General data protection regulation

REGULATION no. 679 of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation)

(on October 31, 2018, the act was related to Decision 174/2018)
(on May 25, 2018, see application references from Decision 743/16-May-2018) (on October 06, 2016, the act was related to Directive 1629/14-Sep-2016)
(on May 05, 2016, the act was related to Directive 680/27-Apr-2016)

(Text with relevance for the EEA)
THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,
having regard to the Treaty on the Functioning of the European Union, in particular Article 16,
considering the proposal of the European Commission,
after the submission of the draft legislative act to the national parliaments,
considering the opinion of the European Economic and Social Committee (1),
(1) OJ C 229, 31.7.2012, p. 90.
considering the opinion of the Committee of the Regions (2),
(2) OJ C 391, 18.12.2012, p. 127.
deciding in accordance with the ordinary legislative procedure (3),
(3) The position of the European Parliament of March 12, 2014 (not yet published in the Official Journal) and the Council's first reading position of April 8, 2016 (not yet published in the Official Journal). The position of the European Parliament of April 14, 2016.
whereas:
(1) The protection of natural persons regarding the processing of personal data is a fundamental right. Article 8(1) of the Charter of Fundamental Rights of the European Union ("the Charter") and Article 16(1) of the Treaty on the Functioning of the European Union (TFEU) provide for the right of any person to the protection of personal data concerning him.
(2) The principles and rules relating to the protection of natural persons with regard to the processing of their personal data should, regardless of the natural persons' citizenship or place of residence, respect their fundamental rights and freedoms, in particular the right to protection personal data. This regulation seeks to contribute to the realization of an area of ​​freedom, security and justice and an economic union, to economic and social progress, to the consolidation and convergence of economies within the internal market and to the well-being of natural persons. (3) Directive 95/46/EC of the European Parliament and of the Council (4) aims at harmonizing the level of protection of the fundamental rights and freedoms of natural persons with regard to processing activities and ensuring the free movement of personal data between member states . (4) Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of natural persons with regard to the processing of personal data and the free movement of such data (OJ L 281, 23.11.1995, p. 31 ).
(4) The processing of personal data should be at the service of citizens. The right to the protection of personal data is not an absolute right; it must be taken into account in relation to the function it fulfills in society and balanced with other fundamental rights, in accordance with the principle of proportionality. This regulation respects all the fundamental rights and freedoms and principles recognized in the charter as enshrined in the treaties, in particular respect for private and family life, residence and communications, protection of personal data, freedom of thought, conscience and of religion, freedom of expression and information, freedom to carry out a commercial activity, the right to an effective remedy and a fair trial, as well as cultural, religious and linguistic diversity.
(5) The economic and social integration resulting from the functioning of the internal market has led to a substantial increase in the cross-border flows of personal data. The exchange of personal data between public and private actors, including individuals, associations and enterprises, has intensified throughout the Union. According to Union law, the national authorities of the member states are called to cooperate and exchange personal data in order to be able to fulfill their duties or perform tasks on behalf of an authority from another member state.
(6) Rapid technological developments and globalization have generated new challenges for the protection of personal data. The scope of the collection and exchange of personal data has increased significantly. Technology allows both private companies and public authorities to use personal data at an unprecedented level in their activities. More and more, natural persons are making public worldwide personal information. Technology has transformed both the economy and social life and should further facilitate the free circulation of personal data within the Union and the transfer to third countries and international organizations, ensuring, at the same time, a high level of personal data protection.

(7) These developments require a solid and more coherent framework in terms of data protection in the Union, accompanied by a rigorous application of the rules, taking into account the importance of creating a climate of trust that will allow the digital economy to develop on the internal market. Individuals should have control over their personal data, and legal and practical security for individuals, economic operators and public authorities should be strengthened.

(8) If this regulation provides for specifications or restrictions of its rules by domestic law, the member states may, to the extent that this is necessary for coherence and to ensure the understanding of the national provisions by the persons to whom they apply , to incorporate elements of this regulation into their domestic law.

(9) The objectives and principles of Directive 95/46/EC remain sound, but this has not prevented the fragmentation of the way data protection is implemented in the Union, the legal insecurity or the widespread public perception that there are significant risks for the protection of natural persons, especially in relation to online activity. The differences between the levels of protection of the rights and freedoms of natural persons, in particular the right to the protection of personal data, with regard to the processing of personal data in the Member States may prevent the free movement of personal data throughout the Union. These differences can, therefore, constitute an obstacle in the carrying out of economic activities at the level of the Union, they can distort competition and they can prevent the authorities from fulfilling their responsibilities under Union law. This difference between the levels of protection is caused by the existence of some differences regarding the transposition and application of Directive 95/46/EC.

(10) In order to ensure a consistent and high level of protection of natural persons and to remove obstacles to the circulation of personal data within the Union, the level of protection of the rights and freedoms of natural persons with regard to the processing of such data it should be equivalent in all member states. The consistent and homogeneous application of the rules regarding the protection of the fundamental rights and freedoms of natural persons with regard to the processing of personal data should be ensured throughout the Union. With regard to the processing of personal data in order to comply with a legal obligation, to fulfill a task that serves a public interest or that results from the exercise of public authority with which the operator is vested, Member States should be allowed to maintain or introduce provisions of domestic law to clarify to a greater extent the application of the rules of this regulation. In conjunction with the general and horizontal data protection legislation, which implements Directive 95/46/EC, the member states have several specific sectoral laws in areas that require more precise provisions. This regulation also gives Member States a margin of maneuver in specifying its rules, including with regard to the processing of special categories of personal data ("sensitive data"). In this sense, this regulation does not exclude the law of the member states that establishes the circumstances related to specific processing situations, including establishing with greater precision the conditions under which the processing of personal data is legal.

(11) The effective protection of personal data throughout the Union requires not only the consolidation and detailed establishment of the rights of the data subjects and the obligations of those who process and decide on the processing of personal data, but also equivalent powers for

monitoring and ensuring compliance with personal data protection rules and equivalent sanctions for crimes in the member states.
(12) Article 16 paragraph (2) of the TFEU mandates the European Parliament and the Council to establish the rules regarding the protection of natural persons regarding the processing of personal data, as well as the rules regarding the free movement of such data.

(13) In order to ensure a uniform level of protection for natural persons throughout the Union and to prevent discrepancies that prevent the free circulation of data within the internal market, a regulation is necessary in order to provide legal security and transparency for economic operators, including micro-enterprises and small and medium-sized enterprises, as well as to offer natural persons in all member states the same level of legally enforceable rights, obligations and responsibilities for operators and their authorized persons, in order to ensure a coherent monitoring of data processing of a personal nature, equivalent sanctions in all member states, as well as the effective cooperation of the supervisory authorities of the different member states. For the proper functioning of the internal market, it is necessary that the free movement of personal data within the Union is not restricted or prohibited for reasons related to the protection of natural persons in terms of the processing of personal data. In order to take into account the specific situation of micro-enterprises and small and medium-sized enterprises, this regulation includes a derogation for organizations with less than 250 employees in terms of record keeping. In addition, the institutions and bodies of the Union and the Member States and their supervisory authorities are encouraged to take into account the specific needs of micro-enterprises and small and medium-sized enterprises in the application of this Regulation. The notion of micro-enterprises and small and medium-sized enterprises should be based on Article 2 of the annex to Commission Recommendation 2003/361/EC (1). (1) Commission Recommendation 2003/361/EC of 6 May 2003 on the definition of micro-enterprises and small and medium-sized enterprises [C(2003) 1422] (OJ L 124, 20.5.2003, p. 36).

(14) The protection conferred by this regulation should concern natural persons, regardless of their citizenship or place of residence, regarding the processing of their personal data. This regulation does not apply to the processing of personal data concerning legal entities and, in particular, companies with legal personality, including the name and type of legal entity and the contact details of the legal entity.

(15) In order to prevent the occurrence of a major risk of evasion, the protection of natural persons should be technologically neutral and not depend on the technologies used. The protection of natural persons should apply to the processing of personal data by automated means, as well as to manual processing, if the personal data are included or intended to be included in a record system. Files or sets of files, as well as their covers, which are not structured according to specific criteria should not fall within the scope of this regulation.

(16) This regulation does not apply to matters of protection of fundamental rights and liberties or to the free movement of personal data related to activities that do not fall within the scope of Union law, for example national security activities. This regulation does not apply to the processing of personal data by the member states when they carry out activities related to the foreign policy and the common security of the Union. (17) Regulation (EC) no. 45/2001 of the European Parliament and of the Council (2) applies to the processing of personal data by the institutions, bodies, offices and agencies of the Union. Regulation (EC) no. 45/2001 and other legal acts of the Union applicable to such processing of personal data should be adapted to the principles and rules established in this regulation and applied in accordance with this regulation. In order to ensure a solid and coherent framework in terms of data protection in the Union, after the adoption of this regulation, Regulation (EC) no. 45/2001 the necessary adaptations, so that they can be applied together with this regulation.

(2) Regulation (EC) no. 45/2001 of the European Parliament and of the Council of 18 December 2000 regarding the protection of natural persons with regard to the processing of personal data by community institutions and bodies and regarding the free movement of such data (OJ L 8, 12.1.2001, p. 1 ).

(18) This regulation does not apply to the processing of personal data by a natural person within an exclusively personal or domestic activity and which, therefore, is not related to a professional or commercial activity. Personal or domestic activities could include correspondence and the directory of addresses or activities within social networks and online activities carried out in the context of those activities. However, this regulation applies to operators or persons authorized by operators who provide the means of processing personal data for such personal or domestic activities.

(19) The protection of natural persons with regard to the processing of personal data by the competent authorities for the purpose of prevention, investigation, detection or criminal prosecution of crimes or the execution of punishments, including protection against threats to public safety and their prevention, as well as the free circulation of this data, is the subject of a specific legal act of the Union. Therefore, this Regulation should not apply to processing activities for these purposes. However, personal data processed by public authorities pursuant to this regulation, when used for these purposes, should be regulated by a more specific legal act of the Union, namely Directive (EU) 2016/680 of the European Parliament and the Council (1). Member States may entrust the competent authorities within the meaning of Directive (EU) 2016/680 with tasks that are not necessarily carried out for the purpose of preventing, investigating, detecting or prosecuting crimes or executing penalties, including protecting against threats to public safety and preventing them, so that the processing of personal data for other purposes, to the extent that it falls within the scope of Union law, falls within the scope of this regulation.

(1) Directive (EU) 2016/680 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons regarding the processing of personal data by the competent authorities for the purpose of preventing, detecting, investigating or prosecuting crimes or executing them penalties and regarding the free circulation of this data and the repeal of the Council's Framework Decision 2008/977/JAI (see page 89 of this Official Journal).

As regards the processing of personal data by these competent authorities for purposes falling within the scope of this Regulation, Member States should be able to maintain or introduce more detailed provisions to adapt the application of the rules of this Regulation. These provisions may more precisely establish specific requirements for the processing of personal data by the respective competent authorities for these other purposes, taking into account the constitutional, organizational and administrative structure of the member state in question. When the processing of personal data by private bodies is the subject of this regulation, this regulation should provide for the possibility for member states, under certain conditions, to impose by law restrictions on certain obligations and rights, if such restrictions constitute a necessary and proportionate measure in a democratic society for the purpose of guaranteeing important specific interests, among which are public safety and the prevention, investigation, detection and prosecution of crimes or the execution of punishments, including protection against threats to public safety and their prevention . This is relevant, for example, in the fight against money laundering or the activities of forensic laboratories.

(20) Although this regulation applies, inter alia, to the activities of courts and other judicial authorities, the law of the Union or of the member states could specify the processing operations and procedures regarding the processing of personal data by courts and other authorities judicial. The processing of personal data should not be the competence of the supervisory authorities in the event that the courts exercise their judicial powers, in order to guarantee the independence of the judicial system in the fulfillment of its judicial tasks, including in making decisions. The supervision of such data processing operations should be able to be entrusted to specific bodies within the judicial system of the member state, which should in particular ensure compliance with the rules provided by this regulation, sensitize the members of the judicial system regarding the obligations that fall under this regulation and to deal with complaints related to such data processing operations.

(21) This regulation does not affect the application of Directive 2000/31/EC of the European Parliament and of the Council (2), in particular the rules regarding the liability of intermediary service providers provided for in articles 12-15 of the said directive. The respective directive aims to contribute to the smooth functioning of the internal market, by ensuring the free movement of information society services between member states.

(2) Directive 2000/31/EC of the European Parliament and of the Council of June 8, 2000 regarding certain legal aspects of information society services, especially electronic commerce, on the internal market (directive on electronic commerce) (OJ L 178, 17.7.2000. 1, p. XNUMX).
(22) Any processing of personal data within the activities of an office of an operator or a person authorized by the operator in the Union should be carried out in accordance with this regulation, regardless of whether the processing itself takes place within the Union or not . Headquarters implies the effective and real exercise of an activity within stable agreements. The legal form of such agreements, through a branch or a subsidiary with legal personality, is not the determining factor in this regard.

(23) In order to ensure that natural persons are not deprived of the protection to which they are entitled under this regulation, the processing of the personal data of the persons concerned who are on the territory of the Union by an operator or a person authorized by him who does not and is based in the Union should be subject to this regulation if the processing activities are related to the provision of goods or services to such data subjects, regardless of whether or not they are related to a payment. In order to determine whether such an operator or such a person authorized by the operator offers goods or services to data subjects located on the territory of the Union, it should be established whether it appears that the operator or the person authorized by the operator intends to provide services to the data subjects from one or more member states of the Union. Since the simple fact that there is access to a website of the operator, of the person authorized by the operator or of an intermediary in the Union, that an e-mail address and other contact data are available or that a language generally used in the third country is used in which the operator has its headquarters is insufficient to confirm such an intention, factors such as the use of a language or a currency generally used in one or more member states with the possibility of ordering goods and services in that language or the mention of some customers or users located on the territory of the Union may lead to the conclusion that the operator intends to offer goods or services to targeted persons in the Union.

(24) The processing of the personal data of the persons concerned who are in the territory of the Union by an operator or a person authorized by him who is not based in the Union should also be subject to this regulation if it is related to the monitoring of the behavior of such targeted persons, to the extent that this behavior is manifested on the territory of the Union. In order to determine whether a processing activity can be considered as "behavioral monitoring" of the data subjects, it should be established whether the natural persons are tracked on the Internet, including the possible subsequent use of some personal data processing techniques that consist in creating a profile of a natural person, especially in order to make decisions about him or to analyze or make predictions about his personal preferences, behaviors and attitudes.

(25) If the law of a Member State applies under public international law, this Regulation should also apply to an operator who is not established in the Union, but, for example, in a diplomatic mission or in a consular office of a member state. (26) The principles of data protection should apply to any information relating to an identified or identifiable natural person. Personal data that has undergone pseudonymization, which could be attributed to a natural person through the use of additional information, should be considered information relating to an identifiable natural person. In order to determine whether a natural person is identifiable, all means, such as individualization, that either the controller or another person is reasonably likely to use for the purpose of identification should be taken into account, directly or indirectly, of the respective natural person. In order to determine whether it is reasonably likely that means of identifying the natural person will be used, consideration should be given to

taking into account all the objective factors, such as the costs and the time interval required for identification, taking into account both the technology available at the time of processing and the technological development. The principles of data protection should therefore not apply to anonymous information, i.e. to information that is not related to an identified or identifiable natural person or to personal data that is anonymized so that the person concerned is not or is no longer identifiable. Therefore, this regulation does not apply to the processing of such anonymous information, including if it is used for statistical or research purposes. (27) This regulation does not apply to personal data relating to deceased persons. Member States may provide rules regarding the processing of personal data relating to deceased persons.

(28) The application of pseudonymization of personal data can reduce the risks for the persons concerned and can help the operators and the persons empowered by them to fulfill their data protection obligations. The explicit introduction of the concept of "pseudonymization" in this regulation is not intended to prevent other possible data protection measures.

(29) In order to create incentives for the application of pseudonymisation when processing personal data, measures of pseudonymisation should be possible, while allowing general analysis, within the same operator when the operator has taken the necessary technical and organizational measures to to ensure that this regulation is implemented with regard to the respective data processing and that additional information for assigning personal data to a specific data subject is kept separately. The operator that processes personal data should indicate the authorized persons within the same operator. (30) Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as IP addresses, cookie identifiers or others identifiers such as radio frequency identification tags. They can leave traces that, especially when combined with unique identifiers and other information received by servers, can be used to create profiles of natural persons and to identify them.

(31) Public authorities to whom personal data is disclosed in accordance with a legal obligation in order to exercise their official function, such as tax and customs authorities, financial investigation units, independent administrative authorities or financial market authorities responsible for regulating and the supervision of the securities markets, should not be considered recipients if they receive personal data that are necessary for carrying out a certain investigation of general interest, in accordance with the law of the Union or that of the member states. Disclosure requests sent by public authorities should always be presented in writing, motivated and occasional and should not refer to a record system in its entirety or lead to the interconnection of record systems. The processing of personal data by the respective public authorities should comply with the applicable data protection rules in accordance with the purposes of the processing.

(32) Consent should be granted through an unequivocal action that constitutes a freely expressed, specific, knowing and clear manifestation of the data subject's consent to the processing of his personal data, such as a statement made in writing, including in electronic or verbal format. This could include ticking a box when the person visits a site, choosing technical parameters for information society services or any other statement or action that clearly indicates in this context the data subject's acceptance of the proposed processing of his personal data. Therefore, the absence of a response, pre-ticked boxes or the absence of an action should not constitute consent. Consent should cover all processing activities carried out for the same purpose or for the same purposes. If data processing is done for several purposes, consent should be given for all processing purposes. If the data subject's consent must be granted following a request sent electronically, the said request must be clear and concise and not unnecessarily disrupt the use of the service for which the consent is granted.

(33) It is often not possible, at the time of collecting personal data, to fully identify the purpose of data processing for scientific research purposes. For this reason, the persons concerned would

they should be allowed to express their consent for certain areas of scientific research when recognized ethical standards for scientific research are respected. Data subjects should have the possibility to express their consent only for certain fields of research or parts of research projects to the extent permitted by the intended purpose.

(34) Genetic data should be defined as personal data relating to the inherited or acquired genetic characteristics of a natural person, resulting from an analysis of a sample of biological material of the natural person in question, in particular a chromosomal analysis, of an analysis of deoxyribonucleic acid (DNA) or ribonucleic acid (RNA) or of an analysis of any other element that allows obtaining equivalent information.

(35) Personal health data should include all data related to the health of the data subject that discloses information about the data subject's past, present or future physical or mental health. These include information about the natural person collected as part of his registration for medical assistance services or as part of the provision of the respective services to the natural person in question, as mentioned in Directive 2011/24/EU of the European Parliament and of the Council (1); a number, a symbol or a distinctive sign assigned to a natural person for the unique identification of that person for medical purposes; information resulting from the testing or examination of a part of the body or a bodily substance, including genetic data and samples of biological material; as well as any information regarding, for example, a disease, disability, risk of illness, medical history, clinical treatment or physiological or biomedical condition of the person concerned, regardless of their source, such as a doctor or other medical staff , a hospital, a medical device or an in vitro diagnostic test.

(1) Directive 2011/24/EU of the European Parliament and of the Council of 9 March 2011 on the application of patients' rights in cross-border medical care (OJ L 88, 4.4.2011, p. 45). (36) The main headquarters of an operator in the Union should be the place where its central administration is located in the Union, unless the decisions regarding the purposes and means of personal data processing are taken in another headquarters of the operator in the Union. In this case, the latter should be considered as the main establishment. The main seat of an operator in the Union should be determined according to objective criteria and should involve the effective and real exercise of management activities that determine the main decisions regarding the purposes and means of processing within stable agreements. This criterion should not depend on the processing of personal data in that place. The presence and use of technical means and technologies for processing personal data or processing activities do not constitute a main office and, therefore, are not the determining criterion in this respect. The main headquarters of the person authorized by the operator should be the place where its central administration is located in the Union or, if it does not have a central administration in the Union, the place where the main processing activities are carried out in the Union. In cases involving both the operator and the person authorized by the operator, the competent main supervisory authority should remain the supervisory authority of the Member State in which the operator has its principal place of business, but the supervisory authority of the person authorized by the operator should be considered as being a targeted supervisory authority and that supervisory authority should participate in the cooperation procedure provided by this regulation. In any case, the supervisory authorities of the Member State or Member States where the person authorized by the operator has one or more offices should not be considered as the supervisory authorities concerned if the draft decision only refers to the operator. If the processing is carried out by a group of companies, the main headquarters of the company exercising control should be considered as the main headquarters of the company group, unless the purposes and means of the processing are established by another company.

(37) An enterprise group should include an enterprise that exercises control and the enterprises controlled by it, within which the enterprise that exercises control should be the enterprise that can exercise a dominant influence over the other enterprises, for example by virtue of ownership, of the financial participation or of the rules that regulate it or of the competence to implement rules regarding the protection of personal data. A company that

controls the processing of personal data in its affiliated companies should be considered, together with the latter, as a "group of companies".
(38) Children need a specific protection of their personal data, as they may be less aware of the risks, consequences, guarantees in question and their rights regarding the processing of personal data. This specific protection should apply in particular to the use of children's personal data for marketing purposes or to create personality or user profiles and to the collection of children's personal data when using services offered directly to children. The consent of the holder of parental responsibility should not be necessary in the context of prevention or counseling services offered directly to children.

(39) Any processing of personal data should be legal and fair. It should be transparent for natural persons that the personal data concerning them are collected, used, consulted or otherwise processed and to what extent the personal data are or will be processed. The principle of transparency provides that any information and communications related to the processing of the respective personal data are easily accessible and easy to understand and that simple and clear language is used. This principle refers in particular to informing the data subjects regarding the identity of the operator and the purposes of the processing, as well as to the provision of additional information, in order to ensure a fair and transparent processing with regard to the natural persons concerned and their right to be confirmed and communicated to them the personal data concerning them that are processed. Individuals should be informed about the risks, rules, guarantees and rights regarding the processing of personal data and about how to exercise their rights in relation to the processing. In particular, the specific purposes for which personal data are processed should be explicit and legitimate and be determined at the time of collection of the respective data. Personal data should be adequate, relevant and limited to what is necessary for the purposes for which they are processed. This requires, in particular, ensuring that the period for which personal data is stored is strictly limited to the minimum. Personal data should only be processed if the purpose of the processing cannot reasonably be fulfilled by other means. In order to ensure that personal data are not kept longer than necessary, the operator should set deadlines for deletion or periodic review. All reasonable steps should be taken to ensure that personal data that is inaccurate is rectified or deleted. Personal data should be processed in a way that adequately ensures their security and confidentiality, including for the purpose of preventing unauthorized access to them or the unauthorized use of personal data and the equipment used for processing.

(40) In order for the processing of personal data to be legal, it should be carried out based on the consent of the person concerned or on the basis of another legitimate reason, provided by law, either in this regulation or in another act of Union law or of the law internally, as provided in this regulation, including the need to comply with the legal obligations to which the operator is subject or the need to execute a contract to which the data subject is a party or to go through the steps preceding the conclusion of a contract, at the request of the data subject.

(41) Whenever this regulation refers to a legal basis or a legislative measure, this does not necessarily require a legislative act adopted by a parliament, without prejudice to the requirements arising from the constitutional order of the member state in question. However, such a legal basis or such a legislative measure should be clear and precise, and its application should be predictable for the persons concerned by it, in accordance with the jurisprudence of the Court of Justice of the European Union ("Court of of Justice") and the European Court of Human Rights.

(42) If the processing is based on the consent of the data subject, the operator should be able to demonstrate that the data subject has given his consent for the processing operation. In particular, in the context of a written statement regarding another matter, safeguards should ensure that the data subject is aware of the fact that he has given his consent and to what extent he has done so. In accordance with Council Directive 93/13/EEC (1), a declaration of consent formulated in advance by the operator, in an intelligible form, should be provided

and easily accessible, using clear and simple language, and this statement should not contain abusive clauses. In order for the granting of consent to be in the knowledge of the cause, the concerned person should be aware at least of the identity of the operator and the purposes of the processing for which the personal data are intended. Consent should not be considered freely given if the person concerned does not really have the freedom of choice or is not in a position to refuse or withdraw consent without being prejudiced.

(1) Council Directive 93/13/CEE of April 5, 1993 regarding abusive clauses in consumer contracts (OJ L 95, 21.4.1993, p. 29).
(43) In order to guarantee that it was freely granted, consent should not constitute a valid legal basis for the processing of personal data in the particular case where there is an obvious imbalance between the data subject and the operator, especially in the case in which the operator is a public authority, and this makes it improbable to give consent freely in all the circumstances related to that particular situation. Consent is considered not to be freely granted if it does not allow separate consent to be granted for the various personal data processing operations, although this is appropriate in the particular case, or if the execution of a contract, including the provision of a service, is conditioned by consent, despite the fact that the consent in question is not necessary for the execution of the contract.

(44) The processing should be considered legal if it is necessary within a contract or in order to conclude a contract.
(45) If the processing is carried out in accordance with a legal obligation of the operator or if the processing is necessary for the performance of a task that serves a public interest or is part of the exercise of public authority, the processing should have a basis in Union law or domestic law. This regulation does not require the existence of a specific law for each individual processing. A single law may be sufficient as the basis for several processing operations carried out in accordance with a legal obligation of the operator or if the processing is necessary for the performance of a task that serves a public interest or is part of the exercise of public authority. Also, the purpose of the processing should be established in Union law or domestic law. Moreover, the respective right could specify the general conditions of this regulation that regulate the legality of personal data processing, determine the specifications for establishing the operator, the type of personal data that are the subject of processing, the persons concerned, the entities to whom the personal data may be disclosed, the limitations depending on the purpose, the storage period and other measures to guarantee a legal and fair processing. It should also be established in Union or national law whether the operator performing a task that serves a public interest or that is part of the exercise of public authority should be a public authority or another natural or legal person governed by public law or, when reasons of public interest justify this, including for medical purposes, such as public health and social protection, as well as the management of medical assistance services, by private law, such as a professional association.

(46) The processing of personal data should also be considered legal if it is necessary for the purpose of ensuring the protection of an interest that is essential for the life of the person concerned or for the life of another natural person. The processing of personal data based on the vital interests of another natural person should be carried out only if the processing cannot obviously be based on another legal basis. Some types of processing may serve both important reasons of public interest and the vital interests of the data subject, for example if the processing is necessary for humanitarian purposes, including in order to monitor an epidemic and its spread or in emergency situations humanitarian, especially in situations of natural or man-made disasters.

(47) The legitimate interests of an operator, including those of an operator to whom personal data may be disclosed or of a third party, may constitute a legal basis for processing, provided that the interests or fundamental rights and freedoms of the person do not prevail targeted, taking

taking into account the reasonable expectations of the data subjects based on their relationship with the operator. This legitimate interest could exist, for example, when there is a relevant and appropriate relationship between the data subject and the operator, such as when the data subject is a customer of the operator or is in its service. In any case, the existence of a legitimate interest would require a careful assessment, which would also establish whether a data subject can reasonably foresee, at the time and in the context of the collection of personal data, the possibility of processing for this purpose. The fundamental interests and rights of the data subject could prevail in particular in relation to the interest of the data controller when the personal data are processed in circumstances where the data subjects do not reasonably expect further processing. Since the legislator must provide the legal basis for the processing of personal data by the public authorities, the respective legal basis should not apply to the processing by the public authorities in the performance of their tasks. The processing of personal data strictly necessary for the purpose of fraud prevention also constitutes a legitimate interest of the data operator in question. The processing of personal data aimed at direct marketing can be considered to be carried out for a legitimate interest.

(48) Operators who are part of a group of companies or institutions affiliated to a central body may have a legitimate interest in transmitting personal data within the group of companies for internal administrative purposes, including for the purpose of processing the personal data of customers or employees. The general principles of the transfer of personal data, within a group of enterprises, to an enterprise located in a third country remain unchanged.

(49) The processing of personal data to the extent strictly necessary and proportionate in order to ensure the security of networks and information, namely the ability of a network or an information system to face, at a certain level of confidence, accidental events or actions illegal or malicious that compromise the availability, authenticity, integrity and confidentiality of personal data stored or transmitted, as well as the security of related services offered by these networks and systems, or accessible through them, by public authorities, intervention teams in case of computer emergencies, intervention teams in the event of incidents that affect IT security, providers of electronic communications networks and services, as well as by providers of services and technologies of security, constitutes a legitimate interest of the data operator in question. This could include, for example, preventing unauthorized access to electronic communications networks and the dissemination of malicious code and stopping "denial of service" attacks, as well as preventing damage to computers and electronic communications systems.

(50) The processing of personal data for purposes other than the purposes for which the personal data were initially collected should be allowed only when the processing is compatible with the respective purposes for which the personal data were initially collected. In this case, a legal basis separate from the one on the basis of which the collection of personal data was allowed is not necessary. If the processing is necessary for the performance of a task that serves a public interest or that results from the exercise of public authority with which the operator is vested, Union law or internal law may establish and specify the tasks and purposes for which further processing should be considered to be compatible and legal. Subsequent processing for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes should be considered as representing compatible legal processing operations. The legal basis provided for in Union law or in domestic law for the processing of personal data may also constitute a legal basis for further processing. In order to determine whether the purpose of the subsequent processing is compatible with the purpose for which the personal data were initially collected, the operator, after fulfilling all the requirements regarding the legality of the initial processing, should take into account, among other things, any connection between those purposes and the intended further processing purposes, the context in which the personal data were collected, in particular the reasonable expectations of the data subjects, based on their relationship with the operator, regarding the subsequent use of the data, the nature of the personal data, of the consequences of further processing

expected on the persons concerned, as well as the existence of the corresponding guarantees both within the initial processing operations and within the expected subsequent processing operations.
If the data subject has given his consent or the processing is based on Union law or domestic law, which constitutes a necessary and proportionate measure in a democratic society to protect, in particular, important objectives of general public interest, the operator should have the possibility to continue processing personal data, regardless of the compatibility of the purposes. In any case, the application of the principles established by this regulation and, in particular, the information of the data subject regarding these other purposes and his rights, including the right to opposition, should be guaranteed. The indication of possible crimes or threats to public safety by the operator and the transmission to a competent authority of relevant personal data in individual cases or in several cases related to the same crime or to the same threats to public safety should be considered as in the legitimate interest pursued by the operator. However, such a transmission in the legitimate interest of the operator or the subsequent processing of personal data should be prohibited if the processing is not compatible with a legal, professional or other confidentiality obligation.

(51) Personal data which are, by their very nature, particularly sensitive in terms of fundamental rights and freedoms require specific protection, because the context of their processing could generate considerable risks to fundamental rights and freedoms. This personal data should include personal data revealing racial or ethnic origin, the use of the term "racial origin" in this regulation not implying an acceptance by the Union of theories that seek to establish the existence of separate human races. The processing of photographs should not be systematically considered as the processing of special categories of personal data, as photographs fall under the definition of biometric data only in cases where they are processed by specific technical means that allow the unique identification or authentication of a natural persons. Such personal data should not be processed, unless the processing is allowed in specific cases provided by this regulation, taking into account the fact that the law of the member states may provide specific provisions regarding data protection in order to adapt the application of the rules of this regulation in order to comply with a legal obligation or to fulfill a task that serves a public interest or that results from the exercise of the public authority with which the operator is invested. In addition to the specific requirements for such processing, the general principles and other rules provided by this regulation should apply, especially regarding the conditions for legal processing. Derogations from the general prohibition of processing these special categories of personal data should be explicitly provided for, among others when the data subject gives explicit consent or with regard to specific needs, especially when the processing is carried out in the framework of legitimate activities by certain associations or foundations whose purpose is to allow the exercise of fundamental freedoms.

(52) Derogation from the prohibition regarding the processing of special categories of personal data should also be allowed if Union law or national law provides for this and should be subject to adequate guarantees, so that personal data and other fundamental rights be protected, when this is justified for reasons of public interest, especially in the case of personal data processing in the field of employment legislation, social protection, including pensions, as well as in security, surveillance and health alert purposes, for the prevention or control of communicable diseases and other serious threats to health. This derogation may be granted for medical purposes, including public health and the management of medical assistance services, especially in order to ensure the quality and cost-effectiveness of the procedures used to resolve requests for benefits and services within the health insurance system , or for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes. Also, the processing of such personal data should be allowed, through a derogation, when it is necessary for establishing, exercising or defending a right in court, regardless of whether it takes place within a

proceedings before a court or within an administrative or extrajudicial procedure.
(53) Special categories of personal data that require a higher level of protection should only be processed for health-related purposes when it is necessary to achieve these purposes for the benefit of individuals and society in general, especially in the context of managing of the health or social assistance services and systems, including the processing of this data by the management authorities and by the national central authorities in the field of health for the purpose of quality control, the provision of management information and the general supervision of the health or social assistance system at national and local level, as well as in the context of ensuring the continuity of medical or social assistance and cross-border medical assistance or for security, surveillance and health alert purposes or for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes based on Union law or internal law, which must pursue an objective of public interest, as well as in the case of studies carried out in the public interest in the field of public health. Therefore, this Regulation should provide for harmonized conditions for the processing of special categories of personal health data, with regard to specific needs, in particular when the processing of such data is carried out for certain health-related purposes by persons who subject to a legal obligation to maintain professional secrecy. Union law or national law should provide for specific and appropriate measures to protect the fundamental rights and personal data of natural persons. Member States should be able to maintain or introduce additional conditions, including restrictions, regarding the processing of genetic data, biometric data or health data. However, this should not prevent the free movement of personal data within the Union when these conditions apply to the cross-border processing of such data.

(54) The processing of special categories of personal data may be necessary for reasons of public interest in the fields of public health, without the consent of the person concerned. Such processing should be conditioned by appropriate and specific measures designed to protect the rights and freedoms of natural persons. In this context, the concept of "public health" should be interpreted as defined in Regulation (EC) no. 1338/2008 of the European Parliament and of the Council (1), namely all the elements related to health and namely the state of health, including morbidity or disability, the determining factors that have an effect on the state of health, the needs in the field of medical assistance, the resources allocated to the assistance medical care, the provision of medical assistance and ensuring universal access to it, as well as the expenses and sources of financing in the health field and the causes of mortality. This processing of health data for reasons of public interest should not lead to the processing of this data for other purposes by third parties, such as employers or insurance companies and banks.

(1) Regulation (EC) no. 1338/2008 of the European Parliament and of the Council of 16 December 2008 on community statistics relating to public health, as well as health and safety at work (OJ L 354, 31.12.2008, p. 70).
(55) In addition, the processing of personal data by public authorities in order to achieve the objectives provided by constitutional law or public international law, of officially recognized religious associations is carried out for reasons of public interest.

(56) If, during the electoral activities, the functioning of the democratic system requires, in a member state, that political parties collect personal data regarding the political opinions of individuals, the processing of such data may be allowed for reasons of public interest, provided that the appropriate guarantees are provided.

(57) If the personal data processed by an operator do not allow him to identify a natural person, the data operator should not have the obligation to obtain additional information in order to identify the data subject, with the sole purpose of complying with any of the provisions of this regulation. However, the operator should not refuse to take the additional information provided by the data subject in order to support the exercise of his rights. Identification should include the digital identification of a data subject, for example through mechanisms of

authentication such as the same credentials used by the data subject to access the online services offered by the data operator.
(58) The principle of transparency requires that any information addressed to the public or the person concerned be concise, easily accessible and easy to understand and that simple and clear language be used, as well as visualization where appropriate. This information could be provided in electronic format, for example when addressed to the public, through a website. This is especially important in situations where, due to the multitude of actors and the complexity, from a technological point of view, of the practice, it is difficult for the data subject to know and understand if the personal data concerning him is collected, by whom and for what purpose, as in the case of online advertising. Since children require specific protection, any information and any communication, if the processing is aimed at a child, should be expressed in simple and clear language, so that the child can easily understand it.

(59) Modalities should be provided to facilitate the exercise by the data subject of the rights conferred on him by this regulation, including the mechanisms through which he can request and, if necessary, obtain, free of charge, in particular, access to personal data, as well as their rectification or deletion, and the exercise of the right to opposition. The operator should also offer ways to submit requests electronically, especially if personal data is processed by electronic means. The operator should have the obligation to respond to the requests of the persons concerned without undue delay and within one month at the latest and, in the event that he does not intend to comply with those requests, to give reasons for this refusal. (60) In accordance with the principles of fair processing and transparently, the data subject is informed about the existence of a processing operation and its purposes. The operator should provide the data subject with any additional information necessary to ensure a fair and transparent processing, taking into account the specific circumstances and the context in which the personal data are processed. In addition, the data subject should be informed about the creation of profiles, as well as its consequences. When personal data is collected from the data subject, he should also be informed if he has the obligation to provide personal data and what the consequences are in case of a refusal. This information can be provided in combination with standardized icons to provide in an easily visible, intelligible and clearly legible way a significant overview of the intended processing. If the icons are presented in electronic format, they should be able to be read automatically.

(61) Information related to the processing of personal data concerning the data subject should be provided to him at the time of collection from the data subject or, if the personal data is obtained from another source, within a reasonable period, in depending on the circumstances of the case. If the personal data can be legitimately disclosed to another recipient, the data subject should be informed when the personal data is disclosed for the first time to the recipient. If the operator intends to process personal data for a purpose other than the one for which they were collected, the operator should provide the data subject, before this further processing, with information regarding the respective secondary purpose and other necessary information. If the origin of the personal data could not be communicated to the data subject because different sources were used, general information should be provided. (62) However, it is not necessary to impose the obligation to provide information if the data subject already has the information, if the registration or disclosure of personal data is expressly provided for by law or if the information to the person concerned proves to be impossible or would involve disproportionate efforts. The latter could be the case especially when the processing is carried out for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes. In this regard, the number of data subjects, the age of the data and any appropriate safeguards adopted should be taken into account.

(63) A data subject should have the right of access to the collected personal data concerning him and should exercise this right easily and at reasonable time intervals, in order to be informed about the processing and to verify its legality. This includes the right of data subjects to have access to their health data, for example data from their records

medical records containing information such as diagnoses, examination results, evaluations of attending physicians and any treatment or intervention performed. Any data subject should, therefore, have the right to know and be informed in particular of the purposes for which the data are processed, if possible the period for which the personal data is processed, the recipients of the personal data, the logic of automatic processing of personal data and, at least if it is based on the creation of profiles, the consequences of such processing. If this is possible, the data controller should be able to provide remote access to a secure system, which gives the data subject direct access to his personal data. This right should not affect the rights or freedoms of others, including trade secrets or intellectual property and, in particular, copyrights that ensure the protection of software programs. However, the above considerations should not result in the refusal to provide all information to the data subject. When the operator processes a large volume of information regarding the data subject, the operator should be able to request that, before the information is provided, the data subject specify the information or processing activities to which his request refers. (64) The operator should take all reasonable steps to verify the identity of a data subject requesting access to data, in particular in the context of online services and online identifiers. An operator should not retain personal data for the sole purpose of being able to respond to potential requests.

(65) A data subject should have the right to rectification of personal data concerning him and the "right to be forgotten", if the retention of this data violates this regulation or the Union law or the internal law under which the operator falls . In particular, data subjects should have the right to have their personal data deleted and no longer processed, if the personal data are no longer necessary for the purposes for which they are collected or are processed, if in which the data subjects have withdrawn their consent for processing or in the event that they oppose the processing of their personal data or in the event that the processing of their personal data does not comply with this regulation. This right is particularly relevant if the data subject gave his consent when he was a child and was not fully aware of the risks involved in the processing, and subsequently wishes to remove such personal data, especially from the Internet. The person concerned should have the opportunity to exercise this right despite the fact that he is no longer a child. However, the continued retention of personal data should be legal if it is necessary to exercise the right to freedom of expression and information, to comply with a legal obligation, to fulfill a task that serves a public interest or which results from the exercise of the public authority with which the operator is vested, for reasons of public interest in the field of public health, for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes or for ascertainment, exercising or defending a right in court.

(66) In order to strengthen the "right to be forgotten" in the online environment, the right to erasure should be extended so that an operator who has made personal data public should have the obligation to inform the operators who process those data personal data to delete any links to the respective data or copies or reproductions thereof. For this purpose, the operator in question should take reasonable measures, taking into account the available technology and the means at his disposal, including technical measures, to inform the operators that process the personal data regarding the request of the data subject.

(67) The methods of restricting the processing of personal data could include, among others, the temporary moving of selected personal data to another processing system, or the cancellation of users' access to the selected data or the temporary removal of data published by on a site. With regard to automated data recording systems, the restriction of processing should, in principle, be ensured by technical means in such a way that personal data are not subject to further processing operations and cannot be changed. The fact that the processing of personal data is restricted should be clearly indicated in the system.

(68) In order to additionally increase the control over their own data, the data subject should, in case the personal data are processed by automatic means, be able to receive the personal data concerning them and which they have provided to an operator , in a structured format, currently used, automatically processed and interoperable and to be able to transmit them to another operator. Data operators should be encouraged to develop interoperable formats that allow data portability. This right should apply if the data subject has provided the personal data based on their own consent or if the data processing is necessary for the execution of a contract. This right should not apply if the processing is based on another legal basis than consent or contract. By its very nature, this right should not be exercised against operators who process personal data in the exercise of their public functions. It should not apply in particular if the processing of personal data is necessary in order to comply with a legal obligation to which the operator is subject or in the case of the performance of a task that serves a public interest or results from the exercise of an authority public with which the operator is invested. The right of the data subject to transmit or receive personal data concerning him should not create for operators the obligation to adopt or maintain processing systems that are technically compatible. If, in a certain set of personal data, several data subjects are involved, the right to receive personal data should not affect the rights and freedoms of other data subjects, in accordance with this regulation. Also, this right should not affect the data subject's right to obtain the deletion of personal data and the limitations of that right, as provided in this regulation, and should not, in particular, involve the deletion of those personal data personal data related to the data subject that were provided by him in order to execute a contract, to the extent and as long as the respective data is necessary for the execution of the contract. The data subject should have the right to have personal data transmitted directly from one operator to another, if this is technically feasible.

(69) In cases where personal data could be processed legally because the processing is necessary for the performance of a task that serves a public interest or that results from the exercise of public authority with which the operator is invested or based on the legitimate interests of a operator or of a third party, a data subject should still have the right to object to the processing of any personal data relating to his particular situation. It should be the responsibility of the operator to demonstrate that his legitimate and compelling interests prevail over the interests or fundamental rights and freedoms of the data subject.

(70) If personal data are processed for direct marketing purposes, the data subject should have the right to oppose such processing, including the creation of profiles to the extent that it is related to direct marketing, regardless of whether the processing in question is the initial one or a subsequent one, at any time and free of charge. This right should be explicitly brought to the attention of the data subject and presented clearly and separately from any other information.

(71) The data subject should have the right not to be subject to a decision, which may include a measure, which evaluates personal aspects concerning the data subject, which is based exclusively on

automatic processing and which produces legal effects that concern the data subject or similarly affect him to a significant extent, such as the automatic refusal of an online credit application or electronic recruitment practices, without human intervention. Such processing includes "profiling", which consists of any form of automatic processing of personal data

by evaluating the personal aspects relating to a natural person, especially in order to analyze or predict certain aspects regarding the performance at the workplace of the person concerned, the economic situation, the state of health, personal preferences or interests, reliability or behavior,

the location or movements, when this produces legal effects that concern the person concerned or similarly affects him to a significant extent. However, decision-making on the basis of such processing, including profiling, should be allowed where it is expressly authorized by Union law or national law applicable to the operator, including for the purpose

the monitoring and prevention of fraud and tax evasion, carried out in accordance with the regulations,

the standards and recommendations of Union institutions or national supervisory bodies, and in order to ensure the security and reliability of a service offered by the operator or in case it is

necessary for the conclusion or execution of a contract between the data subject and an operator or if the data subject has explicitly given his consent. In any case, such processing should be subject to appropriate guarantees, which should include a specific information of the data subject and his right to obtain human intervention, to

express the point of view, to receive an explanation regarding the decision taken following such an evaluation,

as well as the right to appeal the decision. Such a measure should not refer to a child.

To ensure a fair and transparent processing with regard to the data subject, having in

given the specific circumstances and the context in which the personal data are processed, the operator should use appropriate mathematical or statistical procedures for creating profiles, implement appropriate technical and organizational measures to ensure in particular that the factors leading to inaccuracies of the data of a personal nature are corrected and that the risk of errors is

reduced to a minimum, as well as to secure personal data in a way that takes into account the potential dangers to the interests and rights of the data subject and to prevent, among other things, discriminatory effects against people on the basis of race or ethnic origin, opinions politics, religion

or beliefs, trade union membership, genetic characteristics, state of health or sexual orientation or processing that leads to measures that have such effects. Automated decision-making and profiling based on special categories of personal data should be allowed

only under specific conditions.

(on May 23, 2018, paragraph (71

) corrected by point 1. of the Correction of May 23, 2018 )
(72) The creation of profiles is subject to the rules of this regulation that regulate the processing of personal data, such as the legal bases of the processing or the principles of data protection. The European Data Protection Board established by this Regulation ("the Board") should be able to issue guidelines in this context.
(73) Union law or internal law may impose restrictions regarding specific principles, regarding the right to information, the right of access to personal data and their rectification or deletion, regarding the right to data portability, the right to opposition, of decisions based on the creation of profiles, as well as regarding the communication of a breach of the security of personal data to the data subject and certain related obligations of the operators, to the extent that this is necessary and proportionate in a democratic society in order to public safety is guaranteed, including the protection of human life, especially in response to natural or man-made disasters, the prevention, investigation and prosecution of crimes or the execution of sentences, including protection against threats to public safety or against ethical violations in the case of regulated professions and their prevention, other important objectives of general public interest of the Union or of a member state, in particular an important economic or financial interest of the Union or of a member state, the maintenance of public registers for reasons of general public interest, the subsequent processing of data personal data archived to transmit specific information related to political behavior during the regimes of former totalitarian states, the protection of the data subject or the rights and freedoms of third parties, including social protection, public health and humanitarian purposes. These restrictions should comply with the requirements provided by the Charter and the European Convention for the Protection of Human Rights and Fundamental Freedoms.
(74) The responsibility and liability of the operator should be established for any processing of personal data carried out by him or on his behalf. In particular, the operator should be obliged to implement adequate and effective measures and be able to demonstrate the compliance of the processing activities with this regulation, including the effectiveness of the measures. These measures should take into account the nature, scope, context and purposes of the processing, as well as the risk to the rights and freedoms of natural persons.
(75) The risk for the rights and freedoms of natural persons, presenting different degrees of probability of materialization and severity, may be the result of a processing of personal data that could generate damages of a physical, material or moral nature, especially in cases in which: processing may lead to discrimination, identity theft or fraud, financial loss, compromise

reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorized reversal of pseudonymization or any other significant disadvantage of an economic or social nature; data subjects could be deprived of their rights and freedoms or prevented from exercising control over their personal data; personal data processed are data that reveal racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership; genetic data, health data or sex life data or criminal convictions and offenses or related security measures are processed; aspects of a personal nature are evaluated, in particular the analysis or forecasting of aspects regarding performance at work, economic situation, state of health, personal preferences or interests, reliability or behavior, location or travel, in order to create or personal profiles are used; personal data of vulnerable persons, especially children, are processed; or the processing involves a large volume of personal data and affects a large number of data subjects.

(76) The probability of materialization and the seriousness of the risk for the rights and freedoms of the data subject should be determined according to the nature, scope, context and purposes of the processing of personal data. The risk should be assessed on the basis of an objective assessment by which it is established whether the data processing operations present a risk or a high risk. (77) Guidelines for the implementation of appropriate measures and for the demonstration of compliance by the operator or the person authorized by the operator, especially regarding the identification of the risk related to the processing, its evaluation from the point of view of origin, nature, probability of materialization and gravity, as well as the identification of good practices for mitigating risk could be provided in particular through approved codes of conduct, approved certifications, committee guidelines or through guidance provided by a data protection officer. The Committee may also issue guidance on processing operations that are considered unlikely to pose a high risk to the rights and freedoms of natural persons and indicate the measures that may prove sufficient in such cases to address such a risk. risk.

(78) The protection of the rights and freedoms of natural persons with regard to the processing of personal data requires the adoption of appropriate technical and organizational measures to ensure the fulfillment of the requirements of this regulation. In order to be able to demonstrate compliance with this regulation, the operator should adopt internal policies and implement measures that respect in particular the principle of data protection starting from the moment of conception and that of implicit data protection. Such measures could consist, among others, in minimizing the processing of personal data, pseudonymizing this data as soon as possible, transparency regarding the functions and processing of personal data, empowering the data subject to monitor data processing, enabling the operator to create safety elements and improve them. When developing, designing, selecting and using applications, services and products that rely on the processing of personal data or that process personal data to fulfill their role, the manufacturers of these products and the providers of these services and applications should be encouraged to take into account the right to data protection at the time of the development and design of such products, services and applications and, taking into account the current stage of development, to ensure that the operators and the persons authorized by the operators are able to fulfill their obligations regarding to data protection. The principle of data protection starting with the moment of conception and that of implicit data protection should also be taken into account in the context of public tenders.

(79) The protection of the rights and freedoms of data subjects, as well as the responsibility and liability of operators and persons authorized by the operator, including in terms of monitoring by the supervisory authorities and the measures adopted by them, requires a clear attribution of responsibilities under this regulation , including if an operator establishes the purposes and means of processing together with other operators or if a processing operation is carried out on behalf of an operator.

(80) When an operator or a person authorized by the operator who is not established in the Union processes personal data of data subjects located in the territory of the Union, and

its processing activities are related to the provision of goods or services to such data subjects in the Union, regardless of whether or not a payment is requested by the data subject, or to the monitoring of the behavior of data subjects if it occurs within the Union, the operator or the person authorized by the operator should appoint a representative, unless the processing is of an occasional nature, does not include the large-scale processing of special categories of personal data, nor the processing of data related to criminal convictions and offences, and is unlikely to generate a risk for the rights and freedoms of natural persons, considering the nature, context, scope and purposes of the processing, as well as the case where the operator is a public authority or a public body. The representative should act on behalf of the operator or the person authorized by the operator, being able to be contacted by any supervisory authority. The representative should be explicitly designated, through a written mandate of the operator or the person authorized by the operator, to act on his/her behalf with regard to their obligations under this regulation. The appointment of such a representative does not affect the responsibility or liability of the operator or the person authorized by the operator under this regulation. Such a representative should perform his duties in accordance with the mandate received from the operator or the person authorized by the operator, including cooperating with the competent supervisory authorities regarding any action taken to ensure compliance with this regulation. The designated representative should be subject to procedures to ensure compliance with the law in case of non-compliance with this regulation by the operator or by the person authorized by the operator.

(81) In order to ensure compliance with the requirements imposed by this regulation regarding the processing that must be carried out on behalf of the operator by the person authorized by the operator, when assigning processing activities to a person authorized by the operator, the latter should only use authorized persons who offer sufficient guarantees, especially in terms of specialist knowledge, reliability and resources, to implement technical and organizational measures that meet the requirements imposed by this regulation, including for processing security. Adherence by the person authorized by the operator to an approved code of conduct or to an approved certification mechanism can be used as an element to demonstrate compliance with the operator's obligations. The carrying out of the processing by a person authorized by an operator should be regulated by a contract or another type of legal act, based on Union law or domestic law, which creates obligations for the person authorized by the operator in relation to the operator and which establishes the object and duration of the processing, the nature and purposes of the processing, the type of personal data and the categories of persons concerned, and should take into account the specific tasks and responsibilities of the person authorized by the operator in the context of the processing to be carried out, as well as the risk for the rights and freedoms of the person concerned. The operator and the person authorized by the operator may choose to use an individual contract or standard contractual clauses that are adopted either directly by the Commission or by a supervisory authority in accordance with the consistency mechanism and then adopted by the Commission. After completing the processing on behalf of the operator, the person authorized by the operator should return or delete, depending on the operator's option, the personal data, unless there is a requirement to store personal data under Union law or of the internal law that establishes obligations for the person authorized by the operator.

(82) In order to demonstrate compliance with this regulation, the operator or the person authorized by the operator should keep records of the processing activities under his responsibility. Each operator and each person authorized by the operator should have the obligation to cooperate with the supervisory authority and to make available to it, upon request, these records, so that they can be used for the purpose of monitoring the respective processing operations. (83) In order to maintain security and prevent processing that violates this regulation, the operator or the person authorized by the operator should assess the risks inherent in the processing and implement measures to mitigate these risks, such as encryption. Those measures should ensure an appropriate level of security, including confidentiality, taking into account the current state of development and the costs of implementation in relation to the risks and the nature of the data with

personal character whose protection must be ensured. When assessing the risk to the security of personal data, attention should be paid to the risks posed by data processing, such as destruction, loss, alteration, unauthorized disclosure or unauthorized access to personal data transmitted, stored or processed in another way, accidentally or illegally, which can lead in particular to physical, material or moral damages.

(84) In order to promote compliance with the provisions of this regulation in cases where processing operations are likely to generate a high risk for the rights and freedoms of natural persons, the operator should be responsible for carrying out an impact assessment on data protection, which estimates , in particular, the origin, nature, specificity and severity of this risk. The result of the assessment should be taken into account when determining the appropriate measures to be taken to demonstrate that the processing of personal data complies with this regulation. If an assessment of the impact on data protection shows that the processing operations involve a high risk, which the operator cannot mitigate with appropriate measures in terms of available technology and implementation costs, a consultation with the data protection authority should take place. supervision before processing.

(85) If it is not solved in time and in an adequate way, a breach of the security of personal data can lead to physical, material or moral damages to natural persons, such as the loss of control over their personal data or the limitation of their rights, discrimination, identity theft or fraud, financial loss, unauthorized reversal of pseudonymization, reputational compromise, loss of confidentiality of personal data protected by professional secrecy or any other significant disadvantage of an economic or social nature to the natural person in question. Therefore, as soon as it has become aware of the occurrence of a personal data security breach, the operator should notify this breach to the supervisory authority, without undue delay and, if possible, no later than 72 hours after taking aware of its existence, unless the operator is able to demonstrate, in accordance with the principle of responsibility, that the breach of personal data security is not likely to generate a risk for the rights and freedoms of natural persons. When the notification cannot be made within 72 hours, it should include the reasons for the delay, and the information can be provided gradually, without further delay.

(86) The operator should communicate to the data subject a breach of the security of personal data, without undue delay, when the breach is likely to generate a high risk for the rights and freedoms of the natural person, to allow him to take the necessary precautions. The communication should describe the nature of the personal data security breach and include recommendations for the natural person in question in order to mitigate any negative effects. Communications to data subjects should be carried out as soon as reasonably possible and in close cooperation with the supervisory authority, respecting the guidelines provided by it or other competent authorities, such as law enforcement authorities. For example, the need to mitigate an immediate risk of harm would require prompt communication to data subjects, while the need to implement appropriate measures against further personal data security breaches or similar security breaches personal data could justify a longer term for communication. (87) It should be established whether all appropriate technological protection and organizational measures have been implemented in order to immediately establish whether a personal data security breach has occurred and to promptly inform the supervisory authority and the person targeted. The fact that the notification was made without undue delay should be established taking into account, in particular, the nature and seriousness of the personal data security breach, as well as its consequences and negative effects on the data subject. This notification may lead to an intervention by the supervisory authority, in accordance with the tasks and powers specified in this regulation.

(88) When establishing detailed rules regarding the format and procedures applicable to the notification regarding personal data security breaches, due attention should be paid to the circumstances in which the breach occurred, including establishing whether the protection of personal data

personal was or was not ensured by appropriate technical protection measures, which would effectively limit the probability of identity fraud or other forms of abusive use. In addition, such rules and procedures should take into account the legitimate interests of law enforcement authorities in cases where early disclosure could unnecessarily complicate the investigation of the circumstances in which a personal data breach occurred.

(89) Directive 95/46/EC provided for a general obligation to notify the processing of personal data to the supervisory authorities. Although the respective obligation generates administrative and financial burdens, it has not always contributed to improving the protection of personal data. Therefore, such undifferentiated general notification obligations should be repealed and replaced with effective procedures and mechanisms that focus instead on those types of processing operations likely to generate a high risk for the rights and freedoms of natural persons through their very nature, by their scope, by their context and by their goals. Such types of processing operations may be those that presuppose, in particular, the use of new technologies or that represent a new type of operations, for which no data protection impact assessment was previously carried out by the operator or that become necessary the date being the period of time that has passed since the initial processing.

(90) In such cases, the operator should carry out, before processing, an assessment of the impact on data protection, in order to assess the specific degree of probability of the materialization of the high risk and its seriousness, considering the nature, scope, the context and purposes of the processing, as well as the sources of risk. The respective impact assessment should include, in particular, the measures, guarantees and mechanisms considered to mitigate the respective risk, to ensure the protection of personal data and to demonstrate compliance with this regulation.

(91) This should apply, in particular, to large-scale processing operations, which aim to process a considerable volume of personal data at a regional, national or supranational level, which could affect a large number of people targeted and which are likely to generate a high risk, for example, due to their sensitivity, if, in accordance with the achieved level of technological knowledge, a new technology is used on a large scale, as well as other processing operations that generates a high risk for the rights and freedoms of the data subjects, especially if the respective operations limit the ability of the data subjects to exercise their rights. An assessment of the impact on data protection should also be carried out in situations where personal data are processed for the purpose of making decisions targeting certain natural persons following a systematic and comprehensive assessment of the personal aspects relating to natural persons, based on the creation of profiles for the respective data, or following the processing of special categories of personal data, biometric data or data regarding criminal convictions and offenses or related security measures. An assessment of the impact on data protection is equally necessary for the large-scale monitoring of areas accessible to the public, especially in the case of the use of optoelectronic devices or for any other operations where the competent supervisory authority considers that the processing is likely to generate a high risk for the rights and freedoms of data subjects, in particular because they prevent data subjects from exercising a right or using a service or contract, or because they are carried out systematically on a large scale. The processing of personal data should not be considered to be on a large scale if the processing refers to personal data from patients or clients by a particular doctor, other healthcare professional or lawyer. In these cases, a data protection impact assessment should not be mandatory.

(92) In some circumstances it might be reasonable and economically useful for a data protection impact assessment to have a broader perspective than that of a single project, for example where authorities or public bodies intend to establishes a common application or processing platform or in case several operators intend to introduce a common application or a common processing environment within an industrial sector or segment or for a horizontal activity used on a large scale.

(93) In the context of the adoption of the national legislation on which the fulfillment of the tasks of the public authority or public body is based and which regulates the operation or series of processing operations in question, the member states may consider it necessary to carry out such an assessment before carrying out the processing activities .

(94) If an impact assessment on data protection shows that the processing would generate, in the absence of guarantees, security measures and risk mitigation mechanisms, a high risk for the rights and freedoms of natural persons, and the operator considers that the risk does not can be mitigated by reasonable means in terms of available technologies and implementation costs, the supervisory authority should be consulted before starting processing activities. Such a high risk is likely to be generated by certain types of processing, as well as by the extent and frequency of processing, which may also lead to damages or affect the rights and freedoms of natural persons. The supervisory authority should respond to the request for consultation within a certain period. However, the lack of a reaction from the supervisory authority within the respective term should not affect any intervention of the supervisory authority in accordance with its tasks and powers provided in this regulation, including the power to prohibit processing operations. As part of this consultation process, the result of a data protection impact assessment carried out with regard to the processing in question may be transmitted to the supervisory authority, in particular the measures envisaged to mitigate the risk to the rights and freedoms of natural persons.

(95) The person authorized by the operator should assist the operator, if necessary and upon request, in ensuring compliance with the obligations arising from carrying out data protection impact assessments and prior consultation with the supervisory authority.
(96) During the elaboration of a legislative or regulatory measure that provides for the processing of personal data, a consultation of the supervisory authority should also take place, to guarantee the compliance of the processing considered with this regulation and, in especially, to mitigate the risk to which the concerned person is exposed.

(97) If the processing is carried out by a public authority, with the exception of courts or independent judicial authorities when acting in their judicial capacity, if, in the private sector, the processing is carried out by an operator whose main activity consists of processing operations that require a regular and systematic monitoring of the persons concerned on a large scale, or if the main activity of the operator or the person authorized by the operator consists in the large-scale processing of special categories of personal data and data on criminal convictions and offences, a person with specialist knowledge of legislation and practices regarding data protection should assist the operator or the person authorized by the operator to monitor internal compliance with this regulation. In the private sector, the main activities of an operator refer to its core activities, and not to the processing of personal data as ancillary activities. The necessary level of specialist knowledge should be established in particular depending on the data processing operations carried out and the level of protection required for personal data processed by the operator or the person authorized by the operator. These data protection officers, regardless of whether or not they are employees of the operator, should be able to perform their duties and tasks independently.

(98) Associations or other bodies representing categories of operators or persons authorized by operators should be encouraged to develop codes of conduct, within the limits of this regulation, so as to facilitate the effective application of this regulation, taking into account the specific characteristics of the processing carried out in certain sectors and the specific needs of micro-enterprises and small and medium-sized enterprises. In particular, such codes of conduct could adjust the obligations of the operators and the persons authorized by the operators, taking into account the risk related to the processing that is likely to be generated for the rights and freedoms of natural persons.

(99) When they draw up a code of conduct or when they modify or extend such a code, the associations and other bodies that represent categories of operators or persons authorized by

operators should consult relevant stakeholders, including data subjects, if feasible, and take into account the contributions submitted and the views expressed in such consultations. (100) In order to improve transparency and compliance with this Regulation, the establishment of certification mechanisms as well as data protection seals and marks should be encouraged, allowing data subjects to quickly assess the level of data protection data related to relevant products and services.

(101) Personal data flows to and from countries located outside the Union and international organizations are necessary for the development of international trade and international cooperation. The growth of these flows has generated new challenges and concerns regarding the protection of personal data. However, if personal data is transferred from the Union to operators, persons authorized by operators or other recipients from third countries or international organizations, the level of protection of natural persons ensured in the Union by this regulation should not be reduced, including in cases of subsequent transfers of personal data from the third country or international organization to operators, persons authorized by operators from the same or from another third country or international organization. In any case, transfers to third countries and international organizations can only be carried out in full compliance with this regulation. A transfer could only take place if, subject to compliance with the other provisions of this regulation, the operator or the person authorized by the operator fulfills the conditions stipulated by the provisions of this regulation regarding the transfer of personal data to third countries or international organizations.

(102) This regulation does not affect the international agreements concluded between the Union and third countries in order to regulate the transfer of personal data, including adequate guarantees for the persons concerned. Member States may conclude international agreements involving the transfer of personal data to third countries or international organizations, insofar as such agreements do not affect this regulation or other provisions of Union law and include an appropriate level of protection of the fundamental rights of the persons concerned.

(103) The Commission can decide, with effect throughout the Union, that a third country, a territory or a certain sector of a third country or an international organization offers an adequate level of data protection, thus ensuring legal security and uniformity in the Union in relation to the third country or international organization which is considered to provide such a level of protection. In these cases, personal data transfers to the respective third country or international organization can take place without the need to obtain additional authorizations. Also, the Commission may decide, after sending a notification and a complete justification to the third country or the international organization, to cancel such a decision.

(104) In accordance with the fundamental values ​​on which the Union is founded, in particular the protection of human rights, the Commission should, in its assessment of the third country or a specified territory or sector of a third country, take into account how it respects the rule of law, access to justice, as well as international human rights norms and standards and its general and sectoral legislation, including public safety, defense and national security legislation, as well as public order and criminal law . Making a decision on the adequacy of the level of protection for a specified territory or sector in a third country should take into account clear and objective criteria, such as the specific processing activities and the scope of applicable legal standards and legislation in force in the respective third country. The third country should offer guarantees that ensure an adequate level of protection, essentially equivalent to that provided within the Union, especially when personal data are processed in one or more specific sectors. In particular, the third country should ensure effective independent data protection supervision and provide cooperation mechanisms with Member States' data protection authorities, and data subjects should benefit from effective and enforceable rights and effective remedies administratively and judicially.

(105) In addition to the international commitments assumed by the third country or international organization, the Commission should take into account the obligations arising from the participation of the third country or international organization in multilateral or regional systems, in particular with regard to data protection with

personal character, as well as the implementation of such obligations. In particular, the accession of the third country to the Convention of the Council of Europe of January 28, 1981 for the protection of individuals from automated processing of personal data and the additional protocol should be taken into account. The Commission should consult the Committee when assessing the level of protection in third countries or international organizations.

(106) The Commission should monitor the operation of decisions regarding the level of protection in a third country or a territory or a specific sector in a third country or in an international organization and monitor the operation of decisions adopted pursuant to Article 25(6) ) or of Article 26 paragraph (4) of Directive 95/46/EC. In its decisions regarding the adequacy of the level of protection, the Commission should provide for a mechanism for periodic review of their functioning. This periodic review should be carried out in consultation with the third country or international organization concerned and should take into account all relevant developments in the third country or international organization. For the purpose of monitoring and carrying out periodic reviews, the Commission should take into account the opinions and findings of the European Parliament and the Council, as well as other relevant bodies and sources. The Commission should evaluate, within a reasonable time, the functioning of the decisions from the past and report all the relevant findings to the committee, in the sense of Regulation (EU) no. 182/2011 of the European Parliament and of the Council (1), as established under this regulation, of the European Parliament and of the Council.

(1) Regulation (EU) no. 182/2011 of the European Parliament and of the Council of 16 February 2011 establishing the rules and general principles regarding the control mechanisms by the Member States of the exercise of enforcement powers by the Commission (OJ L 55, 28.2.2011, p. 13).
(107) The Commission may recognize the fact that a third country, a territory or a specified sector of a third country or an international organization no longer ensures an adequate level of data protection. Consequently, the transfer of personal data to the third country or international organization concerned should be prohibited, unless the requirements set out in this regulation regarding transfers are met under appropriate safeguards, including mandatory corporate rules and derogations from specific situations. In this case, provision should be made for consultations between the Commission and such third countries or international organisations. The Commission should, in good time, inform the third country or the international organization about these reasons and initiate consultations with it to remedy the situation.

(108) In the absence of a decision on the adequacy of the level of protection, the operator or the person authorized by the operator should take measures to compensate for the lack of data protection in a third country by means of adequate guarantees for the data subject. Such adequate safeguards may consist of the use of mandatory corporate rules, standard data protection clauses adopted by the Commission, standard data protection clauses adopted by a supervisory authority or contractual clauses authorized by a supervisory authority. Those guarantees should ensure compliance with data protection requirements and the rights of data subjects corresponding to processing within the Union, including the availability of opposing rights of data subjects and effective remedies, including the right of access to effective redress on administrative or judicial way and the right to request compensation, in the Union or in a third country. These should refer in particular to the observance of the general principles regarding the processing of personal data: the principle of data protection starting with the moment of conception and the principle of implicit data protection. Transfers can also be carried out by authorities or public bodies with authorities or public bodies in third countries or with international organizations with corresponding powers and functions, including on the basis of the provisions that provide opposable and effective rights for the persons concerned, which must be introduced in the administrative agreements, such as a memorandum of understanding. Authorization from the competent supervisory authority should be obtained when guarantees are offered under non-legally binding administrative agreements.

(109) The possibility for the operator or the person authorized by the operator to use standard clauses in the matter of data protection, adopted by the Commission or a supervisory authority, should not prevent the operators or the persons authorized by them to include the standard clauses in the matter

of data protection in a larger contract, such as a contract between the person authorized by the operator and another person authorized by the operator, nor to add other clauses or additional guarantees, as long as they do not contravene, directly or indirectly, the contractual clauses standards adopted by the Commission or a supervisory authority or does not prejudice the rights or fundamental freedoms of the persons concerned. Operators and persons authorized by operators should be encouraged to offer additional guarantees through contractual commitments that complement the standard protection clauses.

(110) A group of enterprises or a group of enterprises involved in a common economic activity should be able to use the mandatory corporate rules approved for its international transfers from the Union to organizations within the same group of enterprises or group of enterprises involved in a common economic activity, provided that such corporate rules include all essential principles and opposable rights in order to ensure adequate safeguards for transfers or categories of transfers of personal data.

(111) Provision should be made for the possibility to carry out transfers in certain circumstances where the data subject has given his explicit consent, where the transfer is occasional and necessary in connection with a contract or legal action, regardless of whether it is in the context of a judicial procedure or in the context of an administrative or extrajudicial procedure, including within the procedures submitted to regulatory bodies. Also, provision should be made for the possibility of making transfers if important reasons of public interest established by Union law or domestic law require this or if the transfer is made from a register established by law and intended to be consulted by the public or by persons who have a legitimate interest. In this last case, such a transfer should not involve the totality of personal data or all the categories of data contained in the register, and when the register is intended to be consulted by persons who have a legitimate interest, the transfer should be carried out only at the request of the respective persons or if they are the recipients, fully taking into account the interests and fundamental rights of the person concerned.

(112) These exemptions should apply, in particular, to data transfers requested and necessary for important reasons of public interest, for example in the case of international data exchange between competition authorities, tax or customs administrations, between supervisory authorities financial, between the competent services in terms of social security or public health, for example in the case of detecting contact points for contagious diseases or for the reduction and/or elimination of doping in sports. A transfer of personal data should also be considered lawful if it is necessary for the purpose of protecting an interest that is essential to the vital interests of the data subject or another person, including for physical integrity or life to it, in case the concerned person does not have the capacity to give his consent. In the absence of a decision regarding the adequacy of the level of protection, Union law or domestic law may, for important reasons of public interest, expressly establish limits on the transfer of specific categories of data to a third country or an international organization. Member States should notify the Commission of these provisions. Any transfer to an international humanitarian organization of the personal data of a data subject who is physically or legally unable to give consent, in order to fulfill a task arising from the Geneva Conventions or in order to comply with international humanitarian law applicable in armed conflicts, could be considered necessary for an important reason of public interest or because it is in the vital interest of the person concerned.

(113) Transfers that can be considered as non-repetitive and that only refer to a limited number of data subjects, could also be carried out in order to achieve the legitimate interests pursued by the operator, when those interests do not prevail or the rights and freedoms of the data subject and when the operator has evaluated all the circumstances related to the data transfer. The operator should pay particular attention to the nature of the personal data, the purpose and duration of the proposed processing operation or operations, as well as the situation in the country of origin, in the third country and in the country of final destination and should offer adequate guarantees for the protection the fundamental rights and freedoms of natural persons in what

regarding the processing of their personal data. Such transfers should only be possible in residual cases where none of the other reasons for transfer can be applied. Regarding the purposes of scientific or historical research or statistical purposes, the legitimate expectations of society regarding the increase in the level of knowledge should be taken into account. The operator should inform the supervisory authority and the data subject about the transfer.

(114) In any case, when the Commission has not taken a decision on the appropriate level of data protection in a third country, the operator or the person authorized by the operator should use solutions that offer the data subjects opposable and effective rights regarding the processing of their data in the Union once these data have been transferred, so that the persons concerned continue to benefit from fundamental rights and guarantees.

(115) Some third countries have adopted laws, regulations and other legal acts whose objective is to directly regulate the data processing activities of natural and legal persons under the jurisdiction of the member states. This may include court orders or decisions of administrative authorities in third countries requiring an operator or a person authorized by the operator to transfer or disclose personal data and which is not based on an international agreement, such as a treaty of mutual legal assistance, in force between the requesting third country and the Union or a member state. The extraterritorial application of these laws, regulations and other legal acts may violate international law and may prevent the protection of natural persons ensured in the Union by this regulation. Transfers should be allowed only if the conditions stipulated by this regulation are fulfilled for a transfer to third countries. This could be the case, inter alia, when the disclosure is necessary for an important reason of public interest recognized in the Union law or in the internal law that applies to the operator.

(116) The cross-border flow of personal data outside the Union may expose to increased risk the ability of natural persons to exercise their data protection rights, in particular to ensure their protection against the illegal use or disclosure of these information. At the same time, the supervisory authorities may find that they are unable to deal with complaints or carry out investigations regarding the activities carried out outside their borders. Their efforts to collaborate in a cross-border context can also be hampered by the insufficiency of prevention or remedial powers, the heterogeneous nature of legal regimes and the existence of practical obstacles, such as resource constraints. Therefore, it is necessary to promote closer cooperation between data protection supervisory authorities in order to be able to exchange information and carry out investigations together with their international counterparts. In order to develop international cooperation mechanisms to facilitate and provide mutual international assistance in ensuring the application of legislation in the field of personal data protection, the Commission and the supervisory authorities should exchange information and cooperate in activities related to the exercise their competences with the competent authorities of third countries, on the basis of reciprocity and in accordance with this regulation.

(117) The establishment in the member states of supervisory authorities, empowered to carry out their tasks and exercise their powers in complete independence, is an essential element of the protection of natural persons with regard to the processing of their personal data. Member States should be able to establish several supervisory authorities, to reflect their constitutional, organizational and administrative structure.

(118) The independence of the supervisory authorities should not mean that the supervisory authorities cannot be subject to control or monitoring mechanisms regarding their expenses or to a jurisdictional control.
(119) If a member state establishes several supervisory authorities, it should establish by law mechanisms to ensure the effective participation of the respective supervisory authorities in the mechanism for ensuring coherence. The respective Member State should, in particular, designate the supervisory authority that fulfills the function of a single point of contact for the effective participation of these authorities in the mechanism, in order to ensure a rapid and harmonious cooperation with other supervisory authorities, with the committee and with the Commission .

