Digital Omnibus proposal
Recital 44b
Compare the available Commission, Council and Parliament texts and amendments affecting this recital.
Recital total: 1 part · 3 Council drafts · 0 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
The wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Recital 44b
June Presidency compromise · 10 June
With a view to reducing the compliance burden and providing legal clarity, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by a subscriber or user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of information, or the gaining of access to information already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, the Directive should therefore provide that such processing is lawful, including when being carried out jointly with or on the behalf of a controller. For example a media service provider, may mandate a third party, such as a market research company, to carry out such processing. Consent should not be required, where placing of information on or gaining access to information stored is necessary to provide a service explicitly requested by user or subscriber. This should include placing of information or gaining access to information stored for the purpose of ensuring certain functionalities necessary for the service explicitly requested by the user or subscriber. This could include memorising the user’s choices and selected elements such as, among others, the user’s language settings, configuration choices, items placed in shopping baskets or memorising information to facilitate filling in of online forms. Measuring the audience of an online service in order to create anonymous aggregated information about the usage of an online service, where it is carried out by the provider of that online service, or by a third party such as a market research company or a Joint Industry Committee, acting together with or on behalf of this provider, , also referred to as ‘audience measurement’, means processing such data and information to obtain insight into the performance and use of the online service in an anonymised, aggregated and general manner. This includes the performance of audience by an entitled and independent third party performing audience measurement as defined in Regulation (EU) 2024/1083. The aggregated information should not relate to a specific data subject and should therefore be anonymous aggregated information. The anonymous aggregated information can be shared with third parties, including companies and non-commercial organizations. Processing of personal data with the aim of creating anonymous aggregated information contributes to the sustainability of the media ecosystem as highlighted in Regulation 2024/1083 and should be subject to strict limitations designed to ensure that the personal data is not reused for providing personalised advertising, profiling or other unrelated purposes. The personal data initially collected should not be further processed for another purpose, combined with data from other services from the provider of the online service or from a third party, such as analytics information from other websites or apps, or shared with third parties. Maintaining or restoring the security of a service provided by an information society service provider and requested by the subscriber or user, or the terminal equipment used for the provision of such service, should only be allowed without consent to the extent that the security updates are strictly necessary, proportionate, discretely packaged and do not in any way change the functionality of the software on the terminal equipment, including the interaction with other software or settings chosen by the subscriber or user, the subscriber or user is informed in advance each time an update is being installed, and the subscriber or user has the possibility to turn off the automatic installation of these updates. The maintaining or restoring the security of the service or of the terminal equipment should include in particular cybersecurity and the necessary security requirements to ensure a proper functioning of the terminal equipment as well as the protection of personal data and privacy of the user. Measures taken for the detection and prevention of fraud should only be possible to be taken without consent insofar as they are strictly necessary and such measures do not override the fundamental rights and interests of users and subscribers.
Recital 44b
June Presidency compromise · 18 June
With a view to reducing the compliance burden and providing legal clarity, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by a subscriber or user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of information, or the gaining of access to information already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, the Directive should therefore provide that such processing is lawful, including when being carried out jointly with or on the behalf of a controller. For example a media service provider, may mandate a third party, such as a market research company, to carry out such processing. Consent should not be required, where placing of information on or gaining access to information stored is necessary to provide a service explicitly requested by user or subscriber. This should include placing of information or gaining access to information stored for the purpose of ensuring certain functionalities necessary for the service explicitly requested by the user or subscriber. This could include memorising the user’s choices and selected elements such as, among others, the user’s language settings, configuration choices, items placed in shopping baskets , information to facilitate filling in of online forms, or functionalities of a requested service related to information on vehicles. Measuring the audience of an online service by creating anonymous aggregated information about the usage of an online service, where it is carried out by the provider of that online service, or by a third party acting together with or on behalf of this provider, or by a third party such as a market research company or a Joint Industry Committee, acting together with or on behalf of this provider, also referred to as ‘audience measurement’ as defined in paragraph 16 of Article 2 and in accordance with Article 24 of Regulation (EU) 2024/1083, means processing such data and information to obtain insight into the performance and use of the online service in an instantly anonymised, aggregated and general manner. This includes the performance of audience by an entitled and independent third party performing audience measurement as defined in Regulation (EU) 2024/1083. The aggregated information should not relate to a specific data subject and should therefore be anonymous aggregated information. The anonymous aggregated information can be shared with third parties, including companies and non-commercial organizations. Processing of personal data with the aim of creating anonymous aggregated information contributes to the sustainability of the media ecosystem as highlighted in Regulation 2024/1083 and should be subject to strict limitations designed to ensure that the personal data is not reused for providing personalised advertising, profiling or other unrelated purposes. The personal data of users or subscribers initially collected should not be further processed for another purpose, combined with data from other services from the provider of the online service or from a third party, such as analytics information from other websites or apps, or shared with third parties. Maintaining or restoring the security of a service provided by an information society service provider and requested by the subscriber or user, or the terminal equipment used for the provision of such service, should only be allowed without consent to the extent that the security updates are strictly necessary, proportionate, discretely packaged and do not in any way change the functionality of the software on the terminal equipment, including the interaction with other software or settings chosen by the subscriber or user, the subscriber or user is informed in advance each time an update is being installed, and the subscriber or user has the possibility to turn off the automatic installation of these updates. The maintaining or restoring the security of the service or of the terminal equipment should include in particular cybersecurity and the necessary security requirements to ensure a proper functioning of the terminal equipment as well as the protection of personal data and privacy of the user.
Recital 44b
September Presidency compromise
With a view to reducing the compliance burden and providing legal clarity, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by a subscriber or user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of information, or the gaining of access to information already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, the Directive should therefore provide that such processing is lawful, including when being carried out jointly with or on the behalf of a controller. For example a media service provider, may mandate a third party, such as a market research company, to carry out such processing. Consent should not be required, where placing of information on or gaining access to information stored is necessary to provide a service explicitly requested by user or subscriber. This should include placing of information or gaining access to information stored for the purpose of ensuring certain functionalities necessary for the service explicitly requested by the user or subscriber. This could include memorising the user’s choices and selected elements such as, among others, the user’s language settings, configuration choices, items placed in shopping baskets , information to facilitate filling in of online forms, or functionalities of a requested service related to information on vehicles. Measuring the audience of an online service by creating anonymous aggregated information about the usage of an online service, where it is carried out by the provider of that online service, or by a third party acting together with or on behalf of this provider, or by a third party such as a market research company or a Joint Industry Committee, acting together with or on behalf of this provider, also referred to as ‘audience measurement’ as defined in paragraph 16 of Article 2 and in accordance with Article 24 of Regulation (EU) 2024/1083, means processing such data and information to obtain insight into the performance and use of the online service in an instantly anonymised, aggregated and general manner. This includes the performance of audience by an entitled and independent third party performing audience measurement as defined in Regulation (EU) 2024/1083. The aggregated information should not relate to a specific data subject and should therefore be anonymous aggregated information. The anonymous aggregated information can be shared with third parties, including companies and non-commercial organizations. Processing of personal data with the aim of creating anonymous aggregated information contributes to the sustainability of the media ecosystem as highlighted in Regulation 2024/1083 and should be subject to strict limitations designed to ensure that the personal data is not reused for providing personalised advertising, profiling or other unrelated purposes. The personal data of users or subscribers initially collected should not be further processed for another purpose, combined with data from other services from the provider of the online service or from a third party, such as analytics information from other websites or apps, or shared with third parties. Maintaining or restoring the security of a service provided by an information society service provider and requested by the subscriber or user, or the terminal equipment used for the provision of such service, should only be allowed without consent to the extent that the security updates are strictly necessary, proportionate, discretely packaged and do not in any way change the functionality of the software on the terminal equipment, including the interaction with other software or settings chosen by the subscriber or user, the subscriber or user is informed in advance each time an update is being installed, and the subscriber or user has the possibility to turn off the automatic installation of these updates. The maintaining or restoring the security of the service or of the terminal equipment should include in particular cybersecurity and the necessary security requirements to ensure a proper functioning of the terminal equipment as well as the protection of personal data and privacy of the user.
Recital 44b 3 Council drafts
Recital 44b
10 June 2026 · June Presidency compromise · 10 June
With a view to reducing the compliance burden and providing legal clarity, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by a subscriber or user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of information, or the gaining of access to information already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, the Directive should therefore provide that such processing is lawful, including when being carried out jointly with or on the behalf of a controller. For example a media service provider, may mandate a third party, such as a market research company, to carry out such processing. Consent should not be required, where placing of information on or gaining access to information stored is necessary to provide a service explicitly requested by user or subscriber. This should include placing of information or gaining access to information stored for the purpose of ensuring certain functionalities necessary for the service explicitly requested by the user or subscriber. This could include memorising the user’s choices and selected elements such as, among others, the user’s language settings, configuration choices, items placed in shopping baskets or memorising information to facilitate filling in of online forms. Measuring the audience of an online service in order to create anonymous aggregated information about the usage of an online service, where it is carried out by the provider of that online service, or by a third party such as a market research company or a Joint Industry Committee, acting together with or on behalf of this provider, , also referred to as ‘audience measurement’, means processing such data and information to obtain insight into the performance and use of the online service in an anonymised, aggregated and general manner. This includes the performance of audience by an entitled and independent third party performing audience measurement as defined in Regulation (EU) 2024/1083. The aggregated information should not relate to a specific data subject and should therefore be anonymous aggregated information. The anonymous aggregated information can be shared with third parties, including companies and non-commercial organizations. Processing of personal data with the aim of creating anonymous aggregated information contributes to the sustainability of the media ecosystem as highlighted in Regulation 2024/1083 and should be subject to strict limitations designed to ensure that the personal data is not reused for providing personalised advertising, profiling or other unrelated purposes. The personal data initially collected should not be further processed for another purpose, combined with data from other services from the provider of the online service or from a third party, such as analytics information from other websites or apps, or shared with third parties. Maintaining or restoring the security of a service provided by an information society service provider and requested by the subscriber or user, or the terminal equipment used for the provision of such service, should only be allowed without consent to the extent that the security updates are strictly necessary, proportionate, discretely packaged and do not in any way change the functionality of the software on the terminal equipment, including the interaction with other software or settings chosen by the subscriber or user, the subscriber or user is informed in advance each time an update is being installed, and the subscriber or user has the possibility to turn off the automatic installation of these updates. The maintaining or restoring the security of the service or of the terminal equipment should include in particular cybersecurity and the necessary security requirements to ensure a proper functioning of the terminal equipment as well as the protection of personal data and privacy of the user. Measures taken for the detection and prevention of fraud should only be possible to be taken without consent insofar as they are strictly necessary and such measures do not override the fundamental rights and interests of users and subscribers.
Recital 44b
18 June 2026 · June Presidency compromise · 18 June
With a view to reducing the compliance burden and providing legal clarity, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by a subscriber or user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of information, or the gaining of access to information already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, the Directive should therefore provide that such processing is lawful, including when being carried out jointly with or on the behalf of a controller. For example a media service provider, may mandate a third party, such as a market research company, to carry out such processing. Consent should not be required, where placing of information on or gaining access to information stored is necessary to provide a service explicitly requested by user or subscriber. This should include placing of information or gaining access to information stored for the purpose of ensuring certain functionalities necessary for the service explicitly requested by the user or subscriber. This could include memorising the user’s choices and selected elements such as, among others, the user’s language settings, configuration choices, items placed in shopping baskets , information to facilitate filling in of online forms, or functionalities of a requested service related to information on vehicles. Measuring the audience of an online service by creating anonymous aggregated information about the usage of an online service, where it is carried out by the provider of that online service, or by a third party acting together with or on behalf of this provider, or by a third party such as a market research company or a Joint Industry Committee, acting together with or on behalf of this provider, also referred to as ‘audience measurement’ as defined in paragraph 16 of Article 2 and in accordance with Article 24 of Regulation (EU) 2024/1083, means processing such data and information to obtain insight into the performance and use of the online service in an instantly anonymised, aggregated and general manner. This includes the performance of audience by an entitled and independent third party performing audience measurement as defined in Regulation (EU) 2024/1083. The aggregated information should not relate to a specific data subject and should therefore be anonymous aggregated information. The anonymous aggregated information can be shared with third parties, including companies and non-commercial organizations. Processing of personal data with the aim of creating anonymous aggregated information contributes to the sustainability of the media ecosystem as highlighted in Regulation 2024/1083 and should be subject to strict limitations designed to ensure that the personal data is not reused for providing personalised advertising, profiling or other unrelated purposes. The personal data of users or subscribers initially collected should not be further processed for another purpose, combined with data from other services from the provider of the online service or from a third party, such as analytics information from other websites or apps, or shared with third parties. Maintaining or restoring the security of a service provided by an information society service provider and requested by the subscriber or user, or the terminal equipment used for the provision of such service, should only be allowed without consent to the extent that the security updates are strictly necessary, proportionate, discretely packaged and do not in any way change the functionality of the software on the terminal equipment, including the interaction with other software or settings chosen by the subscriber or user, the subscriber or user is informed in advance each time an update is being installed, and the subscriber or user has the possibility to turn off the automatic installation of these updates. The maintaining or restoring the security of the service or of the terminal equipment should include in particular cybersecurity and the necessary security requirements to ensure a proper functioning of the terminal equipment as well as the protection of personal data and privacy of the user.
Recital 44b
3 September 2026 · September Presidency compromise
With a view to reducing the compliance burden and providing legal clarity, and given that certain purposes of processing pose a low risk to the rights and freedoms of data subjects or that such processing may be necessary to provide a service requested by a subscriber or user, it is necessary to define a limitative list of purposes for which the processing should be permitted without consent. As regards storing of information, or the gaining of access to information already stored, in a terminal equipment, and subsequent processing that is necessary for those purposes, the Directive should therefore provide that such processing is lawful, including when being carried out jointly with or on the behalf of a controller. For example a media service provider, may mandate a third party, such as a market research company, to carry out such processing. Consent should not be required, where placing of information on or gaining access to information stored is necessary to provide a service explicitly requested by user or subscriber. This should include placing of information or gaining access to information stored for the purpose of ensuring certain functionalities necessary for the service explicitly requested by the user or subscriber. This could include memorising the user’s choices and selected elements such as, among others, the user’s language settings, configuration choices, items placed in shopping baskets , information to facilitate filling in of online forms, or functionalities of a requested service related to information on vehicles. Measuring the audience of an online service by creating anonymous aggregated information about the usage of an online service, where it is carried out by the provider of that online service, or by a third party acting together with or on behalf of this provider, or by a third party such as a market research company or a Joint Industry Committee, acting together with or on behalf of this provider, also referred to as ‘audience measurement’ as defined in paragraph 16 of Article 2 and in accordance with Article 24 of Regulation (EU) 2024/1083, means processing such data and information to obtain insight into the performance and use of the online service in an instantly anonymised, aggregated and general manner. This includes the performance of audience by an entitled and independent third party performing audience measurement as defined in Regulation (EU) 2024/1083. The aggregated information should not relate to a specific data subject and should therefore be anonymous aggregated information. The anonymous aggregated information can be shared with third parties, including companies and non-commercial organizations. Processing of personal data with the aim of creating anonymous aggregated information contributes to the sustainability of the media ecosystem as highlighted in Regulation 2024/1083 and should be subject to strict limitations designed to ensure that the personal data is not reused for providing personalised advertising, profiling or other unrelated purposes. The personal data of users or subscribers initially collected should not be further processed for another purpose, combined with data from other services from the provider of the online service or from a third party, such as analytics information from other websites or apps, or shared with third parties. Maintaining or restoring the security of a service provided by an information society service provider and requested by the subscriber or user, or the terminal equipment used for the provision of such service, should only be allowed without consent to the extent that the security updates are strictly necessary, proportionate, discretely packaged and do not in any way change the functionality of the software on the terminal equipment, including the interaction with other software or settings chosen by the subscriber or user, the subscriber or user is informed in advance each time an update is being installed, and the subscriber or user has the possibility to turn off the automatic installation of these updates. The maintaining or restoring the security of the service or of the terminal equipment should include in particular cybersecurity and the necessary security requirements to ensure a proper functioning of the terminal equipment as well as the protection of personal data and privacy of the user.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
No Parliament amendment is mapped to these tracked parts.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Recital 44b
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Recital 44b
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded