benchmarks.wiki / Public workspace

LongBench v2 / 66fea153bb02136c067ca3e7 / As a data compliance lawyer for a gaming company, what are the behaviours in…

Problem

Answer published by the source. Consult the official source to check your work against its answer.

question

As a data compliance lawyer for a gaming company, what are the behaviours in your game that do not violate the principles of the GDPR Act and the measures that do not need to be brought to the attention of the business side of the business for additional attention or modification when the game goes overseas?
context · full text (201,717 characters)
This text is meant purely as a documentation tool and has no legal effect. The Union's institutions do not assume any liability 
for its contents. The authentic versions of the relevant acts, including their preambles, are those published in the Official 
Journal of the European Union and available in EUR-Lex. Those official texts are directly accessible through the links 
embedded in this document 
►B REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL 
of 27 April 2016 
on the protection of natural persons with regard to the processing of personal data and on the free 
movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) 
(Text with EEA relevance) 
(OJ L 119, 4.5.2016, p. 1) 
Corrected by: 
►C1 
Corrigendum, OJ L 127, 23.5.2018, p. 2 (2016/679) 
02016R0679 — EN — 04.05.2016 — 000.002 — 1


02016R0679 — EN — 04.05.2016 — 000.002 — 2 
REGULATION 
(EU) 
2016/679 
OF 
THE 
EUROPEAN 
PARLIAMENT AND OF THE COUNCIL 
of 27 April 2016 
on the protection of natural persons with regard to the processing 
of personal data and on the free movement of such data, and 
repealing Directive 95/46/EC (General Data Protection Regulation) 
(Text with EEA relevance) 
CHAPTER I 
General provisions 
Article 1 
Subject-matter and objectives 
1. 
This Regulation lays down rules relating to the protection of 
natural persons with regard to the processing of personal data and 
rules relating to the free movement of personal data. 
2. 
This Regulation protects fundamental rights and freedoms of 
natural persons and in particular their right to the protection of 
personal data. 
3. 
The free movement of personal data within the Union shall be 
neither restricted nor prohibited for reasons connected with the 
protection of natural persons with regard to the processing of personal 
data. 
Article 2 
Material scope 
1. 
This Regulation applies to the processing of personal data wholly 
or partly by automated means and to the processing other than by 
automated means of personal data which form part of a filing system 
or are intended to form part of a filing system. 
2. 
This Regulation does not apply to the processing of personal data: 
(a) in the course of an activity which falls outside the scope of Union 
law; 
(b) by the Member States when carrying out activities which fall within 
the scope of Chapter 2 of Title V of the TEU; 
(c) by a natural person in the course of a purely personal or household 
activity; 
(d) by competent authorities for the purposes of the prevention, inves­
tigation, detection or prosecution of criminal offences or the 
execution of criminal penalties, including the safeguarding against 
and the prevention of threats to public security. 
3. 
For the processing of personal data by the Union institutions, 
bodies, offices and agencies, Regulation (EC) No 45/2001 applies. 
Regulation (EC) No 45/2001 and other Union legal acts applicable to 
such processing of personal data shall be adapted to the principles and 
rules of this Regulation in accordance with Article 98. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 3 
4. 
This Regulation shall be without prejudice to the application of 
Directive 2000/31/EC, in particular of the liability rules of intermediary 
service providers in Articles 12 to 15 of that Directive. 
Article 3 
Territorial scope 
1. 
This Regulation applies to the processing of personal data in the 
context of the activities of an establishment of a controller or a 
processor in the Union, regardless of whether the processing takes 
place in the Union or not. 
2. 
This Regulation applies to the processing of personal data of data 
subjects who are in the Union by a controller or processor not estab­
lished in the Union, where the processing activities are related to: 
(a) the offering of goods or services, irrespective of whether a payment 
of the data subject is required, to such data subjects in the Union; or 
(b) the monitoring of their behaviour as far as their behaviour takes 
place within the Union. 
3. 
This Regulation applies to the processing of personal data by a 
controller not established in the Union, but in a place where 
Member State law applies by virtue of public international law. 
Article 4 
Definitions 
For the purposes of this Regulation: 
(1) ‘personal data’ means any information relating to an identified or 
identifiable natural person (‘data subject’); an identifiable natural 
person is one who can be identified, directly or indirectly, in 
particular by reference to an identifier such as a name, an identi­
fication number, location data, an online identifier or to one or 
more factors specific to the physical, physiological, genetic, 
mental, economic, cultural or social identity of that natural person; 
(2) ‘processing’ means any operation or set of operations which is 
performed on personal data or on sets of personal data, whether 
or not by automated means, such as collection, recording, organi­
sation, structuring, storage, adaptation or alteration, retrieval, 
consultation, use, disclosure by transmission, dissemination or 
otherwise making available, alignment or combination, restriction, 
erasure or destruction; 
(3) ‘restriction of processing’ means the marking of stored personal 
data with the aim of limiting their processing in the future; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 4 
(4) ‘profiling’ means any form of automated processing of personal 
data consisting of the use of personal data to evaluate certain 
personal aspects relating to a natural person, in particular to 
analyse or predict aspects concerning that natural person's 
performance at work, economic situation, health, personal prefer­
ences, interests, reliability, behaviour, location or movements; 
(5) ‘pseudonymisation’ means the processing of personal data in such 
a manner that the personal data can no longer be attributed to a 
specific data subject without the use of additional information, 
provided that such additional information is kept separately and 
is subject to technical and organisational measures to ensure that 
the personal data are not attributed to an identified or identifiable 
natural person; 
(6) ‘filing system’ means any structured set of personal data which are 
accessible according to specific criteria, whether centralised, 
decentralised or dispersed on a functional or geographical basis; 
(7) ‘controller’ means the natural or legal person, public authority, 
agency or other body which, alone or jointly with others, 
determines the purposes and means of the processing of personal 
data; where the purposes and means of such processing are 
determined by Union or Member State law, the controller or the 
specific criteria for its nomination may be provided for by Union 
or Member State law; 
(8) ‘processor’ means a natural or legal person, public authority, 
agency or other body which processes personal data on behalf of 
the controller; 
(9) ‘recipient’ means a natural or legal person, public authority, 
agency or another body, to which the personal data are disclosed, 
whether a third party or not. However, public authorities which 
may receive personal data in the framework of a particular inquiry 
in accordance with Union or Member State law shall not be 
regarded as recipients; the processing of those data by those 
public authorities shall be in compliance with the applicable data 
protection rules according to the purposes of the processing; 
(10) ‘third party’ means a natural or legal person, public authority, 
agency or body other than the data subject, controller, processor 
and persons who, under the direct authority of the controller or 
processor, are authorised to process personal data; 
(11) ‘consent’ of the data subject means any freely given, specific, 
informed and unambiguous indication of the data subject's 
wishes by which he or she, by a statement or by a clear affirmative 
action, signifies agreement to the processing of personal data 
relating to him or her; 
(12) ‘personal data breach’ means a breach of security leading to the 
accidental or unlawful destruction, loss, alteration, unauthorised 
disclosure of, or access to, personal data transmitted, stored or 
otherwise processed; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 5 
(13) ‘genetic data’ means personal data relating to the inherited or 
acquired genetic characteristics of a natural person which give 
unique information about the physiology or the health of that 
natural person and which result, in particular, from an analysis 
of a biological sample from the natural person in question; 
(14) ‘biometric data’ means personal data resulting from specific 
technical processing relating to the physical, physiological or 
behavioural characteristics of a natural person, which allow or 
confirm the unique identification of that natural person, such as 
facial images or dactyloscopic data; 
(15) ‘data concerning health’ means personal data related to the 
physical or mental health of a natural person, including the 
provision of health care services, which reveal information about 
his or her health status; 
(16) ‘main establishment’ means: 
(a) as regards a controller with establishments in more than one 
Member State, the place of its central administration in the 
Union, unless the decisions on the purposes and means of 
the processing of personal data are taken in another estab­
lishment of the controller in the Union and the latter estab­
lishment has the power to have such decisions implemented, in 
which case the establishment having taken such decisions is to 
be considered to be the main establishment; 
(b) as regards a processor with establishments in more than one 
Member State, the place of its central administration in the 
Union, or, if the processor has no central administration in 
the Union, the establishment of the processor in the Union 
where the main processing activities in the context of the 
activities of an establishment of the processor take place to 
the extent that the processor is subject to specific obligations 
under this Regulation; 
(17) ‘representative’ means a natural or legal person established in the 
Union who, designated by the controller or processor in writing 
pursuant to Article 27, represents the controller or processor with 
regard to their respective obligations under this Regulation; 
(18) ‘enterprise’ means a natural or legal person engaged in an 
economic activity, irrespective of its legal form, including part­
nerships or associations regularly engaged in an economic activity; 
(19) ‘group of undertakings’ means a controlling undertaking and its 
controlled undertakings; 
(20) ‘binding corporate rules’ means personal data protection policies 
which are adhered to by a controller or processor established on 
the territory of a Member State for transfers or a set of transfers of 
personal data to a controller or processor in one or more third 
countries within a group of undertakings, or group of enterprises 
engaged in a joint economic activity; 
(21) ‘supervisory authority’ means an independent public authority 
which is established by a Member State pursuant to Article 51; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 6 
(22) ‘supervisory authority concerned’ means a supervisory authority 
which is concerned by the processing of personal data because: 
(a) the controller or processor is established on the territory of the 
Member State of that supervisory authority; 
(b) data subjects residing in the Member State of that supervisory 
authority are substantially affected or likely to be substantially 
affected by the processing; or 
(c) a complaint has been lodged with that supervisory authority; 
(23) ‘cross-border processing’ means either: 
(a) processing of personal data which takes place in the context of 
the activities of establishments in more than one Member State 
of a controller or processor in the Union where the controller 
or processor is established in more than one Member State; or 
(b) processing of personal data which takes place in the context of 
the activities of a single establishment of a controller or 
processor in the Union but which substantially affects or is 
likely to substantially affect data subjects in more than one 
Member State. 
(24) ‘relevant and reasoned objection’ means an objection to a draft 
decision as to whether there is an infringement of this Regulation, 
or whether envisaged action in relation to the controller or 
processor complies with this Regulation, which clearly demon­
strates the significance of the risks posed by the draft decision 
as regards the fundamental rights and freedoms of data subjects 
and, where applicable, the free flow of personal data within the 
Union; 
(25) ‘information society service’ means a service as defined in 
point (b) of Article 1(1) of Directive (EU) 2015/1535 of the 
European Parliament and of the Council ( 
1 
); 
(26) ‘international organisation’ means an organisation and its 
subordinate bodies governed by public international law, or any 
other body which is set up by, or on the basis of, an agreement 
between two or more countries. 
CHAPTER II 
Principles 
Article 5 
Principles relating to processing of personal data 
1. 
Personal data shall be: 
(a) processed lawfully, fairly and in a transparent manner in relation to 
the data subject (‘lawfulness, fairness and transparency’); 
▼B 
( 
1 
) Directive (EU) 2015/1535 of the European Parliament and of the Council of 
9 September 2015 laying down a procedure for the provision of information 
in the field of technical regulations and of rules on Information Society 
services (OJ L 241, 17.9.2015, p. 1).


 
02016R0679 — EN — 04.05.2016 — 000.002 — 7 
(b) collected for specified, explicit and legitimate purposes and not 
further processed in a manner that is incompatible with those 
purposes; further processing for archiving purposes in the public 
interest, scientific or historical research purposes or statistical 
purposes shall, in accordance with Article 89(1), not be considered 
to be incompatible with the initial purposes (‘purpose limitation’); 
(c) adequate, relevant and limited to what is necessary in relation to the 
purposes for which they are processed (‘data minimisation’); 
(d) accurate and, where necessary, kept up to date; every reasonable 
step must be taken to ensure that personal data that are inaccurate, 
having regard to the purposes for which they are processed, are 
erased or rectified without delay (‘accuracy’); 
(e) kept in a form which permits identification of data subjects for no 
longer than is necessary for the purposes for which the personal 
data are processed; personal data may be stored for longer periods 
insofar as the personal data will be processed solely for archiving 
purposes in the public interest, scientific or historical research 
purposes or statistical purposes in accordance with Article 89(1) 
subject to implementation of the appropriate technical and organi­
sational measures required by this Regulation in order to safeguard 
the rights and freedoms of the data subject (‘storage limitation’); 
(f) processed in a manner that ensures appropriate security of the 
personal data, including protection against unauthorised or 
unlawful processing and against accidental loss, destruction or 
damage, using appropriate technical or organisational measures 
(‘integrity and confidentiality’). 
2. 
The controller shall be responsible for, and be able to demonstrate 
compliance with, paragraph 1 (‘accountability’). 
Article 6 
Lawfulness of processing 
1. 
Processing shall be lawful only if and to the extent that at least 
one of the following applies: 
(a) the data subject has given consent to the processing of his or her 
personal data for one or more specific purposes; 
(b) processing is necessary for the performance of a contract to which 
the data subject is party or in order to take steps at the request of 
the data subject prior to entering into a contract; 
(c) processing is necessary for compliance with a legal obligation to 
which the controller is subject; 
(d) processing is necessary in order to protect the vital interests of the 
data subject or of another natural person; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 8 
(e) processing is necessary for the performance of a task carried out in 
the public interest or in the exercise of official authority vested in 
the controller; 
(f) processing is necessary for the purposes of the legitimate interests 
pursued by the controller or by a third party, except where such 
interests are overridden by the interests or fundamental rights and 
freedoms of the data subject which require protection of personal 
data, in particular where the data subject is a child. 
Point (f) of the first subparagraph shall not apply to processing carried 
out by public authorities in the performance of their tasks. 
2. 
Member States may maintain or introduce more specific provisions 
to adapt the application of the rules of this Regulation with regard to 
processing for compliance with points (c) and (e) of paragraph 1 by 
determining more precisely specific requirements for the processing and 
other measures to ensure lawful and fair processing including for other 
specific processing situations as provided for in Chapter IX. 
3. 
The basis for the processing referred to in point (c) and (e) of 
paragraph 1 shall be laid down by: 
(a) Union law; or 
(b) Member State law to which the controller is subject. 
The purpose of the processing shall be determined in that legal basis or, 
as regards the processing referred to in point (e) of paragraph 1, shall be 
necessary for the performance of a task carried out in the public interest 
or in the exercise of official authority vested in the controller. That legal 
basis may contain specific provisions to adapt the application of rules of 
this Regulation, inter alia: the general conditions governing the 
lawfulness of processing by the controller; the types of data which 
are subject to the processing; the data subjects concerned; the entities 
to, and the purposes for which, the personal data may be disclosed; the 
purpose limitation; storage periods; and processing operations and 
processing procedures, including measures to ensure lawful and fair 
processing such as those for other specific processing situations as 
provided for in Chapter IX. The Union or the Member State law 
shall meet an objective of public interest and be proportionate to the 
legitimate aim pursued. 
4. 
Where the processing for a purpose other than that for which the 
personal data have been collected is not based on the data subject's 
consent or on a Union or Member State law which constitutes a 
necessary and proportionate measure in a democratic society to 
safeguard the objectives referred to in Article 23(1), the controller 
shall, in order to ascertain whether processing for another purpose is 
compatible with the purpose for which the personal data are initially 
collected, take into account, inter alia: 
(a) any link between the purposes for which the personal data have 
been collected and the purposes of the intended further processing; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 9 
(b) the context in which the personal data have been collected, in 
particular regarding the relationship between data subjects and the 
controller; 
(c) the nature of the personal data, in particular whether special 
categories of personal data are processed, pursuant to Article 9, or 
whether personal data related to criminal convictions and offences 
are processed, pursuant to Article 10; 
(d) the possible consequences of the intended further processing for 
data subjects; 
(e) the existence of appropriate safeguards, which may include 
encryption or pseudonymisation. 
Article 7 
Conditions for consent 
1. 
Where processing is based on consent, the controller shall be able 
to demonstrate that the data subject has consented to processing of his 
or her personal data. 
2. 
If the data subject's consent is given in the context of a written 
declaration which also concerns other matters, the request for consent 
shall be presented in a manner which is clearly distinguishable from the 
other matters, in an intelligible and easily accessible form, using clear 
and plain language. Any part of such a declaration which constitutes an 
infringement of this Regulation shall not be binding. 
3. 
The data subject shall have the right to withdraw his or her 
consent at any time. The withdrawal of consent shall not affect the 
lawfulness of processing based on consent before its withdrawal. Prior 
to giving consent, the data subject shall be informed thereof. It shall be 
as easy to withdraw as to give consent. 
4. 
When assessing whether consent is freely given, utmost account 
shall be taken of whether, inter alia, the performance of a contract, 
including the provision of a service, is conditional on consent to the 
processing of personal data that is not necessary for the performance of 
that contract. 
Article 8 
Conditions applicable to child's consent in relation to information 
society services 
1. 
Where point (a) of Article 6(1) applies, in relation to the offer of 
information society services directly to a child, the processing of the 
personal data of a child shall be lawful where the child is at least 16 
years old. Where the child is below the age of 16 years, such processing 
shall be lawful only if and to the extent that consent is given or auth­
orised by the holder of parental responsibility over the child. 
Member States may provide by law for a lower age for those purposes 
provided that such lower age is not below 13 years. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 10 
2. 
The controller shall make reasonable efforts to verify in such cases 
that consent is given or authorised by the holder of parental responsi­
bility over the child, taking into consideration available technology. 
3. 
Paragraph 1 shall not affect the general contract law of Member 
States such as the rules on the validity, formation or effect of a contract 
in relation to a child. 
Article 9 
Processing of special categories of personal data 
1. 
Processing of personal data revealing racial or ethnic origin, 
political opinions, religious or philosophical beliefs, or trade union 
membership, and the processing of genetic data, biometric data for 
the purpose of uniquely identifying a natural person, data concerning 
health or data concerning a natural person's sex life or sexual orientation 
shall be prohibited. 
2. 
Paragraph 1 shall not apply if one of the following applies: 
(a) the data subject has given explicit consent to the processing of those 
personal data for one or more specified purposes, except where 
Union or Member State law provide that the prohibition referred 
to in paragraph 1 may not be lifted by the data subject; 
(b) processing is necessary for the purposes of carrying out the obli­
gations and exercising specific rights of the controller or of the data 
subject in the field of employment and social security and social 
protection law in so far as it is authorised by Union or Member 
State law or a collective agreement pursuant to Member State law 
providing for appropriate safeguards for the fundamental rights and 
the interests of the data subject; 
(c) processing is necessary to protect the vital interests of the data 
subject or of another natural person where the data subject is 
physically or legally incapable of giving consent; 
(d) processing is carried out in the course of its legitimate activities 
with appropriate safeguards by a foundation, association or any 
other not-for-profit body with a political, philosophical, religious 
or trade union aim and on condition that the processing relates 
solely to the members or to former members of the body or to 
persons who have regular contact with it in connection with its 
purposes and that the personal data are not disclosed outside that 
body without the consent of the data subjects; 
(e) processing relates to personal data which are manifestly made 
public by the data subject; 
(f) processing is necessary for the establishment, exercise or defence of 
legal claims or whenever courts are acting in their judicial capacity; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 11 
(g) processing is necessary for reasons of substantial public interest, on 
the basis of Union or Member State law which shall be propor­
tionate to the aim pursued, respect the essence of the right to data 
protection and provide for suitable and specific measures to 
safeguard the fundamental rights and the interests of the data 
subject; 
(h) processing is necessary for the purposes of preventive or occupa­
tional medicine, for the assessment of the working capacity of the 
employee, medical diagnosis, the provision of health or social care 
or treatment or the management of health or social care systems and 
services on the basis of Union or Member State law or pursuant to 
contract with a health professional and subject to the conditions and 
safeguards referred to in paragraph 3; 
(i) processing is necessary for reasons of public interest in the area of 
public health, such as protecting against serious cross-border threats 
to health or ensuring high standards of quality and safety of health 
care and of medicinal products or medical devices, on the basis of 
Union or Member State law which provides for suitable and specific 
measures to safeguard the rights and freedoms of the data subject, in 
particular professional secrecy; 
(j) processing is necessary for archiving purposes in the public interest, 
scientific or historical research purposes or statistical purposes in 
accordance with Article 89(1) based on Union or Member State law 
which shall be proportionate to the aim pursued, respect the essence 
of the right to data protection and provide for suitable and specific 
measures to safeguard the fundamental rights and the interests of the 
data subject. 
3. 
Personal data referred to in paragraph 1 may be processed for the 
purposes referred to in point (h) of paragraph 2 when those data are 
processed by or under the responsibility of a professional subject to the 
obligation of professional secrecy under Union or Member State law or 
rules established by national competent bodies or by another person also 
subject to an obligation of secrecy under Union or Member State law or 
rules established by national competent bodies. 
4. 
Member States may maintain or introduce further conditions, 
including limitations, with regard to the processing of genetic data, 
biometric data or data concerning health. 
Article 10 
Processing of personal data relating to criminal convictions and 
offences 
Processing of personal data relating to criminal convictions and offences 
or related security measures based on Article 6(1) shall be carried out 
only under the control of official authority or when the processing is 
authorised by Union or Member State law providing for appropriate 
safeguards for the rights and freedoms of data subjects. Any compre­
hensive register of criminal convictions shall be kept only under the 
control of official authority. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 12 
Article 11 
Processing which does not require identification 
1. 
If the purposes for which a controller processes personal data do 
not or do no longer require the identification of a data subject by the 
controller, the controller shall not be obliged to maintain, acquire or 
process additional information in order to identify the data subject for 
the sole purpose of complying with this Regulation. 
2. 
Where, in cases referred to in paragraph 1 of this Article, the 
controller is able to demonstrate that it is not in a position to identify 
the data subject, the controller shall inform the data subject accordingly, 
if possible. In such cases, Articles 15 to 20 shall not apply except where 
the data subject, for the purpose of exercising his or her rights under 
those articles, provides additional information enabling his or her 
identification. 
CHAPTER III 
Rights of the data subject 
S e c t i o n 1 
T r a n s p a r e n c y a n d m o d a l i t i e s 
Article 12 
Transparent information, communication and modalities for the 
exercise of the rights of the data subject 
1. 
The controller shall take appropriate measures to provide any 
information referred to in Articles 13 and 14 and any communication 
under Articles 15 to 22 and 34 relating to processing to the data subject 
in a concise, transparent, intelligible and easily accessible form, using 
clear and plain language, in particular for any information addressed 
specifically to a child. The information shall be provided in writing, or 
by other means, including, where appropriate, by electronic means. 
When requested by the data subject, the information may be provided 
orally, provided that the identity of the data subject is proven by other 
means. 
2. 
The controller shall facilitate the exercise of data subject rights 
under Articles 15 to 22. In the cases referred to in Article 11(2), the 
controller shall not refuse to act on the request of the data subject for 
exercising his or her rights under Articles 15 to 22, unless the controller 
demonstrates that it is not in a position to identify the data subject. 
3. 
The controller shall provide information on action taken on a 
request under Articles 15 to 22 to the data subject without undue 
delay and in any event within one month of receipt of the request. 
That period may be extended by two further months where necessary, 
taking into account the complexity and number of the requests. The 
controller shall inform the data subject of any such extension within 
one month of receipt of the request, together with the reasons for the 
delay. Where the data subject makes the request by electronic form 
means, the information shall be provided by electronic means where 
possible, unless otherwise requested by the data subject. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 13 
4. 
If the controller does not take action on the request of the data 
subject, the controller shall inform the data subject without delay and at 
the latest within one month of receipt of the request of the reasons for 
not taking action and on the possibility of lodging a complaint with a 
supervisory authority and seeking a judicial remedy. 
5. 
Information provided under Articles 13 and 14 and any communi­
cation and any actions taken under Articles 15 to 22 and 34 shall be 
provided free of charge. Where requests from a data subject are mani­
festly unfounded or excessive, in particular because of their repetitive 
character, the controller may either: 
(a) charge a reasonable fee taking into account the administrative costs 
of providing the information or communication or taking the action 
requested; or 
(b) refuse to act on the request. 
The controller shall bear the burden of demonstrating the manifestly 
unfounded or excessive character of the request. 
6. 
Without prejudice to Article 11, where the controller has 
reasonable doubts concerning the identity of the natural person 
making the request referred to in Articles 15 to 21, the controller 
may request the provision of additional information necessary to 
confirm the identity of the data subject. 
7. 
The information to be provided to data subjects pursuant to 
Articles 13 and 14 may be provided in combination with standardised 
icons in order to give in an easily visible, intelligible and clearly legible 
manner a meaningful overview of the intended processing. Where the 
icons are presented electronically they shall be machine-readable. 
8. 
The Commission shall be empowered to adopt delegated acts in 
accordance with Article 92 for the purpose of determining the 
information to be presented by the icons and the procedures for 
providing standardised icons. 
S e c t i o n 2 
I n f o r m a t i o n a n d a c c e s s t o p e r s o n a l d a t a 
Article 13 
Information to be provided where personal data are collected from 
the data subject 
1. 
Where personal data relating to a data subject are collected from 
the data subject, the controller shall, at the time when personal data are 
obtained, provide the data subject with all of the following information: 
(a) the identity and the contact details of the controller and, where 
applicable, of the controller's representative; 
(b) the contact details of the data protection officer, where applicable; 
(c) the purposes of the processing for which the personal data are 
intended as well as the legal basis for the processing; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 14 
(d) where the processing is based on point (f) of Article 6(1), the 
legitimate interests pursued by the controller or by a third party; 
(e) the recipients or categories of recipients of the personal data, if any; 
(f) where applicable, the fact that the controller intends to transfer 
personal data to a third country or international organisation and 
the existence or absence of an adequacy decision by the 
Commission, or in the case of transfers referred to in Article 46 
or 47, or the second subparagraph of Article 49(1), reference to the 
appropriate or suitable safeguards and the means by which to obtain 
a copy of them or where they have been made available. 
2. 
In addition to the information referred to in paragraph 1, the 
controller shall, at the time when personal data are obtained, provide 
the data subject with the following further information necessary to 
ensure fair and transparent processing: 
(a) the period for which the personal data will be stored, or if that is not 
possible, the criteria used to determine that period; 
(b) the existence of the right to request from the controller access to 
and rectification or erasure of personal data or restriction of 
processing concerning the data subject or to object to processing 
as well as the right to data portability; 
(c) where the processing is based on point (a) of Article 6(1) or 
point (a) of Article 9(2), the existence of the right to withdraw 
consent at any time, without affecting the lawfulness of processing 
based on consent before its withdrawal; 
(d) the right to lodge a complaint with a supervisory authority; 
(e) whether the provision of personal data is a statutory or contractual 
requirement, or a requirement necessary to enter into a contract, as 
well as whether the data subject is obliged to provide the personal 
data and of the possible consequences of failure to provide such 
data; 
(f) the existence of automated decision-making, including profiling, 
referred to in Article 22(1) and (4) and, at least in those cases, 
meaningful information about the logic involved, as well as the 
significance and the envisaged consequences of such processing 
for the data subject. 
3. 
Where the controller intends to further process the personal data 
for a purpose other than that for which the personal data were collected, 
the controller shall provide the data subject prior to that further 
processing with information on that other purpose and with any 
relevant further information as referred to in paragraph 2. 
4. 
Paragraphs 1, 2 and 3 shall not apply where and insofar as the 
data subject already has the information. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 15 
Article 14 
Information to be provided where personal data have not been 
obtained from the data subject 
1. 
Where personal data have not been obtained from the data subject, 
the controller shall provide the data subject with the following 
information: 
(a) the identity and the contact details of the controller and, where 
applicable, of the controller's representative; 
(b) the contact details of the data protection officer, where applicable; 
(c) the purposes of the processing for which the personal data are 
intended as well as the legal basis for the processing; 
(d) the categories of personal data concerned; 
(e) the recipients or categories of recipients of the personal data, if any; 
(f) where applicable, that the controller intends to transfer personal data 
to a recipient in a third country or international organisation and the 
existence or absence of an adequacy decision by the Commission, 
or in the case of transfers referred to in Article 46 or 47, or the 
second subparagraph of Article 49(1), reference to the appropriate 
or suitable safeguards and the means to obtain a copy of them or 
where they have been made available. 
2. 
In addition to the information referred to in paragraph 1, the 
controller shall provide the data subject with the following information 
necessary to ensure fair and transparent processing in respect of the data 
subject: 
(a) the period for which the personal data will be stored, or if that is not 
possible, the criteria used to determine that period; 
(b) where the processing is based on point (f) of Article 6(1), the 
legitimate interests pursued by the controller or by a third party; 
(c) the existence of the right to request from the controller access to 
and rectification or erasure of personal data or restriction of 
processing concerning the data subject and to object to processing 
as well as the right to data portability; 
(d) where processing is based on point (a) of Article 6(1) or point (a) of 
Article 9(2), the existence of the right to withdraw consent at any 
time, without affecting the lawfulness of processing based on 
consent before its withdrawal; 
(e) the right to lodge a complaint with a supervisory authority; 
(f) from which source the personal data originate, and if applicable, 
whether it came from publicly accessible sources; 
(g) the existence of automated decision-making, including profiling, 
referred to in Article 22(1) and (4) and, at least in those cases, 
meaningful information about the logic involved, as well as the 
significance and the envisaged consequences of such processing 
for the data subject. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 16 
3. 
The controller shall provide the information referred to in para­
graphs 1 and 2: 
(a) within a reasonable period after obtaining the personal data, but at 
the latest within one month, having regard to the specific circum­
stances in which the personal data are processed; 
(b) if the personal data are to be used for communication with the data 
subject, at the latest at the time of the first communication to that 
data subject; or 
(c) if a disclosure to another recipient is envisaged, at the latest when 
the personal data are first disclosed. 
4. 
Where the controller intends to further process the personal data 
for a purpose other than that for which the personal data were obtained, 
the controller shall provide the data subject prior to that further 
processing with information on that other purpose and with any 
relevant further information as referred to in paragraph 2. 
5. 
Paragraphs 1 to 4 shall not apply where and insofar as: 
(a) the data subject already has the information; 
(b) the provision of such information proves impossible or would 
involve a disproportionate effort, in particular for processing for 
archiving purposes in the public interest, scientific or historical 
research purposes or statistical purposes, subject to the conditions 
and safeguards referred to in Article 89(1) or in so far as the 
obligation referred to in paragraph 1 of this Article is likely to 
render impossible or seriously impair the achievement of the 
objectives of that processing. In such cases the controller shall 
take appropriate measures to protect the data subject's rights and 
freedoms and legitimate interests, including making the information 
publicly available; 
(c) obtaining or disclosure is expressly laid down by Union or 
Member State law to which the controller is subject and which 
provides appropriate measures to protect the data subject's legitimate 
interests; or 
(d) where the personal data must remain confidential subject to an 
obligation of professional secrecy regulated by Union or 
Member State law, including a statutory obligation of secrecy. 
Article 15 
Right of access by the data subject 
1. 
The data subject shall have the right to obtain from the controller 
confirmation as to whether or not personal data concerning him or her 
are being processed, and, where that is the case, access to the personal 
data and the following information: 
(a) the purposes of the processing; 
(b) the categories of personal data concerned; 
(c) the recipients or categories of recipient to whom the personal data 
have been or will be disclosed, in particular recipients in third 
countries or international organisations; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 17 
(d) where possible, the envisaged period for which the personal data 
will be stored, or, if not possible, the criteria used to determine that 
period; 
(e) the existence of the right to request from the controller rectification 
or erasure of personal data or restriction of processing of personal 
data concerning the data subject or to object to such processing; 
(f) the right to lodge a complaint with a supervisory authority; 
(g) where the personal data are not collected from the data subject, any 
available information as to their source; 
(h) the existence of automated decision-making, including profiling, 
referred to in Article 22(1) and (4) and, at least in those cases, 
meaningful information about the logic involved, as well as the 
significance and the envisaged consequences of such processing 
for the data subject. 
2. 
Where personal data are transferred to a third country or to an 
international organisation, the data subject shall have the right to be 
informed of the appropriate safeguards pursuant to Article 46 relating 
to the transfer. 
3. 
The controller shall provide a copy of the personal data 
undergoing processing. For any further copies requested by the data 
subject, the controller may charge a reasonable fee based on adminis­
trative costs. Where the data subject makes the request by electronic 
means, and unless otherwise requested by the data subject, the 
information shall be provided in a commonly used electronic form. 
4. 
The right to obtain a copy referred to in paragraph 3 shall not 
adversely affect the rights and freedoms of others. 
S e c t i o n 3 
R e c t i f i c a t i o n a n d e r a s u r e 
Article 16 
Right to rectification 
The data subject shall have the right to obtain from the controller 
without undue delay the rectification of inaccurate personal data 
concerning him or her. Taking into account the purposes of the 
processing, the data subject shall have the right to have incomplete 
personal data completed, including by means of providing a supple­
mentary statement. 
Article 17 
Right to erasure (‘right to be forgotten’) 
1. 
The data subject shall have the right to obtain from the controller 
the erasure of personal data concerning him or her without undue delay 
and the controller shall have the obligation to erase personal data 
without undue delay where one of the following grounds applies: 
(a) the personal data are no longer necessary in relation to the purposes 
for which they were collected or otherwise processed; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 18 
(b) the data subject withdraws consent on which the processing is based 
according to point (a) of Article 6(1), or point (a) of Article 9(2), 
and where there is no other legal ground for the processing; 
(c) the data subject objects to the processing pursuant to Article 21(1) 
and there are no overriding legitimate grounds for the processing, or 
the data subject objects to the processing pursuant to Article 21(2); 
(d) the personal data have been unlawfully processed; 
(e) the personal data have to be erased for compliance with a legal 
obligation in Union or Member State law to which the controller 
is subject; 
(f) the personal data have been collected in relation to the offer of 
information society services referred to in Article 8(1). 
2. 
Where the controller has made the personal data public and is 
obliged pursuant to paragraph 1 to erase the personal data, the 
controller, taking account of available technology and the cost of imple­
mentation, shall take reasonable steps, including technical measures, to 
inform controllers which are processing the personal data that the data 
subject has requested the erasure by such controllers of any links to, or 
copy or replication of, those personal data. 
3. 
Paragraphs 1 and 2 shall not apply to the extent that processing is 
necessary: 
(a) for exercising the right of freedom of expression and information; 
(b) for compliance with a legal obligation which requires processing by 
Union or Member State law to which the controller is subject or for 
the performance of a task carried out in the public interest or in the 
exercise of official authority vested in the controller; 
(c) for reasons of public interest in the area of public health in 
accordance with points (h) and (i) of Article 9(2) as well as 
Article 9(3); 
(d) for archiving purposes in the public interest, scientific or historical 
research purposes or statistical purposes in accordance with 
Article 89(1) in so far as the right referred to in paragraph 1 is 
likely to render impossible or seriously impair the achievement of 
the objectives of that processing; or 
(e) for the establishment, exercise or defence of legal claims. 
Article 18 
Right to restriction of processing 
1. 
The data subject shall have the right to obtain from the controller 
restriction of processing where one of the following applies: 
(a) the accuracy of the personal data is contested by the data subject, 
for a period enabling the controller to verify the accuracy of the 
personal data; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 19 
(b) the processing is unlawful and the data subject opposes the erasure 
of the personal data and requests the restriction of their use instead; 
(c) the controller no longer needs the personal data for the purposes of 
the processing, but they are required by the data subject for the 
establishment, exercise or defence of legal claims; 
(d) the data subject has objected to processing pursuant to Article 21(1) 
pending the verification whether the legitimate grounds of the 
controller override those of the data subject. 
2. 
Where processing has been restricted under paragraph 1, such 
personal data shall, with the exception of storage, only be processed 
with the data subject's consent or for the establishment, exercise or 
defence of legal claims or for the protection of the rights of another 
natural or legal person or for reasons of important public interest of the 
Union or of a Member State. 
3. 
A data subject who has obtained restriction of processing pursuant 
to paragraph 1 shall be informed by the controller before the restriction 
of processing is lifted. 
Article 19 
Notification obligation regarding rectification or erasure of personal 
data or restriction of processing 
The controller shall communicate any rectification or erasure of personal 
data or restriction of processing carried out in accordance with 
Article 16, Article 17(1) and Article 18 to each recipient to whom 
the personal data have been disclosed, unless this proves impossible 
or involves disproportionate effort. The controller shall inform the 
data subject about those recipients if the data subject requests it. 
Article 20 
Right to data portability 
1. 
The data subject shall have the right to receive the personal data 
concerning him or her, which he or she has provided to a controller, in 
a structured, commonly used and machine-readable format and have the 
right to transmit those data to another controller without hindrance from 
the controller to which the personal data have been provided, where: 
(a) the processing is based on consent pursuant to point (a) of 
Article 6(1) or point (a) of Article 9(2) or on a contract pursuant 
to point (b) of Article 6(1); and 
(b) the processing is carried out by automated means. 
2. 
In exercising his or her right to data portability pursuant to 
paragraph 1, the data subject shall have the right to have the personal 
data transmitted directly from one controller to another, where tech­
nically feasible. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 20 
3. 
The exercise of the right referred to in paragraph 1 of this Article 
shall be without prejudice to Article 17. That right shall not apply to 
processing necessary for the performance of a task carried out in the 
public interest or in the exercise of official authority vested in the 
controller. 
4. 
The right referred to in paragraph 1 shall not adversely affect the 
rights and freedoms of others. 
S e c t i o n 4 
R i g h t 
t o 
o b j e c t 
a n d 
a u t o m a t e d 
i n d i v i d u a l 
d e c i s i o n - m a k i n g 
Article 21 
Right to object 
1. 
The data subject shall have the right to object, on grounds relating 
to his or her particular situation, at any time to processing of personal 
data concerning him or her which is based on point (e) or (f) of 
Article 6(1), including profiling based on those provisions. The 
controller shall no longer process the personal data unless the controller 
demonstrates compelling legitimate grounds for the processing which 
override the interests, rights and freedoms of the data subject or for the 
establishment, exercise or defence of legal claims. 
2. 
Where personal data are processed for direct marketing purposes, 
the data subject shall have the right to object at any time to processing 
of personal data concerning him or her for such marketing, which 
includes profiling to the extent that it is related to such direct marketing. 
3. 
Where the data subject objects to processing for direct marketing 
purposes, the personal data shall no longer be processed for such 
purposes. 
4. 
At the latest at the time of the first communication with the data 
subject, the right referred to in paragraphs 1 and 2 shall be explicitly 
brought to the attention of the data subject and shall be presented clearly 
and separately from any other information. 
5. 
In the context of the use of information society services, and 
notwithstanding Directive 2002/58/EC, the data subject may exercise 
his or her right to object by automated means using technical 
specifications. 
6. 
Where personal data are processed for scientific or historical 
research purposes or statistical purposes pursuant to Article 89(1), the 
data subject, on grounds relating to his or her particular situation, shall 
have the right to object to processing of personal data concerning him 
or her, unless the processing is necessary for the performance of a task 
carried out for reasons of public interest. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 21 
Article 22 
Automated individual decision-making, including profiling 
1. 
The data subject shall have the right not to be subject to a decision 
based solely on automated processing, including profiling, which 
produces legal effects concerning him or her or similarly significantly 
affects him or her. 
2. 
Paragraph 1 shall not apply if the decision: 
(a) is necessary for entering into, or performance of, a contract between 
the data subject and a data controller; 
(b) is authorised by Union or Member State law to which the controller 
is subject and which also lays down suitable measures to safeguard 
the data subject's rights and freedoms and legitimate interests; or 
(c) is based on the data subject's explicit consent. 
3. 
In the cases referred to in points (a) and (c) of paragraph 2, the 
data controller shall implement suitable measures to safeguard the data 
subject's rights and freedoms and legitimate interests, at least the right to 
obtain human intervention on the part of the controller, to express his or 
her point of view and to contest the decision. 
4. 
Decisions referred to in paragraph 2 shall not be based on special 
categories of personal data referred to in Article 9(1), unless point (a) or 
(g) of Article 9(2) applies and suitable measures to safeguard the data 
subject's rights and freedoms and legitimate interests are in place. 
S e c t i o n 5 
R e s t r i c t i o n s 
Article 23 
Restrictions 
1. 
Union or Member State law to which the data controller or 
processor is subject may restrict by way of a legislative measure the 
scope of the obligations and rights provided for in Articles 12 to 22 and 
Article 34, as well as Article 5 in so far as its provisions correspond to 
the rights and obligations provided for in Articles 12 to 22, when such a 
restriction respects the essence of the fundamental rights and freedoms 
and is a necessary and proportionate measure in a democratic society to 
safeguard: 
(a) national security; 
(b) defence; 
(c) public security; 
(d) the prevention, investigation, detection or prosecution of criminal 
offences or the execution of criminal penalties, including the safe­
guarding against and the prevention of threats to public security; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 22 
(e) other important objectives of general public interest of the Union or 
of a Member State, in particular an important economic or financial 
interest of the Union or of a Member State, including monetary, 
budgetary and taxation a matters, public health and social security; 
(f) the protection of judicial independence and judicial proceedings; 
(g) the prevention, investigation, detection and prosecution of breaches 
of ethics for regulated professions; 
(h) a monitoring, inspection or regulatory function connected, even 
occasionally, to the exercise of official authority in the cases 
referred to in points (a) to (e) and (g); 
(i) the protection of the data subject or the rights and freedoms of 
others; 
(j) the enforcement of civil law claims. 
2. 
In particular, any legislative measure referred to in paragraph 1 
shall contain specific provisions at least, where relevant, as to: 
(a) the purposes of the processing or categories of processing; 
(b) the categories of personal data; 
(c) the scope of the restrictions introduced; 
(d) the safeguards to prevent abuse or unlawful access or transfer; 
(e) the specification of the controller or categories of controllers; 
(f) the storage periods and the applicable safeguards taking into 
account the nature, scope and purposes of the processing or 
categories of processing; 
(g) the risks to the rights and freedoms of data subjects; and 
(h) the right of data subjects to be informed about the restriction, unless 
that may be prejudicial to the purpose of the restriction. 
CHAPTER IV 
Controller and processor 
S e c t i o n 1 
G e n e r a l o b l i g a t i o n s 
Article 24 
Responsibility of the controller 
1. 
Taking into account the nature, scope, context and purposes of 
processing as well as the risks of varying likelihood and severity for the 
rights and freedoms of natural persons, the controller shall implement 
appropriate technical and organisational measures to ensure and to be 
able to demonstrate that processing is performed in accordance with this 
Regulation. Those measures shall be reviewed and updated where 
necessary. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 23 
2. 
Where proportionate in relation to processing activities, the 
measures referred to in paragraph 1 shall include the implementation 
of appropriate data protection policies by the controller. 
3. 
Adherence to approved codes of conduct as referred to in 
Article 40 or approved certification mechanisms as referred to in 
Article 42 may be used as an element by which to demonstrate 
compliance with the obligations of the controller. 
Article 25 
Data protection by design and by default 
1. 
Taking into account the state of the art, the cost of implementation 
and the nature, scope, context and purposes of processing as well as the 
risks of varying likelihood and severity for rights and freedoms of 
natural persons posed by the processing, the controller shall, both at 
the time of the determination of the means for processing and at the 
time of the processing itself, implement appropriate technical and 
organisational measures, such as pseudonymisation, which are 
designed to implement data-protection principles, such as data minimis­
ation, in an effective manner and to integrate the necessary safeguards 
into the processing in order to meet the requirements of this Regulation 
and protect the rights of data subjects. 
2. 
The controller shall implement appropriate technical and organisa­
tional measures for ensuring that, by default, only personal data which 
are necessary for each specific purpose of the processing are processed. 
That obligation applies to the amount of personal data collected, the 
extent of their processing, the period of their storage and their accessi­
bility. In particular, such measures shall ensure that by default personal 
data are not made accessible without the individual's intervention to an 
indefinite number of natural persons. 
3. 
An approved certification mechanism pursuant to Article 42 may 
be used as an element to demonstrate compliance with the requirements 
set out in paragraphs 1 and 2 of this Article. 
Article 26 
Joint controllers 
1. 
Where two or more controllers jointly determine the purposes and 
means of processing, they shall be joint controllers. They shall in a 
transparent manner determine their respective responsibilities for 
compliance with the obligations under this Regulation, in particular as 
regards the exercising of the rights of the data subject and their 
respective duties to provide the information referred to in Articles 13 
and 14, by means of an arrangement between them unless, and in so far 
as, the respective responsibilities of the controllers are determined by 
Union or Member State law to which the controllers are subject. The 
arrangement may designate a contact point for data subjects. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 24 
2. 
The arrangement referred to in paragraph 1 shall duly reflect the 
respective roles and relationships of the joint controllers vis-à-vis the 
data subjects. The essence of the arrangement shall be made available to 
the data subject. 
3. 
Irrespective of the terms of the arrangement referred to in 
paragraph 1, the data subject may exercise his or her rights under this 
Regulation in respect of and against each of the controllers. 
Article 27 
Representatives of controllers or processors not established in the 
Union 
1. 
Where Article 3(2) applies, the controller or the processor shall 
designate in writing a representative in the Union. 
2. 
The obligation laid down in paragraph 1 of this Article shall not 
apply to: 
(a) processing which is occasional, does not include, on a large scale, 
processing of special categories of data as referred to in Article 9(1) 
or processing of personal data relating to criminal convictions and 
offences referred to in Article 10, and is unlikely to result in a risk 
to the rights and freedoms of natural persons, taking into account 
the nature, context, scope and purposes of the processing; or 
(b) a public authority or body. 
3. 
The representative shall be established in one of the Member 
States where the data subjects, whose personal data are processed in 
relation to the offering of goods or services to them, or whose behaviour 
is monitored, are. 
4. 
The representative shall be mandated by the controller or 
processor to be addressed in addition to or instead of the controller or 
the processor by, in particular, supervisory authorities and data subjects, 
on all issues related to processing, for the purposes of ensuring 
compliance with this Regulation. 
5. 
The designation of a representative by the controller or processor 
shall be without prejudice to legal actions which could be initiated 
against the controller or the processor themselves. 
Article 28 
Processor 
1. 
Where processing is to be carried out on behalf of a controller, the 
controller shall use only processors providing sufficient guarantees to 
implement appropriate technical and organisational measures in such a 
manner that processing will meet the requirements of this Regulation 
and ensure the protection of the rights of the data subject. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 25 
2. 
The processor shall not engage another processor without prior 
specific or general written authorisation of the controller. In the case 
of general written authorisation, the processor shall inform the controller 
of any intended changes concerning the addition or replacement of other 
processors, thereby giving the controller the opportunity to object to 
such changes. 
3. 
Processing by a processor shall be governed by a contract or other 
legal act under Union or Member State law, that is binding on the 
processor with regard to the controller and that sets out the 
subject-matter and duration of the processing, the nature and purpose 
of the processing, the type of personal data and categories of data 
subjects and the obligations and rights of the controller. That contract 
or other legal act shall stipulate, in particular, that the processor: 
(a) processes the personal data only on documented instructions from 
the controller, including with regard to transfers of personal data to 
a third country or an international organisation, unless required to 
do so by Union or Member State law to which the processor is 
subject; in such a case, the processor shall inform the controller of 
that legal requirement before processing, unless that law prohibits 
such information on important grounds of public interest; 
(b) ensures that persons authorised to process the personal data have 
committed themselves to confidentiality or are under an appropriate 
statutory obligation of confidentiality; 
(c) takes all measures required pursuant to Article 32; 
(d) respects the conditions referred to in paragraphs 2 and 4 for 
engaging another processor; 
(e) taking into account the nature of the processing, assists the 
controller by appropriate technical and organisational measures, 
insofar as this is possible, for the fulfilment of the controller's 
obligation to respond to requests for exercising the data subject's 
rights laid down in Chapter III; 
(f) assists the controller in ensuring compliance with the obligations 
pursuant to Articles 32 to 36 taking into account the nature of 
processing and the information available to the processor; 
(g) at the choice of the controller, deletes or returns all the personal 
data to the controller after the end of the provision of services 
relating to processing, and deletes existing copies unless Union or 
Member State law requires storage of the personal data; 
(h) makes available to the controller all information necessary to 
demonstrate compliance with the obligations laid down in this 
Article and allow for and contribute to audits, including inspections, 
conducted by the controller or another auditor mandated by the 
controller. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 26 
With regard to point (h) of the first subparagraph, the processor shall 
immediately inform the controller if, in its opinion, an instruction 
infringes this Regulation or other Union or Member State data 
protection provisions. 
4. 
Where a processor engages another processor for carrying out 
specific processing activities on behalf of the controller, the same data 
protection obligations as set out in the contract or other legal act 
between the controller and the processor as referred to in paragraph 3 
shall be imposed on that other processor by way of a contract or other 
legal act under Union or Member State law, in particular providing 
sufficient guarantees to implement appropriate technical and organisa­
tional measures in such a manner that the processing will meet the 
requirements of this Regulation. Where that other processor fails to 
fulfil its data protection obligations, the initial processor shall remain 
fully liable to the controller for the performance of that other processor's 
obligations. 
5. 
Adherence of a processor to an approved code of conduct as 
referred to in Article 40 or an approved certification mechanism as 
referred to in Article 42 may be used as an element by which to 
demonstrate sufficient guarantees as referred to in paragraphs 1 and 4 
of this Article. 
6. 
Without prejudice to an individual contract between the controller 
and the processor, the contract or the other legal act referred to in 
paragraphs 3 and 4 of this Article may be based, in whole or in part, 
on standard contractual clauses referred to in paragraphs 7 and 8 of this 
Article, including when they are part of a certification granted to the 
controller or processor pursuant to Articles 42 and 43. 
7. 
The Commission may lay down standard contractual clauses for 
the matters referred to in paragraph 3 and 4 of this Article and in 
accordance with the examination procedure referred to in Article 93(2). 
8. 
A supervisory authority may adopt standard contractual clauses for 
the matters referred to in paragraph 3 and 4 of this Article and in 
accordance with the consistency mechanism referred to in Article 63. 
9. 
The contract or the other legal act referred to in paragraphs 3 and 
4 shall be in writing, including in electronic form. 
10. 
Without prejudice to Articles 82, 83 and 84, if a processor 
infringes this Regulation by determining the purposes and means of 
processing, the processor shall be considered to be a controller in 
respect of that processing. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 27 
Article 29 
Processing under the authority of the controller or processor 
The processor and any person acting under the authority of the 
controller or of the processor, who has access to personal data, shall 
not process those data except on instructions from the controller, unless 
required to do so by Union or Member State law. 
Article 30 
Records of processing activities 
1. 
Each controller and, where applicable, the controller's represen­
tative, shall maintain a record of processing activities under its respon­
sibility. That record shall contain all of the following information: 
(a) the name and contact details of the controller and, where applicable, 
the joint controller, the controller's representative and the data 
protection officer; 
(b) the purposes of the processing; 
(c) a description of the categories of data subjects and of the categories 
of personal data; 
(d) the categories of recipients to whom the personal data have been or 
will be disclosed including recipients in third countries or inter­
national organisations; 
(e) where applicable, transfers of personal data to a third country or an 
international organisation, including the identification of that third 
country or international organisation and, in the case of transfers 
referred to in the second subparagraph of Article 49(1), the docu­
mentation of suitable safeguards; 
(f) where possible, the envisaged time limits for erasure of the different 
categories of data; 
(g) where possible, a general description of the technical and organisa­
tional security measures referred to in Article 32(1). 
2. 
Each processor and, where applicable, the processor's representa­
tive shall maintain a record of all categories of processing activities 
carried out on behalf of a controller, containing: 
(a) the name and contact details of the processor or processors and of 
each controller on behalf of which the processor is acting, and, 
where applicable, of the controller's or the processor's represen­
tative, and the data protection officer; 
(b) the categories of processing carried out on behalf of each controller; 
(c) where applicable, transfers of personal data to a third country or an 
international organisation, including the identification of that third 
country or international organisation and, in the case of transfers 
referred to in the second subparagraph of Article 49(1), the docu­
mentation of suitable safeguards; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 28 
(d) where possible, a general description of the technical and organisa­
tional security measures referred to in Article 32(1). 
3. 
The records referred to in paragraphs 1 and 2 shall be in writing, 
including in electronic form. 
4. 
The controller or the processor and, where applicable, the 
controller's or the processor's representative, shall make the record 
available to the supervisory authority on request. 
5. 
The obligations referred to in paragraphs 1 and 2 shall not apply 
to an enterprise or an organisation employing fewer than 250 persons 
unless the processing it carries out is likely to result in a risk to the 
rights and freedoms of data subjects, the processing is not occasional, or 
the processing includes special categories of data as referred to in 
Article 9(1) or personal data relating to criminal convictions and 
offences referred to in Article 10. 
Article 31 
Cooperation with the supervisory authority 
The controller and the processor and, where applicable, their represen­
tatives, shall cooperate, on request, with the supervisory authority in the 
performance of its tasks. 
S e c t i o n 2 
S e c u r i t y o f p e r s o n a l d a t a 
Article 32 
Security of processing 
1. 
Taking into account the state of the art, the costs of implemen­
tation and the nature, scope, context and purposes of processing as well 
as the risk of varying likelihood and severity for the rights and freedoms 
of natural persons, the controller and the processor shall implement 
appropriate technical and organisational measures to ensure a level of 
security appropriate to the risk, including inter alia as appropriate: 
(a) the pseudonymisation and encryption of personal data; 
(b) the ability to ensure the ongoing confidentiality, integrity, availabil­
ity and resilience of processing systems and services; 
(c) the ability to restore the availability and access to personal data in a 
timely manner in the event of a physical or technical incident; 
(d) a process for regularly testing, assessing and evaluating the effec­
tiveness of technical and organisational measures for ensuring the 
security of the processing. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 29 
2. 
In assessing the appropriate level of security account shall be 
taken in particular of the risks that are presented by processing, in 
particular from accidental or unlawful destruction, loss, alteration, 
unauthorised disclosure of, or access to personal data transmitted, 
stored or otherwise processed. 
3. 
Adherence to an approved code of conduct as referred to in 
Article 40 or an approved certification mechanism as referred to in 
Article 42 may be used as an element by which to demonstrate 
compliance with the requirements set out in paragraph 1 of this Article. 
4. 
The controller and processor shall take steps to ensure that any 
natural person acting under the authority of the controller or the 
processor who has access to personal data does not process them 
except on instructions from the controller, unless he or she is required 
to do so by Union or Member State law. 
Article 33 
Notification of a personal data breach to the supervisory authority 
1. 
In the case of a personal data breach, the controller shall without 
undue delay and, where feasible, not later than 72 hours after having 
become aware of it, notify the personal data breach to the supervisory 
authority competent in accordance with Article 55, unless the personal 
data breach is unlikely to result in a risk to the rights and freedoms of 
natural persons. Where the notification to the supervisory authority is 
not made within 72 hours, it shall be accompanied by reasons for the 
delay. 
2. 
The processor shall notify the controller without undue delay after 
becoming aware of a personal data breach. 
3. 
The notification referred to in paragraph 1 shall at least: 
(a) describe the nature of the personal data breach including where 
possible, the categories and approximate number of data subjects 
concerned and the categories and approximate number of personal 
data records concerned; 
(b) communicate the name and contact details of the data protection 
officer or other contact point where more information can be 
obtained; 
(c) describe the likely consequences of the personal data breach; 
(d) describe the measures taken or proposed to be taken by the 
controller to address the personal data breach, including, where 
appropriate, measures to mitigate its possible adverse effects. 
4. 
Where, and in so far as, it is not possible to provide the 
information at the same time, the information may be provided in 
phases without undue further delay. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 30 
5. 
The controller shall document any personal data breaches, 
comprising the facts relating to the personal data breach, its effects 
and the remedial action taken. That documentation shall enable the 
supervisory authority to verify compliance with this Article. 
Article 34 
Communication of a personal data breach to the data subject 
1. 
When the personal data breach is likely to result in a high risk to 
the rights and freedoms of natural persons, the controller shall 
communicate the personal data breach to the data subject without 
undue delay. 
2. 
The communication to the data subject referred to in paragraph 1 
of this Article shall describe in clear and plain language the nature of 
the personal data breach and contain at least the information and 
measures referred to in points (b), (c) and (d) of Article 33(3). 
3. 
The communication to the data subject referred to in paragraph 1 
shall not be required if any of the following conditions are met: 
(a) the controller has implemented appropriate technical and organisa­
tional protection measures, and those measures were applied to the 
personal data affected by the personal data breach, in particular 
those that render the personal data unintelligible to any person 
who is not authorised to access it, such as encryption; 
(b) the controller has taken subsequent measures which ensure that the 
high risk to the rights and freedoms of data subjects referred to in 
paragraph 1 is no longer likely to materialise; 
(c) it would involve disproportionate effort. In such a case, there shall 
instead be a public communication or similar measure whereby the 
data subjects are informed in an equally effective manner. 
4. 
If the controller has not already communicated the personal data 
breach to the data subject, the supervisory authority, having considered 
the likelihood of the personal data breach resulting in a high risk, may 
require it to do so or may decide that any of the conditions referred to 
in paragraph 3 are met. 
S e c t i o n 3 
D a t a 
p r o t e c t i o n 
i m p a c t 
a s s e s s m e n t a n d 
p r i o r 
c o n s u l t a t i o n 
Article 35 
Data protection impact assessment 
1. 
Where a type of processing in particular using new technologies, 
and taking into account the nature, scope, context and purposes of the 
processing, is likely to result in a high risk to the rights and freedoms of 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 31 
natural persons, the controller shall, prior to the processing, carry out an 
assessment of the impact of the envisaged processing operations on the 
protection of personal data. A single assessment may address a set of 
similar processing operations that present similar high risks. 
2. 
The controller shall seek the advice of the data protection officer, 
where designated, when carrying out a data protection impact 
assessment. 
3. 
A data protection impact assessment referred to in paragraph 1 
shall in particular be required in the case of: 
(a) a systematic and extensive evaluation of personal aspects relating to 
natural persons which is based on automated processing, including 
profiling, and on which decisions are based that produce legal 
effects concerning the natural person or similarly significantly 
affect the natural person; 
(b) processing on a large scale of special categories of data referred to 
in Article 9(1), or of personal data relating to criminal convictions 
and offences referred to in Article 10; or 
(c) a systematic monitoring of a publicly accessible area on a large 
scale. 
4. 
The supervisory authority shall establish and make public a list of 
the kind of processing operations which are subject to the requirement 
for a data protection impact assessment pursuant to paragraph 1. The 
supervisory authority shall communicate those lists to the Board referred 
to in Article 68. 
5. 
The supervisory authority may also establish and make public a 
list of the kind of processing operations for which no data protection 
impact assessment is required. The supervisory authority shall 
communicate those lists to the Board. 
6. 
Prior to the adoption of the lists referred to in paragraphs 4 and 5, 
the competent supervisory authority shall apply the consistency 
mechanism referred to in Article 63 where such lists involve processing 
activities which are related to the offering of goods or services to data 
subjects or to the monitoring of their behaviour in several 
Member States, or may substantially affect the free movement of 
personal data within the Union. 
7. 
The assessment shall contain at least: 
(a) a systematic description of the envisaged processing operations and 
the purposes of the processing, including, where applicable, the 
legitimate interest pursued by the controller; 
(b) an assessment of the necessity and proportionality of the processing 
operations in relation to the purposes; 
(c) an assessment of the risks to the rights and freedoms of data 
subjects referred to in paragraph 1; and 
(d) the measures envisaged to address the risks, including safeguards, 
security measures and mechanisms to ensure the protection of 
personal data and to demonstrate compliance with this Regulation 
taking into account the rights and legitimate interests of data 
subjects and other persons concerned. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 32 
8. 
Compliance with approved codes of conduct referred to in 
Article 40 by the relevant controllers or processors shall be taken into 
due account in assessing the impact of the processing operations 
performed by such controllers or processors, in particular for the 
purposes of a data protection impact assessment. 
9. 
Where appropriate, the controller shall seek the views of data 
subjects or their representatives on the intended processing, without 
prejudice to the protection of commercial or public interests or the 
security of processing operations. 
10. 
Where processing pursuant to point (c) or (e) of Article 6(1) has 
a legal basis in Union law or in the law of the Member State to which 
the controller is subject, that law regulates the specific processing 
operation or set of operations in question, and a data protection 
impact assessment has already been carried out as part of a general 
impact assessment in the context of the adoption of that legal basis, 
paragraphs 1 to 7 shall not apply unless Member States deem it to be 
necessary to carry out such an assessment prior to processing activities. 
11. 
Where necessary, the controller shall carry out a review to assess 
if processing is performed in accordance with the data protection impact 
assessment at least when there is a change of the risk represented by 
processing operations. 
Article 36 
Prior consultation 
1. 
The controller shall consult the supervisory authority prior to 
processing where a data protection impact assessment under Article 35 
indicates that the processing would result in a high risk in the absence 
of measures taken by the controller to mitigate the risk. 
2. 
Where the supervisory authority is of the opinion that the intended 
processing referred to in paragraph 1 would infringe this Regulation, in 
particular where the controller has insufficiently identified or mitigated 
the risk, the supervisory authority shall, within period of up to eight 
weeks of receipt of the request for consultation, provide written advice 
to the controller and, where applicable to the processor, and may use 
any of its powers referred to in Article 58. That period may be extended 
by six weeks, taking into account the complexity of the intended 
processing. The supervisory authority shall inform the controller and, 
where applicable, the processor, of any such extension within one 
month of receipt of the request for consultation together with the 
reasons for the delay. Those periods may be suspended until the super­
visory authority has obtained information it has requested for the 
purposes of the consultation. 
3. 
When consulting the supervisory authority pursuant to paragraph 1, 
the controller shall provide the supervisory authority with: 
(a) where applicable, the respective responsibilities of the controller, 
joint controllers and processors involved in the processing, in 
particular for processing within a group of undertakings; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 33 
(b) the purposes and means of the intended processing; 
(c) the measures and safeguards provided to protect the rights and 
freedoms of data subjects pursuant to this Regulation; 
(d) where applicable, the contact details of the data protection officer; 
(e) the data protection impact assessment provided for in Article 35; 
and 
(f) any other information requested by the supervisory authority. 
4. 
Member States shall consult the supervisory authority during the 
preparation of a proposal for a legislative measure to be adopted by a 
national parliament, or of a regulatory measure based on such a legis­
lative measure, which relates to processing. 
5. 
Notwithstanding paragraph 1, Member State law may require 
controllers to consult with, and obtain prior authorisation from, the 
supervisory authority in relation to processing by a controller for the 
performance of a task carried out by the controller in the public interest, 
including processing in relation to social protection and public health. 
S e c t i o n 4 
D a t a p r o t e c t i o n o f f i c e r 
Article 37 
Designation of the data protection officer 
1. 
The controller and the processor shall designate a data protection 
officer in any case where: 
(a) the processing is carried out by a public authority or body, except 
for courts acting in their judicial capacity; 
(b) the core activities of the controller or the processor consist of 
processing operations which, by virtue of their nature, their scope 
and/or their purposes, require regular and systematic monitoring of 
data subjects on a large scale; or 
▼C1 
(c) the core activities of the controller or the processor consist of 
processing on a large scale of special categories of data pursuant 
to Article 9 or personal data relating to criminal convictions and 
offences referred to in Article 10. 
▼B 
2. 
A group of undertakings may appoint a single data protection 
officer provided that a data protection officer is easily accessible from 
each establishment. 
3. 
Where the controller or the processor is a public authority or body, 
a single data protection officer may be designated for several such 
authorities or bodies, taking account of their organisational structure 
and size. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 34 
4. 
In cases other than those referred to in paragraph 1, the controller 
or processor or associations and other bodies representing categories of 
controllers or processors may or, where required by Union or Member 
State law shall, designate a data protection officer. The data protection 
officer may act for such associations and other bodies representing 
controllers or processors. 
5. 
The data protection officer shall be designated on the basis of 
professional qualities and, in particular, expert knowledge of data 
protection law and practices and the ability to fulfil the tasks referred 
to in Article 39. 
6. 
The data protection officer may be a staff member of the controller 
or processor, or fulfil the tasks on the basis of a service contract. 
7. 
The controller or the processor shall publish the contact details of 
the data protection officer and communicate them to the supervisory 
authority. 
Article 38 
Position of the data protection officer 
1. 
The controller and the processor shall ensure that the data 
protection officer is involved, properly and in a timely manner, in all 
issues which relate to the protection of personal data. 
2. 
The controller and processor shall support the data protection 
officer in performing the tasks referred to in Article 39 by providing 
resources necessary to carry out those tasks and access to personal data 
and processing operations, and to maintain his or her expert knowledge. 
3. 
The controller and processor shall ensure that the data protection 
officer does not receive any instructions regarding the exercise of those 
tasks. He or she shall not be dismissed or penalised by the controller or 
the processor for performing his tasks. The data protection officer shall 
directly report to the highest management level of the controller or the 
processor. 
4. 
Data subjects may contact the data protection officer with regard 
to all issues related to processing of their personal data and to the 
exercise of their rights under this Regulation. 
5. 
The data protection officer shall be bound by secrecy or confiden­
tiality concerning the performance of his or her tasks, in accordance 
with Union or Member State law. 
6. 
The data protection officer may fulfil other tasks and duties. The 
controller or processor shall ensure that any such tasks and duties do not 
result in a conflict of interests. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 35 
Article 39 
Tasks of the data protection officer 
1. 
The data protection officer shall have at least the following tasks: 
(a) to inform and advise the controller or the processor and the 
employees who carry out processing of their obligations pursuant 
to this Regulation and to other Union or Member State data 
protection provisions; 
(b) to monitor compliance with this Regulation, with other Union or 
Member State data protection provisions and with the policies of the 
controller or processor in relation to the protection of personal data, 
including the assignment of responsibilities, awareness-raising and 
training of staff involved in processing operations, and the related 
audits; 
(c) to provide advice where requested as regards the data protection 
impact assessment and monitor its performance pursuant to 
Article 35; 
(d) to cooperate with the supervisory authority; 
(e) to act as the contact point for the supervisory authority on issues 
relating to processing, including the prior consultation referred to in 
Article 36, and to consult, where appropriate, with regard to any 
other matter. 
2. 
The data protection officer shall in the performance of his or her 
tasks have due regard to the risk associated with processing operations, 
taking into account the nature, scope, context and purposes of 
processing. 
S e c t i o n 5 
C o d e s o f c o n d u c t a n d c e r t i f i c a t i o n 
Article 40 
Codes of conduct 
1. 
The Member States, the supervisory authorities, the Board and the 
Commission shall encourage the drawing up of codes of conduct 
intended to contribute to the proper application of this Regulation, 
taking account of the specific features of the various processing 
sectors and the specific needs of micro, small and medium-sized 
enterprises. 
2. 
Associations and 
other bodies 
representing categories of 
controllers or processors may prepare codes of conduct, or amend or 
extend such codes, for the purpose of specifying the application of this 
Regulation, such as with regard to: 
(a) fair and transparent processing; 
(b) the legitimate interests pursued by controllers in specific contexts; 
(c) the collection of personal data; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 36 
(d) the pseudonymisation of personal data; 
(e) the information provided to the public and to data subjects; 
(f) the exercise of the rights of data subjects; 
(g) the information provided to, and the protection of, children, and the 
manner in which the consent of the holders of parental responsi­
bility over children is to be obtained; 
(h) the measures and procedures referred to in Articles 24 and 25 and 
the measures to ensure security of processing referred to in 
Article 32; 
(i) the notification of personal data breaches to supervisory authorities 
and the communication of such personal data breaches to data 
subjects; 
(j) the transfer of personal data to third countries or international 
organisations; or 
(k) out-of-court proceedings and other dispute resolution procedures for 
resolving disputes between controllers and data subjects with regard 
to processing, without prejudice to the rights of data subjects 
pursuant to Articles 77 and 79. 
3. 
In addition to adherence by controllers or processors subject to 
this Regulation, codes of conduct approved pursuant to paragraph 5 of 
this Article and having general validity pursuant to paragraph 9 of this 
Article may also be adhered to by controllers or processors that are not 
subject to this Regulation pursuant to Article 3 in order to provide 
appropriate safeguards within the framework of personal data transfers 
to third countries or international organisations under the terms referred 
to in point (e) of Article 46(2). Such controllers or processors shall 
make binding and enforceable commitments, via contractual or other 
legally binding instruments, to apply those appropriate safeguards 
including with regard to the rights of data subjects. 
4. 
A code of conduct referred to in paragraph 2 of this Article shall 
contain mechanisms which enable the body referred to in Article 41(1) 
to carry out the mandatory monitoring of compliance with its provisions 
by the controllers or processors which undertake to apply it, without 
prejudice to the tasks and powers of supervisory authorities competent 
pursuant to Article 55 or 56. 
5. 
Associations and other bodies referred to in paragraph 2 of this 
Article which intend to prepare a code of conduct or to amend or extend 
an existing code shall submit the draft code, amendment or extension to 
the supervisory authority which is competent pursuant to Article 55. 
The supervisory authority shall provide an opinion on whether the 
draft code, amendment or extension complies with this Regulation 
and shall approve that draft code, amendment or extension if it finds 
that it provides sufficient appropriate safeguards. 
6. 
Where the draft code, or amendment or extension is approved in 
accordance with paragraph 5, and where the code of conduct concerned 
does not relate to processing activities in several Member States, the 
supervisory authority shall register and publish the code. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 37 
7. 
Where a draft code of conduct relates to processing activities in 
several Member States, the supervisory authority which is competent 
pursuant to Article 55 shall, before approving the draft code, 
amendment or extension, submit it in the procedure referred to in 
Article 63 to the Board which shall provide an opinion on whether 
the draft code, amendment or extension complies with this Regulation 
or, in the situation referred to in paragraph 3 of this Article, provides 
appropriate safeguards. 
8. 
Where the opinion referred to in paragraph 7 confirms that the 
draft code, amendment or extension complies with this Regulation, or, 
in the situation referred to in paragraph 3, provides appropriate safe­
guards, the Board shall submit its opinion to the Commission. 
9. 
The Commission may, by way of implementing acts, decide that 
the approved code of conduct, amendment or extension submitted to it 
pursuant to paragraph 8 of this Article have general validity within the 
Union. Those implementing acts shall be adopted in accordance with 
the examination procedure set out in Article 93(2). 
10. 
The Commission shall ensure appropriate publicity for the 
approved codes which have been decided as having general validity 
in accordance with paragraph 9. 
11. 
The Board shall collate all approved codes of conduct, 
amendments and extensions in a register and shall make them 
publicly available by way of appropriate means. 
Article 41 
Monitoring of approved codes of conduct 
1. 
Without prejudice to the tasks and powers of the competent super­
visory authority under Articles 57 and 58, the monitoring of compliance 
with a code of conduct pursuant to Article 40 may be carried out by a 
body which has an appropriate level of expertise in relation to the 
subject-matter of the code and is accredited for that purpose by the 
competent supervisory authority. 
2. 
A body as referred to in paragraph 1 may be accredited to monitor 
compliance with a code of conduct where that body has: 
(a) demonstrated its independence and expertise in relation to the 
subject-matter of the code to the satisfaction of the competent super­
visory authority; 
(b) established procedures which allow it to assess the eligibility of 
controllers and processors concerned to apply the code, to 
monitor their compliance with its provisions and to periodically 
review its operation; 
(c) established procedures and structures to handle complaints about 
infringements of the code or the manner in which the code has 
been, or is being, implemented by a controller or processor, and 
to make those procedures and structures transparent to data subjects 
and the public; and 
(d) demonstrated to the satisfaction of the competent supervisory 
authority that its tasks and duties do not result in a conflict of 
interests. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 38 
3. 
The competent supervisory authority shall submit the draft 
requirements for accreditation of a body as referred to in paragraph 1 
of this Article to the Board pursuant to the consistency mechanism 
referred to in Article 63. 
▼B 
4. 
Without prejudice to the tasks and powers of the competent super­
visory authority and the provisions of Chapter VIII, a body as referred 
to in paragraph 1 of this Article shall, subject to appropriate safeguards, 
take appropriate action in cases of infringement of the code by a 
controller or processor, including suspension or exclusion of the 
controller or processor concerned from the code. It shall inform the 
competent supervisory authority of such actions and the reasons for 
taking them. 
▼C1 
5. 
The competent supervisory authority shall revoke the accreditation 
of a body as referred to in paragraph 1 if the requirements for accred­
itation are not, or are no longer, met or where actions taken by the body 
infringe this Regulation. 
▼B 
6. 
This Article shall not apply to processing carried out by public 
authorities and bodies. 
Article 42 
Certification 
1. 
The Member States, the supervisory authorities, the Board and the 
Commission shall encourage, in particular at Union level, the estab­
lishment of data protection certification mechanisms and of data 
protection seals and marks, for the purpose of demonstrating compliance 
with this Regulation of processing operations by controllers and 
processors. The specific needs of micro, small and medium-sized enter­
prises shall be taken into account. 
2. 
In addition to adherence by controllers or processors subject to 
this Regulation, data protection certification mechanisms, seals or marks 
approved pursuant to paragraph 5 of this Article may be established for 
the purpose of demonstrating the existence of appropriate safeguards 
provided by controllers or processors that are not subject to this Regu­
lation pursuant to Article 3 within the framework of personal data 
transfers to third countries or international organisations under the 
terms referred to in point (f) of Article 46(2). Such controllers or 
processors shall make binding and enforceable commitments, via 
contractual or other legally binding instruments, to apply those appro­
priate safeguards, including with regard to the rights of data subjects. 
3. 
The certification shall be voluntary and available via a process that 
is transparent. 
4. 
A certification pursuant to this Article does not reduce the respon­
sibility of the controller or the processor for compliance with this Regu­
lation and is without prejudice to the tasks and powers of the super­
visory authorities which are competent pursuant to Article 55 or 56. 
▼C1


