Digital Omnibus tracker

GDPR · Regulation (EU) 2016/679

Article 43

Compare the available Commission, Council and Parliament texts and amendments affecting this article.

Article total: 1 part · 0 Council drafts · 1 Parliament amendment

Removed wording is struck through; added or replacement wording is highlighted.

Institutional text

European Commission proposal

All Commission’s changes to GDPR

The wording proposed by the Commission at the start of this legislative file.

No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.

Institutional text

Council Presidency texts

Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.

No Council wording is mapped to these tracked parts.

Competing proposals

European Parliament amendments

These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.

More filters

Alternative wording Amendment 1305 · Axel Voss ITRE · LIBE
10b. In Article 43, paragraphs 2 and 7 are replaced by the following:
2. Certification bodies referred to in paragraph 1 shall be accredited in accordance with that paragraph only where they have: (ea) have not repeatedly and knowingly certified processing or other conduct that clearly violated guidelines or recommendation under Article 70(1)(d) that was issued before the certification or have not repeatedly and knowingly certified processing that was later subject to corrective powers under Article 58(2) or fines under Article 83. 7. Without prejudice to Chapter VIII, the competent supervisory authority or the national accreditation body shall revoke an accreditation of a certification body pursuant to paragraph 1 of this Article where the conditions for the accreditation are not, or are no longer, met or where actions taken by a certification body infringe this Regulation. Supervisory authorities shall report complaints under Article 77, any exercise of corrective powers under Article 58(2) and any fine under Article 83 against a controller or processor that was certified to the relevant certification body and the competent supervisory authority that has accredited the relevant certification body."
Justification

RISK-BASED APPROACH #12: This package makes the GDPR’s risk-based approach practical by introducing objective categories for small, medium and large controllers. Small controllers with limited, non-core processing receive relief from selected administrative duties, while data-subject rights and enforcement remain intact. Very large controllers, gatekeepers and VLOPs/VLOSEs face stronger transparency, annual certification and closer supervision. Compliance effort is thus reduced where risks are low and increased where scale and systemic impact are greatest.

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 10 b (new) / Regulation (EU) 2016/679 / Article 43 – paragraphs 2 and 7