Skip to content
EU Parl Watch

report parliamentary committee draft, 22 June 2026

On the proposal for a regulation of the European Parliament and of the Council amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557 as regards the simplification of the digital legislative framework, and repealing Regulations (EU) 2018/1807, (EU) 2019/1150, (EU) 2022/868, and Directive (EU) 2019/1024 (Digital Omnibus

Document CJ72-PR-786818 · (COM(2025)0837 – C100303/2025 – 2025/0360(COD))

Committee on Industry, Research and Energy Committee on Civil Liberties, Justice and Home Affairs · Rapporteur: Aura Salla, Marina Kaljurand

On Parliament’s site PDF Word

Full text

Jump to an amendment (78)
Draft european parliament legislative resolution 539 paragraphs

(COM(2025)0837 – C10-0303/2025 – 2025/0360(COD))

(Ordinary legislative procedure: first reading)

The European Parliament,

–having regard to the Commission proposal to Parliament and the Council (COM(2025)0837),

–having regard to Article 294(2) and Articles 114 and 16 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C100303/2025),

–having regard to Article 294(3) of the Treaty on the Functioning of the European Union,

–having regard to the budgetary assessment by the Committee on Budgets,

–having regard to the opinion of the European Economic and Social Committee of 18 March 2026,

–having regard to Rule 60 of its Rules of Procedure,

–having regard to the joint deliberations of the Committee on Industry, Research and Energy and the Committee on Civil Liberties, Justice and Home Affairs under Rule 59 of the Rules of Procedure,

–having regard to the opinions of the Committee on the Internal Market and Consumer Protection and the Committee on Legal Affairs,

–having regard to the report of the Committee on Industry, Research and Energy and the Committee on Civil Liberties, Justice and Home Affairs (A100000/2026),

Read the rest (527 paragraphs)

1.Adopts its position at first reading hereinafter set out;

2.Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;

3. Instructs its President to forward its position to the Council, the Commission and the national parliaments

Amendment 1

Proposal for a regulation

Recital 6

Text proposed by the CommissionAmendment
(6) Similarly, with the iterative regulation of online platforms over the past years, more recent rules have established a clearer and more ambitious framework than some of the predating rules, rendering them obsolete. It is therefore necessary that the legal framework evolves, eliminating any unnecessary duplications that add legal complexity.deleted

Or. en

Amendment 2

Proposal for a regulation

Recital 29

Text proposed by the CommissionAmendment
(29) It should be reiterated that further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be considered to be compatible lawful processing operations. In such cases it is not necessary to ascertain on the basis of Article 6(4) of this Regulation whether the purpose of the further processing is compatible with the purpose for which the personal data are initially collected.(29) It should be reiterated that further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be considered to be compatible lawful processing operations. In such cases it is not necessary to ascertain on the basis of Article 6(4) of Regulation (EU) 2016/679 whether the purpose of the further processing is compatible with the purpose for which the personal data are initially collected. Such further processing should be carried out in compliance with the principles and appropriate safeguards laid down in Regulation (EU) 2016/679, in particular Article 89 thereof.

Or. en

Amendment 3

Proposal for a regulation

Recital 32

Text proposed by the CommissionAmendment
(32) The processing of personal data for scientific research purposes and the application of the GDPR’s provisions on scientific research are conditional on the adoption of appropriate safeguards for the rights and freedoms of data subjects, pursuant to Article 89(1) GDPR. To that end, the GDPR balances the right to protection of personal data, pursuant to Article 8 CFREU, with the freedom of science, pursuant to Article 13 CFREU. The processing of personal data for the purpose of scientific research therefore pursues a legitimate interest within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679, provided that such research is not contrary to Union or Member State law. This is without prejudice to the obligation of the controller to ensure that all other conditions of Article 6(1)(f) of Regulation (EU) 2016/679 as well as all other requirements and principles of that Regulation are met.(32) The processing of personal data for scientific research purposes and the application of the provisions on scientific research of Regulation (EU) 2016/679 are conditional on the adoption of appropriate safeguards for the rights and freedoms of data subjects, pursuant to Article 89(1) of Regulation (EU) 2016/679. To that end, the GDPR seeks to ensure a proportionate balance between the right to protection of personal data, pursuant to Article 8 of the Charter of Fundamental Rights of the European Union (the ‘CFREU’), and the freedom of science, pursuant to Article 13 CFREU. The processing of personal data for the purpose of scientific research therefore pursues a legitimate interest within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679, provided that such research is not contrary to Union or Member State law. This is without prejudice to the obligation of the controller to ensure that all other conditions of Article 6(1)(f) of Regulation (EU) 2016/679 as well as all other requirements and principles of that Regulation are met.

Or. en

Amendment 4

Proposal for a regulation

Recital 34

Text proposed by the CommissionAmendment
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.(34) Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric recognition includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of their claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming their identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary and proportionate for a legitimate purpose pursued by the controller, and subject to appropriate safeguards laid down under Union law. When such verification is necessary, the controller should choose the least intrusive of the equally effective means available. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and should be subject to appropriate safeguards. That derogation should only apply where suitable safeguards apply to ensure that the biometric data are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how their biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, where the biometric data are securely stored solely on the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject and subject to measures ensuring the overall security of processing, including during the enrolment phase of the data subject’s biometric data during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.

Or. en

Amendment 5

Proposal for a regulation

Recital 35

Text proposed by the CommissionAmendment
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning them are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable them to exercise their other rights under Regulation (EU) 2016/679. Where a request is manifestly unfounded or excessive a controller should give the choice to a data subject to either pay a defined fee or have the request refused to ensure a proportionate response and avoid unexpected costs for the data subject. Rights under Regulation (EU) 2016/679 may be used as an enabler of other rights or in the public interest. The use of rights under that Regulation as an enabler of other rights or other legitimate aims should not be deemed abusive, unfounded or excessive. The broad nature of a request should not render a request unfounded or excessive. The data subject, in the exercise of their data subject rights, should be presumed to act for reasonable purposes, unless the controller unequivocally demonstrates abusive intent on the part of the data subject.

