Lex Browse everything How it works For developers

What changed, Directive (EU) 2016/680

2016-04-27 → 2016-05-04 · no interpretation, just the text delta

on 2016-04-27eu-eurlex:32016l0680:2016-04-27 (2016-04-27 → 2016-05-03) · official source ↗
on 2016-05-04eu-eurlex:32016l0680:2016-05-04 (2016-05-04 → open) · official source ↗

Open the structured article comparison → matched by provision anchor, with changed, added, removed and unchanged articles separated

1,173 line(s) in the old middle, 623 in the new; 1 unchanged leading and 3 trailing lines trimmed.

+ ## CHAPTER I — General provisions
− ### art_1
+ ### Article 1 — Subject-matter and objectives
− Article 1
+ **1.** This Directive lays down the rules relating to the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, inc…
− 1. This Directive lays down the rules relating to the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, includi…
+ **2.** In accordance with this Directive, Member States shall:(a) protect the fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data; and(b) ensure that the exchange of personal data by competent authorities within the Union, where such ex…
− 2. In accordance with this Directive, Member States shall:
+ **3.** This Directive shall not preclude Member States from providing higher safeguards than those established in this Directive for the protection of the rights and freedoms of the data subject with regard to the processing of personal data by competent authorities.
− | (a) | protect the fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data; and |
− | --- | --- |
+ ### Article 2 — Scope
− | (b) | ensure that the exchange of personal data by competent authorities within the Union, where such exchange is required by Union or Member State law, is neither restricted nor prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data.…
− | --- | --- |
+ **1.** This Directive applies to the processing of personal data by competent authorities for the purposes set out in Article 1(1).
− 3. This Directive shall not preclude Member States from providing higher safeguards than those established in this Directive for the protection of the rights and freedoms of the data subject with regard to the processing of personal data by competent authorities.
+ **2.** This Directive applies to the processing of personal data wholly or partly by automated means, and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.
− ### art_2
+ **3.** This Directive does not apply to the processing of personal data:(a) in the course of an activity which falls outside the scope of Union law;(b) by the Union institutions, bodies, offices and agencies.
− Article 2

− 1. This Directive applies to the processing of personal data by competent authorities for the purposes set out in Article 1(1).

− 2. This Directive applies to the processing of personal data wholly or partly by automated means, and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.

− 3. This Directive does not apply to the processing of personal data:
+ ### Article 3 — Definitions
− | (a) | in the course of an activity which falls outside the scope of Union law; |
− | --- | --- |

− | (b) | by the Union institutions, bodies, offices and agencies. |
− | --- | --- |

− ### art_3

− Article 3
+ (1) ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location dat…
− | (1) | ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location…
− | --- | --- |
+ (2) ‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by trans…
− | (2) | ‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by t…
− | --- | --- |
+ (3) ‘restriction of processing’ means the marking of stored personal data with the aim of limiting their processing in the future;
− | (3) | ‘restriction of processing’ means the marking of stored personal data with the aim of limiting their processing in the future; |
− | --- | --- |
+ (4) ‘profiling’ means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, heal…
− | (4) | ‘profiling’ means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, …
− | --- | --- |
+ (5) ‘pseudonymisation’ means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisa…
− | (5) | ‘pseudonymisation’ means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and orga…
− | --- | --- |
+ (6) ‘filing system’ means any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis;
− | (6) | ‘filing system’ means any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis; |
− | --- | --- |
+ (7) ‘competent authority’ means: (a) any public authority competent for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security; or (b) any other body or e…
− | (7) | ‘competent authority’ means:(a)any public authority competent for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security; or(b)any other body or e…
− | --- | --- |
− | (a) | any public authority competent for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security; or |
− | (b) | any other body or entity entrusted by Member State law to exercise public authority and public powers for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention…
+ (8) ‘controller’ means the competent authority which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomin…
− | (8) | ‘controller’ means the competent authority which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its n…
− | --- | --- |
+ (9) ‘processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
− | (9) | ‘processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller; |
− | --- | --- |
+ (10) ‘recipient’ means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Member State law…
− | (10) | ‘recipient’ means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Member State…
− | --- | --- |
+ (11) ‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
− | (11) | ‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed; |
− | --- | --- |
+ (12) ‘genetic data’ means personal data, relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural…
− | (12) | ‘genetic data’ means personal data, relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the nat…
− | --- | --- |
+ (13) ‘biometric data’ means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data;
− | (13) | ‘biometric data’ means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data;…
− | --- | --- |
+ (14) ‘data concerning health’ means personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status;
− | (14) | ‘data concerning health’ means personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status; |
− | --- | --- |
+ (15) ‘supervisory authority’ means an independent public authority which is established by a Member State pursuant to Article 41;
− | (15) | ‘supervisory authority’ means an independent public authority which is established by a Member State pursuant to Article 41; |
− | --- | --- |
+ (16) ‘international organisation’ means an organisation and its subordinate bodies governed by public international law, or any other body which is set up by, or on the basis of, an agreement between two or more countries.
− | (16) | ‘international organisation’ means an organisation and its subordinate bodies governed by public international law, or any other body which is set up by, or on the basis of, an agreement between two or more countries. |
− | --- | --- |
+ ## CHAPTER II — Principles
− ### art_4
+ ### Article 4 — Principles relating to processing of personal data
− Article 4
+ **1.** Member States shall provide for personal data to be:(a) processed lawfully and fairly;(b) collected for specified, explicit and legitimate purposes and not processed in a manner that is incompatible with those purposes;(c) adequate, relevant and not excessive in relation to the purposes for w…
− 1. Member States shall provide for personal data to be:
+ **2.** Processing by the same or another controller for any of the purposes set out in Article 1(1) other than that for which the personal data are collected shall be permitted in so far as:(a) the controller is authorised to process such personal data for such a purpose in accordance with Union or …
− | (a) | processed lawfully and fairly; |
− | --- | --- |
+ **3.** Processing by the same or another controller may include archiving in the public interest, scientific, statistical or historical use, for the purposes set out in Article 1(1), subject to appropriate safeguards for the rights and freedoms of data subjects.
− | (b) | collected for specified, explicit and legitimate purposes and not processed in a manner that is incompatible with those purposes; |
− | --- | --- |
+ **4.** The controller shall be responsible for, and be able to demonstrate compliance with, paragraphs 1, 2 and 3.
− | (c) | adequate, relevant and not excessive in relation to the purposes for which they are processed; |
− | --- | --- |
+ ### Article 5 — Time-limits for storage and review
− | (d) | accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay; |
− | --- | --- |
− | (e) | kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are processed; |
− | --- | --- |

− | (f) | processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures. |
− | --- | --- |

− 2. Processing by the same or another controller for any of the purposes set out in Article 1(1) other than that for which the personal data are collected shall be permitted in so far as:

− | (a) | the controller is authorised to process such personal data for such a purpose in accordance with Union or Member State law; and |
− | --- | --- |

− | (b) | processing is necessary and proportionate to that other purpose in accordance with Union or Member State law. |
− | --- | --- |

− 3. Processing by the same or another controller may include archiving in the public interest, scientific, statistical or historical use, for the purposes set out in Article 1(1), subject to appropriate safeguards for the rights and freedoms of data subjects.

− 4. The controller shall be responsible for, and be able to demonstrate compliance with, paragraphs 1, 2 and 3.

− ### art_5

− Article 5

+ ### Article 6 — Distinction between different categories of data subject
− ### art_6

− Article 6
+ (a) persons with regard to whom there are serious grounds for believing that they have committed or are about to commit a criminal offence;
− | (a) | persons with regard to whom there are serious grounds for believing that they have committed or are about to commit a criminal offence; |
− | --- | --- |
+ (b) persons convicted of a criminal offence;
− | (b) | persons convicted of a criminal offence; |
− | --- | --- |
+ (c) victims of a criminal offence or persons with regard to whom certain facts give rise to reasons for believing that he or she could be the victim of a criminal offence; and
− | (c) | victims of a criminal offence or persons with regard to whom certain facts give rise to reasons for believing that he or she could be the victim of a criminal offence; and |
− | --- | --- |
+ (d) other parties to a criminal offence, such as persons who might be called on to testify in investigations in connection with criminal offences or subsequent criminal proceedings, persons who can provide information on criminal offences, or contacts or associates of one of the persons referred to …
− | (d) | other parties to a criminal offence, such as persons who might be called on to testify in investigations in connection with criminal offences or subsequent criminal proceedings, persons who can provide information on criminal offences, or contacts or associates of one of the persons referred…
− | --- | --- |
+ ### Article 7 — Distinction between personal data and verification of quality of personal data
− ### art_7
+ **1.** Member States shall provide for personal data based on facts to be distinguished, as far as possible, from personal data based on personal assessments.
− Article 7
+ **2.** Member States shall provide for the competent authorities to take all reasonable steps to ensure that personal data which are inaccurate, incomplete or no longer up to date are not transmitted or made available. To that end, each competent authority shall, as far as practicable, verify the qu…
− 1. Member States shall provide for personal data based on facts to be distinguished, as far as possible, from personal data based on personal assessments.
+ **3.** If it emerges that incorrect personal data have been transmitted or personal data have been unlawfully transmitted, the recipient shall be notified without delay. In such a case, the personal data shall be rectified or erased or processing shall be restricted in accordance with Article 16.
− 2. Member States shall provide for the competent authorities to take all reasonable steps to ensure that personal data which are inaccurate, incomplete or no longer up to date are not transmitted or made available. To that end, each competent authority shall, as far as practicable, verify the qualit…
+ ### Article 8 — Lawfulness of processing
− 3. If it emerges that incorrect personal data have been transmitted or personal data have been unlawfully transmitted, the recipient shall be notified without delay. In such a case, the personal data shall be rectified or erased or processing shall be restricted in accordance with Article 16.
+ **1.** Member States shall provide for processing to be lawful only if and to the extent that processing is necessary for the performance of a task carried out by a competent authority for the purposes set out in Article 1(1) and that it is based on Union or Member State law.
− ### art_8
+ **2.** Member State law regulating processing within the scope of this Directive shall specify at least the objectives of processing, the personal data to be processed and the purposes of the processing.
− Article 8
+ ### Article 9 — Specific processing conditions
− 1. Member States shall provide for processing to be lawful only if and to the extent that processing is necessary for the performance of a task carried out by a competent authority for the purposes set out in Article 1(1) and that it is based on Union or Member State law.
+ **1.** Personal data collected by competent authorities for the purposes set out in Article 1(1) shall not be processed for purposes other than those set out in Article 1(1) unless such processing is authorised by Union or Member State law. Where personal data are processed for such other purposes, …
− 2. Member State law regulating processing within the scope of this Directive shall specify at least the objectives of processing, the personal data to be processed and the purposes of the processing.
+ **2.** Where competent authorities are entrusted by Member State law with the performance of tasks other than those performed for the purposes set out in Article 1(1), Regulation (EU) 2016/679 shall apply to processing for such purposes, including for archiving purposes in the public interest, scien…
− ### art_9
+ **3.** Member States shall, where Union or Member State law applicable to the transmitting competent authority provides specific conditions for processing, provide for the transmitting competent authority to inform the recipient of such personal data of those conditions and the requirement to comply…
− Article 9
+ **4.** Member States shall provide for the transmitting competent authority not to apply conditions pursuant to paragraph 3 to recipients in other Member States or to agencies, offices and bodies established pursuant to Chapters 4 and 5 of Title V of the TFEU other than those applicable to similar t…
− 1. Personal data collected by competent authorities for the purposes set out in Article 1(1) shall not be processed for purposes other than those set out in Article 1(1) unless such processing is authorised by Union or Member State law. Where personal data are processed for such other purposes, Regu…
+ ### Article 10 — Processing of special categories of personal data
− 2. Where competent authorities are entrusted by Member State law with the performance of tasks other than those performed for the purposes set out in Article 1(1), Regulation (EU) 2016/679 shall apply to processing for such purposes, including for archiving purposes in the public interest, scientifi…

− 3. Member States shall, where Union or Member State law applicable to the transmitting competent authority provides specific conditions for processing, provide for the transmitting competent authority to inform the recipient of such personal data of those conditions and the requirement to comply wit…

− 4. Member States shall provide for the transmitting competent authority not to apply conditions pursuant to paragraph 3 to recipients in other Member States or to agencies, offices and bodies established pursuant to Chapters 4 and 5 of Title V of the TFEU other than those applicable to similar trans…

