Digital Omnibus proposal
Recital 27a
Compare the available Commission, Council and Parliament texts and amendments affecting this recital.
Recital total: 1 part · 1 Council draft · 4 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
The wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Recital 27a
September Presidency compromise
Pseudonymisation is one of the possible security measures within the meaning of Article 32 of Regulation (EU) 2016/679 and does not necessarily have to be applied in all cases. Its legal effect should depend upon its actual effectiveness in preventing identification of a natural person by the relevant recipient. Controllers and processors should remain free to use other equally effective or more effective technical and organisational measures capable of achieving the substantive confidentiality, integrity and data-protection outcomes required by this Regulation. Whether pseudonymisation is appropriate, should be assessed on a case-by-case basis and depends on the context, the nature of the personal data and the existence of other appropriate technical and organisational measures. The effective application of pseudonymisation may also be clarified for controllers and processors through the approval of specific codes of conduct in accordance with Article 40 of Regulation (EU) 2016/679, taking account of the specific characteristics of the processing carried out in certain sectors and the specific needs of micro, small and medium enterprises. Apart from pseudonymisation, other privacy-enhancing technologies could be applied as appropriate.
Recital 27a 1 Council draft
Recital 27a
3 September 2026 · September Presidency compromise
Pseudonymisation is one of the possible security measures within the meaning of Article 32 of Regulation (EU) 2016/679 and does not necessarily have to be applied in all cases. Its legal effect should depend upon its actual effectiveness in preventing identification of a natural person by the relevant recipient. Controllers and processors should remain free to use other equally effective or more effective technical and organisational measures capable of achieving the substantive confidentiality, integrity and data-protection outcomes required by this Regulation. Whether pseudonymisation is appropriate, should be assessed on a case-by-case basis and depends on the context, the nature of the personal data and the existence of other appropriate technical and organisational measures. The effective application of pseudonymisation may also be clarified for controllers and processors through the approval of specific codes of conduct in accordance with Article 40 of Regulation (EU) 2016/679, taking account of the specific characteristics of the processing carried out in certain sectors and the specific needs of micro, small and medium enterprises. Apart from pseudonymisation, other privacy-enhancing technologies could be applied as appropriate.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Additional proposed wording Amendment 224 · Axel Voss ITRE · LIBE
Regulation (EU) 2016/679 already has elements of a risk-based approach. However, especially small and medium enterprises cannot benefit from a risk-based approach if the necessary legal certainty is not provided through clear thresholds. To increase the legal certainty for more limited processing the objective categories for small, medium and large processers is introduced. Small controllers are all controllers that have or will process the data of less than [100.000] data subjects in the pending or preceding financial year, including short-term transactional processing. As a default the current rules in the Regulation are maintained and controllers are deemed a medium controller. A controller may only benefit from the privileges for small controllers if there is positive knowledge about fulfilling the criteria. Controllers like hospitals or Unions that by their very nature process large numbers of sensitive data under Article 9 or 10 of Regulation (EU) 2016/679 shall not be deemed a small controller. While small controllers must not comply with many administrative requirements of the Regulation, the rights of data subjects, which are largely based on Article 8(2) of the Charter are not altered. Given the existing burden of proof of controllers, the lack of formal documentation shall not limit the effective enforcement of data subjects’ rights. In the rare case of a complaint or procedure against a small controller, they may proof compliance with any formal or informal evidence according to national procedural law.
Justification
RISK-BASED APPROACH #1: This package makes the GDPR’s risk-based approach practical by introducing objective categories for small, medium and large controllers. Small controllers with limited, non-core processing receive relief from selected administrative duties, while data-subject rights and enforcement remain intact. Very large controllers, gatekeepers and VLOPs/VLOSEs face stronger transparency, annual certification and closer supervision. Compliance effort is thus reduced where risks are low and increased where scale and systemic impact are greatest.
Additional proposed wording Amendment 225 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
Trustworthy processing of data and legal clarity is necessary for economic growth and supporting innovation with socially beneficial outcomes. In order to achieve this, some clarifications are necessary particularly to enable wide use of anonymisation. Personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable natural person. However, personal data that cannot be directly or indirectly attributed to a natural person is not within the scope of Regulation (EU) 2016/679. Controllers should be allowed to process personal data for the sole purpose of anonymizing personal data. Such processing should typically be understood as a legitimate interest for a controller. At the same time, the protection of data subjects’ rights typically benefits from anonymization. Consequently, the balancing test should favour the processing of personal data for anonymization. To ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and foreseeable technological developments.
Additional proposed wording Amendment 226 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
The case-law of the Court of Justice (Case C-413/23 P, EDPS v SRB) confirms that the personal character of data is not an absolute feature and that pseudonymised data may, depending on the circumstances of the case, not be identifiable for a given recipient. However, that assessment is, by the Court's own method, a factual analysis to be carried out in each individual case, taking into account the means reasonably likely to be used and the technical, organisational and legal measures in place. Such a contextual and evolving assessment cannot be transposed into a general and abstract rule written into the definition of personal data in Article 4 without distorting that method and weakening the level of protection. The definition of personal data therefore remains unchanged. The relative and contextual character of identifiability is reflected in the graded regime of Article 4: what is decisive is whether the data is re-identifiable. Pseudonymous data is potentially re-identifiable; anonymised data is not re-identifiable; pseudonymised data is data that has undergone a state-of-the-art privacy-preserving service or technique. Pseudonymised data remain personal data for the controller holding the additional information and cannot as such be regarded as anonymised.
Justification
The Court proceeds by factual analysis on a case-by-case basis. Transposing that reasoning into a general and abstract rule inside the definition would distort the Court's own method. The relativity confirmed by the Court belongs to the notion of pseudonymisation, where the Court itself located it, not to Article 4(1).
Additional proposed wording Amendment 227 · Jörgen Warborn, Arba Kokalari ITRE · LIBE
Pseudonymised data should be presumed not to constitute personal data for an entity that has no lawful means of access to the additional information necessary for identification and no means reasonably likely to be used to identify the natural person, in line with the case-law of the Court of Justice of the European Union. That relative approach provides legal certainty for the sharing of data for research, statistics and the development of artificial intelligence, without lowering the level of protection where identification remains reasonably likely.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.