Digital Omnibus tracker

GDPR · Regulation (EU) 2016/679

Article 33

Compare the available Commission, Council and Parliament texts and amendments affecting this article.

Article total: 7 parts · 4 Council drafts · 42 Parliament amendments

Removed wording is struck through; added or replacement wording is highlighted.

Institutional text

European Commission proposal

All Commission’s changes to GDPR

The wording proposed by the Commission at the start of this legislative file.

Full article with Commission changes

Article with proposed changes

Official consolidated text dated 4 May 2016, with all 4 Commission proposal changes affecting this article applied.

Article 33

Notification of a personal data breach to the supervisory authority

  1. 1.

    In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 7296 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedomsArticle of natural persons56. Where the notification to the supervisory authority is not made within 7296 hours, it shall be accompanied by reasons for the delay.

  2. 1a.

    Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.

  3. 2.

    The processor shall notify the controller without undue delay after becoming aware of a personal data breach.

  4. 3.

    The notification referred to in paragraph 1 shall at least:

    1. (a)

      describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;

    2. (b)

      communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;

    3. (c)

      describe the likely consequences of the personal data breach;

    4. (d)

      describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

  5. 4.

    Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.

  6. 5.

    The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.

  7. 6.

    The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).

  8. 7.

    The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.

Commission source wording and instructions

Article 33(1)

Commission proposal

1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.

Article 33(1a)

Commission proposal

1a. Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.

Article 33(6)

Commission proposal

6. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).

Article 33(7)

Commission proposal

7. The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.

Institutional text

Council Presidency texts

Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.

Article 33(1)

May Presidency compromise

Council wording reconstructed for this provision from the official operation

Article 33(1a)

May Presidency compromise

Council wording reconstructed for this provision from the official operation

1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.

Article 33(6)

May Presidency compromise

Council wording reconstructed for this provision from the official operation

6. The Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The template and lists shall be available within [OP date = nine months of the entry into application of this Regulation]. The Commission may adopt the template as established by the Board by way of an implementing act, in accordance with the examination procedure set out in Article 93(2).

Article 33(7)

May Presidency compromise

Council wording reconstructed for this provision from the official operation

7. The template and lists referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Commission may adopt any updates of the template by way of an implementing act following the procedure referred to in paragraph 6.

Competing proposals

European Parliament amendments

These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.

More filters

Political group at the amendment date where available; otherwise the current Parliament affiliation.

Alternative wording Amendment 54 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
Preview
against:
Alternative wording Amendment 55 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
1a. Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
Preview
against:
Alternative wording Amendment 56 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
6. TheBy …[PO please insert date: nine months from the entry into application of this amending Regulation] the Board shall prepareestablish and transmitmake to the Commission a proposal forpublic a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposalsCommission shallmay be submitted toadopt the Commissiontemplate withinas [OPestablished date = nine months ofby the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt itBoard by way of an implementing act in accordance with the examination procedure set out in Article 93(2) of this Regulation.
Preview
against:
Alternative wording Amendment 57 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
7. The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The BoardCommission shallmay submitadopt its assessment and possible proposals fornecessary updates to the Commission in due time. The Commission after due consideration of the proposalstemplate reviewsby themway andof isan empoweredimplementing to adopt any updatesact following the procedure referred to in paragraph 6.
Preview
against:
Alternative wording Amendment 108 IMCO draft opinion · Alex Agius Saliba (rapporteur)
6. The Board shall prepare, make public and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
Preview
against:
Alternative wording Amendment 109 IMCO draft opinion · Alex Agius Saliba (rapporteur)
7. The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission aftershall duetake considerationutmost account of the proposalsBoard's reviews them and is empowered to adopt any updates following the procedure in paragraph 6assessment.
Preview
against:
Additional proposed wording Amendment 110 IMCO draft opinion · Alex Agius Saliba (rapporteur)
Preview
against:
Alternative wording Amendment 251 · Daniel Buda JURI
(1) In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entryelectronic channel made available by the competent supervisory authority or, if the competent Member State has so decided, via a national contact point establishedor pursuantan tointerface interoperable with the framework provided for in Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.’
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 (GDPR) / Article 33 – paragraph 1

Alternative wording Amendment 252 · Ton Diepeveen, Pascale Piera JURI
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entrysingle pointintegrated establishednational pursuantreporting to Article 23a of Directive (EU) 2022/2555portal to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
Preview
against:
Source identification

The literal header reads Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 / Article 3 – paragraph 1 – point 8 – point a. Its amended-law locator is inconsistent with the base column, but the proposal operation and matching base text support Regulation (EU) 2016/679 Article 33(1). The literal header remains visible and the target is labelled as an inference.

Header printed in the source: Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 / Article 3 – paragraph 1 – point 8 – point a

Alternative wording Amendment 253 · Daniel Buda JURI
1a. Until the establishment and testing of the single-entryinteroperable pointframework pursuantprovided tofor in Article 23a of Directive (EU) 2022/2555 and until the applicable channel is designated by the competent Member State, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.’
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point b / 2016/679 (GDPR) / Article 33 – paragraph 1 a

Alternative wording Amendment 254 · Ton Diepeveen, Pascale Piera JURI
1a. Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
Preview
against:
Source identification

The literal header reads Article 3 – paragraph 1 – point 8 – point b / Regulation (EU) 2016/679 / Article 3 – paragraph 1 – point 8 – point b. Its amended-law locator is inconsistent with the base column, but the proposal operation and matching base text support Regulation (EU) 2016/679 Article 33(1a). The literal header remains visible and the target is labelled as an inference.

Header printed in the source: Article 3 – paragraph 1 – point 8 – point b / Regulation (EU) 2016/679 / Article 3 – paragraph 1 – point 8 – point b

Alternative wording Amendment 384 · Virginie Joron IMCO
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via theits single-entrynational point of entry established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.; Controllers shall continue to document breaches which are not notified, including the facts relating to the personal data breach, its effects and the remedial action taken.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 / Article 33 – paragraph 1

Remove proposed wording Amendment 385 · Virginie Joron IMCO
(b) the following paragraph is added: 1a. Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.’
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point b / Regulation (EU) 2016/679 / Article 33 – paragraphe 1 a

Deletion marker printed in the source: deleted

Alternative wording Amendment 386 · Virginie Joron IMCO
6. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviewsrefers itthem to the Board so that the latter can review them, as necessary, and is empowered to adopt itthem by way of an implementing act in accordance with the examination procedure set out in Article 93(2). If the Commission departs from the proposal submitted by the Board, it shall set out the reasons for doing so. These reasons shall be made public at the same time as the implementing act.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point c / Regulation (EU) 2016/679 / Article 33 – paragraph 6

Alternative wording Amendment 387 · Arba Kokalari IMCO
6. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). This shall not go beyond existing obligations under this Regulation or mandate any retroactive obligations.
Source identification

The literal header reads Article 3 – paragraph 1 – point 8 – point c / Regulation (EU) 2016/679 / Article 35 – paragraph 6a. Its amended-law locator is inconsistent with the base column, but the proposal operation and matching base text support Regulation (EU) 2016/679 Article 33(6). The literal header remains visible and the target is labelled as an inference.

Header printed in the source: Article 3 – paragraph 1 – point 8 – point c / Regulation (EU) 2016/679 / Article 35 – paragraph 6a

Alternative wording Amendment 388 · Virginie Joron IMCO
7. The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6. If the Commission departs from the Board’s proposed updates, it shall set out the reasons for doing so, and these reasons shall be made public at the same time as the adopted updates.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point c / Regulation (EU) 2016/679 / Article 33 – paragraph 7

Additional proposed wording Amendment 389 · David Cormand on behalf of the Verts/ALE Group IMCO
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point c / Regulation (EU) 2016/679 / Article 33

Alternative wording Amendment 1176 · Markus Buchheit ITRE · LIBE
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach viato the single-entrycompetent pointsupervisory establishedauthority. Notifications pursuant to this Article 23ashall ofbe Directive (EU) 2022/2555made to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority of the Member State in which the controller is notestablished madeor withinwhere 96the hours,personal itdata breach has occurred. The use of any Union-level technical reporting tools or single-entry points shall remain voluntary and shall be accompaniedlimited byto reasonspersonal fordata thebreaches delaywith clear cross-border or Union-wide systemic relevance, without prejudice to national notification channels.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 / Article 33 – paragraph 1

Alternative wording Amendment 1177 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via thetheir national single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay. Controllers shall continue to document non-notified breaches, including the facts relating to the personal data breach, its effects and the remedial action taken.
Justification

The controller documents every personal data breach, including those which are not notified. The documentation comprises the facts relating to the breach, its effects and the remedial action taken, and enables the supervisory authority to verify compliance in the course of an inspection.

