GDPR · Regulation (EU) 2016/679
Articles 88e, 88f, 88g (new)
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 1 part · 0 Council drafts · 1 Parliament amendment
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to GDPRThe wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to these tracked parts.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Additional proposed wording Amendment 1598 · Axel Voss ITRE · LIBE
After Article 88c, the following Articles 88e, 88f, 88g are added:
'Article 88e
Data protection regulatory sandboxes
Member States shall ensure that their competent supervisory authorities establish at least one data protection regulatory sandbox at national level, which shall be operational by 2 August 2028. That sandbox may also be established jointly with the supervisory authorities of other Member States. The Commission may provide technical support, advice and tools for the establishment and operation of data protection regulatory sandboxes. The obligation under the first subparagraph may also be fulfilled by participating in an existing sandbox in so far as that participation provides an equivalent level of national coverage for the participating Member States. This Chapter is without prejudice to the rules laid down by other Union legal acts related to regulatory sandboxs, in particular Chapter 6 of Regulation (EU) 2024/1689.
Additional data protection regulatory sandboxes at regional or local level, or established jointly with the supervisory authorities of other Member States may also be established. 3. The European Data Protection Supervisor may also establish an data protection regulatory sandbox for Union institutions, bodies, offices and agencies. For this purpose references to national supervisory authorities in this Chapter shall be construed as references to the European Data Protection Supervisor.
Member States shall ensure that the supervisory authorities referred to in paragraphs 1 and 2 allocate sufficient resources to comply with this Article effectively and in a timely manner. Where appropriate, national supervisory authorities shall cooperate with other relevant authorities, and may allow for the involvement of other actors within the data protection ecosystem. This Article shall not affect other regulatory sandboxes established under Union or national law. Member States shall ensure an appropriate level of cooperation between the authorities supervising those other sandboxes and the national supervisory authorities.
Data protection regulatory sandboxes established under this Article shall provide for a controlled environment that fosters innovation and facilitates the development, testing and validation of innovative data processing for a limited time before processing of personal data takes place pursuant to a specific sandbox plan agreed between the controller and the supervisory authority, ensuring that appropriate safeguards are in place.
Supervisory authorities shall provide, as appropriate, guidance, supervision and support within the data protection regulatory sandbox with a view to identifying risks, in particular to fundamental rights, health and safety, testing, mitigation measures, and their effectiveness in relation to the obligations and requirements of this Regulation and, where relevant, other Union and national law supervised within the sandbox. 7. Supervisory authorities shall provide controllers participating in the data protection regulatory sandbox with guidance on regulatory expectations and how to fulfil the requirements and obligations set out in this Regulation. Upon request of the controller, the supervisory authority shall provide a written proof of the activities successfully carried out in the sandbox. The supervisory authority shall also provide an exit report detailing the activities carried out in the sandbox and the related results and learning outcomes
If the controller and the national supervisory authority explicitly agree, the exit report may be made publicly available through the single information platform referred to in this Article.
The establishment of data protection regulatory sandboxes shall aim to contribute to the following objectives:
improving legal certainty to achieve regulatory compliance with this Regulation or, where relevant, other applicable Union and national law;
supporting the sharing of best practices through cooperation with the authorities involved in the data protection regulatory sandbox;
fostering innovation and competitiveness and facilitating the development of a data protection ecosystem;
contributing to evidence-based regulatory learning;
facilitating and accelerating access to the Union market for technical developments, in particular when provided by SMEs, including start-ups, and SMCs.
Where the technical developments constitute AI systems, the competent national authorities shall additionally ensure that the national market surveillance authorities within the meaning of Article 3, point (26), of Regulation (EU) 2024/1689 are involved in the operation of the data protection regulatory sandbox to the extent of their respective tasks and powers.
The data protection regulatory sandboxes shall not affect the supervisory or corrective powers of the competent authorities supervising the sandboxes, including at regional or local level. Any significant risks to health and safety and fundamental rights identified during the development and testing of such technical developments shall result in an adequate mitigation. National competent authorities shall have the power to temporarily or permanently suspend the testing process, or the participation in the sandbox if no effective mitigation is possible, and shall inform the EDPB of such decision. National competent authorities shall exercise their supervisory powers within the limits of the relevant law, using their discretionary powers when implementing legal provisions in respect of a specific data protection regulatory sandbox project, with the objective of supporting innovation in data protection in the Union.
Controllers participating in the data protection regulatory sandbox shall remain liable under applicable Union and national liability law for any damage inflicted on third parties as a result of the experimentation taking place in the sandbox. However, provided that the controllers observe the specific plan and the terms and conditions for their participation and follow in good faith the guidance given by the national supervisory authority, no administrative fines shall be imposed by the authorities for infringements of this Regulation. Where other competent authorities responsible for other Union and national law were actively involved in the supervision of the data processing in the sandbox and provided guidance for compliance, no administrative fines shall be imposed regarding that law.
The data protection regulatory sandboxes shall be designed and implemented in such a way that, where relevant, they facilitate cross-border cooperation between national supervisory authorities.
National supervisory authorities, the EDPS and the Commission shall, as appropriate and within their respective competences, coordinate their activities and cooperate within the framework of the EDPB. They may support the joint establishment and operation of data protection regulatory sandboxes, including in different sectors and exchange best practices on related matters.
National supervisory authorities shall inform the EDPB of the establishment of a sandbox. The EDPB shall make publicly available a list of planned and existing sandboxes and keep it up to date in order to encourage more interaction in the data protection regulatory sandboxes and cross-border cooperation.
National supervisory authorities shall submit annual reports to the EDPB and the Commission, from one year after the establishment of the data protection regulatory sandbox and every year thereafter until its termination, and a final report. Those reports shall provide information on the progress and results of the implementation of those sandboxes, including best practices, incidents, lessons learnt and recommendations on their setup and, where relevant, on the application and possible revision of this Regulation, including its delegated and implementing acts, and on the application of other Union law supervised by the competent authorities within the sandbox. The national supervisory authorities shall make those annual reports or abstracts thereof available to the public, online. The Commission shall, where appropriate, take the annual reports into account when exercising its tasks under this Regulation.
The Commission shall develop a single and dedicated interface containing all relevant information related to data protection regulatory sandboxes to allow stakeholders to interact with data protection regulatory sandboxes and to raise enquiries with supervisory authorities, and to seek non-binding guidance on the conformity of innovative products, services, business models embedding data protection technologies. The Commission shall proactively coordinate with national supervisory authorities, where relevant.
Article 88f
Detailed arrangements for, and functioning of, data protection regulatory sandboxes
In order to avoid fragmentation across the Union, the EDPB shall establish and make public a framework specifying the detailed arrangements for the establishment, development, implementation, operation, governance, and supervision of the data protection regulatory sandboxes. The framework shall include common principles on the following issues:
eligibility and selection criteria for participation in the data protection regulatory sandbox;
procedures for the application, participation, monitoring, exiting from and termination of the data protection regulatory sandbox, including the sandbox plan and the exit report;
the terms and conditions applicable to the participants;
the detailed rules applicable to the governance of data protection regulatory sandboxes covered under Article 88x, including the coordination and cooperation at national and EU level.
The framework referred to in paragraph 1 shall ensure:
that data protection regulatory sandboxes are open to any applying controller of a technical developments who fulfils eligibility and selection criteria, which shall be transparent and fair, and that national supervisory authorities inform applicants of their decision within three months of the application;
that data protection regulatory sandboxes allow broad and equal access and keep up with demand for participation; controllers may also submit applications in partnerships with other controllers and other relevant third parties;
that the detailed arrangements for, and conditions concerning data protection regulatory sandboxes support, to the best extent possible, flexibility for national supervisory authorities to establish and operate their data protection regulatory sandboxes;
that access to the data protection regulatory sandboxes is free of charge for SMEs, including start-ups, without prejudice to exceptional costs that national supervisory authorities may recover in a fair and proportionate manner;
that data protection regulatory sandboxes facilitate the involvement of other relevant actors within the data protection ecosystem, such as SMEs, including start-ups, enterprises, innovators, testing and experimentation facilities, research and experimentation labs and European Digital Innovation Hubs, centres of excellence, individual researchers, in order to allow and facilitate cooperation with the public and private sectors;
that procedures, processes and administrative requirements for application, selection, participation and exiting the data protection regulatory sandbox are simple, easily intelligible, and clearly communicated in order to facilitate the participation of SMEs, including start-ups, with limited legal and administrative capacities and are streamlined across the Union, in order to avoid fragmentation and that participation in an data protection regulatory sandbox established by a Member State, or by the European Data Protection Supervisor is mutually and uniformly recognised and carries the same legal effects across the Union;
that participation in the data protection regulatory sandbox is limited to a period that is appropriate to the complexity and scale of the project and that may be extended by the national supervisory authority;
that data protection regulatory sandboxes facilitate the development of tools and infrastructure for testing, benchmarking, assessing and explaining dimensions of data processing relevant for regulatory learning, such as accuracy, data minimisation and security of processing as well as measures to mitigate risks to fundamental rights and society at large.
Article 88g
Further processing of personal data for developing certain technical developments data processing in the public interest in the data protection regulatory sandbox
In the data protection regulatory sandbox, personal data lawfully collected for other purposes may be processed solely for the purpose of developing and testing certain technical developments in the sandbox when all of the following conditions are met:
Technical developments shall be developed for safeguarding substantial public interest by a public authority or another natural or legal person and in one or more of the following areas:
public safety and public health, including disease detection, diagnosis prevention, control and treatment and improvement of health care systems;
a high level of protection and improvement of the quality of the environment, protection of biodiversity, protection against pollution, green transition measures, climate change mitigation and adaptation measures;
energy sustainability;
safety and resilience of transport systems and mobility, critical infrastructure and networks;
efficiency and quality of public administration and public services;
the protection of the data subject or the rights and freedoms of others;
the data processed are necessary for complying with one or more of the requirements referred to in Articles 25, 32 or 35 where those requirements cannot effectively be fulfilled by processing anonymised, synthetic or other non-personal data;
there are effective monitoring mechanisms to identify if any high risks to the rights and freedoms of the data subjects, as referred to in Article 35, may arise during the sandbox experimentation, as well as response mechanisms to promptly mitigate those risks and, where necessary, stop the processing;
any personal data to be processed in the context of the sandbox are in a functionally separate, isolated and protected data processing environment under the responsibility of the controller and only authorised persons have access to those data;
controllers can further share the originally collected data only in accordance with Union data protection law; any personal data created in the sandbox cannot be shared outside the sandbox;
any processing of personal data in the context of the sandbox does not leads to measures or decisions affecting the data subjects;
any personal data processed in the context of the sandbox are protected by means of appropriate technical and organisational measures and deleted once the participation in the sandbox has terminated or the personal data has reached the end of its retention period;
the logs of the processing of personal data in the context of the sandbox are kept for the duration of the participation in the sandbox, unless provided otherwise by Union or national law;
a complete and detailed description of the process and rationale behind the testing and validation of the data processing is kept together with the testing results;
a short summary of the data processing project developed in the sandbox, its objectives and expected results is published on the website of the supervisory authorities; this obligation shall not cover sensitive operational data in relation to the activities of law enforcement, border control, immigration or asylum authorities.
To the processing of personal data carried out within an data protection regulatory sandbox, provided that the processing takes place exclusively within the Union and it is ensured that authorities or other bodies of third countries cannot gain access to the processed data, only Article 5(1), point (f), in conjunction with paragraph 2, Article 24 and Article 32 shall apply, in addition to Chapters I, X and XI.
For the processing of personal data carried out within a data protection regulatory sandbox, and provided that the processing takes place exclusively within the Union and that access to the processed data by authorities or other bodies of third countries is prevented, Member States shall provide for derogations from or exemptions to Chapter II (Principles), Chapter III (Rights of the data subject), Chapter IV (Controller and processor), Chapter V (Transfers of personal data to third countries or international organisations), Chapter VI (Independent supervisory authorities), Chapter VII (Cooperation and consistency) and Chapter IX (Provisions relating to specific processing situations) where this is necessary to reconcile the right to the protection of personal data with the objective of fostering innovation and strengthening the competitiveness of the Union.
Paragraph 1 is without prejudice to Union or national law which excludes processing of personal data for other purposes than those explicitly mentioned in that law, as well as to Union or national law laying down the basis for the processing of personal data which is necessary for the purpose of developing, testing of innovative processing operations or any other legal basis, in compliance with Union law on the protection of personal data.'
Justification
Data protection sandboxes make GDPR compliance more predictable for innovative processing, PETs and AI use cases. Building on the AI Act model, they provide controlled testing, supervisory guidance, exit reports, cross-border learning and SME access. No-fine protection applies only where participants follow the agreed plan in good faith; authorities keep corrective powers, liability remains, high risks must be mitigated and public-interest further processing is subject to strict safeguards.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.