GDPR · Regulation (EU) 2016/679
Article 30
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 2 parts · 0 Council drafts · 2 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to GDPRThe wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to these tracked parts.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Additional proposed wording Amendment 1165 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay ITRE · LIBE
In Article 30, paragraph 1, the following point ga is added
where personal data are collected from a third party, purchased, aggregated, enriched, sold or otherwise made available to third parties for commercial purposes, the categories of data providers and of data recipients, the categories of data concerned, the purposes pursued, the legal basis relied upon, and the elements demonstrating the lawful origin of the data and of their making available.
The identity of the providers and recipients concerned shall be retained by the controller and made available to the supervisory authority upon request."
Context reproduced in the official amendment
The amendment reproduces a wider legal passage. It is shown as context because it does not cover the same legal unit as the proposed wording.
(new)
against:
Article 30
Records of processing activities
- 1.
Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility. That record shall contain all of the following information:
- (a)
the name and contact details of the controller and, where applicable, the joint controller, the controller's representative and the data protection officer;
- (b)
the purposes of the processing;
- (c)
a description of the categories of data subjects and of the categories of personal data;
- (d)
the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or international organisations;
- (e)
where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards;
- (f)
where possible, the envisaged time limits for erasure of the different categories of data;
- (g)
where possible, a general description of the technical and organisational security measures referred to in Article 32(1).
- (ga)
where personal data are collected from a third party, purchased, aggregated, enriched, sold or otherwise made available to third parties for commercial purposes, the categories of data providers and of data recipients, the categories of data concerned, the purposes pursued, the legal basis relied upon, and the elements demonstrating the lawful origin of the data and of their making available.
The identity of the providers and recipients concerned shall be retained by the controller and made available to the supervisory authority upon request."
- (a)
- 2.
Each processor and, where applicable, the processor's representative shall maintain a record of all categories of processing activities carried out on behalf of a controller, containing:
- (a)
the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller's or the processor's representative, and the data protection officer;
- (b)
the categories of processing carried out on behalf of each controller;
- (c)
where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards;
- (d)
where possible, a general description of the technical and organisational security measures referred to in Article 32(1).
- (a)
- 3.
The records referred to in paragraphs 1 and 2 shall be in writing, including in electronic form.
- 4.
The controller or the processor and, where applicable, the controller's or the processor's representative, shall make the record available to the supervisory authority on request.
- 5.
The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.
Additional proposed wording Amendment 1600 · Andrea Wechsler, Marie-Sophie Lanig, Stefan Köhler, Alexandra Mehnert, Lena Düpont, Angelika Niebler, Verena Mertens, Christian Doleschal, Sabine Verheyen ITRE · LIBE
In Article 30, paragraph 5a is added
Paragraphs 1-4 shall not apply to associations, foundations, and other non-profit organisations whose processing activities are limited to the purposes described in Article 13(6).
Context reproduced in the official amendment
The amendment reproduces a wider legal passage. It is shown as context because it does not cover the same legal unit as the proposed wording.
Article 30 Records of processing activities 1. Each controller and, where applicable, the controller's represen tative, shall maintain a record of processing activities under its respon sibility. That record shall contain all of the following information:
the name and contact details of the controller and, where applicable, the joint controller, the controller's representative and the data protection officer; (b) the purposes of the processing; (c) a description of the categories of data subjects and of the categories of personal data; (d) the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or inter national organisations;
where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the docu mentation of suitable safeguards; (f) where possible, the envisaged time limits for erasure of the different categories of data; (g) where possible, a general description of the technical and organisa tional security measures referred to in Article 32(1). 2. Each processor and, where applicable, the processor's representa tive shall maintain a record of all categories of processing activities carried out on behalf of a controller, containing: (a) the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller's or the processor's represen tative, and the data protection officer; (b) the categories of processing carried out on behalf of each controller; (c) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the docu mentation of suitable safeguards; B (d) where possible, a general description of the technical and organisa tional security measures referred to in Article 32(1). 3. The records referred to in paragraphs 1 and 2 shall be in writing, including in electronic form. 4. The controller or the processor and, where applicable, the controller's or the processor's representative, shall make the record available to the supervisory authority on request. 5. The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.
Justification
Record-keeping obligations under Article 30 should be proportionate to the actual risk of the processing activity. Small non-profit organisations, associations and foundations often lack dedicated compliance structures and process data only for limited internal administrative purposes. Requiring full records of processing activities in such low-risk cases creates administrative burdens without a corresponding benefit for data subjects. This amendment clarifies that the exemption applies to non-profit organisations where processing is limited to the purposes set out in Article 13(6), while preserving the full obligation where processing is likely to result in a high risk to the rights and freedoms of data subjects.
against:
Article 30
Records of processing activities
- 1.
Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility. That record shall contain all of the following information:
- (a)
the name and contact details of the controller and, where applicable, the joint controller, the controller's representative and the data protection officer;
- (b)
the purposes of the processing;
- (c)
a description of the categories of data subjects and of the categories of personal data;
- (d)
the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or international organisations;
- (e)
where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards;
- (f)
where possible, the envisaged time limits for erasure of the different categories of data;
- (g)
where possible, a general description of the technical and organisational security measures referred to in Article 32(1).
- (a)
- 2.
Each processor and, where applicable, the processor's representative shall maintain a record of all categories of processing activities carried out on behalf of a controller, containing:
- (a)
the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller's or the processor's representative, and the data protection officer;
- (b)
the categories of processing carried out on behalf of each controller;
- (c)
where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards;
- (d)
where possible, a general description of the technical and organisational security measures referred to in Article 32(1).
- (a)
- 3.
The records referred to in paragraphs 1 and 2 shall be in writing, including in electronic form.
- 4.
The controller or the processor and, where applicable, the controller's or the processor's representative, shall make the record available to the supervisory authority on request.
- 5.
The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.
- 5a.
Paragraphs 1-4 shall not apply to associations, foundations, and other non-profit organisations whose processing activities are limited to the purposes described in Article 13(6).
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.