Civil Liberties, Justice and Home Affairs

On Parliament’s site PDF Word

Full text

Jump to an amendment (126)
Text 798 paragraphs

Amendment 401

Lena Düpont, Oliver Schenk

Proposal for a regulation

Recital 43

Text proposed by the CommissionAmendment
(43) In order to provide a strong and coherent data protection framework in the Union, the necessary adaptations of Directive (EU) 2016/680 and any other Union legal act applicable to such processing of personal data should follow after the adoption of this regulation, in order to allow for their application as close as possible to the entry into application of the amendments to Regulation (EU) 2016/679 and Regulation (EU) 2018/1725.(43) In order to provide a strong and coherent data protection framework in the Union, the necessary adaptations of Directive (EU) 2016/680 and any other Union legal act applicable to such processing of personal data should follow after the adoption of this regulation, in order to allow for their application as close as possible to the entry into application of the amendments to Regulation (EU) 2016/679 and Regulation (EU) 2018/1725. Any following adaption of Directive (EU) 2016/680 should not impair the ability of competent authorities to process personal data collected in the context of the prevention, investigation, detection or prosecution of specific criminal offences in order to develop an understanding of criminal activities and to make links between different criminal offences detected. Moreover, any concurrent adaptation of Regulation (EU) 2018/1725 shall not impair the processing of personal data for the purpose of preventing threats to public security, internal security of Union institutions and bodies, or other important objectives of general public interest of the Union or of a Member State, in particular the objectives of the Common Foreign and Security Policy of the Union or an important economic or financial interest of the Union or of a Member State.

Or. en

Amendment 402

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 a (new)

Text proposed by the CommissionAmendment
(43a) Article 7 of the Charter of Fundamental Rights of the European Union ("the Charter") protects the fundamental right of everyone to the respect for his or her private and family life, home and communications. Respect for the privacy of one’s communications is an essential dimension of this right. Confidentiality of electronic communications ensures that information exchanged between parties and the external elements of such communication, including when the information has been sent, from where, to whom, is not to be revealed to anyone other than to the parties involved in a communication. The principle of confidentiality should apply to current and future means of communication, including calls, internet access, instant messaging applications, e-mail, internet phone calls and personal messaging provided through social media. The confidentiality of electronic communications provided for by Article 7 of the Charter should be ensured and the information related to the terminal equipment of users accessing their publicly available websites and mobile applications should be protected.

Or. en

Read the rest (786 paragraphs)

Amendment 403

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 b (new)

Text proposed by the CommissionAmendment
(43b) The content of electronic communications pertains to the essence of the fundamental right to respect for private and family life, home and communications protected under Article 7 of the Charter. Any processing of content data of electronic communications should be allowed only under strictly defined conditions, for specific purposes and be subject to adequate safeguards against abuse. This Regulation provides for the possibility of providers of electronic communications services to process electronic communications data in transit, with the informed consent of all the users concerned. For example, providers may offer services that entail the scanning of emails to remove certain pre-defined material. Given the sensitivity of the content of communications, Regulation (EU)2016/679 sets forth a presumption that the processing of such content data will result in high risks to the rights and freedoms of natural persons. When processing such type of data, the provider of the electronic communications service should always carry out a data protection impact assessment and, if necessary, consult the supervisory authority prior to the processing. After electronic communications content has been sent by the user and received by the intended user or users, it may be recorded or stored by the user, users or by a third party entrusted by them to record or store such data, which could be the electronic communications service provider. Any processing of such stored communications data where the data is stored on behalf of the user must comply with Regulation (EU)2016/679.

Or. en

Amendment 404

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 c (new)

Text proposed by the CommissionAmendment
(43c) Interference with the confidentiality of metadata or interference with the protection of information stored in and related to users’ terminal equipment should only be considered to be lawful where it is strictly proportionate and necessary to protect an interest which is essential for the life of the data subject or that of another natural person. Such interference based on the vital interest of another natural person should take place only in a specific case and where the processing cannot be manifestly based on another legal basis.

Or. en

Amendment 405

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 d (new)

Text proposed by the CommissionAmendment
(43d) The processing of electronic communications data can be useful for businesses, consumers and society as a whole. However, users attach great importance to the confidentiality of their communications, including their online activities, and they want to control the use of electronic communications data for purposes other than conveying the communication. Regulation (EU)2016/679 should require providers of electronic communications services to obtain users' consent to process electronic communications metadata, which includes data on the location of the device generated for the purposes of granting and maintaining access and connection to the service. Where a type of processing of electronic communications metadata, in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, a data protection impact assessment and, as the case may be, a consultation of the supervisory authority should take place prior to the processing, in accordance with Articles 35 and 36.

Or. en

Amendment 406

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 e (new)

Text proposed by the CommissionAmendment
(43e) Terminal equipment of users of electronic communications networks and any information relating to the usage of such terminal equipment, whether, in particular, it is stored in or emitted by such equipment, requested from or processed in order to enable it to connect to another device and or network equipment, are part of the private sphere of the users requiring protection under the Charter of Fundamental Rights of the European Union and the European Convention for the Protection of Human Rights and Fundamental Freedoms. Given that such equipment contains or processes very sensitive data that may reveal details of the behaviour, psychological features, emotional, political and social preferences, including the content of communications, pictures, the location of individuals by accessing the GPS capabilities of the device, contact lists, and other information already stored in the device, the information related to such equipment requires enhanced privacy protection. Information related to the user’s device may also be collected remotely for the purpose of identification and tracking, using techniques such as the so-called ‘device fingerprinting’, often without the knowledge of the user, and may seriously intrude upon the privacy of these users. Furthermore, the so-called spyware, web bugs, hidden identifiers, tracking cookies and other similar unwanted tracking tools can enter user's terminal equipment without their knowledge in order to gain access to information, to store hidden information and to trace the activities. Techniques that surreptitiously monitor the actions of users, for example by tracking their activities online or the location of their terminal equipment, or subvert the operation of the users’ terminal equipment pose a serious threat to the privacy of users. Therefore, any such interference with the user's terminal equipment should be allowed only with the user's consent and for specific and transparent purposes.

Or. en

Amendment 407

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 f (new)

Text proposed by the CommissionAmendment
(43f) Electronic communications data may also reveal information concerning legal entities, such as business secrets or other sensitive information that has economic value. Therefore, the provisions of Chapter IVa of this Regulation should apply to both natural and legal persons. Legal persons should have the same rights as users that are natural persons regarding the supervisory authorities.

Or. en

Amendment 408

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 g (new)

Text proposed by the CommissionAmendment
(43g) Users may consent to the processing of their metadata to receive specific services such as protection services against fraudulent activities (by analysing usage data, location and customer account in real time). In the digital economy, services are often supplied against counter-performance other than money, for instance by exposing users to advertisements. Consent for processing data from internet or voice communication usage will not be valid if the data subject has no genuine and free choice, or is unable to refuse or withdraw consent without detriment. Consent should not be considered as freely given if it is obtained through repetitive requests. In order to prevent such abusive requests, users should be able to order service providers to remember their choice not to consent and to adhere to technical specifications signalling not to consent, withdrawal of consent, or a refusal to all processing that may otherwise be based on consent including for purposes related to cross-site tracking or downstream processing for personalised advertising.

Or. en

Amendment 409

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 h (new)

Text proposed by the CommissionAmendment
(43h) Respecting an indication of data subjects’ choices under Article 91e(1)(ba) of Regulation (EU)2016/679 should include, where applicable, refraining from storing or accessing personal data on terminal equipment for the purposes covered by the indication, unless and until the data subject changes their choice.

Or. en

Amendment 410

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 i (new)

Text proposed by the CommissionAmendment
(43i) The principles of data protection by design and by default should be taken into consideration regarding software placed on the market to enable electronic communication or to allow for the retrieval of information on the internet. This should entail that the most privacy protective settings should be enabled by default in accordance with Article 25 of this regulation to prevent the processing, including the storing, transmission and transfer of information already stored on the terminal equipment of a user, except where otherwise provided in Article 91c. At the time of installing the software the user should be offered different options allowing them to consent or to change the default privacy settings of the terminal equipment. Furthermore, the user should be offered different options to choose from to enable them to make an informed decision on whether or not to allow different processing activities, including but not limited to the storing and transmission of data. The user should be provided with understandable and easily to navigate language and settings, that should be adaptable and permit the user to revise the settings of their terminal equipment at any time. The user's choice should be communicated to other parties that should implement and enforce the user's choices and any updates thereof. Controllers should not design consent interfaces that could lead to the systematic overriding, undermining, or circumvention of automated and machine-readable indications. In the absence of an explicit affirmative action, consent should not be inferred from the default configuration of a browser or operating system, nor from the user’s practice of use of such tools.

Or. en

Amendment 411

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 j (new)

Text proposed by the CommissionAmendment
(43j) Exceptions to the obligation to obtain consent to make use of the processing and storage capabilities of terminal equipment or to access information stored in, or processed by, terminal equipment should be limited to situations that involve no, or only very limited, intrusion of privacy, for instance the technical storage or access which is strictly necessary and proportionate for the legitimate purpose of enabling the use of a service requested by the user. This may include the storing of information, such as cookies and other identifiers necessary for enabling the use of a service requested by the user, for the duration of a single established session on a website to keep track of the user's input when filling in online forms over several pages.

Or. en

Amendment 412

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 k (new)

Text proposed by the CommissionAmendment
(43k) Maintaining or restoring the technical security of a service provided by the controller and requested by the data subject or the technical security of the terminal equipment used for the provision of such service should only be allowed without consent to the extent that the security updates are proportionate, discretely packaged and do not in any way change the functionality of the software on the terminal equipment, including the interaction with other software or settings chosen by the user, the user is informed in advance each time an update is being installed, and the user has the possibility to turn off the automatic installation of these updates.

Or. en

Amendment 413

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 l (new)

Text proposed by the CommissionAmendment
(43l) The exceptions to the obligation to obtain consent may also cover situations where users use a service across devices for the purpose of service personalisation and content recommendation. Such techniques, if implemented with appropriate privacy safeguards, could also be a legitimate and useful tool, for example, in measuring web traffic to a website. Such measuring could also be carried out by another party which acts as a data processor for the provider of the service. Similarly, providers of terminal equipment and the software needed to operate such equipment regularly could need access to configuration and other device information and the processing and storage capabilities to maintain the equipment or its use, and correct problems related to the equipment's operation. Information society providers and electronic communications service providers that engage in configuration checking to provide the service in compliance with the user's settings, and the mere logging of the fact that the user's device is unable to receive content requested by the user, should not constitute illegitimate access.

Or. en

Amendment 414

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 m (new)

Text proposed by the CommissionAmendment
(43m) Providers of online services may have a legitimate interest in monetising their services, including through advertising. Therefore, providers of online services should be able to deliver basic forms of online advertising that carry minimal privacy and personal data protection risks. That ability may become particularly important where users are able to refuse consent at the browser or operating system level for the processing of their personal data, as well as the storing and accessing of information on their terminal equipment. In such cases, without specific exemptions, online service providers would be unable to seek consent for low-risk advertising practices, even where they would have justifiable legitimate interests in doing so. Such low-risk advertising practices should therefore be exempt from the obligation to obtain consent for use of the processing and storage capabilities of terminal equipment.

Or. en

Amendment 415

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 n (new)

Text proposed by the CommissionAmendment
(43n) Low-risk advertising practices that should be exempt from consent include the delivery and targeting of strictly limited contextual advertising, which should be restricted to processing information about the device, such as operating system and browser type, abstracted to high-level categories. For example, specific browser versions should not be processed for this purpose. Such advertising may also make use of coarse geolocation data abstracted to the level of a region, or at the narrowest to the level of a city; temporal information such as date and time; and the content the user is immediately viewing, abstracted to broad categories and taxonomies, such as "sports", "travel", or "luxury goods". Search query data should not fall within strictly limited contextual advertising.

Or. en

Amendment 416

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 o (new)

Text proposed by the CommissionAmendment
(43o) To incentivise the uptake, effectiveness and attractiveness of strictly limited contextual advertising, certain additional practices should also be exempt from the consent requirement, including frequency capping, defence against ad fraud, and measurement and attribution. Exemptions for these practices should be defined narrowly, and should be conducted by the online service itself, or by a trusted third party acting exclusively on its behalf. For frequency capping, for example, the online service being accessed by the user may process no more than a counter, without any unique identifier, for the sole purpose of limiting a user's exposure to a particular advertisement.

Or. en

Amendment 417

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 p (new)

Text proposed by the CommissionAmendment
(43p) These exemptions may further permit on-device processing by a browser or operating system, where such processing employs privacy-enhancing technologies and immediately anonymises and aggregates data through an aggregation service, reducing the risk of individual identifiability to a minimal level. On-device processing of this kind may only be used to support strictly limited contextual advertising, and the underlying data may not be used for any other purpose including profiling, training artificial intelligence systems, or any other secondary use. Data that is not required for the permitted purpose should be deleted immediately.

Or. en

Amendment 418

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 q (new)

Text proposed by the CommissionAmendment
(43q) Creating instant anonymous aggregated information about the usage of an online service to measure the audience of such a service where it is carried out by the controller of that online service or by a processor acting on behalf of this controller for the sole use of the controller, means processing to obtain insight into the performance and use of the online service in an instantly anonymised, aggregated and general manner. The aggregated information should not relate to a specific data subject and should therefore be anonymous aggregated information. It should not involve fingerprinting techniques or the creation of persistent identifiers. The data collected should not be further processed for another purpose, combined with data from other services from the provider of the online service or from a third party, such as analytics information from other websites or apps, or shared with third parties.

Or. en

Amendment 419

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 43 r (new)

Text proposed by the CommissionAmendment
(43r) Strictly limited contextual advertising, frequency capping, and audience measurement should not be based on any type of profiling, nor involve any retention or link with the user's past or future activity, any combining with other personal data about the individual, nor linkability of identifiers to other personal data about the individual. Personal data and metadata regarding the data subject should be deleted immediately after any strictly necessary measurement of the advertisement’s display or performance has occurred and in any case after the browsing session is closed. Cookies used for contextual advertising should be exclusively temporary, transient, non-persistent cookies that are immediately deleted after the browsing session, or any equivalent technology technically designed to expire automatically.

