GDPR · Regulation (EU) 2016/679
Article 25a
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 1 part · 0 Council drafts · 1 Parliament amendment
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to GDPRThe wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to these tracked parts.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Additional proposed wording Amendment 1159 · Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Andrea Wechsler, Henrik Dahl, Oliver Schenk, Pekka Toveri, Christian Ehler ITRE · LIBE
7a. The following Article 25a is added
Article 25a
Privacy Enhancing Technologies
The Commission may adopt implementing acts to lay down technical specifications for Privacy Enhancing Technologies (PETs), including pseudonymisation, anonymisation and cryptographic techniques. These specifications shall serve to establish standardised technical and organisational measures that assist controllers and processors in ensuring and demonstrating that their data processing operations adhere to high data protection standards. ·
The implementing acts referred to in paragraph 1 may establish technical specifications regarding:
Pseudonymisation and Anonymisation: standards for state-of-the-art cryptographic techniques that can effectively reduce or eliminate the linkability of personal data;
Technical criteria for legal bases: specifications defining the technical parameters for assisting controllers in verifying whether the criteria for legal bases, including further processing, under Article 6(1) may be met;
Risk-mitigation: technical standards controllers may use when assessing risks to the rights and freedoms of natural persons, including criteria for further simplified data protection impact assessments under Article 35(10); · (d) Security measures: technical specifications for state-of-the-art security measures, including end-to-end encryption and decentralised architectures, to ensure a level of security appropriate to the risk pursuant to Article 32. ·
When preparing the implementing acts, the Commission shall, in accordance with Article 10 of Regulation (EU) No 1025/2012, mandate one or more European standardisation organisations to draw up harmonised standards for the types of standards referred to in paragraph 2. The European standardisation organisations shall, where appropriate, take into account existing international standards developed by international standardisation organisations, as well as emerging technical specifications developed by relevant industry consortia. The mandate shall specify a time limit of not more than 18 months from the date of the mandate. When drawing up the standardisation mandate, the Commission shall consult the European Data Protection Board and an advisory forum comprising representatives of industry, SMEs, consumer protection organisations, academia and civil society. The Commission shall condition such mandates on the standardisation organisations ensuring balanced representation and equal participation of industry, SMEs, consumer protection organisations, academia and civil society, and supervisory authorities within the technical committees, and shall provide financial support to facilitate their involvement. The Commission shall monitor the progress of the standardisation work and may, where necessary, initiate the preparation of common specifications in accordance with paragraph 7.
The Commission shall closely involve the EDPB in the preparations of the implementing acts. The EPDB shall issue an opinion on the draft implementing acts within a deadline of 8 weeks as of the receipt of the draft from the Commission. Where data complies with the harmonised standards or parts thereof referred to in paragraph 2(a), the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, it shall be presumed that the data satisfies the criteria for effective pseudonymisation or anonymisation.
Where data processing operations comply with the harmonised standards or parts thereof referred to in paragraph 2(b), (c) or (d), the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, it shall be presumed that the controller or processor has fulfilled the corresponding technical and organisational requirements of this Regulation covered by those standards, ·
Controllers and processors relying on the presumption under paragraphs 4 or 5 shall document compliance with the relevant standards by means of appropriate evidence. The evidence shall include at minimum:
technical documentation describing the implementation of the PET; ·
a description of the parameters and configurations used to meet the standard requirements;
results of tests and validations demonstrating the effectiveness of the
a risk analysis demonstrating that the
freedoms of data subjects to an appropriate level;
in the case of pseudonymisation standards: evidence that the means to identify the data subject cannot reasonably be used.
The Commission may adopt implementing acts laying down certification procedures and audit requirements for compliance with the standards referred to in paragraph 2. Such procedures may provide for:
certification by accredited bodies;
self-certification under certain conditions;
regular audits by independent third parties;
peer-review procedures for complex implementations. Certification pursuant to this paragraph shall be without prejudice to the documentation obligations laid down in paragraph 6. Where a controller or processor holds a valid certificate pursuant to this paragraph, the documentation requirements under paragraph 6 shall be considered fulfilled to the extent that the certificate covers the same technical elements.
The Commission may adopt implementing acts laying down common specifications where:
the Commission has mandated one or more European standardisation organisations to draw up harmonised standards for the purposes referred to in paragraph 2 and;
the mandate was not accepted within 6 months from the date of the mandate or;
the harmonised standards were not drawn up within the time limit set or;
the harmonised standards do not comply with the mandate or do not sufficiently address concerns in relation to fundamental rights;
or (b) where, in view of the urgency of the matter or the need to ensure a high level of data protection, the Commission considers it necessary to adopt common specifications without awaiting the outcome of the standardisation process.
Common specifications adopted pursuant to this paragraph shall prevail over conflicting harmonised standards until such time as a reference to harmonised standards is published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012.
The implementing acts referred to in paragraphs 1 and 7 shall take account of the state of the art, implementation costs, the nature, scope, context and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons resulting from the processing. They shall ensure that the technologies are open, non-discriminatory and interoperable.
The Commission shall review regularly the need to update the implementing acts, taking into account technical progress and developments in international standards.
The Implementing Acts shall be adopted in accordance with the examination procedure referred to in Article 93(3).
against:
Article 25a
Privacy Enhancing Technologies
- 1.
The Commission may adopt implementing acts to lay down technical specifications for Privacy Enhancing Technologies (PETs), including pseudonymisation, anonymisation and cryptographic techniques. These specifications shall serve to establish standardised technical and organisational measures that assist controllers and processors in ensuring and demonstrating that their data processing operations adhere to high data protection standards. ·
- 2.
The implementing acts referred to in paragraph 1 may establish technical specifications regarding:
- (a)
Pseudonymisation and Anonymisation: standards for state-of-the-art cryptographic techniques that can effectively reduce or eliminate the linkability of personal data;
- (b)
Technical criteria for legal bases: specifications defining the technical parameters for assisting controllers in verifying whether the criteria for legal bases, including further processing, under Article 6(1) may be met;
- (c)
Risk-mitigation: technical standards controllers may use when assessing risks to the rights and freedoms of natural persons, including criteria for further simplified data protection impact assessments under Article 35(10); · (d) Security measures: technical specifications for state-of-the-art security measures, including end-to-end encryption and decentralised architectures, to ensure a level of security appropriate to the risk pursuant to Article 32. ·
- (a)
- 3.
When preparing the implementing acts, the Commission shall, in accordance with Article 10 of Regulation (EU) No 1025/2012, mandate one or more European standardisation organisations to draw up harmonised standards for the types of standards referred to in paragraph
- 2.
The European standardisation organisations shall, where appropriate, take into account existing international standards developed by international standardisation organisations, as well as emerging technical specifications developed by relevant industry consortia. The mandate shall specify a time limit of not more than 18 months from the date of the mandate. When drawing up the standardisation mandate, the Commission shall consult the European Data Protection Board and an advisory forum comprising representatives of industry, SMEs, consumer protection organisations, academia and civil society. The Commission shall condition such mandates on the standardisation organisations ensuring balanced representation and equal participation of industry, SMEs, consumer protection organisations, academia and civil society, and supervisory authorities within the technical committees, and shall provide financial support to facilitate their involvement. The Commission shall monitor the progress of the standardisation work and may, where necessary, initiate the preparation of common specifications in accordance with paragraph 7.
- 4.
The Commission shall closely involve the EDPB in the preparations of the implementing acts. The EPDB shall issue an opinion on the draft implementing acts within a deadline of 8 weeks as of the receipt of the draft from the Commission. Where data complies with the harmonised standards or parts thereof referred to in paragraph 2(a), the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, it shall be presumed that the data satisfies the criteria for effective pseudonymisation or anonymisation.
- 5.
Where data processing operations comply with the harmonised standards or parts thereof referred to in paragraph 2(b), (c) or (d), the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, it shall be presumed that the controller or processor has fulfilled the corresponding technical and organisational requirements of this Regulation covered by those standards, ·
- 6.
Controllers and processors relying on the presumption under paragraphs 4 or 5 shall document compliance with the relevant standards by means of appropriate evidence. The evidence shall include at minimum:
- (a)
technical documentation describing the implementation of the PET; · (b) a description of the parameters and configurations used to meet the standard requirements;
- (c)
results of tests and validations demonstrating the effectiveness of the (d) a risk analysis demonstrating that the freedoms of data subjects to an appropriate level;
- (e)
in the case of pseudonymisation standards: evidence that the means to identify the data subject cannot reasonably be used.
- (a)
- 7.
The Commission may adopt implementing acts laying down certification procedures and audit requirements for compliance with the standards referred to in paragraph
- 2.
Such procedures may provide for:
- (a)
certification by accredited bodies;
- (b)
self-certification under certain conditions;
- (c)
regular audits by independent third parties;
- (d)
peer-review procedures for complex implementations. Certification pursuant to this paragraph shall be without prejudice to the documentation obligations laid down in paragraph
- (a)
- 6.
Where a controller or processor holds a valid certificate pursuant to this paragraph, the documentation requirements under paragraph 6 shall be considered fulfilled to the extent that the certificate covers the same technical elements.
- 8.
The Commission may adopt implementing acts laying down common specifications where:
- (a)
the Commission has mandated one or more European standardisation organisations to draw up harmonised standards for the purposes referred to in paragraph 2 and;
- (i)
the mandate was not accepted within 6 months from the date of the mandate or;
- (ii)
the harmonised standards were not drawn up within the time limit set or;
- (iii)
the harmonised standards do not comply with the mandate or do not sufficiently address concerns in relation to fundamental rights; or
- (b)
where, in view of the urgency of the matter or the need to ensure a high level of data protection, the Commission considers it necessary to adopt common specifications without awaiting the outcome of the standardisation process. Common specifications adopted pursuant to this paragraph shall prevail over conflicting harmonised standards until such time as a reference to harmonised standards is published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012.
- (a)
- 9.
The implementing acts referred to in paragraphs 1 and 7 shall take account of the state of the art, implementation costs, the nature, scope, context and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons resulting from the processing. They shall ensure that the technologies are open, non-discriminatory and interoperable.
- 10.
The Commission shall review regularly the need to update the implementing acts, taking into account technical progress and developments in international standards.
- 11.
The Implementing Acts shall be adopted in accordance with the examination procedure referred to in Article 93(3).
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.