GDPR · Regulation (EU) 2016/679
Article 39
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 2 parts · 0 Council drafts · 2 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to GDPRThe wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to these tracked parts.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Additional proposed wording Amendment 1240 · Axel Voss ITRE · LIBE
In Article 39, paragraph 1 the following point ea is added
to handle complaints from a data subject or complaints from a body, organisation or association pursuant to Article 80 against the processing of personal data by the controller or the processor, to investigate the subject matter of the complaint to an appropriate extent, and to advise the controller or the processor on appropriate remedial measures in the event of a breach of this Regulation.
Justification
DPO Package #3: The amendment strengthens accountability by recognising DPOs as practical governance safeguards and first points of contact for complaints. DPOs already advise controllers and processors, monitor compliance and support data subjects; giving them an explicit complaint-handling role makes resolution faster, less bureaucratic and closer to the facts. Voluntary or shared DPOs are encouraged. Supervisory authorities remain available where the complaint is not addressed or not fully remedied within one month.
against:
Article 39
Tasks of the data protection officer
- 1.
The data protection officer shall have at least the following tasks:
- (a)
to inform and advise the controller or the processor and the employees who carry out processing of their obligations pursuant to this Regulation and to other Union or Member State data protection provisions;
- (b)
to monitor compliance with this Regulation, with other Union or Member State data protection provisions and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits;
- (c)
to provide advice where requested as regards the data protection impact assessment and monitor its performance pursuant to Article 35;
- (d)
to cooperate with the supervisory authority;
- (e)
to act as the contact point for the supervisory authority on issues relating to processing, including the prior consultation referred to in Article 36, and to consult, where appropriate, with regard to any other matter.
- (ea)
to handle complaints from a data subject or complaints from a body, organisation or association pursuant to Article 80 against the processing of personal data by the controller or the processor, to investigate the subject matter of the complaint to an appropriate extent, and to advise the controller or the processor on appropriate remedial measures in the event of a breach of this Regulation.
- (a)
- 2.
The data protection officer shall in the performance of his or her tasks have due regard to the risk associated with processing operations, taking into account the nature, scope, context and purposes of processing.
Alternative wording Amendment 1242 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 39
Tasks of the data protection officer
- 1.
The data protection officer shall have at least the following tasks:
- (a)
to inform and advise the controller or the processor and the employees who carry out processing of their obligations pursuant to this Regulation and to other Union or Member State data protection provisions;
- (b)
to monitor compliance with this Regulation, with other Union or Member State data protection provisions and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits;
- (c)
to provide advice where requested as regards the data protection impact assessment and monitor its performance pursuant to Article 35;
- (d)
to cooperate with the supervisory authority;
- (e)
to act as the contact point for the supervisory authority on issues relating to processing, including the prior consultation referred to in Article 36, and to consult, where appropriate, with regard to any other matter.
- (a)
- 2.
The data protection officer shall in the performance of his or her tasks have due regard to the risk associated with processing operations, taking into account the nature, scope, context and purposes of processing, including, where the data protection officer acts for several enterprises pursuant to Article 37(2a) or (4a), the specific processing operations of each of them."
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Article 39 – paragraph 2
Wording reproduced in the amendment → Amendment 1242 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded