GDPR · Regulation (EU) 2016/679
Article 41b
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 1 part · 0 Council drafts · 2 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to GDPRThe wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to these tracked parts.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Additional proposed wording Amendment 1301 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
10a. The following Article 41b is inserted
Article 41b
Guidelines on the recipient-specific assessment of data resulting from pseudonymisation 1. The European Data Protection Board established by Article 68 of Regulation (EU) 2016/679 shall issue guidelines on the application of Article 4, point (1), to data resulting from pseudonymisation, in particular where such data are disclosed to a recipient and may be considered not to constitute personal data for that recipient.
Those guidelines shall address, in particular:
the criteria for assessing whether a recipient is realistically able to identify the data subject, either from the data alone or by combining the data with other information reasonably available to it;
the information, documentation and commitments that may be provided by the recipient concerning its means, access rights, available datasets, technical capabilities, organisational measures, and legal or contractual restrictions;
the proportionate due diligence to be carried out by the controller disclosing the data before relying on the conclusion that the recipient is not realistically able to identify the data subject;
the conditions under which recipients may be grouped by category where their relevant circumstances are materially equivalent;
the evidence to be retained by the controller and, where relevant, by the recipient, in order to demonstrate the basis for the assessment to the competent supervisory authority upon request;
the circumstances in which a material change in the recipient's means, access rights, available datasets, technical capabilities, organisational measures, or legal or contractual restrictions requires the assessment to be reviewed; and
the effect of such assessment on the qualification of the data for the controller, the recipient and any other person that is realistically able to identify the data subject.
The guidelines referred to in paragraph 1 shall take into account the state of the art; relevant case law; supervisory practice; risks of identification through attribution, singling out, linkage, or inference; and the use of technical and organisational measures reducing the risk of identification.
Those guidelines shall not alter the definition of personal data under Article 4, point (1), create a presumption that data resulting from pseudonymisation are not personal data, or reduce the level of protection of personal data under this Regulation.
against:
Article 41b
Guidelines on the recipient-specific assessment of data resulting from pseudonymisation
- 1.
The European Data Protection Board established by Article 68 of Regulation (EU) 2016/679 shall issue guidelines on the application of Article 4, point (1), to data resulting from pseudonymisation, in particular where such data are disclosed to a recipient and may be considered not to constitute personal data for that recipient.
- 2.
Those guidelines shall address, in particular:
- (a)
the criteria for assessing whether a recipient is realistically able to identify the data subject, either from the data alone or by combining the data with other information reasonably available to it;
- (b)
the information, documentation and commitments that may be provided by the recipient concerning its means, access rights, available datasets, technical capabilities, organisational measures, and legal or contractual restrictions;
- (c)
the proportionate due diligence to be carried out by the controller disclosing the data before relying on the conclusion that the recipient is not realistically able to identify the data subject;
- (d)
the conditions under which recipients may be grouped by category where their relevant circumstances are materially equivalent;
- (e)
the evidence to be retained by the controller and, where relevant, by the recipient, in order to demonstrate the basis for the assessment to the competent supervisory authority upon request;
- (f)
the circumstances in which a material change in the recipient's means, access rights, available datasets, technical capabilities, organisational measures, or legal or contractual restrictions requires the assessment to be reviewed; and (g) the effect of such assessment on the qualification of the data for the controller, the recipient and any other person that is realistically able to identify the data subject.
- (a)
- 3.
The guidelines referred to in paragraph 1 shall take into account the state of the art; relevant case law; supervisory practice; risks of identification through attribution, singling out, linkage, or inference; and the use of technical and organisational measures reducing the risk of identification.
- 4.
Those guidelines shall not alter the definition of personal data under Article 4, point (1), create a presumption that data resulting from pseudonymisation are not personal data, or reduce the level of protection of personal data under this Regulation.
Additional proposed wording Amendment 1302 · Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Henrik Dahl, Andrea Wechsler, Oliver Schenk, Pekka Toveri, Christian Ehler ITRE · LIBE
10a. The following Article 41b is inserted
Article 41b
Application of pseudonymisation and identification of a natural person
Controllers and processors may apply pseudonymisation, and anonymisation, or other Privacy Enhancing Technologies referred to in Article 25a to personal data in order to reduce the risks to the data subjects concerned and to help meet their obligations under this Regulation, in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information. To determine whether a natural person is identifiable, including through personal data having undergone pseudonymisation, account shall be taken of all the means reasonably likely to be used, such as singling out or online identifiers, either by the controller or by another person to identify the natural person directly or indirectly.
Paragraph 1 is without prejudice to other provisions and obligations applicable to the controller and processor, including under Chapter IV and V of this Regulation.
The Board shall issue an opinion, in accordance with Article 64(2) of this Regulation, addressing the application of pseudonymisation and anonymisation to personal data, including related technical and organisational measures, and specifying means and criteria to determine whether and when such may effectively prevent persons other than the controller from identifying a data subject, in such a way that, for them, the data subject is not or is no longer identifiable, and where information relating to the data subject no longer constitutes personal data for that person other than the controller.
The Chair of the Board shall request the opinion referred to in paragraph 3 no later than 6 months after the entry into force of this Regulation. The opinion shall be reviewed and updated where necessary.
The Commission may adopt implementing acts specifying technical and organisational criteria, methodologies and standards where necessary to ensure uniform conditions for the application of paragraphs 1 and 3, or where further clarity is required following the issuance of the opinion referred to in paragraph 3, The Commission shall closely involve the EDPB in the preparations of the implementing acts. The EPDB shall issue an opinion on the draft implementing acts within a deadline of 8 weeks as of the receipt of the draft from the Commission. The Implementing Acts shall be adopted in accordance with the examination procedure referred to in Article 93(3).
against:
Article 41b
Application of pseudonymisation and identification of a natural person
- 1.
Controllers and processors may apply pseudonymisation, and anonymisation, or other Privacy Enhancing Technologies referred to in Article 25a to personal data in order to reduce the risks to the data subjects concerned and to help meet their obligations under this Regulation, in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information. To determine whether a natural person is identifiable, including through personal data having undergone pseudonymisation, account shall be taken of all the means reasonably likely to be used, such as singling out or online identifiers, either by the controller or by another person to identify the natural person directly or indirectly.
- 2.
Paragraph 1 is without prejudice to other provisions and obligations applicable to the controller and processor, including under Chapter IV and V of this Regulation.
- 3.
The Board shall issue an opinion, in accordance with Article 64(2) of this Regulation, addressing the application of pseudonymisation and anonymisation to personal data, including related technical and organisational measures, and specifying means and criteria to determine whether and when such may effectively prevent persons other than the controller from identifying a data subject, in such a way that, for them, the data subject is not or is no longer identifiable, and where information relating to the data subject no longer constitutes personal data for that person other than the controller.
- 4.
The Chair of the Board shall request the opinion referred to in paragraph 3 no later than 6 months after the entry into force of this Regulation. The opinion shall be reviewed and updated where necessary.
- 5.
The Commission may adopt implementing acts specifying technical and organisational criteria, methodologies and standards where necessary to ensure uniform conditions for the application of paragraphs 1 and 3, or where further clarity is required following the issuance of the opinion referred to in paragraph 3, The Commission shall closely involve the EDPB in the preparations of the implementing acts. The EPDB shall issue an opinion on the draft implementing acts within a deadline of 8 weeks as of the receipt of the draft from the Commission. The Implementing Acts shall be adopted in accordance with the examination procedure referred to in Article 93(3).
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.