Digital Omnibus proposal
Recital 27b
Compare the available Commission, Council and Parliament texts and amendments affecting this recital.
Recital total: 1 part · 4 Council drafts · 2 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
The wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Recital 27a
May Presidency compromise
In order to determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used to identify the natural person directly or indirectly. The identification of a natural person should be assessed by the controller or the processor, considering the actual technical, organisational and legal capabilities of the controller or processor. In light of the interpretation provided in the case‑law of the Court of Justice of the European Union, it is important to provide further clarity on when a natural person should be considered to be identifiable following the application of pseudonymisation to personal data and the transmission to a recipient. The European Data Protection Board should ensure consistency and support controllers by adopting an opinion on pseudonymisation and anonymisation, assessing and specifying the state of the art of available techniques, as well as the technical and organisational measures and criteria to apply pseudonymisation and anonymisation to personal data effectively and by clarifying circumstances whether and when the application of pseudonymisation to personal data may effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable. The opinion should also address the processing to be undertaken and other measures to be applied in order to effectively render personal data anonymous. It is important that the Board carries out a public consultation with relevant stakeholders prior to issuing its opinion. While controllers remain fully responsible to determine and demonstrate whether pseudonymised data do not lead to re-identification of data subjects by persons other than the controller, the opinion should support and provide guidance to controllers regarding the effective application of pseudonymisation to personal data.
Recital 27a
June Presidency compromise · 10 June
In order to determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used to identify the natural person directly or indirectly. The identifiability of a natural person should be assessed by the controller, considering the actual technical and organisational measures, and applicable prohibitions by law . In light of the interpretation provided in the case‑law of the Court of Justice of the European Union, it is important to provide further clarity on when a natural person should be considered to be identifiable following the application of pseudonymisation to personal data and the transmission to a recipient. The European Data Protection Board should ensure consistency and support controllers and processors by adopting an opinion on pseudonymisation and anonymisation, assessing and specifying the state of the art of available techniques, as well as the technical and organisational measures and criteria to apply pseudonymisation and anonymisation to personal data effectively and by clarifying circumstances whether and when the application of pseudonymisation to personal data may effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable. The opinion should also address the processing to be undertaken and other measures to be applied in order to effectively render personal data anonymous. It is important that the Board carries out a public consultation with relevant stakeholders prior to issuing its opinion. While controllers remain fully responsible to determine and demonstrate whether pseudonymised data do not lead to reidentification of data subjects by persons other than the controller, the opinion should support and provide guidance to controllers regarding the effective application of pseudonymisation to personal data.
Recital 27a
June Presidency compromise · 18 June
In order to determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used to identify the natural person directly or indirectly. The identifiability of a natural person should be assessed by the controller, considering the actual technical and organisational measures, and applicable prohibitions by law . In light of the interpretation provided in the case‑law of the Court of Justice of the European Union, it is important to provide further clarity on when a natural person should be considered to be identifiable following the application of pseudonymisation to personal data and the transmission to a recipient. The European Data Protection Board should ensure consistency and support controllers and processors by adopting an opinion on pseudonymisation and anonymisation, assessing and specifying the state of the art of available techniques, as well as the technical and organisational measures and criteria to apply pseudonymisation and anonymisation to personal data effectively and by clarifying circumstances whether and when the application of pseudonymisation to personal data may effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable. The opinion should also address the processing to be undertaken and other measures to be applied in order to effectively render personal data anonymous. It is important that the Board carries out a public consultation with relevant stakeholders prior to issuing its opinion. While controllers remain fully responsible to determine and demonstrate whether pseudonymised data do not lead to reidentification of data subjects by persons other than the controller, the opinion should support and provide guidance to controllers regarding the effective application of pseudonymisation to personal data.
Recital 27b
September Presidency compromise
In light of the interpretation provided in the case-law of the Court of Justice of the European Union, it is important to provide further clarity on when a natural person should be considered to be identifiable following the application of pseudonymisation to personal data and the transmission to a recipient, as well as when such recipient further discloses, transmits or otherwise makes such data available to a third party. In order to determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used to identify the natural person directly or indirectly, such as singling out or online identifiers. The identifiability of a natural person should be assessed considering the actual technical and organisational measures, and based on objective factors and applicable prohibitions by law. These factors may include the state of the art of the techniques used to pseudonymise the data, the properties of the data subject itself, the cost and time needed for the third party to obtain such additional information and the legal obligations of the third party. Data which are in themselves impersonal may become ‘personal’ in nature where they are put at the disposal of other persons who have means reasonably likely to enable the data subject to be identified. This applies to both the party that transmits this data and the third party that subsequently processes this data. Whether means are reasonably likely to be used will depend on the relevant entity’s perspective, which depends on the specific nature and context of the processing, such as who has access to or control over the data, whether the data is being transmitted from one party to another, the relationship between those parties, and whether the receiver of the data might process it on behalf of another party.
Recital 27b 4 Council drafts
Recital 27a
21 May 2026 · May Presidency compromise
In order to determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used to identify the natural person directly or indirectly. The identification of a natural person should be assessed by the controller or the processor, considering the actual technical, organisational and legal capabilities of the controller or processor. In light of the interpretation provided in the case‑law of the Court of Justice of the European Union, it is important to provide further clarity on when a natural person should be considered to be identifiable following the application of pseudonymisation to personal data and the transmission to a recipient. The European Data Protection Board should ensure consistency and support controllers by adopting an opinion on pseudonymisation and anonymisation, assessing and specifying the state of the art of available techniques, as well as the technical and organisational measures and criteria to apply pseudonymisation and anonymisation to personal data effectively and by clarifying circumstances whether and when the application of pseudonymisation to personal data may effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable. The opinion should also address the processing to be undertaken and other measures to be applied in order to effectively render personal data anonymous. It is important that the Board carries out a public consultation with relevant stakeholders prior to issuing its opinion. While controllers remain fully responsible to determine and demonstrate whether pseudonymised data do not lead to re-identification of data subjects by persons other than the controller, the opinion should support and provide guidance to controllers regarding the effective application of pseudonymisation to personal data.
Recital 27a
10 June 2026 · June Presidency compromise · 10 June
In order to determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used to identify the natural person directly or indirectly. The identifiability of a natural person should be assessed by the controller, considering the actual technical and organisational measures, and applicable prohibitions by law . In light of the interpretation provided in the case‑law of the Court of Justice of the European Union, it is important to provide further clarity on when a natural person should be considered to be identifiable following the application of pseudonymisation to personal data and the transmission to a recipient. The European Data Protection Board should ensure consistency and support controllers and processors by adopting an opinion on pseudonymisation and anonymisation, assessing and specifying the state of the art of available techniques, as well as the technical and organisational measures and criteria to apply pseudonymisation and anonymisation to personal data effectively and by clarifying circumstances whether and when the application of pseudonymisation to personal data may effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable. The opinion should also address the processing to be undertaken and other measures to be applied in order to effectively render personal data anonymous. It is important that the Board carries out a public consultation with relevant stakeholders prior to issuing its opinion. While controllers remain fully responsible to determine and demonstrate whether pseudonymised data do not lead to reidentification of data subjects by persons other than the controller, the opinion should support and provide guidance to controllers regarding the effective application of pseudonymisation to personal data.
Recital 27a
18 June 2026 · June Presidency compromise · 18 June
In order to determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used to identify the natural person directly or indirectly. The identifiability of a natural person should be assessed by the controller, considering the actual technical and organisational measures, and applicable prohibitions by law . In light of the interpretation provided in the case‑law of the Court of Justice of the European Union, it is important to provide further clarity on when a natural person should be considered to be identifiable following the application of pseudonymisation to personal data and the transmission to a recipient. The European Data Protection Board should ensure consistency and support controllers and processors by adopting an opinion on pseudonymisation and anonymisation, assessing and specifying the state of the art of available techniques, as well as the technical and organisational measures and criteria to apply pseudonymisation and anonymisation to personal data effectively and by clarifying circumstances whether and when the application of pseudonymisation to personal data may effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable. The opinion should also address the processing to be undertaken and other measures to be applied in order to effectively render personal data anonymous. It is important that the Board carries out a public consultation with relevant stakeholders prior to issuing its opinion. While controllers remain fully responsible to determine and demonstrate whether pseudonymised data do not lead to reidentification of data subjects by persons other than the controller, the opinion should support and provide guidance to controllers regarding the effective application of pseudonymisation to personal data.
Recital 27b
3 September 2026 · September Presidency compromise
In light of the interpretation provided in the case-law of the Court of Justice of the European Union, it is important to provide further clarity on when a natural person should be considered to be identifiable following the application of pseudonymisation to personal data and the transmission to a recipient, as well as when such recipient further discloses, transmits or otherwise makes such data available to a third party. In order to determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used to identify the natural person directly or indirectly, such as singling out or online identifiers. The identifiability of a natural person should be assessed considering the actual technical and organisational measures, and based on objective factors and applicable prohibitions by law. These factors may include the state of the art of the techniques used to pseudonymise the data, the properties of the data subject itself, the cost and time needed for the third party to obtain such additional information and the legal obligations of the third party. Data which are in themselves impersonal may become ‘personal’ in nature where they are put at the disposal of other persons who have means reasonably likely to enable the data subject to be identified. This applies to both the party that transmits this data and the third party that subsequently processes this data. Whether means are reasonably likely to be used will depend on the relevant entity’s perspective, which depends on the specific nature and context of the processing, such as who has access to or control over the data, whether the data is being transmitted from one party to another, the relationship between those parties, and whether the receiver of the data might process it on behalf of another party.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Additional proposed wording Amendment 228 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
The recognised privacy-enhancing techniques on which the protection of pseudonymous data relies should reflect the state of the art and be promoted across the Union. They include, in particular, pseudonymisation and key separation, strong encryption of data at rest and in transit, aggregation and generalisation, the addition of statistical noise and differential privacy, synthetic data generation, secure multi-party computation, the use of secure processing environments, and contractual and organisational prohibitions on re-identification. The Commission, in close cooperation with the European Data Protection Board, should support controllers and processors in applying such techniques and in assessing the residual risk of re-identification, taking into account the means reasonably likely to be used, and should stipulate the relevant technical criteria by means of an implementing act.
Justification
Gives operational content to the notion of privacy-enhancing technique, on which the regime for pseudonymised data rests. The reference to an implementing act avoids freezing into the Regulation a state of the art that is bound to evolve.
Additional proposed wording Amendment 229 · Axel Voss ITRE · LIBE
At the same time the rules in Regulation (EU) 2016/679 have proven to be too lenient for very large controllers, such as data brokers or large platforms. Hence a category of large controllers is introduced to ensure more stringent rules of controllers with large processing operations. Large controllers shall for example be regularly inspected, face increased transparency and reporting obligations. Large controllers are defined by absolute or relative number of data subjects in any given Member State, to include dominant controllers in all Member States. A national list of such large controllers shall allow supervisory authorities and the public to have transparency about relevant controllers.
Justification
RISK-BASED APPROACH #2: This package makes the GDPR’s risk-based approach practical by introducing objective categories for small, medium and large controllers. Small controllers with limited, non-core processing receive relief from selected administrative duties, while data-subject rights and enforcement remain intact. Very large controllers, gatekeepers and VLOPs/VLOSEs face stronger transparency, annual certification and closer supervision. Compliance effort is thus reduced where risks are low and increased where scale and systemic impact are greatest.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Recital 27b
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Recital 27b
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Recital 27b
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded