EU institutions data protection regulation · Regulation (EU) 2018/1725
Article 39
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 5 parts · 3 Council drafts · 5 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to EU institutions data protection regulationThe wording proposed by the Commission at the start of this legislative file.
Full article with Commission changes
Article with proposed changes
Official consolidated text dated 23 October 2018, with all 3 Commission proposal changes affecting this article applied.
Removed by the proposal: Article 39(5), Article 39(6).
Article 39
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 10, or of personal data relating to criminal convictions and offences referred to in Article 11; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The
Europeanlists,DatatheProtection Supervisor shall establishtemplate andmakemethodologypublicadoptedabylistthe Commission and referred to in paragraph 6a oftheArticlekind35 ofprocessingRegulationoperations(EU)which2016/679areshouldsubjectapply to therequirementprocessingforofapersonal dataprotectionunderimpactthisassessment pursuant to paragraph 1Regulation. - 5.
The European Data Protection Supervisor may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. - 6.
Prior to the adoption of the lists referred to in paragraphs 4 and 5 of this Article, the European Data Protection Supervisor shall request that the European Data Protection Board set up by Article 68 of Regulation (EU) 2016/679 examine such lists in accordance with point (e) of Article 70(1) of that Regulation where they refer to processing operations by a controller acting jointly with one or more controllers other than Union institutions and bodies. - 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 of the Regulation (EU) 2016/679 by the relevant processors other than Union institutions and bodies shall be taken into due account in assessing the impact of the processing operations performed by such processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of public interests or the security of processing operations.
- 10.
Where processing pursuant to point (a) or (b) of Article 5(1) has a legal basis in a legal act adopted on the basis of the Treaties, which regulates the specific processing operation or set of operations in question, and where a data protection impact assessment has already been carried out as part of a general impact assessment preceding the adoption of that legal act, paragraphs 1 to 6 of this Article shall not apply unless that legal act provides otherwise.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
No standalone Commission wording is mapped to this tracked part. A newly proposed provision may have no earlier text of its own.
Commission source wording and instructions
Article 39(4)
Commission proposal
4. The lists, the template and methodology adopted by the Commission and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation.
Article 39(5)
Commission proposal
(8) Article 39 is amended as follows: (a) Paragraph 4 is replaced by the following: ‘4. The lists, the template and methodology adopted by the Commission and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation.’ (b) Paragraphs 5 and 6 are deleted.
Article 39(6)
Commission proposal
(8) Article 39 is amended as follows: (a) Paragraph 4 is replaced by the following: ‘4. The lists, the template and methodology adopted by the Commission and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation.’ (b) Paragraphs 5 and 6 are deleted.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Article in June Presidency compromise · 10 June Council text
Comparison basis: Existing law (23 October 2018) compared with June Presidency compromise · 10 June (10 June 2026)
Article 39
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 10, or of personal data relating to criminal convictions and offences referred to in Article 11; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The
Europeanlists,DatatheProtection Supervisor shall establishtemplate andmakemethodologypublicestablishedabylistthe Board and referred to in paragraph 6a oftheArticlekind35 ofprocessingRegulationoperations(EU)which2016/679areshouldsubjectapply to therequirementprocessingforofapersonal dataprotectionunderimpactthisassessmentRegulation.’pursuant(b)toParagraphsparagraph51and 6 are deleted. - 5.
The European Data Protection Supervisor may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
Prior to the adoption of the lists referred to in paragraphs 4 and 5 of this Article, the European Data Protection Supervisor shall request that the European Data Protection Board set up by Article 68 of Regulation (EU) 2016/679 examine such lists in accordance with point (e) of Article 70(1) of that Regulation where they refer to processing operations by a controller acting jointly with one or more controllers other than Union institutions and bodies.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 of the Regulation (EU) 2016/679 by the relevant processors other than Union institutions and bodies shall be taken into due account in assessing the impact of the processing operations performed by such processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of public interests or the security of processing operations.
- 10.
Where processing pursuant to point (a) or (b) of Article 5(1) has a legal basis in a legal act adopted on the basis of the Treaties, which regulates the specific processing operation or set of operations in question, and where a data protection impact assessment has already been carried out as part of a general impact assessment preceding the adoption of that legal act, paragraphs 1 to 6 of this Article shall not apply unless that legal act provides otherwise.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Article 39(4)
June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
4. The lists, the template and methodology established by the Board and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation.’
Paragraphs 5 and 6 are deleted.
Article 39(5)
June Presidency compromise · 10 June
Exact provision wording unavailable within a wider Council operation
This provision forms part of a wider Council operation. Its wording is not available separately here; open the official source for the full passage.
Official source passage and amending instruction
Article 39 is amended as follows:
Paragraph 4 is replaced by the following: ‘4. The lists, the template and methodology established by the Board and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation.’
Paragraphs 5 and 6 are deleted.
Article 39(6)
June Presidency compromise · 10 June
Exact provision wording unavailable within a wider Council operation
This provision forms part of a wider Council operation. Its wording is not available separately here; open the official source for the full passage.
Official source passage and amending instruction
Article 39 is amended as follows:
Paragraph 4 is replaced by the following: ‘4. The lists, the template and methodology established by the Board and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation.’
Paragraphs 5 and 6 are deleted.
Article in June Presidency compromise · 18 June Council text
Comparison basis: Existing law (23 October 2018) compared with June Presidency compromise · 18 June (18 June 2026)
Article 39
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 10, or of personal data relating to criminal convictions and offences referred to in Article 11; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The European Data Protection Supervisor shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The European Data Protection Supervisor may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
Prior to the adoption of the lists referred to in paragraphs 4 and 5 of this Article, the European Data Protection Supervisor shall request that the European Data Protection Board set up by Article 68 of Regulation (EU) 2016/679 examine such lists in accordance with point (e) of Article 70(1) of that Regulation where they refer to processing operations by a controller acting jointly with one or more controllers other than Union institutions and bodies.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 of the Regulation (EU) 2016/679 by the relevant processors other than Union institutions and bodies shall be taken into due account in assessing the impact of the processing operations performed by such processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of public interests or the security of processing operations.
- 10.
Where processing pursuant to point (a) or (b) of Article 5(1) has a legal basis in a legal act adopted on the basis of the Treaties, which regulates the specific processing operation or set of operations in question, and where a data protection impact assessment has already been carried out as part of a general impact assessment preceding the adoption of that legal act, paragraphs 1 to 6 of this Article shall not apply unless that legal act provides otherwise.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Article 39(4)
June Presidency compromise · 18 June
Exact provision wording unavailable within a wider Council operation
This provision forms part of a wider Council operation. Its wording is not available separately here; open the official source for the full passage.
Official source passage and amending instruction
9. (a) ‘4. (b)
Article 39(5)
June Presidency compromise · 18 June
Exact provision wording unavailable within a wider Council operation
This provision forms part of a wider Council operation. Its wording is not available separately here; open the official source for the full passage.
Official source passage and amending instruction
9. (a) ‘4. (b)
Article 39(6)
June Presidency compromise · 18 June
Exact provision wording unavailable within a wider Council operation
This provision forms part of a wider Council operation. Its wording is not available separately here; open the official source for the full passage.
Official source passage and amending instruction
9. (a) ‘4. (b)
Article in September Presidency compromise Council text
Comparison basis: Existing law (23 October 2018) compared with September Presidency compromise (3 September 2026)
Article 39
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 10, or of personal data relating to criminal convictions and offences referred to in Article 11; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The European Data Protection Supervisor shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1.
- 5.
The European Data Protection Supervisor may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
Prior to the adoption of the lists referred to in paragraphs 4 and 5 of this Article, the European Data Protection Supervisor shall request that the European Data Protection Board set up by Article 68 of Regulation (EU) 2016/679 examine such lists in accordance with point (e) of Article 70(1) of that Regulation where they refer to processing operations by a controller acting jointly with one or more controllers other than Union institutions and bodies.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 of the Regulation (EU) 2016/679 by the relevant processors other than Union institutions and bodies shall be taken into due account in assessing the impact of the processing operations performed by such processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of public interests or the security of processing operations.
- 10.
Where processing pursuant to point (a) or (b) of Article 5(1) has a legal basis in a legal act adopted on the basis of the Treaties, which regulates the specific processing operation or set of operations in question, and where a data protection impact assessment has already been carried out as part of a general impact assessment preceding the adoption of that legal act, paragraphs 1 to 6 of this Article shall not apply unless that legal act provides otherwise.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Article 39
September Presidency compromise
Proposed change withdrawn
The 3 September Council text marks this proposed change as withdrawn and supplies no replacement wording. This does not by itself remove text from existing law.
Article 39(4) 3 Council drafts
Article 39(4)
10 June 2026 · June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
4. The lists, the template and methodology established by the Board and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation.’
Paragraphs 5 and 6 are deleted.
Article 39(4)
18 June 2026 · June Presidency compromise · 18 June
Exact provision wording unavailable within a wider Council operation
This provision forms part of a wider Council operation. Its wording is not available separately here; open the official source for the full passage.
Official source passage and amending instruction
9. (a) ‘4. (b)
Article 39
3 September 2026 · September Presidency compromise
Proposed change withdrawn
The 3 September Council text marks this proposed change as withdrawn and supplies no replacement wording. This does not by itself remove text from existing law.
Article 39(5) 3 Council drafts
Article 39(5)
10 June 2026 · June Presidency compromise · 10 June
Exact provision wording unavailable within a wider Council operation
This provision forms part of a wider Council operation. Its wording is not available separately here; open the official source for the full passage.
Official source passage and amending instruction
Article 39 is amended as follows:
Paragraph 4 is replaced by the following: ‘4. The lists, the template and methodology established by the Board and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation.’
Paragraphs 5 and 6 are deleted.
Article 39(5)
18 June 2026 · June Presidency compromise · 18 June
Exact provision wording unavailable within a wider Council operation
This provision forms part of a wider Council operation. Its wording is not available separately here; open the official source for the full passage.
Official source passage and amending instruction
9. (a) ‘4. (b)
Article 39
3 September 2026 · September Presidency compromise
Proposed change withdrawn
The 3 September Council text marks this proposed change as withdrawn and supplies no replacement wording. This does not by itself remove text from existing law.
Article 39(6) 3 Council drafts
Article 39(6)
10 June 2026 · June Presidency compromise · 10 June
Exact provision wording unavailable within a wider Council operation
This provision forms part of a wider Council operation. Its wording is not available separately here; open the official source for the full passage.
Official source passage and amending instruction
Article 39 is amended as follows:
Paragraph 4 is replaced by the following: ‘4. The lists, the template and methodology established by the Board and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation.’
Paragraphs 5 and 6 are deleted.
Article 39(6)
18 June 2026 · June Presidency compromise · 18 June
Exact provision wording unavailable within a wider Council operation
This provision forms part of a wider Council operation. Its wording is not available separately here; open the official source for the full passage.
Official source passage and amending instruction
9. (a) ‘4. (b)
Article 39
3 September 2026 · September Presidency compromise
Proposed change withdrawn
The 3 September Council text marks this proposed change as withdrawn and supplies no replacement wording. This does not by itself remove text from existing law.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Political group at the amendment date where available; otherwise the current Parliament affiliation.
Alternative wording Amendment 74 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
against:
Article 39
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 10, or of personal data relating to criminal convictions and offences referred to in Article 11; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The
Europeanlists,DatatheProtection Supervisor shall establishtemplate andmakemethodologypublicestablishedabylistthe Board and referred to in paragraph 6a oftheArticlekind35 ofprocessingRegulationoperations(EU)which2016/679areshouldsubjectapply to therequirementprocessingforofapersonal dataprotectionunderimpactthisassessment pursuant to paragraph 1Regulation. - 5.
The European Data Protection Supervisor may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. - 6.
Prior to the adoption of the lists referred to in paragraphs 4 and 5 of this Article, the European Data Protection Supervisor shall request that the European Data Protection Board set up by Article 68 of Regulation (EU) 2016/679 examine such lists in accordance with point (e) of Article 70(1) of that Regulation where they refer to processing operations by a controller acting jointly with one or more controllers other than Union institutions and bodies. - 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 of the Regulation (EU) 2016/679 by the relevant processors other than Union institutions and bodies shall be taken into due account in assessing the impact of the processing operations performed by such processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of public interests or the security of processing operations.
- 10.
Where processing pursuant to point (a) or (b) of Article 5(1) has a legal basis in a legal act adopted on the basis of the Treaties, which regulates the specific processing operation or set of operations in question, and where a data protection impact assessment has already been carried out as part of a general impact assessment preceding the adoption of that legal act, paragraphs 1 to 6 of this Article shall not apply unless that legal act provides otherwise.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Article 39
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 10, or of personal data relating to criminal convictions and offences referred to in Article 11; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The lists, the template and methodology
adoptedestablished by theCommissionBoard and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation. - 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 of the Regulation (EU) 2016/679 by the relevant processors other than Union institutions and bodies shall be taken into due account in assessing the impact of the processing operations performed by such processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of public interests or the security of processing operations.
- 10.
Where processing pursuant to point (a) or (b) of Article 5(1) has a legal basis in a legal act adopted on the basis of the Treaties, which regulates the specific processing operation or set of operations in question, and where a data protection impact assessment has already been carried out as part of a general impact assessment preceding the adoption of that legal act, paragraphs 1 to 6 of this Article shall not apply unless that legal act provides otherwise.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 495 · Virginie Joron IMCO
against:
Article 39
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 10, or of personal data relating to criminal convictions and offences referred to in Article 11; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The lists, the template and methodology adopted by the Commission and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation, without prejudice to the right of the national supervisory authorities to draft their own guidelines, standards and lists, which shall be taken into account by the Board and the Commission.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 of the Regulation (EU) 2016/679 by the relevant processors other than Union institutions and bodies shall be taken into due account in assessing the impact of the processing operations performed by such processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of public interests or the security of processing operations.
- 10.
Where processing pursuant to point (a) or (b) of Article 5(1) has a legal basis in a legal act adopted on the basis of the Treaties, which regulates the specific processing operation or set of operations in question, and where a data protection impact assessment has already been carried out as part of a general impact assessment preceding the adoption of that legal act, paragraphs 1 to 6 of this Article shall not apply unless that legal act provides otherwise.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1703 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 39
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 10, or of personal data relating to criminal convictions and offences referred to in Article 11; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The lists, the template and methodology adopted by the Commission and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation, without prejudice to the right of the national supervisiory authorities to develop their own guidance, standards and lists, which the Board and the Commission shall take into account.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 of the Regulation (EU) 2016/679 by the relevant processors other than Union institutions and bodies shall be taken into due account in assessing the impact of the processing operations performed by such processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of public interests or the security of processing operations.
- 10.
Where processing pursuant to point (a) or (b) of Article 5(1) has a legal basis in a legal act adopted on the basis of the Treaties, which regulates the specific processing operation or set of operations in question, and where a data protection impact assessment has already been carried out as part of a general impact assessment preceding the adoption of that legal act, paragraphs 1 to 6 of this Article shall not apply unless that legal act provides otherwise.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Alternative wording Amendment 1704 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
against:
Article 39
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 10, or of personal data relating to criminal convictions and offences referred to in Article 11; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The lists, the template and methodology
adoptedestablished and made public by theCommissionBoard and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation. - 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 of the Regulation (EU) 2016/679 by the relevant processors other than Union institutions and bodies shall be taken into due account in assessing the impact of the processing operations performed by such processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of public interests or the security of processing operations.
- 10.
Where processing pursuant to point (a) or (b) of Article 5(1) has a legal basis in a legal act adopted on the basis of the Treaties, which regulates the specific processing operation or set of operations in question, and where a data protection impact assessment has already been carried out as part of a general impact assessment preceding the adoption of that legal act, paragraphs 1 to 6 of this Article shall not apply unless that legal act provides otherwise.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Remove proposed wording Amendment 1705 · Pernando Barrena Arza, João Oliveira ITRE · LIBE
against:
Article 39
Data protection impact assessment
- 1.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 2.
The controller shall seek the advice of the data protection officer when carrying out a data protection impact assessment.
- 3.
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- (a)
a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- (b)
processing on a large scale of special categories of data referred to in Article 10, or of personal data relating to criminal convictions and offences referred to in Article 11; or
- (c)
a systematic monitoring of a publicly accessible area on a large scale.
- (a)
- 4.
The lists, the template and methodology adopted by the Commission and referred to in paragraph 6a of Article 35 of Regulation (EU) 2016/679 should apply to the processing of personal data under this Regulation.
- 5.
The European Data Protection Supervisor may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required.
- 6.
Prior to the adoption of the lists referred to in paragraphs 4 and 5 of this Article, the European Data Protection Supervisor shall request that the European Data Protection Board set up by Article 68 of Regulation (EU) 2016/679 examine such lists in accordance with point (e) of Article 70(1) of that Regulation where they refer to processing operations by a controller acting jointly with one or more controllers other than Union institutions and bodies.
- 7.
The assessment shall contain at least:
- (a)
a systematic description of the envisaged processing operations and the purposes of the processing;
- (b)
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
- (c)
an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
- (d)
the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
- (a)
- 8.
Compliance with approved codes of conduct referred to in Article 40 of the Regulation (EU) 2016/679 by the relevant processors other than Union institutions and bodies shall be taken into due account in assessing the impact of the processing operations performed by such processors, in particular for the purposes of a data protection impact assessment.
- 9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of public interests or the security of processing operations.
- 10.
Where processing pursuant to point (a) or (b) of Article 5(1) has a legal basis in a legal act adopted on the basis of the Treaties, which regulates the specific processing operation or set of operations in question, and where a data protection impact assessment has already been carried out as part of a general impact assessment preceding the adoption of that legal act, paragraphs 1 to 6 of this Article shall not apply unless that legal act provides otherwise.
- 11.
Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Article 39 – paragraphs 5 and 6
Wording reproduced in the amendment → Amendment 1705 · ITRE–LIBE amendments 1565–1740 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1705 · ITRE–LIBE amendments 1565–1740 to the draft report: removal
This wording is removed.
Article 39(4)
European Commission proposal → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
European Commission proposal
Council Presidency text · ST 10426/26
Article 39 – Paragraph 4
Wording reproduced in the amendment → Amendment 1703 · ITRE–LIBE amendments 1565–1740 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1703 · ITRE–LIBE amendments 1565–1740 to the draft report
Article 39 – Paragraph 4
Wording reproduced in the amendment → Amendment 1704 · ITRE–LIBE amendments 1565–1740 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1704 · ITRE–LIBE amendments 1565–1740 to the draft report
Article 39 – Paragraph 4
Wording reproduced in the amendment → Amendment 74 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 74 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Article 39 – Paragraph 4
Wording reproduced in the amendment → Amendment 495 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded