GDPR · Regulation (EU) 2016/679
Article 43
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 1 part · 0 Council drafts · 1 Parliament amendment
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to GDPRThe wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to these tracked parts.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Alternative wording Amendment 1305 · Axel Voss ITRE · LIBE
Justification
RISK-BASED APPROACH #12: This package makes the GDPR’s risk-based approach practical by introducing objective categories for small, medium and large controllers. Small controllers with limited, non-core processing receive relief from selected administrative duties, while data-subject rights and enforcement remain intact. Very large controllers, gatekeepers and VLOPs/VLOSEs face stronger transparency, annual certification and closer supervision. Compliance effort is thus reduced where risks are low and increased where scale and systemic impact are greatest.
against:
Article 43
Certification bodies
- 1.
Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58, certification bodies which have an appropriate level of expertise in relation to data protection shall, after informing the supervisory authority in order to allow it to exercise its powers pursuant to point (h) of Article 58(2) where necessary, issue and renew certification. Member States shall ensure that those certification bodies are accredited by one or both of the following:- (a)
the supervisory authority which is competent pursuant to Article 55 or 56; - (b)
the national accreditation body named in accordance with Regulation (EC) No 765/2008 of the European Parliament and of the Council (2) in accordance with EN-ISO/IEC 17065/2012 and with the additional requirements established by the supervisory authority which is competent pursuant to Article 55 or 56.
- (a)
- 2.
Certification bodies referred to in paragraph 1 shall be accredited in accordance with that paragraph only where they have:
- (a)
demonstrated their independence and expertise in relation to the subject-matter of the certification to the satisfaction of the competent supervisory authority; - (b)
undertaken to respect the criteria referred to in Article 42(5) and approved by the supervisory authority which is competent pursuant to Article 55 or 56 or by the Board pursuant to Article 63; - (c)
established procedures for the issuing, periodic review and withdrawal of data protection certification, seals and marks; - (d)
established procedures and structures to handle complaints about infringements of the certification or the manner in which the certification has been, or is being, implemented by the controller or processor, and to make those procedures and structures transparent to data subjects and the public; and - (e)
demonstrated, to the satisfaction of the competent supervisory authority, that their tasks and duties do not result in a conflict of interests. - (ea)
have not repeatedly and knowingly certified processing or other conduct that clearly violated guidelines or recommendation under Article 70(1)(d) that was issued before the certification or have not repeatedly and knowingly certified processing that was later subject to corrective powers under Article 58(2) or fines under Article 83.
- (a)
- 3.
►C1 The accreditation of certification bodies as referred to in paragraphs 1 and 2 of this Article shall take place on the basis of requirements approved by the supervisory authority which is competent pursuant to Article 55 or 56 or by the Board pursuant to Article 63.◄ In the case of accreditation pursuant to point (b) of paragraph 1 of this Article, those requirements shall complement those envisaged in Regulation (EC) No 765/2008 and the technical rules that describe the methods and procedures of the certification bodies. - 4.
The certification bodies referred to in paragraph 1 shall be responsible for the proper assessment leading to the certification or the withdrawal of such certification without prejudice to the responsibility of the controller or processor for compliance with this Regulation. The accreditation shall be issued for a maximum period of five years and may be renewed on the same conditions provided that the certification body meets the requirements set out in this Article. - 5.
The certification bodies referred to in paragraph 1 shall provide the competent supervisory authorities with the reasons for granting or withdrawing the requested certification. - 6.
The requirements referred to in paragraph 3 of this Article and the criteria referred to in Article 42(5) shall be made public by the supervisory authority in an easily accessible form. The supervisory authorities shall also transmit those requirements and criteria to the Board. - 7.
Without prejudice to Chapter VIII, the competent supervisory authority or the national accreditation body shall revoke an accreditation of a certification body pursuant to paragraph 1 of this Article where the conditions for the accreditation are not, or are no longer, met or where actions taken by a certification body infringe this Regulation. Supervisory authorities shall report complaints under Article 77, any exercise of corrective powers under Article 58(2) and any fine under Article 83 against a controller or processor that was certified to the relevant certification body and the competent supervisory authority that has accredited the relevant certification body.
- 8.
The Commission shall be empowered to adopt delegated acts in accordance with Article 92 for the purpose of specifying the requirements to be taken into account for the data protection certification mechanisms referred to in Article 42(1). - 9.
The Commission may adopt implementing acts laying down technical standards for certification mechanisms and data protection seals and marks, and mechanisms to promote and recognise those certification mechanisms, seals and marks. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2).
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Article 43 – paragraphs 2 and 7
Wording reproduced in the amendment → Amendment 1305 · ITRE–LIBE amendments 1261–1564 to the draft report
Changes in context
RemovedAdded