Text · Amendment list
Amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557 as regards the simplification of the digital legislative framework, and repealing Regulations (EU) 2018/1807, (EU) 2019/1150, (EU) 2022/868, and Directive (EU) 2019/1024 (Digital Omnibus)
Full title
Amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557 as regards the simplification of the digital legislative framework, and repealing Regulations (EU) 2018/1807, (EU) 2019/1150, (EU) 2022/868, and Directive (EU) 2019/1024 (Digital Omnibus)
Document CJ72-AM-791874 · COM(2025)0837 – 2025/0360(COD)
- Kind
- Amendment list CJ72-AM-791874
- Date
- 27 July 2026
- Committee
- Committee on Industry, Research and Energy Committee on Civil Liberties, Justice and Home Affairs
- Dossier
- 2025-0360
More facts (2)
- Formats
- Official page PDF Word
- Reference
- COM(2025)0837 – 2025/0360(COD)
Text
The text as parsed from the official Word file. Every paragraph has a link (¶) and can be saved to a project as a passage.
Jump to an amendment (176)
- Amendment 1565
- Amendment 1566
- Amendment 1567
- Amendment 1568
- Amendment 1569
- Amendment 1570
- Amendment 1571
- Amendment 1572
- Amendment 1573
- Amendment 1574
- Amendment 1575
- Amendment 1576
- Amendment 1577
- Amendment 1578
- Amendment 1579
- Amendment 1580
- Amendment 1581
- Amendment 1582
- Amendment 1583
- Amendment 1584
- Amendment 1585
- Amendment 1586
- Amendment 1587
- Amendment 1588
- Amendment 1589
- Amendment 1590
- Amendment 1591
- Amendment 1592
- Amendment 1593
- Amendment 1594
- Amendment 1595
- Amendment 1596
- Amendment 1597
- Amendment 1598
- Amendment 1599
- Amendment 1600
- Amendment 1601
- Amendment 1602
- Amendment 1603
- Amendment 1604
- Amendment 1605
- Amendment 1606
- Amendment 1607
- Amendment 1608
- Amendment 1609
- Amendment 1610
- Amendment 1611
- Amendment 1612
- Amendment 1613
- Amendment 1614
- Amendment 1615
- Amendment 1616
- Amendment 1617
- Amendment 1618
- Amendment 1619
- Amendment 1620
- Amendment 1621
- Amendment 1622
- Amendment 1623
- Amendment 1624
- Amendment 1625
- Amendment 1626
- Amendment 1627
- Amendment 1628
- Amendment 1629
- Amendment 1630
- Amendment 1631
- Amendment 1632
- Amendment 1633
- Amendment 1634
- Amendment 1635
- Amendment 1636
- Amendment 1637
- Amendment 1638
- Amendment 1639
- Amendment 1640
- Amendment 1641
- Amendment 1642
- Amendment 1643
- Amendment 1644
- Amendment 1645
- Amendment 1646
- Amendment 1647
- Amendment 1648
- Amendment 1649
- Amendment 1650
- Amendment 1651
- Amendment 1652
- Amendment 1653
- Amendment 1654
- Amendment 1655
- Amendment 1656
- Amendment 1657
- Amendment 1658
- Amendment 1659
- Amendment 1660
- Amendment 1661
- Amendment 1662
- Amendment 1663
- Amendment 1664
- Amendment 1665
- Amendment 1666
- Amendment 1667
- Amendment 1668
- Amendment 1669
- Amendment 1670
- Amendment 1671
- Amendment 1672
- Amendment 1673
- Amendment 1674
- Amendment 1675
- Amendment 1676
- Amendment 1677
- Amendment 1678
- Amendment 1679
- Amendment 1680
- Amendment 1681
- Amendment 1682
- Amendment 1683
- Amendment 1684
- Amendment 1685
- Amendment 1686
- Amendment 1687
- Amendment 1688
- Amendment 1689
- Amendment 1690
- Amendment 1691
- Amendment 1692
- Amendment 1693
- Amendment 1694
- Amendment 1695
- Amendment 1696
- Amendment 1697
- Amendment 1698
- Amendment 1699
- Amendment 1700
- Amendment 1701
- Amendment 1702
- Amendment 1703
- Amendment 1704
- Amendment 1705
- Amendment 1706
- Amendment 1707
- Amendment 1708
- Amendment 1709
- Amendment 1710
- Amendment 1711
- Amendment 1712
- Amendment 1713
- Amendment 1714
- Amendment 1715
- Amendment 1716
- Amendment 1717
- Amendment 1718
- Amendment 1719
- Amendment 1720
- Amendment 1721
- Amendment 1722
- Amendment 1723
- Amendment 1724
- Amendment 1725
- Amendment 1726
- Amendment 1727
- Amendment 1728
- Amendment 1729
- Amendment 1730
- Amendment 1731
- Amendment 1732
- Amendment 1733
- Amendment 1734
- Amendment 1735
- Amendment 1736
- Amendment 1737
- Amendment 1738
- Amendment 1739
- Amendment 1740
| Text proposed by the Commission | Amendment |
|---|---|
| Where the processing of personal data is necessary for the interests of the controller in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, such processing may be pursued for legitimate interests within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679, where appropriate, except where other Union or national laws explicitly require consent, and where such interests are overridden by the interests, or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. | Where the processing of personal data is necessary for the interests of the controller in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, such processing may be pursued for legitimate interests within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679, where such interests are overridden by the interests, or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. |
| Text proposed by the Commission | Amendment |
|---|---|
| Where the processing of personal data is necessary for the interests of the controller in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, such processing may be pursued for legitimate interests within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679, where appropriate, except where other Union or national laws explicitly require consent, and where such interests are overridden by the interests, or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. | Where the processing of personal data is necessary for the interests of the controller in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, such processing may be pursued for legitimate interests within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679, where appropriate, except where other Union laws explicitly require consent, and where such interests are overridden by the interests, or fundamental rights and freedoms of the data subject which require protection of personal data. |
Europe needs a clear, harmonised lawful basis for responsible AI development and operation. Divergent interpretations of legitimate interest create uncertainty, compliance costs and incentives to train, test and validate AI outside Europe. The amendment confirms that Article 6(1)(f) may apply where processing is necessary and balanced against data-subject rights, while preserving consent requirements, the duty to choose the correct lawful basis and safeguards against disclosure of residually retained data.
Zala Černilec Tomašič, Jan Farský, Ondřej Krutílek, Tomáš Zdechovský, Michał Wawrykiewicz, Henrik Dahl, Alexandr Vondra, Veronika Vrecionová, Lukas Mandl
| Text proposed by the Commission | Amendment |
|---|---|
| Where the processing of personal data is necessary for the interests of the controller in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, such processing may be pursued for legitimate interests within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679, where appropriate, except where other Union or national laws explicitly require consent, and where such interests are overridden by the interests, or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. | Where the processing of personal data is necessary for the interests of the controller or a third party in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, such processing may be pursued for legitimate interests within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679, where appropriate, and where such interests are overridden by the interests, or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. |
This amendment aligns Article 88c with the GDPR by recognising the legitimate interests of both controllers and third parties, avoiding unnecessary restrictions on AI supply chains. It removes references that could reintroduce divergent national rules on consent and an "unconditional right to object," which is already governed by Article 21 GDPR. The amendment preserves data protection while improving legal certainty, consistency, and Single Market harmonisation.
| Text proposed by the Commission | Amendment |
|---|---|
| Where the processing of personal data is necessary for the interests of the controller in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, such processing may be pursued for legitimate interests within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679, where appropriate, except where other Union or national laws explicitly require consent, and where such interests are overridden by the interests, or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. | Where the processing of personal data is necessary for the interests of the controller or a third party in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, such processing may be pursued for legitimate interests within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679, where appropriate, except where other Union or national laws explicitly require consent, and where such interests are overridden by the interests, or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. |
Article 88c should remain fully coherent not to create new sources of legal fragmentation within the Union. While the Commission’s objective of simplification is well founded, the current wording of Article 88c does not fully achieve that aim.First, Article 6 GDPR expressly refers to the legitimate interests of both the controller and a third party. Limiting Article 88c to the interests of the controller alone would therefore introduce an unnecessary restriction and would reduce legal certainty for the development and operation of AI systems. Second, the reference to an “unconditional right to object” is not aligned with the GDPR framework. The right to object is already comprehensively governed by Article 21 GDPR, which establishes the applicable conditions and limitations. Introducing an unconditional variant within Article 88c would deviate from that framework, create inconsistencies in interpretation and enforcement, and effectively render the legitimate interests ground unavailable in practice for the purposes covered by this provision.
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| Where the processing of personal data is necessary for the interests of the controller in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, such processing may be pursued for legitimate interests within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679, where appropriate, except where other Union or national laws explicitly require consent, and where such interests are overridden by the interests, or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. | Processing of personal data that is necessary for the legitimate interests pursued by the controller or by a third party may be carried out on the basis of Article 6(1)(f), where appropriate, except where other Union or national laws explicitly require consent, and where such interests are overridden by the interests, or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. Such processing shall remain subject to an assessment carried out on a case-by-case basis. It shall not benefit from any presumption of lawfulness. |
| Text proposed by the Commission | Amendment |
|---|---|
| Where the processing of personal data is necessary for the interests of the controller in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, such processing may be pursued for legitimate interests within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679, where appropriate, except where other Union or national laws explicitly require consent, and where such interests are overridden by the interests, or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. | Where the processing of personal data is necessary for the interests of the controller in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, such processing may be pursued for legitimate interests within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679 except where other Union or national laws explicitly require consent, and where such interests are overridden by the interests, or fundamental rights and freedoms of the data subject in accordance with Articles 6 and 21 of this Regulation, in particular where the data subject is a child. |
| Text proposed by the Commission | Amendment |
|---|---|
| Where the processing of personal data is necessary for the interests of the controller in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, such processing may be pursued for legitimate interests within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679, where appropriate, except where other Union or national laws explicitly require consent, and where such interests are overridden by the interests, or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. | Where the processing of personal data is necessary for the interests of the controller in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, such processing may be pursued for legitimate interests within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679, except where other Union or national laws explicitly require consent, and where such interests are overridden by the interests, or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. |
| (The intention is to remove the words "where appropriate") |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| In Article 88c, the following paragraph is inserted: | |
| '1a. In addition to the information referred to in Article 13 and 14, the controller shall provide the data subject with details of the actions taken under paragraph 1.' |
| Text proposed by the Commission | Amendment |
|---|---|
| In Article 88c, the following paragraph is added: | |
| '2a. The Commission shall issue guidelines on the assessment of legitimate interests in the context of training and testing of AI systems and AI models.' |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| In Article 88c, the following paragraph is added: | |
| '2a. Member States shall ensure that data subjects can exercise their absolute right to object under paragraph 1, subparagraph (a) with a public body, that provides such objections and pseudonymous identification data to controllers for the sole purpose of administering objections.' |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| In Article 88c, the following paragraph is added: | |
| '2b. Paragraph 1 does not apply to the processing of personal data under Article 85 GDPR.' |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| In Article 88c, the following paragraph is added: | |
| '2c. The Commission shall, in accordance with Article 10(1) of Regulation (EU) 1025/2012, request one or more European standardisation organisations to draft minimum standards for anonymization and abstraction techniques under paragraph 1, subparagraph (b) and (c).' |
| Text proposed by the Commission | Amendment |
|---|---|
| Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with an unconditional right to object to the processing of their personal data. | deleted |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with an unconditional right to object to the processing of their personal data. | deleted |
Andrea Wechsler, Marie-Sophie Lanig, Stefan Köhler, Alexandra Mehnert, Verena Mertens, Sabine Verheyen
| Text proposed by the Commission | Amendment |
|---|---|
| Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with an unconditional right to object to the processing of their personal data. | 2) Where the task or official authority of a public authority or body is laid down by Union or Member State law in accordance with Article 6(3), personal data may be further processed for the purposes referred to in paragraph 1 on the basis of Article 6(1), point (e), where: |
| (a) the development or use of the AI system or AI model serves the performance of that task or the exercise of that official authority; | |
| (b) the purpose pursued cannot be effectively achieved by processing non-personal or anonymised data; and | |
| (c) the processing is necessary and proportionate to the public interest objective pursued. This paragraph shall not confer any new task or official authority on a public authority or body. | |
| 3) Controllers shall use non-personal or anonymised data where the purpose of the processing can reasonably and effectively be achieved by using such data.Where the use of personal data is necessary, controllers shall use pseudonymised data wherever the purpose can reasonably and effectively be achieved by using such data. | |
| 4) Processing pursuant to paragraphs 1 and 2 shall be subject to appropriate technical and organisational measures and safeguards for the rights and freedoms of data subjects. Those measures shall include, as appropriate: | |
| (a) ensuring data minimisation during the selection of data sources and throughout the training, testing, validation, deployment and operation of the AI system or AI model; | |
| (b) limiting the processing to data that are adequate, relevant and necessary for the intended purpose; | |
| (c) applying state-of-the-art privacy-enhancing technologies, including pseudonymisation, where appropriate; | |
| (d) testing, monitoring and mitigating the risks of memorisation, regurgitation, data leakage, inference and unauthorised disclosure; | |
| (e) effectively preventing personal data retained or memorised in the AI system or AI model from being used to generate outputs which disclose or otherwise make those data available to persons not authorised to receive them; | |
| (f) ensuring that personal data are included in an output only where such inclusion is necessary for the intended purpose, the recipient is authorised to receive the data and the disclosure has a legal basis under Article 6 and, where applicable, Article 9; | |
| (g) providing appropriate transparency to data subjects; and | |
| (h) facilitating the exercise of the rights of data subjects under this Regulation. | |
| 5) Where the controller cannot effectively prevent the unauthorised disclosure of personal data through the output of the AI system or AI model, the controller shall not deploy or operate that system or model in a manner that enables such disclosure. | |
| 6) The processing of special categories of personal data shall be permitted only where one of the conditions laid down in Article 9(2) is fulfilled. Where point (k) of Article 9(2) applies, the conditions and safeguards laid down in Article 9(5) shall apply. | |
| 7) Paragraphs 1 to 6 shall be without prejudice to the other provisions of this Regulation, Regulation (EU) 2024/1689 and other applicable Union or Member State law. |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with an unconditional right to object to the processing of their personal data. | Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, , including measures to limit the derivation, inference, extraction or regurgitation of personal data by the system or model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with an unconditional right to object to the processing of their personal data. Where the processing is carried out in the context of a high-risk AI system within the meaning of Regulation (EU) 2024/1689, or in the context of an AI regulatory sandbox or of testing in real world conditions under that Regulation, it shall comply with the conditions and safeguards laid down, respectively, in Articles 14, 59, 60 and 61 of that Regulation, which continue to apply. |
The processing of personal data for the development and operation of AI systems and models must be accompanied by robust safeguards. This amendment specifies the organisational and technical measures required — data minimisation at the stage of source selection and of training and testing, protection of residually retained data against disclosure, enhanced transparency, and an unconditional right to object. It further clarifies that, where such processing is carried out in the context of a high-risk AI system, an AI regulatory sandbox or testing in real world conditions, it must comply with the conditions and safeguards laid down in Articles 14, 59, 60 and 61 of Regulation (EU) 2024/1689, which continue to apply. This ensures the coherence of the Union acquis and prevents the facilitation of data processing for AI purposes from derogating from the requirements applicable under the Artificial Intelligence Act.
| Text proposed by the Commission | Amendment |
|---|---|
| Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with an unconditional right to object to the processing of their personal data. | Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects. |
Europe needs a clear, harmonised lawful basis for responsible AI development and operation. Divergent interpretations of legitimate interest create uncertainty, compliance costs and incentives to train, test and validate AI outside Europe. The amendment confirms that Article 6(1)(f) may apply where processing is necessary and balanced against data-subject rights, while preserving consent requirements, the duty to choose the correct lawful basis and safeguards against disclosure of residually retained data.
| Text proposed by the Commission | Amendment |
|---|---|
| Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with an unconditional right to object to the processing of their personal data. | Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with an unconditional right to object to the processing of their personal data. Where age assurance is necessary, it should rely on privacy-preserving and data-minimising techniques, and should not undermine the anonymity or confidentiality of communications. |
| Text proposed by the Commission | Amendment |
|---|---|
| Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with an unconditional right to object to the processing of their personal data. | Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with an unconditional right to object to the processing of their personal data. When assessing the safeguards required, account shall be taken of safeguards already provided for under Union or national law. |
| Text proposed by the Commission | Amendment |
|---|---|
| Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with an unconditional right to object to the processing of their personal data. | Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model. |
| Text proposed by the Commission | Amendment |
|---|---|
| Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with an unconditional right to object to the processing of their personal data. | Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of an AI system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with right to object to the processing of their personal data in accordance with Article 21 of Regulation (EU) 2016/679. |
Article 88c should remain fully coherent not to create new sources of legal fragmentation within the Union. While the Commission’s objective of simplification is well founded, the current wording of Article 88c does not fully achieve that aim.First, Article 6 GDPR expressly refers to the legitimate interests of both the controller and a third party. Limiting Article 88c to the interests of the controller alone would therefore introduce an unnecessary restriction and would reduce legal certainty for the development and operation of AI systems. Second, the reference to an “unconditional right to object” is not aligned with the GDPR framework. The right to object is already comprehensively governed by Article 21 GDPR, which establishes the applicable conditions and limitations. Introducing an unconditional variant within Article 88c would deviate from that framework, create inconsistencies in interpretation and enforcement, and effectively render the legitimate interests ground unavailable in practice for the purposes covered by this provision.
Zala Černilec Tomašič, Jan Farský, Ondřej Krutílek, Tomáš Zdechovský, Michał Wawrykiewicz, Henrik Dahl, Alexandr Vondra, Veronika Vrecionová, Lukas Mandl
| Text proposed by the Commission | Amendment |
|---|---|
| Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with an unconditional right to object to the processing of their personal data. | Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of an AI system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with right to object to the processing of their personal data in accordance with Article 21 of Regulation (EU) 2016/679. |
This amendment aligns Article 88c with the GDPR by recognising the legitimate interests of both controllers and third parties, avoiding unnecessary restrictions on AI supply chains. It removes references that could reintroduce divergent national rules on consent and an "unconditional right to object," which is already governed by Article 21 GDPR. The amendment preserves data protection while improving legal certainty, consistency, and Single Market harmonisation.
Oliver Schenk, François-Xavier Bellamy, Angelika Niebler, Monika Hohlmeier, Dimitris Tsiodras, Christian Doleschal, Axel Voss, Ana Miguel Pedro, Marion Walsmann, Lena Düpont, Romana Tomc, Marie-Sophie Lanig, Aura Salla
| Text proposed by the Commission | Amendment |
|---|---|
| Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with an unconditional right to object to the processing of their personal data. | Any such processing shall be subject to appropriate organisational, technical and legal measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects. |
| Text proposed by the Commission | Amendment |
|---|---|
| Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with an unconditional right to object to the processing of their personal data. | Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with a right to object to the processing of their personal data. |
Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Angelika Niebler, Oliver Schenk, Christian Ehler
| Text proposed by the Commission | Amendment |
|---|---|
| Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with an unconditional right to object to the processing of their personal data. | Any such processing shall be subject to appropriate organisational, technical measures and safeguards for the rights and freedoms of the data subject, such as to ensure respect of data minimisation during the stage of selection of sources and the training and testing of AI an system or AI model, to protect against non-disclosure of residually retained data in the AI system or AI model to ensure enhanced transparency to data subjects and providing data subjects with a right to object to the processing of their personal data. |
| Text proposed by the Commission | Amendment |
|---|---|
| After Article 88c, the following article is inserted: | |
| 'Article 88d | |
| Processing in the context of the provision of audiovisual media services of general interest | |
| Where the processing of personal data, including the storage of or access to personal data already stored in the terminal equipment of a natural person, is necessary for the delivery and audience measurement of both programmes and advertising provided by audiovisual media services of general interest, as referred to in Article 7a of Directive 2010/13/EU, such processing shall be carried out on the basis of legitimate interests within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679. This shall apply except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject requiring the protection of personal data, in particular where the data subject is a child. | |
| Any such processing shall be subject to appropriate organisational and technical measures, as well as safeguards to protect the rights and freedoms of the data subject. These measures and safeguards shall be set out in a sectoral code of conduct established in accordance with Article 40(2)(b) of Regulation (EU) 2016/679 and approved pursuant to Article 40(5) thereof.' |
| Text proposed by the Commission | Amendment |
|---|---|
| In Article 88c, the following paragraph is added: | |
| '2a. When assessing the compliance of processing for the development, testing, validation or operation of artificial intelligence systems, competent authorities shall take due account of the actual availability of harmonised standards, common specifications, technical guidance and supporting compliance tools necessary for the effective implementation of the applicable obligations. The application timeline for high-risk AI obligations should be aligned with the actual current availability of technical standards and supporting tools.' |
| Text proposed by the Commission | Amendment |
|---|---|
| In Article 88c, the following paragraph is added: | |
| '2a. This does not affect the obligation of the controller to choose the most appropriate lawful ground of processing set out in Article 6 of Regulation (EU) 2016/679, such as Article 6(1)(e) with regard to processing by public authorities.' |
Europe needs a clear, harmonised lawful basis for responsible AI development and operation. Divergent interpretations of legitimate interest create uncertainty, compliance costs and incentives to train, test and validate AI outside Europe. The amendment confirms that Article 6(1)(f) may apply where processing is necessary and balanced against data-subject rights, while preserving consent requirements, the duty to choose the correct lawful basis and safeguards against disclosure of residually retained data.
| Text proposed by the Commission | Amendment |
|---|---|
| After Article 88c, the following article is inserted: | |
| 'Article 88d | |
| 1. The Commission and the European Data Protection Board shall develop voluntary, standardised and machine-readable templates tailored to SMEs for the fulfilment of information, documentation and notification obligations under this Regulation. | |
| 2. Supervisory authorities shall provide accessible and proportionate guidance channels for SMEs, taking due account of their administrative and financial capacity when determining practical compliance measures. | |
| 3. The measures referred to in paragraphs 1 and 2 shall be without prejudice to the responsibility of controllers and processors to comply with this Regulation.' |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| 15a. After Article 91 the following Chapter is added: | |
| 'Chapter IXa | |
| Confidentiality of communications and processing of electronic communications and information in terminal equipment | |
| Article 91a | |
| Confidentiality of electronic communications | |
| Electronic communications shall be confidential. Any interference with electronic communications, such as listening, tapping, storing, monitoring, scanning or other types of interception, surveillance, or any processing of electronic communications, by persons other than the user using the terminal equipment, shall be prohibited. Confidentiality of electronic communications shall also apply to data related to or processed by the terminal equipment. | |
| Article 91b | |
| Lawful processing of electronic communications data | |
| 1. Providers of electronic communications networks and electronic communications services may process electronic communications data only if it is technically necessary to achieve the transmission of the communication, for the duration necessary for that purpose. | |
| 2. Providers of electronic communications networks and services, or other parties acting on behalf of the provider or the user, may process electronic communications data only if it is technically necessary to maintain or restore the availability, integrity and confidentiality of the respective electronic communications network or services, or to detect technical faults and/or errors in the transmission of electronic communications, for the duration necessary for that purpose. | |
| 3. Providers of electronic communications networks and services may process electronic communications metadata only if: | |
| (a) processing is strictly necessary to meet mandatory quality of service requirements, including network management, pursuant to Directive (EU) 2018/1972 or Regulation (EU) 2015/2120 for the duration technically necessary for that purpose; | |
| (b) processing is strictly necessary for billing, determining interconnection payments, detecting or stopping fraudulent use of, or subscription to, electronic communications services; | |
| (c) the user concerned has given their consent to the processing of their communications metadata for one or more specified purposes in accordance with Article 4(11) provided that the purpose or purposes concerned could not be fulfilled without processing such metadata. | |
| 4. Providers of the electronic communications services may process electronic communications content data only: | |
| (a) for the sole purpose of the provision of a specific service requested by the user, if the -user concerned has given their consent to the processing of their electronic communications content data and the provision of that service cannot be fulfilled by the provider without the processing of such content data; | |
| (b) if all users have consented to the processing of their electronic communications content pursuant to Article 4(11) for one or more specified purposes that cannot be fulfilled by processing information that is made anonymous; or | |
| (c) for the purpose of the provision of a specific service explicitly requested by a user, for purely personal use, only for the duration necessary for that purpose and without the consent of all users only where such requested processing does not adversely affect the fundamental rights and interests of another user or users. | |
| Article 91c | |
| Protection of information transmitted to, stored in, related to, processed by and collected from users’ terminal equipment | |
| 1. Storing of information, or gaining of access to information already stored, in the terminal equipment including about its software and hardware, other than by the user concerned, shall be prohibited, except on the following grounds: | |
| (a) it is strictly necessary for the sole purpose of carrying out the transmission of an electronic communication over an electronic communications network, or; | |
| (b) the user has given their specific consent in accordance with this Regulation, or; | |
| (c) it is strictly technically necessary for providing an information society service specifically requested by the user; or | |
| (d) it is technically necessary for maintaining or restoring the technical security of a service provided by the controller and requested by the user, or; | |
| (e) for the purpose of delivering a form of online advertising (“strictly limited contextual advertising”), which is limited to processing the following information: | |
| i) information about the device, operating system and a browser; | |
| ii) coarse geolocation data, which is abstracted to the city level; | |
| iii) temporal information, such as date and time, and; | |
| iv) the content the user is immediately viewing, abstracted in broad categories. | |
| (f) for the purpose of limiting the number of times a specific advertisement is presented to the user (“first party frequency capping”), when such limitation meets the following conditions: | |
| i) an advertisement is delivered as defined under Article 91c (1) (e) of this Regulation; | |
| ii) information stored consists exclusively of a counter, or equivalent minimal signal; | |
| iii) information is stored by the provider of the online interface on which the advertisement is presented, and is automatically deleted no later than 14 days after creation, and; | |
| iv) the information is not used for any purpose other than frequency capping, is not combined, directly or indirectly, with any other dataset, including but not limited to identifiers, or data obtained from third parties, and the information is not transmitted to, or made accessible to any party other than the controller operating the domain under which it is stored. | |
| (g) for the purpose of measuring the reach and performance of specific advertising or an advertising campaign (“privacy preserving attribution”), when such measurement meets all of the following conditions: | |
| i) an advertisement is delivered as defined under Article 91c (1) (e) of this Regulation; | |
| ii) data is pseudonymised at the earliest stage possible; | |
| iii) data is processed solely on device and in an aggregated manner, and; | |
| iv) the information is not used for any purpose other than frequency capping, is not combined, directly or indirectly, with any other dataset, including but not limited to identifiers, or data obtained from third parties, and the information is not transmitted to, or made accessible to any party other than the controller operating the domain under which it is stored. | |
| (g) for the purpose of creating instant anonymous aggregated information about the usage of an online service requested by the user to measure the audience of such a service, where it is carried out by the provider of that online service requested by the user solely for its own use, or by a processor acting on behalf of this controller, solely for the controller’ own use and not further processed for any other purpose, not combined with data from other services from the provider of the online service, or from a third party, nor shared with any third party; | |
| (h) for the purpose of verifying the user’s past refusal to a request to consent without involving the use of a unique identifier or additional processing of personal data. | |
| 2. Where storing of information, or gaining of access to information already stored, in the terminal equipment of a user is based on consent, the following shall apply: | |
| (a) the user shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means; | |
| (b) if the user gives consent, the controller shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the user; | |
| (c) if the user declines a request for consent, the controller shall not make a new request for consent for the same purpose for a period of at least six months. | |
| This paragraph also applies to the subsequent processing of information based on consent. | |
| 3. No user shall be denied access to a renumerated service or functionality on grounds that they have not given their consent to the processing of their personal data and/or the use of the processing or storage capabilities of their terminal equipment that are not necessary for the provision of that service or functionality. | |
| 4. This Article shall apply from [OP: please insert the date = 6 months following the date of entry into force of this Regulation] | |
| Article 91d | |
| Information and options for privacy settings to be provided | |
| Software placed on the market permitting electronic communications and/or the retrieval and presentation of information on the internet, shall | |
| (a) by default, have, in accordance with Article 25 of this Regulation, privacy protective settings activated to prevent other parties from transmitting to or storing information on the terminal equipment of a user and from processing information already stored on or collected from that equipment, except for the purposes laid down in Article 91c. | |
| (b) upon installation, inform and offer the user the possibility to change or confirm the privacy settings options defined in point (a) by requiring the user's consent to a setting and offer the option to prevent other parties from processing information transmitted to, already stored on or collected from the terminal equipment for the purposes laid down by Article 91c; | |
| (c) offer the user the possibility to express specific consent through the settings after the installation of the software. The technical settings shall consist of multiple options for the user to choose from, including an option to prevent the storage of information on the terminal equipment of a user and the processing of information already stored on, or processed by, that equipment. These settings shall be easily accessible during the use of the software and presented in a manner that gives the user the possibility for making an informed decision. | |
