Digital Omnibus tracker

Digital Omnibus proposal

Recital 27a

Compare the available Commission, Council and Parliament texts and amendments affecting this recital.

Recital total: 1 part · 1 Council draft · 4 Parliament amendments

Removed wording is struck through; added or replacement wording is highlighted.

Institutional text

European Commission proposal

The wording proposed by the Commission at the start of this legislative file.

No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.

Institutional text

Council Presidency texts

Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.

Recital 27a

September Presidency compromise

Pseudonymisation is one of the possible security measures within the meaning of Article 32 of Regulation (EU) 2016/679 and does not necessarily have to be applied in all cases. Its legal effect should depend upon its actual effectiveness in preventing identification of a natural person by the relevant recipient. Controllers and processors should remain free to use other equally effective or more effective technical and organisational measures capable of achieving the substantive confidentiality, integrity and data-protection outcomes required by this Regulation. Whether pseudonymisation is appropriate, should be assessed on a case-by-case basis and depends on the context, the nature of the personal data and the existence of other appropriate technical and organisational measures. The effective application of pseudonymisation may also be clarified for controllers and processors through the approval of specific codes of conduct in accordance with Article 40 of Regulation (EU) 2016/679, taking account of the specific characteristics of the processing carried out in certain sectors and the specific needs of micro, small and medium enterprises. Apart from pseudonymisation, other privacy-enhancing technologies could be applied as appropriate.

Competing proposals

European Parliament amendments

These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.

More filters

Additional proposed wording Amendment 224 · Axel Voss ITRE · LIBE
Justification

RISK-BASED APPROACH #1: This package makes the GDPR’s risk-based approach practical by introducing objective categories for small, medium and large controllers. Small controllers with limited, non-core processing receive relief from selected administrative duties, while data-subject rights and enforcement remain intact. Very large controllers, gatekeepers and VLOPs/VLOSEs face stronger transparency, annual certification and closer supervision. Compliance effort is thus reduced where risks are low and increased where scale and systemic impact are greatest.

Additional proposed wording Amendment 225 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
Additional proposed wording Amendment 226 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
Justification

The Court proceeds by factual analysis on a case-by-case basis. Transposing that reasoning into a general and abstract rule inside the definition would distort the Court's own method. The relativity confirmed by the Court belongs to the notion of pseudonymisation, where the Court itself located it, not to Article 4(1).

Additional proposed wording Amendment 227 · Jörgen Warborn, Arba Kokalari ITRE · LIBE