(120) Each supervisory authority should benefit from the financial and human resources, premises and infrastructure necessary for the effective performance of their tasks, including those related to mutual assistance and cooperation with other supervisory authorities throughout the Union. Each supervisory authority should have a separate annual public budget, which can be part of the general state or national budget.

(121) The general conditions for the member or members of the supervisory authority should be established by law in each member state and should, in particular, provide that the respective members are appointed through a transparent procedure either by the parliament, the government or the head of state of the member state based on a proposal from the government, a member of the government, the parliament or a chamber of the parliament, or by an independent body empowered by domestic law. In order to ensure the independence of the supervisory authority, its member or members should act with integrity, not undertake actions incompatible with their duties, and, during the mandate, should not carry out incompatible activities, remunerated or not. The supervisory authority should have its own staff, chosen by the supervisory authority or by an independent body established under domestic law, which should be subordinated exclusively to the member or members of the supervisory authority.

(122) Each supervisory authority should have, on the territory of the member state to which it belongs, the attribution to exercise the powers and fulfill the tasks with which it is invested in accordance with this regulation.
This should include in particular the processing in the context of the activities of a seat of the operator or the person authorized by the operator in the territory of the own member state, the processing of personal data carried out by public authorities or private bodies acting in the public interest, the processing affecting the persons data subjects from its territory or the processing carried out by an operator or a person authorized by the operator who is not based in the Union if it concerns data subjects who have their residence in its territory. This should include handling complaints submitted by a data subject, conducting investigations into the application of this Regulation and promoting public information on the risks, rules, guarantees and rights in the field of personal data processing.

(123) The supervisory authorities should monitor the application of the provisions of this regulation and contribute to its consistent application throughout the Union, in order to ensure the protection of natural persons with regard to the processing of their personal data and to facilitate the free movement of personal data within the internal market. In this sense, the supervisory authorities should cooperate with each other, as well as with the Commission, without the need for any agreement between the Member States regarding the granting of mutual assistance or regarding said cooperation.

(124) If the processing of personal data takes place within the activities of an office of an operator or a person authorized by the operator in the Union, and the operator or person authorized by the operator has offices in several member states, or in case in which the processing that takes place in the context of the activities of a single office of an operator or a person authorized by the operator in the Union affects or is likely to significantly affect data subjects from several member states, the supervisory authority of the main office of the operator or the person authorized by the operator or of the sole headquarters of the operator or of the person authorized by the operator should act as the main authority. It should cooperate with the other concerned authorities, because the operator or the person authorized by the operator has an office in the territory of their member state, because the concerned persons who have their residence in their territory are significantly affected or because they have been filed a complaint. Also, if a data subject who does not reside in the respective Member State has filed a complaint, the supervisory authority to which the complaint was filed should also be a concerned supervisory authority. As part of its tasks to issue guidance on any matter relating to the implementation of this Regulation, the Committee should be able to issue guidance on, in particular, the criteria to be taken into account in order to determine whether

the processing in question significantly affects data subjects from several member states and regarding the content of a relevant and motivated objection.
(125) The main authority should have the power to adopt binding decisions regarding the measures to apply the powers conferred on it in accordance with this regulation. In its capacity as the main authority, the supervisory authority should closely involve and coordinate the activities of the supervisory authorities concerned in the decision-making process. In cases where the decision is a partial or total rejection of the complaint from the concerned person, such a decision should be adopted by the supervisory authority to which the complaint was submitted. (126) The decision should be jointly agreed by the main supervisory authority and the concerned supervisory authorities and should concern the main office or the sole office of the operator or the person authorized by the operator and be binding for the operator and the person authorized by the operator . The operator or the person authorized by the operator should take the necessary measures to ensure compliance with this regulation and the implementation of the decision notified by the main supervisory authority of the head office of the operator or the person authorized by the operator with regard to the processing activities in the Union .

(127) Each supervisory authority that does not act as the main supervisory authority should have the competence to deal with local cases, where the operator or the person authorized by the operator has offices in several Member States, but the object of the respective processing concerns only the processing carried out in a single member state and involving only data subjects from that single member state, for example if the object is the processing of employees' personal data in the specific context related to the workforce from a member state. In such cases, the supervisory authority should inform the lead supervisory authority of the matter without delay. After being informed, the lead supervisory authority should decide whether it will deal with the case itself under the provision on cooperation between the lead supervisory authority and other concerned supervisory authorities (the "one stop shop mechanism"), or if the supervisory authority which informed her that she should deal with the case at the local level. When deciding whether to deal with the case, the lead supervisory authority should take into account whether there is an establishment of the controller or the person authorized by the controller in the Member State of the supervisory authority that informed it, in order to guarantee effective compliance with a decisions regarding the operator or the person authorized by the operator. If the lead supervisory authority decides to deal with the case, the supervisory authority that informed it should have the opportunity to present a draft decision, which the lead supervisory authority should take into account in the most the measure when it prepares its draft decision within the respective one-stop-shop mechanism.

(128) The rules regarding the main supervisory authority and the single window mechanism should not apply if the processing is carried out by public authorities or private bodies in the public interest. In such cases, the only supervisory authority competent to exercise the powers assigned to it in accordance with this regulation should be the supervisory authority of the Member State in which the public authority or private body has its headquarters.

(129) In order to ensure the consistency of the monitoring and application of this Regulation throughout the Union, the supervisory authorities should have the same effective tasks and powers in each Member State, including investigative powers, corrective powers and sanctions, as well as authorization powers and counseling, especially in the case of complaints filed by natural persons, as well as, without prejudice to the powers of the criminal prosecution authorities based on domestic law, to bring to the attention of the judicial authorities the cases of violation of this regulation and to get involved in judicial proceedings. These powers should also include the power to impose a temporary or definitive limitation, including a ban, on the processing. Member States may establish other duties related to the protection of personal data under this Regulation. The competences of the supervisory authorities should be exercised in accordance with adequate procedural guarantees provided for in Union and domestic law, impartially, fairly and within a reasonable time. In particular, each measure should be adequate, necessary and proportionate in order to

ensure compliance with the provisions of this regulation, taking into account the circumstances of each individual case, to respect the right of any person to be heard before taking any individual measure that could affect him and to avoid unnecessary costs and excessive inconveniences for the persons in question . Investigative powers regarding access to premises should be exercised in accordance with the specific requirements of national procedural law, such as the obligation to obtain prior judicial authorization. Each legally binding measure taken by the supervisory authority should be presented in writing, be clear and unambiguous, indicate the supervisory authority that issued the measure, the date of issuing the measure, bear the signature of the head or a member of the supervisory authority authorized by him, to provide the reasons for which the measure was taken and to refer to the right to an effective remedy. This should not preclude additional requirements under national procedural law. The adoption of such legally binding decisions implies the fact that a jurisdictional control may arise in the member state of the supervisory authority that adopted the decision.

(130) If the supervisory authority to which the complaint was submitted is not the main supervisory authority, the main supervisory authority should cooperate closely with the supervisory authority to which the complaint was submitted, in accordance with the provisions on cooperation and consistency provided in this regulation. In such cases, the lead supervisory authority should, when taking measures intended to produce legal effects, including the imposition of administrative fines, take into account as much as possible the opinion of the supervisory authority to which the complaint was submitted and which should to maintain its competence to carry out any investigation on the territory of its own member state, in collaboration with the main supervisory authority.

(131) In cases where another supervisory authority should act as the main supervisory authority for the processing activities of the operator or the person authorized by the operator, but the concrete object of a complaint or the possible violation concerns only the processing activities of the operator or the person authorized by the operator in the member state where the complaint was filed or the possible violation was detected, and the matter does not substantially affect or is not likely to substantially affect persons concerned from other member states, the supervisory authority who received a complaint or detected or was otherwise informed about situations of possible violations of this regulation should try to find an amicable solution with the operator and, if this fails, exercise the full range of powers. This should include specific processing activities carried out on the territory of the member state of the supervisory authority or with regard to data subjects from the territory of that member state, processing activities that take place in the context of an offer of goods or services specifically intended for persons targeted on the territory of the member state of the supervisory authority or processing activities that must be evaluated taking into account the relevant legal obligations under domestic law.

(132) Awareness-raising activities organized for the public by supervisory authorities should include specific measures targeting operators and persons authorized by operators, including micro, small and medium-sized enterprises, as well as natural persons, in particular in the context educational.

(133) The supervisory authorities should give each other assistance in fulfilling their tasks, in order to ensure the coherence of the application of this regulation on the internal market. A supervisory authority requesting mutual assistance may adopt a provisional measure if it does not receive a response to a request for mutual assistance within one month of the receipt of the request by the other supervisory authority.

(134) Each supervisory authority should participate, as appropriate, in joint operations between supervisory authorities. The supervisory authority to which the request was addressed should have the obligation to respond to the request within a certain period.
(135) In order to ensure the consistent application of this Regulation throughout the Union, a mechanism should be established to ensure consistency within which the supervisory authorities

cooperate. This mechanism should apply, in particular, if a supervisory authority intends to adopt a measure intended to produce legal effects with regard to processing operations that substantially affect a significant number of data subjects from more than one member states. The mechanism should also apply if a concerned supervisory authority or the Commission requests that the respective aspect be dealt with within the coherence mechanism. This mechanism should not affect the measures that the Commission can adopt in the exercise of its powers under the treaties.

(136) In applying the mechanism for ensuring coherence, the committee should, within a certain period, issue an opinion if a majority of its members so decides or if any supervisory authority concerned or the Commission so requests . The committee should also be empowered to adopt legally binding decisions in case of disputes between supervisory authorities. For this purpose, it should issue, in principle with a two-thirds majority of its members, legally binding decisions, in well-defined cases, if there are divergent opinions between the supervisory authorities, especially in within the framework of the cooperation mechanism between the main supervisory authority and the supervisory authorities concerned regarding the merits of the case, in particular the existence or not of a violation of this regulation. (137) It is possible that there is an urgent need to act to ensure the protection of the rights and freedoms of the persons concerned, especially if there is a danger that the exercise of a right of a concerned person will be considerably hindered. Therefore, a supervisory authority should be able to adopt provisional measures on its territory, duly justified, having a determined period of validity that should not exceed three months.

(138) The application of such a mechanism should constitute a condition for the legality of a measure intended to produce legal effects, taken by a supervisory authority, in cases where its application is mandatory. In other cases with cross-border relevance, the cooperation mechanism between the main supervisory authority and the targeted supervisory authorities should be implemented, and the targeted supervisory authorities could provide mutual assistance and conduct joint operations on a bilateral basis. or multilateral, without triggering the mechanism to ensure coherence.

(139) In order to promote the coherent application of this regulation, the committee should be established as an independent body of the Union. In order to fulfill its objectives, the committee should have legal personality. The committee should be represented by its president. It should replace the Working Group for the protection of individuals with regard to the processing of personal data, established by Directive 95/46/EC. It should be composed of the heads of supervisory authorities from each member state and the European Data Protection Authority or their representatives. The Commission should participate in the committee's activities without voting rights, and the European Data Protection Authority should have special voting rights. The Committee should contribute to the coherent application of this Regulation throughout the Union, including by providing advice to the Commission, especially regarding the level of protection in third countries and within international organizations, and by promoting the cooperation of supervisory authorities throughout the Union. The committee should act independently in the performance of its duties. (140) The committee should be assisted by a secretariat provided by the European Data Protection Authority. The staff of the European Data Protection Authority involved in the performance of the tasks assigned to the committee under this Regulation should perform their tasks exclusively according to the instructions of the chairman of the committee and report to him.

(141) Any data subject should have the right to submit a complaint to a single supervisory authority, in particular in the Member State where he has his habitual residence, as well as the right to an effective remedy in accordance with Article 47 of charter, if the data subject considers that his rights under this regulation are violated or if the supervisory authority does not react to a complaint, rejects or refuses a complaint in whole or in part or does not act when such an action is necessary to ensure the protection of the rights of the concerned person. The investigation following a complaint should be carried out, under judicial control, to the extent necessary, depending on the case. The supervisory authority should inform

the concerned person regarding the evolution and resolution of the complaint within a reasonable period. In the event that the case requires further investigation or coordination with another supervisory authority, intermediate information should be provided to the data subject. In order to facilitate the submission of complaints, each supervisory authority should take measures such as making available a complaint submission form, which can also be completed in electronic format, without excluding other means of communication.

(142) If the data subject considers that his rights under this regulation are violated, he should have the right to mandate a non-profit body, organization or association that is established in accordance with the law internal, whose (whose) statutory objectives are in the public interest and which carries out its activity in the field of ensuring the protection of personal data, to submit a complaint on its behalf to a supervisory authority, to exercise the right to an appeal on its behalf to the persons concerned or, in the case provided for in domestic law, to exercise the right to receive compensation on behalf of the persons concerned. A Member State may provide that such a body, organization or association shall have the right to lodge a complaint in that Member State, independently of the mandate granted by a data subject, and shall have the right to an effective remedy if has reason to consider that the rights of a data subject have been violated as a result of a processing of personal data that violates this regulation. The body, organization or association in question cannot claim compensation on behalf of a data subject, regardless of the mandate granted by the data subject. (143) Any natural or legal person has the right to file an action for annulment against the committee's decisions before the Court of Justice, in accordance with the conditions provided for in Article 263 of the TFEU. As the addressees of these decisions, the supervisory authorities concerned who wish to contest them must bring an action against the respective decisions within two months of the date on which they were notified, in accordance with Article 263 of the TFEU. If the committee's decisions directly and individually target an operator, a person authorized by the operator or the complainant, the latter can file an action to cancel the respective decisions within two months of their publication on the committee's website, in in accordance with Article 263 of the TFEU. Without prejudice to this right under Article 263 of the TFEU, any natural or legal person should have the right to an effective judicial remedy before the competent national court against a decision of a supervisory authority that produces legal effects on that person . Such a decision refers in particular to the exercise of investigative, corrective and authorization powers by the supervisory authority or to the refusal or rejection of complaints. However, the right to an effective judicial remedy does not include measures by supervisory authorities that are not legally binding, such as opinions issued by the supervisory authority or advice provided by it. Actions against a supervisory authority should be brought before the courts of the Member State in which the supervisory authority is established and should be conducted in accordance with the procedural law of that Member State. Those courts should exercise their full judicial jurisdiction, which should include the power to examine all matters of fact or law relevant to the dispute before them.

If a complaint has been rejected or refused by a supervisory authority, the complainant can file an action in the courts of the same member state. In the context of judicial appeals regarding the application of this regulation, national courts that consider a decision on the matter in question necessary to allow them to take a decision may or, in the case provided for in Article 267 of the TFEU, must request the Court of Justice to issue a preliminary decision on the interpretation of Union law, including this regulation. In addition, if a decision of a supervisory authority implementing a decision of the committee is challenged before a national court and the validity of the committee's decision is in question, that national court does not have the power to declare the committee's decision null and void, but must bring the question of validity before the Court of Justice, in accordance with Article 267 of the TFEU, as interpreted by the Court of Justice, whenever the national court considers the decision null and void. However, a national court may not refer a question regarding the validity of the committee's decision at the request of a person

natural or legal persons who had the opportunity to file an action for annulment against that decision, especially if it was directly and individually concerned by the decision in question, but did not do so within the term provided for in Article 263 of the TFEU.
(144) When a court seised with a procedure against a decision of a supervisory authority has reason to believe that proceedings have been brought before a competent court in another member state regarding the same processing, such as the same object of processing, by the same operator or the same person authorized by the operator, or the same cause, the respective court should contact the second court to confirm the existence of such related procedures. If these related proceedings are pending before a court in another member state, any court, except the one originally referred to, may suspend its proceedings or, at the request of one of the parties, decline jurisdiction in favor of the referred court initially, provided that the latter has the competence to settle the proceedings in question and that the law applied to it allows it to consolidate these related proceedings. Proceedings are considered related when they are so closely related to each other that it is opportune to implement and judge them at the same time in order to avoid the risk of pronouncing irreconcilable decisions in the case of judging them separately.

(145) With regard to the actions initiated against an operator or a person authorized by the operator, the plaintiff should have the possibility to bring the action before the courts of the Member States where the operator or person authorized by the operator has an office or in which the person the subject has its residence, unless the operator is a public authority from a member state acting in the exercise of its public powers.

(146) The operator or the person authorized by the operator should pay compensation for any damage that a person may suffer as a result of a processing that violates this regulation. The operator or the person authorized by the operator should be exempt from liability if they prove that they are in no way responsible for the damage. The concept of damage should be interpreted in a broad sense, from the perspective of the jurisprudence of the Court of Justice, in a way that fully reflects the objectives of this regulation. This provision does not affect any claim for compensation resulting from the violation of other rules of Union law or domestic law. A processing that violates this regulation also includes processing that violates the delegated and implementing acts adopted in accordance with this regulation and the domestic law that specifies the rules of this regulation. The persons concerned should receive full and effective compensation for the damage they have suffered. If the operators or the persons authorized by the operators are involved in the same processing, each operator or each person authorized by the operator should be considered responsible for the entire damage. However, when the legal procedures that concern them are connected, in accordance with domestic law, the compensation can be distributed according to the responsibility of each operator or each person authorized by the operator, provided that the full and effective compensation of the person concerned is ensured who suffered the damage. Any operator or person authorized by the operator who has paid full compensation may subsequently file a recourse action against other operators or persons authorized by operators involved in the same processing.

(147) In the event that this regulation contains specific rules regarding judicial jurisdiction, especially regarding judicial appeals, including actions for damages, against an operator or a person authorized by the operator, the general rules regarding judicial jurisdiction such as those from Regulation (EU) no. 1215/2012 of the European Parliament and of the Council (1) should not affect the application of such specific rules.

(1) Regulation (EU) no. 1215/2012 of the European Parliament and of the Council of 12 December 2012 regarding judicial competence, recognition and enforcement of decisions in civil and commercial matters (OJ L 351, 20.12.2012, p. 1).
(148) In order to strengthen compliance with the application of the rules provided in this regulation, sanctions, including administrative fines, should be imposed for any violation of this regulation, in addition to or instead of the appropriate measures imposed by the supervisory authority under this regulation. In the event of a minor violation or in the event that the fine likely to be imposed would

constitutes a disproportionate burden for a natural person, a warning can be issued instead of a fine. However, due consideration should be given to the nature, seriousness and duration of the breach, the deliberate nature of the breach, the actions taken to mitigate the damage caused, the degree of liability or any relevant previous breaches, the manner in which the breach was brought about to the knowledge of the supervisory authority, compliance with the measures adopted against the operator or the person authorized by the operator, adherence to a code of conduct and any other aggravating or mitigating factor. The imposition of sanctions, including administrative fines, should be subject to adequate procedural guarantees, in accordance with the general principles of Union law and the Charter, including effective judicial protection and a fair trial.

(149) Member States should be able to establish the rules regarding criminal sanctions for violations of this regulation, including for violations of domestic law adopted on the basis of and within the limits of this regulation. The respective criminal sanctions may also allow the deprivation of the profits obtained by violating this regulation. However, the imposition of criminal sanctions for violations of such rules of domestic law and administrative sanctions should not lead to the violation of the ne bis in idem principle, as interpreted by the Court of Justice.

(150) In order to consolidate and harmonize administrative sanctions in case of violation of this regulation, each supervisory authority should have the power to impose administrative fines. This regulation should indicate the violations, and the maximum limit and the criteria for establishing the related administrative fines, which should be established by the competent supervisory authority in each individual case, taking into account all the relevant circumstances of the specific situation, taking into account due consideration, in particular, of the nature, gravity and duration of the breach, as well as its consequences and the measures taken to ensure compliance with the obligations under this regulation and to prevent or mitigate the consequences of the breach. Where administrative fines are imposed on an undertaking, an undertaking should be understood as an undertaking in accordance with Articles 101 and 102 of the TFEU for these purposes. If administrative fines are imposed on persons who are not businesses, the supervisory authority should take into account the general level of income from the respective Member State, as well as the economic situation of the person when estimating the appropriate amount of the fine. The consistency mechanism can also be used to promote the consistent application of administrative fines. The competence to determine whether and to what extent public authorities should be subject to administrative fines should rest with the member states. The imposition of an administrative fine or the sending of a warning does not affect the application of other powers of the supervisory authorities or other sanctions under this regulation. (151) The legal systems of Denmark and Estonia do not allow administrative fines as provided in this regulation. The rules on administrative fines may be applied so that, in Denmark, the fine is imposed by the competent national courts as a criminal sanction, and in Estonia the fine is imposed by the supervisory authority in a tort procedure, provided that such application of the rules in the respective member states to have an effect equivalent to that of the administrative fines imposed by the supervisory authorities. Therefore, the competent national courts should take into account the recommendation of the supervisory authority that initiated the fine. In any case, the fines imposed should be effective, proportionate and dissuasive. (152) Where this Regulation does not harmonize administrative sanctions or in other cases, where necessary, for example in case of serious infringements of this Regulation, Member States should implement a system providing for effective sanctions, proportionate and dissuasive. The nature of such sanctions, whether criminal or administrative, should be determined by domestic law.

(153) Member States' law should establish a balance between the rules governing freedom of expression and information, including journalistic, academic, artistic and/or literary expression, and the right to the protection of personal data under this Regulation. The processing of personal data exclusively for journalistic purposes or for the purpose of academic, artistic or literary expression should be subject to exemptions or exceptions from

certain provisions of this regulation in case it is necessary to establish a balance between the right to the protection of personal data and the right to freedom of expression and information, as provided in article 11 of the charter. This should especially apply to the processing of personal data in the audiovisual field, as well as in news archives and newspaper libraries. Therefore, the member states should adopt legislative measures that provide for the necessary exceptions and derogations in order to ensure the balance between these fundamental rights. Member States should adopt such exceptions and derogations with regard to the general principles, the rights of data subjects, the operator and the person authorized by the operator, the transfer of personal data to third countries or international organizations, independent supervisory authorities, cooperation and coherence , as well as regarding specific data processing situations. If these exceptions or exemptions differ from one member state to another, the law of the member state under which the operator falls should apply. In order to take into account the importance of the right to freedom of expression in every democratic society, it is necessary that notions related to this freedom, such as journalism, be interpreted in a broad sense.

(154) This regulation allows the consideration of the principle of public access to official documents in the application of this regulation. Public access to official documents can be considered to be in the public interest. Personal data from documents held by a public authority or a public body should be able to be disclosed by that authority or that body if the Union law or the internal law under which the public authority or the public body falls provides for this . Union law and national law should ensure a balance between public access to official documents and the re-use of public sector information, on the one hand, and the right to the protection of personal data, on the other, and could therefore provide the necessary balance with the right to the protection of personal data under this regulation. The reference to public authorities and bodies should, in this context, include all authorities or other bodies regulated by domestic law regarding public access to documents. Directive 2003/98/EC of the European Parliament and of the Council (1) leaves intact and does not affect in any way the level of protection of natural persons with regard to the processing of personal data in accordance with Union and internal law and, in particular, it does not modify the rights and obligations provided by this regulation. In particular, the above-mentioned directive does not apply to documents to which access is excluded or restricted under access regimes for reasons related to the protection of personal data, nor to parts of documents accessible under those regimes that contain personal data whose reuse was established by law as being incompatible with the law regarding the protection of natural persons with regard to the processing of personal data.

(1) Directive 2003/98/EC of the European Parliament and of the Council of 17 November 2003 on the reuse of public sector information (OJ L 345, 31.12.2003, p. 90).
(155) Internal law or collective agreements, including "employment agreements", may provide specific rules to regulate the processing of employees' personal data in the context of employment, especially the conditions in which personal data in the context of employment of a workplace can be processed based on the employee's consent, for the purpose of recruitment, compliance with the terms of the employment contract, including the discharge of obligations established by law or collective agreements, management, planning and organizing work, equality and diversity at the workplace, ensuring health and safety at the workplace, as well as for the purpose of exercising and benefiting, individually or collectively, from the rights and benefits related to employment, as well as for the purpose of terminating employment relations.

(156) The processing of personal data for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes should be subject to adequate guarantees for the rights and freedoms of the person concerned under this regulation. The respective guarantees should ensure that the necessary technical and organizational measures have been established to ensure, in particular, the principle of data minimization. The subsequent processing of personal data for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes is carried out when the operator has assessed the feasibility for fulfilling

these objectives by processing personal data that do not allow or no longer allow the identification of the persons concerned, provided that there are adequate guarantees (such as the pseudonymization of personal data). Member States should provide adequate guarantees for the processing of personal data for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes. Member States should be authorized to provide, under certain conditions and subject to adequate guarantees for data subjects, clarifications and exemptions regarding requests for information and the right to rectification, the right to erasure, the right to be forgotten, the right to restriction of processing, the right to data portability, as well as the right to opposition in the case of personal data processing for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes. The conditions and guarantees in question may generate specific procedures so that the data subjects exercise their respective rights if this is appropriate in the context of the purposes targeted by the specific processing, as well as technical and organizational measures aimed at minimizing the processing of personal data, in accordance with the principles of proportionality and necessity. The processing of personal data for scientific purposes should also comply with other relevant legislation, such as those on clinical trials.

(157) By combining information from registries, researchers can gain valuable new knowledge about widespread diseases such as cardiovascular disease, cancer, and depression. Based on registries, research results can be strengthened, as they are based on a larger population. In the social sciences, register-based research allows researchers to obtain essential information about the long-term correlation of a range of social conditions, such as unemployment or education, with other life conditions. Research results obtained on the basis of registers provide solid, high-quality knowledge, which can form the basis for the development and implementation of knowledge-based policies and which can improve the quality of life for a number of people, the efficiency of social services. In order to facilitate scientific research, personal data may be processed for scientific research purposes, subject to the conditions and corresponding guarantees established in Union law or in domestic law.

(158) If personal data are processed for archiving purposes, this regulation should also apply to that processing, taking into account the fact that this regulation should not apply to deceased persons. Public authorities or public or private bodies that hold records of public interest should, under Union law or national law, have a legal obligation to acquire, keep, evaluate, prepare, describe, communicate, promote, disseminate and ensure access to records of lasting value of general public interest. Member States should also be able to provide for further processing of personal data for archiving purposes, for example to provide specific information on political behavior during former totalitarian state regimes, genocides, crimes against humanity, especially the holocaust, or war crimes.

(159) If personal data are processed for scientific research purposes, this regulation should also apply to that processing. For the purposes of this regulation, the processing of personal data for scientific research purposes should be interpreted in a broad sense, including for example technological development and demonstration activities, fundamental research, applied research and research financed from private sources. In addition, the Union's objective of creating a European Research Area, as mentioned in Article 179(1) of the TFEU, should be taken into account. The goals of scientific research should also include studies carried out in the public interest in the field of public health. In order to fulfill the specific characteristics of the processing of personal data for the purposes of scientific research, specific conditions should apply, in particular with regard to the publication or disclosure in another way of personal data in the context of the purposes of scientific research . If the result of scientific research, especially in the health context, constitutes a reason for additional measures in the interest of the person concerned, the general rules of this regulation should be applied with these measures in mind.

(160) If personal data are processed for historical research purposes, this regulation should also apply to that processing. This should also include historical research and research for genealogical purposes, bearing in mind that this regulation should not apply to deceased persons.

(161) In order to grant consent to participate in scientific research activities within clinical trials, the relevant provisions of Regulation (EU) no. 536/2014 of the European Parliament and of the Council (1).
(1) Regulation (EU) no. 536/2014 of the European Parliament and of the Council of April 16, 2014 regarding interventional clinical trials with medicinal products for human use and repealing Directive 2001/20/EC (OJ L 158, 27.5.2014, p. 1).

(162) If personal data are processed for statistical purposes, this regulation should apply to that processing. Union law or national law should, within the limits of this regulation, determine the statistical content, access control, specifications for the processing of personal data for statistical purposes and the appropriate measures to protect the rights and freedoms of data subjects and to ensure the confidentiality of statistical data. These statistical results can be used later for different purposes, including for scientific research purposes. Statistical purposes means any operation of collection and processing of personal data necessary for statistical surveys or for the production of statistical results. Statistical purposes assume that the result of processing for statistical purposes does not constitute personal data, but aggregated data and that this result or personal data are not used to support measures or decisions regarding a certain natural person.

(163) The confidential information that the statistical authorities at the Union and national level collect in order to draw up official European and national statistics should be protected. European statistics should be designed, developed and disseminated in accordance with the statistical principles laid down in Article 338(2) of the TFEU, while national statistics should also be in accordance with domestic law. Regulation (EC) no. 223/2009 of the European Parliament and of the Council (2) provides additional specifications regarding the confidentiality of statistical data for European statistics.

(2) Regulation (EC) no. 223/2009 of the European Parliament and of the Council of March 11, 2009 regarding European statistics and repealing Regulation (EC, Euratom) no. 1101/2008 of the European Parliament and of the Council regarding the transmission of confidential statistical data to the Statistical Office of the European Communities, of Regulation (EC) no. 322/97 of the Council regarding community statistics and Decision 89/382/CEE, Euratom of the Council establishing the Committee for statistical programs of the European Communities (OJ L 87, 31.3.2009, p. 164).

(164) Regarding the powers of the supervisory authorities to obtain from the operator or from the person authorized by the operator access to personal data and access to their buildings, the member states can adopt, through legislation and within the limits established by this regulation, specific rules for protecting professional secrecy or other equivalent obligations, to the extent that this is necessary to ensure a balance between the right to the protection of personal data and the obligation to preserve professional secrecy. This does not affect the existing obligations of the member states to adopt rules regarding professional secrecy in the situations required by Union law.

(165) This regulation respects and does not affect the status enjoyed, based on the existing constitutional law, by churches and religious associations or communities in the member states, as recognized in Article 17 of the TFEU.
(166) In order to fulfill the objectives of this regulation, namely to protect the fundamental rights and freedoms of natural persons and, in particular, their right to the protection of personal data, and to guarantee the free circulation of personal data on the territory of the Union , the power to adopt acts in accordance with Article 290 of the TFEU should be delegated to the Commission. In particular, delegated acts should be adopted regarding the criteria and requirements for certification mechanisms, the information to be presented by standardized pictograms and the procedures for providing such pictograms. It is particularly important that, within

its preparatory activities, the Commission to organize appropriate consultations, including at expert level. When preparing and drafting delegated acts, the Commission should ensure the simultaneous, timely and appropriate transmission of relevant documents to the European Parliament and the Council.

(167) In order to ensure uniform conditions for the implementation of this regulation, the Commission should be invested with enforcement powers in the situations established by this regulation. The respective competences should be exercised in accordance with Regulation (EU) no. 182/2011. In this context, the Commission should consider specific measures for micro-enterprises and for small and medium-sized enterprises.

(168) The examination procedure should be used for the adoption of implementing acts regarding: standard contractual clauses between operators and persons authorized by operators, as well as between persons authorized by operators; codes of conduct; technical standards and certification mechanisms; the appropriate level of protection offered by a third country, a territory or a certain processing sector in that third country, or by an international organization; standard data protection clauses; formats and procedures for the electronic exchange of information between operators, persons authorized by operators and supervisory authorities for mandatory corporate rules; mutual assistance; as well as the modalities for the electronic exchange of information between the supervisory authorities, as well as between the supervisory authorities and the committee.

(169) The Commission should adopt immediately applicable implementing acts where the available evidence shows that a third country, a territory or a certain processing sector in that third country, or an international organization does not ensure an adequate level of protection, as well as for imperative reasons of urgency.

(170) Since the objective of this regulation, namely ensuring an equivalent level of protection of natural persons and the free circulation of personal data throughout the Union, cannot be satisfactorily achieved by the member states, but, considering the scope or effects action, can be better achieved at the level of the Union, it can adopt measures in accordance with the principle of subsidiarity, as defined in Article 5 of the Treaty on European Union ("EU Treaty"). In accordance with the principle of proportionality, as defined in the respective article, this regulation does not go beyond what is necessary to achieve the mentioned objectives.

(171) Directive 95/46/EC should be repealed by this regulation. The processing in progress at the date of application of this regulation should be brought into compliance with this regulation within two years from the date of entry into force of this regulation. If the processing is based on consent under Directive 95/46/EC, it is not necessary for the data subject to give his consent again if the way in which the consent was given is in accordance with the conditions of this regulation , so that the operator is allowed to continue such processing after the date of application of this regulation. The adopted decisions of the Commission and the authorizations of the supervisory authorities issued on the basis of Directive 95/46/EC remain in force until they are modified, replaced or repealed.

(172) The European Data Protection Authority was consulted in accordance with Article 28 paragraph (2) of Regulation (EC) no. 45/2001 and issued an opinion on March 7, 2012 (1).
(1) OJ C 192, 30.6.2012, p. 7.
(173) This regulation should apply to all aspects related to the protection of rights and fundamental freedoms related to the processing of personal data, which are not subject to specific obligations with the same objective as that established in Directive 2002/58/EC of the European Parliament and of the Council (2), including the obligations regarding the operator and the rights of natural persons. In order to clarify the relationship between this regulation and Directive 2002/58/EC, that directive should be amended accordingly. After the adoption of this Regulation, Directive 2002/58/EC should be revised in particular to ensure consistency with this Regulation,

(2) Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 on the processing of personal data and the protection of confidentiality in the public communications sector (Directive on confidentiality and electronic communications) (OJ L 201, 31.7.2002, p. 37 ).
ACCEPT THESE REGULATIONS:

-****-

CHAPTER I: General provisions
Art. 1: Object and objectives
(1) This regulation establishes the rules regarding the protection of natural persons with regard to the processing of personal data, as well as the rules regarding the free movement of personal data.
(2) This regulation ensures the protection of the fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data.
(3) The free movement of personal data within the Union cannot be restricted or prohibited for reasons related to the protection of natural persons with regard to the processing of personal data.
Art. 2: Material scope
(1) This regulation applies to the processing of personal data, carried out in whole or in part by automated means, as well as to the processing by means other than automated of personal data that are part of a data recording system or that are intended to be part of a data recording system.
(2) This regulation does not apply to the processing of personal data:
a) within an activity that does not fall under Union law;
b) by the member states when carrying out activities that fall under Chapter 2 of Title V of the EU Treaty;
c) by a natural person in an exclusively personal or domestic activity;
d) by the competent authorities for the purpose of prevention, investigation, detection or criminal prosecution of crimes, or the execution of criminal sanctions, including protection against threats to public safety and their prevention.
(3) For the processing of personal data by the institutions, bodies, offices and agencies of the Union, Regulation (EC) no. 45/2001. Regulation (EC) no. 45/2001 and other legal acts of the Union applicable to such processing of personal data are adapted to the principles and rules of this regulation in accordance with article 98.
(4) This regulation does not affect the application of Directive 2000/31/EC, in particular the rules regarding the liability of intermediary service providers, provided for in articles 12-15 of the said directive.
Art. 3: Territorial scope
(1) This regulation applies to the processing of personal data within the activities of an office of an operator or a person authorized by the operator on the territory of the Union, regardless of whether the processing takes place on the territory of the Union or not.
(2) This regulation applies to the processing of personal data of data subjects located in the Union by an operator or a person authorized by the operator who is not established in the Union, when the processing activities are related to:
a) offering goods or services to such persons concerned in the Union, regardless of whether or not a payment is requested by the concerned person; or
b) monitoring their behavior if it manifests itself within the Union.
(3) This regulation applies to the processing of personal data by an operator that is not established in the Union, but in a place where domestic law is applied based on public international law.
Art. 4: Definitions
For the purposes of this regulation:
1."personal data" means any information regarding an identified or identifiable natural person ("data subject"); an identifiable natural person is a person who can be

identified, directly or indirectly, in particular by reference to an identification element, such as a name, an identification number, location data, an online identifier, or to one or more specific elements, its own physical, physiological identity , genetic, psychological, economic, cultural or social; 2. "processing" means any operation or set of operations performed on personal data or sets of personal data, with or without the use of automated means, such as collection, recording, organization, structuring, storage, adaptation or modification, extraction, consultation, use, disclosure by transmission, dissemination or making available in any other way, alignment or combination, restriction, deletion or destruction; 3. "restriction of processing" means the marking of stored personal data with the aim of limiting their future processing;

4. "profiling" means any form of automatic processing of personal data that consists in the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects of performance on the job of work, economic situation, health, personal preferences, interests, reliability, behavior, the place where the respective natural person is or his movements;

5. "pseudonymization" means the processing of personal data in such a way that it can no longer be attributed to a specific person concerned without using additional information, provided that this additional information is stored separately and is subject to certain technical and organizational measures to ensure that the respective personal data are not assigned to an identified or identifiable natural person;

6. "data record system" means any structured set of personal data accessible according to specific criteria, be they centralized, decentralized or distributed according to functional or geographical criteria;
7. "operator" means the natural or legal person, public authority, agency or other body that, alone or together with others, establishes the purposes and means of personal data processing; when the purposes and means of processing are established by Union law or domestic law, the operator or the specific criteria for its designation may be provided for in Union law or domestic law;

8. "person authorized by the operator" means the natural or legal person, public authority, agency or other body that processes personal data on behalf of the operator; 9. "recipient" means the natural or legal person, public authority, agency or other body to whom (to whom) the personal data is disclosed, regardless of whether it is a third party or not. However, public authorities to whom personal data may be communicated within the framework of a certain investigation in accordance with Union law or internal law are not considered recipients; the processing of this data by the respective public authorities complies with the applicable data protection rules, in accordance with the purposes of the processing;

10. "third party" means a natural or legal person, public authority, agency or body other than the data subject, the operator, the person authorized by the operator and the persons who, under the direct authority of the operator or the person authorized by the operator, are authorized to process personal data;

11. "consent" of the data subject means any manifestation of the data subject's free, specific, informed and unambiguous will by which he accepts, through a statement or an unequivocal action, that the personal data concerning him to be processed; 12. "personal data security breach" means a security breach that leads, accidentally or illegally, to the destruction, loss, modification, or unauthorized disclosure of personal data transmitted, stored or processed in another way, or to unauthorized access to them;

13. "genetic data" means the personal data relating to the inherited or acquired genetic characteristics of a natural person, which provide unique information regarding the physiology or health of that person and which results in particular from an analysis of a sample of biological material collected by to the person in question;

14. "biometric data" means personal data resulting from specific processing techniques related to the physical, physiological or behavioral characteristics of a natural person that allow or confirm the unique identification of that person, such as facial images or data dactyloscopic;

15. "health data" means personal data related to the physical or mental health of a natural person, including the provision of medical assistance services, which discloses information about his or her state of health;
16. "headquarters" means:

(a) in the case of an operator with headquarters in at least two member states, the place where its central administration is located in the Union, unless the decisions regarding the purposes and means of personal data processing are taken in a another seat of the operator in the Union, seat that has the competence to order the implementation of these decisions, in which case the seat that took the respective decisions is considered to be the main seat;

(b) in the case of a person authorized by the operator with headquarters in at least two member states, the place where its central administration is located in the Union, or, if the person authorized by the operator does not have a central administration in the Union, the headquarters from the Union of the person authorized by the operator in which the main processing activities take place, in the context of the activities of an office of the person authorized by the operator, to the extent that it is subject to specific obligations under this regulation;

17. "representative" means a natural or legal person established in the Union, designated in writing by the operator or the person authorized by the operator pursuant to Article 27, who represents the operator or the authorized person with regard to their respective obligations under this regulations;

18. "enterprise" means a natural or legal person that carries out an economic activity, regardless of its legal form, including partnerships or associations that regularly carry out an economic activity;
19. "group of enterprises" means an enterprise that exercises control and the enterprises controlled by it;

20. "mandatory corporate rules" means the personal data protection policies that must be respected by an operator or a person authorized by the operator established in the territory of a member state, with regard to transfers or sets of data transfers with personal character to an operator or a person authorized by the operator in one or more third countries within a group of companies or a group of companies involved in a common economic activity;

21. "supervisory authority" means an independent public authority established by a member state pursuant to Article 51;
22. "targeted supervisory authority" means a supervisory authority that is targeted by the processing of personal data because:

(a) the operator or the person authorized by the operator is established on the territory of the member state of the respective supervisory authority;
(b) the data subjects residing in the member state where the respective supervisory authority is located are significantly affected or are likely to be significantly affected by the processing; or

(c) a complaint has been submitted to the respective supervisory authority;
23. "cross-border processing" means:
(a) either the processing of personal data that takes place in the context of the activities of the offices in several member states of an operator or a person authorized by the operator on the territory of the Union, if the operator or the person authorized by the operator has offices in at least two member states ; or
(b) either the processing of personal data that takes place in the context of the activities of a single office of an operator or a person authorized by the operator in the territory of the Union, but which affects in

significantly or is likely to significantly affect data subjects from at least two member states;
24. "relevant and reasoned objection" means an objection to a draft decision in order to establish whether there is a violation of this regulation or whether the measures envisaged with regard to the operator or the person authorized by the operator comply with this regulation, which clearly demonstrates clearly the importance of the risks presented by the draft decision regarding the fundamental rights and freedoms of the persons concerned and, as the case may be, the free circulation of personal data within the Union;

25. «information society services» means a service as defined in article 1

paragraph (1) letter (b) of Directive 2015/1535/EC of the European Parliament and of the Council (1);

(1) Directive (EU) 2015/1535 of the European Parliament and of the Council of 9 September 2015 regarding the procedure for providing information in the field of technical regulations and rules regarding information society services (OJ L 241, 17.9.2015, p. 1 ).

(as of May 23, 2018, Art. 4, point 25. of Chapter I rectified by point 2. of the Correction of May 23, 2018)

26. "international organization" means an organization and its subordinate bodies regulated by public international law or any other body that is established by an agreement concluded between two or more countries or on the basis of such an agreement.
CHAPTER II: Principles

Art. 5: Principles related to the processing of personal data
(1) Personal data are:
a) processed legally, fairly and transparently to the data subject ("legality, fairness and transparency");
b) collected for specific, explicit and legitimate purposes and are not subsequently processed in a manner incompatible with these purposes; subsequent processing for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes is not considered incompatible with the initial purposes, in accordance with Article 89 paragraph (1) ("limitations related to the purpose");
c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed ("data minimization");
d) accurate and, if necessary, to be updated; all necessary measures must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are deleted or rectified without delay ("accuracy");
e) kept in a form that allows the identification of the persons concerned for a period that does not exceed the period necessary to fulfill the purposes for which the data are processed; personal data may be stored for longer periods to the extent that they will be processed exclusively for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes, in accordance with Article 89 paragraph (1), subject to the implementation of the appropriate technical and organizational measures provided for in this regulation in order to guarantee the rights and freedoms of the data subject ("storage-related limitations");
f) processed in a way that ensures adequate security of personal data, including protection against unauthorized or illegal processing and against accidental loss, destruction or damage, by taking appropriate technical or organizational measures ("integrity and confidentiality") .
(2) The operator is responsible for compliance with paragraph (1) and can demonstrate this compliance ("responsibility").
Art. 6: Legality of processing
(1) Processing is legal only if and to the extent that at least one of the following conditions applies:
a) the subject has given his consent for the processing of his personal data for one or more specific purposes;
b) the processing is necessary for the execution of a contract to which the data subject is a party or to take steps at the request of the data subject before concluding a contract;
c) the processing is necessary in order to fulfill a legal obligation incumbent on the operator;

d) processing is necessary to protect the vital interests of the data subject or another natural person;
e) the processing is necessary for the fulfillment of a task that serves a public interest or that results from the exercise of the public authority with which the operator is vested;

f) the processing is necessary for the purposes of the legitimate interests pursued by the operator or a third party, unless the interests or fundamental rights and freedoms of the data subject prevail, which require the protection of personal data, especially when the data subject is a child.

Letter (f) of the first paragraph does not apply in the case of processing carried out by public authorities in the fulfillment of their duties.
(2) Member States may maintain or introduce more specific provisions to adapt the application of the rules of this regulation regarding processing in order to comply with paragraph (1) letters (c) and (e) by defining more precise specific requirements regarding processing and other measures to ensure legal and fair processing, including for other specific processing situations, as provided in chapter IX.

(3) The basis for the processing referred to in paragraph (1) letters (c) and (e) must be provided in: a) Union law; or
b) the domestic law that applies to the operator.
The purpose of the processing is established on the basis of the respective legal basis or, as regards the processing referred to in paragraph (1) letter (e), it is necessary for the performance of a task carried out in the public interest or in the exercise of a public function assigned to the operator. The respective legal basis may contain specific provisions regarding the adaptation of the application of the rules of this regulation, among others: the general conditions that regulate the legality of processing by the operator; the types of data that are the subject of processing; the persons concerned; the entities to which the data may be disclosed and the purpose for which the said personal data may be disclosed; purpose limitations; storage periods; and processing operations and procedures, including measures to ensure legal and fair processing such as those for other specific processing situations as provided in Chapter IX. Union law or domestic law pursues an objective of public interest and is proportionate to the legitimate objective pursued.

(4) If the processing for a purpose other than the one for which the personal data were collected is not based on the consent of the data subject or on Union law or internal law, which constitutes a necessary and proportionate measure in a democratic society for to protect the objectives referred to in Article 23 paragraph (1), the operator, in order to determine whether the processing for another purpose is compatible with the purpose for which the personal data were initially collected, takes into account, among others:

a) any connection between the purposes for which the personal data were collected and the purposes of the subsequent processing envisaged;
b) the context in which the personal data were collected, especially regarding the relationship between the data subjects and the operator;

c) the nature of personal data, especially in the case of the processing of special categories of personal data, in accordance with Article 9, or in the event that personal data related to criminal convictions and offenses are processed, in accordance with Article 10;
d) the possible consequences on the data subjects of the expected subsequent processing;

e) the existence of adequate guarantees, which may include encryption or pseudonymization.
Art. 7: Conditions regarding consent
(1) If the processing is based on consent, the operator must be able to demonstrate that the data subject has given his consent for the processing of his personal data.
(2) If the consent of the person concerned is given in the context of a written statement that also refers to other aspects, the request for consent must be presented in a form that clearly differentiates it from the other aspects, in a form comprehensible and easily accessible, using a

clear and simple language. Any part of that statement that constitutes a violation of this regulation is not mandatory.
(3) The concerned person has the right to withdraw his consent at any time. The withdrawal of the consent does not affect the legality of the processing carried out on the basis of the consent before its withdrawal. Before giving consent, the data subject is informed about this. Withdrawing consent is as simple as giving it.

(4) When evaluating whether the consent is given freely, account is taken as much as possible of the fact that, among other things, the execution of a contract, including the provision of a service, is conditioned or not by the consent regarding the processing of personal data personal that is not necessary for the execution of this contract.

Art. 8: Applicable conditions regarding children's consent in relation to information society services

(1) If Article 6 paragraph (1) letter (a) is applied, regarding the provision of information society services directly to a child, the processing of a child's personal data is legal if the child has the at least 16 years old. If the child is under the age of 16, the respective processing is legal only if and to the extent that the respective consent is granted or authorized by the holder of parental responsibility over the child.

Member States may provide by law a lower age for these purposes, provided that the lower age is not less than 13 years.
(2) The operator makes all reasonable efforts to verify in such cases that the holder of parental responsibility has granted or authorized consent, taking into account the available technologies.

(3) Paragraph (1) does not affect the general contract law applicable in the member states, such as the rules regarding the validity, conclusion or effects of a contract in relation to a child.
Art. 9: Processing of special categories of personal data
(1) It is forbidden to process personal data revealing racial or ethnic origin, political opinions, religious confession or philosophical beliefs or trade union membership and the processing of genetic data, biometric data for the unique identification of a natural person, data regarding health or data regarding the sexual life or sexual orientation of a natural person.

(2) Paragraph (1) does not apply in the following situations:
a) the person concerned has given his explicit consent for the processing of this personal data for one or more specific purposes, unless Union law or internal law provides that the prohibition provided for in paragraph (1) cannot be lifted by consent of the concerned person;
b) the processing is necessary for the purpose of fulfilling the obligations and exercising specific rights of the operator or the person concerned in the field of employment and social security and social protection, to the extent that this is authorized by Union law or internal law or a collective labor agreement concluded under domestic law that provides adequate guarantees for the fundamental rights and interests of the person concerned;
c) the processing is necessary to protect the vital interests of the data subject or another natural person, when the data subject is physically or legally unable to give consent;
d) the processing is carried out within their legitimate activities and with adequate guarantees by a foundation, an association or any other non-profit organization with political, philosophical, religious or trade union specifics, provided that its processing refers only to its members or to the former members of the respective body or to persons with whom it has permanent contacts in connection with its purposes and that personal data are not communicated to third parties without the consent of the persons concerned; e) the processing refers to personal data that are openly made public by the concerned person;
f) the processing is necessary for establishing, exercising or defending a right in court or whenever the courts act in the exercise of their judicial function;

g) the processing is necessary for reasons of major public interest, based on Union law or internal law, which is proportional to the objective pursued, respects the essence of the right to data protection and provides appropriate and specific measures to protect the fundamental rights and interests of the data subject;

h) the processing is necessary for purposes related to preventive or occupational medicine, the assessment of the employee's work capacity, the establishment of a medical diagnosis, the provision of medical or social assistance or medical treatment or the management of health systems and services or of social assistance, based on Union law or internal law or based on a contract concluded with a medical staff and subject to compliance with the conditions and guarantees provided for in paragraph (3);

i) processing is necessary for reasons of public interest in the field of public health, such as protection against serious cross-border threats to health or ensuring high quality standards and the safety of medical care and medicines or medical devices, based on Union law or of domestic law, which provides for appropriate and specific measures to protect the rights and freedoms of the person concerned, especially professional secrecy; or j) the processing is necessary for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes, in accordance with Article 89 paragraph (1), based on Union law or internal law, which is proportional to the objective followed, respects the essence of the right to data protection and provides appropriate and specific measures to protect the fundamental rights and interests of the data subject.

(3) The personal data referred to in paragraph (1) may be processed for the purposes referred to in paragraph (2) letter (h) if the respective data are processed by a professional subject to the obligation to maintain professional secrecy or under the responsibility it, under Union law or domestic law or under the rules established by competent national bodies or by another person also subject to an obligation of confidentiality under Union law or domestic law or under the rules established by competent national bodies.

(4) Member States may maintain or introduce additional conditions, including restrictions, regarding the processing of genetic data, biometric data or health data.
Art. 10: Processing of personal data related to criminal convictions and crimes

The processing of personal data relating to criminal convictions and offenses or to related security measures pursuant to Article 6 paragraph (1) is carried out only under the control of a state authority or when the processing is authorized by Union law or by national law that provides adequate guarantees for the rights and freedoms of the persons concerned. Any comprehensive register of criminal convictions is kept only under the control of a state authority.

Art. 11: Processing that does not require identification
(1) If the purposes for which an operator processes personal data do not require or no longer require the identification of a data subject by the operator, the operator does not have the obligation to keep, obtain or process additional information to identify the data subject in the sole purpose of complying with this regulation.
(2) If, in the cases mentioned in paragraph (1) of this article, the operator can demonstrate that it is not able to identify the person concerned, the operator informs the person concerned accordingly, if possible. In such cases, articles 15-20 do not apply, unless the data subject, in order to exercise his rights under the respective articles, provides additional information that allows his identification.
CHAPTER III: Rights of the data subject
Section 1: Transparency and modalities
Art. 12: Transparency of information, communications and methods of exercising the rights of the data subject
(1) The operator takes appropriate measures to provide the data subject with any information referred to in articles 13 and 14 and any communications based on articles 15-22 and 34 related to processing, in a concise, transparent, understandable and easily accessible form, using a clear and simple language, in particular

for any information specifically addressed to a child. The information is provided in writing or by other means, including, when appropriate, in electronic format. At the request of the data subject, the information can be provided verbally, provided that the identity of the data subject is proven by other means.

(2) The operator facilitates the exercise of the rights of the data subject pursuant to articles 15-22. In the cases referred to in article 11 paragraph (2), the operator does not refuse to comply with the request of the data subject to exercise his rights in accordance with articles 15-22, unless the operator demonstrates that he is unable to identify the data subject .

(3) The operator provides the data subject with information on the actions taken following a request based on articles 15-22, without undue delay and in any case within one month at the latest from receiving the request. This period can be extended by two months when necessary, taking into account the complexity and number of applications. The operator informs the person concerned about any such extension, within one month of receiving the request, presenting the reasons for the delay. If the data subject submits a request in electronic format, the information is provided in electronic format where possible, unless the data subject requests another format. (4) If it does not take measures regarding the request of the person concerned, the operator informs the person concerned, without delay and within a maximum of one month from receiving the request, about the reasons why it does not take measures and about the possibility of filing a complaint to a supervisory authority and to file a judicial appeal.

(5) The information provided under Articles 13 and 14 and any communication and any measures taken under Articles 15-22 and 34 are provided free of charge. If the requests from a data subject are clearly unfounded or excessive, in particular due to their repetitive nature, the operator may:

a) either to charge a reasonable fee taking into account the administrative costs for providing the information or communication or for taking the requested measures;

b) or refuse to comply with the request.
In these cases, the operator has the burden of proving the manifestly unfounded or excessive character of the request.
(6) Without prejudice to article 11, if it has reasonable doubts about the identity of the natural person submitting the request mentioned in articles 15-21, the operator may request the provision of additional information necessary to confirm the identity of the person concerned. (7) The information to be provided to the data subjects pursuant to articles 13 and 14 may be provided in combination with standardized icons to provide in an easily visible, intelligible and clearly legible way a significant overview of the intended processing. If the icons are presented in electronic format, they must be able to be read automatically. (8) The commission is empowered to adopt delegated acts in accordance with article 92 in order to determine the information to be presented by the pictograms and the procedures for providing standardized pictograms.
Section 2: Information and access to personal data
Art. 13: Information to be provided if personal data is collected from the data subject
(1) If personal data relating to a data subject are collected from him, the operator, at the time of obtaining this personal data, provides the data subject with all the following information:
a) the identity and contact details of the operator and, as the case may be, of his representative;
b) the contact details of the data protection officer, as the case may be;
c) the purposes for which the personal data are processed, as well as the legal basis of the processing; d) if the processing is done pursuant to Article 6 paragraph (1) letter (f), the legitimate interests pursued by the operator or a third party;
e) recipients or categories of recipients of personal data;
f) if applicable, the intention of the operator to transfer personal data to a third country or an international organization and the existence or absence of a Commission decision regarding the appropriateness

or, in the case of transfers referred to in Article 46 or 47 or in the second subparagraph of Article 49(1), a reference to the appropriate or appropriate guarantees and to the means of obtaining a copy thereof, if they have been placed at disposition.
(2) In addition to the information mentioned in paragraph (1), when the personal data is obtained, the operator provides the data subject with the following additional information necessary to ensure a fair and transparent processing:

a) the period for which the personal data will be stored or, if this is not possible, the criteria used to establish this period;
b) the existence of the right to request the operator, regarding the personal data relating to the data subject, access to them, their rectification or deletion or the restriction of the processing or the right to oppose the processing, as well as the right to data portability; c) when the processing is based on Article 6 paragraph (1) letter (a) or on Article 9 paragraph (2) letter (a), the existence of the right to withdraw consent at any time, without affecting the legality of the processing carried out on the basis of consent before its withdrawal;

d) the right to file a complaint before a supervisory authority;
e) if the provision of personal data represents a legal or contractual obligation or an obligation necessary for the conclusion of a contract, as well as if the data subject is obliged to provide this personal data and what are the possible consequences of not complying with this obligation;
f) the existence of an automated decision-making process including the creation of profiles, referred to in Article 22 paragraphs (1) and (4), as well as, at least in the respective cases, pertinent information regarding the logic used and regarding the importance and expected consequences of such processing for the person concerned.
(3) If the operator intends to subsequently process the personal data for a purpose other than the one for which they were collected, the operator shall provide the data subject, before this subsequent processing, with information regarding the respective secondary purpose and any additional information relevant, in accordance with paragraph (2).
(4) Paragraphs (1), (2) and (3) do not apply if and to the extent that the concerned person already possesses the respective information.
Art. 14: Information to be provided if the personal data were not obtained from the data subject

(1) If the personal data were not obtained from the data subject, the operator provides the data subject with the following information:
a) the identity and contact details of the operator and, as the case may be, of his representative;
b) the contact details of the data protection officer, as the case may be;

c) the purposes for which the personal data are processed, as well as the legal basis of the processing; d) categories of personal data concerned;
e) recipients or categories of recipients of personal data, as the case may be;
f) if applicable, the intention of the operator to transfer personal data to a recipient from a third country or an international organization and the existence or absence of a decision by the Commission regarding the appropriateness or, in the case of the transfers referred to in article 46 or 47 or in Article 49 paragraph (1) second paragraph, a reference to adequate or appropriate guarantees and to the means of obtaining a copy of them, if they have been made available.

(2) In addition to the information mentioned in paragraph (1), the operator provides the data subject with the following information necessary to ensure a fair and transparent processing regarding the data subject:
a) the period for which the personal data will be stored or, if this is not possible, the criteria used to establish this period;

b) if the processing is done pursuant to Article 6 paragraph (1) letter (f), the legitimate interests pursued by the operator or a third party;

c) the existence of the right to request the operator, regarding the personal data relating to the data subject, access to them, their rectification or deletion or the restriction of the processing and the right to oppose the processing, as well as the right to data portability; d) when the processing is based on Article 6 paragraph (1) letter (a) or on Article 9 paragraph (2) letter (a), the existence of the right to withdraw consent at any time, without affecting the legality of the processing carried out on the basis of consent before its withdrawal;

e) the right to file a complaint before a supervisory authority;
f) the source of the personal data and, if applicable, if they come from publicly available sources;
g) the existence of an automated decision-making process including the creation of profiles, referred to in Article 22 paragraphs (1) and (4), as well as, at least in the respective cases, relevant information regarding the logic used and regarding the importance and expected consequences of such processing for the person concerned.
(3) The operator provides the information mentioned in paragraphs (1) and (2):
a) within a reasonable time after obtaining the personal data, but no longer than one month, taking into account the specific circumstances in which the personal data are processed; b) if the personal data are to be used for communication with the data subject, at the latest at the time of the first communication to the respective data subject; or
c) if it is intended to disclose personal data to another recipient, at the latest on the date on which they are disclosed for the first time.
(4) If the operator intends to subsequently process the personal data for a purpose other than the one for which they were obtained, the operator shall provide the data subject, before this further processing, with information regarding the respective secondary purpose and any additional information relevant, in accordance with paragraph (2).
(5) Paragraphs (1)-(4) do not apply if and to the extent that:
a) the concerned person already owns the information;
b) the provision of this information proves to be impossible or would involve disproportionate efforts, especially in the case of processing for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes, subject to the conditions and guarantees provided for in the article 89 paragraph (1), or to the extent that the obligation mentioned in paragraph (1) of this article is likely to make impossible or seriously affect the achievement of the objectives of the respective processing In such cases, the operator takes appropriate measures to protect the rights, the freedoms and legitimate interests of the data subject, including making information available to the public;
c) obtaining or disclosing data is expressly provided for by Union law or internal law under which the operator falls and which provides for appropriate measures to protect the legitimate interests of the data subject; or
d) if the personal data must remain confidential on the basis of a statutory obligation of professional secrecy regulated by Union law or internal law, including a legal obligation to maintain secrecy.
Art. 15: The data subject's right of access
(1) The data subject has the right to obtain from the operator a confirmation as to whether or not personal data concerning him or her is being processed and, if so, access to the respective data and the following information:
a) the purposes of the processing;
b) the categories of personal data concerned;
c) recipients or categories of recipients to whom personal data have been or will be disclosed, especially recipients from third countries or international organizations;
d) where possible, the period for which personal data is expected to be stored or, if this is not possible, the criteria used to establish this period; e) the existence of the right to request the operator to rectify or delete personal data or to restrict the processing of personal data relating to the person concerned or the right to oppose the processing;

f) the right to file a complaint before a supervisory authority;
g) if the personal data are not collected from the data subject, any available information regarding their source;
h) the existence of an automated decision-making process including the creation of profiles, referred to in Article 22 paragraphs (1) and (4), as well as, at least in the respective cases, pertinent information regarding the logic used and regarding the importance and expected consequences of such processing for the person concerned.
(2) If personal data are transferred to a third country or an international organization, the data subject has the right to be informed about the appropriate guarantees under Article 46 regarding the transfer.
(3) The operator provides a copy of the personal data that are the subject of processing. For any other copies requested by the data subject, the operator may charge a reasonable fee, based on administrative costs. If the data subject submits the application in electronic format and unless the data subject requests another format, the information is provided in a currently used electronic format.
(4) The right to obtain a copy referred to in paragraph (3) does not affect the rights and freedoms of others.
Section 3: Rectification and Deletion
Art. 16: The right to rectification
The data subject has the right to obtain from the operator, without undue delay, the rectification of inaccurate personal data concerning him. Taking into account the purposes for which the data were processed, the data subject has the right to obtain the completion of incomplete personal data, including by providing an additional statement.
Art. 17: Right to data deletion ("right to be forgotten")
(1) The data subject has the right to obtain from the operator the deletion of the personal data concerning him, without undue delay, and the operator has the obligation to delete the personal data without undue delay if one of the following reasons applies : a) personal data are no longer necessary to fulfill the purposes for which they were collected or processed;
b) the data subject withdraws the consent on the basis of which the processing takes place, in accordance with Article 6 paragraph (1) letter (a) or Article 9 paragraph (2) letter (a), and there is no other legal basis for the processing;
c) the data subject objects to the processing pursuant to Article 21 paragraph (1) and there are no legitimate reasons to prevail regarding the processing or the data subject objects to the processing pursuant to Article 21 paragraph (2);
d) personal data were processed illegally;
e) personal data must be deleted in order to comply with a legal obligation that rests with the operator based on Union law or the internal law under which the operator is; f) personal data were collected in connection with the provision of information society services referred to in Article 8 paragraph (1).
(2) If the operator has made personal data public and is obliged, pursuant to paragraph (1), to delete it, the operator, taking into account the available technology and the cost of implementation, takes reasonable measures, including technical measures, to inform the operators who process the personal data that the data subject has requested the deletion by these operators of any links to the respective data or of any copies or reproductions of these personal data.

(3) Paragraphs (1) and (2) do not apply to the extent that the processing is necessary:

a) for the exercise of the right to free expression and information;

b) for compliance with a legal obligation that provides for processing based on Union law or internal law that applies to the operator or for the fulfillment of a task executed in the interest

publicly or in the exercise of an official authority with which the operator is vested;

c) for reasons of public interest in the field of public health, in accordance with Article 9 paragraph (2)

letters (h) and (i) and with Article 9 paragraph (3);

d) for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes, in accordance with Article 89 paragraph (1), to the extent that the right mentioned in paragraph (1) is likely to make it impossible or to seriously affect the achievement of the processing objectives

respectively; or

e) for ascertaining, exercising or defending a right in court. (as of May 23, 2018, Art. 17, paragraph (3) of Chapter III, Section 3, amended by point 3 of the Amendment of May 23

2018)
Art. 18: The right to restrict processing
(1) The data subject has the right to obtain from the operator the restriction of processing if one of the following cases applies:
a) the concerned person contests the accuracy of the data, for a period that allows the operator to verify the accuracy of the data;
b) the processing is illegal, and the data subject opposes the deletion of personal data, requesting instead the restriction of their use;
c) the operator no longer needs the personal data for the purpose of processing, but the data subject requests them for ascertaining, exercising or defending a right in court; or
d) the data subject objected to the processing in accordance with Article 21 paragraph (1), for the period of time in which it is checked whether the legitimate rights of the operator prevail over those of the data subject.
(2) If processing has been restricted pursuant to paragraph (1), such personal data may, with the exception of storage, be processed only with the consent of the data subject or for establishing, exercising or defending a right in court or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or a member state.
(3) A data subject who has obtained processing restriction pursuant to paragraph (1) is informed by the operator before lifting the processing restriction.
Art. 19: Notification obligation regarding the rectification or deletion of personal data or restriction of processing
The operator communicates to each recipient to whom personal data has been disclosed any rectification or deletion of personal data or restriction of processing carried out in accordance with article 16, article 17 paragraph (1) and article 18, unless this this proves impossible or requires disproportionate efforts. The operator informs the data subject about the respective recipients if the data subject requests this.
Art. 20: The right to data portability
(1) The data subject has the right to receive the personal data concerning him and which he has provided to the operator in a structured, commonly used and machine-readable format and he has the right to transmit this data to another operator, without obstacles from the operator to whom the personal data was provided, in the event that:
a) the processing is based on consent pursuant to Article 6 paragraph (1) letter (a) or Article 9 paragraph (2) letter (a) or on a contract pursuant to Article 6 paragraph (1) letter (b); and b) the processing is carried out by automatic means.
(2) In exercising the right to data portability pursuant to paragraph (1), the data subject has the right to have personal data transmitted directly from one operator to another where this is technically feasible.
(3) The exercise of the right mentioned in paragraph (1) of this article does not affect article 17. This right does not apply to the processing necessary to fulfill a task performed in the public interest or within the exercise of an official authority with which the operator is vested.
(4) The right mentioned in paragraph (1) does not affect the rights and freedoms of others.
Section 4: The right to opposition and the automated individual decision-making process
Art. 21: The right to opposition

(1) At any time, the data subject has the right to object, for reasons related to the particular situation in which he is, to the processing pursuant to Article 6 paragraph (1) letter (e) or (f), of personal data

personnel that concern it, including the creation of profiles based on those provisions. The operator no longer processes personal data, unless the operator demonstrates that it has legitimate and compelling reasons that justify the processing and that prevail over the interests, rights and freedoms of the data subject or that the purpose is to establish, exercise or defend a right in

instance.

(to date

May 23, 2018 Art. 21, para. (1) from chapter III, section 4 rectified by point 4. of the Rectification of May 23, 2018)

(2) When the processing of personal data is aimed at direct marketing, the data subject has the right to object at any time to the processing for this purpose of the personal data concerning him, including the creation of profiles, to the extent that it is related to the respective direct marketing.

(3) If the data subject objects to the processing for the purpose of direct marketing, the personal data are no longer processed for this purpose.
(4) At the latest at the time of the first communication with the data subject, the right mentioned in paragraphs (1) and (2) is explicitly brought to the attention of the data subject and is presented clearly and separately from any other information.

(5) In the context of the use of information society services and despite Directive 2002/58/EC, the data subject can exercise his right to object through automatic means that use technical specifications.
(6) If personal data are processed for scientific or historical research purposes or for statistical purposes in accordance with Article 89 paragraph (1), the data subject, for reasons related to his particular situation, has the right to opposes the processing of personal data concerning her, unless the processing is necessary for the performance of a task for reasons of public interest.

Art. 22: The automated individual decision-making process, including the creation of profiles
(1) The data subject has the right not to be subject to a decision based exclusively on automatic processing, including the creation of profiles, which produces legal effects that concern the data subject or similarly affects him to a significant extent.

(2) Paragraph (1) does not apply if the decision:
a) is necessary for the conclusion or execution of a contract between the data subject and a data operator;
b) is authorized by Union law or internal law that applies to the operator and that also provides for appropriate measures to protect the rights, freedoms and legitimate interests of the person concerned; or
c) is based on the explicit consent of the person concerned.
(3) In the cases referred to in paragraph (2) letters (a) and (c), the data operator implements appropriate measures to protect the rights, freedoms and legitimate interests of the data subject, at least his right to obtain human intervention from the part of the operator, to express his point of view and to appeal the decision.
(4) The decisions referred to in paragraph (2) are not based on the special categories of personal data referred to in Article 9 paragraph (1), unless Article 9 paragraph (2) letter (a) or (g) applies ) and in which appropriate measures have been instituted to protect the rights, freedoms and legitimate interests of the person concerned.
Section 5: Restrictions
Art. 23: Restrictions
(1) Union law or internal law that applies to the data operator or the person authorized by the operator may restrict through a legislative measure the scope of the obligations and rights provided for in articles 12-22 and 34, as well as in article 5 to the extent in which its provisions correspond to the rights and obligations provided for in articles 12-22, when such a

restriction respects the essence of fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society, to ensure:
a) national security;
b) defense;

c) public security;
d) the prevention, investigation, detection or criminal prosecution of crimes or the execution of criminal sanctions, including protection against threats to public security and their prevention; e) other important objectives of general public interest of the Union or of a member state, in particular an important economic or financial interest of the Union or of a member state, including in the monetary, budgetary and fiscal fields and in the field of public health and social security ;
f) protecting judicial independence and judicial procedures;
g) prevention, investigation, detection and prosecution of ethical violations in the case of regulated professions;
h) the function of monitoring, inspection or regulation related, even occasionally, to the exercise of official authority in the cases mentioned in letters (a)-(e) and (g);
i) protection of the person concerned or the rights and freedoms of others; (j) enforcement of civil law claims.
(2) In particular, any legislative measure referred to in paragraph (1) contains specific provisions at least, if applicable, regarding:
a) the purposes of processing or categories of processing;
b) categories of personal data;
c) the scope of the introduced restrictions;
d) guarantees to prevent abuses or illegal access or transfer;
e) mention of the operator or categories of operators;
f) storage periods and applicable guarantees considering the nature, scope and purposes of processing or processing categories;
g) the risks for the rights and freedoms of the persons concerned; and
h) the right of the persons concerned to be informed about the restriction, unless this may affect the purpose of the restriction.
CHAPTER IV: The operator and the person authorized by the operator
Section 1: General obligations
Art. 24: Liability of the operator
(1) Taking into account the nature, scope, context and purposes of the processing, as well as the risks with different degrees of probability and severity for the rights and freedoms of natural persons, the operator implements appropriate technical and organizational measures to guarantee and be in order to demonstrate that the processing is carried out in accordance with this regulation. The respective measures are reviewed and updated if necessary.
(2) When they are proportional in relation to the processing operations, the measures mentioned in paragraph (1) include the implementation by the operator of appropriate data protection policies. (3) Adherence to approved codes of conduct, referred to in Article 40, or to an approved certification mechanism, referred to in Article 42, can be used as an element to demonstrate compliance with obligations by the operator.
Art. 25: Ensuring data protection starting from the moment of conception and by default (1) Considering the current state of technology, implementation costs, and the nature, scope, context and purposes of processing, as well as risks with different degrees of probability and gravity for the rights and freedoms of natural persons that the processing presents, the operator, both at the time of establishing the means of processing and at the time of the processing itself, implements appropriate technical and organizational measures, such as pseudonymization, which are intended to effectively implement data protection principles, such as data minimization, and integrate the necessary guarantees in the processing, to meet the requirements of this regulation and protect the rights of data subjects.

(2) The operator implements appropriate technical and organizational measures to ensure that, by default, only personal data that are necessary for each specific purpose of processing are processed. This obligation applies to the volume of data collected, the degree of their processing, their storage period and their accessibility. In particular, such measures ensure that, by default, personal data cannot be accessed, without the intervention of the person, by an unlimited number of people.

(3) A certification mechanism approved in accordance with article 42 can be used as an element to demonstrate the fulfillment of the requirements provided for in paragraphs (1) and (2) of this article.
Art. 26: Associated operators
(1) If two or more operators jointly establish the purposes and means of processing, they are associated operators. They establish in a transparent way the responsibilities of everyone in terms of fulfilling their obligations under this regulation, in particular in terms of the exercise of the rights of the data subjects and the obligations of everyone to provide the information provided for in articles 13 and 14, by means of a agreement between them, except in the case and to the extent that the responsibilities of the operators are established in the Union law or in the internal law that applies to them. The agreement may designate a point of contact for the persons concerned.

(2) The agreement referred to in paragraph (1) adequately reflects the respective roles and relationships of the associated operators vis-à-vis the persons concerned. The essence of this agreement is made known to the person concerned.
(3) Regardless of the clauses of the agreement referred to in paragraph (1), the data subject may exercise his rights under this regulation regarding and in relation to each of the operators.

Art. 27: Representatives of operators or persons authorized by operators who do not have their headquarters in the Union
(1) If article 3 paragraph (2) applies, the operator or the person authorized by the operator designates in writing a representative in the Union.

(2) The obligation stipulated in paragraph (1) of this article does not apply:
a) processing that has an occasional character, which does not include, on a large scale, the processing of special categories of data, as provided for in Article 9 paragraph (1), or the processing of personal data related to criminal convictions and offenses mentioned to article 10, and which is unlikely to generate a risk for the rights and freedoms of individuals, taking into account the nature, context, scope and purposes of the processing; or
b) an authority or a public body.
(3) The representative is based in one of the member states where the data subjects whose personal data are processed in connection with the provision of goods and services or whose behavior is monitored are located.
(4) The representative receives from the operator or the person authorized by the operator a mandate by which the supervisory authorities and the persons concerned, in particular, can address the representative, in addition to the operator or the person authorized by the operator or instead of them, regarding to all issues related to processing, in order to ensure compliance with this regulation.
(5) The appointment of a representative by the operator or the person authorized by the operator does not affect the legal actions that could be brought against the operator or the person authorized by the operator themselves.
Art. 28: The person authorized by the operator
(1) If the processing is to be carried out on behalf of an operator, the operator only uses authorized persons who offer sufficient guarantees for the implementation of appropriate technical and organizational measures, so that the processing complies with the requirements stipulated in this regulation and to ensure the protection of the rights of the concerned person.
(2) The person authorized by the operator does not recruit another person authorized by the operator without first receiving a written authorization, specific or general, from the operator. In the case of a general written authorization, the person authorized by the operator informs the operator about everything

expected changes regarding the addition or replacement of other persons authorized by the operator, thus giving the operator the opportunity to object to these changes.

(3) The processing by a person authorized by an operator is regulated by a contract or other legal act based on Union law or internal law which is binding for the person authorized by the operator in relation to the operator and which establishes the object and duration of the processing , the nature and purpose of the processing, the type of personal data and the categories of persons concerned and the obligations and rights of the operator. The respective contract or legal act provides in particular that the person authorized by the operator:

a) process personal data only on the basis of documented instructions from the operator, including with regard to transfers of personal data to a third country or an international organization, unless this obligation rests with the authorized person under the Union law or the internal law that applies to it; in this case, notify this legal obligation to the operator before processing, unless the respective law prohibits such notification for important reasons related to the public interest;

b) it is ensured that the persons authorized to process personal data have undertaken to respect confidentiality or have an appropriate statutory obligation of confidentiality;
c) adopt all the necessary measures in accordance with article 32;
d) comply with the conditions mentioned in paragraphs (2) and (4) regarding the recruitment of another person authorized by the operator;

e) taking into account the nature of the processing, offers assistance to the operator through appropriate technical and organizational measures, to the extent that this is possible, for the fulfillment of the operator's obligation to respond to requests regarding the exercise by the data subject of the rights provided for in Chapter III; f) help the operator to ensure compliance with the obligations stipulated in articles 32-36, taking into account the nature of the processing and the information available to the person authorized by the operator;

g) at the choice of the operator, delete or return to the operator all personal data after the termination of the provision of services related to processing and eliminate the existing copies, unless Union law or internal law requires the storage of personal data;
h) provides the operator with all the necessary information to demonstrate compliance with the obligations stipulated in this article, allows the audits, including inspections, carried out by the operator or other authorized auditor and contributes to them.

Regarding the first paragraph letter (h), the person authorized by the operator immediately informs the operator if, in his opinion, an instruction violates this regulation or other provisions of internal or Union law regarding data protection.
(4) In the event that a person authorized by an operator recruits another authorized person to carry out specific processing activities on behalf of the operator, the same data protection obligations stipulated in the contract or other legal act concluded between the operator and the person authorized by the operator , as provided in paragraph (3), fall to the second authorized person, by means of a contract or another legal act, based on Union law or internal law, in particular the provision of sufficient guarantees for the implementation of to appropriate technical and organizational measures, so that the processing meets the requirements of this regulation. In the event that this second authorized person does not comply with his obligations regarding data protection, the initial authorized person remains fully responsible to the operator regarding the fulfillment of the obligations of this second authorized person.

(5) The adherence of the person authorized by the operator to an approved code of conduct, referred to in Article 40, or to an approved certification mechanism, referred to in Article 42, can be used as an element to demonstrate the existence of sufficient guarantees referred to in paragraphs ( 1) and (4) of this article.

(6) Without prejudice to an individual contract concluded between the operator and the person authorized by the operator, the contract or other legal act referred to in paragraphs (3) and (4) of this article may be based, in whole or in part, on the standard contractual clauses mentioned to paragraphs (7) and (8) of this article, including when they are part of a certification granted to the operator or the person authorized by the operator pursuant to articles 42 and 43.

(7) The Commission may provide standard contractual clauses for the aspects mentioned in paragraphs (3) and (4) of this article and in accordance with the examination procedure mentioned in article 93 paragraph (2).
(8) A supervisory authority may adopt standard contractual clauses for the aspects mentioned in paragraphs (3) and (4) of this article and in accordance with the mechanism for ensuring consistency mentioned in article 63.

(9) The contract or other legal act mentioned in paragraphs (3) and (4) shall be formulated in writing, including in electronic format.
(10) Without prejudice to articles 82, 83 and 84, if a person authorized by the operator violates this regulation, by establishing the purposes and means of processing personal data, the person authorized by the operator is considered to be an operator regarding the respective processing.

Art. 29: Carrying out the processing activity under the authority of the operator or the person authorized by the operator
The person authorized by the operator and any person acting under the authority of the operator or the person authorized by the operator who has access to personal data do not process them except at the request of the operator, unless Union law or internal law obliges him to do so .

Art. 30: Records of processing activities
(1) Each operator and, as the case may be, his representative keep a record of the processing activities carried out under their responsibility. The record includes all the following information:
a) the name and contact details of the operator and, as the case may be, of the associated operator, of the operator's representative and of the data protection officer;
b) the purposes of the processing;
c) a description of the categories of persons concerned and the categories of personal data; d) the categories of recipients to whom personal data have been or will be disclosed, including recipients from third countries or international organizations;
e) if applicable, transfers of personal data to a third country or an international organization, including the identification of the respective third country or international organization and, in the case of the transfers referred to in Article 49 paragraph (1), second paragraph, the documentation that proves the existence of adequate guarantees;
f) where possible, the expected deadlines for the deletion of different categories of data; g) where possible, a general description of the technical and organizational security measures referred to in Article 32 paragraph (1).

(2) Each person authorized by the operator and, as the case may be, the representative of the person authorized by the operator keeps a record of all categories of processing activities carried out on behalf of

the operator, which include:

a) the name and contact details of the person or persons authorized by the operator and of each operator on whose behalf this person (these persons) acts, as well as, as the case may be, of

the representative of the operator or the representative of the person authorized by the operator, and of

the data protection officer;

b) the categories of processing activities carried out on behalf of each operator;

c) if applicable, transfers of personal data to a third country or an organization

international, including the identification of the respective third country or international organization and, in the case of transfers provided for in Article 49 paragraph (1) second paragraph, the documentation proving

the existence of adequate guarantees;

d) where possible, a general description of technical and organizational security measures

mentioned in article 32 paragraph (1).

(as of May 23, 2018, Art. 30, paragraph (2) of c

chapter IV, section 1 rectified by point 5. of the Correction of May 23- (3) The records referred to in paragraphs (1) and (2) are formulated in writing, including in electronic format.

2018)

(4) The operator or the person authorized by him, as well as, as the case may be, the representative of the operator or the person authorized by the operator make the records available to the supervisory authority, at its request.
(5) The obligations mentioned in paragraphs 1 and 2 do not apply to an enterprise or organization with less than 250 employees, unless the processing it carries out is likely to generate a risk for the rights and freedoms of the persons concerned, the processing does not is occasional or the processing includes special categories of data, as set out in Article 9 paragraph (1), or personal data relating to criminal convictions and offences, as set out in Article 10.

Art. 31: Cooperation with the supervisory authority

The operator and the person authorized by the operator and, as the case may be, their representative cooperate, at

request, with the supervisory authority in fulfilling its tasks.

(on May 23, 2018, Art. 31 of Chapter IV, Section 1 amended by point 7. of Re

ctification of 23-May-2018 )

Section 2: Security of personal data
Art. 32: Security of processing
(1) Taking into account the current stage of development, implementation costs and the nature, scope, context and purposes of processing, as well as the risk with varying degrees of probability and severity for the rights and freedoms of natural persons, the operator and the person authorized by him implement measures appropriate technical and organizational measures in order to ensure a level of security corresponding to this risk, including among others, as the case may be:
a) pseudonymization and encryption of personal data;
b) the ability to ensure the confidentiality, integrity, availability and continuous resistance of processing systems and services;
c) the ability to restore the availability of personal data and access to them in a timely manner in the event of a physical or technical incident;
d) a process for periodic testing, evaluation and assessment of the effectiveness of technical and organizational measures to guarantee processing security.
(2) When assessing the appropriate level of security, account is taken in particular of the risks presented by the processing, generated in particular, accidentally or illegally, by the destruction, loss, modification, unauthorized disclosure or unauthorized access to the personal data transmitted, stored or processed in another way.
(3) Adherence to an approved code of conduct, referred to in Article 40, or to an approved certification mechanism, referred to in Article 42, can be used as an element to demonstrate the fulfillment of the requirements stipulated in paragraph (1) of this article .
(4) The operator and the person authorized by him take measures to ensure that any natural person who acts under the authority of the operator or the person authorized by the operator and who has access to personal data only processes them at the request of the operator, except in the case in which this obligation rests with him under Union law or internal law.
Art. 33: Notification of the supervisory authority in case of breach of personal data security

(1) If there is a breach of personal data security, the operator shall notify

this to the competent supervisory authorities under Article 55, without undue delay and, if possible, within no more than 72 hours of the date on which it became aware of it, unless it is unlikely to generate a risk for rights and freedoms

natural persons. If the notification to the supervisory authority does not take place within the deadline

of 72 hours, this is accompanied by a reasoned explanation for the delay.

(on May 23, 2018 Art. 33, paragraph (1) of chapter IV, section 2 amended by point

8. from the Correction of May 23-

2018)
(2) The person authorized by the operator notifies the operator without undue delay after becoming aware of a breach of personal data security.
(3) The notification referred to in paragraph (1) at least:

a) describe the nature of the breach of personal data security, including, where possible, the categories and approximate number of persons concerned, as well as the categories and approximate number of personal data records in question;
b) communicate the name and contact details of the data protection officer or another point of contact where more information can be obtained;

c) describe the likely consequences of the breach of personal data security;
d) describe the measures taken or proposed to be taken by the operator to remedy the problem of the personal data security breach, including, as the case may be, the measures to mitigate its possible negative effects.
(4) When and to the extent that it is not possible to provide the information at the same time, it can be provided in several stages, without unjustified delays.
(5) The operator keeps documents related to all cases of personal data security breaches, which include a description of the factual situation in which the personal data security breach took place, its effects and the remedial measures taken. This documentation allows the supervisory authority to verify compliance with this article.
Art. 34: Informing the person concerned about the breach of personal data security
(1) If the breach of the security of personal data is likely to generate a high risk for the rights and freedoms of natural persons, the operator informs the person concerned about this breach without undue delay.
(2) The information sent to the data subject provided for in paragraph (1) of this article includes a description in clear and simple language of the nature of the personal data security breach, as well as at least the information and measures mentioned in article 33 paragraph ( 3) letters (b), (c) and (d).

(3) Informing the data subject referred to in paragraph (1) is not necessary if any of the following conditions are met:
a) the operator has implemented appropriate technical and organizational protection measures, and these measures have been applied in the case of personal data affected by the breach of personal data security, in particular measures to ensure that personal data become unintelligible to any person who is not authorized to access them, such as encryption;

b) the operator has taken further measures to ensure that the high risk for the rights and freedoms of the persons concerned referred to in paragraph (1) is no longer likely to materialize;
c) would require a disproportionate effort. In this situation, a public information is carried out instead or a similar measure is taken by which the persons concerned are informed in an equally effective way.

(4) If the operator has not already communicated the personal data security breach to the data subject, the supervisory authority, after taking into account the probability that the personal data security breach will generate a high risk, may request him to do so or may decide that any of the conditions mentioned in paragraph (3) are met.

Section 3: Data protection impact assessment and prior consultation

Art. 35: Evaluation of the impact on data protection
(1) Considering the nature, scope, context and purposes of the processing, if a type of processing, especially that based on the use of new technologies, is likely to generate a high risk for the rights and freedoms of natural persons, the operator performs, before processing, an assessment of the impact of the provided processing operations on the protection of personal data. A single assessment can address a set of similar processing operations that present similar high risks.
(2) When carrying out an assessment of the impact on data protection, the operator requests the opinion of the data protection officer, if he has been appointed.
(3) The data protection impact assessment referred to in paragraph (1) is required especially in the case of:

a) a systematic and comprehensive evaluation of the personal aspects related to natural persons, which is based on automatic processing, including the creation of profiles, and which is the basis of decisions that produce legal effects regarding the natural person or that affect them in a similar way in a significant measure;

b) large-scale processing of special categories of data, referred to in Article 9 paragraph (1), or of personal data regarding criminal convictions and offences, referred to in Article 10; or
c) systematic large-scale monitoring of an area accessible to the public.

(4) The supervisory authority draws up and publishes a list of the types of processing operations that are subject to the requirement to carry out an impact assessment on data protection, in accordance with paragraph (1). The supervisory authority communicates these lists to the committee referred to in Article 68.

(5) The supervisory authority may also establish and make available to the public a list of the types of processing operations for which an assessment of the impact on data protection is not necessary. The supervisory authority communicates these lists to the committee.
(6) Before adopting the lists referred to in paragraphs (4) and (5), the competent supervisory authority shall apply the mechanism for ensuring consistency referred to in Article 63 in the event that these active lists involve processing that involves the supply of goods or the provision of services to the persons concerned or the monitoring of their behavior in several member states or which may substantially affect the free circulation of personal data within the Union. (7) The assessment contains at least:

a) a systematic description of the expected processing operations and the purposes of the processing, including, as the case may be, the legitimate interest pursued by the operator;
b) an assessment of the necessity and proportionality of the processing operations in relation to these purposes; c) an assessment of the risks for the rights and freedoms of the persons concerned referred to in paragraph (1); and d) the measures expected to address the risks, including guarantees, security measures and mechanisms designed to ensure the protection of personal data and demonstrate compliance with the provisions of this regulation, taking into account the rights and legitimate interests of the data subjects and other interested persons .

(8) When assessing the impact of the processing operations carried out by the operators or the persons authorized by the relevant operators, the respect by the respective operators or authorized persons of the approved codes of conduct referred to in article 40, in particular with a view to a data protection impact assessments.

(9) The operator requests, where appropriate, the consent of the persons concerned or their representatives regarding the provided processing, without prejudice to the protection of commercial or public interests or the security of the processing operations.
(10) When the processing pursuant to article 6 paragraph (1) letter (c) or (e) has a legal basis in the law of the Union or of a member state under which the operator falls, and that law regulates the specific processing operation or the set of specific operations in question and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of the respective legal basis, paragraphs (1)-(7) do not apply, unless the Member States considers that it is necessary to carry out such an evaluation before carrying out the processing activities.

(11) Where necessary, the operator performs an analysis to assess whether the processing takes place in accordance with the data protection impact assessment, at least when there is a change in the risk represented by the processing operations.
Art. 36: Prior consultation

(1) The operator consults the supervisory authority before processing when the assessment of the impact on data protection provided for in article 35 indicates that the processing would generate a high risk in the absence of measures taken by the operator to mitigate the risk.
(2) When it considers that the provided processing mentioned in paragraph (1) would violate this regulation, especially when the risk has not been identified or mitigated to a sufficient extent

to the operator, the supervisory authority provides written advice to the operator and, as the case may be, to the person authorized by the operator, within eight weeks at most from receiving the request for consultation, and can use any of the powers mentioned in article 58. This period can be extended with six weeks, taking into account the complexity of the provided processing. The supervisory authority informs the operator and, as the case may be, the person authorized by the operator, within one month of receiving the request, regarding any such extension, presenting the reasons for the delay. These periods can be suspended until the supervisory authority has obtained the information it requested for the purpose of the consultation.

(3) When consulting the supervisory authority in accordance with paragraph (1), the operator provides it with:
a) if applicable, the respective responsibilities of the operator, associated operators and persons authorized by the operator involved in processing activities, especially for processing within a group of companies;

b) the purposes and means of the intended processing;
c) the measures and guarantees provided for the protection of the rights and freedoms of the persons concerned, in accordance with this regulation;
d) if applicable, the contact details of the data protection officer;
e) the assessment of the impact on data protection provided for in Article 35; and
f) any other information requested by the supervisory authority.
(4) Member States consult the supervisory authority in the process of preparing a proposal for a legislative measure to be adopted by a national parliament or a regulatory measure based on such a legislative measure, which refers to processing. (5) Notwithstanding paragraph (1), domestic law may require operators to consult with the supervisory authority and to obtain prior authorization from it in connection with the processing by an operator in order to fulfill a task exercised by him in the public interest , including processing related to social protection and public health.
Section 4: Data Protection Officer
Art. 37: Designation of the data protection officer
(1) The operator and the person authorized by the operator appoint a data protection officer whenever:
a) the processing is carried out by a public authority or body, with the exception of courts acting in the exercise of their jurisdictional function;
b) the main activities of the operator or the person authorized by the operator consist of processing operations which, by their nature, scope and/or purposes, require a periodic and systematic monitoring of the persons concerned on a large scale; or

c) the main activities of the operator or the person authorized by the operator consist of

large-scale processing of special categories of data pursuant to Article 9 or of data with

personal character related to criminal convictions and crimes, mentioned in article 10.

(as of May 23, 2018, Art. 37, paragraph (1), letter C. of chapter IV, section 4 as amended by point 9. of the Rectification of 23-

May-2018 )
(2) A group of enterprises may appoint a single data protection officer, provided that the data protection officer is easily accessible from each enterprise.
(3) If the operator or the person authorized by the operator is a public authority or a public body, a single data protection officer may be appointed for several of these authorities or bodies, taking into account their organizational structure and size. (4) In cases other than those mentioned in paragraph (1), the operator or the person authorized by the operator or the associations and other bodies that represent categories of operators or persons authorized by operators may designate or, where Union law or internal law requires this work, designates a data protection officer. The data protection officer can act in favor of such associations and other bodies that represent operators or persons authorized by operators.

(5) The data protection officer is appointed on the basis of professional qualities and, in particular, of specialized knowledge in the law and practices in the field of data protection, as well as on the basis of the ability to perform the tasks provided for in article 39.
(6) The person in charge of data protection may be a member of the operator's staff or the person authorized by the operator or may perform his duties on the basis of a service contract. (7) The operator or the person authorized by the operator publishes the contact details of the data protection officer and communicates them to the supervisory authorities.

Art. 38: Function of data protection officer
(1) The operator and the person authorized by the operator ensure that the person in charge of data protection is properly and timely involved in all aspects related to the protection of personal data.
(2) The operator and the person authorized by the operator support the data protection officer in fulfilling the tasks mentioned in article 39, ensuring him the necessary resources for the execution of these tasks, as well as access to personal data and processing operations, and to maintain his knowledge specialty.
(3) The operator and the person authorized by the operator ensure that the data protection officer does not receive any instructions regarding the performance of these tasks. He is not dismissed or sanctioned by the operator or by the person authorized by the operator to fulfill his duties. The data protection officer is directly responsible to the highest level of management of the operator or the person authorized by the operator.
(4) Data subjects may contact the data protection officer regarding all matters related to the processing of their data and the exercise of their rights under this regulation. (5) The person in charge of data protection has the obligation to respect secrecy or confidentiality in the performance of his duties, in accordance with Union law or domestic law. (6) The data protection officer may perform other duties and responsibilities. The operator or the person authorized by the operator ensures that none of these tasks and duties generate a conflict of interests.
Art. 39: Duties of the data protection officer
(1) The data protection officer has at least the following duties:
a) informing and advising the operator, or the person authorized by the operator, as well as the employees who deal with the processing regarding their obligations under this regulation and other provisions of Union law or internal law regarding data protection; b) monitoring compliance with this regulation, other provisions of Union law or internal law relating to data protection and the policies of the operator or the person authorized by the operator regarding the protection of personal data, including the allocation of responsibilities and awareness-raising actions and training of personnel involved in processing operations, as well as related audits;
c) the provision of advice upon request regarding the assessment of the impact on data protection and the monitoring of its functioning, in accordance with article 35;
d) cooperation with the supervisory authority;
e) assuming the role of contact point for the supervisory authority regarding the issues related to the processing, including the prior consultation referred to in Article 36, as well as, if necessary, the consultation regarding any other matter.
(2) In fulfilling his duties, the data protection officer takes into account the risk associated with the processing operations, taking into account the nature, scope, context and purposes of the processing.
Section 5: Codes of Conduct and Certification
Art. 40: Codes of conduct
(1) The Member States, the supervisory authorities, the committee and the Commission encourage the development of codes of conduct intended to contribute to the proper application of this regulation, taking into account the specific characteristics of the various processing sectors and the specific needs of micro-enterprises and small enterprises and the middle ones.

(2) Associations and other bodies that represent categories of operators or persons authorized by operators may prepare codes of conduct or may modify or extend the existing ones, in order to specify the manner of application of this regulation, such as in what regarding:
a) fair and transparent processing;

b) the legitimate interests pursued by operators in specific contexts; c) collection of personal data;
d) pseudonymization of personal data;
e) informing the public and the persons concerned;

f) exercising the rights of the persons concerned;
g) informing and protecting children and the manner in which the consent of the holders of parental responsibility for the children must be obtained;
h) the measures and procedures mentioned in articles 24 and 25 and the measures to ensure processing security, mentioned in article 32;
i) notification of the supervisory authorities regarding personal data security violations and informing the persons concerned about these violations;
j) the transfer of personal data to third countries or international organizations; or
k) extrajudicial procedures and other dispute resolution procedures to resolve disputes between operators and data subjects regarding processing, without prejudice to the rights of data subjects, pursuant to articles 77 and 79.
(3) The codes of conduct approved pursuant to paragraph (5) of this article and which have a general validity pursuant to paragraph (9) of this article may adhere not only to operators or persons authorized by operators who are the subject of this regulation, but also operators or persons authorized by operators who are not subject to this regulation pursuant to Article 3, in order to provide adequate guarantees in the framework of transfers of personal data to third countries or international organizations under the conditions referred to in Article 46 paragraph (2) letter ( e). These operators or persons authorized by the operators assume binding and enforceable commitments, by means of contractual instruments or other legally binding instruments, in order to apply the respective appropriate guarantees, including regarding the rights of the persons concerned.
(4) The code of conduct provided for in paragraph (2) of this article includes mechanisms that allow the body referred to in article 41, paragraph (1) to carry out the mandatory monitoring of compliance with its provisions by operators or persons authorized by operators who undertake to apply it , without prejudice to the duties and powers of the supervisory authorities that are competent under Article 55 or 56.
(5) The associations and other bodies mentioned in paragraph (2) of this article that intend to prepare a code of conduct or to modify or extend an existing code shall submit the draft code, modification or extension to the supervisory authority that is competent in pursuant to article 55. The supervisory authority issues an opinion regarding the compliance with this regulation of the draft code, amendment or extension and approves it if it is found that it offers sufficient adequate guarantees.
(6) If the draft code, amendment or extension is approved in accordance with paragraph (5), and the code of conduct in question is not related to processing activities in several member states, the supervisory authority shall also register publish the code.
(7) If a draft code of conduct, amendment or extension is related to processing activities in several member states, before approval, the competent supervisory authority pursuant to Article 55 shall transmit it, through the procedure referred to article 63, to the committee, which issues an opinion regarding the compliance with this regulation of the respective project, or, in the situation mentioned in paragraph (3) of this article, offers adequate guarantees.
(8) If the opinion referred to in paragraph (7) confirms compliance with this regulation of the draft code, amendment or extension or if, in the situation referred to in paragraph (3), it offers adequate guarantees, the committee transmits the opinion of the Commission.

(9) The Commission may adopt implementing acts to decide that the approved code of conduct, amendment or extension presented to it pursuant to paragraph (8) of this article have general validity in the Union. The respective implementing acts are adopted in accordance with the examination procedure provided for in Article 93 paragraph (2).

(10) The commission ensures adequate publicity for the approved codes that have been decided to have general validity in accordance with paragraph (9).
(11) The Committee regroups all approved codes of conduct, modifications and extensions in a register and makes them available to the public by appropriate means.

Art. 41: Monitoring of approved codes of conduct
(1) Without prejudice to the duties and powers of the competent supervisory authority pursuant to articles 57 and 58, the monitoring of compliance with a code of conduct pursuant to article 40 may be carried out by a body that has an appropriate level of expertise in relation to the subject of the code and which is accredited for this purpose by the competent supervisory authority.
(2) A body referred to in paragraph (1) can be accredited for monitoring compliance with a code of conduct if:
a) demonstrated to the competent supervisory authorities, in a satisfactory manner, his independence and expertise in relation to the object of the code;
b) instituted procedures that allow it to evaluate the eligibility of operators and persons authorized by operators in order to apply the code, to monitor their compliance with the provisions of the code and to periodically review its operation;
c) instituted procedures and structures for handling complaints regarding violations of the code or regarding how the code was or is being implemented by an operator or a person authorized by the operator, as well as to ensure the transparency of these procedures and structures for the persons concerned and for the public; and
d) demonstrated to the competent supervisory authorities, in a satisfactory manner, that his duties and attributions do not create conflicts of interest.

(3) The competent supervisory authority submits the draft requirements for the accreditation of a body referred to in paragraph (1) of this article to the committee, in accordance with the mechanism

to ensure the consistency referred to in article 63.

(as of May 23, 2018, Art. 41, paragraph (3) of chapter IV, section

nea 5 corrected by point 10. of the Correction of 23-May-

2018)
(4) Without prejudice to the duties and powers of the competent supervisory authority and the provisions of Chapter VIII, a body referred to in paragraph (1) of this article takes appropriate measures, subject to adequate guarantees, in the event of a violation of the code by an operator or a the person authorized by the operator, including by suspending or excluding that operator or that person from the code. The body in question informs the competent supervisory authority about these measures and the reasons that determined them.

