Compare the available Commission, Council and Parliament texts and amendments affecting this recital.
Recital total: 1 part · 4 Council drafts · 45 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
The wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to this tracked part. A newly proposed provision may have no earlier text of its own.
Commission source wording and instructions
Recital 44
Commission proposal
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person. The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679. With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf. For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life. Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Recital 44
May Presidency compromise
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. With a view to reducing the compliance burden and providing legal clarity, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by a subscriber or user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, the Directive should therefore provide that such processing is lawful, including when being carried out jointly with or on the behalf of a controller. For example, a media service provider, may mandate a third party, such as a market research company, to carry out such processing. Creating aggregated information about the usage of an online service to measure the audience of such a service where it is carried out by the controller of that online service solely for its own use, or by a processor acting jointly with or on behalf of this provider, also referred to as ‘audience measurement’, means processing to obtain insight into the performance and use of the online service in an instantly anonymised, aggregated and general manner. This includes the performance of audience measurement as defined in Regulation (EU) 2024/1083. The aggregated information should not relate to a specific data subject and should therefore be anonymous aggregated information. The data collected should not be further processed for another purpose, combined with data from other services from the provider of the online service or from a third party, such as analytics information from other websites or apps, or shared with third parties. Maintaining or restoring the security of a service provided by an information society service provider and requested by the subscriber or user, or the terminal equipment used for the provision of such service, should only be allowed without consent to the extent that the security updates are strictly necessary, proportionate, discretely packaged and do not in any way change the functionality of the software on the terminal equipment, including the interaction with other software or settings chosen by the subscriber or user, the subscriber or user is informed in advance each time an update is being installed, and the subscriber or user has the possibility to turn off the automatic installation of these updates. For the further processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the further processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Recital 44
June Presidency compromise · 10 June
The storing of information, or the gaining of access to information already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Directive 2002/58/EC on privacy and electronic communications, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment.
Recital 44
June Presidency compromise · 18 June
The storing of information, or the gaining of access to information already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Directive 2002/58/EC on privacy and electronic communications , where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment.
Recital 44
September Presidency compromise
The storing of information, or the gaining of access to information already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Directive 2002/58/EC on privacy and electronic communications , where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment.
Recital 44 4 Council drafts
Recital 44
21 May 2026 · May Presidency compromise
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. With a view to reducing the compliance burden and providing legal clarity, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by a subscriber or user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, the Directive should therefore provide that such processing is lawful, including when being carried out jointly with or on the behalf of a controller. For example, a media service provider, may mandate a third party, such as a market research company, to carry out such processing. Creating aggregated information about the usage of an online service to measure the audience of such a service where it is carried out by the controller of that online service solely for its own use, or by a processor acting jointly with or on behalf of this provider, also referred to as ‘audience measurement’, means processing to obtain insight into the performance and use of the online service in an instantly anonymised, aggregated and general manner. This includes the performance of audience measurement as defined in Regulation (EU) 2024/1083. The aggregated information should not relate to a specific data subject and should therefore be anonymous aggregated information. The data collected should not be further processed for another purpose, combined with data from other services from the provider of the online service or from a third party, such as analytics information from other websites or apps, or shared with third parties. Maintaining or restoring the security of a service provided by an information society service provider and requested by the subscriber or user, or the terminal equipment used for the provision of such service, should only be allowed without consent to the extent that the security updates are strictly necessary, proportionate, discretely packaged and do not in any way change the functionality of the software on the terminal equipment, including the interaction with other software or settings chosen by the subscriber or user, the subscriber or user is informed in advance each time an update is being installed, and the subscriber or user has the possibility to turn off the automatic installation of these updates. For the further processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the further processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Recital 44
10 June 2026 · June Presidency compromise · 10 June
The storing of information, or the gaining of access to information already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Directive 2002/58/EC on privacy and electronic communications, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment.
Recital 44
18 June 2026 · June Presidency compromise · 18 June
The storing of information, or the gaining of access to information already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Directive 2002/58/EC on privacy and electronic communications , where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment.
Recital 44
3 September 2026 · September Presidency compromise
The storing of information, or the gaining of access to information already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Directive 2002/58/EC on privacy and electronic communications , where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Political group at the amendment date where available; otherwise the current Parliament affiliation.
Alternative wordingAmendment 21 IMCO draft opinion · Alex Agius Saliba (rapporteur)
With a view to reducing the compliance burden and providing legal clarity to controllers and providers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service explicitly requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is strictly necessary and proportionate for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Providers wishing to process aggregated information should anonymise such information immediately. They may mandate a third party to carry out the processing, provided that the latter exclusively process the data solely for the use of the provider. No subsequent processing of information for other purposes than those defined in the limitative list should take place.
Alternative wordingAmendment 176 · David Cormand on behalf of the Verts/ALE Group IMCO
The introduction of Article 88a in the GDPR should continue to offer the highest levels of protection, in particular consumer protection and privacy, while simplifying the experiences of consumers in exerting their rights and expressing their choices online. This article should be seen as strengthening Article 5 of Directive 2002/58/EC on privacy and electronic communications (‘ePrivacy Directive’), last revised in 2009, by providing specific rules in relation to processing of personal data in the context of electronic communication services. The amendments concern in particular access to and storage of personal data in the terminal equipment, accessing or otherwise collecting personal data from that equipment through cookies or similar technologies to gain information from the terminal equipment. As this access and storage constitute by itself an interference with the private sphere of a consumers as protected by Article 7 and 8 of the Charter of Fundamental Rights, it begs the question whether the information qualifies as personal data. The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment andshould therefore continue to be allowed only on the subsequent processingbasis of suchconsentdata shouldand be regulatedsubjectunderto clear rules able to guarantee a singlehighlegallevelframework,ofnamelyprotectionRegulationof(EU)consumers2016/679,whilewheresafeguarding the subscriberfunctioning of the electronicinternalcommunicationsmarket.serviceRulesorgoverning the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storagestoring of information in thatterminal equipment,accessingandoraccessotherwisetocollectingsuch information from that equipment that entailsprotect the processingconfidentiality of communications and the integrity of user devices. These protections apply independently of whether the information accessed constitutes personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should alsoand apply regardless of whether the terminalinformationequipmentaccessed constitutes personal data. With a view of providing legal clarity it is ownednecessarybyto define a limitative list of purposes, strictly defined and necessary, for which the naturalprocessingpersonshould be permitted without consent. These exemptions should be interpreted strictly.
Non-personalised advertising is a form of advertising that provides the highest level of consumer protection as it minimizes the collection of consumer data while still ensuring the provision of advertising on the internal market and the establishment of new businesses models in this sector. In the context of Article 88a (3) (d) (a) (new) it shall not involve the retention, storage, reuse or bylinkinganotheroflegalany data generated in connection with such interaction, nor the processing, inference or naturalusepersonof any data relating to the consumer’s location whether precise or approximate, including where such location data is derived, inferred or processed in aggregated anonymized form. Contextual advertising as defined in Article 4 (b) (xx) and in the context of Article 88a (3) (d) (a) (new) shall not involve the retention, storage, reuse or linking of any data generated in connection with such interaction, nor the processing, inference or use of any data relating to the consumer’s location whether precise or approximate, including where such location data is derived, inferred or processed in aggregated anonymized form. If a controller invokes the exception of Article 88a (3) (d) (a) (new) , the controller will not be able to engage in any other advertising activities other than contextual advertising as defined in Article (4) (b) (xx), including, but not limited, personalised and targeted advertising activities as defined in the EDPB Guidelines 8/2020 on the targeting of social media use.
Remove proposed wordingAmendment 177 · David Cormand on behalf of the Verts/ALE Group IMCO
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Alternative wordingAmendment 178 · Sophia Kircher IMCO
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Alternative wordingAmendment 179 · David Cormand on behalf of the Verts/ALE Group IMCO
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service explicitly requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is strictly necessary and proportionate for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf. Controllers wishing to collect aggregated information of consumers should anonymise such information instantly and may mandate a processor to carry out the processing, provided that the processor will exclusively process the data for the use of the controller. No subsequent processing of personal data for other purposes than those defined in the limitative list should take place.
Alternative wordingAmendment 180 · Sabine Verheyen IMCO
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor or joint controller, such as a market research company and Joint Industry Controller, to carry out the processing jointly or on its behalf.
Alternative wordingAmendment 181 · Christian Doleschal IMCO
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor or joint controller, such as a market research company and Joint Industry Committee, to carry out the processing on its behalf.
Remove proposed wordingAmendment 420 · Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Alternative wordingAmendment 423 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookiestrackers, identifiers or similar technologies located on, or interacting with, terminal equipment, including but not limited to cookies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person. These rules are without prejudice to Directive 2002/58/EC, which continues to apply in full, and in particular to the confidentiality of communications and of the related traffic data, the protection of traffic and location data, the safeguards against unsolicited communications, and the possibility for Member States to adopt restrictive measures, as provided for in Articles 5, 6, 9, 13 and 15(1) of that Directive.
Alternative wordingAmendment 424 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
The storing of personal datainformation, or the gaining of access to personal datainformation already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely RegulationDirective(EU) 20162002/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person58/EC. The amendments presented in this Regulation should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Alternative wordingAmendment 425 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
The amendments presented in this Regulation regarding the storing of personal data,information or the gaining of access to personal datainformation already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails inter alia the processing of personal data or other information through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Alternative wordingAmendment 426 · Diana Iovanovici Şoşoacă ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online, but they should include potential penalties to be applied in the event of an information leak involving personal data or access by persons who are not authorised to access this personal information and data. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Alternative wordingAmendment 427 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and theany subsequent processing constitutes a highly intrusive interference with the fundamental rights to confidentiality of suchcommunicationsdataand device integrity, and should be regulatedthereforeundersubjectatosinglestrictlegal framework, namely Regulation (EU) 2016/679protections, where the subscriber of the electronic communications service or the user of the terminal equipment is a naturaldatapersonsubject. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the naturaldatapersonsubject or by another legal or natural person.
Alternative wordingAmendment 428 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
The storing of personal datainformation, or the gaining of access to personal datainformation already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Alternative wordingAmendment 429 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
The storing of personalinformationdataon, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal datainformation already stored, in the terminal equipment of a natural person, wheninthatparticularisthroughbasedcookies and similar technologies, should continue to be governed by Directive 2002/58/EC. In order to ensure legal certainty, avoid fragmentation and reduce unnecessary compliance burdens on Unionbusinesses, a single and coherent regulatory framework should apply to all such practices, irrespective of whether they involve personal or Membernon-personalStatedata.lawAwithindifferentiatedtheregimemeaningunderofwhichArticleonly6cookiesofinvolving personal data would be subject to Regulation (EU) 2016/679 while others remain under Directive 2002/58/EC would create legal complexity and ifincreaseitcostsfulfilsforallundertakings,conditionsin particular small and medium-sized enterprises, without providing additional protection to data subjects. Therefore, the rules on the storing of lawfulnessinformationlaidanddowngaining of access to information stored in thatterminalprovision,equipmentandshouldisremaindoneunifiedforwithin the objectives laid down in Article 23(1)framework of RegulationDirective(EU) 20162002/67958/EC.
Alternative wordingAmendment 430 · Ana Vasconcelos, João Cotrim De Figueiredo ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679, provided that any such measure is necessary and proportionate and does not require the general identification of users, nor the weakening of anonymity, encryption or other protective tools on which users, including journalists, activists and other persons at risk, rely.
Alternative wordingAmendment 431 · Pernando Barrena Arza, João Oliveira ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, thisThis requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, whenunderthat is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils allcertain conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Alternative wordingAmendment 432 · Diana Iovanovici Şoşoacă ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679. At the same time, it is important to include potential penalties to be applied in the event of an information leak involving personal data or access by persons who are not authorised to access this personal information and data.
Alternative wordingAmendment 433 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a naturaldatapersonsubject, when that is based on Union or Member State law within the meaning of, and subject to the conditions of, Article 6 (3) of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Alternative wordingAmendment 434 · Alex Agius Saliba ITRE · LIBE
The storing of personal datainformation, or the gaining of access to personal datainformation already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement under Regulation (EU) 2016/679 should not preclude storing of personal data, or gaining of access to personal data already stored, in thea terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6(3) of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Alternative wordingAmendment 435 · Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Angelika Niebler, Andrea Wechsler, Oliver Schenk, Christian Ehler ITRE · LIBE
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Remove proposed wordingAmendment 436 · João Oliveira ITRE · LIBE
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Alternative wordingAmendment 438 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
With a view to increase innovation and competitiveness, reducing the compliance burden and providing legal clarity to controllersall stakeholders, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide, among other things, a safe and functional service requested by the datasubscribersubjector user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal datainformation, or the gaining of access to personal datainformation already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf. Such exceptions should cover the transmission of electronic communications, the provision of a service explicitly requested by the user including its functionality and personalisation, audience measurement limited to aggregated data without repurposing for profiling or advertising, and joint audience measurement involving media service providers or their mandated entities. Exceptions should further include measures strictly necessary to ensure the security of the service or network and to prevent fraud directly related to the requested service, as well as the provision, display and measurement of contextual advertising based solely on the content immediately presented to the user, without any profiling. In recognition of the important role played by media service providers and the low privacy risk associated with their typical processing activities, specific provisions should also allow them to offer users a clear choice between consenting to the processing of personal data for purposes such as advertising, service improvement, product development and analytics, or paying a reasonable fee for an equivalent version of the service without such processing. In all cases, these exceptions are designed to strike an appropriate balance between the protection of users’ rights, the sustainability of media pluralism, and the need to foster innovation and competitiveness in the digital single market.
Alternative wordingAmendment 439 · Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Juan Ignacio Zoido Álvarez, Angelika Niebler, Andrea Wechsler, Oliver Schenk, Pekka Toveri, Christian Ehler ITRE · LIBE
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. This list should include measuring the audience of an online service by creating aggregated information about the usage of an online service, where it is carried out by the provider of that online service, or by a third party, such as a market research company or a Joint Industry Committee, acting together with or on behalf of this provider. ‘Audience measurement’ should be understood in accordance with Article 2(16) and with Article 24(1) of Regulation (EU) 2024/1083. Gatekeepers designated under Regulation (EU) 2022/1925 carrying out audience measurement may not rely on article 88a(3)c of this Regulation. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Alternative wordingAmendment 440 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is strictly necessary for those specific purposes, this Regulation should therefore provide that the processing is lawful. TheThese narrow exceptions should strictly apply to technical communications transmission, the execution of explicit services requested by the data subject, necessary security operations, or audience measurement metrics for media service providers, or third-party providers of audience measurement for media services providers, provided it follows conditions for low processing risks, namely for statistical counting and is not utilised for profiling of data subject and does not involve core platfroms services as defined in Regulation (EU) 2022/1925. Following these conditions, the controller, such as a media service provider, may therefore mandate a processor, such as a market research company, to carry out the processing on its behalf.
Alternative wordingAmendment 441 · Wouter Beke ITRE · LIBE
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as an online service or a media service provider, may mandate a processor or joint controller, such as a market research company or Joint Industry Committee, to carry out the processing jointly or on its behalf, subject to strict safeguards ensuring that such processing is proportionate, compliant with the requirements of Article 24(1) of Regulation (EU) 2024/1083 and is not repurposed for advertising, profiling, or other unrelated purposes.
Justification
This amendment ensures consistency with Article 5.3(c) of Regulation (EU) 2016/679 by clarifying that audience measurement may be conducted by mandated joint controllers, including Joint Industry Committees and research companies. It aligns the recital with the EMFA framework, strengthening legal certainty, independent measurement and safeguards against profiling or advertising purposes.
Alternative wordingAmendment 442 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processingstoringposeor gaining access to the information on the terminal equipment of a natural person poses a low risk to the rights and freedoms of data subjects or that such processingit may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. AsThisregardslimitedstoringlist of personallowdatarisk operations includes audience measurement, especially in the case of media providers, and the restoration or the gainingmaintenance of accessthetosecuritypersonalofdata already stored, in athe terminal equipment, and subsequent processingprovided that service providers fulfill certain conditions. In the case of audience measurement, the data should be instantly anonymised and aggregated. The user’s personal data could, for instance, be retained for a short time session. At the end of the session, the data would be aggregated in such a way that it does not constitute personal data and remaining personal data from the session is deleted or anonymised. The user should still be informed about the storing or gaining access. All of these operations should always be strictly technically and solely necessary for those purposes, this Regulation should therefore provide that the processing is lawfulpurpose. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Alternative wordingAmendment 443 · Ana Vasconcelos, João Cotrim De Figueiredo ITRE · LIBE
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. Those purposes should be interpreted narrowly and should not serve as a basis for tracking, profiling or the large-scale monitoring of the online activity of data subjects. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Remove proposed wordingAmendment 444 · João Oliveira ITRE · LIBE
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Alternative wordingAmendment 447 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Alternative wordingAmendment 448 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
For the subsequent processing of personal data for other purpose than those defined in the limitative list, such as development and operating of artificial intelligence models, controllers may seek to rely on legitimate interest under Article 6 and(1), wherepointrelevant,(f) while Article 9 of Regulation (EU) 2016/679 should nevertheless be applied. However, to ensure that such processing does not override the fundamental rights and freedoms of data subjects, controllers must implement mandatory checklist of technical and organisational standards. These must include providing data subjects with an absolute right to object after being fully informed, ensuring state-of-the-art technics for data anonymisation, the executing rigorous technical abstration during the model training phase to make data disclosure extremely unlikely. To reduce individual administrative burdens, Member States should enable data subjects to administer their absolute right to object through a centralised public body. To ease complience and ensure uniformed approach, minimum standards for these techniques should be technically defined through standardisation. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmostutmost account of the following elements: whether the data subject is a child; the reasonable expectations of the data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Alternative wordingAmendment 449 · Diana Iovanovici Şoşoacă ITRE · LIBE
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life, and there should also be potential penalties in the event of information misuse or leaks involving personal data or access by persons who are not authorised to access this personal information and data.
Alternative wordingAmendment 450 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements:; whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life. Sensitive categories of personal data shoud only be processed in accordance with Article 9 of Regulation 2016/679, unless otherwise provided for in this regulation.
Alternative wordingAmendment 451 · Ana Vasconcelos, João Cotrim De Figueiredo ITRE · LIBE
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life. Where age assurance is necessary, it should rely on privacy-preserving and data-minimising techniques, and should not undermine the anonymity or confidentiality of communications.
Remove proposed wordingAmendment 452 · João Oliveira ITRE · LIBE
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
Remove proposed wordingAmendment 453 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
Remove proposed wordingAmendment 456 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Recital 44
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented into this RegulationDirective should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person. The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679. With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by theadatasubscribersubjector user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, thistheRegulationDirective should therefore provide that thesuch processing is lawful, including when being carried out jointly with or on the behalf of a controller. TheForcontrollerexample, such as a media service provider, may mandate a processorthird party, such as a market research company, to carry out such processing. Creating aggregated information about the usage of an online service to measure the audience of such a service where it is carried out by the controller of that online service solely for its own use, or by a processor acting jointly with or on behalf of this provider, also referred to as ‘audience measurement’, means processing to obtain insight into the performance and use of the online service in an instantly anonymised, aggregated and general manner. This includes the performance of audience measurement as defined in Regulation (EU) 2024/1083. The aggregated information should not relate to a specific data subject and should therefore be anonymous aggregated information. The data collected should not be further processed for another purpose, combined with data from other services from the provider of the online service or from a third party, such as analytics information from other websites or apps, or shared with third parties. Maintaining or restoring the security of a service provided by an information society service provider and requested by the subscriber or user, or the terminal equipment used for the provision of such service, should only be allowed without consent to the extent that the security updates are strictly necessary, proportionate, discretely packaged and do not in any way change the functionality of the software on itsthebehalfterminal equipment, including the interaction with other software or settings chosen by the subscriber or user, the subscriber or user is informed in advance each time an update is being installed, and the subscriber or user has the possibility to turn off the automatic installation of these updates. For the subsequentfurther processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequentfurther processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life. Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
RemovedAdded
Both texts in full
European Commission proposal
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person. The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679. With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf. For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life. Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
Council Presidency text · ST 9547/26
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. With a view to reducing the compliance burden and providing legal clarity, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by a subscriber or user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, the Directive should therefore provide that such processing is lawful, including when being carried out jointly with or on the behalf of a controller. For example, a media service provider, may mandate a third party, such as a market research company, to carry out such processing. Creating aggregated information about the usage of an online service to measure the audience of such a service where it is carried out by the controller of that online service solely for its own use, or by a processor acting jointly with or on behalf of this provider, also referred to as ‘audience measurement’, means processing to obtain insight into the performance and use of the online service in an instantly anonymised, aggregated and general manner. This includes the performance of audience measurement as defined in Regulation (EU) 2024/1083. The aggregated information should not relate to a specific data subject and should therefore be anonymous aggregated information. The data collected should not be further processed for another purpose, combined with data from other services from the provider of the online service or from a third party, such as analytics information from other websites or apps, or shared with third parties. Maintaining or restoring the security of a service provided by an information society service provider and requested by the subscriber or user, or the terminal equipment used for the provision of such service, should only be allowed without consent to the extent that the security updates are strictly necessary, proportionate, discretely packaged and do not in any way change the functionality of the software on the terminal equipment, including the interaction with other software or settings chosen by the subscriber or user, the subscriber or user is informed in advance each time an update is being installed, and the subscriber or user has the possibility to turn off the automatic installation of these updates. For the further processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the further processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Recital 44
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
The storing of personal datainformation, or the gaining of access to personal datainformation already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely RegulationDirective(EU)2002/58/EC2016/679on privacy and electronic communications, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. With a view to reducing the compliance burden and providing legal clarity, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by a subscriber or user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, the Directive should therefore provide that such processing is lawful, including when being carried out jointly with or on the behalf of a controller. For example, a media service provider, may mandate a third party, such as a market research company, to carry out such processing. Creating aggregated information about the usage of an online service to measure the audience of such a service where it is carried out by the controller of that online service solely for its own use, or by a processor acting jointly with or on behalf of this provider, also referred to as ‘audience measurement’, means processing to obtain insight into the performance and use of the online service in an instantly anonymised, aggregated and general manner. This includes the performance of audience measurement as defined in Regulation (EU) 2024/1083. The aggregated information should not relate to a specific data subject and should therefore be anonymous aggregated information. The data collected should not be further processed for another purpose, combined with data from other services from the provider of the online service or from a third party, such as analytics information from other websites or apps, or shared with third parties. Maintaining or restoring the security of a service provided by an information society service provider and requested by the subscriber or user, or the terminal equipment used for the provision of such service, should only be allowed without consent to the extent that the security updates are strictly necessary, proportionate, discretely packaged and do not in any way change the functionality of the software on the terminal equipment, including the interaction with other software or settings chosen by the subscriber or user, the subscriber or user is informed in advance each time an update is being installed, and the subscriber or user has the possibility to turn off the automatic installation of these updates. For the further processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the further processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. With a view to reducing the compliance burden and providing legal clarity, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by a subscriber or user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, the Directive should therefore provide that such processing is lawful, including when being carried out jointly with or on the behalf of a controller. For example, a media service provider, may mandate a third party, such as a market research company, to carry out such processing. Creating aggregated information about the usage of an online service to measure the audience of such a service where it is carried out by the controller of that online service solely for its own use, or by a processor acting jointly with or on behalf of this provider, also referred to as ‘audience measurement’, means processing to obtain insight into the performance and use of the online service in an instantly anonymised, aggregated and general manner. This includes the performance of audience measurement as defined in Regulation (EU) 2024/1083. The aggregated information should not relate to a specific data subject and should therefore be anonymous aggregated information. The data collected should not be further processed for another purpose, combined with data from other services from the provider of the online service or from a third party, such as analytics information from other websites or apps, or shared with third parties. Maintaining or restoring the security of a service provided by an information society service provider and requested by the subscriber or user, or the terminal equipment used for the provision of such service, should only be allowed without consent to the extent that the security updates are strictly necessary, proportionate, discretely packaged and do not in any way change the functionality of the software on the terminal equipment, including the interaction with other software or settings chosen by the subscriber or user, the subscriber or user is informed in advance each time an update is being installed, and the subscriber or user has the possibility to turn off the automatic installation of these updates. For the further processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the further processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Council Presidency text · ST 10426/26
The storing of information, or the gaining of access to information already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Directive 2002/58/EC on privacy and electronic communications, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment.
Recital 44
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
The storing of information, or the gaining of access to information already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Directive 2002/58/EC on privacy and electronic communications, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment.
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
The storing of information, or the gaining of access to information already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Directive 2002/58/EC on privacy and electronic communications, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment.
Council Presidency text · ST 10677/26
The storing of information, or the gaining of access to information already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Directive 2002/58/EC on privacy and electronic communications , where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment.
Recital 44
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
The storing of information, or the gaining of access to information already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Directive 2002/58/EC on privacy and electronic communications , where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment.
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
The storing of information, or the gaining of access to information already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Directive 2002/58/EC on privacy and electronic communications , where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment.
Council Presidency text · ST 12535/26
The storing of information, or the gaining of access to information already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Directive 2002/58/EC on privacy and electronic communications , where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments to this Directive should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment.
Recital 44
Wording reproduced in the amendment → Amendment 420 · ITRE–LIBE amendments 401–526 to the draft report: removal
Changes in context
[...]
RemovedAdded
Both texts in full
Wording reproduced in the amendment
[...]
Amendment 420 · ITRE–LIBE amendments 401–526 to the draft report: removal
Wording reproduced in the amendment → Amendment 421 · ITRE–LIBE amendments 401–526 to the draft report: removal
Changes in context
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Amendment 421 · ITRE–LIBE amendments 401–526 to the draft report: removal
Wording reproduced in the amendment → Amendment 422 · ITRE–LIBE amendments 401–526 to the draft report: removal
Changes in context
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Amendment 422 · ITRE–LIBE amendments 401–526 to the draft report: removal
Wording reproduced in the amendment → Amendment 423 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookiestrackers, identifiers or similar technologies located on, or interacting with, terminal equipment, including but not limited to cookies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person. These rules are without prejudice to Directive 2002/58/EC, which continues to apply in full, and in particular to the confidentiality of communications and of the related traffic data, the protection of traffic and location data, the safeguards against unsolicited communications, and the possibility for Member States to adopt restrictive measures, as provided for in Articles 5, 6, 9, 13 and 15(1) of that Directive.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Amendment 423 · ITRE–LIBE amendments 401–526 to the draft report
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through trackers, identifiers or similar technologies located on, or interacting with, terminal equipment, including but not limited to cookies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person. These rules are without prejudice to Directive 2002/58/EC, which continues to apply in full, and in particular to the confidentiality of communications and of the related traffic data, the protection of traffic and location data, the safeguards against unsolicited communications, and the possibility for Member States to adopt restrictive measures, as provided for in Articles 5, 6, 9, 13 and 15(1) of that Directive.
Wording reproduced in the amendment → Amendment 424 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
The storing of personal datainformation, or the gaining of access to personal datainformation already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely RegulationDirective(EU) 20162002/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person58/EC. The amendments presented in this Regulation should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Amendment 424 · ITRE–LIBE amendments 401–526 to the draft report
The storing of information, or the gaining of access to information already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Directive 2002/58/EC. The amendments presented in this Regulation should continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment.
Wording reproduced in the amendment → Amendment 425 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
The amendments presented in this Regulation regarding the storing of personal data,information or the gaining of access to personal datainformation already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails inter alia the processing of personal data or other information through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Amendment 425 · ITRE–LIBE amendments 401–526 to the draft report
The amendments presented in this Regulation regarding the storing of information or the gaining of access to information already stored in a terminal equipment continue to offer the highest levels of protection, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails inter alia the processing of personal data or other information through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Wording reproduced in the amendment → Amendment 426 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online, but they should include potential penalties to be applied in the event of an information leak involving personal data or access by persons who are not authorised to access this personal information and data. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Amendment 426 · ITRE–LIBE amendments 401–526 to the draft report
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online, but they should include potential penalties to be applied in the event of an information leak involving personal data or access by persons who are not authorised to access this personal information and data. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Wording reproduced in the amendment → Amendment 427 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and theany subsequent processing constitutes a highly intrusive interference with the fundamental rights to confidentiality of suchcommunicationsdataand device integrity, and should be regulatedthereforeundersubjectatosinglestrictlegal framework, namely Regulation (EU) 2016/679protections, where the subscriber of the electronic communications service or the user of the terminal equipment is a naturaldatapersonsubject. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the naturaldatapersonsubject or by another legal or natural person.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Amendment 427 · ITRE–LIBE amendments 401–526 to the draft report
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and any subsequent processing constitutes a highly intrusive interference with the fundamental rights to confidentiality of communications and device integrity, and should be therefore subject to strict protections, where the subscriber of the electronic communications service or the user of the terminal equipment is a data subject. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the data subject or by another legal or natural person.
Wording reproduced in the amendment → Amendment 428 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
The storing of personal datainformation, or the gaining of access to personal datainformation already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Amendment 428 · ITRE–LIBE amendments 401–526 to the draft report
The storing of information, or the gaining of access to information already stored, in a terminal equipment should continue to be allowed only on the basis of consent.
Wording reproduced in the amendment → Amendment 429 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
The storing of personalinformationdataon, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal datainformation already stored, in the terminal equipment of a natural person, wheninthatparticularisthroughbasedcookies and similar technologies, should continue to be governed by Directive 2002/58/EC. In order to ensure legal certainty, avoid fragmentation and reduce unnecessary compliance burdens on Unionbusinesses, a single and coherent regulatory framework should apply to all such practices, irrespective of whether they involve personal or Membernon-personalStatedata.lawAwithindifferentiatedtheregimemeaningunderofwhichArticleonly6cookiesofinvolving personal data would be subject to Regulation (EU) 2016/679 while others remain under Directive 2002/58/EC would create legal complexity and ifincreaseitcostsfulfilsforallundertakings,conditionsin particular small and medium-sized enterprises, without providing additional protection to data subjects. Therefore, the rules on the storing of lawfulnessinformationlaidanddowngaining of access to information stored in thatterminalprovision,equipmentandshouldisremaindoneunifiedforwithin the objectives laid down in Article 23(1)framework of RegulationDirective(EU) 20162002/67958/EC.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Amendment 429 · ITRE–LIBE amendments 401–526 to the draft report
The storing of information on, or the gaining of access to information already stored, in the terminal equipment of a natural person, in particular through cookies and similar technologies, should continue to be governed by Directive 2002/58/EC. In order to ensure legal certainty, avoid fragmentation and reduce unnecessary compliance burdens on businesses, a single and coherent regulatory framework should apply to all such practices, irrespective of whether they involve personal or non-personal data. A differentiated regime under which only cookies involving personal data would be subject to Regulation (EU) 2016/679 while others remain under Directive 2002/58/EC would create legal complexity and increase costs for undertakings, in particular small and medium-sized enterprises, without providing additional protection to data subjects. Therefore, the rules on the storing of information and gaining of access to information stored in terminal equipment should remain unified within the framework of Directive 2002/58/EC.
Wording reproduced in the amendment → Amendment 430 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679, provided that any such measure is necessary and proportionate and does not require the general identification of users, nor the weakening of anonymity, encryption or other protective tools on which users, including journalists, activists and other persons at risk, rely.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Amendment 430 · ITRE–LIBE amendments 401–526 to the draft report
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679, provided that any such measure is necessary and proportionate and does not require the general identification of users, nor the weakening of anonymity, encryption or other protective tools on which users, including journalists, activists and other persons at risk, rely.
Wording reproduced in the amendment → Amendment 431 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, thisThis requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, whenunderthat is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils allcertain conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Amendment 431 · ITRE–LIBE amendments 401–526 to the draft report
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. This requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, under certain conditions.
Wording reproduced in the amendment → Amendment 432 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679. At the same time, it is important to include potential penalties to be applied in the event of an information leak involving personal data or access by persons who are not authorised to access this personal information and data.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Amendment 432 · ITRE–LIBE amendments 401–526 to the draft report
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679. At the same time, it is important to include potential penalties to be applied in the event of an information leak involving personal data or access by persons who are not authorised to access this personal information and data.
Wording reproduced in the amendment → Amendment 433 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a naturaldatapersonsubject, when that is based on Union or Member State law within the meaning of, and subject to the conditions of, Article 6 (3) of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Amendment 433 · ITRE–LIBE amendments 401–526 to the draft report
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a data subject, when that is based on Union or Member State law within the meaning of, and subject to the conditions of, Article 6 (3) of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Wording reproduced in the amendment → Amendment 434 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
The storing of personal datainformation, or the gaining of access to personal datainformation already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement under Regulation (EU) 2016/679 should not preclude storing of personal data, or gaining of access to personal data already stored, in thea terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6(3) of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Amendment 434 · ITRE–LIBE amendments 401–526 to the draft report
The storing of information, or the gaining of access to information already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement under Regulation (EU) 2016/679 should not preclude storing of personal data, or gaining of access to personal data already stored, in a terminal equipment, when that is based on Union or Member State law within the meaning of Article 6(3) of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Wording reproduced in the amendment → Amendment 435 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Amendment 435 · ITRE–LIBE amendments 401–526 to the draft report
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Wording reproduced in the amendment → Amendment 436 · ITRE–LIBE amendments 401–526 to the draft report: removal
Changes in context
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Amendment 436 · ITRE–LIBE amendments 401–526 to the draft report: removal
Wording reproduced in the amendment → Amendment 437 · ITRE–LIBE amendments 401–526 to the draft report: removal
Changes in context
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Amendment 437 · ITRE–LIBE amendments 401–526 to the draft report: removal
Wording reproduced in the amendment → Amendment 438 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
With a view to increase innovation and competitiveness, reducing the compliance burden and providing legal clarity to controllersall stakeholders, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide, among other things, a safe and functional service requested by the datasubscribersubjector user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal datainformation, or the gaining of access to personal datainformation already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf. Such exceptions should cover the transmission of electronic communications, the provision of a service explicitly requested by the user including its functionality and personalisation, audience measurement limited to aggregated data without repurposing for profiling or advertising, and joint audience measurement involving media service providers or their mandated entities. Exceptions should further include measures strictly necessary to ensure the security of the service or network and to prevent fraud directly related to the requested service, as well as the provision, display and measurement of contextual advertising based solely on the content immediately presented to the user, without any profiling. In recognition of the important role played by media service providers and the low privacy risk associated with their typical processing activities, specific provisions should also allow them to offer users a clear choice between consenting to the processing of personal data for purposes such as advertising, service improvement, product development and analytics, or paying a reasonable fee for an equivalent version of the service without such processing. In all cases, these exceptions are designed to strike an appropriate balance between the protection of users’ rights, the sustainability of media pluralism, and the need to foster innovation and competitiveness in the digital single market.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Amendment 438 · ITRE–LIBE amendments 401–526 to the draft report
With a view to increase innovation and competitiveness, reducing the compliance burden and providing legal clarity to all stakeholders, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide, among other things, a safe and functional service requested by the subscriber or user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of information, or the gaining of access to information already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf. Such exceptions should cover the transmission of electronic communications, the provision of a service explicitly requested by the user including its functionality and personalisation, audience measurement limited to aggregated data without repurposing for profiling or advertising, and joint audience measurement involving media service providers or their mandated entities. Exceptions should further include measures strictly necessary to ensure the security of the service or network and to prevent fraud directly related to the requested service, as well as the provision, display and measurement of contextual advertising based solely on the content immediately presented to the user, without any profiling. In recognition of the important role played by media service providers and the low privacy risk associated with their typical processing activities, specific provisions should also allow them to offer users a clear choice between consenting to the processing of personal data for purposes such as advertising, service improvement, product development and analytics, or paying a reasonable fee for an equivalent version of the service without such processing. In all cases, these exceptions are designed to strike an appropriate balance between the protection of users’ rights, the sustainability of media pluralism, and the need to foster innovation and competitiveness in the digital single market.
Wording reproduced in the amendment → Amendment 439 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. This list should include measuring the audience of an online service by creating aggregated information about the usage of an online service, where it is carried out by the provider of that online service, or by a third party, such as a market research company or a Joint Industry Committee, acting together with or on behalf of this provider. ‘Audience measurement’ should be understood in accordance with Article 2(16) and with Article 24(1) of Regulation (EU) 2024/1083. Gatekeepers designated under Regulation (EU) 2022/1925 carrying out audience measurement may not rely on article 88a(3)c of this Regulation. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Amendment 439 · ITRE–LIBE amendments 401–526 to the draft report
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. This list should include measuring the audience of an online service by creating aggregated information about the usage of an online service, where it is carried out by the provider of that online service, or by a third party, such as a market research company or a Joint Industry Committee, acting together with or on behalf of this provider. ‘Audience measurement’ should be understood in accordance with Article 2(16) and with Article 24(1) of Regulation (EU) 2024/1083. Gatekeepers designated under Regulation (EU) 2022/1925 carrying out audience measurement may not rely on article 88a(3)c of this Regulation. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Wording reproduced in the amendment → Amendment 440 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is strictly necessary for those specific purposes, this Regulation should therefore provide that the processing is lawful. TheThese narrow exceptions should strictly apply to technical communications transmission, the execution of explicit services requested by the data subject, necessary security operations, or audience measurement metrics for media service providers, or third-party providers of audience measurement for media services providers, provided it follows conditions for low processing risks, namely for statistical counting and is not utilised for profiling of data subject and does not involve core platfroms services as defined in Regulation (EU) 2022/1925. Following these conditions, the controller, such as a media service provider, may therefore mandate a processor, such as a market research company, to carry out the processing on its behalf.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Amendment 440 · ITRE–LIBE amendments 401–526 to the draft report
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is strictly necessary for those specific purposes, this Regulation should therefore provide that the processing is lawful. These narrow exceptions should strictly apply to technical communications transmission, the execution of explicit services requested by the data subject, necessary security operations, or audience measurement metrics for media service providers, or third-party providers of audience measurement for media services providers, provided it follows conditions for low processing risks, namely for statistical counting and is not utilised for profiling of data subject and does not involve core platfroms services as defined in Regulation (EU) 2022/1925. Following these conditions, the controller, such as a media service provider, may therefore mandate a processor, such as a market research company, to carry out the processing on its behalf.
Wording reproduced in the amendment → Amendment 441 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as an online service or a media service provider, may mandate a processor or joint controller, such as a market research company or Joint Industry Committee, to carry out the processing jointly or on its behalf, subject to strict safeguards ensuring that such processing is proportionate, compliant with the requirements of Article 24(1) of Regulation (EU) 2024/1083 and is not repurposed for advertising, profiling, or other unrelated purposes.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Amendment 441 · ITRE–LIBE amendments 401–526 to the draft report
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as an online service or a media service provider, may mandate a processor or joint controller, such as a market research company or Joint Industry Committee, to carry out the processing jointly or on its behalf, subject to strict safeguards ensuring that such processing is proportionate, compliant with the requirements of Article 24(1) of Regulation (EU) 2024/1083 and is not repurposed for advertising, profiling, or other unrelated purposes.
Wording reproduced in the amendment → Amendment 442 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processingstoringposeor gaining access to the information on the terminal equipment of a natural person poses a low risk to the rights and freedoms of data subjects or that such processingit may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. AsThisregardslimitedstoringlist of personallowdatarisk operations includes audience measurement, especially in the case of media providers, and the restoration or the gainingmaintenance of accessthetosecuritypersonalofdata already stored, in athe terminal equipment, and subsequent processingprovided that service providers fulfill certain conditions. In the case of audience measurement, the data should be instantly anonymised and aggregated. The user’s personal data could, for instance, be retained for a short time session. At the end of the session, the data would be aggregated in such a way that it does not constitute personal data and remaining personal data from the session is deleted or anonymised. The user should still be informed about the storing or gaining access. All of these operations should always be strictly technically and solely necessary for those purposes, this Regulation should therefore provide that the processing is lawfulpurpose. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Amendment 442 · ITRE–LIBE amendments 401–526 to the draft report
With a view to reducing the compliance burden and providing legal clarity, and given that certain purposes of storing or gaining access to the information on the terminal equipment of a natural person poses a low risk to the rights and freedoms of data subjects or that it may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. This limited list of low risk operations includes audience measurement, especially in the case of media providers, and the restoration or maintenance of the security of the terminal equipment, provided that service providers fulfill certain conditions. In the case of audience measurement, the data should be instantly anonymised and aggregated. The user’s personal data could, for instance, be retained for a short time session. At the end of the session, the data would be aggregated in such a way that it does not constitute personal data and remaining personal data from the session is deleted or anonymised. The user should still be informed about the storing or gaining access. All of these operations should always be strictly technically and solely necessary for the purpose.
Wording reproduced in the amendment → Amendment 443 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. Those purposes should be interpreted narrowly and should not serve as a basis for tracking, profiling or the large-scale monitoring of the online activity of data subjects. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Amendment 443 · ITRE–LIBE amendments 401–526 to the draft report
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. Those purposes should be interpreted narrowly and should not serve as a basis for tracking, profiling or the large-scale monitoring of the online activity of data subjects. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Wording reproduced in the amendment → Amendment 444 · ITRE–LIBE amendments 401–526 to the draft report: removal
Changes in context
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Amendment 444 · ITRE–LIBE amendments 401–526 to the draft report: removal
Wording reproduced in the amendment → Amendment 445 · ITRE–LIBE amendments 401–526 to the draft report: removal
Changes in context
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Amendment 445 · ITRE–LIBE amendments 401–526 to the draft report: removal
Wording reproduced in the amendment → Amendment 446 · ITRE–LIBE amendments 401–526 to the draft report: removal
Changes in context
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Amendment 446 · ITRE–LIBE amendments 401–526 to the draft report: removal
Wording reproduced in the amendment → Amendment 447 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Amendment 447 · ITRE–LIBE amendments 401–526 to the draft report
For the subsequent processing of personal data Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing.
Wording reproduced in the amendment → Amendment 448 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
For the subsequent processing of personal data for other purpose than those defined in the limitative list, such as development and operating of artificial intelligence models, controllers may seek to rely on legitimate interest under Article 6 and(1), wherepointrelevant,(f) while Article 9 of Regulation (EU) 2016/679 should nevertheless be applied. However, to ensure that such processing does not override the fundamental rights and freedoms of data subjects, controllers must implement mandatory checklist of technical and organisational standards. These must include providing data subjects with an absolute right to object after being fully informed, ensuring state-of-the-art technics for data anonymisation, the executing rigorous technical abstration during the model training phase to make data disclosure extremely unlikely. To reduce individual administrative burdens, Member States should enable data subjects to administer their absolute right to object through a centralised public body. To ease complience and ensure uniformed approach, minimum standards for these techniques should be technically defined through standardisation. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmostutmost account of the following elements: whether the data subject is a child; the reasonable expectations of the data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Amendment 448 · ITRE–LIBE amendments 401–526 to the draft report
For the subsequent processing of personal data for other purpose than those defined in the limitative list, such as development and operating of artificial intelligence models, controllers may seek to rely on legitimate interest under Article 6 (1), point (f) while Article 9 of Regulation (EU) 2016/679 should nevertheless be applied. However, to ensure that such processing does not override the fundamental rights and freedoms of data subjects, controllers must implement mandatory checklist of technical and organisational standards. These must include providing data subjects with an absolute right to object after being fully informed, ensuring state-of-the-art technics for data anonymisation, the executing rigorous technical abstration during the model training phase to make data disclosure extremely unlikely. To reduce individual administrative burdens, Member States should enable data subjects to administer their absolute right to object through a centralised public body. To ease complience and ensure uniformed approach, minimum standards for these techniques should be technically defined through standardisation. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take utmost account of the following elements: whether the data subject is a child; the reasonable expectations of the data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Wording reproduced in the amendment → Amendment 449 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life, and there should also be potential penalties in the event of information misuse or leaks involving personal data or access by persons who are not authorised to access this personal information and data.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Amendment 449 · ITRE–LIBE amendments 401–526 to the draft report
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life, and there should also be potential penalties in the event of information misuse or leaks involving personal data or access by persons who are not authorised to access this personal information and data.
Wording reproduced in the amendment → Amendment 450 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements:; whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life. Sensitive categories of personal data shoud only be processed in accordance with Article 9 of Regulation 2016/679, unless otherwise provided for in this regulation.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Amendment 450 · ITRE–LIBE amendments 401–526 to the draft report
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements; whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the monitoring of the data subject’s private life. Sensitive categories of personal data shoud only be processed in accordance with Article 9 of Regulation 2016/679, unless otherwise provided for in this regulation.
Wording reproduced in the amendment → Amendment 451 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life. Where age assurance is necessary, it should rely on privacy-preserving and data-minimising techniques, and should not undermine the anonymity or confidentiality of communications.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life.
Amendment 451 · ITRE–LIBE amendments 401–526 to the draft report
For the subsequent processing of personal data for other purpose than those defined in the limitative list, Article 6 and, where relevant, Article 9 of Regulation (EU) 2016/679 should be applied. It is the responsibility of the controller in the light of the principle of accountability to choose the appropriate legal basis for the intended processing. In order to be able to rely on legitimate interest under Article 6(1), point f, of Regulation (EU) 2016/679 as a ground for the subsequent processing of personal data, the controller must show that it pursues the controller’s or third parties’ legitimate interest, the processing is necessary in order to achieve the purpose of that legitimate interest, and the interests or fundamental rights of the data subject do not override the interests pursued by the controller. In this context, controllers should take outmost account of the following elements: whether the data subject is a child; the reasonable expectations of data subject; the impact on the individual either because of the scale of data processed or the sensitivity of the data processed; the scale of the processing at issue in the sense that the processing cannot be particularly extensive either because of their amount or the range of categories of data; the processing should be based on data limited to what is necessary and cannot be based on monitoring of large parts of the online activity of the data subjects; and other relevant factors as appropriate. The processing should not give rise to the continuous monitoring of the data subject’s private life. Where age assurance is necessary, it should rely on privacy-preserving and data-minimising techniques, and should not undermine the anonymity or confidentiality of communications.
Wording reproduced in the amendment → Amendment 452 · ITRE–LIBE amendments 401–526 to the draft report: removal
Changes in context
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
Amendment 452 · ITRE–LIBE amendments 401–526 to the draft report: removal
Wording reproduced in the amendment → Amendment 453 · ITRE–LIBE amendments 401–526 to the draft report: removal
Changes in context
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
Amendment 453 · ITRE–LIBE amendments 401–526 to the draft report: removal
Wording reproduced in the amendment → Amendment 454 · ITRE–LIBE amendments 401–526 to the draft report: removal
Changes in context
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
Amendment 454 · ITRE–LIBE amendments 401–526 to the draft report: removal
Wording reproduced in the amendment → Amendment 455 · ITRE–LIBE amendments 401–526 to the draft report: removal
Changes in context
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
Amendment 455 · ITRE–LIBE amendments 401–526 to the draft report: removal
Wording reproduced in the amendment → Amendment 456 · ITRE–LIBE amendments 401–526 to the draft report: removal
Changes in context
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Where the controller cannot rely on legitimate interest as a legal ground for the subsequent processing, the processing should be based on another ground in Article 6(1), in particular on consent in accordance with Articles 6 and 7 of Regulation (EU) 2016/679, provided that all principles of Regulation (EU) 2016/679 are met.
Amendment 456 · ITRE–LIBE amendments 401–526 to the draft report: removal
Wording reproduced in the amendment → Amendment 176 · IMCO amendments 125–328 to the draft opinion
Changes in context
The introduction of Article 88a in the GDPR should continue to offer the highest levels of protection, in particular consumer protection and privacy, while simplifying the experiences of consumers in exerting their rights and expressing their choices online. This article should be seen as strengthening Article 5 of Directive 2002/58/EC on privacy and electronic communications (‘ePrivacy Directive’), last revised in 2009, by providing specific rules in relation to processing of personal data in the context of electronic communication services. The amendments concern in particular access to and storage of personal data in the terminal equipment, accessing or otherwise collecting personal data from that equipment through cookies or similar technologies to gain information from the terminal equipment. As this access and storage constitute by itself an interference with the private sphere of a consumers as protected by Article 7 and 8 of the Charter of Fundamental Rights, it begs the question whether the information qualifies as personal data. The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment andshould therefore continue to be allowed only on the subsequent processingbasis of suchconsentdata shouldand be regulatedsubjectunderto clear rules able to guarantee a singlehighlegallevelframework,ofnamelyprotectionRegulationof(EU)consumers2016/679,whilewheresafeguarding the subscriberfunctioning of the electronicinternalcommunicationsmarket.serviceRulesorgoverning the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storagestoring of information in thatterminal equipment,accessingandoraccessotherwisetocollectingsuch information from that equipment that entailsprotect the processingconfidentiality of communications and the integrity of user devices. These protections apply independently of whether the information accessed constitutes personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should alsoand apply regardless of whether the terminalinformationequipmentaccessed constitutes personal data. With a view of providing legal clarity it is ownednecessarybyto define a limitative list of purposes, strictly defined and necessary, for which the naturalprocessingpersonshould be permitted without consent. These exemptions should be interpreted strictly.
Non-personalised advertising is a form of advertising that provides the highest level of consumer protection as it minimizes the collection of consumer data while still ensuring the provision of advertising on the internal market and the establishment of new businesses models in this sector. In the context of Article 88a (3) (d) (a) (new) it shall not involve the retention, storage, reuse or bylinkinganotheroflegalany data generated in connection with such interaction, nor the processing, inference or naturalusepersonof any data relating to the consumer’s location whether precise or approximate, including where such location data is derived, inferred or processed in aggregated anonymized form. Contextual advertising as defined in Article 4 (b) (xx) and in the context of Article 88a (3) (d) (a) (new) shall not involve the retention, storage, reuse or linking of any data generated in connection with such interaction, nor the processing, inference or use of any data relating to the consumer’s location whether precise or approximate, including where such location data is derived, inferred or processed in aggregated anonymized form. If a controller invokes the exception of Article 88a (3) (d) (a) (new) , the controller will not be able to engage in any other advertising activities other than contextual advertising as defined in Article (4) (b) (xx), including, but not limited, personalised and targeted advertising activities as defined in the EDPB Guidelines 8/2020 on the targeting of social media use.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment and the subsequent processing of such data should be regulated under a single legal framework, namely Regulation (EU) 2016/679, where the subscriber of the electronic communications service or the user of the terminal equipment is a natural person. The amendments presented in this Regulation continue to offer the highest levels of protection for personal data, while simplifying the experiences of data subjects in exerting their rights and expressing their choices online. The amendments concern in particular storage of information in that equipment, accessing or otherwise collecting information from that equipment that entails the processing of personal data through cookies or similar technologies to gain information from the terminal equipment. The relevant rules should also apply regardless of whether the terminal equipment is owned by the natural person or by another legal or natural person.
Amendment 176 · IMCO amendments 125–328 to the draft opinion
The introduction of Article 88a in the GDPR should continue to offer the highest levels of protection, in particular consumer protection and privacy, while simplifying the experiences of consumers in exerting their rights and expressing their choices online. This article should be seen as strengthening Article 5 of Directive 2002/58/EC on privacy and electronic communications (‘ePrivacy Directive’), last revised in 2009, by providing specific rules in relation to processing of personal data in the context of electronic communication services. The amendments concern in particular access to and storage of personal data in the terminal equipment, accessing or otherwise collecting personal data from that equipment through cookies or similar technologies to gain information from the terminal equipment. As this access and storage constitute by itself an interference with the private sphere of a consumers as protected by Article 7 and 8 of the Charter of Fundamental Rights, it begs the question whether the information qualifies as personal data. The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should therefore continue to be allowed only on the basis of consent and be subject to clear rules able to guarantee a high level of protection of consumers while safeguarding the functioning of the internal market. Rules governing the storing of information in terminal equipment and access to such information protect the confidentiality of communications and the integrity of user devices. These protections apply independently of whether the information accessed constitutes personal data and apply regardless of whether the information accessed constitutes personal data. With a view of providing legal clarity it is necessary to define a limitative list of purposes, strictly defined and necessary, for which the processing should be permitted without consent. These exemptions should be interpreted strictly.
Non-personalised advertising is a form of advertising that provides the highest level of consumer protection as it minimizes the collection of consumer data while still ensuring the provision of advertising on the internal market and the establishment of new businesses models in this sector. In the context of Article 88a (3) (d) (a) (new) it shall not involve the retention, storage, reuse or linking of any data generated in connection with such interaction, nor the processing, inference or use of any data relating to the consumer’s location whether precise or approximate, including where such location data is derived, inferred or processed in aggregated anonymized form. Contextual advertising as defined in Article 4 (b) (xx) and in the context of Article 88a (3) (d) (a) (new) shall not involve the retention, storage, reuse or linking of any data generated in connection with such interaction, nor the processing, inference or use of any data relating to the consumer’s location whether precise or approximate, including where such location data is derived, inferred or processed in aggregated anonymized form. If a controller invokes the exception of Article 88a (3) (d) (a) (new) , the controller will not be able to engage in any other advertising activities other than contextual advertising as defined in Article (4) (b) (xx), including, but not limited, personalised and targeted advertising activities as defined in the EDPB Guidelines 8/2020 on the targeting of social media use.
Wording reproduced in the amendment → Amendment 177 · IMCO amendments 125–328 to the draft opinion: removal
Changes in context
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Amendment 177 · IMCO amendments 125–328 to the draft opinion: removal
Wording reproduced in the amendment → Amendment 178 · IMCO amendments 125–328 to the draft opinion
Changes in context
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union or Member State law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Amendment 178 · IMCO amendments 125–328 to the draft opinion
The storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment should continue to be allowed only on the basis of consent. Similar to the approach in Directive 2002/58/EC, this requirement should not preclude storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person, when that is based on Union law within the meaning of Article 6 of Regulation (EU) 2016/679 and if it fulfils all conditions of lawfulness laid down in that provision, and is done for the objectives laid down in Article 23(1) of Regulation (EU) 2016/679.
Wording reproduced in the amendment → Amendment 179 · IMCO amendments 125–328 to the draft opinion
Changes in context
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service explicitly requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is strictly necessary and proportionate for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf. Controllers wishing to collect aggregated information of consumers should anonymise such information instantly and may mandate a processor to carry out the processing, provided that the processor will exclusively process the data for the use of the controller. No subsequent processing of personal data for other purposes than those defined in the limitative list should take place.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Amendment 179 · IMCO amendments 125–328 to the draft opinion
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service explicitly requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is strictly necessary and proportionate for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf. Controllers wishing to collect aggregated information of consumers should anonymise such information instantly and may mandate a processor to carry out the processing, provided that the processor will exclusively process the data for the use of the controller. No subsequent processing of personal data for other purposes than those defined in the limitative list should take place.
Wording reproduced in the amendment → Amendment 180 · IMCO amendments 125–328 to the draft opinion
Changes in context
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor or joint controller, such as a market research company and Joint Industry Controller, to carry out the processing jointly or on its behalf.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Amendment 180 · IMCO amendments 125–328 to the draft opinion
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor or joint controller, such as a market research company and Joint Industry Controller, to carry out the processing jointly or on its behalf.
Wording reproduced in the amendment → Amendment 181 · IMCO amendments 125–328 to the draft opinion
Changes in context
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor or joint controller, such as a market research company and Joint Industry Committee, to carry out the processing on its behalf.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
Amendment 181 · IMCO amendments 125–328 to the draft opinion
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor or joint controller, such as a market research company and Joint Industry Committee, to carry out the processing on its behalf.
Wording reproduced in the amendment → Amendment 21 · IMCO draft opinion · Alex Agius Saliba (rapporteur)
Changes in context
With a view to reducing the compliance burden and providing legal clarity to controllers and providers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service explicitly requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is strictly necessary and proportionate for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
With a view to reducing the compliance burden and providing legal clarity to controllers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.
With a view to reducing the compliance burden and providing legal clarity to controllers and providers, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service explicitly requested by the data subject, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of personal data, or the gaining of access to personal data already stored, in a terminal equipment, and subsequent processing that is strictly necessary and proportionate for those purposes, this Regulation should therefore provide that the processing is lawful. The controller, such as a media service provider, may mandate a processor, such as a market research company, to carry out the processing on its behalf.