− ### art_10

− Article 10

− | (a) | where authorised by Union or Member State law; |
− | --- | --- |
+ (a) where authorised by Union or Member State law;
− | (b) | to protect the vital interests of the data subject or of another natural person; or |
− | --- | --- |
+ (b) to protect the vital interests of the data subject or of another natural person; or
− | (c) | where such processing relates to data which are manifestly made public by the data subject. |
− | --- | --- |
+ (c) where such processing relates to data which are manifestly made public by the data subject.
− ### art_11
+ ### Article 11 — Automated individual decision-making
− Article 11
+ **1.** Member States shall provide for a decision based solely on automated processing, including profiling, which produces an adverse legal effect concerning the data subject or significantly affects him or her, to be prohibited unless authorised by Union or Member State law to which the controller…
− 1. Member States shall provide for a decision based solely on automated processing, including profiling, which produces an adverse legal effect concerning the data subject or significantly affects him or her, to be prohibited unless authorised by Union or Member State law to which the controller is …
+ **2.** Decisions referred to in paragraph 1 of this Article shall not be based on special categories of personal data referred to in Article 10, unless suitable measures to safeguard the data subject's rights and freedoms and legitimate interests are in place.
− 2. Decisions referred to in paragraph 1 of this Article shall not be based on special categories of personal data referred to in Article 10, unless suitable measures to safeguard the data subject's rights and freedoms and legitimate interests are in place.
+ **3.** Profiling that results in discrimination against natural persons on the basis of special categories of personal data referred to in Article 10 shall be prohibited, in accordance with Union law.
− 3. Profiling that results in discrimination against natural persons on the basis of special categories of personal data referred to in Article 10 shall be prohibited, in accordance with Union law.
+ ## CHAPTER III — Rights of the data subject
− ### art_12
+ ### Article 12 — Communication and modalities for exercising the rights of the data subject
− Article 12
+ **1.** Member States shall provide for the controller to take reasonable steps to provide any information referred to in Article 13 and make any communication with regard to Articles 11, 14 to 18 and 31 relating to processing to the data subject in a concise, intelligible and easily accessible form,…
− 1. Member States shall provide for the controller to take reasonable steps to provide any information referred to in Article 13 and make any communication with regard to Articles 11, 14 to 18 and 31 relating to processing to the data subject in a concise, intelligible and easily accessible form, usi…
+ **2.** Member States shall provide for the controller to facilitate the exercise of the rights of the data subject under Articles 11 and 14 to 18.
− 2. Member States shall provide for the controller to facilitate the exercise of the rights of the data subject under Articles 11 and 14 to 18.

− 3. Member States shall provide for the controller to inform the data subject in writing about the follow up to his or her request without undue delay.
+ **3.** Member States shall provide for the controller to inform the data subject in writing about the follow up to his or her request without undue delay.
− 4. Member States shall provide for the information provided under Article 13 and any communication made or action taken pursuant to Articles 11, 14 to 18 and 31 to be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their rep…
+ **4.** Member States shall provide for the information provided under Article 13 and any communication made or action taken pursuant to Articles 11, 14 to 18 and 31 to be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their…
− | (a) | charge a reasonable fee, taking into account the administrative costs of providing the information or communication or taking the action requested; or |
− | --- | --- |

− | (b) | refuse to act on the request. |
− | --- | --- |
+ **5.** Where the controller has reasonable doubts concerning the identity of the natural person making a request referred to in Article 14 or 16, the controller may request the provision of additional information necessary to confirm the identity of the data subject.
− 5. Where the controller has reasonable doubts concerning the identity of the natural person making a request referred to in Article 14 or 16, the controller may request the provision of additional information necessary to confirm the identity of the data subject.
+ ### Article 13 — Information to be made available or given to the data subject
− ### art_13
+ **1.** Member States shall provide for the controller to make available to the data subject at least the following information:(a) the identity and the contact details of the controller;(b) the contact details of the data protection officer, where applicable;(c) the purposes of the processing for wh…
− Article 13
+ **2.** In addition to the information referred to in paragraph 1, Member States shall provide by law for the controller to give to the data subject, in specific cases, the following further information to enable the exercise of his or her rights:(a) the legal basis for the processing;(b) the period …
− 1. Member States shall provide for the controller to make available to the data subject at least the following information:
+ **3.** Member States may adopt legislative measures delaying, restricting or omitting the provision of the information to the data subject pursuant to paragraph 2 to the extent that, and for as long as, such a measure constitutes a necessary and proportionate measure in a democratic society with due…
− | (a) | the identity and the contact details of the controller; |
− | --- | --- |
+ **4.** Member States may adopt legislative measures in order to determine categories of processing which may wholly or partly fall under any of the points listed in paragraph 3.
− | (b) | the contact details of the data protection officer, where applicable; |
− | --- | --- |
+ ### Article 14 — Right of access by the data subject
− | (c) | the purposes of the processing for which the personal data are intended; |
− | --- | --- |
− | (d) | the right to lodge a complaint with a supervisory authority and the contact details of the supervisory authority; |
− | --- | --- |

− | (e) | the existence of the right to request from the controller access to and rectification or erasure of personal data and restriction of processing of the personal data concerning the data subject. |
− | --- | --- |

− 2. In addition to the information referred to in paragraph 1, Member States shall provide by law for the controller to give to the data subject, in specific cases, the following further information to enable the exercise of his or her rights:

− | (a) | the legal basis for the processing; |
− | --- | --- |

− | (b) | the period for which the personal data will be stored, or, where that is not possible, the criteria used to determine that period; |
− | --- | --- |

− | (c) | where applicable, the categories of recipients of the personal data, including in third countries or international organisations; |
− | --- | --- |

− | (d) | where necessary, further information, in particular where the personal data are collected without the knowledge of the data subject. |
− | --- | --- |

− 3. Member States may adopt legislative measures delaying, restricting or omitting the provision of the information to the data subject pursuant to paragraph 2 to the extent that, and for as long as, such a measure constitutes a necessary and proportionate measure in a democratic society with due reg…

− | (a) | avoid obstructing official or legal inquiries, investigations or procedures; |
− | --- | --- |

− | (b) | avoid prejudicing the prevention, detection, investigation or prosecution of criminal offences or the execution of criminal penalties; |
− | --- | --- |

− | (c) | protect public security; |
− | --- | --- |

− | (d) | protect national security; |
− | --- | --- |

− | (e) | protect the rights and freedoms of others. |
− | --- | --- |

− 4. Member States may adopt legislative measures in order to determine categories of processing which may wholly or partly fall under any of the points listed in paragraph 3.

− ### art_14

− Article 14

+ (a) the purposes of and legal basis for the processing;
− | (a) | the purposes of and legal basis for the processing; |
− | --- | --- |
+ (b) the categories of personal data concerned;
− | (b) | the categories of personal data concerned; |
− | --- | --- |
+ (c) the recipients or categories of recipients to whom the personal data have been disclosed, in particular recipients in third countries or international organisations;
− | (c) | the recipients or categories of recipients to whom the personal data have been disclosed, in particular recipients in third countries or international organisations; |
− | --- | --- |
+ (d) where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
− | (d) | where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period; |
− | --- | --- |
+ (e) the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject;
− | (e) | the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject; |
− | --- | --- |
+ (f) the right to lodge a complaint with the supervisory authority and the contact details of the supervisory authority;
− | (f) | the right to lodge a complaint with the supervisory authority and the contact details of the supervisory authority; |
− | --- | --- |
+ (g) communication of the personal data undergoing processing and of any available information as to their origin.
− | (g) | communication of the personal data undergoing processing and of any available information as to their origin. |
− | --- | --- |
+ ### Article 15 — Limitations to the right of access
− ### art_15
+ **1.** Member States may adopt legislative measures restricting, wholly or partly, the data subject's right of access to the extent that, and for as long as such a partial or complete restriction constitutes a necessary and proportionate measure in a democratic society with due regard for the fundam…
− Article 15
+ **2.** Member States may adopt legislative measures in order to determine categories of processing which may wholly or partly fall under points (a) to (e) of paragraph 1.
− 1. Member States may adopt legislative measures restricting, wholly or partly, the data subject's right of access to the extent that, and for as long as such a partial or complete restriction constitutes a necessary and proportionate measure in a democratic society with due regard for the fundamenta…
+ **3.** In the cases referred to in paragraphs 1 and 2, Member States shall provide for the controller to inform the data subject, without undue delay, in writing of any refusal or restriction of access and of the reasons for the refusal or the restriction. Such information may be omitted where the p…
− | (a) | avoid obstructing official or legal inquiries, investigations or procedures; |
− | --- | --- |
+ **4.** Member States shall provide for the controller to document the factual or legal reasons on which the decision is based. That information shall be made available to the supervisory authorities.
− | (b) | avoid prejudicing the prevention, detection, investigation or prosecution of criminal offences or the execution of criminal penalties; |
− | --- | --- |
+ ### Article 16 — Right to rectification or erasure of personal data and restriction of processing
− | (c) | protect public security; |
− | --- | --- |
+ **1.** Member States shall provide for the right of the data subject to obtain from the controller without undue delay the rectification of inaccurate personal data relating to him or her. Taking into account the purposes of the processing, Member States shall provide for the data subject to have th…
− | (d) | protect national security; |
− | --- | --- |
+ **2.** Member States shall require the controller to erase personal data without undue delay and provide for the right of the data subject to obtain from the controller the erasure of personal data concerning him or her without undue delay where processing infringes the provisions adopted pursuant t…
− | (e) | protect the rights and freedoms of others. |
− | --- | --- |
+ **3.** Instead of erasure, the controller shall restrict processing where:(a) the accuracy of the personal data is contested by the data subject and their accuracy or inaccuracy cannot be ascertained; or(b) the personal data must be maintained for the purposes of evidence.
− 2. Member States may adopt legislative measures in order to determine categories of processing which may wholly or partly fall under points (a) to (e) of paragraph 1.

− 3. In the cases referred to in paragraphs 1 and 2, Member States shall provide for the controller to inform the data subject, without undue delay, in writing of any refusal or restriction of access and of the reasons for the refusal or the restriction. Such information may be omitted where the provi…

− 4. Member States shall provide for the controller to document the factual or legal reasons on which the decision is based. That information shall be made available to the supervisory authorities.

− ### art_16

− Article 16

− 1. Member States shall provide for the right of the data subject to obtain from the controller without undue delay the rectification of inaccurate personal data relating to him or her. Taking into account the purposes of the processing, Member States shall provide for the data subject to have the ri…

− 2. Member States shall require the controller to erase personal data without undue delay and provide for the right of the data subject to obtain from the controller the erasure of personal data concerning him or her without undue delay where processing infringes the provisions adopted pursuant to Ar…

− 3. Instead of erasure, the controller shall restrict processing where:

− | (a) | the accuracy of the personal data is contested by the data subject and their accuracy or inaccuracy cannot be ascertained; or |
− | --- | --- |

− | (b) | the personal data must be maintained for the purposes of evidence. |
− | --- | --- |
+ **4.** Member States shall provide for the controller to inform the data subject in writing of any refusal of rectification or erasure of personal data or restriction of processing and of the reasons for the refusal. Member States may adopt legislative measures restricting, wholly or partly, the obl…
− 4. Member States shall provide for the controller to inform the data subject in writing of any refusal of rectification or erasure of personal data or restriction of processing and of the reasons for the refusal. Member States may adopt legislative measures restricting, wholly or partly, the obligat…

− | (a) | avoid obstructing official or legal inquiries, investigations or procedures; |
− | --- | --- |

− | (b) | avoid prejudicing the prevention, detection, investigation or prosecution of criminal offences or the execution of criminal penalties; |
− | --- | --- |

− | (c) | protect public security; |
− | --- | --- |

− | (d) | protect national security; |
− | --- | --- |

− | (e) | protect the rights and freedoms of others. |
− | --- | --- |
+ **5.** Member States shall provide for the controller to communicate the rectification of inaccurate personal data to the competent authority from which the inaccurate personal data originate.
− 5. Member States shall provide for the controller to communicate the rectification of inaccurate personal data to the competent authority from which the inaccurate personal data originate.
+ **6.** Member States shall, where personal data has been rectified or erased or processing has been restricted pursuant to paragraphs 1, 2 and 3, provide for the controller to notify the recipients and that the recipients shall rectify or erase the personal data or restrict processing of the persona…
− 6. Member States shall, where personal data has been rectified or erased or processing has been restricted pursuant to paragraphs 1, 2 and 3, provide for the controller to notify the recipients and that the recipients shall rectify or erase the personal data or restrict processing of the personal da…
+ ### Article 17 — Exercise of rights by the data subject and verification by the supervisory authority
− ### art_17
+ **1.** In the cases referred to in Article 13(3), Article 15(3) and Article 16(4) Member States shall adopt measures providing that the rights of the data subject may also be exercised through the competent supervisory authority.
− Article 17
+ **2.** Member States shall provide for the controller to inform the data subject of the possibility of exercising his or her rights through the supervisory authority pursuant to paragraph 1.
− 1. In the cases referred to in Article 13(3), Article 15(3) and Article 16(4) Member States shall adopt measures providing that the rights of the data subject may also be exercised through the competent supervisory authority.
+ **3.** Where the right referred to in paragraph 1 is exercised, the supervisory authority shall inform the data subject at least that all necessary verifications or a review by the supervisory authority have taken place. The supervisory authority shall also inform the data subject of his or her righ…
− 2. Member States shall provide for the controller to inform the data subject of the possibility of exercising his or her rights through the supervisory authority pursuant to paragraph 1.

− 3. Where the right referred to in paragraph 1 is exercised, the supervisory authority shall inform the data subject at least that all necessary verifications or a review by the supervisory authority have taken place. The supervisory authority shall also inform the data subject of his or her right to…
+ ### Article 18 — Rights of the data subject in criminal investigations and proceedings
− ### art_18

− Article 18
+ ## CHAPTER IV — Controller and processor / Section 1 — General obligations
− ### art_19
+ ### Article 19 — Obligations of the controller
− Article 19
+ **1.** Member States shall provide for the controller, taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, to implement appropriate technical and organisational measures to e…
− 1. Member States shall provide for the controller, taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, to implement appropriate technical and organisational measures to ensur…
+ **2.** Where proportionate in relation to the processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller.
− 2. Where proportionate in relation to the processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller.
+ ### Article 20 — Data protection by design and by default
− ### art_20
+ **1.** Member States shall provide for the controller, taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing, as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the proce…
− Article 20
+ **2.** Member States shall provide for the controller to implement appropriate technical and organisational measures ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data col…
− 1. Member States shall provide for the controller, taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing, as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processin…
+ ### Article 21 — Joint controllers
− 2. Member States shall provide for the controller to implement appropriate technical and organisational measures ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collect…
+ **1.** Member States shall, where two or more controllers jointly determine the purposes and means of processing, provide for them to be joint controllers. They shall, in a transparent manner, determine their respective responsibilities for compliance with this Directive, in particular as regards th…
− ### art_21
+ **2.** Irrespective of the terms of the arrangement referred to in paragraph 1, Member States may provide for the data subject to exercise his or her rights under the provisions adopted pursuant to this Directive in respect of and against each of the controllers.
− Article 21
+ ### Article 22 — Processor
− 1. Member States shall, where two or more controllers jointly determine the purposes and means of processing, provide for them to be joint controllers. They shall, in a transparent manner, determine their respective responsibilities for compliance with this Directive, in particular as regards the ex…
+ **1.** Member States shall, where processing is to be carried out on behalf of a controller, provide for the controller to use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirement…
− 2. Irrespective of the terms of the arrangement referred to in paragraph 1, Member States may provide for the data subject to exercise his or her rights under the provisions adopted pursuant to this Directive in respect of and against each of the controllers.
+ **2.** Member States shall provide for the processor not to engage another processor without prior specific or general written authorisation by the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or r…
− ### art_22
+ **3.** Member States shall provide for the processing by a processor to be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and pur…
− Article 22
+ **4.** The contract or the other legal act referred to in paragraph 3 shall be in writing, including in an electronic form.
− 1. Member States shall, where processing is to be carried out on behalf of a controller, provide for the controller to use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of…
+ **5.** If a processor determines, in infringement of this Directive, the purposes and means of processing, that processor shall be considered to be a controller in respect of that processing.
− 2. Member States shall provide for the processor not to engage another processor without prior specific or general written authorisation by the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or repla…
+ ### Article 23 — Processing under the authority of the controller or processor
− 3. Member States shall provide for the processing by a processor to be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose…

− | (a) | acts only on instructions from the controller; |
− | --- | --- |

− | (b) | ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality; |
− | --- | --- |

− | (c) | assists the controller by any appropriate means to ensure compliance with the provisions on the data subject's rights; |
− | --- | --- |

− | (d) | at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of data processing services, and deletes existing copies unless Union or Member State law requires storage of the personal data; |
− | --- | --- |

− | (e) | makes available to the controller all information necessary to demonstrate compliance with this Article; |
− | --- | --- |

− | (f) | complies with the conditions referred to in paragraphs 2 and 3 for engaging another processor. |
− | --- | --- |

− 4. The contract or the other legal act referred to in paragraph 3 shall be in writing, including in an electronic form.

