Digital Omnibus proposal
Recital 39a
Compare the available Commission, Council and Parliament texts and amendments affecting this recital.
Recital total: 1 part · 4 Council drafts · 1 Parliament amendment
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
The wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Recital 39a
May Presidency compromise
In order to facilitate compliance obligations and the establishment of the contract or other legal act governing the processing by a processor on behalf of the controller, the processor should also be subject to the general obligation of data protection by design and by default under Regulation (EU) 2016/679 to extent it relates to its own obligations under that Regulation. This obligation on the processor does not affect level of responsibility and relationship between the controller and processor, nor the principle of accountability or the respective obligation of controller and processor as laid down under Article 28 of Regulation (EU) 2016/679). As such, the controller remains solely responsible of determining the purpose and means of processing and apply related obligations, while the processor should ensure that data protection by design and by default is applied to its processing offer and services.
Recital 39a
June Presidency compromise · 10 June
In order to facilitate compliance obligations and the establishment of the contract or other legal act governing the processing by a processor on behalf of the controller, the processor should also be subject to the general obligation of data protection by design and by default under Regulation (EU) 2016/679 to extent it relates to their own obligations under that Regulation. This obligation does not affect the level of responsibility and relationship between the controller and processor, nor does it affect the principle of accountability or the respective obligations of controller and processor as laid down under Article 28 of Regulation (EU) 2016/679). Accordingly, the controller remains solely responsible for determining the purpose and means of processing and for complying with related obligations, while the processor should ensure that data protection by design and by default is applied to its offered means and services to carry out processing.
Recital 39a
June Presidency compromise · 18 June
In order to facilitate compliance obligations and the establishment of the contract or other legal act governing the processing by a processor on behalf of the controller, the processor should also be subject to the general obligation of data protection by design and by default under Regulation (EU) 2016/679 to extent it relates to their own obligations under that Regulation. This obligation does not affect the level of responsibility and relationship between the controller and processor, nor does it affect the principle of accountability or the respective obligations of controller and processor as laid down under Article 28 of Regulation (EU) 2016/679). Accordingly, the controller remains solely responsible for determining the purpose and means of processing and for complying with related obligations, while the processor should ensure that data protection by design and by default is applied to its offered means and services to carry out processing.
Recital 39a
September Presidency compromise
In order to facilitate compliance obligations and the establishment of the contract or other legal act governing the processing by a processor on behalf of the controller, the processor should also be subject to the general obligation of data protection by design and by default under Regulation (EU) 2016/679 to extent it relates to their own obligations under that Regulation. This obligation does not affect the level of responsibility and relationship between the controller and processor, nor does it affect the principle of accountability or the respective obligations of controller and processor as laid down under Article 28 of Regulation (EU) 2016/679). Accordingly, the controller remains solely responsible for determining the purpose and means of processing and for complying with related obligations, while the processor should ensure that data protection by design and by default is applied to its offered means and services to carry out processing.
Recital 39a 4 Council drafts
Recital 39a
21 May 2026 · May Presidency compromise
In order to facilitate compliance obligations and the establishment of the contract or other legal act governing the processing by a processor on behalf of the controller, the processor should also be subject to the general obligation of data protection by design and by default under Regulation (EU) 2016/679 to extent it relates to its own obligations under that Regulation. This obligation on the processor does not affect level of responsibility and relationship between the controller and processor, nor the principle of accountability or the respective obligation of controller and processor as laid down under Article 28 of Regulation (EU) 2016/679). As such, the controller remains solely responsible of determining the purpose and means of processing and apply related obligations, while the processor should ensure that data protection by design and by default is applied to its processing offer and services.
Recital 39a
10 June 2026 · June Presidency compromise · 10 June
In order to facilitate compliance obligations and the establishment of the contract or other legal act governing the processing by a processor on behalf of the controller, the processor should also be subject to the general obligation of data protection by design and by default under Regulation (EU) 2016/679 to extent it relates to their own obligations under that Regulation. This obligation does not affect the level of responsibility and relationship between the controller and processor, nor does it affect the principle of accountability or the respective obligations of controller and processor as laid down under Article 28 of Regulation (EU) 2016/679). Accordingly, the controller remains solely responsible for determining the purpose and means of processing and for complying with related obligations, while the processor should ensure that data protection by design and by default is applied to its offered means and services to carry out processing.
Recital 39a
18 June 2026 · June Presidency compromise · 18 June
In order to facilitate compliance obligations and the establishment of the contract or other legal act governing the processing by a processor on behalf of the controller, the processor should also be subject to the general obligation of data protection by design and by default under Regulation (EU) 2016/679 to extent it relates to their own obligations under that Regulation. This obligation does not affect the level of responsibility and relationship between the controller and processor, nor does it affect the principle of accountability or the respective obligations of controller and processor as laid down under Article 28 of Regulation (EU) 2016/679). Accordingly, the controller remains solely responsible for determining the purpose and means of processing and for complying with related obligations, while the processor should ensure that data protection by design and by default is applied to its offered means and services to carry out processing.
Recital 39a
3 September 2026 · September Presidency compromise
In order to facilitate compliance obligations and the establishment of the contract or other legal act governing the processing by a processor on behalf of the controller, the processor should also be subject to the general obligation of data protection by design and by default under Regulation (EU) 2016/679 to extent it relates to their own obligations under that Regulation. This obligation does not affect the level of responsibility and relationship between the controller and processor, nor does it affect the principle of accountability or the respective obligations of controller and processor as laid down under Article 28 of Regulation (EU) 2016/679). Accordingly, the controller remains solely responsible for determining the purpose and means of processing and for complying with related obligations, while the processor should ensure that data protection by design and by default is applied to its offered means and services to carry out processing.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Additional proposed wording Amendment 387 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
The collection of personal data from third parties, and their purchase, aggregation, enrichment, sale or making available to third parties for commercial purposes, have given rise to opaque chains in which the origin of the data, the legal basis for their initial collection and the validity of any consent obtained can no longer be established. Successive transfers dilute accountability to the point where no operator in the chain is in a position to demonstrate the lawfulness of the processing. The principle of accountability laid down in Article 5(2) of Regulation (EU) 2016/679 requires that a controller engaging in such activities verify and document the lawful origin of the data, and refrain from processing them where that lawfulness cannot be demonstrated. A general declaration of compliance or a standard contractual term supplied by the data provider cannot suffice. That verification, which forms part of the measures referred to in Article 24 of that Regulation, should be strengthened where the data originate from an undisclosed or indeterminate source, where they concern a large number of data subjects, or where they have been obtained through successive transfers. This is without prejudice to the processing of personal data which is strictly necessary for the prevention and detection of fraud, where the data are processed exclusively for that purpose.
Justification
Data brokerage is the blind spot of the Regulation: personal data circulate through chains in which no operator can any longer demonstrate lawful origin. This recital does not create a new obligation — it specifies what the existing accountability principle requires of those who trade in data, and underpins the record-keeping and penalty provisions introduced in the operative part.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Recital 39a
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Recital 39a
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Recital 39a
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded