Digital Omnibus tracker

GDPR · Regulation (EU) 2016/679

Article 42

Compare the available Commission, Council and Parliament texts and amendments affecting this article.

Article total: 1 part · 0 Council drafts · 1 Parliament amendment

Removed wording is struck through; added or replacement wording is highlighted.

Institutional text

European Commission proposal

All Commission’s changes to GDPR

The wording proposed by the Commission at the start of this legislative file.

No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.

Institutional text

Council Presidency texts

Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.

No Council wording is mapped to these tracked parts.

Competing proposals

European Parliament amendments

These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.

More filters

Alternative wording Amendment 1303 · Axel Voss ITRE · LIBE
10a. In Article 42, paragraph 3 and 7 are amended as follows:
3. The certification shall be voluntary and available via a process that is transparent for small and medium controllers and large processors. Large controllers must be certified within one year after meeting the conditions in Article 4(28). 7. Certification shall be issued to a controller or processor for a maximum period of three years for small and medium controller and large processors. Certifications shall be issued for a maximum period of one year for large controllers. It may be renewed, under the same conditions, provided that the relevant criteria continue to be met. Certification shall be withdrawn, as applicable, by the certification bodies referred to in Article 43 or by the competent supervisory authority where the criteria for the certification are not or are no longer met."
Justification

RISK-BASED APPROACH #11: This package makes the GDPR’s risk-based approach practical by introducing objective categories for small, medium and large controllers. Small controllers with limited, non-core processing receive relief from selected administrative duties, while data-subject rights and enforcement remain intact. Very large controllers, gatekeepers and VLOPs/VLOSEs face stronger transparency, annual certification and closer supervision. Compliance effort is thus reduced where risks are low and increased where scale and systemic impact are greatest.

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 10 a (new) / Regulation (EU) 2016/679 / Article 42 – paragraphs 3 and 7