Data Act · Regulation (EU) 2023/2854
Article 32c
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 27 parts · 3 Council drafts · 66 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to Data ActThe wording proposed by the Commission at the start of this legislative file.
Full article with Commission changes
Article with proposed changes
Official consolidated text dated 13 December 2023, with the Commission proposal change affecting this article applied.
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
No standalone Commission wording is mapped to this tracked part. A newly proposed provision may have no earlier text of its own.
Commission source wording and instructions
Article 32c
Commission proposal
Article 32c General requirements for registration of recognised data intermediation services providers In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Article in June Presidency compromise · 10 June Council text
Comparison basis: Existing law (13 December 2023) compared with June Presidency compromise · 10 June (10 June 2026)
Article 32c
-
General requirements for registration of recognised data intermediation services providers In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), data intermediation services providers shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service, which may entail the use of data for the detection of fraud or cybersecurity. (c) where they offer additional tools and services to data holders, data subjects or data users for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation or other relevant privacy-enhancing technologies, such tools and services are used only at the explicit request or approval of the data holder or data subject or data user; (d) where data intermediation service providers offer services to their clients other than data intermediation services and the additional tools and services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder, data subject or data user; (ii) the data are not used for other purposes than performing the requested service; (iii) the data intermediation services are offered through an entity functionally separate from entities offering other services; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent. (f) the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service; (g) the data intermediation services provider maintains a log record of the data intermediation activity; (h) the data intermediation services provider takes necessary technical or organizational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data. Point (d)(iii), of the first sub-paragraph does not apply to micro and small sized enterprises.
Article 32c
June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
Article 32c General requirements for registration of recognised data intermediation services providers In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), data intermediation services providers shall meet all of the following requirements:
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service, which may entail the use of data for the detection of fraud or cybersecurity.
where they offer additional tools and services to data holders, data subjects or data users for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation or other relevant privacy-enhancing technologies, such tools and services are used only at the explicit request or approval of the data holder or data subject or data user; (d) where data intermediation service providers offer services to their clients other than data intermediation services and the additional tools and services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder, data subject or data user;
the data are not used for other purposes than performing the requested service; (iii) the data intermediation services are offered through an entity functionally separate from entities offering other services; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity;
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
the data intermediation services provider maintains a log record of the data intermediation activity;
the data intermediation services provider takes necessary technical or organizational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data. Point (d)(iii), of the first sub-paragraph does not apply to micro and small sized enterprises.
Article in June Presidency compromise · 18 June Council text
Comparison basis: Existing law (13 December 2023) compared with June Presidency compromise · 18 June (18 June 2026)
Article 32c
-
General requirements for registration of recognised data intermediation services providers In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), data intermediation services providers shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service, which may entail the use of data for the detection of fraud or cybersecurity. (c) where they offer additional tools and services to data holders, data subjects or data users for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation or other relevant privacy-enhancing technologies, such tools and services are used only at the explicit request or approval of the data holder or data subject or data user; (d) where data intermediation service providers offer services to their clients other than data intermediation services and the additional tools and services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder, data subject or data user; (ii) the data are not used for other purposes than performing the requested service; (iii) the data intermediation services are offered through an entity functionally separate from entities offering other services; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent. (f) the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service; (g) the data intermediation services provider maintains a log record of the data intermediation activity; (h) the data intermediation services provider takes necessary technical or organizational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data. Point (d)(iii), of the first sub-paragraph does not apply to micro and small sized enterprises.
Article 32c
June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
Article 32c General requirements for registration of recognised data intermediation services providers In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), data intermediation services providers shall meet all of the following requirements:
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service, which may entail the use of data for the detection of fraud or cybersecurity.
where they offer additional tools and services to data holders, data subjects or data users for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation or other relevant privacy-enhancing technologies, such tools and services are used only at the explicit request or approval of the data holder or data subject or data user; (d) where data intermediation service providers offer services to their clients other than data intermediation services and the additional tools and services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder, data subject or data user;
the data are not used for other purposes than performing the requested service; (iii) the data intermediation services are offered through an entity functionally separate from entities offering other services; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity;
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
the data intermediation services provider maintains a log record of the data intermediation activity;
the data intermediation services provider takes necessary technical or organizational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data. Point (d)(iii), of the first sub-paragraph does not apply to micro and small sized enterprises.
Article in September Presidency compromise Council text
Comparison basis: Existing law (13 December 2023) compared with September Presidency compromise (3 September 2026)
Article 32c
-
General requirements for registration of recognised data intermediation services providers In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), data intermediation services providers shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service, which may entail the use of data for the detection of fraud or cybersecurity. (c) where they offer additional tools and services to data holders, data subjects or data users for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation or other relevant privacy-enhancing technologies, such tools and services are used only at the explicit request or approval of the data holder or data subject or data user; (d) where data intermediation service providers offer services to their clients other than data intermediation services and the additional tools and services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder, data subject or data user; (ii) the data are not used for other purposes than performing the requested service; (iii) the data intermediation services are offered through an entity functionally separate from entities offering other services; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent. (f) the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service; (g) the data intermediation services provider maintains a log record of the data intermediation activity; (h) the data intermediation services provider takes necessary technical or organizational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data. Point (d)(iii), of the first sub-paragraph does not apply to micro and small sized enterprises.
Article 32c
September Presidency compromise
Council wording reconstructed for this provision from the official operation
Article 32c General requirements for registration of recognised data intermediation services providers In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), data intermediation services providers shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service, which may entail the use of data for the detection of fraud or cybersecurity. (c) where they offer additional tools and services to data holders, data subjects or data users for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation or other relevant privacy-enhancing technologies, such tools and services are used only at the explicit request or approval of the data holder or data subject or data user; (d) where data intermediation service providers offer services to their clients other than data intermediation services and the additional tools and services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder, data subject or data user; (ii) the data are not used for other purposes than performing the requested service; (iii) the data intermediation services are offered through an entity functionally separate from entities offering other services; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent. (f) the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service; (g) the data intermediation services provider maintains a log record of the data intermediation activity; (h) the data intermediation services provider takes necessary technical or organizational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data. Point (d)(iii), of the first sub-paragraph does not apply to micro and small sized enterprises.
Article 32c 3 Council drafts
Article 32c
10 June 2026 · June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
Article 32c General requirements for registration of recognised data intermediation services providers In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), data intermediation services providers shall meet all of the following requirements:
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service, which may entail the use of data for the detection of fraud or cybersecurity.
where they offer additional tools and services to data holders, data subjects or data users for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation or other relevant privacy-enhancing technologies, such tools and services are used only at the explicit request or approval of the data holder or data subject or data user; (d) where data intermediation service providers offer services to their clients other than data intermediation services and the additional tools and services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder, data subject or data user;
the data are not used for other purposes than performing the requested service; (iii) the data intermediation services are offered through an entity functionally separate from entities offering other services; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity;
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
the data intermediation services provider maintains a log record of the data intermediation activity;
the data intermediation services provider takes necessary technical or organizational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data. Point (d)(iii), of the first sub-paragraph does not apply to micro and small sized enterprises.
Article 32c
18 June 2026 · June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
Article 32c General requirements for registration of recognised data intermediation services providers In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), data intermediation services providers shall meet all of the following requirements:
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service, which may entail the use of data for the detection of fraud or cybersecurity.
where they offer additional tools and services to data holders, data subjects or data users for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation or other relevant privacy-enhancing technologies, such tools and services are used only at the explicit request or approval of the data holder or data subject or data user; (d) where data intermediation service providers offer services to their clients other than data intermediation services and the additional tools and services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder, data subject or data user;
the data are not used for other purposes than performing the requested service; (iii) the data intermediation services are offered through an entity functionally separate from entities offering other services; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity;
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
the data intermediation services provider maintains a log record of the data intermediation activity;
the data intermediation services provider takes necessary technical or organizational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data. Point (d)(iii), of the first sub-paragraph does not apply to micro and small sized enterprises.
Article 32c
3 September 2026 · September Presidency compromise
Council wording reconstructed for this provision from the official operation
Article 32c General requirements for registration of recognised data intermediation services providers In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), data intermediation services providers shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service, which may entail the use of data for the detection of fraud or cybersecurity. (c) where they offer additional tools and services to data holders, data subjects or data users for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation or other relevant privacy-enhancing technologies, such tools and services are used only at the explicit request or approval of the data holder or data subject or data user; (d) where data intermediation service providers offer services to their clients other than data intermediation services and the additional tools and services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder, data subject or data user; (ii) the data are not used for other purposes than performing the requested service; (iii) the data intermediation services are offered through an entity functionally separate from entities offering other services; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent. (f) the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service; (g) the data intermediation services provider maintains a log record of the data intermediation activity; (h) the data intermediation services provider takes necessary technical or organizational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data. Point (d)(iii), of the first sub-paragraph does not apply to micro and small sized enterprises.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Political group at the amendment date where available; otherwise the current Parliament affiliation.
Additional proposed wording Amendment 21 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
they have in place adequate technical, legal and organisational measures in order to prevent the transfer of or access to non-personal data that is contrary to Union law or the national law of the relevant Member State;
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for purposes other than performing the value-added service, such as advertising, profiling, ranking, price discrimination and training of AI systems; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider. Micro, small and medium- sized enterprises may rely on a functional separation only where they demonstrate that such separation ensures equivalent protection against conflicts of interest, cross-use of data and discriminatory treatment; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ba)
they have in place adequate technical, legal and organisational measures in order to prevent the transfer of or access to non-personal data that is contrary to Union law or the national law of the relevant Member State;
- (bb)
they keep a log record of their data intermediation activity, corresponding to the risks involved;
- (bc)
they provide for a possibility to use the details collected about activity on the data intermediation service for the purposes of security and detection of abusive or fraudulent access;
- (bd)
they provide an opportunity for, data subjects to exercise their rights in the event of insolvency;
- (ba)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (ba)
they have in place adequate technical, legal and organisational measures in order to prevent the transfer of or access to non-personal data that is contrary to Union law or the national law of the relevant Member State;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Additional proposed wording Amendment 22 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
they keep a log record of their data intermediation activity, corresponding to the risks involved;
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for purposes other than performing the value-added service, such as advertising, profiling, ranking, price discrimination and training of AI systems; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider. Micro, small and medium- sized enterprises may rely on a functional separation only where they demonstrate that such separation ensures equivalent protection against conflicts of interest, cross-use of data and discriminatory treatment; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ba)
they have in place adequate technical, legal and organisational measures in order to prevent the transfer of or access to non-personal data that is contrary to Union law or the national law of the relevant Member State;
- (bb)
they keep a log record of their data intermediation activity, corresponding to the risks involved;
- (bc)
they provide for a possibility to use the details collected about activity on the data intermediation service for the purposes of security and detection of abusive or fraudulent access;
- (bd)
they provide an opportunity for, data subjects to exercise their rights in the event of insolvency;
- (ba)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (bb)
they keep a log record of their data intermediation activity, corresponding to the risks involved;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Additional proposed wording Amendment 23 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
they provide for a possibility to use the details collected about activity on the data intermediation service for the purposes of security and detection of abusive or fraudulent access;
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for purposes other than performing the value-added service, such as advertising, profiling, ranking, price discrimination and training of AI systems; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider. Micro, small and medium- sized enterprises may rely on a functional separation only where they demonstrate that such separation ensures equivalent protection against conflicts of interest, cross-use of data and discriminatory treatment; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ba)
they have in place adequate technical, legal and organisational measures in order to prevent the transfer of or access to non-personal data that is contrary to Union law or the national law of the relevant Member State;
- (bb)
they keep a log record of their data intermediation activity, corresponding to the risks involved;
- (bc)
they provide for a possibility to use the details collected about activity on the data intermediation service for the purposes of security and detection of abusive or fraudulent access;
- (bd)
they provide an opportunity for, data subjects to exercise their rights in the event of insolvency;
- (ba)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (bc)
they provide for a possibility to use the details collected about activity on the data intermediation service for the purposes of security and detection of abusive or fraudulent access;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Additional proposed wording Amendment 24 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
they provide an opportunity for, data subjects to exercise their rights in the event of insolvency;
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for purposes other than performing the value-added service, such as advertising, profiling, ranking, price discrimination and training of AI systems; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider. Micro, small and medium- sized enterprises may rely on a functional separation only where they demonstrate that such separation ensures equivalent protection against conflicts of interest, cross-use of data and discriminatory treatment; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ba)
they have in place adequate technical, legal and organisational measures in order to prevent the transfer of or access to non-personal data that is contrary to Union law or the national law of the relevant Member State;
- (bb)
they keep a log record of their data intermediation activity, corresponding to the risks involved;
- (bc)
they provide for a possibility to use the details collected about activity on the data intermediation service for the purposes of security and detection of abusive or fraudulent access;
- (bd)
they provide an opportunity for, data subjects to exercise their rights in the event of insolvency;
- (ba)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (bd)
they provide an opportunity for, data subjects to exercise their rights in the event of insolvency;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 25 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for purposes other than performing the value-added service, such as advertising, profiling, ranking, price discrimination and training of AI systems; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider. Micro, small and medium- sized enterprises may rely on a functional separation only where they demonstrate that such separation ensures equivalent protection against conflicts of interest, cross-use of data and discriminatory treatment; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ba)
they have in place adequate technical, legal and organisational measures in order to prevent the transfer of or access to non-personal data that is contrary to Union law or the national law of the relevant Member State;
- (bb)
they keep a log record of their data intermediation activity, corresponding to the risks involved;
- (bc)
they provide for a possibility to use the details collected about activity on the data intermediation service for the purposes of security and detection of abusive or fraudulent access;
- (bd)
they provide an opportunity for, data subjects to exercise their rights in the event of insolvency;
- (ba)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for purposes other than performing the value-added service, such as advertising, profiling, ranking, price discrimination and training of AI systems; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 26 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for purposes other than performing the value-added service, such as advertising, profiling, ranking, price discrimination and training of AI systems; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider. Micro, small and medium- sized enterprises may rely on a functional separation only where they demonstrate that such separation ensures equivalent protection against conflicts of interest, cross-use of data and discriminatory treatment; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ba)
they have in place adequate technical, legal and organisational measures in order to prevent the transfer of or access to non-personal data that is contrary to Union law or the national law of the relevant Member State;
- (bb)
they keep a log record of their data intermediation activity, corresponding to the risks involved;
- (bc)
they provide for a possibility to use the details collected about activity on the data intermediation service for the purposes of security and detection of abusive or fraudulent access;
- (bd)
they provide an opportunity for, data subjects to exercise their rights in the event of insolvency;
- (ba)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider. Micro, small and medium- sized enterprises may rely on a functional separation only where they demonstrate that such separation ensures equivalent protection against conflicts of interest, cross-use of data and discriminatory treatment; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 38 JURI draft opinion · Brando Benifei (rapporteur)
Justification
This amendment clarifies that value-added services may only be provided at the explicit request of the relevant data holder or data subject and that data may only be used for the specific requested service. This strengthens user control, purpose limitation and legal certainty within data intermediation services.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder or data subject; (ii) the data are not used for other purposes than performing the requested service; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ea)
the data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject;
- (eb)
the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (ec)
the data intermediation services provider maintains a log record of the data intermediation activity;
- (ed)
the data intermediation services provider takes necessary technical or organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder or data subject; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 39 JURI draft opinion · Brando Benifei (rapporteur)
Justification
This amendment clarifies that value-added services may only be provided at the explicit request of the relevant data holder or data subject and that data may only be used for the specific requested service. This strengthens user control, purpose limitation and legal certainty within data intermediation services.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder or data subject; (ii) the data are not used for other purposes than performing the requested service; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ea)
the data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject;
- (eb)
the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (ec)
the data intermediation services provider maintains a log record of the data intermediation activity;
- (ed)
the data intermediation services provider takes necessary technical or organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the requested service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 40 JURI draft opinion · Brando Benifei (rapporteur)
Justification
This amendment strengthens the independence and neutrality of data intermediation services by requiring a clear legal, organisational and operational separation between intermediation activities and other commercial services. This helps reduce conflicts of interest, improve trust and prevent the indirect exploitation of shared data.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder or data subject; (ii) the data are not used for other purposes than performing the requested service; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ea)
the data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject;
- (eb)
the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (ec)
the data intermediation services provider maintains a log record of the data intermediation activity;
- (ed)
the data intermediation services provider takes necessary technical or organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 41 JURI draft opinion · Brando Benifei (rapporteur)
Justification
This amendment improves the clarity and consistency of the provision by referring more broadly to “other services” rather than “value-added services”. It helps ensure that neutrality and anti-tying safeguards apply to all additional commercial services linked to data intermediation activities.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder or data subject; (ii) the data are not used for other purposes than performing the requested service; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ea)
the data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject;
- (eb)
the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (ec)
the data intermediation services provider maintains a log record of the data intermediation activity;
- (ed)
the data intermediation services provider takes necessary technical or organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 42 JURI draft opinion · Brando Benifei (rapporteur)
Justification
This amendment improves the clarity and consistency of the provision by referring more broadly to “other services” rather than “value-added services”. It helps ensure that neutrality and anti-tying safeguards apply to all additional commercial services linked to data intermediation activities.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder or data subject; (ii) the data are not used for other purposes than performing the requested service; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ea)
the data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject;
- (eb)
the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (ec)
the data intermediation services provider maintains a log record of the data intermediation activity;
- (ed)
the data intermediation services provider takes necessary technical or organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Additional proposed wording Amendment 43 JURI draft opinion · Brando Benifei (rapporteur)
the data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject;
Justification
This amendment strengthens the neutrality and trustworthiness of data intermediation services by prohibiting the secondary commercial exploitation of data made available through such services. It helps ensure that data intermediation providers act solely as neutral facilitators and not as entities monetising or repurposing shared data for their own commercial interests.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder or data subject; (ii) the data are not used for other purposes than performing the requested service; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ea)
the data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject;
- (eb)
the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (ec)
the data intermediation services provider maintains a log record of the data intermediation activity;
- (ed)
the data intermediation services provider takes necessary technical or organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ea)
the data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject;
- (a)
Additional proposed wording Amendment 44 JURI draft opinion · Brando Benifei (rapporteur)
the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
Justification
This amendment strengthens fairness and neutrality obligations for data intermediation services by ensuring that access conditions, pricing and terms of service remain transparent and non-discriminatory for all parties involved.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder or data subject; (ii) the data are not used for other purposes than performing the requested service; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ea)
the data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject;
- (eb)
the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (ec)
the data intermediation services provider maintains a log record of the data intermediation activity;
- (ed)
the data intermediation services provider takes necessary technical or organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (eb)
the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (a)
Additional proposed wording Amendment 45 JURI draft opinion · Brando Benifei (rapporteur)
the data intermediation services provider maintains a log record of the data intermediation activity;
Justification
This amendment improves accountability and traceability by requiring data intermediation service providers to maintain records of their intermediation activities.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder or data subject; (ii) the data are not used for other purposes than performing the requested service; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ea)
the data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject;
- (eb)
the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (ec)
the data intermediation services provider maintains a log record of the data intermediation activity;
- (ed)
the data intermediation services provider takes necessary technical or organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ec)
the data intermediation services provider maintains a log record of the data intermediation activity;
- (a)
Additional proposed wording Amendment 46 JURI draft opinion · Brando Benifei (rapporteur)
the data intermediation services provider takes necessary technical or organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) such other services are explicitly requested by the data holder or data subject; (ii) the data are not used for other purposes than performing the requested service; (iii) the value-added services are offered through a separate legal person that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the other services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses other services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ea)
the data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject;
- (eb)
the data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (ec)
the data intermediation services provider maintains a log record of the data intermediation activity;
- (ed)
the data intermediation services provider takes necessary technical or organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ed)
the data intermediation services provider takes necessary technical or organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data.
- (a)
Alternative wording Amendment 59 IMCO draft opinion · Alex Agius Saliba (rapporteur)
Justification
In line with the EDPB-EDPS joint opinion, paragraph 138.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a separate entity that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the value-added services is not designated as a Very Large Online Platform pursuant to Article 33 of Regulation (EU) 2022/1925 or as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent. Data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject.
- (ea)
The data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (eb)
The data intermediation services provider maintains a log record of the data intermediation activity;
- (ec)
The data intermediation services provider takes the necessary technical, organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data;
- (ed)
The data intermediation services provider shall have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services;
- (ee)
the data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 60 IMCO draft opinion · Alex Agius Saliba (rapporteur)
Justification
In line with the EDPB-EDPS opinion paragraph 135.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a separate entity that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the value-added services is not designated as a Very Large Online Platform pursuant to Article 33 of Regulation (EU) 2022/1925 or as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent. Data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject.
- (ea)
The data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (eb)
The data intermediation services provider maintains a log record of the data intermediation activity;
- (ec)
The data intermediation services provider takes the necessary technical, organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data;
- (ed)
The data intermediation services provider shall have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services;
- (ee)
the data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a separate entity that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 61 IMCO draft opinion · Alex Agius Saliba (rapporteur)
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a separate entity that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the value-added services is not designated as a Very Large Online Platform pursuant to Article 33 of Regulation (EU) 2022/1925 or as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent. Data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject.
- (ea)
The data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (eb)
The data intermediation services provider maintains a log record of the data intermediation activity;
- (ec)
The data intermediation services provider takes the necessary technical, organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data;
- (ed)
The data intermediation services provider shall have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services;
- (ee)
the data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a Very Large Online Platform pursuant to Article 33 of Regulation (EU) 2022/1925 or as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 62 IMCO draft opinion · Alex Agius Saliba (rapporteur)
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a separate entity that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the value-added services is not designated as a Very Large Online Platform pursuant to Article 33 of Regulation (EU) 2022/1925 or as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent. Data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject.
- (ea)
The data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (eb)
The data intermediation services provider maintains a log record of the data intermediation activity;
- (ec)
The data intermediation services provider takes the necessary technical, organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data;
- (ed)
The data intermediation services provider shall have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services;
- (ee)
the data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent. Data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Additional proposed wording Amendment 63 IMCO draft opinion · Alex Agius Saliba (rapporteur)
The data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a separate entity that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the value-added services is not designated as a Very Large Online Platform pursuant to Article 33 of Regulation (EU) 2022/1925 or as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent. Data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject.
- (ea)
The data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (eb)
The data intermediation services provider maintains a log record of the data intermediation activity;
- (ec)
The data intermediation services provider takes the necessary technical, organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data;
- (ed)
The data intermediation services provider shall have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services;
- (ee)
the data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ea)
The data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (a)
Additional proposed wording Amendment 64 IMCO draft opinion · Alex Agius Saliba (rapporteur)
The data intermediation services provider maintains a log record of the data intermediation activity;
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a separate entity that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the value-added services is not designated as a Very Large Online Platform pursuant to Article 33 of Regulation (EU) 2022/1925 or as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent. Data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject.
- (ea)
The data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (eb)
The data intermediation services provider maintains a log record of the data intermediation activity;
- (ec)
The data intermediation services provider takes the necessary technical, organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data;
- (ed)
The data intermediation services provider shall have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services;
- (ee)
the data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (eb)
The data intermediation services provider maintains a log record of the data intermediation activity;
- (a)
Additional proposed wording Amendment 65 IMCO draft opinion · Alex Agius Saliba (rapporteur)
The data intermediation services provider takes the necessary technical, organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data;
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a separate entity that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the value-added services is not designated as a Very Large Online Platform pursuant to Article 33 of Regulation (EU) 2022/1925 or as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent. Data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject.
- (ea)
The data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (eb)
The data intermediation services provider maintains a log record of the data intermediation activity;
- (ec)
The data intermediation services provider takes the necessary technical, organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data;
- (ed)
The data intermediation services provider shall have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services;
- (ee)
the data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ec)
The data intermediation services provider takes the necessary technical, organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data;
- (a)
Additional proposed wording Amendment 66 IMCO draft opinion · Alex Agius Saliba (rapporteur)
The data intermediation services provider shall have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services;
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a separate entity that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the value-added services is not designated as a Very Large Online Platform pursuant to Article 33 of Regulation (EU) 2022/1925 or as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent. Data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject.
- (ea)
The data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (eb)
The data intermediation services provider maintains a log record of the data intermediation activity;
- (ec)
The data intermediation services provider takes the necessary technical, organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data;
- (ed)
The data intermediation services provider shall have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services;
- (ee)
the data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ed)
The data intermediation services provider shall have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services;
- (a)
Additional proposed wording Amendment 67 IMCO draft opinion · Alex Agius Saliba (rapporteur)
the data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a separate entity that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the value-added services is not designated as a Very Large Online Platform pursuant to Article 33 of Regulation (EU) 2022/1925 or as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent. Data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject.
- (ea)
The data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service;
- (eb)
The data intermediation services provider maintains a log record of the data intermediation activity;
- (ec)
The data intermediation services provider takes the necessary technical, organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data;
- (ed)
The data intermediation services provider shall have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services;
- (ee)
the data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights.
- (ea)
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ee)
the data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights.
- (a)
Alternative wording Amendment 200 · Emil Radev JURI
against:
Article 32c
General requirements for voluntary registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Remove proposed wording Amendment 201 · David Cormand JURI
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 202 · Mario Mantovani JURI
Justification
Authorising data intermediation service providers to use metadata for the benefit of their own development without providing suitable user controls would contravene the principle of control enshrined in Article 4(11). Only authorising data intermediation service providers to access metadata would undermine the level playing field. SMEs may also need to access metadata to comply with Union requirements such as the General Production Safety Regulation. Clarifying this would prevent legal fragmentation and ensure that SMEs continue to comply with Union legislation.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service and only in so far as such use adheres to the principle of user control referred to in Article 4(11), including, where applicable, the user’s consent or explicit request. This provision shall not preclude manufacturers or other relevant economic operators from accessing such metadata for the purposes of fulfilling their legal requirements under Union law; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 203 · David Cormand JURI
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 204 · Laurence Farreng JURI
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a legally, organisationally and operationally separate entity from the data intermediation service provider; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 205 · Emil Radev JURI
Justification
This amendment reverts to the original wording to preserve the independence of data intermediation services. In a highly concentrated cloud market, allowing providers to act as intermediaries may create conflicts of interest. The requirement for a separate legal entity ensures functional separation, transparency and effective oversight, thereby fostering trust and fair competition.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a separate legal person. SMEs/SMCs may offer value-added services through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Additional proposed wording Amendment 206 · Arash Saeidi JURI
the data intermediation services provider takes necessary technical or organisational measures to ensure that storage of non-personal data can be done on the territory of the European Union upon explicit and motivated request of the data explicit request of the data holder or data subject;
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ea)
the data intermediation services provider takes necessary technical or organisational measures to ensure that storage of non-personal data can be done on the territory of the European Union upon explicit and motivated request of the data explicit request of the data holder or data subject;
- (a)
Additional proposed wording Amendment 207 · David Cormand JURI
The data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ea)
The data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to prices and terms of service.
- (a)
Additional proposed wording Amendment 208 · David Cormand JURI
The data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (eb)
The data intermediation service providers shall not use data made available through their services for advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject.
- (a)
Additional proposed wording Amendment 209 · David Cormand JURI
The data intermediation services provider takes the necessary technical, organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data, including by maintaining a log record of the intermediation.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ec)
The data intermediation services provider takes the necessary technical, organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data, including by maintaining a log record of the intermediation.
- (a)
Additional proposed wording Amendment 210 · David Cormand JURI
The data intermediation services provider shall have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ed)
The data intermediation services provider shall have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services.
- (a)
Additional proposed wording Amendment 211 · David Cormand JURI
The data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ee)
The data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights.
- (a)
Alternative wording Amendment 279 · Virginie Joron IMCO
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) the data intermediation services provider shall provide the tools and services necessary for facilitating the exchange of data, such as temporary storage, preservation, conversion, encryption, anonymisation and pseudonymisation, and shall implement appropriate technical and organisational measures to prevent the re-identification of pseudonymised data, personal data breaches and any unlawful acquisition, use, disclosure or transfer of data for which it provides data intermediation services; where the data are made available in pseudonymised or anonymised form, the provider shall apply state-of-the-art techniques aimed at preserving and reinforcing privacy protection. (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 280 · David Cormand on behalf of the Verts/ALE Group IMCO
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity that is legally, organisationally and operationally separate from the data intermediation service provider; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 281 · Sophia Kircher IMCO
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a separate legal person. SMEs/SMCs may offer value-added services through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 282 · David Cormand on behalf of the Verts/ALE Group IMCO
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent. Data intermediation service providers shall not use data made available through their services for advertising, insurance, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Additional proposed wording Amendment 283 · David Cormand on behalf of the Verts/ALE Group IMCO
The data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to pricing structure, contracts and terms of service;
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
- (ea)
The data intermediation services provider ensures that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data users, including with regard to pricing structure, contracts and terms of service;
Additional proposed wording Amendment 284 · Kateřina Konečná IMCO
the data intermediation services provider takes necessary technical or organisational measures to ensure that storage of non-personal data can be done on the territory of the European Union upon explicit and motivated request of the data explicit request of the data holder or data subject;
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ea)
the data intermediation services provider takes necessary technical or organisational measures to ensure that storage of non-personal data can be done on the territory of the European Union upon explicit and motivated request of the data explicit request of the data holder or data subject;
- (a)
Additional proposed wording Amendment 285 · David Cormand on behalf of the Verts/ALE Group IMCO
The data intermediation services provider takes the necessary technical, organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data, including by maintaining a log record of the intermediation and have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services;
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
- (eb)
The data intermediation services provider takes the necessary technical, organisational measures to ensure an appropriate level of security for the storage, processing and transmission of non-personal data, including by maintaining a log record of the intermediation and have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services;
Additional proposed wording Amendment 286 · David Cormand on behalf of the Verts/ALE Group IMCO
The data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
- (ec)
The data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights.
Alternative wording Amendment 724 · Damian Boeselager on behalf of the Verts/ALE Group ITRE · LIBE
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 725 · Damian Boeselager on behalf of the Verts/ALE Group ITRE · LIBE
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), aA data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 726 · João Oliveira ITRE · LIBE
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public
Union registerregisters referred to in Article 32a paragraph 1 point (a) and paragraph 1a point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Additional proposed wording Amendment 727 · Damian Boeselager on behalf of the Verts/ALE Group ITRE · LIBE
'the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user shall be provided in a transparent and non-discriminatory manner and not be dependent upon whether the data holder or data user uses other services provided by the same data intermediation services provider or by a related entity, and if so to what degree the data holder or data user uses such other services;'
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (aa)
'the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user shall be provided in a transparent and non-discriminatory manner and not be dependent upon whether the data holder or data user uses other services provided by the same data intermediation services provider or by a related entity, and if so to what degree the data holder or data user uses such other services;'
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 728 · Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler ITRE · LIBE
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service, which may entail the use of data for the detection of fraud or cybersecurity; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Additional proposed wording Amendment 729 · Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba ITRE · LIBE
(ba) In Article 32c, paragraph 1, the following point is inserted
they shall provide that, in the event of insolvency, data subjects have an opportunity to exercise their rights, ensuring a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights;'
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (ba)
they shall provide that, in the event of insolvency, data subjects have an opportunity to exercise their rights, ensuring a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights;'
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 730 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) the data intermediation services provider shall provide the tools and services necessary to facilitate the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, and shall systematically implement appropriate technical and organisational measures to prevent the re-identification of pseudonymised data, personal data breaches, and any unlawful acquisition, use, disclosure or transfer of the data for which it provides data intermediation services; where the data are made available in pseudonymised or anonymised form, the provider shall apply state-of-the-art privacy-preserving and privacy-enhancing techniques to that effect. (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 731 · Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba ITRE · LIBE
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or explicit consent of the data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Additional proposed wording Amendment 732 · Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler ITRE · LIBE
(ca) In Article 32c, paragraph 1, the follwoing point is inserted
where a data intermediation services provider provides tools for obtaining consent from data subjects or permissions to process data made available by data holders, it shall, where relevant, specify the third-country jurisdiction in which the data use is intended to take place and provide data subjects with tools to both give and withdraw consent and data holders with tools to both give and withdraw permissions to process data;'
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (ca)
where a data intermediation services provider provides tools for obtaining consent from data subjects or permissions to process data made available by data holders, it shall, where relevant, specify the third-country jurisdiction in which the data use is intended to take place and provide data subjects with tools to both give and withdraw consent and data holders with tools to both give and withdraw permissions to process data;'
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Additional proposed wording Amendment 733 · Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler ITRE · LIBE
(cb) In Article 32c, paragraph 1, the following point is inserted
the data intermediation services provider shall maintain a log record of the data intermediation activity, corresponding to the risks involved;'
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (cb)
the data intermediation services provider shall maintain a log record of the data intermediation activity, corresponding to the risks involved;'
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Additional proposed wording Amendment 734 · Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler ITRE · LIBE
(cc) In Article 32c, paragraph 1, the following point is inserted
the data intermediation services provider shall have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services, corresponding to the risks involved;'
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (cc)
the data intermediation services provider shall have procedures in place to prevent fraudulent or abusive practices in relation to parties seeking access through its data intermediation services, corresponding to the risks involved;'
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Additional proposed wording Amendment 735 · Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler ITRE · LIBE
(cd) In Article 32c, paragraph 1, the following point is inserted
the data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights;'
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (cd)
the data intermediation services provider shall, in the event of its insolvency, ensure a reasonable continuity of the provision of its data intermediation services and, where such data intermediation services ensure the storage of data, shall have mechanisms in place to allow data holders and data users to obtain access to, to transfer or to retrieve their data and, where such data intermediation services are provided between data subjects and data users, to allow data subjects to exercise their rights;'
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 736 · Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba ITRE · LIBE
Justification
This amendment addresses concerns expressed in the EDPB-EDPS opinion. The Proposal does not specifically justify the reason for exempting small and micro enterprises entirely from the functional separation requirement. Ensuring neutrality by managing conflicting interests would appear relevant, regardless of enterprise size.
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 737 · Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba ITRE · LIBE
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service, such as advertising, profiling, ranking, price discrimination, training of AI systems or any purpose other than putting those data at the disposal of data users in accordance with the instructions of the data holder or data subject; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 738 · João Oliveira ITRE · LIBE
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service, including advertising, profiling, ranking, price discrimination and training of AI systems; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 739 · Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler ITRE · LIBE
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity, as demonstrated by criteria including technical and organisational segregation of data, absence of conflicts of interest, cross-use of data, and discriminatory treatment, and separate management, financing and staff ; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 740 · Damian Boeselager on behalf of the Verts/ALE Group ITRE · LIBE
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a legally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Alternative wording Amendment 741 · Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Matthias Ecke, Lina Gálvez, Francisco Assis, Alex Agius Saliba ITRE · LIBE
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not a very large enterprise, including gatekeepers as designated pursuant to Article 3 of Regulation (EU) 2022/1925; (v) the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Remove proposed wording Amendment 742 · Damian Boeselager on behalf of the Verts/ALE Group ITRE · LIBE
Justification
Moved
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements: (a) they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; (b) the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; (c) where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; (d) where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions: (i) the value-added services are explicitly requested by the user; (ii) the data are not used for other purposes than performing the value-added service; (iii) the value-added services are offered through a functionally separate entity; (iv) the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; (e) the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users; - (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service; - (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject; - (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:- (i)
the value-added services are explicitly requested by the user; - (ii)
the data are not used for other purposes than performing the value-added service; - (iii)
the value-added services are offered through a functionally separate entity; - (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; - (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (a)
Additional proposed wording Amendment 743 · Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba ITRE · LIBE
(ea) In Article 32c, paragraph 1, the following point is added
the data intermediation services provider ensure that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data usrs, including with regard to prices and terms of service;'
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ea)
the data intermediation services provider ensure that the procedure for access to its service is fair, transparent and non-discriminatory for both data subjects and data holders, as well as for data usrs, including with regard to prices and terms of service;'
- (a)
Additional proposed wording Amendment 744 · Mary Khan ITRE · LIBE
in Article 32c(1), the following point (ea) is added
where the data intermediation service passes on personal data, special categories of personal data or data held by public sector bodies, this shall remain legally and organisationally separate from the provider’s other activities.’
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (ea)
where the data intermediation service passes on personal data, special categories of personal data or data held by public sector bodies, this shall remain legally and organisationally separate from the provider’s other activities.’
- (a)
Additional proposed wording Amendment 745 · Mary Khan ITRE · LIBE
in Article 32c(1), the following point (eb) is added
the provider must not merge the data passed on, or any data derived from it, with data from other services, or use it for advertising, profiling, scoring, creditworthiness assessment, or price customisation, or for the training, testing or validation of AI systems or AI models. The sale or other provision of such data for the provider’s own or third-parties’ secondary purposes shall be prohibited.’
against:
Article 32c
General requirements for registration of recognised data intermediation services providers
-
In order to qualify for registration in the public Union register referred to in Article 32a paragraph 1 point (a), a data intermediation services provider shall meet all of the following requirements:
- (a)
they do not use the data for which it provides data intermediation services for purposes other than to put them at the disposal of data users;
- (b)
the data they collect with respect to any activity of a natural or legal person for the purpose of the provision of the data intermediation service, including the date, time and geolocation data, duration of activity and connections to other natural or legal persons established by the person who uses the data intermediation service, are used only for the development of that data intermediation service;
- (c)
where they offer additional tools and services to data holders or data subjects for the specific purpose of facilitating the exchange of data, such as temporary storage, curation, conversion, encryption, anonymisation and pseudonymisation, such tools and services are used only at the explicit request or approval of the data holder or data subject;
- (d)
where data intermediation service providers which are not micro and small sized enterprises offer value-added services to their clients other than the services referred to in point (c), they fulfil the following conditions:
- (i)
the value-added services are explicitly requested by the user;
- (ii)
the data are not used for other purposes than performing the value-added service;
- (iii)
the value-added services are offered through a functionally separate entity;
- (iv)
the undertaking seeking to offer the value-added services is not designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925;
- (v)
the commercial terms, including pricing, for the provision of data intermediation services to a data holder or data user are not dependent upon whether the data holder or data user uses value-added services provided by the data intermediation services provider or by a related entity;
- (i)
- (e)
the data intermediation services provider offering services to data subjects acts in the data subjects’ best interest where it facilitates the exercise of their rights, in particular by informing and, where appropriate, advising data subjects in a concise, transparent, intelligible and easily accessible manner about intended data uses by data users and standard terms and conditions attached to such uses before data subjects give consent.
- (eb)
the provider must not merge the data passed on, or any data derived from it, with data from other services, or use it for advertising, profiling, scoring, creditworthiness assessment, or price customisation, or for the training, testing or validation of AI systems or AI models. The sale or other provision of such data for the provider’s own or third-parties’ secondary purposes shall be prohibited.’
- (a)
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Article 32c
European Commission proposal → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
European Commission proposal
Council Presidency text · ST 10426/26
Article 32c
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Article 32c
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Council Presidency text · ST 12535/26
Article 32c
Wording reproduced in the amendment → Amendment 724 · ITRE–LIBE amendments 527–776 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 724 · ITRE–LIBE amendments 527–776 to the draft report
Article 32c
Wording reproduced in the amendment → Amendment 725 · ITRE–LIBE amendments 527–776 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 725 · ITRE–LIBE amendments 527–776 to the draft report
Article 32c
Wording reproduced in the amendment → Amendment 726 · ITRE–LIBE amendments 527–776 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 726 · ITRE–LIBE amendments 527–776 to the draft report
Article 32c
Wording reproduced in the amendment → Amendment 736 · ITRE–LIBE amendments 527–776 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 736 · ITRE–LIBE amendments 527–776 to the draft report
Article 32c
Wording reproduced in the amendment → Amendment 742 · ITRE–LIBE amendments 527–776 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 742 · ITRE–LIBE amendments 527–776 to the draft report: removal
This wording is removed.
Article 32c
Wording reproduced in the amendment → Amendment 59 · IMCO draft opinion · Alex Agius Saliba (rapporteur)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 59 · IMCO draft opinion · Alex Agius Saliba (rapporteur)
Article 32c
Wording reproduced in the amendment → Amendment 200 · JURI amendments 69–296 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 200 · JURI amendments 69–296 to the draft opinion
Article 32c
Wording reproduced in the amendment → Amendment 42 · JURI draft opinion · Brando Benifei (rapporteur)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 42 · JURI draft opinion · Brando Benifei (rapporteur)
Article 32c(b)
Wording reproduced in the amendment → Amendment 728 · ITRE–LIBE amendments 527–776 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 728 · ITRE–LIBE amendments 527–776 to the draft report
Article 32c(b)
Wording reproduced in the amendment → Amendment 201 · JURI amendments 69–296 to the draft opinion: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 201 · JURI amendments 69–296 to the draft opinion: removal
This wording is removed.
Article 32c(b)
Wording reproduced in the amendment → Amendment 202 · JURI amendments 69–296 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 202 · JURI amendments 69–296 to the draft opinion
Article 32c(c)
Wording reproduced in the amendment → Amendment 730 · ITRE–LIBE amendments 527–776 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 730 · ITRE–LIBE amendments 527–776 to the draft report
Article 32c(c)
Wording reproduced in the amendment → Amendment 731 · ITRE–LIBE amendments 527–776 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 731 · ITRE–LIBE amendments 527–776 to the draft report
Article 32c(c)
Wording reproduced in the amendment → Amendment 279 · IMCO amendments 125–328 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 279 · IMCO amendments 125–328 to the draft opinion
Article 32c(d)
Wording reproduced in the amendment → Amendment 736 · ITRE–LIBE amendments 527–776 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 736 · ITRE–LIBE amendments 527–776 to the draft report
Article 32c(d)
Wording reproduced in the amendment → Amendment 59 · IMCO draft opinion · Alex Agius Saliba (rapporteur)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 59 · IMCO draft opinion · Alex Agius Saliba (rapporteur)
Article 32c(d)(i)
Wording reproduced in the amendment → Amendment 38 · JURI draft opinion · Brando Benifei (rapporteur)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 38 · JURI draft opinion · Brando Benifei (rapporteur)
Article 32c(d)(ii)
Wording reproduced in the amendment → Amendment 737 · ITRE–LIBE amendments 527–776 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 737 · ITRE–LIBE amendments 527–776 to the draft report
Article 32c(d)(ii)
Wording reproduced in the amendment → Amendment 738 · ITRE–LIBE amendments 527–776 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 738 · ITRE–LIBE amendments 527–776 to the draft report
Article 32c(d)(ii)
Wording reproduced in the amendment → Amendment 25 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 25 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Article 32c(d)(ii)
Wording reproduced in the amendment → Amendment 39 · JURI draft opinion · Brando Benifei (rapporteur)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 39 · JURI draft opinion · Brando Benifei (rapporteur)
Article 32c(d)(iii)
Wording reproduced in the amendment → Amendment 739 · ITRE–LIBE amendments 527–776 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 739 · ITRE–LIBE amendments 527–776 to the draft report
Article 32c(d)(iii)
Wording reproduced in the amendment → Amendment 740 · ITRE–LIBE amendments 527–776 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 740 · ITRE–LIBE amendments 527–776 to the draft report
Article 32c(d)(iii)
Wording reproduced in the amendment → Amendment 26 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 26 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Article 32c(d)(iii)
Wording reproduced in the amendment → Amendment 280 · IMCO amendments 125–328 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 280 · IMCO amendments 125–328 to the draft opinion
Article 32c(d)(iii)
Wording reproduced in the amendment → Amendment 281 · IMCO amendments 125–328 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 281 · IMCO amendments 125–328 to the draft opinion
Article 32c(d)(iii)
Wording reproduced in the amendment → Amendment 60 · IMCO draft opinion · Alex Agius Saliba (rapporteur)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 60 · IMCO draft opinion · Alex Agius Saliba (rapporteur)
Article 32c(d)(iii)
Wording reproduced in the amendment → Amendment 203 · JURI amendments 69–296 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 203 · JURI amendments 69–296 to the draft opinion
Article 32c(d)(iii)
Wording reproduced in the amendment → Amendment 204 · JURI amendments 69–296 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 204 · JURI amendments 69–296 to the draft opinion
Article 32c(d)(iii)
Wording reproduced in the amendment → Amendment 205 · JURI amendments 69–296 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 205 · JURI amendments 69–296 to the draft opinion
Article 32c(d)(iii)
Wording reproduced in the amendment → Amendment 40 · JURI draft opinion · Brando Benifei (rapporteur)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 40 · JURI draft opinion · Brando Benifei (rapporteur)
Article 32c(d)(iv)
Wording reproduced in the amendment → Amendment 741 · ITRE–LIBE amendments 527–776 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 741 · ITRE–LIBE amendments 527–776 to the draft report
Article 32c(d)(iv)
Wording reproduced in the amendment → Amendment 61 · IMCO draft opinion · Alex Agius Saliba (rapporteur)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 61 · IMCO draft opinion · Alex Agius Saliba (rapporteur)
Article 32c(d)(iv)
Wording reproduced in the amendment → Amendment 41 · JURI draft opinion · Brando Benifei (rapporteur)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 41 · JURI draft opinion · Brando Benifei (rapporteur)
Article 32c(e)
Wording reproduced in the amendment → Amendment 282 · IMCO amendments 125–328 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 282 · IMCO amendments 125–328 to the draft opinion
Article 32c(e)
Wording reproduced in the amendment → Amendment 62 · IMCO draft opinion · Alex Agius Saliba (rapporteur)
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 62 · IMCO draft opinion · Alex Agius Saliba (rapporteur)
Article 32c, heading
Wording reproduced in the amendment → Amendment 724 · ITRE–LIBE amendments 527–776 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 724 · ITRE–LIBE amendments 527–776 to the draft report
Article 32c, heading
Wording reproduced in the amendment → Amendment 725 · ITRE–LIBE amendments 527–776 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 725 · ITRE–LIBE amendments 527–776 to the draft report
Article 32c, heading
Wording reproduced in the amendment → Amendment 726 · ITRE–LIBE amendments 527–776 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 726 · ITRE–LIBE amendments 527–776 to the draft report
Article 32c, heading
Wording reproduced in the amendment → Amendment 200 · JURI amendments 69–296 to the draft opinion
Changes in context
RemovedAdded