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 (GDPR) / Article 33 – Paragraph 1

Alternative wording Amendment 1178 · Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller, Christophe Grudler ITRE · LIBE
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, in which case particular consideration shall be given to the risk to children, the controller shall without undue delay and, where feasible, not later than 9672 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 9672 hours, it shall be accompanied by reasons for the delay.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 / Article 33 – paragraph 1

Alternative wording Amendment 1179 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entrynational entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 / Article 33 – paragraph 1

Alternative wording Amendment 1180 · Niels Flemming Hansen ITRE · LIBE
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entrynational entry point established pursuant to Article 23a23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 / Article 33 paragraph 1

Alternative wording Amendment 1181 · Henrik Dahl ITRE · LIBE
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entrynational entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 / Article 33 – paragraph 1

Alternative wording Amendment 1182 · Francesco Torselli ITRE · LIBE
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96four hoursworking days after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96four hoursworking days, it shall be accompanied by reasons for the delay. (We do not intend to propose to change the timing which remains exactly the same, but only to express it in working days, therefore starting from Monday in the event that an accident occurs on Saturday or Sunday.)
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 / Article 33 – paragraph 1

Alternative wording Amendment 1183 · Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec ITRE · LIBE
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 9672 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 9672 hours, it shall be accompanied by reasons for the delay.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 / Article 33 – paragraph 1

Alternative wording Amendment 1184 · Pernando Barrena Arza ITRE · LIBE
1. In the case of a personal data breach that is likely to result in aan highincreased risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
Justification

The threshold for the obligation to notify the supervisory authority should be lower that the threshold to communicate a personal data breach to the data subject, since controllers generally are incentivised to avoid the communication of a personal data breach to the affected data subject. This tendency to avoid such communication could influence the respective assessment by the controller. While it makes sense to increase the threshold and avoid that supervisory authorities are swamped with personal data breach notifications regarding every incident, it is important that the supervisory authority is informed about the more severe incidents and can also re-asses the controllers risk assessment. In such cases, the supervisory authority could require the controller to communicate the personal data breach to the affected data subjects even if the controller’s initial assessment result in no high risk. This process is stipulated in Article 33(4) GDPR which would basically lose its purpose in case the threshold of Article 33 (notification of a personal data breach to the supervisory authority) would be increased to the threshold of Article 34 GDPR (communication of a personal data breach to the data subjects).

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 / Article 33 – paragraph 1

Alternative wording Amendment 1185 · Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba ITRE · LIBE
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 9672 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 9672 hours, it shall be accompanied by reasons for the delay.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 / Article 33 – paragraph 1

Alternative wording Amendment 1186 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 9672 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 9672 hours, it shall be accompanied by reasons for the delay.
Justification

NIS2, where the single-entry point is established, also only has 72 hours. One aim of simplification is to have harmonised rules.

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 / Article 33 – paragraph 1

Alternative wording Amendment 1187 · Alex Agius Saliba ITRE · LIBE
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 9672 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 9672 hours, it shall be accompanied by reasons for the delay.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 / Article 33 – paragraph 1

Alternative wording Amendment 1188 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 9672 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 9672 hours, it shall be accompanied by reasons for the delay.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point a / Regulation (EU) 2016/679 / Article 33 – paragraph 1

Remove proposed wording Amendment 1189 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
(b) the following paragraph is added: 1a. Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.’
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point b / Regulation (EU) 2016/679 / Article 33 – Paragraph 1a

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 1190 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
1a. Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point b / Regulation (EU) 2016/679 / Article 33 – Paragraph 1a

Deletion marker printed in the source: deleted

Alternative wording Amendment 1191 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay ITRE · LIBE
6. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The common template shall include fields enabling the controller to describe any privacy-enhancing measures relevant to the breach, including encryption, pseudonymisation, federated or local processing, confidential computing, access controls, logging, and measures taken to prevent model memorisation, regurgitation, or unauthorised disclosure. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). Where the Commission departs from the proposal submitted by the Board, it shall state the reasons for doing so. Those reasons shall be made publicly available together with the implementing act.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point c / Regulation (EU) 2016/679 / Article 33 – Paragraph 6

Alternative wording Amendment 1192 · Oliver Schenk, Axel Voss, Ana Miguel Pedro, Romana Tomc, Marion Walsmann, Lena Düpont, Marie-Sophie Lanig, Andrea Wechsler, Angelika Niebler, Monika Hohlmeier, Eva Maydell, Dimitris Tsiodras, Christian Doleschal, François-Xavier Bellamy ITRE · LIBE
6. The Board shall prepareestablish and transmitmake to the Commission a proposal for apublic common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk.. The proposalstemplate and lists shall be submittedavailable to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 7. The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.’
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point c / Regulation (EU) 2016/679 / Article 33 – paragraph 6

Alternative wording Amendment 1193 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
6. 6. The Board shall prepareestablish and transmitmake to the Commission a proposal for apublic common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposalstemplate and the list shall be submitted to the Commission withinavailable [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point c / Regulation (EU) 2016/679 / Article 33 – paragraph 6

Alternative wording Amendment 1194 · Tomas Tobé, Arba Kokalari, Jörgen Warborn ITRE · LIBE
6. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). This shall not go beyond existing obligations under this Regulation or mandate any retroactive obligations.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point c / Regulation (EU) 2016/679 / Article 33 – paragraph 6

Alternative wording Amendment 1195 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
6. TheBy …[PO please insert date: nine months from the entry into application of this amending Regulation] the Board shall prepareestablish and transmitmake to the Commission a proposal forpublic a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adoptdecide itthat the template and the list have general validity within the Union by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
Justification

modeled after Article 40(9) GDPR on the Codes of Conduct

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point c / Regulation (EU) 2016/679 / Article 33 – paragraph 6

Alternative wording Amendment 1196 · Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec ITRE · LIBE
6. The Board shall prepareestablish and transmitmake to the Commission a proposal forpublic a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is not likely to result in a high risk to the rights and freedoms of a natural person under paragraph 1. The proposalstemplate and list shall be submitted to the Commissionpublished within [OP date = nine months of the entry into application of this Regulation]. The Commission aftermay dueadopt considerationthe reviews it,template as necessary,established andby isthe empowered to adopt itBoard by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point c / Regulation (EU) 2016/679 / Article 33 – paragraph 6

Alternative wording Amendment 1197 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
7. The template and the list referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point c / Regulation (EU) 2016/679 / Article 33 – paragraph 7

Alternative wording Amendment 1198 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
7. The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6. Where the Commission departs from the Board's proposals for updates, it shall state the reasons for doing so, and those reasons shall be made publicly available together with the adopted updates.
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point c / Regulation (EU) 2016/679 / Article 33 – Paragraph 7

Alternative wording Amendment 1199 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
7. The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submitpublish, itswhere assessmentnecessary, any updates of the template and possible proposals for updates to the Commissionlist in due time. The Commission after due consideration of the proposals reviews them and is empowered to adoptdecide anythat updatesthe updated template and list have general validity within the Union following the procedure in paragraph 6.
Justification

modeled after Article 40(9) GDPR on Codes of Conduct

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point c / Regulation (EU) 2016/679 / Article 33 – paragraph 7

Additional proposed wording Amendment 1200 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE

7a. In Article 33, the following paragraph 7a is inserted:

The Commission may adopt the template and any updates as referred to in paragraph 6 and 7, as established by the Board, by way of an implementing act following the examination procedure set out in Article 93(2).'

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 8 – point c / Regulation (EU) 2016/679 / Article 33 – paragraph 7a (new)