GDPR · Regulation (EU) 2016/679
Articles 91a, 91b, 91c, 91d, 91e (new)
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 1 part · 0 Council drafts · 1 Parliament amendment
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to GDPRThe wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to these tracked parts.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Additional proposed wording Amendment 1594 · Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec ITRE · LIBE
After Article 91 the following Chapter is added:
'Chapter IXa
Confidentiality of communications and processing of electronic communications and information in terminal equipment
Article 91a
Confidentiality of electronic communications
Electronic communications shall be confidential. Any interference with electronic communications, such as listening, tapping, storing, monitoring, scanning or other types of interception, surveillance, or any processing of electronic communications, by persons other than the user using the terminal equipment, shall be prohibited. Confidentiality of electronic communications shall also apply to data related to or processed by the terminal equipment.
Article 91b
Lawful processing of electronic communications data
Providers of electronic communications networks and electronic communications services may process electronic communications data only if it is technically necessary to achieve the transmission of the communication, for the duration necessary for that purpose.
Providers of electronic communications networks and services, or other parties acting on behalf of the provider or the user, may process electronic communications data only if it is technically necessary to maintain or restore the availability, integrity and confidentiality of the respective electronic communications network or services, or to detect technical faults and/or errors in the transmission of electronic communications, for the duration necessary for that purpose.
Providers of electronic communications networks and services may process electronic communications metadata only if:
processing is strictly necessary to meet mandatory quality of service requirements, including network management, pursuant to Directive (EU) 2018/1972 or Regulation (EU) 2015/2120 for the duration technically necessary for that purpose;
processing is strictly necessary for billing, determining interconnection payments, detecting or stopping fraudulent use of, or subscription to, electronic communications services;
the user concerned has given their consent to the processing of their communications metadata for one or more specified purposes in accordance with Article 4(11) provided that the purpose or purposes concerned could not be fulfilled without processing such metadata.
Providers of the electronic communications services may process electronic communications content data only:
for the sole purpose of the provision of a specific service requested by the user, if the -user concerned has given their consent to the processing of their electronic communications content data and the provision of that service cannot be fulfilled by the provider without the processing of such content data;
if all users have consented to the processing of their electronic communications content pursuant to Article 4(11) for one or more specified purposes that cannot be fulfilled by processing information that is made anonymous; or (c) for the purpose of the provision of a specific service explicitly requested by a user, for purely personal use, only for the duration necessary for that purpose and without the consent of all users only where such requested processing does not adversely affect the fundamental rights and interests of another user or users.
Article 91c
Protection of information transmitted to, stored in, related to, processed by and collected from users’ terminal equipment
Storing of information, or gaining of access to information already stored, in the terminal equipment including about its software and hardware, other than by the user concerned, shall be prohibited, except on the following grounds:
it is strictly necessary for the sole purpose of carrying out the transmission of an electronic communication over an electronic communications network, or;
the user has given their specific consent in accordance with this Regulation, or;
it is strictly technically necessary for providing an information society service specifically requested by the user; or
it is technically necessary for maintaining or restoring the technical security of a service provided by the controller and requested by the user, or;
for the purpose of delivering a form of online advertising (“strictly limited contextual advertising”), which is limited to processing the following information:
information about the device, operating system and a browser;
coarse geolocation data, which is abstracted to the city level;
temporal information, such as date and time, and;
the content the user is immediately viewing, abstracted in broad categories.
for the purpose of limiting the number of times a specific advertisement is presented to the user (“first party frequency capping”), when such limitation meets the following conditions:
an advertisement is delivered as defined under Article 91c (1) (e) of this Regulation;
information stored consists exclusively of a counter, or equivalent minimal signal;
information is stored by the provider of the online interface on which the advertisement is presented, and is automatically deleted no later than 14 days after creation, and;
the information is not used for any purpose other than frequency capping, is not combined, directly or indirectly, with any other dataset, including but not limited to identifiers, or data obtained from third parties, and the information is not transmitted to, or made accessible to any party other than the controller operating the domain under which it is stored.
for the purpose of measuring the reach and performance of specific advertising or an advertising campaign (“privacy preserving attribution”), when such measurement meets all of the following conditions:
an advertisement is delivered as defined under Article 91c (1) (e) of this Regulation;
data is pseudonymised at the earliest stage possible;
data is processed solely on device and in an aggregated manner, and;
the information is not used for any purpose other than frequency capping, is not combined, directly or indirectly, with any other dataset, including but not limited to identifiers, or data obtained from third parties, and the information is not transmitted to, or made accessible to any party other than the controller operating the domain under which it is stored.
for the purpose of creating instant anonymous aggregated information about the usage of an online service requested by the user to measure the audience of such a service, where it is carried out by the provider of that online service requested by the user solely for its own use, or by a processor acting on behalf of this controller, solely for the controller’ own use and not further processed for any other purpose, not combined with data from other services from the provider of the online service, or from a third party, nor shared with any third party;
for the purpose of verifying the user’s past refusal to a request to consent without involving the use of a unique identifier or additional processing of personal data.
Where storing of information, or gaining of access to information already stored, in the terminal equipment of a user is based on consent, the following shall apply:
the user shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means;
if the user gives consent, the controller shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the user;
if the user declines a request for consent, the controller shall not make a new request for consent for the same purpose for a period of at least six months. This paragraph also applies to the subsequent processing of information based on consent.
No user shall be denied access to a renumerated service or functionality on grounds that they have not given their consent to the processing of their personal data and/or the use of the processing or storage capabilities of their terminal equipment that are not necessary for the provision of that service or functionality.
This Article shall apply from [OP: please insert the date = 6 months following the date of entry into force of this Regulation]
Article 91d
Information and options for privacy settings to be provided
Software placed on the market permitting electronic communications and/or the retrieval and presentation of information on the internet, shall
by default, have, in accordance with Article 25 of this Regulation, privacy protective settings activated to prevent other parties from transmitting to or storing information on the terminal equipment of a user and from processing information already stored on or collected from that equipment, except for the purposes laid down in Article 91c.
upon installation, inform and offer the user the possibility to change or confirm the privacy settings options defined in point (a) by requiring the user's consent to a setting and offer the option to prevent other parties from processing information transmitted to, already stored on or collected from the terminal equipment for the purposes laid down by Article 91c;
offer the user the possibility to express specific consent through the settings after the installation of the software. The technical settings shall consist of multiple options for the user to choose from, including an option to prevent the storage of information on the terminal equipment of a user and the processing of information already stored on, or processed by, that equipment. These settings shall be easily accessible during the use of the software and presented in a manner that gives the user the possibility for making an informed decision.
The settings shall lead to a signal based on technical specifications which is sent to the other parties to inform them about the user's intentions with regard to consent, withdrawal of consent or objection. This signal shall be legally valid and be binding on, and enforceable against, any other party.
For software already placed on the market at the entry into force of this Regulation, the requirements under points (a) to (c) shall be complied with at the time of the first update of the software, but no later than one year after entry into force of this Regulation.
Article 91e
Automated and machine-readable indications of data subject’s choices with respect to processing of personal data in the terminal equipment of natural persons
Controllers shall ensure that their online interfaces allow data subjects to:
Give specific consent per purpose through automated and machine-readable means, provided that the conditions for consent laid down in this Regulation are fulfilled;
decline a request for consent, exercise the right to withdraw consent pursuant to Article 7(3) and the right to object pursuant to Article 21(1) and 21(2) through automated and machine-readable means.
refuse, by automated and machine-readable means, such as automated signals, all processing on terminal equipment that may otherwise be based on consent through automated and machine-readable means. This shall include processing for purposes related to cross-site tracking, profiling, personalised content, personalised advertising, and training of artificial intelligence systems.
Controllers shall respect the choices made by data subjects in accordance with paragraph 1.
Points (a) and (b) in paragraph 1 shall not apply to controllers that are media service providers when providing a media service.
Controllers shall not request the consent or choices of the data subject made in accordance with paragraph 1 (c) for the same purposes through separate consent or similar interfaces unless the data subject actively modifies their initial choices.
The choices made by data subjects in accordance with paragraph 1 shall be communicated to all online interfaces visited by the data subject when using the same terminal equipment.
The Commission shall, in accordance with Article 10(1) of Regulation (EU) 1025/2012, request one or more European standardisation organisations to draft standards for the interpretation of machine-readable indications of data subjects’ choices.
Online interfaces of controllers which are in conformity with harmonised standards or parts thereof the references of which have been published in the Official Journal of the European Union shall be presumed to be in conformity with the requirements covered by those standards or parts thereof, set out in paragraph 1.
The Commission shall ensure a balanced representation of interests and the effective participation of all relevant stakeholders in the standardisation process in accordance with Article 5 of Regulation (EU) No 1025/2012.
The Commission shall adopt implementing acts establishing common specifications for the requirements set out in paragraph 1 if the following conditions are fulfilled:
the Commission has requested one or more European standardisation organisations to draft harmonised standards as set out in paragraph 5, and:
the request has not been accepted by any of the European standardisation organisations; or
the harmonised standards addressing that request are not delivered within the deadline set in accordance with Article 10(1) of Regulation (EU) No 1025/2012; or
the harmonised standards do not comply with the request; and
no reference to harmonised standards covering the requirements set out in paragraph 1 of this article has been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012 and no such reference is expected to be published within a reasonable period. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2).
Paragraphs 1 and 2 shall apply from [OP: please insert the date = 24 months following the date of entry into force of this Regulation].
Providers of software to access online interfaces, such as operating systems or web browsers, shall provide the technical means to allow data subjects to exercise, modify or withdraw their choices as defined in paragraph 1 of this Article through the automated and machine-readable means referred to therein. 10. The data subject’s choices set out in paragraph 1 shall be managed by a third-party software provider acting structurally and economically independently from the software providing access to online interfaces.
Where the third-party software provider, as referred to in paragraph 10, is itself a controller processing personal data on the terminal equipment of the data subject, the refusal signal referred to in Paragraphs 1 and 4 shall apply to such processing on the same terms as it applies to any other controller.
In such a case, those software providers shall not process data derived from the data subject’s interaction with that software for purposes other than those necessary for provisioning of this software, including for purposes such as advertising, profiling, audience building, attribution, or the training of AI systems.
Paragraph 9 shall apply from [OP: please insert the date = 18 months following the date of entry into force of this Regulation].'
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.