| The settings shall lead to a signal based on technical specifications which is sent to the other parties to inform them about the user's intentions with regard to consent, withdrawal of consent or objection. This signal shall be legally valid and be binding on, and enforceable against, any other party. | |
| For software already placed on the market at the entry into force of this Regulation, the requirements under points (a) to (c) shall be complied with at the time of the first update of the software, but no later than one year after entry into force of this Regulation. | |
| Article 91e | |
| Automated and machine-readable indications of data subject’s choices with respect to processing of personal data in the terminal equipment of natural persons | |
| 1. Controllers shall ensure that their online interfaces allow data subjects to: | |
| (a) Give specific consent per purpose through automated and machine-readable means, provided that the conditions for consent laid down in this Regulation are fulfilled; | |
| (b) decline a request for consent, exercise the right to withdraw consent pursuant to Article 7(3) and the right to object pursuant to Article 21(1) and 21(2) through automated and machine-readable means. | |
| (c) refuse, by automated and machine-readable means, such as automated signals, all processing on terminal equipment that may otherwise be based on consent through automated and machine-readable means. This shall include processing for purposes related to cross-site tracking, profiling, personalised content, personalised advertising, and training of artificial intelligence systems. | |
| 2. Controllers shall respect the choices made by data subjects in accordance with paragraph 1. | |
| 3. Points (a) and (b) in paragraph 1 shall not apply to controllers that are media service providers when providing a media service. | |
| 4. Controllers shall not request the consent or choices of the data subject made in accordance with paragraph 1 (c) for the same purposes through separate consent or similar interfaces unless the data subject actively modifies their initial choices. | |
| The choices made by data subjects in accordance with paragraph 1 shall be communicated to all online interfaces visited by the data subject when using the same terminal equipment. | |
| 5. The Commission shall, in accordance with Article 10(1) of Regulation (EU) 1025/2012, request one or more European standardisation organisations to draft standards for the interpretation of machine-readable indications of data subjects’ choices. | |
| Online interfaces of controllers which are in conformity with harmonised standards or parts thereof the references of which have been published in the Official Journal of the European Union shall be presumed to be in conformity with the requirements covered by those standards or parts thereof, set out in paragraph 1. | |
| 6. The Commission shall ensure a balanced representation of interests and the effective participation of all relevant stakeholders in the standardisation process in accordance with Article 5 of Regulation (EU) No 1025/2012. | |
| 7. The Commission shall adopt implementing acts establishing common specifications for the requirements set out in paragraph 1 if the following conditions are fulfilled: | |
| (a) the Commission has requested one or more European standardisation organisations to draft harmonised standards as set out in paragraph 5, and: | |
| (i) the request has not been accepted by any of the European standardisation organisations; or | |
| (ii) the harmonised standards addressing that request are not delivered within the deadline set in accordance with Article 10(1) of Regulation (EU) No 1025/2012; or | |
| (iii) the harmonised standards do not comply with the request; and | |
| (b) no reference to harmonised standards covering the requirements set out in paragraph 1 of this article has been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012 and no such reference is expected to be published within a reasonable period. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2). | |
| 8. Paragraphs 1 and 2 shall apply from [OP: please insert the date = 24 months following the date of entry into force of this Regulation]. | |
| 9. Providers of software to access online interfaces, such as operating systems or web browsers, shall provide the technical means to allow data subjects to exercise, modify or withdraw their choices as defined in paragraph 1 of this Article through the automated and machine-readable means referred to therein. | |
| 10. The data subject’s choices set out in paragraph 1 shall be managed by a third-party software provider acting structurally and economically independently from the software providing access to online interfaces. | |
| 11. Where the third-party software provider, as referred to in paragraph 10, is itself a controller processing personal data on the terminal equipment of the data subject, the refusal signal referred to in Paragraphs 1 and 4 shall apply to such processing on the same terms as it applies to any other controller. | |
| In such a case, those software providers shall not process data derived from the data subject’s interaction with that software for purposes other than those necessary for provisioning of this software, including for purposes such as advertising, profiling, audience building, attribution, or the training of AI systems. | |
| Paragraph 9 shall apply from [OP: please insert the date = 18 months following the date of entry into force of this Regulation].' |
| Present text | Amendment |
|---|---|
| 15a. After Annex 1, the following Annex is added: | |
| No equivalent | "ANNEX Ia |
| Legitimate interests within the meaning of point (f) of the first subparagraph of Article 6 paragraph 1 include, but are not restricted to: | |
| 1. Legal and Regulatory Compliance | |
| a. preventing, detecting or investigating fraud and other criminal activities; | |
| b. ensuring workplace safety and security (eg, CCTV monitoring in public areas of the workplace or monitoring premises with sensitive operations); | |
| c. conducting audits or compliance checks; | |
| d. reporting illegal activities or threats to public safety to authorities; | |
| e. cooperating with authorities in situations of emergency. | |
| 2. Business Operations and Management | |
| a. ensuring the proper functioning of equipment, IT systems or infrastructure; | |
| b. ensuring network and information security (eg, preventing unauthorised access or cyberattacks) and preventing misuse of services or systems (eg, detecting bots or spam); | |
| c. protecting the controller’s or a third party’s assets, reputation, or intellectual property; | |
| d. establishing, exercising, or defending legal claims; | |
| e. monitoring business performance or productivity. | |
| 3. Research and Development | |
| a. conducting scientific or historical research; | |
| b. improving products or services (eg, based on customer feedback); | |
| c. developing new technologies or services (eg, training, validating or testing of artificial intelligence); | |
| d. clinical trials; | |
| e. archiving or statistical activities in the public interest. | |
| 4. Distribution and Marketing | |
| a. ensuring seamless transactions and user experiences on websites or apps; | |
| b. maintaining customer records for service continuity; | |
| c. conducting market research or customer satisfaction surveys; | |
| d. measuring the effectiveness of marketing campaigns. | |
| 5. Business Transactions | |
| a. transfers of employee, customer or supplier files within a group of companies; | |
| b. carrying out mergers, acquisitions, or similar business transactions; | |
| c. conducting due diligence in business transactions; | |
| d. assignment of claims, or provision of claims as a security, within common financial transactions. | |
| The fact that a processing operation is covered by subparagraph 1 does not exempt the controller from ensuring that the processing operation is necessary for the purposes of the relevant legitimate interests pursued by the controller or by a third party, and that the interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. In doing so, the controller shall take into account, among others, the possible consequences of the intended processing for data subjects and the existence of appropriate safeguards." |
The package makes Article 6 more predictable by clarifying that anonymisation may require a lawful processing step, recognising safeguarded intra-group administrative transfers, and adding a non-exhaustive Annex of legitimate-interest use cases. This supports consistent application across the Union without creating a blanket permission: necessity, proportionality and the balancing test remain required, especially for children. Commission updates after EDPB consultation keep the framework adaptable to new technologies and business practices.
| Text proposed by the Commission | Amendment |
|---|---|
| The following point (da) is added to Article 2(2): | |
| '(da) by a natural person in the course of an activity carried out entirely on a voluntary basis, unless that activity involves a type of processing listed pursuant to Article 35(4) GDPR.' |
| Text proposed by the Commission | Amendment |
|---|---|
| 15b. A new Article 88d is added after Article 88c: | |
| 'Article 88d | |
| Processing of personal data in industrial operational environments | |
| 1. Where personal data are generated or collected by industrial machinery, industrial equipment, production systems or industrial internet-of-things devices in the course of their operation in an industrial operational environment, and are processed by a controller or processor solely for the purposes of operating, maintaining, monitoring, improving or securing such machinery, equipment, systems or devices, Articles 15 to 22, Article 30 and Article 35 shall not apply, provided that the conditions laid down in paragraph 2 are met. | |
| 2. Paragraph 1 shall apply only where the controller or processor, as applicable, implements appropriate technical and organisational measures to ensure that the personal data are pseudonymised, or that any identifiers that are not strictly needed for the purposes described in paragraph 1 are removed, and are not processed for the purpose of evaluating the performance, behaviour or conduct of an identified or identifiable natural person, and are not used to take a decision producing legal effects concerning a data subject or similarly significantly affecting him or her within the meaning of Article 22(1). | |
| 3. This Article shall not apply to the processing of special categories of personal data referred to in Article 9(1), nor to personal data relating to criminal convictions and offences referred to in Article 10.' |
Industrial machinery, production systems and IIoT devices generate operational data that may incidentally include identifiers such as user IDs, staff numbers or logs. Where processing is solely for operating, maintaining, improving or securing equipment, and not for monitoring workers or taking decisions about individuals, selected GDPR duties can be disproportionate. The amendment creates a narrow risk-based exemption, requiring pseudonymisation or identifier removal, excluding Article 9/10 data and preserving core GDPR principles, lawful basis and security duties.
| Text proposed by the Commission | Amendment |
|---|---|
| 15c. After Article 88c, the following Articles 88e, 88f, 88g are added: | |
| 'Article 88e | |
| Data protection regulatory sandboxes | |
| 1. Member States shall ensure that their competent supervisory authorities establish at least one data protection regulatory sandbox at national level, which shall be operational by 2 August 2028. That sandbox may also be established jointly with the supervisory authorities of other Member States. The Commission may provide technical support, advice and tools for the establishment and operation of data protection regulatory sandboxes. The obligation under the first subparagraph may also be fulfilled by participating in an existing sandbox in so far as that participation provides an equivalent level of national coverage for the participating Member States. This Chapter is without prejudice to the rules laid down by other Union legal acts related to regulatory sandboxs, in particular Chapter 6 of Regulation (EU) 2024/1689. | |
| 2. Additional data protection regulatory sandboxes at regional or local level, or established jointly with the supervisory authorities of other Member States may also be established. | |
| 3. The European Data Protection Supervisor may also establish an data protection regulatory sandbox for Union institutions, bodies, offices and agencies. For this purpose references to national supervisory authorities in this Chapter shall be construed as references to the European Data Protection Supervisor. | |
| 4. Member States shall ensure that the supervisory authorities referred to in paragraphs 1 and 2 allocate sufficient resources to comply with this Article effectively and in a timely manner. Where appropriate, national supervisory authorities shall cooperate with other relevant authorities, and may allow for the involvement of other actors within the data protection ecosystem. This Article shall not affect other regulatory sandboxes established under Union or national law. Member States shall ensure an appropriate level of cooperation between the authorities supervising those other sandboxes and the national supervisory authorities. | |
| 5. Data protection regulatory sandboxes established under this Article shall provide for a controlled environment that fosters innovation and facilitates the development, testing and validation of innovative data processing for a limited time before processing of personal data takes place pursuant to a specific sandbox plan agreed between the controller and the supervisory authority, ensuring that appropriate safeguards are in place. | |
| 6. Supervisory authorities shall provide, as appropriate, guidance, supervision and support within the data protection regulatory sandbox with a view to identifying risks, in particular to fundamental rights, health and safety, testing, mitigation measures, and their effectiveness in relation to the obligations and requirements of this Regulation and, where relevant, other Union and national law supervised within the sandbox. | |
| 7. Supervisory authorities shall provide controllers participating in the data protection regulatory sandbox with guidance on regulatory expectations and how to fulfil the requirements and obligations set out in this Regulation. Upon request of the controller, the supervisory authority shall provide a written proof of the activities successfully carried out in the sandbox. The supervisory authority shall also provide an exit report detailing the activities carried out in the sandbox and the related results and learning outcomes | |
| 8. If the controller and the national supervisory authority explicitly agree, the exit report may be made publicly available through the single information platform referred to in this Article. | |
| 9. The establishment of data protection regulatory sandboxes shall aim to contribute to the following objectives: | |
| a. improving legal certainty to achieve regulatory compliance with this Regulation or, where relevant, other applicable Union and national law; | |
| b. supporting the sharing of best practices through cooperation with the authorities involved in the data protection regulatory sandbox; | |
| c. fostering innovation and competitiveness and facilitating the development of a data protection ecosystem; | |
| d. contributing to evidence-based regulatory learning; | |
| e. facilitating and accelerating access to the Union market for technical developments, in particular when provided by SMEs, including start-ups, and SMCs. | |
| 10. Where the technical developments constitute AI systems, the competent national authorities shall additionally ensure that the national market surveillance authorities within the meaning of Article 3, point (26), of Regulation (EU) 2024/1689 are involved in the operation of the data protection regulatory sandbox to the extent of their respective tasks and powers. | |
| 11. The data protection regulatory sandboxes shall not affect the supervisory or corrective powers of the competent authorities supervising the sandboxes, including at regional or local level. Any significant risks to health and safety and fundamental rights identified during the development and testing of such technical developments shall result in an adequate mitigation. National competent authorities shall have the power to temporarily or permanently suspend the testing process, or the participation in the sandbox if no effective mitigation is possible, and shall inform the EDPB of such decision. National competent authorities shall exercise their supervisory powers within the limits of the relevant law, using their discretionary powers when implementing legal provisions in respect of a specific data protection regulatory sandbox project, with the objective of supporting innovation in data protection in the Union. | |
| 12. Controllers participating in the data protection regulatory sandbox shall remain liable under applicable Union and national liability law for any damage inflicted on third parties as a result of the experimentation taking place in the sandbox. However, provided that the controllers observe the specific plan and the terms and conditions for their participation and follow in good faith the guidance given by the national supervisory authority, no administrative fines shall be imposed by the authorities for infringements of this Regulation. Where other competent authorities responsible for other Union and national law were actively involved in the supervision of the data processing in the sandbox and provided guidance for compliance, no administrative fines shall be imposed regarding that law. | |
| 13. The data protection regulatory sandboxes shall be designed and implemented in such a way that, where relevant, they facilitate cross-border cooperation between national supervisory authorities. | |
| 14. National supervisory authorities, the EDPS and the Commission shall, as appropriate and within their respective competences, coordinate their activities and cooperate within the framework of the EDPB. They may support the joint establishment and operation of data protection regulatory sandboxes, including in different sectors and exchange best practices on related matters. | |
| 15. National supervisory authorities shall inform the EDPB of the establishment of a sandbox. The EDPB shall make publicly available a list of planned and existing sandboxes and keep it up to date in order to encourage more interaction in the data protection regulatory sandboxes and cross-border cooperation. | |
| 16. National supervisory authorities shall submit annual reports to the EDPB and the Commission, from one year after the establishment of the data protection regulatory sandbox and every year thereafter until its termination, and a final report. Those reports shall provide information on the progress and results of the implementation of those sandboxes, including best practices, incidents, lessons learnt and recommendations on their setup and, where relevant, on the application and possible revision of this Regulation, including its delegated and implementing acts, and on the application of other Union law supervised by the competent authorities within the sandbox. The national supervisory authorities shall make those annual reports or abstracts thereof available to the public, online. The Commission shall, where appropriate, take the annual reports into account when exercising its tasks under this Regulation. | |
| 17. The Commission shall develop a single and dedicated interface containing all relevant information related to data protection regulatory sandboxes to allow stakeholders to interact with data protection regulatory sandboxes and to raise enquiries with supervisory authorities, and to seek non-binding guidance on the conformity of innovative products, services, business models embedding data protection technologies. The Commission shall proactively coordinate with national supervisory authorities, where relevant. | |
| Article 88f | |
| Detailed arrangements for, and functioning of, data protection regulatory sandboxes | |
| 1. In order to avoid fragmentation across the Union, the EDPB shall establish and make public a framework specifying the detailed arrangements for the establishment, development, implementation, operation, governance, and supervision of the data protection regulatory sandboxes. The framework shall include common principles on the following issues: | |
| a. eligibility and selection criteria for participation in the data protection regulatory sandbox; | |
| b. procedures for the application, participation, monitoring, exiting from and termination of the data protection regulatory sandbox, including the sandbox plan and the exit report; | |
| c. the terms and conditions applicable to the participants; | |
| d. the detailed rules applicable to the governance of data protection regulatory sandboxes covered under Article 88x, including the coordination and cooperation at national and EU level. | |
| 2. The framework referred to in paragraph 1 shall ensure: | |
| a. that data protection regulatory sandboxes are open to any applying controller of a technical developments who fulfils eligibility and selection criteria, which shall be transparent and fair, and that national supervisory authorities inform applicants of their decision within three months of the application; | |
| b. that data protection regulatory sandboxes allow broad and equal access and keep up with demand for participation; controllers may also submit applications in partnerships with other controllers and other relevant third parties; | |
| c. that the detailed arrangements for, and conditions concerning data protection regulatory sandboxes support, to the best extent possible, flexibility for national supervisory authorities to establish and operate their data protection regulatory sandboxes; | |
| d. that access to the data protection regulatory sandboxes is free of charge for SMEs, including start-ups, without prejudice to exceptional costs that national supervisory authorities may recover in a fair and proportionate manner; | |
| e. that data protection regulatory sandboxes facilitate the involvement of other relevant actors within the data protection ecosystem, such as SMEs, including start-ups, enterprises, innovators, testing and experimentation facilities, research and experimentation labs and European Digital Innovation Hubs, centres of excellence, individual researchers, in order to allow and facilitate cooperation with the public and private sectors; | |
| f. that procedures, processes and administrative requirements for application, selection, participation and exiting the data protection regulatory sandbox are simple, easily intelligible, and clearly communicated in order to facilitate the participation of SMEs, including start-ups, with limited legal and administrative capacities and are streamlined across the Union, in order to avoid fragmentation and that participation in an data protection regulatory sandbox established by a Member State, or by the European Data Protection Supervisor is mutually and uniformly recognised and carries the same legal effects across the Union; | |
| g. that participation in the data protection regulatory sandbox is limited to a period that is appropriate to the complexity and scale of the project and that may be extended by the national supervisory authority; | |
| h. that data protection regulatory sandboxes facilitate the development of tools and infrastructure for testing, benchmarking, assessing and explaining dimensions of data processing relevant for regulatory learning, such as accuracy, data minimisation and security of processing as well as measures to mitigate risks to fundamental rights and society at large. | |
| Article 88g | |
| Further processing of personal data for developing certain technical developments data processing in the public interest in the data protection regulatory sandbox | |
| 1. In the data protection regulatory sandbox, personal data lawfully collected for other purposes may be processed solely for the purpose of developing and testing certain technical developments in the sandbox when all of the following conditions are met: | |
| a. Technical developments shall be developed for safeguarding substantial public interest by a public authority or another natural or legal person and in one or more of the following areas: | |
| i. public safety and public health, including disease detection, diagnosis prevention, control and treatment and improvement of health care systems; | |
| ii. a high level of protection and improvement of the quality of the environment, protection of biodiversity, protection against pollution, green transition measures, climate change mitigation and adaptation measures; | |
| iii. energy sustainability; | |
| iv. safety and resilience of transport systems and mobility, critical infrastructure and networks; | |
| v. efficiency and quality of public administration and public services; | |
| vi. the protection of the data subject or the rights and freedoms of others; | |
| b. the data processed are necessary for complying with one or more of the requirements referred to in Articles 25, 32 or 35 where those requirements cannot effectively be fulfilled by processing anonymised, synthetic or other non-personal data; | |
| c. there are effective monitoring mechanisms to identify if any high risks to the rights and freedoms of the data subjects, as referred to in Article 35, may arise during the sandbox experimentation, as well as response mechanisms to promptly mitigate those risks and, where necessary, stop the processing; | |
| d. any personal data to be processed in the context of the sandbox are in a functionally separate, isolated and protected data processing environment under the responsibility of the controller and only authorised persons have access to those data; | |
| e. controllers can further share the originally collected data only in accordance with Union data protection law; any personal data created in the sandbox cannot be shared outside the sandbox; | |
| f. any processing of personal data in the context of the sandbox does not leads to measures or decisions affecting the data subjects; | |
| g. any personal data processed in the context of the sandbox are protected by means of appropriate technical and organisational measures and deleted once the participation in the sandbox has terminated or the personal data has reached the end of its retention period; | |
| h. the logs of the processing of personal data in the context of the sandbox are kept for the duration of the participation in the sandbox, unless provided otherwise by Union or national law; | |
| i. a complete and detailed description of the process and rationale behind the testing and validation of the data processing is kept together with the testing results; | |
| j. a short summary of the data processing project developed in the sandbox, its objectives and expected results is published on the website of the supervisory authorities; this obligation shall not cover sensitive operational data in relation to the activities of law enforcement, border control, immigration or asylum authorities. | |
| 2. To the processing of personal data carried out within an data protection regulatory sandbox, provided that the processing takes place exclusively within the Union and it is ensured that authorities or other bodies of third countries cannot gain access to the processed data, only Article 5(1), point (f), in conjunction with paragraph 2, Article 24 and Article 32 shall apply, in addition to Chapters I, X and XI. | |
| For the processing of personal data carried out within a data protection regulatory sandbox, and provided that the processing takes place exclusively within the Union and that access to the processed data by authorities or other bodies of third countries is prevented, Member States shall provide for derogations from or exemptions to Chapter II (Principles), Chapter III (Rights of the data subject), Chapter IV (Controller and processor), Chapter V (Transfers of personal data to third countries or international organisations), Chapter VI (Independent supervisory authorities), Chapter VII (Cooperation and consistency) and Chapter IX (Provisions relating to specific processing situations) where this is necessary to reconcile the right to the protection of personal data with the objective of fostering innovation and strengthening the competitiveness of the Union. | |
| 3. Paragraph 1 is without prejudice to Union or national law which excludes processing of personal data for other purposes than those explicitly mentioned in that law, as well as to Union or national law laying down the basis for the processing of personal data which is necessary for the purpose of developing, testing of innovative processing operations or any other legal basis, in compliance with Union law on the protection of personal data.' |
Data protection sandboxes make GDPR compliance more predictable for innovative processing, PETs and AI use cases. Building on the AI Act model, they provide controlled testing, supervisory guidance, exit reports, cross-border learning and SME access. No-fine protection applies only where participants follow the agreed plan in good faith; authorities keep corrective powers, liability remains, high risks must be mitigated and public-interest further processing is subject to strict safeguards.
Andrea Wechsler, Marie-Sophie Lanig, Stefan Köhler, Alexandra Mehnert, Lena Düpont, Angelika Niebler, Verena Mertens, Christian Doleschal, Sabine Verheyen
| Present text | Amendment |
|---|---|
| In Article 14, paragraph 5a is added: | |
| Article 14 Information to be provided where personal data have not been obtained from the data subject 1. Where personal data have not been obtained from the data subject, the controller shall provide the data subject with the following information: (a) the identity and the contact details of the controller and, where applicable, of the controller's representative; (b) the contact details of the data protection officer, where applicable; (c) the purposes of the processing for which the personal data are intended as well as the legal basis for the processing; (d) the categories of personal data concerned; (e) the recipients or categories of recipients of the personal data, if any; (f) where applicable, that the controller intends to transfer personal data to a recipient in a third country or international organisation and the existence or absence of an adequacy decision by the Commission, or in the case of transfers referred to in Article 46 or 47, or the second subparagraph of Article 49(1), reference to the appropriate or suitable safeguards and the means to obtain a copy of them or where they have been made available. 2. In addition to the information referred to in paragraph 1, the controller shall provide the data subject with the following information necessary to ensure fair and transparent processing in respect of the data subject: (a) the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period; (b) where the processing is based on point (f) of Article 6(1), the legitimate interests pursued by the controller or by a third party; (c) the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject and to object to processing as well as the right to data portability; (d) where processing is based on point (a) of Article 6(1) or point (a) of Article 9(2), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal; (e) the right to lodge a complaint with a supervisory authority; (f) from which source the personal data originate, and if applicable, whether it came from publicly accessible sources; (g) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject. The controller shall provide the information referred to in para graphs 1 and 2: (a) within a reasonable period after obtaining the personal data, but at the latest within one month, having regard to the specific circum stances in which the personal data are processed; (b) if the personal data are to be used for communication with the data subject, at the latest at the time of the first communication to that data subject; or (c) if a disclosure to another recipient is envisaged, at the latest when the personal data are first disclosed. 4. Where the controller intends to further process the personal data for a purpose other than that for which the personal data were obtained, the controller shall provide the data subject prior to that further processing with information on that other purpose and with any relevant further information as referred to in paragraph 2. 5. Paragraphs 1 to 4 shall not apply where and insofar as: (a) the data subject already has the information; (b) the provision of such information proves impossible or would involve a disproportionate effort, in particular for processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available; (c) obtaining or disclosure is expressly laid down by Union or Member State law to which the controller is subject and which provides appropriate measures to protect the data subject's legitimate interests; or (d) where the personal data must remain confidential subject to an obligation of professional secrecy regulated by Union or Member State law, including a statutory obligation of secrecy. | "'5a. Where the controller is an association, foundation, or other non-profit organisation, and the personal data have not been obtained from the data subject, paragraphs 1 to 5 shall not apply where providing the information would require a disproportionate effort and the processing is limited to the internal purposes described in Article 13(6). In such cases, the controller shall adopt appropriate transparency measures.'" |
Non-profit organisations may receive personal data indirectly in the context of volunteer coordination, beneficiary support, charitable activities or membership-related administration. In such situations, providing individual information notices to each data subject can require disproportionate effort, particularly for small or volunteer-based organisations. This amendment allows proportionate transparency measures, such as public notices or online publication, where the processing remains limited to low-risk internal purposes. It preserves transparency while avoiding unnecessary bureaucracy for civil-society organisations.
Andrea Wechsler, Marie-Sophie Lanig, Stefan Köhler, Alexandra Mehnert, Lena Düpont, Angelika Niebler, Verena Mertens, Christian Doleschal, Sabine Verheyen
| Present text | Amendment |
|---|---|
| In Article 30, paragraph 5a is added | |
| Article 30 Records of processing activities 1. Each controller and, where applicable, the controller's represen tative, shall maintain a record of processing activities under its respon sibility. That record shall contain all of the following information: (a) the name and contact details of the controller and, where applicable, the joint controller, the controller's representative and the data protection officer; (b) the purposes of the processing; (c) a description of the categories of data subjects and of the categories of personal data; (d) the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or inter national organisations; (e) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the docu mentation of suitable safeguards; (f) where possible, the envisaged time limits for erasure of the different categories of data; (g) where possible, a general description of the technical and organisa tional security measures referred to in Article 32(1). 2. Each processor and, where applicable, the processor's representa tive shall maintain a record of all categories of processing activities carried out on behalf of a controller, containing: (a) the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller's or the processor's represen tative, and the data protection officer; (b) the categories of processing carried out on behalf of each controller; (c) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the docu mentation of suitable safeguards; B (d) where possible, a general description of the technical and organisa tional security measures referred to in Article 32(1). 3. The records referred to in paragraphs 1 and 2 shall be in writing, including in electronic form. 4. The controller or the processor and, where applicable, the controller's or the processor's representative, shall make the record available to the supervisory authority on request. 5. The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10. | "'5a. Paragraphs 1-4 shall not apply to associations, foundations, and other non-profit organisations whose processing activities are limited to the purposes described in Article 13(6).'" |
Record-keeping obligations under Article 30 should be proportionate to the actual risk of the processing activity. Small non-profit organisations, associations and foundations often lack dedicated compliance structures and process data only for limited internal administrative purposes. Requiring full records of processing activities in such low-risk cases creates administrative burdens without a corresponding benefit for data subjects. This amendment clarifies that the exemption applies to non-profit organisations where processing is limited to the purposes set out in Article 13(6), while preserving the full obligation where processing is likely to result in a high risk to the rights and freedoms of data subjects.
Andrea Wechsler, Marie-Sophie Lanig, Stefan Köhler, Alexandra Mehnert, Lena Düpont, Angelika Niebler, Verena Mertens, Christian Doleschal, Sabine Verheyen
| Present text | Amendment |
|---|---|
| In Article 2, the following point e is added: | |
| 2. This Regulation does not apply to the processing of personal data: | "'(e) by associations, foundations and other non-profit organisations established in the Union, where the processing is carried out solely in the course of their statutory non-commercial activities and is limited to the administration of members, former members, volunteers, donors or beneficiaries, provided that such processing does not involve systematic monitoring or processing likely to result in a high risk to the rights and freedoms of natural persons within the meaning of Article 35, and that the personal data are not disclosed to third parties for commercial purposes.'" |
| (a) in the course of an activity which falls outside the scope of Union law; | |
| (b) by the Member States when carrying out activities which fall within the scope of Chapter 2 of Title V of the TEU; | |
| (c) by a natural person in the course of a purely personal or household activity; |
Associations, foundations and other non-profit organisations generally process personal data within clear, direct and non-commercial relationships with their members, volunteers, donors or beneficiaries. Subjecting such limited and low-risk processing to the full scope of Regulation (EU) 2016/679 places a disproportionate administrative burden on civil-society and volunteer-based organisations, many of which lack dedicated compliance structures. This targeted exclusion complements the specific simplifications proposed for Articles 13, 14 and 30, while preserving the application of the Regulation to systematic monitoring, automated decision-making, high-risk processing and the commercial disclosure of personal data.
Andrea Wechsler, Marie-Sophie Lanig, Stefan Köhler, Alexandra Mehnert, Angelika Niebler, Verena Mertens, Christian Doleschal, Sabine Verheyen
| Present text | Amendment |
|---|---|
| In Article 9, paragraph 2 the following point k is added: | |
| 2. Paragraph 1 shall not apply if one of the following applies: | "'(ja) processing is strictly necessary for the anonymisation of personal data pursuant to Article 6(3a), provided that the processing is subject to appropriate technical and organisational safeguards, that the data are not used to take measures or decisions concerning individual data subjects and that identifiable data are erased or rendered inaccessible as soon as they are no longer necessary for the anonymisation process.'" |
| (a)the data subject has given explicit consent to the processing of those personal data for one or more specified purposes, except where Union or Member State law provide that the prohibition referred to in paragraph 1 may not be lifted by the data subject; | |
| (b)processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law in so far as it is authorised by Union or Member State law or a collective agreement pursuant to Member State law providing for appropriate safeguards for the fundamental rights and the interests of the data subject; | |
| (c)processing is necessary to protect the vital interests of the data subject or of another natural person where the data subject is physically or legally incapable of giving consent; | |
| (d)processing is carried out in the course of its legitimate activities with appropriate safeguards by a foundation, association or any other not-for-profit body with a political, philosophical, religious or trade union aim and on condition that the processing relates solely to the members or to former members of the body or to persons who have regular contact with it in connection with its purposes and that the personal data are not disclosed outside that body without the consent of the data subjects;(e)processing relates to personal data which are manifestly made public by the data subject;(f)processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity; | |
| (g)processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject; | |
| (h)processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards referred to in paragraph 3; | |
| (i)processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices, on the basis of Union or Member State law which provides for suitable and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy; |
Andrea Wechsler, Marie-Sophie Lanig, Stefan Köhler, Alexandra Mehnert, Monika Hohlmeier, Angelika Niebler, Verena Mertens, Christian Doleschal, Sabine Verheyen
| Present text | Amendment |
|---|---|
| Article 3 a (new) | |
| Article 80 is deleted. | |
| Article 80 | "" |
| Representation of data subjects | |
| 1. The data subject shall have the right to mandate a not-for-profit body, organisation or association which has been properly constituted in accordance with the law of a Member State, has statutory objectives which are in the public interest, and is active in the field of the protection of data subjects' rights and freedoms with regard to the protection of their personal data to lodge the complaint on his or her behalf, to exercise the rights referred to in Articles 77, 78 and 79 on his or her behalf, and to exercise the right to receive compensation referred to in Article 82 on his or her behalf where provided for by Member State law. |
Andrea Wechsler, Marie-Sophie Lanig, Stefan Köhler, Alexandra Mehnert, Angelika Niebler, Verena Mertens, Christian Doleschal, Sabine Verheyen
| Present text | Amendment |
|---|---|
| Article 3 b (new) | |
| In Article 6, the following paragraph 3a is inserted: | |
| 3. The basis for the processing referred to in point (c) and (e) of paragraph 1 shall be laid down by:(a)Union law; or | "3a. Further processing of personal data for the sole purpose of anonymising those data shall be considered compatible with the purposes for which the personal data were initially collected and shall be lawful on the basis applicable to the initial processing." |
Andrea Wechsler, Marie-Sophie Lanig, Stefan Köhler, Alexandra Mehnert, Angelika Niebler, Verena Mertens, Christian Doleschal, Sabine Verheyen
| Present text | Amendment |
|---|---|
| Article 3 c (new) | |
| In Article 4, the following point 5a is inserted | |
| Article 4Definitions | "'(5a) “anonymisation” means the processing of personal data in such a manner that the resulting information does not or no longer constitute personal data for the controller or recipient concerned because the natural person to whom the information relates cannot be identified by means reasonably likely to be used by that controller or recipient, taking into account all objective factors and the means and criteria referred to in Article 41a;'" |
| For the purposes of this Regulation: | |
| (1)‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; | |
| (2)‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; | |
| (3)‘restriction of processing’ means the marking of stored personal data with the aim of limiting their processing in the future; | |
| (4)‘profiling’ means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements; |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) in point 1, the following sentences are added: | deleted |
| ‘Information relating to a natural person is not necessarily personal data for every other person or entity, merely because another entity can identify that natural person. Information shall not be personal for a given entity where that entity cannot identify the natural person to whom the information relates, taking into account the means reasonably likely to be used by that entity. Such information does not become personal for that entity merely because a potential subsequent recipient has means reasonably likely to be used to identify the natural person to whom the information relates.’ |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) in point 1, the following sentences are added: | deleted |
| ‘Information relating to a natural person is not necessarily personal data for every other person or entity, merely because another entity can identify that natural person. Information shall not be personal for a given entity where that entity cannot identify the natural person to whom the information relates, taking into account the means reasonably likely to be used by that entity. Such information does not become personal for that entity merely because a potential subsequent recipient has means reasonably likely to be used to identify the natural person to whom the information relates.’ |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) in point 1, the following sentences are added: | deleted |
| ‘Information relating to a natural person is not necessarily personal data for every other person or entity, merely because another entity can identify that natural person. Information shall not be personal for a given entity where that entity cannot identify the natural person to whom the information relates, taking into account the means reasonably likely to be used by that entity. Such information does not become personal for that entity merely because a potential subsequent recipient has means reasonably likely to be used to identify the natural person to whom the information relates.’ |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| (a) in point 1, the following sentences are added: | deleted |
| ‘Information relating to a natural person is not necessarily personal data for every other person or entity, merely because another entity can identify that natural person. Information shall not be personal for a given entity where that entity cannot identify the natural person to whom the information relates, taking into account the means reasonably likely to be used by that entity. Such information does not become personal for that entity merely because a potential subsequent recipient has means reasonably likely to be used to identify the natural person to whom the information relates.’ |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| (a) in point 1, the following sentences are added: | deleted |
| ‘Information relating to a natural person is not necessarily personal data for every other person or entity, merely because another entity can identify that natural person. Information shall not be personal for a given entity where that entity cannot identify the natural person to whom the information relates, taking into account the means reasonably likely to be used by that entity. Such information does not become personal for that entity merely because a potential subsequent recipient has means reasonably likely to be used to identify the natural person to whom the information relates.’ |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| Information relating to a natural person is not necessarily personal data for every other person or entity, merely because another entity can identify that natural person. Information shall not be personal for a given entity where that entity cannot identify the natural person to whom the information relates, taking into account the means reasonably likely to be used by that entity. Such information does not become personal for that entity merely because a potential subsequent recipient has means reasonably likely to be used to identify the natural person to whom the information relates. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| Information relating to a natural person is not necessarily personal data for every other person or entity, merely because another entity can identify that natural person. Information shall not be personal for a given entity where that entity cannot identify the natural person to whom the information relates, taking into account the means reasonably likely to be used by that entity. Such information does not become personal for that entity merely because a potential subsequent recipient has means reasonably likely to be used to identify the natural person to whom the information relates. | Information relating to a natural person is not necessarily personal data for every other person or entity, merely because another entity can identify that natural person. Information shall not be personal for a given entity where that entity cannot identify the natural person to whom the information relates, taking into account the means reasonably likely to be used through technical and organisational measures, as well as state of the art technology available to that entity. Such information does not become personal for that entity merely because a potential subsequent recipient has means reasonably likely to be used to identify the natural person to whom the information relates. |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| Information relating to a natural person is not necessarily personal data for every other person or entity, merely because another entity can identify that natural person. Information shall not be personal for a given entity where that entity cannot identify the natural person to whom the information relates, taking into account the means reasonably likely to be used by that entity. Such information does not become personal for that entity merely because a potential subsequent recipient has means reasonably likely to be used to identify the natural person to whom the information relates. | Information relating to a natural person is not necessarily identifiable data for every other person or entity, merely because another entity can identify that natural person. Information shall not fall under the regime of personal data for a given entity where that entity cannot identify the natural person to whom the information relates, taking into account the means reasonably likely to be used by that entity. Such information does not become identifiable for that entity merely because a potential subsequent recipient has means reasonably likely to be used to identify the natural person to whom the information relates. |
Mirrors AM 134. The entity-relative definition is deleted; the definition of personal data remains unchanged.
| Text proposed by the Commission | Amendment |
|---|---|
| (b) point 25 is replaced by the following: | deleted |
| ‘(25) for ‘electronic communications networks’ the definition of Article 2(1) of Directive (EU) 2018/1972 shall apply;’ |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| (b) point 25 is replaced by the following: | deleted |
| ‘(25) for ‘electronic communications networks’ the definition of Article 2(1) of Directive (EU) 2018/1972 shall apply;’ |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| (25) for ‘electronic communications networks’ the definition of Article 2(1) of Directive (EU) 2018/1972 shall apply; | (25) the definitions of ‘electronic communications network’, ‘electronic communications service’, ‘interpersonal communications service’ in points (1), (4) and (5) respectively of Article 2 of Directive (EU) 2018/1972 shall apply. |
| For the purposes of this Regulation, the definition of ‘interpersonal communications service’ shall include services whether provided for remuneration or not, as well as services which enable interpersonal and interactive communication merely as a minor ancillary feature that is intrinsically linked to another service; |
| Text proposed by the Commission | Amendment |
|---|---|
| (27) ‘mobile application’ means a mobile application as defined in Article 3(2) of Directive (EU) 2016/2102; | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| (28) ‘online interface’ means an online interface as defined in Article 3(m) of Regulation (EU) 2022/2065; | deleted |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| (28a) ‘operating system’ means a system software as defined in Article 2(10) of Regulation (EU) 2022/1925; |
| Text proposed by the Commission | Amendment |
|---|---|
| (29) “scientific research” means any research which can also support innovation, such as technological development and demonstration. These actions shall contribute to existing scientific knowledge or apply existing knowledge in novel ways, be carried out with the aim of contributing to the growth of society´s general knowledge and wellbeing and adhere to ethical standards in the relevant research area. This does not exclude that the research may also aim to further a commercial interest. | deleted |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| (29) “scientific research” means any research which can also support innovation, such as technological development and demonstration. These actions shall contribute to existing scientific knowledge or apply existing knowledge in novel ways, be carried out with the aim of contributing to the growth of society´s general knowledge and wellbeing and adhere to ethical standards in the relevant research area. This does not exclude that the research may also aim to further a commercial interest. | (29) “scientific research” means research conducted according to a recognised methodological and systematic approach, producing verifiable and transparent results and adhering to the applicable ethical and professional standards, which can also support innovation, such as technological development and demonstration. These actions shall contribute to existing scientific knowledge or apply existing knowledge in novel ways, be carried out with the aim of contributing to the growth of society´s general knowledge and wellbeing and adhere to ethical standards in the relevant research area. This does not exclude that the research may also aim to further a commercial interest. Scientific research shall not include the profiling of natural persons, direct marketing, the monitoring of individuals' behaviour, or activities whose purpose is to influence or nudge the behaviour of natural persons, even where such activities apply scientific methods. |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| (29) “scientific research” means any research which can also support innovation, such as technological development and demonstration. These actions shall contribute to existing scientific knowledge or apply existing knowledge in novel ways, be carried out with the aim of contributing to the growth of society´s general knowledge and wellbeing and adhere to ethical standards in the relevant research area. This does not exclude that the research may also aim to further a commercial interest. | (29) “scientific research” means any research conducted in an autonomous and indepentent manner with the aim of contributing to the growth of society´s general knowledge and wellbeing, adhere to recognised ethical standards for scientific research in the public interest and producing verifiable and transparent results. |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| (29) “scientific research” means any research which can also support innovation, such as technological development and demonstration. These actions shall contribute to existing scientific knowledge or apply existing knowledge in novel ways, be carried out with the aim of contributing to the growth of society´s general knowledge and wellbeing and adhere to ethical standards in the relevant research area. This does not exclude that the research may also aim to further a commercial interest. | (29) “scientific research” means research conducted in an autonomous and independent manner, with the aim of contributing to the growth of society’s public knowledge, to the public interest or to serve the mankind, generating new or complementing existing scientific knowledge, following a methodological and systematic approach consistent with generally recognised ethical standards, including the respect for human autonomy and the concept of consent to participate in research, as well as standards applicable in the relevant scientific field, producing evidence-based, testable, transparent and published results. |
| Text proposed by the Commission | Amendment |
|---|---|
| (29) “scientific research” means any research which can also support innovation, such as technological development and demonstration. These actions shall contribute to existing scientific knowledge or apply existing knowledge in novel ways, be carried out with the aim of contributing to the growth of society´s general knowledge and wellbeing and adhere to ethical standards in the relevant research area. This does not exclude that the research may also aim to further a commercial interest. | (29) “scientific research” means any research which can also support competitiveness, innovation, such as technological development and demonstration. These actions shall contribute to existing scientific knowledge or apply existing knowledge in novel ways, be carried out with the aim of contributing to the growth of society´s general knowledge and wellbeing and adhere to ethical standards in the relevant research area. This does not exclude that the research may also aim to further a commercial interest. |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| (29a) ‘user’ means a natural or legal person using or requesting a publicly available electronic communications service as defined in Article 2(14) of Directive (EU) 2018/1972 ; |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Article 4 (1)(b) is replaced by the following: | deleted |
| ‘(b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 13, be considered to be compatible with the initial purposes, independent of the conditions of Article 6 of this Regulation, (‘purpose limitation’);’ |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| (b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 13, be considered to be compatible with the initial purposes, independent of the conditions of Article 6 of this Regulation, (‘purpose limitation’); | (b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, subject to the application of appropriate safeguards in accordance with Article 13 and the principle of lawfulness, be considered to be compatible with the initial purposes, independent of the conditions of Article 6 of this Regulation, (‘purpose limitation’); |
| Text proposed by the Commission | Amendment |
|---|---|
| ‘(b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 13, be considered to be compatible with the initial purposes, independent of the conditions of Article 6 of this Regulation, (‘purpose limitation’);’ | ‘(b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 13, not be considered to be incompatible with the initial purposes (‘purpose limitation’);’ |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) in paragraph 2, the following points are added: | deleted |
| ‘(k) processing in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, subject to the conditions referred to in paragraph 4. | |
| (l) processing of biometric data is necessary for the purpose of confirming the identity of a data subject (verification), where the biometric data or the means needed for the verification is under the sole control of the data subject.’ |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) in paragraph 2, the following points are added: | deleted |
| ‘(k) processing in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, subject to the conditions referred to in paragraph 4. . | |
| (l) processing of biometric data is necessary for the purpose of confirming the identity of a data subject (verification), where the biometric data or the means needed for the verification is under the sole control of the data subject.’ |
| Text proposed by the Commission | Amendment |
|---|---|
| (k) processing in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, subject to the conditions referred to in paragraph 4. | deleted |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| (k) processing in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, subject to the conditions referred to in paragraph 4. . | deleted |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| (k) processing in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, subject to the conditions referred to in paragraph 4. . | (k) processing in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, subject to the conditions referred to in paragraph 4, and without prejudice to the prohibited practices laid down in Article 5, the classification rules for high-risk AI systems laid down in Article 6, the obligations of deployers of high-risk AI systems laid down in Article 26, and the transparency obligations laid down in Article 50 of that Regulation. |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| (k) processing in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, subject to the conditions referred to in paragraph 4. . | (k) strictly incidental and residual processing in the context of the development and operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model, subject to the conditions referred to in paragraph 4. |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| (l) processing of biometric data is necessary for the purpose of confirming the identity of a data subject (verification), where the biometric data or the means needed for the verification is under the sole control of the data subject. | (l) processing of biometric data is necessary for the purpose of confirming the identity of a data subject (verification), by means of a one-to-one comparison performed locally on the data subject's own device, where the biometric data or the means needed for the verification is under the sole control of the data subject. This point applies solely to verification and does not cover the identification of a natural person by comparing their biometric data to biometric data stored in a database within the meaning of Regulation (EU) 2024/1689; it is without prejudice to the prohibition laid down in Article 5(1), point (e), of that Regulation. |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| (l) processing of biometric data is necessary for the purpose of confirming the identity of a data subject (verification), where the biometric data or the means needed for the verification is under the sole control of the data subject. | (l) processing of biometric data is strictly necessary and proportionate for the purpose of confirming the identity of a data subject (verification), where the biometric data or the means needed for the verification is under the sole control of the data subject., and subject to apropriate safeguards to protect the fundamental rights and the interest of the data subject, as laid down in Unio law or Member State law, in accordance with paragraph 4 of this Article. |
| Text proposed by the Commission | Amendment |
|---|---|
| (l) processing of biometric data is necessary for the purpose of confirming the identity of a data subject (verification), where the biometric data or the means needed for the verification is under the sole control of the data subject. | (l) processing of biometric data is strictly necessary for the purpose of confirming the identity of a data subject using one-to-one verification, where the biometric data or the means needed for the recognition is under the sole control of the data subject and occurs on the data subject's device, except in highly exceptional cases where this is strictly necessary, proportional and uses state of the art privacy preserving technology, such as encryption and zero knowledge proofs. |
| Text proposed by the Commission | Amendment |
|---|---|
| (l) processing of biometric data is necessary for the purpose of confirming the identity of a data subject (verification), where the biometric data or the means needed for the verification is under the sole control of the data subject.’ | (l) processing of biometric data is necessary for the purpose of confirming the identity of a data subject, where the biometric data and the means needed for the verification are under the sole control of the data subject, are not stored centrally and are not processed for other purposes.’ |
| Text proposed by the Commission | Amendment |
|---|---|
| (b) the following paragraph 4 is added: | deleted |
| ‘4. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.’ |
| Text proposed by the Commission | Amendment |
|---|---|
| (b) the following paragraph 4 is added: | deleted |
| ‘4. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.’ |
| Text proposed by the Commission | Amendment |
|---|---|
| (b) the following paragraph 4 is added: | deleted |
| ‘4. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.’ |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| (b) the following paragraph 4 is added: | deleted |
| ‘4. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties.’ |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| 4. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties. | 4. For processing referred to in point (k) of paragraph 2, strict organisational and technical measures shall be implemented to prevent the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing, the controller shall erase such data without undue delay prior to completion of the training phase of the Ai system or AI model. If erasure of those data from an already trained AI system or AI model proves to be technically impossible, the controller shall fully document the technical impossibility, notify the competent supervisory authority, and, without undue delay and in any event effectively protect such data by applying state of the art filtering or aligment techniques to guarantee such data cannot be further procesed, used to produce outputs, re-identified, disclosed or otherwise made available to third parties. Processing referred to in point (k) of paragraph 2 should exlude the processing of special categories of personal data originating from data provided by, or generated through, the activity of end users on an online platforms or a core platfrom services as defined in Regulation (EU) 2022/1925, irrespective of whether such processing occurs during the development, training, or operational phase of any AI system or AI model. |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| 4. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties. | 4. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid the collection and otherwise processing of special categories of personal data, such as pseudonymisation, data minimisation and filtering at the point of collection, input filtering of training data, access restrictions, and state-of-the-art privacy-preserving and privacy-enhancing techniques. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data, without undue delay . If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties. In assessing whether the removal of those data requires a disproportionate effort, account shall be taken of the state of the art, the costs of implementation, the volume of data concerned, the technical feasibility of isolating or extracting the data, and the nature, scope and purposes of the processing. |
| Text proposed by the Commission | Amendment |
|---|---|
| 4. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, the controller shall in any event effectively protect without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties. | 4. For processing referred to in point (k) of paragraph 2, appropriate organisational and technical measures shall be implemented to avoid v the collection and otherwise processing of special categories of personal data. Where, despite the implementation of such measures, the controller identifies special categories of personal data in the datasets used for training, testing or validation or in the AI system or AI model, the controller shall remove such data. If removal of those data requires disproportionate effort, taking into account technical feasibility, available resources, the nature of the AI system or model, and state of the art technology, the controller shall in any event take appropriate measures proportionate to the risks posed that without undue delay such data from being used to produce outputs, from being disclosed or otherwise made available to third parties. |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| 4a. In Article 10, the following paragraph is added: | |
| '4a. Where the processing referred to in point (k) of paragraph 2 is carried out in the context of an AI regulatory sandbox established under Article 57 of Regulation (EU) 2024/1689, or in the context of testing in real world conditions under Article 60 of that Regulation, the processing shall comply with the conditions and safeguards laid down, respectively, in Article 59 and in Articles 60 and 61 of that Regulation. In particular, the personal data shall be processed in a functionally separate, isolated and protected environment under the control of the controller; effective monitoring and response mechanisms shall be in place to identify and mitigate high risks to the rights and freedoms of the data subjects and, where necessary, to stop the processing; and any personal data shall be deleted once the participation in the sandbox or the testing has terminated.' |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| 4. in Article 14, paragraph 5 is replaced by the following: | deleted |
| ‘5. Information provided under Articles 15 and 16 and any communication and any actions taken under Articles 17 to 24 and 35 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 17 because the data subject abuses the rights conferred by this Regulation for purposes other than the protection of their data, the controller may refuse to act on the request. The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive.’ |
| Text proposed by the Commission | Amendment |
|---|---|
| 4. in Article 14, paragraph 5 is replaced by the following: | deleted |
| ‘5. Information provided under Articles 15 and 16 and any communication and any actions taken under Articles 17 to 24 and 35 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 17 because the data subject abuses the rights conferred by this Regulation for purposes other than the protection of their data, the controller may refuse to act on the request. The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive.’ |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| 5. Information provided under Articles 15 and 16 and any communication and any actions taken under Articles 17 to 24 and 35 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 17 because the data subject abuses the rights conferred by this Regulation for purposes other than the protection of their data, the controller may refuse to act on the request. The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive. | 5. Information provided under Articles 15 and 16 and any communication and any actions taken under Articles 17 to 24 and 35 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 17 because the data subject abuses the rights conferred by this Regulation for purposes other than the protection of their data, the controller may refuse to act on the request. The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive. This paragraph is without prejudice to the conditions and safeguards applicable to the processing of personal data in AI regulatory sandboxes and in testing in real world conditions under Articles 59, 60 and 61 of Regulation (EU) 2024/1689, which continue to apply. |
| Text proposed by the Commission | Amendment |
|---|---|
| ‘5. Information provided under Articles 15 and 16 and any communication and any actions taken under Articles 17 to 24 and 35 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 17 because the data subject abuses the rights conferred by this Regulation for purposes other than the protection of their data, the controller may refuse to act on the request. The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive.’ | ‘5. Information provided under Articles 15 and 16 and any communication and any actions taken under Articles 17 to 24 and 35 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may refuse to act on the request. The controller shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request.’ |
| Text proposed by the Commission | Amendment |
|---|---|
| 5. Information provided under Articles 15 and 16 and any communication and any actions taken under Articles 17 to 24 and 35 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests under Article 17 because the data subject abuses the rights conferred by this Regulation for purposes other than the protection of their data, the controller may refuse to act on the request. The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive. | 5. Information provided under Articles 15 and 16 and any communication and any actions taken under Articles 17 to 24 and 35 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character or also, for requests where the controller is able to demonstrate an abusive intention because the data subject abuses the rights conferred by this Regulation for purposes other than the protection of their data, the controller may refuse to act on the request. The controller shall bear the burden of demonstrating that the request is manifestly unfounded or that there are reasonable grounds to believe that it is excessive. |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Present text | Amendment |
|---|---|
| 4a. In Article 14, paragraphs 7 and 8 are deleted. | |
| 7. The information to be provided to data subjects pursuant to Articles 15 and 16 may be provided in combination with standardised icons in order to give in an easily visible, intelligible and clearly legible manner a meaningful overview of the intended processing. Where the icons are presented electronically they shall be machine-readable. | "" |
Alignment with change made within GDPR in the draft joint report. The delegated acts for these standardised icons have not been adopted.
| Text proposed by the Commission | Amendment |
|---|---|
| 5. in Article 15 the new paragraph 5 is added: | deleted |
| ‘5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 13 or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available.’ |
| Text proposed by the Commission | Amendment |
|---|---|
| 5. in Article 15 the new paragraph 5 is added: | deleted |
| ‘5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 13 or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available.’ |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| 5. in Article 15 the new paragraph 5 is added: | deleted |
| ‘5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 13 or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available.’ |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| 5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 13 or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available. | 5. When the further processing takes place for scientific research purposes, provided it is not used for commercial product development, advertising, marketing, profiling or the training of data processing models for commercial deployment, and where the controller does not possess or cannot reasonably obtain the contact details of the data subject without disproportionate effort, and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 13 or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall document the reliance of this exception, make such documentation available to the supervisory authority upon request, and take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including announcing the information publicly or informing the data subject without undue delay as soon as the conditions of this paragraph have ceased to exist. |
| Text proposed by the Commission | Amendment |
|---|---|
| 5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort subject to the conditions and safeguards referred to in Article 13 or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available. | 5. When the processing takes place for scientific research purposes and the provision of information referred to under paragraphs 1, 2 and 3 proves impossible or would involve a disproportionate effort, taking into account available technical and organisational means, subject to the conditions and safeguards referred to in Article 13 or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing, the controller does not need to provide the information referred to under paragraphs 1, 2 and 3. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available. |
| Text proposed by the Commission | Amendment |
|---|---|
| 5a. ‘neural data’ means personal data obtained through the monitoring or processing of the activity of the nervous system, or personal data that makes it possible to derive information about a natural person’s cognitive, emotional or mental state. |
| Text proposed by the Commission | Amendment |
|---|---|
| 5b. ‘cognitive inference’ means any information, classification, prediction or assessment relating to a natural person’s cognitive, emotional, attentional, mnemonic or decision-making states, obtained through the automated processing of personal data. |
| Text proposed by the Commission | Amendment |
|---|---|
| 5c. the existence of any cognitive inferences derived through the automated processing of the data subject’s personal data, as well as relevant information regarding the categories of such inferences and the purposes for which they are used |
| Text proposed by the Commission | Amendment |
|---|---|
| 6. in Article 24 paragraphs 1 and 2 are replaced by the following: | deleted |
| ‘1. A decision which produces legal effects for a data subject or similarly significantly affects him or her may be based solely on automated processing, including profiling, only where that decision: | |
| (a) is necessary for entering into, or performance of, a contract between the data subject and a data controller regardless of whether the decision could be taken otherwise than by solely automated means; | |
| (b) is authorised by Union law to which the controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests; or | |
| (c) is based on the data subject's explicit consent.’ |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| 6. in Article 24 paragraphs 1 and 2 are replaced by the following: | 6. in Article 24 is replaced by the following: |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| 1. A decision which produces legal effects for a data subject or similarly significantly affects him or her may be based solely on automated processing, including profiling, only where that decision: | 1. The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal affect concerning them or similarly significantly affects them, unless such processing: |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) is necessary for entering into, or performance of, a contract between the data subject and a data controller regardless of whether the decision could be taken otherwise than by solely automated means; | (a) is necessary for entering into, or performance of, a contract between the data subject and a data controller regardless of whether the decision could be taken otherwise than by solely automated means, when several equally effective automated processing solutions exist, the controller should use the less intrusive one when it does not result in a significant additional administrative burden for the controller; |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| (a) is necessary for entering into, or performance of, a contract between the data subject and a data controller regardless of whether the decision could be taken otherwise than by solely automated means; | (a) is necessary for entering into, or performance of, a contract between the data subject and a data controller |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| (a) is necessary for entering into, or performance of, a contract between the data subject and a data controller regardless of whether the decision could be taken otherwise than by solely automated means; | (a) is necessary for entering into, or performance of, a contract between the data subject and a data controller; |
| Text proposed by the Commission | Amendment |
|---|---|
| (ca) (d) the data controller shall implement technical and organisational measures to ensure that the generation of cognitive inferences is limited to what is necessary in relation to the purposes pursued and is not used to exploit the data subject’s cognitive vulnerabilities. | |
| (Our intention is to insert a paragraph (d) following paragraphs (a), (b) and (c) of the abovementioned article.) |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| 1a. In Article 24, the following paragraph is inserted: | |
| '1a. Where a decision referred to in paragraph 1 is based on the output of a high-risk AI system within the meaning of Regulation (EU) 2024/1689, the safeguards accompanying that decision shall be without prejudice to the human oversight requirements laid down in Article 14 of that Regulation. In particular, natural persons to whom human oversight is assigned shall be enabled to properly understand the capacities and limitations of the system, to correctly interpret its output, to remain aware of the risk of over-reliance on that output, and to decide not to use the system or to disregard, override or reverse its output. Automated processing shall not deprive the data subject of the right to obtain human intervention, to express his or her point of view and to contest the decision.' |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| 1a. In Article 24, the following paragraph is inserted: | |
| '1a. In the cases referred to in points (a), (b) and (c) of paragraph 1, the data controller shall implement suitable technical and organisational measures to safeguard the data subject's rights and freedoms and legitimate interests, at least the right to obtain genuine human intervention of the part of the controller, to express his or her point of view and to contest the decision. The human reveiwer designated to perform such intervention shall possess the necessary competance, knowledge to understand all revelant underlining data, and shall be empowered to modify or overide the decision without delay.' |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| 1c. In Article 24, the following paragraph is inserted: | |
| '1c. Decisions referred to in paragraph 1 shall not be based on special categories of personal data referred to in Article 9(1), unless point (a) or (g) of Article 9(2) applies and suitable technical and organisational measures to safeguard the data subject's rights and freedoms and legitimate interests are in place.' |
| Text proposed by the Commission | Amendment |
|---|---|
| 7. in Article 34, paragraph 1 is replaced by the following | deleted |
| ‘1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay.’ |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| 1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay. | 1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay. Controllers shall continue to document non-notified personal data breaches. |
Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| 1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay. | 1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 72 hours, it shall be accompanied by reasons for the delay. |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| 1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay. | 1. In the case of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 72 hours, it shall be accompanied by reasons for the delay. |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann
| Text proposed by the Commission | Amendment |
|---|---|
| 1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay. | 1. In the case of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 72 hours, it shall be accompanied by reasons for the delay. |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Present text | Amendment |
|---|---|
| 7a. Article 36 is replaced by the following: | |
| Confidentiality of electronic communications | "Confidentiality of electronic communications |
| Union institutions and bodies shall ensure the confidentiality of electronic communications, in particular by securing their electronic communications networks. | Electronic communications shall be confidential. Any interference with electronic communications, such as listening, tapping, storing, monitoring, scanning or other types of interception, surveillance, or any processing of electronic communications, by persons other than the user using the terminal equipment, shall be prohibited. Confidentiality of electronic communications shall also apply to data related to or processed by the terminal equipment." |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| [...] | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| [...] | deleted |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| [...] | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| ‘(2) Storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person is only allowed when that person has given his or her consent, in accordance with this Regulation. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| (3) Paragraph 1 does not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, based on Union law within the meaning of, and subject to the conditions of Article 5, to safeguard the objectives referred to in Article 25(1). | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| (3) Paragraph 1 does not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, based on Union law within the meaning of, and subject to the conditions of Article 5, to safeguard the objectives referred to in Article 25(1). | (3) This shall not prevent any technical storage or access and the corresponding processing of personal data if it is exclusively related to and strictly necessary for: |
| a) carrying out the transmission of an electronic communication over an electronic communications network; | |
| b) providing a service explicitly requested by the subscriber or user; | |
| c) measuring the general audience of an online service requested by a subscriber or user in an immediately anonymised and aggregated form; | |
| d) maintaining or restoring the technical security of a service explicitly requested by the subscriber or user through strictly proportionate means; | |
| If the subscriber or user refuses a request for consent, the provider shall not make a new request for consent for the same purpose for a period of at least six months. Refusing to give consent should not be more difficult than giving consent. Consent shall by default not be considered to be given in an informed and specific manner when the request for consent involves the disclosure of data to more than 10 controllers in a single action. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3a) In Article 37 the following paragraph 3a is inserted: | |
| ‘3a. This article may not be interpreted as a legal basis for accessing the content of electronic communication, for weakening, circumventing or preventing end-to-end encryption, for performing client-side scanning, for gaining covert access to terminal equipment, or for performing device fingerprinting or cross-service tracking. Interference with the terminal equipment of natural persons by Union bodies or institutions shall require a specific legal basis and shall be subject to prior, independent judicial control.’ |
EU bodies must respect secure communication and may not reinterpret the provisions on cookies and terminal equipment for monitoring purposes.
| Text proposed by the Commission | Amendment |
|---|---|
| (4) Storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person without consent, and subsequent processing, shall be lawful to the extent it is necessary for any of the following: | deleted |
| (a) carrying out the transmission of an electronic communication over an electronic communications network; | |
| (b) providing a service explicitly requested by the data subject; | |
| (c) creating aggregated information about the usage of an online service to measure the audience of such a service, where it is carried out by the controller of that online service solely for its own use; | |
| (d) maintaining or restoring the security of a service provided by the controller and requested by the data subject or the terminal equipment used for the provision of such service. |
| Text proposed by the Commission | Amendment |
|---|---|
| (4) Storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person without consent, and subsequent processing, shall be lawful to the extent it is necessary for any of the following: | deleted |
| (a) carrying out the transmission of an electronic communication over an electronic communications network; | |
| (b) providing a service explicitly requested by the data subject; | |
| (c) creating aggregated information about the usage of an online service to measure the audience of such a service, where it is carried out by the controller of that online service solely for its own use; | |
| (d) maintaining or restoring the security of a service provided by the controller and requested by the data subject or the terminal equipment used for the provision of such service. |
| Text proposed by the Commission | Amendment |
|---|---|
| (5) Where storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person is based on consent, the following shall apply: | deleted |
| (a) the data subject shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means; | |
| (b) if the data subject gives consent, the controller shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the data subject; | |
| (c) if the data subject declines a request for consent, the controller shall not make a new request for consent for the same purpose for a period of at least six months. | |
| This paragraph also applies to the subsequent processing of personal data based on consent. |
| Text proposed by the Commission | Amendment |
|---|---|
| (5) Where storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person is based on consent, the following shall apply: | deleted |
| (a) the data subject shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means; | |
| (b) if the data subject gives consent, the controller shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the data subject; | |
| (c) if the data subject declines a request for consent, the controller shall not make a new request for consent for the same purpose for a period of at least six months. | |
| This paragraph also applies to the subsequent processing of personal data based on consent. |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| Where storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person is based on consent, the following shall apply: | Where the storing of personal data, or the gaining of access to personal data already stored, in the terminal equipment of a natural person is based on consent, that consent shall comply with the principles of freedom, specificity, information, unambiguity, fair design, withdrawal and demonstrability, as defined in Regulation (EU) 2016/679. |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| (a) the data subject shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means; | deleted |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| (b) if the data subject gives consent, the controller shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the data subject; | deleted |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| (c) if the data subject declines a request for consent, the controller shall not make a new request for consent for the same purpose for a period of at least six months. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| (6) This Article shall apply from [OP: please insert the date = 6 months following the date of entry into force of this Regulation] ] | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| (6) This Article shall apply from [OP: please insert the date = 6 months following the date of entry into force of this Regulation] ] | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| (7) Controllers shall ensure that their online interfaces allow data subjects to: | deleted |
| (a) give consent through automated and machine-readable means, provided that the conditions for consent laid down in this Regulation are fulfilled; | |
| (b) decline a request for consent through automated and machine-readable means. |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) give consent through automated and machine-readable means, provided that the conditions for consent laid down in this Regulation are fulfilled; | (a) Give, refuse and withdraw consent through automated and machine-readable means, provided that such means allow specific and informed choices; |
| Text proposed by the Commission | Amendment |
|---|---|
| (b) decline a request for consent through automated and machine-readable means. | (b) exercise the right to object pursuant to Article 23(2) through automated and machine-readable means. |
| Text proposed by the Commission | Amendment |
|---|---|
| (8) Controllers shall respect the choices made by data subjects in accordance with paragraph 7. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| (8) Controllers shall respect the choices made by data subjects in accordance with paragraph 7. | (8) Controllers shall disclose the purposes for which they request consent or where a data subject can object through automated and machine-readable means and be respect the choices made by data subjects in accordance with paragraph 7. |
| Text proposed by the Commission | Amendment |
|---|---|
| (9) Online interfaces of controllers which are in conformity with harmonised standards or parts thereof referred to in paragraph 4 of Article 88b of Regulation (EC) 2016/679 shall be presumed to be in conformity with the requirements covered by those standards or parts thereof, set out in paragraph 7. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| (10) Paragraphs 7 to 9 shall apply from [OP: please insert the date = 24 months following the date of entry into force of this Regulation]. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| (10) Paragraphs 7 to 9 shall apply from [OP: please insert the date = 24 months following the date of entry into force of this Regulation]. | deleted |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| 8a. Article 37 is replaced by the following: | |
| Protection of information transmitted to, stored in, related to, processed by and collected from users’ terminal equipment | |
| 1. Storing of information, or gaining of access to information already stored, in the terminal equipment including about its software and hardware, other than by the user concerned, shall be prohibited, except on the following grounds: | |
| (a) it is strictly necessary for the sole purpose of carrying out the transmission of an electronic communication over an electronic communications network; | |
| (b) the user has given their specific consent in accordance with this Regulation, or; | |
| (c) it is strictly technically necessary for providing an information society service specifically requested by the user; | |
| (d) it is technically necessary for maintaining or restoring the technical security of a service provided by the controller and requested by the user; | |
| (e) for the purpose of creating instant anonymous aggregated information about the usage of an online service requested by the user to measure the audience of such a service, where it is carried out by the provider of that online service requested by the user solely for its own use, or by a processor acting on behalf of this controller, solely for the controller’ own use and not further processed for any other purpose, not combined with data from other services from the provider of the online service, or from a third party, nor shared with any third party, or; | |
| (f) for the purpose of verifying the user’s past refusal to a request to consent without involving the use of a unique identifier or additional processing of personal data. | |
| 2. Where storing of information, or gaining of access to information already stored, in the terminal equipment of a user is based on consent, the following shall apply: | |
| (a) the user shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means; | |
| (b) if the user gives consent, the controller shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the user; | |
| (c) if the user declines a request for consent, the controller shall not make a new request for consent for the same purpose for a period of at least six months. This paragraph also applies to the subsequent processing of information based on consent. | |
| 3. This Article shall apply from [OP: please insert the date = 6 months following the date of entry into force of this Regulation] |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| 4. The lists, the template and methodology adopted by the Commission and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation. | 4. The lists, the template and methodology adopted by the Commission and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation, without prejudice to the right of the national supervisiory authorities to develop their own guidance, standards and lists, which the Board and the Commission shall take into account. |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| 4. The lists, the template and methodology adopted by the Commission and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation. | 4. The lists, the template and methodology established and made public by the Board and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation. |
| Text proposed by the Commission | Amendment |
|---|---|
| (b) Paragraphs 5 and 6 are deleted. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| (10) The following article is added: | deleted |
| ‘Article 45a | |
| The common criteria adopted by the Commission and referred to in article 41a of the Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation.’ |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| 10. the following article is added: | deleted |
| ‘Article 45a | |
| The common criteria adopted by the Commission and referred to in article 41a of the Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation.’ |
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| 10. the following article is added: | deleted |
| ‘Article 45a | |
| The common criteria adopted by the Commission and referred to in article 41a of the Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation.’ |
| Text proposed by the Commission | Amendment |
|---|---|
| 10. the following article is added: | deleted |
| ‘Article 45a | |
| The common criteria adopted by the Commission and referred to in article 41a of the Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation.’ |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| The common criteria adopted by the Commission and referred to in article 41a of the Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation. | The common criteria adopted by the Commission and referred to in article 41a of the Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation, without prejudice to the guidelines issued by the European Data Protection Board and the interpretation of Union law by the Court of Justice of the European Union, including as regards the concepts of personal data, identifiable natural person, pseudonymised data and anonymisation. . |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Article 4 is deleted; | deleted |
Article 5(3) of Directive 2002/58/EC is maintained. The transfer of the terminal regime to Regulation (EU) 2016/679 must not have the effect of repealing the specific protection which the ePrivacy Directive affords to the integrity of terminal equipment, which applies irrespective of whether the information stored or accessed constitutes personal data. Maintaining Article 5(3) preserves the protection of legal persons and of information which is not personal data, which would otherwise be left without any protection.
| Present text | Amendment |
|---|---|
| 1a. In Article 5(3), the last sentence is replaced by the following: | |
| 3. Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service. | "3. Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service, or storage of or access to anonymous and necessary information in terminal equipment for the purposes of road safety, transport safety, and accident prevention, including the operation and maintenance of connected vehicles and mobility systems." |
The narrow exemptions of Article 5 have led to interpretations that effectively reduce the regime to a “consent-first” model, making even low-risk or anonymous data uses unnecessarily complex. It creates significant difficulties for vehicle manufacturers; any time the onboard telematics unit or sensors send data externally, it may qualify as “accessing/storing information” under Article 5(3). A vehicle is rarely used by a single individual; it may be driven by the owner, a family member, an employee, or a short-term renter, with passengers also potentially implicated.
| Text proposed by the Commission | Amendment |
|---|---|
| 1a. After Article 5(1), the following paragraph is added: | |
| ‘1a. Confidentiality of electronic communications shall also apply to data related to or processed by terminal equipment.” |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. After Article 5(3), the following subparagraph is added: | deleted |
| ‘This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.’ |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| 2. After Article 5(3), the following subparagraph is added: | deleted |
| ‘This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.’ |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. After Article 5(3), the following subparagraph is added: | deleted |
| ‘This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.’ |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. After Article 5(3), the following subparagraph is added: | 2. In Article 5, paragraph 3 is replaced by the following paragraph: |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. After Article 5(3), the following subparagraph is added: | 2. In Article 5 paragraph 3 is replaced by the following paragraph: |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| 2. After Article 5(3), the following subparagraph is added: | 2. Article 5 is deleted: |
This change is proposed due to other amendments tabled moving e-privacy provisions under Regulation (EU) 2016/679.
| Text proposed by the Commission | Amendment |
|---|---|
| 2. After Article 5(3), the following subparagraph is added: | 2. After Article 5(3), the following paragraphs are added: |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. After Article 5(3), the following subparagraph is added: | 2. Article 5(3) is deleted. |
The AM removes overlapping ePrivacy rules on security, terminal access, metadata, location data and direct marketing where personal-data processing is already governed by the GDPR. Keeping parallel regimes creates consent fatigue, divergent national transpositions and legal uncertainty, including stricter rules for some anonymous device data than for personal data. Consolidation under the GDPR’s risk-based framework simplifies compliance, strengthens coherent rights exercise, supports innovation and preserves sector-specific rules in dedicated instruments.
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| 2. After Article 5(3), the following subparagraph is added: | 2. After Article 5, the following Article is added: |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. After Article 5(3), the following subparagraph is added: | 2. Article 5(3) is replaced by the following: |
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data. | deleted |
This change is proposed due to other amendments tabled moving e-privacy provisions under Regulation (EU) 2016/679.
| Text proposed by the Commission | Amendment |
|---|---|
| This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data. | In Article 5, the following paragraph is added: |
| '3a. Member States shall ensure that the storing of information, or gaining of access to information already stored, in the terminal equipment of a natural person without specific consent, shall be lawful to the extent it is strictly technically and solely necessary for any of the following purpose: | |
| (a) carrying out or facilitating the transmission of an electronic communication over an electronic communications network; | |
| (b) providing an information society service specifically requested by the natural person; | |
| (c) measuring the audience of an information society service explicitly requested by the data subject by creating instantly anonymous aggregated information about the usage of that service, where | |
| (i) it is carried out by the provider of that service, or by a processor acting on behalf of this provider, or by an entitled and independent third party performing audience measurement in accordance with Article 24 of Regulation (EU) 2024/1083. This provision does not apply to gatekeepers within the meaning of Regulation (EU) 2022/1925; | |
| (ii) it is carried out solely for the provider’s own use and not processed for other purposes; | |
| (iii) the data is not combined with data from other services from the provider service, or from a third party, nor shared with a third party except for third parties referred to in point (i); | |
| (iv) such measurement does not adversely affect the fundamental rights of the natural person; and | |
| (v) the natural person is given a possibility to object; | |
| (d) maintaining or restoring the security, confidentiality, integrity, availability and authenticity of the terminal equipment of the user, by means of updates, for the duration necessary for that purpose of a service provided by the controller and explicitly requested by the user or the terminal equipment used for the provision of such service given that | |
| (i) such interest is not overridden by the interests or fundamental rights and freedoms of the data subject; | |
| (ii) the user is informed about the storing or gaining access and their purpose; | |
| (iii) a genuine choice is given to the user to postpone and decide on the automatic nature of such updates, except in the case of a vulnerability presenting a significant cybersecurity risk; and | |
| (iv) this does not in any way change the functionality of the hardware or software or the privacy settings chosen by the user; | |
| (e) complying with paragraph 4 point c of this Article, without storing personal data including unique identifiers; | |
| 5. Member States shall ensure that where storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person is based on consent, the following shall apply: | |
| (a) the data subject shall be able to refuse requests for consent in an easy and intelligible manner with a prominently displayed single-click button; | |
| (b) if the data subject gives consent, the controller shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the data subject; | |
| (c) if the data subject declines a request for consent, the controller shall not make a new request for consent for the same purpose; | |
| (d) the interface used to request consent shall be presented in a machine-readable format. | |
| 6. Member States shall ensure that no user shall be denied access to any information society service or functionality, regardless of whether this service is remunerated or not, on grounds that he or she has not given his or her consent to the processing of personal information and/or the use of processing or storage capabilities of his or her terminal equipment that is not necessary for the provision of that service or functionality. | |
| 7. Member States shall ensure that the conditions for giving, refusing or withdrawing consent using automated and machine-readable signals pursuant to Article 88b of Regulation (EU) 2016/679 shall also apply to this Article. | |
| 8. This Article shall apply from [OP: please insert the date = 6 months following the date of entry into force of this Regulation]. |
Article 88a moved back to ePrivacy, in order to avoid that non-personal data is protected better than personal data stored in the terminal equipment.
Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller
| Text proposed by the Commission | Amendment |
|---|---|
| This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data. | The following Article is inserted: |
| 'Article 5a | |
| Processing of personal data in the terminal equipment of natural persons | |
| 1. Storing of personal data, or gaining of access to personal data of the data subject already stored, in the terminal equipment and any subsequent processing for the same purpose, is only allowed when that person has given his or her consent. | |
| 2. Paragraph 1 does not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment and subsequent processing, based on Union or Member State law within the meaning of, and subject to the conditions of Article 6(3) of Regulation (EU) 2016/679, to safeguard the objectives referred to in Article 23(1) of that Regulation. | |
| 3. Storing of personal data, or gaining of access to personal data already stored, in the terminal equipment without consent, and subsequent processing, shall be lawful only to the extent it is necessary for any of the following purposes: | |
| (a) carrying out the transmission of an electronic communication over an electronic communications network; | |
| (b) providing a service, feature or content, explicitly requested by the data subject, providing that the processing is strictly limited to the specific functionality requested; | |
| (c) Measuring the audience of an online service to create aggregated information about the usage of such a service, where it is carried out by the controller or a processor solely for the use of the online service, that does not contain personal data anymore, or, exceptionally, by a third-party providers of audience measurement to a media service provider, both as defined in Regulation (EU) 2024/1083, provided they comply with the provisions of that Regulation, that such data is restricted to statistical counting, is not cross-using data from separate services, is not utilised for personalised advertising or fingerprinting, and does not involve profiling of data subject. This exception shall not apply to core platform services as defined in Regulation (EU) 2022/1925. | |
| (d) maintaining or restoring overriding interests in the technical security of a service provided by the controller and requested by the data subject or the terminal equipment used for the provision of such service limited strictly to what is necessary for that security purpose; | |
| 4. Where storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person is based on consent, the following shall apply: | |
| (a) the data subject shall be able to refuse and withdraw consent in an easy, user-friendly, straightforward and intelligible manner with a prominently displayed single-click button; it shall be as easy to refuse or withdraw consent as to give it; | |
| (b) if the data subject gives consent, the controller shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the data subject; | |
| (c) if the data subject declines a request for consent, the controller shall not make a new request for consent for the same purpose for a period of at least one year; processing of personal data for the sole purpose of respecting such refusal shall not rely on tracking or identification beyond what is strictly necessary; | |
| (d) when online interface designs utilize an online choice architecture that includes dark patterns or other deceptive techniques to manipulate a data subject into giving consent, with the aim to distort or impair their free choice, such consent shall be invalidated; | |
| This paragraph also applies to any consent under Regulation (EU) 2026/697 and to any subsequent processing of personal data based on consent. | |
| 5. This Article shall apply from [OP: please insert the date = 6 months following the date of entry into force of this Regulation]. |
| Text proposed by the Commission | Amendment |
|---|---|
| This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data. | Article 5 is replaced by the following: |
| 1. Member States shall ensure that the storing of information, or gaining access to information already stored, in the terminal equipment of a user of a service or a subscriber of a service can only be done based on consent of said user or subscriber, in accordance with Regulation 2016/679. | |
| 2. The storing of information, or gaining access to information already stored, in the terminal equipment of a subscriber or user of a specific service and the subsequent processing of personal data for the same purpose shall only be lawful without obtaining consent to the extent that is strictly necessary and solely related for the following purposes: | |
| (a) carrying out the transmission of an electronic communication over an electronic communications network; | |
| (b) providing a service requested by the user or subscriber, as well as its full functionality and personalisation; including the storing of or access to data strictly necessary for the provision of content such as personalisation or recommendation of content, the management of a digital subscription, or the maintenance of a user session; | |
| (c) measuring the audience of an online service by creating aggregated information about the usage of that online service, also by a third party, provided that the measuring does not involve repurposing of said data for profiling, advertising, or other privacy intrusive purposes and is subject to relevant safeguards; | |
| (d) measuring the audience of an online service by a trade association or its mandated measurement entity on behalf of one or more media service providers for joint audience measurement purposes in accordance with Article 24 of Regulation (EU) 2024/1083, subject to appropriate technical and organisational safeguards; or by a third party acting on behalf of the controller of that online service pursuant to a contractual arrangement with that controller, solely for the purpose of measuring the audience of that online service; or by an entity belonging to the same digital ecosystem as the controller of that online service, for the purpose of measuring the audience of services within that digital ecosystem; | |
| (e) ensuring the security of the information society service or of the electronic communications network, provided that it is strictly necessary, proportionate, subject to appropriate safeguards, and only limited to information strictly necessary for this purpose and does not involve any general scanning or monitoring of information stored in the terminal equipment of a user or subscriber; | |
| (f) preventing fraud directly related to the use of the specific service requested by the user, provided that such processing is strictly necessary, proportionate, subject to appropriate safeguards, limited to the smallest amount of data required for the purpose, and does not involve any general scanning or monitoring of information stored in the terminal equipment of a user or subscriber; | |
| (g) provision, displaying and measurement of such advertising that is solely based on the content immediately displayed to the subscriber or user while using said service, no form of profiling or other privacy intrusive technologies shall be used. | |
| 3. The subscriber or user shall be able to refuse requests for consent in an easy | |
| and intelligible manner with a single-click button or equivalent means. If the subscriber or user gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the subscriber or user. | |
| 4. Nothing in this Article shall prevent a media service provider from conditioning access to its service upon the data subject’s consent to the processing of personal data for one or more specified purposes, or upon the payment of a reasonable fee for an equivalent version of the service that does not involve such processing. The specified purposes may include, but are not limited to, advertising, service improvement, product development, and analytics. Where such a choice is offered, both options must be presented to the data subject with equal prominence, in clear and plain language, and without the use of dark patterns. |
| Text proposed by the Commission | Amendment |
|---|---|
| This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data. | 3. Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed when that person has given his or her consent, in accordance with Regulation (EU) 2016/679. |
| This shall not prevent any technical storage or access and the corresponding processing of personal data if it is exclusively related to and strictly necessary for: | |
| a) carrying out the transmission of an electronic communication over an electronic communications network; | |
| b) providing a service explicitly requested by the subscriber or user; | |
| c) measuring the general audience of an online service requested by a subscriber or user in an immediately anonymised and aggregated form; | |
| d) maintaining or restoring the technical security of a service explicitly requested by the subscriber or user through strictly proportionate means; | |
| If the subscriber or user refuses a request for consent, the provider shall not make a new request for consent for the same purpose for a period of at least six months. Refusing to give consent should not be more difficult than giving consent. Consent shall by default not be considered to be given in an informed and specific manner when the request for consent involves the disclosure of data to more than 10 controllers in a single action. | |
| Member States shall designate the competent supervisory authority under Regulation (EU) 2016/679 for the supervision and enforcement of the rules under this paragraph. |
| Text proposed by the Commission | Amendment |
|---|---|
| This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data. | Member States shall ensure that the storing of information, or gaining of access to information already stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given their consent, having been provided with clear and comprehensive information, in accordance with Regulation (EU) 2016/679, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the purposes set out in Article 88a(3) of Regulation (EU) 2016/679 of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an online service explicitly requested by the subscriber or user to provide the service. This paragraph shall not apply if the information constitutes processing of personal data. |
| Text proposed by the Commission | Amendment |
|---|---|
| This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data. | The processing of personal data previously governed by these provisions shall be exclusively subject to Regulation (EU) 2016/679. |
| (It applies to overall directive.) |
The AM removes overlapping ePrivacy rules on security, terminal access, metadata, location data and direct marketing where personal-data processing is already governed by the GDPR. Keeping parallel regimes creates consent fatigue, divergent national transpositions and legal uncertainty, including stricter rules for some anonymous device data than for personal data. Consolidation under the GDPR’s risk-based framework simplifies compliance, strengthens coherent rights exercise, supports innovation and preserves sector-specific rules in dedicated instruments.
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| 2a. Article 6 is deleted. |
This change is proposed due to other amendments tabled moving e-privacy provisions under Regulation (EU) 2016/679.
| Text proposed by the Commission | Amendment |
|---|---|
| 2a. Article 6 is deleted. |
The AM removes overlapping ePrivacy rules on security, terminal access, metadata, location data and direct marketing where personal-data processing is already governed by the GDPR. Keeping parallel regimes creates consent fatigue, divergent national transpositions and legal uncertainty, including stricter rules for some anonymous device data than for personal data. Consolidation under the GDPR’s risk-based framework simplifies compliance, strengthens coherent rights exercise, supports innovation and preserves sector-specific rules in dedicated instruments.
| Text proposed by the Commission | Amendment |
|---|---|
| 2b. Article 9 is deleted. |
The AM removes overlapping ePrivacy rules on security, terminal access, metadata, location data and direct marketing where personal-data processing is already governed by the GDPR. Keeping parallel regimes creates consent fatigue, divergent national transpositions and legal uncertainty, including stricter rules for some anonymous device data than for personal data. Consolidation under the GDPR’s risk-based framework simplifies compliance, strengthens coherent rights exercise, supports innovation and preserves sector-specific rules in dedicated instruments.
Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec
| Text proposed by the Commission | Amendment |
|---|---|
| 2b. Article 9 is deleted. |
This change is proposed due to other amendments tabled moving e-privacy provisions under Regulation (EU) 2016/679.
| Text proposed by the Commission | Amendment |
|---|---|
| 2c. Article 13 is deleted. |
The AM removes overlapping ePrivacy rules on security, terminal access, metadata, location data and direct marketing where personal-data processing is already governed by the GDPR. Keeping parallel regimes creates consent fatigue, divergent national transpositions and legal uncertainty, including stricter rules for some anonymous device data than for personal data. Consolidation under the GDPR’s risk-based framework simplifies compliance, strengthens coherent rights exercise, supports innovation and preserves sector-specific rules in dedicated instruments.
| Text proposed by the Commission | Amendment |
|---|---|
| [...] | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| Single-entry point for incident reporting | National single-entry points and interoperability for incident reporting/data breaches |
Businesses in the EU are subject toseveral reporting mechanisms forsecurity incidents under NIS2, CRA,GDPR, and DORA, creating undesirableoverlap and double work. For example, different bumpers exist for securityincidents in the CRA, DORA and NIS2,and different reports are required for thesame event due to divergingrequirements in the various acts. Thereporting deadlines are alsoinconsistent. Uploading to the reportingplatform is merely the final step in alonger process. To achieve an actualreduction in administrative burdens forEuropean businesses it is necessary toharmonise all steps within the securityincident reporting process. Work towardsgreater alignment of reportingrequirements, including timelines (96hours) and trigger points, to reduceunnecessary administrative burden andduplication.
| Text proposed by the Commission | Amendment |
|---|---|
| Single-entry point for incident reporting | National single-entry points and interoperability for incident reporting/data breaches |
| Text proposed by the Commission | Amendment |
|---|---|
| Single-entry point for incident reporting | National single-entry points and interoperability for incident reporting/data breaches |
Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay
| Text proposed by the Commission | Amendment |
|---|---|
| (1) ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation. | (1) ENISA may develop and maintain an EU entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘EU entry-point'). ENISA shall act as the single European point of coordination between the national single-entry points established or designated by the Member States, ensuring their interoperability and the secure routing of notifications; it shall not constitute a centralised point for the substantive receipt, transmission or storage of notifications. Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the coordination between national points of entry builds on the single reporting platform established by the Member States under that Regulation. |
Member States establish a single national entry point for the submission of notifications. The simplification sought for reporting entities is achieved through a single national interface, not through the transfer to a Union body of competences exercised at national level. A single Union database of incident notifications would by its very nature constitute a target of the first order and a single point of vulnerability.
Connections
The dossier, the decisions on this text and its other versions.
No connections found for this item.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 25 September 2026
Cite as
European Parliament (2026). “AMENDMENTS 1565 - 1740 - Draft report Amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557 as regards the simplification of the digital legislative framework, and repealing Regulations (EU) 2018/1807, (EU) 2019/1150, (EU) 2022/868, and Directive (EU) 2019/1024 (Digital Omnibus)”. Text, 27 July 2026. docId CJ72-AM-791874. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/CJ72-AM-791874 (retrieved 25 September 2026). Data: EP Open Data API: document record, https://data.europarl.europa.eu/api/v2/documents/CJ72-AM-791874 (CC BY 4.0).
BibTeX
@misc{epw-text-cj72-am-791874,
author = {{European Parliament}},
title = {{AMENDMENTS 1565 - 1740 - Draft report Amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557 as regards the simplification of the digital legislative framework, and repealing Regulations (EU) 2018/1807, (EU) 2019/1150, (EU) 2022/868, and Directive (EU) 2019/1024 (Digital Omnibus)}},
year = {2026},
date = {2026-07-27},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/CJ72-AM-791874}},
url = {https://news.eu-parl.st-solutions.dev/texts/CJ72-AM-791874},
urldate = {2026-09-25},
publisher = {EU Parl Watch Research},
note = {Text. docId CJ72-AM-791874. Data: EP Open Data API: document record (CC BY 4.0)}
}