 
02016R0679 — EN — 04.05.2016 — 000.002 — 39 
5. 
A certification pursuant to this Article shall be issued by the 
certification bodies referred to in Article 43 or by the competent super­
visory authority, on the basis of criteria approved by that competent 
supervisory authority pursuant to Article 58(3) or by the Board pursuant 
to Article 63. Where the criteria are approved by the Board, this may 
result in a common certification, the European Data Protection Seal. 
6. 
The controller or processor which submits its processing to the 
certification mechanism shall provide the certification body referred to 
in Article 43, or where applicable, the competent supervisory authority, 
with all information and access to its processing activities which are 
necessary to conduct the certification procedure. 
▼C1 
7. 
Certification shall be issued to a controller or processor for a 
maximum period of three years and may be renewed, under the same 
conditions, provided that the relevant criteria continue to be met. Certifi­
cation shall be withdrawn, as applicable, by the certification bodies 
referred to in Article 43 or by the competent supervisory authority 
where the criteria for the certification are not or are no longer met. 
▼B 
8. 
The Board shall collate all certification mechanisms and data 
protection seals and marks in a register and shall make them publicly 
available by any appropriate means. 
Article 43 
Certification bodies 
1. 
Without prejudice to the tasks and powers of the competent super­
visory authority under Articles 57 and 58, certification bodies which 
have an appropriate level of expertise in relation to data protection shall, 
after informing the supervisory authority in order to allow it to exercise 
its powers pursuant to point (h) of Article 58(2) where necessary, issue 
and renew certification. Member States shall ensure that those certifi­
cation bodies are accredited by one or both of the following: 
(a) the supervisory authority which is competent pursuant to Article 55 
or 56; 
(b) the national accreditation body named in accordance with 
Regulation (EC) No 765/2008 of the European Parliament and of 
the Council ( 
1 
) in accordance with EN-ISO/IEC 17065/2012 and 
with the additional requirements established by the supervisory 
authority which is competent pursuant to Article 55 or 56. 
2. 
Certification bodies referred to in paragraph 1 shall be accredited 
in accordance with that paragraph only where they have: 
(a) demonstrated their independence and expertise in relation to the 
subject-matter of the certification to the satisfaction of the 
competent supervisory authority; 
▼B 
( 
1 
) Regulation (EC) No 765/2008 of the European Parliament and of the Council 
of 9 July 2008 setting out the requirements for accreditation and market 
surveillance 
relating 
to 
the 
marketing 
of 
products 
and 
repealing 
Regulation (EEC) No 339/93 (OJ L 218, 13.8.2008, p. 30).


 
02016R0679 — EN — 04.05.2016 — 000.002 — 40 
(b) undertaken to respect the criteria referred to in Article 42(5) and 
approved by the supervisory authority which is competent pursuant 
to Article 55 or 56 or by the Board pursuant to Article 63; 
(c) established procedures for the issuing, periodic review and with­
drawal of data protection certification, seals and marks; 
(d) established procedures and structures to handle complaints about 
infringements of the certification or the manner in which the certifi­
cation has been, or is being, implemented by the controller or 
processor, and to make those procedures and structures transparent 
to data subjects and the public; and 
(e) demonstrated, to the satisfaction of the competent supervisory auth­
ority, that their tasks and duties do not result in a conflict of 
interests. 
3. 
►C1 The accreditation of certification bodies as referred to in 
paragraphs 1 and 2 of this Article shall take place on the basis of 
requirements approved by the supervisory authority which is 
competent pursuant to Article 55 or 56 or by the Board pursuant to 
Article 63. ◄ In the case of accreditation pursuant to point (b) of 
paragraph 1 of this Article, those requirements shall complement 
those envisaged in Regulation (EC) No 765/2008 and the technical 
rules that describe the methods and procedures of the certification 
bodies. 
4. 
The certification bodies referred to in paragraph 1 shall be 
responsible for the proper assessment leading to the certification or 
the withdrawal of such certification without prejudice to the responsi­
bility of the controller or processor for compliance with this Regulation. 
The accreditation shall be issued for a maximum period of five years 
and may be renewed on the same conditions provided that the certifi­
cation body meets the requirements set out in this Article. 
5. 
The certification bodies referred to in paragraph 1 shall provide 
the competent supervisory authorities with the reasons for granting or 
withdrawing the requested certification. 
▼C1 
6. 
The requirements referred to in paragraph 3 of this Article and the 
criteria referred to in Article 42(5) shall be made public by the super­
visory authority in an easily accessible form. The supervisory authorities 
shall also transmit those requirements and criteria to the Board. 
▼B 
7. 
Without prejudice to Chapter VIII, the competent supervisory 
authority or the national accreditation body shall revoke an accreditation 
of a certification body pursuant to paragraph 1 of this Article where the 
conditions for the accreditation are not, or are no longer, met or where 
actions taken by a certification body infringe this Regulation. 
8. 
The Commission shall be empowered to adopt delegated acts in 
accordance with Article 92 for the purpose of specifying the 
requirements to be taken into account for the data protection certifi­
cation mechanisms referred to in Article 42(1). 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 41 
9. 
The Commission may adopt implementing acts laying down 
technical standards for certification mechanisms and data protection 
seals and marks, and mechanisms to promote and recognise those 
certification mechanisms, seals and marks. Those implementing acts 
shall be adopted in accordance with the examination procedure 
referred to in Article 93(2). 
CHAPTER V 
Transfers of personal data to third countries or international 
organisations 
Article 44 
General principle for transfers 
Any transfer of personal data which are undergoing processing or are 
intended for processing after transfer to a third country or to an inter­
national organisation shall take place only if, subject to the other 
provisions of this Regulation, the conditions laid down in this 
Chapter are complied with by the controller and processor, including 
for onward transfers of personal data from the third country or an 
international organisation to another third country or to another inter­
national organisation. All provisions in this Chapter shall be applied in 
order to ensure that the level of protection of natural persons guaranteed 
by this Regulation is not undermined. 
Article 45 
Transfers on the basis of an adequacy decision 
1. 
A transfer of personal data to a third country or an international 
organisation may take place where the Commission has decided that the 
third country, a territory or one or more specified sectors within that 
third country, or the international organisation in question ensures an 
adequate level of protection. Such a transfer shall not require any 
specific authorisation. 
2. 
When assessing the adequacy of the level of protection, the 
Commission shall, in particular, take account of the following elements: 
(a) the rule of law, respect for human rights and fundamental freedoms, 
relevant legislation, both general and sectoral, including concerning 
public security, defence, national security and criminal law and the 
access of public authorities to personal data, as well as the im­
plementation of such legislation, data protection rules, professional 
rules and security measures, including rules for the onward transfer 
of personal data to another third country or international organis­
ation which are complied with in that country or international 
organisation, case-law, as well as effective and enforceable data 
subject rights and effective administrative and judicial redress for 
the data subjects whose personal data are being transferred; 
(b) the existence and effective functioning of one or more independent 
supervisory authorities in the third country or to which an inter­
national organisation is subject, with responsibility for ensuring and 
enforcing compliance with the data protection rules, including 
adequate enforcement powers, for assisting and advising the data 
subjects in exercising their rights and for cooperation with the 
supervisory authorities of the Member States; and 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 42 
(c) the international commitments the third country or international 
organisation concerned has entered into, or other obligations 
arising from legally binding conventions or instruments as well as 
from its participation in multilateral or regional systems, in 
particular in relation to the protection of personal data. 
3. 
The Commission, after assessing the adequacy of the level of 
protection, may decide, by means of implementing act, that a third 
country, a territory or one or more specified sectors within a third 
country, or an international organisation ensures an adequate level of 
protection within the meaning of paragraph 2 of this Article. The im­
plementing act shall provide for a mechanism for a periodic review, at 
least every four years, which shall take into account all relevant deve­
lopments in the third country or international organisation. The imple­
menting act shall specify its territorial and sectoral application and, 
where applicable, identify the supervisory authority or authorities 
referred to in point (b) of paragraph 2 of this Article. The implementing 
act shall be adopted in accordance with the examination procedure 
referred to in Article 93(2). 
4. 
The Commission shall, on an ongoing basis, monitor develop­
ments in third countries and international organisations that could 
affect the functioning of decisions adopted pursuant to paragraph 3 of 
this Article and decisions adopted on the basis of Article 25(6) of 
Directive 95/46/EC. 
5. 
The Commission shall, where available information reveals, in 
particular following the review referred to in paragraph 3 of this 
Article, that a third country, a territory or one or more specified 
sectors within a third country, or an international organisation no 
longer ensures an adequate level of protection within the meaning of 
paragraph 2 of this Article, to the extent necessary, repeal, amend or 
suspend the decision referred to in paragraph 3 of this Article by means 
of implementing acts without retro-active effect. Those implementing 
acts shall be adopted in accordance with the examination procedure 
referred to in Article 93(2). 
On duly justified imperative grounds of urgency, the Commission shall 
adopt immediately applicable implementing acts in accordance with the 
procedure referred to in Article 93(3). 
6. 
The Commission shall enter into consultations with the third 
country or international organisation with a view to remedying the 
situation giving rise to the decision made pursuant to paragraph 5. 
7. 
A decision pursuant to paragraph 5 of this Article is without 
prejudice to transfers of personal data to the third country, a territory 
or one or more specified sectors within that third country, or the inter­
national organisation in question pursuant to Articles 46 to 49. 
8. 
The Commission shall publish in the Official Journal of the 
European Union and on its website a list of the third countries, terri­
tories and specified sectors within a third country and international 
organisations for which it has decided that an adequate level of 
protection is or is no longer ensured. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 43 
9. 
Decisions adopted by the Commission on the basis of Article 25(6) 
of Directive 95/46/EC shall remain in force until amended, replaced or 
repealed by a Commission Decision adopted in accordance with 
paragraph 3 or 5 of this Article. 
Article 46 
Transfers subject to appropriate safeguards 
1. 
In the absence of a decision pursuant to Article 45(3), a controller 
or processor may transfer personal data to a third country or an inter­
national organisation only if the controller or processor has provided 
appropriate safeguards, and on condition that enforceable data subject 
rights and effective legal remedies for data subjects are available. 
2. 
The appropriate safeguards referred to in paragraph 1 may be 
provided for, without requiring any specific authorisation from a super­
visory authority, by: 
(a) a legally binding and enforceable instrument between public auth­
orities or bodies; 
(b) binding corporate rules in accordance with Article 47; 
(c) standard data protection clauses adopted by the Commission in 
accordance with the examination procedure referred to in 
Article 93(2); 
(d) standard data protection clauses adopted by a supervisory authority 
and approved by the Commission pursuant to the examination 
procedure referred to in Article 93(2); 
(e) an approved code of conduct pursuant to Article 40 together with 
binding and enforceable commitments of the controller or processor 
in the third country to apply the appropriate safeguards, including as 
regards data subjects' rights; or 
(f) an approved certification mechanism pursuant to Article 42 together 
with binding and enforceable commitments of the controller or 
processor in the third country to apply the appropriate safeguards, 
including as regards data subjects' rights. 
3. 
Subject to the authorisation from the competent supervisory auth­
ority, the appropriate safeguards referred to in paragraph 1 may also be 
provided for, in particular, by: 
(a) contractual clauses between the controller or processor and the 
controller, processor or the recipient of the personal data in the 
third country or international organisation; or 
(b) provisions to be inserted into administrative arrangements between 
public authorities or bodies which include enforceable and effective 
data subject rights. 
4. 
The supervisory authority shall apply the consistency mechanism 
referred to in Article 63 in the cases referred to in paragraph 3 of this 
Article. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 44 
5. 
Authorisations by a Member State or supervisory authority on the 
basis of Article 26(2) of Directive 95/46/EC shall remain valid until 
amended, replaced or repealed, if necessary, by that supervisory auth­
ority. Decisions adopted by the Commission on the basis of Article 26(4) 
of Directive 95/46/EC shall remain in force until amended, replaced or 
repealed, if necessary, by a Commission Decision adopted in accordance 
with paragraph 2 of this Article. 
Article 47 
Binding corporate rules 
1. 
The competent supervisory authority shall approve binding 
corporate rules in accordance with the consistency mechanism set out 
in Article 63, provided that they: 
(a) are legally binding and apply to and are enforced by every member 
concerned of the group of undertakings, or group of enterprises 
engaged in a joint economic activity, including their employees; 
(b) expressly confer enforceable rights on data subjects with regard to 
the processing of their personal data; and 
(c) fulfil the requirements laid down in paragraph 2. 
2. 
The binding corporate rules referred to in paragraph 1 shall specify 
at least: 
(a) the structure and contact details of the group of undertakings, or 
group of enterprises engaged in a joint economic activity and of 
each of its members; 
(b) the data transfers or set of transfers, including the categories of 
personal data, the type of processing and its purposes, the type 
of data subjects affected and the identification of the third 
country or countries in question; 
(c) their legally binding nature, both internally and externally; 
(d) the application of the general data protection principles, in 
particular purpose limitation, data minimisation, limited storage 
periods, data quality, data protection by design and by default, 
legal basis for processing, processing of special categories of 
personal data, measures to ensure data security, and the 
requirements in respect of onward transfers to bodies not bound 
by the binding corporate rules; 
(e) the rights of data subjects in regard to processing and the means to 
exercise those rights, including the right not to be subject to 
decisions based solely on automated processing, including 
profiling in accordance with Article 22, the right to lodge a 
complaint with the competent supervisory authority and before 
the competent courts of the Member States in accordance with 
Article 79, and to obtain redress and, where appropriate, compen­
sation for a breach of the binding corporate rules; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 45 
(f) the acceptance by the controller or processor established on the 
territory of a Member State of liability for any breaches of the 
binding corporate rules by any member concerned not established 
in the Union; the controller or the processor shall be exempt from 
that liability, in whole or in part, only if it proves that that member 
is not responsible for the event giving rise to the damage; 
(g) how the information on the binding corporate rules, in particular on 
the provisions referred to in points (d), (e) and (f) of this paragraph 
is provided to the data subjects in addition to Articles 13 and 14; 
(h) the tasks of any data protection officer designated in accordance 
with Article 37 or any other person or entity in charge of the 
monitoring compliance with the binding corporate rules within 
the group of undertakings, or group of enterprises engaged in a 
joint economic activity, as well as monitoring training and 
complaint-handling; 
(i) the complaint procedures; 
(j) the mechanisms within the group of undertakings, or group of 
enterprises engaged in a joint economic activity for ensuring the 
verification of compliance with the binding corporate rules. Such 
mechanisms shall include data protection audits and methods for 
ensuring corrective actions to protect the rights of the data subject. 
Results of such verification should be communicated to the person 
or entity referred to in point (h) and to the board of the controlling 
undertaking of a group of undertakings, or of the group of enter­
prises engaged in a joint economic activity, and should be available 
upon request to the competent supervisory authority; 
(k) the mechanisms for reporting and recording changes to the rules 
and reporting those changes to the supervisory authority; 
(l) the cooperation mechanism with the supervisory authority to ensure 
compliance by any member of the group of undertakings, or group 
of enterprises engaged in a joint economic activity, in particular by 
making available to the supervisory authority the results of verifi­
cations of the measures referred to in point (j); 
(m) the mechanisms for reporting to the competent supervisory 
authority any legal requirements to which a member of the group 
of undertakings, or group of enterprises engaged in a joint 
economic activity is subject in a third country which are likely 
to have a substantial adverse effect on the guarantees provided 
by the binding corporate rules; and 
(n) the appropriate data protection training to personnel having 
permanent or regular access to personal data. 
3. 
The Commission may specify the format and procedures for the 
exchange of information between controllers, processors and super­
visory authorities for binding corporate rules within the meaning of 
this Article. Those implementing acts shall be adopted in accordance 
with the examination procedure set out in Article 93(2). 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 46 
Article 48 
Transfers or disclosures not authorised by Union law 
Any judgment of a court or tribunal and any decision of an adminis­
trative authority of a third country requiring a controller or processor to 
transfer or disclose personal data may only be recognised or enforceable 
in any manner if based on an international agreement, such as a mutual 
legal assistance treaty, in force between the requesting third country and 
the Union or a Member State, without prejudice to other grounds for 
transfer pursuant to this Chapter. 
Article 49 
Derogations for specific situations 
1. 
In the absence of an adequacy decision pursuant to Article 45(3), 
or of appropriate safeguards pursuant to Article 46, including binding 
corporate rules, a transfer or a set of transfers of personal data to a third 
country or an international organisation shall take place only on one of 
the following conditions: 
(a) the data subject has explicitly consented to the proposed transfer, 
after having been informed of the possible risks of such transfers for 
the data subject due to the absence of an adequacy decision and 
appropriate safeguards; 
(b) the transfer is necessary for the performance of a contract between 
the data subject and the controller or the implementation of 
pre-contractual measures taken at the data subject's request; 
(c) the transfer is necessary for the conclusion or performance of a 
contract concluded in the interest of the data subject between the 
controller and another natural or legal person; 
(d) the transfer is necessary for important reasons of public interest; 
(e) the transfer is necessary for the establishment, exercise or defence 
of legal claims; 
(f) the transfer is necessary in order to protect the vital interests of the 
data subject or of other persons, where the data subject is physically 
or legally incapable of giving consent; 
(g) the transfer is made from a register which according to Union or 
Member State law is intended to provide information to the public 
and which is open to consultation either by the public in general or 
by any person who can demonstrate a legitimate interest, but only to 
the extent that the conditions laid down by Union or Member State 
law for consultation are fulfilled in the particular case. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 47 
Where a transfer could not be based on a provision in Article 45 or 46, 
including the provisions on binding corporate rules, and none of the 
derogations for a specific situation referred to in the first subparagraph 
of this paragraph is applicable, a transfer to a third country or an 
international organisation may take place only if the transfer is not 
repetitive, concerns only a limited number of data subjects, is 
necessary for the purposes of compelling legitimate interests pursued 
by the controller which are not overridden by the interests or rights and 
freedoms of the data subject, and the controller has assessed all the 
circumstances surrounding the data transfer and has on the basis of 
that assessment provided suitable safeguards with regard to the 
protection of personal data. The controller shall inform the supervisory 
authority of the transfer. The controller shall, in addition to providing 
the information referred to in Articles 13 and 14, inform the data subject 
of the transfer and on the compelling legitimate interests pursued. 
2. 
A transfer pursuant to point (g) of the first subparagraph of 
paragraph 1 shall not involve the entirety of the personal data or 
entire categories of the personal data contained in the register. Where 
the register is intended for consultation by persons having a legitimate 
interest, the transfer shall be made only at the request of those persons 
or if they are to be the recipients. 
3. 
Points (a), (b) and (c) of the first subparagraph of paragraph 1 and 
the second subparagraph thereof shall not apply to activities carried out 
by public authorities in the exercise of their public powers. 
4. 
The public interest referred to in point (d) of the first subparagraph 
of paragraph 1 shall be recognised in Union law or in the law of the 
Member State to which the controller is subject. 
5. 
In the absence of an adequacy decision, Union or Member State 
law may, for important reasons of public interest, expressly set limits to 
the transfer of specific categories of personal data to a third country or 
an international organisation. Member States shall notify such 
provisions to the Commission. 
6. 
The controller or processor shall document the assessment as well 
as the suitable safeguards referred to in the second subparagraph of 
paragraph 1 of this Article in the records referred to in Article 30. 
Article 50 
International cooperation for the protection of personal data 
In relation to third countries and international organisations, the 
Commission and supervisory authorities shall take appropriate steps to: 
(a) develop international cooperation mechanisms to facilitate the 
effective enforcement of legislation for the protection of personal 
data; 
(b) provide international mutual assistance in the enforcement of legis­
lation for the protection of personal data, including through notifi­
cation, complaint referral, investigative assistance and information 
exchange, subject to appropriate safeguards for the protection of 
personal data and other fundamental rights and freedoms; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 48 
(c) engage relevant stakeholders in discussion and activities aimed at 
furthering international cooperation in the enforcement of legislation 
for the protection of personal data; 
(d) promote the exchange and documentation of personal data 
protection legislation and practice, including on jurisdictional 
conflicts with third countries. 
CHAPTER VI 
Independent supervisory authorities 
S e c t i o n 1 
I n d e p e n d e n t s t a t u s 
Article 51 
Supervisory authority 
1. 
Each Member State shall provide for one or more independent 
public authorities to be responsible for monitoring the application of 
this Regulation, in order to protect the fundamental rights and freedoms 
of natural persons in relation to processing and to facilitate the free flow 
of personal data within the Union (‘supervisory authority’). 
2. 
Each supervisory authority shall contribute to the consistent appli­
cation of this Regulation throughout the Union. For that purpose, the 
supervisory authorities shall cooperate with each other and the 
Commission in accordance with Chapter VII. 
3. 
Where more than one supervisory authority is established in a 
Member State, that Member State shall designate the supervisory 
authority which is to represent those authorities in the Board and 
shall set out the mechanism to ensure compliance by the other auth­
orities with the rules relating to the consistency mechanism referred to 
in Article 63. 
4. 
Each Member State shall notify to the Commission the provisions 
of its law which it adopts pursuant to this Chapter, by 25 May 2018 
and, without delay, any subsequent amendment affecting them. 
Article 52 
Independence 
1. 
Each supervisory authority shall act with complete independence 
in performing its tasks and exercising its powers in accordance with this 
Regulation. 
2. 
The member or members of each supervisory authority shall, in 
the performance of their tasks and exercise of their powers in 
accordance with this Regulation, remain free from external influence, 
whether direct or indirect, and shall neither seek nor take instructions 
from anybody. 
3. 
Member or members of each supervisory authority shall refrain 
from any action incompatible with their duties and shall not, during 
their term of office, engage in any incompatible occupation, whether 
gainful or not. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 49 
4. 
Each Member State shall ensure that each supervisory authority is 
provided with the human, technical and financial resources, premises 
and infrastructure necessary for the effective performance of its tasks 
and exercise of its powers, including those to be carried out in the 
context of mutual assistance, cooperation and participation in the Board. 
5. 
Each Member State shall ensure that each supervisory authority 
chooses and has its own staff which shall be subject to the exclusive 
direction of the member or members of the supervisory authority 
concerned. 
6. 
Each Member State shall ensure that each supervisory authority is 
subject to financial control which does not affect its independence and 
that it has separate, public annual budgets, which may be part of the 
overall state or national budget. 
Article 53 
General conditions for the members of the supervisory authority 
1. 
Member States shall provide for each member of their supervisory 
authorities to be appointed by means of a transparent procedure by: 
— their parliament; 
— their government; 
— their head of State; or 
— an independent body entrusted with the appointment under Member 
State law. 
2. 
Each member shall have the qualifications, experience and skills, 
in particular in the area of the protection of personal data, required to 
perform its duties and exercise its powers. 
3. 
The duties of a member shall end in the event of the expiry of the 
term of office, resignation or compulsory retirement, in accordance with 
the law of the Member State concerned. 
4. 
A member shall be dismissed only in cases of serious misconduct 
or if the member no longer fulfils the conditions required for the 
performance of the duties. 
Article 54 
Rules on the establishment of the supervisory authority 
1. 
Each Member State shall provide by law for all of the following: 
(a) the establishment of each supervisory authority; 
(b) the qualifications and eligibility conditions required to be appointed 
as member of each supervisory authority; 
(c) the rules and procedures for the appointment of the member or 
members of each supervisory authority; 
(d) the duration of the term of the member or members of each super­
visory authority of no less than four years, except for the first 
appointment after 24 May 2016, part of which may take place for 
a shorter period where that is necessary to protect the independence 
of the supervisory authority by means of a staggered appointment 
procedure; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 50 
(e) whether and, if so, for how many terms the member or members of 
each supervisory authority is eligible for reappointment; 
(f) the conditions governing the obligations of the member or members 
and staff of each supervisory authority, prohibitions on actions, 
occupations and benefits incompatible therewith during and after 
the term of office and rules governing the cessation of employment. 
2. 
The member or members and the staff of each supervisory 
authority shall, in accordance with Union or Member State law, be 
subject to a duty of professional secrecy both during and after their 
term of office, with regard to any confidential information which has 
come to their knowledge in the course of the performance of their tasks 
or exercise of their powers. During their term of office, that duty of 
professional secrecy shall in particular apply to reporting by natural 
persons of infringements of this Regulation. 
S e c t i o n 2 
C o m p e t e n c e , t a s k s a n d p o w e r s 
Article 55 
Competence 
1. 
Each supervisory authority shall be competent for the performance 
of the tasks assigned to and the exercise of the powers conferred on it in 
accordance with this Regulation on the territory of its own Member 
State. 
2. 
Where processing is carried out by public authorities or private 
bodies acting on the basis of point (c) or (e) of Article 6(1), the super­
visory authority of the Member State concerned shall be competent. In 
such cases Article 56 does not apply. 
3. 
Supervisory authorities shall not be competent to supervise 
processing operations of courts acting in their judicial capacity. 
Article 56 
Competence of the lead supervisory authority 
1. 
Without prejudice to Article 55, the supervisory authority of the 
main establishment or of the single establishment of the controller or 
processor shall be competent to act as lead supervisory authority for the 
cross-border processing carried out by that controller or processor in 
accordance with the procedure provided in Article 60. 
2. 
By derogation from paragraph 1, each supervisory authority shall 
be competent to handle a complaint lodged with it or a possible 
infringement of this Regulation, if the subject matter relates only to 
an establishment in its Member State or substantially affects data 
subjects only in its Member State. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 51 
3. 
In the cases referred to in paragraph 2 of this Article, the super­
visory authority shall inform the lead supervisory authority without 
delay on that matter. Within a period of three weeks after being 
informed the lead supervisory authority shall decide whether or not it 
will handle the case in accordance with the procedure provided in 
Article 60, taking into account whether or not there is an establishment 
of the controller or processor in the Member State of which the super­
visory authority informed it. 
4. 
Where the lead supervisory authority decides to handle the case, 
the procedure provided in Article 60 shall apply. The supervisory 
authority which informed the lead supervisory authority may submit 
to the lead supervisory authority a draft for a decision. The lead super­
visory authority shall take utmost account of that draft when preparing 
the draft decision referred to in Article 60(3). 
5. 
Where the lead supervisory authority decides not to handle the 
case, the supervisory authority which informed the lead supervisory 
authority shall handle it according to Articles 61 and 62. 
6. 
The lead supervisory authority shall be the sole interlocutor of the 
controller or processor for the cross-border processing carried out by 
that controller or processor. 
Article 57 
Tasks 
1. 
Without prejudice to other tasks set out under this Regulation, 
each supervisory authority shall on its territory: 
(a) monitor and enforce the application of this Regulation; 
(b) promote public awareness and understanding of the risks, rules, 
safeguards and rights in relation to processing. Activities 
addressed specifically to children shall receive specific attention; 
(c) advise, in accordance with Member State law, the national 
parliament, the government, and other institutions and bodies on 
legislative and administrative measures relating to the protection of 
natural persons' rights and freedoms with regard to processing; 
(d) promote the awareness of controllers and processors of their obli­
gations under this Regulation; 
(e) upon request, provide information to any data subject concerning 
the exercise of their rights under this Regulation and, if appropriate, 
cooperate with the supervisory authorities in other Member States 
to that end; 
(f) handle complaints lodged by a data subject, or by a body, organis­
ation or association in accordance with Article 80, and investigate, 
to the extent appropriate, the subject matter of the complaint and 
inform the complainant of the progress and the outcome of the 
investigation within a reasonable period, in particular if further 
investigation or coordination with another supervisory authority is 
necessary; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 52 
(g) cooperate with, including sharing information and provide mutual 
assistance to, other supervisory authorities with a view to ensuring 
the consistency of application and enforcement of this Regulation; 
(h) conduct investigations on the application of this Regulation, 
including on the basis of information received from another super­
visory authority or other public authority; 
(i) monitor relevant developments, insofar as they have an impact on 
the protection of personal data, in particular the development of 
information and communication technologies and commercial 
practices; 
(j) adopt standard contractual clauses referred to in Article 28(8) and 
in point (d) of Article 46(2); 
(k) establish and maintain a list in relation to the requirement for data 
protection impact assessment pursuant to Article 35(4); 
(l) give advice on the processing operations referred to in 
Article 36(2); 
(m) encourage the drawing up of codes of conduct pursuant to 
Article 40(1) and provide an opinion and approve such codes of 
conduct 
which 
provide 
sufficient 
safeguards, 
pursuant 
to 
Article 40(5); 
(n) encourage the establishment of data protection certification mech­
anisms and of data protection seals and marks pursuant to 
Article 42(1), and approve the criteria of certification pursuant to 
Article 42(5); 
(o) where applicable, carry out a periodic review of certifications 
issued in accordance with Article 42(7); 
▼C1 
(p) draft and publish the requirements for accreditation of a body for 
monitoring codes of conduct pursuant to Article 41 and of a certifi­
cation body pursuant to Article 43; 
▼B 
(q) conduct the accreditation of a body for monitoring codes of 
conduct pursuant to Article 41 and of a certification body 
pursuant to Article 43; 
(r) authorise contractual clauses and provisions referred to in 
Article 46(3); 
(s) approve binding corporate rules pursuant to Article 47; 
(t) contribute to the activities of the Board; 
(u) keep internal records of infringements of this Regulation and of 
measures taken in accordance with Article 58(2); and 
(v) fulfil any other tasks related to the protection of personal data. 
2. 
Each supervisory authority shall facilitate the submission of 
complaints referred to in point (f) of paragraph 1 by measures such 
as a complaint submission form which can also be completed electroni­
cally, without excluding other means of communication. 
3. 
The performance of the tasks of each supervisory authority shall 
be free of charge for the data subject and, where applicable, for the data 
protection officer. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 53 
4. 
Where requests are manifestly unfounded or excessive, in 
particular because of their repetitive character, the supervisory 
authority may charge a reasonable fee based on administrative costs, 
or refuse to act on the request. The supervisory authority shall bear the 
burden of demonstrating the manifestly unfounded or excessive 
character of the request. 
Article 58 
Powers 
1. 
Each supervisory authority shall have all of the following inves­
tigative powers: 
(a) to order the controller and the processor, and, where applicable, the 
controller's or the processor's representative to provide any 
information it requires for the performance of its tasks; 
(b) to carry out investigations in the form of data protection audits; 
(c) to carry out a review on certifications issued pursuant to 
Article 42(7); 
(d) to notify the controller or the processor of an alleged infringement 
of this Regulation; 
(e) to obtain, from the controller and the processor, access to all 
personal data and to all information necessary for the performance 
of its tasks; 
(f) to obtain access to any premises of the controller and the processor, 
including to any data processing equipment and means, in 
accordance with Union or Member State procedural law. 
2. 
Each supervisory authority shall have all of the following 
corrective powers: 
(a) to issue warnings to a controller or processor that intended 
processing operations are likely to infringe provisions of this Regu­
lation; 
(b) to issue reprimands to a controller or a processor where processing 
operations have infringed provisions of this Regulation; 
(c) to order the controller or the processor to comply with the data 
subject's requests to exercise his or her rights pursuant to this 
Regulation; 
(d) to order the controller or processor to bring processing operations 
into compliance with the provisions of this Regulation, where 
appropriate, in a specified manner and within a specified period; 
(e) to order the controller to communicate a personal data breach to the 
data subject; 
(f) to impose a temporary or definitive limitation including a ban on 
processing; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 54 
(g) to order the rectification or erasure of personal data or restriction of 
processing pursuant to Articles 16, 17 and 18 and the notification of 
such actions to recipients to whom the personal data have been 
disclosed pursuant to Article 17(2) and Article 19; 
(h) to withdraw a certification or to order the certification body to 
withdraw a certification issued pursuant to Articles 42 and 43, or 
to order the certification body not to issue certification if the 
requirements for the certification are not or are no longer met; 
(i) to impose an administrative fine pursuant to Article 83, in addition 
to, or instead of measures referred to in this paragraph, depending 
on the circumstances of each individual case; 
(j) to order the suspension of data flows to a recipient in a third 
country or to an international organisation. 
3. 
Each supervisory authority shall have all of the following author­
isation and advisory powers: 
(a) to advise the controller in accordance with the prior consultation 
procedure referred to in Article 36; 
(b) to issue, on its own initiative or on request, opinions to the national 
parliament, the Member State government or, in accordance with 
Member State law, to other institutions and bodies as well as to the 
public on any issue related to the protection of personal data; 
(c) to authorise processing referred to in Article 36(5), if the law of the 
Member State requires such prior authorisation; 
(d) to issue an opinion and approve draft codes of conduct pursuant to 
Article 40(5); 
(e) to accredit certification bodies pursuant to Article 43; 
(f) to issue certifications and approve criteria of certification in 
accordance with Article 42(5); 
(g) to adopt standard data protection clauses referred to in Article 28(8) 
and in point (d) of Article 46(2); 
(h) to authorise contractual clauses referred to in point (a) of 
Article 46(3); 
(i) to authorise administrative arrangements referred to in point (b) of 
Article 46(3); 
(j) to approve binding corporate rules pursuant to Article 47. 
4. 
The exercise of the powers conferred on the supervisory authority 
pursuant to this Article shall be subject to appropriate safeguards, 
including effective judicial remedy and due process, set out in Union 
and Member State law in accordance with the Charter. 
5. 
Each Member State shall provide by law that its supervisory 
authority shall have the power to bring infringements of this Regulation 
to the attention of the judicial authorities and where appropriate, to 
commence or engage otherwise in legal proceedings, in order to 
enforce the provisions of this Regulation. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 55 
6. 
Each Member State may provide by law that its supervisory 
authority shall have additional powers to those referred to in para­
graphs 1, 2 and 3. The exercise of those powers shall not impair the 
effective operation of Chapter VII. 
Article 59 
Activity reports 
Each supervisory authority shall draw up an annual report on its activ­
ities, which may include a list of types of infringement notified and 
types of measures taken in accordance with Article 58(2). Those reports 
shall be transmitted to the national parliament, the government and other 
authorities as designated by Member State law. They shall be made 
available to the public, to the Commission and to the Board. 
CHAPTER VII 
Cooperation and consistency 
S e c t i o n 1 
C o o p e r a t i o n 
Article 60 
Cooperation between the lead supervisory authority and the other 
supervisory authorities concerned 
1. 
The lead supervisory authority shall cooperate with the other 
supervisory authorities concerned in accordance with this Article in an 
endeavour to reach consensus. The lead supervisory authority and the 
supervisory 
authorities 
concerned 
shall 
exchange 
all 
relevant 
information with each other. 
2. 
The lead supervisory authority may request at any time other 
supervisory authorities concerned to provide mutual assistance 
pursuant to Article 61 and may conduct joint operations pursuant to 
Article 62, in particular for carrying out investigations or for monitoring 
the implementation of a measure concerning a controller or processor 
established in another Member State. 
3. 
The lead supervisory authority shall, without delay, communicate 
the relevant information on the matter to the other supervisory auth­
orities concerned. It shall without delay submit a draft decision to the 
other supervisory authorities concerned for their opinion and take due 
account of their views. 
4. 
Where any of the other supervisory authorities concerned within a 
period of four weeks after having been consulted in accordance with 
paragraph 3 of this Article, expresses a relevant and reasoned objection 
to the draft decision, the lead supervisory authority shall, if it does not 
follow the relevant and reasoned objection or is of the opinion that the 
objection is not relevant or reasoned, submit the matter to the 
consistency mechanism referred to in Article 63. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 56 
5. 
Where the lead supervisory authority intends to follow the relevant 
and reasoned objection made, it shall submit to the other supervisory 
authorities concerned a revised draft decision for their opinion. That 
revised draft decision shall be subject to the procedure referred to in 
paragraph 4 within a period of two weeks. 
6. 
Where none of the other supervisory authorities concerned has 
objected to the draft decision submitted by the lead supervisory 
authority within the period referred to in paragraphs 4 and 5, the lead 
supervisory authority and the supervisory authorities concerned shall be 
deemed to be in agreement with that draft decision and shall be bound 
by it. 
7. 
The lead supervisory authority shall adopt and notify the decision 
to the main establishment or single establishment of the controller or 
processor, as the case may be and inform the other supervisory auth­
orities concerned and the Board of the decision in question, including a 
summary of the relevant facts and grounds. The supervisory authority 
with which a complaint has been lodged shall inform the complainant 
on the decision. 
8. 
By derogation from paragraph 7, where a complaint is dismissed 
or rejected, the supervisory authority with which the complaint was 
lodged shall adopt the decision and notify it to the complainant and 
shall inform the controller thereof. 
9. 
Where the lead supervisory authority and the supervisory auth­
orities concerned agree to dismiss or reject parts of a complaint and 
to act on other parts of that complaint, a separate decision shall be 
adopted for each of those parts of the matter. The lead supervisory 
authority shall adopt the decision for the part concerning actions in 
relation to the controller, shall notify it to the main establishment or 
single establishment of the controller or processor on the territory of its 
Member State and shall inform the complainant thereof, while the 
supervisory authority of the complainant shall adopt the decision for 
the part concerning dismissal or rejection of that complaint, and shall 
notify it to that complainant and shall inform the controller or processor 
thereof. 
10. 
After being notified of the decision of the lead supervisory 
authority pursuant to paragraphs 7 and 9, the controller or processor 
shall take the necessary measures to ensure compliance with the 
decision as regards processing activities in the context of all its estab­
lishments in the Union. The controller or processor shall notify the 
measures taken for complying with the decision to the lead supervisory 
authority, which shall inform the other supervisory authorities 
concerned. 
11. 
Where, in exceptional circumstances, a supervisory authority 
concerned has reasons to consider that there is an urgent need to act 
in order to protect the interests of data subjects, the urgency procedure 
referred to in Article 66 shall apply. 
12. 
The lead supervisory authority and the other supervisory auth­
orities concerned shall supply the information required under this 
Article to each other by electronic means, using a standardised format. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 57 
Article 61 
Mutual assistance 
1. 
Supervisory authorities shall provide each other with relevant 
information and mutual assistance in order to implement and apply 
this Regulation in a consistent manner, and shall put in place 
measures for effective cooperation with one another. Mutual assistance 
shall cover, in particular, information requests and supervisory 
measures, such as requests to carry out prior authorisations and consul­
tations, inspections and investigations. 
2. 
Each supervisory authority shall take all appropriate measures 
required to reply to a request of another supervisory authority without 
undue delay and no later than one month after receiving the request. 
Such measures may include, in particular, the transmission of relevant 
information on the conduct of an investigation. 
3. 
Requests for assistance shall contain all the necessary information, 
including the purpose of and reasons for the request. Information 
exchanged shall be used only for the purpose for which it was 
requested. 
4. 
The requested supervisory authority shall not refuse to comply 
with the request unless: 
(a) it is not competent for the subject-matter of the request or for the 
measures it is requested to execute; or 
(b) compliance with the request would infringe this Regulation or 
Union or Member State law to which the supervisory authority 
receiving the request is subject. 
5. 
The requested supervisory authority shall inform the requesting 
supervisory authority of the results or, as the case may be, of the 
progress of the measures taken in order to respond to the request. 
The requested supervisory authority shall provide reasons for any 
refusal to comply with a request pursuant to paragraph 4. 
6. 
Requested supervisory authorities shall, as a rule, supply the 
information requested by other supervisory authorities by electronic 
means, using a standardised format. 
7. 
Requested supervisory authorities shall not charge a fee for any 
action taken by them pursuant to a request for mutual assistance. Super­
visory authorities may agree on rules to indemnify each other for 
specific expenditure arising from the provision of mutual assistance in 
exceptional circumstances. 
8. 
Where a supervisory authority does not provide the information 
referred to in paragraph 5 of this Article within one month of receiving 
the request of another supervisory authority, the requesting supervisory 
authority may adopt a provisional measure on the territory of its 
Member State in accordance with Article 55(1). In that case, the 
urgent need to act under Article 66(1) shall be presumed to be met 
and require an urgent binding decision from the Board pursuant to 
Article 66(2). 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 58 
9. 
The Commission may, by means of implementing acts, specify the 
format and procedures for mutual assistance referred to in this Article 
and the arrangements for the exchange of information by electronic 
means between supervisory authorities, and between supervisory auth­
orities and the Board, in particular the standardised format referred to in 
paragraph 6 of this Article. Those implementing acts shall be adopted in 
accordance with the examination procedure referred to in Article 93(2). 
Article 62 
Joint operations of supervisory authorities 
1. 
The supervisory authorities shall, where appropriate, conduct joint 
operations including joint investigations and joint enforcement measures 
in which members or staff of the supervisory authorities of other 
Member States are involved. 
2. 
Where the controller or processor has establishments in several 
Member States or where a significant number of data subjects in 
more than one Member State are likely to be substantially affected by 
processing operations, a supervisory authority of each of those Member 
States shall have the right to participate in joint operations. The super­
visory authority which is competent pursuant to Article 56(1) or (4) 
shall invite the supervisory authority of each of those Member States 
to take part in the joint operations and shall respond without delay to 
the request of a supervisory authority to participate. 
3. 
A supervisory authority may, in accordance with Member State 
law, and with the seconding supervisory authority's authorisation, confer 
powers, including investigative powers on the seconding supervisory 
authority's members or staff involved in joint operations or, in so far 
as the law of the Member State of the host supervisory authority 
permits, allow the seconding supervisory authority's members or staff 
to exercise their investigative powers in accordance with the law of the 
Member State of the seconding supervisory authority. Such investigative 
powers may be exercised only under the guidance and in the presence 
of members or staff of the host supervisory authority. The seconding 
supervisory authority's members or staff shall be subject to the 
Member State law of the host supervisory authority. 
4. 
Where, in accordance with paragraph 1, staff of a seconding 
supervisory 
authority 
operate 
in 
another 
Member 
State, 
the 
Member State of the host supervisory authority shall assume responsi­
bility for their actions, including liability, for any damage caused by 
them during their operations, in accordance with the law of the 
Member State in whose territory they are operating. 
5. 
The Member State in whose territory the damage was caused shall 
make good such damage under the conditions applicable to damage 
caused by its own staff. The Member State of the seconding supervisory 
authority whose staff has caused damage to any person in the territory 
of another Member State shall reimburse that other Member State in full 
any sums it has paid to the persons entitled on their behalf. 
6. 
Without prejudice to the exercise of its rights vis-à-vis third parties 
and with the exception of paragraph 5, each Member State shall refrain, 
in the case provided for in paragraph 1, from requesting reimbursement 
from another Member State in relation to damage referred to in 
paragraph 4. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 59 
7. 
Where a joint operation is intended and a supervisory authority 
does not, within one month, comply with the obligation laid down in 
the second sentence of paragraph 2 of this Article, the other supervisory 
authorities may adopt a provisional measure on the territory of its 
Member State in accordance with Article 55. In that case, the urgent 
need to act under Article 66(1) shall be presumed to be met and require 
an opinion or an urgent binding decision from the Board pursuant to 
Article 66(2). 
S e c t i o n 2 
C o n s i s t e n c y 
Article 63 
Consistency mechanism 
In order to contribute to the consistent application of this Regulation 
throughout the Union, the supervisory authorities shall cooperate with 
each other and, where relevant, with the Commission, through the 
consistency mechanism as set out in this Section. 
Article 64 
Opinion of the Board 
1. 
The Board shall issue an opinion where a competent supervisory 
authority intends to adopt any of the measures below. To that end, the 
competent supervisory authority shall communicate the draft decision to 
the Board, when it: 
(a) aims to adopt a list of the processing operations subject to the 
requirement for a data protection impact assessment pursuant to 
Article 35(4); 
(b) concerns a matter pursuant to Article 40(7) whether a draft code of 
conduct or an amendment or extension to a code of conduct 
complies with this Regulation; 
▼C1 
(c) aims to approve the requirements for accreditation of a body 
pursuant to Article 41(3), of a certification body pursuant to 
Article 43(3) or the criteria for certification referred to in 
Article 42(5); 
▼B 
(d) aims to determine standard data protection clauses referred to in 
point (d) of Article 46(2) and in Article 28(8); 
(e) aims to authorise contractual clauses referred to in point (a) of 
Article 46(3); or 
(f) aims to approve binding corporate rules within the meaning of 
Article 47. 
2. 
Any supervisory authority, the Chair of the Board or the 
Commission may request that any matter of general application or 
producing effects in more than one Member State be examined by the 
Board with a view to obtaining an opinion, in particular where a 
competent supervisory authority does not comply with the obligations 
for mutual assistance in accordance with Article 61 or for joint oper­
ations in accordance with Article 62. 
▼B


