Digital Omnibus tracker

GDPR · Regulation (EU) 2016/679

Article 31

Compare the available Commission, Council and Parliament texts and amendments affecting this article.

Article total: 1 part · 0 Council drafts · 1 Parliament amendment

Removed wording is struck through; added or replacement wording is highlighted.

Institutional text

European Commission proposal

All Commission’s changes to GDPR

The wording proposed by the Commission at the start of this legislative file.

No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.

Institutional text

Council Presidency texts

Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.

No Council wording is mapped to these tracked parts.

Competing proposals

European Parliament amendments

These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.

More filters

Additional proposed wording Amendment 1164 · Axel Voss ITRE · LIBE

7a. In Article 31, the following paragraph is added:

Large controllers shall report all information complied under Article 13(1f2) and 14(1f2) and the certification under Article 42, as well as any other information the supervisory authority may specify, to the supervisory authority at their main establishment or the main establishment of their representative under Article 27. The information shall be provided no later than one month after the end for their financial year in a machine-readable format specified by the supervisory authority. The supervisory authorities shall compile and keep up to date a public national list of all large controllers, including their address, contact details, number of data subjects processed in the last three financial years, the certification body that most recently certified them, number of procedures under Article 77 and 79 and a link to the information published under Article 13 and 14."

Justification

RISK-BASED APPROACH #10: This package makes the GDPR’s risk-based approach practical by introducing objective categories for small, medium and large controllers. Small controllers with limited, non-core processing receive relief from selected administrative duties, while data-subject rights and enforcement remain intact. Very large controllers, gatekeepers and VLOPs/VLOSEs face stronger transparency, annual certification and closer supervision. Compliance effort is thus reduced where risks are low and increased where scale and systemic impact are greatest.

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 7 a (new) / Regulation (EU) 2016/679 / Article 31 – paragraph 1a (new)