Skip to content
EU Parl Watch

amendment list, 27 July 2026

Amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557 as regards the simplification of the digital legislative framework, and repealing Regulations (EU) 2018/1807, (EU) 2019/1150, (EU) 2022/868, and Directive (EU) 2019/1024 (Digital Omnibus)

Document CJ72-AM-791073 · (COM(2025)0837 – 2025/0360(COD))

Committee on Industry, Research and Energy Committee on Civil Liberties, Justice and Home Affairs

On Parliament’s site PDF Word

Full text

Jump to an amendment (208)
Text 1,790 paragraphs

Amendment 1053

João Oliveira

Proposal for a regulation

Article 3 – paragraph 1 – point 3 – point b

Regulation (EU) 2016/679

Article 9 – paragraph 5

Text proposed by the CommissionAmendment
5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.’5. In the context of the development and operation of an AI system or an AI model, the personal data controller shall implement, by design and by default, robust, appropriate and demonstrably effective organisational and technical measures to avoid the collection and any other form of processing of special categories of personal data in the datasets used for training, testing or validation, and in the AI systems and models. Where, despite the application of those measures, special categories of personal data are discovered in those sets, systems or models, the controller shall have a primary and irrevocable obligation to remove them, irrespective of the effort or cost involved, unless the controller objectively demonstrates in documented form, and under its exclusive responsibility, that the removal is materially impossible and not merely disproportionate or burdensome. In that exceptional case, and only for as long as the material impossibility of removal persists, the controller shall adopt, without undue delay, all necessary and sufficient technical and organisational safeguards to ensure, in an effective and continuous manner, that such data are not used to produce outputs, disclosed, or in any way made available to third parties, and such safeguards shall be subject to periodic verification, audit and documentation in order to demonstrate compliance with this obligation to the competent supervisory authority.’

Or. pt

Amendment 1054

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 3 – point b

Read the rest (1,778 paragraphs)

Regulation (EU) 2016/679

Article 9 – paragraph 5

Text proposed by the CommissionAmendment
5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid v the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid v the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.
The controller shall apply effective technical and organisational measures to prevent their inference, disclosure or use. Those measures shall reflect the state of the art and shall include, as appropriate, the filtering and removal of such data from training, testing and validation datasets, pseudonymisation and key separation, and technical measures preventing their inference, regurgitation or disclosure through the outputs of the AI system or model; their application shall be proportionate to the risk and shall be documented by the controller.

Or. en

Amendment 1055

Zala Černilec Tomašič, Jan Farský, Ondřej Krutílek, Tomáš Zdechovský, Henrik Dahl, Alexandr Vondra, Veronika Vrecionová, Lukas Mandl

Proposal for a regulation

Article 3 – paragraph 1 – point 3 – point b

Regulation (EU) 2016/679

Article 9 – paragraph 5

Text proposed by the CommissionAmendment
5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid v the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid and mitigate the risk of the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the is notified of or identifies special categories of personal data relating to specific data subjects in the aforementioned datasets used for training, testing or validation or in the AI system or AI model, the controller shall implement technically and economically feasible measures to cease processing of those special categories of personal data for the purpose of training or developing an AI system or AI model. If cessation of processing requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.

Or. en

Justification

This amendment makes Article 9(5) more practical by replacing the obligation to "avoid" processing special categories of personal data with a proportionate duty to mitigate risks through appropriate technical and organisational measures. It clarifies that controllers must act when such data is identified or reported, and, where deletion is disproportionate, apply technically and economically feasible safeguards. The amendment preserves strong data protection while ensuring legal certainty and practical implementation.

Amendment 1056

Axel Voss

Proposal for a regulation

Article 3 – paragraph 1 – point 3 – point b

Regulation (EU) 2016/679

Article 9 – paragraph 5

Text proposed by the CommissionAmendment
5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid v the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid the collection and otherwise processing of special categories of personal data.

Or. en

Justification

The amendment clarifies that Article 9 applies where data is processed to reveal sensitive attributes, not where such attributes could merely be inferred incidentally from lawful processing. This reduces uncertainty for AI, safety, mobility, cybersecurity and other public-benefit technologies using large datasets, while preserving strong safeguards. Voluntary biometric use remains allowed only with a comparable non-biometric alternative, and safeguards such as minimisation, access limits and pseudonymisation.

Amendment 1057

Oliver Schenk, Axel Voss, Marie-Sophie Lanig, Ana Miguel Pedro, Romana Tomc, Marion Walsmann, Lena Düpont, Andrea Wechsler, Angelika Niebler, Monika Hohlmeier, Dimitris Tsiodras, Christian Doleschal, François-Xavier Bellamy

Proposal for a regulation

Article 3 – paragraph 1 – point 3 – point b

Regulation (EU) 2016/679

Article 9 – paragraph 5

Text proposed by the CommissionAmendment
5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid v the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented, in accordance with Article 89 safeguards to limit the processing of special categories of personal data and to mitigate the risk associated with the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall ensure that such data are processed under one or more of the conditions referred to in paragraph 2, points a to j, or remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.’

Or. en

Amendment 1058

Jana Nagyová, Ondřej Knotek, Tomáš Kubín, Jaroslav Bžoch

Proposal for a regulation

Article 3 – paragraph 1 – point 3 – point b

Regulation (EU) 2016/679

Article 9 – paragraph 5

Text proposed by the CommissionAmendment
5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid v the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to mitigate the risk of the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller is notified of or identifies special categories of personal data relating to specific data subjects in the aforementioned datasets used for training, testing or validation or in the AI system or AI model, the controller shall implement technically and economically feasible measures to cease processing of those special categories of personal data for the purpose of training or developing an AI system or AI model. If cessation of processing requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.

Or. en

Justification

The current wording of Article 9(5), requiring controllers to “avoid” the collection and processing of special categories of personal data, may be interpreted too broadly and create the expectation that controllers must eliminate such data entirely in advance. In practice, this is often not feasible, especially where large and diverse datasets are used for training and testing AI systems, and thus it could hinder AI development where appropriate safeguards are already in place. The amendment therefore replaces this overly rigid standard with a more proportionate obligation to mitigate the risk through appropriate technical and organisational measures. This approach is consistent with Article 25 - the principle of data protection by design and by default. At the same time, it preserves the duty to act where the controller is notified of, or identifies, the presence of such data - thereby covering situations in which the relevant data is brought to the controller's attention by third parties, and not only cases of self-identification. Where cessation of processing would require disproportionate effort, the controller shall implement technically and economically feasible measures to protect the data from being used to produce outputs or otherwise made available to third parties. This standard avoids imposing obligations that are impossible to fulfil in practice and is in line with the GDPR framework.

Amendment 1059

Krzysztof Hetman, Adam Jarubas

Proposal for a regulation

Article 3 – paragraph 1 – point 3 – point b

Regulation (EU) 2016/679

Article 9 – paragraph 5

Text proposed by the CommissionAmendment
5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid v the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to mitigate the risk of collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller is notified of special categories of personal data relating to specific data subjects in the aforementioned datasets used for training, testing or validation or in the AI system or AI model, the controller shall, taking into account its capabilities, implement appropriate technical and organisational measures to cease processing that special category data for the purpose of training or developing an AI system or AI model.

Or. en

Amendment 1060

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Article 3 – paragraph 1 – point 3 – point b

Regulation (EU) 2016/679

Article 9 – paragraph 5

Text proposed by the CommissionAmendment
5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid v the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, taking into account technical feasibility, available resources, the nature of the AI system or model, and state of the art technology, the controller shall in any event take appropriate measures proportionate to the risks posed without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.

Or. en

Amendment 1061

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Angelika Niebler, Henrik Dahl, Andrea Wechsler, Christian Ehler

Proposal for a regulation

Article 3 – paragraph 1 – point 3 – point b

Regulation (EU) 2016/679

Article 9 – paragraph 5

Text proposed by the CommissionAmendment
5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid v the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid v the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data that are incidentally and residually involved in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data without undue delay. If removal of those data requires manifestly disproportionate effort, the controller shall without undue delay and in any event, effectively protect such data from being further processed or processed for other purposes, used to produce outputs, being disclosed or otherwise made available to third parties.

Or. en

Amendment 1062

Tomas Tobé, Arba Kokalari, Jörgen Warborn

Proposal for a regulation

Article 3 – paragraph 1 – point 3 – point b

Regulation (EU) 2016/679

Article 9 – paragraph 5

Text proposed by the CommissionAmendment
5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid v the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.5. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to mitigate risks associated with the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being disclosed or otherwise made available to third parties.

Or. en

Amendment 1063

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 3 – point b

Regulation (EU) 2016/679

Article 9 – paragraph 5a (new)

Text proposed by the CommissionAmendment
5a. 'Where the processing referred to in point k of paragraph 2 is carried out in the context of an AI regulatory sandbox established under Article 57 of Regulation (EU) 2024/1689, or in the context of testing in real world conditions under Article 60 of that Regulation, the processing shall comply with the conditions and safeguards laid down, respectively, in Article 59 and in Articles 60 and 61 of that Regulation. In particular, the personal data shall be processed in a functionally separate, isolated and protected environment under the control of the controller; effective monitoring and response mechanisms shall be in place to identify and mitigate high risks to the rights and freedoms of the data subjects and, where necessary, to stop the processing; and any personal data shall be deleted once the participation in the sandbox or the testing has terminated.'

Or. en

Justification

The processing of personal data for the development of AI systems must be accompanied by robust safeguards, in particular as regards special categories of personal data. This amendment specifies the organisational and technical measures to be implemented, provides objective criteria for assessing whether the removal of inadvertently collected special categories of data would require a disproportionate effort, and subjects the removal itself to a requirement of promptness. It further establishes a graduated approach: where the processing takes place within an AI regulatory sandbox or in the course of testing in real world conditions, it must comply with the conditions and safeguards laid down, respectively, in Articles 59, 60 and 61 of Regulation (EU) 2024/1689, thereby importing the risk-control mechanisms of that Regulation — isolated processing environments, effective monitoring and response mechanisms, and deletion upon completion. Where the controller is a small or medium-sized enterprise or a small mid-cap, the measures are to be applied in a manner adapted to its capacities, without reducing the protection afforded to data subjects. This ensures coherence with the Artificial Intelligence Act while supporting innovation, in particular by smaller Union operators.

Amendment 1064

Sibylle Berg, Martin Sonneborn

Proposal for a regulation

Article 3 – paragraph 1 – point 3 – point b

Regulation (EU) 2016/679

Article 12 – paragraph 1a (new)

Text proposed by the CommissionAmendment
(5a) the following paragraph is inserted:
‘1a. Where the information referred to in Articles 13 and 14 is provided electronically, a version of that information shall be made available to the data subject for download in a structured, machine-readable and commonly used file format, in addition to any other form of provision. Simply providing a link to a website, the content of which may be unilaterally altered by the controller, does not satisfy this requirement. The obligation laid down in the first sentence shall be deemed to have been fulfilled if the data subject is offered a file for download which contains the information in full, in an unaltered and permanently retrievable form.’

Or. de

Justification

The principles developed to ensure that mandatory information is accessible to consumers need to be applied to information obligations under data protection law in order to ensure that data subjects can assert and exercise their rights, even retrospectively, for example in the event of a dispute (see recital (new)).

Amendment 1065

Francesco Torselli

Proposal for a regulation

Article 3 – paragraph 1 – point 3 – point b

Regulation (EU) 2016/679

Article 9 – paragraph 5a (new)

Text proposed by the CommissionAmendment
5a. ‘processing using artificial intelligence systems that involves the systematic generation of cognitive inferences concerning natural persons.’

Or. it

Amendment 1066

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 3 – point b

Regulation (EU) 2016/679

Article 9 – paragraph 5b (new)

Text proposed by the CommissionAmendment
5b. In Article 9, the following paragraph 5b is inserted:
'5b. Where the controller is a small or medium-sized enterprise or a small mid-cap, the organisational and technical measures referred to in this paragraph shall be applied in a manner adapted to its size and capacities, without reducing the level of protection afforded to data subjects and, in particular, without affecting the obligation to remove or effectively protect special categories of personal data. Competent authorities shall provide such enterprises with guidance to that effect.'

Or. en

Amendment 1067

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 3 a (new)

Regulation (EU) 2016/679

Article 9 – paragraph 5c (new)

Text proposed by the CommissionAmendment
3a. In Article 9, the following paragraph 5c is inserted:
'5c. Where, in the course of web scraping from publicly accessible sources for the purposes of developing or training an artificial intelligence system or model, special categories of personal data are collected incidentally and residually, without the controller intending to collect them, the prohibition laid down in paragraph 1 shall apply to that controller only within the framework of its responsibilities, powers and capabilities, provided that:
(a) the processing has relevant similarities with the processing carried out by a search engine operator;
(b) the processing of special categories of personal data is only incidental and residual, and no such processing is intentional;
(c) it is difficult or impossible to assess, before collection, whether and to what extent the processing includes special categories of personal data; and
(d) the controller implements measures, within the framework of its responsibilities, powers and capabilities, to prevent the collection and the dissemination of such data.
The measures referred to in point (d) shall include, at least: defining precise criteria and applying filters to prevent collection before collection, and excluding sources structurally containing such data; deleting such data immediately after collection or as soon as identified, including upon a request by the data subject constituting a plausible indication that the data fall under paragraph 1; preventing the extraction of such data from the model and ensuring state-of-the-art resistance to privacy attacks during development; and monitoring the output of the system after development, applying output filters and, where available, model unlearning.
The controller shall be able to demonstrate that these conditions are met and shall regularly verify the effectiveness of the measures.'

Or. en

Amendment 1068

Pernando Barrena Arza, João Oliveira

Proposal for a regulation

Article 3 – paragraph 1 – point 3 a (new)

Regulation (EU) 2016/679

Article 12 – paragraph 2

Text proposed by the CommissionAmendment
3a. In Article 12, paragraph 2 is replaced by the following:
2. The controller shall facilitate the exercise of data subject rights under Articles 15 to 22 of this Regulation. The controller cannot require them to exercise their rights by particular means or limit their rights by offering restrictive online tools that do not allow to request all information under Article 15(1) to (3). In any case, the controller has to provide and publicly disclose an electronic-mail address which allows data subjects to send requests electronically. In the cases referred to in Article 11(2), the controller shall not refuse to act on the request of the data subject for exercising his or her rights under Articles 15 to 22, unless the controller demonstrates that it is not in a position to identify the data subject.

Or. en

Justification

It is up to data subjects how they exercise their rights under the GDPR. They are not bound by any form requirements. Similarly, the controller cannot require data subjects to use a particular form or medium to exercise their rights. This fact should be clarified while it should be required from controllers that they designate an email-address for data subjects who want to electronically exercise their rights. Controllers might also provide online-forms but they should still provide the alternative way of submitting an E-Mail.

Amendment 1069

Angelika Winzig

Proposal for a regulation

Article 3 – paragraph 1 – point 3 a (new)

Regulation (EU) 2016/679

Article 12 – paragraph 3

Text proposed by the CommissionAmendment
3a. in Article 12, paragraph 3 is replaced by the following:
'3. The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. The controller shall inform the data subject of any such extension without undue delay and in any event within one month of receipt of the request, together with the reasons for the delay. Where the data subject makes the request by electronic means, the information shall be provided by electronic means unless impossible despite the controller’s continuous efforts, unless otherwise requested by the data subject.'

Or. en

Amendment 1070

Axel Voss

Proposal for a regulation

Article 3 – paragraph 1 – point 3 a (new)

Regulation (EU) 2016/679

Article 9 – paragraph 1

Present textAmendment
3a. In Article 9, paragraph 1 is replaced by the following:
1. Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited."1. Processing of personal data that is intended to directly reveal, in relation to an identified or identifiable natural person, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health status, sex life or sexual orientation, and the processing of genetic data or biometric data for the purpose of uniquely identifying a natural person, shall be prohibited unless one of the conditions set out in paragraph 2 applies.
The mere possibility that one of the characteristics referred to in the first subparagraph may be inferred indirectly from personal data processed for another lawful purpose shall not, in itself, render such processing subject to this Article, provided that the controller does not process the data for the purpose of revealing such characteristic."

Or. en

Justification

The amendment clarifies that Article 9 applies where data is processed to reveal sensitive attributes, not where such attributes could merely be inferred incidentally from lawful processing. This reduces uncertainty for AI, safety, mobility, cybersecurity and other public-benefit technologies using large datasets, while preserving strong safeguards. Voluntary biometric use remains allowed only with a comparable non-biometric alternative, and safeguards such as minimisation, access limits and pseudonymisation.

Amendment 1071

Tomas Tobé, Arba Kokalari, Jörgen Warborn

Proposal for a regulation

Article 3 – paragraph 1 – point 3 a (new)

Regulation (EU) 2016/679

Article 9 – paragraph 1

Present textAmendment
Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited."Processing of personal data directly revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited."

Or. en

(Regulation (EU) 2016/679)

Amendment 1072

Axel Voss

Proposal for a regulation

Article 3 – paragraph 1 – point 3 b (new)

Regulation (EU) 2016/679

Article 9 – paragraph 2a (new)

Present textAmendment
3b. In Article 9, the following paragraphs are added:
No equivalent"2a. For the purposes of paragraph 2, point (la), important public-benefit purposes shall include in particular:
(a) the protection of life, health and physical integrity;
(b) road safety, accident prevention and transport safety;
(c) prevention of criminal offenses;
(d) anti-discrimination and foster inclusion and participation of all persons on an equal basis;
(e) cybersecurity, including the resilience of connected products, transport and traffic systems and critical infrastructure;
(f) scientific research and technological development contributing to the purposes referred to in points (a) to (e).
2b. Processing pursuant to paragraph 2, point (la), shall not be used for the purpose of identifying natural persons, monitoring individual behaviour for unrelated purposes, or taking decisions concerning identified natural persons, unless another legal basis under this Regulation applies."

