GDPR · Regulation (EU) 2016/679
Article 33
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 7 parts · 4 Council drafts · 42 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to GDPRThe wording proposed by the Commission at the start of this legislative file.
Full article with Commission changes
Article with proposed changes
Official consolidated text dated 4 May 2016, with all 4 Commission proposal changes affecting this article applied.
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
7296 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rightsandfreedomsArticleof natural persons56. Where the notification to the supervisory authority is not made within7296 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
No standalone Commission wording is mapped to this tracked part. A newly proposed provision may have no earlier text of its own.
Commission source wording and instructions
Article 33(1)
Commission proposal
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
Article 33(1a)
Commission proposal
1a. Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
Article 33(6)
Commission proposal
6. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
Article 33(7)
Commission proposal
7. The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Article in May Presidency compromise Council text
Comparison basis: Existing law (4 May 2016) compared with May Presidency compromise (21 May 2026)
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach via the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55
, unless the personal data breach is unlikely to result in a risk to the rightsandfreedomsArticle 56 ofnaturalthispersonsRegulation. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The template and lists shall be available within [OP date = nine months of the entry into application of this Regulation]. The Commission may adopt the template as established by the Board by way of an implementing act, in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and lists referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Commission may adopt any updates of the template by way of an implementing act following the procedure referred to in paragraph 6.
Article 33(1)
May Presidency compromise
Council wording reconstructed for this provision from the official operation
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach via the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.
Article 33(1a)
May Presidency compromise
Council wording reconstructed for this provision from the official operation
1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
Article 33(6)
May Presidency compromise
Council wording reconstructed for this provision from the official operation
6. The Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The template and lists shall be available within [OP date = nine months of the entry into application of this Regulation]. The Commission may adopt the template as established by the Board by way of an implementing act, in accordance with the examination procedure set out in Article 93(2).
Article 33(7)
May Presidency compromise
Council wording reconstructed for this provision from the official operation
7. The template and lists referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Commission may adopt any updates of the template by way of an implementing act following the procedure referred to in paragraph 6.
Article in June Presidency compromise · 10 June Council text
Comparison basis: Existing law (4 May 2016) compared with June Presidency compromise · 10 June (10 June 2026)
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
7296 hours after having become aware of it, notify the personal data breach via the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rightsandfreedomsArticle 56 ofnaturalthispersonsRegulation. Where the notification to the supervisory authority is not made within7296 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The template and lists shall be available within [OP date = nine months of the entry into application of this Regulation]. The Commission may adopt the template as established by the Board by way of an implementing act, in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and lists referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary. Where the the Commission has adopted the previous version of the template by way of an implementing act, itshall adopt any updates of the template by way of an implementing act following the procedure referred to in paragraph 6.
Article 33(1)
June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
Article 33(1a)
June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
Article 33(6)
June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
6. The Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The template and lists shall be available within [OP date = nine months of the entry into application of this Regulation]. The Commission may adopt the template as established by the Board by way of an implementing act, in accordance with the examination procedure set out in Article 93(2).
Article 33(7)
June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
7. The template and lists referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary. Where the the Commission has adopted the previous version of the template by way of an implementing act, itshall adopt any updates of the template by way of an implementing act following the procedure referred to in paragraph 6.
Article in June Presidency compromise · 18 June Council text
Comparison basis: Existing law (4 May 2016) compared with June Presidency compromise · 18 June (18 June 2026)
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
7296 hours after having become aware of it, notify the personal data breach via the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rightsandfreedomsArticle 56 ofnaturalthispersonsRegulation. Where the notification to the supervisory authority is not made within7296 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The template and lists shall be available within [OP date = nine months of the entry into application of this Regulation].
- 7.
The template and lists referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary. 7a. The Commission may adopt the template and any updates referred to in paragraphs 6 and 7, as established by the Board, by way of an implementing act following the examination procedure set out in Article 93(2).
Article 33(1)
June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
Article 33(1a)
June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
Article 33(6)
June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
6. The Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The template and lists shall be available within [OP date = nine months of the entry into application of this Regulation].
Article 33(7)
June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
7. The template and lists referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary.
The Commission may adopt the template and any updates referred to in paragraphs 6 and 7, as established by the Board, by way of an implementing act following the examination procedure set out in Article 93(2).
Article in September Presidency compromise Council text
Comparison basis: Existing law (4 May 2016) compared with September Presidency compromise (3 September 2026)
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
7296 hours after having become aware of it, notify the personal data breach with the support of the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rightsandfreedomsArticle 56 ofnaturalthispersonsRegulation. Where the notification to the supervisory authority is not made within7296 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall establish and make public a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The lists shall be available within [OP date = nine months from the date of entry into application of this Regulation].
- 7.
The list referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary.
- 8.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1. That proposal shall be submitted to the Commission by [OP date = nine months from the date of entry into application of this Regulation]. The Commission after due consideration of the proposal reviews it and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 9.
The template referred to in paragraph 8 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposal reviews it and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
Article 33(1)
September Presidency compromise
Council wording reconstructed for this provision from the official operation
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach with the support of the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
Official source passage and amending instruction
8. Article 33 is amended as follows: (a) paragraph 1 is replaced by the following: ‘1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach with the support of the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.’ (b) the following paragraph is added: ‘1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.’ (c) the following paragraphs are added: ‘6. The Board shall establish and make public a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The lists shall be available within [OP date = nine months from the date of entry into application of this Regulation]. 7. The list referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary. 8. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1. That proposal shall be submitted to the Commission by [OP date = nine months from the date of entry into application of this Regulation]. The Commission after due consideration of the proposal reviews it and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 9. The template referred to in paragraph 8 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposal reviews it and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2).’
Article 33(1a)
September Presidency compromise
Council wording reconstructed for this provision from the official operation
1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
Official source passage and amending instruction
8. Article 33 is amended as follows: (a) paragraph 1 is replaced by the following: ‘1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach with the support of the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.’ (b) the following paragraph is added: ‘1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.’ (c) the following paragraphs are added: ‘6. The Board shall establish and make public a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The lists shall be available within [OP date = nine months from the date of entry into application of this Regulation]. 7. The list referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary. 8. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1. That proposal shall be submitted to the Commission by [OP date = nine months from the date of entry into application of this Regulation]. The Commission after due consideration of the proposal reviews it and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 9. The template referred to in paragraph 8 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposal reviews it and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2).’
Article 33(6)
September Presidency compromise
Council wording reconstructed for this provision from the official operation
6. The Board shall establish and make public a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The lists shall be available within [OP date = nine months from the date of entry into application of this Regulation].
Official source passage and amending instruction
8. Article 33 is amended as follows: (a) paragraph 1 is replaced by the following: ‘1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach with the support of the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.’ (b) the following paragraph is added: ‘1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.’ (c) the following paragraphs are added: ‘6. The Board shall establish and make public a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The lists shall be available within [OP date = nine months from the date of entry into application of this Regulation]. 7. The list referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary. 8. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1. That proposal shall be submitted to the Commission by [OP date = nine months from the date of entry into application of this Regulation]. The Commission after due consideration of the proposal reviews it and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 9. The template referred to in paragraph 8 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposal reviews it and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2).’
Article 33(7)
September Presidency compromise
Council wording reconstructed for this provision from the official operation
7. The list referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary.
Official source passage and amending instruction
8. Article 33 is amended as follows: (a) paragraph 1 is replaced by the following: ‘1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach with the support of the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.’ (b) the following paragraph is added: ‘1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.’ (c) the following paragraphs are added: ‘6. The Board shall establish and make public a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The lists shall be available within [OP date = nine months from the date of entry into application of this Regulation]. 7. The list referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary. 8. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1. That proposal shall be submitted to the Commission by [OP date = nine months from the date of entry into application of this Regulation]. The Commission after due consideration of the proposal reviews it and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 9. The template referred to in paragraph 8 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposal reviews it and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2).’
Article 33(1) 4 Council drafts
Article 33(1)
21 May 2026 · May Presidency compromise
Council wording reconstructed for this provision from the official operation
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach via the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.
Article 33(1)
10 June 2026 · June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
Article 33(1)
18 June 2026 · June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
Article 33(1)
3 September 2026 · September Presidency compromise
Council wording reconstructed for this provision from the official operation
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach with the support of the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
Official source passage and amending instruction
8. Article 33 is amended as follows: (a) paragraph 1 is replaced by the following: ‘1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach with the support of the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.’ (b) the following paragraph is added: ‘1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.’ (c) the following paragraphs are added: ‘6. The Board shall establish and make public a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The lists shall be available within [OP date = nine months from the date of entry into application of this Regulation]. 7. The list referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary. 8. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1. That proposal shall be submitted to the Commission by [OP date = nine months from the date of entry into application of this Regulation]. The Commission after due consideration of the proposal reviews it and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 9. The template referred to in paragraph 8 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposal reviews it and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2).’
Article 33(1a) 4 Council drafts
Article 33(1a)
21 May 2026 · May Presidency compromise
Council wording reconstructed for this provision from the official operation
1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
Article 33(1a)
10 June 2026 · June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
Article 33(1a)
18 June 2026 · June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
Article 33(1a)
3 September 2026 · September Presidency compromise
Council wording reconstructed for this provision from the official operation
1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
Official source passage and amending instruction
8. Article 33 is amended as follows: (a) paragraph 1 is replaced by the following: ‘1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach with the support of the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.’ (b) the following paragraph is added: ‘1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.’ (c) the following paragraphs are added: ‘6. The Board shall establish and make public a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The lists shall be available within [OP date = nine months from the date of entry into application of this Regulation]. 7. The list referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary. 8. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1. That proposal shall be submitted to the Commission by [OP date = nine months from the date of entry into application of this Regulation]. The Commission after due consideration of the proposal reviews it and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 9. The template referred to in paragraph 8 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposal reviews it and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2).’
Article 33(6) 4 Council drafts
Article 33(6)
21 May 2026 · May Presidency compromise
Council wording reconstructed for this provision from the official operation
6. The Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The template and lists shall be available within [OP date = nine months of the entry into application of this Regulation]. The Commission may adopt the template as established by the Board by way of an implementing act, in accordance with the examination procedure set out in Article 93(2).
Article 33(6)
10 June 2026 · June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
6. The Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The template and lists shall be available within [OP date = nine months of the entry into application of this Regulation]. The Commission may adopt the template as established by the Board by way of an implementing act, in accordance with the examination procedure set out in Article 93(2).
Article 33(6)
18 June 2026 · June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
6. The Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The template and lists shall be available within [OP date = nine months of the entry into application of this Regulation].
Article 33(6)
3 September 2026 · September Presidency compromise
Council wording reconstructed for this provision from the official operation
6. The Board shall establish and make public a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The lists shall be available within [OP date = nine months from the date of entry into application of this Regulation].
Official source passage and amending instruction
8. Article 33 is amended as follows: (a) paragraph 1 is replaced by the following: ‘1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach with the support of the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.’ (b) the following paragraph is added: ‘1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.’ (c) the following paragraphs are added: ‘6. The Board shall establish and make public a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The lists shall be available within [OP date = nine months from the date of entry into application of this Regulation]. 7. The list referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary. 8. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1. That proposal shall be submitted to the Commission by [OP date = nine months from the date of entry into application of this Regulation]. The Commission after due consideration of the proposal reviews it and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 9. The template referred to in paragraph 8 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposal reviews it and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2).’
Article 33(7) 4 Council drafts
Article 33(7)
21 May 2026 · May Presidency compromise
Council wording reconstructed for this provision from the official operation
7. The template and lists referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Commission may adopt any updates of the template by way of an implementing act following the procedure referred to in paragraph 6.
Article 33(7)
10 June 2026 · June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
7. The template and lists referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary. Where the the Commission has adopted the previous version of the template by way of an implementing act, itshall adopt any updates of the template by way of an implementing act following the procedure referred to in paragraph 6.
Article 33(7)
18 June 2026 · June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
7. The template and lists referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary.
The Commission may adopt the template and any updates referred to in paragraphs 6 and 7, as established by the Board, by way of an implementing act following the examination procedure set out in Article 93(2).
Article 33(7)
3 September 2026 · September Presidency compromise
Council wording reconstructed for this provision from the official operation
7. The list referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary.
Official source passage and amending instruction
8. Article 33 is amended as follows: (a) paragraph 1 is replaced by the following: ‘1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach with the support of the national entry point established pursuant to Article 23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.’ (b) the following paragraph is added: ‘1a. Until the establishment of the national entry point pursuant to Article 23b of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.’ (c) the following paragraphs are added: ‘6. The Board shall establish and make public a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk. The lists shall be available within [OP date = nine months from the date of entry into application of this Regulation]. 7. The list referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary. 8. The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1. That proposal shall be submitted to the Commission by [OP date = nine months from the date of entry into application of this Regulation]. The Commission after due consideration of the proposal reviews it and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 9. The template referred to in paragraph 8 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposal reviews it and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2).’
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Political group at the amendment date where available; otherwise the current Parliament affiliation.
Alternative wording Amendment 54 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
7296 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rightsandfreedomsArticle 56 ofnaturalthispersonsRegulation. Where the notification to the supervisory authority is not made within7296 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
By …[PO please insert date: nine months from the entry into application of this amending Regulation] the Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The Commission may adopt the template as established by the Board by way of an implementing act in accordance with the examination procedure set out in Article 93(2) of this Regulation.
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Commission may adopt necessary updates of the template by way of an implementing act following the procedure referred to in paragraph 6.
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 55 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
7296 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rightsandfreedomsArticle 56 ofnaturalthispersonsRegulation. Where the notification to the supervisory authority is not made within7296 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
By …[PO please insert date: nine months from the entry into application of this amending Regulation] the Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The Commission may adopt the template as established by the Board by way of an implementing act in accordance with the examination procedure set out in Article 93(2) of this Regulation.
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Commission may adopt necessary updates of the template by way of an implementing act following the procedure referred to in paragraph 6.
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 56 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
7296 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rightsandfreedomsArticle 56 ofnaturalthispersonsRegulation. Where the notification to the supervisory authority is not made within7296 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
By …[PO please insert date: nine months from the entry into application of this amending Regulation] the Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The Commission may adopt the template as established by the Board by way of an implementing act in accordance with the examination procedure set out in Article 93(2) of this Regulation.
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Commission may adopt necessary updates of the template by way of an implementing act following the procedure referred to in paragraph 6.
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
TheBy …[PO please insert date: nine months from the entry into application of this amending Regulation] the Board shallprepareestablish andtransmitmaketo the Commission a proposal forpublic a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well asfora list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. TheproposalsCommissionshallmaybe submitted toadopt theCommissiontemplatewithinas[OPestablisheddate = nine months ofby theentry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt itBoard by way of an implementing act in accordance with the examination procedure set out in Article 93(2) of this Regulation. - 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 57 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
7296 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rightsandfreedomsArticle 56 ofnaturalthispersonsRegulation. Where the notification to the supervisory authority is not made within7296 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56 of this Regulation.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
By …[PO please insert date: nine months from the entry into application of this amending Regulation] the Board shall establish and make public a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The Commission may adopt the template as established by the Board by way of an implementing act in accordance with the examination procedure set out in Article 93(2) of this Regulation.
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Commission may adopt necessary updates of the template by way of an implementing act following the procedure referred to in paragraph 6.
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The
BoardCommissionshallmaysubmitadoptits assessment and possible proposals fornecessary updatesto the Commission in due time. The Commission after due considerationof theproposalstemplatereviewsbythemwayandofisanempoweredimplementingto adopt any updatesact following the procedure referred to in paragraph 6.
Alternative wording Amendment 108 IMCO draft opinion · Alex Agius Saliba (rapporteur)
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
7296 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rightsandfreedomsArticleof natural persons56. Where the notification to the supervisory authority is not made within7296 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare, make public and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission shall take utmost account of the Board's assessment.
- 7a.
The submission of notifications, reports or other information provided for in this provision shall not reduce or otherwise affect the scope, frequency or level of detail of the reporting obligations laid down in this Regulation or other applicable Union Law. The establishment of a single-entry point in this Article shall serve solely to simplify procedural aspects and guarantee coordination between competent authorities. It shall not result in lowering the level of security, privacy, consumer and data protection nor limit the power of supervisory authorities to request additional information, conduct investigations or require further reporting where necessary to guarantee compliance with the law.’
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare, make public and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 109 IMCO draft opinion · Alex Agius Saliba (rapporteur)
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
7296 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rightsandfreedomsArticleof natural persons56. Where the notification to the supervisory authority is not made within7296 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare, make public and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission shall take utmost account of the Board's assessment.
- 7a.
The submission of notifications, reports or other information provided for in this provision shall not reduce or otherwise affect the scope, frequency or level of detail of the reporting obligations laid down in this Regulation or other applicable Union Law. The establishment of a single-entry point in this Article shall serve solely to simplify procedural aspects and guarantee coordination between competent authorities. It shall not result in lowering the level of security, privacy, consumer and data protection nor limit the power of supervisory authorities to request additional information, conduct investigations or require further reporting where necessary to guarantee compliance with the law.’
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission
aftershallduetakeconsiderationutmost account of theproposalsBoard'sreviews them and is empowered to adopt any updates following the procedure in paragraph 6assessment.
Additional proposed wording Amendment 110 IMCO draft opinion · Alex Agius Saliba (rapporteur)
The submission of notifications, reports or other information provided for in this provision shall not reduce or otherwise affect the scope, frequency or level of detail of the reporting obligations laid down in this Regulation or other applicable Union Law. The establishment of a single-entry point in this Article shall serve solely to simplify procedural aspects and guarantee coordination between competent authorities. It shall not result in lowering the level of security, privacy, consumer and data protection nor limit the power of supervisory authorities to request additional information, conduct investigations or require further reporting where necessary to guarantee compliance with the law.’
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
7296 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rightsandfreedomsArticleof natural persons56. Where the notification to the supervisory authority is not made within7296 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare, make public and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission shall take utmost account of the Board's assessment.
- 7a.
The submission of notifications, reports or other information provided for in this provision shall not reduce or otherwise affect the scope, frequency or level of detail of the reporting obligations laid down in this Regulation or other applicable Union Law. The establishment of a single-entry point in this Article shall serve solely to simplify procedural aspects and guarantee coordination between competent authorities. It shall not result in lowering the level of security, privacy, consumer and data protection nor limit the power of supervisory authorities to request additional information, conduct investigations or require further reporting where necessary to guarantee compliance with the law.’
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
- 7a.
The submission of notifications, reports or other information provided for in this provision shall not reduce or otherwise affect the scope, frequency or level of detail of the reporting obligations laid down in this Regulation or other applicable Union Law. The establishment of a single-entry point in this Article shall serve solely to simplify procedural aspects and guarantee coordination between competent authorities. It shall not result in lowering the level of security, privacy, consumer and data protection nor limit the power of supervisory authorities to request additional information, conduct investigations or require further reporting where necessary to guarantee compliance with the law.’
Alternative wording Amendment 251 · Daniel Buda JURI
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the
single-entryelectronic channel made available by the competent supervisory authority or, if the competent Member State has so decided, via a national contact pointestablishedorpursuantantointerface interoperable with the framework provided for in Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.’ - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 252 · Ton Diepeveen, Pascale Piera JURI
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
This change cannot be reconstructed from the source: source amended-law header conflicts with the independently matched Commission base; the source header remains authoritative and no corrected legal target is substituted
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 253 · Daniel Buda JURI
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment and testing of the
single-entryinteroperablepointframeworkpursuantprovidedtofor in Article 23a of Directive (EU) 2022/2555 and until the applicable channel is designated by the competent Member State, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.’ - 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 254 · Ton Diepeveen, Pascale Piera JURI
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
This change cannot be reconstructed from the source: source amended-law header conflicts with the independently matched Commission base; the source header remains authoritative and no corrected legal target is substituted
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 384 · Virginie Joron IMCO
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via
theitssingle-entrynational point of entry established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay. Controllers shall continue to document breaches which are not notified, including the facts relating to the personal data breach, its effects and the remedial action taken. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Remove proposed wording Amendment 385 · Virginie Joron IMCO
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56. - 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 386 · Virginie Joron IMCO
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration
reviewsrefersitthem to the Board so that the latter can review them, as necessary, and is empowered to adoptitthem by way of an implementing act in accordance with the examination procedure set out in Article 93(2). If the Commission departs from the proposal submitted by the Board, it shall set out the reasons for doing so. These reasons shall be made public at the same time as the implementing act. - 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 387 · Arba Kokalari IMCO
Alternative wording Amendment 388 · Virginie Joron IMCO
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6. If the Commission departs from the Board’s proposed updates, it shall set out the reasons for doing so, and these reasons shall be made public at the same time as the adopted updates.
Additional proposed wording Amendment 389 · David Cormand on behalf of the Verts/ALE Group IMCO
The submission of notifications, reports or other information provided for in this provision shall not reduce the scope, frequency or level of detail of the reporting obligations laid down in this Regulation or other applicable Union Law. The establishment of a single point of entry under this Article shall serve solely to simplify procedural aspects and ensure better coordination between competent authorities. It shall not result in lowering the level of data protection nor limit the power of supervisory authorities to request additional information, conduct investigations or require further reporting where necessary to guarantee compliance with this Regulation.
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
- 7a.
The submission of notifications, reports or other information provided for in this provision shall not reduce the scope, frequency or level of detail of the reporting obligations laid down in this Regulation or other applicable Union Law. The establishment of a single point of entry under this Article shall serve solely to simplify procedural aspects and ensure better coordination between competent authorities. It shall not result in lowering the level of data protection nor limit the power of supervisory authorities to request additional information, conduct investigations or require further reporting where necessary to guarantee compliance with this Regulation.
Alternative wording Amendment 1176 · Markus Buchheit ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach
viato the competent supervisory authority. Notifications pursuant to this Article shall be made to the competent supervisory authority of the Member State in which the controller is established or where the personal data breach has occurred. The use of any Union-level technical reporting tools or single-entrypointpointsestablishedshallpursuantremainto Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55voluntary andArticle 56. Where the notification to the supervisory authority is not made within 96 hours, itshall beaccompaniedlimitedbytoreasonspersonalfordatathebreachesdelaywith clear cross-border or Union-wide systemic relevance, without prejudice to national notification channels. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1177 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
Justification
The controller documents every personal data breach, including those which are not notified. The documentation comprises the facts relating to the breach, its effects and the remedial action taken, and enables the supervisory authority to verify compliance in the course of an inspection.
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via
thetheir national single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay. Controllers shall continue to document non-notified breaches, including the facts relating to the personal data breach, its effects and the remedial action taken. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1178 · Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller, Christophe Grudler ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a
highrisk to the rights and freedoms of natural persons, in which case particular consideration shall be given to the risk to children, the controller shall without undue delay and, where feasible, not later than9672 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within9672 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1179 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the
single-national entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1180 · Niels Flemming Hansen ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the
single-national entry point established pursuant to Article23a23b of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1181 · Henrik Dahl ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the
single-national entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1182 · Francesco Torselli ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
96fourhoursworking days after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within96fourhoursworking days, it shall be accompanied by reasons for the delay.(We do not intend to propose to change the timing which remains exactly the same, but only to express it in working days, therefore starting from Monday in the event that an accident occurs on Saturday or Sunday.)
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1183 · Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a
highrisk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than9672 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56 of this Regulation. Where the notification to the supervisory authority is not made within9672 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1184 · Pernando Barrena Arza ITRE · LIBE
Justification
The threshold for the obligation to notify the supervisory authority should be lower that the threshold to communicate a personal data breach to the data subject, since controllers generally are incentivised to avoid the communication of a personal data breach to the affected data subject. This tendency to avoid such communication could influence the respective assessment by the controller. While it makes sense to increase the threshold and avoid that supervisory authorities are swamped with personal data breach notifications regarding every incident, it is important that the supervisory authority is informed about the more severe incidents and can also re-asses the controllers risk assessment. In such cases, the supervisory authority could require the controller to communicate the personal data breach to the affected data subjects even if the controller’s initial assessment result in no high risk. This process is stipulated in Article 33(4) GDPR which would basically lose its purpose in case the threshold of Article 33 (notification of a personal data breach to the supervisory authority) would be increased to the threshold of Article 34 GDPR (communication of a personal data breach to the data subjects).
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in
aanhighincreased risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1185 · Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
9672 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within9672 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1186 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
Justification
NIS2, where the single-entry point is established, also only has 72 hours. One aim of simplification is to have harmonised rules.
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
9672 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within9672 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1187 · Alex Agius Saliba ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a
highrisk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than9672 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within9672 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1188 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a
highrisk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than9672 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within9672 hours, it shall be accompanied by reasons for the delay. - 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Remove proposed wording Amendment 1189 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56. - 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Remove proposed wording Amendment 1190 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56. - 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1191 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The common template shall include fields enabling the controller to describe any privacy-enhancing measures relevant to the breach, including encryption, pseudonymisation, federated or local processing, confidential computing, access controls, logging, and measures taken to prevent model memorisation, regurgitation, or unauthorised disclosure. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). Where the Commission departs from the proposal submitted by the Board, it shall state the reasons for doing so. Those reasons shall be made publicly available together with the implementing act.
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1192 · Oliver Schenk, Axel Voss, Ana Miguel Pedro, Romana Tomc, Marion Walsmann, Lena Düpont, Marie-Sophie Lanig, Andrea Wechsler, Angelika Niebler, Monika Hohlmeier, Eva Maydell, Dimitris Tsiodras, Christian Doleschal, François-Xavier Bellamy ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall
prepareestablish andtransmitmaketo the Commission a proposal for apublic common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person and a list of the circumstances in which it is not likely to result in such a high risk.. Theproposalstemplate and lists shall besubmittedavailable to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 7. The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.’ - 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1193 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person6.The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).- 6.
The Board shall establish and make public common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a risk to the rights and freedoms of a natural person. The template and the list shall be available [OP date = nine months of the entry into application of this Regulation].
- 6.
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1194 · Tomas Tobé, Arba Kokalari, Jörgen Warborn ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2). This shall not go beyond existing obligations under this Regulation or mandate any retroactive obligations.
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1195 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
Justification
modeled after Article 40(9) GDPR on the Codes of Conduct
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
TheBy …[PO please insert date: nine months from the entry into application of this amending Regulation] the Board shallprepareestablish andtransmitmaketo the Commission a proposal forpublic a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well asfora list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. Theproposals shall be submitted to theCommissionwithin [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, andis empowered toadoptdecideitthat the template and the list have general validity within the Union by way of an implementing act in accordance with the examination procedure set out in Article 93(2). - 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1196 · Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall
prepareestablish andtransmitmaketo the Commission a proposal forpublic a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well asfora list of the circumstances in which a personal data breach is not likely to result in ahighrisk to the rights and freedoms of a natural person under paragraph 1. Theproposalstemplate and list shall besubmitted to the Commissionpublished within [OP date = nine months of the entry into application of this Regulation]. The Commissionaftermaydueadoptconsiderationthereviews it,template asnecessary,establishedandbyistheempowered to adopt itBoard by way of an implementing act in accordance with the examination procedure set out in Article 93(2). - 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1197 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed by the Board at least every three years and updated where necessary.
The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
Alternative wording Amendment 1198 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6. Where the Commission departs from the Board's proposals for updates, it shall state the reasons for doing so, and those reasons shall be made publicly available together with the adopted updates.
Alternative wording Amendment 1199 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
Justification
modeled after Article 40(9) GDPR on Codes of Conduct
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed
at least every three yearsand updated where necessary. The Board shallsubmitpublish,itswhereassessmentnecessary, any updates of the template andpossible proposals for updates totheCommissionlist in due time. The Commissionafter due consideration of the proposals reviews them andis empowered toadoptdecideanythatupdatesthe updated template and list have general validity within the Union following the procedure in paragraph 6.
Additional proposed wording Amendment 1200 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
7a. In Article 33, the following paragraph 7a is inserted:
The Commission may adopt the template and any updates as referred to in paragraph 6 and 7, as established by the Board, by way of an implementing act following the examination procedure set out in Article 93(2).'
against:
Article 33
Notification of a personal data breach to the supervisory authority
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay.
- 1a.
Until the establishment of the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555, controllers shall continue to notify personal data breaches directly to the competent supervisory authority in accordance with Article 55 and Article 56.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template for notifying a personal data breach to the competent supervisory authority referred to in paragraph 1 as well as for a list of the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person. The proposals shall be submitted to the Commission within [OP date = nine months of the entry into application of this Regulation]. The Commission after due consideration reviews it, as necessary, and is empowered to adopt it by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 7.
The template and the list referred to in paragraph 6 shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6.
- 7a.
The Commission may adopt the template and any updates as referred to in paragraph 6 and 7, as established by the Board, by way of an implementing act following the examination procedure set out in Article 93(2).'
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Article 33 – paragraphe 1 a
Wording reproduced in the amendment → Amendment 385 · IMCO amendments 329–532 to the draft opinion: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 385 · IMCO amendments 329–532 to the draft opinion: removal
This wording is removed.