Or. en

Amendment 420

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 44

Text proposed by the CommissionAmendment
[...]deleted

Or. en

Justification

Replaced with recitals 43a-43r tabled as amendments.

Amendment 421

João Oliveira

Proposal for a regulation

Recital 44 – paragraph 1

Text proposed by the CommissionAmendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.deleted

Or. pt

Amendment 422

Pernando Barrena Arza, João Oliveira

Proposal for a regulation

Recital 44 – paragraph 1

Text proposed by the CommissionAmendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.deleted

Or. en

Amendment 423

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 44 – paragraph 1

Text proposed by the CommissionAmendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through trackers, identifiers or similar technologies located on, or interacting with, terminal equipment, including but not limited to cookies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person. These rules are without prejudice to Directive 2002/58/EC, which continues to apply in full, and in particular to the confidentiality of communications and of the related traffic data, the protection of traffic and location data, the safeguards against unsolicited communications, and the possibility for Member States to adopt restrictive measures, as provided for in Articles 5, 6, 9, 13 and 15(1) of that Directive.

Or. en

Amendment 424

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Recital 44 – paragraph 1

Text proposed by the CommissionAmendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.The storing of information, or the gaining of access to information already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Directive 2002/58/EC. The amendments presented in this Regulation should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment.

Or. en

Amendment 425

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Recital 44 – paragraph 1

Text proposed by the CommissionAmendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.The amendments presented in this Regulation regarding the storing of information or the gaining of access to information already stored in a terminal equipment continue to offer the highest levels of protection, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails inter alia the processing of personal data or other information through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.

Or. en

Amendment 426

Diana Iovanovici Şoşoacă

Proposal for a regulation

Recital 44 – paragraph 1

Text proposed by the CommissionAmendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online, but they should include potential penalties to be applied in the event of an information leak involving personal data or access by persons who are not authorised to access this personal information and data. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.

Or. ro

Amendment 427

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Recital 44 – paragraph 1

Text proposed by the CommissionAmendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and any subsequent processing constitutes a highly intrusive interference with the fundamental rights to confidentiality of communications and device integrity, and should be therefore subject to strict protections, where the subscriber of the electronic communications service or the user of the terminal equipment is a data subject. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the data subject or by another legal or natural person.

Or. en

Amendment 428

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Recital 44 – paragraph 2

Text proposed by the CommissionAmendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.The storing of information, or the gaining of access to information already stored, in a terminal equipment should continue to be allowed only on the basis of consent.

Or. en

Amendment 429

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Recital 44 – paragraph 2

Text proposed by the CommissionAmendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.The storing of information on, or the gaining of access to information already stored, in the terminal equipment of a natural person, in particular through cookies and similar technologies, should continue to be governed by Directive 2002/58/EC. In order to ensure legal certainty, avoid fragmentation and reduce unnecessary compliance burdens on businesses, a single and coherent regulatory framework should apply to all such practices, irrespective of whether they involve personal or non-personal data. A differentiated regime under which only cookies involving personal data would be subject to Regulation (EU) 2016/679 while others remain under Directive 2002/58/EC would create legal complexity and increase costs for undertakings, in particular small and medium-sized enterprises, without providing additional protection to data subjects. Therefore, the rules on the storing of information and gaining of access to information stored in terminal equipment should remain unified within the framework of Directive 2002/58/EC.

Or. en

Amendment 430

Ana Vasconcelos, João Cotrim De Figueiredo

Proposal for a regulation

Recital 44 – paragraph 2

Text proposed by the CommissionAmendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679, provided that any such measure is necessary and proportionate and does not require the general identification of users, nor the weakening of anonymity, encryption or other protective tools on which users, including journalists, activists and other persons at risk, rely.

Or. en

Amendment 431

Pernando Barrena Arza, João Oliveira

Proposal for a regulation

Recital 44 – paragraph 2

Text proposed by the CommissionAmendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. This requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, under certain conditions.

Or. en

Amendment 432

Diana Iovanovici Şoşoacă

Proposal for a regulation

Recital 44 – paragraph 2

Text proposed by the CommissionAmendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679. At the same time, it is important to include potential penalties to be applied in the event of an information leak involving personal data or access by persons who are not authorised to access this personal information and data.

Or. ro

Amendment 433

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Recital 44 – paragraph 2

Text proposed by the CommissionAmendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a data subject, when that is based on Union or Member State law within the meaning of, and subject to the conditions of, Article 6 (3) of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.

Or. en

Amendment 434

Alex Agius Saliba

Proposal for a regulation

Recital 44 – paragraph 2

Text proposed by the CommissionAmendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.The storing of information, or the gaining of access to information already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement under Regulation (EU) 2016/679 should not preclude storing of personal data, or gaining of access to personal data already stored, in a terminal equipment, when that is based on Union or Member State law within the meaning of Article 6(3) of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.

Or. en

Amendment 435

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Angelika Niebler, Andrea Wechsler, Oliver Schenk, Christian Ehler

Proposal for a regulation

Recital 44 – paragraph 2

Text proposed by the CommissionAmendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.

Or. en

Amendment 436

João Oliveira

Proposal for a regulation

Recital 44 – paragraph 3

Text proposed by the CommissionAmendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.deleted

Or. pt

Amendment 437

Pernando Barrena Arza, João Oliveira

Proposal for a regulation

Recital 44 – paragraph 3

Text proposed by the CommissionAmendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.deleted

Or. en

Amendment 438

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Recital 44 – paragraph 3

Text proposed by the CommissionAmendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.With a view to increase innovation and competitiveness, reducing the compliance burden and providing legal clarity to all stakeholders, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide, among other things, a safe and functional service requested by the subscriber or user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of information, or the gaining of access to information already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf. Such exceptions should cover the transmission of electronic communications, the provision of a service explicitly requested by the user including its functionality and personalisation, audience measurement limited to aggregated data without repurposing for profiling or advertising, and joint audience measurement involving media service providers or their mandated entities. Exceptions should further include measures strictly necessary to ensure the security of the service or network and to prevent fraud directly related to the requested service, as well as the provision, display and measurement of contextual advertising based solely on the content immediately presented to the user, without any profiling. In recognition of the important role played by media service providers and the low privacy risk associated with their typical processing activities, specific provisions should also allow them to offer users a clear choice between consenting to the processing of personal data for purposes such as advertising, service improvement, product development and analytics, or paying a reasonable fee for an equivalent version of the service without such processing. In all cases, these exceptions are designed to strike an appropriate balance between the protection of users’ rights, the sustainability of media pluralism, and the need to foster innovation and competitiveness in the digital single market.

Or. en

Amendment 439

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Juan Ignacio Zoido Álvarez, Angelika Niebler, Andrea Wechsler, Oliver Schenk, Pekka Toveri, Christian Ehler

Proposal for a regulation

Recital 44 – paragraph 3

Text proposed by the CommissionAmendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. This list should include measuring the audience of an online service by creating aggregated information about the usage of an online service, where it is carried out by the provider of that online service, or by a third party, such as a market research company or a Joint Industry Committee, acting together with or on behalf of this provider. ‘Audience measurement’ should be understood in accordance with Article 2(16) and with Article 24(1) of Regulation (EU) 2024/1083. Gatekeepers designated under Regulation (EU) 2022/1925 carrying out audience measurement may not rely on article 88a(3)c of this Regulation. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.

Or. en

Amendment 440

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Recital 44 – paragraph 3

Text proposed by the CommissionAmendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is strictly necessary for those specific purposes, this Regulation should therefore provide that the processing is lawful. These narrow exceptions should strictly apply to technical communications transmission, the execution of explicit services requested by the data subject, necessary security operations, or audience measurement metrics for media service providers, or third-party providers of audience measurement for media services providers, provided it follows conditions for low processing risks, namely for statistical counting and is not utilised for profiling of data subject and does not involve core platfroms services as defined in Regulation (EU) 2022/1925. Following these conditions, the controller, such as a media service provider, may therefore mandate a processor, such as a market research company, to carry out the processing on its behalf.

Or. en

Amendment 441

Wouter Beke

Proposal for a regulation

Recital 44 – paragraph 3

Text proposed by the CommissionAmendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as an online service or a media service provider, may mandate a processor or joint controller, such as a market research company or Joint Industry Committee, to carry out the processing jointly or on its behalf, subject to strict safeguards ensuring that such processing is proportionate, compliant with the requirements of Article 24(1) of Regulation (EU) 2024/1083 and is not repurposed for advertising, profiling, or other unrelated purposes.

Or. en

Justification

This amendment ensures consistency with Article 5.3(c) of Regulation (EU) 2016/679 by clarifying that audience measurement may be conducted by mandated joint controllers, including Joint Industry Committees and research companies. It aligns the recital with the EMFA framework, strengthening legal certainty, independent measurement and safeguards against profiling or advertising purposes.

Amendment 442

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Recital 44 – paragraph 3

Text proposed by the CommissionAmendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.With a view to reducing the compliance burden and providing legal clarity, and given that certain purposes of storing or gaining access to the information on the terminal equipment of a natural person poses a low risk to the rights and freedoms of data subjects or that it may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. This limited list of low risk operations includes audience measurement, especially in the case of media providers, and the restoration or maintenance of the security of the terminal equipment, provided that service providers fulfill certain conditions. In the case of audience measurement, the data should be instantly anonymised and aggregated. The user’s personal data could, for instance, be retained for a short time session. At the end of the session, the data would be aggregated in such a way that it does not constitute personal data and remaining personal data from the session is deleted or anonymised. The user should still be informed about the storing or gaining access. All of these operations should always be strictly technically and solely necessary for the purpose.

Or. en

Amendment 443

Ana Vasconcelos, João Cotrim De Figueiredo

Proposal for a regulation

Recital 44 – paragraph 3

Text proposed by the CommissionAmendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. Those purposes should be interpreted narrowly and should not serve as a basis for tracking, profiling or the large-scale monitoring of the online activity of data subjects. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.

Or. en

Amendment 444

João Oliveira

Proposal for a regulation

Recital 44 – paragraph 4

Text proposed by the CommissionAmendment
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.deleted

Or. pt

Amendment 445

Pernando Barrena Arza, João Oliveira

Proposal for a regulation

Recital 44 – paragraph 4

Text proposed by the CommissionAmendment
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.deleted

Or. en

Amendment 446

Alex Agius Saliba

Proposal for a regulation

Recital 44 – paragraph 4

Text proposed by the CommissionAmendment
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.deleted

Or. en

Amendment 447

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Recital 44 – paragraph 4

Text proposed by the CommissionAmendment
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.For the subsequent processing of personal data Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing.

Or. en

Amendment 448

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Recital 44 – paragraph 4

Text proposed by the CommissionAmendment
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.For the subsequent processing of personal data for other purpose than those defined in the limitative list, such as development and operating of artificial intelligence models, controllers may seek to rely on legitimate interest under Article 6 (1), point (f) while Article 9 of Regulation (EU) 2016/679 should nevertheless be applied. However, to ensure that such processing does not override the fundamental rights and freedoms of data subjects, controllers must implement mandatory checklist of technical and organisational standards. These must include providing data subjects with an absolute right to object after being fully informed, ensuring state-of-the-art technics for data anonymisation, the executing rigorous technical abstration during the model training phase to make data disclosure extremely unlikely. To reduce individual administrative burdens, Member States should enable data subjects to administer their absolute right to object through a centralised public body. To ease complience and ensure uniformed approach, minimum standards for these techniques should be technically defined through standardisation. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take utmost account of the following elements: whether the data subject is a child; the reasonable expectations of the data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.

Or. en

Amendment 449

Diana Iovanovici Şoşoacă

Proposal for a regulation

Recital 44 – paragraph 4

Text proposed by the CommissionAmendment
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life, and there should also be potential penalties in the event of information misuse or leaks involving personal data or access by persons who are not authorised to access this personal information and data.

Or. ro

Amendment 450

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Recital 44 – paragraph 4

Text proposed by the CommissionAmendment
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements; whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the monitoring of the data subject’s private life. Sensitive categories of personal data shoud only be processed in accordance with Article 9 of Regulation 2016/679, unless otherwise provided for in this regulation.

Or. en

Amendment 451

Ana Vasconcelos, João Cotrim De Figueiredo

Proposal for a regulation

Recital 44 – paragraph 4

Text proposed by the CommissionAmendment
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life. Where age assurance is necessary, it should rely on privacy-preserving and data-minimising techniques, and should not undermine the anonymity or confidentiality of communications.

Or. en

Amendment 452

João Oliveira

Proposal for a regulation

Recital 44 – paragraph 5

Text proposed by the CommissionAmendment
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.deleted

Or. pt

Amendment 453

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Recital 44 – paragraph 5

Text proposed by the CommissionAmendment
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.deleted

Or. en

Amendment 454

Pernando Barrena Arza, João Oliveira

Proposal for a regulation

Recital 44 – paragraph 5

Text proposed by the CommissionAmendment
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.deleted

Or. en

Amendment 455

Alex Agius Saliba

Proposal for a regulation

Recital 44 – paragraph 5

Text proposed by the CommissionAmendment
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.deleted

Or. en

Amendment 456

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Recital 44 – paragraph 5

Text proposed by the CommissionAmendment
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.deleted

Or. en

Amendment 457

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 44 a (new)

Text proposed by the CommissionAmendment
(44a) Information relating to other natural persons stored in the terminal equipment of a user or subscriber, such as contact details, constitutes personal data of those persons. Consent given by the user or subscriber to the storing of, or access to, such information does not constitute consent by the natural persons to whom that information relates, nor a legal basis for any further processing of their personal data. Such information should not be transmitted to third parties, nor used for purposes other than those strictly necessary for the service explicitly requested by the user or subscriber. This confirms the confidentiality of communications protected by Directive 2002/58/EC, which extends to the identity of the persons with whom a user communicates.

Or. en

Justification

Address books are the personal data of persons who have never consented to anything. Their systematic upload for the purpose of building social graphs or enriching profiles has no legal basis.

Amendment 458

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Recital 45

Text proposed by the CommissionAmendment
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period.(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. To enable genuine freedom of choice, the controller should therefore be obliged to respect the data subject’s choices to refuse, withdraw, or receive relavent information to make informed decision regarding a request for consent for at least one year, prevening continuous requests, including via pop-up windows on online interface. Moreover, data subject’s freedom to express a refusal or withdrawal of consent must be as effortless and instantaneous as granting it. Therefore, web browsers and operating systems should enable user-friendly, straightforward and prominently displayed single-click button to refuse or withdraw consent directly alongside any option to accept. Furthermore, users should never be put in the situation of surrendering their data by providers of services denying them access to a service or any functionality of that service, unless it is strictly necessary for the functioning of that service. It is also necesarry to protect users from unsolicited invasive stealth tracking methods. Therefore, online choice architectures should be designed neutrally, and the processing of indentifiers beyond what is strictly to remember a privacy choice when consent is refused or withdrawn should not be permitted. Furthermore, in order to guarantee the validity of user intent, consent obtained through manipulative designs or dark patters that distors free choice should be considered legally invalid.

Or. en

Amendment 459

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Recital 45

Text proposed by the CommissionAmendment
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period.(45) Users that have refused a request for consent are often confronted with a new request to give consent each time they visit the same service again. This may have detrimental effects to the data subjects or users which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the users’ choices to refuse a request for consent and not ask for consent again where the user has already expressed their choice for the given purpose. For consistency purposes, this Regulation further specifies that the refusal of a request for consent should be as easy as consenting or withdrawing consent, as required under Article 7 of Regulation (EU) 2016/679. The requirements for consent were also strengthened in the case of accessing information already stored or storing information on the terminal equipment of a natural person. Both should be read in conjunction, as the intent is that an option to refuse consent in an easy and intelligible manner is to be provided with a prominently displayed single-click button, especially when there is a possibility to consent to all purposes with a single-click button in the case of Regulation (EU) 2016/679.

Or. en

Amendment 460

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 45

Text proposed by the CommissionAmendment
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period.(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. The single-click modality and the period referred to constitute an ergonomic ideal rather than a mandatory technological standard, their practical implementation being more complex and capable of varying according to context. Data subjects should be able to express and modulate their consent at several levels — terminal equipment, operating system, web browser, application or on a site-by-site basis — and to outsource its management to a consent and agency-enhancing service provider, a data intermediation service provided to data subjects or a personal data space. An automated indication should not preclude the expression of service-specific choices.

Or. en

Justification

Privacy choices are contextual. A blanket signal imposed without granularity would conflict with the specificity requirement of consent under the Regulation itself. The amendment preserves the anti-fatigue objective while restoring the data subject's ability to modulate.

Amendment 461

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Recital 45

Text proposed by the CommissionAmendment
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period.(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s refusal of consent for a reasonable period of time, taking into account the context of the processing, the means by which the data subject accessed the service, and technical feasibility. This obligation should not prevent a provider from requesting consent at a later stage, for example if the data subject requests to access the service, through a different device, browser, account or access method, nor should it lead to a disproportionate deterioration of the service or prevent the data subject from accessing the service under different conditions. The provider should also make available effective and easily accessible means for the data subject to withdraw or modify their choice at any time.

Or. en

Amendment 462

Diana Iovanovici Şoşoacă

Proposal for a regulation

Recital 45

Text proposed by the CommissionAmendment
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period.(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. In such cases, a validation or consent request could clarify situations that might add legal uncertainty.

Or. ro

Amendment 463

João Oliveira

Proposal for a regulation

Recital 46

Text proposed by the CommissionAmendment
(46) Data subjects should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request or object to the processing of data. Such means should follow the state of the art. They can be implemented in the settings of a web browser or in the EU Digital Identity Wallet as set out by Regulation (EU) 914/2014, or any other adequate means. Rules set out in this Regulation should support the emergence of market-driven solutions with appropriate interfaces. The controller should be obliged to respect automated and machine-readable indications of data subject’s choices once there are available standards. In light of the importance of independent journalism in a democratic society and in order not to undermine the economic basis for that, media service providers should not be obliged to respect the machine-readable indications of data subject’s choices. The obligation for providers of web browsers to provide the technical means for data subjects to make choices with respect to the processing should not undermine the possibility for media service providers to request consent by data subjects.deleted

Or. pt

Amendment 464

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Recital 46

Text proposed by the CommissionAmendment
(46) Data subjects should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request or object to the processing of data. Such means should follow the state of the art. They can be implemented in the settings of a web browser or in the EU Digital Identity Wallet as set out by Regulation (EU) 914/2014, or any other adequate means. Rules set out in this Regulation should support the emergence of market-driven solutions with appropriate interfaces. The controller should be obliged to respect automated and machine-readable indications of data subject’s choices once there are available standards. In light of the importance of independent journalism in a democratic society and in order not to undermine the economic basis for that, media service providers should not be obliged to respect the machine-readable indications of data subject’s choices. The obligation for providers of web browsers to provide the technical means for data subjects to make choices with respect to the processing should not undermine the possibility for media service providers to request consent by data subjects.(46) Data subjects should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request or object to the processing of data. Such means should follow the state of the art. They can be implemented in the settings of a web browser or operating systems, or any other adequate means. Rules set out in this Regulation should support the emergence of market-driven solutions with appropriate interfaces. The controller should be obliged to respect automated and machine-readable indications of data subject’s choices once there are available standards. To simplify interactions across the digital ecosystem and prevent consent fatique, data subjects should have the posibility to configure their general privacy pereferences globally and centrally within the settings of their web browser or operating systems. At the same time, to perserve a high degree of choice granularity and foster a competative market for innovative privacy-enhancing services within the Union, data subjects should have the option to delegate the dynamic management of these preferences to independent third-party software applications, browser extentions, or automated consent agents acting on their behalf. Providers of web browsers and operating systems should ensure their underlining technical infrastructure natively supports such tools, and should present users upon first use with a clear prompt to select their preferred configuration. Furthermore, data subjects should not face technical barriers or artificial degradation of service functionality when choosing to safeguard their privacy. Providers of web browsers and operating systems, as well as online service providers, should therefore not be allowed from restricting, denying or limiting access to their interfaces or core features merely because data subjects use privacy-enhancing technologies, such as Virtual Private Networks, or broweser extentions, provided that these tools comply with technical specificiations established by harmonised standards. To allow further choices for users and ensure granuality, and in light of the importance of independent journalism in a democratic society and in order not to undermine their economic basis and the need to protect its economic sustainability, data subjects should have the practical options to import pre-configured recommemded choices, which may come, for example, as whilelists to allow interaction with trusted online interfaces, such as editorially independent media service providers, which would therefore be granted a specfic exception. In this way, an exception for media service provided would not only ensure that automated signals do not inadvertenly cut off revenue for public interest media, but would also spare these providers from having to deploy standalone pop-up windows to obtain consent. Therefore, media service providers providing news and current affairs content that comply with the editorial independence standards of Regulation (EU) 2024/1083 should have the right to have their online interfaces included in recommended whitelists maintained by web browsers or operating systems, or third-party agents. To ensure user autonomy remains paramount, web browsers and operating systems should explicitly and neutrally prompt the data subject upon first use to allow this specific media exception. Finally, to maintain the integrity of this choice ecosystem, providers of web browsers and operating systems should be acting strictly as neutral technical conduits, while those acting as a core service providers should be prohibited from processing, analyzing, or capitalising on the privacy choices expressed by the user for any secondary purpose other than transmitting the signal.

Or. en

Amendment 465

Diana Iovanovici Şoşoacă

Proposal for a regulation

Recital 46

Text proposed by the CommissionAmendment
(46) Data subjects should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request or object to the processing of data. Such means should follow the state of the art. They can be implemented in the settings of a web browser or in the EU Digital Identity Wallet as set out by Regulation (EU) 914/2014, or any other adequate means. Rules set out in this Regulation should support the emergence of market-driven solutions with appropriate interfaces. The controller should be obliged to respect automated and machine-readable indications of data subject’s choices once there are available standards. In light of the importance of independent journalism in a democratic society and in order not to undermine the economic basis for that, media service providers should not be obliged to respect the machine-readable indications of data subject’s choices. The obligation for providers of web browsers to provide the technical means for data subjects to make choices with respect to the processing should not undermine the possibility for media service providers to request consent by data subjects.(46) Data subjects should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request or object to the processing of data. Such means should follow the state of the art. They can be implemented in the settings of a web browser or in the EU Digital Identity Wallet as set out by Regulation (EU) 914/2014, or any other adequate means. Rules set out in this Regulation should support the emergence of market-driven solutions with appropriate interfaces. The controller should be obliged to respect automated and machine-readable indications of data subject’s choices once there are available standards. In light of the importance of independent journalism in a democratic society and in order not to undermine the economic basis for that, media service providers should not be obliged to respect the machine-readable indications of data subject’s choices. The obligation for providers of web browsers to provide the technical means for data subjects to make choices with respect to the processing should not undermine the possibility for media service providers to request consent by data subjects. At the same time, data subjects should be able to easily change or withdraw the choices they made by such automated means at any time without being subject to disproportionate procedures or discriminatory effects. The technical standards used for the transmission and interpretation of these indications should be interoperable, open and technologically neutral in order to ensure consistent application of the choices of data subjects and foster a high level of protection of personal data across the Union. These standards should be developed in a transparent and inclusive manner, taking into account technological developments, the need for innovation and the legitimate rights and interests of all parties involved.

Or. ro

Amendment 466

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 46

Text proposed by the CommissionAmendment
(46) Data subjects should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request or object to the processing of data. Such means should follow the state of the art. They can be implemented in the settings of a web browser or in the EU Digital Identity Wallet as set out by Regulation (EU) 914/2014, or any other adequate means. Rules set out in this Regulation should support the emergence of market-driven solutions with appropriate interfaces. The controller should be obliged to respect automated and machine-readable indications of data subject’s choices once there are available standards. In light of the importance of independent journalism in a democratic society and in order not to undermine the economic basis for that, media service providers should not be obliged to respect the machine-readable indications of data subject’s choices. The obligation for providers of web browsers to provide the technical means for data subjects to make choices with respect to the processing should not undermine the possibility for media service providers to request consent by data subjects.(46) Data subjects should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request or object to the processing of data. Such means should follow the state of the art. They can be implemented in the settings of a web browser or in the EU Digital Identity Wallet as set out by Regulation (EU) 914/2014, or any other adequate means. Rules set out in this Regulation should support the emergence of market-driven solutions with appropriate interfaces. Such means should be interoperable, so that a signal expressed at one level, whether terminal, operating system, browser, application or website, is recognised and given effect at the others, including between different applications and between different terminal devices used by the same data subject, and should not constitute a single mandatory mechanism nor be provided in a manner that concentrates the management of consent within a single system or entity. The technical means should not be designed or operated so as to confer on the provider of a browser, operating system or terminal a preferential position in obtaining, refusing or managing consent. The controller should be obliged to respect automated and machine-readable indications of data subject’s choices once there are available standards. In light of the importance of independent journalism in a democratic society and in order not to undermine the economic basis for that, media service providers should not be obliged to respect the machine-readable indications of data subject’s choices. The obligation for providers of web browsers to provide the technical means for data subjects to make choices with respect to the processing should not undermine the possibility for media service providers to request consent by data subjects.

Or. en

Justification

A mandate imposed on browsers risks creating a compulsory intermediary between publishers and their audience, reinforcing the very gatekeepers who control browsers and operating systems. The amendment preserves the interoperability of signals — including across applications and devices — while ruling out centralisation and the capture of consent management by access controllers.

Amendment 467

Oliver Schenk, Axel Voss, Marie-Sophie Lanig, Ana Miguel Pedro, Romana Tomc, Marion Walsmann, Lena Düpont, François-Xavier Bellamy, Andrea Wechsler, Aura Salla

Proposal for a regulation

Recital 46

Text proposed by the CommissionAmendment
(46) Data subjects should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request or object to the processing of data. Such means should follow the state of the art. They can be implemented in the settings of a web browser or in the EU Digital Identity Wallet as set out by Regulation (EU) 914/2014, or any other adequate means. Rules set out in this Regulation should support the emergence of market-driven solutions with appropriate interfaces. The controller should be obliged to respect automated and machine-readable indications of data subject’s choices once there are available standards. In light of the importance of independent journalism in a democratic society and in order not to undermine the economic basis for that, media service providers should not be obliged to respect the machine-readable indications of data subject’s choices. The obligation for providers of web browsers to provide the technical means for data subjects to make choices with respect to the processing should not undermine the possibility for media service providers to request consent by data subjects.(46) Data subjects should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request or object to the processing of data. Such means should follow the state of the art. They can be implemented in the settings of a web browser or in the EU Digital Identity Wallet as set out by Regulation (EU) 914/2014, or any other adequate means. Rules set out in this Regulation should support the emergence of market-driven solutions with appropriate interfaces. The controller should be obliged to respect automated and machine-readable indications of data subject’s choices once there are available standards. In light of the importance of independent journalism in a democratic society and in order not to undermine the economic basis for that, media service providers should not be obliged to respect the machine-readable indications of data subject’s choices. The obligation for providers of web browsers to provide the technical means for data subjects to make choices with respect to the processing should not undermine the possibility for media service providers to request consent by data subjects. To support media sustainability in Europe, Media Service Providers can ask for consent or establish necessary conditions for other legal bases for third parties as long as that is done for data processing required to support the functioning or funding of Media Service Providers and is conducted exclusively on their properties.

