Digital Omnibus proposal
Recital 26a
Compare the available Commission, Council and Parliament texts and amendments affecting this recital.
Recital total: 1 part · 3 Council drafts · 2 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
The wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Recital 26a
June Presidency compromise · 10 June
While Member State are required to designate one or more competent authorities to be responsible for the application and enforcement of Regulation (EU) 2023/2854 (competent authorities), uncertainty persists about the role of supervisory authorities responsible for monitoring and enforcement of Regulation (EU) 2016/679 and Regulation (EU) 2018/1725 under Regulation (EU) 2023/2854. Regulation (EU) 2023/2854 recalls that Regulation (EU) 2016/679 applies to the processing of personal data by private and public authorities of the Member States and Regulation (EU) 2018/1725 applies to the processing of personal data by all Union institutions and bodies when these organisations are data holders, data users or third parties under this regulation. It further stipulates that the powers and competences of supervisory authorities under Regulation (EU) 2016/679 and (EU) 2017/1725 remain unaffected by Regulation (EU) 2023/2854. In addition, the current rules of Regulation (EU) 2023/2854 state that these authorities are responsible for monitoring the application of Regulation (EU) 2023/2854 insofar as the protection of personal data is concerned and impose fines for the infringement of this regulation. To clarify the role and responsibilities of the supervisory authorities responsible for monitoring and enforcing Regulation (EU) 2016/679 and Regulation (EU) 2018/1725 when personal data are processed pursuant to this regulation and to increase legal certainty, it is necessary to amend Regulation (EU) 2023/2854 by deleting Articles 37(3) and 40(4) and (5) of that Regulation.
Recital 26a
June Presidency compromise · 18 June
While Member State are required to designate one or more competent authorities to be responsible for the application and enforcement of Regulation (EU) 2023/2854 (competent authorities), uncertainty persists about the role of supervisory authorities responsible for monitoring and enforcement of Regulation (EU) 2016/679 and Regulation (EU) 2018/1725 under Regulation (EU) 2023/2854. Regulation (EU) 2023/2854 recalls that Regulation (EU) 2016/679 applies to the processing of personal data by private and public authorities of the Member States and Regulation (EU) 2018/1725 applies to the processing of personal data by all Union institutions and bodies when these organisations are data holders, data users or third parties under this regulation. It further stipulates that the powers and competences of supervisory authorities under Regulation (EU) 2016/679 and (EU) 2017/1725 remain unaffected by Regulation (EU) 2023/2854. In addition, the current rules of Regulation (EU) 2023/2854 state that these authorities are responsible for monitoring the application of Regulation (EU) 2023/2854 insofar as the protection of personal data is concerned and impose fines for the infringement of this regulation. To clarify the role and responsibilities of the supervisory authorities responsible for monitoring and enforcing Regulation (EU) 2016/679 and Regulation (EU) 2018/1725 when personal data are processed pursuant to this regulation and to increase legal certainty, it is necessary to amend Regulation (EU) 2023/2854 by deleting Articles 37(3) and 40(4) and (5) of that Regulation.
Recital 26a
September Presidency compromise
While Member State are required to designate one or more competent authorities to be responsible for the application and enforcement of Regulation (EU) 2023/2854 (competent authorities), uncertainty persists about the role of supervisory authorities responsible for monitoring and enforcement of Regulation (EU) 2016/679 and Regulation (EU) 2018/1725 under Regulation (EU) 2023/2854. Regulation (EU) 2023/2854 recalls that Regulation (EU) 2016/679 applies to the processing of personal data by private and public authorities of the Member States and Regulation (EU) 2018/1725 applies to the processing of personal data by all Union institutions and bodies when these organisations are data holders, data users or third parties under this regulation. It further stipulates that the powers and competences of supervisory authorities under Regulation (EU) 2016/679 and (EU) 2017/1725 remain unaffected by Regulation (EU) 2023/2854. In addition, the current rules of Regulation (EU) 2023/2854 state that these authorities are responsible for monitoring the application of Regulation (EU) 2023/2854 insofar as the protection of personal data is concerned and impose fines for the infringement of this regulation. To clarify the role and responsibilities of the supervisory authorities responsible for monitoring and enforcing Regulation (EU) 2016/679 and Regulation (EU) 2018/1725 when personal data are processed pursuant to this regulation and to increase legal certainty, it is necessary to amend Regulation (EU) 2023/2854 by deleting Articles 37(3) and 40(4) and (5) of that Regulation.
Recital 26a 3 Council drafts
Recital 26a
10 June 2026 · June Presidency compromise · 10 June
While Member State are required to designate one or more competent authorities to be responsible for the application and enforcement of Regulation (EU) 2023/2854 (competent authorities), uncertainty persists about the role of supervisory authorities responsible for monitoring and enforcement of Regulation (EU) 2016/679 and Regulation (EU) 2018/1725 under Regulation (EU) 2023/2854. Regulation (EU) 2023/2854 recalls that Regulation (EU) 2016/679 applies to the processing of personal data by private and public authorities of the Member States and Regulation (EU) 2018/1725 applies to the processing of personal data by all Union institutions and bodies when these organisations are data holders, data users or third parties under this regulation. It further stipulates that the powers and competences of supervisory authorities under Regulation (EU) 2016/679 and (EU) 2017/1725 remain unaffected by Regulation (EU) 2023/2854. In addition, the current rules of Regulation (EU) 2023/2854 state that these authorities are responsible for monitoring the application of Regulation (EU) 2023/2854 insofar as the protection of personal data is concerned and impose fines for the infringement of this regulation. To clarify the role and responsibilities of the supervisory authorities responsible for monitoring and enforcing Regulation (EU) 2016/679 and Regulation (EU) 2018/1725 when personal data are processed pursuant to this regulation and to increase legal certainty, it is necessary to amend Regulation (EU) 2023/2854 by deleting Articles 37(3) and 40(4) and (5) of that Regulation.