Article 33(1)
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
RemovedAdded
Both texts in full
European Commission proposal
Council Presidency text · ST 9547/26
Article 33(1)
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Article 33(1)
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Article 33(1)
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Council Presidency text · ST 12535/26
Article 33(1)
Wording reproduced in the amendment → Amendment 1176 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1176 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(1)
Wording reproduced in the amendment → Amendment 1177 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1177 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(1)
Wording reproduced in the amendment → Amendment 1178 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1178 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(1)
Wording reproduced in the amendment → Amendment 1179 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1179 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(1)
Wording reproduced in the amendment → Amendment 1180 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1180 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(1)
Wording reproduced in the amendment → Amendment 1181 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1181 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(1)
Wording reproduced in the amendment → Amendment 1182 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1182 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(1)
Wording reproduced in the amendment → Amendment 1183 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1183 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(1)
Wording reproduced in the amendment → Amendment 1184 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1184 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(1)
Wording reproduced in the amendment → Amendment 1185 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1185 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(1)
Wording reproduced in the amendment → Amendment 1186 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1186 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(1)
Wording reproduced in the amendment → Amendment 1187 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1187 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(1)
Wording reproduced in the amendment → Amendment 1188 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1188 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(1)
Wording reproduced in the amendment → Amendment 54 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 54 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Article 33(1)
Wording reproduced in the amendment → Amendment 384 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 384 · IMCO amendments 329–532 to the draft opinion
Article 33(1)
Wording reproduced in the amendment → Amendment 251 · JURI amendments 69–296 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 251 · JURI amendments 69–296 to the draft opinion
Article 33(1)
Wording reproduced in the amendment → Amendment 252 · JURI amendments 69–296 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 252 · JURI amendments 69–296 to the draft opinion
Article 33(1a)
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
RemovedAdded
Both texts in full
European Commission proposal
Council Presidency text · ST 9547/26
Article 33(1a)
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Article 33(1a)
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Article 33(1a)
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Council Presidency text · ST 12535/26
Article 33(1a)
Wording reproduced in the amendment → Amendment 1189 · ITRE–LIBE amendments 1053–1260 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1189 · ITRE–LIBE amendments 1053–1260 to the draft report: removal
This wording is removed.
Article 33(1a)
Wording reproduced in the amendment → Amendment 1190 · ITRE–LIBE amendments 1053–1260 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1190 · ITRE–LIBE amendments 1053–1260 to the draft report: removal
This wording is removed.
Article 33(1a)
Wording reproduced in the amendment → Amendment 55 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 55 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Article 33(1a)
Wording reproduced in the amendment → Amendment 253 · JURI amendments 69–296 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 253 · JURI amendments 69–296 to the draft opinion
Article 33(1a)
Wording reproduced in the amendment → Amendment 254 · JURI amendments 69–296 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 254 · JURI amendments 69–296 to the draft opinion
Article 33(6)
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
RemovedAdded
Both texts in full
European Commission proposal
Council Presidency text · ST 9547/26
Article 33(6)
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Article 33(6)
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Article 33(6)
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Council Presidency text · ST 12535/26
Article 33(6)
Wording reproduced in the amendment → Amendment 1191 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1191 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(6)
Wording reproduced in the amendment → Amendment 1192 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1192 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(6)
Wording reproduced in the amendment → Amendment 1193 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1193 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(6)
Wording reproduced in the amendment → Amendment 1194 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1194 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(6)
Wording reproduced in the amendment → Amendment 1195 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1195 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(6)
Wording reproduced in the amendment → Amendment 1196 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1196 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(6)
Wording reproduced in the amendment → Amendment 56 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 56 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Article 33(6)
Wording reproduced in the amendment → Amendment 386 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 386 · IMCO amendments 329–532 to the draft opinion
Article 33(6)
Wording reproduced in the amendment → Amendment 387 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 387 · IMCO amendments 329–532 to the draft opinion
Article 33(6)
Wording reproduced in the amendment → Amendment 108 · IMCO draft opinion · Alex Agius Saliba (rapporteur)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 108 · IMCO draft opinion · Alex Agius Saliba (rapporteur)
Article 33(7)
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
RemovedAdded
Both texts in full
European Commission proposal
Council Presidency text · ST 9547/26
Article 33(7)
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Article 33(7)
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Article 33(7)
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Council Presidency text · ST 12535/26
Article 33(7)
Wording reproduced in the amendment → Amendment 1197 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1197 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(7)
Wording reproduced in the amendment → Amendment 1198 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1198 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(7)
Wording reproduced in the amendment → Amendment 1199 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1199 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 33(7)
Wording reproduced in the amendment → Amendment 57 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 57 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Article 33(7)
Wording reproduced in the amendment → Amendment 388 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 388 · IMCO amendments 329–532 to the draft opinion
Article 33(7)
Wording reproduced in the amendment → Amendment 109 · IMCO draft opinion · Alex Agius Saliba (rapporteur)
Changes in context
RemovedAdded