Digital Omnibus proposal
Recital 38a
Compare the available Commission, Council and Parliament texts and amendments affecting this recital.
Recital total: 1 part · 0 Council drafts · 4 Parliament amendments
Source notes (1)
- No Commission counterpart is printed for this Parliament-proposed recital.
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
The wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to these tracked parts.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Additional proposed wording Amendment 374 · Axel Voss ITRE · LIBE
To ensure compliance with the requirements of this Regulation in respect of the processing to be carried out by the processor on behalf of the controller, when entrusting a processor with processing activities, the controller should use only processors providing sufficient guarantees, in particular in terms of expert knowledge, reliability and resources, to implement technical and organisational measures which will meet the requirements of this Regulation, including for the security of processing. The adherence of the processor to an approved code of conduct or an approved certification mechanism may be used as an element to demonstrate compliance with the obligations of the controller. If processing by a processor is governed by an agreement with the controller which specifies the subject matter and duration of the processing, the nature and purpose of the processing, the types of data to be processed and the categories of data subjects the tasks and duties of the processor shall be directly qualified by this Regulation in order to avoid legal uncertainty and provide clear standards for all parties, which process personal data within the scope of European law. Furthermore, if the processor provides a binding assurance as to the level of protection to which it is able to ensure the security of the processing and its obligation to assist the controller by means of appropriate technical and organisational measures and confirms the suitability of these safeguards for the processing operations it intends to carry out, due to the nature of these services as mere digital infrastructure Services their agreements may renounce on some specific notification requirements of controllers. However, processors who fail to fulfil those assurances are directly liable for this non compliance. After the completion of the processing on behalf of the controller, the processor should, at the choice of the controller, return or delete the personal data, unless there is a requirement to store the personal data under Union or Member State law to which the processor is subject.
Justification
Article 28 should better reflect modern cloud, hosting, security and infrastructure services, which are standardised, layered and technically complex. For such infrastructure processing, controllers need enforceable assurances on security, assistance and downstream liability, not bespoke descriptions of every technical sub-operation. The amendment cuts formalistic contract burdens while preserving core duties: confidentiality, security, assistance, deletion or return, audits, controller suitability checks and processor liability for sub-processors.
Additional proposed wording Amendment 375 · Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Andrea Wechsler, Pekka Toveri, Christian Ehler ITRE · LIBE
While Article 28 of Regulation 2016/679 establishes a robust framework for contractual accountability, its practical application has created a structural asymmetry when controllers often rely on systemic digital actors designated as gatekeepers under Regulation (EU) 2022/1925. This creates a redundant administrative burden for small and medium-sized enterprises (SMEs), small mid-cap enterprises (SMCs) and public authorities. To eliminate this red tape and enhance digital sovereignty, a direct compliance mechanism should apply solely to gatekeepers by way of derogation from Article 28. Where a processor is a designated gatekeeper, its core data protection duties should come directly from this Regulation. Processors not designated as gatekeepers do not possess equivalent market power and remain entirely subject to the standard contractual framework, preserving contractual freedom and a competitive digital ecosystem.
Additional proposed wording Amendment 376 · Pernando Barrena Arza ITRE · LIBE
Controllers employing large-scale automated individual decision-making systems, such as automatic rejections or terminations of contracts or accounts, credit scoring or hiring decisions benefit from more efficient procedures, but should also ensure compliance of these systems. Therefore, all automated individual decision-making systems affecting a relevant number of individuals should be subject to a data protection impact assessment and should be demonstratable based scientifically recognised mathematical and statistical methods.
Additional proposed wording Amendment 377 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
For the purposes of this Regulation and Regulation (EU) 2016/679, free and open-source software, including whether it has been developed or supplied outside the course of a commercial activity, should have the same meaning as defined and further specified in Regulation (EU) 2024/2847.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.