Digital Omnibus tracker

Digital Omnibus proposal

Recital 44

Compare the available Commission, Council and Parliament texts and amendments affecting this recital.

Recital total: 1 part · 4 Council drafts · 45 Parliament amendments

Removed wording is struck through; added or replacement wording is highlighted.

Institutional text

European Commission proposal

The wording proposed by the Commission at the start of this legislative file.

Commission source wording and instructions

Recital 44

Commission proposal

The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person. The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679. With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf. For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life. Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.

Institutional text

Council Presidency texts

Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.

Recital 44

May Presidency compromise

The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. With a view to reducing the compliance burden and providing legal clarity, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by a subscriber or user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, the Directive should therefore provide that such processing is lawful, including when being carried out jointly with or on the behalf of a controller. For example, a media service provider, may mandate a third party, such as a market research company, to carry out such processing. Creating aggregated information about the usage of an online service to measure the audience of such a service where it is carried out by the controller of that online service solely for its own use, or by a processor acting jointly with or on behalf of this provider, also referred to as ‘audience measurement’, means processing to obtain insight into the performance and use of the online service in an instantly anonymised, aggregated and general manner. This includes the performance of audience measurement as defined in Regulation (EU) 2024/1083. The aggregated information should not relate to a specific data subject and should therefore be anonymous aggregated information. The data collected should not be further processed for another purpose, combined with data from other services from the provider of the online service or from a third party, such as analytics information from other websites or apps, or shared with third parties. Maintaining or restoring the security of a service provided by an information society service provider and requested by the subscriber or user, or the terminal equipment used for the provision of such service, should only be allowed without consent to the extent that the security updates are strictly necessary, proportionate, discretely packaged and do not in any way change the functionality of the software on the terminal equipment, including the interaction with other software or settings chosen by the subscriber or user, the subscriber or user is informed in advance each time an update is being installed, and the subscriber or user has the possibility to turn off the automatic installation of these updates. For the further processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the further processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.

Competing proposals

European Parliament amendments

These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.

More filters

Political group at the amendment date where available; otherwise the current Parliament affiliation.

Alternative wording Amendment 21 IMCO draft opinion · Alex Agius Saliba (rapporteur)
With a view to reducing the compliance burden and providing legal clarity to controllers and providers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service explicitly requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is strictly necessary and proportionate for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Source identification

Header printed in the source: Recital 44 – paragraph 3

Additional proposed wording Amendment 22 IMCO draft opinion · Alex Agius Saliba (rapporteur)

Providers wishing to process aggregated information should anonymise such information immediately. They may mandate a third party to carry out the processing, provided that the latter exclusively process the data solely for the use of the provider. No subsequent processing of information for other purposes than those defined in the limitative list should take place.

Source identification

Header printed in the source: Recital 44 – paragraph 3 a (new)

Alternative wording Amendment 176 · David Cormand on behalf of the Verts/ALE Group IMCO
The introduction of Article 88a in the GDPR should continue to offer the highest levels of protection, in particular consumer protection and privacy, while simplifying the experiences of consumers in exerting their rights and expressing their choices online. This article should be seen as strengthening Article 5 of Directive 2002/58/EC on privacy and electronic communications (‘ePrivacy Directive’), last revised in 2009, by providing specific rules in relation to processing of personal data in the context of electronic communication services. The amendments concern in particular access to and storage of personal data in the terminal equipment, accessing or otherwise collecting personal data from that equipment through cookies or similar technologies to gain information from the terminal equipment. As this access and storage constitute by itself an interference with the private sphere of a consumers as protected by Article 7 and 8 of the Charter of Fundamental Rights, it begs the question whether the information qualifies as personal data. The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment andshould therefore continue to be allowed only on the subsequent processingbasis of suchconsent data shouldand be regulatedsubject underto clear rules able to guarantee a singlehigh legallevel framework,of namelyprotection Regulationof (EU)consumers 2016/679,while wheresafeguarding the subscriberfunctioning of the electronicinternal communicationsmarket. serviceRules orgoverning the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storagestoring of information in thatterminal equipment, accessingand oraccess otherwiseto collectingsuch information from that equipment that entailsprotect the processingconfidentiality of communications and the integrity of user devices. These protections apply independently of whether the information accessed constitutes personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should alsoand apply regardless of whether the terminalinformation equipmentaccessed constitutes personal data. With a view of providing legal clarity it is ownednecessary byto define a limitative list of purposes, strictly defined and necessary, for which the naturalprocessing personshould be permitted without consent. These exemptions should be interpreted strictly. Non-personalised advertising is a form of advertising that provides the highest level of consumer protection as it minimizes the collection of consumer data while still ensuring the provision of advertising on the internal market and the establishment of new businesses models in this sector. In the context of Article 88a (3) (d) (a) (new) it shall not involve the retention, storage, reuse or bylinking anotherof legalany data generated in connection with such interaction, nor the processing, inference or naturaluse personof any data relating to the consumer’s location whether precise or approximate, including where such location data is derived, inferred or processed in aggregated anonymized form. Contextual advertising as defined in Article 4 (b) (xx) and in the context of Article 88a (3) (d) (a) (new) shall not involve the retention, storage, reuse or linking of any data generated in connection with such interaction, nor the processing, inference or use of any data relating to the consumer’s location whether precise or approximate, including where such location data is derived, inferred or processed in aggregated anonymized form. If a controller invokes the exception of Article 88a (3) (d) (a) (new) , the controller will not be able to engage in any other advertising activities other than contextual advertising as defined in Article (4) (b) (xx), including, but not limited, personalised and targeted advertising activities as defined in the EDPB Guidelines 8/2020 on the targeting of social media use.
Source identification

Header printed in the source: Recital 44 – paragraph 1

Remove proposed wording Amendment 177 · David Cormand on behalf of the Verts/ALE Group IMCO
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Source identification

Header printed in the source: Recital 44 – paragraph 2

Deletion marker printed in the source: deleted

Alternative wording Amendment 178 · Sophia Kircher IMCO
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Source identification

Header printed in the source: Recital 44 – paragraph 2

Alternative wording Amendment 179 · David Cormand on behalf of the Verts/ALE Group IMCO
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service explicitly requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is strictly necessary and proportionate for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf. Controllers wishing to collect aggregated information of consumers should anonymise such information instantly and may mandate a processor to carry out the processing, provided that the processor will exclusively process the data for the use of the controller. No subsequent processing of personal data for other purposes than those defined in the limitative list should take place.
Source identification

Header printed in the source: Recital 44 – paragraph 3

Alternative wording Amendment 180 · Sabine Verheyen IMCO
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor or joint controller, such as a market research company and Joint Industry Controller, to carry out the processing jointly or on its behalf.
Source identification

Header printed in the source: Recital 44 – paragraph 3

Alternative wording Amendment 181 · Christian Doleschal IMCO
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor or joint controller, such as a market research company and Joint Industry Committee, to carry out the processing on its behalf.
Source identification

Header printed in the source: Recital 44 – paragraph 3

Remove proposed wording Amendment 420 · Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec ITRE · LIBE
[...]
Justification

Replaced with recitals 43a-43r tabled as amendments.

Source identification

Header printed in the source: Recital 44

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 421 · João Oliveira ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Source identification

Header printed in the source: Recital 44 – paragraph 1

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 422 · Pernando Barrena Arza, João Oliveira ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Source identification

Header printed in the source: Recital 44 – paragraph 1

Deletion marker printed in the source: deleted

Alternative wording Amendment 423 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookiestrackers, identifiers or similar technologies located on, or interacting with, terminal equipment, including but not limited to cookies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person. These rules are without prejudice to Directive 2002/58/EC, which continues to apply in full, and in particular to the confidentiality of communications and of the related traffic data, the protection of traffic and location data, the safeguards against unsolicited communications, and the possibility for Member States to adopt restrictive measures, as provided for in Articles 5, 6, 9, 13 and 15(1) of that Directive.
Source identification

Header printed in the source: Recital 44 – paragraph 1

Alternative wording Amendment 424 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
The storing of personal datainformation, or the gaining of access to personal datainformation already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely RegulationDirective (EU) 20162002/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person58/EC. The amendments presented in this Regulation should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Source identification

Header printed in the source: Recital 44 – paragraph 1

Alternative wording Amendment 425 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
The amendments presented in this Regulation regarding the storing of personal data,information or the gaining of access to personal datainformation already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails inter alia the processing of personal data or other information through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Source identification

Header printed in the source: Recital 44 – paragraph 1

Alternative wording Amendment 426 · Diana Iovanovici Şoşoacă ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online, but they should include potential penalties to be applied in the event of an information leak involving personal data or access by persons who are not authorised to access this personal information and data. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Source identification

Header printed in the source: Recital 44 – paragraph 1

Alternative wording Amendment 427 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and theany subsequent processing constitutes a highly intrusive interference with the fundamental rights to confidentiality of suchcommunications dataand device integrity, and should be regulatedtherefore undersubject ato singlestrict legal framework, namely Regulation (EU) 2016/679protections, where the subscriber of the electronic communications service or the user of the terminal equipment is a naturaldata personsubject. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the naturaldata personsubject or by another legal or natural person.
Source identification

Header printed in the source: Recital 44 – paragraph 1

Alternative wording Amendment 428 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
The storing of personal datainformation, or the gaining of access to personal datainformation already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Source identification

Header printed in the source: Recital 44 – paragraph 2

Alternative wording Amendment 429 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
The storing of personalinformation dataon, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal datainformation already stored, in the terminal equipment of a natural person, whenin thatparticular isthrough basedcookies and similar technologies, should continue to be governed by Directive 2002/58/EC. In order to ensure legal certainty, avoid fragmentation and reduce unnecessary compliance burdens on Unionbusinesses, a single and coherent regulatory framework should apply to all such practices, irrespective of whether they involve personal or Membernon-personal Statedata. lawA withindifferentiated theregime meaningunder ofwhich Articleonly 6cookies ofinvolving personal data would be subject to Regulation (EU) 2016/679 while others remain under Directive 2002/58/EC would create legal complexity and ifincrease itcosts fulfilsfor allundertakings, conditionsin particular small and medium-sized enterprises, without providing additional protection to data subjects. Therefore, the rules on the storing of lawfulnessinformation laidand downgaining of access to information stored in thatterminal provision,equipment andshould isremain doneunified forwithin the objectives laid down in Article 23(1)framework of RegulationDirective (EU) 20162002/67958/EC.
Source identification

Header printed in the source: Recital 44 – paragraph 2

Alternative wording Amendment 430 · Ana Vasconcelos, João Cotrim De Figueiredo ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679, provided that any such measure is necessary and proportionate and does not require the general identification of users, nor the weakening of anonymity, encryption or other protective tools on which users, including journalists, activists and other persons at risk, rely.
Source identification

Header printed in the source: Recital 44 – paragraph 2

Alternative wording Amendment 431 · Pernando Barrena Arza, João Oliveira ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, thisThis requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, whenunder that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils allcertain conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Source identification

Header printed in the source: Recital 44 – paragraph 2

Alternative wording Amendment 432 · Diana Iovanovici Şoşoacă ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679. At the same time, it is important to include potential penalties to be applied in the event of an information leak involving personal data or access by persons who are not authorised to access this personal information and data.
Source identification

Header printed in the source: Recital 44 – paragraph 2

Alternative wording Amendment 433 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a naturaldata personsubject, when that is based on Union or Member State law within the meaning of, and subject to the conditions of, Article 6 (3) of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Source identification

Header printed in the source: Recital 44 – paragraph 2

Alternative wording Amendment 434 · Alex Agius Saliba ITRE · LIBE
The storing of personal datainformation, or the gaining of access to personal datainformation already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement under Regulation (EU) 2016/679 should not preclude storing of personal data, or gaining of access to personal data already stored, in thea terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6(3) of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Source identification

Header printed in the source: Recital 44 – paragraph 2

Alternative wording Amendment 435 · Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Angelika Niebler, Andrea Wechsler, Oliver Schenk, Christian Ehler ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Source identification

Header printed in the source: Recital 44 – paragraph 2

Remove proposed wording Amendment 436 · João Oliveira ITRE · LIBE
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Source identification

Header printed in the source: Recital 44 – paragraph 3

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 437 · Pernando Barrena Arza, João Oliveira ITRE · LIBE
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Source identification

Header printed in the source: Recital 44 – paragraph 3

Deletion marker printed in the source: deleted

Alternative wording Amendment 438 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
With a view to increase innovation and competitiveness, reducing the compliance burden and providing legal clarity to controllersall stakeholders, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide, among other things, a safe and functional service requested by the datasubscriber subjector user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal datainformation, or the gaining of access to personal datainformation already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf. Such exceptions should cover the transmission of electronic communications, the provision of a service explicitly requested by the user including its functionality and personalisation, audience measurement limited to aggregated data without repurposing for profiling or advertising, and joint audience measurement involving media service providers or their mandated entities. Exceptions should further include measures strictly necessary to ensure the security of the service or network and to prevent fraud directly related to the requested service, as well as the provision, display and measurement of contextual advertising based solely on the content immediately presented to the user, without any profiling. In recognition of the important role played by media service providers and the low privacy risk associated with their typical processing activities, specific provisions should also allow them to offer users a clear choice between consenting to the processing of personal data for purposes such as advertising, service improvement, product development and analytics, or paying a reasonable fee for an equivalent version of the service without such processing. In all cases, these exceptions are designed to strike an appropriate balance between the protection of users’ rights, the sustainability of media pluralism, and the need to foster innovation and competitiveness in the digital single market.
Source identification

Header printed in the source: Recital 44 – paragraph 3

Alternative wording Amendment 439 · Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Juan Ignacio Zoido Álvarez, Angelika Niebler, Andrea Wechsler, Oliver Schenk, Pekka Toveri, Christian Ehler ITRE · LIBE
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. This list should include measuring the audience of an online service by creating aggregated information about the usage of an online service, where it is carried out by the provider of that online service, or by a third party, such as a market research company or a Joint Industry Committee, acting together with or on behalf of this provider. ‘Audience measurement’ should be understood in accordance with Article 2(16) and with Article 24(1) of Regulation (EU) 2024/1083. Gatekeepers designated under Regulation (EU) 2022/1925 carrying out audience measurement may not rely on article 88a(3)c of this Regulation. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Source identification

Header printed in the source: Recital 44 – paragraph 3

Alternative wording Amendment 440 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is strictly necessary for those specific purposes, this Regulation should therefore provide that the processing is lawful. TheThese narrow exceptions should strictly apply to technical communications transmission, the execution of explicit services requested by the data subject, necessary security operations, or audience measurement metrics for media service providers, or third-party providers of audience measurement for media services providers, provided it follows conditions for low processing risks, namely for statistical counting and is not utilised for profiling of data subject and does not involve core platfroms services as defined in Regulation (EU) 2022/1925. Following these conditions, the controller, such as a media service provider, may therefore mandate a processor, such as a market research company, to carry out the processing on its behalf.
Source identification

Header printed in the source: Recital 44 – paragraph 3

Alternative wording Amendment 441 · Wouter Beke ITRE · LIBE
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as an online service or a media service provider, may mandate a processor or joint controller, such as a market research company or Joint Industry Committee, to carry out the processing jointly or on its behalf, subject to strict safeguards ensuring that such processing is proportionate, compliant with the requirements of Article 24(1) of Regulation (EU) 2024/1083 and is not repurposed for advertising, profiling, or other unrelated purposes.
Justification

This amendment ensures consistency with Article 5.3(c) of Regulation (EU) 2016/679 by clarifying that audience measurement may be conducted by mandated joint controllers, including Joint Industry Committees and research companies. It aligns the recital with the EMFA framework, strengthening legal certainty, independent measurement and safeguards against profiling or advertising purposes.

Source identification

Header printed in the source: Recital 44 – paragraph 3

Alternative wording Amendment 442 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processingstoring poseor gaining access to the information on the terminal equipment of a natural person poses a low risk to the rights and freedoms of data subjects or that such processingit may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. AsThis regardslimited storinglist of personallow datarisk operations includes audience measurement, especially in the case of media providers, and the restoration or the gainingmaintenance of accessthe tosecurity personalof data already stored, in athe terminal equipment, and subsequent processingprovided that service providers fulfill certain conditions. In the case of audience measurement, the data should be instantly anonymised and aggregated. The user’s personal data could, for instance, be retained for a short time session. At the end of the session, the data would be aggregated in such a way that it does not constitute personal data and remaining personal data from the session is deleted or anonymised. The user should still be informed about the storing or gaining access. All of these operations should always be strictly technically and solely necessary for those purposes, this Regulation should therefore provide that the processing is lawfulpurpose. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Source identification

Header printed in the source: Recital 44 – paragraph 3

Alternative wording Amendment 443 · Ana Vasconcelos, João Cotrim De Figueiredo ITRE · LIBE
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. Those purposes should be interpreted narrowly and should not serve as a basis for tracking, profiling or the large-scale monitoring of the online activity of data subjects. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Source identification

Header printed in the source: Recital 44 – paragraph 3

Remove proposed wording Amendment 444 · João Oliveira ITRE · LIBE
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Source identification

Header printed in the source: Recital 44 – paragraph 4

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 445 · Pernando Barrena Arza, João Oliveira ITRE · LIBE
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Source identification

Header printed in the source: Recital 44 – paragraph 4

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 446 · Alex Agius Saliba ITRE · LIBE
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Source identification

Header printed in the source: Recital 44 – paragraph 4

Deletion marker printed in the source: deleted

Alternative wording Amendment 447 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Source identification

Header printed in the source: Recital 44 – paragraph 4

Alternative wording Amendment 448 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
For the subsequent processing of personal data for other purpose than those defined in the limitative list, such as development and operating of artificial intelligence models, controllers may seek to rely on legitimate interest under Article 6 and(1), wherepoint relevant,(f) while Article 9 of Regulation (EU) 2016/679 should nevertheless be applied. However, to ensure that such processing does not override the fundamental rights and freedoms of data subjects, controllers must implement mandatory checklist of technical and organisational standards. These must include providing data subjects with an absolute right to object after being fully informed, ensuring state-of-the-art technics for data anonymisation, the executing rigorous technical abstration during the model training phase to make data disclosure extremely unlikely. To reduce individual administrative burdens, Member States should enable data subjects to administer their absolute right to object through a centralised public body. To ease complience and ensure uniformed approach, minimum standards for these techniques should be technically defined through standardisation. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmostutmost account of the following elements: whether the data subject is a child; the reasonable expectations of the data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Source identification

Header printed in the source: Recital 44 – paragraph 4

Alternative wording Amendment 449 · Diana Iovanovici Şoşoacă ITRE · LIBE
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life, and there should also be potential penalties in the event of information misuse or leaks involving personal data or access by persons who are not authorised to access this personal information and data.
Source identification

Header printed in the source: Recital 44 – paragraph 4

Alternative wording Amendment 450 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements:; whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life. Sensitive categories of personal data shoud only be processed in accordance with Article 9 of Regulation 2016/679, unless otherwise provided for in this regulation.
Source identification

Header printed in the source: Recital 44 – paragraph 4

Alternative wording Amendment 451 · Ana Vasconcelos, João Cotrim De Figueiredo ITRE · LIBE
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life. Where age assurance is necessary, it should rely on privacy-preserving and data-minimising techniques, and should not undermine the anonymity or confidentiality of communications.
Source identification

Header printed in the source: Recital 44 – paragraph 4

Remove proposed wording Amendment 452 · João Oliveira ITRE · LIBE
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
Source identification

Header printed in the source: Recital 44 – paragraph 5

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 453 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
Source identification

Header printed in the source: Recital 44 – paragraph 5

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 454 · Pernando Barrena Arza, João Oliveira ITRE · LIBE
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
Source identification

Header printed in the source: Recital 44 – paragraph 5

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 455 · Alex Agius Saliba ITRE · LIBE
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
Source identification

Header printed in the source: Recital 44 – paragraph 5

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 456 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
Source identification

Header printed in the source: Recital 44 – paragraph 5

Deletion marker printed in the source: deleted