GDPR · Regulation (EU) 2016/679
Article 35
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 13 parts · 4 Council drafts · 44 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to GDPRThe wording proposed by the Commission at the start of this legislative file.
Full article with Commission changes
Article with proposed changes
Official consolidated text dated 4 May 2016, with all 6 Commission proposal changes affecting this article applied.
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The
supervisory authorityBoard shallestablishprepare andmaketransmitpublicto the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.The supervisory authority shall communicate those lists to the Board referred to in Article 68. - 5.
The
supervisoryBoardauthorityshallmay also establishprepare andmaketransmitpublicto the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.The supervisory authority shall communicate those lists to the Board. - 6.
PriorThe Board shall prepare and transmit to theadoptionCommissionofatheproposallistsforreferredatocommonin paragraphs 4template and5,athecommoncompetentmethodologysupervisoryforauthority shall apply the consistency mechanism referred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services toconducting datasubjectsprotectionorimpactto the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Unionassessments. - 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
No standalone Commission wording is mapped to this tracked part. A newly proposed provision may have no earlier text of its own.
Commission source wording and instructions
Article 35(4)
Commission proposal
4. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
Article 35(5)
Commission proposal
5. The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
Article 35(6)
Commission proposal
6. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
Article 35(6a)
Commission proposal
6a. The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
Article 35(6b)
Commission proposal
6b. The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
Article 35(6c)
Commission proposal
6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Article in May Presidency compromise Council text
Comparison basis: Existing law (4 May 2016) compared with May Presidency compromise (21 May 2026)
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The
supervisory authorityBoard shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.The supervisory authority shall communicate those lists to the Board referred to in Article 68. - 5.
The
supervisoryBoardauthority may alsoshall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.The supervisory authority shall communicate those lists to the Board. - 6.
PriorThetoBoardtheshalladoption of the lists referred to in paragraphs 4establish and5,makethepubliccompetentasupervisorycommonauthoritytemplateshallandapplyathecommonconsistencymethodologymechanismforreferred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services toconducting datasubjectsprotectionorimpactto the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Unionassessments. - 6a.
The lists referred to in paragraphs 4 and 5 and the template and methodology referred to in paragraph 6 shall be published within [OP date = 9 months of the entry into application of this Regulation]. The Commission may adopt the template as established by the Board by way of an implementing act, in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a- shall be reviewed by the Board at least every three years and updated where necessary. The Commission may adopt any updates of the template by way of an implementing act following the procedure referred to in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraph 4 and
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Article 35(4)
May Presidency compromise
Council wording reconstructed for this provision from the official operation
4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
Article 35(5)
May Presidency compromise
Council wording reconstructed for this provision from the official operation
5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.
Article 35(6)
May Presidency compromise
Council wording reconstructed for this provision from the official operation
6. The Board shall establish and make public a common template and a common methodology for conducting data protection impact assessments.
Article 35(6a)
May Presidency compromise
Council wording reconstructed for this provision from the official operation
6a. The lists referred to in paragraphs 4 and 5 and the template and methodology referred to in paragraph 6 shall be published within [OP date = 9 months of the entry into application of this Regulation]. The Commission may adopt the template as established by the Board by way of an implementing act, in accordance with the examination procedure set out in Article 93(2).
Article 35(6b)
May Presidency compromise
Council wording reconstructed for this provision from the official operation
The lists and the template and methodology referred to in paragraph 6a- shall be reviewed by the Board at least every three years and updated where necessary. The Commission may adopt any updates of the template by way of an implementing act following the procedure referred to in paragraph 6a.
Article 35(6c)
May Presidency compromise
Council wording reconstructed for this provision from the official operation
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraph 4 and
Article in June Presidency compromise · 10 June Council text
Comparison basis: Existing law (4 May 2016) compared with June Presidency compromise · 10 June (10 June 2026)
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The
supervisory authorityBoard shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.The supervisory authority shall communicate those lists to the Board referred to in Article 68. - 5.
The
supervisoryBoardauthority may alsoshall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.The supervisory authority shall communicate those lists to the Board. - 6.
PriorThetoBoardtheshalladoption of the lists referred to in paragraphs 4establish and5,makethepubliccompetentasupervisorycommonauthoritytemplateshallandapplyathecommonconsistencymethodologymechanismforreferred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services toconducting datasubjectsprotectionorimpactto the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Unionassessments. - 6a.
The lists referred to in paragraphs 4 and 5 and the template and methodology referred to in paragraph 6 shall be published within [OP date = 9 months of the entry into application of this Regulation]. The Commission may adopt the template as established by the Board by way of an implementing act, in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a- shall be reviewed by the Board at least every three years and updated where necessary. Where the the Commission has adopted the previous version of the template by way of an implementing act, it shall adopt any updates of the template by way of an implementing act following the procedure referred to in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraph 4 and
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Article 35(4)
June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
Article 35(5)
June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.
Article 35(6)
June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
6. The Board shall establish and make public a common template and a common methodology for conducting data protection impact assessments.
Article 35(6a)
June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
6a. The lists referred to in paragraphs 4 and 5 and the template and methodology referred to in paragraph 6 shall be published within [OP date = 9 months of the entry into application of this Regulation]. The Commission may adopt the template as established by the Board by way of an implementing act, in accordance with the examination procedure set out in Article 93(2).
Article 35(6b)
June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
The lists and the template and methodology referred to in paragraph 6a- shall be reviewed by the Board at least every three years and updated where necessary. Where the the Commission has adopted the previous version of the template by way of an implementing act, it shall adopt any updates of the template by way of an implementing act following the procedure referred to in paragraph 6a.
Article 35(6c)
June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraph 4 and
Article in June Presidency compromise · 18 June Council text
Comparison basis: Existing law (4 May 2016) compared with June Presidency compromise · 18 June (18 June 2026)
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The
supervisory authorityBoard shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.The supervisory authority shall communicate those lists to the Board referred to in Article 68. - 5.
The
supervisoryBoardauthority may alsoshall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.The supervisory authority shall communicate those lists to the Board. - 6.
PriorThetoBoardtheshalladoption of the lists referred to in paragraphs 4establish and5,makethepubliccompetentasupervisorycommonauthoritytemplateshallandapplyathecommonconsistencymethodologymechanismforreferred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services toconducting datasubjectsprotectionorimpactto the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Unionassessments. - 6a.
The lists referred to in paragraphs 4 and 5 and the template and methodology referred to in paragraph 6 shall be published within [OP date = 9 months of the entry into application of this Regulation].
- 6b.
The lists and the template and methodology referred to in paragraph 6a- shall be reviewed by the Board at least every three years and updated where necessary. 6ba. The Commission may adopt the template and any updates referred to in paragraphs 6a and 6b, as established by the Board, by way of an implementing act following the examination procedure set out in Article 93(2).