Or. en

Amendment 468

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Recital 46

Text proposed by the CommissionAmendment
(46) Data subjects should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request or object to the processing of data. Such means should follow the state of the art. They can be implemented in the settings of a web browser or in the EU Digital Identity Wallet as set out by Regulation (EU) 914/2014, or any other adequate means. Rules set out in this Regulation should support the emergence of market-driven solutions with appropriate interfaces. The controller should be obliged to respect automated and machine-readable indications of data subject’s choices once there are available standards. In light of the importance of independent journalism in a democratic society and in order not to undermine the economic basis for that, media service providers should not be obliged to respect the machine-readable indications of data subject’s choices. The obligation for providers of web browsers to provide the technical means for data subjects to make choices with respect to the processing should not undermine the possibility for media service providers to request consent by data subjects.(46) Data subjects and users should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request, withdraw consent or object to the processing of data. Such means should follow the state of the art. They can be implemented in the settings of a web browser, an operating system or an application. Rules set out in this Regulation should support the emergence of market-driven solutions with appropriate interfaces. This is why gatekeepers in the meaning of Regulation (EU) 2022/1925 should allow for third parties to provide for such means and the interface and providers should abide by certain conditions that ensure that no dark patterns are implemented and level playing field is ensured for controllers. Providers should also not be prevented from configuring the technical means to convey a refusal of consent and an exercise of the right to object in such a way that the data subject is not faced with banners, including from the provider. The controller should be obliged to respect automated and machine-readable indications of data subject’s choices once there are available standards or common specifications. Controllers should not make requests for consent for the same purpose through different means if the data subject is using automated and machine-readable signals and they should not override the choices expressed in these signals except if the data subject explicitly requests it.

Or. en

Amendment 469

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 46

Text proposed by the CommissionAmendment
(46) Data subjects should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request or object to the processing of data. Such means should follow the state of the art. They can be implemented in the settings of a web browser or in the EU Digital Identity Wallet as set out by Regulation (EU) 914/2014, or any other adequate means. Rules set out in this Regulation should support the emergence of market-driven solutions with appropriate interfaces. The controller should be obliged to respect automated and machine-readable indications of data subject’s choices once there are available standards. In light of the importance of independent journalism in a democratic society and in order not to undermine the economic basis for that, media service providers should not be obliged to respect the machine-readable indications of data subject’s choices. The obligation for providers of web browsers to provide the technical means for data subjects to make choices with respect to the processing should not undermine the possibility for media service providers to request consent by data subjects.(46) Data subjects should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request or object to the processing of data. Such means should follow the state of the art. Rules set out in this Regulation should support the emergence of market-driven solutions with appropriate interfaces. The controller should be obliged to respect automated and machine-readable indications of data subject’s choices once there are available standards. In light of the importance of independent journalism in a democratic society and in order not to undermine the economic basis for that, the obligation for providers of web browsers to provide the technical means for data subjects to make choices with respect to the processing should not undermine the possibility for media service providers to request consent by data subjects.

Or. en

Amendment 470

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Recital 46

Text proposed by the CommissionAmendment
(46) Data subjects should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request or object to the processing of data. Such means should follow the state of the art. They can be implemented in the settings of a web browser or in the EU Digital Identity Wallet as set out by Regulation (EU) 914/2014, or any other adequate means. Rules set out in this Regulation should support the emergence of market-driven solutions with appropriate interfaces. The controller should be obliged to respect automated and machine-readable indications of data subject’s choices once there are available standards. In light of the importance of independent journalism in a democratic society and in order not to undermine the economic basis for that, media service providers should not be obliged to respect the machine-readable indications of data subject’s choices. The obligation for providers of web browsers to provide the technical means for data subjects to make choices with respect to the processing should not undermine the possibility for media service providers to request consent by data subjects.(46) In order to address the issue of consent fatigue and to explore long-term technical solutions that enhance user autonomy while reducing the prevalence of interruptive cookie banners, the Commission is invited to promote a voluntary and time-limited pilot project. This pilot should aim to develop and test interoperable, machine-readable standards for communicating user preferences. Such a project should be developed in close cooperation with the European Data Protection Board (EDPB) and relevant stakeholders, ensuring it remains fully voluntary, technology-neutral, and without prejudice to the high level of protection provided by Directive 2002/58/EC and Regulation (EU)2016/679. The pilot should specifically evaluate the feasibility of decentralized standards that prevent market fragmentation and avoid the creation of new digital gatekeepers, while simultaneously protecting innovation and competitiveness in Europe and ensuring that European companies in the digital environment can continue to operate without significant and disproportionate disruptions to their business models.

Or. en

Amendment 471

Pernando Barrena Arza

Proposal for a regulation

Recital 46

Text proposed by the CommissionAmendment
(46) Data subjects should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request or object to the processing of data. Such means should follow the state of the art. They can be implemented in the settings of a web browser or in the EU Digital Identity Wallet as set out by Regulation (EU) 914/2014, or any other adequate means. Rules set out in this Regulation should support the emergence of market-driven solutions with appropriate interfaces. The controller should be obliged to respect automated and machine-readable indications of data subject’s choices once there are available standards. In light of the importance of independent journalism in a democratic society and in order not to undermine the economic basis for that, media service providers should not be obliged to respect the machine-readable indications of data subject’s choices. The obligation for providers of web browsers to provide the technical means for data subjects to make choices with respect to the processing should not undermine the possibility for media service providers to request consent by data subjects.(46) Data subjects should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request or object to the processing of data. Such means should follow the state of the art and Regulation (EU) 2016/679 by including specific consent per controller as well as withdrawal and objections. They can for example be implemented in the settings of a web browser or in the EU Digital Identity Wallet as set out by Regulation (EU) 914/2014, or any other adequate means in other technological contexts. Rules set out in this Regulation should support the emergence of market-driven third-party solutions with appropriate interfaces. Such solutions shall be neutral and not have any commercial interest in gaining consent from data subjects. The controller should be obliged to respect automated and machine-readable indications of data subject’s choices once there are available standards. This includes automated responses by the data subject, when a software responds according to the wishes of the data subject, but without individual actions by the data subject. The mere fact that choices are made on behalf of the data subject in an automated way shall not be used by controllers to claim that these choices are not valid.

Or. en

Amendment 472

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 46 a (new)

Text proposed by the CommissionAmendment
(46a) When the processing of electronic communications data by providers of electronic communications services falls within its scope, this Regulation should provide for the possibility for the Union or Member States under specific conditions to restrict by law certain obligations and rights when such a restriction constitutes a necessary and proportionate measure in a democratic society to safeguard specific public interests, including national security, defence, public security and the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security. Therefore, this Regulation should not affect the ability of Member States to carry out lawful interception of electronic communications or take other measures, if necessary and proportionate to safeguard the public interests mentioned above, in accordance with the Charter of Fundamental Rights of the European Union and the European Convention for the Protection of Human Rights and Fundamental Freedoms, as interpreted by the Court of Justice of the European Union and of the European Court of Human Rights.

Or. en

Amendment 473

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 46 a (new)

Text proposed by the CommissionAmendment
(46a) The amendments are without prejudice to Article 25 of Regulation (EU) 2016/679: controllers should implement data protection by design and by default, embedding state-of-the-art privacy-preserving and privacy-enhancing techniques from the outset. The amendments are equally without prejudice to the security of processing (Article 32), the notification of a personal data breach to the supervisory authority (Article 33) and the communication of a personal data breach to the data subject (Article 34).

Or. en

Justification

A safeguard clause preventing the simplifications from being read as an implicit weakening of the security and notification obligations, which the proposal does not amend.

Amendment 474

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 46 b (new)

Text proposed by the CommissionAmendment
(46b) The processing of personal data should not give rise to profiling or to manipulative techniques contrary to Union law, in particular as regards behavioural targeting and the protection of children; the prohibitions and safeguards of Regulation (EU) 2016/679 and Regulation (EU) 2024/1689 continue to apply. Scientific research does not include processing whose principal object is to observe, profile or influence the behaviour of natural persons for commercial purposes, in particular behavioural advertising or the commercial targeting of individuals, even where scientific methods are used; this is without prejudice to fundamental or applied research, including where it delivers benefits in the general interest.

Or. en

Justification

The broadening of research purposes must not allow processing whose principal object is behavioural targeting to be re-labelled as scientific research. The criterion retained is the principal object of the processing, not the method employed.

Amendment 475

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 46 b (new)

Text proposed by the CommissionAmendment
(46b) In order to safeguard the security and integrity of networks and services, the use of end-to-end encryption should be promoted and, where necessary, be mandatory in accordance with the principles of security and privacy by design. Member States should not impose any obligation on encryption providers, on providers of electronic communications services or on any other organisations (at any level of the supply chain) that would result in the weakening of the security of their networks and services, such as the creation or facilitation of “backdoors”.

Or. en

Amendment 476

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 46 c (new)

Text proposed by the CommissionAmendment
(46c) The interface used to request, give, refuse or withdraw consent should be designed in a fair and neutral manner. It should not be designed, structured or operated in a way that deceives or manipulates the data subject, or that otherwise impairs their ability to make a free and informed decision. In particular, it should not give visual or other prominence to acceptance over refusal, whether through the size, colour, positioning or wording of the options; present the option to accept and the option to refuse in a manner that is not equally easy and equally accessible; use wording or design liable to create confusion or to induce consent; or repeat requests for consent in a manner liable to pressure the data subject into consenting. The option to refuse consent should be as easy to exercise, and presented with equivalent prominence, as the option to give consent. Consent should be freely given, specific, informed and unambiguous, and capable of being withdrawn as easily as it was given.

Or. en

Justification

Codifies the elements of valid consent set out by the Board in its Guidelines 05/2020 and the prohibition of deceptive design in its Guidelines 03/2022. Consent that is obtained through a manipulated interface is not consent.

Amendment 477

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 46 d (new)

Text proposed by the CommissionAmendment
(46d) The creation of a permanent user account, or the provision of personal data by the data subject, may be required in order to access offers or to purchase goods or services only where strictly necessary. Where such access or purchase can be ensured without it, the controller should offer the data subject a clear, easily accessible and non-discriminatory means to proceed, which should not give rise to less favourable conditions for the data subject. Making access to a service conditional on the creation of an account which is not necessary for the performance of the contract deprives consent of its free character.

Or. en

Justification

Forced account creation is a widespread practice which conditions access to a service on the provision of data that is unnecessary for the contract. The guest option restores the free character of consent required by Article 7(4).

Amendment 478

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Recital 47

Text proposed by the CommissionAmendment
(47) Directive 2002/58/EC on privacy and electronic communications ‘ePrivacy Directive’), last revised in 2009, provides a framework for the protection of the right to privacy, including the confidentiality of communications. It also specifies Regulation (EU) 2016/679 in relation to processing of personal data in the context of electronic communication services. It protects the privacy and the integrity of user’s or subscriber’s terminal equipment used for such communications. The current provision of Article 5(3) of Directive 2002/58/EC should remain applicable insofar as the subscriber or user is not a natural person, and the information stored or accessed does not constitute or lead to the processing of personal data.deleted

Or. en

Justification

Access to terminal equipment and confidentiality of communications is moved to Regulation (EU) 2016/679 in amendments.

Amendment 479

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Recital 47

Text proposed by the CommissionAmendment
(47) Directive 2002/58/EC on privacy and electronic communications ‘ePrivacy Directive’), last revised in 2009, provides a framework for the protection of the right to privacy, including the confidentiality of communications. It also specifies Regulation (EU) 2016/679 in relation to processing of personal data in the context of electronic communication services. It protects the privacy and the integrity of user’s or subscriber’s terminal equipment used for such communications. The current provision of Article 5(3) of Directive 2002/58/EC should remain applicable insofar as the subscriber or user is not a natural person, and the information stored or accessed does not constitute or lead to the processing of personal data.deleted

Or. en

Amendment 480

Sibylle Berg, Martin Sonneborn

Proposal for a regulation

Recital 47

Text proposed by the CommissionAmendment
(47) Directive 2002/58/EC on privacy and electronic communications ‘ePrivacy Directive’), last revised in 2009, provides a framework for the protection of the right to privacy, including the confidentiality of communications. It also specifies Regulation (EU) 2016/679 in relation to processing of personal data in the context of electronic communication services. It protects the privacy and the integrity of user’s or subscriber’s terminal equipment used for such communications. The current provision of Article 5(3) of Directive 2002/58/EC should remain applicable insofar as the subscriber or user is not a natural person, and the information stored or accessed does not constitute or lead to the processing of personal data.(47) Directive 2002/58/EC on privacy and electronic communications ‘ePrivacy Directive’), last revised in 2009, provides a framework for the protection of the right to privacy, including the confidentiality of communications. It also specifies Regulation (EU) 2016/679 in relation to processing of personal data in the context of electronic communication services. It protects the privacy and the integrity of user’s or subscriber’s terminal equipment used for such communications.

Or. de

Amendment 481

João Oliveira

Proposal for a regulation

Recital 47

Text proposed by the CommissionAmendment
(47) Directive 2002/58/EC on privacy and electronic communications ‘ePrivacy Directive’), last revised in 2009, provides a framework for the protection of the right to privacy, including the confidentiality of communications. It also specifies Regulation (EU) 2016/679 in relation to processing of personal data in the context of electronic communication services. It protects the privacy and the integrity of user’s or subscriber’s terminal equipment used for such communications. The current provision of Article 5(3) of Directive 2002/58/EC should remain applicable insofar as the subscriber or user is not a natural person, and the information stored or accessed does not constitute or lead to the processing of personal data.(47) Directive 2002/58/EC on privacy and electronic communications ‘ePrivacy Directive’), last revised in 2009, provides a framework for the protection of the right to privacy, including the confidentiality of communications. It also specifies Regulation (EU) 2016/679 in relation to processing of personal data in the context of electronic communication services. It protects the privacy and the integrity of user’s or subscriber’s terminal equipment used for such communications.

Or. pt

Amendment 482

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Recital 47

Text proposed by the CommissionAmendment
(47) Directive 2002/58/EC on privacy and electronic communications ‘ePrivacy Directive’), last revised in 2009, provides a framework for the protection of the right to privacy, including the confidentiality of communications. It also specifies Regulation (EU) 2016/679 in relation to processing of personal data in the context of electronic communication services. It protects the privacy and the integrity of user’s or subscriber’s terminal equipment used for such communications. The current provision of Article 5(3) of Directive 2002/58/EC should remain applicable insofar as the subscriber or user is not a natural person, and the information stored or accessed does not constitute or lead to the processing of personal data.(47) Directive 2002/58/EC on privacy and electronic communications ‘ePrivacy Directive’), last revised in 2009, provides a framework for the protection of the right to privacy, including the confidentiality of communications. It also specifies Regulation (EU) 2016/679 in relation to processing of personal data in the context of electronic communication services. It protects the privacy and the integrity of user’s or subscriber’s terminal equipment used for such communications.