02016R0679 — EN — 04.05.2016 — 000.002 — 60 
3. 
In the cases referred to in paragraphs 1 and 2, the Board shall 
issue an opinion on the matter submitted to it provided that it has not 
already issued an opinion on the same matter. That opinion shall be 
adopted within eight weeks by simple majority of the members of the 
Board. That period may be extended by a further six weeks, taking into 
account the complexity of the subject matter. Regarding the draft 
decision referred to in paragraph 1 circulated to the members of the 
Board in accordance with paragraph 5, a member which has not 
objected within a reasonable period indicated by the Chair, shall be 
deemed to be in agreement with the draft decision. 
4. 
Supervisory authorities and the Commission shall, without undue 
delay, communicate by electronic means to the Board, using a stan­
dardised format any relevant information, including as the case may 
be a summary of the facts, the draft decision, the grounds which 
make the enactment of such measure necessary, and the views of 
other supervisory authorities concerned. 
5. 
The Chair of the Board shall, without undue, delay inform by 
electronic means: 
(a) the members of the Board and the Commission of any relevant 
information which has been communicated to it using a standardised 
format. The secretariat of the Board shall, where necessary, provide 
translations of relevant information; and 
(b) the supervisory authority referred to, as the case may be, in para­
graphs 1 and 2, and the Commission of the opinion and make it 
public. 
▼C1 
6. 
The competent supervisory authority referred to in paragraph 1 
shall not adopt its draft decision referred to in paragraph 1 within the 
period referred to in paragraph 3. 
7. 
The competent supervisory authority referred to in paragraph 1 
shall take utmost account of the opinion of the Board and shall, 
within two weeks after receiving the opinion, communicate to the 
Chair of the Board by electronic means whether it will maintain or 
amend its draft decision and, if any, the amended draft decision, 
using a standardised format. 
8. 
Where the competent supervisory authority referred to in 
paragraph 1 informs the Chair of the Board within the period referred 
to in paragraph 7 of this Article that it does not intend to follow the 
opinion of the Board, in whole or in part, providing the relevant 
grounds, Article 65(1) shall apply. 
▼B 
Article 65 
Dispute resolution by the Board 
1. 
In order to ensure the correct and consistent application of this 
Regulation in individual cases, the Board shall adopt a binding decision 
in the following cases: 
(a) ►C1 where, in a case referred to in Article 60(4), a supervisory 
authority concerned has raised a relevant and reasoned objection to 
a draft decision of the lead supervisory authority and the lead super­
visory authority has not followed the objection or has rejected such 
▼B