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraph 4 and
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Article 35(4)
June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
Article 35(5)
June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.
Article 35(6)
June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
6. The Board shall establish and make public a common template and a common methodology for conducting data protection impact assessments.
Article 35(6a)
June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
6a. The lists referred to in paragraphs 4 and 5 and the template and methodology referred to in paragraph 6 shall be published within [OP date = 9 months of the entry into application of this Regulation].
Article 35(6b)
June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
The lists and the template and methodology referred to in paragraph 6a- shall be reviewed by the Board at least every three years and updated where necessary. 6ba. The Commission may adopt the template and any updates referred to in paragraphs 6a and 6b, as established by the Board, by way of an implementing act following the examination procedure set out in Article 93(2).
Article 35(6c)
June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraph 4 and
Article in September Presidency compromise Council text
Comparison basis: Existing law (4 May 2016) compared with September Presidency compromise (3 September 2026)
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The
supervisory authorityBoard shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.The supervisory authority shall communicate those lists to the Board referred to in Article 68. - 5.
The
supervisoryBoardauthority may alsoshall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.The supervisory authority shall communicate those lists to the Board. - 6.
Prior to the adoption of theThe lists referred to in paragraphs 4 and 5,shall be published by [OP date = 9 months from thecompetentdatesupervisoryofauthorityentry into application of this Regulation]. These lists shallapplybe reviewed by theconsistencyBoardmechanismatreferredleasttoeveryinthreeArticleyears63and updated wheresuch lists involve processing activities which are related to the offering of goods or services to data subjects or to the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Unionnecessary. - 6a.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments. The template and methodology shall be submitted to the Commission by [OP date = 9 months from the date of entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The template and methodology referred to in paragraph 6a shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Article 35(4)
September Presidency compromise
Council wording reconstructed for this provision from the official operation
4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
Official source passage and amending instruction
9. Article 35 is amended as follows: (a) paragraphs 4, 5 and 6 are replaced by the following: ‘4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. 5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. 6. The lists referred to in paragraphs 4 and 5 shall be published by [OP date = 9 months from the date of entry into application of this Regulation]. These lists shall be reviewed by the Board at least every three years and updated where necessary.’ (b) the following paragraphs are inserted: ‘6a. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments. The template and methodology shall be submitted to the Commission by [OP date = 9 months from the date of entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6b. The template and methodology referred to in paragraph 6a shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.’
Article 35(5)
September Presidency compromise
Council wording reconstructed for this provision from the official operation
5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.
Official source passage and amending instruction
9. Article 35 is amended as follows: (a) paragraphs 4, 5 and 6 are replaced by the following: ‘4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. 5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. 6. The lists referred to in paragraphs 4 and 5 shall be published by [OP date = 9 months from the date of entry into application of this Regulation]. These lists shall be reviewed by the Board at least every three years and updated where necessary.’ (b) the following paragraphs are inserted: ‘6a. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments. The template and methodology shall be submitted to the Commission by [OP date = 9 months from the date of entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6b. The template and methodology referred to in paragraph 6a shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.’
Article 35(6)
September Presidency compromise
Council wording reconstructed for this provision from the official operation
6. The lists referred to in paragraphs 4 and 5 shall be published by [OP date = 9 months from the date of entry into application of this Regulation]. These lists shall be reviewed by the Board at least every three years and updated where necessary.
Official source passage and amending instruction
9. Article 35 is amended as follows: (a) paragraphs 4, 5 and 6 are replaced by the following: ‘4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. 5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. 6. The lists referred to in paragraphs 4 and 5 shall be published by [OP date = 9 months from the date of entry into application of this Regulation]. These lists shall be reviewed by the Board at least every three years and updated where necessary.’ (b) the following paragraphs are inserted: ‘6a. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments. The template and methodology shall be submitted to the Commission by [OP date = 9 months from the date of entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6b. The template and methodology referred to in paragraph 6a shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.’
Article 35(6a)
September Presidency compromise
Council wording reconstructed for this provision from the official operation
6a. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments. The template and methodology shall be submitted to the Commission by [OP date = 9 months from the date of entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
Official source passage and amending instruction
9. Article 35 is amended as follows: (a) paragraphs 4, 5 and 6 are replaced by the following: ‘4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. 5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. 6. The lists referred to in paragraphs 4 and 5 shall be published by [OP date = 9 months from the date of entry into application of this Regulation]. These lists shall be reviewed by the Board at least every three years and updated where necessary.’ (b) the following paragraphs are inserted: ‘6a. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments. The template and methodology shall be submitted to the Commission by [OP date = 9 months from the date of entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6b. The template and methodology referred to in paragraph 6a shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.’
Article 35(6b)
September Presidency compromise
Council wording reconstructed for this provision from the official operation
6b. The template and methodology referred to in paragraph 6a shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
Official source passage and amending instruction
9. Article 35 is amended as follows: (a) paragraphs 4, 5 and 6 are replaced by the following: ‘4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. 5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. 6. The lists referred to in paragraphs 4 and 5 shall be published by [OP date = 9 months from the date of entry into application of this Regulation]. These lists shall be reviewed by the Board at least every three years and updated where necessary.’ (b) the following paragraphs are inserted: ‘6a. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments. The template and methodology shall be submitted to the Commission by [OP date = 9 months from the date of entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6b. The template and methodology referred to in paragraph 6a shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.’
Article 35(6c)
September Presidency compromise
Council wording reconstructed for this provision from the official operation
6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.
Official source passage and amending instruction
9. Article 35 is amended as follows: (a) paragraphs 4, 5 and 6 are replaced by the following: ‘4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. 5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. 6. The lists referred to in paragraphs 4 and 5 shall be published by [OP date = 9 months from the date of entry into application of this Regulation]. These lists shall be reviewed by the Board at least every three years and updated where necessary.’ (b) the following paragraphs are inserted: ‘6a. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments. The template and methodology shall be submitted to the Commission by [OP date = 9 months from the date of entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6b. The template and methodology referred to in paragraph 6a shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.’
Article 35(4) 4 Council drafts
Article 35(4)
21 May 2026 · May Presidency compromise
Council wording reconstructed for this provision from the official operation
4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
Article 35(4)
10 June 2026 · June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
Article 35(4)
18 June 2026 · June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
Article 35(4)
3 September 2026 · September Presidency compromise
Council wording reconstructed for this provision from the official operation
4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
Official source passage and amending instruction
9. Article 35 is amended as follows: (a) paragraphs 4, 5 and 6 are replaced by the following: ‘4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. 5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. 6. The lists referred to in paragraphs 4 and 5 shall be published by [OP date = 9 months from the date of entry into application of this Regulation]. These lists shall be reviewed by the Board at least every three years and updated where necessary.’ (b) the following paragraphs are inserted: ‘6a. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments. The template and methodology shall be submitted to the Commission by [OP date = 9 months from the date of entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6b. The template and methodology referred to in paragraph 6a shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.’
Article 35(5) 4 Council drafts
Article 35(5)
21 May 2026 · May Presidency compromise
Council wording reconstructed for this provision from the official operation
5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.
Article 35(5)
10 June 2026 · June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.
Article 35(5)
18 June 2026 · June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.
Article 35(5)
3 September 2026 · September Presidency compromise
Council wording reconstructed for this provision from the official operation
5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.
Official source passage and amending instruction
9. Article 35 is amended as follows: (a) paragraphs 4, 5 and 6 are replaced by the following: ‘4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. 5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. 6. The lists referred to in paragraphs 4 and 5 shall be published by [OP date = 9 months from the date of entry into application of this Regulation]. These lists shall be reviewed by the Board at least every three years and updated where necessary.’ (b) the following paragraphs are inserted: ‘6a. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments. The template and methodology shall be submitted to the Commission by [OP date = 9 months from the date of entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6b. The template and methodology referred to in paragraph 6a shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.’
Article 35(6) 4 Council drafts
Article 35(6)
21 May 2026 · May Presidency compromise
Council wording reconstructed for this provision from the official operation
6. The Board shall establish and make public a common template and a common methodology for conducting data protection impact assessments.
Article 35(6)
10 June 2026 · June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
6. The Board shall establish and make public a common template and a common methodology for conducting data protection impact assessments.
Article 35(6)
18 June 2026 · June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
6. The Board shall establish and make public a common template and a common methodology for conducting data protection impact assessments.
Article 35(6)
3 September 2026 · September Presidency compromise
Council wording reconstructed for this provision from the official operation
6. The lists referred to in paragraphs 4 and 5 shall be published by [OP date = 9 months from the date of entry into application of this Regulation]. These lists shall be reviewed by the Board at least every three years and updated where necessary.
Official source passage and amending instruction
9. Article 35 is amended as follows: (a) paragraphs 4, 5 and 6 are replaced by the following: ‘4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. 5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. 6. The lists referred to in paragraphs 4 and 5 shall be published by [OP date = 9 months from the date of entry into application of this Regulation]. These lists shall be reviewed by the Board at least every three years and updated where necessary.’ (b) the following paragraphs are inserted: ‘6a. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments. The template and methodology shall be submitted to the Commission by [OP date = 9 months from the date of entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6b. The template and methodology referred to in paragraph 6a shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.’
Article 35(6a) 4 Council drafts
Article 35(6a)
21 May 2026 · May Presidency compromise
Council wording reconstructed for this provision from the official operation
6a. The lists referred to in paragraphs 4 and 5 and the template and methodology referred to in paragraph 6 shall be published within [OP date = 9 months of the entry into application of this Regulation]. The Commission may adopt the template as established by the Board by way of an implementing act, in accordance with the examination procedure set out in Article 93(2).
Article 35(6a)
10 June 2026 · June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
6a. The lists referred to in paragraphs 4 and 5 and the template and methodology referred to in paragraph 6 shall be published within [OP date = 9 months of the entry into application of this Regulation]. The Commission may adopt the template as established by the Board by way of an implementing act, in accordance with the examination procedure set out in Article 93(2).
Article 35(6a)
18 June 2026 · June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
6a. The lists referred to in paragraphs 4 and 5 and the template and methodology referred to in paragraph 6 shall be published within [OP date = 9 months of the entry into application of this Regulation].
Article 35(6a)
3 September 2026 · September Presidency compromise
Council wording reconstructed for this provision from the official operation
6a. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments. The template and methodology shall be submitted to the Commission by [OP date = 9 months from the date of entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
Official source passage and amending instruction
9. Article 35 is amended as follows: (a) paragraphs 4, 5 and 6 are replaced by the following: ‘4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. 5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. 6. The lists referred to in paragraphs 4 and 5 shall be published by [OP date = 9 months from the date of entry into application of this Regulation]. These lists shall be reviewed by the Board at least every three years and updated where necessary.’ (b) the following paragraphs are inserted: ‘6a. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments. The template and methodology shall be submitted to the Commission by [OP date = 9 months from the date of entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6b. The template and methodology referred to in paragraph 6a shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.’
Article 35(6b) 4 Council drafts
Article 35(6b)
21 May 2026 · May Presidency compromise
Council wording reconstructed for this provision from the official operation
The lists and the template and methodology referred to in paragraph 6a- shall be reviewed by the Board at least every three years and updated where necessary. The Commission may adopt any updates of the template by way of an implementing act following the procedure referred to in paragraph 6a.
Article 35(6b)
10 June 2026 · June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
The lists and the template and methodology referred to in paragraph 6a- shall be reviewed by the Board at least every three years and updated where necessary. Where the the Commission has adopted the previous version of the template by way of an implementing act, it shall adopt any updates of the template by way of an implementing act following the procedure referred to in paragraph 6a.
Article 35(6b)
18 June 2026 · June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
The lists and the template and methodology referred to in paragraph 6a- shall be reviewed by the Board at least every three years and updated where necessary. 6ba. The Commission may adopt the template and any updates referred to in paragraphs 6a and 6b, as established by the Board, by way of an implementing act following the examination procedure set out in Article 93(2).
Article 35(6b)
3 September 2026 · September Presidency compromise
Council wording reconstructed for this provision from the official operation
6b. The template and methodology referred to in paragraph 6a shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
Official source passage and amending instruction
9. Article 35 is amended as follows: (a) paragraphs 4, 5 and 6 are replaced by the following: ‘4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. 5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. 6. The lists referred to in paragraphs 4 and 5 shall be published by [OP date = 9 months from the date of entry into application of this Regulation]. These lists shall be reviewed by the Board at least every three years and updated where necessary.’ (b) the following paragraphs are inserted: ‘6a. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments. The template and methodology shall be submitted to the Commission by [OP date = 9 months from the date of entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6b. The template and methodology referred to in paragraph 6a shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.’
Article 35(6c) 4 Council drafts
Article 35(6c)
21 May 2026 · May Presidency compromise
Council wording reconstructed for this provision from the official operation
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraph 4 and
Article 35(6c)
10 June 2026 · June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraph 4 and
Article 35(6c)
18 June 2026 · June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraph 4 and
Article 35(6c)
3 September 2026 · September Presidency compromise
Council wording reconstructed for this provision from the official operation
6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.
Official source passage and amending instruction
9. Article 35 is amended as follows: (a) paragraphs 4, 5 and 6 are replaced by the following: ‘4. The Board shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. 5. The Board shall establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. 6. The lists referred to in paragraphs 4 and 5 shall be published by [OP date = 9 months from the date of entry into application of this Regulation]. These lists shall be reviewed by the Board at least every three years and updated where necessary.’ (b) the following paragraphs are inserted: ‘6a. The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments. The template and methodology shall be submitted to the Commission by [OP date = 9 months from the date of entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6b. The template and methodology referred to in paragraph 6a shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates by way of an implementing act in accordance with the examination procedure set out in Article 93(2). 6c. Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.’
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Political group at the amendment date where available; otherwise the current Parliament affiliation.
Alternative wording Amendment 58 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
TheBysupervisory…[POauthorityplease insert date: nine months from the entry into application of this amending Regulation] the Board shall establish and make publica list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. The supervisory authority shall communicate those lists to the Board referred to in Article 68.:- (a)
a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1;
- (b)
a list of the kind of processing operations for which no data protection impact assessment is required;
- (c)
a common template and a common methodology for conducting data protection impact assessments.
- (a)
- 5.
The supervisory authority may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. The supervisory authority shall communicate those lists to the Board.
- 6.
Prior to the adoption of the lists referred to in paragraphs 4 and 5, the competent supervisory authority shall apply the consistency mechanism referred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services to data subjects or to the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Union.
- 6a.
The Commission may adopt the template as established by the Board by way of an implementing act in accordance with the examination procedure set out in Article 93(2) of this Regulation.
- 6b.
The lists and the template and methodology referred to in paragraph 4 shall be reviewed by the Board at least every three years and updated where necessary. The Commission may adopt any updates of the template by way of an implementing act in accordance with the procedure referred to in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraph 4, points (a) and (b).
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
TheBy …[PO please insert date: nine months from the entry into application of this amending Regulation] the Board shallprepareestablish andtransmitmaketo the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.public:- (a)
a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1;
- (b)
a list of the kind of processing operations for which no data protection impact assessment is required;
- (c)
a common template and a common methodology for conducting data protection impact assessments.
- (a)
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Remove proposed wording Amendment 59 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
TheBysupervisory…[POauthorityplease insert date: nine months from the entry into application of this amending Regulation] the Board shall establish and make publica list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. The supervisory authority shall communicate those lists to the Board referred to in Article 68.:- (a)
a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1;
- (b)
a list of the kind of processing operations for which no data protection impact assessment is required;
- (c)
a common template and a common methodology for conducting data protection impact assessments.
- (a)
- 5.
The supervisory authority may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. The supervisory authority shall communicate those lists to the Board.
- 6.
Prior to the adoption of the lists referred to in paragraphs 4 and 5, the competent supervisory authority shall apply the consistency mechanism referred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services to data subjects or to the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Union.
- 6a.
The Commission may adopt the template as established by the Board by way of an implementing act in accordance with the examination procedure set out in Article 93(2) of this Regulation.
- 6b.
The lists and the template and methodology referred to in paragraph 4 shall be reviewed by the Board at least every three years and updated where necessary. The Commission may adopt any updates of the template by way of an implementing act in accordance with the procedure referred to in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraph 4, points (a) and (b).
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The
Boardsupervisoryshallauthoritypreparemay also establish andtransmitmaketo the Commission a proposal forpublic a list of the kind of processing operations for which no data protection impact assessment is required. The supervisory authority shall communicate those lists to the Board. - 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Remove proposed wording Amendment 60 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
TheBysupervisory…[POauthorityplease insert date: nine months from the entry into application of this amending Regulation] the Board shall establish and make publica list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. The supervisory authority shall communicate those lists to the Board referred to in Article 68.:- (a)
a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1;
- (b)
a list of the kind of processing operations for which no data protection impact assessment is required;
- (c)
a common template and a common methodology for conducting data protection impact assessments.
- (a)
- 5.
The supervisory authority may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. The supervisory authority shall communicate those lists to the Board.
- 6.
Prior to the adoption of the lists referred to in paragraphs 4 and 5, the competent supervisory authority shall apply the consistency mechanism referred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services to data subjects or to the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Union.
- 6a.
The Commission may adopt the template as established by the Board by way of an implementing act in accordance with the examination procedure set out in Article 93(2) of this Regulation.
- 6b.
The lists and the template and methodology referred to in paragraph 4 shall be reviewed by the Board at least every three years and updated where necessary. The Commission may adopt any updates of the template by way of an implementing act in accordance with the procedure referred to in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraph 4, points (a) and (b).
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmitPrior to theCommissionadoptionaofproposaltheforlistsareferredcommontotemplatein paragraphs 4 anda5,commonthemethodologycompetentforsupervisoryconductingauthority shall apply the consistency mechanism referred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services to dataprotectionsubjectsimpactorassessmentsto the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Union. - 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 61 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
TheBysupervisory…[POauthorityplease insert date: nine months from the entry into application of this amending Regulation] the Board shall establish and make publica list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. The supervisory authority shall communicate those lists to the Board referred to in Article 68.:- (a)
a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1;
- (b)
a list of the kind of processing operations for which no data protection impact assessment is required;
- (c)
a common template and a common methodology for conducting data protection impact assessments.
- (a)
- 5.
The supervisory authority may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. The supervisory authority shall communicate those lists to the Board.
- 6.
Prior to the adoption of the lists referred to in paragraphs 4 and 5, the competent supervisory authority shall apply the consistency mechanism referred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services to data subjects or to the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Union.
- 6a.
The Commission may adopt the template as established by the Board by way of an implementing act in accordance with the examination procedure set out in Article 93(2) of this Regulation.
- 6b.
The lists and the template and methodology referred to in paragraph 4 shall be reviewed by the Board at least every three years and updated where necessary. The Commission may adopt any updates of the template by way of an implementing act in accordance with the procedure referred to in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraph 4, points (a) and (b).
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The
proposalsCommissionformaythe lists referred to in paragraphs 4 and 5 and foradopt the templateandasmethodologyestablishedreferred to in paragraph 6 shall be submitted toby theCommission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt themBoard by way of an implementing act in accordance with the examination procedure set out in Article 93(2) of this Regulation. - 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 62 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
TheBysupervisory…[POauthorityplease insert date: nine months from the entry into application of this amending Regulation] the Board shall establish and make publica list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. The supervisory authority shall communicate those lists to the Board referred to in Article 68.:- (a)
a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1;
- (b)
a list of the kind of processing operations for which no data protection impact assessment is required;
- (c)
a common template and a common methodology for conducting data protection impact assessments.
- (a)
- 5.
The supervisory authority may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. The supervisory authority shall communicate those lists to the Board.
- 6.
Prior to the adoption of the lists referred to in paragraphs 4 and 5, the competent supervisory authority shall apply the consistency mechanism referred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services to data subjects or to the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Union.
- 6a.
The Commission may adopt the template as established by the Board by way of an implementing act in accordance with the examination procedure set out in Article 93(2) of this Regulation.
- 6b.
The lists and the template and methodology referred to in paragraph 4 shall be reviewed by the Board at least every three years and updated where necessary. The Commission may adopt any updates of the template by way of an implementing act in accordance with the procedure referred to in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraph 4, points (a) and (b).
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph
6a-4 shall be reviewed by the Board at least every three years and updated where necessary. TheBoard shall submit its assessment and possible proposals for updates to theCommissionin due time. The Commission after due consideration of the proposals reviews them and is empowered tomay adopt any updatesfollowingof the template by way of an implementing act in accordance with the procedure referred to in paragraph 6a. - 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 63 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
TheBysupervisory…[POauthorityplease insert date: nine months from the entry into application of this amending Regulation] the Board shall establish and make publica list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. The supervisory authority shall communicate those lists to the Board referred to in Article 68.:- (a)
a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1;
- (b)
a list of the kind of processing operations for which no data protection impact assessment is required;
- (c)
a common template and a common methodology for conducting data protection impact assessments.
- (a)
- 5.
The supervisory authority may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. The supervisory authority shall communicate those lists to the Board.
- 6.
Prior to the adoption of the lists referred to in paragraphs 4 and 5, the competent supervisory authority shall apply the consistency mechanism referred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services to data subjects or to the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Union.
- 6a.
The Commission may adopt the template as established by the Board by way of an implementing act in accordance with the examination procedure set out in Article 93(2) of this Regulation.
- 6b.
The lists and the template and methodology referred to in paragraph 4 shall be reviewed by the Board at least every three years and updated where necessary. The Commission may adopt any updates of the template by way of an implementing act in accordance with the procedure referred to in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraph 4, points (a) and (b).
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the
CommissionBoardadoptsestablishes and makes public theimplementing actlists referred to in paragraph6a4, points (a) and (b). - 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 390 · Morten Løkkegaard, Svenja Hahn, Jeannette Baljeu, Sandro Gozi IMCO
Justification
Keeps the simplification agenda credible for smaller businesses and not only for large compliance departments.
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments. The template and methodology shall be proportionate, risk-based and easily usable by SMEs and small mid-cap enterprises, including in cross-border processing activities.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Additional proposed wording Amendment 391 · Virginie Joron IMCO
The common template and methodology for conducting data protection impact assessments shall require the controller to evaluate the following:
the risk of reidentification, including using algorithms, and taking into account the means reasonably likely to be used;
the availability and suitability of state-of-the-art privacy-preserving and privacy-strengthening methods to remove or mitigate this risk, including pseudonymisation, encryption, aggregation, synthetic data, federated analytics and secure processing environments; and
the risk remaining after applying such techniques.
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The
proposals for the lists referred to in paragraphs 4 and 5 and for thecommon template and methodologyreferredfor conducting data protection impact assessments shall require the controller toin paragraph 6 shall be submitted toevaluate theCommission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).following:- (a)
the risk of reidentification, including using algorithms, and taking into account the means reasonably likely to be used;
- (b)
the availability and suitability of state-of-the-art privacy-preserving and privacy-strengthening methods to remove or mitigate this risk, including pseudonymisation, encryption, aggregation, synthetic data, federated analytics and secure processing environments; and
- (c)
the risk remaining after applying such techniques.
- (a)
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 392 · Morten Løkkegaard, Svenja Hahn, Jeannette Baljeu, Sandro Gozi IMCO
Justification
A common DPIA template only reduces burden if it prevents 27 additional national variants.
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act, which shall be directly applicable across the Union. Supervisory authorities shall not require controllers to use additional national templates, methodologies or lists for the same processing operations covered by that implementing act. in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Additional proposed wording Amendment 393 · Virginie Joron IMCO
The proposals referred to in paragraphs 4, 5 and 6 shall be without prejudice to the right of the competent authorities and the supervisory authorities of the Member States to draw up their own guidance, standards and lists, in particular the lists referred to in Article 35(4) and (5). The Board shall take into account this national guidance and these national standards and lists when developing the common templates, methodology and lists referred to in these paragraphs.
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals
forreferred to in paragraphs 4, 5 and 6 shall be without prejudice to the right of the competent authorities and the supervisory authorities of the Member States to draw up their own guidance, standards and lists, in particular the lists referred to inparagraphsArticle 35(4) and (5). The Board shall take into account this national guidance andforthese national standards and lists when developing thetemplatecommon templates, methodology andmethodologylists referred to inparagraphthese6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]paragraphs.The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). - 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1203 · Pernando Barrena Arza ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
TheBy … [nine months from the entry into application of this amending Regulation], the Board shallprepareestablish andtransmitmaketo the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.public:- (a)
a Union-level list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1;
- (b)
a Union-level list of the kind of processing operations for which no data protection impact assessment is required;
- (c)
a common template and a common methodology for conducting data protection impact assessments.
-
The lists referred to in points (a) and (b) shall support the consistent application of this Regulation and shall not prevent supervisory authorities from establishing and making public additional lists of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1, where such processing operations are likely to result in a high risk in the context of the Member State concerned.
- (a)
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1204 · Niels Flemming Hansen ITRE · LIBE
Justification
Reducing fragmentation and legal uncertainty while ensuring that compliance requirements remain proportionate and focused on genuinely high-risk activities should be at the core of the Digital Omnibus, in order to avoid unnecessary burdens for SMEs.
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. In preparing its proposal, the Board shall take due account of the lists established and made public by supervisory authorities and relevant guidance of the Board, and shall ensure that its proposal reflects a consistent and proportionate approximation of the common elements of those lists, focusing on processing operations most likely to result in high risk. Newly identified triggers shall apply prospectively to new processing or materially changed processing.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1205 · Krzysztof Hetman, Adam Jarubas ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. In preparing its proposal, the Board shall take due account the lists of processing operations established and made public by supervisory authorities and shall ensure that its proposal reflects a consistent and proportionate approximation of the processing operations identified in those lists, taking into account the principle of legal certainty.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1206 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall
prepareestablish andtransmitmaketo the Commission a proposal forpublic a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. - 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1207 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and
transmit to the Commissionpublish a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. - 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1208 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall
prepareestablish andtransmitmaketo the Commission a proposal forpublic a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. - 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1209 · Oliver Schenk, Axel Voss, Marie-Sophie Lanig, Marion Walsmann, Lena Düpont, Ana Miguel Pedro, Andrea Wechsler, Angelika Niebler, Monika Hohlmeier, Dimitris Tsiodras, Christian Doleschal, Romana Tomc, François-Xavier Bellamy ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall
prepareestablish andtransmitmaketo the Commission a proposal forpublic a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph1. - 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1210 · Sibylle Berg, Martin Sonneborn ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and
transmit to the Commissionpublish a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. - 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1211 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall
prepareestablish andtransmitmaketo the Commission a proposal forpublic a list of the kind of processing operations for which no data protection impact assessment is required. - 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1212 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and
transmit to the Commissionpublish a proposal for a list of the kind of processing operations for which no data protection impact assessment is required. - 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1213 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall
prepareestablish andtransmitmaketo the Commission a proposal forpublic a list of the kind of processing operations for which no data protection impact assessment is required. - 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1214 · Oliver Schenk, Axel Voss, Marie-Sophie Lanig, Ana Miguel Pedro, Lena Düpont, Marion Walsmann, Romana Tomc, Andrea Wechsler, Angelika Niebler, Monika Hohlmeier, Dimitris Tsiodras, Christian Doleschal, François-Xavier Bellamy ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
TheProcessingBoardoperations not covered by the list in paragraph 4 shallpreparenotandbetransmitsubject to theCommission a proposalrequirement for alist of the kind of processing operations for which nodata protection impact assessmentispursuantrequiredto paragraph 1. - 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1215 · Sibylle Berg, Martin Sonneborn ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and
transmit to the Commissionpublish a proposal for a list of the kind of processing operations for which no data protection impact assessment is required. - 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Additional proposed wording Amendment 1216 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
5a. In Article 35, the following paragraph is inserted:
For processing operations that are on none of the lists in paragraph 4 and 5, the controller is required to assess the need for a data protection impact assessment.'
Justification
To clarify that both lists combined cannot possibly cover the whole universe, but contain the clear edge cases.
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 5a.
For processing operations that are on none of the lists in paragraph 4 and 5, the controller is required to assess the need for a data protection impact assessment.'
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1217 · Oliver Schenk, Eva Maydell, Andrea Wechsler, Angelika Niebler, Monika Hohlmeier, Dimitris Tsiodras, Christian Doleschal, Marie-Sophie Lanig, Axel Voss, Ana Miguel Pedro, Romana Tomc, Marion Walsmann, Lena Düpont, François-Xavier Bellamy ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall
prepare and transmit to the Commission a proposal forestablish a common template and a common methodology for conducting data protection impact assessments. - 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1218 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall
prepareestablish andtransmitmaketo the Commission a proposal forpublic a common template and a common methodology for conducting data protection impact assessments. - 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1219 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and
transmitmaketo the Commissionpublic a proposal for a common template and a common methodology for conducting data protection impact assessments. - 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Additional proposed wording Amendment 1220 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
6a. In Article 35, the following paragraph is inserted:
The common template and methodology for data protection impact assessments shall require the controller to assess:
the risk of re-identification, including by algorithmic means and taking into account the means reasonably likely to be used;
the availability and suitability of state-of-the-art privacy-preserving and privacy-enhancing techniques to remove or mitigate that risk, including pseudonymisation, encryption, aggregation, synthetic data, federated analysis and secure processing environments; and
the residual risk after application of such techniques.'
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The
proposals for the lists referred to in paragraphs 4 and 5 and for thecommon template and methodologyreferredfor data protection impact assessments shall require the controller toin paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).assess:- (a)
the risk of re-identification, including by algorithmic means and taking into account the means reasonably likely to be used;
- (b)
the availability and suitability of state-of-the-art privacy-preserving and privacy-enhancing techniques to remove or mitigate that risk, including pseudonymisation, encryption, aggregation, synthetic data, federated analysis and secure processing environments; and
- (c)
the residual risk after application of such techniques.'
- (a)
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Additional proposed wording Amendment 1221 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
In Article 35, the following paragraphs 6a, 6b, 6c are inserted:
The lists referred to in paragraphs 4 and 5 and the template and methodology referred to in paragraph 6 shall be published within [PO insert date: 9 months after the entry into application of this amending Regulation]. The Commission is empowered to decide that the lists, the template and the methodology as established by the Board have general validity within the Union by way of implementing acts in accordance with the examination procedure set out in Article 93(2).
The lists and the template and methodology referred to in paragraph 6a shall be reviewed by the Board and updated where necessary. The Commission is empowered to decide that the updated list, template and methodology have general validity within the Union by way of an implementing act following the procedure referred to in paragraph 6a.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Board establishes and makes public the lists referred to in paragraphs 4 and 5.
Justification
modeled after Article 40(9) GDPR on Codes of Conduct
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The
proposals for thelists referred to in paragraphs 4 and 5 andforthe template and methodology referred to in paragraph 6 shall besubmitted to the Commissionpublished within [OPPO insert date=: 9 monthsofafter the entry into application of this amending Regulation]. The Commissionafter due consideration reviews them, as necessary, andis empowered toadoptdecidethemthat the lists, the template and the methodology as established by the Board have general validity within the Union by way ofanimplementingactacts in accordance with the examination procedure set out in Article 93(2). - 6b.
The lists and the template and methodology referred to in paragraph 6a
-shall be reviewedatbyleasttheevery three yearsBoard and updated where necessary. TheBoard shall submit its assessment and possible proposals for updates to theCommissionin due time. The Commission after due consideration of the proposals reviews them andis empowered toadoptdecideanythatupdatesthe updated list, template and methodology have general validity within the Union by way of an implementing act following the procedure referred to in paragraph 6a. - 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the
CommissionBoardadoptsestablishes and makes public theimplementing actlists referred to inparagraphparagraphs6a4 and 5. - 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Additional proposed wording Amendment 1222 · Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller, Christophe Grudler ITRE · LIBE
(aa) In Article 35, paragraph 1 is replaced by the following:
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. Where children are affected by the processing, the risks and consequences that the processing may have on their specific rights shall be explicitly addressed. A single assessment may address a set of similar processing operations that present similar risks.
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. Where children are affected by the processing, the risks and consequences that the processing may have on their specific rights shall be explicitly addressed. A single assessment may address a set of similar processing operations that present similar
highrisks. - 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Additional proposed wording Amendment 1223 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
(aa) In Article 35, the following paragraph is inserted:
The proposals referred to in paragraphs 4, 5 and 6 shall be without prejudice to the right of the competent authorities and supervisory authorities of the Member States to develop their own guidance, standards and lists, in particular the lists referred to in Article 35(4) and (5). The Board shall take such national guidance, standards and lists into account when preparing the common templates, methodology and lists referred to in those paragraphs.'
Justification
The preparation by the Board of common templates, a common methodology and common lists relating to data protection impact assessments contributes to a consistent application of this Regulation. However, this harmonisation of form should not deprive the competent authorities and supervisory authorities of the Member States of their power — recognised in particular in Article 35(4) and (5) — to develop their own guidance, standards and lists reflecting national circumstances. This amendment confirms that the proposals referred to in paragraphs 4, 5 and 6 are without prejudice to that power, and provides that the Board shall take such national guidance, standards and lists into account when preparing the common instruments. This ensures a bottom-up articulation between the national and Union levels, preserving both consistency and the ability of national authorities to address specific national risks.
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The
lists and the template and methodologyproposals referred to inparagraphparagraphs6a-4, 5 and 6 shall bereviewedwithoutatprejudiceleasttoeverythethreerightyearsof the competent authorities andupdatedsupervisorywhereauthoritiesnecessaryof the Member States to develop their own guidance, standards and lists, in particular the lists referred to in Article 35(4) and (5). The Board shallsubmittakeitssuchassessmentnational guidance, standards andpossiblelistsproposalsintoforaccountupdateswhen preparing the common templates, methodology and lists referred tothe Commissioninduethosetimeparagraphs.The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.' - 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1224 · Oliver Schenk, Andrea Wechsler, Monika Hohlmeier, Angelika Niebler, Dimitris Tsiodras, Christian Doleschal, Axel Voss, Ana Miguel Pedro, Marion Walsmann, Lena Düpont, Romana Tomc, Marie-Sophie Lanig, François-Xavier Bellamy ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The
proposalsproposal for thelistslist referred to inparagraphsparagraph 4and 5and for the template and methodology referred to in paragraph6 shall be submitted to the Commissionwithin [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). That list shall be based on convergence area from national authorities and shall not introduce new categories of processing operations that go beyond existing obligations under this Regulation. Processing operations lawfully in place at the time of their initiation shall not be subject to a retroactive obligation to carry out a data protection impact assessment as a result of the adoption of the harmonised list. - 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1225 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The
proposals for thelists referred to in paragraphs 4 and 5 andforthe template and methodology referred to in paragraph 6 shall besubmitted to the Commissionpublished within [OP date = 9 months of the entry into application of this Regulation].The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). - 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1226 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The
proposals for thelists referred to in paragraphs 4 and 5 andforthe template and methodology referred to in paragraph 6 shall besubmittedmade public to the Commission within [OP date = 9 months of the entry into application of this Regulation].The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2). - 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1227 · Pernando Barrena Arza ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation].The Commissionaftermaydueadoptconsiderationthereviewscommonthem,templateasestablishednecessary,byandtheisBoardempoweredpursuant toadoptparagraphthem4, point (c), by way of an implementing act in accordance with the examination procedure set out in Article 93(2). The Commission shall not modify the substance of the common methodology or of the lists established by the Board pursuant to paragraph 4, points (a) and (b). - 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1228 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a
-shall be reviewed at least every three years and updated where necessary.The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a. - 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1229 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed by the Board at least every three years and updated where necessary.
The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a. - 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Additional proposed wording Amendment 1230 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
In Article 35, the following paragraph 6ba is inserted
6ba. The Commission may adopt the template and any updates referred to in paragraphs 6a and 6b, as established by the Board, by way of an implementing act following the examination procedure set out in Article 93(2).
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
- ba.
6ba. The Commission may adopt the template and any updates referred to in paragraphs 6a and 6b, as established by the Board, by way of an implementing act following the examination procedure set out in Article 93(2).
Alternative wording Amendment 1231 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
ListsTheoflists and thekind of processing operations which are subject to the requirement for a data protection impact assessmenttemplate andof the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing actmethodology referred to in paragraph 6a-shall be reviewed by the Board at least every three years and updated where necessary. - 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1232 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid
until the Commission adopts the implementing act referred to in paragraph 6a. - 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Additional proposed wording Amendment 1233 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
6ca. In Article 35, the following paragraph is inserted:
A data protection impact assessment shall not be required, on the sole basis of the Union list referred to in Article 35(4), for processing operations that were already underway before [the date of application of that list], provided that those operations have not since been subject to substantial modification. This is without prejudice to the obligation to carry out an assessment where processing is likely to result in a high risk on other grounds under Article 35(1).'
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for aA data protection impact assessmentandshall not be required, on the sole basis of thekindUnionof processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing actlist referred to inparagraphArticle6a35(4), for processing operations that were already underway before [the date of application of that list], provided that those operations have not since been subject to substantial modification. This is without prejudice to the obligation to carry out an assessment where processing is likely to result in a high risk on other grounds under Article 35(1).' - 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Additional proposed wording Amendment 1234 · Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller, Christophe Grudler ITRE · LIBE
(ba) In paragraph 7 of Article 35, points c and d are replaced by the following
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1, taking particular account where the personal data of a child is concerned; and
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned, in particular children.
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1, taking particular account where the personal data of a child is concerned; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned, in particular children.
- (d)
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Additional proposed wording Amendment 1235 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
9a. In Article 35, the following paragraph 7a is inserted:
Where, in respect of the same processing operation or activity, the controller is required to carry out a data protection impact assessment under this Article and is also subject to an obligation to carry out a fundamental rights impact assessment under Article 27 of Regulation (EU) 2024/1689, or to a reporting obligation in respect of automated monitoring or decision-making systems under other Union law, those obligations may be satisfied by means of a single integrated assessment.
The integrated assessment shall be deemed to satisfy each of those obligations only where it covers all the elements required by each applicable provision. The substantive requirements, thresholds and triggering conditions laid down in those provisions remain unaffected.
A data protection impact assessment carried out under this Article that addresses the elements required for the fundamental rights impact assessment under Article 27 of Regulation (EU) 2024/1689 shall be relied upon in accordance with Article 27(4) of that Regulation, without duplication.
The integrated assessment shall be made available to each competent authority within the framework of its respective competences. This paragraph does not modify the allocation of supervisory competences under the acts referred to in the first subparagraph, nor does it require submission of the assessment to a single authority.'
Justification
Where, for the same processing operation, a controller must carry out a data protection impact assessment under Article 35 and a fundamental rights impact assessment under Article 27 of Regulation (EU) 2024/1689, or a reporting obligation in respect of automated monitoring systems, those obligations may be satisfied by a single integrated assessment. The assessment satisfies each obligation only where it covers all the elements required by each provision; the substantive requirements, thresholds and triggering conditions remain unaffected. The assessment is made available to each competent authority within its respective competences and is not submitted to a single authority: the documentary instrument is mutualised, not the supervisory competence.
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 7a.
Where, in respect of the same processing operation or activity, the controller is required to carry out a data protection impact assessment under this Article and is also subject to an obligation to carry out a fundamental rights impact assessment under Article 27 of Regulation (EU) 2024/1689, or to a reporting obligation in respect of automated monitoring or decision-making systems under other Union law, those obligations may be satisfied by means of a single integrated assessment.
The integrated assessment shall be deemed to satisfy each of those obligations only where it covers all the elements required by each applicable provision. The substantive requirements, thresholds and triggering conditions laid down in those provisions remain unaffected.
A data protection impact assessment carried out under this Article that addresses the elements required for the fundamental rights impact assessment under Article 27 of Regulation (EU) 2024/1689 shall be relied upon in accordance with Article 27(4) of that Regulation, without duplication.
The integrated assessment shall be made available to each competent authority within the framework of its respective competences. This paragraph does not modify the allocation of supervisory competences under the acts referred to in the first subparagraph, nor does it require submission of the assessment to a single authority.'
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.
- 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Remove proposed wording Amendment 1236 · Henrik Dahl ITRE · LIBE
against:
Article 35
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The Board shall prepare and transmit to the Commission a proposal for a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
The Board shall prepare and transmit to the Commission a proposal for a common template and a common methodology for conducting data protection impact assessments.
- 6a.
The proposals for the lists referred to in paragraphs 4 and 5 and for the template and methodology referred to in paragraph 6 shall be submitted to the Commission within [OP date = 9 months of the entry into application of this Regulation]. The Commission after due consideration reviews them, as necessary, and is empowered to adopt them by way of an implementing act in accordance with the examination procedure set out in Article 93(2).
- 6b.
The lists and the template and methodology referred to in paragraph 6a-shall be reviewed at least every three years and updated where necessary. The Board shall submit its assessment and possible proposals for updates to the Commission in due time. The Commission after due consideration of the proposals reviews them and is empowered to adopt any updates following the procedure in paragraph 6a.
- 6c.
Lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment and of the kind of processing operations for which no data protection impact assessment is required established and made public by supervisory authorities remain valid until the Commission adopts the implementing act referred to in paragraph 6a.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations. - 10.
Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Article 35(4)
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
RemovedAdded
Both texts in full
European Commission proposal
Council Presidency text · ST 9547/26
Article 35(4)
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Article 35(4)
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Article 35(4)
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Council Presidency text · ST 12535/26
Article 35(4)
Wording reproduced in the amendment → Amendment 1203 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1203 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(4)
Wording reproduced in the amendment → Amendment 1204 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1204 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(4)
Wording reproduced in the amendment → Amendment 1205 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1205 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(4)
Wording reproduced in the amendment → Amendment 1206 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1206 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(4)
Wording reproduced in the amendment → Amendment 1207 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1207 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(4)
Wording reproduced in the amendment → Amendment 1208 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1208 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(4)
Wording reproduced in the amendment → Amendment 1209 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1209 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(4)
Wording reproduced in the amendment → Amendment 1210 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1210 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(4)
Wording reproduced in the amendment → Amendment 58 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 58 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Article 35(5)
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
RemovedAdded
Both texts in full
European Commission proposal
Council Presidency text · ST 9547/26
Article 35(5)
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Article 35(5)
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Article 35(5)
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Council Presidency text · ST 12535/26
Article 35(5)
Wording reproduced in the amendment → Amendment 1211 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1211 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(5)
Wording reproduced in the amendment → Amendment 1212 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1212 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(5)
Wording reproduced in the amendment → Amendment 1213 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1213 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(5)
Wording reproduced in the amendment → Amendment 1214 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1214 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(5)
Wording reproduced in the amendment → Amendment 1215 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1215 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(5)
Wording reproduced in the amendment → Amendment 59 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs): removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 59 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs): removal
This wording is removed.
Article 35(6)
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
RemovedAdded
Both texts in full
European Commission proposal
Council Presidency text · ST 9547/26
Article 35(6)
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Article 35(6)
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Article 35(6)
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Council Presidency text · ST 12535/26
Article 35(6)
Wording reproduced in the amendment → Amendment 1217 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1217 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(6)
Wording reproduced in the amendment → Amendment 1218 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1218 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(6)
Wording reproduced in the amendment → Amendment 1219 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1219 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(6)
Wording reproduced in the amendment → Amendment 1228 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1228 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(6)
Wording reproduced in the amendment → Amendment 60 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs): removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 60 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs): removal
This wording is removed.
Article 35(6)
Wording reproduced in the amendment → Amendment 390 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 390 · IMCO amendments 329–532 to the draft opinion
Article 35(6a)
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
RemovedAdded
Both texts in full
European Commission proposal
Council Presidency text · ST 9547/26
Article 35(6a)
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Article 35(6a)
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Article 35(6a)
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Council Presidency text · ST 12535/26
Article 35(6a)
Wording reproduced in the amendment → Amendment 1224 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1224 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(6a)
Wording reproduced in the amendment → Amendment 1225 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1225 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(6a)
Wording reproduced in the amendment → Amendment 1226 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1226 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(6a)
Wording reproduced in the amendment → Amendment 1227 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1227 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(6a)
Wording reproduced in the amendment → Amendment 61 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 61 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Article 35(6a)
Wording reproduced in the amendment → Amendment 392 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 392 · IMCO amendments 329–532 to the draft opinion
Article 35(6b)
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
RemovedAdded
Both texts in full
European Commission proposal
Council Presidency text · ST 9547/26
Article 35(6b)
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Article 35(6b)
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Article 35(6b)
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Council Presidency text · ST 12535/26
Article 35(6b)
Wording reproduced in the amendment → Amendment 1229 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1229 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(6b)
Wording reproduced in the amendment → Amendment 62 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 62 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Article 35(6c)
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
RemovedAdded
Both texts in full
European Commission proposal
Council Presidency text · ST 9547/26
Article 35(6c)
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Article 35(6c)
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Article 35(6c)
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Council Presidency text · ST 12535/26
Article 35(6c)
Wording reproduced in the amendment → Amendment 1231 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1231 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(6c)
Wording reproduced in the amendment → Amendment 1232 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1232 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 35(6c)
Wording reproduced in the amendment → Amendment 63 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 63 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Article 35 – paragraph 9
Wording reproduced in the amendment → Amendment 1236 · ITRE–LIBE amendments 1053–1260 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1236 · ITRE–LIBE amendments 1053–1260 to the draft report: removal
This wording is removed.