Or. en

Amendment 483

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Recital 47

Text proposed by the CommissionAmendment
(47) Directive 2002/58/EC on privacy and electronic communications ‘ePrivacy Directive’), last revised in 2009, provides a framework for the protection of the right to privacy, including the confidentiality of communications. It also specifies Regulation (EU) 2016/679 in relation to processing of personal data in the context of electronic communication services. It protects the privacy and the integrity of user’s or subscriber’s terminal equipment used for such communications. The current provision of Article 5(3) of Directive 2002/58/EC should remain applicable insofar as the subscriber or user is not a natural person, and the information stored or accessed does not constitute or lead to the processing of personal data.(47) Directive 2002/58/EC on privacy and electronic communications ‘ePrivacy Directive’), last revised in 2009, provides a framework for the protection of the right to privacy, including the confidentiality of communications. It also specifies Regulation (EU) 2016/679 in relation to processing of personal data in the context of electronic communication services. It protects the privacy and the integrity of user’s or subscriber’s terminal equipment used for such communications.

Or. en

Amendment 484

Pernando Barrena Arza, João Oliveira

Proposal for a regulation

Recital 47

Text proposed by the CommissionAmendment
(47) Directive 2002/58/EC on privacy and electronic communications ‘ePrivacy Directive’), last revised in 2009, provides a framework for the protection of the right to privacy, including the confidentiality of communications. It also specifies Regulation (EU) 2016/679 in relation to processing of personal data in the context of electronic communication services. It protects the privacy and the integrity of user’s or subscriber’s terminal equipment used for such communications. The current provision of Article 5(3) of Directive 2002/58/EC should remain applicable insofar as the subscriber or user is not a natural person, and the information stored or accessed does not constitute or lead to the processing of personal data.(47) Directive 2002/58/EC on privacy and electronic communications ‘ePrivacy Directive’), last revised in 2009, provides a framework for the protection of the right to privacy, including the confidentiality of communications. It also specifies Regulation (EU) 2016/679 in relation to processing of personal data in the context of electronic communication services. It protects the privacy and the integrity of user’s or subscriber’s terminal equipment used for such communications. The current provision of Article 5(3) of Directive 2002/58/EC should remain applicable.

Or. en

Amendment 485

Alex Agius Saliba

Proposal for a regulation

Recital 47

Text proposed by the CommissionAmendment
(47) Directive 2002/58/EC on privacy and electronic communications ‘ePrivacy Directive’), last revised in 2009, provides a framework for the protection of the right to privacy, including the confidentiality of communications. It also specifies Regulation (EU) 2016/679 in relation to processing of personal data in the context of electronic communication services. It protects the privacy and the integrity of user’s or subscriber’s terminal equipment used for such communications. The current provision of Article 5(3) of Directive 2002/58/EC should remain applicable insofar as the subscriber or user is not a natural person, and the information stored or accessed does not constitute or lead to the processing of personal data.(47) Directive 2002/58/EC on privacy and electronic communications ‘ePrivacy Directive’), last revised in 2009, provides a framework for the protection of the right to privacy, including the confidentiality of communications. It also specifies Regulation (EU) 2016/679 in relation to processing of personal data in the context of electronic communication services. It protects the privacy and the integrity of user’s or subscriber’s terminal equipment used for such communications. The current provision of Article 5(3) of Directive 2002/58/EC should remain applicable insofar as the information stored or accessed does not constitute processing of personal data.

Or. en

Amendment 486

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 48

Text proposed by the CommissionAmendment
(48) Article 4 of Directive 2002/58/EC should be repealed. Article 4 of Directive 2002/58/EC sets requirements for providers of publicly available electronic communications services as regards safeguarding the security of their services and notification requirements. Subsequently, Directive (EU) 2022/2555 has set new requirements as regards cybersecurity risk-management measures and incident reporting for those providers. In order to reduce overlapping obligations for entities in the electronic communications sector, Article 4 of Directive 2002/58/EC should be repealed. As regards the security of processing of personal data pursuant to Article 4(1) and (1a) of this directive and the notification of personal data breaches pursuant to Article 4(3) to (5) of Directive 2002/58/EC this directive, the Regulation (EU) 2016/679 already provide for comprehensive and up-to-date rules. These rules should therefore apply to providers of publicly available electronic communication services and providers of public communications networks, thereby ensuring that one regime applies to the controllers and processors.deleted

Or. en

Amendment 487

Diego Solier, Sebastian Tynkkynen, Elena Donazzan

Proposal for a regulation

Recital 48

Text proposed by the CommissionAmendment
(48) Article 4 of Directive 2002/58/EC should be repealed. Article 4 of Directive 2002/58/EC sets requirements for providers of publicly available electronic communications services as regards safeguarding the security of their services and notification requirements. Subsequently, Directive (EU) 2022/2555 has set new requirements as regards cybersecurity risk-management measures and incident reporting for those providers. In order to reduce overlapping obligations for entities in the electronic communications sector, Article 4 of Directive 2002/58/EC should be repealed. As regards the security of processing of personal data pursuant to Article 4(1) and (1a) of this directive and the notification of personal data breaches pursuant to Article 4(3) to (5) of Directive 2002/58/EC this directive, the Regulation (EU) 2016/679 already provide for comprehensive and up-to-date rules. These rules should therefore apply to providers of publicly available electronic communication services and providers of public communications networks, thereby ensuring that one regime applies to the controllers and processors.(48) Article 4 of Directive 2002/58/EC should be repealed. Article 4 of Directive 2002/58/EC sets requirements for providers of publicly available electronic communications services as regards safeguarding the security of their services and notification requirements. Subsequently, Directive (EU) 2022/2555 has set new requirements as regards cybersecurity risk-management measures and incident reporting for those providers. In order to reduce overlapping obligations for entities in the electronic communications sector, Article 4 of Directive 2002/58/EC should be repealed. As regards the security of processing of personal data pursuant to Article 4(1) and (1a) of this directive and the notification of personal data breaches pursuant to Article 4(3) to (5) of Directive 2002/58/EC this directive, the Regulation (EU) 2016/679 already provide for comprehensive and up-to-date rules. These rules should therefore apply to providers of publicly available electronic communication services and providers of public communications networks, thereby ensuring that one regime applies to the controllers and processors. The fragmented legal requirements in cybersecurity shall be consolidated into harmonized, single-entry-point reporting systems.

Or. en

Amendment 488

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 48

Text proposed by the CommissionAmendment
(48) Article 4 of Directive 2002/58/EC should be repealed. Article 4 of Directive 2002/58/EC sets requirements for providers of publicly available electronic communications services as regards safeguarding the security of their services and notification requirements. Subsequently, Directive (EU) 2022/2555 has set new requirements as regards cybersecurity risk-management measures and incident reporting for those providers. In order to reduce overlapping obligations for entities in the electronic communications sector, Article 4 of Directive 2002/58/EC should be repealed. As regards the security of processing of personal data pursuant to Article 4(1) and (1a) of this directive and the notification of personal data breaches pursuant to Article 4(3) to (5) of Directive 2002/58/EC this directive, the Regulation (EU) 2016/679 already provide for comprehensive and up-to-date rules. These rules should therefore apply to providers of publicly available electronic communication services and providers of public communications networks, thereby ensuring that one regime applies to the controllers and processors.(48) Article 4 of Directive 2002/58/EC should be maintained. That Article sets specific requirements for providers of publicly available electronic communications services as regards safeguarding the security of their services and the notification of security breaches. That Article sets specific requirements for providers of publicly available electronic communications services as regards safeguarding the security of their services and the notification of security breaches. Those requirements are specific to the electronic communications sector and are not fully substituted by the general regimes of Directive (EU) 2022/2555 and Regulation (EU) 2016/679. Its repeal would leave sector-specific obligations without an equivalent, to the detriment of the confidentiality and integrity of communications. Those requirements are specific to the electronic communications sector and are not fully substituted by the general regimes of Directive (EU) 2022/2555 and Regulation (EU) 2016/679. Its repeal would leave sector-specific obligations without an equivalent, to the detriment of the confidentiality and integrity of communications.

Or. en

Justification

The repeal of Article 4 of the ePrivacy Directive would empty of substance the sector-specific security regime applicable to electronic communications, on the assumption that NIS2 and the GDPR fully substitute for it. That assumption is not established. The Union should not dismantle a functioning protection in the name of an alignment whose equivalence is not demonstrated.

Amendment 489

Axel Voss

Proposal for a regulation

Recital 48 a (new)

Text proposed by the CommissionAmendment
(48a) The free movement of personal data within the Union and the protection of natural persons are objectives of equal rank of this Regulation. Where a provision of this Regulation is open to more than one interpretation in respect of processing privileged under Article 10a, preference is to be given to the interpretation that gives effect to both objectives. The privilege rests on an exchange: the controller or processor obtains a presumption of compliance and relief from documentation duties, and in return makes data available for objectives of general interest; that exchange establishes, in the assessment under Article 52(1) of the Charter, the proportionality of the privilege as a whole. The extent of the data to be made available should be proportionate to the nature and scale of the processing and to the size and capacity of the controller or processor. Standards applied in the market, including international standards, may afford safeguards equivalent to those of approved codes of conduct and certification mechanisms; the Board should include a standard in its list where compliance with the standard is independently verifiable and monitored and where its safeguards afford an equivalent level of protection, and should remove it where those conditions cease to be met. The ordinary commercial activities of a micro, small or medium-sized enterprise do not include the making available of personal data against remuneration as its principal activity. Article 10a provides a basis in Union law for the purposes of points (g) and (j) of Article 9(2); whether the processing is necessary remains to be assessed in the individual case, and the essence of the right to data protection is to be respected in every application of the Article. Specific and substantiated indications require concrete elements relating to the processing in question; the assertion of an infringement does not suffice, and full proof is not required. Standardised information fulfils the purpose of Articles 13 and 14 where it enables data subjects to identify the controller, understand the purposes of the processing and exercise their rights. For transfers to third countries, the presumption leaves intact the requirement that data subjects enjoy a level of protection essentially equivalent to that guaranteed within the Union. The rights of data subjects do not depend on the commitment; its withdrawal ends the privilege for the future and leaves obligations already incurred unaffected. The powers of supervisory authorities and the rights and remedies of data subjects shall remain unaffected.

Or. en

Justification

This amendment creates an incentive model for data use serving general-interest objectives, such as intra-group administration, SME operations, research, archiving and statistics. Privileged status is limited to actors that make a data-sharing commitment and follow recognised safeguards, including codes, certification, BCRs or listed standards. The rebuttable presumption rewards accountable governance without lowering protection, excludes gatekeepers and VLOPs/VLOSEs, and covers high-risk processing only after a DPIA.

Amendment 490

Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Sophie Wilmès, Nikola Minchev, Svenja Hahn, Andreas Glück, Katri Kulmuni, João Cotrim De Figueiredo, Ana Vasconcelos

Proposal for a regulation

Recital 48 a (new)

Text proposed by the CommissionAmendment
(48a) The incident reporting obligations under Union cybersecurity and digital legislation impose a significant administrative burden on entities especially because they have divergent timelines, deadlines, reporting thresholds, and other divergent reporting obligations. A harmonised approach is therefore necessary.

Or. en

Amendment 491

Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Sophie Wilmès, Nikola Minchev, Svenja Hahn, Andreas Glück, Katri Kulmuni, João Cotrim De Figueiredo, Ana Vasconcelos

Proposal for a regulation

Recital 48 b (new)

Text proposed by the CommissionAmendment
(48b) To support efficient reporting through the single-entry point, the Commission, together with ENISA, the CSIRTs and competent authorities, should, through implementing acts, develop a European template that maximally harmonizes timelines, deadlines, thresholds, incident type, severity level, impact category, root cause, corrective measures, preventive measures and other data relevant to the reporting obligations. The intended goal of those implementing acts is to maximally align and harmonize the reporting obligations and procedures of the Union legislations that will report through the single-entry point, including Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2016/679 (GDPR, Directive (EU) 2022/2557 (CER), Regulation (EU) No 910/2014 (eIDAS), Regulation (EU) 2022/2554 (DORA), Regulation (EU) 2024/2847 (Cyber Resilience Act), Regulation (EU) 2024/1689 (AI Act). The single-entry point, together with the European template, will cre ate a one-stop european reporting platform, allowing organisations to prepare one notification that will be automatically forwarded to the relevant competent authorities. Those authorities may still request additional information where necessary. The template wille consist of a core section of data points applicable across all reporting obligations from relevant Union legislation, and may be complemented by modular extensions that incorporate sectoral or other data fields specific to a particular Union legal act.

Or. en

Amendment 492

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay

Proposal for a regulation

Recital 49

Text proposed by the CommissionAmendment
(49) Several horizontal or sectorial Union legal acts require the notification of the same event to different authorities using different technical means and channels. The single-entry point for incident reporting should allow entities to fulfil reporting obligations under Directive (EU) 2022/2555, Regulation (EU) 2016/679, Regulation (EU) 2022/2554, Regulation (EU) No 910/2014 and Directive (EU) 2022/2557 by submitting notifications to a single interface. Furthermore, the single-entry point should give a possibility for entities to retrieve information that they have previously submitted using the single-entry point, thereby helping entities to keep track of their compliance with reporting obligations in connection with specific incidents.(49) Several horizontal or sectorial Union legal acts require the notification of the same event to different authorities using different technical means and channels. The EU entry point and national single-entry points for incident reporting should allow entities to fulfil reporting obligations under Directive (EU) 2022/2555, Regulation (EU) 2016/679, Regulation (EU) 2022/2554, Regulation (EU) No 910/2014 and Directive (EU) 2022/2557 by submitting notifications to a single interface. Member States should establish a single national entry point for the submission of those notifications. The competent national authorities should remain solely responsible for receiving, assessing and handling notifications. Information received through the national single entry points may be made available, where relevant and in accordance with applicable Union law, to ENISA for the purposes of situational awareness, trend analysis, risk monitoring and the identification of systemic vulnerabilities. Such cooperation should not affect the competences of national authorities nor the independence of supervisory authorities established under Union law. Furthermore, the layered single-entry points structure should give a possibility for entities to retrieve information that they have previously submitted using the single-entry points, thereby helping entities to keep track of their compliance with reporting obligations in connection with specific incidents.

Or. en

Justification

Simplification for reporting entities does not justify transferring to a Union body competences exercised at national level. The single entry point must be national; ENISA's role is one of aggregation for situational awareness, not of substantive handling.

Amendment 493

Markus Buchheit

Proposal for a regulation

Recital 49

Text proposed by the CommissionAmendment
(49) Several horizontal or sectorial Union legal acts require the notification of the same event to different authorities using different technical means and channels. The single-entry point for incident reporting should allow entities to fulfil reporting obligations under Directive (EU) 2022/2555, Regulation (EU) 2016/679, Regulation (EU) 2022/2554, Regulation (EU) No 910/2014 and Directive (EU) 2022/2557 by submitting notifications to a single interface. Furthermore, the single-entry point should give a possibility for entities to retrieve information that they have previously submitted using the single-entry point, thereby helping entities to keep track of their compliance with reporting obligations in connection with specific incidents.(49) Several horizontal or sectoral Union legal acts require the notification of the same event to different authorities using different technical means and channels. In order to avoid unnecessary duplicate reporting, Member States should be able to provide for national technical solutions or national coordinating points for the structured onward transmission of such notifications. A Union single-entry point should be used only in a supporting role for clearly cross-border or Union-wide systemic incidents and should neither replace nor de facto displace national reporting channels for purely national incidents."

Or. en

Amendment 494

Diana Iovanovici Şoşoacă

Proposal for a regulation

Recital 49

Text proposed by the CommissionAmendment
(49) Several horizontal or sectorial Union legal acts require the notification of the same event to different authorities using different technical means and channels. The single-entry point for incident reporting should allow entities to fulfil reporting obligations under Directive (EU) 2022/2555, Regulation (EU) 2016/679, Regulation (EU) 2022/2554, Regulation (EU) No 910/2014 and Directive (EU) 2022/2557 by submitting notifications to a single interface. Furthermore, the single-entry point should give a possibility for entities to retrieve information that they have previously submitted using the single-entry point, thereby helping entities to keep track of their compliance with reporting obligations in connection with specific incidents.(49) Several horizontal or sectorial Union legal acts require the notification of the same event to different authorities using different technical means and channels. The single-entry point for incident reporting should allow entities to fulfil reporting obligations under Directive (EU) 2022/2555, Regulation (EU) 2016/679, Regulation (EU) 2022/2554, Regulation (EU) No 910/2014 and Directive (EU) 2022/2557 by submitting notifications to a single interface. Furthermore, the single-entry point should give a possibility for entities to retrieve information that they have previously submitted using the single-entry point, thereby helping entities to keep track of their compliance with reporting obligations in connection with specific incidents based on a legal certainty programme, without diverging national interpretations.

Or. ro

Amendment 495

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay

Proposal for a regulation

Recital 49 a (new)

Text proposed by the CommissionAmendment
(49a) The layered single-entry points structure should not result in the centralisation, within a single body, of the storage and processing of incident notifications. In accordance with the principles of subsidiarity and proportionality, and in order to avoid creating a single point of failure that could itself become a target for cybersecurity threats, the single-entry point should be designed as a layered architecture. ENISA should provide a common interface enabling entities to submit a single notification, while the competent authorities designated under the relevant Union legal acts should remain responsible, at national level, for receiving, accessing and processing the information relating to incidents within their respective fields of competence. The EU entry point should accordingly act as a means of routing and interoperability between entities and the competent national authorities, building on the technical solutions and reporting systems already in place at national level, rather than as a centralised repository. The role of ENISA should be limited to the technical operation, routing and format check of the notifications, ENISA not being a recipient of the notifications for substantive purposes. Where ENISA receives information directly that may be relevant for the performance of the tasks of the competent national authorities, it should transmit such information without undue delay to the authorities concerned.

Or. en

Justification

A single database of incident notifications would by its very nature be a target of the first order. The layered architecture preserves the proximity and expertise of national authorities while delivering, for reporting entities, the benefit of a single interface.

Amendment 496

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Matthias Ecke, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Recital 49 a (new)

Text proposed by the CommissionAmendment
(49a) To ensure that Directive (EU) 2022/2555 is applied consistently and proportionately across the Union and in line with the principle of administrative simplification and the 'report-once' policy, duplicative or unclear reporting obligations or diverging national interpretations and additional obligations should be avoided. The Commission should, in cooperation with the Cooperation Group referred to in Article 14 of Directive (EU) 2022/2555 and the European Union Agency for Cybersecurity (ENISA), issue guidance on the harmonised interpretation and application of key obligations under that Directive. These guidelines shall be developed under the relevant sectorial legislation.

Or. en

Justification

The development of detailed guidance on sector-specific cybersecurity obligations should be addressed in the context of the revision of the Cybersecurity Act, which provides the appropriate framework for considering horizontal cybersecurity governance, certification and related guidance mechanisms. This approach ensures coherence between Directive (EU) 2022/2555 and the evolving Union cybersecurity framework, while allowing sector-specific legislation to define requirements reflecting the specific risks and operational characteristics of each sector. It also avoids duplication, divergent interpretations and additional administrative burdens for entities subject to multiple cybersecurity obligations.

Amendment 497

Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Recital 49 a (new)

Text proposed by the CommissionAmendment
(49a) ENISA's role in the reporting process is limited to establishing and operating the single-entry point portal and routing reports to the competent CSIRT(s) without having access to the content of incident reports. Responsibility for the management and follow-up of incident reports remains with the national CSIRTs or competent authorities to which ENISA directs them.

Or. en

Amendment 498

Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Nikola Minchev, Svenja Hahn, Andreas Glück, João Cotrim De Figueiredo, Ana Vasconcelos

Proposal for a regulation

Recital 50

Text proposed by the CommissionAmendment
(50) To ensure the security of the single-entry point, ENISA should take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. When assessing the risk, and the appropriateness and proportionality of those measures, ENISA should take into account the sensitivity of information submitted or disseminated pursuant to the relevant Union legal acts. ENISA should consult competent authorities under the relevant Union legal acts when drafting the technical, operational and organisational measures necessary to establish, maintain and securely operate the single-entry point by making use of existing cooperation groups and networks of Member States established under these acts.(50) To ensure the security of the single-entry point, ENISA should take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. When assessing the risk, and the appropriateness and proportionality of those measures, ENISA should take into account the sensitivity of information submitted or disseminated pursuant to the relevant Union legal acts. ENISA should consult competent authorities under the relevant Union legal acts when drafting the technical, operational and organisational measures necessary to establish, maintain and securely operate the single-entry point by making use of existing cooperation groups and networks of Member States established under these acts. ENISA's role in the reporting process is limited to establishing and operating the single-entry point portal and routing reports to the competent CSIRT(s) without having access to the content of incident reports. Responsibility for the management and follow-up of incident reports remains with the national CSIRTs or competent authorities to which ENISA directs them.

Or. en

Amendment 499

Diana Iovanovici Şoşoacă

Proposal for a regulation

Recital 50

Text proposed by the CommissionAmendment
(50) To ensure the security of the single-entry point, ENISA should take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. When assessing the risk, and the appropriateness and proportionality of those measures, ENISA should take into account the sensitivity of information submitted or disseminated pursuant to the relevant Union legal acts. ENISA should consult competent authorities under the relevant Union legal acts when drafting the technical, operational and organisational measures necessary to establish, maintain and securely operate the single-entry point by making use of existing cooperation groups and networks of Member States established under these acts.(50) To ensure the security of the single-entry point, ENISA should take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point, including measures to protect against cyberattacks. When assessing the risk, and the appropriateness and proportionality of those measures, ENISA should take into account the sensitivity of information submitted or disseminated pursuant to the relevant Union legal acts. ENISA should consult competent authorities under the relevant Union legal acts when drafting the technical, operational and organisational measures necessary to establish, maintain and securely operate the single-entry point by making use of existing cooperation groups and networks of Member States established under these acts, as well as providing for potential penalties in the event of failure to comply with the provisions on data protection and the potential dissemination of personal data without the consent of the persons in question.

Or. ro

Amendment 500

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 50

Text proposed by the CommissionAmendment
(50) To ensure the security of the single-entry point, ENISA should take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. When assessing the risk, and the appropriateness and proportionality of those measures, ENISA should take into account the sensitivity of information submitted or disseminated pursuant to the relevant Union legal acts. ENISA should consult competent authorities under the relevant Union legal acts when drafting the technical, operational and organisational measures necessary to establish, maintain and securely operate the single-entry point by making use of existing cooperation groups and networks of Member States established under these acts.(50) To ensure the security of the layered single-entry points structure, ENISA should take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the EU and national single-entry points and the information submitted or disseminated via the national single-entry points to the EU entry point. When assessing the risk, and the appropriateness and proportionality of those measures, ENISA should take into account the sensitivity of information submitted or disseminated pursuant to the relevant Union legal acts. ENISA should consult competent authorities under the relevant Union legal acts when drafting the technical, operational and organisational measures necessary to establish, maintain and securely operate the layered single-entry points structure by making use of existing cooperation groups and networks of Member States established under these acts.

Or. en

Amendment 501

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Matthias Ecke, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Recital 50

Text proposed by the CommissionAmendment
(50) To ensure the security of the single-entry point, ENISA should take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. When assessing the risk, and the appropriateness and proportionality of those measures, ENISA should take into account the sensitivity of information submitted or disseminated pursuant to the relevant Union legal acts. ENISA should consult competent authorities under the relevant Union legal acts when drafting the technical, operational and organisational measures necessary to establish, maintain and securely operate the single-entry point by making use of existing cooperation groups and networks of Member States established under these acts.(50) To ensure the security of the single-entry point, ENISA should take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. When assessing the risk, and the appropriateness and proportionality of those measures, ENISA should take into account the sensitivity of information submitted or disseminated pursuant to the relevant Union legal acts. ENISA should consult and take utmost account of feedback from competent authorities under the relevant Union legal acts when drafting the technical, operational and organisational measures necessary to establish, maintain and securely operate the single-entry point by making use of existing cooperation groups and networks of Member States established under these acts.

Or. en

Amendment 502

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 50 a (new)

Text proposed by the CommissionAmendment
(50a) A layered architecture also strengthens the security and resilience of incident reporting. By limiting the concentration of sensitive information within a single body and by relying on the involvement of national authorities, such an architecture reduces the systemic risk associated with a single point of failure. To that end, and consistently with the fact that ENISA should not, as a rule, have access to the notifications submitted through the single-entry point, the security measures referred to in this Regulation should ensure the confidentiality and integrity of information in transit between reporting entities and the competent national authorities. The EU entry point should become operational for a given Union legal act only after the Member States have assessed and confirmed that it meets those requirements and is interoperable with the national reporting arrangements. Member States should not be required to dismantle or replace functioning national reporting systems, nor to bear disproportionate adaptation costs.

Or. en

Justification

Conditions the deployment of the single entry point on prior verification of its interoperability by the Member States, and rules out any obligation to dismantle functioning national systems.

Amendment 503

Diana Iovanovici Şoşoacă

Proposal for a regulation

Recital 51

Text proposed by the CommissionAmendment
(51) Before enabling the notification of incidents, ENISA should pilot the functioning of the single-entry point which should include a thorough testing of the specificities and requirements for the notifications for the relevant Union legal acts. Based on the results of the piloting, the Commission should assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. The Commission should consult the CSIRTs network and the competent authorities under the relevant Union legal acts, by making use of existing cooperation groups and networks of Member States established under these acts, when carrying out the assessment. Where the Commission finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it should publish a notice to that effect in the Official Journal of the European Union. In case the Commission considers that the proper functioning, reliability, integrity and confidentiality is not ensured, ENISA should take all necessary corrective measures, followed by a reassessment by the Commission.(51) Before enabling the notification of incidents, ENISA should pilot the functioning of the single-entry point which should include a thorough testing of the specificities and requirements for the notifications for the relevant Union legal acts. Based on the results of the piloting, the Commission should assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. The Commission should consult the CSIRTs network and the competent authorities under the relevant Union legal acts, by making use of existing cooperation groups and networks of Member States established under these acts, when carrying out the assessment. Where the Commission finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it should publish a notice to that effect in the Official Journal of the European Union. In case the Commission considers that the proper functioning, reliability, integrity and confidentiality is not ensured, ENISA should take all necessary corrective measures, including punitive measures for failure to comply with the provisions in force, followed by a reassessment by the Commission and notification of the respective reassessment measures to Parliament and the Council.

Or. ro

Amendment 504

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Matthias Ecke, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Recital 51

Text proposed by the CommissionAmendment
(51) Before enabling the notification of incidents, ENISA should pilot the functioning of the single-entry point which should include a thorough testing of the specificities and requirements for the notifications for the relevant Union legal acts. Based on the results of the piloting, the Commission should assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. The Commission should consult the CSIRTs network and the competent authorities under the relevant Union legal acts, by making use of existing cooperation groups and networks of Member States established under these acts, when carrying out the assessment. Where the Commission finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it should publish a notice to that effect in the Official Journal of the European Union. In case the Commission considers that the proper functioning, reliability, integrity and confidentiality is not ensured, ENISA should take all necessary corrective measures, followed by a reassessment by the Commission.(51) Before enabling the notification of incidents, ENISA should pilot the functioning of the single-entry point which should include a thorough testing of the specificities and requirements for the notifications for the relevant Union legal acts. Based on the results of the piloting, the Commission should assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. The Commission should consult the CSIRTs network and the competent authorities under the relevant Union legal acts, by making use of existing cooperation groups and networks of Member States established under these acts, when carrying out the assessment. Where the Commission finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it should publish a notice to that effect in the Official Journal of the European Union. In case the Commission considers that the proper functioning, reliability, integrity and confidentiality is not ensured, ENISA should take all necessary corrective measures without undue delay, followed by a reassessment by the Commission without undue delay.

Or. en

Amendment 505

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 51

Text proposed by the CommissionAmendment
(51) Before enabling the notification of incidents, ENISA should pilot the functioning of the single-entry point which should include a thorough testing of the specificities and requirements for the notifications for the relevant Union legal acts. Based on the results of the piloting, the Commission should assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. The Commission should consult the CSIRTs network and the competent authorities under the relevant Union legal acts, by making use of existing cooperation groups and networks of Member States established under these acts, when carrying out the assessment. Where the Commission finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it should publish a notice to that effect in the Official Journal of the European Union. In case the Commission considers that the proper functioning, reliability, integrity and confidentiality is not ensured, ENISA should take all necessary corrective measures, followed by a reassessment by the Commission.(51) Before enabling the notification of incidents, ENISA should pilot the functioning of the EU entry point which should include a thorough testing of the specificities and requirements for the notifications for the relevant Union legal acts. Based on the results of the piloting, the Commission should assess the proper functioning, reliability, integrity and confidentiality of the EU entry point. The Commission should consult the CSIRTs network and the competent authorities under the relevant Union legal acts, by making use of existing cooperation groups and networks of Member States established under these acts, when carrying out the assessment. Where the Commission finds that the EU entry point ensures the proper functioning, reliability, integrity and confidentiality, it should publish a notice to that effect in the Official Journal of the European Union. In case the Commission considers that the proper functioning, reliability, integrity and confidentiality is not ensured, ENISA should take all necessary corrective measures, followed by a reassessment by the Commission.

Or. en

Amendment 506

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 52

Text proposed by the CommissionAmendment
(52) To ensure the continuity and interoperability with existing national technical solutions that facilitate incident reporting, to the extent feasible, ENISA should take into account such national technical solutions when developing the specifications on the technical, operational and organisational measures necessary to establish, maintain and securely operate the single-entry point. Further, ENISA should consider technical protocols and tools such as application programming interfaces and machine-readable standards that enable entities to integrate reporting obligations into business processes, and authorities to connect the single-entry point with their national reporting systems.(52) To ensure the continuity and interoperability with existing national technical solutions that facilitate incident reporting, to the extent feasible, ENISA should take into account such national technical solutions when developing the specifications on the technical, operational and organisational measures necessary to establish, maintain and securely operate the single-entry point. Further, ENISA should consider technical protocols and tools such as application programming interfaces and machine-readable standards that enable entities to integrate reporting obligations into business processes, and authorities to connect with the EU entry point through their national reporting systems.

Or. en

Amendment 507

Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Recital 52 a (new)

Text proposed by the CommissionAmendment
(52a) The incident reporting obligations under Union cybersecurity and digital legislation impose a significant administrative burden on entities especially because they have divergent timelines, deadlines, reporting thresholds, and other divergent reporting obligations. A harmonised approach is therefore necessary.

Or. en

Amendment 508

Diana Iovanovici Şoşoacă

Proposal for a regulation

Recital 53

Text proposed by the CommissionAmendment
(53) To ensure that the single-entry point enables the relevant entities to submit the type of information and the format required under the relevant Union legal acts, ENISA should consult the Commission and the competent authorities under those acts. Where a Union legal act is not fully harmonized regarding the type of information and the format of notifications, Member States should inform ENISA about their national provisions.(53) To ensure that the single-entry point enables the relevant entities to submit the type of information and the format required under the relevant Union legal acts, ENISA should consult the Commission and the competent authorities under those acts. Where a Union legal act is not fully harmonized regarding the type of information and the format of notifications, Member States should inform ENISA about their national provisions. Accordingly, ENISA, in cooperation with the Commission and the competent authorities, should establish a common framework for the type of information and the format of notifications, including technical guidelines, interfaces and transmission channels, reporting deadlines and update mechanisms. Where a Union legal act is not fully harmonised for this purpose, Member States will inform ENISA about their national provisions, and ENISA, in consultation with the Commission, will ensure interoperability, adaptability to regulatory developments and compliance monitoring.

Or. ro

Amendment 509

Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Recital 53

Text proposed by the CommissionAmendment
(53) To ensure that the single-entry point enables the relevant entities to submit the type of information and the format required under the relevant Union legal acts, ENISA should consult the Commission and the competent authorities under those acts. Where a Union legal act is not fully harmonized regarding the type of information and the format of notifications, Member States should inform ENISA about their national provisions.(53) To ensure that the single-entry point enables the relevant entities to submit the type of information and the format required under the relevant Union legal acts, ENISA should consult the Commission and the competent authorities under those acts. Where a Union legal act is not fully harmonized regarding the type of information and the format of notifications, Member States should inform ENISA about their national provisions, and the Commission would be empowered to issue a delegated act to harmonize further.

Or. en

Amendment 510

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 53

Text proposed by the CommissionAmendment
(53) To ensure that the single-entry point enables the relevant entities to submit the type of information and the format required under the relevant Union legal acts, ENISA should consult the Commission and the competent authorities under those acts. Where a Union legal act is not fully harmonized regarding the type of information and the format of notifications, Member States should inform ENISA about their national provisions.(53) To ensure that the layered single-entry points structure enables the relevant entities to submit the type of information and the format required under the relevant Union legal acts, ENISA should consult the Commission and the competent authorities under those acts. Where a Union legal act is not fully harmonized regarding the type of information and the format of notifications, Member States should inform ENISA about their national provisions.

Or. en

Amendment 511

Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Recital 53 a (new)

Text proposed by the CommissionAmendment
(53a) To support efficient reporting through the single-entry point, the Commission, together with ENISA, the CSIRTs and competent authorities, should, through delegated acts, develop a European template that maximally harmonizes timelines, deadlines, thresholds, incident type, severity level, impact category, root cause, corrective measures, preventive measures and other data relevant to the reporting obligations. The intended goal of those delegated acts is to maximally align and harmonize the reporting obligations and procedures of the Union legislations that will report through the single-entry point, including Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2016/679 (GDPR, Directive (EU) 2022/2557 (CER), Regulation (EU) No 910/2014 (eIDAS), Regulation (EU) 2022/2554 (DORA), and Regulation (EU) 2024/2847 (Cyber Resilience Act)). The single-entry point, together with the European template, will create a one-stop European reporting platform, allowing organisations to prepare one notification that will be automatically forwarded to the relevant competent authorities. Those authorities may still request additional information where necessary. The template will consist of a core section of data points applicable across all reporting obligations from relevant Union legislation, and may be complemented by modular extensions that incorporate sectoral or other data fields specific to a particular Union legal act.

Or. en

Amendment 512

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 54

Text proposed by the CommissionAmendment
(54) Based on Regulation (EU) 2022/2554, the financial sector has been at the forefront in implementing a harmonised, comprehensive and effective framework, including with regard to incident reporting. In order to simplify compliance, it is appropriate to align the incident reporting framework established under Regulation (EU) 2022/2554 with the single-entry point, while ensuring continuity and stability of the existing reporting framework, and considering that the single-entry point would be operational after it has been assessed that it ensures the proper functioning, reliability, integrity and confidentiality. Further, Regulation (EU) 2022/2554 has introduced standardised reporting templates streamlining the content of reports for major ICT-related incidents for the financial sector. The experience gained from the adoption of these templates provides valuable insights and best practices that should be taken into account when specifying the type of information, the format and the procedure of a notification for the purposes of reporting to the single-entry point under Directive (EU) 2022/2555, Directive (EU) 2022/2557 or Regulation (EU) 2016/679, where appropriate. For this purpose, the Commission should take due account of the regulatory technical standards adopted pursuant to Regulation (EU) 2022/2554, which specify the content of the initial notification, as well as the intermediate and final reports, concerning major ICT-related incidents. This approach aims to ensure consistency, promote synergies and reduce administrative burden on entities by minimizing the number of data fields that entities are required to complete, thereby facilitating more efficient and streamlined reporting processes.(54) Based on Regulation (EU) 2022/2554, the financial sector has been at the forefront in implementing a harmonised, comprehensive and effective framework, including with regard to incident reporting. In order to simplify compliance, it is appropriate to align the incident reporting framework established under Regulation (EU) 2022/2554 with the single-entry point, while ensuring continuity and stability of the existing reporting framework, and considering that the layered single-entry points structure would be operational after it has been assessed that it ensures the proper functioning, reliability, integrity and confidentiality. Further, Regulation (EU) 2022/2554 has introduced standardised reporting templates streamlining the content of reports for major ICT-related incidents for the financial sector. The experience gained from the adoption of these templates provides valuable insights and best practices that should be taken into account when specifying the type of information, the format and the procedure of a notification for the purposes of reporting to the single-entry point under Directive (EU) 2022/2555, Directive (EU) 2022/2557 or Regulation (EU) 2016/679, where appropriate. For this purpose, the Commission should take due account of the regulatory technical standards adopted pursuant to Regulation (EU) 2022/2554, which specify the content of the initial notification, as well as the intermediate and final reports, concerning major ICT-related incidents. This approach aims to ensure consistency, promote synergies and reduce administrative burden on entities by minimizing the number of data fields that entities are required to complete, thereby facilitating more efficient and streamlined reporting processes.

Or. en

Amendment 513

Diana Iovanovici Şoşoacă

Proposal for a regulation

Recital 55

Text proposed by the CommissionAmendment
(55) Under the relevant Union legal acts, certain incident-specific information is to be shared at a subsequent stage between competent authorities to facilitate effective oversight and coordination. Therefore, the single-entry point should be designed to accommodate and support the exchange of information at that level for each relevant Union legal act, ensuring that appropriate data flows between authorities are enabled in a secure, timely, and efficient manner, should the Member States decide to make use of this additional feature.(55) Under the relevant Union legal acts, certain incident-specific information is to be shared at a subsequent stage between competent authorities to facilitate effective oversight and coordination. Therefore, the single-entry point should be designed to accommodate and support the exchange of information at that level for each relevant Union legal act, ensuring that appropriate data flows between authorities are enabled in a secure, timely, and efficient manner, should the Member States decide to make use of this additional feature, and rapid response solutions exist in the event of unforeseen incidents.

Or. ro

Amendment 514

Markus Buchheit

Proposal for a regulation

Recital 55

Text proposed by the CommissionAmendment
(55) Under the relevant Union legal acts, certain incident-specific information is to be shared at a subsequent stage between competent authorities to facilitate effective oversight and coordination. Therefore, the single-entry point should be designed to accommodate and support the exchange of information at that level for each relevant Union legal act, ensuring that appropriate data flows between authorities are enabled in a secure, timely, and efficient manner, should the Member States decide to make use of this additional feature.(55) Under the relevant Union legal acts, certain incident-specific information may, in duly justified cases, be shared at a subsequent stage between the competent national authorities in order to facilitate effective oversight and coordination. Any technical support at Union level should be provided only at the request of the Member States concerned and exclusively for cross-border or Union-wide systemic incidents. Routine or automated Union-wide exchange of sensitive incident information shall be excluded.

Or. en

Amendment 515

Markus Buchheit

Proposal for a regulation

Recital 56

Text proposed by the CommissionAmendment
(56) To ensure that incident reporting is carried out via the single-entry point Directive (EU) 2022/2555, Regulation (EU) 2016/679, Regulation (EU) 2022/2554, Regulation (EU) 910/2014, and Directive (EU) 2022/2557 should therefore be amended accordingly. The single-entry point should start being used for the purpose of reporting under those acts within 18 months from the entry into force of this Regulation. When the Commission initiates the mechanisms of the notice delaying the date of application to 24 months from the entry into force of the Regulation, the corresponding provisions of Directive (EU) 2022/2555, Regulation (EU) 910/2014, Regulation (EU) 2022/2554 and Directive (EU) 2022/2557 should continue to apply for the purpose of meeting the reporting obligations laid down in the provisions.(56) In order to reduce duplicate reporting, Member States may provide for interoperable national reporting solutions. Amendments to Directive (EU) 2022/2555, Regulation (EU) 2016/679, Regulation (EU) 2022/2554, Regulation (EU) No 910/2014, and Directive (EU) 2022/2557 shall not result in a mandatory Union-wide central reporting structure for purely national incidents. The single-entry point should start being used for the purpose of reporting under those acts within 18 months from the entry into force of this Regulation. When the Commission initiates the mechanisms of the notice delaying the date of application to 24 months from the entry into force of the Regulation, the corresponding provisions of Directive (EU) 2022/2555, Regulation (EU) 910/2014, Regulation (EU) 2022/2554 and Directive (EU) 2022/2557 should continue to apply for the purpose of meeting the reporting obligations laid down in the provisions.

Or. en

Amendment 516

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Recital 56

Text proposed by the CommissionAmendment
(56) To ensure that incident reporting is carried out via the single-entry point Directive (EU) 2022/2555, Regulation (EU) 2016/679, Regulation (EU) 2022/2554, Regulation (EU) 910/2014, and Directive (EU) 2022/2557 should therefore be amended accordingly. The single-entry point should start being used for the purpose of reporting under those acts within 18 months from the entry into force of this Regulation. When the Commission initiates the mechanisms of the notice delaying the date of application to 24 months from the entry into force of the Regulation, the corresponding provisions of Directive (EU) 2022/2555, Regulation (EU) 910/2014, Regulation (EU) 2022/2554 and Directive (EU) 2022/2557 should continue to apply for the purpose of meeting the reporting obligations laid down in the provisions.(56) To ensure that incident reporting is carried out via the single-entry point Directive (EU) 2022/2555, Regulation (EU) 2016/679, Regulation (EU) 2022/2554, Regulation (EU) 910/2014, Directive (EU) 2022/2557 and Regulation (EU) 2024/2847 should therefore be amended accordingly. The single-entry point should start being used for the purpose of reporting under those acts within 18 months from the entry into force of this Regulation. When the Commission initiates the mechanisms of the notice delaying the date of application to 24 months from the entry into force of the Regulation, the corresponding provisions of Directive (EU) 2022/2555, Regulation (EU) 910/2014, Regulation (EU) 2022/2554, Directive (EU) 2022/2557 and Regulation (EU) 2024/2847 should continue to apply for the purpose of meeting the reporting obligations laid down in the provisions.

Or. en

Amendment 517

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 56

Text proposed by the CommissionAmendment
(56) To ensure that incident reporting is carried out via the single-entry point Directive (EU) 2022/2555, Regulation (EU) 2016/679, Regulation (EU) 2022/2554, Regulation (EU) 910/2014, and Directive (EU) 2022/2557 should therefore be amended accordingly. The single-entry point should start being used for the purpose of reporting under those acts within 18 months from the entry into force of this Regulation. When the Commission initiates the mechanisms of the notice delaying the date of application to 24 months from the entry into force of the Regulation, the corresponding provisions of Directive (EU) 2022/2555, Regulation (EU) 910/2014, Regulation (EU) 2022/2554 and Directive (EU) 2022/2557 should continue to apply for the purpose of meeting the reporting obligations laid down in the provisions.(56) To ensure that incident reporting is carried out via the layered single-entry points Directive (EU) 2022/2555, Regulation (EU) 2016/679, Regulation (EU) 2022/2554, Regulation (EU) 910/2014, and Directive (EU) 2022/2557 should therefore be amended accordingly. The layered single-entry points structure should start being used for the purpose of reporting under those acts within 18 months from the entry into force of this Regulation. When the Commission initiates the mechanisms of the notice delaying the date of application to 24 months from the entry into force of the Regulation, the corresponding provisions of Directive (EU) 2022/2555, Regulation (EU) 910/2014, Regulation (EU) 2022/2554 and Directive (EU) 2022/2557 should continue to apply for the purpose of meeting the reporting obligations laid down in the provisions.

Or. en

Amendment 518

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Recital 58 a (new)

Text proposed by the CommissionAmendment
(58a) The simplification measures introduced by this Regulation should not result in a reduction of the level of protection for data subjects, users and consumers guaranteed under Regulations (EU) 2016/679 and (EU) 2023/2854, nor weaken safeguards ensuring fair competition, data portability, transparency and user control. This Regulation should not affect the application of the rules on competition, and in particular Articles 101 and 102 TFEU. The measures provided for in this Regulation should not be used to restrict competition in a manner contrary to the TFEU.

Or. en

Amendment 519

João Oliveira

Proposal for a regulation

Recital 59

Text proposed by the CommissionAmendment
(59) Regulation (EU) 2019/1150 establishes a targeted set of mandatory rules at Union level to ensure a fair, predictable, sustainable and trusted online business environment within the internal market. Regulation (EU) 2022/2065 and Regulation (EU) 2022/1925 provide a comprehensive regulatory framework for a safe, predictable and trusted online environments for all end-users of online services, and establish a level playing field for businesses in digital markets. In the interest of simplification of Union legislation in the field of online intermediation services and online platforms, and given that the objectives and material provisions of the Platform-to-Business Regulation are largely covered by the Digital Services Act and the Digital Markets Act, Regulation (EU) 2019/1050 should be repealed. Regulation (EU) 2022/2065 and Regulation (EU) 2022/1925 contribute to a fully harmonised regulatory framework for digital services and digital markets, by approximating national measures concerning the requirements for providers of intermediary services and the contestability and fairness of core platforms services provided by gatekeepers. For purposes of legal certainty, selected definitions in Article 2, the provisions on restrictions and suspensions in Article 4, as well as on the internal complaint-handling system in Article 11 of Regulation (EU) 2019/1150 that are cross-referenced by other legal acts, in particular Directive (EU) 2023/2831 on improving working conditions in platform work, and Article 15 ensuring enforcement, will temporarily remain in application until the original acts are amended.deleted

Or. pt

Amendment 520

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Recital 59

Text proposed by the CommissionAmendment
(59) Regulation (EU) 2019/1150 establishes a targeted set of mandatory rules at Union level to ensure a fair, predictable, sustainable and trusted online business environment within the internal market. Regulation (EU) 2022/2065 and Regulation (EU) 2022/1925 provide a comprehensive regulatory framework for a safe, predictable and trusted online environments for all end-users of online services, and establish a level playing field for businesses in digital markets. In the interest of simplification of Union legislation in the field of online intermediation services and online platforms, and given that the objectives and material provisions of the Platform-to-Business Regulation are largely covered by the Digital Services Act and the Digital Markets Act, Regulation (EU) 2019/1050 should be repealed. Regulation (EU) 2022/2065 and Regulation (EU) 2022/1925 contribute to a fully harmonised regulatory framework for digital services and digital markets, by approximating national measures concerning the requirements for providers of intermediary services and the contestability and fairness of core platforms services provided by gatekeepers. For purposes of legal certainty, selected definitions in Article 2, the provisions on restrictions and suspensions in Article 4, as well as on the internal complaint-handling system in Article 11 of Regulation (EU) 2019/1150 that are cross-referenced by other legal acts, in particular Directive (EU) 2023/2831 on improving working conditions in platform work, and Article 15 ensuring enforcement, will temporarily remain in application until the original acts are amended.deleted

Or. en

Amendment 521

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Recital 59

Text proposed by the CommissionAmendment
(59) Regulation (EU) 2019/1150 establishes a targeted set of mandatory rules at Union level to ensure a fair, predictable, sustainable and trusted online business environment within the internal market. Regulation (EU) 2022/2065 and Regulation (EU) 2022/1925 provide a comprehensive regulatory framework for a safe, predictable and trusted online environments for all end-users of online services, and establish a level playing field for businesses in digital markets. In the interest of simplification of Union legislation in the field of online intermediation services and online platforms, and given that the objectives and material provisions of the Platform-to-Business Regulation are largely covered by the Digital Services Act and the Digital Markets Act, Regulation (EU) 2019/1050 should be repealed. Regulation (EU) 2022/2065 and Regulation (EU) 2022/1925 contribute to a fully harmonised regulatory framework for digital services and digital markets, by approximating national measures concerning the requirements for providers of intermediary services and the contestability and fairness of core platforms services provided by gatekeepers. For purposes of legal certainty, selected definitions in Article 2, the provisions on restrictions and suspensions in Article 4, as well as on the internal complaint-handling system in Article 11 of Regulation (EU) 2019/1150 that are cross-referenced by other legal acts, in particular Directive (EU) 2023/2831 on improving working conditions in platform work, and Article 15 ensuring enforcement, will temporarily remain in application until the original acts are amended.deleted

Or. en

Amendment 522

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Recital 59

Text proposed by the CommissionAmendment
(59) Regulation (EU) 2019/1150 establishes a targeted set of mandatory rules at Union level to ensure a fair, predictable, sustainable and trusted online business environment within the internal market. Regulation (EU) 2022/2065 and Regulation (EU) 2022/1925 provide a comprehensive regulatory framework for a safe, predictable and trusted online environments for all end-users of online services, and establish a level playing field for businesses in digital markets. In the interest of simplification of Union legislation in the field of online intermediation services and online platforms, and given that the objectives and material provisions of the Platform-to-Business Regulation are largely covered by the Digital Services Act and the Digital Markets Act, Regulation (EU) 2019/1050 should be repealed. Regulation (EU) 2022/2065 and Regulation (EU) 2022/1925 contribute to a fully harmonised regulatory framework for digital services and digital markets, by approximating national measures concerning the requirements for providers of intermediary services and the contestability and fairness of core platforms services provided by gatekeepers. For purposes of legal certainty, selected definitions in Article 2, the provisions on restrictions and suspensions in Article 4, as well as on the internal complaint-handling system in Article 11 of Regulation (EU) 2019/1150 that are cross-referenced by other legal acts, in particular Directive (EU) 2023/2831 on improving working conditions in platform work, and Article 15 ensuring enforcement, will temporarily remain in application until the original acts are amended.(59) Regulation (EU) 2019/1150 establishes a targeted set of mandatory rules at Union level to ensure a fair, predictable, sustainable and trusted online business environment within the internal market. Regulation (EU) 2022/2065 and Regulation (EU) 2022/1925 provide a comprehensive regulatory framework for a safe, predictable and trusted online environments for all end-users of online services, and establish a level playing field for businesses in digital markets. (EU) 2019/1150 should be maintained. That Regulation protects business users of online intermediation services against unilateral practices, in particular through requirements relating to notice periods for changes to terms and conditions, the statement of reasons for restrictions, suspensions and terminations, transparency of ranking, and access to an internal complaint-handling system. Those protections are not substituted by Regulation (EU) 2022/2065, which pursues a different objective and protects recipients of the service, nor by Regulation (EU) 2022/1925, which applies only to undertakings designated as gatekeepers. A large number of online intermediation services on which micro, small and medium-sized enterprises depend fall within neither of those categories. Its repeal would therefore deprive those enterprises of their only source of protection against unilateral practices, without any equivalent safeguard. Regulation (EU) 2022/2065 and Regulation (EU) 2022/1925 contribute to a fully harmonised regulatory framework for digital services and digital markets, by approximating national measures concerning the requirements for providers of intermediary services and the contestability and fairness of core platforms services provided by gatekeepers. For purposes of legal certainty, selected definitions in Article 2, the provisions on restrictions and suspensions in Article 4, as well as on the internal complaint-handling system in Article 11 of Regulation (EU) 2019/1150 that are cross-referenced by other legal acts, in particular Directive (EU) 2023/2831 on improving working conditions in platform work, and Article 15 ensuring enforcement, will temporarily remain in application until the original acts are amended.

Or. en

Amendment 523

Tomas Tobé, Arba Kokalari, Jörgen Warborn

Proposal for a regulation

Recital 59

Text proposed by the CommissionAmendment
(59) Regulation (EU) 2019/1150 establishes a targeted set of mandatory rules at Union level to ensure a fair, predictable, sustainable and trusted online business environment within the internal market. Regulation (EU) 2022/2065 and Regulation (EU) 2022/1925 provide a comprehensive regulatory framework for a safe, predictable and trusted online environments for all end-users of online services, and establish a level playing field for businesses in digital markets. In the interest of simplification of Union legislation in the field of online intermediation services and online platforms, and given that the objectives and material provisions of the Platform-to-Business Regulation are largely covered by the Digital Services Act and the Digital Markets Act, Regulation (EU) 2019/1050 should be repealed. Regulation (EU) 2022/2065 and Regulation (EU) 2022/1925 contribute to a fully harmonised regulatory framework for digital services and digital markets, by approximating national measures concerning the requirements for providers of intermediary services and the contestability and fairness of core platforms services provided by gatekeepers. For purposes of legal certainty, selected definitions in Article 2, the provisions on restrictions and suspensions in Article 4, as well as on the internal complaint-handling system in Article 11 of Regulation (EU) 2019/1150 that are cross-referenced by other legal acts, in particular Directive (EU) 2023/2831 on improving working conditions in platform work, and Article 15 ensuring enforcement, will temporarily remain in application until the original acts are amended.(59) Regulation (EU) 2019/1150 establishes a targeted set of mandatory rules at Union level to ensure a fair, predictable, sustainable and trusted online business environment within the internal market. Regulation (EU) 2022/2065 and Regulation (EU) 2022/1925 provide a comprehensive regulatory framework for a safe, predictable and trusted online environments for all end-users of online services, and establish a level playing field for businesses in digital markets. In the interest of simplification of Union legislation in the field of online intermediation services and online platforms, and given that the objectives and material provisions of the Platform-to-Business Regulation are largely covered by the Digital Services Act and the Digital Markets Act, several provisions of Regulation (EU) 2019/1050 should be deleted. Regulation (EU) 2022/2065 and Regulation (EU) 2022/1925 contribute to a fully harmonised regulatory framework for digital services and digital markets, by approximating national measures concerning the requirements for providers of intermediary services and the contestability and fairness of core platforms services provided by gatekeepers. For purposes of legal certainty and for purposes of keeping a necessary level of protection for business users, selected definitions in Article 2, provisions on terms of conditions in Article 3, restrictions and suspensions in Article 4, on ranking in Article 5, and on differentiated treatment in Article 7, on the internal complaint-handling system in Article 11 of Regulation (EU) 2019/1150 and provisions in Article 15 ensuring enforcement and in Article 18(1) mandating the Commission to evaluate that Regulation are maintained.

Or. en

Justification

Regulation (EU) 2019/1150 fills a gap that is not fully covered by Regulation (EU) 2022/2065 or Regulation (EU) 2022/1925. To avoid overlaps while keeping safeguards for SMEs that rely on online intermediaries, some provisions in Regulation (EU) 2019/1150 should be maintained.

Amendment 524

João Oliveira

Proposal for a regulation

Recital 60

Text proposed by the CommissionAmendment
(60) Given the technical nature of the amendments proposed in this Regulation and the urgency to deliver on a simplified legal framework, this Regulation should enter into force immediately after its publication in the Official Journal. As appropriate, transitional periods should be afforded for Member States and regulated entities to adjust to the rules.deleted

Or. pt

Amendment 525

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Recital 60

Text proposed by the CommissionAmendment
(60) Given the technical nature of the amendments proposed in this Regulation and the urgency to deliver on a simplified legal framework, this Regulation should enter into force immediately after its publication in the Official Journal. As appropriate, transitional periods should be afforded for Member States and regulated entities to adjust to the rules.(60) Given the nature of the amendments proposed in this Regulation and the need to deliver on a simplified legal framework while providing time for enterprises to adapt, this Regulation should enter into force within a reasonable timeframe after its publication in the Official Journal. As appropriate, transitional periods should be afforded for Member States and regulated entities to adjust to the rules and for data subjects, users and consumers to become aware of the changes and their rights .

Or. en

Amendment 526

Francesco Torselli

Proposal for a regulation

Recital 60 a (new)

Text proposed by the CommissionAmendment
(60a) Advances in neurotechnology and artificial intelligence make it possible to derive information about individuals’ cognitive, emotional and mental states, including through the automated processing of personal data other than that directly collected by the nervous system. With a view to providing a high level of protection for fundamental rights, it should be clarified that Regulation (EU) 2016/679 also applies to processing operations that produce cognitive inferences likely to affect a person’s dignity, decision-making autonomy and free development.

Or. it