Or. en

Amendment 6

Proposal for a regulation

Recital 38

Text proposed by the CommissionAmendment
(38) Article 22 of Regulation (EU) 2016/679 provides for rules governing the processing of personal data when the data controller makes decisions which have legal effects or similarly significant effects on the data subject, based solely on automated processing. In order to provide greater legal certainty, it should be clarified that decisions based solely on automated processing are allowed when specific conditions are met, as set out in Regulation (EU) 2016/679. It should also be clarified that when assessing whether a decision is necessary for entering into, or performance of, a contract between the data subject and a data controller, as set out in Article 22(2)(a) of Regulation (EU) 2016/679, it should not be required that the decision could be taken only by solely automated processing. This means that the fact that the decision could also be taken by a human does not prevent the controller from taking the decision by solely automated processing When several equally effective automated processing solutions exist, the controller should use the less intrusive one.(38) Article 22 of Regulation (EU) 2016/679 provides that data subjects have the right not to be subject to a decision based solely on automated processing, except where specific conditions are met and in accordance with rules governing the processing of personal data when the data controller makes decisions which have legal effects or similarly significant effects on the data subject, based solely on automated processing. In order to provide greater legal certainty, it should be clarified that when assessing whether a decision based solely on automated processing is necessary for entering into, or performance of, a contract between the data subject and a data controller, as set out in Article 22(2)(a) of Regulation (EU) 2016/679, it should not be required that the decision could be taken only by solely automated processing. This means that the fact that the decision could also be taken by a human does not prevent the controller from taking the decision by solely automated processing. However, when several equally effective automated processing solutions exist, the controller should use the less intrusive one. The data subject’s rights should not be negatively impacted by the implementation of automated individual decision-making. Human involvement with regard to automated decision-making should be meaningful, and a mere symbolic gesture by a human of viewing the decision made without having a real and factual influence on the decision-making should not be categorised as human involvement.

Or. en

Amendment 7

Proposal for a regulation

Recital 39

Text proposed by the CommissionAmendment
(39) In order to reduce the burden on controllers while ensuring that supervisory authorities have access to the relevant information and can act on violations of the Regulation, the threshold for notification of a personal data breach to the supervisory authority under Article 33 of Regulation (EU) 2016/679 should be aligned with that of communication of a personal data breach to the data subject under Article 34 of that Regulation. In the case of a data breach that is not likely to result in a high risk to the rights and freedoms of natural persons, the controller should not be required to notify the competent supervisory authority. The higher threshold for notifying a data breach to the supervisory authority does not affect the obligation of the controller to document the breach in accordance with paragraph 5 of Article 33 of Regulation (EU) 2016/679, or its obligation to be able to demonstrate its compliance with that Regulation, in accordance with Article 5(2) of that Regulation. In order to facilitate compliance by controllers and a harmonised approach in the Union, the Board should prepare a common template for notifying data breaches to the competent supervisory authority and a common list of circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The Commission should take due account of the proposal prepared by the Board and review them, as necessary, prior to adoption. In order to take account of new information security threats, the common template and the list should be reviewed at least every three years and updated where necessary. The lack of a common list of circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person should not affect the obligations of controllers to notify those breaches.(39) In order to reduce the burden on controllers while ensuring that supervisory authorities have access to the relevant information and can act on violations of Regulation (EU) 2016/679, the threshold for notification of a personal data breach to the supervisory authority under Article 33 of Regulation (EU) 2016/679 should be aligned with that of communication of a personal data breach to the data subject under Article 34 of that Regulation. In the case of a data breach that is not likely to result in a high risk to the rights and freedoms of natural persons, the controller should not be required to notify the competent supervisory authority. The higher threshold for notifying a data breach to the supervisory authority does not affect the obligation of the controller to document the breach in accordance with paragraph 5 of Article 33 of Regulation (EU) 2016/679, or its obligation to be able to demonstrate its compliance with that Regulation, in accordance with Article 5(2) of that Regulation. In order to facilitate compliance by controllers and a harmonised approach in the Union, the European Data Protection Board should establish and make public a common template for notifying data breaches to the competent supervisory authority and a common list of circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. In order to take account of new information security threats, the common template and the list should be reviewed at least every three years and updated where necessary. The Commission may adopt, by means of an implementing act, the common template as established by the Board, as well as its updates where necessary. The lack of a common list of circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person should not affect the obligations of controllers to notify those breaches.

Or. en

Amendment 8

Proposal for a regulation

Recital 40

Text proposed by the CommissionAmendment
(40) Article 35 of that Regulation (EU) 2016/679 requires controllers to conduct a data protection impact assessment where the processing of personal data is likely to result in a high risk to the rights and freedoms of natural persons. The supervisory authorities established pursuant to that Regulation are required to establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment. In addition, the Regulation provides that supervisory authorities may establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. In order to effectively contribute to the aim of convergence of the economies and to effectively ensure free flow of personal data between Member States, increase legal certainty, facilitate compliance by controllers and ensure a harmonised interpretation of the notion of a high risk to the rights and freedoms of data subjects, a single list of processing operations should be provided at EU level, to replace the existing national lists. In addition, the publication of a list of the type of processing operations for which no data protection impact assessment is required, which is currently optional, should be made mandatory. The lists of processing operations should be prepared by the Board and adopted by the Commission as an implementing act. In order to facilitate compliance by controllers, the Board should also prepare a common template and a common methodology for conducting data protection impact assessments, to be adopted by the Commission as an implementing act. The Commission should take due account of the proposals prepared by the Board and review them, as necessary, prior to adoption. In order to take account of technological developments, the lists and the common template and methodology should be reviewed at least every three years and updated where necessary.(40) Article 35 of Regulation (EU) 2016/679 requires controllers to conduct a data protection impact assessment where the processing of personal data is likely to result in a high risk to the rights and freedoms of natural persons. The supervisory authorities established pursuant to that Regulation are required to establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment. In addition, that Regulation provides that supervisory authorities may establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. In order to effectively contribute to the aim of convergence of the economies and to effectively ensure free flow of personal data between Member States, increase legal certainty, facilitate compliance by controllers and ensure a harmonised interpretation of the notion of a high risk to the rights and freedoms of data subjects, a single list of processing operations should be provided at EU level, to replace the existing national lists. In addition, the publication of a list of the type of processing operations for which no data protection impact assessment is required, which is currently optional, should be made mandatory. The lists of processing operations should be established and made public by the European Data Protection Board. When establishing the lists, due account should be taken of the nature, scope, context and purposes of the processing and the risk to the rights and freedoms of natural persons. In order to facilitate compliance by controllers, the Board should also establish and make public a common template and a common methodology for conducting data protection impact assessments. In order to take account of technological developments, the lists and the common template and methodology should be reviewed at least every three years and updated where necessary. The Commission may adopt, by means of an implementing act, the common template as established by the Board, as well as updates to the common template, where necessary.

Or. en

Amendment 9

Proposal for a regulation

Recital 41

Text proposed by the CommissionAmendment
(41) Regulation (EU) 2018/1725 of the European Parliament and of the Council16 applies to the processing of personal data by the Union institutions, bodies, offices and agencies. Directive (EU) 2016/680 of the European Parliament and of the Council17 applies to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties. Regulation (EU) 2018/1725 and Directive (EU) 2016/680 should be brough into alignment with the amendments to Regulation (EU) 2016/679 introduced by this Regulation.(41) Regulation (EU) 2018/1725 of the European Parliament and of the Council16 applies to the processing of personal data by the Union institutions, bodies, offices and agencies. Directive (EU) 2016/680 of the European Parliament and of the Council17 applies to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties. Regulation (EU) 2018/1725 should be brought into alignment with the amendments to Regulation (EU) 2016/679 introduced by this Regulation.
16 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39, ELI: http://data.europa.eu/eli/reg/2018/1725/oj).16 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39, ELI: http://data.europa.eu/eli/reg/2018/1725/oj).
17 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, p. 89, ELI: http://data.europa.eu/eli/dir/2016/680/oj).17 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, p. 89, ELI: http://data.europa.eu/eli/dir/2016/680/oj).

Or. en

Amendment 10

Proposal for a regulation

Recital 43

Text proposed by the CommissionAmendment
(43) In order to provide a strong and coherent data protection framework in the Union, the necessary adaptations of Directive (EU) 2016/680 and any other Union legal act applicable to such processing of personal data should follow after the adoption of this regulation, in order to allow for their application as close as possible to the entry into application of the amendments to Regulation (EU) 2016/679 and Regulation (EU) 2018/1725.deleted

Or. en

Amendment 11

Proposal for a regulation

Recital 49 a (new)

Text proposed by the CommissionAmendment
(49a) To ensure that Directive (EU) 2022/2555 is applied consistently and proportionately across the Union and in line with the principle of administrative simplification and the 'report-once' policy, duplicative or unclear reporting obligations or diverging national interpretations and additional obligations should be avoided. The Commission should, in cooperation with the Cooperation Group referred to in Article 14 of Directive (EU) 2022/2555 and the European Union Agency for Cybersecurity (ENISA), issue guidance on the harmonised interpretation and application of key obligations under that Directive.

Or. en

Amendment 12

Proposal for a regulation

Recital 59

Text proposed by the CommissionAmendment
(59) Regulation (EU) 2019/1150 establishes a targeted set of mandatory rules at Union level to ensure a fair, predictable, sustainable and trusted online business environment within the internal market. Regulation (EU) 2022/2065 and Regulation (EU) 2022/1925 provide a comprehensive regulatory framework for a safe, predictable and trusted online environments for all end-users of online services, and establish a level playing field for businesses in digital markets. In the interest of simplification of Union legislation in the field of online intermediation services and online platforms, and given that the objectives and material provisions of the Platform-to-Business Regulation are largely covered by the Digital Services Act and the Digital Markets Act, Regulation (EU) 2019/1050 should be repealed. Regulation (EU) 2022/2065 and Regulation (EU) 2022/1925 contribute to a fully harmonised regulatory framework for digital services and digital markets, by approximating national measures concerning the requirements for providers of intermediary services and the contestability and fairness of core platforms services provided by gatekeepers. For purposes of legal certainty, selected definitions in Article 2, the provisions on restrictions and suspensions in Article 4, as well as on the internal complaint-handling system in Article 11 of Regulation (EU) 2019/1150 that are cross-referenced by other legal acts, in particular Directive (EU) 2023/2831 on improving working conditions in platform work, and Article 15 ensuring enforcement, will temporarily remain in application until the original acts are amended.deleted

Or. en

Amendment 13

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point a

Regulation (EU) 2023/2854

Article 2 – paragraph 1 – point 4c

Text proposed by the CommissionAmendment
(4c) ‘access’ means data use, in accordance with specific technical, legal or organisational requirements, without necessarily implying the transmission or downloading of data;deleted

Or. en

Amendment 14

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point d

Regulation (EU) 2023/2854

Article 2 – paragraph 1– point 38a

Text proposed by the CommissionAmendment
(38a) ‘data intermediation service’ means a service which aims to establish relationships of an economic character for the purposes of data sharing between an undetermined number of data subjects or data holders and data users, through technical, legal or other means, including for the purpose of exercising the rights of data subjects in relation to personal data, and which:(38a) ‘data intermediation service’ means a service which aims to establish commercial relationships for the purposes of data sharing between an undetermined number of data subjects and data holders on the one hand and data users on the other, through technical, legal or other means, including for the purpose of exercising the rights of data subjects in relation to personal data, excluding the following:
(a) services that obtain data from data holders and aggregate, enrich or transform the data for the purpose of adding substantial value to it and license the use of the resulting data to data users, without establishing a commercial relationship between data holders and data users;
(b) services that focus on the intermediation of copyright-protected content;
(c) services that are exclusively used by one data holder in order to enable the use of the data held by that data holder, or that are used by multiple legal persons in a closed group, including supplier or customer relationship or collaborations established by contract, in particular those that have as a main objective to ensure the functionalities of objects and devices connected to the Internet of Things;
(d) data sharing services offered by public sector bodies that do not aim to establish commercial relationships;
(1) do not have as their main purpose the intermediation of copyright-protected content;
(2) are not jointly procured by several legal persons for exclusive use among them;

Or. en

Amendment 15

Proposal for a regulation

Article 1 – paragraph 1 – point 2 – point e a (new)

Regulation (EU) 2023/2854

Article 2 – paragraph 1 – point 63a(new)

Text proposed by the CommissionAmendment
(ea) the following point is added:
(63a) “responding to a public emergency” means the immediate actions necessary to address and manage the emergency while it is ongoing, whereas “mitigating or supporting the recovery from a public emergency” means actions taken after or once the immediate phase of the emergency has passed and is aimed at limiting its consequences and restoring normal conditions;

Or. en

Amendment 16

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) 2023/2854

Article 15a – paragraph 2

Text proposed by the CommissionAmendment
2. Where the data requested are necessary to respond to a public emergency, and the requesting body pursuant to paragraph 1 is unable to obtain such data by other means in a timely and effective manner under equivalent conditions, the request shall concern non-personal data. Where the provision of non-personal data is insufficient to address the public emergency, personal data may also be requested and, where possible, made available in pseudonymized form, subject to appropriate technical and organisational measures to ensure their protection.2. Where the data requested are necessary to respond to a public emergency, and the requesting body pursuant to paragraph 1 is unable to obtain such data by other means in a timely and effective manner under equivalent conditions, the request shall concern non-personal data. Where the provision of non-personal data is insufficient to respond to the public emergency, personal data may also be requested and where strictly necessary, made available in pseudonymized form, subject to appropriate technical and organisational measures to ensure their protection.

Or. en

Amendment 17

Proposal for a regulation

Article 1 – paragraph 1 – point 9 – point b – point ii

Regulation (EU) 2023/2854

Article 17 – paragraph 2 – subparagraph 1 – point e

Text proposed by the CommissionAmendment
(ii) point (e) is deleted.;deleted

Or. en

Amendment 18

Proposal for a regulation

Article 1 – paragraph 1 – point 9 – point b – point ii a (new)

Regulation (EU) 2023/2854

Article 17 – paragraph 2 – subparagraph 2 a (new)

Text proposed by the CommissionAmendment
(iia) the following subparagraph is added:
The Commission, the European Central Bank (ECB) or any of the Union Bodies, shall notify the European Data Protection Supervisor of their requests for personal data.

Or. en

Amendment 19

Proposal for a regulation

Article 1 – paragraph 1 – point 10 – point -a (new)

Regulation (EU) 2023/2854

Article 18 – paragraph 1

Text proposed by the CommissionAmendment
(-a) paragraph 1 is replaced by the following:
1. A data holder receiving a request to make data available under this Chapter shall make the data available to the requesting public sector body, the Commission, the European Central Bank or a Union body without undue delay, taking into account necessary technical, organisational and legal measures.1. A data holder receiving a request to make data available under this Chapter shall make the data available to the requesting public sector body, the Commission, the European Central Bank or a Union body without undue delay, having implemented the necessary technical, organisational and legal measures.

Or. en

Amendment 20

Proposal for a regulation

Article 1 – paragraph 1 – point 16 – point c

Regulation (EU) 2023/2854

Article 32 – paragraph 5

Text proposed by the CommissionAmendment
5. The provider of data processing services, the public sector body making available data or documents in accordance with Chapter VIIc Section 3, the natural or legal person to which the right to re-use data or documents in accordance with Chapter VIIc Section 3 was granted, the data intermediation services provider or the recognised data altruism organisation shall inform the natural or legal person whose rights and interests might be affected about the existence of a request of a third-country authority to access its data before complying with that request, except where the request serves law enforcement purposes and for as long as this is necessary to preserve the effectiveness of the law enforcement activity.;5. The provider of data processing services, the public sector body making available data or documents in accordance with Chapter VIIc Section 3, the natural or legal person to which the right to re-use data or documents in accordance with Chapter VIIc Section 3 was granted, the data intermediation services provider or the recognised data altruism organisation shall inform the natural or legal person whose rights and interests might be affected about the existence of a request of a third-country authority to access its data before complying with that request, except where the request is made by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties and for as long as this is necessary to preserve the effectiveness of the law enforcement activity. Where informing the natural or legal person before compliance would seriously and demonstrably undermine a lawful investigation or enforcement activity, notification may be delayed only for as long as strictly necessary and proportionate. The reasons for delayed notification shall be documented and made available to the competent authority upon request. The affected person shall be informed as soon as the reason for delay no longer applies. Providers and other addressees shall publish annual transparency reports containing aggregate information on third-country access requests, legal bases invoked, categories of data concerned, the number of requests complied with, refused, or challenged, and the number of cases in which notification was delayed.’;

Or. en

Amendment 21

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point b a (new)

Text proposed by the CommissionAmendment
(ba) they have in place adequate technical, legal and organisational measures in order to prevent the transfer of or access to non-personal data that is contrary to Union law or the national law of the relevant Member State;

Or. en

Amendment 22

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point b b (new)

Text proposed by the CommissionAmendment
(bb) they keep a log record of their data intermediation activity, corresponding to the risks involved;

Or. en

Amendment 23

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point b c (new)

Text proposed by the CommissionAmendment
(bc) they provide for a possibility to use the details collected about activity on the data intermediation service for the purposes of security and detection of abusive or fraudulent access;

Or. en

Amendment 24

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point b d (new)

Text proposed by the CommissionAmendment
(bd) they provide an opportunity for, data subjects to exercise their rights in the event of insolvency;

Or. en

Amendment 25

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point d – point ii

Text proposed by the CommissionAmendment
(ii) the data are not used for other purposes than performing the value-added service;(ii) the data are not used for purposes other than performing the value-added service, such as advertising, profiling, ranking, price discrimination and training of AI systems;

Or. en

Amendment 26

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32c – paragraph 1 – point d – point iii

Text proposed by the CommissionAmendment
(iii) the value-added services are offered through a functionally separate entity;(iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider. Micro, small and medium- sized enterprises may rely on a functional separation only where they demonstrate that such separation ensures equivalent protection against conflicts of interest, cross-use of data and discriminatory treatment;

Or. en

Amendment 27

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32e – paragraph 1 – subparagraph 1

Text proposed by the CommissionAmendment
Data intermediation services provider which meets the requirements set out in Article 32c may submit an application for registration in the public Union register of recognised data intermediation services providers to the competent authority referred to in Article 32b in the Member State in which they have their main establishment.(1) Data intermediation services provider which meets the requirements set out in Article 32c shall submit an application for registration in the public Union register of recognised data intermediation services providers to the competent authority referred to in Article 32b in the Member State in which they have their main establishment.

Or. en

Amendment 28

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32i – paragraph 1 a (new)

Text proposed by the CommissionAmendment
(1a) This Regulation does not create a legal basis for the processing of personal data, nor does it affect any of the rights and obligations set out in Regulation (EU) 2016/679 or (EU) 2018/1725 or in Directive 2002/58/EC or (EU) 2016/680.

Or. en

Amendment 29

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32i – paragraph 5

Text proposed by the CommissionAmendment
(5) This Chapter builds on, and is without prejudice to, Union and national access regimes, in particular with regard to the granting of access to and disclosure of official documents.(5) This Chapter builds on, and is without prejudice to Union and national access regimes, in particular with regard to the granting of access to and disclosure of official documents, or the re-use of data, and is without prejudice to the confidentiality obligations of public sector bodies under Union or national law.

Or. en

Amendment 30

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32k – paragraph 3

Text proposed by the CommissionAmendment
(3) By way of derogation of paragraph 1, where an exclusive right relates to the digitisation of cultural resources, the period of exclusivity shall in general not exceed 10 years. Where that period exceeds 10 years, its duration shall be in accordance with applicable Union and national law subject to review during the 11th year and, if applicable, every seven years thereafter.(3) By way of derogation of paragraph 1, where an exclusive right relates to the digitisation of cultural resources, the period of exclusivity shall not exceed 10 years, and for very large enterprises designated as gatekeepers under Article 3(1) of Regulation (EU) 2022/1925, five years. No renewal or extension of the period of exclusivity shall be permitted unless the public sector body demonstrates that the exclusive right remains strictly necessary, proportionate, and in the public interest. Digitised cultural resources that are in the public domain shall remain in the public domain after digitisation. Contractual terms shall not restrict their re-use beyond the period of exclusivity permitted under paragraph 3 of this Article.

Or. en

Amendment 31

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32q – paragraph 6

Text proposed by the CommissionAmendment
(6) Public sector bodies may set out higher charges for the re-use of data and documents by very large enterprises than the charges provided for in paragraphs 1, 4 and 5. Any such charges shall be proportionate and based on objective criteria, taking into account the economic power, or the ability of the entity to acquire data, including in particular a designation as a gatekeeper under Regulation (EU) 2022/1925. In addition to the elements listed in paragraph 1 of this Article, such charges may cover the cost of collection, production, reproduction dissemination and data storage and where applicable the cost of anonymisation or measures to protect the confidentiality of the data or documents, together with a reasonable return on investment.(6) Public sector bodies shall set out higher charges for the re-use of data and documents for entities designated as gatekeepers in accordance with Article 3(1) of Regulation (EU) 2022/1925 other than the charges provided for in paragraphs 1, 4 and 5 of this Article. Public sector bodies may also set out higher charges for the re-use of data and documents by very large enterprises than the charges provided for in paragraphs 1, 4 and 5 of this Article. Any such charges shall be proportionate and based on objective criteria, and shall be transparent, non-discriminatory, and subject to effective review. They shall take into account the economic power, or the ability of the entity to acquire data, in addition to the elements listed in paragraph 1 of this Article, such charges may cover the cost of collection, production, reproduction dissemination and data storage and where applicable the cost of anonymisation or measures to protect the confidentiality of the data or documents, together with a reasonable return on investment. The Commission shall adopt guidelines to ensure harmonised application of this paragraph, including criteria for calculating charges, avoiding arbitrary discrimination and protecting access for SMEs, researchers, civil society, public-interest actors and non-commercial re-users.

Or. en

Amendment 32

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32w – paragraph 3 – point a – point (ii)

Text proposed by the CommissionAmendment
(ii) subject to other forms of preparation of personal data;deleted

Or. en

Amendment 33

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2023/2854

Article 32w – paragraph 5 – subparagraph 1– point (a)

Text proposed by the CommissionAmendment
(a) where there is no legal basis other than consent for transmitting the data under Regulation (EU) 2016/679, with the consent of the data subjects;deleted

Or. en

Amendment 34

Proposal for a regulation

Article 1 – paragraph 1 – point 18 a (new)

Regulation (EU) 2023/2854

Article 37 – paragraph 3 a (new)

Text proposed by the CommissionAmendment
18a. In Article 37, the following paragraphs are inserted after paragraph 3:
3a. Supervisory authorities competent to enforce Regulation (EU) 2016/679 shall participate in the monitoring of the application of this Regulation in accordance with their competences and tasks under Regulation (EU) 2016/679 to ensure harmonisation and consistency within the single market.

Or. en

Amendment 35

Proposal for a regulation

Article 1 – paragraph 1 – point 18 a (new)

Regulation (EU) 2023/2854

Article 37 – paragraph 3 b (new)

Text proposed by the CommissionAmendment
3b. Competent authorities under Article 37(1) of this Regulation shall cooperate with the supervisory authorities under Regulation (EU) 2016/679 to ensure a consistent application of both Regulations. As part of such cooperation, supervisory authorities competent under Regulation (EU) 2016/679 shall be consulted by the competent authorities under Article 37(1) of this Regulation in relation to Union and national data protection law.

Or. en

Amendment 36

Proposal for a regulation

Article 1 – paragraph 1 – point 18 a (new)

Regulation (EU) 2023/2854

Article 37 – paragraph 3 c (new)

Text proposed by the CommissionAmendment
3c. Competent authorities shall cooperate to handle and resolve complaints effectively and in a timely manner, including by exchanging all relevant information by electronic means, including information obtained in the context of enforcement activities, without undue delay. This cooperation shall not affect the cooperation mechanisms provided for by Chapters VI and VII of Regulation (EU) 2016/679 and by Regulation (EU) 2017/2394.

Or. en

Amendment 37

Proposal for a regulation

Article 1 – paragraph 1 – point 19

Regulation (EU) 2023/2854

Article 38 – paragraph 3 a (new)

Text proposed by the CommissionAmendment
(3a) Competent authorities shall cooperate to handle and resolve complaints effectively and in a timely manner, including by exchanging all relevant information by electronic means, without undue delay. This cooperation shall not affect the cooperation mechanisms provided for by Chapters VI and VII of Regulation (EU) 2016/679 and by Regulation (EU) 2017/2394.

Or. en

Amendment 38

Proposal for a regulation

Article 1 – paragraph 1 – point 22

Regulation (EU) 2023/2854

Article 41a – paragraph 2

Text proposed by the CommissionAmendment
(2) It shall be composed at least of representatives of Member States competent for matters related to data, the competent authorities for enforcement of Chapters II, III, V, VIIa and VIIc of this Regulation, the European Data Protection Board, the European Data Protection Supervisor, ENISA, the EU SME Envoy or a representative appointed by the network of SME envoys. The Commission may decide to add additional categories of members. In its appointments of individual experts, the Commission shall aim to achieve gender and geographical balance among the members of the group.(2) It shall be composed at least of representatives of Member States competent for matters related to data, the competent authorities for enforcement of Chapters II, III, V, VIIa and VIIc of this Regulation, the European Data Protection Board, the European Data Protection Supervisor, ENISA, the EU SME Envoy or a representative appointed by the network of SME envoys. The Commission may decide to add additional categories of members. In its appointments of individual experts, the Commission shall aim to achieve gender and geographical balance among the members of the group The European Data Innovation Board (EDIB) shall include structured participation from all relevant stakeholders, and such participation shall ensure balanced representation and shall not affect the independence of competent authorities.

Or. en

Amendment 39

Proposal for a regulation

Article 1 – paragraph 1 – point 23

Regulation (EU) 2023/2854

Article 42 – paragraph 1 – point b a (new)

Text proposed by the CommissionAmendment
(ba) regularly exchanging information and coordinating with the European Data Protection Board;

Or. en

Amendment 40

Proposal for a regulation

Article 1 – paragraph 1 – point 23

Regulation (EU) 2023/2854

Article 42 – paragraph 1 – point c

Text proposed by the CommissionAmendment
(c) facilitating cooperation between competent authorities through capacity-building and the exchange of information;(c) facilitating cooperation between competent authorities through capacity-building and the exchange of information, in particular by establishing methods for the efficient exchange of information relating to the enforcement of the rights and obligations under Chapters II, III and V in cross-border cases, including coordination with regard to the setting of penalties;

Or. en

Amendment 41

Proposal for a regulation

Article 1 – paragraph 1 – point 23

Regulation (EU) 2023/2854

Article 42 – paragraph 1 – point d a (new)

Text proposed by the CommissionAmendment
(da) publishing agendas, minutes, non-confidential documents, adopted guidance, and records of stakeholder participation

Or. en

Amendment 42

Proposal for a regulation

Article 1 – paragraph 1 – point 26 – point a – point ii a(new)

Regulation (EU) 2023/2854

Article 49 – paragraph 1 – point m a (new)

Text proposed by the CommissionAmendment
(iia) the following point is added:
(ma) the impact of this Regulation on concentration of data access, control, and intermediation power, including the role of undertakings designated as gatekeepers under Regulation (EU) 2022/1925 and very large enterprises;

Or. en

Amendment 43

Proposal for a regulation

Article 3 – paragraph 1 – point 1 – point b

Regulation (EU) 2016/679

Article 4 – paragraph 1 – point 32

Text proposed by the CommissionAmendment
(32) ‘terminal equipment’ means terminal equipment as set out in Article 1(1) of Directive 2008/63/EC;(32) ‘terminal equipment’ means terminal equipment as defined in Article 1(1) of Directive 2008/63/EC;

Or. en

Amendment 44

Proposal for a regulation

Article 3 – paragraph 1 – point 1 – point b

Regulation (EU) 2016/679

Article 4 – paragraph 1 – point 33

Text proposed by the CommissionAmendment
(33) for ‘electronic communications networks’ the definition of Article 2(1) of Directive (EU) 2018/1972 shall apply;(33) ‘electronic communications networks’ means electronic communications networks as defined in Article 2(1) point (1) of Directive (EU) 2018/1972;

Or. en

Amendment 45

Proposal for a regulation

Article 3 – paragraph 1 – point 2

Regulation (EU) 2016/679

Article 5 – paragraph 1 – point b

Text proposed by the CommissionAmendment
collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), be considered to be compatible with the initial purposes, independent of the conditions of Article 6(4) of this Regulation, (‘purpose limitation’);(b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, subject to the application of appropriate safeguards in accordance with Article 89(1), be considered to be compatible with the initial purposes, independent of the conditions of Article 6(4) of this Regulation, (‘purpose limitation’);

Or. en

Amendment 46

Proposal for a regulation

Article 3 – paragraph 1 – point 3 – point a

Regulation (EU) 2016/679

Article 9 – paragraph 2 – point l

Text proposed by the CommissionAmendment
(l) processing of biometric data is necessary for the purpose of confirming the identity of a data subject (verification), where the biometric data or the means needed for the verification is under the sole control of the data subject.(l) processing of biometric data is necessary for the purpose of confirming the identity of a data subject (verification), where the biometric data or the means needed for the one-to-one verification is under the sole control of the data subject, subject to appropriate safeguards laid down in Union law to protect the fundamental rights and the interests of the data subject.

Or. en

Amendment 47

Proposal for a regulation

Article 3 – paragraph 1 – point 3 a (new)

Regulation (EU) 2016/679

Article 12 – paragraph 3

Present textAmendment
3a. in Article 12, paragraph 3 is replaced by the following:
3. The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. The controller shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay. Where the data subject makes the request by electronic form means, the information shall be provided by electronic means where possible, unless otherwise requested by the data subject.3. The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. The controller shall inform the data subject of any such extension without undue delay and in any event within one month of receipt of the request, together with the reasons for the delay. Where the data subject makes the request by electronic form means, the information shall be provided by electronic means where possible, unless otherwise requested by the data subject.

Or. en

Amendment 48

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5 – subparagraph 1 – introductory part

Text proposed by the CommissionAmendment
Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 15 because the data subject abuses the rights conferred by this regulation for purposes other than the protection of their data, the controller may either:(5) Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the controller shall give the data subject a choice between:
(a) charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or(a) paying a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or
(b) refuse to act on the request.(b) their request being refused.

Or. en

Amendment 49

Proposal for a regulation

Article 3 – paragraph 1 – point 4

Regulation (EU) 2016/679

Article 12 – paragraph 5 – subparagraph 2

Text proposed by the CommissionAmendment
The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive.The controller shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request.

Or. en

Amendment 50

Proposal for a regulation

Article 3 – paragraph 1 – point 4 a (new)

Regulation (EU) 2016/679

Article 12 – paragraphs 7 and 8

Text proposed by the CommissionAmendment
4a. In Article 12, paragraphs 7 and 8 are deleted.

Or. en

Justification

The delegated acts for the purpose of determining the information to be presented by the icons and the procedures for providing standardised icons have never been adopted. Therefore it seems that these paragraphs are no longer needed.

Amendment 51

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – paragraph 1 – introductory part

Text proposed by the CommissionAmendment
1. A decision which produces legal effects for a data subject or similarly significantly affects him or her may be based solely on automated processing, including profiling, only where that decision:1. The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or that similarly significantly affects them, unless such processing:

Or. en

Amendment 52

Proposal for a regulation

Article 3 – paragraph 1 – point 7

Regulation (EU) 2016/679

Article 22 – paragraph 1 – point b

Text proposed by the CommissionAmendment
(b) is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests; or(b) is authorised by Union or Member State law to which the controller is subject and which lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests; or

Or. en

Amendment 53

Proposal for a regulation

Article 3 – paragraph 1 – point 7 a (new)

Regulation (EU) 2016/679

Article 22 – paragraph 3

Present textAmendment
7a. In Article 22, paragraph 3 is replaced by the following:
3. In the cases referred to in points (a) and (c) of paragraph 2, the data controller shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.3. In the cases referred to in points (a) and (c) of paragraph 1, the data controller shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, at least the right to obtain meaningful human intervention on the part of the controller, to express his or her point of view and to challenge the decision taken in respect of them. Meaningful human intervention on the part of the controller requires that the human reviewer has the authority, knowledge, and competence to modify the contested decision, and that they actively analyse all relevant data, not merely the output of the system.

Or. en

Amendment 54

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point a

Regulation (EU) 2016/679

Article 33 – paragraph 1

Text proposed by the CommissionAmendment
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.

Or. en

Amendment 55

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point b

Regulation (EU) 2016/679

Article 33 – paragraph 1 a

Text proposed by the CommissionAmendment
1a. Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.1a. Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.

Or. en

Amendment 56

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point c

Regulation (EU) 2016/679

Article 33 – paragraph 6

Text proposed by the CommissionAmendment
6. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).6. By …[PO please insert date: nine months from the entry into application of this amending Regulation] the Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The Commission may adopt the template as established by the Board by way of an implementing act in accordance with the examination procedure set out in Article 93(2) of this Regulation.

Or. en

Amendment 57

Proposal for a regulation

Article 3 – paragraph 1 – point 8 – point c

Regulation (EU) 2016/679

Article 33 – paragraph 7

Text proposed by the CommissionAmendment
7. The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.7. The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Commission may adopt necessary updates of the template by way of an implementing act following the procedure referred to in paragraph 6.

Or. en

Amendment 58

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 4

Text proposed by the CommissionAmendment
4. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.4. By …[PO please insert date: nine months from the entry into application of this amending Regulation] the Board shall establish and make public:
(a) a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1;
(b) a list of the kind of processing operations for which no data protection impact assessment is required;
(c) a common template and a common methodology for conducting data protection impact assessments.

Or. en

Amendment 59

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 5

Text proposed by the CommissionAmendment
5. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.deleted.

Or. en

Amendment 60

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point a

Regulation (EU) 2016/679

Article 35 – paragraph 6

Text proposed by the CommissionAmendment
6. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.deleted

Or. en

Amendment 61

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point b

Regulation (EU) 2016/679

Article 35 – paragraph 6 a

Text proposed by the CommissionAmendment
6a. The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).6a. The Commission may adopt the template as established by the Board by way of an implementing act in accordance with the examination procedure set out in Article 93(2) of this Regulation.

Or. en

Amendment 62

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point b

Regulation (EU) 2016/679

Article 35 – paragraph 6 b

Text proposed by the CommissionAmendment
6b. The lists and the template and methodology referred to in paragraph 6a- shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.6b. The lists and the template and methodology referred to in paragraph 4 shall be reviewed by the Board at least every three years and updated where necessary. The Commission may adopt any updates of the template by way of an implementing act in accordance with the procedure referred to in paragraph 6a.

Or. en

Amendment 63

Proposal for a regulation

Article 3 – paragraph 1 – point 9 – point b

Regulation (EU) 2016/679

Article 35 – paragraph 6 c

Text proposed by the CommissionAmendment
6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraph 4, points (a) and (b).

Or. en

Amendment 64

Proposal for a regulation

Article 3 – paragraph 1 – point 14

Regulation (EU) 2016/679

Article 70 – paragraph 1 – point h a

Text proposed by the CommissionAmendment
(ha) prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment and for which no data protection impact assessment is required, pursuant to Article 35.(ha) establish a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment and for which no data protection impact assessment is required, pursuant to Article 35.

Or. en

Amendment 65

Proposal for a regulation

Article 3 – paragraph 1 – point 14

Regulation (EU) 2016/679

Article 70 – paragraph 1 – point h b

Text proposed by the CommissionAmendment
(hb) prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments, pursuant to Article 35.(hb) establish a common template and a common methodology for conducting data protection impact assessments, pursuant to Article 35.

Or. en

Amendment 66

Proposal for a regulation

Article 3 – paragraph 1 – point 14

Regulation (EU) 2016/679

Article 70 – paragraph 1 – point h c

Text proposed by the CommissionAmendment
(hc) prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person pursuant to Article 33(hc) establish a common template for notifying a personal data breach to the competent supervisory authority as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person pursuant to Article 33.

Or. en

Amendment 67

Proposal for a regulation

Article 3 – paragraph 1 – point 14 a (new)

Regulation (EU) 2016/679

Article 70 – paragraph 3

Present textAmendment
14a. in Article 70, paragraph 3 is replaced by the following:
3. The Board shall forward its opinions, guidelines, recommendations, and best practices to the Commission and to the committee referred to in Article 93 and make them public.3. The Board shall forward its opinions, guidelines, recommendations, templates, lists and best practices to the Commission and to the committee referred to in Article 93 and make them public.

Or. en

Amendment 68

Proposal for a regulation

Article 4 – paragraph 1 – point 1 – point b

Regulation (EU) 2018/1725

Article 3 – paragraph 1 – point 25

Text proposed by the CommissionAmendment
(25) for ‘electronic communications networks’ the definition of Article 2(1) of Directive (EU) 2018/1972 shall apply;(25) ‘electronic communications networks’ means electronic communications networks as defined in Article 2(1) point (1) of Directive (EU) 2018/1972;

Or. en

Amendment 69

Proposal for a regulation

Article 4 – paragraph 1 – point 2

Regulation (EU) 2018/1725

Article 4 – paragraph 1 – point b

Text proposed by the CommissionAmendment
(b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 13, be considered to be compatible with the initial purposes, independent of the conditions of Article 6 of this Regulation, (‘purpose limitation’);(b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, subject to the application of appropriate safeguards in accordance with Article 13, be considered to be compatible with the initial purposes, independent of the conditions of Article 6 of this Regulation, (‘purpose limitation’);

Or. en

Amendment 70

Proposal for a regulation

Article 4 – paragraph 1 – point 3 – point a

Regulation (EU) 2018/1725

Article 10 – paragraph 2 – point l

Text proposed by the CommissionAmendment
(l) processing of biometric data is necessary for the purpose of confirming the identity of a data subject (verification), where the biometric data or the means needed for the verification is under the sole control of the data subject.(l) processing of biometric data is necessary for the purpose of confirming the identity of a data subject (verification), where the biometric data or the means needed for the one-to-one verification is under the sole control of the data subject, subject to appropriate safeguards laid down in Union law to protect the fundamental rights and the interests of the data subject.

Or. en

Amendment 71

Proposal for a regulation

Article 4 – paragraph 1 – point 4

Regulation (EU) 2018/1725

Article 14 – paragraph 5

Text proposed by the CommissionAmendment
4. in Article 14, paragraph 5 is replaced by the following:deleted
5. Information provided under Articles 15 and 16 and any communication and any actions taken under Articles 17 to 24 and 35 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 17 because the data subject abuses the rights conferred by this Regulation for purposes other than the protection of their data, the controller may refuse to act on the request. The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive.

Or. en

Justification

This amendment is deleted in order to align with amendments made by rapporteurs in Regulation (EU) 2016/679.

Amendment 72

Proposal for a regulation

Article 4 – paragraph 1 – point 6

Regulation (EU) 2018/1725

Article 24 – paragraph 1 – introductory part

Text proposed by the CommissionAmendment
1. A decision which produces legal effects for a data subject or similarly significantly affects him or her may be based solely on automated processing, including profiling, only where that decision:1. The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or that similarly significantly affects them, unless such processing:

Or. en

Amendment 73

Proposal for a regulation

Article 4 – paragraph 1 – point 6

Regulation (EU) 2018/1725

Article 24 – paragraph 1 – point b

Text proposed by the CommissionAmendment
(b) is authorised by Union law to which the controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests; or(b) is authorised by Union law to which the controller is subject and which lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests; or

Or. en

Amendment 74

Proposal for a regulation

Article 4 – paragraph 1 – point 9 – point a

Regulation (EU) 2018/1725

Article 39 – paragraph 4

Text proposed by the CommissionAmendment
4. The lists, the template and methodology adopted by the Commission and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation.4. The lists, the template and methodology established by the Board and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation.

Or. en

Amendment 75

Proposal for a regulation

Article 6 – paragraph 1 – point -1 (new)

Directive (EU) 2022/2555

Article 14 a (new)

Text proposed by the CommissionAmendment
(-1) The following Article is inserted:
Article 14a
Harmonised application of the NIS2 Directive
1. To ensure the consistent and proportionate application of this Directive across the Union, the Commission shall, in cooperation with the Cooperation Group referred to in Article 14 of this Directive and ENISA, issue guidance on the harmonised interpretation and application of key obligations under the NIS2 Directive;

Or. en

Amendment 76

Proposal for a regulation

Article 6 – paragraph 1 – point 1 (new)

Directive (EU) 2022/2555

Article 23a – paragraph 3 a (new)

Text proposed by the CommissionAmendment
(3a) The Commission shall, by means of implementing acts, develop a common notification template for the single-entry point covering the Union acts referred to in paragraph 1 that provide for notification through that single-entry point. It shall enable entities to submit a single notification to fulfil multiple reporting obligations. When preparing the draft implementing acts, the Commission shall consult ENISA, the Cooperation Group, the network of computer security incident response teams (CSIRTs Network) and, where relevant, other competent authorities responsible for the Union legal acts concerned;

Or. en

Amendment 77

Proposal for a regulation

Article 10 – paragraph 1

Regulation 2019/1150/EU

Text proposed by the CommissionAmendment
1. Regulation 2019/1150/EU is repealed with effect from [date = entry into application of this Regulation].deleted

Or. en

Amendment 78

Proposal for a regulation

Article 10 – paragraph 2

Regulation 2019/1150/EU

Text proposed by the CommissionAmendment
2. By way of derogation from paragraph 1, the following provisions shall continue to apply until 31 December 2032:deleted
(a) Article 2, point (1);
(b) Article 2, point (2);
(c) Article 2, point (5);
(d) Article 4;
(e) Article 11;
(f) Article 15.

Or. en

Explanatory statement 5 paragraphs

The objective of the Digital Omnibus is to reduce unnecessary administrative burden, improve implementation, support compliance and provide for enhanced legal certainty, whilst safeguarding the EU acquis on privacy and personal data. In recent months, a priority policy objective for the EU has been to address our lack of technological sovereignty, and simplification initiatives could be an important part of this. It is important to be able to develop AI and other digital services, in Europe, by European companies. To do so we need predictable rules that also guarantee a high level of protection of privacy and personal data to ensure the trust of Europeans in these technologies.

Particular attention should be paid to ensuring that we foster a highly competitive, innovative, and secure data economy within the Union, by having clear rules and trust in European data sharing environments. The Single-Entry Point is a welcome proposal to streamline the reporting process but we must look beyond a single portal by aligning what is being reported to truly alleviate administrative burden for businesses. While simplification efforts are welcome, they should not come at a disadvantage to European SMEs, as regards the entire repeal of the P2B, that has important transparency measures and contractual predictability for SMEs that should be maintained.

Simplification for the purpose of greater compliance of data protection rules by the companies for the protection of individuals is a shared objective of the rapporteurs. Common templates for notifying a personal data breach and for data protection impact assessments provide greater simplification and harmonisation. The same is true for the lists specifying in which circumstances a data breach is likely to result in a high risk, and those specifying which processing operations require a data protection impact assessment. The expertise of the EDPB with regard to establishing these lists and templates is indisputable and would merit a clarification. The Rapporteurs do not find limiting the rights of data subject’s access to data processed concerning them necessary or proportionate to achieve simplification. Therefore, the self-standing rights provided by Article 8 of the Charter of Fundamental Rights, including for purposes beyond the protection of the data subject's own data, should continue to be upheld.

General remarks

In the preparation of this report, the co-rapporteurs have heard from a wide variety of stakeholders and understand that there are varying degrees of possible impacts and interpretations of the proposal of the Commission. To support our work, the Parliament has requested a targeted impact assessment on specific provisions in Articles 3, 4 and 10 of the proposal, in order to provide greater legal certainty and achieve the core objectives of the Digital Omnibus without compromising the protection of fundamental rights.

Annex: declarations of input 10 paragraphs

DECLARATION OF INPUT FROM AURA SALLA

Pursuant to Article 8 of Annex I to the Rules of Procedure, the rapporteur declares that she included in her report input on matters pertaining to the subject of the file that she received, in the preparation of the draft report, from the following interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register, or from the following representatives of public authorities of third countries, including their diplomatic missions and embassies:

1. Interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register
Alliance for the Freedom of Car Repair (AFCAR)
Automotive Data Publishers’ Association (ADPA)
University of Tampere
Häme University of Applied Sciences
BMW
Applia
Medtech Europe
SOK
COCIR
Philips
Technology Industries of Finland (Teknologiateollisuus ry)
Telefonica
Edri – European Digital Rights
German Advertising Federation (ZAW)
BEUC
European Fintech Association
European Data Protection Supervisor (EDPS)
Orgalim
EU Tech Alliance (EUTA)
Hotrec
European Hotel Forum
Amadeus
Axceptio
Finanssiala
Volkswagen Group
Alstom
EFPIA (European Federation of Pharmaceutical Industries and Associations)
EFCA (European Engineering Consultancies)
IAB Europe
German Insurance Association (GDV)
VDMA
Sanoma Media
Schibsted
JP Politiken Media Group
Zalando
AI Sweden
Noyb
Suomen Yrittäjät
Criteo
Siemens Energy
Ledger
L’AFEP
ZVEI
Delivery Hero
Clever Cloud
CISPE
France Digitale
Business Europe
ENISA
Insurance Europe
Civil Liberties Union for Europe
EK (Confederation of Finnish industries)
OLX
Wolt
European Data Protection Board (EDPB)
Enterprise Mobility
AI Finland
Digitaleurope
FiCom
Finnish Commerce Federation
The Finnish Hospitality Association MaRa
Finnish Food and Drink Industries’ Federation
Finnmedia
CSC
Elisa
Nokia
Planmeca
European Law Institute
Shopify
Reaktor
Sanoma Media Finland
Telia
Terveystalo
Valmet
Wärtsilä
Dittmar & Indrenius
Dottir
Krogerus
Laissa Oy
European Banking Federation (EBF)
SAP
Ikea
Siemens
Salesforce
IBM
Mozilla
Pensions Europe
UNIFE
Rasmussen Global
Mouvement des Entreprises de France – MEDEF
Confindustria
BDI
Skyscanner
Audience Measurement Coalition
Federation of Finnish Enterprises
ACT Europe
Check My Ads
FIGIEFA
ZDH German Confederation of skilled crafts and small business
ICCL (Irish Council of Civil Liberties)
Allegro
IMT Atlantique
2. Representatives of public authorities of third countries, including their diplomatic missions and embassies
None

The list above is drawn up under the exclusive responsibility of the rapporteur.

Where natural persons are identified in the list by their name, by their function or by both, the rapporteur declares that she has submitted to the natural persons concerned the European Parliament's Data Protection Notice No 484 (https://www.europarl.europa.eu/data-protect/index.do), which sets out the conditions applicable to the processing of their personal data and the rights linked to that processing.

DECLARATION OF INPUT FROM MARINA KALJURAND

Pursuant to Article 8 of Annex I to the Rules of Procedure, the rapporteur declares that she included in her report input on matters pertaining to the subject of the file that she received, in the preparation of the draft report, from the following interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register, or from the following representatives of public authorities of third countries, including their diplomatic missions and embassies:

1. Interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register
Allegro
Alliance for the Freedom of Car Repair
Amadeus
Apple Inc.
BEUC
Bundesverband Digitale Wirtschaft
Centre for Democracy & Technology
Check My Ads
Cisco Systems Inc.
Civil Liberties Union for Europe
Computer and Communications Industry Association
Digitaleurope
DOT Europe
Eesti Meediaettevõtete Liit
European Digital Rights
European Federation of Pharmaceutical Industries and Associations
European FinTech Association
European Magazine Media Association
European Newspaper Publishers' Association
European Tech Alliance
FIGIEFA
Google
IBM Corporation
Irish Council for Civil Liberties
ITI - The Information Technology Industry Council
Microsoft Corporation
Mozilla Corporation
noyb - European Center for Digital Rights
Orgalim – Europe's Technology Industries
Palo Alto Networks Inc.
PensionsEurope
SAP
Siemens
Volkswagen
Zentralverband des Deutschen Handwerks e.V.
2. Representatives of public authorities of third countries, including their diplomatic missions and embassies
None

The list above is drawn up under the exclusive responsibility of the rapporteur.

Where natural persons are identified in the list by their name, by their function or by both, the rapporteur declares that she has submitted to the natural persons concerned the European Parliament's Data Protection Notice No 484 (https://www.europarl.europa.eu/data-protect/index.do), which sets out the conditions applicable to the processing of their personal data and the rights linked to that processing.