Skip to content
EU Parl Watch

amendment list, 27 July 2026

Amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557 as regards the simplification of the digital legislative framework, and repealing Regulations (EU) 2018/1807, (EU) 2019/1150, (EU) 2022/868, and Directive (EU) 2019/1024 (Digital Omnibus)

Document CJ72-AM-791071 · (COM(2025)0837 – 2025/0360(COD))

Committee on Industry, Research and Energy Committee on Civil Liberties, Justice and Home Affairs

On Parliament’s site PDF Word

Full text

Jump to an amendment (250)
Text 2,183 paragraphs

Amendment 527

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point a

Regulation (EU) 2023/2854

Article 1 – paragraph 1 – point ea

Text proposed by the CommissionAmendment
(ea) voluntary registration of data intermediation services;deleted

Or. en

Justification

This amendment preserves a stronger and more reliable oversight framework for data intermediation services. Maintaining mandatory registration helps ensure transparency, accountability and effective supervision, particularly where sensitive or high-risk data processing activities are involved, and contributes to greater trust and legal certainty within the European data-sharing ecosystem.

Amendment 528

Damian Boeselager

Read the rest (2,171 paragraphs)

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point a

Regulation (EU) 2023/2854

Article 1 – paragraph 1 – point ea

Text proposed by the CommissionAmendment
(ea) voluntary registration of data intermediation services;(ea) notification and supervisory framework for the provision of data intermediation services;

Or. en

Amendment 529

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point a

Regulation (EU) 2023/2854

Article 1 – paragraph 1 – point ea

Text proposed by the CommissionAmendment
(ea) voluntary registration of data intermediation services;(ea) mandatory registration of data intermediation services;

Or. pt

Amendment 530

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point a

Regulation (EU) 2023/2854

Article 1 – Paragraph 1 – point ea a (new)

Text proposed by the CommissionAmendment
(eaa) voluntary registration of providers of data processing services that process pseudonymised data which have undergone state-of-the-art privacy-preserving and privacy-enhancing techniques on the basis of Article 6(1)(f) of Regulation (EU) 2016/679;

Or. en

Justification

The debates surrounding the codification of the case-law of the Court of Justice on the concept of pseudonymised data have revealed an urgent need to clarify the legal status of this category of data. Such debates cannot be settled by a mere definition of personal data, but only through guidelines enabling economic operators to take all appropriate risk-mitigation measures so as to ensure their legal certainty and their due diligence. In order to produce guidelines informed by the best practices of data holders, this amendment establishes a voluntary registration scheme. This scheme will feed the work of the European Data Innovation Board, which, in cooperation with the European Data Protection Board and the Commission, will be able to issue such guidelines.

Amendment 531

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point a

Regulation (EU) 2023/2854

Article 1 – Paragraph 1 – point ea b (new)

Text proposed by the CommissionAmendment
(eab) voluntary registration of providers of data processing services that process high-value data sets or sensitive trade secrets;

Or. en

Justification

For data processing services handling high-value or sensitive data — whether personal data, open public data or economic data (industrial data, trade secrets) — a voluntary registration scheme would allow operators to make themselves known to the European Data Innovation Board, to take part in its work and to share their best practices with operators subject to the same obligations.

Amendment 532

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point a

Regulation (EU) 2023/2854

Article 1 – Paragraph 1 – point ea c (new)

Text proposed by the CommissionAmendment
(eac) voluntary registration of providers of data processing services on which the performance of a function in the general interest or the continuity of an essential service in the Union depends, and which are exposed to unilateral suspension, switching obstacles or transfer to a third country;

Or. en

Justification

The Regulation pays sustained attention to the risks arising from transfers — whether forced or voluntary — of sensitive data to third countries, and to the risk of disruption of digital services through unilateral measures of an extraterritorial nature. A voluntary registration scheme for providers on which the performance of a function in the general interest or the continuity of an essential service in the Union depends would enable such providers to make themselves known to the European Data Innovation Board and would inform the definition of protective measures against such extraterritorial reach.

Amendment 533

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point a

Regulation (EU) 2023/2854

Article 1 – Paragraph 1 – point ea d (new)

Text proposed by the CommissionAmendment
(ead) voluntary registration of providers of data processing services which process sensitive data on the basis of legitimate interest for the research and development of innovative solutions and processes;

Or. en

Justification

The Regulation seeks to lift the ambiguity surrounding the status of pseudonymised data in order to make high-value datasets available for the research and development of innovative solutions and processes. A voluntary registration scheme for providers of data processing services which process sensitive data on the basis of legitimate interest, pursuant to Article 6(1)(f) of Regulation (EU) 2016/679, would allow these operators to make themselves known to the European Data Innovation Board and to share their practices as regards, in particular, the arrangements for obtaining consent where required and the measures taken to mitigate re-identification risks. This would inform the work of the Board and the development of guidelines enabling operators to secure their legal certainty and their due diligence.

Amendment 534

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point a

Regulation (EU) 2023/2854

Article 1 – paragraph 1 – point eb

Text proposed by the CommissionAmendment
(eb) voluntary registration of entities which collect and process data made available for altruistic purposes;deleted

Or. en

Amendment 535

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point a

Regulation (EU) 2023/2854

Article 1 – paragraph 1 – point eb

Text proposed by the CommissionAmendment
(eb) voluntary registration of entities which collect and process data made available for altruistic purposes;(eb) notification and supervisory framework of entities which collect and process data made available for altruistic purposes;

Or. en

Amendment 536

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point a

Regulation (EU) 2023/2854

Article 1 – paragraph 1 – point eb

Text proposed by the CommissionAmendment
(eb) voluntary registration of entities which collect and process data made available for altruistic purposes;(eb) mandatory registration of entities which collect and process data made available for altruistic purposes;

Or. pt

Amendment 537

Diana Iovanovici Şoşoacă

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point a

Regulation (EU) 2023/2854

Article 1 – paragraph 1 – point ee

Text proposed by the CommissionAmendment
(ee) (ee) the re-use of certain data and documents held by public sector bodies or by certain public undertakings, and of research data.’;(ee) the re-use of certain data and documents held by public sector bodies or by certain public undertakings, and of research data, under well-defined conditions of access and access periods, ensuring data protection and with potential penalties in the event of uncontrolled data leaks;

Or. ro

Justification

Data protection is key, especially access to this data and the persons who have access to this data.

Amendment 538

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point a

Regulation (EU) 2023/2854

Article 1 – paragraph 1 – point ee

Text proposed by the CommissionAmendment
(ee) the re-use of certain data and documents held by public sector bodies or by certain public undertakings, and of research data.;(ee) the re-use of certain data and documents held by public sector bodies or by certain public undertakings, and of research data subject to safeguards;

Or. en

Amendment 539

Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Nikola Minchev, Svenja Hahn, Andreas Glück, João Cotrim De Figueiredo, Ana Vasconcelos

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point b a (new)

Text proposed by the CommissionAmendment
(ba) ‘Chapter II applies to data, with the exception of content, concerning the performance, use and environment of connected products and related services; Chapter II does not apply in business-to-business relations;’

Or. en

Amendment 540

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point c

Regulation (EU) 2023/2854

Article 1 – paragraph 3 – point g

Text proposed by the CommissionAmendment
(g) participants in data spaces.;(g) participants in data spaces and vendors of applications using smart contracts and persons whose trade, business or profession involves the deployment of smart contracts for others in the context of executing an agreement.;

Or. en

Justification

Smart contracts are increasingly used as automated execution mechanisms for data-sharing arrangements, including triggering, authorising, restricting, or logging access to data and related services. Where deployed in connected products, digital ecosystems, or data spaces, such applications may determine or materially influence the conditions under which data are made available, accessed, or transferred between parties. In such cases, operators and deployers of smart contract-based systems function as technical intermediaries in the execution of data-sharing obligations under this Regulation and should therefore fall within its scope to ensure enforceability, transparency, and non-discriminatory access conditions.

Amendment 541

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point c a (new)

Regulation (EU) 2023/2854

Article 1 – paragraph 5 – subparagraph (new)

Text proposed by the CommissionAmendment
(ca) in paragraph (5) the following subparagraph is added:
‘The rules set out in Chapters VIIa and VIIc do not create a legal basis for the processing of personal data.’

Or. en

Amendment 542

Axel Voss

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point d a (new)

Regulation (EU) 2023/2854

Article 1 – paragraph 8

Present textAmendment
(da) In Article 1, paragraph 8 is replaced by the following text:
8. This Regulation is without prejudice to Union and national legal acts providing for the protection of intellectual property rights, in particular Directives 2001/29/EC, 2004/48/EC and (EU) 2019/790."8. This Regulation is without prejudice to Union and national legal acts providing for the protection of intellectual property rights and Trade Secrets, in particular Directives 2001/29/EC, 2004/48/EC, (EU) 2016/943 and (EU) 2019/790. It is also without prejudice to the achievement of the Union Cyber Resilience objectives, defined in particular by the NIS2 Directive and the Cyber Resilience Act."

Or. en

(Regulation (EU) 2023/2854)

Justification

The amendments ensure that Data Act access rights do not override trade secrets, IP or EU cybersecurity objectives. Industrial and IoT data can reveal know-how, algorithms, control logic, production methods or R&D results when combined, sequenced or analysed in bulk. Disclosure without the trade secret holder’s consent would weaken innovation, expose EU manufacturers to unfair competition and security risks, and reduce trust in data sharing, while preserving coherence with the Trade Secrets Directive, NIS2 and the Cyber Resilience Act.

Amendment 543

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point e

Regulation (EU) 2023/2854

Article 1 – paragraph 12

Text proposed by the CommissionAmendment
12. Where sector-specific Union or national law requires public sector bodies, data intermediation services providers or recognised data altruism organisations to comply with specific additional technical, administrative or organisational requirements that relate to Chapters VIIa and VIIb, including through an authorisation or certification regime, those provisions of that sector-specific Union or national law shall also apply. Any such specific additional requirements shall be non-discriminatory, proportionate and objectively justified.’deleted

Or. en

Amendment 544

Diana Iovanovici Şoşoacă

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point e

Regulation (EU) 2023/2854

Article 1 – paragraph 13

Text proposed by the CommissionAmendment
(13) With regards to data and documents in scope of Section II of Chapter VIIc, Chapter VIIc of this Regulation does not affect the possibility for Member States to adopt more detailed or stricter rules, provided that those rules allow for more extensive re-use of data and documents.’(13) With regards to data and documents in scope of Section II of Chapter VIIc, Chapter VIIc of this Regulation does not affect the possibility for Member States to adopt more detailed or stricter rules, provided that those rules allow for more extensive re-use of data and documents, while respecting data protection and rapid response rules in the event of uncontrolled data leaks.

Or. ro

Justification

Respect for data protection is crucial under all circumstances.

Amendment 545

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Andrea Wechsler, Oliver Schenk, Christian Ehler

Proposal for a regulation

Article 1 – paragraph 1 – point 1 – point e a (new)

Regulation (EU) 2023/2854

Article 1 – paragraph 14

Text proposed by the CommissionAmendment
(ea) Paragraph 14 is added, as follows:
Chapters II and III of this Regulation shall not apply to:
(a) data generated by medical devices and in vitro diagnostic medical devices as defined in Regulation (EU) 2017/745 and Regulation (EU) 2017/746 respectively, including accessories and software within the meaning of those Regulations;
(b) data generated by or processed through electronic health record systems as defined in Article 2, point (2), of Regulation (EU) 2025/327;
(c) data generated by or processed through related services within the meaning of Article 2, point (6), of this Regulation that are connected to the products referred to in points (a) and (b).
Manufacturers and providers of the products and services referred to in the first subparagraph may voluntarily comply with the obligations set out in Chapters II and III of this Regulation.

Or. en

Amendment 546

François-Xavier Bellamy

Proposal for a regulation

Article 1 – paragraph 1 – point 1 a (new)

Regulation (EU) 2024/2847

Annex I – Part II – point 8

Text proposed by the CommissionAmendment
1a. Amendment to Regulation (EU) 2024/2847
Point 8 of Annex I, Part 2 is amended as follows:
Ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless there is a contractual agreement between a manufacturer and a business user in relation to a product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken.

Or. en

Amendment 547

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Andrea Wechsler, Christian Ehler

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point a

Regulation (EU) 2023/2854

Article 2 – point 4a a (new)

Text proposed by the CommissionAmendment
(4aa) 'connected product’ means an item whose primary function is obtaining, generating, or collecting data concerning its use or environment and that is able to communicate product data via an electronic communications service, physical connection or on-device access, excluding any item whose primary function is not the storing, processing or transmission of data other than data concerning its use or environment;

Or. en

Amendment 548

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point a

Regulation (EU) 2023/2854

Article 2 – point 4b

Text proposed by the CommissionAmendment
(4b) ‘permission’ means giving data users the right to the processing of non-personal data;deleted

Or. en

Amendment 549

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point a

Regulation (EU) 2023/2854

Article 2 – point 4c

Text proposed by the CommissionAmendment
(4c) ‘access’ means data use, in accordance with specific technical, legal or organisational requirements, without necessarily implying the transmission or downloading of data;deleted

Or. pt

Amendment 550

Pilar del Castillo Vera

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point a

Regulation (EU) 2023/2854

Article 2 – point 4c

Text proposed by the CommissionAmendment
(4c) ‘access’ means data use, in accordance with specific technical, legal or organisational requirements, without necessarily implying the transmission or downloading of data;deleted

Or. en

Justification

This definition of 'access' risks undermining the effectiveness of the right of access under the Data Act. By providing that access does not necessarily imply the transmission or downloading of data, it could permit view-only or similarly restrictive solutions that prevent users from making effective use of the data, thereby depriving the right of its practical effect (effet utile). Moreover, Article 4 of the Data Act already comprehensively sets out the rights and obligations of users and data holders regarding access.

Amendment 551

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point a

Regulation (EU) 2023/2854

Article 2 – point 4c

Text proposed by the CommissionAmendment
(4c) ‘access’ means data use, in accordance with specific technical, legal or organisational requirements, without necessarily implying the transmission or downloading of data;deleted

Or. en

Amendment 552

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point a

Regulation (EU) 2022/868

Article 2 – point 4c

Text proposed by the CommissionAmendment
(4c) ‘access’ means data use, in accordance with specific technical, legal or organisational requirements, without necessarily implying the transmission or downloading of data;deleted

Or. en

Justification

As per draft report

Amendment 553

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point a

Regulation (EU) 2023/2854

Article 2 – point 4c

Text proposed by the CommissionAmendment
(4c) ‘access’ means data use, in accordance with specific technical, legal or organisational requirements, without necessarily implying the transmission or downloading of data;deleted

Or. en

Amendment 554

Diana Iovanovici Şoşoacă

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point a

Regulation (EU) 2023/2854

Article 2 – point 4c

Text proposed by the CommissionAmendment
(4c) ‘access’ means data use, in accordance with specific technical, legal or organisational requirements, without necessarily implying the transmission or downloading of data;’(4c) ‘access’ means data use, in accordance with specific technical, legal or organisational requirements, without necessarily implying the transmission or downloading of data, with the obligation to respect data protection in accordance with the legislation in force, determine who has access and the access period, and establish penalties in the event of uncontrolled data leaks or inadequate data protection;

Or. ro

Justification

Access to data must be clearly established by identifying the persons who have access to it and the access period.

Amendment 555

Tomas Tobé, Arba Kokalari, Jörgen Warborn

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point a a (new)

Regulation (EU) 2023/2854

Article 2 – point 5

Present textAmendment
(aa) (ba) Point (5) is replaced by the following:
(5) ‘connected product’ means an item that obtains, generates or collects data concerning its use or environment and that is able to communicate product data via an electronic communications service, physical connection or on-device access, and whose primary function is not the storing, processing or transmission of data on behalf of any party other than the user;"(5) ‘connected product’ means an item whose primary function is to obtain, generate or collect data concerning its use or environment and that is able to communicate product data via an electronic communications service, physical connection or on-device access, and whose primary function is not the storing, processing or transmission of data on behalf of any party other than the user;"

Or. en

(Regulation (EU) 2023/2854)

Amendment 556

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point a a (new)

Regulation (EU) 2023/2854

Article 2 – point 10

Text proposed by the CommissionAmendment
(aa) point (10) is deleted.

Or. en

Justification

Since the draft report introduces a new definition of intermediation services we need to delete point 10 of Article 2 of the Data Act (on top of deleting point 38a)

Amendment 557

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point a a (new)

Regulation (EU) 2023/2854

Article 2 – point 10

Text proposed by the CommissionAmendment
(aa) point (10) is deleted;

Or. pt

Amendment 558

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point b

Regulation (EU) 2023/2854

Article 2 – point 13

Text proposed by the CommissionAmendment
(13) ‘data holder’ means a natural or legal person that has the right or obligation, in accordance with this Regulation, applicable Union law or national legislation adopted in accordance with Union law, to use or make available data, including, where contractually agreed, product data or related service data, which it has retrieved or generated during the provision of a related service;(13) ‘data holder’ means a natural or legal person that has the right or obligation, in accordance with this Regulation, applicable Union law or national legislation adopted in accordance with Union law, to use and make available data, including, where contractually agreed, product data or related service data, which it has retrieved or generated during the provision of a related service;

Or. en

Amendment 559

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Andrea Wechsler, Pekka Toveri, Christian Ehler

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point b

Regulation (EU) 2023/2854

Article 2 – point 22

Text proposed by the CommissionAmendment
(13a) Article 2, paragraph 1, point 22 is replaced by the following:
‘(22) placing on the market’ means the first making available of a connected product on the Union market, meaning that if at least one individual unit has been lawfully placed on the market or put into service before the date specified in Article 50, other individual units of the same type and model of connected products are subject to the grace period provided in Article 50 and thus may continue to be placed on the market, made available or put into service on the Union market without any additional obligations, requirements or the need for additional certification;'

Or. en

Amendment 560

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point c

Regulation (EU) 2023/2854

Article 2 – point 28a

Text proposed by the CommissionAmendment
(28a) ‘bodies governed by public law’ means bodies that have all of the following characteristics:deleted
(a) they are established for the specific purpose of meeting needs in the general interest, not having an industrial or commercial character;
(b) they have legal personality;
(c) they are financed, for the most part by the State, regional or local authorities, or by other bodies governed by public law; or are subject to management supervision by those authorities or bodies; or have an administrative, managerial or supervisory board, more than half of whose members are appointed by the State, regional or local authorities, or by other bodies governed by public law;

Or. en

Justification

This amendment preserves the existing definition in order to maintain greater legal clarity and ensure that the notion of bodies governed by public law continues to be interpreted in a manner consistent with the public-interest objectives of the Regulation.

Amendment 561

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point c

Regulation (EU) 2023/2854

Article 2 – point 28b

Text proposed by the CommissionAmendment
(28b) ‘public undertaking’ means any undertaking over which a public sector body may exercise directly or indirectly a dominant influence by virtue of their ownership of it, their financial participation therein, or the rules which govern it. A dominant influence on the part of the public sector bodies shall be presumed in any of the following cases in which those bodies, directly or indirectly:deleted
(a) hold the majority of the undertaking's subscribed capital;
(b) control the majority of the votes attaching to shares issued by the undertaking;
(c) can appoint more than half of the undertaking's administrative, management or supervisory body;;

Or. en

Amendment 562

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point d

Regulation (EU) 2023/2854

Article 2 – point 38a

Text proposed by the CommissionAmendment
(38a) ‘data intermediation service’ means a service which aims to establish relationships of an economic character for the purposes of data sharing between an undetermined number of data subjects or data holders and data users, through technical, legal or other means, including for the purpose of exercising the rights of data subjects in relation to personal data, and which:deleted
(1) do not have as their main purpose the intermediation of copyright-protected content;
(2) are not jointly procured by several legal persons for exclusive use among them;

Or. en

Justification

Deleted definition of data intermediation service as in draft report since another definition is provided .

