Digital Omnibus tracker

GDPR · Regulation (EU) 2016/679

Article 2

Compare the available Commission, Council and Parliament texts and amendments affecting this article.

Article total: 6 parts · 0 Council drafts · 6 Parliament amendments

Removed wording is struck through; added or replacement wording is highlighted.

Institutional text

European Commission proposal

All Commission’s changes to GDPR

The wording proposed by the Commission at the start of this legislative file.

No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.

Institutional text

Council Presidency texts

Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.

No Council wording is mapped to these tracked parts.

Competing proposals

European Parliament amendments

These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.

More filters

Alternative wording Amendment 923 · Axel Voss ITRE · LIBE
No-1 equivalentArticle 2 is amended by adding the following paragraph:
4a. Articles [19, 20, 27, 30, 35 to 39] of this Regulation do not apply to small controllers."
Justification

RISK-BASED APPROACH #4: This package makes the GDPR’s risk-based approach practical by introducing objective categories for small, medium and large controllers. Small controllers with limited, non-core processing receive relief from selected administrative duties, while data-subject rights and enforcement remain intact. Very large controllers, gatekeepers and VLOPs/VLOSEs face stronger transparency, annual certification and closer supervision. Compliance effort is thus reduced where risks are low and increased where scale and systemic impact are greatest.

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph -1 (new) / Regulation (EU) 2016/679 / Article 2 – paragraph 4a

Alternative wording Amendment 924 · Axel Voss ITRE · LIBE
-1 a In Article 2, four new points are added to paragraph 2:
2. This Regulation does not apply to the processing of personal data: (a) in the course of an activity which falls outside the scope of Union law; (b) by the Member States when carrying out activities which fall within the scope of Chapter 2 of Title V of the TEU; (c) by a natural person in the course of a purely personal or household activity; (d) by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security; (da) by natural or legal persons for non-professional or non-commercial purposes; (db) in the course of an activity that is likely to result in a low risk to the rights and freedoms of natural persons; (dc) by micro, small and medium-sized enterprises; (dd) which is of a purely incidental or transitory nature and is carried out for a purpose unrelated to the data subject as an identified or identifiable natural person."
Justification

SCOPE EXCLUSION #1: This amendment offers an alternative to the proposed risk-based simplification package by excluding non-commercial, low-risk, SME and purely incidental processing from the GDPR’s full scope. It does not deregulate such processing: Member States must ensure protection through other suitable laws, including private-life, contract, consumer, labour, tort, unfair-competition and criminal law. This reduces disproportionate administrative burdens, supports data flows and focuses GDPR enforcement on processing that creates real risks for individuals.

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph -1 a (new) / Regulation (EU) 2016/679 / Article 2 – paragraph 2

Alternative wording Amendment 925 · Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec ITRE · LIBE
-1 a Article 2 is replaced by the following:
"Material scope 1. This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system. 2. This Regulation does not apply to the processing of personal data: (a)in the course of an activity which falls outside the scope of Union law; (b)by the Member States when carrying out activities which fall within the scope of Chapter 2 of Title V of the TEU; (c)by a natural person in the course of a purely personal or household activity; (d)by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security. 3. For the processing of personal data by the Union institutions, bodies, offices and agencies, Regulation (EC) No 45/2001 applies. Regulation (EC) No 45/2001 and other Union legal acts applicable to such processing of personal data shall be adapted to the principles and rules of this Regulation in accordance with Article 98. 3a. This Regulation applies to the storing of information, or gaining of access to information already stored, in terminal equipment of users. 4. This Regulation shall be without prejudice to the application of Directive 2000/31/EC, in particular of the liability rules of intermediary service providers in Articles 12 to 15 of that Directive."
Justification

This change is proposed due to other amendments tabled moving e-privacy provisions under Regulation (EU) 2016/679.

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph -1 a (new) / Regulation (EU) 2016/679 / Article 2

Additional proposed wording Amendment 926 · Axel Voss ITRE · LIBE

– In Article 2, a new paragraph is added after paragraph 4

Justification

SCOPE EXCLUSION #2: This amendment offers an alternative to the proposed risk-based simplification package by excluding non-commercial, low-risk, SME and purely incidental processing from the GDPR’s full scope. It does not deregulate such processing: Member States must ensure protection through other suitable laws, including private-life, contract, consumer, labour, tort, unfair-competition and criminal law. This reduces disproportionate administrative burdens, supports data flows and focuses GDPR enforcement on processing that creates real risks for individuals.

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point -1 (new) / Regulation (EU) 2016/679 / Article 2 – paragraph 4 (new)

Additional proposed wording Amendment 1596 · Angelika Niebler, Monika Hohlmeier ITRE · LIBE

The following point (da) is added to Article 2(2)

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – subparagraph 1 (new) / Regulation (EU) 2016/679 / Article 2 – paragraph 2 – point da (new)

Additional proposed wording Amendment 1601 · Andrea Wechsler, Marie-Sophie Lanig, Stefan Köhler, Alexandra Mehnert, Lena Düpont, Angelika Niebler, Verena Mertens, Christian Doleschal, Sabine Verheyen ITRE · LIBE

In Article 2, the following point e is added:

'(e) by associations, foundations and other non-profit organisations established in the Union, where the processing is carried out solely in the course of their statutory non-commercial activities and is limited to the administration of members, former members, volunteers, donors or beneficiaries, provided that such processing does not involve systematic monitoring or processing likely to result in a high risk to the rights and freedoms of natural persons within the meaning of Article 35, and that the personal data are not disclosed to third parties for commercial purposes.'

Context reproduced in the official amendment

The amendment reproduces a wider legal passage. It is shown as context because it does not cover the same legal unit as the proposed wording.

Justification

Associations, foundations and other non-profit organisations generally process personal data within clear, direct and non-commercial relationships with their members, volunteers, donors or beneficiaries. Subjecting such limited and low-risk processing to the full scope of Regulation (EU) 2016/679 places a disproportionate administrative burden on civil-society and volunteer-based organisations, many of which lack dedicated compliance structures. This targeted exclusion complements the specific simplifications proposed for Articles 13, 14 and 30, while preserving the application of the Regulation to systematic monitoring, automated decision-making, high-risk processing and the commercial disclosure of personal data.

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 c (new) / Regulation (EU) 2016/679 / Article 2 – paragraph 2 – point e (new)