GDPR · Regulation (EU) 2016/679
Article 29a
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 1 part · 0 Council drafts · 1 Parliament amendment
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to GDPRThe wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to these tracked parts.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Additional proposed wording Amendment 1169 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay ITRE · LIBE
7b. The following article is added
Article 29a
Application of pseudonymisation and identification of a natural person :
Controllers and processors may apply pseudonymisation in order to reduce the risks to the data subjects concerned and to comply with their obligations under this Regulation, in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information. The Commission may adopt implementing acts to specify means and criteria to determine whether a natural person is identifiable, including through personal data having undergone data resulting from pseudonymisation, account shall be taken of all the means reasonably likely to be used, such as singling out or online identifiers, either by the controller or by another person to identify the natural person directly or indirectly no longer constitutes personal data for certain entities.
The application of pseudonymisation to personal data may, depending on the circumstances of the case and provided that appropriate technical and organisational measures are put in place and are such as to prevent the data in question from being attributed to the data subject, effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable.
Where a person other than the controller referred to in paragraph 2 discloses, transmits or otherwise makes such data available to a third party and it cannot be ruled out that this third party possesses or can obtain means reasonably likely to enable the data subject to be identified, both the transmission of the data to this third party and the subsequent processing of the data by this third party is to be considered as processing of data relating to an identifiable natural person.
Context reproduced in the official amendment
The amendment reproduces a wider legal passage. It is shown as context because it does not cover the same legal unit as the proposed wording.
(new)
against:
Article 29a
Application of pseudonymisation and identification of a natural person :
- 1.
Controllers and processors may apply pseudonymisation in order to reduce the risks to the data subjects concerned and to comply with their obligations under this Regulation, in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information. The Commission may adopt implementing acts to specify means and criteria to determine whether a natural person is identifiable, including through personal data having undergone data resulting from pseudonymisation, account shall be taken of all the means reasonably likely to be used, such as singling out or online identifiers, either by the controller or by another person to identify the natural person directly or indirectly no longer constitutes personal data for certain entities.
- 2.
The application of pseudonymisation to personal data may, depending on the circumstances of the case and provided that appropriate technical and organisational measures are put in place and are such as to prevent the data in question from being attributed to the data subject, effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable.
- 3.
Where a person other than the controller referred to in paragraph 2 discloses, transmits or otherwise makes such data available to a third party and it cannot be ruled out that this third party possesses or can obtain means reasonably likely to enable the data subject to be identified, both the transmission of the data to this third party and the subsequent processing of the data by this third party is to be considered as processing of data relating to an identifiable natural person.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.