Recital 26a
18 June 2026 · June Presidency compromise · 18 June
While Member State are required to designate one or more competent authorities to be responsible for the application and enforcement of Regulation (EU) 2023/2854 (competent authorities), uncertainty persists about the role of supervisory authorities responsible for monitoring and enforcement of Regulation (EU) 2016/679 and Regulation (EU) 2018/1725 under Regulation (EU) 2023/2854. Regulation (EU) 2023/2854 recalls that Regulation (EU) 2016/679 applies to the processing of personal data by private and public authorities of the Member States and Regulation (EU) 2018/1725 applies to the processing of personal data by all Union institutions and bodies when these organisations are data holders, data users or third parties under this regulation. It further stipulates that the powers and competences of supervisory authorities under Regulation (EU) 2016/679 and (EU) 2017/1725 remain unaffected by Regulation (EU) 2023/2854. In addition, the current rules of Regulation (EU) 2023/2854 state that these authorities are responsible for monitoring the application of Regulation (EU) 2023/2854 insofar as the protection of personal data is concerned and impose fines for the infringement of this regulation. To clarify the role and responsibilities of the supervisory authorities responsible for monitoring and enforcing Regulation (EU) 2016/679 and Regulation (EU) 2018/1725 when personal data are processed pursuant to this regulation and to increase legal certainty, it is necessary to amend Regulation (EU) 2023/2854 by deleting Articles 37(3) and 40(4) and (5) of that Regulation.
Recital 26a
3 September 2026 · September Presidency compromise
While Member State are required to designate one or more competent authorities to be responsible for the application and enforcement of Regulation (EU) 2023/2854 (competent authorities), uncertainty persists about the role of supervisory authorities responsible for monitoring and enforcement of Regulation (EU) 2016/679 and Regulation (EU) 2018/1725 under Regulation (EU) 2023/2854. Regulation (EU) 2023/2854 recalls that Regulation (EU) 2016/679 applies to the processing of personal data by private and public authorities of the Member States and Regulation (EU) 2018/1725 applies to the processing of personal data by all Union institutions and bodies when these organisations are data holders, data users or third parties under this regulation. It further stipulates that the powers and competences of supervisory authorities under Regulation (EU) 2016/679 and (EU) 2017/1725 remain unaffected by Regulation (EU) 2023/2854. In addition, the current rules of Regulation (EU) 2023/2854 state that these authorities are responsible for monitoring the application of Regulation (EU) 2023/2854 insofar as the protection of personal data is concerned and impose fines for the infringement of this regulation. To clarify the role and responsibilities of the supervisory authorities responsible for monitoring and enforcing Regulation (EU) 2016/679 and Regulation (EU) 2018/1725 when personal data are processed pursuant to this regulation and to increase legal certainty, it is necessary to amend Regulation (EU) 2023/2854 by deleting Articles 37(3) and 40(4) and (5) of that Regulation.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Additional proposed wording Amendment 206 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay ITRE · LIBE
The framework should mitigate vendor lock-in, in particular dependence on non-European providers, and facilitate switching between data processing services, including Artificial Intelligence-as-a-Service (AIaaS), in accordance with the free flow of data within the Union. Very large enterprises and operators of closed or restricted data ecosystems should not, without objective justification, create unnecessary barriers to the lawful sharing, licensing, exchange or re-use of high-value datasets used for research, innovation, advanced data processing or the development of artificial intelligence systems. Such datasets may include trade secrets, strategic industrial information, research data and data originating from natural persons, whether identifiable, pseudonymised or otherwise non-identifiable. Any such sharing, licensing, exchange or re-use should be subject to appropriate safeguards for personal data, trade secrets, cybersecurity, intellectual property rights and legitimate economic-security interests. Where appropriate, operators should apply measures supporting interoperability, portability, privacy-preserving technologies, secure processing environments, business continuity and resilience against unilateral service disruption, including disruption resulting from measures adopted by third-country authorities.
Justification
Recital 26 addresses dominant positions in the re-use of public sector data but says nothing of closed private ecosystems, nor of AI-as-a-Service, which is where lock-in is now most acute. The safeguards clause ensures that opening high-value datasets does not come at the expense of European industrial interests.
Additional proposed wording Amendment 207 · Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler ITRE · LIBE
The European Data Innovation Board’s character as a consultative body as regards the implementation and the enforcement of the Data Act should be maintained. However, its structure should be simplified and should allow for more strategic discussions. Notwithstanding these changes, the Board should continue to serve as a forum to develop consistent practice of competent authorities in the enforcement of Chapters II, III, V and VII, VIIa and VIIc. To this end, technical exchanges relating to best practices and dialogue between national enforcement bodies, including information sharing shall continue to be possible in various subgroups, and, where appropriate, should involve or consult relevant stakeholders, including representatives of users, data holders, data recipients, SMEs and sector-specific organisations, in order to provide practical market expertise, identify implementation obstacles and support the consistent and effective application and enforcement of the Data Act across the Union. These subgroups should also be able to discuss matters relating to the newly added Chapters VIIa and VIIc. The European Data Innovation Board should also be consulted on guidelines the Commission may issue to support the sectorial implementation of the Data Act.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Recital 26a
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Recital 26a
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded