Digital Omnibus tracker

GDPR · Regulation (EU) 2016/679

Article 83

Compare the available Commission, Council and Parliament texts and amendments affecting this article.

Article total: 6 parts · 0 Council drafts · 9 Parliament amendments

Removed wording is struck through; added or replacement wording is highlighted.

Institutional text

European Commission proposal

All Commission’s changes to GDPR

The wording proposed by the Commission at the start of this legislative file.

No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.

Institutional text

Council Presidency texts

Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.

No Council wording is mapped to these tracked parts.

Competing proposals

European Parliament amendments

These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.

More filters

Political group at the amendment date where available; otherwise the current Parliament affiliation.

Additional proposed wording Amendment 113 IMCO draft opinion · Alex Agius Saliba (rapporteur)
Preview
against:
Additional proposed wording Amendment 114 IMCO draft opinion · Alex Agius Saliba (rapporteur)

14b. In Article 83, the following paragraph is added:

The provisions shall apply mutatis mutandis to providers of software to access online interfaces in the context of Article 88b even when they are not processing personal data.’

Justification

Amendment to ensure supervision and enforcement of art 88b.

Preview
against:
Alternative wording Amendment 482 · David Cormand on behalf of the Verts/ALE Group IMCO
1Article 3 b (new) Article 83 The following paragraph is added:
10. EachThe supervisorypreceding authorityprovisions shall ensureapply thatmutatis mutandis to providers of software to access online interfaces in the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.2. Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j)context of Article 5888b(26). Wheneven decidingwhen whetherthey toare impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:(a)the nature, gravity and duration of the infringement taking into account the nature scope or purpose of thenot processing concerned as well as the number of data subjects affected and the level of damage suffered by them;(b)the intentional or negligent character of the infringement;(c)any action taken by the controller or processor to mitigate the damage suffered by data subjects;(d)the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32;(e)any relevant previous infringements by the controller or processor;(f)the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;(g)the categories of personal data affected by the infringement;(h)the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement;(i)where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures;(j)adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and(k)any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement.3. If a controller or processor intentionally or negligently, for the same or linked processing operations, infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the gravest infringement.4. Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:(a)the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43;(b)the obligations of the certification body pursuant to Articles 42 and 43;(c)the obligations of the monitoring body pursuant to Article 41(4).5. Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:(a)the basic principles for processing, including conditions for consent, pursuant to Articles 5, 6, 7 and 9;(b)the data subjects' rights pursuant to Articles 12 to 22;(c)the transfers of personal data to a recipient in a third country or an international organisation pursuant to Articles 44 to 49;(d)any obligations pursuant to Member State law adopted under Chapter IX;(e)non-compliance with an order or a temporary or definitive limitation on processing or the suspension of data flows by the supervisory authority pursuant to Article 58(2) or failure to provide access in violation of Article 58(1).6. Non-compliance with an order by the supervisory authority as referred to in Article 58(2) shall, in accordance with paragraph 2 of this Article, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher.7. Without prejudice to the corrective powers of supervisory authorities pursuant to Article 58(2), each Member State may lay down the rules on whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State.8. The exercise by the supervisory authority of its powers under this Article shall be subject to appropriate procedural safeguards in accordance with Union and Member State law, including effective judicial remedy and due process.9. Where the legal system of the Member State does not provide for administrative fines, this Article may be applied in such a manner that the fine is initiated by the competent supervisory authority and imposed by competent national courts, while ensuring that those legal remedies are effective and have an equivalent effect to the administrative fines imposed by supervisory authorities. In any event, the fines imposed shall be effective, proportionate and dissuasive. Those Member States shall notify to the Commission the provisions of their laws which they adopt pursuant to this paragraph by 25 May 2018 and, without delay, any subsequent amendment law or amendment affecting them."
Justification

Penal provisions must be extended to software vendors if they are covered in Article 88b.

Preview
against:
Source identification

Header printed in the source: Article 3 b (new) / Regulation (EU) 2016/679 / Article 83

Additional proposed wording Amendment 1342 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE

14a. In Article 83(5), the following point is added:

Context reproduced in the official amendment

The amendment reproduces a wider legal passage. It is shown as context because it does not cover the same legal unit as the proposed wording.

(new)

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 14 a (new) / Regulation (EU) 2016/679 / Article 83 – Paragraph 5 – point ea (new)

Alternative wording Amendment 1344 · Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec ITRE · LIBE
14a. Article 83 paragraph 5 is replaced by the following:
5. Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher: (a) the basic principles for processing, including conditions for consent, pursuant to Articles 5, 6, 7 and 9; (b) the data subjects' rights pursuant to Articles 12 to 22; (c) the transfers of personal data to a recipient in a third country or an international organisation pursuant to Articles 44 to 49; (d) any obligations pursuant to Member State law adopted under Chapter IX; (e) non-compliance with an order or a temporary or definitive limitation on processing or the suspension of data flows by the supervisory authority pursuant to Article 58(2) or failure to provide access in violation of Article 58(1). (f) confidentiality of Communications pursuant to Articles 91a, 91b, 91c, 91d and 91e."
Justification

This change is proposed due to other amendments tabled moving e-privacy provisions under Regulation (EU) 2016/679.

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 14 a (new) / Regulation (EU) 2016/679 / Article 83 – paragraph 5

Additional proposed wording Amendment 1345 · Axel Voss ITRE · LIBE

14a. Article 83 is amended by adding the following paragraph 5a

Justification

RISK-BASED APPROACH #13: This package makes the GDPR’s risk-based approach practical by introducing objective categories for small, medium and large controllers. Small controllers with limited, non-core processing receive relief from selected administrative duties, while data-subject rights and enforcement remain intact. Very large controllers, gatekeepers and VLOPs/VLOSEs face stronger transparency, annual certification and closer supervision. Compliance effort is thus reduced where risks are low and increased where scale and systemic impact are greatest.

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 14 a (new) / Regulation (EU) 2016/679 / Article 83 – paragraph 5a (new)

Additional proposed wording Amendment 1346 · Pernando Barrena Arza ITRE · LIBE
Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 14 a (new) / Regulation (EU) 2016/679 / Article 83 – paragraph 5 – point ea (new)

Additional proposed wording Amendment 1349 · Pernando Barrena Arza ITRE · LIBE

14b. In Article 83, paragraph 9a is added:

Justification

Certain industry sectors, such as social media companies, primary make their revenue from the unlawful processing of personal data. In such cases, where almost 100% of the profits are made from unlawful processing, the 4% fine under Article 83 is not sufficient as a deterrent, but amounts more to a tax for unlawful actions. As in many other laws, the requirement to confiscate unlawful profits shall be added to ensure fair competition and efficient enforcement.

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 14 b (new) / Regulation (EU) 2016/679 / Article 83 – paragraph 9a (new)

Additional proposed wording Amendment 1355 · Markéta Gregorová, Damian Boeselager on behalf of the Verts/ALE Group ITRE · LIBE

In Article 83, paragraph 5, the following point ea is added

obligations related to automated and machine-readable signals of data subject’s choices with respect to processing of personal data in the terminal equipment pursuant to Article 88b;'

Preview
against:
Source identification

Header printed in the source: Article 3 – paragraph 1 – point 14 e (new) / Regulation (EU) 2016/679 / Article 83 – paragraph 5 – point ea (new)