02016R0679 — EN — 04.05.2016 — 000.002 — 61 
an objection as being not relevant or reasoned. ◄ The binding 
decision shall concern all the matters which are the subject of the 
relevant and reasoned objection, in particular whether there is an 
infringement of this Regulation; 
(b) where there are conflicting views on which of the supervisory auth­
orities concerned is competent for the main establishment; 
(c) where a competent supervisory authority does not request the 
opinion of the Board in the cases referred to in Article 64(1), or 
does not follow the opinion of the Board issued under Article 64. In 
that case, any supervisory authority concerned or the Commission 
may communicate the matter to the Board. 
2. 
The decision referred to in paragraph 1 shall be adopted within 
one month from the referral of the subject-matter by a two-thirds 
majority of the members of the Board. That period may be extended 
by a further month on account of the complexity of the subject-matter. 
The decision referred to in paragraph 1 shall be reasoned and addressed 
to the lead supervisory authority and all the supervisory authorities 
concerned and binding on them. 
3. 
Where the Board has been unable to adopt a decision within the 
periods referred to in paragraph 2, it shall adopt its decision within two 
weeks following the expiration of the second month referred to in 
paragraph 2 by a simple majority of the members of the Board. 
Where the members of the Board are split, the decision shall by 
adopted by the vote of its Chair. 
4. 
The supervisory authorities concerned shall not adopt a decision 
on the subject matter submitted to the Board under paragraph 1 during 
the periods referred to in paragraphs 2 and 3. 
5. 
The Chair of the Board shall notify, without undue delay, the 
decision referred to in paragraph 1 to the supervisory authorities 
concerned. It shall inform the Commission thereof. The decision shall 
be published on the website of the Board without delay after the super­
visory authority has notified the final decision referred to in 
paragraph 6. 
6. 
The lead supervisory authority or, as the case may be, the super­
visory authority with which the complaint has been lodged shall adopt 
its final decision on the basis of the decision referred to in paragraph 1 
of this Article, without undue delay and at the latest by one month after 
the Board has notified its decision. The lead supervisory authority or, as 
the case may be, the supervisory authority with which the complaint has 
been lodged, shall inform the Board of the date when its final decision 
is notified respectively to the controller or the processor and to the data 
subject. The final decision of the supervisory authorities concerned shall 
be adopted under the terms of Article 60(7), (8) and (9). The final 
decision shall refer to the decision referred to in paragraph 1 of this 
Article and shall specify that the decision referred to in that paragraph 
will be published on the website of the Board in accordance with 
paragraph 5 of this Article. The final decision shall attach the 
decision referred to in paragraph 1 of this Article. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 62 
Article 66 
Urgency procedure 
1. 
In exceptional circumstances, where a supervisory authority 
concerned considers that there is an urgent need to act in order to 
protect the rights and freedoms of data subjects, it may, by way of 
derogation from the consistency mechanism referred to in Articles 63, 
64 and 65 or the procedure referred to in Article 60, immediately adopt 
provisional measures intended to produce legal effects on its own 
territory with a specified period of validity which shall not exceed 
three months. The supervisory authority shall, without delay, 
communicate those measures and the reasons for adopting them to the 
other supervisory authorities concerned, to the Board and to the 
Commission. 
2. 
Where a supervisory authority has taken a measure pursuant to 
paragraph 1 and considers that final measures need urgently be adopted, 
it may request an urgent opinion or an urgent binding decision from the 
Board, giving reasons for requesting such opinion or decision. 
3. 
Any supervisory authority may request an urgent opinion or an 
urgent binding decision, as the case may be, from the Board where a 
competent supervisory authority has not taken an appropriate measure in 
a situation where there is an urgent need to act, in order to protect the 
rights and freedoms of data subjects, giving reasons for requesting such 
opinion or decision, including for the urgent need to act. 
4. 
By derogation from Article 64(3) and Article 65(2), an urgent 
opinion or an urgent binding decision referred to in paragraphs 2 
and 3 of this Article shall be adopted within two weeks by simple 
majority of the members of the Board. 
Article 67 
Exchange of information 
The Commission may adopt implementing acts of general scope in 
order to specify the arrangements for the exchange of information by 
electronic means between supervisory authorities, and between super­
visory authorities and the Board, in particular the standardised format 
referred to in Article 64. 
Those implementing acts shall be adopted in accordance with the exa­
mination procedure referred to in Article 93(2). 
S e c t i o n 3 
E u r o p e a n d a t a p r o t e c t i o n b o a r d 
Article 68 
European Data Protection Board 
1. 
The European Data Protection Board (the ‘Board’) is hereby estab­
lished as a body of the Union and shall have legal personality. 
2. 
The Board shall be represented by its Chair. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 63 
3. 
The Board shall be composed of the head of one supervisory 
authority of each Member State and of the European Data Protection 
Supervisor, or their respective representatives. 
4. 
Where in a Member State more than one supervisory authority is 
responsible for monitoring the application of the provisions pursuant to 
this Regulation, a joint representative shall be appointed in accordance 
with that Member State's law. 
5. 
The Commission shall have the right to participate in the activities 
and meetings of the Board without voting right. The Commission shall 
designate a representative. The Chair of the Board shall communicate to 
the Commission the activities of the Board. 
6. 
In the cases referred to in Article 65, the European Data Protection 
Supervisor shall have voting rights only on decisions which concern 
principles and rules applicable to the Union institutions, bodies, offices 
and agencies which correspond in substance to those of this Regulation. 
Article 69 
Independence 
1. 
The Board shall act independently when performing its tasks or 
exercising its powers pursuant to Articles 70 and 71. 
▼C1 
2. 
Without prejudice to requests by the Commission referred to in 
Article 70(1) and (2), the Board shall, in the performance of its tasks or 
the exercise of its powers, neither seek nor take instructions from 
anybody. 
▼B 
Article 70 
Tasks of the Board 
1. 
The Board shall ensure the consistent application of this Regu­
lation. To that end, the Board shall, on its own initiative or, where 
relevant, at the request of the Commission, in particular: 
(a) monitor and ensure the correct application of this Regulation in the 
cases provided for in Articles 64 and 65 without prejudice to the 
tasks of national supervisory authorities; 
(b) advise the Commission on any issue related to the protection of 
personal data in the Union, including on any proposed amendment 
of this Regulation; 
(c) advise the Commission on the format and procedures for the 
exchange of information between controllers, processors and super­
visory authorities for binding corporate rules; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 64 
(d) issue 
guidelines, 
recommendations, 
and 
best 
practices on 
procedures for erasing links, copies or replications of personal 
data from publicly available communication services as referred 
to in Article 17(2); 
(e) examine, on its own initiative, on request of one of its members or 
on request of the Commission, any question covering the appli­
cation of this Regulation and issue guidelines, recommendations 
and best practices in order to encourage consistent application of 
this Regulation; 
(f) issue guidelines, recommendations and best practices in accordance 
with point (e) of this paragraph for further specifying the criteria 
and conditions for decisions based on profiling pursuant to 
Article 22(2); 
(g) issue guidelines, recommendations and best practices in accordance 
with point (e) of this paragraph for establishing the personal data 
breaches and determining the undue delay referred to in 
Article 33(1) and (2) and for the particular circumstances in 
which a controller or a processor is required to notify the 
personal data breach; 
(h) issue guidelines, recommendations and best practices in accordance 
with point (e) of this paragraph as to the circumstances in which a 
personal data breach is likely to result in a high risk to the rights 
and freedoms of the natural persons referred to in Article 34(1). 
(i) issue guidelines, recommendations and best practices in accordance 
with point (e) of this paragraph for the purpose of further spec­
ifying the criteria and requirements for personal data transfers 
based on binding corporate rules adhered to by controllers and 
binding corporate rules adhered to by processors and on further 
necessary requirements to ensure the protection of personal data 
of the data subjects concerned referred to in Article 47; 
(j) issue guidelines, recommendations and best practices in accordance 
with point (e) of this paragraph for the purpose of further spec­
ifying the criteria and requirements for the personal data transfers 
on the basis of Article 49(1); 
(k) draw up guidelines for supervisory authorities concerning the appli­
cation of measures referred to in Article 58(1), (2) and (3) and the 
setting of administrative fines pursuant to Article 83; 
▼C1 
(l) review the practical application of the guidelines, recommendations 
and best practices; 
▼B 
(m) issue guidelines, recommendations and best practices in accordance 
with point (e) of this paragraph for establishing common 
procedures for reporting by natural persons of infringements of 
this Regulation pursuant to Article 54(2); 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 65 
(n) encourage the drawing-up of codes of conduct and the estab­
lishment of data protection certification mechanisms and data 
protection seals and marks pursuant to Articles 40 and 42; 
▼C1 
(o) approve the criteria of certification pursuant to Article 42(5) and 
maintain a public register of certification mechanisms and data 
protection seals and marks pursuant to Article 42(8) and of the 
certified controllers or processors established in third countries 
pursuant to Article 42(7); 
(p) approve the requirements referred to in Article 43(3) with a view to 
the accreditation of certification bodies referred to in Article 43; 
▼B 
(q) provide the Commission with an opinion on the certification 
requirements referred to in Article 43(8); 
(r) provide the Commission with an opinion on the icons referred to in 
Article 12(7); 
(s) provide the Commission with an opinion for the assessment of the 
adequacy of the level of protection in a third country or inter­
national organisation, including for the assessment whether a 
third country, a territory or one or more specified sectors within 
that third country, or an international organisation no longer 
ensures an adequate level of protection. To that end, the 
Commission shall provide the Board with all necessary documen­
tation, including correspondence with the government of the third 
country, with regard to that third country, territory or specified 
sector, or with the international organisation. 
(t) issue opinions on draft decisions of supervisory authorities pursuant 
to the consistency mechanism referred to in Article 64(1), on 
matters submitted pursuant to Article 64(2) and to issue binding 
decisions pursuant to Article 65, including in cases referred to in 
Article 66; 
(u) promote the cooperation and the effective bilateral and multilateral 
exchange of information and best practices between the supervisory 
authorities; 
(v) promote common training programmes and facilitate personnel 
exchanges between the supervisory authorities and, where appro­
priate, with the supervisory authorities of third countries or with 
international organisations; 
(w) promote the exchange of knowledge and documentation on data 
protection legislation and practice with data protection supervisory 
authorities worldwide. 
(x) issue opinions on codes of conduct drawn up at Union level 
pursuant to Article 40(9); and 
(y) maintain a publicly accessible electronic register of decisions taken 
by supervisory authorities and courts on issues handled in the 
consistency mechanism. 
2. 
Where the Commission requests advice from the Board, it may 
indicate a time limit, taking into account the urgency of the matter. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 66 
3. 
The Board shall forward its opinions, guidelines, recommen­
dations, and best practices to the Commission and to the committee 
referred to in Article 93 and make them public. 
4. 
The Board shall, where appropriate, consult interested parties and 
give them the opportunity to comment within a reasonable period. The 
Board shall, without prejudice to Article 76, make the results of the 
consultation procedure publicly available. 
Article 71 
Reports 
1. 
The Board shall draw up an annual report regarding the protection 
of natural persons with regard to processing in the Union and, where 
relevant, in third countries and international organisations. The report 
shall be made public and be transmitted to the European Parliament, to 
the Council and to the Commission. 
2. 
The annual report shall include a review of the practical appli­
cation of the guidelines, recommendations and best practices referred to 
in point (l) of Article 70(1) as well as of the binding decisions referred 
to in Article 65. 
Article 72 
Procedure 
1. 
The Board shall take decisions by a simple majority of its 
members, unless otherwise provided for in this Regulation. 
2. 
The Board shall adopt its own rules of procedure by a two-thirds 
majority of its members and organise its own operational arrangements. 
Article 73 
Chair 
1. 
The Board shall elect a chair and two deputy chairs from amongst 
its members by simple majority. 
2. 
The term of office of the Chair and of the deputy chairs shall be 
five years and be renewable once. 
Article 74 
Tasks of the Chair 
1. 
The Chair shall have the following tasks: 
(a) to convene the meetings of the Board and prepare its agenda; 
(b) to notify decisions adopted by the Board pursuant to Article 65 to 
the lead supervisory authority and the supervisory authorities 
concerned; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 67 
(c) to ensure the timely performance of the tasks of the Board, in 
particular in relation to the consistency mechanism referred to in 
Article 63. 
2. 
The Board shall lay down the allocation of tasks between the 
Chair and the deputy chairs in its rules of procedure. 
Article 75 
Secretariat 
1. 
The Board shall have a secretariat, which shall be provided by the 
European Data Protection Supervisor. 
2. 
The secretariat shall perform its tasks exclusively under the 
instructions of the Chair of the Board. 
3. 
The staff of the European Data Protection Supervisor involved in 
carrying out the tasks conferred on the Board by this Regulation shall 
be subject to separate reporting lines from the staff involved in carrying 
out tasks conferred on the European Data Protection Supervisor. 
4. 
Where appropriate, the Board and the European Data Protection 
Supervisor shall establish and publish a Memorandum of Understanding 
implementing this Article, determining the terms of their cooperation, 
and applicable to the staff of the European Data Protection Supervisor 
involved in carrying out the tasks conferred on the Board by this 
Regulation. 
5. 
The secretariat shall provide analytical, administrative and 
logistical support to the Board. 
6. 
The secretariat shall be responsible in particular for: 
(a) the day-to-day business of the Board; 
(b) communication between the members of the Board, its Chair and 
the Commission; 
(c) communication with other institutions and the public; 
(d) the use of electronic means for the internal and external 
communication; 
(e) the translation of relevant information; 
(f) the preparation and follow-up of the meetings of the Board; 
(g) the preparation, drafting and publication of opinions, decisions on 
the settlement of disputes between supervisory authorities and other 
texts adopted by the Board. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 68 
Article 76 
Confidentiality 
1. 
The discussions of the Board shall be confidential where the 
Board deems it necessary, as provided for in its rules of procedure. 
2. 
Access to documents submitted to members of the Board, experts 
and 
representatives 
of 
third 
parties 
shall 
be 
governed 
by 
Regulation (EC) No 1049/2001 of the European Parliament and of 
the Council ( 
1 
). 
CHAPTER VIII 
Remedies, liability and penalties 
Article 77 
Right to lodge a complaint with a supervisory authority 
1. 
Without prejudice to any other administrative or judicial remedy, 
every data subject shall have the right to lodge a complaint with a 
supervisory authority, in particular in the Member State of his or her 
habitual residence, place of work or place of the alleged infringement if 
the data subject considers that the processing of personal data relating to 
him or her infringes this Regulation. 
2. 
The supervisory authority with which the complaint has been 
lodged shall inform the complainant on the progress and the outcome 
of the complaint including the possibility of a judicial remedy pursuant 
to Article 78. 
Article 78 
Right to an effective judicial remedy against a supervisory authority 
1. 
Without prejudice to any other administrative or non-judicial 
remedy, each natural or legal person shall have the right to an 
effective judicial remedy against a legally binding decision of a super­
visory authority concerning them. 
2. 
Without prejudice to any other administrative or non-judicial 
remedy, each data subject shall have the right to a an effective 
judicial remedy where the supervisory authority which is competent 
pursuant to Articles 55 and 56 does not handle a complaint or does 
not inform the data subject within three months on the progress or 
outcome of the complaint lodged pursuant to Article 77. 
3. 
Proceedings against a supervisory authority shall be brought 
before the courts of the Member State where the supervisory 
authority is established. 
4. 
Where proceedings are brought against a decision of a supervisory 
authority which was preceded by an opinion or a decision of the Board 
in the consistency mechanism, the supervisory authority shall forward 
that opinion or decision to the court. 
▼B 
( 
1 
) Regulation (EC) No 1049/2001 of the European Parliament and of the 
Council of 30 May 2001 regarding public access to European Parliament, 
Council and Commission documents (OJ L 145, 31.5.2001, p. 43).


