# LongBench v2 / 66fea153bb02136c067ca3e7

task_id: ab3f8207-c785-568d-ab36-4f9e30b1139d
task_key: train--66fea153bb02136c067ca3e7
task_revision_id: 3

{"choice_A":"In order to implement the team voice connection function in the game, if players need to use the microphone for voice connection during team matching, the recording will be temporarily stored in the mobile phone.","choice_B":"In order to run the game on different models of mobile phones, online channels and PCs, the game needs to have software interfaces for different mobile phones.","choice_C":"If players wish to add friends from their address book in the game, they can do so by associating them with their address book.","choice_D":"None of these above","context":"This text is meant purely as a documentation tool and has no legal effect. The Union's institutions do not assume any liability \nfor its contents. The authentic versions of the relevant acts, including their preambles, are those published in the Official \nJournal of the European Union and available in EUR-Lex. Those official texts are directly accessible through the links \nembedded in this document \n►B REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL \nof 27 April 2016 \non the protection of natural persons with regard to the processing of personal data and on the free \nmovement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) \n(Text with EEA relevance) \n(OJ L 119, 4.5.2016, p. 1) \nCorrected by: \n►C1 \nCorrigendum, OJ L 127, 23.5.2018, p. 2 (2016/679) \n02016R0679 — EN — 04.05.2016 — 000.002 — 1\n\n\n02016R0679 — EN — 04.05.2016 — 000.002 — 2 \nREGULATION \n(EU) \n2016/679 \nOF \nTHE \nEUROPEAN \nPARLIAMENT AND OF THE COUNCIL \nof 27 April 2016 \non the protection of natural persons with regard to the processing \nof personal data and on the free movement of such data, and \nrepealing Directive 95/46/EC (General Data Protection Regulation) \n(Text with EEA relevance) \nCHAPTER I \nGeneral provisions \nArticle 1 \nSubject-matter and objectives \n1. \nThis Regulation lays down rules relating to the protection of \nnatural persons with regard to the processing of personal data and \nrules relating to the free movement of personal data. \n2. \nThis Regulation protects fundamental rights and freedoms of \nnatural persons and in particular their right to the protection of \npersonal data. \n3. \nThe free movement of personal data within the Union shall be \nneither restricted nor prohibited for reasons connected with the \nprotection of natural persons with regard to the processing of personal \ndata. \nArticle 2 \nMaterial scope \n1. \nThis Regulation applies to the processing of personal data wholly \nor partly by automated means and to the processing other than by \nautomated means of personal data which form part of a filing system \nor are intended to form part of a filing system. \n2. \nThis Regulation does not apply to the processing of personal data: \n(a) in the course of an activity which falls outside the scope of Union \nlaw; \n(b) by the Member States when carrying out activities which fall within \nthe scope of Chapter 2 of Title V of the TEU; \n(c) by a natural person in the course of a purely personal or household \nactivity; \n(d) by competent authorities for the purposes of the prevention, inves­\ntigation, detection or prosecution of criminal offences or the \nexecution of criminal penalties, including the safeguarding against \nand the prevention of threats to public security. \n3. \nFor the processing of personal data by the Union institutions, \nbodies, offices and agencies, Regulation (EC) No 45/2001 applies. \nRegulation (EC) No 45/2001 and other Union legal acts applicable to \nsuch processing of personal data shall be adapted to the principles and \nrules of this Regulation in accordance with Article 98. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 3 \n4. \nThis Regulation shall be without prejudice to the application of \nDirective 2000/31/EC, in particular of the liability rules of intermediary \nservice providers in Articles 12 to 15 of that Directive. \nArticle 3 \nTerritorial scope \n1. \nThis Regulation applies to the processing of personal data in the \ncontext of the activities of an establishment of a controller or a \nprocessor in the Union, regardless of whether the processing takes \nplace in the Union or not. \n2. \nThis Regulation applies to the processing of personal data of data \nsubjects who are in the Union by a controller or processor not estab­\nlished in the Union, where the processing activities are related to: \n(a) the offering of goods or services, irrespective of whether a payment \nof the data subject is required, to such data subjects in the Union; or \n(b) the monitoring of their behaviour as far as their behaviour takes \nplace within the Union. \n3. \nThis Regulation applies to the processing of personal data by a \ncontroller not established in the Union, but in a place where \nMember State law applies by virtue of public international law. \nArticle 4 \nDefinitions \nFor the purposes of this Regulation: \n(1) ‘personal data’ means any information relating to an identified or \nidentifiable natural person (‘data subject’); an identifiable natural \nperson is one who can be identified, directly or indirectly, in \nparticular by reference to an identifier such as a name, an identi­\nfication number, location data, an online identifier or to one or \nmore factors specific to the physical, physiological, genetic, \nmental, economic, cultural or social identity of that natural person; \n(2) ‘processing’ means any operation or set of operations which is \nperformed on personal data or on sets of personal data, whether \nor not by automated means, such as collection, recording, organi­\nsation, structuring, storage, adaptation or alteration, retrieval, \nconsultation, use, disclosure by transmission, dissemination or \notherwise making available, alignment or combination, restriction, \nerasure or destruction; \n(3) ‘restriction of processing’ means the marking of stored personal \ndata with the aim of limiting their processing in the future; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 4 \n(4) ‘profiling’ means any form of automated processing of personal \ndata consisting of the use of personal data to evaluate certain \npersonal aspects relating to a natural person, in particular to \nanalyse or predict aspects concerning that natural person's \nperformance at work, economic situation, health, personal prefer­\nences, interests, reliability, behaviour, location or movements; \n(5) ‘pseudonymisation’ means the processing of personal data in such \na manner that the personal data can no longer be attributed to a \nspecific data subject without the use of additional information, \nprovided that such additional information is kept separately and \nis subject to technical and organisational measures to ensure that \nthe personal data are not attributed to an identified or identifiable \nnatural person; \n(6) ‘filing system’ means any structured set of personal data which are \naccessible according to specific criteria, whether centralised, \ndecentralised or dispersed on a functional or geographical basis; \n(7) ‘controller’ means the natural or legal person, public authority, \nagency or other body which, alone or jointly with others, \ndetermines the purposes and means of the processing of personal \ndata; where the purposes and means of such processing are \ndetermined by Union or Member State law, the controller or the \nspecific criteria for its nomination may be provided for by Union \nor Member State law; \n(8) ‘processor’ means a natural or legal person, public authority, \nagency or other body which processes personal data on behalf of \nthe controller; \n(9) ‘recipient’ means a natural or legal person, public authority, \nagency or another body, to which the personal data are disclosed, \nwhether a third party or not. However, public authorities which \nmay receive personal data in the framework of a particular inquiry \nin accordance with Union or Member State law shall not be \nregarded as recipients; the processing of those data by those \npublic authorities shall be in compliance with the applicable data \nprotection rules according to the purposes of the processing; \n(10) ‘third party’ means a natural or legal person, public authority, \nagency or body other than the data subject, controller, processor \nand persons who, under the direct authority of the controller or \nprocessor, are authorised to process personal data; \n(11) ‘consent’ of the data subject means any freely given, specific, \ninformed and unambiguous indication of the data subject's \nwishes by which he or she, by a statement or by a clear affirmative \naction, signifies agreement to the processing of personal data \nrelating to him or her; \n(12) ‘personal data breach’ means a breach of security leading to the \naccidental or unlawful destruction, loss, alteration, unauthorised \ndisclosure of, or access to, personal data transmitted, stored or \notherwise processed; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 5 \n(13) ‘genetic data’ means personal data relating to the inherited or \nacquired genetic characteristics of a natural person which give \nunique information about the physiology or the health of that \nnatural person and which result, in particular, from an analysis \nof a biological sample from the natural person in question; \n(14) ‘biometric data’ means personal data resulting from specific \ntechnical processing relating to the physical, physiological or \nbehavioural characteristics of a natural person, which allow or \nconfirm the unique identification of that natural person, such as \nfacial images or dactyloscopic data; \n(15) ‘data concerning health’ means personal data related to the \nphysical or mental health of a natural person, including the \nprovision of health care services, which reveal information about \nhis or her health status; \n(16) ‘main establishment’ means: \n(a) as regards a controller with establishments in more than one \nMember State, the place of its central administration in the \nUnion, unless the decisions on the purposes and means of \nthe processing of personal data are taken in another estab­\nlishment of the controller in the Union and the latter estab­\nlishment has the power to have such decisions implemented, in \nwhich case the establishment having taken such decisions is to \nbe considered to be the main establishment; \n(b) as regards a processor with establishments in more than one \nMember State, the place of its central administration in the \nUnion, or, if the processor has no central administration in \nthe Union, the establishment of the processor in the Union \nwhere the main processing activities in the context of the \nactivities of an establishment of the processor take place to \nthe extent that the processor is subject to specific obligations \nunder this Regulation; \n(17) ‘representative’ means a natural or legal person established in the \nUnion who, designated by the controller or processor in writing \npursuant to Article 27, represents the controller or processor with \nregard to their respective obligations under this Regulation; \n(18) ‘enterprise’ means a natural or legal person engaged in an \neconomic activity, irrespective of its legal form, including part­\nnerships or associations regularly engaged in an economic activity; \n(19) ‘group of undertakings’ means a controlling undertaking and its \ncontrolled undertakings; \n(20) ‘binding corporate rules’ means personal data protection policies \nwhich are adhered to by a controller or processor established on \nthe territory of a Member State for transfers or a set of transfers of \npersonal data to a controller or processor in one or more third \ncountries within a group of undertakings, or group of enterprises \nengaged in a joint economic activity; \n(21) ‘supervisory authority’ means an independent public authority \nwhich is established by a Member State pursuant to Article 51; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 6 \n(22) ‘supervisory authority concerned’ means a supervisory authority \nwhich is concerned by the processing of personal data because: \n(a) the controller or processor is established on the territory of the \nMember State of that supervisory authority; \n(b) data subjects residing in the Member State of that supervisory \nauthority are substantially affected or likely to be substantially \naffected by the processing; or \n(c) a complaint has been lodged with that supervisory authority; \n(23) ‘cross-border processing’ means either: \n(a) processing of personal data which takes place in the context of \nthe activities of establishments in more than one Member State \nof a controller or processor in the Union where the controller \nor processor is established in more than one Member State; or \n(b) processing of personal data which takes place in the context of \nthe activities of a single establishment of a controller or \nprocessor in the Union but which substantially affects or is \nlikely to substantially affect data subjects in more than one \nMember State. \n(24) ‘relevant and reasoned objection’ means an objection to a draft \ndecision as to whether there is an infringement of this Regulation, \nor whether envisaged action in relation to the controller or \nprocessor complies with this Regulation, which clearly demon­\nstrates the significance of the risks posed by the draft decision \nas regards the fundamental rights and freedoms of data subjects \nand, where applicable, the free flow of personal data within the \nUnion; \n(25) ‘information society service’ means a service as defined in \npoint (b) of Article 1(1) of Directive (EU) 2015/1535 of the \nEuropean Parliament and of the Council ( \n1 \n); \n(26) ‘international organisation’ means an organisation and its \nsubordinate bodies governed by public international law, or any \nother body which is set up by, or on the basis of, an agreement \nbetween two or more countries. \nCHAPTER II \nPrinciples \nArticle 5 \nPrinciples relating to processing of personal data \n1. \nPersonal data shall be: \n(a) processed lawfully, fairly and in a transparent manner in relation to \nthe data subject (‘lawfulness, fairness and transparency’); \n▼B \n( \n1 \n) Directive (EU) 2015/1535 of the European Parliament and of the Council of \n9 September 2015 laying down a procedure for the provision of information \nin the field of technical regulations and of rules on Information Society \nservices (OJ L 241, 17.9.2015, p. 1).\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 7 \n(b) collected for specified, explicit and legitimate purposes and not \nfurther processed in a manner that is incompatible with those \npurposes; further processing for archiving purposes in the public \ninterest, scientific or historical research purposes or statistical \npurposes shall, in accordance with Article 89(1), not be considered \nto be incompatible with the initial purposes (‘purpose limitation’); \n(c) adequate, relevant and limited to what is necessary in relation to the \npurposes for which they are processed (‘data minimisation’); \n(d) accurate and, where necessary, kept up to date; every reasonable \nstep must be taken to ensure that personal data that are inaccurate, \nhaving regard to the purposes for which they are processed, are \nerased or rectified without delay (‘accuracy’); \n(e) kept in a form which permits identification of data subjects for no \nlonger than is necessary for the purposes for which the personal \ndata are processed; personal data may be stored for longer periods \ninsofar as the personal data will be processed solely for archiving \npurposes in the public interest, scientific or historical research \npurposes or statistical purposes in accordance with Article 89(1) \nsubject to implementation of the appropriate technical and organi­\nsational measures required by this Regulation in order to safeguard \nthe rights and freedoms of the data subject (‘storage limitation’); \n(f) processed in a manner that ensures appropriate security of the \npersonal data, including protection against unauthorised or \nunlawful processing and against accidental loss, destruction or \ndamage, using appropriate technical or organisational measures \n(‘integrity and confidentiality’). \n2. \nThe controller shall be responsible for, and be able to demonstrate \ncompliance with, paragraph 1 (‘accountability’). \nArticle 6 \nLawfulness of processing \n1. \nProcessing shall be lawful only if and to the extent that at least \none of the following applies: \n(a) the data subject has given consent to the processing of his or her \npersonal data for one or more specific purposes; \n(b) processing is necessary for the performance of a contract to which \nthe data subject is party or in order to take steps at the request of \nthe data subject prior to entering into a contract; \n(c) processing is necessary for compliance with a legal obligation to \nwhich the controller is subject; \n(d) processing is necessary in order to protect the vital interests of the \ndata subject or of another natural person; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 8 \n(e) processing is necessary for the performance of a task carried out in \nthe public interest or in the exercise of official authority vested in \nthe controller; \n(f) processing is necessary for the purposes of the legitimate interests \npursued by the controller or by a third party, except where such \ninterests are overridden by the interests or fundamental rights and \nfreedoms of the data subject which require protection of personal \ndata, in particular where the data subject is a child. \nPoint (f) of the first subparagraph shall not apply to processing carried \nout by public authorities in the performance of their tasks. \n2. \nMember States may maintain or introduce more specific provisions \nto adapt the application of the rules of this Regulation with regard to \nprocessing for compliance with points (c) and (e) of paragraph 1 by \ndetermining more precisely specific requirements for the processing and \nother measures to ensure lawful and fair processing including for other \nspecific processing situations as provided for in Chapter IX. \n3. \nThe basis for the processing referred to in point (c) and (e) of \nparagraph 1 shall be laid down by: \n(a) Union law; or \n(b) Member State law to which the controller is subject. \nThe purpose of the processing shall be determined in that legal basis or, \nas regards the processing referred to in point (e) of paragraph 1, shall be \nnecessary for the performance of a task carried out in the public interest \nor in the exercise of official authority vested in the controller. That legal \nbasis may contain specific provisions to adapt the application of rules of \nthis Regulation, inter alia: the general conditions governing the \nlawfulness of processing by the controller; the types of data which \nare subject to the processing; the data subjects concerned; the entities \nto, and the purposes for which, the personal data may be disclosed; the \npurpose limitation; storage periods; and processing operations and \nprocessing procedures, including measures to ensure lawful and fair \nprocessing such as those for other specific processing situations as \nprovided for in Chapter IX. The Union or the Member State law \nshall meet an objective of public interest and be proportionate to the \nlegitimate aim pursued. \n4. \nWhere the processing for a purpose other than that for which the \npersonal data have been collected is not based on the data subject's \nconsent or on a Union or Member State law which constitutes a \nnecessary and proportionate measure in a democratic society to \nsafeguard the objectives referred to in Article 23(1), the controller \nshall, in order to ascertain whether processing for another purpose is \ncompatible with the purpose for which the personal data are initially \ncollected, take into account, inter alia: \n(a) any link between the purposes for which the personal data have \nbeen collected and the purposes of the intended further processing; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 9 \n(b) the context in which the personal data have been collected, in \nparticular regarding the relationship between data subjects and the \ncontroller; \n(c) the nature of the personal data, in particular whether special \ncategories of personal data are processed, pursuant to Article 9, or \nwhether personal data related to criminal convictions and offences \nare processed, pursuant to Article 10; \n(d) the possible consequences of the intended further processing for \ndata subjects; \n(e) the existence of appropriate safeguards, which may include \nencryption or pseudonymisation. \nArticle 7 \nConditions for consent \n1. \nWhere processing is based on consent, the controller shall be able \nto demonstrate that the data subject has consented to processing of his \nor her personal data. \n2. \nIf the data subject's consent is given in the context of a written \ndeclaration which also concerns other matters, the request for consent \nshall be presented in a manner which is clearly distinguishable from the \nother matters, in an intelligible and easily accessible form, using clear \nand plain language. Any part of such a declaration which constitutes an \ninfringement of this Regulation shall not be binding. \n3. \nThe data subject shall have the right to withdraw his or her \nconsent at any time. The withdrawal of consent shall not affect the \nlawfulness of processing based on consent before its withdrawal. Prior \nto giving consent, the data subject shall be informed thereof. It shall be \nas easy to withdraw as to give consent. \n4. \nWhen assessing whether consent is freely given, utmost account \nshall be taken of whether, inter alia, the performance of a contract, \nincluding the provision of a service, is conditional on consent to the \nprocessing of personal data that is not necessary for the performance of \nthat contract. \nArticle 8 \nConditions applicable to child's consent in relation to information \nsociety services \n1. \nWhere point (a) of Article 6(1) applies, in relation to the offer of \ninformation society services directly to a child, the processing of the \npersonal data of a child shall be lawful where the child is at least 16 \nyears old. Where the child is below the age of 16 years, such processing \nshall be lawful only if and to the extent that consent is given or auth­\norised by the holder of parental responsibility over the child. \nMember States may provide by law for a lower age for those purposes \nprovided that such lower age is not below 13 years. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 10 \n2. \nThe controller shall make reasonable efforts to verify in such cases \nthat consent is given or authorised by the holder of parental responsi­\nbility over the child, taking into consideration available technology. \n3. \nParagraph 1 shall not affect the general contract law of Member \nStates such as the rules on the validity, formation or effect of a contract \nin relation to a child. \nArticle 9 \nProcessing of special categories of personal data \n1. \nProcessing of personal data revealing racial or ethnic origin, \npolitical opinions, religious or philosophical beliefs, or trade union \nmembership, and the processing of genetic data, biometric data for \nthe purpose of uniquely identifying a natural person, data concerning \nhealth or data concerning a natural person's sex life or sexual orientation \nshall be prohibited. \n2. \nParagraph 1 shall not apply if one of the following applies: \n(a) the data subject has given explicit consent to the processing of those \npersonal data for one or more specified purposes, except where \nUnion or Member State law provide that the prohibition referred \nto in paragraph 1 may not be lifted by the data subject; \n(b) processing is necessary for the purposes of carrying out the obli­\ngations and exercising specific rights of the controller or of the data \nsubject in the field of employment and social security and social \nprotection law in so far as it is authorised by Union or Member \nState law or a collective agreement pursuant to Member State law \nproviding for appropriate safeguards for the fundamental rights and \nthe interests of the data subject; \n(c) processing is necessary to protect the vital interests of the data \nsubject or of another natural person where the data subject is \nphysically or legally incapable of giving consent; \n(d) processing is carried out in the course of its legitimate activities \nwith appropriate safeguards by a foundation, association or any \nother not-for-profit body with a political, philosophical, religious \nor trade union aim and on condition that the processing relates \nsolely to the members or to former members of the body or to \npersons who have regular contact with it in connection with its \npurposes and that the personal data are not disclosed outside that \nbody without the consent of the data subjects; \n(e) processing relates to personal data which are manifestly made \npublic by the data subject; \n(f) processing is necessary for the establishment, exercise or defence of \nlegal claims or whenever courts are acting in their judicial capacity; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 11 \n(g) processing is necessary for reasons of substantial public interest, on \nthe basis of Union or Member State law which shall be propor­\ntionate to the aim pursued, respect the essence of the right to data \nprotection and provide for suitable and specific measures to \nsafeguard the fundamental rights and the interests of the data \nsubject; \n(h) processing is necessary for the purposes of preventive or occupa­\ntional medicine, for the assessment of the working capacity of the \nemployee, medical diagnosis, the provision of health or social care \nor treatment or the management of health or social care systems and \nservices on the basis of Union or Member State law or pursuant to \ncontract with a health professional and subject to the conditions and \nsafeguards referred to in paragraph 3; \n(i) processing is necessary for reasons of public interest in the area of \npublic health, such as protecting against serious cross-border threats \nto health or ensuring high standards of quality and safety of health \ncare and of medicinal products or medical devices, on the basis of \nUnion or Member State law which provides for suitable and specific \nmeasures to safeguard the rights and freedoms of the data subject, in \nparticular professional secrecy; \n(j) processing is necessary for archiving purposes in the public interest, \nscientific or historical research purposes or statistical purposes in \naccordance with Article 89(1) based on Union or Member State law \nwhich shall be proportionate to the aim pursued, respect the essence \nof the right to data protection and provide for suitable and specific \nmeasures to safeguard the fundamental rights and the interests of the \ndata subject. \n3. \nPersonal data referred to in paragraph 1 may be processed for the \npurposes referred to in point (h) of paragraph 2 when those data are \nprocessed by or under the responsibility of a professional subject to the \nobligation of professional secrecy under Union or Member State law or \nrules established by national competent bodies or by another person also \nsubject to an obligation of secrecy under Union or Member State law or \nrules established by national competent bodies. \n4. \nMember States may maintain or introduce further conditions, \nincluding limitations, with regard to the processing of genetic data, \nbiometric data or data concerning health. \nArticle 10 \nProcessing of personal data relating to criminal convictions and \noffences \nProcessing of personal data relating to criminal convictions and offences \nor related security measures based on Article 6(1) shall be carried out \nonly under the control of official authority or when the processing is \nauthorised by Union or Member State law providing for appropriate \nsafeguards for the rights and freedoms of data subjects. Any compre­\nhensive register of criminal convictions shall be kept only under the \ncontrol of official authority. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 12 \nArticle 11 \nProcessing which does not require identification \n1. \nIf the purposes for which a controller processes personal data do \nnot or do no longer require the identification of a data subject by the \ncontroller, the controller shall not be obliged to maintain, acquire or \nprocess additional information in order to identify the data subject for \nthe sole purpose of complying with this Regulation. \n2. \nWhere, in cases referred to in paragraph 1 of this Article, the \ncontroller is able to demonstrate that it is not in a position to identify \nthe data subject, the controller shall inform the data subject accordingly, \nif possible. In such cases, Articles 15 to 20 shall not apply except where \nthe data subject, for the purpose of exercising his or her rights under \nthose articles, provides additional information enabling his or her \nidentification. \nCHAPTER III \nRights of the data subject \nS e c t i o n 1 \nT r a n s p a r e n c y a n d m o d a l i t i e s \nArticle 12 \nTransparent information, communication and modalities for the \nexercise of the rights of the data subject \n1. \nThe controller shall take appropriate measures to provide any \ninformation referred to in Articles 13 and 14 and any communication \nunder Articles 15 to 22 and 34 relating to processing to the data subject \nin a concise, transparent, intelligible and easily accessible form, using \nclear and plain language, in particular for any information addressed \nspecifically to a child. The information shall be provided in writing, or \nby other means, including, where appropriate, by electronic means. \nWhen requested by the data subject, the information may be provided \norally, provided that the identity of the data subject is proven by other \nmeans. \n2. \nThe controller shall facilitate the exercise of data subject rights \nunder Articles 15 to 22. In the cases referred to in Article 11(2), the \ncontroller shall not refuse to act on the request of the data subject for \nexercising his or her rights under Articles 15 to 22, unless the controller \ndemonstrates that it is not in a position to identify the data subject. \n3. \nThe controller shall provide information on action taken on a \nrequest under Articles 15 to 22 to the data subject without undue \ndelay and in any event within one month of receipt of the request. \nThat period may be extended by two further months where necessary, \ntaking into account the complexity and number of the requests. The \ncontroller shall inform the data subject of any such extension within \none month of receipt of the request, together with the reasons for the \ndelay. Where the data subject makes the request by electronic form \nmeans, the information shall be provided by electronic means where \npossible, unless otherwise requested by the data subject. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 13 \n4. \nIf the controller does not take action on the request of the data \nsubject, the controller shall inform the data subject without delay and at \nthe latest within one month of receipt of the request of the reasons for \nnot taking action and on the possibility of lodging a complaint with a \nsupervisory authority and seeking a judicial remedy. \n5. \nInformation provided under Articles 13 and 14 and any communi­\ncation and any actions taken under Articles 15 to 22 and 34 shall be \nprovided free of charge. Where requests from a data subject are mani­\nfestly unfounded or excessive, in particular because of their repetitive \ncharacter, the controller may either: \n(a) charge a reasonable fee taking into account the administrative costs \nof providing the information or communication or taking the action \nrequested; or \n(b) refuse to act on the request. \nThe controller shall bear the burden of demonstrating the manifestly \nunfounded or excessive character of the request. \n6. \nWithout prejudice to Article 11, where the controller has \nreasonable doubts concerning the identity of the natural person \nmaking the request referred to in Articles 15 to 21, the controller \nmay request the provision of additional information necessary to \nconfirm the identity of the data subject. \n7. \nThe information to be provided to data subjects pursuant to \nArticles 13 and 14 may be provided in combination with standardised \nicons in order to give in an easily visible, intelligible and clearly legible \nmanner a meaningful overview of the intended processing. Where the \nicons are presented electronically they shall be machine-readable. \n8. \nThe Commission shall be empowered to adopt delegated acts in \naccordance with Article 92 for the purpose of determining the \ninformation to be presented by the icons and the procedures for \nproviding standardised icons. \nS e c t i o n 2 \nI n f o r m a t i o n a n d a c c e s s t o p e r s o n a l d a t a \nArticle 13 \nInformation to be provided where personal data are collected from \nthe data subject \n1. \nWhere personal data relating to a data subject are collected from \nthe data subject, the controller shall, at the time when personal data are \nobtained, provide the data subject with all of the following information: \n(a) the identity and the contact details of the controller and, where \napplicable, of the controller's representative; \n(b) the contact details of the data protection officer, where applicable; \n(c) the purposes of the processing for which the personal data are \nintended as well as the legal basis for the processing; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 14 \n(d) where the processing is based on point (f) of Article 6(1), the \nlegitimate interests pursued by the controller or by a third party; \n(e) the recipients or categories of recipients of the personal data, if any; \n(f) where applicable, the fact that the controller intends to transfer \npersonal data to a third country or international organisation and \nthe existence or absence of an adequacy decision by the \nCommission, or in the case of transfers referred to in Article 46 \nor 47, or the second subparagraph of Article 49(1), reference to the \nappropriate or suitable safeguards and the means by which to obtain \na copy of them or where they have been made available. \n2. \nIn addition to the information referred to in paragraph 1, the \ncontroller shall, at the time when personal data are obtained, provide \nthe data subject with the following further information necessary to \nensure fair and transparent processing: \n(a) the period for which the personal data will be stored, or if that is not \npossible, the criteria used to determine that period; \n(b) the existence of the right to request from the controller access to \nand rectification or erasure of personal data or restriction of \nprocessing concerning the data subject or to object to processing \nas well as the right to data portability; \n(c) where the processing is based on point (a) of Article 6(1) or \npoint (a) of Article 9(2), the existence of the right to withdraw \nconsent at any time, without affecting the lawfulness of processing \nbased on consent before its withdrawal; \n(d) the right to lodge a complaint with a supervisory authority; \n(e) whether the provision of personal data is a statutory or contractual \nrequirement, or a requirement necessary to enter into a contract, as \nwell as whether the data subject is obliged to provide the personal \ndata and of the possible consequences of failure to provide such \ndata; \n(f) the existence of automated decision-making, including profiling, \nreferred to in Article 22(1) and (4) and, at least in those cases, \nmeaningful information about the logic involved, as well as the \nsignificance and the envisaged consequences of such processing \nfor the data subject. \n3. \nWhere the controller intends to further process the personal data \nfor a purpose other than that for which the personal data were collected, \nthe controller shall provide the data subject prior to that further \nprocessing with information on that other purpose and with any \nrelevant further information as referred to in paragraph 2. \n4. \nParagraphs 1, 2 and 3 shall not apply where and insofar as the \ndata subject already has the information. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 15 \nArticle 14 \nInformation to be provided where personal data have not been \nobtained from the data subject \n1. \nWhere personal data have not been obtained from the data subject, \nthe controller shall provide the data subject with the following \ninformation: \n(a) the identity and the contact details of the controller and, where \napplicable, of the controller's representative; \n(b) the contact details of the data protection officer, where applicable; \n(c) the purposes of the processing for which the personal data are \nintended as well as the legal basis for the processing; \n(d) the categories of personal data concerned; \n(e) the recipients or categories of recipients of the personal data, if any; \n(f) where applicable, that the controller intends to transfer personal data \nto a recipient in a third country or international organisation and the \nexistence or absence of an adequacy decision by the Commission, \nor in the case of transfers referred to in Article 46 or 47, or the \nsecond subparagraph of Article 49(1), reference to the appropriate \nor suitable safeguards and the means to obtain a copy of them or \nwhere they have been made available. \n2. \nIn addition to the information referred to in paragraph 1, the \ncontroller shall provide the data subject with the following information \nnecessary to ensure fair and transparent processing in respect of the data \nsubject: \n(a) the period for which the personal data will be stored, or if that is not \npossible, the criteria used to determine that period; \n(b) where the processing is based on point (f) of Article 6(1), the \nlegitimate interests pursued by the controller or by a third party; \n(c) the existence of the right to request from the controller access to \nand rectification or erasure of personal data or restriction of \nprocessing concerning the data subject and to object to processing \nas well as the right to data portability; \n(d) where processing is based on point (a) of Article 6(1) or point (a) of \nArticle 9(2), the existence of the right to withdraw consent at any \ntime, without affecting the lawfulness of processing based on \nconsent before its withdrawal; \n(e) the right to lodge a complaint with a supervisory authority; \n(f) from which source the personal data originate, and if applicable, \nwhether it came from publicly accessible sources; \n(g) the existence of automated decision-making, including profiling, \nreferred to in Article 22(1) and (4) and, at least in those cases, \nmeaningful information about the logic involved, as well as the \nsignificance and the envisaged consequences of such processing \nfor the data subject. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 16 \n3. \nThe controller shall provide the information referred to in para­\ngraphs 1 and 2: \n(a) within a reasonable period after obtaining the personal data, but at \nthe latest within one month, having regard to the specific circum­\nstances in which the personal data are processed; \n(b) if the personal data are to be used for communication with the data \nsubject, at the latest at the time of the first communication to that \ndata subject; or \n(c) if a disclosure to another recipient is envisaged, at the latest when \nthe personal data are first disclosed. \n4. \nWhere the controller intends to further process the personal data \nfor a purpose other than that for which the personal data were obtained, \nthe controller shall provide the data subject prior to that further \nprocessing with information on that other purpose and with any \nrelevant further information as referred to in paragraph 2. \n5. \nParagraphs 1 to 4 shall not apply where and insofar as: \n(a) the data subject already has the information; \n(b) the provision of such information proves impossible or would \ninvolve a disproportionate effort, in particular for processing for \narchiving purposes in the public interest, scientific or historical \nresearch purposes or statistical purposes, subject to the conditions \nand safeguards referred to in Article 89(1) or in so far as the \nobligation referred to in paragraph 1 of this Article is likely to \nrender impossible or seriously impair the achievement of the \nobjectives of that processing. In such cases the controller shall \ntake appropriate measures to protect the data subject's rights and \nfreedoms and legitimate interests, including making the information \npublicly available; \n(c) obtaining or disclosure is expressly laid down by Union or \nMember State law to which the controller is subject and which \nprovides appropriate measures to protect the data subject's legitimate \ninterests; or \n(d) where the personal data must remain confidential subject to an \nobligation of professional secrecy regulated by Union or \nMember State law, including a statutory obligation of secrecy. \nArticle 15 \nRight of access by the data subject \n1. \nThe data subject shall have the right to obtain from the controller \nconfirmation as to whether or not personal data concerning him or her \nare being processed, and, where that is the case, access to the personal \ndata and the following information: \n(a) the purposes of the processing; \n(b) the categories of personal data concerned; \n(c) the recipients or categories of recipient to whom the personal data \nhave been or will be disclosed, in particular recipients in third \ncountries or international organisations; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 17 \n(d) where possible, the envisaged period for which the personal data \nwill be stored, or, if not possible, the criteria used to determine that \nperiod; \n(e) the existence of the right to request from the controller rectification \nor erasure of personal data or restriction of processing of personal \ndata concerning the data subject or to object to such processing; \n(f) the right to lodge a complaint with a supervisory authority; \n(g) where the personal data are not collected from the data subject, any \navailable information as to their source; \n(h) the existence of automated decision-making, including profiling, \nreferred to in Article 22(1) and (4) and, at least in those cases, \nmeaningful information about the logic involved, as well as the \nsignificance and the envisaged consequences of such processing \nfor the data subject. \n2. \nWhere personal data are transferred to a third country or to an \ninternational organisation, the data subject shall have the right to be \ninformed of the appropriate safeguards pursuant to Article 46 relating \nto the transfer. \n3. \nThe controller shall provide a copy of the personal data \nundergoing processing. For any further copies requested by the data \nsubject, the controller may charge a reasonable fee based on adminis­\ntrative costs. Where the data subject makes the request by electronic \nmeans, and unless otherwise requested by the data subject, the \ninformation shall be provided in a commonly used electronic form. \n4. \nThe right to obtain a copy referred to in paragraph 3 shall not \nadversely affect the rights and freedoms of others. \nS e c t i o n 3 \nR e c t i f i c a t i o n a n d e r a s u r e \nArticle 16 \nRight to rectification \nThe data subject shall have the right to obtain from the controller \nwithout undue delay the rectification of inaccurate personal data \nconcerning him or her. Taking into account the purposes of the \nprocessing, the data subject shall have the right to have incomplete \npersonal data completed, including by means of providing a supple­\nmentary statement. \nArticle 17 \nRight to erasure (‘right to be forgotten’) \n1. \nThe data subject shall have the right to obtain from the controller \nthe erasure of personal data concerning him or her without undue delay \nand the controller shall have the obligation to erase personal data \nwithout undue delay where one of the following grounds applies: \n(a) the personal data are no longer necessary in relation to the purposes \nfor which they were collected or otherwise processed; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 18 \n(b) the data subject withdraws consent on which the processing is based \naccording to point (a) of Article 6(1), or point (a) of Article 9(2), \nand where there is no other legal ground for the processing; \n(c) the data subject objects to the processing pursuant to Article 21(1) \nand there are no overriding legitimate grounds for the processing, or \nthe data subject objects to the processing pursuant to Article 21(2); \n(d) the personal data have been unlawfully processed; \n(e) the personal data have to be erased for compliance with a legal \nobligation in Union or Member State law to which the controller \nis subject; \n(f) the personal data have been collected in relation to the offer of \ninformation society services referred to in Article 8(1). \n2. \nWhere the controller has made the personal data public and is \nobliged pursuant to paragraph 1 to erase the personal data, the \ncontroller, taking account of available technology and the cost of imple­\nmentation, shall take reasonable steps, including technical measures, to \ninform controllers which are processing the personal data that the data \nsubject has requested the erasure by such controllers of any links to, or \ncopy or replication of, those personal data. \n3. \nParagraphs 1 and 2 shall not apply to the extent that processing is \nnecessary: \n(a) for exercising the right of freedom of expression and information; \n(b) for compliance with a legal obligation which requires processing by \nUnion or Member State law to which the controller is subject or for \nthe performance of a task carried out in the public interest or in the \nexercise of official authority vested in the controller; \n(c) for reasons of public interest in the area of public health in \naccordance with points (h) and (i) of Article 9(2) as well as \nArticle 9(3); \n(d) for archiving purposes in the public interest, scientific or historical \nresearch purposes or statistical purposes in accordance with \nArticle 89(1) in so far as the right referred to in paragraph 1 is \nlikely to render impossible or seriously impair the achievement of \nthe objectives of that processing; or \n(e) for the establishment, exercise or defence of legal claims. \nArticle 18 \nRight to restriction of processing \n1. \nThe data subject shall have the right to obtain from the controller \nrestriction of processing where one of the following applies: \n(a) the accuracy of the personal data is contested by the data subject, \nfor a period enabling the controller to verify the accuracy of the \npersonal data; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 19 \n(b) the processing is unlawful and the data subject opposes the erasure \nof the personal data and requests the restriction of their use instead; \n(c) the controller no longer needs the personal data for the purposes of \nthe processing, but they are required by the data subject for the \nestablishment, exercise or defence of legal claims; \n(d) the data subject has objected to processing pursuant to Article 21(1) \npending the verification whether the legitimate grounds of the \ncontroller override those of the data subject. \n2. \nWhere processing has been restricted under paragraph 1, such \npersonal data shall, with the exception of storage, only be processed \nwith the data subject's consent or for the establishment, exercise or \ndefence of legal claims or for the protection of the rights of another \nnatural or legal person or for reasons of important public interest of the \nUnion or of a Member State. \n3. \nA data subject who has obtained restriction of processing pursuant \nto paragraph 1 shall be informed by the controller before the restriction \nof processing is lifted. \nArticle 19 \nNotification obligation regarding rectification or erasure of personal \ndata or restriction of processing \nThe controller shall communicate any rectification or erasure of personal \ndata or restriction of processing carried out in accordance with \nArticle 16, Article 17(1) and Article 18 to each recipient to whom \nthe personal data have been disclosed, unless this proves impossible \nor involves disproportionate effort. The controller shall inform the \ndata subject about those recipients if the data subject requests it. \nArticle 20 \nRight to data portability \n1. \nThe data subject shall have the right to receive the personal data \nconcerning him or her, which he or she has provided to a controller, in \na structured, commonly used and machine-readable format and have the \nright to transmit those data to another controller without hindrance from \nthe controller to which the personal data have been provided, where: \n(a) the processing is based on consent pursuant to point (a) of \nArticle 6(1) or point (a) of Article 9(2) or on a contract pursuant \nto point (b) of Article 6(1); and \n(b) the processing is carried out by automated means. \n2. \nIn exercising his or her right to data portability pursuant to \nparagraph 1, the data subject shall have the right to have the personal \ndata transmitted directly from one controller to another, where tech­\nnically feasible. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 20 \n3. \nThe exercise of the right referred to in paragraph 1 of this Article \nshall be without prejudice to Article 17. That right shall not apply to \nprocessing necessary for the performance of a task carried out in the \npublic interest or in the exercise of official authority vested in the \ncontroller. \n4. \nThe right referred to in paragraph 1 shall not adversely affect the \nrights and freedoms of others. \nS e c t i o n 4 \nR i g h t \nt o \no b j e c t \na n d \na u t o m a t e d \ni n d i v i d u a l \nd e c i s i o n - m a k i n g \nArticle 21 \nRight to object \n1. \nThe data subject shall have the right to object, on grounds relating \nto his or her particular situation, at any time to processing of personal \ndata concerning him or her which is based on point (e) or (f) of \nArticle 6(1), including profiling based on those provisions. The \ncontroller shall no longer process the personal data unless the controller \ndemonstrates compelling legitimate grounds for the processing which \noverride the interests, rights and freedoms of the data subject or for the \nestablishment, exercise or defence of legal claims. \n2. \nWhere personal data are processed for direct marketing purposes, \nthe data subject shall have the right to object at any time to processing \nof personal data concerning him or her for such marketing, which \nincludes profiling to the extent that it is related to such direct marketing. \n3. \nWhere the data subject objects to processing for direct marketing \npurposes, the personal data shall no longer be processed for such \npurposes. \n4. \nAt the latest at the time of the first communication with the data \nsubject, the right referred to in paragraphs 1 and 2 shall be explicitly \nbrought to the attention of the data subject and shall be presented clearly \nand separately from any other information. \n5. \nIn the context of the use of information society services, and \nnotwithstanding Directive 2002/58/EC, the data subject may exercise \nhis or her right to object by automated means using technical \nspecifications. \n6. \nWhere personal data are processed for scientific or historical \nresearch purposes or statistical purposes pursuant to Article 89(1), the \ndata subject, on grounds relating to his or her particular situation, shall \nhave the right to object to processing of personal data concerning him \nor her, unless the processing is necessary for the performance of a task \ncarried out for reasons of public interest. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 21 \nArticle 22 \nAutomated individual decision-making, including profiling \n1. \nThe data subject shall have the right not to be subject to a decision \nbased solely on automated processing, including profiling, which \nproduces legal effects concerning him or her or similarly significantly \naffects him or her. \n2. \nParagraph 1 shall not apply if the decision: \n(a) is necessary for entering into, or performance of, a contract between \nthe data subject and a data controller; \n(b) is authorised by Union or Member State law to which the controller \nis subject and which also lays down suitable measures to safeguard \nthe data subject's rights and freedoms and legitimate interests; or \n(c) is based on the data subject's explicit consent. \n3. \nIn the cases referred to in points (a) and (c) of paragraph 2, the \ndata controller shall implement suitable measures to safeguard the data \nsubject's rights and freedoms and legitimate interests, at least the right to \nobtain human intervention on the part of the controller, to express his or \nher point of view and to contest the decision. \n4. \nDecisions referred to in paragraph 2 shall not be based on special \ncategories of personal data referred to in Article 9(1), unless point (a) or \n(g) of Article 9(2) applies and suitable measures to safeguard the data \nsubject's rights and freedoms and legitimate interests are in place. \nS e c t i o n 5 \nR e s t r i c t i o n s \nArticle 23 \nRestrictions \n1. \nUnion or Member State law to which the data controller or \nprocessor is subject may restrict by way of a legislative measure the \nscope of the obligations and rights provided for in Articles 12 to 22 and \nArticle 34, as well as Article 5 in so far as its provisions correspond to \nthe rights and obligations provided for in Articles 12 to 22, when such a \nrestriction respects the essence of the fundamental rights and freedoms \nand is a necessary and proportionate measure in a democratic society to \nsafeguard: \n(a) national security; \n(b) defence; \n(c) public security; \n(d) the prevention, investigation, detection or prosecution of criminal \noffences or the execution of criminal penalties, including the safe­\nguarding against and the prevention of threats to public security; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 22 \n(e) other important objectives of general public interest of the Union or \nof a Member State, in particular an important economic or financial \ninterest of the Union or of a Member State, including monetary, \nbudgetary and taxation a matters, public health and social security; \n(f) the protection of judicial independence and judicial proceedings; \n(g) the prevention, investigation, detection and prosecution of breaches \nof ethics for regulated professions; \n(h) a monitoring, inspection or regulatory function connected, even \noccasionally, to the exercise of official authority in the cases \nreferred to in points (a) to (e) and (g); \n(i) the protection of the data subject or the rights and freedoms of \nothers; \n(j) the enforcement of civil law claims. \n2. \nIn particular, any legislative measure referred to in paragraph 1 \nshall contain specific provisions at least, where relevant, as to: \n(a) the purposes of the processing or categories of processing; \n(b) the categories of personal data; \n(c) the scope of the restrictions introduced; \n(d) the safeguards to prevent abuse or unlawful access or transfer; \n(e) the specification of the controller or categories of controllers; \n(f) the storage periods and the applicable safeguards taking into \naccount the nature, scope and purposes of the processing or \ncategories of processing; \n(g) the risks to the rights and freedoms of data subjects; and \n(h) the right of data subjects to be informed about the restriction, unless \nthat may be prejudicial to the purpose of the restriction. \nCHAPTER IV \nController and processor \nS e c t i o n 1 \nG e n e r a l o b l i g a t i o n s \nArticle 24 \nResponsibility of the controller \n1. \nTaking into account the nature, scope, context and purposes of \nprocessing as well as the risks of varying likelihood and severity for the \nrights and freedoms of natural persons, the controller shall implement \nappropriate technical and organisational measures to ensure and to be \nable to demonstrate that processing is performed in accordance with this \nRegulation. Those measures shall be reviewed and updated where \nnecessary. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 23 \n2. \nWhere proportionate in relation to processing activities, the \nmeasures referred to in paragraph 1 shall include the implementation \nof appropriate data protection policies by the controller. \n3. \nAdherence to approved codes of conduct as referred to in \nArticle 40 or approved certification mechanisms as referred to in \nArticle 42 may be used as an element by which to demonstrate \ncompliance with the obligations of the controller. \nArticle 25 \nData protection by design and by default \n1. \nTaking into account the state of the art, the cost of implementation \nand the nature, scope, context and purposes of processing as well as the \nrisks of varying likelihood and severity for rights and freedoms of \nnatural persons posed by the processing, the controller shall, both at \nthe time of the determination of the means for processing and at the \ntime of the processing itself, implement appropriate technical and \norganisational measures, such as pseudonymisation, which are \ndesigned to implement data-protection principles, such as data minimis­\nation, in an effective manner and to integrate the necessary safeguards \ninto the processing in order to meet the requirements of this Regulation \nand protect the rights of data subjects. \n2. \nThe controller shall implement appropriate technical and organisa­\ntional measures for ensuring that, by default, only personal data which \nare necessary for each specific purpose of the processing are processed. \nThat obligation applies to the amount of personal data collected, the \nextent of their processing, the period of their storage and their accessi­\nbility. In particular, such measures shall ensure that by default personal \ndata are not made accessible without the individual's intervention to an \nindefinite number of natural persons. \n3. \nAn approved certification mechanism pursuant to Article 42 may \nbe used as an element to demonstrate compliance with the requirements \nset out in paragraphs 1 and 2 of this Article. \nArticle 26 \nJoint controllers \n1. \nWhere two or more controllers jointly determine the purposes and \nmeans of processing, they shall be joint controllers. They shall in a \ntransparent manner determine their respective responsibilities for \ncompliance with the obligations under this Regulation, in particular as \nregards the exercising of the rights of the data subject and their \nrespective duties to provide the information referred to in Articles 13 \nand 14, by means of an arrangement between them unless, and in so far \nas, the respective responsibilities of the controllers are determined by \nUnion or Member State law to which the controllers are subject. The \narrangement may designate a contact point for data subjects. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 24 \n2. \nThe arrangement referred to in paragraph 1 shall duly reflect the \nrespective roles and relationships of the joint controllers vis-à-vis the \ndata subjects. The essence of the arrangement shall be made available to \nthe data subject. \n3. \nIrrespective of the terms of the arrangement referred to in \nparagraph 1, the data subject may exercise his or her rights under this \nRegulation in respect of and against each of the controllers. \nArticle 27 \nRepresentatives of controllers or processors not established in the \nUnion \n1. \nWhere Article 3(2) applies, the controller or the processor shall \ndesignate in writing a representative in the Union. \n2. \nThe obligation laid down in paragraph 1 of this Article shall not \napply to: \n(a) processing which is occasional, does not include, on a large scale, \nprocessing of special categories of data as referred to in Article 9(1) \nor processing of personal data relating to criminal convictions and \noffences referred to in Article 10, and is unlikely to result in a risk \nto the rights and freedoms of natural persons, taking into account \nthe nature, context, scope and purposes of the processing; or \n(b) a public authority or body. \n3. \nThe representative shall be established in one of the Member \nStates where the data subjects, whose personal data are processed in \nrelation to the offering of goods or services to them, or whose behaviour \nis monitored, are. \n4. \nThe representative shall be mandated by the controller or \nprocessor to be addressed in addition to or instead of the controller or \nthe processor by, in particular, supervisory authorities and data subjects, \non all issues related to processing, for the purposes of ensuring \ncompliance with this Regulation. \n5. \nThe designation of a representative by the controller or processor \nshall be without prejudice to legal actions which could be initiated \nagainst the controller or the processor themselves. \nArticle 28 \nProcessor \n1. \nWhere processing is to be carried out on behalf of a controller, the \ncontroller shall use only processors providing sufficient guarantees to \nimplement appropriate technical and organisational measures in such a \nmanner that processing will meet the requirements of this Regulation \nand ensure the protection of the rights of the data subject. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 25 \n2. \nThe processor shall not engage another processor without prior \nspecific or general written authorisation of the controller. In the case \nof general written authorisation, the processor shall inform the controller \nof any intended changes concerning the addition or replacement of other \nprocessors, thereby giving the controller the opportunity to object to \nsuch changes. \n3. \nProcessing by a processor shall be governed by a contract or other \nlegal act under Union or Member State law, that is binding on the \nprocessor with regard to the controller and that sets out the \nsubject-matter and duration of the processing, the nature and purpose \nof the processing, the type of personal data and categories of data \nsubjects and the obligations and rights of the controller. That contract \nor other legal act shall stipulate, in particular, that the processor: \n(a) processes the personal data only on documented instructions from \nthe controller, including with regard to transfers of personal data to \na third country or an international organisation, unless required to \ndo so by Union or Member State law to which the processor is \nsubject; in such a case, the processor shall inform the controller of \nthat legal requirement before processing, unless that law prohibits \nsuch information on important grounds of public interest; \n(b) ensures that persons authorised to process the personal data have \ncommitted themselves to confidentiality or are under an appropriate \nstatutory obligation of confidentiality; \n(c) takes all measures required pursuant to Article 32; \n(d) respects the conditions referred to in paragraphs 2 and 4 for \nengaging another processor; \n(e) taking into account the nature of the processing, assists the \ncontroller by appropriate technical and organisational measures, \ninsofar as this is possible, for the fulfilment of the controller's \nobligation to respond to requests for exercising the data subject's \nrights laid down in Chapter III; \n(f) assists the controller in ensuring compliance with the obligations \npursuant to Articles 32 to 36 taking into account the nature of \nprocessing and the information available to the processor; \n(g) at the choice of the controller, deletes or returns all the personal \ndata to the controller after the end of the provision of services \nrelating to processing, and deletes existing copies unless Union or \nMember State law requires storage of the personal data; \n(h) makes available to the controller all information necessary to \ndemonstrate compliance with the obligations laid down in this \nArticle and allow for and contribute to audits, including inspections, \nconducted by the controller or another auditor mandated by the \ncontroller. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 26 \nWith regard to point (h) of the first subparagraph, the processor shall \nimmediately inform the controller if, in its opinion, an instruction \ninfringes this Regulation or other Union or Member State data \nprotection provisions. \n4. \nWhere a processor engages another processor for carrying out \nspecific processing activities on behalf of the controller, the same data \nprotection obligations as set out in the contract or other legal act \nbetween the controller and the processor as referred to in paragraph 3 \nshall be imposed on that other processor by way of a contract or other \nlegal act under Union or Member State law, in particular providing \nsufficient guarantees to implement appropriate technical and organisa­\ntional measures in such a manner that the processing will meet the \nrequirements of this Regulation. Where that other processor fails to \nfulfil its data protection obligations, the initial processor shall remain \nfully liable to the controller for the performance of that other processor's \nobligations. \n5. \nAdherence of a processor to an approved code of conduct as \nreferred to in Article 40 or an approved certification mechanism as \nreferred to in Article 42 may be used as an element by which to \ndemonstrate sufficient guarantees as referred to in paragraphs 1 and 4 \nof this Article. \n6. \nWithout prejudice to an individual contract between the controller \nand the processor, the contract or the other legal act referred to in \nparagraphs 3 and 4 of this Article may be based, in whole or in part, \non standard contractual clauses referred to in paragraphs 7 and 8 of this \nArticle, including when they are part of a certification granted to the \ncontroller or processor pursuant to Articles 42 and 43. \n7. \nThe Commission may lay down standard contractual clauses for \nthe matters referred to in paragraph 3 and 4 of this Article and in \naccordance with the examination procedure referred to in Article 93(2). \n8. \nA supervisory authority may adopt standard contractual clauses for \nthe matters referred to in paragraph 3 and 4 of this Article and in \naccordance with the consistency mechanism referred to in Article 63. \n9. \nThe contract or the other legal act referred to in paragraphs 3 and \n4 shall be in writing, including in electronic form. \n10. \nWithout prejudice to Articles 82, 83 and 84, if a processor \ninfringes this Regulation by determining the purposes and means of \nprocessing, the processor shall be considered to be a controller in \nrespect of that processing. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 27 \nArticle 29 \nProcessing under the authority of the controller or processor \nThe processor and any person acting under the authority of the \ncontroller or of the processor, who has access to personal data, shall \nnot process those data except on instructions from the controller, unless \nrequired to do so by Union or Member State law. \nArticle 30 \nRecords of processing activities \n1. \nEach controller and, where applicable, the controller's represen­\ntative, shall maintain a record of processing activities under its respon­\nsibility. That record shall contain all of the following information: \n(a) the name and contact details of the controller and, where applicable, \nthe joint controller, the controller's representative and the data \nprotection officer; \n(b) the purposes of the processing; \n(c) a description of the categories of data subjects and of the categories \nof personal data; \n(d) the categories of recipients to whom the personal data have been or \nwill be disclosed including recipients in third countries or inter­\nnational organisations; \n(e) where applicable, transfers of personal data to a third country or an \ninternational organisation, including the identification of that third \ncountry or international organisation and, in the case of transfers \nreferred to in the second subparagraph of Article 49(1), the docu­\nmentation of suitable safeguards; \n(f) where possible, the envisaged time limits for erasure of the different \ncategories of data; \n(g) where possible, a general description of the technical and organisa­\ntional security measures referred to in Article 32(1). \n2. \nEach processor and, where applicable, the processor's representa­\ntive shall maintain a record of all categories of processing activities \ncarried out on behalf of a controller, containing: \n(a) the name and contact details of the processor or processors and of \neach controller on behalf of which the processor is acting, and, \nwhere applicable, of the controller's or the processor's represen­\ntative, and the data protection officer; \n(b) the categories of processing carried out on behalf of each controller; \n(c) where applicable, transfers of personal data to a third country or an \ninternational organisation, including the identification of that third \ncountry or international organisation and, in the case of transfers \nreferred to in the second subparagraph of Article 49(1), the docu­\nmentation of suitable safeguards; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 28 \n(d) where possible, a general description of the technical and organisa­\ntional security measures referred to in Article 32(1). \n3. \nThe records referred to in paragraphs 1 and 2 shall be in writing, \nincluding in electronic form. \n4. \nThe controller or the processor and, where applicable, the \ncontroller's or the processor's representative, shall make the record \navailable to the supervisory authority on request. \n5. \nThe obligations referred to in paragraphs 1 and 2 shall not apply \nto an enterprise or an organisation employing fewer than 250 persons \nunless the processing it carries out is likely to result in a risk to the \nrights and freedoms of data subjects, the processing is not occasional, or \nthe processing includes special categories of data as referred to in \nArticle 9(1) or personal data relating to criminal convictions and \noffences referred to in Article 10. \nArticle 31 \nCooperation with the supervisory authority \nThe controller and the processor and, where applicable, their represen­\ntatives, shall cooperate, on request, with the supervisory authority in the \nperformance of its tasks. \nS e c t i o n 2 \nS e c u r i t y o f p e r s o n a l d a t a \nArticle 32 \nSecurity of processing \n1. \nTaking into account the state of the art, the costs of implemen­\ntation and the nature, scope, context and purposes of processing as well \nas the risk of varying likelihood and severity for the rights and freedoms \nof natural persons, the controller and the processor shall implement \nappropriate technical and organisational measures to ensure a level of \nsecurity appropriate to the risk, including inter alia as appropriate: \n(a) the pseudonymisation and encryption of personal data; \n(b) the ability to ensure the ongoing confidentiality, integrity, availabil­\nity and resilience of processing systems and services; \n(c) the ability to restore the availability and access to personal data in a \ntimely manner in the event of a physical or technical incident; \n(d) a process for regularly testing, assessing and evaluating the effec­\ntiveness of technical and organisational measures for ensuring the \nsecurity of the processing. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 29 \n2. \nIn assessing the appropriate level of security account shall be \ntaken in particular of the risks that are presented by processing, in \nparticular from accidental or unlawful destruction, loss, alteration, \nunauthorised disclosure of, or access to personal data transmitted, \nstored or otherwise processed. \n3. \nAdherence to an approved code of conduct as referred to in \nArticle 40 or an approved certification mechanism as referred to in \nArticle 42 may be used as an element by which to demonstrate \ncompliance with the requirements set out in paragraph 1 of this Article. \n4. \nThe controller and processor shall take steps to ensure that any \nnatural person acting under the authority of the controller or the \nprocessor who has access to personal data does not process them \nexcept on instructions from the controller, unless he or she is required \nto do so by Union or Member State law. \nArticle 33 \nNotification of a personal data breach to the supervisory authority \n1. \nIn the case of a personal data breach, the controller shall without \nundue delay and, where feasible, not later than 72 hours after having \nbecome aware of it, notify the personal data breach to the supervisory \nauthority competent in accordance with Article 55, unless the personal \ndata breach is unlikely to result in a risk to the rights and freedoms of \nnatural persons. Where the notification to the supervisory authority is \nnot made within 72 hours, it shall be accompanied by reasons for the \ndelay. \n2. \nThe processor shall notify the controller without undue delay after \nbecoming aware of a personal data breach. \n3. \nThe notification referred to in paragraph 1 shall at least: \n(a) describe the nature of the personal data breach including where \npossible, the categories and approximate number of data subjects \nconcerned and the categories and approximate number of personal \ndata records concerned; \n(b) communicate the name and contact details of the data protection \nofficer or other contact point where more information can be \nobtained; \n(c) describe the likely consequences of the personal data breach; \n(d) describe the measures taken or proposed to be taken by the \ncontroller to address the personal data breach, including, where \nappropriate, measures to mitigate its possible adverse effects. \n4. \nWhere, and in so far as, it is not possible to provide the \ninformation at the same time, the information may be provided in \nphases without undue further delay. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 30 \n5. \nThe controller shall document any personal data breaches, \ncomprising the facts relating to the personal data breach, its effects \nand the remedial action taken. That documentation shall enable the \nsupervisory authority to verify compliance with this Article. \nArticle 34 \nCommunication of a personal data breach to the data subject \n1. \nWhen the personal data breach is likely to result in a high risk to \nthe rights and freedoms of natural persons, the controller shall \ncommunicate the personal data breach to the data subject without \nundue delay. \n2. \nThe communication to the data subject referred to in paragraph 1 \nof this Article shall describe in clear and plain language the nature of \nthe personal data breach and contain at least the information and \nmeasures referred to in points (b), (c) and (d) of Article 33(3). \n3. \nThe communication to the data subject referred to in paragraph 1 \nshall not be required if any of the following conditions are met: \n(a) the controller has implemented appropriate technical and organisa­\ntional protection measures, and those measures were applied to the \npersonal data affected by the personal data breach, in particular \nthose that render the personal data unintelligible to any person \nwho is not authorised to access it, such as encryption; \n(b) the controller has taken subsequent measures which ensure that the \nhigh risk to the rights and freedoms of data subjects referred to in \nparagraph 1 is no longer likely to materialise; \n(c) it would involve disproportionate effort. In such a case, there shall \ninstead be a public communication or similar measure whereby the \ndata subjects are informed in an equally effective manner. \n4. \nIf the controller has not already communicated the personal data \nbreach to the data subject, the supervisory authority, having considered \nthe likelihood of the personal data breach resulting in a high risk, may \nrequire it to do so or may decide that any of the conditions referred to \nin paragraph 3 are met. \nS e c t i o n 3 \nD a t a \np r o t e c t i o n \ni m p a c t \na s s e s s m e n t a n d \np r i o r \nc o n s u l t a t i o n \nArticle 35 \nData protection impact assessment \n1. \nWhere a type of processing in particular using new technologies, \nand taking into account the nature, scope, context and purposes of the \nprocessing, is likely to result in a high risk to the rights and freedoms of \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 31 \nnatural persons, the controller shall, prior to the processing, carry out an \nassessment of the impact of the envisaged processing operations on the \nprotection of personal data. A single assessment may address a set of \nsimilar processing operations that present similar high risks. \n2. \nThe controller shall seek the advice of the data protection officer, \nwhere designated, when carrying out a data protection impact \nassessment. \n3. \nA data protection impact assessment referred to in paragraph 1 \nshall in particular be required in the case of: \n(a) a systematic and extensive evaluation of personal aspects relating to \nnatural persons which is based on automated processing, including \nprofiling, and on which decisions are based that produce legal \neffects concerning the natural person or similarly significantly \naffect the natural person; \n(b) processing on a large scale of special categories of data referred to \nin Article 9(1), or of personal data relating to criminal convictions \nand offences referred to in Article 10; or \n(c) a systematic monitoring of a publicly accessible area on a large \nscale. \n4. \nThe supervisory authority shall establish and make public a list of \nthe kind of processing operations which are subject to the requirement \nfor a data protection impact assessment pursuant to paragraph 1. The \nsupervisory authority shall communicate those lists to the Board referred \nto in Article 68. \n5. \nThe supervisory authority may also establish and make public a \nlist of the kind of processing operations for which no data protection \nimpact assessment is required. The supervisory authority shall \ncommunicate those lists to the Board. \n6. \nPrior to the adoption of the lists referred to in paragraphs 4 and 5, \nthe competent supervisory authority shall apply the consistency \nmechanism referred to in Article 63 where such lists involve processing \nactivities which are related to the offering of goods or services to data \nsubjects or to the monitoring of their behaviour in several \nMember States, or may substantially affect the free movement of \npersonal data within the Union. \n7. \nThe assessment shall contain at least: \n(a) a systematic description of the envisaged processing operations and \nthe purposes of the processing, including, where applicable, the \nlegitimate interest pursued by the controller; \n(b) an assessment of the necessity and proportionality of the processing \noperations in relation to the purposes; \n(c) an assessment of the risks to the rights and freedoms of data \nsubjects referred to in paragraph 1; and \n(d) the measures envisaged to address the risks, including safeguards, \nsecurity measures and mechanisms to ensure the protection of \npersonal data and to demonstrate compliance with this Regulation \ntaking into account the rights and legitimate interests of data \nsubjects and other persons concerned. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 32 \n8. \nCompliance with approved codes of conduct referred to in \nArticle 40 by the relevant controllers or processors shall be taken into \ndue account in assessing the impact of the processing operations \nperformed by such controllers or processors, in particular for the \npurposes of a data protection impact assessment. \n9. \nWhere appropriate, the controller shall seek the views of data \nsubjects or their representatives on the intended processing, without \nprejudice to the protection of commercial or public interests or the \nsecurity of processing operations. \n10. \nWhere processing pursuant to point (c) or (e) of Article 6(1) has \na legal basis in Union law or in the law of the Member State to which \nthe controller is subject, that law regulates the specific processing \noperation or set of operations in question, and a data protection \nimpact assessment has already been carried out as part of a general \nimpact assessment in the context of the adoption of that legal basis, \nparagraphs 1 to 7 shall not apply unless Member States deem it to be \nnecessary to carry out such an assessment prior to processing activities. \n11. \nWhere necessary, the controller shall carry out a review to assess \nif processing is performed in accordance with the data protection impact \nassessment at least when there is a change of the risk represented by \nprocessing operations. \nArticle 36 \nPrior consultation \n1. \nThe controller shall consult the supervisory authority prior to \nprocessing where a data protection impact assessment under Article 35 \nindicates that the processing would result in a high risk in the absence \nof measures taken by the controller to mitigate the risk. \n2. \nWhere the supervisory authority is of the opinion that the intended \nprocessing referred to in paragraph 1 would infringe this Regulation, in \nparticular where the controller has insufficiently identified or mitigated \nthe risk, the supervisory authority shall, within period of up to eight \nweeks of receipt of the request for consultation, provide written advice \nto the controller and, where applicable to the processor, and may use \nany of its powers referred to in Article 58. That period may be extended \nby six weeks, taking into account the complexity of the intended \nprocessing. The supervisory authority shall inform the controller and, \nwhere applicable, the processor, of any such extension within one \nmonth of receipt of the request for consultation together with the \nreasons for the delay. Those periods may be suspended until the super­\nvisory authority has obtained information it has requested for the \npurposes of the consultation. \n3. \nWhen consulting the supervisory authority pursuant to paragraph 1, \nthe controller shall provide the supervisory authority with: \n(a) where applicable, the respective responsibilities of the controller, \njoint controllers and processors involved in the processing, in \nparticular for processing within a group of undertakings; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 33 \n(b) the purposes and means of the intended processing; \n(c) the measures and safeguards provided to protect the rights and \nfreedoms of data subjects pursuant to this Regulation; \n(d) where applicable, the contact details of the data protection officer; \n(e) the data protection impact assessment provided for in Article 35; \nand \n(f) any other information requested by the supervisory authority. \n4. \nMember States shall consult the supervisory authority during the \npreparation of a proposal for a legislative measure to be adopted by a \nnational parliament, or of a regulatory measure based on such a legis­\nlative measure, which relates to processing. \n5. \nNotwithstanding paragraph 1, Member State law may require \ncontrollers to consult with, and obtain prior authorisation from, the \nsupervisory authority in relation to processing by a controller for the \nperformance of a task carried out by the controller in the public interest, \nincluding processing in relation to social protection and public health. \nS e c t i o n 4 \nD a t a p r o t e c t i o n o f f i c e r \nArticle 37 \nDesignation of the data protection officer \n1. \nThe controller and the processor shall designate a data protection \nofficer in any case where: \n(a) the processing is carried out by a public authority or body, except \nfor courts acting in their judicial capacity; \n(b) the core activities of the controller or the processor consist of \nprocessing operations which, by virtue of their nature, their scope \nand/or their purposes, require regular and systematic monitoring of \ndata subjects on a large scale; or \n▼C1 \n(c) the core activities of the controller or the processor consist of \nprocessing on a large scale of special categories of data pursuant \nto Article 9 or personal data relating to criminal convictions and \noffences referred to in Article 10. \n▼B \n2. \nA group of undertakings may appoint a single data protection \nofficer provided that a data protection officer is easily accessible from \neach establishment. \n3. \nWhere the controller or the processor is a public authority or body, \na single data protection officer may be designated for several such \nauthorities or bodies, taking account of their organisational structure \nand size. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 34 \n4. \nIn cases other than those referred to in paragraph 1, the controller \nor processor or associations and other bodies representing categories of \ncontrollers or processors may or, where required by Union or Member \nState law shall, designate a data protection officer. The data protection \nofficer may act for such associations and other bodies representing \ncontrollers or processors. \n5. \nThe data protection officer shall be designated on the basis of \nprofessional qualities and, in particular, expert knowledge of data \nprotection law and practices and the ability to fulfil the tasks referred \nto in Article 39. \n6. \nThe data protection officer may be a staff member of the controller \nor processor, or fulfil the tasks on the basis of a service contract. \n7. \nThe controller or the processor shall publish the contact details of \nthe data protection officer and communicate them to the supervisory \nauthority. \nArticle 38 \nPosition of the data protection officer \n1. \nThe controller and the processor shall ensure that the data \nprotection officer is involved, properly and in a timely manner, in all \nissues which relate to the protection of personal data. \n2. \nThe controller and processor shall support the data protection \nofficer in performing the tasks referred to in Article 39 by providing \nresources necessary to carry out those tasks and access to personal data \nand processing operations, and to maintain his or her expert knowledge. \n3. \nThe controller and processor shall ensure that the data protection \nofficer does not receive any instructions regarding the exercise of those \ntasks. He or she shall not be dismissed or penalised by the controller or \nthe processor for performing his tasks. The data protection officer shall \ndirectly report to the highest management level of the controller or the \nprocessor. \n4. \nData subjects may contact the data protection officer with regard \nto all issues related to processing of their personal data and to the \nexercise of their rights under this Regulation. \n5. \nThe data protection officer shall be bound by secrecy or confiden­\ntiality concerning the performance of his or her tasks, in accordance \nwith Union or Member State law. \n6. \nThe data protection officer may fulfil other tasks and duties. The \ncontroller or processor shall ensure that any such tasks and duties do not \nresult in a conflict of interests. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 35 \nArticle 39 \nTasks of the data protection officer \n1. \nThe data protection officer shall have at least the following tasks: \n(a) to inform and advise the controller or the processor and the \nemployees who carry out processing of their obligations pursuant \nto this Regulation and to other Union or Member State data \nprotection provisions; \n(b) to monitor compliance with this Regulation, with other Union or \nMember State data protection provisions and with the policies of the \ncontroller or processor in relation to the protection of personal data, \nincluding the assignment of responsibilities, awareness-raising and \ntraining of staff involved in processing operations, and the related \naudits; \n(c) to provide advice where requested as regards the data protection \nimpact assessment and monitor its performance pursuant to \nArticle 35; \n(d) to cooperate with the supervisory authority; \n(e) to act as the contact point for the supervisory authority on issues \nrelating to processing, including the prior consultation referred to in \nArticle 36, and to consult, where appropriate, with regard to any \nother matter. \n2. \nThe data protection officer shall in the performance of his or her \ntasks have due regard to the risk associated with processing operations, \ntaking into account the nature, scope, context and purposes of \nprocessing. \nS e c t i o n 5 \nC o d e s o f c o n d u c t a n d c e r t i f i c a t i o n \nArticle 40 \nCodes of conduct \n1. \nThe Member States, the supervisory authorities, the Board and the \nCommission shall encourage the drawing up of codes of conduct \nintended to contribute to the proper application of this Regulation, \ntaking account of the specific features of the various processing \nsectors and the specific needs of micro, small and medium-sized \nenterprises. \n2. \nAssociations and \nother bodies \nrepresenting categories of \ncontrollers or processors may prepare codes of conduct, or amend or \nextend such codes, for the purpose of specifying the application of this \nRegulation, such as with regard to: \n(a) fair and transparent processing; \n(b) the legitimate interests pursued by controllers in specific contexts; \n(c) the collection of personal data; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 36 \n(d) the pseudonymisation of personal data; \n(e) the information provided to the public and to data subjects; \n(f) the exercise of the rights of data subjects; \n(g) the information provided to, and the protection of, children, and the \nmanner in which the consent of the holders of parental responsi­\nbility over children is to be obtained; \n(h) the measures and procedures referred to in Articles 24 and 25 and \nthe measures to ensure security of processing referred to in \nArticle 32; \n(i) the notification of personal data breaches to supervisory authorities \nand the communication of such personal data breaches to data \nsubjects; \n(j) the transfer of personal data to third countries or international \norganisations; or \n(k) out-of-court proceedings and other dispute resolution procedures for \nresolving disputes between controllers and data subjects with regard \nto processing, without prejudice to the rights of data subjects \npursuant to Articles 77 and 79. \n3. \nIn addition to adherence by controllers or processors subject to \nthis Regulation, codes of conduct approved pursuant to paragraph 5 of \nthis Article and having general validity pursuant to paragraph 9 of this \nArticle may also be adhered to by controllers or processors that are not \nsubject to this Regulation pursuant to Article 3 in order to provide \nappropriate safeguards within the framework of personal data transfers \nto third countries or international organisations under the terms referred \nto in point (e) of Article 46(2). Such controllers or processors shall \nmake binding and enforceable commitments, via contractual or other \nlegally binding instruments, to apply those appropriate safeguards \nincluding with regard to the rights of data subjects. \n4. \nA code of conduct referred to in paragraph 2 of this Article shall \ncontain mechanisms which enable the body referred to in Article 41(1) \nto carry out the mandatory monitoring of compliance with its provisions \nby the controllers or processors which undertake to apply it, without \nprejudice to the tasks and powers of supervisory authorities competent \npursuant to Article 55 or 56. \n5. \nAssociations and other bodies referred to in paragraph 2 of this \nArticle which intend to prepare a code of conduct or to amend or extend \nan existing code shall submit the draft code, amendment or extension to \nthe supervisory authority which is competent pursuant to Article 55. \nThe supervisory authority shall provide an opinion on whether the \ndraft code, amendment or extension complies with this Regulation \nand shall approve that draft code, amendment or extension if it finds \nthat it provides sufficient appropriate safeguards. \n6. \nWhere the draft code, or amendment or extension is approved in \naccordance with paragraph 5, and where the code of conduct concerned \ndoes not relate to processing activities in several Member States, the \nsupervisory authority shall register and publish the code. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 37 \n7. \nWhere a draft code of conduct relates to processing activities in \nseveral Member States, the supervisory authority which is competent \npursuant to Article 55 shall, before approving the draft code, \namendment or extension, submit it in the procedure referred to in \nArticle 63 to the Board which shall provide an opinion on whether \nthe draft code, amendment or extension complies with this Regulation \nor, in the situation referred to in paragraph 3 of this Article, provides \nappropriate safeguards. \n8. \nWhere the opinion referred to in paragraph 7 confirms that the \ndraft code, amendment or extension complies with this Regulation, or, \nin the situation referred to in paragraph 3, provides appropriate safe­\nguards, the Board shall submit its opinion to the Commission. \n9. \nThe Commission may, by way of implementing acts, decide that \nthe approved code of conduct, amendment or extension submitted to it \npursuant to paragraph 8 of this Article have general validity within the \nUnion. Those implementing acts shall be adopted in accordance with \nthe examination procedure set out in Article 93(2). \n10. \nThe Commission shall ensure appropriate publicity for the \napproved codes which have been decided as having general validity \nin accordance with paragraph 9. \n11. \nThe Board shall collate all approved codes of conduct, \namendments and extensions in a register and shall make them \npublicly available by way of appropriate means. \nArticle 41 \nMonitoring of approved codes of conduct \n1. \nWithout prejudice to the tasks and powers of the competent super­\nvisory authority under Articles 57 and 58, the monitoring of compliance \nwith a code of conduct pursuant to Article 40 may be carried out by a \nbody which has an appropriate level of expertise in relation to the \nsubject-matter of the code and is accredited for that purpose by the \ncompetent supervisory authority. \n2. \nA body as referred to in paragraph 1 may be accredited to monitor \ncompliance with a code of conduct where that body has: \n(a) demonstrated its independence and expertise in relation to the \nsubject-matter of the code to the satisfaction of the competent super­\nvisory authority; \n(b) established procedures which allow it to assess the eligibility of \ncontrollers and processors concerned to apply the code, to \nmonitor their compliance with its provisions and to periodically \nreview its operation; \n(c) established procedures and structures to handle complaints about \ninfringements of the code or the manner in which the code has \nbeen, or is being, implemented by a controller or processor, and \nto make those procedures and structures transparent to data subjects \nand the public; and \n(d) demonstrated to the satisfaction of the competent supervisory \nauthority that its tasks and duties do not result in a conflict of \ninterests. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 38 \n3. \nThe competent supervisory authority shall submit the draft \nrequirements for accreditation of a body as referred to in paragraph 1 \nof this Article to the Board pursuant to the consistency mechanism \nreferred to in Article 63. \n▼B \n4. \nWithout prejudice to the tasks and powers of the competent super­\nvisory authority and the provisions of Chapter VIII, a body as referred \nto in paragraph 1 of this Article shall, subject to appropriate safeguards, \ntake appropriate action in cases of infringement of the code by a \ncontroller or processor, including suspension or exclusion of the \ncontroller or processor concerned from the code. It shall inform the \ncompetent supervisory authority of such actions and the reasons for \ntaking them. \n▼C1 \n5. \nThe competent supervisory authority shall revoke the accreditation \nof a body as referred to in paragraph 1 if the requirements for accred­\nitation are not, or are no longer, met or where actions taken by the body \ninfringe this Regulation. \n▼B \n6. \nThis Article shall not apply to processing carried out by public \nauthorities and bodies. \nArticle 42 \nCertification \n1. \nThe Member States, the supervisory authorities, the Board and the \nCommission shall encourage, in particular at Union level, the estab­\nlishment of data protection certification mechanisms and of data \nprotection seals and marks, for the purpose of demonstrating compliance \nwith this Regulation of processing operations by controllers and \nprocessors. The specific needs of micro, small and medium-sized enter­\nprises shall be taken into account. \n2. \nIn addition to adherence by controllers or processors subject to \nthis Regulation, data protection certification mechanisms, seals or marks \napproved pursuant to paragraph 5 of this Article may be established for \nthe purpose of demonstrating the existence of appropriate safeguards \nprovided by controllers or processors that are not subject to this Regu­\nlation pursuant to Article 3 within the framework of personal data \ntransfers to third countries or international organisations under the \nterms referred to in point (f) of Article 46(2). Such controllers or \nprocessors shall make binding and enforceable commitments, via \ncontractual or other legally binding instruments, to apply those appro­\npriate safeguards, including with regard to the rights of data subjects. \n3. \nThe certification shall be voluntary and available via a process that \nis transparent. \n4. \nA certification pursuant to this Article does not reduce the respon­\nsibility of the controller or the processor for compliance with this Regu­\nlation and is without prejudice to the tasks and powers of the super­\nvisory authorities which are competent pursuant to Article 55 or 56. \n▼C1\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 39 \n5. \nA certification pursuant to this Article shall be issued by the \ncertification bodies referred to in Article 43 or by the competent super­\nvisory authority, on the basis of criteria approved by that competent \nsupervisory authority pursuant to Article 58(3) or by the Board pursuant \nto Article 63. Where the criteria are approved by the Board, this may \nresult in a common certification, the European Data Protection Seal. \n6. \nThe controller or processor which submits its processing to the \ncertification mechanism shall provide the certification body referred to \nin Article 43, or where applicable, the competent supervisory authority, \nwith all information and access to its processing activities which are \nnecessary to conduct the certification procedure. \n▼C1 \n7. \nCertification shall be issued to a controller or processor for a \nmaximum period of three years and may be renewed, under the same \nconditions, provided that the relevant criteria continue to be met. Certifi­\ncation shall be withdrawn, as applicable, by the certification bodies \nreferred to in Article 43 or by the competent supervisory authority \nwhere the criteria for the certification are not or are no longer met. \n▼B \n8. \nThe Board shall collate all certification mechanisms and data \nprotection seals and marks in a register and shall make them publicly \navailable by any appropriate means. \nArticle 43 \nCertification bodies \n1. \nWithout prejudice to the tasks and powers of the competent super­\nvisory authority under Articles 57 and 58, certification bodies which \nhave an appropriate level of expertise in relation to data protection shall, \nafter informing the supervisory authority in order to allow it to exercise \nits powers pursuant to point (h) of Article 58(2) where necessary, issue \nand renew certification. Member States shall ensure that those certifi­\ncation bodies are accredited by one or both of the following: \n(a) the supervisory authority which is competent pursuant to Article 55 \nor 56; \n(b) the national accreditation body named in accordance with \nRegulation (EC) No 765/2008 of the European Parliament and of \nthe Council ( \n1 \n) in accordance with EN-ISO/IEC 17065/2012 and \nwith the additional requirements established by the supervisory \nauthority which is competent pursuant to Article 55 or 56. \n2. \nCertification bodies referred to in paragraph 1 shall be accredited \nin accordance with that paragraph only where they have: \n(a) demonstrated their independence and expertise in relation to the \nsubject-matter of the certification to the satisfaction of the \ncompetent supervisory authority; \n▼B \n( \n1 \n) Regulation (EC) No 765/2008 of the European Parliament and of the Council \nof 9 July 2008 setting out the requirements for accreditation and market \nsurveillance \nrelating \nto \nthe \nmarketing \nof \nproducts \nand \nrepealing \nRegulation (EEC) No 339/93 (OJ L 218, 13.8.2008, p. 30).\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 40 \n(b) undertaken to respect the criteria referred to in Article 42(5) and \napproved by the supervisory authority which is competent pursuant \nto Article 55 or 56 or by the Board pursuant to Article 63; \n(c) established procedures for the issuing, periodic review and with­\ndrawal of data protection certification, seals and marks; \n(d) established procedures and structures to handle complaints about \ninfringements of the certification or the manner in which the certifi­\ncation has been, or is being, implemented by the controller or \nprocessor, and to make those procedures and structures transparent \nto data subjects and the public; and \n(e) demonstrated, to the satisfaction of the competent supervisory auth­\nority, that their tasks and duties do not result in a conflict of \ninterests. \n3. \n►C1 The accreditation of certification bodies as referred to in \nparagraphs 1 and 2 of this Article shall take place on the basis of \nrequirements approved by the supervisory authority which is \ncompetent pursuant to Article 55 or 56 or by the Board pursuant to \nArticle 63. ◄ In the case of accreditation pursuant to point (b) of \nparagraph 1 of this Article, those requirements shall complement \nthose envisaged in Regulation (EC) No 765/2008 and the technical \nrules that describe the methods and procedures of the certification \nbodies. \n4. \nThe certification bodies referred to in paragraph 1 shall be \nresponsible for the proper assessment leading to the certification or \nthe withdrawal of such certification without prejudice to the responsi­\nbility of the controller or processor for compliance with this Regulation. \nThe accreditation shall be issued for a maximum period of five years \nand may be renewed on the same conditions provided that the certifi­\ncation body meets the requirements set out in this Article. \n5. \nThe certification bodies referred to in paragraph 1 shall provide \nthe competent supervisory authorities with the reasons for granting or \nwithdrawing the requested certification. \n▼C1 \n6. \nThe requirements referred to in paragraph 3 of this Article and the \ncriteria referred to in Article 42(5) shall be made public by the super­\nvisory authority in an easily accessible form. The supervisory authorities \nshall also transmit those requirements and criteria to the Board. \n▼B \n7. \nWithout prejudice to Chapter VIII, the competent supervisory \nauthority or the national accreditation body shall revoke an accreditation \nof a certification body pursuant to paragraph 1 of this Article where the \nconditions for the accreditation are not, or are no longer, met or where \nactions taken by a certification body infringe this Regulation. \n8. \nThe Commission shall be empowered to adopt delegated acts in \naccordance with Article 92 for the purpose of specifying the \nrequirements to be taken into account for the data protection certifi­\ncation mechanisms referred to in Article 42(1). \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 41 \n9. \nThe Commission may adopt implementing acts laying down \ntechnical standards for certification mechanisms and data protection \nseals and marks, and mechanisms to promote and recognise those \ncertification mechanisms, seals and marks. Those implementing acts \nshall be adopted in accordance with the examination procedure \nreferred to in Article 93(2). \nCHAPTER V \nTransfers of personal data to third countries or international \norganisations \nArticle 44 \nGeneral principle for transfers \nAny transfer of personal data which are undergoing processing or are \nintended for processing after transfer to a third country or to an inter­\nnational organisation shall take place only if, subject to the other \nprovisions of this Regulation, the conditions laid down in this \nChapter are complied with by the controller and processor, including \nfor onward transfers of personal data from the third country or an \ninternational organisation to another third country or to another inter­\nnational organisation. All provisions in this Chapter shall be applied in \norder to ensure that the level of protection of natural persons guaranteed \nby this Regulation is not undermined. \nArticle 45 \nTransfers on the basis of an adequacy decision \n1. \nA transfer of personal data to a third country or an international \norganisation may take place where the Commission has decided that the \nthird country, a territory or one or more specified sectors within that \nthird country, or the international organisation in question ensures an \nadequate level of protection. Such a transfer shall not require any \nspecific authorisation. \n2. \nWhen assessing the adequacy of the level of protection, the \nCommission shall, in particular, take account of the following elements: \n(a) the rule of law, respect for human rights and fundamental freedoms, \nrelevant legislation, both general and sectoral, including concerning \npublic security, defence, national security and criminal law and the \naccess of public authorities to personal data, as well as the im­\nplementation of such legislation, data protection rules, professional \nrules and security measures, including rules for the onward transfer \nof personal data to another third country or international organis­\nation which are complied with in that country or international \norganisation, case-law, as well as effective and enforceable data \nsubject rights and effective administrative and judicial redress for \nthe data subjects whose personal data are being transferred; \n(b) the existence and effective functioning of one or more independent \nsupervisory authorities in the third country or to which an inter­\nnational organisation is subject, with responsibility for ensuring and \nenforcing compliance with the data protection rules, including \nadequate enforcement powers, for assisting and advising the data \nsubjects in exercising their rights and for cooperation with the \nsupervisory authorities of the Member States; and \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 42 \n(c) the international commitments the third country or international \norganisation concerned has entered into, or other obligations \narising from legally binding conventions or instruments as well as \nfrom its participation in multilateral or regional systems, in \nparticular in relation to the protection of personal data. \n3. \nThe Commission, after assessing the adequacy of the level of \nprotection, may decide, by means of implementing act, that a third \ncountry, a territory or one or more specified sectors within a third \ncountry, or an international organisation ensures an adequate level of \nprotection within the meaning of paragraph 2 of this Article. The im­\nplementing act shall provide for a mechanism for a periodic review, at \nleast every four years, which shall take into account all relevant deve­\nlopments in the third country or international organisation. The imple­\nmenting act shall specify its territorial and sectoral application and, \nwhere applicable, identify the supervisory authority or authorities \nreferred to in point (b) of paragraph 2 of this Article. The implementing \nact shall be adopted in accordance with the examination procedure \nreferred to in Article 93(2). \n4. \nThe Commission shall, on an ongoing basis, monitor develop­\nments in third countries and international organisations that could \naffect the functioning of decisions adopted pursuant to paragraph 3 of \nthis Article and decisions adopted on the basis of Article 25(6) of \nDirective 95/46/EC. \n5. \nThe Commission shall, where available information reveals, in \nparticular following the review referred to in paragraph 3 of this \nArticle, that a third country, a territory or one or more specified \nsectors within a third country, or an international organisation no \nlonger ensures an adequate level of protection within the meaning of \nparagraph 2 of this Article, to the extent necessary, repeal, amend or \nsuspend the decision referred to in paragraph 3 of this Article by means \nof implementing acts without retro-active effect. Those implementing \nacts shall be adopted in accordance with the examination procedure \nreferred to in Article 93(2). \nOn duly justified imperative grounds of urgency, the Commission shall \nadopt immediately applicable implementing acts in accordance with the \nprocedure referred to in Article 93(3). \n6. \nThe Commission shall enter into consultations with the third \ncountry or international organisation with a view to remedying the \nsituation giving rise to the decision made pursuant to paragraph 5. \n7. \nA decision pursuant to paragraph 5 of this Article is without \nprejudice to transfers of personal data to the third country, a territory \nor one or more specified sectors within that third country, or the inter­\nnational organisation in question pursuant to Articles 46 to 49. \n8. \nThe Commission shall publish in the Official Journal of the \nEuropean Union and on its website a list of the third countries, terri­\ntories and specified sectors within a third country and international \norganisations for which it has decided that an adequate level of \nprotection is or is no longer ensured. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 43 \n9. \nDecisions adopted by the Commission on the basis of Article 25(6) \nof Directive 95/46/EC shall remain in force until amended, replaced or \nrepealed by a Commission Decision adopted in accordance with \nparagraph 3 or 5 of this Article. \nArticle 46 \nTransfers subject to appropriate safeguards \n1. \nIn the absence of a decision pursuant to Article 45(3), a controller \nor processor may transfer personal data to a third country or an inter­\nnational organisation only if the controller or processor has provided \nappropriate safeguards, and on condition that enforceable data subject \nrights and effective legal remedies for data subjects are available. \n2. \nThe appropriate safeguards referred to in paragraph 1 may be \nprovided for, without requiring any specific authorisation from a super­\nvisory authority, by: \n(a) a legally binding and enforceable instrument between public auth­\norities or bodies; \n(b) binding corporate rules in accordance with Article 47; \n(c) standard data protection clauses adopted by the Commission in \naccordance with the examination procedure referred to in \nArticle 93(2); \n(d) standard data protection clauses adopted by a supervisory authority \nand approved by the Commission pursuant to the examination \nprocedure referred to in Article 93(2); \n(e) an approved code of conduct pursuant to Article 40 together with \nbinding and enforceable commitments of the controller or processor \nin the third country to apply the appropriate safeguards, including as \nregards data subjects' rights; or \n(f) an approved certification mechanism pursuant to Article 42 together \nwith binding and enforceable commitments of the controller or \nprocessor in the third country to apply the appropriate safeguards, \nincluding as regards data subjects' rights. \n3. \nSubject to the authorisation from the competent supervisory auth­\nority, the appropriate safeguards referred to in paragraph 1 may also be \nprovided for, in particular, by: \n(a) contractual clauses between the controller or processor and the \ncontroller, processor or the recipient of the personal data in the \nthird country or international organisation; or \n(b) provisions to be inserted into administrative arrangements between \npublic authorities or bodies which include enforceable and effective \ndata subject rights. \n4. \nThe supervisory authority shall apply the consistency mechanism \nreferred to in Article 63 in the cases referred to in paragraph 3 of this \nArticle. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 44 \n5. \nAuthorisations by a Member State or supervisory authority on the \nbasis of Article 26(2) of Directive 95/46/EC shall remain valid until \namended, replaced or repealed, if necessary, by that supervisory auth­\nority. Decisions adopted by the Commission on the basis of Article 26(4) \nof Directive 95/46/EC shall remain in force until amended, replaced or \nrepealed, if necessary, by a Commission Decision adopted in accordance \nwith paragraph 2 of this Article. \nArticle 47 \nBinding corporate rules \n1. \nThe competent supervisory authority shall approve binding \ncorporate rules in accordance with the consistency mechanism set out \nin Article 63, provided that they: \n(a) are legally binding and apply to and are enforced by every member \nconcerned of the group of undertakings, or group of enterprises \nengaged in a joint economic activity, including their employees; \n(b) expressly confer enforceable rights on data subjects with regard to \nthe processing of their personal data; and \n(c) fulfil the requirements laid down in paragraph 2. \n2. \nThe binding corporate rules referred to in paragraph 1 shall specify \nat least: \n(a) the structure and contact details of the group of undertakings, or \ngroup of enterprises engaged in a joint economic activity and of \neach of its members; \n(b) the data transfers or set of transfers, including the categories of \npersonal data, the type of processing and its purposes, the type \nof data subjects affected and the identification of the third \ncountry or countries in question; \n(c) their legally binding nature, both internally and externally; \n(d) the application of the general data protection principles, in \nparticular purpose limitation, data minimisation, limited storage \nperiods, data quality, data protection by design and by default, \nlegal basis for processing, processing of special categories of \npersonal data, measures to ensure data security, and the \nrequirements in respect of onward transfers to bodies not bound \nby the binding corporate rules; \n(e) the rights of data subjects in regard to processing and the means to \nexercise those rights, including the right not to be subject to \ndecisions based solely on automated processing, including \nprofiling in accordance with Article 22, the right to lodge a \ncomplaint with the competent supervisory authority and before \nthe competent courts of the Member States in accordance with \nArticle 79, and to obtain redress and, where appropriate, compen­\nsation for a breach of the binding corporate rules; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 45 \n(f) the acceptance by the controller or processor established on the \nterritory of a Member State of liability for any breaches of the \nbinding corporate rules by any member concerned not established \nin the Union; the controller or the processor shall be exempt from \nthat liability, in whole or in part, only if it proves that that member \nis not responsible for the event giving rise to the damage; \n(g) how the information on the binding corporate rules, in particular on \nthe provisions referred to in points (d), (e) and (f) of this paragraph \nis provided to the data subjects in addition to Articles 13 and 14; \n(h) the tasks of any data protection officer designated in accordance \nwith Article 37 or any other person or entity in charge of the \nmonitoring compliance with the binding corporate rules within \nthe group of undertakings, or group of enterprises engaged in a \njoint economic activity, as well as monitoring training and \ncomplaint-handling; \n(i) the complaint procedures; \n(j) the mechanisms within the group of undertakings, or group of \nenterprises engaged in a joint economic activity for ensuring the \nverification of compliance with the binding corporate rules. Such \nmechanisms shall include data protection audits and methods for \nensuring corrective actions to protect the rights of the data subject. \nResults of such verification should be communicated to the person \nor entity referred to in point (h) and to the board of the controlling \nundertaking of a group of undertakings, or of the group of enter­\nprises engaged in a joint economic activity, and should be available \nupon request to the competent supervisory authority; \n(k) the mechanisms for reporting and recording changes to the rules \nand reporting those changes to the supervisory authority; \n(l) the cooperation mechanism with the supervisory authority to ensure \ncompliance by any member of the group of undertakings, or group \nof enterprises engaged in a joint economic activity, in particular by \nmaking available to the supervisory authority the results of verifi­\ncations of the measures referred to in point (j); \n(m) the mechanisms for reporting to the competent supervisory \nauthority any legal requirements to which a member of the group \nof undertakings, or group of enterprises engaged in a joint \neconomic activity is subject in a third country which are likely \nto have a substantial adverse effect on the guarantees provided \nby the binding corporate rules; and \n(n) the appropriate data protection training to personnel having \npermanent or regular access to personal data. \n3. \nThe Commission may specify the format and procedures for the \nexchange of information between controllers, processors and super­\nvisory authorities for binding corporate rules within the meaning of \nthis Article. Those implementing acts shall be adopted in accordance \nwith the examination procedure set out in Article 93(2). \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 46 \nArticle 48 \nTransfers or disclosures not authorised by Union law \nAny judgment of a court or tribunal and any decision of an adminis­\ntrative authority of a third country requiring a controller or processor to \ntransfer or disclose personal data may only be recognised or enforceable \nin any manner if based on an international agreement, such as a mutual \nlegal assistance treaty, in force between the requesting third country and \nthe Union or a Member State, without prejudice to other grounds for \ntransfer pursuant to this Chapter. \nArticle 49 \nDerogations for specific situations \n1. \nIn the absence of an adequacy decision pursuant to Article 45(3), \nor of appropriate safeguards pursuant to Article 46, including binding \ncorporate rules, a transfer or a set of transfers of personal data to a third \ncountry or an international organisation shall take place only on one of \nthe following conditions: \n(a) the data subject has explicitly consented to the proposed transfer, \nafter having been informed of the possible risks of such transfers for \nthe data subject due to the absence of an adequacy decision and \nappropriate safeguards; \n(b) the transfer is necessary for the performance of a contract between \nthe data subject and the controller or the implementation of \npre-contractual measures taken at the data subject's request; \n(c) the transfer is necessary for the conclusion or performance of a \ncontract concluded in the interest of the data subject between the \ncontroller and another natural or legal person; \n(d) the transfer is necessary for important reasons of public interest; \n(e) the transfer is necessary for the establishment, exercise or defence \nof legal claims; \n(f) the transfer is necessary in order to protect the vital interests of the \ndata subject or of other persons, where the data subject is physically \nor legally incapable of giving consent; \n(g) the transfer is made from a register which according to Union or \nMember State law is intended to provide information to the public \nand which is open to consultation either by the public in general or \nby any person who can demonstrate a legitimate interest, but only to \nthe extent that the conditions laid down by Union or Member State \nlaw for consultation are fulfilled in the particular case. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 47 \nWhere a transfer could not be based on a provision in Article 45 or 46, \nincluding the provisions on binding corporate rules, and none of the \nderogations for a specific situation referred to in the first subparagraph \nof this paragraph is applicable, a transfer to a third country or an \ninternational organisation may take place only if the transfer is not \nrepetitive, concerns only a limited number of data subjects, is \nnecessary for the purposes of compelling legitimate interests pursued \nby the controller which are not overridden by the interests or rights and \nfreedoms of the data subject, and the controller has assessed all the \ncircumstances surrounding the data transfer and has on the basis of \nthat assessment provided suitable safeguards with regard to the \nprotection of personal data. The controller shall inform the supervisory \nauthority of the transfer. The controller shall, in addition to providing \nthe information referred to in Articles 13 and 14, inform the data subject \nof the transfer and on the compelling legitimate interests pursued. \n2. \nA transfer pursuant to point (g) of the first subparagraph of \nparagraph 1 shall not involve the entirety of the personal data or \nentire categories of the personal data contained in the register. Where \nthe register is intended for consultation by persons having a legitimate \ninterest, the transfer shall be made only at the request of those persons \nor if they are to be the recipients. \n3. \nPoints (a), (b) and (c) of the first subparagraph of paragraph 1 and \nthe second subparagraph thereof shall not apply to activities carried out \nby public authorities in the exercise of their public powers. \n4. \nThe public interest referred to in point (d) of the first subparagraph \nof paragraph 1 shall be recognised in Union law or in the law of the \nMember State to which the controller is subject. \n5. \nIn the absence of an adequacy decision, Union or Member State \nlaw may, for important reasons of public interest, expressly set limits to \nthe transfer of specific categories of personal data to a third country or \nan international organisation. Member States shall notify such \nprovisions to the Commission. \n6. \nThe controller or processor shall document the assessment as well \nas the suitable safeguards referred to in the second subparagraph of \nparagraph 1 of this Article in the records referred to in Article 30. \nArticle 50 \nInternational cooperation for the protection of personal data \nIn relation to third countries and international organisations, the \nCommission and supervisory authorities shall take appropriate steps to: \n(a) develop international cooperation mechanisms to facilitate the \neffective enforcement of legislation for the protection of personal \ndata; \n(b) provide international mutual assistance in the enforcement of legis­\nlation for the protection of personal data, including through notifi­\ncation, complaint referral, investigative assistance and information \nexchange, subject to appropriate safeguards for the protection of \npersonal data and other fundamental rights and freedoms; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 48 \n(c) engage relevant stakeholders in discussion and activities aimed at \nfurthering international cooperation in the enforcement of legislation \nfor the protection of personal data; \n(d) promote the exchange and documentation of personal data \nprotection legislation and practice, including on jurisdictional \nconflicts with third countries. \nCHAPTER VI \nIndependent supervisory authorities \nS e c t i o n 1 \nI n d e p e n d e n t s t a t u s \nArticle 51 \nSupervisory authority \n1. \nEach Member State shall provide for one or more independent \npublic authorities to be responsible for monitoring the application of \nthis Regulation, in order to protect the fundamental rights and freedoms \nof natural persons in relation to processing and to facilitate the free flow \nof personal data within the Union (‘supervisory authority’). \n2. \nEach supervisory authority shall contribute to the consistent appli­\ncation of this Regulation throughout the Union. For that purpose, the \nsupervisory authorities shall cooperate with each other and the \nCommission in accordance with Chapter VII. \n3. \nWhere more than one supervisory authority is established in a \nMember State, that Member State shall designate the supervisory \nauthority which is to represent those authorities in the Board and \nshall set out the mechanism to ensure compliance by the other auth­\norities with the rules relating to the consistency mechanism referred to \nin Article 63. \n4. \nEach Member State shall notify to the Commission the provisions \nof its law which it adopts pursuant to this Chapter, by 25 May 2018 \nand, without delay, any subsequent amendment affecting them. \nArticle 52 \nIndependence \n1. \nEach supervisory authority shall act with complete independence \nin performing its tasks and exercising its powers in accordance with this \nRegulation. \n2. \nThe member or members of each supervisory authority shall, in \nthe performance of their tasks and exercise of their powers in \naccordance with this Regulation, remain free from external influence, \nwhether direct or indirect, and shall neither seek nor take instructions \nfrom anybody. \n3. \nMember or members of each supervisory authority shall refrain \nfrom any action incompatible with their duties and shall not, during \ntheir term of office, engage in any incompatible occupation, whether \ngainful or not. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 49 \n4. \nEach Member State shall ensure that each supervisory authority is \nprovided with the human, technical and financial resources, premises \nand infrastructure necessary for the effective performance of its tasks \nand exercise of its powers, including those to be carried out in the \ncontext of mutual assistance, cooperation and participation in the Board. \n5. \nEach Member State shall ensure that each supervisory authority \nchooses and has its own staff which shall be subject to the exclusive \ndirection of the member or members of the supervisory authority \nconcerned. \n6. \nEach Member State shall ensure that each supervisory authority is \nsubject to financial control which does not affect its independence and \nthat it has separate, public annual budgets, which may be part of the \noverall state or national budget. \nArticle 53 \nGeneral conditions for the members of the supervisory authority \n1. \nMember States shall provide for each member of their supervisory \nauthorities to be appointed by means of a transparent procedure by: \n— their parliament; \n— their government; \n— their head of State; or \n— an independent body entrusted with the appointment under Member \nState law. \n2. \nEach member shall have the qualifications, experience and skills, \nin particular in the area of the protection of personal data, required to \nperform its duties and exercise its powers. \n3. \nThe duties of a member shall end in the event of the expiry of the \nterm of office, resignation or compulsory retirement, in accordance with \nthe law of the Member State concerned. \n4. \nA member shall be dismissed only in cases of serious misconduct \nor if the member no longer fulfils the conditions required for the \nperformance of the duties. \nArticle 54 \nRules on the establishment of the supervisory authority \n1. \nEach Member State shall provide by law for all of the following: \n(a) the establishment of each supervisory authority; \n(b) the qualifications and eligibility conditions required to be appointed \nas member of each supervisory authority; \n(c) the rules and procedures for the appointment of the member or \nmembers of each supervisory authority; \n(d) the duration of the term of the member or members of each super­\nvisory authority of no less than four years, except for the first \nappointment after 24 May 2016, part of which may take place for \na shorter period where that is necessary to protect the independence \nof the supervisory authority by means of a staggered appointment \nprocedure; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 50 \n(e) whether and, if so, for how many terms the member or members of \neach supervisory authority is eligible for reappointment; \n(f) the conditions governing the obligations of the member or members \nand staff of each supervisory authority, prohibitions on actions, \noccupations and benefits incompatible therewith during and after \nthe term of office and rules governing the cessation of employment. \n2. \nThe member or members and the staff of each supervisory \nauthority shall, in accordance with Union or Member State law, be \nsubject to a duty of professional secrecy both during and after their \nterm of office, with regard to any confidential information which has \ncome to their knowledge in the course of the performance of their tasks \nor exercise of their powers. During their term of office, that duty of \nprofessional secrecy shall in particular apply to reporting by natural \npersons of infringements of this Regulation. \nS e c t i o n 2 \nC o m p e t e n c e , t a s k s a n d p o w e r s \nArticle 55 \nCompetence \n1. \nEach supervisory authority shall be competent for the performance \nof the tasks assigned to and the exercise of the powers conferred on it in \naccordance with this Regulation on the territory of its own Member \nState. \n2. \nWhere processing is carried out by public authorities or private \nbodies acting on the basis of point (c) or (e) of Article 6(1), the super­\nvisory authority of the Member State concerned shall be competent. In \nsuch cases Article 56 does not apply. \n3. \nSupervisory authorities shall not be competent to supervise \nprocessing operations of courts acting in their judicial capacity. \nArticle 56 \nCompetence of the lead supervisory authority \n1. \nWithout prejudice to Article 55, the supervisory authority of the \nmain establishment or of the single establishment of the controller or \nprocessor shall be competent to act as lead supervisory authority for the \ncross-border processing carried out by that controller or processor in \naccordance with the procedure provided in Article 60. \n2. \nBy derogation from paragraph 1, each supervisory authority shall \nbe competent to handle a complaint lodged with it or a possible \ninfringement of this Regulation, if the subject matter relates only to \nan establishment in its Member State or substantially affects data \nsubjects only in its Member State. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 51 \n3. \nIn the cases referred to in paragraph 2 of this Article, the super­\nvisory authority shall inform the lead supervisory authority without \ndelay on that matter. Within a period of three weeks after being \ninformed the lead supervisory authority shall decide whether or not it \nwill handle the case in accordance with the procedure provided in \nArticle 60, taking into account whether or not there is an establishment \nof the controller or processor in the Member State of which the super­\nvisory authority informed it. \n4. \nWhere the lead supervisory authority decides to handle the case, \nthe procedure provided in Article 60 shall apply. The supervisory \nauthority which informed the lead supervisory authority may submit \nto the lead supervisory authority a draft for a decision. The lead super­\nvisory authority shall take utmost account of that draft when preparing \nthe draft decision referred to in Article 60(3). \n5. \nWhere the lead supervisory authority decides not to handle the \ncase, the supervisory authority which informed the lead supervisory \nauthority shall handle it according to Articles 61 and 62. \n6. \nThe lead supervisory authority shall be the sole interlocutor of the \ncontroller or processor for the cross-border processing carried out by \nthat controller or processor. \nArticle 57 \nTasks \n1. \nWithout prejudice to other tasks set out under this Regulation, \neach supervisory authority shall on its territory: \n(a) monitor and enforce the application of this Regulation; \n(b) promote public awareness and understanding of the risks, rules, \nsafeguards and rights in relation to processing. Activities \naddressed specifically to children shall receive specific attention; \n(c) advise, in accordance with Member State law, the national \nparliament, the government, and other institutions and bodies on \nlegislative and administrative measures relating to the protection of \nnatural persons' rights and freedoms with regard to processing; \n(d) promote the awareness of controllers and processors of their obli­\ngations under this Regulation; \n(e) upon request, provide information to any data subject concerning \nthe exercise of their rights under this Regulation and, if appropriate, \ncooperate with the supervisory authorities in other Member States \nto that end; \n(f) handle complaints lodged by a data subject, or by a body, organis­\nation or association in accordance with Article 80, and investigate, \nto the extent appropriate, the subject matter of the complaint and \ninform the complainant of the progress and the outcome of the \ninvestigation within a reasonable period, in particular if further \ninvestigation or coordination with another supervisory authority is \nnecessary; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 52 \n(g) cooperate with, including sharing information and provide mutual \nassistance to, other supervisory authorities with a view to ensuring \nthe consistency of application and enforcement of this Regulation; \n(h) conduct investigations on the application of this Regulation, \nincluding on the basis of information received from another super­\nvisory authority or other public authority; \n(i) monitor relevant developments, insofar as they have an impact on \nthe protection of personal data, in particular the development of \ninformation and communication technologies and commercial \npractices; \n(j) adopt standard contractual clauses referred to in Article 28(8) and \nin point (d) of Article 46(2); \n(k) establish and maintain a list in relation to the requirement for data \nprotection impact assessment pursuant to Article 35(4); \n(l) give advice on the processing operations referred to in \nArticle 36(2); \n(m) encourage the drawing up of codes of conduct pursuant to \nArticle 40(1) and provide an opinion and approve such codes of \nconduct \nwhich \nprovide \nsufficient \nsafeguards, \npursuant \nto \nArticle 40(5); \n(n) encourage the establishment of data protection certification mech­\nanisms and of data protection seals and marks pursuant to \nArticle 42(1), and approve the criteria of certification pursuant to \nArticle 42(5); \n(o) where applicable, carry out a periodic review of certifications \nissued in accordance with Article 42(7); \n▼C1 \n(p) draft and publish the requirements for accreditation of a body for \nmonitoring codes of conduct pursuant to Article 41 and of a certifi­\ncation body pursuant to Article 43; \n▼B \n(q) conduct the accreditation of a body for monitoring codes of \nconduct pursuant to Article 41 and of a certification body \npursuant to Article 43; \n(r) authorise contractual clauses and provisions referred to in \nArticle 46(3); \n(s) approve binding corporate rules pursuant to Article 47; \n(t) contribute to the activities of the Board; \n(u) keep internal records of infringements of this Regulation and of \nmeasures taken in accordance with Article 58(2); and \n(v) fulfil any other tasks related to the protection of personal data. \n2. \nEach supervisory authority shall facilitate the submission of \ncomplaints referred to in point (f) of paragraph 1 by measures such \nas a complaint submission form which can also be completed electroni­\ncally, without excluding other means of communication. \n3. \nThe performance of the tasks of each supervisory authority shall \nbe free of charge for the data subject and, where applicable, for the data \nprotection officer. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 53 \n4. \nWhere requests are manifestly unfounded or excessive, in \nparticular because of their repetitive character, the supervisory \nauthority may charge a reasonable fee based on administrative costs, \nor refuse to act on the request. The supervisory authority shall bear the \nburden of demonstrating the manifestly unfounded or excessive \ncharacter of the request. \nArticle 58 \nPowers \n1. \nEach supervisory authority shall have all of the following inves­\ntigative powers: \n(a) to order the controller and the processor, and, where applicable, the \ncontroller's or the processor's representative to provide any \ninformation it requires for the performance of its tasks; \n(b) to carry out investigations in the form of data protection audits; \n(c) to carry out a review on certifications issued pursuant to \nArticle 42(7); \n(d) to notify the controller or the processor of an alleged infringement \nof this Regulation; \n(e) to obtain, from the controller and the processor, access to all \npersonal data and to all information necessary for the performance \nof its tasks; \n(f) to obtain access to any premises of the controller and the processor, \nincluding to any data processing equipment and means, in \naccordance with Union or Member State procedural law. \n2. \nEach supervisory authority shall have all of the following \ncorrective powers: \n(a) to issue warnings to a controller or processor that intended \nprocessing operations are likely to infringe provisions of this Regu­\nlation; \n(b) to issue reprimands to a controller or a processor where processing \noperations have infringed provisions of this Regulation; \n(c) to order the controller or the processor to comply with the data \nsubject's requests to exercise his or her rights pursuant to this \nRegulation; \n(d) to order the controller or processor to bring processing operations \ninto compliance with the provisions of this Regulation, where \nappropriate, in a specified manner and within a specified period; \n(e) to order the controller to communicate a personal data breach to the \ndata subject; \n(f) to impose a temporary or definitive limitation including a ban on \nprocessing; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 54 \n(g) to order the rectification or erasure of personal data or restriction of \nprocessing pursuant to Articles 16, 17 and 18 and the notification of \nsuch actions to recipients to whom the personal data have been \ndisclosed pursuant to Article 17(2) and Article 19; \n(h) to withdraw a certification or to order the certification body to \nwithdraw a certification issued pursuant to Articles 42 and 43, or \nto order the certification body not to issue certification if the \nrequirements for the certification are not or are no longer met; \n(i) to impose an administrative fine pursuant to Article 83, in addition \nto, or instead of measures referred to in this paragraph, depending \non the circumstances of each individual case; \n(j) to order the suspension of data flows to a recipient in a third \ncountry or to an international organisation. \n3. \nEach supervisory authority shall have all of the following author­\nisation and advisory powers: \n(a) to advise the controller in accordance with the prior consultation \nprocedure referred to in Article 36; \n(b) to issue, on its own initiative or on request, opinions to the national \nparliament, the Member State government or, in accordance with \nMember State law, to other institutions and bodies as well as to the \npublic on any issue related to the protection of personal data; \n(c) to authorise processing referred to in Article 36(5), if the law of the \nMember State requires such prior authorisation; \n(d) to issue an opinion and approve draft codes of conduct pursuant to \nArticle 40(5); \n(e) to accredit certification bodies pursuant to Article 43; \n(f) to issue certifications and approve criteria of certification in \naccordance with Article 42(5); \n(g) to adopt standard data protection clauses referred to in Article 28(8) \nand in point (d) of Article 46(2); \n(h) to authorise contractual clauses referred to in point (a) of \nArticle 46(3); \n(i) to authorise administrative arrangements referred to in point (b) of \nArticle 46(3); \n(j) to approve binding corporate rules pursuant to Article 47. \n4. \nThe exercise of the powers conferred on the supervisory authority \npursuant to this Article shall be subject to appropriate safeguards, \nincluding effective judicial remedy and due process, set out in Union \nand Member State law in accordance with the Charter. \n5. \nEach Member State shall provide by law that its supervisory \nauthority shall have the power to bring infringements of this Regulation \nto the attention of the judicial authorities and where appropriate, to \ncommence or engage otherwise in legal proceedings, in order to \nenforce the provisions of this Regulation. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 55 \n6. \nEach Member State may provide by law that its supervisory \nauthority shall have additional powers to those referred to in para­\ngraphs 1, 2 and 3. The exercise of those powers shall not impair the \neffective operation of Chapter VII. \nArticle 59 \nActivity reports \nEach supervisory authority shall draw up an annual report on its activ­\nities, which may include a list of types of infringement notified and \ntypes of measures taken in accordance with Article 58(2). Those reports \nshall be transmitted to the national parliament, the government and other \nauthorities as designated by Member State law. They shall be made \navailable to the public, to the Commission and to the Board. \nCHAPTER VII \nCooperation and consistency \nS e c t i o n 1 \nC o o p e r a t i o n \nArticle 60 \nCooperation between the lead supervisory authority and the other \nsupervisory authorities concerned \n1. \nThe lead supervisory authority shall cooperate with the other \nsupervisory authorities concerned in accordance with this Article in an \nendeavour to reach consensus. The lead supervisory authority and the \nsupervisory \nauthorities \nconcerned \nshall \nexchange \nall \nrelevant \ninformation with each other. \n2. \nThe lead supervisory authority may request at any time other \nsupervisory authorities concerned to provide mutual assistance \npursuant to Article 61 and may conduct joint operations pursuant to \nArticle 62, in particular for carrying out investigations or for monitoring \nthe implementation of a measure concerning a controller or processor \nestablished in another Member State. \n3. \nThe lead supervisory authority shall, without delay, communicate \nthe relevant information on the matter to the other supervisory auth­\norities concerned. It shall without delay submit a draft decision to the \nother supervisory authorities concerned for their opinion and take due \naccount of their views. \n4. \nWhere any of the other supervisory authorities concerned within a \nperiod of four weeks after having been consulted in accordance with \nparagraph 3 of this Article, expresses a relevant and reasoned objection \nto the draft decision, the lead supervisory authority shall, if it does not \nfollow the relevant and reasoned objection or is of the opinion that the \nobjection is not relevant or reasoned, submit the matter to the \nconsistency mechanism referred to in Article 63. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 56 \n5. \nWhere the lead supervisory authority intends to follow the relevant \nand reasoned objection made, it shall submit to the other supervisory \nauthorities concerned a revised draft decision for their opinion. That \nrevised draft decision shall be subject to the procedure referred to in \nparagraph 4 within a period of two weeks. \n6. \nWhere none of the other supervisory authorities concerned has \nobjected to the draft decision submitted by the lead supervisory \nauthority within the period referred to in paragraphs 4 and 5, the lead \nsupervisory authority and the supervisory authorities concerned shall be \ndeemed to be in agreement with that draft decision and shall be bound \nby it. \n7. \nThe lead supervisory authority shall adopt and notify the decision \nto the main establishment or single establishment of the controller or \nprocessor, as the case may be and inform the other supervisory auth­\norities concerned and the Board of the decision in question, including a \nsummary of the relevant facts and grounds. The supervisory authority \nwith which a complaint has been lodged shall inform the complainant \non the decision. \n8. \nBy derogation from paragraph 7, where a complaint is dismissed \nor rejected, the supervisory authority with which the complaint was \nlodged shall adopt the decision and notify it to the complainant and \nshall inform the controller thereof. \n9. \nWhere the lead supervisory authority and the supervisory auth­\norities concerned agree to dismiss or reject parts of a complaint and \nto act on other parts of that complaint, a separate decision shall be \nadopted for each of those parts of the matter. The lead supervisory \nauthority shall adopt the decision for the part concerning actions in \nrelation to the controller, shall notify it to the main establishment or \nsingle establishment of the controller or processor on the territory of its \nMember State and shall inform the complainant thereof, while the \nsupervisory authority of the complainant shall adopt the decision for \nthe part concerning dismissal or rejection of that complaint, and shall \nnotify it to that complainant and shall inform the controller or processor \nthereof. \n10. \nAfter being notified of the decision of the lead supervisory \nauthority pursuant to paragraphs 7 and 9, the controller or processor \nshall take the necessary measures to ensure compliance with the \ndecision as regards processing activities in the context of all its estab­\nlishments in the Union. The controller or processor shall notify the \nmeasures taken for complying with the decision to the lead supervisory \nauthority, which shall inform the other supervisory authorities \nconcerned. \n11. \nWhere, in exceptional circumstances, a supervisory authority \nconcerned has reasons to consider that there is an urgent need to act \nin order to protect the interests of data subjects, the urgency procedure \nreferred to in Article 66 shall apply. \n12. \nThe lead supervisory authority and the other supervisory auth­\norities concerned shall supply the information required under this \nArticle to each other by electronic means, using a standardised format. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 57 \nArticle 61 \nMutual assistance \n1. \nSupervisory authorities shall provide each other with relevant \ninformation and mutual assistance in order to implement and apply \nthis Regulation in a consistent manner, and shall put in place \nmeasures for effective cooperation with one another. Mutual assistance \nshall cover, in particular, information requests and supervisory \nmeasures, such as requests to carry out prior authorisations and consul­\ntations, inspections and investigations. \n2. \nEach supervisory authority shall take all appropriate measures \nrequired to reply to a request of another supervisory authority without \nundue delay and no later than one month after receiving the request. \nSuch measures may include, in particular, the transmission of relevant \ninformation on the conduct of an investigation. \n3. \nRequests for assistance shall contain all the necessary information, \nincluding the purpose of and reasons for the request. Information \nexchanged shall be used only for the purpose for which it was \nrequested. \n4. \nThe requested supervisory authority shall not refuse to comply \nwith the request unless: \n(a) it is not competent for the subject-matter of the request or for the \nmeasures it is requested to execute; or \n(b) compliance with the request would infringe this Regulation or \nUnion or Member State law to which the supervisory authority \nreceiving the request is subject. \n5. \nThe requested supervisory authority shall inform the requesting \nsupervisory authority of the results or, as the case may be, of the \nprogress of the measures taken in order to respond to the request. \nThe requested supervisory authority shall provide reasons for any \nrefusal to comply with a request pursuant to paragraph 4. \n6. \nRequested supervisory authorities shall, as a rule, supply the \ninformation requested by other supervisory authorities by electronic \nmeans, using a standardised format. \n7. \nRequested supervisory authorities shall not charge a fee for any \naction taken by them pursuant to a request for mutual assistance. Super­\nvisory authorities may agree on rules to indemnify each other for \nspecific expenditure arising from the provision of mutual assistance in \nexceptional circumstances. \n8. \nWhere a supervisory authority does not provide the information \nreferred to in paragraph 5 of this Article within one month of receiving \nthe request of another supervisory authority, the requesting supervisory \nauthority may adopt a provisional measure on the territory of its \nMember State in accordance with Article 55(1). In that case, the \nurgent need to act under Article 66(1) shall be presumed to be met \nand require an urgent binding decision from the Board pursuant to \nArticle 66(2). \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 58 \n9. \nThe Commission may, by means of implementing acts, specify the \nformat and procedures for mutual assistance referred to in this Article \nand the arrangements for the exchange of information by electronic \nmeans between supervisory authorities, and between supervisory auth­\norities and the Board, in particular the standardised format referred to in \nparagraph 6 of this Article. Those implementing acts shall be adopted in \naccordance with the examination procedure referred to in Article 93(2). \nArticle 62 \nJoint operations of supervisory authorities \n1. \nThe supervisory authorities shall, where appropriate, conduct joint \noperations including joint investigations and joint enforcement measures \nin which members or staff of the supervisory authorities of other \nMember States are involved. \n2. \nWhere the controller or processor has establishments in several \nMember States or where a significant number of data subjects in \nmore than one Member State are likely to be substantially affected by \nprocessing operations, a supervisory authority of each of those Member \nStates shall have the right to participate in joint operations. The super­\nvisory authority which is competent pursuant to Article 56(1) or (4) \nshall invite the supervisory authority of each of those Member States \nto take part in the joint operations and shall respond without delay to \nthe request of a supervisory authority to participate. \n3. \nA supervisory authority may, in accordance with Member State \nlaw, and with the seconding supervisory authority's authorisation, confer \npowers, including investigative powers on the seconding supervisory \nauthority's members or staff involved in joint operations or, in so far \nas the law of the Member State of the host supervisory authority \npermits, allow the seconding supervisory authority's members or staff \nto exercise their investigative powers in accordance with the law of the \nMember State of the seconding supervisory authority. Such investigative \npowers may be exercised only under the guidance and in the presence \nof members or staff of the host supervisory authority. The seconding \nsupervisory authority's members or staff shall be subject to the \nMember State law of the host supervisory authority. \n4. \nWhere, in accordance with paragraph 1, staff of a seconding \nsupervisory \nauthority \noperate \nin \nanother \nMember \nState, \nthe \nMember State of the host supervisory authority shall assume responsi­\nbility for their actions, including liability, for any damage caused by \nthem during their operations, in accordance with the law of the \nMember State in whose territory they are operating. \n5. \nThe Member State in whose territory the damage was caused shall \nmake good such damage under the conditions applicable to damage \ncaused by its own staff. The Member State of the seconding supervisory \nauthority whose staff has caused damage to any person in the territory \nof another Member State shall reimburse that other Member State in full \nany sums it has paid to the persons entitled on their behalf. \n6. \nWithout prejudice to the exercise of its rights vis-à-vis third parties \nand with the exception of paragraph 5, each Member State shall refrain, \nin the case provided for in paragraph 1, from requesting reimbursement \nfrom another Member State in relation to damage referred to in \nparagraph 4. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 59 \n7. \nWhere a joint operation is intended and a supervisory authority \ndoes not, within one month, comply with the obligation laid down in \nthe second sentence of paragraph 2 of this Article, the other supervisory \nauthorities may adopt a provisional measure on the territory of its \nMember State in accordance with Article 55. In that case, the urgent \nneed to act under Article 66(1) shall be presumed to be met and require \nan opinion or an urgent binding decision from the Board pursuant to \nArticle 66(2). \nS e c t i o n 2 \nC o n s i s t e n c y \nArticle 63 \nConsistency mechanism \nIn order to contribute to the consistent application of this Regulation \nthroughout the Union, the supervisory authorities shall cooperate with \neach other and, where relevant, with the Commission, through the \nconsistency mechanism as set out in this Section. \nArticle 64 \nOpinion of the Board \n1. \nThe Board shall issue an opinion where a competent supervisory \nauthority intends to adopt any of the measures below. To that end, the \ncompetent supervisory authority shall communicate the draft decision to \nthe Board, when it: \n(a) aims to adopt a list of the processing operations subject to the \nrequirement for a data protection impact assessment pursuant to \nArticle 35(4); \n(b) concerns a matter pursuant to Article 40(7) whether a draft code of \nconduct or an amendment or extension to a code of conduct \ncomplies with this Regulation; \n▼C1 \n(c) aims to approve the requirements for accreditation of a body \npursuant to Article 41(3), of a certification body pursuant to \nArticle 43(3) or the criteria for certification referred to in \nArticle 42(5); \n▼B \n(d) aims to determine standard data protection clauses referred to in \npoint (d) of Article 46(2) and in Article 28(8); \n(e) aims to authorise contractual clauses referred to in point (a) of \nArticle 46(3); or \n(f) aims to approve binding corporate rules within the meaning of \nArticle 47. \n2. \nAny supervisory authority, the Chair of the Board or the \nCommission may request that any matter of general application or \nproducing effects in more than one Member State be examined by the \nBoard with a view to obtaining an opinion, in particular where a \ncompetent supervisory authority does not comply with the obligations \nfor mutual assistance in accordance with Article 61 or for joint oper­\nations in accordance with Article 62. \n▼B\n\n\n02016R0679 — EN — 04.05.2016 — 000.002 — 60 \n3. \nIn the cases referred to in paragraphs 1 and 2, the Board shall \nissue an opinion on the matter submitted to it provided that it has not \nalready issued an opinion on the same matter. That opinion shall be \nadopted within eight weeks by simple majority of the members of the \nBoard. That period may be extended by a further six weeks, taking into \naccount the complexity of the subject matter. Regarding the draft \ndecision referred to in paragraph 1 circulated to the members of the \nBoard in accordance with paragraph 5, a member which has not \nobjected within a reasonable period indicated by the Chair, shall be \ndeemed to be in agreement with the draft decision. \n4. \nSupervisory authorities and the Commission shall, without undue \ndelay, communicate by electronic means to the Board, using a stan­\ndardised format any relevant information, including as the case may \nbe a summary of the facts, the draft decision, the grounds which \nmake the enactment of such measure necessary, and the views of \nother supervisory authorities concerned. \n5. \nThe Chair of the Board shall, without undue, delay inform by \nelectronic means: \n(a) the members of the Board and the Commission of any relevant \ninformation which has been communicated to it using a standardised \nformat. The secretariat of the Board shall, where necessary, provide \ntranslations of relevant information; and \n(b) the supervisory authority referred to, as the case may be, in para­\ngraphs 1 and 2, and the Commission of the opinion and make it \npublic. \n▼C1 \n6. \nThe competent supervisory authority referred to in paragraph 1 \nshall not adopt its draft decision referred to in paragraph 1 within the \nperiod referred to in paragraph 3. \n7. \nThe competent supervisory authority referred to in paragraph 1 \nshall take utmost account of the opinion of the Board and shall, \nwithin two weeks after receiving the opinion, communicate to the \nChair of the Board by electronic means whether it will maintain or \namend its draft decision and, if any, the amended draft decision, \nusing a standardised format. \n8. \nWhere the competent supervisory authority referred to in \nparagraph 1 informs the Chair of the Board within the period referred \nto in paragraph 7 of this Article that it does not intend to follow the \nopinion of the Board, in whole or in part, providing the relevant \ngrounds, Article 65(1) shall apply. \n▼B \nArticle 65 \nDispute resolution by the Board \n1. \nIn order to ensure the correct and consistent application of this \nRegulation in individual cases, the Board shall adopt a binding decision \nin the following cases: \n(a) ►C1 where, in a case referred to in Article 60(4), a supervisory \nauthority concerned has raised a relevant and reasoned objection to \na draft decision of the lead supervisory authority and the lead super­\nvisory authority has not followed the objection or has rejected such \n▼B\n\n\n02016R0679 — EN — 04.05.2016 — 000.002 — 61 \nan objection as being not relevant or reasoned. ◄ The binding \ndecision shall concern all the matters which are the subject of the \nrelevant and reasoned objection, in particular whether there is an \ninfringement of this Regulation; \n(b) where there are conflicting views on which of the supervisory auth­\norities concerned is competent for the main establishment; \n(c) where a competent supervisory authority does not request the \nopinion of the Board in the cases referred to in Article 64(1), or \ndoes not follow the opinion of the Board issued under Article 64. In \nthat case, any supervisory authority concerned or the Commission \nmay communicate the matter to the Board. \n2. \nThe decision referred to in paragraph 1 shall be adopted within \none month from the referral of the subject-matter by a two-thirds \nmajority of the members of the Board. That period may be extended \nby a further month on account of the complexity of the subject-matter. \nThe decision referred to in paragraph 1 shall be reasoned and addressed \nto the lead supervisory authority and all the supervisory authorities \nconcerned and binding on them. \n3. \nWhere the Board has been unable to adopt a decision within the \nperiods referred to in paragraph 2, it shall adopt its decision within two \nweeks following the expiration of the second month referred to in \nparagraph 2 by a simple majority of the members of the Board. \nWhere the members of the Board are split, the decision shall by \nadopted by the vote of its Chair. \n4. \nThe supervisory authorities concerned shall not adopt a decision \non the subject matter submitted to the Board under paragraph 1 during \nthe periods referred to in paragraphs 2 and 3. \n5. \nThe Chair of the Board shall notify, without undue delay, the \ndecision referred to in paragraph 1 to the supervisory authorities \nconcerned. It shall inform the Commission thereof. The decision shall \nbe published on the website of the Board without delay after the super­\nvisory authority has notified the final decision referred to in \nparagraph 6. \n6. \nThe lead supervisory authority or, as the case may be, the super­\nvisory authority with which the complaint has been lodged shall adopt \nits final decision on the basis of the decision referred to in paragraph 1 \nof this Article, without undue delay and at the latest by one month after \nthe Board has notified its decision. The lead supervisory authority or, as \nthe case may be, the supervisory authority with which the complaint has \nbeen lodged, shall inform the Board of the date when its final decision \nis notified respectively to the controller or the processor and to the data \nsubject. The final decision of the supervisory authorities concerned shall \nbe adopted under the terms of Article 60(7), (8) and (9). The final \ndecision shall refer to the decision referred to in paragraph 1 of this \nArticle and shall specify that the decision referred to in that paragraph \nwill be published on the website of the Board in accordance with \nparagraph 5 of this Article. The final decision shall attach the \ndecision referred to in paragraph 1 of this Article. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 62 \nArticle 66 \nUrgency procedure \n1. \nIn exceptional circumstances, where a supervisory authority \nconcerned considers that there is an urgent need to act in order to \nprotect the rights and freedoms of data subjects, it may, by way of \nderogation from the consistency mechanism referred to in Articles 63, \n64 and 65 or the procedure referred to in Article 60, immediately adopt \nprovisional measures intended to produce legal effects on its own \nterritory with a specified period of validity which shall not exceed \nthree months. The supervisory authority shall, without delay, \ncommunicate those measures and the reasons for adopting them to the \nother supervisory authorities concerned, to the Board and to the \nCommission. \n2. \nWhere a supervisory authority has taken a measure pursuant to \nparagraph 1 and considers that final measures need urgently be adopted, \nit may request an urgent opinion or an urgent binding decision from the \nBoard, giving reasons for requesting such opinion or decision. \n3. \nAny supervisory authority may request an urgent opinion or an \nurgent binding decision, as the case may be, from the Board where a \ncompetent supervisory authority has not taken an appropriate measure in \na situation where there is an urgent need to act, in order to protect the \nrights and freedoms of data subjects, giving reasons for requesting such \nopinion or decision, including for the urgent need to act. \n4. \nBy derogation from Article 64(3) and Article 65(2), an urgent \nopinion or an urgent binding decision referred to in paragraphs 2 \nand 3 of this Article shall be adopted within two weeks by simple \nmajority of the members of the Board. \nArticle 67 \nExchange of information \nThe Commission may adopt implementing acts of general scope in \norder to specify the arrangements for the exchange of information by \nelectronic means between supervisory authorities, and between super­\nvisory authorities and the Board, in particular the standardised format \nreferred to in Article 64. \nThose implementing acts shall be adopted in accordance with the exa­\nmination procedure referred to in Article 93(2). \nS e c t i o n 3 \nE u r o p e a n d a t a p r o t e c t i o n b o a r d \nArticle 68 \nEuropean Data Protection Board \n1. \nThe European Data Protection Board (the ‘Board’) is hereby estab­\nlished as a body of the Union and shall have legal personality. \n2. \nThe Board shall be represented by its Chair. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 63 \n3. \nThe Board shall be composed of the head of one supervisory \nauthority of each Member State and of the European Data Protection \nSupervisor, or their respective representatives. \n4. \nWhere in a Member State more than one supervisory authority is \nresponsible for monitoring the application of the provisions pursuant to \nthis Regulation, a joint representative shall be appointed in accordance \nwith that Member State's law. \n5. \nThe Commission shall have the right to participate in the activities \nand meetings of the Board without voting right. The Commission shall \ndesignate a representative. The Chair of the Board shall communicate to \nthe Commission the activities of the Board. \n6. \nIn the cases referred to in Article 65, the European Data Protection \nSupervisor shall have voting rights only on decisions which concern \nprinciples and rules applicable to the Union institutions, bodies, offices \nand agencies which correspond in substance to those of this Regulation. \nArticle 69 \nIndependence \n1. \nThe Board shall act independently when performing its tasks or \nexercising its powers pursuant to Articles 70 and 71. \n▼C1 \n2. \nWithout prejudice to requests by the Commission referred to in \nArticle 70(1) and (2), the Board shall, in the performance of its tasks or \nthe exercise of its powers, neither seek nor take instructions from \nanybody. \n▼B \nArticle 70 \nTasks of the Board \n1. \nThe Board shall ensure the consistent application of this Regu­\nlation. To that end, the Board shall, on its own initiative or, where \nrelevant, at the request of the Commission, in particular: \n(a) monitor and ensure the correct application of this Regulation in the \ncases provided for in Articles 64 and 65 without prejudice to the \ntasks of national supervisory authorities; \n(b) advise the Commission on any issue related to the protection of \npersonal data in the Union, including on any proposed amendment \nof this Regulation; \n(c) advise the Commission on the format and procedures for the \nexchange of information between controllers, processors and super­\nvisory authorities for binding corporate rules; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 64 \n(d) issue \nguidelines, \nrecommendations, \nand \nbest \npractices on \nprocedures for erasing links, copies or replications of personal \ndata from publicly available communication services as referred \nto in Article 17(2); \n(e) examine, on its own initiative, on request of one of its members or \non request of the Commission, any question covering the appli­\ncation of this Regulation and issue guidelines, recommendations \nand best practices in order to encourage consistent application of \nthis Regulation; \n(f) issue guidelines, recommendations and best practices in accordance \nwith point (e) of this paragraph for further specifying the criteria \nand conditions for decisions based on profiling pursuant to \nArticle 22(2); \n(g) issue guidelines, recommendations and best practices in accordance \nwith point (e) of this paragraph for establishing the personal data \nbreaches and determining the undue delay referred to in \nArticle 33(1) and (2) and for the particular circumstances in \nwhich a controller or a processor is required to notify the \npersonal data breach; \n(h) issue guidelines, recommendations and best practices in accordance \nwith point (e) of this paragraph as to the circumstances in which a \npersonal data breach is likely to result in a high risk to the rights \nand freedoms of the natural persons referred to in Article 34(1). \n(i) issue guidelines, recommendations and best practices in accordance \nwith point (e) of this paragraph for the purpose of further spec­\nifying the criteria and requirements for personal data transfers \nbased on binding corporate rules adhered to by controllers and \nbinding corporate rules adhered to by processors and on further \nnecessary requirements to ensure the protection of personal data \nof the data subjects concerned referred to in Article 47; \n(j) issue guidelines, recommendations and best practices in accordance \nwith point (e) of this paragraph for the purpose of further spec­\nifying the criteria and requirements for the personal data transfers \non the basis of Article 49(1); \n(k) draw up guidelines for supervisory authorities concerning the appli­\ncation of measures referred to in Article 58(1), (2) and (3) and the \nsetting of administrative fines pursuant to Article 83; \n▼C1 \n(l) review the practical application of the guidelines, recommendations \nand best practices; \n▼B \n(m) issue guidelines, recommendations and best practices in accordance \nwith point (e) of this paragraph for establishing common \nprocedures for reporting by natural persons of infringements of \nthis Regulation pursuant to Article 54(2); \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 65 \n(n) encourage the drawing-up of codes of conduct and the estab­\nlishment of data protection certification mechanisms and data \nprotection seals and marks pursuant to Articles 40 and 42; \n▼C1 \n(o) approve the criteria of certification pursuant to Article 42(5) and \nmaintain a public register of certification mechanisms and data \nprotection seals and marks pursuant to Article 42(8) and of the \ncertified controllers or processors established in third countries \npursuant to Article 42(7); \n(p) approve the requirements referred to in Article 43(3) with a view to \nthe accreditation of certification bodies referred to in Article 43; \n▼B \n(q) provide the Commission with an opinion on the certification \nrequirements referred to in Article 43(8); \n(r) provide the Commission with an opinion on the icons referred to in \nArticle 12(7); \n(s) provide the Commission with an opinion for the assessment of the \nadequacy of the level of protection in a third country or inter­\nnational organisation, including for the assessment whether a \nthird country, a territory or one or more specified sectors within \nthat third country, or an international organisation no longer \nensures an adequate level of protection. To that end, the \nCommission shall provide the Board with all necessary documen­\ntation, including correspondence with the government of the third \ncountry, with regard to that third country, territory or specified \nsector, or with the international organisation. \n(t) issue opinions on draft decisions of supervisory authorities pursuant \nto the consistency mechanism referred to in Article 64(1), on \nmatters submitted pursuant to Article 64(2) and to issue binding \ndecisions pursuant to Article 65, including in cases referred to in \nArticle 66; \n(u) promote the cooperation and the effective bilateral and multilateral \nexchange of information and best practices between the supervisory \nauthorities; \n(v) promote common training programmes and facilitate personnel \nexchanges between the supervisory authorities and, where appro­\npriate, with the supervisory authorities of third countries or with \ninternational organisations; \n(w) promote the exchange of knowledge and documentation on data \nprotection legislation and practice with data protection supervisory \nauthorities worldwide. \n(x) issue opinions on codes of conduct drawn up at Union level \npursuant to Article 40(9); and \n(y) maintain a publicly accessible electronic register of decisions taken \nby supervisory authorities and courts on issues handled in the \nconsistency mechanism. \n2. \nWhere the Commission requests advice from the Board, it may \nindicate a time limit, taking into account the urgency of the matter. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 66 \n3. \nThe Board shall forward its opinions, guidelines, recommen­\ndations, and best practices to the Commission and to the committee \nreferred to in Article 93 and make them public. \n4. \nThe Board shall, where appropriate, consult interested parties and \ngive them the opportunity to comment within a reasonable period. The \nBoard shall, without prejudice to Article 76, make the results of the \nconsultation procedure publicly available. \nArticle 71 \nReports \n1. \nThe Board shall draw up an annual report regarding the protection \nof natural persons with regard to processing in the Union and, where \nrelevant, in third countries and international organisations. The report \nshall be made public and be transmitted to the European Parliament, to \nthe Council and to the Commission. \n2. \nThe annual report shall include a review of the practical appli­\ncation of the guidelines, recommendations and best practices referred to \nin point (l) of Article 70(1) as well as of the binding decisions referred \nto in Article 65. \nArticle 72 \nProcedure \n1. \nThe Board shall take decisions by a simple majority of its \nmembers, unless otherwise provided for in this Regulation. \n2. \nThe Board shall adopt its own rules of procedure by a two-thirds \nmajority of its members and organise its own operational arrangements. \nArticle 73 \nChair \n1. \nThe Board shall elect a chair and two deputy chairs from amongst \nits members by simple majority. \n2. \nThe term of office of the Chair and of the deputy chairs shall be \nfive years and be renewable once. \nArticle 74 \nTasks of the Chair \n1. \nThe Chair shall have the following tasks: \n(a) to convene the meetings of the Board and prepare its agenda; \n(b) to notify decisions adopted by the Board pursuant to Article 65 to \nthe lead supervisory authority and the supervisory authorities \nconcerned; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 67 \n(c) to ensure the timely performance of the tasks of the Board, in \nparticular in relation to the consistency mechanism referred to in \nArticle 63. \n2. \nThe Board shall lay down the allocation of tasks between the \nChair and the deputy chairs in its rules of procedure. \nArticle 75 \nSecretariat \n1. \nThe Board shall have a secretariat, which shall be provided by the \nEuropean Data Protection Supervisor. \n2. \nThe secretariat shall perform its tasks exclusively under the \ninstructions of the Chair of the Board. \n3. \nThe staff of the European Data Protection Supervisor involved in \ncarrying out the tasks conferred on the Board by this Regulation shall \nbe subject to separate reporting lines from the staff involved in carrying \nout tasks conferred on the European Data Protection Supervisor. \n4. \nWhere appropriate, the Board and the European Data Protection \nSupervisor shall establish and publish a Memorandum of Understanding \nimplementing this Article, determining the terms of their cooperation, \nand applicable to the staff of the European Data Protection Supervisor \ninvolved in carrying out the tasks conferred on the Board by this \nRegulation. \n5. \nThe secretariat shall provide analytical, administrative and \nlogistical support to the Board. \n6. \nThe secretariat shall be responsible in particular for: \n(a) the day-to-day business of the Board; \n(b) communication between the members of the Board, its Chair and \nthe Commission; \n(c) communication with other institutions and the public; \n(d) the use of electronic means for the internal and external \ncommunication; \n(e) the translation of relevant information; \n(f) the preparation and follow-up of the meetings of the Board; \n(g) the preparation, drafting and publication of opinions, decisions on \nthe settlement of disputes between supervisory authorities and other \ntexts adopted by the Board. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 68 \nArticle 76 \nConfidentiality \n1. \nThe discussions of the Board shall be confidential where the \nBoard deems it necessary, as provided for in its rules of procedure. \n2. \nAccess to documents submitted to members of the Board, experts \nand \nrepresentatives \nof \nthird \nparties \nshall \nbe \ngoverned \nby \nRegulation (EC) No 1049/2001 of the European Parliament and of \nthe Council ( \n1 \n). \nCHAPTER VIII \nRemedies, liability and penalties \nArticle 77 \nRight to lodge a complaint with a supervisory authority \n1. \nWithout prejudice to any other administrative or judicial remedy, \nevery data subject shall have the right to lodge a complaint with a \nsupervisory authority, in particular in the Member State of his or her \nhabitual residence, place of work or place of the alleged infringement if \nthe data subject considers that the processing of personal data relating to \nhim or her infringes this Regulation. \n2. \nThe supervisory authority with which the complaint has been \nlodged shall inform the complainant on the progress and the outcome \nof the complaint including the possibility of a judicial remedy pursuant \nto Article 78. \nArticle 78 \nRight to an effective judicial remedy against a supervisory authority \n1. \nWithout prejudice to any other administrative or non-judicial \nremedy, each natural or legal person shall have the right to an \neffective judicial remedy against a legally binding decision of a super­\nvisory authority concerning them. \n2. \nWithout prejudice to any other administrative or non-judicial \nremedy, each data subject shall have the right to a an effective \njudicial remedy where the supervisory authority which is competent \npursuant to Articles 55 and 56 does not handle a complaint or does \nnot inform the data subject within three months on the progress or \noutcome of the complaint lodged pursuant to Article 77. \n3. \nProceedings against a supervisory authority shall be brought \nbefore the courts of the Member State where the supervisory \nauthority is established. \n4. \nWhere proceedings are brought against a decision of a supervisory \nauthority which was preceded by an opinion or a decision of the Board \nin the consistency mechanism, the supervisory authority shall forward \nthat opinion or decision to the court. \n▼B \n( \n1 \n) Regulation (EC) No 1049/2001 of the European Parliament and of the \nCouncil of 30 May 2001 regarding public access to European Parliament, \nCouncil and Commission documents (OJ L 145, 31.5.2001, p. 43).\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 69 \nArticle 79 \nRight to an effective judicial remedy against a controller or \nprocessor \n1. \nWithout prejudice to any available administrative or non-judicial \nremedy, including the right to lodge a complaint with a supervisory \nauthority pursuant to Article 77, each data subject shall have the right \nto an effective judicial remedy where he or she considers that his or her \nrights under this Regulation have been infringed as a result of the \nprocessing of his or her personal data in non-compliance with this \nRegulation. \n2. \nProceedings against a controller or a processor shall be brought \nbefore the courts of the Member State where the controller or processor \nhas an establishment. Alternatively, such proceedings may be brought \nbefore the courts of the Member State where the data subject has his or \nher habitual residence, unless the controller or processor is a public \nauthority of a Member State acting in the exercise of its public powers. \nArticle 80 \nRepresentation of data subjects \n1. \nThe data subject shall have the right to mandate a not-for-profit \nbody, organisation or association which has been properly constituted in \naccordance with the law of a Member State, has statutory objectives \nwhich are in the public interest, and is active in the field of the \nprotection of data subjects' rights and freedoms with regard to the \nprotection of their personal data to lodge the complaint on his or her \nbehalf, to exercise the rights referred to in Articles 77, 78 and 79 on his \nor her behalf, and to exercise the right to receive compensation referred \nto in Article 82 on his or her behalf where provided for by Member State \nlaw. \n2. \nMember States may provide that any body, organisation or asso­\nciation referred to in paragraph 1 of this Article, independently of a data \nsubject's mandate, has the right to lodge, in that Member State, a \ncomplaint with the supervisory authority which is competent pursuant \nto Article 77 and to exercise the rights referred to in Articles 78 and 79 \nif it considers that the rights of a data subject under this Regulation \nhave been infringed as a result of the processing. \nArticle 81 \nSuspension of proceedings \n1. \nWhere a competent court of a Member State has information on \nproceedings, concerning the same subject matter as regards processing \nby the same controller or processor, that are pending in a court in \nanother Member State, it shall contact that court in the other \nMember State to confirm the existence of such proceedings. \n2. \nWhere proceedings concerning the same subject matter as regards \nprocessing of the same controller or processor are pending in a court in \nanother Member State, any competent court other than the court first \nseized may suspend its proceedings. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 70 \n3. \nWhere those proceedings are pending at first instance, any court \nother than the court first seized may also, on the application of one of \nthe parties, decline jurisdiction if the court first seized has jurisdiction \nover the actions in question and its law permits the consolidation \nthereof. \nArticle 82 \nRight to compensation and liability \n1. \nAny person who has suffered material or non-material damage as a \nresult of an infringement of this Regulation shall have the right to \nreceive compensation from the controller or processor for the damage \nsuffered. \n2. \nAny controller involved in processing shall be liable for the \ndamage caused by processing which infringes this Regulation. A \nprocessor shall be liable for the damage caused by processing only \nwhere it has not complied with obligations of this Regulation \nspecifically directed to processors or where it has acted outside or \ncontrary to lawful instructions of the controller. \n3. \nA controller or processor shall be exempt from liability under \nparagraph 2 if it proves that it is not in any way responsible for the \nevent giving rise to the damage. \n4. \nWhere more than one controller or processor, or both a controller \nand a processor, are involved in the same processing and where they \nare, under paragraphs 2 and 3, responsible for any damage caused by \nprocessing, each controller or processor shall be held liable for the \nentire damage in order to ensure effective compensation of the data \nsubject. \n5. \nWhere a controller or processor has, in accordance with \nparagraph 4, paid full compensation for the damage suffered, that \ncontroller or processor shall be entitled to claim back from the other \ncontrollers or processors involved in the same processing that part of the \ncompensation corresponding to their part of responsibility for the \ndamage, in accordance with the conditions set out in paragraph 2. \n6. \nCourt proceedings for exercising the right to receive compensation \nshall be brought before the courts competent under the law of the \nMember State referred to in Article 79(2). \nArticle 83 \nGeneral conditions for imposing administrative fines \n1. \nEach supervisory authority shall ensure that the imposition of \nadministrative fines pursuant to this Article in respect of infringements \nof this Regulation referred to in paragraphs 4, 5 and 6 shall in each \nindividual case be effective, proportionate and dissuasive. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 71 \n2. \nAdministrative fines shall, depending on the circumstances of each \nindividual case, be imposed in addition to, or instead of, measures \nreferred to in points (a) to (h) and (j) of Article 58(2). When \ndeciding whether to impose an administrative fine and deciding on \nthe amount of the administrative fine in each individual case due \nregard shall be given to the following: \n(a) the nature, gravity and duration of the infringement taking into \naccount the nature scope or purpose of the processing concerned \nas well as the number of data subjects affected and the level of \ndamage suffered by them; \n(b) the intentional or negligent character of the infringement; \n(c) any action taken by the controller or processor to mitigate the \ndamage suffered by data subjects; \n(d) the degree of responsibility of the controller or processor taking into \naccount technical and organisational measures implemented by them \npursuant to Articles 25 and 32; \n(e) any relevant previous infringements by the controller or processor; \n(f) the degree of cooperation with the supervisory authority, in order to \nremedy the infringement and mitigate the possible adverse effects of \nthe infringement; \n(g) the categories of personal data affected by the infringement; \n(h) the manner in which the infringement became known to the super­\nvisory authority, in particular whether, and if so to what extent, the \ncontroller or processor notified the infringement; \n(i) where measures referred to in Article 58(2) have previously been \nordered against the controller or processor concerned with regard to \nthe same subject-matter, compliance with those measures; \n(j) adherence to approved codes of conduct pursuant to Article 40 or \napproved certification mechanisms pursuant to Article 42; and \n(k) any other aggravating or mitigating factor applicable to the circum­\nstances of the case, such as financial benefits gained, or losses \navoided, directly or indirectly, from the infringement. \n3. \nIf a controller or processor intentionally or negligently, for the \nsame or linked processing operations, infringes several provisions of \nthis Regulation, the total amount of the administrative fine shall not \nexceed the amount specified for the gravest infringement. \n4. \nInfringements of the following provisions shall, in accordance with \nparagraph 2, be subject to administrative fines up to 10 000 000 EUR, \nor in the case of an undertaking, up to 2 % of the total worldwide \nannual turnover of the preceding financial year, whichever is higher: \n(a) the obligations of the controller and the processor pursuant to \nArticles 8, 11, 25 to 39 and 42 and 43; \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 72 \n(b) the obligations of the certification body pursuant to Articles 42 \nand 43; \n(c) the obligations of the monitoring body pursuant to Article 41(4). \n5. \nInfringements of the following provisions shall, in accordance with \nparagraph 2, be subject to administrative fines up to 20 000 000 EUR, \nor in the case of an undertaking, up to 4 % of the total worldwide \nannual turnover of the preceding financial year, whichever is higher: \n(a) the basic principles for processing, including conditions for consent, \npursuant to Articles 5, 6, 7 and 9; \n(b) the data subjects' rights pursuant to Articles 12 to 22; \n(c) the transfers of personal data to a recipient in a third country or an \ninternational organisation pursuant to Articles 44 to 49; \n(d) any obligations pursuant to Member State law adopted under \nChapter IX; \n(e) non-compliance with an order or a temporary or definitive limitation \non processing or the suspension of data flows by the supervisory \nauthority pursuant to Article 58(2) or failure to provide access in \nviolation of Article 58(1). \n6. \nNon-compliance with an order by the supervisory authority as \nreferred to in Article 58(2) shall, in accordance with paragraph 2 of \nthis Article, be subject to administrative fines up to 20 000 000 EUR, or \nin the case of an undertaking, up to 4 % of the total worldwide annual \nturnover of the preceding financial year, whichever is higher. \n7. \nWithout prejudice to the corrective powers of supervisory auth­\norities pursuant to Article 58(2), each Member State may lay down the \nrules on whether and to what extent administrative fines may be \nimposed on public authorities and bodies established in that \nMember State. \n8. \nThe exercise by the supervisory authority of its powers under this \nArticle shall be subject to appropriate procedural safeguards in \naccordance with Union and Member State law, including effective \njudicial remedy and due process. \n9. \nWhere the legal system of the Member State does not provide for \nadministrative fines, this Article may be applied in such a manner that \nthe fine is initiated by the competent supervisory authority and imposed \nby competent national courts, while ensuring that those legal remedies \nare effective and have an equivalent effect to the administrative fines \nimposed by supervisory authorities. In any event, the fines imposed \nshall be effective, proportionate and dissuasive. Those Member States \nshall notify to the Commission the provisions of their laws which they \nadopt pursuant to this paragraph by 25 May 2018 and, without delay, \nany subsequent amendment law or amendment affecting them. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 73 \nArticle 84 \nPenalties \n1. \nMember States shall lay down the rules on other penalties \napplicable to infringements of this Regulation in particular for \ninfringements which are not subject to administrative fines pursuant to \nArticle 83, and shall take all measures necessary to ensure that they are \nimplemented. Such penalties shall be effective, proportionate and \ndissuasive. \n2. \nEach Member State shall notify to the Commission the provisions \nof its law which it adopts pursuant to paragraph 1, by 25 May 2018 \nand, without delay, any subsequent amendment affecting them. \nCHAPTER IX \nProvisions relating to specific processing situations \nArticle 85 \nProcessing and freedom of expression and information \n1. \nMember States shall by law reconcile the right to the protection of \npersonal data pursuant to this Regulation with the right to freedom of \nexpression and information, including processing for journalistic \npurposes and the purposes of academic, artistic or literary expression. \n2. \nFor processing carried out for journalistic purposes or the purpose \nof academic artistic or literary expression, Member States shall provide \nfor exemptions or derogations from Chapter II (principles), Chapter III \n(rights of the data subject), Chapter IV (controller and processor), \nChapter V (transfer of personal data to third countries or international \norganisations), Chapter VI (independent supervisory authorities), \nChapter VII (cooperation and consistency) and Chapter IX (specific \ndata processing situations) if they are necessary to reconcile the right \nto the protection of personal data with the freedom of expression and \ninformation. \n3. \nEach Member State shall notify to the Commission the provisions \nof its law which it has adopted pursuant to paragraph 2 and, without \ndelay, any subsequent amendment law or amendment affecting them. \nArticle 86 \nProcessing and public access to official documents \nPersonal data in official documents held by a public authority or a \npublic body or a private body for the performance of a task carried \nout in the public interest may be disclosed by the authority or body in \naccordance with Union or Member State law to which the public \nauthority or body is subject in order to reconcile public access to \nofficial documents with the right to the protection of personal data \npursuant to this Regulation. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 74 \nArticle 87 \nProcessing of the national identification number \nMember States may further determine the specific conditions for the \nprocessing of a national identification number or any other identifier \nof general application. In that case the national identification number or \nany other identifier of general application shall be used only under \nappropriate safeguards for the rights and freedoms of the data subject \npursuant to this Regulation. \nArticle 88 \nProcessing in the context of employment \n1. \nMember States may, by law or by collective agreements, provide \nfor more specific rules to ensure the protection of the rights and \nfreedoms in respect of the processing of employees' personal data in \nthe employment context, in particular for the purposes of the \nrecruitment, the performance of the contract of employment, including \ndischarge of obligations laid down by law or by collective agreements, \nmanagement, planning and organisation of work, equality and diversity \nin the workplace, health and safety at work, protection of employer's or \ncustomer's property and for the purposes of the exercise and enjoyment, \non an individual or collective basis, of rights and benefits related to \nemployment, and for the purpose of the termination of the employment \nrelationship. \n2. \nThose rules shall include suitable and specific measures to \nsafeguard the data subject's human dignity, legitimate interests and \nfundamental rights, with particular regard to the transparency of \nprocessing, the transfer of personal data within a group of undertakings, \nor a group of enterprises engaged in a joint economic activity and \nmonitoring systems at the work place. \n3. \nEach Member State shall notify to the Commission those \nprovisions of its law which it adopts pursuant to paragraph 1, by \n25 May 2018 and, without delay, any subsequent amendment \naffecting them. \nArticle 89 \nSafeguards and derogations relating to processing for archiving \npurposes in the public interest, scientific or historical research \npurposes or statistical purposes \n1. \nProcessing for archiving purposes in the public interest, scientific \nor historical research purposes or statistical purposes, shall be subject to \nappropriate safeguards, in accordance with this Regulation, for the rights \nand freedoms of the data subject. Those safeguards shall ensure that \ntechnical and organisational measures are in place in particular in order \nto ensure respect for the principle of data minimisation. Those measures \nmay include pseudonymisation provided that those purposes can be \nfulfilled in that manner. Where those purposes can be fulfilled by \nfurther processing which does not permit or no longer permits the \nidentification of data subjects, those purposes shall be fulfilled in that \nmanner. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 75 \n2. \nWhere personal data are processed for scientific or historical \nresearch purposes or statistical purposes, Union or Member State law \nmay provide for derogations from the rights referred to in Articles 15, \n16, 18 and 21 subject to the conditions and safeguards referred to in \nparagraph 1 of this Article in so far as such rights are likely to render \nimpossible or seriously impair the achievement of the specific purposes, \nand such derogations are necessary for the fulfilment of those purposes. \n3. \nWhere personal data are processed for archiving purposes in the \npublic interest, Union or Member State law may provide for derogations \nfrom the rights referred to in Articles 15, 16, 18, 19, 20 and 21 subject \nto the conditions and safeguards referred to in paragraph 1 of this \nArticle in so far as such rights are likely to render impossible or \nseriously impair the achievement of the specific purposes, and such \nderogations are necessary for the fulfilment of those purposes. \n4. \nWhere processing referred to in paragraphs 2 and 3 serves at the \nsame time another purpose, the derogations shall apply only to \nprocessing for the purposes referred to in those paragraphs. \nArticle 90 \nObligations of secrecy \n1. \nMember States may adopt specific rules to set out the powers of \nthe supervisory authorities laid down in points (e) and (f) of \nArticle 58(1) in relation to controllers or processors that are subject, \nunder Union or Member State law or rules established by national \ncompetent bodies, to an obligation of professional secrecy or other \nequivalent obligations of secrecy where this is necessary and propor­\ntionate to reconcile the right of the protection of personal data with the \nobligation of secrecy. Those rules shall apply only with regard to \npersonal data which the controller or processor has received as a \nresult of or has obtained in an activity covered by that obligation of \nsecrecy. \n2. \nEach Member State shall notify to the Commission the rules \nadopted pursuant to paragraph 1, by 25 May 2018 and, without \ndelay, any subsequent amendment affecting them. \nArticle 91 \nExisting data protection rules of churches and religious associations \n1. \nWhere in a Member State, churches and religious associations or \ncommunities apply, at the time of entry into force of this Regulation, \ncomprehensive rules relating to the protection of natural persons with \nregard to processing, such rules may continue to apply, provided that \nthey are brought into line with this Regulation. \n2. \nChurches and religious associations which apply comprehensive \nrules in accordance with paragraph 1 of this Article shall be subject \nto the supervision of an independent supervisory authority, which may \nbe specific, provided that it fulfils the conditions laid down in \nChapter VI of this Regulation. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 76 \nCHAPTER X \nDelegated acts and implementing acts \nArticle 92 \nExercise of the delegation \n1. \nThe power to adopt delegated acts is conferred on the Commission \nsubject to the conditions laid down in this Article. \n2. \nThe delegation of power referred to in Article 12(8) and \nArticle 43(8) shall be conferred on the Commission for an indeterminate \nperiod of time from 24 May 2016. \n3. \nThe delegation of power referred to in Article 12(8) and \nArticle 43(8) may be revoked at any time by the European Parliament \nor by the Council. A decision of revocation shall put an end to the \ndelegation of power specified in that decision. It shall take effect the \nday following that of its publication in the Official Journal of the \nEuropean Union or at a later date specified therein. It shall not affect \nthe validity of any delegated acts already in force. \n4. \nAs soon as it adopts a delegated act, the Commission shall notify \nit simultaneously to the European Parliament and to the Council. \n5. \nA delegated act adopted pursuant to Article 12(8) and Article 43(8) \nshall enter into force only if no objection has been expressed by either \nthe European Parliament or the Council within a period of three months \nof notification of that act to the European Parliament and the Council or \nif, before the expiry of that period, the European Parliament and the \nCouncil have both informed the Commission that they will not object. \nThat period shall be extended by three months at the initiative of the \nEuropean Parliament or of the Council. \nArticle 93 \nCommittee procedure \n1. \nThe Commission shall be assisted by a committee. That committee \nshall be a committee within the meaning of Regulation (EU) \nNo 182/2011. \n2. \nWhere reference is made to this paragraph, Article 5 of Regu­\nlation (EU) No 182/2011 shall apply. \n3. \nWhere reference is made to this paragraph, Article 8 of Regu­\nlation (EU) No 182/2011, in conjunction with Article 5 thereof, shall \napply. \nCHAPTER XI \nFinal provisions \nArticle 94 \nRepeal of Directive 95/46/EC \n1. \nDirective 95/46/EC is repealed with effect from 25 May 2018. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 77 \n2. \nReferences to the repealed Directive shall be construed as \nreferences to this Regulation. References to the Working Party on the \nProtection of Individuals with regard to the Processing of Personal Data \nestablished by Article 29 of Directive 95/46/EC shall be construed as \nreferences to the European Data Protection Board established by this \nRegulation. \nArticle 95 \nRelationship with Directive 2002/58/EC \nThis Regulation shall not impose additional obligations on natural or \nlegal persons in relation to processing in connection with the provision \nof publicly available electronic communications services in public \ncommunication networks in the Union in relation to matters for which \nthey are subject to specific obligations with the same objective set out in \nDirective 2002/58/EC. \nArticle 96 \nRelationship with previously concluded Agreements \nInternational agreements involving the transfer of personal data to third \ncountries or international organisations which were concluded by \nMember States prior to 24 May 2016, and which comply with Union \nlaw as applicable prior to that date, shall remain in force until amended, \nreplaced or revoked. \nArticle 97 \nCommission reports \n1. \nBy 25 May 2020 and every four years thereafter, the Commission \nshall submit a report on the evaluation and review of this Regulation to \nthe European Parliament and to the Council. The reports shall be made \npublic. \n2. \nIn the context of the evaluations and reviews referred to in \nparagraph 1, the Commission shall examine, in particular, the appli­\ncation and functioning of: \n(a) Chapter V on the transfer of personal data to third countries or \ninternational organisations with particular regard to decisions \nadopted pursuant to Article 45(3) of this Regulation and decisions \nadopted on the basis of Article 25(6) of Directive 95/46/EC; \n(b) Chapter VII on cooperation and consistency. \n3. \nFor the purpose of paragraph 1, the Commission may request \ninformation from Member States and supervisory authorities. \n4. \nIn carrying out the evaluations and reviews referred to in para­\ngraphs 1 and 2, the Commission shall take into account the positions \nand findings of the European Parliament, of the Council, and of other \nrelevant bodies or sources. \n5. \nThe Commission shall, if necessary, submit appropriate proposals \nto amend this Regulation, in particular taking into account of develop­\nments in information technology and in the light of the state of progress \nin the information society. \n▼B\n\n\n \n02016R0679 — EN — 04.05.2016 — 000.002 — 78 \nArticle 98 \nReview of other Union legal acts on data protection \nThe Commission shall, if appropriate, submit legislative proposals with \na view to amending other Union legal acts on the protection of personal \ndata, in order to ensure uniform and consistent protection of natural \npersons with regard to processing. This shall in particular concern the \nrules relating to the protection of natural persons with regard to \nprocessing by Union institutions, bodies, offices and agencies and on \nthe free movement of such data. \nArticle 99 \nEntry into force and application \n1. \nThis Regulation shall enter into force on the twentieth day \nfollowing that of its publication in the Official Journal of the \nEuropean Union. \n2. \nIt shall apply from 25 May 2018. \nThis Regulation shall be binding in its entirety and directly applicable in \nall Member States. \n▼B","difficulty":"easy","domain":"Single-Document QA","length":"short","question":"As a data compliance lawyer for a gaming company, what are the behaviours in your game that do not violate the principles of the GDPR Act and the measures that do not need to be brought to the attention of the business side of the business for additional attention or modification when the game goes overseas?","sub_domain":"Legal"}

Source: https://huggingface.co/datasets/zai-org/LongBench-v2

initial import

Posting: /agents

GET /api/v1/write?intent=publish&task_id=ab3f8207-c785-568d-ab36-4f9e30b1139d&body={url_encoded_text}&agent_name={optional_name}&nonce={optional_random_id}