Or. en

(Regulation (EU) 2016/679)

Justification

The amendment clarifies that Article 9 applies where data is processed to reveal sensitive attributes, not where such attributes could merely be inferred incidentally from lawful processing. This reduces uncertainty for AI, safety, mobility, cybersecurity and other public-benefit technologies using large datasets, while preserving strong safeguards. Voluntary biometric use remains allowed only with a comparable non-biometric alternative, and safeguards such as minimisation, access limits and pseudonymisation.

Amendment 1073

Axel Voss

Proposal for a regulation

Article 3 – paragraph 1 – point 3 c (new)

Regulation (EU) 2016/679

Article 10a (new)

Present textAmendment
3c. After Article 10, a new Article is added:
No equivalent"Article 10a
Privileged processing of personal data
1. The following processing serves objectives of general interest recognised by the Union and may be privileged in accordance with this Article ('privileged processing'):
(a) processing necessary for internal administrative purposes within a group of undertakings, including the processing of personal data of clients and employees;
(b) processing by a micro, small or medium-sized enterprise within the meaning of the Annex to Recommendation 2003/361/EC, necessary for its ordinary commercial activities;
(c) processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1), whether or not it constitutes further processing within the meaning of point (b) of Article 5(1).
2. Processing referred to in paragraph 1 shall be privileged where the controller or processor:
(a) has committed, by entry in the register referred to in [the Data Act/ Data Governance Act], to making data available for objectives of general interest; and
(b) carries out the processing in demonstrable conformity with an approved code of conduct pursuant to Article 40, an approved certification mechanism pursuant to Article 42, binding corporate rules approved pursuant to Article 47, or a standard included in the list established by the Board pursuant to Article 70 point (o).
3. Privileged processing pursues legitimate interests within the meaning of point (f) of Article 6(1). Where it concerns special categories of personal data and is necessary for the objectives referred to in paragraph 1, this Article constitutes a substantial public interest of Article 9(2)(g), (j).
Privileged processing shall be presumed to comply with the requirements of this Regulation to which the safeguards give effect, including point (f) of Article 6(1), points (g) (j) of Article 9(2) and, where the controller or processor has assessed and documented that the law and practice of the third country do not impair the effectiveness of the safeguards, Article 46(1). The presumption shall be rebutted by specific and substantiated indications of non-compliance; in that event, the controller or processor shall demonstrate compliance in accordance with Article 5(2).
4. The obligations under Articles 13 and 14 may be fulfilled by providing the standardised information laid down in the instrument referred to in point (b) of paragraph 2.
5. Data made available under the commitment shall not be provided to undertakings referred to in point (b) of paragraph 6. The commitment may be withdrawn with effect for the future; upon withdrawal, the processing ceases to be privileged. The Commission shall adopt delegated acts in accordance with Article 92 specifying the categories of data to be made available, the conditions and modalities of making them available, and the safeguards for the protection of personal data and trade secrets.
6. This Article shall not apply to:
(a) processing likely to result in a high risk within the meaning of Article 35, unless a data protection impact assessment has been carried out and its results have been implemented;
(b) processing by an undertaking designated pursuant to Article 3 of Regulation (EU) 2022/1925 or Article 33(4) of Regulation (EU) 2022/2065, or by an undertaking belonging to the same group of undertakings."

Or. en

Justification

This amendment creates an incentive model for data use serving general-interest objectives, such as intra-group administration, SME operations, research, archiving and statistics. Privileged status is limited to actors that make a data-sharing commitment and follow recognised safeguards, including codes, certification, BCRs or listed standards. The rebuttable presumption rewards accountable governance without lowering protection, excludes gatekeepers and VLOPs/VLOSEs, and covers high-risk processing only after a DPIA.

Amendment 1074

Sibylle Berg, Martin Sonneborn

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5

Text proposed by the CommissionAmendment
4. In Article 12, paragraph 5 is replaced by the following:deleted
‘5.
Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 15 because the data subject abuses the rights conferred by this regulation for purposes other than the protection of their data, the controller may either:
(a) charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or
(b) refuse to act on the request.
The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive.’

Or. de

Amendment 1075

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5

Text proposed by the CommissionAmendment
4. In Article 12, paragraph 5 is replaced by the following:deleted
‘5.
Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 15 because the data subject abuses the rights conferred by this regulation for purposes other than the protection of their data, the controller may either:
(a) charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or
(b) refuse to act on the request.
The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive.’

Or. en

Justification

The CJEU was able to decide the "Brillen Rottler" case C-526/24 on the basis of the current wording, no need to introduce new "abuse" or other conditions.

Amendment 1076

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5

Text proposed by the CommissionAmendment
4. In Article 12, paragraph 5 is replaced by the following:deleted
‘5.
Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 15 because the data subject abuses the rights conferred by this regulation for purposes other than the protection of their data, the controller may either:
(a) charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or
(b) refuse to act on the request.
The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive.’

Or. en

Amendment 1077

Birgit Sippel

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5

Text proposed by the CommissionAmendment
5. Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 15 because the data subject abuses the rights conferred by this regulation for purposes other than the protection of their data, the controller may either:deleted
(a) charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or
(b) refuse to act on the request.
The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive.

Or. en

Amendment 1078

João Oliveira

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5

Text proposed by the CommissionAmendment
Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 15 because the data subject abuses the rights conferred by this regulation for purposes other than the protection of their data, the controller may either:Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are deemed manifestly unfounded or excessive, in particular because of their repetitive character, the controller shall propose to the data subject the following scenarios:

Or. pt

Amendment 1079

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5

Text proposed by the CommissionAmendment
Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 15 because the data subject abuses the rights conferred by this regulation for purposes other than the protection of their data, the controller may either:Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 15 because the data subject abuses the means at their disposal to enforce the rights conferred by this regulation for purposes unrelated to the protection of their data, the controller may refuse to act on the request, and inform the data subject of the reasons thereof.

Or. en

Amendment 1080

Pernando Barrena Arza

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2026/679

Article 12 – paragraph 5

Text proposed by the CommissionAmendment
Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 15 because the data subject abuses the rights conferred by this regulation for purposes other than the protection of their data, the controller may either:Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character the controller may refuse to act on the request.

Or. en

Amendment 1081

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5

Text proposed by the CommissionAmendment
Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 15 because the data subject abuses the rights conferred by this regulation for purposes other than the protection of their data, the controller may either:Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests where the controller is able to demonstrate an abusive intention where the data subject abuses the rights conferred by this regulation for purposes other than the protection of their data, the controller may either:

Or. en

Amendment 1082

Pernando Barrena Arza

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5 – point a

Text proposed by the CommissionAmendment
(a) charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; ordeleted

Or. en

Amendment 1083

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5 – point a

Text proposed by the CommissionAmendment
(a) charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; ordeleted

Or. en

Amendment 1084

João Oliveira

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5 – point a

Text proposed by the CommissionAmendment
(a) charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or(a) payment of a marginal fee not exceeding the administrative costs of providing the information or communication or taking the action requested; or

Or. pt

Amendment 1085

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5 – point b

Text proposed by the CommissionAmendment
(b) refuse to act on the request.deleted

Or. en

Amendment 1086

Pernando Barrena Arza

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5 – point b

Text proposed by the CommissionAmendment
(b) refuse to act on the request.deleted

Or. en

Amendment 1087

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5 – second subparagraph

Text proposed by the CommissionAmendment
A request may in particular be regarded as excessive within the meaning of the first subparagraph where the means at the disposal of the data subject are used for the purpose of obtaining commercially sensitive information or gaining insight into the internal processes of the controller, including for the benefit of an undertaking competing with the controller, of exerting pressure in unrelated proceedings, or of disrupting the administrative operations of the controller by imposing a manifestly disproportionate burden.

Or. en

Justification

Specifies the circumstances in which a request may be regarded as excessive: obtaining commercially sensitive information or gaining insight into the internal processes of the controller, including for the benefit of a competing undertaking; exerting pressure in unrelated proceedings; disrupting the administrative operations of the controller by imposing a manifestly disproportionate burden. The criterion is the manifest diversion of purpose, not the mere inconvenience caused to the controller.

Amendment 1088

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5 – third subparagraph

Text proposed by the CommissionAmendment
In Article 12, paragraph 5, the following subparagraph is added:
'The exercise of the rights conferred by this Regulation for the purpose of verifying, in good faith, whether a controller complies with this Regulation shall not be regarded as unfounded or excessive, irrespective of whether those rights are exercised individually or with the assistance of, or through, a body referred to in Article 80.'

Or. en

Amendment 1089

Henrik Dahl

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5 – last subparagraph

Text proposed by the CommissionAmendment
The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive.deleted

Or. en

Amendment 1090

Tomas Tobé, Arba Kokalari, Jörgen Warborn

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5 – last subparagraph

Text proposed by the CommissionAmendment
The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive.deleted

Or. en

Amendment 1091

Niels Flemming Hansen

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5 – last subparagraph

Text proposed by the CommissionAmendment
The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive.deleted

Or. en

Amendment 1092

Alice Teodorescu Måwe

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5 – last subparagraph

Text proposed by the CommissionAmendment
The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive.deleted

Or. en

Amendment 1093

Pernando Barrena Arza

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2026/679

Article 12 – paragraph 5 – last subparagraph

Text proposed by the CommissionAmendment
The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive.The controller shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request. A request shall not be considered manifestly unfounded or excessive solely because it is broad in scope, concerns a long period of time, relates to complex processing operations, concerns profiling or automated decision-making, concerns several recipients or categories of recipients, concerns possible systemic rights issues, or is made for the purpose of exercising rights under this Regulation or other rights, including consumer protection rights, employment rights, rights to non-discrimination, rights of defence, collective redress, research, journalism, regulatory oversight or civil society monitoring. The manifestly unfounded or excessive character of a request shall be assessed restrictively and on the basis of objective and documented circumstances. It shall not be inferred from the purpose of exercising rights, the use of a representative, the use of standardised requests, the scale or complexity of the processing, or the fact that compliance may require a significant effort by the controller.

Or. en

Amendment 1094

João Oliveira

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5 – last subparagraph

Text proposed by the CommissionAmendment
The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive.’The data subject, when making the request, shall be presumed to be acting in the exercise of his or her legitimate interest in defending his or her rights under this Regulation. Any refusal on the grounds that the request is manifestly unfounded or excessive must be substantiated in writing, in a clear, specific and verifiable manner, indicating the objective facts and considerations supporting that conclusion. The justification must be sufficiently detailed to enable the data subject to understand the reasons for the refusal and to challenge it effectively, in particular by lodging a complaint with the supervisory authority or by seeking a judicial remedy. The burden of proof regarding whether the request is manifestly unfounded or excessive shall be on the controller.

Or. pt

Amendment 1095

Nadine Morano

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5 – last subparagraph

Text proposed by the CommissionAmendment
The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive.For the purpose of assessing whether a request is manifestly unfounded or excessive, the controller may ask the data subject to indicate the exact scope of the request and the specific reasons for the request.

Or. fr

Amendment 1096

François-Xavier Bellamy

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5 – last subparagraph

Text proposed by the CommissionAmendment
In Article 12, paragraph 5, the following subparagraph is added:
'The Commission may adopt implementing acts to further specify criteria for what constitutes a manifestly unfounded or excessive character of the request.'

Or. en

Amendment 1097

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 3 – paragraph 1 – point 4 a (new)

Regulation (EU) 2016/679

Article 12 – paragraph 8

Text proposed by the CommissionAmendment
4a. Article 12, paragraph 8 is replaced by the following:
'8. The Commission shall adopt delegated acts in accordance with Article 92 for the purpose of determining the information to be presented by the icons and the procedures for providing standardised icons, after consulting the Board. The Commission shall ensure that the icons cover at least the information requirements on the most common purposes and legal bases used by controllers referred to in Article 13(1)(c). Those delegated acts shall apply by [PO to insert: one year after the entry into force].'

Or. en

Amendment 1098

Angelika Niebler, Monika Hohlmeier

Proposal for a regulation

Article 3 – paragraph 1 – point 4 a (new)

Regulation (EU) 2016/679

Article 12 – paragraph 8a (new)

Text proposed by the CommissionAmendment
4a. In Article 12, the following paragraph 8a is added:
'8a. Where the controller is a SME, the obligations arising under this Chapter and the documentation duties connected with them shall apply in a manner proportionate to the size of the enterprise, the nature of the processing and the risk it presents for data subjects. The Board shall issue guidelines setting out simplified means of compliance for such enterprises.'

Or. en

Amendment 1099

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 5

Regulation (EU) 2016/679

Article 13 – paragraph 4

Text proposed by the CommissionAmendment
5. In Article 13, paragraph 4 is replaced by the following:deleted
‘4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other recipients or categories of recipients, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.’

Or. en

Amendment 1100

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 5

Regulation (EU) 2016/679

Article 13 – paragraph 4

Text proposed by the CommissionAmendment
5. In Article 13, paragraph 4 is replaced by the following:deleted
‘4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other recipients or categories of recipients, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.’

Or. en

Amendment 1101

Alex Agius Saliba

Proposal for a regulation

Article 3 – paragraph 1 – point 5

Regulation (EU) 2016/679

Article 13 – paragraph 4

Text proposed by the CommissionAmendment
5. In Article 13, paragraph 4 is replaced by the following:deleted
‘4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other recipients or categories of recipients, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.’

Or. en

Amendment 1102

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Article 3 – paragraph 1 – point 5

Regulation (EU) 2016/679

Article 13 – paragraph 4

Text proposed by the CommissionAmendment
5. In Article 13, paragraph 4 is replaced by the following:deleted
‘4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other recipients or categories of recipients, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.’

Or. en

Amendment 1103

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 3 – paragraph 1 – point 5

Regulation (EU) 2016/679

Article 13 – paragraph 4

Text proposed by the CommissionAmendment
4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other recipients or categories of recipients, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.4. Paragraphs 1, 2 and 3 shall not apply where:
(a) the data subject already has the information; or
(b) the following conditions are met:
(i) the personal data have been collected by a micro, small, and medium-sized enterprise or an organisation employing fewer than 250 employees;
(ii) the personal data are necessary under point (b) of paragraph 1 of Article 6 in the context of a clear and circumscribed relationship between the data subject and a controller which the data subject fully comprehends and which is not data-intensive;
(iii) the controller is not required to appoint a data protection officer pursuant to Article 37(1);
(iv) the personal data are not special categories of personal data pursuant to Article 9 or personal data relating to criminal convictions and offences pursuant to Article 10;
(v) there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1 and the information remains available to the data subject;
(vi) the controller does not transmit the data to other controllers, or transfer the data to a third country;
(vii) the controller does not carry out automated decision-making, including profiling, referred to in Article 22(1); and
(viii) the processing is not likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.
In those cases, the controller may alternatively provide information solely through the icons referred to in Article 12 paragraph 7, as long as the complete information remains easily and readily available to the data subject.

Or. en

Amendment 1104

Pernando Barrena Arza

Proposal for a regulation

Article 3 – paragraph 1 – point 5

Regulation (EU) 2016/679

Article 13 – paragraph 4

Text proposed by the CommissionAmendment
4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other recipients or categories of recipients, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.4. Paragraphs 1, 2 and 3 shall apply only where and insofar as the controller can demonstrate that the data subject already has the information referred to in points (a) and (c) of paragraph 1 and, where the processing is based on point (f) of Article 6(1), the information referred to in point (d) of paragraph 1, in a concise, transparent, intelligible and easily accessible form.
This exemption shall apply only where the personal data are collected in the context of a direct, ongoing and clearly circumscribed relationship between the data subject and the controller, for purposes that are strictly connected to and reasonably expected in that relationship, and where the processing is not likely to result in a high risk to the rights and freedoms of data subjects, nor involve complex processing operations, systematic monitoring, profiling, the processing of large amounts of personal data, special categories of personal data, or personal data relating to criminal convictions and offences.
The controller shall make the information referred to in paragraphs 1, 2 and 3 available to the data subject in an easily accessible and durable form at the time of collection and shall document the assessment under this paragraph.
The first, second and third subparagraphs shall not apply where the controller intends to process the data collected from the data subject for other purposes, transmits the data to other recipients or categories of recipients, transfers the data to a third country or to an international organisation, combines the data with personal data obtained from other sources, processes the data for direct marketing purposes, carries out automated decision-making, including profiling, referred to in Article 22(1), or where the processing requires a data protection impact assessment under Article 35 or is otherwise likely to result in a high risk to the rights and freedoms of data subjects.

Or. en

Amendment 1105

Sibylle Berg, Martin Sonneborn

Proposal for a regulation

Article 3 – paragraph 1 – point 5

Regulation (EU) 2016/679

Article 13 – paragraph 4

Text proposed by the CommissionAmendment
4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other recipients or categories of recipients, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.4. Paragraphs 1, 2 and 3 shall not apply where and insofar as the data subject already has the information.

Or. de

Amendment 1106

Andrea Wechsler, Marie-Sophie Lanig, Stefan Köhler, Alexandra Mehnert, Verena Mertens, Sabine Verheyen

Proposal for a regulation

Article 3 – paragraph 1 – point 5

Regulation (EU) 2016/679

Article 13 – paragraph 4

Text proposed by the CommissionAmendment
4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other recipients or categories of recipients, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, or where the provision of such information proves impossible or would involve a disproportionate effort, taking into account the nature, scope, context and purposes of the processing, the size and resources of the controller, and the risk to the rights and freedoms of natural persons, unless the controller transmits the data to other recipients or categories of recipients for purposes other than those directly related to the clear and circumscribed relationship with the data subject, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35. In such cases, the controller shall take appropriate measures to protect the rights and freedoms and legitimate interests of the data subject, including, where appropriate, making the information publicly available in an easily accessible form.

Or. en

Justification

Information obligations are essential for transparency, but they should remain proportionate and workable in low-risk situations. The Commission proposal rightly introduces an exemption for clear and circumscribed relationships where the controller does not carry out data-intensive activities. However, the exemption should also cover situations where individual information proves impossible or would involve a disproportionate effort, provided that appropriate safeguards are maintained. In addition, the mere transmission of data to recipients should not automatically exclude the exemption where such transmission is directly related to the existing relationship with the data subject, for example in the context of associations, non-profit organisations, craft businesses or small enterprises. This amendment preserves transparency while reducing unnecessary administrative burdens.

Amendment 1107

João Oliveira

Proposal for a regulation

Article 3 – paragraph 1 – point 5

Regulation (EU) 2016/679

Article 13 – paragraph 4

Text proposed by the CommissionAmendment
4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other recipients or categories of recipients, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.’4. Paragraphs 1, 2 and 3 shall not apply only where the controller can demonstrate that the data subject already has the respective information in his or her possession. At the time the data are collected, the controller shall make the information referred to in paragraphs 1, 2 and 3 permanently available to the data subject in an easily accessible form.’

Or. pt

Amendment 1108

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 5

Regulation (EU) 2016/679

Article 13 – paragraph 4

Text proposed by the CommissionAmendment
4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other recipients or categories of recipients, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and the controller is able to demonstrate that the data subject already has the information referred to in points (a), (c) and (d) of paragraph 1. Where the controller intends to carry out processing for which the information referred to in points (e) and (f) of paragraph 1 is required, such as transmitting the data to other recipients or categories of recipients, transfering the data to a third country, carrying out automated decision-making, including profiling, referred to in Article 22(1), or where the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35, the controller shall provide that information to the data subject.
This exemption shall not apply where processing concerns data relating to health, data inferred from medicine- or pharmacy-related interactions, profiling, direct marketing or disclosure to another recipient.

Or. en

Amendment 1109

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Article 3 – paragraph 1 – point 5

Regulation (EU) 2016/679

Article 13 – paragraph 4

Text proposed by the CommissionAmendment
4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other recipients or categories of recipients, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has, or the data controller has taken reasonable steps available to it, taking into account relevant technical and organisational means to provide the data subject with the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other data processors or controllers, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.

Or. en

Amendment 1110

Henrik Dahl

Proposal for a regulation

Article 3 – paragraph 1 – point 5

Regulation (EU) 2016/679

Article 13 – paragraph 4

Text proposed by the CommissionAmendment
4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other recipients or categories of recipients, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.

Or. en

Amendment 1111

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Henrik Dahl, Andrea Wechsler, Christian Ehler

Proposal for a regulation

Article 3 – paragraph 1 – point 5

Regulation (EU) 2016/679

Article 13 – paragraph 4

Text proposed by the CommissionAmendment
4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other recipients or categories of recipients, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.4. Paragraphs 1, 2 and 3 shall not apply where and insofar as the data subject already has the information or where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not a high risk to the data subject and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other recipients or categories of recipients, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.

Or. en

Amendment 1112

Oliver Schenk, Axel Voss, Ana Miguel Pedro, Romana Tomc, Marion Walsmann, Lena Düpont, Marie-Sophie Lanig, Dimitris Tsiodras, Christian Doleschal, Aura Salla, François-Xavier Bellamy

Proposal for a regulation

Article 3 – paragraph 1 – point 5

Regulation (EU) 2026/679

Article 13 – paragraph 4

Text proposed by the CommissionAmendment
4. Paragraphs 1, 2 and 3 shall not apply where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other recipients or categories of recipients, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.4. Paragraphs 1, 2 and 3 shall not apply where and insofar as the data subject already has the information or where the personal data have been collected in the context of a clear and circumscribed relationship between data subjects and a controller exercising an activity that is not data-intensive and there are reasonable grounds to assume that the data subject already has the information referred to in points (a) and (c) of paragraph 1, unless the controller transmits the data to other recipients or categories of recipients, transfers the data to a third country, carries out automated decision-making, including profiling, referred to in Article 22(1), or the processing is likely to result in a high risk to the rights and freedoms of data subjects within the meaning of Article 35.’

Or. en

Amendment 1113

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 5

Regulation (EU) 2016/679

Article 13 – paragraph 4a (new)

Text proposed by the CommissionAmendment
4a. In Article 13, the following paragraph is inserted:
'4a. An activity is circumscribed and not data-intensive where the processing of personal data is ancillary to the main activity of the controller and is limited in volume, scope and purposes. Such relationships include, in particular:
(a) the relationship between a data subject and a professional bound by a legal or ethical obligation of confidentiality, such as a lawyer, physician or notary, acting within the scope of that relationship;
(b) the commercial relationship between a customer and a trader in the context of the provision of a specific good or service requested by the data subject, provided that the customer list is used solely as an internal management tool and is not intended to be disclosed or monetised to third parties;
(c) the non-commercial relationship between a member and an association, or between an employee and an employer, insofar as the processing is limited to what is necessary for that relationship.'

Or. en

Justification

Extends the derogation from the information obligation to circumscribed relationships in which the controller's activity is not data-intensive: associations, sport clubs, micro, small and medium-sized enterprises where processing is confined to the management of membership, communication with members, the organisation of activities or the performance of a contract. The derogation is expressly excluded where the controller engages in data brokerage, which is by nature data-intensive.

Amendment 1114

Nadine Morano

Proposal for a regulation

Article 3 – paragraph 1 – point 5 a (new)

Regulation (EU) 2016/679

Article 15 – paragraph 4

Present textAmendment
5a. In Article 15, paragraph 4 is replaced by the following:
4. The right to obtain a copy referred to in paragraph 3 shall not adversely affect the rights and freedoms of others.‘4. The right to obtain a copy referred to in paragraph 3 shall not adversely affect the rights and freedoms of others, including the right to a fair trial, the right to privacy and confidentiality of communications, and the protection of trade secrets. In particular, that right cannot be interpreted as a general right of access to documents containing the data subject’s personal data, but shall relate only to the personal data concerning him or her. The controller may restrict or refuse a request to obtain a copy where it is likely to adversely affect the rights and freedoms of others, and where the assessment or implementation of the measures necessary to prevent such an adverse affect would impose a burden that is manifestly disproportionate to the volume, nature or complexity of the documents concerned. The right to obtain a copy shall not apply to requests for information or documents that are unrelated to the purposes of the processing carried out by the controller or that are made exclusively in the context of a dispute, a pre-litigation phase or court proceedings between the controller and the data subject.’

Or. fr

(32016R0679)

Amendment 1115

Axel Voss

Proposal for a regulation

Article 3 – paragraph 1 – point 5 a (new)

Regulation (EU) 2016/679

Article 13 – paragraph 1 – points fa (new) and fb (new)

Present textAmendment
5a. In Article 13, paragraph 1, the following points are added:
No equivalent"(fa) if the controller is a small, medium or large controller under Article 4(27) to (29) and;
(fb) if the controller is a large controller, the number of data subjects they processed personal data about, the number of times data subjects have exercised their rights against them under Articles 13 to 22 and the number of each type of outcome, the number of data breaches under Article 32 and the number of likely affected data subjects, the number of procedures filed against them under Article 78 and 79, the certifications received or revoked under Article 42 and the name and contact details of the certification body that has certified them for the past three financial years."

Or. en

Justification

RISK-BASED APPROACH #8: This package makes the GDPR’s risk-based approach practical by introducing objective categories for small, medium and large controllers. Small controllers with limited, non-core processing receive relief from selected administrative duties, while data-subject rights and enforcement remain intact. Very large controllers, gatekeepers and VLOPs/VLOSEs face stronger transparency, annual certification and closer supervision. Compliance effort is thus reduced where risks are low and increased where scale and systemic impact are greatest.

Amendment 1116

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 3 – paragraph 1 – point 6

Regulation (EU) 2016/679

Article 13 – paragraph 5

Text proposed by the CommissionAmendment
6. In Article 13, paragraph 5 is added:deleted
‘5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available.’

Or. en

Amendment 1117

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Article 3 – paragraph 1 – point 6

Regulation (EU) 2016/679

Article 13 – paragraph 5

Text proposed by the CommissionAmendment
6. In Article 13, paragraph 5 is added:deleted
‘5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available.’

Or. en

Amendment 1118

Pernando Barrena Arza

Proposal for a regulation

Article 3 – paragraph 1 – point 6

Regulation (EU) 2016/679

Article 13 – paragraph 5

Text proposed by the CommissionAmendment
6. In Article 13, paragraph 5 is added:deleted
‘5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available.’

Or. en

Amendment 1119

Alex Agius Saliba

Proposal for a regulation

Article 3 – paragraph 1 – point 6

Regulation (EU) 2016/679

Article 13 – paragraph 5

Text proposed by the CommissionAmendment
6. In Article 13, paragraph 5 is added:deleted
‘5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available.’

Or. en

Amendment 1120

Birgit Sippel

Proposal for a regulation

Article 3 – paragraph 1 – point 6

Regulation (EU) 2016/679

Article 13 – paragraph 5

Text proposed by the CommissionAmendment
6. In Article 13, paragraph 5 is added:deleted
‘5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available.’

Or. en

Amendment 1121

João Oliveira

Proposal for a regulation

Article 3 – paragraph 1 – point 6

Regulation (EU) 2016/679

Article 13 – paragraph 5

Text proposed by the CommissionAmendment
5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available.’deleted

Or. pt

Amendment 1122

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 6

Regulation (EU) 2016/679

Article 13 – paragraph 5

Text proposed by the CommissionAmendment
5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available.5. When the further processing takes place for scientific research purposes, provided it is not used for commercial product development, advertising, marketing, profiling or the training of data processing models for commercial deployment, and where the controller does not possess or cannot reasonably obtain the contact details of the data subject without disproportionate effort, and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall document the reliance of this exception, make such documentation available to the supervisory authority upon request, and take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including annoucing the information publicy or informing the data subject without undue delay as soon as the conditions of this paragraph have ceased to exist.

Or. en

Amendment 1123

Oliver Schenk, Axel Voss, Marie-Sophie Lanig, Ana Miguel Pedro, Romana Tomc, Marion Walsmann, Lena Düpont, Andrea Wechsler, Angelika Niebler, Monika Hohlmeier, Dimitris Tsiodras, Christian Doleschal, Aura Salla, François-Xavier Bellamy

Proposal for a regulation

Article 3 – paragraph 1 – point 6

Regulation (EU) 2016/679

Article 13 – paragraph 5

Text proposed by the CommissionAmendment
5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available.5. When the processing takes place for scientific research purposes, including scientific research in the public interest aiming to further a commercial interest, and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort, including cases where the change of purpose could not have been anticipated at the time of collection, subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available. This scenario shall apply equally to the obligations under Article 14(5)(b).

Or. en

Amendment 1124

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 6

Regulation (EU) 2016/679

Article 13 – paragraph 5

Text proposed by the CommissionAmendment
5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available.5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available. This paragraph is without prejudice to the conditions and safeguards applicable to the processing of personal data in AI regulatory sandboxes and in testing in real world conditions under Articles 59, 60 and 61 of Regulation (EU) 2024/1689, which continue to apply.

Or. en

Justification

The exemption from the information obligations for scientific research purposes must not operate to the detriment of the safeguards applicable to the processing of personal data in the context of AI development. This amendment specifies that paragraph 5 is without prejudice to the conditions and safeguards laid down in Articles 59, 60 and 61 of Regulation (EU) 2024/1689 governing AI regulatory sandboxes and testing in real world conditions — in particular the requirements relating to isolated processing environments, monitoring and response mechanisms, deletion of data, and informed consent — which continue to apply. This ensures the coherence of the Union acquis and prevents the research exemption from being used to circumvent the risk-control obligations of the Artificial Intelligence Act.

Amendment 1125

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Henrik Dahl, Andrea Wechsler, Christian Ehler

Proposal for a regulation

Article 3 – paragraph 1 – point 6

Regulation (EU) 2016/679

Article 13 – paragraph 5

Text proposed by the CommissionAmendment
5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available.5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort, including cases where the change of purpose could not have been anticipated at the time of collection, subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available

Or. en

Amendment 1126

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Article 3 – paragraph 1 – point 6

Regulation (EU) 2016/679

Article 13 – paragraph 5

Text proposed by the CommissionAmendment
5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available.5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort, taking into account the relevant technical and organisational circumstances, subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available.

Or. en

Amendment 1127

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Andrea Wechsler, Oliver Schenk, Pekka Toveri, Christian Ehler

Proposal for a regulation

Article 3 – paragraph 1 – point 6

Regulation (EU) 2016/679

Article 14 – paragraph 5a (new)

Text proposed by the CommissionAmendment
5a. In Article 14, paragraph 5a is added:
'5a. The obligation to make information available pursuant to Article 14 shall be deemed fulfilled where such information is published and maintained in an easily accessible manner on the entity's website.'

Or. en

Amendment 1128

Andrea Wechsler, Marie-Sophie Lanig, Stefan Köhler, Alexandra Mehnert, Lena Düpont, Angelika Niebler, Verena Mertens, Christian Doleschal, Sabine Verheyen

Proposal for a regulation

Article 3 – paragraph 1 – point 6 a (new)

Regulation (EU) 2016/679

Article 13 – paragraph 4a (new)

Present textAmendment
6a. In Article 13, paragraph 4a is added:
Article 13 Information to be provided where personal data are collected from the data subject 1. Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information: (a) the identity and the contact details of the controller and, where applicable, of the controller's representative; (b) the contact details of the data protection officer, where applicable; (c) the purposes of the processing for which the personal data are intended as well as the legal basis for the processing; (d) where the processing is based on point (f) of Article 6(1), the legitimate interests pursued by the controller or by a third party; (e) the recipients or categories of recipients of the personal data, if any; (f) where applicable, the fact that the controller intends to transfer personal data to a third country or international organisation and the existence or absence of an adequacy decision by the Commission, or in the case of transfers referred to in Article 46 or 47, or the second subparagraph of Article 49(1), reference to the appropriate or suitable safeguards and the means by which to obtain a copy of them or where they have been made available. 2. In addition to the information referred to in paragraph 1, the controller shall, at the time when personal data are obtained, provide the data subject with the following further information necessary to ensure fair and transparent processing: (a) the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period; (b) the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject or to object to processing as well as the right to data portability; (c) where the processing is based on point (a) of Article 6(1) or point (a) of Article 9(2), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal; (d) the right to lodge a complaint with a supervisory authority; (e) whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether the data subject is obliged to provide the personal data and of the possible consequences of failure to provide such data; (f) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject. 3. Where the controller intends to further process the personal data for a purpose other than that for which the personal data were collected, the controller shall provide the data subject prior to that further processing with information on that other purpose and with any relevant further information as referred to in paragraph 2. 4. Paragraphs 1, 2 and 3 shall not apply where and insofar as the data subject already has the information."Paragraphs 1 to 4 shall not apply to associations, foundations, and other non-profit organisations established in the Union, provided that: (a) the processing of personal data is limited to the administration of membership, volunteers, donors, or beneficiaries; (b) such processing is not likely to result in a high risk to the rights and freedoms of natural persons; and (c) the data are not shared with third parties for commercial purposes."

Or. en

(https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:02016R0679-20160504)

Justification

Article 13 information obligations are essential for transparency, but they can create disproportionate administrative burdens for small non-profit organisations where the processing relationship is clear, direct and limited to internal administrative purposes. Associations, foundations and other non-profit organisations should therefore be allowed to fulfil transparency obligations through publicly accessible information where processing is limited to members, volunteers, donors or beneficiaries, does not involve systematic monitoring, is not likely to result in a high risk and is not used for commercial third-party sharing. This targeted clarification supports civic engagement and volunteer work while preserving the substance of the right to information.

Amendment 1129

Oliver Schenk

Proposal for a regulation

Article 3 – paragraph 1 – point 6 a (new)

Regulation (EU) 2016/679

Article 15 – paragraph 1 – last sentence

Present textAmendment
6a. In Article 15, paragraph 1, the following sentence is added:
1. The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information: (a) the purposes of the processing; (b) the categories of personal data concerned; (c) the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations; (d) where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period; (e) the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing; (f) the right to lodge a complaint with a supervisory authority; (g) where the personal data are not collected from the data subject, any available information as to their source; (h) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject."The right of access under this Article shall not extend to personal data which the data subject has created, authored, transmitted or received in the ordinary course of the relevant activity and which remain available to the data subject through the controller's systems or by other lawful means."

Or. en

(REGULATION (EU) 2016/679)

Amendment 1130

Axel Voss

Proposal for a regulation

Article 3 – paragraph 1 – point 6 a (new)

Regulation (EU) 2016/679

Article 14 – paragraph 1 – points fa and fb (new)

Present textAmendment
6a. In Article 14(1), the following points are added:
No equivalent"(fa) if the controller is a small, medium or large controller under Article 4(27) to (29), and;
(fb) if the controller is a large controller, the number of data subjects they processed personal data about, the number of times data subjects have exercised their rights against them under Articles 13 to 22 and the number of each type of outcome, the number of data breaches under Article 32 and the number of likely affected data subjects, the number of procedure filed against them under Article 78 and 79, the certifications received or revoked under Article 42 and the name and contact details of the certification body that has certified them for the past three financial years."

Or. en

Justification

RISK-BASED APPROACH #9: This package makes the GDPR’s risk-based approach practical by introducing objective categories for small, medium and large controllers. Small controllers with limited, non-core processing receive relief from selected administrative duties, while data-subject rights and enforcement remain intact. Very large controllers, gatekeepers and VLOPs/VLOSEs face stronger transparency, annual certification and closer supervision. Compliance effort is thus reduced where risks are low and increased where scale and systemic impact are greatest.

Amendment 1131

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller, Christophe Grudler

Proposal for a regulation

Article 3 – paragraph 1 – point 6 a (new)

Regulation (EU) 2016/679

Article 21 – paragraph 1

Text proposed by the CommissionAmendment
6a. In Article 21, paragraph 1 is replaced by the following:
'1. The data subject shall have the right to object, on grounds relating to his or her particular situation, notably where the data subject is a child, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1), including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.'

Or. en

Amendment 1132

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Andrea Wechsler, Oliver Schenk, Christian Ehler

Proposal for a regulation

Article 3 – paragraph 1 – point 6 a (new)

Regulation (EU) 2016/679

Article 13 – paragraph 4a (new)

Text proposed by the CommissionAmendment
6a. In Article 13, paragraph 4a is added:
'4a. The obligation to make information available pursuant to Article 13 shall be deemed fulfilled where such information is published and maintained in an easily accessible manner on the entity's website.'

Or. en

Amendment 1133

Angelika Niebler, Monika Hohlmeier

Proposal for a regulation

Article 3 – paragraph 1 – point 6 a (new)

Regulation (EU) 2016/679

Article 15 – paragraph 3

Text proposed by the CommissionAmendment
6a. Article 15, paragraph 3 is amended as follows:
3. The controller shall provide the data subject with a copy of the personal data undergoing processing; that copy shall be confined to the personal data as such.

Or. en

Amendment 1134

Kristian Vigenin

Proposal for a regulation

Article 3 – paragraph 1 – point 6 a (new)

Regulation (EU) 2016/679

Article 15 – paragraph 1 – point a

Text proposed by the CommissionAmendment
6a. In Article 15, paragraph 1 point (a) is amended as follows:
(a) the purposes of the processing as well as the legal basis for the processing;

Or. en

Amendment 1135

Nadine Morano

Proposal for a regulation

Article 3 – paragraph 1 – point 6 a (new)

Regulation (EU) 2016/679

Article 15 – paragraph 3

Present textAmendment
(Does not affect the English version.)
3. The controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs. Where the data subject makes his or her request by electronic means, and unless otherwise requested by the data subject, the information shall be provided in a commonly used electronic form.

Or. fr

(32016R0679)

Amendment 1136

Kristian Vigenin

Proposal for a regulation

Article 3 – paragraph 1 – point 6 b (new)

Regulation (EU) 2016/679

Article 14 – paragraph 3

Text proposed by the CommissionAmendment
6b. In Article 14, paragraph 3 is amended as follows:
3. The controller shall provide the information referred to in paragraphs 1 and 2 within a reasonable period after obtaining the personal data, having regard to the specific circumstances in which the personal data are processed.
If the personal data are to be used for communication with the data subject, the information referred to in paragraphs 1 and 2 has to be provided to the data subject at the latest at the time of the first communication to that data subject.
If a disclosure to another recipient is envisaged, the information referred to in paragraphs 1 and 2 has to be provided to the data subject at the latest when the personal data are first disclosed.
In any case, the information referred to in paragraphs 1 and 2 has to be provided to the data subject at the latest within one month.

Or. en

Amendment 1137

Angelika Niebler, Monika Hohlmeier

Proposal for a regulation

Article 3 – paragraph 1 – point 6 b (new)

Regulation (EU) 2016/679

Article 15 – paragraph 4

Text proposed by the CommissionAmendment
6b. Article 15, paragraph 4 is amended as follows:
4. The right of access referred to in paragraphs 1 and 2 and the right to obtain a copy referred to in paragraph 3 shall not affect the rights and freedoms of other persons, including the controller. Paragraph 3 shall not apply if and to the extent that the provision of the copy proves impossible or would require a disproportionate effort.

Or. en

Amendment 1138

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 7 – introductory part

Regulation (EU) 2016/679

Article 22

Text proposed by the CommissionAmendment
7. In Article 22, paragraphs 1 and 2 are replaced by the following:7. Article 22 is replaced by the following:

Or. en

Amendment 1139

Pernando Barrena Arza

Proposal for a regulation

Article 3 – paragraph 1 – point 7 – introductory part

Regulation (EU) 2016/679

Article 22

Text proposed by the CommissionAmendment
7. In Article 22, paragraphs 1 and 2 are replaced by the following:7. Article 22 is replaced by the following:

Or. en

Amendment 1140

Alex Agius Saliba

Proposal for a regulation

Article 3 – paragraph 1 – point 7 – introductory part

Regulation (EU) 2016/679

Article 22

Text proposed by the CommissionAmendment
7. In Article 22, paragraphs 1 and 2 are replaced by the following:7. Article 22 is replaced by the following:

Or. en

Amendment 1141

Birgit Sippel

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – paragraph 1

Text proposed by the CommissionAmendment
1. A decision which produces legal effects for a data subject or similarly significantly affects him or her may be based solely on automated processing, including profiling, only where that decision:deleted
(a) is necessary for entering into, or performance of, a contract between the data subject and a data controller regardless of whether the decision could be taken otherwise than by solely automated means;
(b) is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests; or
(c) is based on the data subject's explicit consent.

Or. en

Amendment 1142

Pernando Barrena Arza

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22

Text proposed by the CommissionAmendment
1. A decision which produces legal effects for a data subject or similarly significantly affects him or her may be based solely on automated processing, including profiling, only where that decision:1. Article 22 shall be replaced by the following:
The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
A decision shall be considered to be based solely on automated processing where automated processing materially determines the outcome and any human involvement is merely formal, symbolic, limited to validation, or does not include a genuine assessment of the individual case.
2. Paragraph 1 shall not apply only where the decision:
(a) is strictly necessary for entering into, or performance of, a contract between the data subject and the controller, and no less intrusive means reasonably available to the controller can achieve the same specific contractual purpose;
(b) is authorised by Union or Member State law to which the controller is subject, which respects the essence of the rights and freedoms of the data subject, is necessary and proportionate in a democratic society, and lays down suitable and specific measures to safeguard the data subject’s rights and freedoms and legitimate interests; or
(c) is based on the data subject’s explicit consent.
For the purposes of point (a), a decision shall not be considered strictly necessary merely because it is useful, efficient, economically advantageous, scalable, faster, more consistent, part of the controller’s business model, or capable of reducing costs. Commercial convenience, service optimisation, fraud prevention at scale, profiling, risk scoring, behavioural prediction or personalised pricing shall not, in themselves, constitute necessity.
3. In the cases referred to in paragraph 2, points (a) and (c), the controller shall implement suitable and specific measures to safeguard the data subject’s rights and freedoms and legitimate interests, including at least:
(a) the right to obtain meaningful human intervention on the part of the controller;
(b) the right to express their point of view before, or where this is not possible, without undue delay after, the decision is taken;
(c) the right to receive meaningful information about the main reasons for the decision, including the main categories of personal data relied upon, the use of profiling or inferred data, the key parameters, factors or criteria that materially influenced the decision, and, where relevant, their relative importance, as well as the steps available to correct inaccurate data, express their point of view and contest the decision;
(d) the right to contest the decision and obtain a fresh assessment by a human reviewer.
Human intervention shall be carried out by a person with the competence, information, time, resources and authority necessary to assess the individual case and to modify, reverse or otherwise change the decision. The human reviewer shall actively assess the relevant facts and shall not merely rely on, confirm or reproduce the output of the automated system.
Information provided pursuant to point (c) shall be sufficiently specific to allow the data subject to understand why the decision was taken in their individual case and to exercise their rights effectively. Controllers shall not rely on trade secrets, intellectual property or security considerations to refuse information that is necessary to understand the main reasons for the decision, without prejudice to proportionate measures to protect confidential information.
4. Decisions referred to in paragraph 2 shall not be based on special categories of personal data referred to in Article 9(1), unless Article 9(2), point (a) or point (g), applies and suitable and specific measures to safeguard the data subject’s rights and freedoms and legitimate interests are in place.
5. The controller shall document the assessment referred to in paragraph 2, point (a), the less intrusive means considered, including human-led or human-reviewed alternatives, and the measures implemented pursuant to paragraph 3. That documentation shall include the reasons why the decision is strictly necessary, the less intrusive alternatives considered, the organisation of human review, the competence and authority of reviewers, the information made available to them, and the number and proportion of decisions modified, reversed or otherwise changed following human intervention.
Where the processing is subject to a data protection impact assessment pursuant to Article 35, that assessment shall include an assessment of whether the same specific purpose can reasonably be achieved through less intrusive means, including human-led, human-reviewed or non-automated alternatives, and an assessment of the risks created by automation, profiling, inferred data and the organisation of human review.
The documentation shall be made available to the supervisory authority upon request. Where necessary to verify compliance with this Article, the supervisory authority may require access to relevant testing documentation, evaluation results and controlled testing environments, subject to appropriate confidentiality safeguards.

Or. en

Amendment 1143

João Oliveira

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – paragraph 1

Text proposed by the CommissionAmendment
1. A decision which produces legal effects for a data subject or similarly significantly affects him or her may be based solely on automated processing, including profiling, only where that decision:1. The data subject shall have the right not to be subject to any decision based solely on automated processing, including profiling, that produces legal effects concerning them or that similarly significantly affects them, unless that decision:

Or. pt

Amendment 1144

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – paragraph 1

Text proposed by the CommissionAmendment
1. A decision which produces legal effects for a data subject or similarly significantly affects him or her may be based solely on automated processing, including profiling, only where that decision:1. The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effect concerning them or similarly significantly affects them, unless such processing:

Or. en

Amendment 1145

Alex Agius Saliba

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – paragraph 1

Text proposed by the CommissionAmendment
1. A decision which produces legal effects for a data subject or similarly significantly affects him or her may be based solely on automated processing, including profiling, only where that decision:1. A decision which produces legal effects for a data subject or similarly significantly affects them shall not be based solely on automated processing, including profiling, unless that decision:

Or. en

Justification

Changes in line with EDPB-EDPS opinion, para. 66, in line with CJEU case law.

Amendment 1146

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – paragraph 1 – point a

Text proposed by the CommissionAmendment
(a) is necessary for entering into, or performance of, a contract between the data subject and a data controller regardless of whether the decision could be taken otherwise than by solely automated means;(a) is necessary for entering into, or performance of, a contract between the data subject and a data controller regardless of whether the decision could be taken otherwise than by solely automated means, when several equally effective automated processing solutions exist, the controller should use the less intrusive one when it does not result in a significant additional administrative burden for the controller;

Or. en

Amendment 1147

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – paragraph 2 – point a

Text proposed by the CommissionAmendment
(a) is necessary for entering into, or performance of, a contract between the data subject and a data controller regardless of whether the decision could be taken otherwise than by solely automated means;(a) is necessary for entering into, or performance of, a contract between the data subject and a data controller

Or. en

Amendment 1148

João Oliveira

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – paragraph 1 – point a

Text proposed by the CommissionAmendment
(a) is necessary for entering into, or performance of, a contract between the data subject and a data controller regardless of whether the decision could be taken otherwise than by solely automated means;(a) is necessary for entering into, or performance of, a contract between the data subject and a data controller;

Or. pt

Amendment 1149

Alex Agius Saliba

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulations (EU) 2016/679

Article 22 – paragraph 1 – point a

Text proposed by the CommissionAmendment
(a) is necessary for entering into, or performance of, a contract between the data subject and a data controller regardless of whether the decision could be taken otherwise than by solely automated means;(a) is necessary for entering into, or performance of, a contract between the data subject and a data controller;

Or. en

Justification

Moved to recital 38 as per EDPB-EDPS opinion, para. 72.

Amendment 1150

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – paragraph 1 – point a

Text proposed by the CommissionAmendment
(a) is necessary for entering into, or performance of, a contract between the data subject and a data controller regardless of whether the decision could be taken otherwise than by solely automated means;(a) is necessary for entering into, or performance of, a contract between the data subject and a data controller;

Or. en

Amendment 1151

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – paragraph 1 – point a

Text proposed by the CommissionAmendment
(a) is necessary for entering into, or performance of, a contract between the data subject and a data controller regardless of whether the decision could be taken otherwise than by solely automated means;(a) is necessary for entering into, or performance of, a contract between the data subject and a data controller;

Or. en

Amendment 1152

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – paragraph 1 – point c

Text proposed by the CommissionAmendment
(c) is based on the data subject's explicit consent.(c) is based on the data subject's explicit consent, provided that the data subject is not a child.

Or. en

Amendment 1153

Alex Agius Saliba

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulations (EU) 2016/679

Article 22 – paragraphs 2, 3, 4

Text proposed by the CommissionAmendment
(ca) 2. The data subject shall have the right not to be subject to a decision under Article 22(1) unless one of the conditions mentioned in letters (a) to (c) of that provision is met.
3. In the cases referred to in points (a) and (c) of paragraph 1, the data controller shall implement suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express their point of view and to contest the decision. Any human intervention on the part of the controller must be meaningful and the human must have the necessary knowledge and competences to comprehend and have the possibility to modify the contested decision.
4. Before a controller makes any decision under Article 22(1), it must ensure that the affected data subject is informed about the decision in accordance with Articles 13 or 14, and that, at the time of the decision, it has implemented suitable measures in accordance with Article 22(3).
5. Decisions referred to in paragraph 2 shall not be based on special categories of personal data referred to in Article 9(1), unless point (a) or (g) of Article 9(2) applies and suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests are in place.

Or. en

Amendment 1154

Tomas Tobé, Arba Kokalari, Jörgen Warborn

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – paragraph 1 – point ca (new)

Text proposed by the CommissionAmendment
(ca) is taken by an AI system which can be reviewed and overseen by a natural person before or after it takes effect, and where appropriate safeguards are in place;

Or. en

Amendment 1155

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – paragraph 1a (new)

Text proposed by the CommissionAmendment
1a. In Article 22, the following paragraph is inserted:
'1a. In the cases referred to in points (a), (b) and (c) of paragraph 1, the data controller shall implement suitable technical and organisational measures to safeguard the data subject's rights and freedoms and legitimate interests, at least the right to obtain genuine human intervention of the part of the controller, to express his or her point of view and to contest the decision taken, as referred to in paragraph 1. The human reviewer designated to perform such intervention shall possess the necessary competence, knowledge to understand all relevant underlining data, and shall be empowered to modify or override the decision without delay.'

Or. en

Amendment 1156

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – Paragraph 1a (new)

Text proposed by the CommissionAmendment
1a. In Article 22, the following paragraph is inserted:
'1a. The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.'

Or. en

Amendment 1157

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – paragraph 1b (new)

Text proposed by the CommissionAmendment
1b. In Article 22, the following paragraph is inserted:
'1b. Where a decision referred to in paragraph 1 is based on the output of a high-risk AI system within the meaning of Regulation (EU) 2024/1689, the measures referred to in point (b) of paragraph 1, and the safeguards accompanying a decision taken pursuant to points (a) and (c) thereof, shall be without prejudice to the human oversight requirements laid down in Article 14 of that Regulation. In particular, natural persons to whom human oversight is assigned shall be enabled to properly understand the capacities and limitations of the system, to correctly interpret its output, to remain aware of the risk of over-reliance on that output, and to decide not to use the system or to disregard, override or reverse its output. Automated processing shall not deprive the data subject of the right to obtain human intervention, to express his or her point of view and to contest the decision.'

Or. en

Justification

Decisions based solely on automated processing that produce legal effects or similarly significantly affect a data subject raise particular risks where they rely on the output of a high-risk AI system. This amendment clarifies that, in such cases, the safeguards under Article 22 are without prejudice to the human oversight requirements laid down in Article 14 of Regulation (EU) 2024/1689: the natural persons to whom oversight is assigned must be able to understand the system's capacities and limitations, to interpret its output correctly, to remain aware of the risk of over-reliance, and to disregard, override or reverse that output. It further recalls that automated processing may not deprive the data subject of the right to obtain human intervention, to express his or her point of view and to contest the decision. This ensures the coherence of the Union acquis by articulating the structural obligation of human oversight under the Artificial Intelligence Act with the individual right to human intervention under the General Data Protection Regulation.

Amendment 1158

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – paragraph 4

Text proposed by the CommissionAmendment
1b. 4. Decisions referred to in paragraph 1 shall not be based on special categories of personal data referred to in Article 9(1), unless point (a) or (g) of Article 9(2) applies and suitable technical and organisational measures to safeguard the data subject's rights and freedoms and legitimate interests are in place.

Or. en

Amendment 1159

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Andrea Wechsler, Henrik Dahl, Oliver Schenk, Pekka Toveri, Christian Ehler

Proposal for a regulation

Article 3 – paragraph 1 – point 7 a (new)

Regulation (EU) 2016/679

Article 25a (new)

Text proposed by the CommissionAmendment
7a. The following Article 25a is added:
'Article 25a
Privacy Enhancing Technologies
1. The Commission may adopt implementing acts to lay down technical specifications for Privacy Enhancing Technologies (PETs), including pseudonymisation, anonymisation and cryptographic techniques. These specifications shall serve to establish standardised technical and organisational measures that assist controllers and processors in ensuring and demonstrating that their data processing operations adhere to high data protection standards. ·
2. The implementing acts referred to in paragraph 1 may establish technical specifications regarding:
(a) Pseudonymisation and Anonymisation: standards for state-of-the-art cryptographic techniques that can effectively reduce or eliminate the linkability of personal data;
(b) Technical criteria for legal bases: specifications defining the technical parameters for assisting controllers in verifying whether the criteria for legal bases, including further processing, under Article 6(1) may be met;
(c) Risk-mitigation: technical standards controllers may use when assessing risks to the rights and freedoms of natural persons, including criteria for further simplified data protection impact assessments under Article 35(10); ·
(d) Security measures: technical specifications for state-of-the-art security measures, including end-to-end encryption and decentralised architectures, to ensure a level of security appropriate to the risk pursuant to Article 32. ·
(3) When preparing the implementing acts, the Commission shall, in accordance with Article 10 of Regulation (EU) No 1025/2012, mandate one or more European standardisation organisations to draw up harmonised standards for the types of standards referred to in paragraph 2. The European standardisation organisations shall, where appropriate, take into account existing international standards developed by international standardisation organisations, as well as emerging technical specifications developed by relevant industry consortia. The mandate shall specify a time limit of not more than 18 months from the date of the mandate. When drawing up the standardisation mandate, the Commission shall consult the European Data Protection Board and an advisory forum comprising representatives of industry, SMEs, consumer protection organisations, academia and civil society. The Commission shall condition such mandates on the standardisation organisations ensuring balanced representation and equal participation of industry, SMEs, consumer protection organisations, academia and civil society, and supervisory authorities within the technical committees, and shall provide financial support to facilitate their involvement. The Commission shall monitor the progress of the standardisation work and may, where necessary, initiate the preparation of common specifications in accordance with paragraph 7.
(4) The Commission shall closely involve the EDPB in the preparations of the implementing acts. The EPDB shall issue an opinion on the draft implementing acts within a deadline of 8 weeks as of the receipt of the draft from the Commission. Where data complies with the harmonised standards or parts thereof referred to in paragraph 2(a), the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, it shall be presumed that the data satisfies the criteria for effective pseudonymisation or anonymisation.
(5) Where data processing operations comply with the harmonised standards or parts thereof referred to in paragraph 2(b), (c) or (d), the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, it shall be presumed that the controller or processor has fulfilled the corresponding technical and organisational requirements of this Regulation covered by those standards, ·
(6) Controllers and processors relying on the presumption under paragraphs 4 or 5 shall document compliance with the relevant standards by means of appropriate evidence. The evidence shall include at minimum:
(a) technical documentation describing the implementation of the PET; ·
(b) a description of the parameters and configurations used to meet the standard requirements;
(c) results of tests and validations demonstrating the effectiveness of the PET;
(d) a risk analysis demonstrating that the PET reduces the risks to the rights and freedoms of data subjects to an appropriate level;
(e) in the case of pseudonymisation standards: evidence that the means to identify the data subject cannot reasonably be used.
(7) The Commission may adopt implementing acts laying down certification procedures and audit requirements for compliance with the standards referred to in paragraph 2. Such procedures may provide for:
(a) certification by accredited bodies;
(b) self-certification under certain conditions;
(c) regular audits by independent third parties;
(d) peer-review procedures for complex implementations. Certification pursuant to this paragraph shall be without prejudice to the documentation obligations laid down in paragraph 6. Where a controller or processor holds a valid certificate pursuant to this paragraph, the documentation requirements under paragraph 6 shall be considered fulfilled to the extent that the certificate covers the same technical elements.
(8) The Commission may adopt implementing acts laying down common specifications where:
(a) the Commission has mandated one or more European standardisation organisations to draw up harmonised standards for the purposes referred to in paragraph 2 and;
(i) the mandate was not accepted within 6 months from the date of the mandate or;
(ii) the harmonised standards were not drawn up within the time limit set or;
(iii) the harmonised standards do not comply with the mandate or do not sufficiently address concerns in relation to fundamental rights;
or (b) where, in view of the urgency of the matter or the need to ensure a high level of data protection, the Commission considers it necessary to adopt common specifications without awaiting the outcome of the standardisation process.
Common specifications adopted pursuant to this paragraph shall prevail over conflicting harmonised standards until such time as a reference to harmonised standards is published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012.
(9) The implementing acts referred to in paragraphs 1 and 7 shall take account of the state of the art, implementation costs, the nature, scope, context and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons resulting from the processing. They shall ensure that the technologies are open, non-discriminatory and interoperable.
(10) The Commission shall review regularly the need to update the implementing acts, taking into account technical progress and developments in international standards.
(11) The Implementing Acts shall be adopted in accordance with the examination procedure referred to in Article 93(3).'

Or. en

Amendment 1160

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller, Christophe Grudler

Proposal for a regulation

Article 3 – paragraph 1 – point 7 a (new)

Regulation (EU) 2016/679

Article 25 – paragraphs 1 and 2

Text proposed by the CommissionAmendment
7a. In Article 25, paragraph 1 and 2 are replaced by the following:
'1. Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects. In doing so, particular attention shall be paid to the protection of the rights of children.
2. The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons. The default settings shall take into account, in particular, the vulnerability of children.'

Or. en

Amendment 1161

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 3 – paragraph 1 – point 7 a (new)

Regulation (EU) 2016/679

Article 22 – paragraph 3

Text proposed by the CommissionAmendment
7a. In Article 22, paragraph 3 is replaced by the following:
3. In the cases referred to in points (a) and (c) of paragraph 1, the data controller shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, at least the right to obtain meaningful human intervention on the part of the controller, to express his or her point of view and to challenge the decision taken in their regard.
Meaningful human intervention, on the part of the controller, requires that the human reviewer reviews the accuracy of the data, the logic involved in the decision and the consequences of the decision, not merely the output of the system.
The human reviewer shall have the competence, training and authority necessary to exercise that function, including for overriding automated decisions. The human reviewer shall enjoy protection from dismissal or its equivalent, disciplinary measures and other adverse treatment where they exercise their functions.

Or. en

Justification

Sub-paragraph 3 based on Article 10(2) of the Platform Workers Directive (EU) 2024/2831.

Amendment 1162

Dario Nardella

Proposal for a regulation

Article 3 – paragraph 1 – point 7 a (new)

Regulation (EU) 2016/679

Article 22 – paragraph 3

Text proposed by the CommissionAmendment
7a. 3. In the cases referred to in points (a) and (c) of paragraph 2, the data controller shall apply suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, at least the right to obtain meaningful human intervention on the part of the controller, to express his or her point of view and to contest the decision. Human intervention is meaningful when the person in charge of the review has the requisite authority, knowledge and expertise to amend the contested decision and actively analyses the set of relevant data, going beyond the outcome produced by the system. In proceedings concerning access to agricultural credit, the setting of premiums for agricultural insurance policies and the disbursement of payments under the common agricultural policy, the person responsible for the review shall also possess the technical and agronomic expertise relevant to the proceedings in question.

Or. it

Justification

L'emendamento contribuisce alla riarticolazione dell'articolo 22, paragrafo 3, del regolamento (UE) 2016/679, che la proposta della Commissione non modifica, in coerenza con l'emendamento 53 del Draft Report, ma ne specifica le particolarità degli impatti sugli imprenditori agricoli europei. Alla qualificazione dell'intervento umano come significativo aggiunge il requisito della competenza tecnica e agronomica del revisore nei procedimenti che coinvolgono imprese agricole. La revisione umana di una decisione automatizzata sull'erogazione di un pagamento nell'ambito della politica agricola comune, sul merito creditizio agrario o sul premio di una polizza parametrica richiede, per essere effettiva, la conoscenza dei meccanismi di condizionalità, dei parametri agronomici e dei sistemi integrati di controllo. Il presente emendamento può essere depositato come emendamento autonomo al testo della proposta oppure come sub-emendamento all'emendamento 53 del Draft Report.

Amendment 1163

Francesco Torselli, Paolo Inselvini

Proposal for a regulation

Article 3 – paragraph 1 – point 7 a (new)

Regulation (EU) 2016/679

Article 22 – paragraph 3

Text proposed by the CommissionAmendment
7a. In the cases referred to in points (a) and (c) of paragraph 2, the data controller shall apply suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, at least the right to obtain meaningful human intervention on the part of the controller, to express his or her point of view and to contest the decision. Human intervention is meaningful when the person in charge of the review has the requisite authority, knowledge and expertise to amend the contested decision and actively analyses the set of relevant data, going beyond the outcome produced by the system. In proceedings concerning access to agricultural credit, the setting of premiums for agricultural insurance policies and the disbursement of payments under the common agricultural policy, the person responsible for the review shall also possess the technical and agronomic expertise relevant to the proceedings in question.

Or. it

Amendment 1164

Axel Voss

Proposal for a regulation

Article 3 – paragraph 1 – point 7 a (new)

Regulation (EU) 2016/679

Article 31 – paragraph 1a (new)

Present textAmendment
7a. In Article 31, the following paragraph is added:
No equivalent"1a. Large controllers shall report all information complied under Article 13(1f2) and 14(1f2) and the certification under Article 42, as well as any other information the supervisory authority may specify, to the supervisory authority at their main establishment or the main establishment of their representative under Article 27. The information shall be provided no later than one month after the end for their financial year in a machine-readable format specified by the supervisory authority. The supervisory authorities shall compile and keep up to date a public national list of all large controllers, including their address, contact details, number of data subjects processed in the last three financial years, the certification body that most recently certified them, number of procedures under Article 77 and 79 and a link to the information published under Article 13 and 14."

Or. en

Justification

RISK-BASED APPROACH #10: This package makes the GDPR’s risk-based approach practical by introducing objective categories for small, medium and large controllers. Small controllers with limited, non-core processing receive relief from selected administrative duties, while data-subject rights and enforcement remain intact. Very large controllers, gatekeepers and VLOPs/VLOSEs face stronger transparency, annual certification and closer supervision. Compliance effort is thus reduced where risks are low and increased where scale and systemic impact are greatest.

Amendment 1165

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 7 a (new)

Regulation (EU) 2016/679

Article 30 – Paragraph 1 – point ga (new)

Present textAmendment
7a. In Article 30, paragraph 1, the following point ga is added:
(new)"(ga) where personal data are collected from a third party, purchased, aggregated, enriched, sold or otherwise made available to third parties for commercial purposes, the categories of data providers and of data recipients, the categories of data concerned, the purposes pursued, the legal basis relied upon, and the elements demonstrating the lawful origin of the data and of their making available.
The identity of the providers and recipients concerned shall be retained by the controller and made available to the supervisory authority upon request."

Or. en

(32016R0679)

Amendment 1166

Pernando Barrena Arza

Proposal for a regulation

Article 3 – paragraph 1 – point 7 a (new)

Regulation (EU) 2016/679

Article 22 – paragraph 4a (new)

Text proposed by the CommissionAmendment
7a. In Article 22, the following paragraph 4a is added:
'4a. Without any prejudice to Article 35, any automated decision making under Article 22(1) of this Regulation that is likely to affect more than 100 data subjects per year shall be subject to a data protection impact assessment performed by the controller.'

Or. en

Justification

Automated individual decision-making under Article 22 GDPR will regularly trigger the obligation to perform a data protection impact assessment under Article 35 GDPR. However, this provision should introduce relatively hard factors triggering this obligation in cases of large-scale processing and processing of sensitive data in order to avoid situations in which a controller considers the requirements under Article 35 not to be met.

Amendment 1167

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Article 3 – paragraph 1 – point 7 a (new)

Regulation (EU) 2016/679

Article 23 – paragraph 1

Present textAmendment
7a. Article 23(1) is replaced by the following:
1. Union or Member State law to which the data controller or processor is subject may restrict by way of a legislative measure the scope of the obligations and rights provided for in Articles 12 to 22 and Article 34, as well as Article 5 in so far as its provisions correspond to the rights and obligations provided for in Articles 12 to 22, when such a restriction respects the essence of the fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to safeguard:"1. Union or Member State law to which the data controller or processor is subject may restrict by way of a legislative measure the scope of the obligations and rights provided for in Articles 12 to 22 and Article 34 and Chapter IXa, as well as Article 5 in so far as its provisions correspond to the rights and obligations provided for in Articles 12 to 22, when such a restriction respects the essence of the fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to safeguard:
(a)national security;(a)national security;
(b)defence;(b)defence;
(c)public security;(c)public security;
(d)the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security:(d)the prevention, investigation, detection or prosecution of criminal offences or of unauthorised use of the electronic communication system, or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security:
(e)other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, including monetary, budgetary and taxation a matters, public health and social security;(e)other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, including monetary, budgetary and taxation a matters, public health and social security;
(f)the protection of judicial independence and judicial proceedings;(f)the protection of judicial independence and judicial proceedings;
(g)the prevention, investigation, detection and prosecution of breaches of ethics for regulated professions;(g)the prevention, investigation, detection and prosecution of breaches of ethics for regulated professions;
(h)a monitoring, inspection or regulatory function connected, even occasionally, to the exercise of official authority in the cases referred to in points (a) to (e) and (g);(h)a monitoring, inspection or regulatory function connected, even occasionally, to the exercise of official authority in the cases referred to in points (a) to (e) and (g);
(i)the protection of the data subject or the rights and freedoms of others;(i)the protection of the data subject or the rights and freedoms of others;
(j)the enforcement of civil law claims.(j)the enforcement of civil law claims."

Or. en

(02016R0679-20160504)

Justification

This change is proposed due to other amendments tabled moving e-privacy provisions under Regulation (EU) 2016/679.

Amendment 1168

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Andrea Wechsler, Pekka Toveri, Christian Ehler

Proposal for a regulation

Article 3 – paragraph 1 – point 7 b (new)

Regulation (EU) 2016/679

Article 28 – paragraphs 3a, 3b, 3c (new) and paragraph 4

Text proposed by the CommissionAmendment
7b. In Article 28, the following paragraphs 3a, 3b and 3c are added and paragraph 4 is amended as follows:
'3a. By way of derogation from paragraph 3 and the general processor requirements therein, where a processor has been designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925, the processing shall instead be governed directly by this Regulation. Any such gatekeeper processor shall strictly adhere to the following obligations:
(a) processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the processor is subject; in such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;
(b) ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
(c) takes all measures required pursuant to Article 32;
(d) respects the conditions referred to in paragraphs 2 and 4 for engaging another processor;
(e) taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller’s obligation to respond to requests for exercising the data subject’s rights laid down in Chapter III;
(f) assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 taking into account the nature of processing and the information available to the processor;
(g) at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data;
(h) makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
With regard to point (h) of the first subparagraph, the processor shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation or other Union or Member State data protection provisions.
3b. A controller that is using a gatekeeper as a processor may form a contract or other legal act under Union or Member State law, that is binding on the gatekeeper processor and that sets out further details, like the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. Such contracts shall not contain terms that are unfair or limit the rights of the controllers under this Regulation.
3c. A contractual term shall be regarded as unfair if it requires undue extra payment for the exercise of rights of the controller, limits the rights of the controller to enforce the contract or otherwise legally, factually or economically interferes with the rights of controllers under this Regulation. The European Commission shall specify further terms of a contract that are regarded as unfair in accordance with the examination procedure referred to in Article 93(2).
4. Where a processor engages another processor for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in paragraph 3 to 3c shall apply or, if this Regulation does not apply to them directly, be imposed on that other processor by way of a contract or other legal act under Union or Member State law and jurisdiction, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of this Regulation. Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor’s obligations.'

Or. en

Amendment 1169

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 7 b (new)

Regulation (EU) 2016/679

Article 29a (new)

Present textAmendment
7b. The following article is added:
(new)"Article 29a
Application of pseudonymisation and identification of a natural person :
1. Controllers and processors may apply pseudonymisation in order to reduce the risks to the data subjects concerned and to comply with their obligations under this Regulation, in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information. The Commission may adopt implementing acts to specify means and criteria to determine whether a natural person is identifiable, including through personal data having undergone data resulting from pseudonymisation, account shall be taken of all the means reasonably likely to be used, such as singling out or online identifiers, either by the controller or by another person to identify the natural person directly or indirectly no longer constitutes personal data for certain entities.
2. The application of pseudonymisation to personal data may, depending on the circumstances of the case and provided that appropriate technical and organisational measures are put in place and are such as to prevent the data in question from being attributed to the data subject, effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable.
3. Where a person other than the controller referred to in paragraph 2 discloses, transmits or otherwise makes such data available to a third party and it cannot be ruled out that this third party possesses or can obtain means reasonably likely to enable the data subject to be identified, both the transmission of the data to this third party and the subsequent processing of the data by this third party is to be considered as processing of data relating to an identifiable natural person."

Or. en

(32016R0679)

Amendment 1170

Axel Voss

Proposal for a regulation

Article 3 – paragraph 1 – point 7 b (new)

Regulation (EU) 2016/679

Article 25 – paragraphs 3a, 3b (new)

Present textAmendment
7b. In Article 25, the following paragraphs are added:
No equivalent"3a. Where personal data processing under paragraph 2 is carried out exclusively by means of Privacy-Enhancing Technologies certified pursuant to paragraph 4, the data controller shall benefit from a rebuttable presumption of compliance with the data minimisation principle under Article 5(1)(c) of Regulation (EU) 2016/679 in respect of that processing. All other obligations under Regulation (EU) 2016/679 shall continue to apply.
3b. The Commission shall be empowered to adopt delegated acts recognising Privacy-Enhancing Technologies (PETs) and establishing the technical standards and criteria for Privacy-Enhancing Technologies eligible for certification under paragraph 3, following the governance model established in Article 41a of Regulation (EU) 2016/679. Those delegated acts shall be adopted in accordance with the examination procedure and following consultation with relevant authorities as appropriate. Standards shall include benchmarks to prevent misuse of PET certification for data practices that do not genuinely meet minimum privacy thresholds."

Or. en

Justification

Certified PETs make data protection by design operational. Technologies such as differential privacy, homomorphic encryption, synthetic data and robust pseudonymisation reduce identifiability and support data minimisation while enabling data-driven innovation and AI. A rebuttable presumption under Article 5(1)(c) creates a real incentive to deploy certified PETs without exempting controllers from other GDPR duties. Commission-set, technology-neutral standards and benchmarks prevent PET-washing and support interoperable European privacy infrastructure.

Amendment 1171

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 3 – paragraph 1 – point 7 b (new)

Regulation (EU) 2016/679

Article 24 – paragraph 4

Text proposed by the CommissionAmendment
7b. In Article 24, paragraph 4 is added:
‘4. The manufacturer shall design and develop its products, services and applications, taking into account the right to the protection of personal data and the state of the art, in such a manner that controllers and processors using those products, services and applications for the processing of personal data are able to comply with their obligations under this Regulation based on the default settings and without having to make disproportionate modifications to those products, services and applications. The manufacturer shall support controllers and processors in fulfilling their obligations under Articles 30, 33 and 34 by providing, upon request, all information necessary for that purpose.
This paragraph does not apply to free and open-source software that is developed or supplied outside the course of a commercial activity.‘

Or. en

Justification

Exception for non-commercial free and open-source software from Article 2(2) of the Product Liability Directive (EU) 2024/2853.

Amendment 1172

Pernando Barrena Arza

Proposal for a regulation

Article 3 – paragraph 1 – point 7 b (new)

Regulation (EU) 2016/679

Article 22 – paragraph 4a (new)

Text proposed by the CommissionAmendment
7b. In Article 22, the following paragraph 4a is added:
'4a. For any processing operation that is likely to entail automated individual decision making affecting and the profiling of more than 1000 data subjects per year, the controller must be able to demonstrate that the methodology used for the profiling and decision making are based on scientifically recognised mathematical and statistical methods and do not cause any unlawful discrimination. Information demonstrating these facts must be made publicly available by the controller.'

Or. en

Justification

In order to ensure that the automated individual decision-making affecting vast amounts of data subjects is compatible with the principle of fairness, controllers should be obliged to demonstrate that the methodologies used are based on scientifically recognised mathematical and statistical methods and non-discriminatory.

Amendment 1173

Axel Voss

Proposal for a regulation

Article 3 – paragraph 1 – point 7 c (new)

Regulation (EU) 2016/679

Article 25 – paragraph 2a (new)

Present textAmendment
7c. In Article 25, the following paragraph 2a is added:
No equivalent"2a. In the case of processing carried out in the course of providing information society services which are likely to be accessed by children, when assessing what are appropriate technical and organisational measures in accordance with paragraph 1, the controller must take into account the children’s higher protection matters. The children’s higher protection matters are:
(a) how children can best be protected and supported when using the services, and;
(b) the fact that children:
(i) merit specific protection with regard to their personal data because they may be less aware of the risks and consequences associated with processing of personal data and of their rights in relation to such processing; and
(ii) have different needs at different ages and at different stages of development.
This paragraph is not to be read as implying anything about the matters that may be relevant to the assessment of what are appropriate technical and organisational measures for the purposes of paragraph 1 and 2 in cases other than those described in this paragraph. In this paragraph “information society services” does not include preventive or counselling services."

Or. en

Justification

The amendment makes children’s higher protection needs a concrete part of data protection by design for information society services likely to be accessed by children. Controllers must consider how children can best be protected and supported, including their lower awareness of risks and their different needs at different ages and development stages. This creates clearer duties without a one-size-fits-all model, preserves other Article 25 assessments and excludes preventive or counselling services.

Amendment 1174

Axel Voss

Proposal for a regulation

Article 3 – paragraph 1 – point 7 d (new)

Regulation (EU) 2016/679

Article 28

Present textAmendment
7d. Article 28 is amended as follows:
1. Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject."1. Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.
2. The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes.2. Where the processor engages further processors, the processor shall always inform the controller of any intended change relating to the engagement or replacement of other processors, thereby giving the controller the opportunity to object to such changes.
3. Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. That contract or other legal act shall stipulate, in particular, that the processor:3. Where the processing of personal data takes place under an agreement with the controller which specifies the subject matter and duration of the processing, the nature and purpose of the processing, the types of data to be processed and the categories of data subjects (processing on behalf of the controller), the processor may process the personal data only for the purposes of carrying out the contract or in accordance with other documented instructions from the controller — including in relation to the transfer of personal data to a third country or an international organisation — unless the processor is obliged to do so by Union or Member State law to which the processor is subject; in such a case, the processor shall inform the controller of those legal requirements prior to processing, unless the law in question prohibits such notification on grounds of an important public interest. The data processor shall ensure:
(a) processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the processor is subject; in such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;(a) that persons authorised to process personal data have undertaken to maintain confidentiality or are subject to an appropriate statutory duty of confidentiality;
(b) ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;(b) that all measures necessary for the performance of the contract, as set out in Article 32, are taken;
(c) takes all measures required pursuant to Article 32;(c) that the conditions set out in paragraphs 2 and 4 regarding the use of the services of a further processor are complied with;
(d) respects the conditions referred to in paragraphs 2 and 4 for engaging another processor;The processor shall assist the controller in:
(e) taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III;(a) fulfilling the controller’s obligations to respond to requests for the exercise of the data subject’s rights referred to in Chapter III, where possible by taking appropriate technical and organisational measures, taking into account the nature of the processing;
(f) assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 taking into account the nature of processing and the information available to the processor;(b) to comply with the controller’s obligations set out in Articles 32 to 36, taking into account the nature of the processing and the information available to the controller.
(g) at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data;The processor is obliged:
(h) makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.(a) upon completion of the processing operations, to either erase or return all personal data, at the choice of the controller, unless there is an obligation under Union law or the law of the Member States to retain the personal data;
With regard to point (h) of the first subparagraph, the processor shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation or other Union or Member State data protection provisions.(b) to provide the controller with all necessary information to demonstrate compliance with the obligations laid down in this Article, and to allow for and cooperate with audits – including inspections – carried out by the controller or another auditor mandated by the controller.
4. Where a processor engages another processor for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in the contract or other legal act between the controller and the processor as referred to in paragraph 3 shall be imposed on that other processor by way of a contract or other legal act under Union or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of this Regulation. Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to thecontroller for the performance of that other processor's obligations.With regard to paragraph 4(b), the processor shall inform the controller without delay if it considers that an instruction infringes this Regulation or other data protection provisions of the Union or the Member States.
5. Adherence of a processor to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate sufficient guarantees as referred to in paragraphs 1 and 4 of this Article.4. Where the processor engages the services of another processor to carry out specific processing activities on behalf of the controller, the following shall apply to that other processor:
6. Without prejudice to an individual contract between the controller and the processor, the contract or the other legal act referred to in paragraphs 3 and 4 of this Article may be based, in whole or in part, on standard contractual clauses referred to in paragraphs 7 and 8 of this Article, including when they are part of a certification granted to the controller or processor pursuant to Articles 42 and 43.(a) the obligations set out in paragraph 3 shall apply mutatis mutandis or, where this Regulation does not apply to that processor pursuant to Articles 2 and 3,
7. The Commission may lay down standard contractual clauses for the matters referred to in paragraph 3 and 4 of this Article and in accordance with the examination procedure referred to in Article 93(2).(b) by means of a contract or other legal instrument under Union law or the law of the Member State concerned, the same data protection obligations as those laid down between the controller and the processor in accordance with paragraph 3, whereby, in particular, sufficient safeguards must be provided to ensure that the appropriate technical and organisational measures are implemented so that the processing is carried out in accordance with the requirements of this Regulation. If the sub-processor fails to fulfil its data protection obligations, the first processor shall be liable to the controller for the fulfilment of the obligations of that sub-processor .
8. A supervisory authority may adopt standard contractual clauses for the matters referred to in paragraph 3 and 4 of this Article and in accordance with the consistency mechanism referred to in Article 63.5. Adherence of a processor to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate sufficient guarantees as referred to in paragraphs 1 and 4 of this Article.
Paragraph 6, 7, and 8 are deleted.
9. The contract or the other legal act referred to in paragraphs 3 and 4 shall be in writing, including in electronic form.
10. Without prejudice to Articles 82, 83 and 84, if a processor infringes this Regulation by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing.
10a. Notwithstanding paragraph 3, the agreement between the controller and the processor need not specify the nature and purpose of the processing, the types of data to be processed and the categories of data subjects, as required by the first sentence of paragraph 3, if
(a) the processor provides a binding assurance as to the level of protection to which it is able to ensure the security of the processing and its obligation to assist the controller in accordance with the third sentence by means of appropriate technical and organisational measures; and
(b) the controller confirms the suitability of these safeguards for the processing operations it intends to carry out (infrastructure processing).
Paragraph 2 shall not apply in the context of infrastructure data processing insofar as:
(a) data transfers to further processors are envisaged on the basis of Article 45 or safeguards pursuant to Article 46(2)(b), (e) and (f), and enforceable rights and effective remedies are available to data subjects; and
(b) the first processor undertakes to the controller and the data subjects to assume liability for compliance with the obligations of the subsequent processors."

Or. en

(Regulation (EU) 2016/679)

Justification

Article 28 should better reflect modern cloud, hosting, security and infrastructure services, which are standardised, layered and technically complex. For such infrastructure processing, controllers need enforceable assurances on security, assistance and downstream liability, not bespoke descriptions of every technical sub-operation. The amendment cuts formalistic contract burdens while preserving core duties: confidentiality, security, assistance, deletion or return, audits, controller suitability checks and processor liability for sub-processors.

Amendment 1175

Axel Voss

Proposal for a regulation

Article 3 – paragraph 1 – point 7 e (new)

Regulation (EU) 2016/679

Article 28

Present textAmendment
7e. Article 28 is replaced by the following:
Article 28 GDPR"Article 28 GDPR
ProcessorProcessor
1. Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.1. Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.
2. The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes.2. The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes.
3. Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. That contract or other legal act shall stipulate, in particular, that the processor:3. Any processor shall:
(a) processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the processor is subject; in such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;(a) processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the processor is subject; in such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;
(b) ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;(b) ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
(c) takes all measures required pursuant to Article 32;(c) takes all measures required pursuant to Article 32;
(d) respects the conditions referred to in paragraphs 2 and 4 for engaging another processor;(d) respects the conditions referred to in paragraphs 2 and 4 for engaging another processor;
(e) taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller’s obligation to respond to requests for exercising the data subject’s rights laid down in Chapter III;(e) taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller’s obligation to respond to requests for exercising the data subject’s rights laid down in Chapter III;
(f) assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 taking into account the nature of processing and the information available to the processor;(f) assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 taking into account the nature of processing and the information available to the processor;
(g) at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data;(g) at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data;
(h) makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.(h) makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
With regard to point (h) of the first subparagraph, the processor shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation or other Union or Member State data protection provisions.With regard to point (h) of the first subparagraph, the processor shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation or other Union or Member State data protection provisions.
4. Where a processor engages another processor for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in the contract or other legal act between the controller and the processor as referred to in paragraph 3 shall be imposed on that other processor by way of a contract or other legal act under Union or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of this Regulation. 2Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor’s obligations.3a. A controller may from a contract or other legal act under Union or Member State law, that is binding on the processor and that sets out further details, like the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. Such contracts shall not contain terms that are unfair or limit the rights and role of the controllers under this Regulation.
5. Adherence of a processor to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate sufficient guarantees as referred to in paragraphs 1 and 4 of this Article.3b. A contractual term shall be regarded as unfair and void if it requires undue extra payment for the exercise of rights of the controller, limits the rights of the controller to enforce the contract or otherwise legally, factually or economically interferes with the rights of controllers under this Regulation. The European Commission may specify further terms of a contract that are regarded as unfair in accordance with the examination procedure referred to in Article 93(2).
6. Without prejudice to an individual contract between the controller and the processor, the contract or the other legal act referred to in paragraphs 3 and 4 of this Article may be based, in whole or in part, on standard contractual clauses referred to in paragraphs 7 and 8 of this Article, including when they are part of a certification granted to the controller or processor pursuant to Articles 42 and 43.4. Where a processor engages another processor for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in paragraph 3 to 3b shall apply or, if this Regulation does not apply to them directly, be imposed on that other processor by way of a contract or other legal act under Union or Member State law and at least the jurisdiction of a Member State, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of this Regulation. Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor’s obligations.
7. The Commission may lay down standard contractual clauses for the matters referred to in paragraph 3 and 4 of this Article and in accordance with the examination procedure referred to in Article 93(2).5. Adherence of a processor to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate sufficient guarantees as referred to in paragraphs 1 and 4 of this Article.
8. A supervisory authority may adopt standard contractual clauses for the matters referred to in paragraph 3 and 4 of this Article and in accordance with the consistency mechanism referred to in Article 63.6. Without prejudice to an individual contract between the controller and the processor, the contract or the other legal act referred to in paragraphs 3 and 4 of this Article may be based, in whole or in part, on standard contractual clauses referred to in paragraphs 7 and 8 of this Article, including when they are part of a certification granted to the controller or processor pursuant to Articles 42 and 43.
9. The contract or the other legal act referred to in paragraphs 3 and 4 shall be in writing, including in electronic form.7. The Commission may lay down standard contractual clauses for the matters referred to in paragraph 3 and 4 of this Article and in accordance with the examination procedure referred to in Article 93(2).
10. Without prejudice to Articles 82, 83 and 84, if a processor infringes this Regulation by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing.8. A supervisory authority may adopt standard contractual clauses for the matters referred to in paragraph 3 and 4 of this Article and in accordance with the consistency mechanism referred to in Article 63.
9. The contract or the other legal act referred to in paragraphs 3 and 4 shall be in writing, including in electronic form.
10. Without prejudice to Articles 82, 83 and 84, if a processor infringes this Regulation by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing."

Or. en

(Regulation (EU) 2016/679)

Justification

Alternative to other Art 28 proposal. Attempts also to shift burdens from SMEs to large processors, hyperscalers and software producers. This change would make the duties directly applicable to processors, removing the need for millions of B2B contracts.

Amendment 1176

Markus Buchheit

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point a

Regulation (EU) 2016/679

Article 33 – paragraph 1

Text proposed by the CommissionAmendment
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the competent supervisory authority. Notifications pursuant to this Article shall be made to the competent supervisory authority of the Member State in which the controller is established or where the personal data breach has occurred. The use of any Union-level technical reporting tools or single-entry points shall remain voluntary and shall be limited to personal data breaches with clear cross-border or Union-wide systemic relevance, without prejudice to national notification channels.

Or. en

Amendment 1177

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point a

Regulation (EU) 2016/679 (GDPR)

Article 33 – Paragraph 1

Text proposed by the CommissionAmendment
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via their national single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay. Controllers shall continue to document non-notified breaches, including the facts relating to the personal data breach, its effects and the remedial action taken.

Or. en

Justification

The controller documents every personal data breach, including those which are not notified. The documentation comprises the facts relating to the breach, its effects and the remedial action taken, and enables the supervisory authority to verify compliance in the course of an inspection.

Amendment 1178

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller, Christophe Grudler

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point a

Regulation (EU) 2016/679

Article 33 – paragraph 1

Text proposed by the CommissionAmendment
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.1. In the case of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, in which case particular consideration shall be given to the risk to children, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.

Or. en

Amendment 1179

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point a

Regulation (EU) 2016/679

Article 33 – paragraph 1

Text proposed by the CommissionAmendment
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the national entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.

Or. en

Amendment 1180

Niels Flemming Hansen

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point a

Regulation (EU) 2016/679

Article 33 paragraph 1

Text proposed by the CommissionAmendment
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.

Or. en

Amendment 1181

Henrik Dahl

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point a

Regulation (EU) 2016/679

Article 33 – paragraph 1

Text proposed by the CommissionAmendment
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the national entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.

Or. en

Amendment 1182

Francesco Torselli

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point a

Regulation (EU) 2016/679

Article 33 – paragraph 1

Text proposed by the CommissionAmendment
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than four working days after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within four working days, it shall be accompanied by reasons for the delay.
(We do not intend to propose to change the timing which remains exactly the same, but only to express it in working days, therefore starting from Monday in the event that an accident occurs on Saturday or Sunday.)

Or. en

Amendment 1183

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point a

Regulation (EU) 2016/679

Article 33 – paragraph 1

Text proposed by the CommissionAmendment
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.1. In the case of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.

Or. en

Amendment 1184

Pernando Barrena Arza

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point a

Regulation (EU) 2016/679

Article 33 – paragraph 1

Text proposed by the CommissionAmendment
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.1. In the case of a personal data breach that is likely to result in an increased risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.

Or. en

Justification

The threshold for the obligation to notify the supervisory authority should be lower that the threshold to communicate a personal data breach to the data subject, since controllers generally are incentivised to avoid the communication of a personal data breach to the affected data subject. This tendency to avoid such communication could influence the respective assessment by the controller. While it makes sense to increase the threshold and avoid that supervisory authorities are swamped with personal data breach notifications regarding every incident, it is important that the supervisory authority is informed about the more severe incidents and can also re-asses the controllers risk assessment. In such cases, the supervisory authority could require the controller to communicate the personal data breach to the affected data subjects even if the controller’s initial assessment result in no high risk. This process is stipulated in Article 33(4) GDPR which would basically lose its purpose in case the threshold of Article 33 (notification of a personal data breach to the supervisory authority) would be increased to the threshold of Article 34 GDPR (communication of a personal data breach to the data subjects).

Amendment 1185

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point a

Regulation (EU) 2016/679

Article 33 – paragraph 1

Text proposed by the CommissionAmendment
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.

Or. en

Amendment 1186

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point a

Regulation (EU) 2016/679

Article 33 – paragraph 1

Text proposed by the CommissionAmendment
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.

Or. en

Justification

NIS2, where the single-entry point is established, also only has 72 hours. One aim of simplification is to have harmonised rules.

Amendment 1187

Alex Agius Saliba

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point a

Regulation (EU) 2016/679

Article 33 – paragraph 1

Text proposed by the CommissionAmendment
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.1. In the case of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.

Or. en

Amendment 1188

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point a

Regulation (EU) 2016/679

Article 33 – paragraph 1

Text proposed by the CommissionAmendment
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.1. In the case of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.

Or. en

Amendment 1189

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point b

Regulation (EU) 2016/679

Article 33 – Paragraph 1a

Text proposed by the CommissionAmendment
(b) the following paragraph is added:deleted
‘1a. Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.’

Or. en

Amendment 1190

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point b

Regulation (EU) 2016/679

Article 33 – Paragraph 1a

Text proposed by the CommissionAmendment
1a. Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.deleted

Or. en

Amendment 1191

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point c

Regulation (EU) 2016/679

Article 33 – Paragraph 6

Text proposed by the CommissionAmendment
6. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).6. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The common template shall include fields enabling the controller to describe any privacy-enhancing measures relevant to the breach, including encryption, pseudonymisation, federated or local processing, confidential computing, access controls, logging, and measures taken to prevent model memorisation, regurgitation, or unauthorised disclosure. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). Where the Commission departs from the proposal submitted by the Board, it shall state the reasons for doing so. Those reasons shall be made publicly available together with the implementing act.

Or. en

Amendment 1192

Oliver Schenk, Axel Voss, Ana Miguel Pedro, Romana Tomc, Marion Walsmann, Lena Düpont, Marie-Sophie Lanig, Andrea Wechsler, Angelika Niebler, Monika Hohlmeier, Eva Maydell, Dimitris Tsiodras, Christian Doleschal, François-Xavier Bellamy

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point c

Regulation (EU) 2016/679

Article 33 – paragraph 6

Text proposed by the CommissionAmendment
6. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).6. The Board shall establish and make public common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk.. The template and lists shall be available to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 7. The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.’

Or. en

Amendment 1193

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point c

Regulation (EU) 2016/679

Article 33 – paragraph 6

Text proposed by the CommissionAmendment
6. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).6. 6. The Board shall establish and make public common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a risk to the rights and freedoms of a natural person. The template and the list shall be available [OP date = nine months of the entry into application of this Regulation].

Or. en

Amendment 1194

Tomas Tobé, Arba Kokalari, Jörgen Warborn

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point c

Regulation (EU) 2016/679

Article 33 – paragraph 6

Text proposed by the CommissionAmendment
6. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).6. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). This shall not go beyond existing obligations under this Regulation or mandate any retroactive obligations.

Or. en

Amendment 1195

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point c

Regulation (EU) 2016/679

Article 33 – paragraph 6

Text proposed by the CommissionAmendment
6. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).6. By …[PO please insert date: nine months from the entry into application of this amending Regulation] the Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The Commission is empowered to decide that the template and the list have general validity within the Union by way of an implementing act in accordance with the examination procedure set out in Article 93(2).

Or. en

Justification

modeled after Article 40(9) GDPR on the Codes of Conduct

Amendment 1196

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point c

Regulation (EU) 2016/679

Article 33 – paragraph 6

Text proposed by the CommissionAmendment
6. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).6. The Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is not likely to result in a risk to the rights and freedoms of a natural person under paragraph 1. The template and list shall be published within [OP date = nine months of the entry into application of this Regulation]. The Commission may adopt the template as established by the Board by way of an implementing act in accordance with the examination procedure set out in Article 93(2).

Or. en

Amendment 1197

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point c

Regulation (EU) 2016/679

Article 33 – paragraph 7

Text proposed by the CommissionAmendment
7. The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.7. The template and the list referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary.

Or. en

Amendment 1198

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point c

Regulation (EU) 2016/679

Article 33 – Paragraph 7

Text proposed by the CommissionAmendment
7. The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.7. The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6. Where the Commission departs from the Board's proposals for updates, it shall state the reasons for doing so, and those reasons shall be made publicly available together with the adopted updates.

Or. en

Amendment 1199

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point c

Regulation (EU) 2016/679

Article 33 – paragraph 7

Text proposed by the CommissionAmendment
7. The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.7. The template and the list referred to in paragraph 6 shall be reviewed and updated where necessary. The Board shall publish, where necessary, any updates of the template and the list in due time. The Commission is empowered to decide that the updated template and list have general validity within the Union following the procedure in paragraph 6.

Or. en

Justification

modeled after Article 40(9) GDPR on Codes of Conduct

Amendment 1200

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point c

Regulation (EU) 2016/679

Article 33 – paragraph 7a (new)

Text proposed by the CommissionAmendment
7a. In Article 33, the following paragraph 7a is inserted:
'7a. The Commission may adopt the template and any updates as referred to in paragraph 6 and 7, as established by the Board, by way of an implementing act following the examination procedure set out in Article 93(2).'

Or. en

Amendment 1201

Angelika Niebler, Monika Hohlmeier

Proposal for a regulation

Article 3 – paragraph 1 – point 8 a (new)

Regulation (EU) 2016/679

Article 34 – paragraph 2

Text proposed by the CommissionAmendment
8a. Article 34, paragraph 2 is amended as follows:
2. The communication to the data subject referred to in paragraph 1 of this Article shall describe in clear and plain language the nature of the personal data breach and contain at least the information and measures referred to in points (b), (c) and (d) of Article 33(3) and, where possible, the categories of personal data records concerned.

Or. en

Amendment 1202

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Article 3 – paragraph 1 – point 8 a (new)

Regulation (EU) 2016/679

Article 34

Present textAmendment
8a. Article 34 is replaced by the following:
Communication of a personal data breach to the data subject"Communication of a personal data breach to the data subject
1. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.1. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.
2. The communication to the data subject referred to in paragraph 1 of this Article shall describe in clear and plain language the nature of the personal data breach and contain at least the information and measures referred to in points (b), (c) and (d) of Article 33(3).2. The communication to the data subject referred to in paragraph 1 of this Article shall describe in clear and plain language the nature of the personal data breach and contain at least the information and measures referred to in points (b), (c) and (d) of Article 33(3).
3. The communication to the data subject referred to in paragraph 1 shall not be required if any of the following conditions are met:(a)the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;(b)the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects referred to in paragraph 1 is no longer likely to materialise;(c)it would involve disproportionate effort. In such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.3. The communication to the data subject referred to in paragraph 1 shall not be required if any of the following conditions are met:(a)the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;(b)the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects referred to in paragraph 1 is no longer likely to materialise;(c)it would involve disproportionate effort. In such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.
4. If the controller has not already communicated the personal data breach to the data subject, the supervisory authority, having considered the likelihood of the personal data breach resulting in a high risk, may require it to do so or may decide that any of the conditions referred to in paragraph 3 are met.4. If the controller has not already communicated the personal data breach to the data subject, the supervisory authority, having considered the likelihood of the personal data breach resulting in a high risk, may require it to do so or may decide that any of the conditions referred to in paragraph 3 are met.
4a. The Board shall establish and make public a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person under paragraph 1."

Or. en

(02016R0679-20160504)

Amendment 1203

Pernando Barrena Arza

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 4

Text proposed by the CommissionAmendment
4. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.4. By … [nine months from the entry into application of this amending Regulation], the Board shall establish and make public:
(a) a Union-level list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1;
(b) a Union-level list of the kind of processing operations for which no data protection impact assessment is required;
(c) a common template and a common methodology for conducting data protection impact assessments.
The lists referred to in points (a) and (b) shall support the consistent application of this Regulation and shall not prevent supervisory authorities from establishing and making public additional lists of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1, where such processing operations are likely to result in a high risk in the context of the Member State concerned.

Or. en

Amendment 1204

Niels Flemming Hansen

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 4

Text proposed by the CommissionAmendment
4. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.4. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. In preparing its proposal, the Board shall take due account of the lists established and made public by supervisory authorities and relevant guidance of the Board, and shall ensure that its proposal reflects a consistent and proportionate approximation of the common elements of those lists, focusing on processing operations most likely to result in high risk. Newly identified triggers shall apply prospectively to new processing or materially changed processing.

Or. en

Justification

Reducing fragmentation and legal uncertainty while ensuring that compliance requirements remain proportionate and focused on genuinely high-risk activities should be at the core of the Digital Omnibus, in order to avoid unnecessary burdens for SMEs.

Amendment 1205

Krzysztof Hetman, Adam Jarubas

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 4

Text proposed by the CommissionAmendment
4. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.4. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. In preparing its proposal, the Board shall take due account the lists of processing operations established and made public by supervisory authorities and shall ensure that its proposal reflects a consistent and proportionate approximation of the processing operations identified in those lists, taking into account the principle of legal certainty.

Or. en

Amendment 1206

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 4

Text proposed by the CommissionAmendment
4. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.

Or. en

Amendment 1207

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 4

Text proposed by the CommissionAmendment
4. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.4. The Board shall prepare and publish a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.

Or. en

Amendment 1208

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 4

Text proposed by the CommissionAmendment
4. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.

Or. en

Amendment 1209

Oliver Schenk, Axel Voss, Marie-Sophie Lanig, Marion Walsmann, Lena Düpont, Ana Miguel Pedro, Andrea Wechsler, Angelika Niebler, Monika Hohlmeier, Dimitris Tsiodras, Christian Doleschal, Romana Tomc, François-Xavier Bellamy

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 4

Text proposed by the CommissionAmendment
4. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.

Or. en

Amendment 1210

Sibylle Berg, Martin Sonneborn

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 4

Text proposed by the CommissionAmendment
4. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.4. The Board shall prepare and publish a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.

Or. de

Amendment 1211

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 5

Text proposed by the CommissionAmendment
5. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.

Or. en

Amendment 1212

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 4

Text proposed by the CommissionAmendment
5. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.5. The Board shall prepare and publish a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.

Or. en

Amendment 1213

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 5

Text proposed by the CommissionAmendment
5. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.

Or. en

Amendment 1214

Oliver Schenk, Axel Voss, Marie-Sophie Lanig, Ana Miguel Pedro, Lena Düpont, Marion Walsmann, Romana Tomc, Andrea Wechsler, Angelika Niebler, Monika Hohlmeier, Dimitris Tsiodras, Christian Doleschal, François-Xavier Bellamy

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 5

Text proposed by the CommissionAmendment
5. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.5. Processing operations not covered by the list in paragraph 4 shall not be subject to the requirement for a data protection impact assessment pursuant to paragraph 1.

Or. en

Amendment 1215

Sibylle Berg, Martin Sonneborn

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 5

Text proposed by the CommissionAmendment
5. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.5. The Board shall prepare and publish a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.

Or. de

Amendment 1216

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 5a (new)

Text proposed by the CommissionAmendment
5a. In Article 35, the following paragraph is inserted:
'5a. For processing operations that are on none of the lists in paragraph 4 and 5, the controller is required to assess the need for a data protection impact assessment.'

Or. en

Justification

To clarify that both lists combined cannot possibly cover the whole universe, but contain the clear edge cases.

Amendment 1217

Oliver Schenk, Eva Maydell, Andrea Wechsler, Angelika Niebler, Monika Hohlmeier, Dimitris Tsiodras, Christian Doleschal, Marie-Sophie Lanig, Axel Voss, Ana Miguel Pedro, Romana Tomc, Marion Walsmann, Lena Düpont, François-Xavier Bellamy

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 6

Text proposed by the CommissionAmendment
6. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.6. The Board shall establish a common template and a common methodology for conducting data protection impact assessments.

Or. en

Amendment 1218

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 paragraph 6

Text proposed by the CommissionAmendment
6. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.6. The Board shall establish and make public a common template and a common methodology for conducting data protection impact assessments.

Or. en

Amendment 1219

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 6

Text proposed by the CommissionAmendment
6. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.6. The Board shall prepare and make public a proposal for a common template and a common methodology for conducting data protection impact assessments.

Or. en

Amendment 1220

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – Paragraph 6a (new)

Text proposed by the CommissionAmendment
6a. In Article 35, the following paragraph is inserted:
'6a. The common template and methodology for data protection impact assessments shall require the controller to assess:
(a) the risk of re-identification, including by algorithmic means and taking into account the means reasonably likely to be used;
(b) the availability and suitability of state-of-the-art privacy-preserving and privacy-enhancing techniques to remove or mitigate that risk, including pseudonymisation, encryption, aggregation, synthetic data, federated analysis and secure processing environments; and
(c) the residual risk after application of such techniques.'

Or. en

Amendment 1221

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a a (new)

Regulation (EU) 2016/679

Article 35 – paragraphs 6a, 6b, 6c (new)

Text proposed by the CommissionAmendment
(aa) In Article 35, the following paragraphs 6a, 6b, 6c are inserted:
‘6a. The lists referred to in paragraphs 4 and 5 and the template and methodology referred to in paragraph 6 shall be published within [PO insert date: 9 months after the entry into application of this amending Regulation]. The Commission is empowered to decide that the lists, the template and the methodology as established by the Board have general validity within the Union by way of implementing acts in accordance with the examination procedure set out in Article 93(2).
6b. The lists and the template and methodology referred to in paragraph 6a shall be reviewed by the Board and updated where necessary. The Commission is empowered to decide that the updated list, template and methodology have general validity within the Union by way of an implementing act following the procedure referred to in paragraph 6a.
6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.’

Or. en

Justification

modeled after Article 40(9) GDPR on Codes of Conduct

Amendment 1222

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller, Christophe Grudler

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a a (new)

Regulation (EU) 2016/679

Article 35 – paragraph 1

Text proposed by the CommissionAmendment
(aa) In Article 35, paragraph 1 is replaced by the following:
1. Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. Where children are affected by the processing, the risks and consequences that the processing may have on their specific rights shall be explicitly addressed. A single assessment may address a set of similar processing operations that present similar risks.

Or. en

Amendment 1223

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a a (new)

Regulation (EU) 2016/679

Article 35 – Paragraph 6b

Text proposed by the CommissionAmendment
(aa) In Article 35, the following paragraph is inserted:
'6b. The proposals referred to in paragraphs 4, 5 and 6 shall be without prejudice to the right of the competent authorities and supervisory authorities of the Member States to develop their own guidance, standards and lists, in particular the lists referred to in Article 35(4) and (5). The Board shall take such national guidance, standards and lists into account when preparing the common templates, methodology and lists referred to in those paragraphs.'

Or. en

Justification

The preparation by the Board of common templates, a common methodology and common lists relating to data protection impact assessments contributes to a consistent application of this Regulation. However, this harmonisation of form should not deprive the competent authorities and supervisory authorities of the Member States of their power — recognised in particular in Article 35(4) and (5) — to develop their own guidance, standards and lists reflecting national circumstances. This amendment confirms that the proposals referred to in paragraphs 4, 5 and 6 are without prejudice to that power, and provides that the Board shall take such national guidance, standards and lists into account when preparing the common instruments. This ensures a bottom-up articulation between the national and Union levels, preserving both consistency and the ability of national authorities to address specific national risks.

Amendment 1224

Oliver Schenk, Andrea Wechsler, Monika Hohlmeier, Angelika Niebler, Dimitris Tsiodras, Christian Doleschal, Axel Voss, Ana Miguel Pedro, Marion Walsmann, Lena Düpont, Romana Tomc, Marie-Sophie Lanig, François-Xavier Bellamy

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point b

Regulation (EU) 2016/679

Article 35 – paragraph 6a

Text proposed by the CommissionAmendment
6a. The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).6a. The proposal for the list referred to in paragraph 4 and for the template and methodology referred to in paragraph within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). That list shall be based on convergence area from national authorities and shall not introduce new categories of processing operations that go beyond existing obligations under this Regulation. Processing operations lawfully in place at the time of their initiation shall not be subject to a retroactive obligation to carry out a data protection impact assessment as a result of the adoption of the harmonised list.

Or. en

Amendment 1225

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point b

Regulation (EU) 2016/679

Article 35 – paragraph 6a

Text proposed by the CommissionAmendment
6a. The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).6a. The lists referred to in paragraphs 4 and 5 and the template and methodology referred to in paragraph 6 shall be published within [OP date = 9 months of the entry into application of this Regulation].

Or. en

Amendment 1226

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point b

Regulation (EU) 2016/679

Article 35 – paragraph 6

Text proposed by the CommissionAmendment
6a. The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).6a. The lists referred to in paragraphs 4 and 5 and the template and methodology referred to in paragraph 6 shall be made public to the Commission within [OP date = 9 months of the entry into application of this Regulation].

Or. en

Amendment 1227

Pernando Barrena Arza

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point b

Regulation (EU) 2016/679

Article 35 – paragraph 6

Text proposed by the CommissionAmendment
6a. The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).6a. The Commission may adopt the common template established by the Board pursuant to paragraph 4, point (c), by way of an implementing act in accordance with the examination procedure set out in Article 93(2). The Commission shall not modify the substance of the common methodology or of the lists established by the Board pursuant to paragraph 4, points (a) and (b).

Or. en

Amendment 1228

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point b

Regulation (EU) 2016/679

Article 35 – paragraph 6

Text proposed by the CommissionAmendment
6b. The lists and the template and methodology referred to in paragraph 6a- shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.6b. The lists and the template and methodology referred to in paragraph 6a shall be reviewed at least every three years and updated where necessary.

Or. en

Amendment 1229

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point b

Regulation (EU) 2016/679

Article 35 – paragraph 6b

Text proposed by the CommissionAmendment
6b. The lists and the template and methodology referred to in paragraph 6a- shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.6b. The lists and the template and methodology referred to in paragraph 6a- shall be reviewed by the Board at least every three years and updated where necessary.

Or. en

Amendment 1230

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point b

Regulation (EU) 2016/679

Article 35 – paragraph ba (new)

Text proposed by the CommissionAmendment
6ba. In Article 35, the following paragraph 6ba is inserted:
'6ba. The Commission may adopt the template and any updates referred to in paragraphs 6a and 6b, as established by the Board, by way of an implementing act following the examination procedure set out in Article 93(2).'

Or. en

Amendment 1231

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point b

Regulation (EU) 2016/679

Article 35 – paragraph 6c

Text proposed by the CommissionAmendment
6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.6c. The lists and the template and methodology referred to in paragraph 6a- shall be reviewed by the Board at least every three years and updated where necessary.

Or. en

Amendment 1232

Sebastian Tynkkynen, Diego Solier

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point b

Regulation (EU) 2016/679

Article 35 – paragraph 6c

Text proposed by the CommissionAmendment
6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid.

Or. en

Amendment 1233

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point b

Regulation (EU) 2016/679

Article 35 – paragraph 6c

Text proposed by the CommissionAmendment
6ca. In Article 35, the following paragraph is inserted:
'6c. A data protection impact assessment shall not be required, on the sole basis of the Union list referred to in Article 35(4), for processing operations that were already underway before [the date of application of that list], provided that those operations have not since been subject to substantial modification. This is without prejudice to the obligation to carry out an assessment where processing is likely to result in a high risk on other grounds under Article 35(1).'

Or. en

Amendment 1234

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller, Christophe Grudler

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point b a (new)

Regulation (EU) 2016/679

Article 35 – paragraph 7 – points c and d

Text proposed by the CommissionAmendment
(ba) In paragraph 7 of Article 35, points c and d are replaced by the following:
(c) an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1, taking particular account where the personal data of a child is concerned; and
(d) the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned, in particular children.

Or. en

Amendment 1235

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 9 a (new)

Regulation (EU) 2016/679

Article 35 – paragraph 7a (new)

Text proposed by the CommissionAmendment
9a. In Article 35, the following paragraph 7a is inserted:
'7a. Where, in respect of the same processing operation or activity, the controller is required to carry out a data protection impact assessment under this Article and is also subject to an obligation to carry out a fundamental rights impact assessment under Article 27 of Regulation (EU) 2024/1689, or to a reporting obligation in respect of automated monitoring or decision-making systems under other Union law, those obligations may be satisfied by means of a single integrated assessment.
The integrated assessment shall be deemed to satisfy each of those obligations only where it covers all the elements required by each applicable provision. The substantive requirements, thresholds and triggering conditions laid down in those provisions remain unaffected.
A data protection impact assessment carried out under this Article that addresses the elements required for the fundamental rights impact assessment under Article 27 of Regulation (EU) 2024/1689 shall be relied upon in accordance with Article 27(4) of that Regulation, without duplication.
The integrated assessment shall be made available to each competent authority within the framework of its respective competences. This paragraph does not modify the allocation of supervisory competences under the acts referred to in the first subparagraph, nor does it require submission of the assessment to a single authority.'

Or. en

Justification

Where, for the same processing operation, a controller must carry out a data protection impact assessment under Article 35 and a fundamental rights impact assessment under Article 27 of Regulation (EU) 2024/1689, or a reporting obligation in respect of automated monitoring systems, those obligations may be satisfied by a single integrated assessment. The assessment satisfies each obligation only where it covers all the elements required by each provision; the substantive requirements, thresholds and triggering conditions remain unaffected. The assessment is made available to each competent authority within its respective competences and is not submitted to a single authority: the documentary instrument is mutualised, not the supervisory competence.

Amendment 1236

Henrik Dahl

Proposal for a regulation

Article 3 – paragraph 1 – point 9 a (new)

Regulation (EU) 2016/679

Article 35 – paragraph 9

Present textAmendment
9. Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations."deleted"

Or. en

(2016/679)

Amendment 1237

Angelika Niebler, Monika Hohlmeier

Proposal for a regulation

Article 3 – paragraph 1 – point 9 a (new)

Regulation (EU) 2016/679

Article 37 – paragraph 7

Text proposed by the CommissionAmendment
9a. Article 37, paragraph 7, is amended as follows:
The controller or the processor shall publish the contact details of the data protection officer.

Or. en

Amendment 1238

Axel Voss

Proposal for a regulation

Article 3 – paragraph 1 – point 9 a (new)

Regulation (EU) 2016/679

Article 37 – paragraph 4

Present textAmendment
9a. In Article 37, paragraph 4 is replaced by the following:
4. In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors."4. In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors."

Or. en

Justification

DPO Package #2: The amendment strengthens accountability by recognising DPOs as practical governance safeguards and first points of contact for complaints. DPOs already advise controllers and processors, monitor compliance and support data subjects; giving them an explicit complaint-handling role makes resolution faster, less bureaucratic and closer to the facts. Voluntary or shared DPOs are encouraged. Supervisory authorities remain available where the complaint is not addressed or not fully remedied within one month.

Amendment 1239

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 9 b (new)

Regulation (EU) 2016/679

Article 37 – paragraphs 2a and 4a (new)

Text proposed by the CommissionAmendment
9b. In Article 37, paragraphs 2a and 4a are inserted:
'2a. Microenterprises, small and medium-sized enterprises within the meaning of Recommendation 2003/361/EC, and small mid-cap enterprises may jointly designate a single data protection officer, whether or not they are partner or linked enterprises, provided that the data protection officer is easily accessible from each of them and is able to perform his or her tasks effectively in respect of each participating enterprise, taking into account the nature, scope, context and purposes of their respective processing operations. The participating enterprises shall specify, in a written arrangement, the allocation of responsibilities and the resources made available to the shared data protection officer.';
'4a. Member States may provide that a public body designated for that purpose makes available data protection officers acting for a pool of microenterprises, small and medium-sized enterprises or small mid-cap enterprises. A data protection officer made available under this paragraph shall perform the tasks referred to in Article 39 independently, in accordance with Article 38, and shall not receive instructions regarding the exercise of those tasks. This paragraph shall not apply to the supervisory authorities referred to in Article 51, so as to avoid any conflict of interest.';

Or. en

Justification

The cost of a dedicated data protection officer is prohibitive for small structures. The amendment allows micro, small and medium-sized enterprises and small mid-caps which are not related undertakings to designate a single data protection officer jointly, provided that the officer is easily accessible from each establishment and that the conditions of independence and absence of conflict of interest are met in respect of each controller concerned. Pooling reduces compliance costs without lowering the level of protection.

Amendment 1240

Axel Voss

Proposal for a regulation

Article 3 – paragraph 1 – point 9 b (new)

Regulation (EU) 2016/679

Article 39 – paragraph 1 – point ea (new)

Present textAmendment
9b. In Article 39, paragraph 1 the following point ea is added:
No equivalent"'(ea) to handle complaints from a data subject or complaints from a body, organisation or association pursuant to Article 80 against the processing of personal data by the controller or the processor, to investigate the subject matter of the complaint to an appropriate extent, and to advise the controller or the processor on appropriate remedial measures in the event of a breach of this Regulation.'"

Or. en

Justification

DPO Package #3: The amendment strengthens accountability by recognising DPOs as practical governance safeguards and first points of contact for complaints. DPOs already advise controllers and processors, monitor compliance and support data subjects; giving them an explicit complaint-handling role makes resolution faster, less bureaucratic and closer to the facts. Voluntary or shared DPOs are encouraged. Supervisory authorities remain available where the complaint is not addressed or not fully remedied within one month.

Amendment 1241

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 9 c (new)

Regulation (EU) 2016/679

Article 38 – paragraph 6

Present textAmendment
9c. In Article 38 paragraph 6 is replaced by the following:
6. The data protection officer may fulfil other tasks and duties. The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests."6. The data protection officer may fulfil other tasks and duties. The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests. Where a data protection officer is shared by several enterprises pursuant to Article 37(2a), or made available by a public body pursuant to Article 37(4a), the absence of a conflict of interests and the independence of the data protection officer shall be ensured in respect of each participating enterprise."

Or. en

(https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02016R0679-20160504)

Amendment 1242

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 9 d (new)

Regulation (EU) 2016/679

Article 39 – paragraph 2

Present textAmendment
9d. in Article 39 paragraph 2 is replaced by the following:
2. The data protection officer shall in the performance of his or her tasks have due regard to the risk associated with processing operations, taking into account the nature, scope, context and purposes of processing."2. The data protection officer shall in the performance of his or her tasks have due regard to the risk associated with processing operations, taking into account the nature, scope, context and purposes of processing, including, where the data protection officer acts for several enterprises pursuant to Article 37(2a) or (4a), the specific processing operations of each of them."

Or. en

(https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02016R0679-20160504)

Amendment 1243

Sibylle Berg, Martin Sonneborn

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41a

Text proposed by the CommissionAmendment
10. The following article is inserted:deleted
‘Article 41a
(1) The Commission may adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities.
(2) For the purpose of paragraph 1 the Commission shall:
(a) assess the state of the art of available techniques;
(b) develop criteria and or categories for controllers and recipients to assess the risk of re-identification in relation to typical recipients of data.
(3) The implementation of the means and criteria outlined in an implementing act may be used as an element to demonstrate that data cannot lead to reidentification of the data subjects.
(4) The Commission shall closely involve the EDPB in the preparations of the implementing acts. The EPDB shall issue an opinion on the draft implementing acts within a deadline of 8 weeks as of the receipt of the draft from the Commission.
(5) The Implementing Acts shall be adopted in accordance with the examination procedure referred to in Article 93(3).’

Or. de

Amendment 1244

Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41 a (new)

Text proposed by the CommissionAmendment
10. The following article is added:deleted
‘Article 41a
(1) The Commission may adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities.
(2) For the purpose of paragraph 1 the Commission shall:
(a) assess the state of the art of available techniques;
(b) develop criteria and or categories for controllers and recipients to assess the risk of re-identification in relation to typical recipients of data.
(3) The implementation of the means and criteria outlined in an implementing act may be used as an element to demonstrate that data cannot lead to reidentification of the data subjects.
(4) The Commission shall closely involve the EDPB in the preparations of the implementing acts. The EPDB shall issue an opinion on the draft implementing acts within a deadline of 8 weeks as of the receipt of the draft from the Commission.
(5) The Implementing Acts shall be adopted in accordance with the examination procedure referred to in Article 93(3).’

Or. en

Amendment 1245

Irena Joveva, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41a

Text proposed by the CommissionAmendment
10. The following article is added:deleted
‘Article 41a
(1) The Commission may adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities.
(2) For the purpose of paragraph 1 the Commission shall:
(a) assess the state of the art of available techniques;
(b) develop criteria and or categories for controllers and recipients to assess the risk of re-identification in relation to typical recipients of data.
(3) The implementation of the means and criteria outlined in an implementing act may be used as an element to demonstrate that data cannot lead to reidentification of the data subjects.
(4) The Commission shall closely involve the EDPB in the preparations of the implementing acts. The EPDB shall issue an opinion on the draft implementing acts within a deadline of 8 weeks as of the receipt of the draft from the Commission.
(5) The Implementing Acts shall be adopted in accordance with the examination procedure referred to in Article 93(3).’

Or. en

Amendment 1246

Pernando Barrena Arza

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41a

Text proposed by the CommissionAmendment
10. The following article is added:deleted
‘Article 41a
(1) The Commission may adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities.
(2) For the purpose of paragraph 1 the Commission shall:
(a) assess the state of the art of available techniques;
(b) develop criteria and or categories for controllers and recipients to assess the risk of re-identification in relation to typical recipients of data.
(3) The implementation of the means and criteria outlined in an implementing act may be used as an element to demonstrate that data cannot lead to reidentification of the data subjects.
(4) The Commission shall closely involve the EDPB in the preparations of the implementing acts. The EPDB shall issue an opinion on the draft implementing acts within a deadline of 8 weeks as of the receipt of the draft from the Commission.
(5) The Implementing Acts shall be adopted in accordance with the examination procedure referred to in Article 93(3).’

Or. en

Amendment 1247

Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41a

Text proposed by the CommissionAmendment
10. The following article is added:deleted
‘Article 41a
(1) The Commission may adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities.
(2) For the purpose of paragraph 1 the Commission shall:
(a) assess the state of the art of available techniques;
(b) develop criteria and or categories for controllers and recipients to assess the risk of re-identification in relation to typical recipients of data.
(3) The implementation of the means and criteria outlined in an implementing act may be used as an element to demonstrate that data cannot lead to reidentification of the data subjects.
(4) The Commission shall closely involve the EDPB in the preparations of the implementing acts. The EPDB shall issue an opinion on the draft implementing acts within a deadline of 8 weeks as of the receipt of the draft from the Commission.
(5) The Implementing Acts shall be adopted in accordance with the examination procedure referred to in Article 93(3).’

Or. en

Amendment 1248

João Oliveira

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41 a

Text proposed by the CommissionAmendment
10. The following article is added:deleted
‘Article 41a
(1) The Commission may adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities.
(2) For the purpose of paragraph 1 the Commission shall:
(a) assess the state of the art of available techniques;
(b) develop criteria and or categories for controllers and recipients to assess the risk of re-identification in relation to typical recipients of data.
(3) The implementation of the means and criteria outlined in an implementing act may be used as an element to demonstrate that data cannot lead to reidentification of the data subjects.
(4) The Commission shall closely involve the EDPB in the preparations of the implementing acts. The EPDB shall issue an opinion on the draft implementing acts within a deadline of 8 weeks as of the receipt of the draft from the Commission.
(5) The Implementing Acts shall be adopted in accordance with the examination procedure referred to in Article 93(3).’

Or. pt

Amendment 1249

Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller

Proposal for a regulation

Article 3 – paragraph 1 – point 10 – introductory part

Regulation (EU) 2016/679

Article 29a (new)

Text proposed by the CommissionAmendment
10. The following article is added:10. The following article is added:
'Article 29a (new)
Application of anonymisation
Controllers may apply anonymisation technics in order to remove risk to the data subjects concerned. Where controllers have verifiably anonymised personal data, the Regulation shall not apply to subsequent processing. Instantly anonymising personal data shall be a legitimate interest under Article 6(1)(f), while Article 9(1) shall not apply to processing with the sole purpose of instantly anonymising personal data.'

Or. en

Amendment 1250

Mary Khan

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41a

Text proposed by the CommissionAmendment
Article 41adeleted

Or. de

Justification

The Commission could, by means of technical implementing acts, define entire categories of pseudonymised data as being outside the scope of the GDPR. Although pseudonymisation reduces risks, it does not eliminate the link to a person. A legal effect as fundamental as this must not be delegated to the Commission.

Amendment 1251

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41a – Paragraph 1

Text proposed by the CommissionAmendment
(1) The Commission may adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities.(1) The Commission shall be empowered to adopt guidelines specifying technical and organisational measures, including consent-management mechanisms, privacy-preserving technologies and privacy-enhancing techniques, that may be taken into account when assessing whether a controller, processor, data holder or data recipient has means reasonably likely to be used to identify a natural person and comply with its consent requesting obligations. Those guidelines shall be adopted in close cooperation with the European Data Protection Board and shall aim to promote legal certainty, interoperability and the consistent application of this Regulation across the Union. The adoption of those guidelines acts shall be without prejudice to the interpretation of Union law by the Court of Justice of the European Union, including as regards the concepts of personal data, identifiable natural person, pseudonymised data, anonymisation and means reasonably likely to be used.

Or. en

Amendment 1252

Alice Teodorescu Måwe

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41a – paragraph 1

Text proposed by the CommissionAmendment
(1) The Commission may adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities.(1) The Commission may adopt implementing acts to specify means and criteria to determine when data
(a) is merely transitory in nature;
(b) is unrelated to the data subject as an identified or identifiable natural person;
(c) has appropriate technical and/or organisational safeguards to prevent any use for a purpose related to the data subject as an identified or identifiable natural person.

Or. en

Amendment 1253

Michael McNamara, Christophe Grudler

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41a – paragraph 1

Text proposed by the CommissionAmendment
(1) The Commission may adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities.(1) The European Data Protection Board (EDPB) shall issue an opinion in accordance with Article 64(2) addressing the application of pseudonymisation and anonymisation, including related technical and organisational measures, to specify the means and criteria to determine whether the application of pseudonymisation and anonymisation to personal data effectively prevents the identification of a data subject and the data subject is not or is no longer identifiable.

Or. en

Justification

Provides for an EDPB opinion addressing pseudonymisation and anonymisation, and determining whether their application to personal data prevents identification. Tasks the Commission with facilitating (rather than only encouraging) a code of conduct at Union level, taking the EDPB opinion into account. Then, according to existing GDPR provisions, the EDPB is empowered to provide another opinion on whether the draft code demonstrates compliance, and, if so, the Commission may give the code general validity via implementing act. This approach promotes a harmonised approach with proper oversight.

Amendment 1254

Oliver Schenk, Angelika Niebler, Monika Hohlmeier, Dimitris Tsiodras, Christian Doleschal, Andrea Wechsler, Marie-Sophie Lanig, Ana Miguel Pedro, Marion Walsmann, Lena Düpont, Romana Tomc, Axel Voss, François-Xavier Bellamy

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41a – paragraph 1

Text proposed by the CommissionAmendment
(1) The Commission may adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities.(1) The Commission may adopt implementing acts to specify technical and organisational measures and criteria supporting controllers in assessing whether data resulting from anonymisation or pseudonymisation no longer constitutes personal data for certain entities and in preventing the risk of re-identification.

Or. en

Amendment 1255

Ondřej Krutílek

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41a – paragraph 1

Text proposed by the CommissionAmendment
(1) The Commission may adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities.(1) The Commission may adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities because those entities are not reasonably likely to identify the natural person.

Or. en

Justification

Generally, the comitology is strongly supported in relation to this issue. Rules of such significance should be adopted in a binding, formal and predictable way to ensure legal certainty for controllers. Soft law in form of EDPB opinion is not acceptable. This is primary concern as regards pseudonymisation; the other proposals just aim to improve on original text.

Amendment 1256

François-Xavier Bellamy

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41a – paragraph 1

Text proposed by the CommissionAmendment
(1) The Commission may adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities.(1) The Commission may adopt implementing acts to specify the technical means and any relevant criteria to determine whether data resulting from pseudonymisation constitutes anonymized data that no longer constitutes personal data for a specific entity.
(Article 41 new of Regulation (EU) 2016/679)

Or. en

Amendment 1257

Henrik Dahl

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41a – paragraph 1

Text proposed by the CommissionAmendment
(1) The Commission may adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities.(1) The Commission may adopt implementing acts to specify means and criteria to determine when data:

Or. en

Amendment 1258

Axel Voss

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41 – paragraph 1

Text proposed by the CommissionAmendment
(1) The Commission may adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities.(1) The Commission may adopt implementing acts providing specifications, criteria, methodologies and practical requirements necessary to ensure the uniform application of this Regulation throughout the Union.

Or. en

Justification

The amendment strengthens harmonised GDPR application by allowing the Commission, with close EDPB involvement, to adopt practical criteria, methodologies and specifications where fragmentation creates uncertainty. This includes anonymisation, pseudonymisation, risk assessment, codes of conduct, certification, technical measures and sectoral use cases. Such acts do not create automatic exemptions, but give controllers and processors reliable tools to demonstrate compliance, reduce over-compliance and support data-driven innovation while preserving safeguards.

Amendment 1259

Tomas Tobé, Arba Kokalari, Jörgen Warborn

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41a – paragraph 1

Text proposed by the CommissionAmendment
(1) The Commission may adopt implementing acts to specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities.(1) The Commission may adopt implementing acts to specify means and criteria to determine when data no longer constitutes personal data for certain entities.

Or. en

Amendment 1260

Henrik Dahl

Proposal for a regulation

Article 3 – paragraph 1 – point 10

Regulation (EU) 2016/679

Article 41a – paragraph 1 – subparagraphs a, b, c (new)

Text proposed by the CommissionAmendment
(1a) In Article 41a, paragraph 1, the following subparagraphs a, b, c are added:
'(a) is merely transitory in nature;
(b) is unrelated to the data subject as an identified or identifiable natural person;
(c) has appropriate technical and/or organisational safeguards to prevent any use for a purpose related to the data subject as an identified or identifiable natural person.'

Or. en