Amendment 563

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point d

Regulation (EU) 2023/2854

Article 2 – point 38a

Text proposed by the CommissionAmendment
(38a) ‘data intermediation service’ means a service which aims to establish relationships of an economic character for the purposes of data sharing between an undetermined number of data subjects or data holders and data users, through technical, legal or other means, including for the purpose of exercising the rights of data subjects in relation to personal data, and which:(38a) ‘data intermediation service’ means a service which aims to establish relationships of an economic character for the purposes of data sharing between an undetermined number of data subjects and data holders on the one hand, and data users on the other hand, through technical, legal or other means, including for the purpose of exercising the rights of data subjects in relation to personal data, and which:

Or. en

Amendment 564

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point d

Regulation (EU) 2023/2854

Article 2 – point 38a

Text proposed by the CommissionAmendment
(38a) ‘data intermediation service’ means a service which aims to establish relationships of an economic character for the purposes of data sharing between an undetermined number of data subjects or data holders and data users, through technical, legal or other means, including for the purpose of exercising the rights of data subjects in relation to personal data, and which :(38a) ‘data intermediation service’ means a service which aims to establish relationships for the purposes of data sharing between an undetermined number of data subjects or data holders and data users, through technical, legal or other means, including for the purpose of exercising the rights of data subjects in relation to personal data, and which :

Or. pt

Amendment 565

Diego Solier, Sebastian Tynkkynen, Elena Donazzan

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point d

Regulation (EU) 2023/2854

Article 2 – point 38a – point 2a (new)

Text proposed by the CommissionAmendment
(2a) In Article 2, point 38a, the following point is inserted:
'(2a) provide analytical, benchmarking, financial, research or other value-added information products and shall be regarded as data intermediation services even if they process third-party data;'

Or. en

Amendment 566

Diana Iovanovici Şoşoacă

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point d

Regulation (EU) 2023/2854

Article 2 – point 38a – point 2a (new)

Text proposed by the CommissionAmendment
(38aa) In Article 2, point 38a, the following point is inserted:
‘(2a) without prejudice to the privacy of individuals, the protection of such data shall be ensured in accordance with the legislation in force and access to this data shall be for a clearly defined period of time;’

Or. ro

Justification

No data intermediation service must exist without personal data protection, for clearly defined time periods.

Amendment 567

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point d

Regulation (EU) 2023/2854

Article 2 – point 38b

Text proposed by the CommissionAmendment
(38b) ‘data altruism’ means the voluntary sharing of data on the basis of the consent of data subjects to process personal data pertaining to them, or of permissions of data holders to allow the use of their non-personal data without seeking or receiving a reward that goes beyond compensation related to the costs that they incur where they make their data available for objectives of general interest as provided for in national law, where applicable, such as healthcare, combating climate change, improving mobility, facilitating the development, production and dissemination of official statistics, improving the provision of public services, public policy making or scientific research purposes in the general interest;(38b) ‘data altruism’ means the voluntary sharing of data on the basis of the consent of data subjects to process personal data pertaining to them, or of permissions of data holders to allow the use of their non-personal data without seeking or receiving a reward that goes beyond fair compensation related to the actual costs that they incur where they make their data available for objectives of general interest in accordance with Union law, and where applicable national law, such as healthcare, combating climate change, improving mobility, facilitating the development, production and dissemination of official statistics, improving the provision of public services, public policy making or scientific research purposes in the general interest;

Or. en

Amendment 568

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point d

Regulation (EU) 2023/2854

Article 2 – point 38b

Text proposed by the CommissionAmendment
(38b) ‘data altruism’ means the voluntary sharing of data on the basis of the consent of data subjects to process personal data pertaining to them, or of permissions of data holders to allow the use of their non-personal data without seeking or receiving a reward that goes beyond compensation related to the costs that they incur where they make their data available for objectives of general interest as provided for in national law, where applicable, such as healthcare, combating climate change, improving mobility, facilitating the development, production and dissemination of official statistics, improving the provision of public services, public policy making or scientific research purposes in the general interest;(38b) ‘data altruism’ means the voluntary sharing of data on the basis of the consent of data subjects to process personal data pertaining to them, or of permissions of data holders to allow the use of their non-personal data without seeking or receiving a reward that goes beyond fair compensation related to the actual costs that they incur where they make their data available for objectives of general interest as provided for in national and Union law, where applicable, such as healthcare, combating climate change, improving mobility, facilitating the development, production and dissemination of official statistics, improving the provision of public services, public policy making or scientific research purposes in the general interest;

Or. en

Amendment 569

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 45

Text proposed by the CommissionAmendment
(45) ‘small mid-cap’ or ‘SMC’ means a small mid-cap enterprise as defined in Article 2 of the Annex to Commission Recommendation (EU) 2025/1099;deleted

Or. pt

Amendment 570

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 45a (new)

Text proposed by the CommissionAmendment
(45a) 'very large enterprise' means an enterprise which is not a start-up, a small or medium-sized enterprise or a small mid-cap within the meaning of this Regulation, and which holds significant economic power on one or more markets in the digital economy, taking into account its designation as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925, or the fact that it provides one or more core platform services within the meaning of that Regulation; its annual worldwide turnover and its market capitalisation or equivalent fair market value; its ability to access, accumulate or aggregate large volumes of data across services or jurisdictions, and to monetise them; the extent to which users established in the Union depend on its services and the existence of barriers preventing them from switching to alternative providers;

Or. en

Justification

The Regulation applies differentiated conditions to very large enterprises without defining them, leaving the notion to be construed case by case. The definition retained is effect-based: significant economic power on one or more markets in the digital economy, designation as a gatekeeper or provision of core platform services, worldwide turnover and market capitalisation, and the ability to access, accumulate or aggregate large volumes of data across services or jurisdictions.

Amendment 571

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 50

Text proposed by the CommissionAmendment
(50) ‘research data’ means data , other than scientific publications, which are collected or produced in the course of scientific research activities and are used as evidence in the research process, or are commonly accepted in the research community as necessary to validate research findings and results;(50) ‘research data’ means data , other than scientific publications, which are collected or produced in the course of scientific research activities, within the meaning of Article 4, point (38), of Regulation (EU) 2016/679, and are used as evidence in the research process, or are commonly accepted in the research community as necessary to validate research findings and results; research data does not include data collected or produced in the course of processing whose principal object is to observe, profile or influence the behaviour of natural persons for commercial purposes, in particular for behavioural advertising or the commercial targeting of individuals, even where scientific methods are used;

Or. en

Justification

The definition of research data conditions the scope of the safeguards attaching to them. Its clarification ensures that data collected or produced in the course of scientific research are covered irrespective of the sector in which the research is carried out, while excluding processing whose principal object is the observation or influencing of behaviour.

Amendment 572

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 50

Text proposed by the CommissionAmendment
(50) ‘research data’ means data , other than scientific publications, which are collected or produced in the course of scientific research activities and are used as evidence in the research process, or are commonly accepted in the research community as necessary to validate research findings and results;(50) ‘research data’ means data which are collected or produced in the course of scientific research activities and are used as evidence in the research process, or are commonly accepted in the research community as necessary to validate research findings and results, including research information, such as abstracts, citations, metadata and other information used to understand and assess research, as well as scientific publications;

Or. en

Amendment 573

Aura Salla

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – paragraph 1 – point 51 – introductory part

Text proposed by the CommissionAmendment
(51) ‘re-use’ means the use by natural persons or legal entities of documents held by:(51) ‘re-use’ means the use by natural or legal persons of data or documents held by:

Or. en

Amendment 574

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 52

Text proposed by the CommissionAmendment
(52) ‘high-value datasets’ means data and documents the re-use of which is associated with important benefits for society, the environment and the economy, in particular because of their suitability for the creation of value-added services, applications and new, high-quality and decent jobs, and because of the number of potential beneficiaries of the value-added services and applications based on those data and documents;(52) ‘high-value datasets’ means data and documents the re-use of which is associated with important benefits for society, the environment and the public interest;

Or. pt

Amendment 575

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 52

Text proposed by the CommissionAmendment
(52) ‘high-value datasets’ means data and documents the re-use of which is associated with important benefits for society, the environment and the economy, in particular because of their suitability for the creation of value-added services, applications and new, high-quality and decent jobs, and because of the number of potential beneficiaries of the value-added services and applications based on those data and documents;(52) ‘high-value datasets’ means personal and non-personal data, as well as documents whose re-use is associated with important benefits for society, the environment and the economy, in particular because of their suitability for the creation of value-added services, applications and new, high-quality and decent jobs, and because of the number of potential beneficiaries of the value-added services and applications based on those data and documents;

Or. en

Amendment 576

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 53 – point da (new)

Text proposed by the CommissionAmendment
(da) national security, public security, defence or public order, in accordance with Article 4(2) of the Treaty on European Union.

Or. en

Justification

Article 4(2) of the Treaty on European Union reserves national security to the exclusive responsibility of each Member State. The addition ensures that the categories of protected data expressly include those relating to national security, public security, defence and public order, so that the re-use regime cannot be invoked to obtain access to data falling within the sole competence of the Member States.

Amendment 577

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 53a (new)

Text proposed by the CommissionAmendment
(53a) 'Industrial or business data should not be regarded as “high-value datasets” within the meaning of this Regulation solely because they have significant economic, commercial or strategic value. Where such data are protected on grounds of commercial confidentiality, including as trade secrets, they should remain subject to the applicable rules governing access, re-use, data sharing and confidentiality. For the purposes of mandatory data-sharing obligations:
(a) “raw data” should mean data automatically captured or generated by an individual sensor, software event or source component in their native form, subject only to operations technically inherent in their capture, recording, transmission or storage;
(b) “derived data” should mean data resulting from processing beyond the minimum adaptations strictly necessary to ensure readability and usability, including transformation, combination, aggregation, enrichment, inference or analysis, as well as data generated through sensor fusion, algorithms, analytics or domain-specific expertise;
(c) mandatory data sharing should be limited to raw data and to the minimum technical adaptations strictly necessary to ensure their usability and readability. Processed, inferred, derived or other value-added data should be excluded from such obligations, unless otherwise expressly required by Union law or agreed by the parties, in order to protect trade secrets, intellectual property rights and investments in data processing and analytics.'

Or. en

Amendment 578

Diana Iovanovici Şoşoacă

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 54

Text proposed by the CommissionAmendment
54. ‘secure processing environment’ means the physical or virtual environment and organisational means to ensure compliance with Union law in particular with regard to data subjects’ rights, intellectual property rights, and commercial and statistical confidentiality, integrity and accessibility, as well as with applicable national law, and to allow the entity providing the secure processing environment to determine and supervise all data processing actions, including the display, storage, download and export of data and the calculation of derivative data through computational algorithms;54. ‘secure processing environment’ means the physical or virtual environment and organisational means to ensure compliance with Union law in particular with regard to data subjects’ rights, intellectual property rights, and commercial and statistical confidentiality, integrity and accessibility, as well as with applicable national law, and to allow the entity providing the secure processing environment to determine and supervise all data processing actions, including the display, storage, download and export of data and the calculation of derivative data through computational algorithms, ensuring governance, access control, traceability, anonymisation, data minimisation, data protection impact assessments and compliance with security requirements, business confidentiality and protection of data subject rights, as well as interoperability with other secure processing environments, within an EU-wide framework;

Or. ro

Justification

Proper supervision of all data processing actions is necessary, while ensuring data protection in accordance with the legislation in force and without prejudice to data subjects.

Amendment 579

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 54

Text proposed by the CommissionAmendment
(54) ‘secure processing environment’ means the physical or virtual environment and organisational means to ensure compliance with Union law in particular with regard to data subjects’ rights, intellectual property rights, and commercial and statistical confidentiality, integrity and accessibility, as well as with applicable national law, and to allow the entity providing the secure processing environment to determine and supervise all data processing actions, including the display, storage, download and export of data and the calculation of derivative data through computational algorithms;(54) ‘secure processing environment’ means the physical or virtual environment and organisational means to ensure compliance with Union law in particular with regard to data subjects’ rights, intellectual property rights, and commercial and statistical confidentiality, integrity and accessibility, as well as with applicable national law, to protect personal data and data relating to identifiable natural persons against re-identification, against personal data breaches, and against unlawful use and trade, and to allow the entity providing the secure processing environment to determine and supervise all data processing actions, including the display, storage, download and export of data and the calculation of derivative data through computational algorithms;

Or. en

Amendment 580

Diana Iovanovici Şoşoacă

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 55

Text proposed by the CommissionAmendment
55. ‘re-user’ means a natural or legal person who was granted the right to re-use data or documents held by a public sector body or a public undertaking under Chapter VIIc or to research data or certain categories of protected data;55. ‘re-user’ means a natural or legal person who was granted the right to re-use data or documents held by a public sector body or a public undertaking under Chapter VIIc or to research data or certain categories of protected data, on condition that said person ensures proper data protection, does not transmit the data for material gain, especially without seeking the consent of the holder and without communicating their intention to the persons concerned;

Or. ro

Justification

The transmission of data by a re-user for material gain is not acceptable.

Amendment 581

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 58

Text proposed by the CommissionAmendment
(58) ‘formal open standard’ means a standard which has been laid down in written form, detailing specifications for the requirements on how to ensure software interoperability;(58) ‘formal open standard’ means a freely accessible standard which has been laid down in written form, detailing specifications for the requirements on how to ensure software interoperability;

Or. en

Amendment 582

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 60

Text proposed by the CommissionAmendment
(60) ‘data localisation requirement’ means any obligation, prohibition, condition, limit or other requirement provided for in the laws, regulations or administrative provisions of a Member State or resulting from general and consistent administrative practices in a Member State and in bodies governed by public law, including in the field of public procurement, without prejudice to Directive 2014/24/EU, which imposes the processing of data in the territory of a specific Member State or hinders the processing of data in any other Member State;(60) ‘data localisation requirement’ means any obligation, prohibition, condition, limit or other requirement provided for in the laws, regulations or administrative provisions of a Member State or resulting from general and consistent administrative practices in a Member State and in bodies governed by public law, including in the field of public procurement, without prejudice to Directive 2014/24/EU, which imposes the processing of data in the territory of a specific Member State or hinders the processing of data in any other Member State; a requirement shall not constitute a data localisation requirement within the meaning of this point where it is justified on grounds of public security, service continuity in the face of unilateral extraterritorial suspension risks, or where it is necessary and proportionate to protect personal data, sensitive data or high-value datasets against access, transfer or use resulting from the extraterritorial application of a third-country law likely to cause harm to the Union or its Member States;

Or. en

Justification

The growing extraterritorial reach of certain third-country laws exposes personal data, sensitive data and high-value datasets held in the Union to access, transfer or use that may run counter to the Union's economic security and to the protection of natural persons. This exception, framed around the established grounds of public security and the principles of necessity and proportionality, ensures that the prohibition on data localisation requirements does not prevent Member States from protecting data whose exposure to extraterritorial reach would be liable to cause harm to the Union or its Member States.

Amendment 583

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 60

Text proposed by the CommissionAmendment
(60) ‘data localisation requirement’ means any obligation, prohibition, condition, limit or other requirement provided for in the laws, regulations or administrative provisions of a Member State or resulting from general and consistent administrative practices in a Member State and in bodies governed by public law, including in the field of public procurement, without prejudice to Directive 2014/24/EU, which imposes the processing of data in the territory of a specific Member State or hinders the processing of data in any other Member State;(60) ‘data localisation requirement’ means any obligation, prohibition, condition, limit or other requirement provided for in the laws, regulations or administrative provisions of a Member State without prejudice to Directive 2014/24/EU, which imposes the processing of data in the territory of a specific Member State or hinders the processing of data in any other Member State;

Or. en

Amendment 584

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Matthias Ecke, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 61a (new)

Text proposed by the CommissionAmendment
(61a) ‘very large enterprise’ means a large undertaking which, by reason of the scale of data generated, collected, aggregated or controlled through connected products, related services or online platform services within the meaning of Regulation (EU) 2022/2065, and by reason of its capacity to derive significant and sustained economic value from the large-scale reuse of such data across services, markets and digital ecosystems, possesses significant bargaining power in data-sharing relationships, including where such control over data results in structural dependencies or material asymmetries in access to or use of data;

Or. en

Justification

The amendment provides legal clarity on the concept of “very large enterprise” by reflecting the realities of data-driven markets, where economic significance is increasingly linked to the ability to generate value from large-scale data processing and reuse. A clear definition ensures consistent, proportionate and predictable application across the Union’s digital acquis.

Amendment 585

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 61a (new)

Text proposed by the CommissionAmendment
(61a) ''pseudonymous data' and 'pseudonymised data' mean pseudonymous data and pseudonymised data as defined in Article 4 of Regulation (EU) 2016/679;'

Or. en

Amendment 586

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e

Regulation (EU) 2023/2854

Article 2 – point 61b (new)

Text proposed by the CommissionAmendment
(61b) 'state-of-the-art privacy-preserving and privacy-enhancing methods' means such techniques as defined in Article 4 of Regulation (EU) 2016/679;’

Or. en

Amendment 587

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e a (new)

Regulation (EU) 2023/2854

Article 2 – point 63a (new)

Text proposed by the CommissionAmendment
(ea) In Article 2, the following point is added:
'(63a) “responding to a public emergency” means the immediate, time-limited actions strictly necessary and proportionate to directly and solely address and manage the emergency until its immediate phase has passed, whereas “mitigating or supporting the recovery from a public emergency” means time-limited actions taken after or once the immediate phase of the emergency has passed and is aimed at limiting its direct consequences and restoring stable conditions;'

Or. en

Amendment 588

François-Xavier Bellamy

Proposal for a regulation

Article 1 – paragraph 1 – point 2 a (new)

Regulation (EU) 2024/2847

Article 13 – paragraph 25a (new)

Text proposed by the CommissionAmendment
2a. Amendment to Regulation (EU) 2024/2847
In Article 13, paragraph 25a (new) is inserted:
Pursuant to Article 13(4), Manufacturers of Products with Digital Elements may deviate from the essential cybersecurity requirements set out in Annex I for the following products:
(a) Products placed on the market after 11 December 2027 under a business-to-business agreement concluded prior to 20 November 2024, where compliance with Annex I is either inapplicable, would impose a disproportionate financial burden, or would result in significant delivery delays due to the advanced stage of design, development, and production.
(b) Products placed on the market after 11 December 2027 that are expected to interface with products placed on the market before that date (e.g., project extensions necessitating integration of new units, subsystems, or systems with existing railway infrastructure), where compliance with Annex I would jeopardize interoperability or compatibility between the legacy system and the extension.
Such deviation shall be justified by manufacturers, by providing a technical justification within the cybersecurity risk assessment, and, where relevant, by proposing compensating controls based on a risk-based approach.

Or. en

Amendment 589

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 2 a (new)

Regulation (EU) 2023/2854

Article 3 – paragraph 1a (new)

Text proposed by the CommissionAmendment
2a. In Article 3, the following paragraph 1a is inserted:
‘Product data and related services data shall be made available to the user in a in real time via a physical interface or local network access. Where relevant, data holders shall explain where this is not technically feasible.’

Or. en

Amendment 590

Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Sophie Wilmès, Nikola Minchev, Svenja Hahn, Andreas Glück, João Cotrim De Figueiredo, Ana Vasconcelos

Proposal for a regulation

Article 1 – paragraph 1 – point 3 – introductory part

Regulation (EU) 2023/2854

Article 4 – paragraph 8

Text proposed by the CommissionAmendment
3. in Article 4, paragraph 8 is replaced by the following:3. in Article 4, paragraph 8 is replaced by the following:
Trade secrets will not be disclosed. Data capable of revealing trade secrets shall likewise be exempt from disclosure, except where the data holder and user have agreed on and implemented sufficient confidentiality safeguards.

Or. en

Justification

Chapter II creates legal uncertainty for B2B relationships as well as huge administrative burdens for companies that want to protect their trade secrets (on a case-by-case basis). Businesses that already have negotiated data-sharing arrangements now face statutory obligations based on legally defined conditions rather than mutual agreement. This amendment introduces a trade secret safeguard to preserve the Data Act's objectives without undermining existing commercial arrangements or business confidentiality.

Amendment 591

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 3 – introductory part

Regulation (EU) 2023/2854

Article 4 – paragraph 8a (new) – introductory part

Text proposed by the CommissionAmendment
3. in Article 4, paragraph 8 is replaced by the following:3. in Article 4, the following paragraphs are added after paragraph 8:

Or. en

Amendment 592

Axel Voss

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 8

Text proposed by the CommissionAmendment
8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;deleted

Or. en

Justification

The amendments ensure that Data Act access rights do not override trade secrets, IP or EU cybersecurity objectives. Industrial and IoT data can reveal know-how, algorithms, control logic, production methods or R&D results when combined, sequenced or analysed in bulk. Disclosure without the trade secret holder’s consent would weaken innovation, expose EU manufacturers to unfair competition and security risks, and reduce trust in data sharing, while preserving coherence with the Trade Secrets Directive, NIS2 and the Cyber Resilience Act.

Amendment 593

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 8

Text proposed by the CommissionAmendment
8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate with sufficient evidence that the product data and related service data constiute a trade secret within the meaning of Article 2(1) of Directive 2016/943, that such trade secrets cannot be eliminated or sufficiently mitigated through design measures pursutant to Aritcle 3(1), and, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious and demonstrable economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent user or trade secret protection compared to that under Union law. For the purposes of this Regulation, 'serious economic damage' does not include normal competitive effects arising from lawful access under the Data Act.
The data holder shall identify the specific data that constitutes a trade secret and shall not classify entire datasets as trade secrets. Any such demonstration shall be duly substantiated on the basis of objective, verifiable and specific evidence, taking into account, in particular, the enforceability of trade secret protection in third countries, the nature and level of confidentiality of the data concerned, the design measures applied pursuant to Article 3(1), and the uniqueness and novelty of the connected product. Such demonstration shall be provided in writing to the user without undue delay.
Where the data holder refuses to share specific data on the basis of trade secret protection, it shall notify the competent authority designated pursuant to Article 37 without undue delay and no later than five working days after communicating the refusal to the user. The competent authority shall review the substantiation provided and issue a binding decision within sixty calendar days of receipt of the notification.
A refusal shall be permitted only on a case-by-case basis and shall be duly reasoned, proportionate and limited to the specific data strictly necessary to protect the trade secret. It shall not prejudice the rights of users under this Regulation. Any claim relating to third-country entities shall be supported by concrete evidence demonstrating a specific risk of unlawful access, use or disclosure.
Access may be refused only where the data holder demonstrates, on the basis of objective and verifiable evidence, that disclosure would create a serious and specific risk of unlawful acquisition, use or disclosure of the trade secret that cannot be adequately mitigated through confidentiality measures, technical safeguards or contractual arrangements.

Or. en

Justification

The amendment ensures that the trade secret safeguard remains an exceptional mechanism and cannot be used to undermine the Data Act’s objective of effective data access. It clarifies that data holders must demonstrate that the data concerned qualify as trade secrets under Article 2(18) of the Data Act and Article 2(1) of the Trade Secrets Directive, and that related risks cannot be adequately mitigated through the design obligations under Article 3(1) of the Data Act. This preserves a balance between protecting legitimate trade secrets and ensuring access to and use of data.

Amendment 594

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 8

Text proposed by the CommissionAmendment
8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;8. The Commission, in consultation with the European Data Innovation Board (EDIB) and representatives of data holders, users, and thrid-parties shall publish a list of high-risk sectors with regards to the disclosure of trade secrets. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or, in high-risk sectors, that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective evidence, such as the enforceability of trade secrets protection in third countries, the verifable insufficiency of specific technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, the high likelihood of suffering serious economic damage, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37 no later than five working days after the refusal was communicated to the user. The competent authority shall approve or reject the data holder’s refusal to share data pursuant to this paragraph based on a review of the evidence submitted by the data holder, and provide in writing an explanation for its decision to the data holder and user within 60 calander days. The user has the right to be heard before the competent authority decides to approve or reject the data holder’s refusal to share data pursuant to this paragraph. The Commission shall issue guidelines, in consultation with the European Data Innovation Board (EDIB) and representatives of data holders, users, and third parties on the application of this paragraph, such as the assessment of serious economic damage, third-country entity direct or indirect control, and the enforceability of trade secrets protection in third countries.

Or. en

Amendment 595

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – Paragraph 8

Text proposed by the CommissionAmendment
8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;8. In exceptional circumstances, where the data holder who is a trade secret holder is able to establish, on the basis of reasonable grounds that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets, or of industrial, strategic or sensitive data whose disclosure would be liable to harm economic security, privacy or public order, or create a serious risk to the cybersecurity of the connected product, related service or the data holder’s systems, or that the disclosure of such data poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, including as a result of the foreseeable onward transmission of the data to such entities, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That assessment shall be reasonably substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, the nature and seriousness of the cybersecurity risk, the reasonably foreseeable chain of onward transmission of the data, and the uniqueness and novelty of the connected product. Data holders shall not be required to undertake a comprehensive assessment of foreign legal systems, enforcement practices, or international law in order to rely on this paragraph. In particular, small and medium-sized enterprises should be entitled to rely on publicly available information and generally recognised risks when assessing the likelihood of unlawful acquisition, use, or disclosure. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.

Or. en

Justification

The right to refuse data sharing where disclosure would cause serious harm should not be confined to trade secrets in the strict sense. Industrial, strategic or sensitive data whose disclosure would be liable to harm the economic security of the Union, the privacy of natural persons or public order warrant equivalent protection. Furthermore, the evidentiary standard applicable to data holders should be calibrated so as to remain workable in practice: requiring a holder to demonstrate that serious damage is highly likely sets a threshold that is difficult to meet ex ante and risks depriving the safeguard of its effectiveness. The introduction of a reasonable grounds standard, together with a requirement that the assessment be reasonably substantiated on the basis of objective elements, preserves the case-by-case and duly reasoned nature of the refusal while ensuring that the safeguard is genuinely operable.

Amendment 596

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Adina Vălean, Andrea Wechsler, Christian Ehler

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 8

Text proposed by the CommissionAmendment
8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;8. where the data holder who is a trade secret holder finds that it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, in particular the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the user requesting the data. The Commission shall consult stakeholders and adopt guidelines on the application of paragraph 4(8). These shall identify specific third-country jurisdictions and types of data or practices that inherently pose a high risk to trade secrets in particular where the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law. The Commission shall provide a simplified template based on the list of objective criteria to help data holders to substantiate 'serious economic damage,' and where access may be granted even if data is highly sensitive and under what conditions.

Or. en

Amendment 597

Dario Nardella

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – point 8

Text proposed by the CommissionAmendment
8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.; Where the request for access involves data reflecting the user’s economic activity, scale of operations and output, the data holder shall inform the user in advance of the request received, specifying the nature of the data requested, the identity of the applicant and the decisions taken regarding the activation of the refusal mechanism referred to in this paragraph. Upon a reasoned request from the user, the data holder shall activate the refusal mechanism for the part of the data which reflects the user’s economic activity, unless the data holder demonstrates in writing that the conditions set out in this paragraph are not met.

Or. it

Justification

L'emendamento non altera l'impianto del meccanismo di rifiuto introdotto dalla proposta della Commissione, ma ne aggiunge due elementi complementari, che intervengono soltanto nel caso in cui la richiesta di accesso riguardi dati che riflettono l'attività e il dimensionamento economico dell'utente e delle sue produzioni. Il primo elemento è un obbligo informativo del detentore dei dati verso l'utente. Il secondo è il diritto dell'utente di richiedere l'attivazione del meccanismo di rifiuto per la parte dei dati che lo riguardano, con inversione dell'onere motivazionale a carico del detentore ove intenda non attivare il meccanismo. La distinzione tra dati riconducibili al funzionamento tecnico del prodotto e dati riconducibili all'attività economica dell'utente può essere oggetto degli orientamenti della Commissione, come previsto dal considerando 13 bis introdotto dall'Emendamento 5.

Amendment 598

Francesco Torselli, Paolo Inselvini

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – point 8

Text proposed by the CommissionAmendment
8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37. Where the request for access involves data reflecting the user’s economic activity, scale of operations and output, the data holder shall inform the user in advance of the request received, specifying the nature of the data requested, the identity of the applicant and the decisions taken regarding the activation of the refusal mechanism referred to in this paragraph. Upon a reasoned request from the user, the data holder shall activate the refusal mechanism for the part of the data which reflects the user’s economic activity, unless the data holder demonstrates in writing that the conditions set out in this paragraph are not met.
(Our intention is to amend part of the text at the end of the article.)

Or. it

Amendment 599

Diego Solier, Sebastian Tynkkynen, Elena Donazzan

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 8

Text proposed by the CommissionAmendment
8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37. Where appropriate technical, organisational or contractual measures cannot reasonably ensure the effective protection of trade secrets or confidential commercial information, the data holder shall not be required to disclose the relevant data. This Regulation shall set measures to prevent the disclosure of trade secrets where equivalent technical or contractual safeguards cannot reasonably ensure the protection of confidential commercial information.

Or. en

Amendment 600

Henrik Dahl

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 8

Text proposed by the CommissionAmendment
8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;8. In any circumstance, where the data holder who is a trade secret holder assesses a risk of disclosing trade secrets, the data holder may refuse a request for access to the specific data in question. The assessment shall be based on the definition of trade secrets stated in Article 2 (1) of Directive (EU) 2016/943 of the European Parliament and of the Council. The refusal shall be provided in writing to the user without undue delay.

Or. en

Amendment 601

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 8

Text proposed by the CommissionAmendment
8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;8. In any circumstance, where the data holder who is a trade secret holder assesses a risk of disclosing trade secrets, the data holder may refuse a request for access to the specific data in question. The assessment shall be based on the definition of trade secrets stated in Article 2 (1) of Directive (EU) 2016/943 of the European Parliament and of the Council. The refusal shall be provided in writing to the user without undue delay.

Or. en

Amendment 602

Niels Flemming Hansen

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 8

Text proposed by the CommissionAmendment
8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;8. In any circumstance, where the data holder who is a trade secret holder assesses a risk of disclosing trade secrets, the data holder may refuse a request for access to the specific data in question. The assessment shall be based on the definition of trade secrets stated in Article 2 (1) of Directive (EU) 2016/943 of the European Parliament and of the Council. The refusal shall be provided in writing to the user without undue delay.

Or. en

Amendment 603

Tomas Tobé, Arba Kokalari, Jörgen Warborn

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 8

Text proposed by the CommissionAmendment
8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;8. Where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is likely to suffer economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse a request for access to the specific data in question. The refusal shall be provided in writing to the user without undue delay.

Or. en

Amendment 604

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 8

Text proposed by the CommissionAmendment
8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.

Or. pt

Amendment 605

Zala Černilec Tomašič, Jan Farský, Ondřej Krutílek, Tomáš Zdechovský, Henrik Dahl, Alexandr Vondra, Veronika Vrecionová, Lukas Mandl

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 8

Text proposed by the CommissionAmendment
8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37. Circumstances that invoke the right to refuse a request for access may also arise if the disclosure of such data would increase cybersecurity risks affecting the security or resilience of the shared data, or the data holder’s network and information systems, connected products, or related services.

Or. en

Justification

This amendment improves legal certainty by recognising cybersecurity as a valid ground to refuse data access where disclosure would demonstrably increase cyber risks or compromise the security of data, systems, products or services. It closes a gap in the Data Act, aligns it with the NIS2 Directive and Cyber Resilience Act, and allows refusal only where objectively justified, preserving data sharing while preventing avoidable cybersecurity risks.

Amendment 606

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 8

Text proposed by the CommissionAmendment
8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious and irreparable economic damage from the disclosure of trade secrets, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, in particular the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37. The data holder and the competent authority shall inform the user of their rights and the relevant procedure under paragraph 7.

Or. en

Amendment 607

Pilar del Castillo Vera

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 8

Text proposed by the CommissionAmendment
8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;8. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, in particular the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the user without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.

Or. en

Justification

Article 4(8), as currently drafted in the Data Act, establishes an exhaustive framework for demonstrating, based on objective elements, the risk of serious economic damage resulting from the disclosure of trade secrets. Replacing “in particular” with “such as” would transform that framework into an open-ended list of criteria, allowing reliance on additional unspecified elements and broadening the grounds for refusal. To preserve legal certainty, the original wording should be retained.

Amendment 608

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 11 – paragraph 1

Text proposed by the CommissionAmendment
8a. Article 11, paragraph 1 is amended as follows:
'1. A data holder may apply appropriate technical protection measures, including smart contracts and encryption, to prevent unauthorised access to data, including metadata, and to ensure compliance with Articles 4, 5, 6, 8 and 9, as well as with the agreed contractual terms for making data available. Such technical protection measures shall not discriminate between data recipients or hinder a user's right to obtain a copy of, retrieve, use or access data, to provide data to third parties pursuant to Article 5 or any right of a third party under Union law or national legislation adopted in accordance with Union law, without prejudice to the right of a data holder to refuse access to specific data in accordance with Article 4(8) or 5(11). Users, third parties and data recipients shall not alter or remove such technical protection measures unless agreed by the data holder.'

Or. en

Amendment 609

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Adina Vălean, Henrik Dahl, Andrea Wechsler, Pekka Toveri, Christian Ehler

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 13

Text proposed by the CommissionAmendment
8a. Article 4, paragraph 13 is amended as follows:
'13. A data holder is entitled to use any readily available data that is non-personal data. Such use shall be without prejudice to Regulation (EU) 2016/679 and shall comply with Union and national law on the protection of trade secrets and intellectual property rights. A data holder shall not use such data to derive insights about the economic situation, assets and production methods of, or the use by, the user in any other manner that could undermine the commercial position of that user on the markets in which the user is active.'

Or. en

Amendment 610

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 8a (new)

Text proposed by the CommissionAmendment
8a. The data holder shall not rely on this Article to refuse data access on the basis of generalised assumptions concerning a third country, ownership structure, technology provider, or category of recipient.
The data holder shall not engage in any behaviour that undermines effective compliance with the data access obligations under this Regulation regardless of whether that behaviour is of a contractual, commercial or technical nature, or of any other nature, or consists in the use of behavioural techniques or interface design.

Or. en

Amendment 611

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 8b (new)

Text proposed by the CommissionAmendment
8b. Before refusing access under paragraph 8, the data holder shall assess whether the identified risk can be effectively addressed through proportionate technical, organisational, contractual, or secure-access measures, including access in a secure processing environment, partial access, aggregation, confidentiality commitments, or other safeguards that enable the user to exercise the rights provided for in this Regulation. Refusal shall be used only where such measures would be insufficient to address a duly substantiated and specific risk.

Or. en

Amendment 612

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 3

Regulation (EU) 2023/2854

Article 4 – paragraph 8c (new)

Text proposed by the CommissionAmendment
8c. The review of the data holder’s refusal to provide data access by the competent authority designated pursuant to Article 37 referred to in paragraph 8 shall be available through an expedited procedure which shall not be later than a month in complex cases. The competent authority shall assess the necessity, proportionality, evidence and non-discriminatory nature of the refusal.

Or. en

Amendment 613

Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Svenja Hahn, Andreas Glück, João Cotrim De Figueiredo, Ana Vasconcelos

Proposal for a regulation

Article 1 – paragraph 1 – point 3 a (new)

Regulation (EU) 2023/2854

Article 4 – paragraph 9

Present textAmendment
3a. Article 4 paragraph 9 is deleted
9. Without prejudice to a user’s right to seek redress at any stage before a court or tribunal of a Member State, a user wishing to challenge a data holder’s decision to refuse or to withhold or suspend data sharing pursuant to paragraphs 7 and 8 may:""
(a)lodge, in accordance with Article 37(5), point (b), a complaint with the competent authority, which shall, without undue delay, decide whether and under which conditions data sharing is to start or resume; or

Or. en

(Regulation (EU) 2023/2854)

Amendment 614

Axel Voss

Proposal for a regulation

Article 1 – paragraph 1 – point 3 a (new)

Regulation (EU) 2023/2854

Article 4 – paragraph 6

Present textAmendment
3 a. Article 4 - paragraph 6 is replaced by the following:
6. Trade secrets shall be preserved and shall be disclosed only where the data holder and the user take all necessary measures prior to the disclosure to preserve their confidentiality in particular regarding third parties. The data holder or, where they are not the same person, the trade secret holder shall identify the data which are protected as trade secrets, including in the relevant metadata, and shall agree with the user proportionate technical and organisational measures necessary to preserve the confidentiality of the shared data, in particular in relation to third parties, such as model contractual terms, confidentiality agreements, strict access protocols, technical standards and the application of codes of conduct."6. Trade secrets shall be preserved and shall not be disclosed without the consent of their respective trade secret holder."

Or. en

(Regulation (EU) 2023/2854)

Justification

The amendments ensure that Data Act access rights do not override trade secrets, IP or EU cybersecurity objectives. Industrial and IoT data can reveal know-how, algorithms, control logic, production methods or R&D results when combined, sequenced or analysed in bulk. Disclosure without the trade secret holder’s consent would weaken innovation, expose EU manufacturers to unfair competition and security risks, and reduce trust in data sharing, while preserving coherence with the Trade Secrets Directive, NIS2 and the Cyber Resilience Act.

Amendment 615

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Adina Vălean, Christian Ehler

Proposal for a regulation

Article 1 – paragraph 1 – point 3 a (new)

Regulation (EU) 2023/2854

Article 4 – paragraph 14

Text proposed by the CommissionAmendment
3a. In Article 4, paragraph 14 is replaced by the following;
“Data holders may make available non-personal product data to third parties for legitimate commercial or non-commercial purposes;”

Or. en

Amendment 616

Henrik Dahl

Proposal for a regulation

Article 1 – paragraph 1 – point 3 a (new)

Regulation (EU) 2023/2854

Article 11 – paragraph 1

Present textAmendment
3a. Article 11 paragraph 1 is replaced by the following:
A data holder may apply appropriate technical protection measures, including smart contracts and encryption, to prevent unauthorised access to data, including metadata, and to ensure compliance with Articles 4, 5, 6, 8 and 9, as well as with the agreed contractual terms for making data available. Such technical protection measures shall not discriminate between data recipients or hinder a user’s right to obtain a copy of, retrieve, use or access data, to provide data to third parties pursuant to Article 5 or any right of a third party under Union law or national legislation adopted in accordance with Union law. Users, third parties and data recipients shall not alter or remove such technical protection measures unless agreed by the data holder."A data holder may apply appropriate technical protection measures, including smart contracts and encryption, to prevent unauthorised access to data, including metadata, and to ensure compliance with Articles 4, 5, 6, 8 and 9, as well as with the agreed contractual terms for making data available. Such technical protection measures shall not discriminate between data recipients or hinder a user's right to obtain a copy of, retrieve, use or access data, to provide data to third parties pursuant to Article 5 or any right of a third party under Union law or national legislation adopted in accordance with Union law, without prejudice to the right of a data holder to refuse access to specific data in accordance with Article 4(8) or 5(11). Users, third parties and data recipients shall not alter or remove such technical protection measures unless agreed by the data holder."

Or. en

(2023/2854)

Amendment 617

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 3 a (new)

Regulation (EU) 2023/2854

Article 4 – paragraph 10

Text proposed by the CommissionAmendment
3a. In Article 4, paragraph 10 is deleted.

Or. en

Amendment 618

Axel Voss

Proposal for a regulation

Article 1 – paragraph 1 – point 3 b (new)

Regulation (EU) 2023/2854

Article 4 – paragraph 7

Present textAmendment
3 b. Article 4 - paragraph 7 is deleted.
7. Where there is no agreement on the necessary measures referred to in paragraph 6, or if the user fails to implement the measures agreed pursuant to paragraph 6 or undermines the confidentiality of the trade secrets, the data holder may withhold or, as the case may be, suspend the sharing of data identified as trade secrets. The decision of the data holder shall be duly substantiated and provided in writing to the user without undue delay. In such cases, the data holder shall notify the competent authority designated pursuant to Article 37 that it has withheld or suspended data sharing and identify which measures have not been agreed or implemented and, where relevant, which trade secrets have had their confidentiality undermined.""

Or. en

(Regulation (EU) 2023/2854)

Justification

The amendments ensure that Data Act access rights do not override trade secrets, IP or EU cybersecurity objectives. Industrial and IoT data can reveal know-how, algorithms, control logic, production methods or R&D results when combined, sequenced or analysed in bulk. Disclosure without the trade secret holder’s consent would weaken innovation, expose EU manufacturers to unfair competition and security risks, and reduce trust in data sharing, while preserving coherence with the Trade Secrets Directive, NIS2 and the Cyber Resilience Act.

Amendment 619

Axel Voss

Proposal for a regulation

Article 1 – paragraph 1 – point 3 c (new)

Regulation (EU) 2023/2854

Article 4 – paragraph 13

Present textAmendment
3c. In Article 4, paragraph 13 is deleted.
13. A data holder shall only use any readily available data that is non-personal data on the basis of a contract with the user. A data holder shall not use such data to derive insights about the economic situation, assets and production methods of, or the use by, the user in any other manner that could undermine the commercial position of that user on the markets in which the user is active.""

Or. en

(Regulation (EU) 2023/2854)

Justification

Deleting Article 4(13) and (14) restores data holders’ ability to use non-personal data generated by connected products for diagnostics, maintenance, safety, cybersecurity, quality assurance, R&D, AI development and product improvement. The current rules create legal uncertainty, contractual friction and barriers for upstream operators and OEM-component partnerships. Deletion simplifies the Data Act, supports industrial competitiveness and leaves safeguards for data protection, trade secrets and IP intact.