− 5. If a processor determines, in infringement of this Directive, the purposes and means of processing, that processor shall be considered to be a controller in respect of that processing.
− ### art_23

− Article 23

+ ### Article 24 — Records of processing activities
− ### art_24
+ **1.** Member States shall provide for controllers to maintain a record of all categories of processing activities under their responsibility. That record shall contain all of the following information:(a) the name and contact details of the controller and, where applicable, the joint controller and…
− Article 24
+ **2.** Member States shall provide for each processor to maintain a record of all categories of processing activities carried out on behalf of a controller, containing:(a) the name and contact details of the processor or processors, of each controller on behalf of which the processor is acting and, …
− 1. Member States shall provide for controllers to maintain a record of all categories of processing activities under their responsibility. That record shall contain all of the following information:
+ **3.** The records referred to in paragraphs 1 and 2 shall be in writing, including in electronic form.
− | (a) | the name and contact details of the controller and, where applicable, the joint controller and the data protection officer; |
− | --- | --- |
− | (b) | the purposes of the processing; |
− | --- | --- |

− | (c) | the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or international organisations; |
− | --- | --- |

− | (d) | a description of the categories of data subject and of the categories of personal data; |
− | --- | --- |

− | (e) | where applicable, the use of profiling; |
− | --- | --- |

− | (f) | where applicable, the categories of transfers of personal data to a third country or an international organisation; |
− | --- | --- |

− | (g) | an indication of the legal basis for the processing operation, including transfers, for which the personal data are intended; |
− | --- | --- |

− | (h) | where possible, the envisaged time limits for erasure of the different categories of personal data; |
− | --- | --- |

− | (i) | where possible, a general description of the technical and organisational security measures referred to in Article 29(1). |
− | --- | --- |

− 2. Member States shall provide for each processor to maintain a record of all categories of processing activities carried out on behalf of a controller, containing:

− | (a) | the name and contact details of the processor or processors, of each controller on behalf of which the processor is acting and, where applicable, the data protection officer; |
− | --- | --- |

− | (b) | the categories of processing carried out on behalf of each controller; |
− | --- | --- |

− | (c) | where applicable, transfers of personal data to a third country or an international organisation where explicitly instructed to do so by the controller, including the identification of that third country or international organisation; |
− | --- | --- |

− | (d) | where possible, a general description of the technical and organisational security measures referred to in Article 29(1). |
− | --- | --- |

− 3. The records referred to in paragraphs 1 and 2 shall be in writing, including in electronic form.

+ ### Article 25 — Logging
− ### art_25
+ **1.** Member States shall provide for logs to be kept for at least the following processing operations in automated processing systems: collection, alteration, consultation, disclosure including transfers, combination and erasure. The logs of consultation and disclosure shall make it possible to es…
− Article 25
+ **2.** The logs shall be used solely for verification of the lawfulness of processing, self-monitoring, ensuring the integrity and security of the personal data, and for criminal proceedings.
− 1. Member States shall provide for logs to be kept for at least the following processing operations in automated processing systems: collection, alteration, consultation, disclosure including transfers, combination and erasure. The logs of consultation and disclosure shall make it possible to establ…
+ **3.** The controller and the processor shall make the logs available to the supervisory authority on request.
− 2. The logs shall be used solely for verification of the lawfulness of processing, self-monitoring, ensuring the integrity and security of the personal data, and for criminal proceedings.
+ ### Article 26 — Cooperation with the supervisory authority
− 3. The controller and the processor shall make the logs available to the supervisory authority on request.
− ### art_26

− Article 26

+ ### Article 27 — Data protection impact assessment
− ### art_27
+ **1.** Where a type of processing, in particular, using new technologies, and taking into account the nature, scope, context and purposes of the processing is likely to result in a high risk to the rights and freedoms of natural persons, Member States shall provide for the controller to carry out, p…
− Article 27
+ **2.** The assessment referred to in paragraph 1 shall contain at least a general description of the envisaged processing operations, an assessment of the risks to the rights and freedoms of data subjects, the measures envisaged to address those risks, safeguards, security measures and mechanisms to…
… diff truncated at 500 changed lines …
tierA, publisher-supplied validity dates
history beginspublisher
index built2026-08-07T19:46:23Z · corpus 8d5e859
stamp signaturevalid (ECDSA-P256)