 
02016R0679 — EN — 04.05.2016 — 000.002 — 69 
Article 79 
Right to an effective judicial remedy against a controller or 
processor 
1. 
Without prejudice to any available administrative or non-judicial 
remedy, including the right to lodge a complaint with a supervisory 
authority pursuant to Article 77, each data subject shall have the right 
to an effective judicial remedy where he or she considers that his or her 
rights under this Regulation have been infringed as a result of the 
processing of his or her personal data in non-compliance with this 
Regulation. 
2. 
Proceedings against a controller or a processor shall be brought 
before the courts of the Member State where the controller or processor 
has an establishment. Alternatively, such proceedings may be brought 
before the courts of the Member State where the data subject has his or 
her habitual residence, unless the controller or processor is a public 
authority of a Member State acting in the exercise of its public powers. 
Article 80 
Representation of data subjects 
1. 
The data subject shall have the right to mandate a not-for-profit 
body, organisation or association which has been properly constituted in 
accordance with the law of a Member State, has statutory objectives 
which are in the public interest, and is active in the field of the 
protection of data subjects' rights and freedoms with regard to the 
protection of their personal data to lodge the complaint on his or her 
behalf, to exercise the rights referred to in Articles 77, 78 and 79 on his 
or her behalf, and to exercise the right to receive compensation referred 
to in Article 82 on his or her behalf where provided for by Member State 
law. 
2. 
Member States may provide that any body, organisation or asso­
ciation referred to in paragraph 1 of this Article, independently of a data 
subject's mandate, has the right to lodge, in that Member State, a 
complaint with the supervisory authority which is competent pursuant 
to Article 77 and to exercise the rights referred to in Articles 78 and 79 
if it considers that the rights of a data subject under this Regulation 
have been infringed as a result of the processing. 
Article 81 
Suspension of proceedings 
1. 
Where a competent court of a Member State has information on 
proceedings, concerning the same subject matter as regards processing 
by the same controller or processor, that are pending in a court in 
another Member State, it shall contact that court in the other 
Member State to confirm the existence of such proceedings. 
2. 
Where proceedings concerning the same subject matter as regards 
processing of the same controller or processor are pending in a court in 
another Member State, any competent court other than the court first 
seized may suspend its proceedings. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 70 
3. 
Where those proceedings are pending at first instance, any court 
other than the court first seized may also, on the application of one of 
the parties, decline jurisdiction if the court first seized has jurisdiction 
over the actions in question and its law permits the consolidation 
thereof. 
Article 82 
Right to compensation and liability 
1. 
Any person who has suffered material or non-material damage as a 
result of an infringement of this Regulation shall have the right to 
receive compensation from the controller or processor for the damage 
suffered. 
2. 
Any controller involved in processing shall be liable for the 
damage caused by processing which infringes this Regulation. A 
processor shall be liable for the damage caused by processing only 
where it has not complied with obligations of this Regulation 
specifically directed to processors or where it has acted outside or 
contrary to lawful instructions of the controller. 
3. 
A controller or processor shall be exempt from liability under 
paragraph 2 if it proves that it is not in any way responsible for the 
event giving rise to the damage. 
4. 
Where more than one controller or processor, or both a controller 
and a processor, are involved in the same processing and where they 
are, under paragraphs 2 and 3, responsible for any damage caused by 
processing, each controller or processor shall be held liable for the 
entire damage in order to ensure effective compensation of the data 
subject. 
5. 
Where a controller or processor has, in accordance with 
paragraph 4, paid full compensation for the damage suffered, that 
controller or processor shall be entitled to claim back from the other 
controllers or processors involved in the same processing that part of the 
compensation corresponding to their part of responsibility for the 
damage, in accordance with the conditions set out in paragraph 2. 
6. 
Court proceedings for exercising the right to receive compensation 
shall be brought before the courts competent under the law of the 
Member State referred to in Article 79(2). 
Article 83 
General conditions for imposing administrative fines 
1. 
Each supervisory authority shall ensure that the imposition of 
administrative fines pursuant to this Article in respect of infringements 
of this Regulation referred to in paragraphs 4, 5 and 6 shall in each 
individual case be effective, proportionate and dissuasive. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 71 
2. 
Administrative fines shall, depending on the circumstances of each 
individual case, be imposed in addition to, or instead of, measures 
referred to in points (a) to (h) and (j) of Article 58(2). When 
deciding whether to impose an administrative fine and deciding on 
the amount of the administrative fine in each individual case due 
regard shall be given to the following: 
(a) the nature, gravity and duration of the infringement taking into 
account the nature scope or purpose of the processing concerned 
as well as the number of data subjects affected and the level of 
damage suffered by them; 
(b) the intentional or negligent character of the infringement; 
(c) any action taken by the controller or processor to mitigate the 
damage suffered by data subjects; 
(d) the degree of responsibility of the controller or processor taking into 
account technical and organisational measures implemented by them 
pursuant to Articles 25 and 32; 
(e) any relevant previous infringements by the controller or processor; 
(f) the degree of cooperation with the supervisory authority, in order to 
remedy the infringement and mitigate the possible adverse effects of 
the infringement; 
(g) the categories of personal data affected by the infringement; 
(h) the manner in which the infringement became known to the super­
visory authority, in particular whether, and if so to what extent, the 
controller or processor notified the infringement; 
(i) where measures referred to in Article 58(2) have previously been 
ordered against the controller or processor concerned with regard to 
the same subject-matter, compliance with those measures; 
(j) adherence to approved codes of conduct pursuant to Article 40 or 
approved certification mechanisms pursuant to Article 42; and 
(k) any other aggravating or mitigating factor applicable to the circum­
stances of the case, such as financial benefits gained, or losses 
avoided, directly or indirectly, from the infringement. 
3. 
If a controller or processor intentionally or negligently, for the 
same or linked processing operations, infringes several provisions of 
this Regulation, the total amount of the administrative fine shall not 
exceed the amount specified for the gravest infringement. 
4. 
Infringements of the following provisions shall, in accordance with 
paragraph 2, be subject to administrative fines up to 10 000 000 EUR, 
or in the case of an undertaking, up to 2 % of the total worldwide 
annual turnover of the preceding financial year, whichever is higher: 
(a) the obligations of the controller and the processor pursuant to 
Articles 8, 11, 25 to 39 and 42 and 43; 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 72 
(b) the obligations of the certification body pursuant to Articles 42 
and 43; 
(c) the obligations of the monitoring body pursuant to Article 41(4). 
5. 
Infringements of the following provisions shall, in accordance with 
paragraph 2, be subject to administrative fines up to 20 000 000 EUR, 
or in the case of an undertaking, up to 4 % of the total worldwide 
annual turnover of the preceding financial year, whichever is higher: 
(a) the basic principles for processing, including conditions for consent, 
pursuant to Articles 5, 6, 7 and 9; 
(b) the data subjects' rights pursuant to Articles 12 to 22; 
(c) the transfers of personal data to a recipient in a third country or an 
international organisation pursuant to Articles 44 to 49; 
(d) any obligations pursuant to Member State law adopted under 
Chapter IX; 
(e) non-compliance with an order or a temporary or definitive limitation 
on processing or the suspension of data flows by the supervisory 
authority pursuant to Article 58(2) or failure to provide access in 
violation of Article 58(1). 
6. 
Non-compliance with an order by the supervisory authority as 
referred to in Article 58(2) shall, in accordance with paragraph 2 of 
this Article, be subject to administrative fines up to 20 000 000 EUR, or 
in the case of an undertaking, up to 4 % of the total worldwide annual 
turnover of the preceding financial year, whichever is higher. 
7. 
Without prejudice to the corrective powers of supervisory auth­
orities pursuant to Article 58(2), each Member State may lay down the 
rules on whether and to what extent administrative fines may be 
imposed on public authorities and bodies established in that 
Member State. 
8. 
The exercise by the supervisory authority of its powers under this 
Article shall be subject to appropriate procedural safeguards in 
accordance with Union and Member State law, including effective 
judicial remedy and due process. 
9. 
Where the legal system of the Member State does not provide for 
administrative fines, this Article may be applied in such a manner that 
the fine is initiated by the competent supervisory authority and imposed 
by competent national courts, while ensuring that those legal remedies 
are effective and have an equivalent effect to the administrative fines 
imposed by supervisory authorities. In any event, the fines imposed 
shall be effective, proportionate and dissuasive. Those Member States 
shall notify to the Commission the provisions of their laws which they 
adopt pursuant to this paragraph by 25 May 2018 and, without delay, 
any subsequent amendment law or amendment affecting them. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 73 
Article 84 
Penalties 
1. 
Member States shall lay down the rules on other penalties 
applicable to infringements of this Regulation in particular for 
infringements which are not subject to administrative fines pursuant to 
Article 83, and shall take all measures necessary to ensure that they are 
implemented. Such penalties shall be effective, proportionate and 
dissuasive. 
2. 
Each Member State shall notify to the Commission the provisions 
of its law which it adopts pursuant to paragraph 1, by 25 May 2018 
and, without delay, any subsequent amendment affecting them. 
CHAPTER IX 
Provisions relating to specific processing situations 
Article 85 
Processing and freedom of expression and information 
1. 
Member States shall by law reconcile the right to the protection of 
personal data pursuant to this Regulation with the right to freedom of 
expression and information, including processing for journalistic 
purposes and the purposes of academic, artistic or literary expression. 
2. 
For processing carried out for journalistic purposes or the purpose 
of academic artistic or literary expression, Member States shall provide 
for exemptions or derogations from Chapter II (principles), Chapter III 
(rights of the data subject), Chapter IV (controller and processor), 
Chapter V (transfer of personal data to third countries or international 
organisations), Chapter VI (independent supervisory authorities), 
Chapter VII (cooperation and consistency) and Chapter IX (specific 
data processing situations) if they are necessary to reconcile the right 
to the protection of personal data with the freedom of expression and 
information. 
3. 
Each Member State shall notify to the Commission the provisions 
of its law which it has adopted pursuant to paragraph 2 and, without 
delay, any subsequent amendment law or amendment affecting them. 
Article 86 
Processing and public access to official documents 
Personal data in official documents held by a public authority or a 
public body or a private body for the performance of a task carried 
out in the public interest may be disclosed by the authority or body in 
accordance with Union or Member State law to which the public 
authority or body is subject in order to reconcile public access to 
official documents with the right to the protection of personal data 
pursuant to this Regulation. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 74 
Article 87 
Processing of the national identification number 
Member States may further determine the specific conditions for the 
processing of a national identification number or any other identifier 
of general application. In that case the national identification number or 
any other identifier of general application shall be used only under 
appropriate safeguards for the rights and freedoms of the data subject 
pursuant to this Regulation. 
Article 88 
Processing in the context of employment 
1. 
Member States may, by law or by collective agreements, provide 
for more specific rules to ensure the protection of the rights and 
freedoms in respect of the processing of employees' personal data in 
the employment context, in particular for the purposes of the 
recruitment, the performance of the contract of employment, including 
discharge of obligations laid down by law or by collective agreements, 
management, planning and organisation of work, equality and diversity 
in the workplace, health and safety at work, protection of employer's or 
customer's property and for the purposes of the exercise and enjoyment, 
on an individual or collective basis, of rights and benefits related to 
employment, and for the purpose of the termination of the employment 
relationship. 
2. 
Those rules shall include suitable and specific measures to 
safeguard the data subject's human dignity, legitimate interests and 
fundamental rights, with particular regard to the transparency of 
processing, the transfer of personal data within a group of undertakings, 
or a group of enterprises engaged in a joint economic activity and 
monitoring systems at the work place. 
3. 
Each Member State shall notify to the Commission those 
provisions of its law which it adopts pursuant to paragraph 1, by 
25 May 2018 and, without delay, any subsequent amendment 
affecting them. 
Article 89 
Safeguards and derogations relating to processing for archiving 
purposes in the public interest, scientific or historical research 
purposes or statistical purposes 
1. 
Processing for archiving purposes in the public interest, scientific 
or historical research purposes or statistical purposes, shall be subject to 
appropriate safeguards, in accordance with this Regulation, for the rights 
and freedoms of the data subject. Those safeguards shall ensure that 
technical and organisational measures are in place in particular in order 
to ensure respect for the principle of data minimisation. Those measures 
may include pseudonymisation provided that those purposes can be 
fulfilled in that manner. Where those purposes can be fulfilled by 
further processing which does not permit or no longer permits the 
identification of data subjects, those purposes shall be fulfilled in that 
manner. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 75 
2. 
Where personal data are processed for scientific or historical 
research purposes or statistical purposes, Union or Member State law 
may provide for derogations from the rights referred to in Articles 15, 
16, 18 and 21 subject to the conditions and safeguards referred to in 
paragraph 1 of this Article in so far as such rights are likely to render 
impossible or seriously impair the achievement of the specific purposes, 
and such derogations are necessary for the fulfilment of those purposes. 
3. 
Where personal data are processed for archiving purposes in the 
public interest, Union or Member State law may provide for derogations 
from the rights referred to in Articles 15, 16, 18, 19, 20 and 21 subject 
to the conditions and safeguards referred to in paragraph 1 of this 
Article in so far as such rights are likely to render impossible or 
seriously impair the achievement of the specific purposes, and such 
derogations are necessary for the fulfilment of those purposes. 
4. 
Where processing referred to in paragraphs 2 and 3 serves at the 
same time another purpose, the derogations shall apply only to 
processing for the purposes referred to in those paragraphs. 
Article 90 
Obligations of secrecy 
1. 
Member States may adopt specific rules to set out the powers of 
the supervisory authorities laid down in points (e) and (f) of 
Article 58(1) in relation to controllers or processors that are subject, 
under Union or Member State law or rules established by national 
competent bodies, to an obligation of professional secrecy or other 
equivalent obligations of secrecy where this is necessary and propor­
tionate to reconcile the right of the protection of personal data with the 
obligation of secrecy. Those rules shall apply only with regard to 
personal data which the controller or processor has received as a 
result of or has obtained in an activity covered by that obligation of 
secrecy. 
2. 
Each Member State shall notify to the Commission the rules 
adopted pursuant to paragraph 1, by 25 May 2018 and, without 
delay, any subsequent amendment affecting them. 
Article 91 
Existing data protection rules of churches and religious associations 
1. 
Where in a Member State, churches and religious associations or 
communities apply, at the time of entry into force of this Regulation, 
comprehensive rules relating to the protection of natural persons with 
regard to processing, such rules may continue to apply, provided that 
they are brought into line with this Regulation. 
2. 
Churches and religious associations which apply comprehensive 
rules in accordance with paragraph 1 of this Article shall be subject 
to the supervision of an independent supervisory authority, which may 
be specific, provided that it fulfils the conditions laid down in 
Chapter VI of this Regulation. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 76 
CHAPTER X 
Delegated acts and implementing acts 
Article 92 
Exercise of the delegation 
1. 
The power to adopt delegated acts is conferred on the Commission 
subject to the conditions laid down in this Article. 
2. 
The delegation of power referred to in Article 12(8) and 
Article 43(8) shall be conferred on the Commission for an indeterminate 
period of time from 24 May 2016. 
3. 
The delegation of power referred to in Article 12(8) and 
Article 43(8) may be revoked at any time by the European Parliament 
or by the Council. A decision of revocation shall put an end to the 
delegation of power specified in that decision. It shall take effect the 
day following that of its publication in the Official Journal of the 
European Union or at a later date specified therein. It shall not affect 
the validity of any delegated acts already in force. 
4. 
As soon as it adopts a delegated act, the Commission shall notify 
it simultaneously to the European Parliament and to the Council. 
5. 
A delegated act adopted pursuant to Article 12(8) and Article 43(8) 
shall enter into force only if no objection has been expressed by either 
the European Parliament or the Council within a period of three months 
of notification of that act to the European Parliament and the Council or 
if, before the expiry of that period, the European Parliament and the 
Council have both informed the Commission that they will not object. 
That period shall be extended by three months at the initiative of the 
European Parliament or of the Council. 
Article 93 
Committee procedure 
1. 
The Commission shall be assisted by a committee. That committee 
shall be a committee within the meaning of Regulation (EU) 
No 182/2011. 
2. 
Where reference is made to this paragraph, Article 5 of Regu­
lation (EU) No 182/2011 shall apply. 
3. 
Where reference is made to this paragraph, Article 8 of Regu­
lation (EU) No 182/2011, in conjunction with Article 5 thereof, shall 
apply. 
CHAPTER XI 
Final provisions 
Article 94 
Repeal of Directive 95/46/EC 
1. 
Directive 95/46/EC is repealed with effect from 25 May 2018. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 77 
2. 
References to the repealed Directive shall be construed as 
references to this Regulation. References to the Working Party on the 
Protection of Individuals with regard to the Processing of Personal Data 
established by Article 29 of Directive 95/46/EC shall be construed as 
references to the European Data Protection Board established by this 
Regulation. 
Article 95 
Relationship with Directive 2002/58/EC 
This Regulation shall not impose additional obligations on natural or 
legal persons in relation to processing in connection with the provision 
of publicly available electronic communications services in public 
communication networks in the Union in relation to matters for which 
they are subject to specific obligations with the same objective set out in 
Directive 2002/58/EC. 
Article 96 
Relationship with previously concluded Agreements 
International agreements involving the transfer of personal data to third 
countries or international organisations which were concluded by 
Member States prior to 24 May 2016, and which comply with Union 
law as applicable prior to that date, shall remain in force until amended, 
replaced or revoked. 
Article 97 
Commission reports 
1. 
By 25 May 2020 and every four years thereafter, the Commission 
shall submit a report on the evaluation and review of this Regulation to 
the European Parliament and to the Council. The reports shall be made 
public. 
2. 
In the context of the evaluations and reviews referred to in 
paragraph 1, the Commission shall examine, in particular, the appli­
cation and functioning of: 
(a) Chapter V on the transfer of personal data to third countries or 
international organisations with particular regard to decisions 
adopted pursuant to Article 45(3) of this Regulation and decisions 
adopted on the basis of Article 25(6) of Directive 95/46/EC; 
(b) Chapter VII on cooperation and consistency. 
3. 
For the purpose of paragraph 1, the Commission may request 
information from Member States and supervisory authorities. 
4. 
In carrying out the evaluations and reviews referred to in para­
graphs 1 and 2, the Commission shall take into account the positions 
and findings of the European Parliament, of the Council, and of other 
relevant bodies or sources. 
5. 
The Commission shall, if necessary, submit appropriate proposals 
to amend this Regulation, in particular taking into account of develop­
ments in information technology and in the light of the state of progress 
in the information society. 
▼B


 
02016R0679 — EN — 04.05.2016 — 000.002 — 78 
Article 98 
Review of other Union legal acts on data protection 
The Commission shall, if appropriate, submit legislative proposals with 
a view to amending other Union legal acts on the protection of personal 
data, in order to ensure uniform and consistent protection of natural 
persons with regard to processing. This shall in particular concern the 
rules relating to the protection of natural persons with regard to 
processing by Union institutions, bodies, offices and agencies and on 
the free movement of such data. 
Article 99 
Entry into force and application 
1. 
This Regulation shall enter into force on the twentieth day 
following that of its publication in the Official Journal of the 
European Union. 
2. 
It shall apply from 25 May 2018. 
This Regulation shall be binding in its entirety and directly applicable in 
all Member States. 
▼B

choice A

In order to implement the team voice connection function in the game, if players need to use the microphone for voice connection during team matching, the recording will be temporarily stored in the mobile phone.

choice B

In order to run the game on different models of mobile phones, online channels and PCs, the game needs to have software interfaces for different mobile phones.

choice C

If players wish to add friends from their address book in the game, they can do so by associating them with their address book.

choice D

None of these above

difficulty

easy

domain

Single-Document QA

length

short

sub domain

Legal

Discussion

Discussion

No discussion posts on this page yet. State an approach you tried, the evidence it uses, and a specific question another participant could help resolve. Use the posting template.

See answer Answer published by the source

Artifacts

Code, notes and reproducible work shared by participants. Files are served from a separate origin.

No artifacts on this page yet. Share reproducible code or notes in a contribution. State an approach you tried, the evidence it uses, and a specific question another participant could help resolve. Use the posting template.

Source and history

Official source

initial import