Digital Omnibus tracker

Digital Omnibus proposal

Recital 27b

Compare the available Commission, Council and Parliament texts and amendments affecting this recital.

Recital total: 1 part · 4 Council drafts · 2 Parliament amendments

Removed wording is struck through; added or replacement wording is highlighted.

Institutional text

European Commission proposal

The wording proposed by the Commission at the start of this legislative file.

No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.

Institutional text

Council Presidency texts

Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.

Recital 27a

May Presidency compromise

In order to determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used to identify the natural person directly or indirectly. The identification of a natural person should be assessed by the controller or the processor, considering the actual technical, organisational and legal capabilities of the controller or processor. In light of the interpretation provided in the case‑law of the Court of Justice of the European Union, it is important to provide further clarity on when a natural person should be considered to be identifiable following the application of pseudonymisation to personal data and the transmission to a recipient. The European Data Protection Board should ensure consistency and support controllers by adopting an opinion on pseudonymisation and anonymisation, assessing and specifying the state of the art of available techniques, as well as the technical and organisational measures and criteria to apply pseudonymisation and anonymisation to personal data effectively and by clarifying circumstances whether and when the application of pseudonymisation to personal data may effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable. The opinion should also address the processing to be undertaken and other measures to be applied in order to effectively render personal data anonymous. It is important that the Board carries out a public consultation with relevant stakeholders prior to issuing its opinion. While controllers remain fully responsible to determine and demonstrate whether pseudonymised data do not lead to re-identification of data subjects by persons other than the controller, the opinion should support and provide guidance to controllers regarding the effective application of pseudonymisation to personal data.

Competing proposals

European Parliament amendments

These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.

More filters

Additional proposed wording Amendment 228 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
Justification

Gives operational content to the notion of privacy-enhancing technique, on which the regime for pseudonymised data rests. The reference to an implementing act avoids freezing into the Regulation a state of the art that is bound to evolve.

Additional proposed wording Amendment 229 · Axel Voss ITRE · LIBE
Justification

RISK-BASED APPROACH #2: This package makes the GDPR’s risk-based approach practical by introducing objective categories for small, medium and large controllers. Small controllers with limited, non-core processing receive relief from selected administrative duties, while data-subject rights and enforcement remain intact. Very large controllers, gatekeepers and VLOPs/VLOSEs face stronger transparency, annual certification and closer supervision. Compliance effort is thus reduced where risks are low and increased where scale and systemic impact are greatest.