Digital Omnibus tracker

GDPR · Regulation (EU) 2016/679

Article 25

Compare the available Commission, Council and Parliament texts and amendments affecting this article.

Article total: 6 parts · 4 Council drafts · 3 Parliament amendments

Removed wording is struck through; added or replacement wording is highlighted.

Institutional text

European Commission proposal

All Commission’s changes to GDPR

The wording proposed by the Commission at the start of this legislative file.

No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.

Institutional text

Council Presidency texts

Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.

Article 25(1)

May Presidency compromise

Article 25(2)

May Presidency compromise

Competing proposals

European Parliament amendments

These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.

More filters

Additional proposed wording Amendment 1160 · Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller, Christophe Grudler ITRE · LIBE
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 7 a (new) / Regulation (EU) 2016/679 / Article 25 – paragraphs 1 and 2

Additional proposed wording Amendment 1170 · Axel Voss ITRE · LIBE
Justification

Certified PETs make data protection by design operational. Technologies such as differential privacy, homomorphic encryption, synthetic data and robust pseudonymisation reduce identifiability and support data minimisation while enabling data-driven innovation and AI. A rebuttable presumption under Article 5(1)(c) creates a real incentive to deploy certified PETs without exempting controllers from other GDPR duties. Commission-set, technology-neutral standards and benchmarks prevent PET-washing and support interoperable European privacy infrastructure.

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 7 b (new) / Regulation (EU) 2016/679 / Article 25 – paragraphs 3a, 3b (new)

Additional proposed wording Amendment 1173 · Axel Voss ITRE · LIBE

7c. In Article 25, the following paragraph 2a is added:

In the case of processing carried out in the course of providing information society services which are likely to be accessed by children, when assessing what are appropriate technical and organisational measures in accordance with paragraph 1, the controller must take into account the children’s higher protection matters. The children’s higher protection matters are:

This paragraph is not to be read as implying anything about the matters that may be relevant to the assessment of what are appropriate technical and organisational measures for the purposes of paragraph 1 and 2 in cases other than those described in this paragraph. In this paragraph “information society services” does not include preventive or counselling services."

Justification

The amendment makes children’s higher protection needs a concrete part of data protection by design for information society services likely to be accessed by children. Controllers must consider how children can best be protected and supported, including their lower awareness of risks and their different needs at different ages and development stages. This creates clearer duties without a one-size-fits-all model, preserves other Article 25 assessments and excludes preventive or counselling services.

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 7 c (new) / Regulation (EU) 2016/679 / Article 25 – paragraph 2a (new)