Amendment 620

Axel Voss

Proposal for a regulation

Article 1 – paragraph 1 – point 3 d (new)

Regulation (EU) 2023/2854

Article 4 – paragraph 14

Present textAmendment
3d. Article 4 - paragraph 14 is deleted.
14. Data holders shall not make available non-personal product data to third parties for commercial or non-commercial purposes other than the fulfilment of their contract with the user. Where relevant, data holders shall contractually bind third parties not to further share data received from them.""

Or. en

(Regulation (EU) 2023/2854)

Justification

Deleting Article 4(13) and (14) restores data holders’ ability to use non-personal data generated by connected products for diagnostics, maintenance, safety, cybersecurity, quality assurance, R&D, AI development and product improvement. The current rules create legal uncertainty, contractual friction and barriers for upstream operators and OEM-component partnerships. Deletion simplifies the Data Act, supports industrial competitiveness and leaves safeguards for data protection, trade secrets and IP intact.

Amendment 621

Axel Voss

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2023/2854

Article 5 – paragraph 11

Text proposed by the CommissionAmendment
11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;deleted

Or. en

Justification

The amendments ensure that Data Act access rights do not override trade secrets, IP or EU cybersecurity objectives. Industrial and IoT data can reveal know-how, algorithms, control logic, production methods or R&D results when combined, sequenced or analysed in bulk. Disclosure without the trade secret holder’s consent would weaken innovation, expose EU manufacturers to unfair competition and security risks, and reduce trust in data sharing, while preserving coherence with the Trade Secrets Directive, NIS2 and the Cyber Resilience Act.

Amendment 622

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2023/2854

Article 5 – paragraph 11

Text proposed by the CommissionAmendment
11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate with sufficient evidence that the product data and related service data constiute a trade secret within the meaning of Article 2(1) of Directive 2016/943, that such trade secrets cannot be eliminated or sufficiently mitigated through design measures pursutant to Aritcle 3(1), and, despite the technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, it is highly likely to suffer serious and demonstrable economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the user poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent user or trade secret protection compared to that under Union law. For the purposes of this Regulation, 'serious economic damage' does not include normal competitive effects arising from lawful access under the Data Act.
The data holder shall identify the specific data that constitutes a trade secret and shall not classify entire datasets as trade secrets. Any such demonstration shall be duly substantiated on the basis of objective, verifiable and specific evidence, taking into account, in particular, the enforceability of trade secret protection in third countries, the nature and level of confidentiality of the data concerned, the design measures applied pursuant to Article 3(1), and the uniqueness and novelty of the connected product. Such demonstration shall be provided in writing to the user without undue delay.
Where the data holder refuses to share specific data on the basis of trade secret protection, it shall notify the competent authority designated pursuant to Article 37 without undue delay and no later than five working days after communicating the refusal to the user. The competent authority shall review the substantiation provided and issue a binding decision within sixty calendar days of receipt of the notification.
A refusal shall be permitted only on a case-by-case basis and shall be duly reasoned, proportionate and limited to the specific data strictly necessary to protect the trade secret. It shall not prejudice the rights of users under this Regulation. Any claim relating to third-country entities shall be supported by concrete evidence demonstrating a specific risk of unlawful access, use or disclosure.
Access may be refused only where the data holder demonstrates, on the basis of objective and verifiable evidence, that disclosure would create a serious and specific risk of unlawful acquisition, use or disclosure of the trade secret that cannot be adequately mitigated through confidentiality measures, technical safeguards or contractual arrangements.

Or. en

Amendment 623

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2023/2854

Article 5 – paragraph 11

Text proposed by the CommissionAmendment
11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;11. The Commission, in consultation with the European Data Innovation Board (EDIB) and representatives of data holders, users, and third parties shall publish a list of high-risk sectors with regards to the disclosure of trade secrets. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or, in high-risk sectors, that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objectiveevidence, such as the enforceability of trade secrets protection in third countries, the verifable insufficiency of specific technical and organisational measures taken by the user pursuant to paragraph 6 of this Article, the high likelihood of suffering serious economic damage, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37 no later than five working days after the refusal was communicated to the third party. The competent authority shall approve or reject the data holder’s refusal to share data pursuant to this paragraph based on a review of the evidence submitted by the data holder, and provide in writing an explanation for its decision to the data holder and third party within 60 calander days. The third party has the right to be heard before the competent authority decides to approve or reject the data holder’s refusal to share data pursuant to this paragraph. The Commission shall issue guidelines, in consultation with the European Data Innovation Board (EDIB) and representatives of data holders, users, and third parties on the application of this paragraph, such as the assessment of serious economic damage, third-country entity direct or indirect control, and the enforceability of trade secrets protection in third countries.

Or. en

Amendment 624

Henrik Dahl

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2023/2854

Article 5 – paragraph 11

Text proposed by the CommissionAmendment
11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;11. In any circumstance, where the data holder who is a trade secret holder assesses a risk of disclosing trade secrets, the data holder may refuse a request for access to the specific data in question. The assessment shall be based on the definition of trade secrets stated in Article 2 (1) of Directive (EU) 2016/943 of the European Parliament and of the Council. The refusal shall be provided in writing to the user without undue delay.;

Or. en

Amendment 625

Niels Flemming Hansen

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2023/2854

Article 5 – paragraph 11

Text proposed by the CommissionAmendment
11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;11. In any circumstance, where the data holder who is a trade secret holder assesses a risk of disclosing trade secrets, the data holder may refuse a request for access to the specific data in question. The assessment shall be based on the definition of trade secrets stated in Article 2 (1) of Directive (EU) 2016/943 of the European Parliament and of the Council. The refusal shall be provided in writing to the user without undue delay.’

Or. en

Amendment 626

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2023/2854

Article 5 – paragraph 11

Text proposed by the CommissionAmendment
11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;11. In any circumstance, where the data holder who is a trade secret holder assesses a risk of disclosing trade secrets, the data holder may refuse a request for access to the specific data in question. The assessment shall be based on the definition of trade secrets stated in Article 2 (1) of Directive (EU) 2016/943 of the European Parliament and of the Council. The refusal shall be provided in writing to the user without undue delay.;

Or. en

Amendment 627

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Adina Vălean, Andrea Wechsler, Christian Ehler

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2023/2854

Article 5 – paragraph 11

Text proposed by the CommissionAmendment
11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;11. Where the data holder who is a trade secret holder finds that it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, in particular the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the third party requesting access to the data.
The Commission shall consult stakeholders and adopt guidelines on the application of paragraph 5(11). These shall identify specific third-country jurisdictions and types of data or practices that inherently pose a high risk to trade secrets in particular where the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law. The Commission shall provide a simplified template based on the list of objective criteria to help data holders to substantiate 'serious economic damage,' and where access may be granted even if data is highly sensitive and under what conditions

Or. en

Amendment 628

Dario Nardella

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2023/2854

Article 5 – point 11

Text proposed by the CommissionAmendment
11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37. Where a third party’s request for access relates to data reflecting the user’s economic activity, scale of operations and output, the data holder shall inform the user in advance of the request received, specifying the nature of the data requested and the decisions taken regarding the activation of the refusal mechanism. This information obligation is without prejudice to the user’s right under Article 5 to designate the third party recipient of the data.

Or. it

Justification

L'emendamento estende in modo simmetrico all'articolo 5, paragrafo 11, del regolamento (UE) 2023/2854 l'obbligo informativo introdotto all'articolo 4, paragrafo 8, dall'Emendamento 6. La ratio è la medesima. Quando la richiesta di accesso riguarda dati che riflettono l'attività e il dimensionamento economica dell'utente e delle sue produzioni, l'utente deve essere messo nella condizione di conoscere la richiesta e le determinazioni del detentore dei dati, anche quando la richiesta provenga da un terzo. L'emendamento è formulato in modo da non incidere sul diritto dell'utente di designare autonomamente terze parti destinatarie dei propri dati, disciplinato dall'articolo 5 del regolamento nella sua struttura complessiva.

Amendment 629

Francesco Torselli, Paolo Inselvini

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2023/2854

Article 5 – point 11

Text proposed by the CommissionAmendment
11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37. Where a third party’s request for access relates to data reflecting the user’s economic activity and scale of operations and their output, the data holder shall inform the user in advance of the request received, specifying the nature of the data requested and the decisions taken regarding the activation of the refusal mechanism. This information obligation is without prejudice to the user’s right under Article 5 to designate the third party recipient of the data.
(Our intention is to amend this article by adding a section of text at the end of the article in question.)

Or. it

Amendment 630

Tomas Tobé, Arba Kokalari, Jörgen Warborn

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2023/2854

Article 5 – paragraph 11

Text proposed by the CommissionAmendment
11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;11. Where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is likely to suffer economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse a request for access to the specific data in question. The refusal shall be provided in writing to the third party without undue delay.

Or. en

Amendment 631

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2023/2854

Article 5 – paragraph 11

Text proposed by the CommissionAmendment
11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.

Or. pt

Amendment 632

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2023/2854

Article 5 – Paragraph 11

Text proposed by the CommissionAmendment
11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;11. In exceptional circumstances, where the data holder who is a trade secret holder is able to establish, on the basis of reasonable grounds, that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is likely to suffer significant economic damage from the disclosure of trade secrets or of industrial, strategic or sensitive data whose disclosure would be liable to harm economic security, privacy or public order, or that the disclosure of such data to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, including as a result of the foreseeable onward transmission of the data to such entities, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That assessment shall be reasonably substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, the reasonably foreseeable chain of onward transmission of the data, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.

Or. en

Amendment 633

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2023/2854

Article 5 – paragraph 11

Text proposed by the CommissionAmendment
11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious and irreparable economic damage from the disclosure of trade secrets, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, in particular the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37. The data holder and the competent authority shall inform the third party of their rights and the relevant procedure under paragraph 12.

Or. en

Amendment 634

Pilar del Castillo Vera

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2023/2854

Article 5 – paragraph 11

Text proposed by the CommissionAmendment
11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, such as the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;11. In exceptional circumstances, where the data holder who is a trade secret holder is able to demonstrate that, despite the technical and organisational measures taken by the third party pursuant to paragraph 9 of this Article, it is highly likely to suffer serious economic damage from the disclosure of trade secrets or that the disclosure of trade secrets to the third party poses a high risk of unlawful acquisition, use, or disclosure to third country entities, or entities established in the Union under the direct or indirect control of such entities, which are subject to jurisdictions offering weaker or non-equivalent protection compared to that under Union law, that data holder may refuse on a case-by-case basis a request for access to the specific data in question. That demonstration shall be duly substantiated on the basis of objective elements, in particular the enforceability of trade secrets protection in third countries, the nature and level of confidentiality of the data requested, and the uniqueness and novelty of the connected product. It shall be provided in writing to the third party without undue delay. Where the data holder refuses to share data pursuant to this paragraph, it shall notify the competent authority designated pursuant to Article 37.;

Or. en

Justification

Article 5(11), as currently drafted in the Data Act, establishes an exhaustive framework for demonstrating, based on objective elements, the risk of serious economic damage resulting from the disclosure of trade secrets. Replacing “in particular” with “such as” would transform that framework into an open-ended list of criteria, allowing reliance on additional unspecified elements and broadening the grounds for refusal. To preserve legal certainty, the original wording should be retained.

Amendment 635

Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Sophie Wilmès, Nikola Minchev, Svenja Hahn, Andreas Glück, João Cotrim De Figueiredo, Ana Vasconcelos

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2023/2854

Article 5 – paragraph 10 – subparagraph (new)

Text proposed by the CommissionAmendment
11a. In Article 5, paragraph 10 the following subparagraph is added:
'Notifications pursuant to this paragraph shall not require the disclosure of the content of a trade secret, as defined in Article 2(1) of Directive (EU) 2016/943, or of any detailed information whose disclosure would be liable to undermine the confidentiality of that trade secret.'

Or. en

Amendment 636

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 4 a (new)

Regulation (EU) 2023/2854

Article 5 – paragraph 13a (new)

Text proposed by the CommissionAmendment
4a. Article 5 is amendment as follows: the following paragraph 13a is inserted:
'13a. [By 12 months from the entry into force of this amending Regulation], the Commission shall adopt a delegated act in accordance with Article 45 of this Regulation for the purpose of ensuring an effective implementation of paragraph 1 with regard to vehicle-generated data, vehicle functions and vehicle resources. The delegated act shall specify categories of data that can be made available, functions and resources, modalities of access, specific interoperability requirements, proportionate security and monitoring measures, and standardised sets of data to be made available to data recipients without unlawfully disclosing personal data. Such access shall be made available by the data holder to the third party in accordance with Articles 8 and 9 and in full respect of Regulation (EU) 2016/679 and Directive 2002/58/EC.'

Or. en

Amendment 637

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 4 a (new)

Regulation (EU) 2023/2854

Article 8 – Paragraph 6a (new)

Present textAmendment
4a. In Article 8, the following paragraph is added:
(new)"'6a. Data holders and data recipients that comply with a code of conduct drawn up by industry associations and recognised by the Commission shall be presumed to comply with the requirement to make data available under fair, reasonable and non-discriminatory terms and conditions laid down in paragraph 1. The Commission may recognise such codes of conduct, taking into account the advice of the EDIB.'"

Or. en

(32023R2854)

Justification

Data holders and recipients complying with a code of conduct drawn up by industry associations and recognised by the Commission are presumed to comply with the requirement of fair, reasonable and non-discriminatory terms. The presumption is rebuttable and does not affect the mandatory character of the obligation to make data available. Sectoral codes provide legal certainty at lower cost, particularly for SMEs.

Amendment 638

Axel Voss

Proposal for a regulation

Article 1 – paragraph 1 – point 4 a (new)

Regulation (EU) 2023/2854

Article 5 – paragraph 9

Present textAmendment
4a. In Article 5, paragraph 9 is being replaced by the following:
Trade secrets shall be preserved and shall be disclosed to third parties only to the extent that such disclosure is strictly necessary to fulfil the purpose agreed between the user and the third party. The data holder or, where they are not the same person, the trade secret holder shall identify the data which are protected as trade secrets, including in the relevant metadata, and shall agree with the third party all proportionate technical and organisational measures necessary to preserve the confidentiality of the shared data, such as model contractual terms, confidentiality agreements, strict access protocols, technical standards and the application of codes of conduct."9. Trade secrets shall be preserved and shall not be disclosed to third parties without the consent of their respective trade secret holder."

Or. en

(Regulation (EU) 2023/2854)

Justification

The amendments ensure that Data Act access rights do not override trade secrets, IP or EU cybersecurity objectives. Industrial and IoT data can reveal know-how, algorithms, control logic, production methods or R&D results when combined, sequenced or analysed in bulk. Disclosure without the trade secret holder’s consent would weaken innovation, expose EU manufacturers to unfair competition and security risks, and reduce trust in data sharing, while preserving coherence with the Trade Secrets Directive, NIS2 and the Cyber Resilience Act.

Amendment 639

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 4 a (new)

Regulation (EU) 2023/2854

Article 6 – paragraph 2 – points e and g

Text proposed by the CommissionAmendment
4a. In Article 6, paragraph 2 is amended as follows:
point (e) is deleted;
point (g) is replaced by the following:
'prevent the user that is a consumer, without renumeration, from making the data it receives available to other parties.'

Or. en

Amendment 640

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 4 b (new)

Regulation (EU) 2023/2854

Article 9 – paragraphs 1, 5, 6a (new) and paragraph 2 – point b

Text proposed by the CommissionAmendment
4b. Article 9 is amended as follows:
paragraph 1 is replaced by the following:
'Any compensation agreed upon between a data holder and a data recipient for making data available in business-to-business relations shall be non- discriminatory and not exceed the cost incurred listed in paragraph 2 and publicly available prices for comparable data.';
paragraph 2 point (b) is deleted;
paragraph 5 is replaced by the following:
'The European Data Innovation Board shall adopt guidelines on the calculation of reasonable compensation.';
the following paragraph 6a is added:
'Where a competent authority identifies discrepancies in pricing between comparable data categories or systematic prohibitive pricing, it may set price ceilings for such cases. Competent authorities shall offer direct channels for data recipients to bring such cases to their attention’.

Or. en

Amendment 641

Axel Voss

Proposal for a regulation

Article 1 – paragraph 1 – point 4 b (new)

Regulation (EU) 2023/2854

Article 5 – paragraph 10

Present textAmendment
4 b. In Article 5, paragraph 10 is deleted.
10. Where there is no agreement on the necessary measures referred to in paragraph 9 of this Article or if the third party fails to implement the measures agreed pursuant to paragraph 9 of this Article or undermines the confidentiality of the trade secrets, the data holder may withhold or, as the case may be, suspend the sharing of data identified as trade secrets. The decision of the data holder shall be duly substantiated and provided in writing to the third party without undue delay. In such cases, the data holder shall notify the competent authority designated pursuant to Article 37 that it has withheld or suspended data sharing and identify which measures have not been agreed or implemented and, where relevant, which trade secrets have had their confidentiality undermined.""

Or. en

(Regulation (EU) 2023/2854)

Justification

The amendments ensure that Data Act access rights do not override trade secrets, IP or EU cybersecurity objectives. Industrial and IoT data can reveal know-how, algorithms, control logic, production methods or R&D results when combined, sequenced or analysed in bulk. Disclosure without the trade secret holder’s consent would weaken innovation, expose EU manufacturers to unfair competition and security risks, and reduce trust in data sharing, while preserving coherence with the Trade Secrets Directive, NIS2 and the Cyber Resilience Act.

Amendment 642

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) 2023/2854

Article 15a – paragraph 1

Text proposed by the CommissionAmendment
1. Where a public sector body, the Commission, the European Central Bank or a Union body demonstrates an exceptional need to use certain data to carry out its statutory duties in the public interest when responding to, mitigating, or supporting the recovery from a public emergency, it may request from data holders that are legal persons, other than public sectors bodies, to make available those data, including the metadata necessary to interpret and use those data. Upon such duly reasoned request, data holders shall make the data and metadata available to the requesting public sector body, the Commission, the European Central Bank or Union body. Such requests may also be made where the production of official statistics is required in relation to a public emergency.1. Where a public sector body, the Commission, the European Central Bank or a Union body demonstrates an exceptional need to use certain data to carry out its statutory duties in the public interest when responding to, mitigating, or supporting the recovery from a public emergency, it may, as a measure of last resort, request from data holders that are legal persons, other than public sectors bodies, to make available those data, including the metadata necessary to interpret and use those data. An exceptional need exists only where the data concerned are strictly necessary for the purpose pursued and cannot be obtained under equivalent conditions by any other means. Upon such duly reasoned request, data holders shall make the data and metadata available to the requesting public sector body, the Commission, the European Central Bank or Union body. Such requests may also be made where the production of official statistics is required in relation to a public emergency.

Or. en

Justification

The power to compel private data holders to make data available constitutes a significant interference with the freedom to conduct a business and, where personal data are concerned, with the right to the protection of personal data. Such a power must therefore be strictly circumscribed. This amendment clarifies that access may be requested only as a measure of last resort, where the data are strictly necessary and cannot be obtained under equivalent conditions by any other means. It further breaks the circularity between the notions of ‘exceptional need’ and ‘public emergency’ by anchoring the former in an objective test of strict necessity and subsidiarity, and the latter in autonomous criteria of gravity and effect. The subsidiary treatment of personal data ensures compliance with the principles of necessity and proportionality and with the data minimisation principle under Regulation (EU) 2016/679.

Amendment 643

Mary Khan

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) 2023/2854

Article 15a – paragraph 1

Text proposed by the CommissionAmendment
(1) Where a public sector body, the Commission, the European Central Bank or a Union body demonstrates an exceptional need to use certain data to carry out its statutory duties in the public interest when responding to, mitigating, or supporting the recovery from a public emergency, it may request from data holders that are legal persons, other than public sectors bodies, to make available those data, including the metadata necessary to interpret and use those data. Upon such duly reasoned request, data holders shall make the data and metadata available to the requesting public sector body, the Commission, the European Central Bank or Union body. Such requests may also be made where the production of official statistics is required in relation to a public emergency.(1) Where a public sector body that is competent under the law of the Member State demonstrates an exceptional need to use certain data to carry out its statutory duties in the public interest when responding immediately to a public emergency, it may request that data holders that are legal persons, other than public sector bodies, make available such data, including the metadata strictly necessary to interpret and use those data.
The Commission, the European Central Bank and Union bodies may address a request for data only to the public sector body that is competent under the national law of the Member State concerned. They may not directly request data from private data holders. The competent public sector body shall be responsible under national law for deciding whether and to what extent it complies with the request.

Or. de

Justification

Access to data in emergencies must remain a national competence, in line with democratic principles and the rule of law. EU bodies may request information, but they may not directly impose obligations on private data holders.

Amendment 644

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) 2023/2854

Article 15a – paragraph 2

Text proposed by the CommissionAmendment
2. Where the data requested are necessary to respond to a public emergency, and the requesting body pursuant to paragraph 1 is unable to obtain such data by other means in a timely and effective manner under equivalent conditions, the request shall concern non-personal data. Where the provision of non-personal data is insufficient to address the public emergency, personal data may also be requested and, where possible, made available in pseudonymized form, subject to appropriate technical and organisational measures to ensure their protection.2. Where the data requested are necessary to respond to a public emergency, and the requesting body pursuant to paragraph 1 is unable to obtain such data by other means in a timely and effective manner under equivalent conditions, the request shall concern non-personal data. Where the provision of non-personal data is insufficient to address the public emergency, personal data may also be requested and, where possible, made available in pseudonymized form, subject to appropriate technical and organisational measures to ensure their protection against further re-identification, personal data breaches and unlawful use.

Or. en

Amendment 645

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) 2023/2854

Article 15a – paragraph 2

Text proposed by the CommissionAmendment
2. Where the data requested are necessary to respond to a public emergency, and the requesting body pursuant to paragraph 1 is unable to obtain such data by other means in a timely and effective manner under equivalent conditions, the request shall concern non-personal data. Where the provision of non-personal data is insufficient to address the public emergency, personal data may also be requested and, where possible, made available in pseudonymized form, subject to appropriate technical and organisational measures to ensure their protection.2. Where the data requested are necessary to respond to a public emergency, and the requesting body pursuant to paragraph 1 is unable to obtain such data by other means in a timely and effective manner under equivalent conditions, the request shall concern non-personal data. Only where the provision of non-personal data is demonstrated to be insufficient to respond to the public emergency, personal data may also be requested and, shall only be made available in pseudonymized form and only when strictly necessary, subject to appropriate technical and organisational measures to ensure their protection

Or. en

Amendment 646

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) 2023/2854

Article 15a – paragraph 2

Text proposed by the CommissionAmendment
2. Where the data requested are necessary to respond to a public emergency, and the requesting body pursuant to paragraph 1 is unable to obtain such data by other means in a timely and effective manner under equivalent conditions, the request shall concern non-personal data. Where the provision of non-personal data is insufficient to address the public emergency, personal data may also be requested and, where possible, made available in pseudonymized form, subject to appropriate technical and organisational measures to ensure their protection.2. Where the data requested are strictly necessary to respond to a public emergency, and the requesting body pursuant to paragraph 1 is unable to obtain such data by other means in a timely and effective manner under equivalent conditions, the request shall concern non-personal data. Personal data may be requested only as a last resort, where the provision of non-personal data is demonstrably insufficient to address the public emergency, and shall, where possible, be made available in pseudonymised form, subject to appropriate technical and organisational measures to ensure their protection.

Or. en

Justification

Access to data by public sector bodies in a public emergency must remain exceptional and bounded. The amendment ties the request to the strict impossibility of obtaining the data by other means and requires the requesting body to substantiate that impossibility, rather than merely assert it.

Amendment 647

Markus Buchheit

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) 2023/2854

Article 15a – paragraph 2a (new)

Text proposed by the CommissionAmendment
2a. 'The provisions of this Chapter shall clarify that a request for data by a public authority shall not be permissible insofar as the data requested contain personal data or permit conclusions to be drawn about identified or identifiable natural persons, unless an express and specific statutory basis of the Member State concerned provides for this in a narrowly delimited individual case. Such a request shall also be impermissible where the public authority can obtain the required information with reasonable effort from its own sources or from other public sources.'

Or. en

Amendment 648

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) 2023/2854

Article 15a – paragraph 2a (new)

Text proposed by the CommissionAmendment
2a. 'The personal data referred to in paragraph 2 may only be requested following prior authorisation by a judicial authority.'

Or. en

Amendment 649

Mary Khan

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) 2023/2854

Article 15a – paragraph 3

Text proposed by the CommissionAmendment
(3) Where the data requested are necessary to mitigate or support the recovery from a public emergency, a requesting body pursuant to paragraph 1 acting on the basis of Union or national law, may request specific non-personal data, the lack of which prevent it from mitigating or supporting the recovery from a public emergency. Such requests shall not be made to microenterprises and small enterprises.deleted

Or. de

Justification

Exceptional B2G powers must be limited to immediate action to address a clearly identified emergency. Standard legislative instruments should be used for reconstruction and general policy planning.

Amendment 650

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) 2023/2854

Article 15a – paragraph 3a (new)

Text proposed by the CommissionAmendment
3a. 'A public sector body, the Commission, the European Central Bank or a Union body that has received data on the basis of a public emergency shall:
(a) implement technical and organisational measures that preserve the confidentiality and integrity of the requested data and the security of the data transfers, in particular of personal data, and safeguard the rights and freedoms of data subjects;
(b) erase the data as soon as they are no longer necessary for the stated purpose and inform the data holder, as well as any natural or legal persons that received the data with a view to carrying out the task for which the request was made, without undue delay, that the data have been erased, unless archiving is required under Union or national law on public access to documents in the context of transparency obligations.'

Or. en

Justification

For reasons of legal clarity and accessibility, the safeguards attached to the use of data obtained in the context of a public emergency should be set out expressly in the operative provision rather than by cross-reference alone. Recalling in full the obligations to implement technical and organisational measures and to erase the data once they are no longer necessary ensures that these safeguards remain readable and enforceable, in line with the principles of purpose limitation and storage limitation under Regulation (EU) 2016/679. In addition, the exclusion of special categories of personal data and of data relating to criminal convictions from the scope of emergency data requests, save where their processing is strictly necessary and authorised by law, reinforces the protection of data subjects’ fundamental rights.

Amendment 651

Mary Khan

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) 2023/2854

Article 15a – paragraph 3 a (new)

Text proposed by the CommissionAmendment
(3a) ‘Data provided under this Article may be processed only for the purpose specified in the data request. Their use for the training, testing or validation of AI systems or AI models, or for profiling, scoring, commercial purposes or administrative purposes other than those explicitly specified in the request shall be prohibited.’

Or. de

Amendment 652

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) 2023/2854

Article 15a – paragraph 3a (new)

Text proposed by the CommissionAmendment
3a. 'Requests shall be limited in time.'

Or. en

Amendment 653

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) 2023/2854

Article 15a – paragraph 3b (new)

Text proposed by the CommissionAmendment
3b. 'Requests shall be notified latest 6 months after the request was made to the European Data Protection Board, including:
- an assessment of whether the criteria laid out in Article 17 were fulfilled a description of the technical and organisational measures taken for the data to be collected, used, stored and deleted;
- an assessment of how the request contributed to the achievement of the public interest objective pursued;
- an assessment of the costs incurred by data providers comparatively to the compensation provided;
- and an assessment of compliance with the applicable rules on the protection of personal data.
- an assessment of the potential need to compensate requested entities for potential misuse or non-fulfilment of the criteria laid out in this Article and Article 17.'

Or. en

Amendment 654

Mary Khan

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) 2023/2854

Article 15a – paragraph 3 b (new)

Text proposed by the CommissionAmendment
(3b) ‘The requesting body shall delete the data received and any copies thereof as soon as the purpose is fulfilled and no later than 30 days after the end of the public emergency. Retention for a longer period is permitted only on the basis of a specific national legal provision and a verifiable decision taken on a case-by-case basis. All access, transmission and deletion operations shall be logged in an audit-compliant manner.’

Or. de

Amendment 655

Mary Khan

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) 2023/2854

Article 15a – paragraph 3 c (new)

Text proposed by the CommissionAmendment
(3c) ‘Member States shall publish, at least once per year, a register of the data requests made pursuant to this Article, indicating the legal basis, purpose and categories of data concerned, the recipients, the duration of the processing and the date of deletion. Where publication during an ongoing emergency would be damaging for compelling reasons of public security, publication shall take place without delay after those reasons cease to exist.’

Or. de

Amendment 656

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 8 a (new)

Regulation (EU) 2023/2854

Article 16 – paragraph 2a (new)

Text proposed by the CommissionAmendment
8a. In Article 16, the following paragraph is added:
'2a. A public sector body, the Commission, the European Central Bank or a Union body that has received data on the basis of a public emergency shall:
(a) have implemented technical and organisational measures that preserve the confidentiality and integrity of the requested data and the security of the data transfers, in particular of personal data, and safeguard the rights and freedoms of data subjects; and
(b) erase the data as soon as they are no longer necessary for the stated purpose and inform the data holder and the individuals or organisations that received the data pursuant to Article 21(1), without undue delay, that the data have been erased, unless archiving is required under Union or national law on public access to documents in the context of transparency obligations.'

Or. en

Amendment 657

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 9 – point a – point ii

Regulation (EU) 2023/2854

Article 17 – paragraph 1 – point c

Text proposed by the CommissionAmendment
(c) explain the purpose of the request, the intended use of the data requested, including, where applicable, by a third party in accordance with paragraph 4 of this Article, the duration of that use, and, where relevant, how the processing of personal data is to address the public emergency;;(c) explain the purpose of the request, the intended use of the data requested, including, where applicable, by a third party in accordance with paragraph 4 of this Article, the duration of that use, and how the processing of personal data is necessary to address and how it will respond to the public emergency;

Or. en

Amendment 658

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 9 – point a – point ii a (new)

Regulation (EU) 2023/2854

Article 17 – paragraph 2 – subparagraph (new)

Text proposed by the CommissionAmendment
(iia) In Article 17, paragraph 2, the following subparagraph is added:
'The Commission, the European Central Bank (ECB) or any of the Union Bodies, shall notify the European Data Protection Supervisor of their requests for personal data.'

Or. en

Amendment 659

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 9 – point b – point i

Regulation (EU) 2023/2854

Article 17 – paragraph 2 – point c

Text proposed by the CommissionAmendment
(c) be proportionate to the public emergency and duly justified, regarding the granularity and volume of the data requested and the frequency of access to the data requested;;(c) be proportionate to the exceptional needs of the public emergency and duly justified, regarding the granularity and volume of the data requested and the frequency of access to the data requested;;

Or. en

Justification

Brings back current wording of the Data Act

Amendment 660

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 9 – point b – point i

Regulation (EU) 2023/2854

Article 17 – paragraph 2 – point c

Text proposed by the CommissionAmendment
(c) be proportionate to the public emergency and duly justified, regarding the granularity and volume of the data requested and the frequency of access to the data requested;;(c) be strictly proportionate to the public emergency and duly justified, regarding the granularity and volume of the data requested and the frequency of access to the data requested;

Or. en

Amendment 661

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 9 – point b – point ii

Regulation (EU) 2023/2854

Article 17 – paragraph 2 – subparagraph 1 – point e

Text proposed by the CommissionAmendment
(ii) point (e) is deleted.;deleted

Or. en

Amendment 662

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 9 – point b – point ii

Regulation (EU) 2023/2854

Article 17 paragraph 2 – subparagraph 1 – point e

Text proposed by the CommissionAmendment
(ii) point (e) is deleted.;deleted

Or. en

Amendment 663

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 9 – point c

Regulation 2023/2854

Article 17 paragraph 6

Text proposed by the CommissionAmendment
(c) paragraphs 5 and 6 are deleted;(c) paragraphs 5 is deleted;

Or. en

Amendment 664

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 9 – point c – point i (new)

Regulation (EU) 2023/2854

Article 17 – paragraph 2 – subparagraph 2 a (new)

Text proposed by the CommissionAmendment
i) In Article 17, paragraph 2, the following subparagraph is added:
'Within six months of the request, the Commission, ECB and Union bodies shall notify the European Data Protection Superviser (EDPS) of their requests for personal data, including how the requested personal data was used to respond to the public emergency and why the requested personal data was necessary to respond to the public emergency.
Within six months of the request, public sector bodies shall notify their supervisory authority within the meaning of Regulation (EU) 2016/679 and the European Data Protection Board (EDPB) of their requests for personal data, including how the requested personal data was used to respond to the public emergency and why the requested personal data was necessary to respond to the public emergency.'

Or. en

Amendment 665

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 10 – point b a (new)

Regulation (EU) 2023/2854

Article 18 – paragraph 1

Text proposed by the CommissionAmendment
(ba) (-a) paragraph 1 is replaced by the following:
1. A data holder receiving a request to make data available under this Chapter shall make the data available to the requesting public sector body, the Commission, the European Central Bank or a Union body without undue delay, having implemented the necessary technical, organisational and legal measures.

Or. en

Amendment 666

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 10 a (new)

Regulation (EU) 2023/2854

Article 18 – paragraph 1

Text proposed by the CommissionAmendment
10a. In Article 18, paragraph 1 is amended as follows:
1. A data holder receiving a request to make data available under this Chapter shall make the data available to the requesting public sector body, the Commission, the European Central Bank or a Union body without undue delay, having implemented the necessary technical, organisational and legal measures to comply with data protection principles and to protect personal data and safeguard the rights and freedoms of data subjects.

Or. en

Amendment 667

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 11 – point a a (new)

Regulation (EU) 2023/2854

Article 19 – paragraph 1 – point c

Text proposed by the CommissionAmendment
(aa) In Article 19, paragraph 1, point c is replaced by the following:
'(c) erase the data as soon as they are no longer necessary for the stated purpose and inform the data holder and individuals or organisations that received the data pursuant to Article 21(1) without undue delay that the data have been erased, unless archiving of the data is required in accordance with Union or national law on public access to information in the context of transparency obligations.'

Or. en

Amendment 668

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 11 – point a a (new)

Regulation (EU) 2023/2854

Article 19 – paragraph 1– point c

Text proposed by the CommissionAmendment
(aa) In Article 19, paragraph 1, point c is replaced by the following:
'(c) erase the data as soon as they are no longer necessary for the stated purpose and inform the data holder and individuals or organisations that received the data pursuant to Article 21(1) without undue delay that the data have been erased, unless archiving of the data is required in accordance with Union or national law on public access to information in the context of transparency obligations.’

Or. en

Amendment 669

Diana Iovanovici Şoşoacă

Proposal for a regulation

Article 1 – paragraph 1 – point 11 – point b

Regulation (EU) 2023/2854

Article 19 – paragraph 3

Text proposed by the CommissionAmendment
(3) Disclosure of trade secrets to a public sector body, the Commission, the European Central Bank or a Union body shall be required only to the extent that it is strictly necessary to achieve the purpose of a request under Article 15a. In such a case, the data holder or, where they are not the same person, the trade secret holder shall identify the data which are protected as trade secrets, including in the relevant metadata. The public sector body, the Commission, the European Central Bank or the Union body shall, prior to the disclosure of trade secrets, take all necessary and appropriate technical and organisational measures to preserve the confidentiality of the trade secrets, including, as appropriate, the use of model contractual terms, technical standards and the application of codes of conduct.(3) Disclosure of trade secrets to a public sector body, the Commission, the European Central Bank or a Union body shall be required only to the extent that it is strictly necessary to achieve the purpose of a request under Article 15a. In such a case, the data holder or, where they are not the same person, the trade secret holder shall identify the data which are protected as trade secrets, including in the relevant metadata. The public sector body, the Commission, the European Central Bank or the Union body shall, prior to the disclosure of trade secrets, take all necessary and appropriate technical and organisational measures to preserve the confidentiality of the trade secrets, including, as appropriate, the use of model contractual terms, technical standards and the application of codes of conduct, as well as the implementation of data minimisation principles, needs-based access separation, encryption of data in transit and at rest, and regular monitoring and assessment of the risks of unauthorised disclosure. In case of disclosure, the public sector body, the Commission, the European Central Bank or the Union body shall notify the trade secret holder within a reasonable period of time, limit the disclosure to what is strictly necessary and take remedial measures, including data recovery or termination of disclosure, as requested or decided upon by the competent authority. Any authorised disclosure shall be conducted in accordance with the applicable legal framework, respecting the rights of the trade secret holder, the safeguards adopted and the principles of transparency, proportionality and information security. The trade secret holder may request that compliance with those measures be monitored and may challenge an unjustified or excessive disclosure before the competent authorities.

Or. ro

Justification

Data privacy is essential, even in emergency situations, and requires clearly defined conditions for access and protection.

Amendment 670

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 11 – point b

Regulation (EU) 2023/2854

Article 19 – paragraph 1

Text proposed by the CommissionAmendment
3. Disclosure of trade secrets to a public sector body, the Commission, the European Central Bank or a Union body shall be required only to the extent that it is strictly necessary to achieve the purpose of a request under Article 15a. In such a case, the data holder or, where they are not the same person, the trade secret holder shall identify the data which are protected as trade secrets, including in the relevant metadata. The public sector body, the Commission, the European Central Bank or the Union body shall, prior to the disclosure of trade secrets, take all necessary and appropriate technical and organisational measures to preserve the confidentiality of the trade secrets, including, as appropriate, the use of model contractual terms, technical standards and the application of codes of conduct.;3. Disclosure of trade secrets to a public sector body, the Commission, the European Central Bank or a Union body shall be required only to the extent that it is strictly necessary to achieve the purpose of a request under Article 15a. In such a case, the data holder or, where they are not the same person, the trade secret holder shall identify the data which are protected as trade secrets, including in the relevant metadata. The public sector body, the Commission, the European Central Bank or the Union body shall, prior to the disclosure of trade secrets, take all necessary and appropriate technical and organisational measures to preserve the confidentiality of the trade secrets, including, as appropriate, the use of model contractual terms, technical standards and the application of codes of conduct. The disclosure of trade secrets shall not automatically prevent access; instead, it must trigger protective measures, limitations, and controls. Such measures must be proportionate and designed to safeguard the confidentiality of trade secrets while allowing necessary access in response to public sector requests.

Or. en

Amendment 671

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 11 – point b

Regulation (EU) 2023/2854

Article 19 – paragraph 3

Text proposed by the CommissionAmendment
3. Disclosure of trade secrets to a public sector body, the Commission, the European Central Bank or a Union body shall be required only to the extent that it is strictly necessary to achieve the purpose of a request under Article 15a. In such a case, the data holder or, where they are not the same person, the trade secret holder shall identify the data which are protected as trade secrets, including in the relevant metadata. The public sector body, the Commission, the European Central Bank or the Union body shall, prior to the disclosure of trade secrets, take all necessary and appropriate technical and organisational measures to preserve the confidentiality of the trade secrets, including, as appropriate, the use of model contractual terms, technical standards and the application of codes of conduct.;3. Disclosure of trade secrets to a public sector body, the Commission, the European Central Bank or a Union body shall be required only to the extent that it is strictly necessary to achieve the purpose of a request under Article 15a. In such a case, the data holder or, where they are not the same person, the trade secret holder shall identify the data which are protected as trade secrets, including in the relevant metadata. The public sector body, the Commission, the European Central Bank or the Union body shall, prior to the disclosure of trade secrets, take all necessary and appropriate technical and organisational measures pursuant to Article 4(6) of this Regulation to preserve the confidentiality of the trade secrets, including, as appropriate, the use of model contractual terms, confidentiality agreements, strict access protocols, technical standards and the application of codes of conduct.

Or. en

Amendment 672

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 11 – point b

Regulation (EU) 2023/2854

Article 19 – paragraph 3a (new)

Text proposed by the CommissionAmendment
3a. In Article 19, the following paragraph 3a is added:
The public sector body, the Commission, the European Central Bank or the Union body, as well as any joint undertaking, shall ensure that trade secrets obtained in the context of a public emergency are erased as soon as they are no longer necessary for the purpose for which the request was made. Where such data are shared with a third party, the recipient shall, to the extent possible, be granted access without transmission or downloading of the data, and shall be bound to erase the data once they are no longer necessary and not to transmit them onward to any further party.

Or. en

Justification

The disclosure of trade secrets to public bodies in the context of a public emergency, even where strictly necessary, exposes their holders to a heightened risk of unlawful use or onward dissemination. In order to preserve the confidentiality of trade secrets and the freedom to conduct a business, the safeguards should not be confined to the moment of disclosure but should extend to the subsequent handling of the data. This amendment provides that trade secrets obtained during a public emergency, including by any joint undertaking, are to be erased once they are no longer necessary, and that any sharing with a third party is, to the extent possible, to take place without transmission or downloading of the data, coupled with an obligation to erase and a prohibition on onward transmission. These measures ensure that the emergency-related use of trade secrets remains strictly proportionate to the purpose pursued.

Amendment 673

Jörgen Warborn, Arba Kokalari

Proposal for a regulation

Article 1 – paragraph 1 – point 12

Regulation (EU) 2023/2854

Article 20 – paragraph 1

Text proposed by the CommissionAmendment
1. Data holders shall make available data necessary to respond to a public emergency pursuant to Article 15a(2) free of charge. The public sector body, the Commission, the European Central Bank or the Union body that has received data shall provide public acknowledgement to the data holder if requested by the data holder.1. Data holders shall make available data necessary to respond to a public emergency pursuant to Article 15a(2) and shall be entitled to fair compensation in accordance with paragraph 2. The public sector body, the Commission, the European Central Bank or the Union body that has received data shall provide public acknowledgement to the data holder if requested by the data holder. The determination or payment of such compensation shall not delay the making of data available to respond to the public emergency.

Or. en

Amendment 674

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 12

Regulation (EU) 2023/2854

Article 20 – paragraph 2

Text proposed by the CommissionAmendment
2. The data holder shall be entitled to fair compensation for making data available in compliance with a request made pursuant to Article 15a(3). Such compensation shall cover the technical and organisational costs incurred to comply with the request including, where applicable, the costs of anonymisation, pseudonymisation, aggregation and of technical adaptation, and a reasonable margin. Upon request of the public sector body, the Commission, the European Central Bank or the Union body, the data holder shall provide information on the basis for the calculation of the costs and the reasonable margin.deleted

Or. en

Justification

The provision is deleted as it risks creating an additional compensation mechanism that may limit effective access to data by public sector bodies, the Commission, the European Central Bank and Union bodies. The Data Act already provides a framework for fair and proportionate compensation where applicable, and introducing a separate right to compensation, including a reasonable margin, could create uncertainty and increase barriers to data access. Costs directly linked to making data available may be addressed through existing safeguards, without incentivising excessive charges or undermining the objective of ensuring access to data for public interest purposes.

Amendment 675

Jörgen Warborn, Arba Kokalari

Proposal for a regulation

Article 1 – paragraph 1 – point 12

Regulation (EU) 2023/2854

Article 20 – paragraph 2

Text proposed by the CommissionAmendment
2. The data holder shall be entitled to fair compensation for making data available in compliance with a request made pursuant to Article 15a(3). Such compensation shall cover the technical and organisational costs incurred to comply with the request including, where applicable, the costs of anonymisation, pseudonymisation, aggregation and of technical adaptation, and a reasonable margin. Upon request of the public sector body, the Commission, the European Central Bank or the Union body, the data holder shall provide information on the basis for the calculation of the costs and the reasonable margin.2. The data holder shall be entitled to fair compensation for making data available in compliance with a request made pursuant to Article 15a(2) or (3). Such compensation shall cover the technical and organisational costs incurred to comply with the request including, where applicable, the costs of anonymisation, pseudonymisation, aggregation and of technical adaptation, and a reasonable margin. Upon request of the public sector body, the Commission, the European Central Bank or the Union body, the data holder shall provide information on the basis for the calculation of the costs and the reasonable margin.

Or. en

Amendment 676

Jörgen Warborn, Arba Kokalari

Proposal for a regulation

Article 1 – paragraph 1 – point 12

Regulation (EU) 2023/2854

Article 20 – paragraph 3

Text proposed by the CommissionAmendment
3. By way of derogation from paragraph 1 of this Article, a data holder that is a microenterprise or small enterprise may claim compensation for making data available in response to a request under Article 15a(2), according to the conditions set in paragraph 2 of this Article.3. By way of derogation from paragraph 1 of this Article, a data holder that is a microenterprise, small and medium-sized enterprise may claim and shall be entitled to compensation for making data available in response to a request under Article 15a(2), according to the conditions set in paragraph 2 of this Article.

Or. en

(See amendment to recital 15)

Amendment 677

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 12

Regulation (EU) 2023/2854

Article 20 – paragraph 4

Text proposed by the CommissionAmendment
4. Data holders shall not be entitled to compensation for making data available in compliance with a request made pursuant to Article 15a(3), where the specific task carried out in the public interest is the production of official statistics and where the purchase of data is not allowed by national law. Member States shall notify the Commission where the purchase of data for the production of official statistics is not allowed by national law.;4. By way of derogation from paragraph 3 of this Article, a data holder that is a mircoenterprise or small enterprise shall not be entitled to compensation for making data available in compliance with a request made pursuant to Article 15a(3), where the specific task carried out in the public interest is the production of official statistics and where the purchase of data is not allowed by national law. Member States shall notify the Commission where the purchase of data for the production of official statistics is not allowed by national law.;

Or. en

Amendment 678

Jörgen Warborn, Arba Kokalari

Proposal for a regulation

Article 1 – paragraph 1 – point 12

Regulation (EU) 2023/2854

Article 20 – paragraph 4

Text proposed by the CommissionAmendment
4. Data holders shall not be entitled to compensation for making data available in compliance with a request made pursuant to Article 15a(3), where the specific task carried out in the public interest is the production of official statistics and where the purchase of data is not allowed by national law. Member States shall notify the Commission where the purchase of data for the production of official statistics is not allowed by national law.;4. Data holders shall nevertheless be entitled to fair compensation in accordance with paragraph 2 for making data available in compliance with a request made pursuant to Article 15a(3), where the specific task carried out in the public interest is the production of official statistics and where the purchase of data is not allowed by national law. Member States shall notify the Commission where the purchase of data for the production of official statistics is not allowed by national law.;

Or. en

(See amendment to recital 15)

Amendment 679

Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 13 – point b

Regulation (EU) 2023/2854

Article 21 – paragraph 5 – point c

Text proposed by the CommissionAmendment
(c) the period for which the data is to be used and the technical protection;(c) the period for which the data is to be used;

Or. en

Amendment 680

Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 13 – point b

Regulation (EU) 2023/2854

Article 21 – paragraph 5 – point d

Text proposed by the CommissionAmendment
(d) the organisational measures taken, including where personal data or trade secrets are involved.;(d) the technical protection and organisational measures taken, including where personal data or trade secrets are involved.;

Or. en

Amendment 681

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 14

Regulation (EU) 2023/2854

Article 22a – paragraph 1

Text proposed by the CommissionAmendment
Where a dispute arises concerning a request for data under Article 15a, including its refusal, modification, the level of compensation, or the transmission or making available of data, the data holder, the public sector body, the Commission, the European Central Bank or the Union body may lodge a complaint with the competent authority, designated pursuant to Article 37, of the Member State where the data holder is established.;Where a dispute arises concerning a request for data under Article 15a, including its refusal, modification, the level of compensation, or the transmission or making available of data, the data holder, the public sector body, the Commission, the European Central Bank or the Union body may lodge a complaint with the competent authority, designated pursuant to Article 37, of the Member State where the data holder is established. Where the data requested by the Commission, the European Central Bank or the Union body concerns personal data, the complaint shall be referred to the supervisory authority within the meaning of Regulation (EU) 2016/679 of the Member State where the data holder is established and the European Data Protection Supervisior (EDPS). Where the data requested by the public body concerns personal data, the complaint shall be referred to the supervisory authority within the meaning of Regulation (EU) 2016/679 of the Member State where the data holder is established and the European Data Protection Board (EDPB).

Or. en

Amendment 682

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 14

Regulation (EU) 2023/2854

Article 22a – paragraph 1

Text proposed by the CommissionAmendment
Where a dispute arises concerning a request for data under Article 15a, including its refusal, modification, the level of compensation, or the transmission or making available of data, the data holder, the public sector body, the Commission, the European Central Bank or the Union body may lodge a complaint with the competent authority, designated pursuant to Article 37, of the Member State where the data holder is established.;Where a dispute arises concerning a request for data under Article 15a, including its refusal or modification under Article 18(5), the level of compensation, or the transmission or making available of data under Article 21(5), the data holder, the public sector body, the Commission, the European Central Bank or the Union body may lodge a complaint with the competent authority, designated pursuant to Article 37, of the Member State where the data holder is established. Prior to referring the matter to the competent authority, the parties shall, where appropriate, seek to resolve the dispute through a modification of the request.

Or. en

Justification

In the interest of legal certainty and of a coherent system of remedies, Article 22a establishes a single procedural avenue for the settlement of disputes arising from data requests made in the context of a public emergency.

Amendment 683

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 14

Regulation (EU) 2023/2854

Article 22a – paragraph 1

Text proposed by the CommissionAmendment
Where a dispute arises concerning a request for data under Article 15a, including its refusal, modification, the level of compensation, or the transmission or making available of data, the data holder, the public sector body, the Commission, the European Central Bank or the Union body may lodge a complaint with the competent authority, designated pursuant to Article 37, of the Member State where the data holder is established.;Without prejudice to Article 38, where a dispute arises concerning a request for data under Article 15a, including its refusal, modification, the level of compensation, or the transmission or making available of data, the data holder, the public sector body, the Commission, the European Central Bank or the Union body may lodge a complaint with the competent authority, designated pursuant to Article 37, of the Member State where the data holder is established.;

Or. en

Justification

The amendment is necessary to ensure legal certainty and a coherent enforcement framework under the Data Act. Introducing a separate right to lodge a complaint in Chapter V, while maintaining the horizontal complaints mechanism in Article 38, creates unnecessary overlap and uncertainty as to the applicable procedural rules. Aligning or merging these provisions would ensure a single, consistent complaints mechanism across the Regulation, in line with the recommendations of the European Data Protection Board and the European Data Protection Supervisor.

Amendment 684

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 14 a (new)

Regulation (EU) 2023/2854

Article 23 – paragraph 2b (new)

Text proposed by the CommissionAmendment
14a. In Article 23, the following paragraph 2b is inserted:
For the switching of services involving the training or operation of artificial intelligence models or other compute-intensive workloads, the obligations under paragraph 2 shall be understood as requiring functional portability. Functional portability is ensured where the provider of data processing services enables the customer to:
(a) export trained model parameters, including model weights, in commonly used and interoperable formats;
(b) obtain the configuration necessary to redeploy the workload in an alternative environment, including through infrastructure-as-code templates or equivalent means.
Proprietary compute optimisations that are specific to a given hardware or software environment, and that cannot reasonably be replicated in an alternative environment, shall not be subject to the obligations under paragraph 2, provided that the provider offers equivalent functional performance guarantees for the redeployment of the workload. Such optimisations shall not be used to create obstacles to switching within the meaning of point (a) of paragraph 2.
The technical standards and formats referred to in this paragraph, including any exceptions specific to artificial intelligence and compute-intensive workloads, may be specified in the implementing acts referred to in Articles 30(3) and 33(5).

Or. en

Justification

Article 23 requires providers to enable data portability, but that requirement is technically unachievable for many AI workloads, in particular large models trained on custom high-performance computing clusters relying on hardware-specific optimisations. The amendment introduces functional portability: export of model parameters in interoperable formats and provision of the configuration necessary to redeploy the workload. Proprietary compute optimisations are exempted only where the provider offers equivalent functional performance guarantees, and may not be used to create obstacles to switching.

Amendment 685

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 14 a (new)

Regulation (EU) 2023/2854

Article 25 – paragraph 2a (new) and paragraph 4

Text proposed by the CommissionAmendment
14a. Article 25 is modified as follows:
the following paragraph (2a) is added:
'2a. In the case of providers of data processing services that are micro, small or medium-sized enterprises within the meaning of EU recommendation 2003/361:
(i) The maximum notice period of 2 months established in paragraph 2 (d) shall be extended to a maximum of 4 months.
(ii) The maximum transitional period of 30 calendar days established in paragraph 2 (a) shall be extended to a maximum of 3 months.
Paragraph (4) is replaced as follow:
'Where the mandatory maximum transitional period as provided for in paragraph 2, point (a) and (2a) is technically unfeasible, the provider of data processing services shall notify the customer within 14 working days of the making of the switching request, and shall duly justify the technical unfeasibility and indicate an alternative transitional period, which shall not exceed seven months, or 12 months for SMEs. In accordance with paragraph 1, service continuity shall be ensured throughout the alternative transitional period.'

Or. en

Amendment 686

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Matthias Ecke, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2023/2854

Article 31 – paragraphs 1a and 1b

Text proposed by the CommissionAmendment
15. in Article 31, the following paragraphs 1a and 1b are inserted:deleted
‘1a.
The obligations laid down in Chapter VI, with the exception of Article 29, and in Article 34 shall not apply to data processing services other than those referred to in Article 30(1), where the majority of features and functionalities of the data processing service has been adapted by the provider to the specific needs of the customer, if the provision of such services is based on a contract concluded before or on 12 September 2025.
The provider of such data processing services shall not be required to renegotiate or amend a contract for the provision of those services before its expiry if that contract was concluded before or on 12 September 2025. Any contractual provision contained in that contract that is contrary to Article 29(1), (2), or (3) shall be considered null and void.
1b.
A provider of a data processing service may include provisions on proportionate early termination penalties in a contract of fixed duration on the provision of data processing services other than those referred to in Article 30(1).
Where the provider of data processing service is a small and medium-sized enterprise or a small mid-cap, the obligations laid down in Chapter VI, with the exception of Article 29, and in Article 34 shall not apply to data processing services other than those referred to in Article 30(1), if the provision of such services is based on a contract concluded before or on 12 September 2025.
Where the provider of a data processing service is a small and medium-sized enterprise or a small mid-cap, the provider shall not be required to renegotiate or amend a contract for the provision of a data processing service other than those referred to in Article 30(1) before its expiry 1 if that contract was concluded before or on 12 September 2025. Any contractual provision contained in that contract that is contrary to Article 29(1), (2), or (3) shall be considered null and void.;’

Or. en

Justification

The proposed exemptions is deleted as they undermine the effectiveness of Chapter VI of the Data Act. Switching rights must remain effective in practice, while any exemptions should be narrowly defined and proportionate. The broad carve-outs introduced by the proposal risk creating loopholes that weaken switching obligations, reinforce vendor lock-in and reduce incentives for interoperability.

Amendment 687

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Andrea Wechsler, Christian Ehler

Proposal for a regulation

Article 1 – paragraph 1 – point 15 – introductory part

Regulation (EU) 2023/2854

Article 31 – introductory part

Text proposed by the CommissionAmendment
15. in Article 31, the following paragraphs 1a and 1b are inserted:15. in Article 31, the following paragraphs 1a,1b and 1c are inserted:

Or. en

Amendment 688

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2023/2854

Article 31 – paragraph 1a – subparagraph 1

Text proposed by the CommissionAmendment
The obligations laid down in Chapter VI, with the exception of Article 29, and in Article 34 shall not apply to data processing services other than those referred to in Article 30(1), where the majority of features and functionalities of the data processing service has been adapted by the provider to the specific needs of the customer, if the provision of such services is based on a contract concluded before or on 12 September 2025.deleted

Or. en

Amendment 689

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2023/2854

Article 31 – paragraph 1a – subparagraph 1

Text proposed by the CommissionAmendment
The obligations laid down in Chapter VI, with the exception of Article 29, and in Article 34 shall not apply to data processing services other than those referred to in Article 30(1), where the majority of features and functionalities of the data processing service has been adapted by the provider to the specific needs of the customer, if the provision of such services is based on a contract concluded before or on 12 September 2025.The obligations laid down in Article 23(d) and Article 34 shall not apply to data processing services other than those referred to in Article 30(1), where the majority of features and functionalities of the data processing service has been adapted by the provider to the specific needs of the customer, if the provision of such services is based on a contract concluded before or on 12 September 2025 and if the provider has not yet charged any fees for the adaptation concerned.

Or. pt

Amendment 690

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2023/2854

Article 31 – paragraph 1a – subparagraph 2

Text proposed by the CommissionAmendment
The provider of such data processing services shall not be required to renegotiate or amend a contract for the provision of those services before its expiry if that contract was concluded before or on 12 September 2025. Any contractual provision contained in that contract that is contrary to Article 29(1), (2), or (3) shall be considered null and void.deleted

Or. en

Amendment 691

Diego Solier, Sebastian Tynkkynen, Elena Donazzan

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) – 2023/2854

Article 31 – paragraph 1c (new)

Text proposed by the CommissionAmendment
1aa. (a) Any early termination obligation shall be transparent, proportionate to the remaining contractual commitment and clearly communicated to the customer before conclusion of the contract.
(b) This Regulation shall permit providers of data processing services from agreeing fixed-term contracts with customers.
(c) Where a customer terminates a fixed-term contract before its expiry, the provider may recover proportionate and objectively justified outstanding contractual obligations, provided that such recovery does not constitute an obstacle to switching within the meaning of this Regulation.

Or. en

Amendment 692

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Christian Ehler

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation 2023/2854

Article 31 – paragraph 1b – subparagraph 1

Text proposed by the CommissionAmendment
A provider of a data processing service may include provisions on proportionate early termination penalties in a contract of fixed duration on the provision of data processing services other than those referred to in Article 30(1).deleted

Or. en

Amendment 693

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2023/2854

Article 31 – paragraph 1b – subparagraph 1

Text proposed by the CommissionAmendment
A provider of a data processing service may include provisions on proportionate early termination penalties in a contract of fixed duration on the provision of data processing services other than those referred to in Article 30(1).A provider of a data processing service may include provisions on proportionate early termination penalties in a fixed-term contract of data processing services other than those referred to in Article 30(1), provided that such penalties are limited to objectively demonstrated, direct and non-amortised customer-specific costs. They shall not have the object or effect of restricting the customer’s effective switching, data retrieval or contract termination.

Or. en

Amendment 694

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2023/2854

Article 31 – paragraph 1b – subparagraph 1

Text proposed by the CommissionAmendment
A provider of a data processing service may include provisions on proportionate early termination penalties in a contract of fixed duration on the provision of data processing services other than those referred to in Article 30(1).Where the customer is not a natural person, a provider of a data processing service may include provisions on proportionate early termination penalties in a contract of fixed duration on the provision of data processing services other than those referred to in Article 30(1). The EDIB shall issue guidelines on the definition of what constitutes proportionate early termination penalties.

Or. en

Amendment 695

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2023/2854

Article 31 – paragraph 1b – subparagraph 1

Text proposed by the CommissionAmendment
A provider of a data processing service may include provisions on proportionate early termination penalties in a contract of fixed duration on the provision of data processing services other than those referred to in Article 30(1).A provider of a data processing service may include provisions on proportionate early termination penalties in a contract of fixed duration on the provision of data processing services other than those referred to in Article 30(1), provided that the penalties are not an obstacle to change.

Or. pt

Amendment 696

Zala Černilec Tomašič, Jan Farský, Ondřej Krutílek, Tomáš Zdechovský, Henrik Dahl, Alexandr Vondra, Veronika Vrecionová, Lukas Mandl

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2023/2854

Article 31 – paragraph 1b – subparagraph 1

Text proposed by the CommissionAmendment
A provider of a data processing service may include provisions on proportionate early termination penalties in a contract of fixed duration on the provision of data processing services other than those referred to in Article 30(1).A provider of a data processing service may include provisions on proportionate early termination penalties in a contract of fixed duration on the provision of data processing services.

Or. en

Justification

This amendment restores consistency with the Data Act by preserving contractual freedom for all cloud service models (SaaS, PaaS and IaaS). It allows proportionate early termination charges in fixed-term contracts, as originally agreed, while maintaining safeguards under Union and national law. Removing the current limitation avoids legal uncertainty, ensures technology-neutral treatment of cloud services, preserves commercial flexibility, and protects customer choice.

Amendment 697

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2023/2854

Article 31 – paragraph 1b – subparagraph 1

Text proposed by the CommissionAmendment
A provider of a data processing service may include provisions on proportionate early termination penalties in a contract of fixed duration on the provision of data processing services other than those referred to in Article 30(1).A provider of a data processing service may include provisions on proportionate early termination penalties in a contract of fixed duration on the provision of data processing services.

Or. en

Amendment 698

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2023/2854

Article 31 – paragraph 1b – subparagraph 2

Text proposed by the CommissionAmendment
Where the provider of data processing service is a small and medium-sized enterprise or a small mid-cap, the obligations laid down in Chapter VI, with the exception of Article 29, and in Article 34 shall not apply to data processing services other than those referred to in Article 30(1), if the provision of such services is based on a contract concluded before or on 12 September 2025.Where the provider of data processing service is a small and medium-sized enterprise or a small mid-cap, the obligations laid down in Chapter VI, with the exception of Article 29, and in Article 34 shall not apply to data processing services other than those referred to in Article 30(1), where the majority of the features and functionalities of the service has been adapted by the provider to the specific needs of the customer.

Or. en

Amendment 699

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2023/2854

Article 31 – paragraph 1b – subparagraph 2

Text proposed by the CommissionAmendment
Where the provider of data processing service is a small and medium-sized enterprise or a small mid-cap, the obligations laid down in Chapter VI, with the exception of Article 29, and in Article 34 shall not apply to data processing services other than those referred to in Article 30(1), if the provision of such services is based on a contract concluded before or on 12 September 2025.Where the provider of data processing service is a small and medium-sized enterprise, the obligations laid down in Article 23(d) and in Article 34 shall not apply to data processing services other than those referred to in Article 30(1), if the provision of such services is based on a contract concluded before or on 12 September 2025.

Or. pt

Amendment 700

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2023/2854

Article 31 paragraph 1b – subparagraph 2

Text proposed by the CommissionAmendment
Where the provider of data processing service is a small and medium-sized enterprise or a small mid-cap, the obligations laid down in Chapter VI, with the exception of Article 29, and in Article 34 shall not apply to data processing services other than those referred to in Article 30(1), if the provision of such services is based on a contract concluded before or on 12 September 2025.Where the provider of data processing service is a small and medium-sized enterprise, the obligations laid down in Chapter VI, with the exception of Article 29, and in Article 34 shall not apply to data processing services other than those referred to in Article 30(1), if the provision of such services is based on a contract concluded before or on 12 September 2025.

Or. en

Amendment 701

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2023/2854

Article 31 – paragraph 1b – subparagraph 3

Text proposed by the CommissionAmendment
Where the provider of a data processing service is a small and medium-sized enterprise or a small mid-cap, the provider shall not be required to renegotiate or amend a contract for the provision of a data processing service other than those referred to in Article 30(1) before its expiry 1 if that contract was concluded before or on 12 September 2025. Any contractual provision contained in that contract that is contrary to Article 29(1), (2), or (3) shall be considered null and void.Where the provider of a data processing service is a small and medium-sized enterprise, the provider shall not be required to renegotiate or amend a contract for the provision of a data processing service other than those referred to in Article 30(1) before its expiry 1 if that contract was concluded before or on 12 September 2025. Any contractual provision contained in that contract that is contrary to Article 29(1), (2), or (3) shall be considered null and void.

Or. pt

Amendment 702

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2023/2854

Article 31 – paragraph 1b – subparagraph 3

Text proposed by the CommissionAmendment
Where the provider of a data processing service is a small and medium-sized enterprise or a small mid-cap, the provider shall not be required to renegotiate or amend a contract for the provision of a data processing service other than those referred to in Article 30(1) before its expiry 1 if that contract was concluded before or on 12 September 2025. Any contractual provision contained in that contract that is contrary to Article 29(1), (2), or (3) shall be considered null and void.;Where the provider of a data processing service is a small and medium-sized enterprise, the provider shall not be required to renegotiate or amend a contract for the provision of a data processing service other than those referred to in Article 30(1) before its expiry 1 if that contract was concluded before or on 12 September 2025. Any contractual provision contained in that contract that is contrary to Article 29(1), (2), or (3) shall be considered null and void.;

Or. en

Amendment 703

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2023/2854

Article 31 – Paragraph 1b a (new)

Text proposed by the CommissionAmendment
1ba. The obligations laid down in Article 23, point (d), Article 29 and Article 30(1) and (3) shall not apply to data processing services of which the majority of main features has been custom-built to accommodate the specific needs of an individual customer, or which are deeply integrated into the customer's own business processes in a manner that makes functional equivalence in an alternative environment technically unachievable, and where those data processing services are not offered at broad commercial scale via the service catalogue of the provider.

Or. en

Amendment 704

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Andrea Wechsler, Christian Ehler

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2023/2854

Article 31 – paragraph 1b a (new)

Text proposed by the CommissionAmendment
1ba. 1c. A provider of a data processing service may include provisions on proportionate early termination penalties in a contract of fixed duration on the provision of data processing services.

Or. en

Amendment 705

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 15 a (new)

Regulation (EU) 2023/2854

Article 31 – paragraph 1c (new)

Text proposed by the CommissionAmendment
15a. In Article 31 the following paragraph is inserted:
'1c. Notwithstanding paragraph 1b, the customer may terminate the contract without incurring any early termination penalty or switching charge, other than reasonable fees essentially covering the costs directly incurred by the switching operation, in any of the following cases:
(a) where the provider unilaterally makes a substantial modification to the contract, in particular a significant price increase, a reduction of functionalities, a modification of the applicable service level agreements, a change to the terms of use, or the withdrawal of an essential feature;
(b) where the provider fails to perform its material obligations under the contract or under this Regulation;
(c) where the provider no longer complies with an obligation arising under Regulation (EU) 2023/2854, Regulation (EU) 2016/679, Directive (EU) 2022/2555 or other applicable law, such that the customer cannot reasonably be expected to maintain the contract;
(d) where the provider, being contractually bound to ensure the continuous improvement of the service, manifestly fails to do so, or where the level of service is otherwise substantially degraded;
(e) where an event occurs that affects confidence in the provider, such as the loss of a contractually required certification, the withdrawal of a regulatory authorisation, or a change of control resulting in an incompatibility with the customer's requirements.
Such termination shall be without prejudice to any other remedy available to the customer under Union or national contract law.'

Or. en

Amendment 706

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 16 – point a

Regulation (EU) 2023/2854

Article 32 – paragraph 1

Text proposed by the CommissionAmendment
1. Providers of data processing services, the public sector body making available data or documents in accordance with Chapter VIIc Section 3, the natural or legal person to which the right to re-use data or documents in accordance with Chapter VIIc Section 3 was granted, a data intermediation services provider or a recognised data altruism organisation shall take all adequate technical, organisational and legal measures, including contracts, in order to prevent international and third-country governmental access and transfer of non-personal data held in the Union where such transfer or access would create a conflict with Union law or with the national law of the relevant Member State, without prejudice to paragraph 2 or 3.1. Providers of data processing services, the public sector body making available data or documents in accordance with Chapter VIIc Section 3, the natural or legal person to which the right to re-use data or documents in accordance with Chapter VIIc Section 3 was granted, a data intermediation services provider or a recognised data altruism organisation, and any processor or subcontractor acting on their behalf, shall take all adequate technical, organisational and legal measures, including contracts, in order to prevent any access to, or transfer of, non-personal data held in the Union that is requested or ordered by a third-country authority or by an international body, where such transfer or access would create a conflict with, or would undermine the objectives of Union law or with the national law of the relevant Member State, without prejudice to paragraph 2 or 3. This obligation shall apply irrespective of the place of establishment of the entity holding or controlling the data, where the data are held in the Union.

Or. en

Amendment 707

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 16 – point a

Regulation (EU) 2023/2854

Article 32 – paragraph 2

Text proposed by the CommissionAmendment
2. Any decision or judgment of a third-country court or tribunal and any decision of a third-country administrative authority requiring a provider of data processing services, the public sector body making available data or documents in accordance with Chapter VIIc Section 3, the natural or legal person to which the right to re-use data or documents in accordance with Chapter VIIc Section 3 was granted, a data intermediation services provider or a recognised data altruism organisation to transfer or give access to non-personal data falling within the scope of this Regulation held in the Union shall be recognised or enforceable in any manner only if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union, or any such agreement between the requesting third country and a Member State.;2. Any decision or judgment of a third-country court or tribunal and any decision of a third-country administrative authority requiring a provider of data processing services, the public sector body making available data or documents in accordance with Chapter VIIc Section 3, the natural or legal person to which the right to re-use data or documents in accordance with Chapter VIIc Section 3 was granted, a data intermediation services provider or a recognised data altruism organisation to transfer or give access to non-personal data falling within the scope of this Regulation held in the Union shall be recognised or enforceable in any manner only if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union, or any such agreement between the requesting third country and a Member State. Where the agreement is concluded between the requesting third country and the Union, it shall only give access to the data held by Union institutions, agencies and bodies, and where it is concluded between the requesting third country and a Member State, it shall not give access to data held in any other Member State.

Or. en

Amendment 708

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 16 – point b

Regulation (EU) 2023/2854

Article 32 – paragraph 3a (new)

Text proposed by the CommissionAmendment
3a. 'By way of derogation to paragraph 2 and 3, Member States may, on grounds of public security or of the protection of their essential security interests, designate categories of non-personal data held in their territory whose transfer to, or access by, a third-country court, tribunal or administrative authority shall be prohibited where such transfer or access would be liable to harm public security, the continuity of essential services or the strategic or economic autonomy of the Union or of the Member State concerned. Such designation shall be limited to what is strictly necessary and proportionate to the objective pursued.'

Or. en

Justification

Non-personal data may include operational, industrial or strategic data whose disclosure to a third-country authority could undermine public security, the continuity of essential services or strategic and economic autonomy. This amendment gives Member States a narrowly framed tool to protect such data, subject to necessity, proportionality, notification to the Commission and publication of the designated categories.

Amendment 709

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 16 – point c

Regulation (EU) 2023/2854

Article 32 – paragraph 5

Text proposed by the CommissionAmendment
5. The provider of data processing services, the public sector body making available data or documents in accordance with Chapter VIIc Section 3, the natural or legal person to which the right to re-use data or documents in accordance with Chapter VIIc Section 3 was granted, the data intermediation services provider or the recognised data altruism organisation shall inform the natural or legal person whose rights and interests might be affected about the existence of a request of a third-country authority to access its data before complying with that request, except where the request serves law enforcement purposes and for as long as this is necessary to preserve the effectiveness of the law enforcement activity.;5. The provider of data processing services, the public sector body making available data or documents in accordance with Chapter VIIc Section 3, the natural or legal person to which the right to re-use data or documents in accordance with Chapter VIIc Section 3 was granted, the data intermediation services provider or the recognised data altruism organisation shall inform the natural or legal person whose rights and interests might be affected about the existence of a request of a third-country authority to access its data before complying with that request, except where the request is made by a competent authority for the purpose of the prevention, investigation, detection or prosecution of criminal offences or for the execution of criminal penalties and for as long as this is necessary to preserve the effectiveness of the law enforcement activity. Where informing the natural or legal person before compliance would seriously and demonstrably undermine a lawful investigation or enforcement activity, notification may be delayed only for as long as strictly necessary and proportionate. The reasons for delayed notification shall be documented and made available to the competent authority upon request. The affected person shall be informed as soon as the reason for delay no longer applies. Providers and other addressees shall publish annual transparency reports containing aggregate information on third-country access requests, including third-countries making the requests, legal bases invoked, categories of data concerned, and the number of requests complied with, refused, or challenged.;

Or. en

Amendment 710

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 16 – point c

Regulation (EU) 2023/2854

Article 32 – Paragraph 5

Text proposed by the CommissionAmendment
5. The provider of data processing services, the public sector body making available data or documents in accordance with Chapter VIIc Section 3, the natural or legal person to which the right to re-use data or documents in accordance with Chapter VIIc Section 3 was granted, the data intermediation services provider or the recognised data altruism organisation shall inform the natural or legal person whose rights and interests might be affected about the existence of a request of a third-country authority to access its data before complying with that request, except where the request serves law enforcement purposes and for as long as this is necessary to preserve the effectiveness of the law enforcement activity.;5. The provider of data processing services, the public sector body making available data or documents in accordance with Chapter VIIc Section 3, the natural or legal person to which the right to re-use data or documents in accordance with Chapter VIIc Section 3 was granted, the data intermediation services provider or the recognised data altruism organisation shall inform the natural or legal person whose rights and interests might be affected about the existence of a request of a third-country authority pursuant to an international agreement referred to in paragraph 2 to access its data before examining with that request, except where the request serves law enforcement purposes and for as long as this is necessary to preserve the effectiveness of the law enforcement activity.;

Or. en

Amendment 711

Mary Khan

Proposal for a regulation

Article 1 – paragraph 1 – point 16 – point c

Regulation (EU) 2023/2854

Article 32 – paragraph 5 a (new)

Text proposed by the CommissionAmendment
(5a) ‘A request from a public authority or court of a third country concerning data held by a public sector body, a public undertaking, an operator of critical infrastructure, a data intermediation services provider or a recognised data altruism organisation may be complied with only with the prior authorisation of the national competent authority of the Member State whose public interests or legal order are affected.
Authorisation may only be granted if the request is based on an applicable international agreement, is limited to data that are strictly necessary, ensures an equivalent level of protection and excludes any onward transfer. The natural or legal persons concerned shall be informed prior to the transfer, unless a national court orders, for compelling reasons, that, for a limited period, they be informed at a later date.’

Or. de

Justification

A private provider should not be able to make unilateral decisions concerning foreign access to strategic, public or sensitive data.

Amendment 712

Mary Khan

Proposal for a regulation

Article 1 – paragraph 1 – point 17

Regulation (EU) 2023/2854

Article 36

Text proposed by the CommissionAmendment
17. Article 36 is deleted.deleted

Or. de

Amendment 713

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 17

Regulation (EU) 2023/2854

Article 36

Text proposed by the CommissionAmendment
17. Article 36 is deleted.deleted

Or. en

Justification

We do not support the deletion of Article 36 on smart contracts would remove the interoperability and trust framework designed to ensure that smart contracts used for data-sharing agreements meet minimum requirements for security, controllability (such as interruption or archiving functions), and conformity with harmonised standards. It will eliminate a key safeguard intended to ensure that automated data-sharing mechanisms remain reliable, interoperable, and auditable across providers.

Amendment 714

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32a – paragraph 1 – point a

Text proposed by the CommissionAmendment
(a) recognised data intermediation services providers and(a) recognised data intermediation services providers authorised to provide data intermediation in the Union and

Or. en

Amendment 715

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32a – paragraph 1 – point a

Text proposed by the CommissionAmendment
(a) recognised data intermediation services providers and(a) data intermediation services providers and

Or. en

Amendment 716

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32a – paragraph 1 – point b

Text proposed by the CommissionAmendment
(b) recognised data altruism organisations.(b) data altruism organisations.

Or. en

Amendment 717

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32a (new) – paragraph 1a (new)

Text proposed by the CommissionAmendment
(1a) In Article 32a, the following paragraph is inserted:
'1a. In addition, and in order to monitor the implementation of this Regulation and to gather best practices, the Commission shall provide for a regime of voluntary registration of providers of data processing services which:
(a) apply state-of-the-art pseudonymisation techniques to the data they process;
(b) process high-value data sets or data protected as trade secrets;
(c) are exposed to risks of extraterritorial interference, including unilateral suspension of services, forced transfer of data or unauthorised access by third-country authorities;
(d) process sensitive data on the basis of legitimate interest for the purposes of scientific research and the development of innovative solutions and processes.'

Or. en

Amendment 718

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32 a – paragraph 1 a (new)

Text proposed by the CommissionAmendment
(1a) Each Member State shall keep and regularly update public national registers of:
(a) recognised data intermediation services providers; and
(b) recognised data altruism organisations,
whose main establishment is located in or which provide services in that Member State.

Or. pt

Amendment 719

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation 2023/2854

Article 32a – paragraph 2

Text proposed by the CommissionAmendment
(2) Data intermediation services providers registered in the public Union register referred to in paragraph 1 point (a) may use the label ‘data intermediation services provider recognised in the Union’ in its written and spoken communication, as well as a common logo referred to in paragraph 4.(2) Data intermediation services providers registered in the public Union register referred to in paragraph 1 point (a) may use the label ‘data intermediation services provider recognised in the Union’ in its written and spoken communication, as well as a common logo referred to in paragraph 4 where they abide by the requirements set in Article 32c.

Or. en

Amendment 720

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32a – paragraph 2

Text proposed by the CommissionAmendment
(2) Data intermediation services providers registered in the public Union register referred to in paragraph 1 point (a) may use the label ‘data intermediation services provider recognised in the Union’ in its written and spoken communication, as well as a common logo referred to in paragraph 4.(2) Data intermediation services providers registered in the public registers referred to in paragraph 1 point (a) and paragraph 1a point (a) may use the label ‘data intermediation services provider recognised in the Union’ in its written and spoken communication, as well as a common logo referred to in paragraph 4.

Or. pt

Amendment 721

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32a – paragraph 3

Text proposed by the CommissionAmendment
(3) Data altruism organisations registered in the public Union register referred to in paragraph 1 point (b) may use the label ‘data altruism organisation recognised in the Union’ in its written and spoken communication, as well as the common logo referred to in paragraph 4.(3) Data altruism organisations registered in the public Union register referred to in paragraph 1 point (b) may use the label ‘data altruism organisation recognised in the Union’ in its written and spoken communication, as well as the common logo referred to in paragraph 4 where they abide by the requirements set in Article 32d.

Or. en

Amendment 722

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32a – paragraph 3

Text proposed by the CommissionAmendment
(3) Data altruism organisations registered in the public Union register referred to in paragraph 1 point (b) may use the label ‘data altruism organisation recognised in the Union’ in its written and spoken communication, as well as the common logo referred to in paragraph 4.(3) Data altruism organisations registered in the public registers referred to in paragraph 1 point (b) and paragraph 1a point (b) may use the label ‘data altruism organisation recognised in the Union’ in its written and spoken communication, as well as the common logo referred to in paragraph 4.

Or. pt

Amendment 723

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation 2023/2854

Article 32b – paragraph 1

Text proposed by the CommissionAmendment
(1) Each Member State shall designate one or more competent authorities responsible for the application and enforcement of this Chapter in accordance with Article 37(1).(1) Each Member State shall designate one or more competent authorities responsible for the application and enforcement of this Chapter in accordance with Article 37(1), and having direct access to the register referred to in Article 32a.

Or. en

Amendment 724

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – title

Text proposed by the CommissionAmendment
General requirements for registration of recognised data intermediation services providersGeneral requirements for data intermediation services providers

Or. en

Amendment 725

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation 2023/2854

Article 32c – paragraph 1 – introductory part

Text proposed by the CommissionAmendment
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:A data intermediation services provider shall meet all of the following requirements:

Or. en

Amendment 726

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32 c – paragraph 1 – introductory part

Text proposed by the CommissionAmendment
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:In order to qualify for registration in the public registers referred to in Article 32a paragraph 1 point (a) and paragraph 1a point (a), a data intermediation services provider shall meet all of the following requirements:

Or. pt

Amendment 727

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point aa (new)

Text proposed by the CommissionAmendment
(aa) 'the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user shall be provided in a transparent and non-discriminatory manner and not be dependent upon whether the data holder or data user uses other services provided by the same data intermediation services provider or by a related entity, and if so to what degree the data holder or data user uses such other services;'

Or. en

Amendment 728

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c– paragraph 1 – point b

Text proposed by the CommissionAmendment
(b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;(b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service, which may entail the use of data for the detection of fraud or cybersecurity;

Or. en

Amendment 729

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point ba (new)

Text proposed by the CommissionAmendment
(ba) In Article 32c, paragraph 1, the following point is inserted:
'(ba) they shall provide that, in the event of insolvency, data subjects have an opportunity to exercise their rights, ensuring a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights;'

Or. en

Amendment 730

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point c

Text proposed by the CommissionAmendment
(c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;(c) the data intermediation services provider shall provide the tools and services necessary to facilitate the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, and shall systematically implement appropriate technical and organisational measures to prevent the re-identification of pseudonymised data, personal data breaches, and any unlawful acquisition, use, disclosure or transfer of the data for which it provides data intermediation services; where the data are made available in pseudonymised or anonymised form, the provider shall apply state-of-the-art privacy-preserving and privacy-enhancing techniques to that effect.

Or. en

Amendment 731

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point c

Text proposed by the CommissionAmendment
(c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;(c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or explicit consent of the data subject;

Or. en

Amendment 732

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point ca (new)

Text proposed by the CommissionAmendment
(ca) In Article 32c, paragraph 1, the follwoing point is inserted:
'(ca) where a data intermediation services provider provides tools for obtaining consent from data subjects or permissions to process data made available by data holders, it shall, where relevant, specify the third-country jurisdiction in which the data use is intended to take place and provide data subjects with tools to both give and withdraw consent and data holders with tools to both give and withdraw permissions to process data;'

Or. en

Amendment 733

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point cb (new)

Text proposed by the CommissionAmendment
(cb) In Article 32c, paragraph 1, the following point is inserted:
'(cb) the data intermediation services provider shall maintain a log record of the data intermediation activity, corresponding to the risks involved;'

Or. en

Amendment 734

Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point cc (new)

Text proposed by the CommissionAmendment
(cc) In Article 32c, paragraph 1, the following point is inserted:
'(cc) the data intermediation services provider shall have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services, corresponding to the risks involved;'

Or. en

Amendment 735

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point cd (new)

Text proposed by the CommissionAmendment
(cd) In Article 32c, paragraph 1, the following point is inserted:
'(cd) the data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights;'

Or. en

Amendment 736

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point d

Text proposed by the CommissionAmendment
(d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:(d) where data intermediation service providers offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:

Or. en

Justification

This amendment addresses concerns expressed in the EDPB-EDPS opinion. The Proposal does not specifically justify the reason for exempting small and micro enterprises entirely from the functional separation requirement. Ensuring neutrality by managing conflicting interests would appear relevant, regardless of enterprise size.

Amendment 737

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point d – point ii

Text proposed by the CommissionAmendment
(ii) the data are not used for other purposes than performing the value-added service;(ii) the data are not used for other purposes than performing the value-added service, such as advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject;

Or. en

Amendment 738

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point d – point ii

Text proposed by the CommissionAmendment
(ii) the data are not used for other purposes than performing the value-added service;(ii) the data are not used for other purposes than performing the value-added service, including advertising, profiling, ranking, price discrimination and training of AI systems;

Or. pt

Amendment 739

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point d – point iii

Text proposed by the CommissionAmendment
(iii) the value-added services are offered through a functionally separate entity;(iii) the value-added services are offered through a functionally separate entity, as demonstrated by criteria including technical and organisational segregation of data, absence of conflicts of interest, cross-use of data, and discriminatory treatment, and separate management, financing and staff ;

Or. en

Amendment 740

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point d – point iii

Text proposed by the CommissionAmendment
(iii) the value-added services are offered through a functionally separate entity;(iii) the value-added services are offered through a legally separate entity;

Or. en

Amendment 741

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Matthias Ecke, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point d – point iv

Text proposed by the CommissionAmendment
(iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;(iv) the undertaking seeking to offer the value-added services is not a very large enterprise, including gatekeepers as designated pursuant to Article 3 of Regulation (EU) 2022/1925;

Or. en

Amendment 742

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point d – point v

Text proposed by the CommissionAmendment
(v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;deleted

Or. en

Justification

Moved

Amendment 743

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point ea (new)

Text proposed by the CommissionAmendment
(ea) In Article 32c, paragraph 1, the following point is added:
'(ea) the data intermediation services provider ensure that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data usrs, including with regard to prices and terms of service;'

Or. en

Amendment 744

Mary Khan

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point e a (new)

Text proposed by the CommissionAmendment
in Article 32c(1), the following point (ea) is added:
‘(ea) where the data intermediation service passes on personal data, special categories of personal data or data held by public sector bodies, this shall remain legally and organisationally separate from the provider’s other activities.’

Or. de

Amendment 745

Mary Khan

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point e b (new)

Text proposed by the CommissionAmendment
in Article 32c(1), the following point (eb) is added:
‘(eb) the provider must not merge the data passed on, or any data derived from it, with data from other services, or use it for advertising, profiling, scoring, creditworthiness assessment, or price customisation, or for the training, testing or validation of AI systems or AI models. The sale or other provision of such data for the provider’s own or third-parties’ secondary purposes shall be prohibited.’

Or. de

Amendment 746

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32d – title

Text proposed by the CommissionAmendment
General requirements for registration of recognised data altruism organisationsGeneral requirements for data altruism organisations

Or. en

Amendment 747

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32d – paragraph 1 – introductory part

Text proposed by the CommissionAmendment
In order to qualify for registration in the public Union register referred to in Art. 32a paragraph 1 point (b), a data altruism organisation shall meet all of the following requirements:a data altruism organisation shall meet all of the following requirements:

Or. en

Amendment 748

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32d – paragraph 1 – introductory part

Text proposed by the CommissionAmendment
In order to qualify for registration in the public Union register referred to in Art. 32a paragraph 1 point (b), a data altruism organisation shall meet all of the following requirements:In order to qualify for registration in the public registers referred to in Art. 32a paragraph 1 point (b) and paragraph 1a point (b), a data altruism organisation shall meet all of the following requirements:

Or. pt

Amendment 749

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – title

Text proposed by the CommissionAmendment
RegistrationNotification

Or. en

Amendment 750

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 1 – subparagraph 1

Text proposed by the CommissionAmendment
Data intermediation services provider which meets the requirements set out in Article 32c may submit an application for registration in the public Union register of recognised data intermediation services providers to the competent authority referred to in Article 32b in the Member State in which they have their main establishment.Data intermediation services provider which meets the requirements set out in Article 32c shall submit an application and shall not provide data intermediation services in the Union unless registered in the public Union register referred to in Article 32 for registration in the public Union register of recognised data intermediation services providers to the competent authority referred to in Article 32b in the Member State in which they have their main establishment. Registration shall be a condition for providing data intermediation services in the Union. Any entity providing services that fall within the definition of data intermediation services shall comply with all obligations under this Chapter, irrespective of its legal form, commercial designation, technical architecture or functional design.

Or. en

Amendment 751

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 1 – subparagraph 1

Text proposed by the CommissionAmendment
Data intermediation services provider which meets the requirements set out in Article 32c may submit an application for registration in the public Union register of recognised data intermediation services providers to the competent authority referred to in Article 32b in the Member State in which they have their main establishment.Data intermediation services provider which meets the requirements set out in Article 32c shall submit an application for registration in the public registers of recognised data intermediation services providers to the competent authorities referred to in Article 32b in the Member States in which they have their main establishment or in which they provide services. Registration in those registers shall be mandatory for the provider to be able to take up business.

Or. pt

Amendment 752

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 1 – subparagraph 1

Text proposed by the CommissionAmendment
Data intermediation services provider which meets the requirements set out in Article 32c may submit an application for registration in the public Union register of recognised data intermediation services providers to the competent authority referred to in Article 32b in the Member State in which they have their main establishment.Data intermediation services provider shall notify their business activities to the competent authority referred to in Article 32b in the Member State in which they have their main establishment.

Or. en

Amendment 753

Mary Khan

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 1 – subparagraph 1

Text proposed by the CommissionAmendment
Data intermediation services provider which meets the requirements set out in Article 32c may submit an application for registration in the public Union register of recognised data intermediation services providers to the competent authority referred to in Article 32b in the Member State in which they have their main establishment.Data intermediation services providers may not provide their services in the Union until they have been registered with the competent authority referred to in Article 32b in the Member State of their main establishment. Member States shall provide a simplified digital registration procedure for small and medium-sized enterprises that exclusively pass on low-risk, non-personal data.

Or. de

Amendment 754

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 1 – subparagraph 1

Text proposed by the CommissionAmendment
Data intermediation services provider which meets the requirements set out in Article 32c may submit an application for registration in the public Union register of recognised data intermediation services providers to the competent authority referred to in Article 32b in the Member State in which they have their main establishment.Data intermediation services provider which meets the requirements set out in Article 32c shall submit an application for registration in the public Union register of recognised data intermediation services providers to the competent authority referred to in Article 32b in the Member State in which they have their main establishment.

Or. en

Amendment 755

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 1 – subparagraph 2

Text proposed by the CommissionAmendment
Data altruism organisation which meets the requirements set out in Article 32d may submit an application for registration in the public Union register of recognised data altruism organisations to the competent authority referred to in Article 32b in the Member State in which they have their main establishment.Data altruism organisation shall notify the competent authority their activities in the Member State in which they have their main establishment.

Or. en

Amendment 756

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 1 – subparagraph 2

Text proposed by the CommissionAmendment
Data altruism organisation which meets the requirements set out in Article 32d may submit an application for registration in the public Union register of recognised data altruism organisations to the competent authority referred to in Article 32b in the Member State in which they have their main establishment.Data altruism organisation which meets the requirements set out in Article 32d shall submit an application for registration in the public registers of recognised data altruism organisations to the competent authorities referred to in Article 32b in the Member States in which they have their main establishment or in which they provide services. Registration in those registers shall be mandatory for the organisation to be able to take up business.

Or. pt

Amendment 757

Mary Khan

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 1 – subparagraph 2

Text proposed by the CommissionAmendment
Data altruism organisation which meets the requirements set out in Article 32d may submit an application for registration in the public Union register of recognised data altruism organisations to the competent authority referred to in Article 32b in the Member State in which they have their main establishment.Data altruism organisations which meet the requirements set out in Article 32d may submit an application for registration in the public Union register to the competent authority referred to in Article 32b in the Member State of their main establishment.

Or. de

Amendment 758

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 1 – subparagraph 2

Text proposed by the CommissionAmendment
Data altruism organisation which meets the requirements set out in Article 32d may submit an application for registration in the public Union register of recognised data altruism organisations to the competent authority referred to in Article 32b in the Member State in which they have their main establishment.Data altruism organisation which meets the requirements set out in Article 32d shall submit an application for registration in the public Union register of recognised data altruism organisations to the competent authority referred to in Article 32b in the Member State in which they have their main establishment.

Or. en

Justification

To foster trust in the label ‘data altruism organisation recognised in the Union’, effective public oversight should be ensured and appropriate accountability mechanisms should be put in place. This amendment follows the EDPB and the EDPS recommendation to maintain the record-keeping obligation, in order to ensure that competent authorities can exercise their oversight in an effective manner.

Amendment 759

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 2 – subparagraph 1

Text proposed by the CommissionAmendment
Data intermediation services providers and data altruism organisations that have no main establishment in the Union shall designate a legal representative in one of the Member States. The legal representative shall be mandated to be addressed in addition to or instead of the data intermediation services provider or data altruism organisation by competent authorities or data subjects and data holders. The legal representative shall cooperate with and comprehensively demonstrate to the competent authority, upon request, the actions taken and provisions put in place by the data intermediation services provider or the data altruism organisation to ensure compliance with this Regulation.Data intermediation services providers and data altruism organisations shall have a main establishment in the Union and shall cooperate with and comprehensively demonstrate to the competent authority, upon request, the actions taken and provisions put in place by the data intermediation services provider or the data altruism organisation to ensure compliance with this Regulation.

Or. en

Amendment 760

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 2 – subparagraph 2

Text proposed by the CommissionAmendment
The data intermediation services provider or data altruism organisation shall be deemed to be under the jurisdiction of the Member State in which the legal representative is located. The designation of a legal representative shall be without prejudice to any legal actions which could be initiated against the data intermediation services provider or data altruism organisation.deleted

Or. en

Amendment 761

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 3

Text proposed by the CommissionAmendment
(3) Competent authorities shall establish the necessary application forms.(3) To ensure consistency and coherence across the EU, the Commission shall, after consulting the EDPB, adopt implementing acts establishing a template application form for the registration of data intermediation services and recognised data altruism organisations, including inter alia a description of the intended processing and other activities, their nature and scope; type of data concerned and any intended value-added services related to the processing of the data.

Or. en

Amendment 762

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 3

Text proposed by the CommissionAmendment
(3) Competent authorities shall establish the necessary application forms.(3) The Commission shall adopt implementing acts to establish the necessary application forms including the required description of the intended nature of data intermediation or data altruism processing activities, such as types of data, including categories of personal data and intended value-added services.

Or. en

Amendment 763

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 4 – subparagraph 1

Text proposed by the CommissionAmendment
Where a data intermediation services provider has submitted all necessary information pursuant to paragraph 3 of this Article, and complies with the requirements set out in Article 32c, the competent authority shall, within 12 weeks after the receipt of the application for registration, take a decision on whether the provider complies with the criteria set out in Article 32c. Where the provider complies with the criteria, the competent authority shall submit the relevant information to the Commission which shall register the providers in the public Union register as a recognised data intermediation services provider.Where a data intermediation services provider has submitted all necessary information pursuant to paragraph 3 of this Article, and complies with the requirements set out in Article 32c, the competent authority shall, within 12 weeks after the receipt of the application for registration, take a decision on whether the provider complies with the criteria set out in Article 32c. Where the provider complies with the criteria, the competent authority shall submit the relevant information to the Commission which shall register the providers in the public Union register as a recognised data intermediation services provider. The competent authority shall include providers in the national public register of their respective Member State.

Or. pt

Amendment 764

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 4 – subparagraph 1

Text proposed by the CommissionAmendment
Where a data intermediation services provider has submitted all necessary information pursuant to paragraph 3 of this Article, and complies with the requirements set out in Article 32c, the competent authority shall, within 12 weeks after the receipt of the application for registration, take a decision on whether the provider complies with the criteria set out in Article 32c. Where the provider complies with the criteria, the competent authority shall submit the relevant information to the Commission which shall register the providers in the public Union register as a recognised data intermediation services provider.Where a data intermediation services provider has submitted all necessary information pursuant to paragraph 3 of this Article, and complies with the requirements set out in Article 32c, the competent authority shall, within 12 weeks after the receipt of the application for registration, take a decision on whether the provider complies with the criteria set out in Article 32c. Where the provider complies with the criteria, the competent authority shall award the label and submit the relevant information to the Commission which shall update the website to mention the label attribution.

Or. en

Amendment 765

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 4 – subparagraph 2

Text proposed by the CommissionAmendment
The first subparagraph shall also apply where a data altruism organisation has submitted all necessary information pursuant to paragraph 2, and complies with the registration requirements set out in Article 32d.The first subparagraph shall also apply where a data altruism organisation has submitted all necessary information pursuant to paragraph 2, and complies with the requirements set out in Article 32d.

Or. en

Amendment 766

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 4a (new)

Text proposed by the CommissionAmendment
(4a) In Article 32r, the following paragraph is inserted:
'4a. Where the competent authority determines that a data intermediation services provider does not comply with the requirements laid down in Article 32d, it shall inform the data intermediation provider of the infrigement and require the provider to take the necessary corrective measures within a proportionate and specified period. Where the provider fails to comply with that decision within the prescribed period, the competent authority may impose effective, proportionate and dissuasive penalties in accordance with this Regulation and suspend the activities of the data intermediation services provider.
The first subparagraph shall also apply for a data altruism organisation.'

Or. en

Amendment 767

João Oliveira

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 5

Text proposed by the CommissionAmendment
(5) The competent authority may charge fees for the registration in accordance with national law. Such fees shall be proportionate and objective and be based on the administrative costs related to the monitoring of compliance. In the case of small-mid caps, small and medium-sized enterprises, and start-ups, the competent authority may charge a discounted fee or waive the fee.(5) The competent authority may charge fees for the registration in accordance with national law. Such fees shall be proportionate and objective and be based on the administrative costs related to the monitoring of compliance. In the case of small and medium-sized enterprises and start-ups, the competent authority may charge a discounted fee or waive the fee.

Or. pt

Amendment 768

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 5

Text proposed by the CommissionAmendment
(5) The competent authority may charge fees for the registration in accordance with national law. Such fees shall be proportionate and objective and be based on the administrative costs related to the monitoring of compliance. In the case of small-mid caps, small and medium-sized enterprises, and start-ups, the competent authority may charge a discounted fee or waive the fee.(5) The competent authority may charge fees for the registration in accordance with national law. Such fees shall be proportionate and objective and be based on the administrative costs related to the monitoring of compliance. In the case of small and medium-sized enterprises, and start-ups, the competent authority shall waive the fee.

Or. en

Amendment 769

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32f – title

Text proposed by the CommissionAmendment
Duties of recognised data altruism organisationsDuties of data altruism organisations
(This amendment applies throughout the text. Adopting it will necessitate corresponding changes throughout.)

Or. en

Amendment 770

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32f – paragraph 4a

Text proposed by the CommissionAmendment
(4a) In Article 32f, the following paragraph is inserted:
'4a. Recognised data altruism organisations shall publish an annual transparency report describing the categories of data collected, the objectives of general interest pursued, the categories of data users receiving access, any third-country transfers or access, the safeguards applied, the number of withdrawals of consent or permission, information on sources of revenue of the recognised data altruism organisation, in particular all revenue from allowing access to the data, and on expenditure.'

Or. en

Justification

Going back to wording on current Digital Governance Act following the EDPB and the EDPS recommendation to maintain an annual overview of the categories of all natural and legal persons that were allowed to process data could be required and an overview of the sources of revenue of the recognised data altruism organisation to ensure effective oversight.

Amendment 771

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32f – paragraph 5a (new)

Text proposed by the CommissionAmendment
(5a) Recognised data altruism organisations shall keep full and accurate records concerning:
(a) natural or legal persons that were given the possibility to process data held by that recognised data altruism organisation, and their contact details;
(b) the date or duration of the processing of personal data or use of non-personal data;
(c) the purpose of the processing as declared by the natural or legal person that was given the possibility of processing;
(d) the fees paid by natural or legal persons processing the data, if any;
(e) a summary description of the objectives of general interest pursued by such data processing and the description of the technical means used for it, including a description of the techniques used to preserve privacy and data protection.

Or. en

Amendment 772

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32f – paragraph 5a (new)

Text proposed by the CommissionAmendment
(5a) Recognised data altruism organisations shall implement appropriate technical and organisational measures to prevent the re-identification of pseudonymised data, personal data breaches, and any unlawful acquisition, use, disclosure or transfer of the data made available to them. Where the data are processed or shared in pseudonymised or anonymised form, they shall apply state-of-the-art privacy-preserving and privacy-enhancing techniques to that effect.

Or. en

Justification

Recognised data altruism organisations collect and make available data voluntarily provided for objectives of general interest, and thereby handle data whose exposure entails significant risks for the natural and legal persons concerned. In addition to the duty to inform data holders after the event, laid down in paragraph 4, such organisations should be required to take preventive measures. This provision requires them to implement appropriate technical and organisational measures to prevent the re-identification of pseudonymised data, personal data breaches, and any unlawful acquisition, use, disclosure or transfer of the data made available to them, and to apply state-of-the-art privacy-preserving and privacy-enhancing techniques where the data are processed or shared in pseudonymised or anonymised form. This reinforces the protection of data subjects and data holders and strengthens trust in data altruism, in line with the principles of integrity and confidentiality laid down in Regulation (EU) 2016/679.

Amendment 773

Mary Khan

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32f – paragraph 5 a (new)

Text proposed by the CommissionAmendment
(5a) Consent or permission must be given separately, voluntarily and in an informed and unambiguous manner for each purpose, data category and data user. Refusal to give consent or permission shall not result in any disadvantage. It must be as easy to withdraw consent or permission as it is to give it.

Or. de

Amendment 774

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32f – paragraph 5b (new)

Text proposed by the CommissionAmendment
(5b) Recognised data altruism organisations shall draw up and transmit to the relevant competent authority for the registration of data altruism organisations an annual activity report which shall contain at least the following:
(a) categories of natural and legal persons that were allowed to process data it holds;
(b) information on sources of revenue of the recognised data altruism organisation, in particular all revenue from allowing access to the data, and on expenditure.

Or. en

Amendment 775

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32g – paragraph 1

Text proposed by the CommissionAmendment
(1) The competent authorities referred to in Article 32b shall, either on their own initiative or on a request by a natural or legal person, monitor and supervise whether recognised data intermediation services providers and recognised data altruism organisations comply with the requirements laid down in this Chapter, including whether they continue to comply with the requirements for registration laid down therein.(1) The competent authorities referred to in Article 32b shall monitor and supervise whether recognised data intermediation services providers and recognised data altruism organisations comply with the requirements laid down in this Chapter, including whether they continue to comply with the requirements for registration laid down therein. The competent authorities shall also monitor and supervise the compliance of data intermediation services providers, on the basis of a request by a natural or legal person.

Or. en

Justification

This amendment introduces a change from discretionary power to mandatory action. By maintaining this discretion, competent authorities will be in a better position to allocate resources more efficiently to take action where it is most needed.

Amendment 776

Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32g – paragraph 1

Text proposed by the CommissionAmendment
(1) The competent authorities referred to in Article 32b shall, either on their own initiative or on a request by a natural or legal person, monitor and supervise whether recognised data intermediation services providers and recognised data altruism organisations comply with the requirements laid down in this Chapter, including whether they continue to comply with the requirements for registration laid down therein.(1) The competent authorities referred to in Article 32b shall monitor and supervise whether recognised data intermediation services providers and recognised data altruism organisations comply with the requirements laid down in this Chapter, including whether they continue to comply with the requirements for registration laid down therein.

Or. en