(5) The competent supervisory authority revokes the accreditation of a body referred to in the paragraph

(1) in case the requirements for accreditation or the measures taken by the body are no longer met

in question violates this regulation.

(as of May 23, 2018, Art. 41, paragraph (5) of c

chapter IV, section 5 rectified by point 11. of the Rectification of 23-May-

2018)
(6) This article does not apply to the processing carried out by authorities and public bodies.
Art. 42: Certification
(1) The member states, the supervisory authorities, the committee and the Commission encourage, especially at the Union level, the establishment of certification mechanisms in the field of data protection, as well as seals and marks in this field, which allow to demonstrate the fact that the processing operations carried out by the operators and the persons authorized by the operators comply with this regulation. The specific needs of micro-enterprises and small and medium-sized enterprises are taken into account. (2) The data protection certification mechanisms, seals or marks approved pursuant to paragraph (5) of this article are established not only to be respected by the operators or the persons authorized by the operators who are the subject of this regulation, but also to demonstrate the existence of adequate guarantees offered by the operators or the persons authorized by

operators who are not subject to this regulation, pursuant to Article 3, in the framework of transfers of personal data to third countries or international organizations under the conditions referred to in Article 46 paragraph (2) letter (f). These operators or persons authorized by the operators assume binding and enforceable commitments, by means of contractual instruments or other legally binding instruments, in order to apply the respective appropriate guarantees, including regarding the rights of the persons concerned.

(3) Certification is voluntary and available through a transparent process.
(4) Certification in accordance with this article does not reduce the responsibility of the operator or the person authorized by the operator to comply with this regulation and does not affect the duties and powers of the supervisory authorities that are competent under article 55 or 56. (5) Certification bodies referred to in article 43 or the competent supervisory authority issue a certification under this article, based on the criteria approved by the respective competent supervisory authority under article 58 paragraph (3), or by the committee under article 63. If the criteria are approved by the committee, this can lead to a common certification, namely the European data protection seal.
(6) The operator or the person authorized by the operator who submits his processing activities to the certification mechanism offers the certification body referred to in article 43 or, as the case may be, the competent supervisory authorities, all the information necessary to carry out the certification procedure, as well as access to the activities respective processing.

(7) The certification is issued to an operator or a person authorized by the operator for a

the maximum period of three years and can be renewed under the same conditions, provided that the relevant criteria are still met. The certification is withdrawn, as the case may be, by the certification bodies referred to in article 43 or by the competent supervisory authority in the event that it no longer

the criteria for certification are met.

(as of May 23, 2018, Art. 42, paragraph (7) of chap

IV, section 5 rectified by point 12. of the Rectification of May 23

2018)
(8) The Committee regroups all certification mechanisms and data protection seals and marks in a register and makes them available to the public by any appropriate means.
Art. 43: Certification bodies
(1) Without prejudice to the tasks and powers of the competent supervisory authority, provided for in articles 57 and 58, the certification bodies that have an adequate level of competence in the field of data protection, after informing the supervisory authority to allow it to exercise the powers under Article 58 paragraph (2) letter (h), issue and renew the certification. Member States shall ensure that these certification bodies are accredited by one or both of the following entities:
a) the supervisory authority that is competent pursuant to article 55 or 56;
b) the national accreditation body designated in accordance with Regulation (EC) no. 765/2008 of the European Parliament and of the Council (1) in accordance with the standard EN-ISO/IEC 17065/2012 and with the additional requirements established by the supervisory authority that is competent under article 55 or 56.
(1) Regulation (EC) no. 765/2008 of the European Parliament and of the Council of July 9, 2008 establishing the requirements for accreditation and market surveillance regarding the marketing of products and repealing Regulation (EEC) no. 339/93 (OJ L 218, 13.8.2008, p. 30)
(2) A certification body referred to in paragraph (1) is accredited in accordance with that paragraph only if:
a) demonstrated to the competent supervisory authorities, in a satisfactory manner, his independence and expertise in relation to the subject of the certification;
b) undertake to comply with the criteria referred to in Article 42 paragraph (5) and approved by the supervisory authority that is competent pursuant to Article 55 or 56, or by the committee pursuant to Article 63;
c) instituted procedures for the issuance, periodic review and withdrawal of certification, seals and marks in the field of data protection;

d) instituted procedures and structures for handling complaints regarding violations of the certification or regarding the way in which the certification was or is implemented by an operator or a person authorized by the operator, as well as to ensure the transparency of these procedures and structures for the persons concerned and for the public; and

e) demonstrated to the competent supervisory authorities, in a satisfactory manner, that his duties and attributions do not create conflicts of interest.

(3) The accreditation of the certification bodies mentioned in paragraphs (1) and (2) of this article is carried out based on the requirements approved by the supervisory authority that is competent under article 55 or 56, or by the committee under article 63. In the case of an accreditation in

pursuant to paragraph (1) letter (b) of this article, these requirements complement those provided for in Regulation (EC) no. 765/2008 and the technical norms that describe the methods and procedures of the bodies

to certify.

(on the 23rd

i-2018 Art. 43, para. (3) from chapter IV, section 5 rectified by point 13. of the Rectification of 23-May-

2018)
(4) The certification bodies referred to in paragraph (1) are responsible for carrying out an appropriate evaluation in order to certify or withdraw this certification, without affecting the responsibility of the operator or the person authorized by the operator to comply with this regulation. Accreditation is issued for a maximum period of five years and can be renewed under the same conditions, provided that the certification body meets the requirements stipulated in this article.
(5) The certification bodies referred to in paragraph (1) transmit to the competent supervisory authorities the reasons for granting or withdrawing the requested certification.

(6) The requirements mentioned in paragraph (3) of this article and the criteria mentioned in article 42 paragraph (5) are published by the supervisory authority in an easily accessible form. authority

of supervision also transmit these requirements and criteria to the committee.

(on May 23, 2018 Art. 43, paragraph (6) of chapter IV, section 5 amended by point 1

4. from the Correction of May 23-

2018)
(7) Without prejudice to the provisions of Chapter VIII, the competent supervisory authority or the national accreditation body revokes the accreditation granted to a certification body pursuant to paragraph (1) of this article if the conditions for accreditation are not or are no longer met or the measures taken by the accreditation body violate this regulation.
(8) The Commission is empowered to adopt delegated acts in accordance with Article 92, in order to specify the requirements that must be taken into account for the data protection certification mechanisms, referred to in Article 42 paragraph (1).
(9) The Commission may adopt implementing acts to establish technical standards for certification mechanisms and seals and marks in the field of data protection, as well as mechanisms for promoting and recognizing those certification mechanisms, seals and marks. The respective implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93 paragraph (2).
CHAPTER V: Transfers of personal data to third countries or international organizations
Art. 44: The general principle of transfers
Any personal data that is the object of processing or that is to be processed after being transferred to a third country or to an international organization can only be transferred if, subject to the other provisions of this regulation, the conditions set out in this chapter are met by the operator and the person authorized by the operator, including with regard to subsequent transfers of personal data from the third country or from the international organization to another third country or to another international organization. All the provisions of this chapter are applied to ensure that the level of protection of natural persons guaranteed by this regulation is not undermined.
Art. 45: Transfers based on a decision regarding the adequacy of the level of protection
(1) The transfer of personal data to a third country or an international organization can be carried out when the Commission has decided that the third country, a territory or one or more specified sectors

from that third country or international organization in question ensures an adequate level of protection. Transfers made under these conditions do not require special authorizations.
(2) When evaluating the adequacy of the level of protection, the Commission takes into account, in particular, the following elements:

a) the rule of law, respect for human rights and fundamental freedoms, the relevant legislation, both general and sectoral, including regarding public security, defense, national security and criminal law, as well as the access of public authorities to personal data, as well as the implementation of this legislation, data protection rules, professional rules and security measures, including the rules regarding the subsequent transfer of personal data to another third country or international organization, which are respected in the respective third country or international organization respectively, the jurisprudence, as well as the existence of effective and opposable rights of the data subjects and of effective administrative and judicial reparations for the data subjects whose personal data are transferred;

b) the existence and efficient functioning of one or more independent supervisory authorities in the third country or under whose jurisdiction an international organization falls, with responsibility for ensuring and enforcing compliance with data protection rules, including adequate powers to ensure compliance with the application, for providing assistance and advice to the persons concerned regarding the exercise of their rights and for cooperation with the supervisory authorities in the member states; and

c) the international commitments to which the third country or international organization in question has joined or other obligations arising from legally binding conventions or instruments, as well as from its participation in multilateral or regional systems, especially in the field of personal data protection personal.

(3) The Commission, after evaluating the adequacy of the level of protection, may decide, through an implementing act, that a third country, a territory or one or more specified sectors of a third country or an international organization ensure an adequate level of protection in the sense of paragraph (2) of this article. The implementing act provides for a periodic review mechanism, at least once every four years, which takes into account all relevant developments in the third country or the international organization. The implementing act mentions the geographical and sectoral application, and, as the case may be, identifies the supervisory authority or authorities referred to in paragraph (2) letter (b) of this article. The implementing act is adopted in accordance with the examination procedure referred to in Article 93 paragraph (2).

(4) The Commission continuously monitors developments in third countries and at the level of international organizations that could affect the operation of decisions adopted pursuant to paragraph (3) of this article and decisions adopted pursuant to article 25 paragraph (6) of Directive 95/46/ WHAT.
(5) If the available information reveals, in particular following the review referred to in paragraph (3) of this article, that a third country, a territory or a specified sector of that third country or an international organization no longer ensures a level of adequate protection within the meaning of paragraph (2) of this article, the Commission, if necessary, repeals, modifies or suspends, by means of an implementing act, the decision referred to in paragraph (3) of this article without retroactive effect. The respective implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93 paragraph (2).

For imperative reasons of urgency, the Commission shall adopt immediately applicable implementing acts in accordance with the procedure referred to in Article 93 paragraph (3).
(6) The commission initiates consultations with the third country or the international organization in order to remedy the situation that was the basis of the decision taken in accordance with paragraph (5).

(7) A decision taken pursuant to paragraph (5) of this article does not affect transfers of personal data to the third country, a territory or one or more specified sectors of that third country or to the international organization in question in accordance with articles 46-49. (8) The Commission publishes in the Official Journal of the European Union and on its website a list of third countries, territories and sectors specified in a third country and international organizations in the case of which it has decided that the appropriate level of protection is ensured or is no longer insured.

(9) Decisions adopted by the Commission pursuant to Article 25 paragraph (6) of Directive 95/46/EC remain in force until they are modified, replaced or repealed by a Commission decision adopted in accordance with paragraph (3) or (5) from this article.
Art. 46: Transfers based on adequate guarantees

(1) In the absence of a decision based on Article 45 paragraph (3), the operator or the person authorized by the operator may transfer personal data to a third country or an international organization only if the operator or the person authorized by the operator has offered adequate guarantees and with the condition that there are opposable rights and effective remedies for the persons concerned.

(2) The appropriate guarantees referred to in paragraph 1 can be provided without the need for any specific authorization from a supervisory authority, by:
a) a legally binding and enforceable instrument between public authorities or bodies;

b) mandatory corporate rules in accordance with article 47;
c) standard data protection clauses adopted by the Commission in accordance with the examination procedure referred to in Article 93 paragraph (2);
d) standard data protection clauses adopted by a supervisory authority and approved by the Commission in accordance with the examination procedure referred to in Article 93 paragraph (2);
e) a code of conduct approved in accordance with Article 40, accompanied by a binding and enforceable commitment from the operator or the person authorized by the operator in the third country to apply adequate guarantees, including regarding the rights of the persons concerned; or
f) a certification mechanism approved in accordance with article 42, accompanied by a binding and enforceable commitment from the operator or the person authorized by the operator in the third country to apply adequate guarantees, including with regard to the rights of the data subjects.

(3) Subject to authorization from the competent supervisory authority, the appropriate guarantees referred to in paragraph (1) may also be provided, in particular, by:
a) contractual clauses between the operator or the person authorized by the operator and the operator, the person authorized by the operator or the recipient of personal data from the third country or the international organization; or

b) provisions to be included in the administrative agreements between the authorities or public bodies, which include opposable and effective rights for the persons concerned.
(4) The supervisory authority shall apply the mechanism for ensuring consistency referred to in Article 63, in the cases referred to in paragraph (3) of this article.

(5) The authorizations granted by a member state or a supervisory authority pursuant to Article 26 paragraph (2) of Directive 95/46/EC are valid until the date on which they are modified, replaced or repealed, if necessary, by the respective supervisory authority. Decisions adopted by the Commission pursuant to Article 26(4) of Directive 95/46/EC shall remain in force until amended, replaced or repealed, if necessary, by a Commission decision adopted in accordance with paragraph (2) of this article.

Art. 47: Mandatory corporate rules
(1) In accordance with the mechanism for ensuring consistency provided for in Article 63, the competent supervisory authority approves mandatory corporate rules, provided that they:
a) to be legally binding and to apply to each concerned member of the group of enterprises or of the group of enterprises involved in a common economic activity, including its employees, as well as to be implemented by the members in question;
b) to grant, expressly, opposable rights to the persons concerned with regard to the processing of their personal data; and
c) to fulfill the requirements stipulated in paragraph (2).
(2) The mandatory corporate rules mentioned in paragraph (1) specify at least:
a) the structure and contact details of the group of enterprises or of the group of enterprises involved in a common economic activity and of each of its members;

b) the data transfers or the set of transfers, including the categories of personal data, the type of processing and the purposes of the processing, the types of data subjects affected and the identification of the third country or third countries in question;
c) their mandatory legal character, both internally and externally;

d) application of general principles in data protection, in particular purpose limitation, data minimization, limited storage periods, data quality, data protection starting from the moment of conception and implicit protection, legal basis for processing, processing of special categories of data personal data, measures to ensure data security, as well as requirements regarding subsequent transfers to bodies that are not subject to mandatory corporate rules;

e) the rights of data subjects with regard to processing and the means of exercising these rights, including the right not to be subject to decisions based exclusively on automatic processing, including the creation of profiles, in accordance with Article 22, the right to file a complaint before the competent supervisory authority and before the competent courts of the Member States, in accordance with Article 79, as well as the right to obtain reparations and, as the case may be, compensation for the breach of the mandatory corporate rules;

f) the acceptance by the operator or by the person authorized by the operator, who is based on the territory of a member state, of the responsibility for any violation of the mandatory corporate rules by any member in the case who is not based in the Union; the operator or the person authorized by the operator is exempted from this liability, fully or partially, only if he proves that the respective member was not responsible for the event that caused the damage;

g) the way in which the information regarding the mandatory corporate rules, in particular regarding the provisions mentioned in letters (d), (e) and (f) of this paragraph, is provided to the persons concerned in addition to the information mentioned in articles 13 and 14;
h) the tasks of any data protection officer designated in accordance with article 37 or of any other person or entity charged with monitoring compliance with mandatory corporate rules within the group of enterprises or the group of enterprises involved in a common economic activity, training activities and complaints management;

i) procedures for formulating complaints;
j) the mechanisms within the group of enterprises or the group of enterprises involved in a common economic activity, intended to ensure compliance with the mandatory corporate rules. These mechanisms include data protection audits and methods of ensuring corrective actions designed to protect the rights of the data subject. The results of these checks should be communicated to the person or entity referred to in letter (h) and the board of directors of the company that exercises control over the group of companies or the group of companies involved in a common economic activity and should be made available to the authority of competent supervision, upon request;
k) the mechanisms for reporting and recording the changes made to the rules and for reporting these changes to the supervisory authority;
l) the cooperation mechanism with the supervisory authority in order to ensure compliance with the rules by any member of the group of enterprises or of the group of enterprises involved in a common economic activity, in particular by making available to the supervisory authority the results of the checks regarding the measures mentioned in point (j);
m) reporting mechanisms to the competent supervisory authority of any legal requirements imposed on a member of the group of companies or of the group of companies involved in a joint economic activity in a third country that may have a considerable adverse effect on the guarantees provided by the rules mandatory corporatists; and
n) appropriate training in the field of data protection for personnel who have permanent or periodic access to personal data.
(3) The Commission may specify the format and procedures for the exchange of information between operators, persons authorized by operators and supervisory authorities for corporate rules

mandatory in the sense of this article. The respective implementing acts are adopted in accordance with the examination procedure provided for in Article 93 paragraph (2).
Art. 48: Transfers or disclosures of information not authorized by Union law
Any decision of a court or tribunal and any decision of an administrative authority of a third country requiring an operator or the person authorized by the operator to transfer or disclose personal data may be recognized or enforced in any way only if it is based on an international agreement, such as a mutual legal assistance treaty in force between the requesting third country and the Union or a Member State, without prejudice to other reasons for transfer under this chapter.

Art. 49: Exemptions for specific situations
(1) In the absence of a decision on the adequacy of the level of protection in accordance with Article 45(3) or adequate safeguards in accordance with Article 46, including mandatory corporate rules, a transfer or a set of data transfers with personal transfer to a third country or an international organization can only take place under one of the following conditions: a) the person concerned has explicitly expressed his agreement regarding the proposed transfer, after being informed of the possible risks that such transfers may involve them for the concerned person as a result of the lack of a decision regarding the adequacy of the level of protection and adequate guarantees;
b) the transfer is necessary for the execution of a contract between the data subject and the operator or for the application of pre-contractual measures adopted at the request of the data subject;
c) the transfer is necessary for the conclusion of a contract or for the execution of a contract concluded in the interest of the concerned person between the operator and another natural or legal person;
d) the transfer is necessary for important reasons of public interest;
e) the transfer is necessary for establishing, exercising or defending a right in court;
f) the transfer is necessary to protect the vital interests of the data subject or other persons, when the data subject does not have the physical or legal capacity to express his consent; g) the transfer is made from a register which, according to Union law or domestic law, has the purpose of providing information to the public and which can be consulted either by the general public or by any person who can prove a legitimate interest, but only to the extent that the conditions regarding consultation provided by Union law or internal law in that specific case are met. If a transfer could not be based on a provision provided in article 45 or 46, including provisions on mandatory corporate rules, and none of the derogations for specific situations provided for in the first paragraph of this paragraph are applicable, a transfer to a third country or an international organization can only take place if the transfer is not repetitive, refers only to a limited number of data subjects, is necessary for the purpose of achieving the major legitimate interests pursued by the operator over which the interests or rights do not prevail and the freedoms of the data subject and the operator evaluated all the circumstances related to the data transfer and, based on this evaluation, presented appropriate guarantees regarding the protection of personal data. The operator informs the supervisory authority about the transfer. The operator, in addition to providing the information mentioned in articles 13 and 14, informs the person concerned about the transfer and the major legitimate interests it pursues.
(2) The transfer pursuant to paragraph (1), first paragraph, letter (g) does not involve all personal data or all categories of personal data included in the register. When the register is to be consulted by persons who have a legitimate interest, the transfer is carried out only at the request of the respective persons or if they will be the recipients. (3) Paragraph (1) first paragraph letters (a), (b) and (c) and the second paragraph do not apply in the case of activities carried out by public authorities in the exercise of their public powers.
(4) The public interest provided for in paragraph (1), first paragraph, letter (d) is recognized in Union law or in the law of the member state under which the operator falls.
(5) In the absence of a decision regarding the adequacy of the level of protection, Union law or domestic law may, for important considerations of public interest, expressly establish limits

on the transfer of specific categories of personal data to a third country or an international organization. Member States shall notify these provisions to the Commission.
(6) The operator or the person authorized by the operator records the evaluation, as well as the appropriate guarantees provided for in the second paragraph of paragraph (1) of this article, in the records mentioned in article 30.

Art. 50: International cooperation in the field of personal data protection
With regard to third countries and international organizations, the Commission and the supervisory authorities shall take appropriate measures to:
(a) the development of international cooperation mechanisms to facilitate ensuring the effective application of the legislation on the protection of personal data;
(b) granting mutual international assistance in ensuring the application of legislation in the field of personal data protection, including through notification, transfer of complaints, assistance in investigations and exchange of information, subject to adequate guarantees for the protection of personal data and other rights and fundamental freedoms;
(c) the involvement of relevant interested parties in the discussions and activities aimed at intensifying international cooperation in the field of the application of the legislation regarding the protection of personal data; (d) promoting the mutual exchange and documentation regarding the legislation and practices regarding the protection of personal data, including regarding jurisdictional conflicts with third countries.
CHAPTER VI: Independent supervisory authorities
Section 1: Independent status
Art. 51: The supervisory authority
(1) Each member state ensures that one or more independent public authorities are responsible for monitoring the application of this regulation, in order to protect the rights and fundamental freedoms of natural persons in terms of processing and in order to facilitate the free movement of personal data within the Union (the "supervisory authority"). (2) Each supervisory authority contributes to the consistent application of this regulation throughout the Union. For this purpose, the supervisory authorities cooperate both among themselves and with the Commission, in accordance with Chapter VII.
(3) If several supervisory authorities are established in a member state, it designates the supervisory authority that represents the respective authorities within the committee and establishes a mechanism to ensure compliance by the other authorities with the rules regarding the mechanism for ensuring the consistency provided for in article 63.
(4) Each member state shall notify the Commission of the legal provisions it adopts pursuant to this chapter by May 25, 2018 and, without delay, any subsequent amendment it makes to these provisions.
Art. 52: Independence
(1) Each supervisory authority benefits from full independence in fulfilling its tasks and exercising its powers in accordance with this regulation.
(2) The member or members of each supervisory authority, in fulfilling their duties and exercising their powers in accordance with this regulation, remains independent of any direct or indirect external influence and neither solicits nor does not accept instructions from an external party.
(3) The member or members of each supervisory authority refrain from taking actions incompatible with their attributions, and during the mandate, do not carry out incompatible activities, remunerated or not.
(4) Each member state ensures that each supervisory authority benefits from human, technical and financial resources, a headquarters and the necessary infrastructure for the fulfillment of tasks and the effective exercise of its powers, including those to be applied in the context of assistance mutual, cooperation and participation within the committee.

(5) Each member state ensures that each supervisory authority selects its own staff and has its own staff under the exclusive management of the member or members of the respective supervisory authority.
(6) Each member state ensures that each supervisory authority is subject to a financial control that does not affect its independence and that it has separate, public annual budgets, which can be part of the general state or national budget.

Art. 53: General conditions applicable to members of the supervisory authority
(1) Member States ensure that each member of their supervisory authority is appointed through a transparent procedure:
– by parliament;
– by the government;
- by the head of state; or
- by an independent body empowered to make appointments under domestic law.
(2) Each member in question has the necessary qualifications, experience and competences, especially in the field of personal data protection, to be able to fulfill their duties and exercise their competences.
(3) The duties of a member cease in the event of the expiry of the mandate, in the event of resignation or ex officio retirement in accordance with the relevant domestic law.
(4) A member can be dismissed only in cases of serious misconduct or if he no longer fulfills the conditions necessary to fulfill his duties.
Art. 54: Rules regarding the establishment of the supervisory authority
(1) Each member state provides, through legislation, the following:
a) the establishment of each supervisory authority;
b) the qualifications and eligibility conditions necessary to be appointed as a member of each supervisory authority;
c) the rules and procedures for appointing the member or members of each supervisory authority;
d) the term of office of the member or members of each supervisory authority, of at least four years, except for the first appointment after May 24, 2016, part of which may be for a shorter period if this is necessary to protect the authority's independence of supervision through a staggered appointment procedure;
e) if and how many times the mandate of the member or members of each supervisory authority is eligible for renewal;
f) the conditions that regulate the obligations of the member or members and the staff of each supervisory authority, prohibitions regarding the actions, occupations and benefits incompatible with them during the mandate and after its termination, as well as the rules that regulate the termination of the employment contract.
(2) The member or members and staff of each supervisory authority have the obligation, in accordance with Union law or domestic law, to respect both during the mandate and after its termination, professional secrecy with regard to the confidential information they have became aware of in the course of fulfilling their duties or exercising their powers. During their term of office, this obligation to maintain professional secrecy applies in particular to the reporting by natural persons of violations of this regulation.
Section 2: Qualifications, tasks and competences
Art. 55: Competence
(1) Each supervisory authority has the competence to perform the tasks and exercise the powers conferred on it in accordance with this regulation on the territory of the member state to which it belongs.

(2) If the processing is carried out by public authorities or private bodies acting on the basis of Article 6 paragraph (1) letter (c) or (e), the supervisory authority in the state

respective member has the competence. In such cases, Article 56 does not apply.

(as of May 23, 2018, Art. 55, paragraph (2) of Chapter VI, Section 2, amended by point 15 of the Amendment of May 23, 2018)
(3) The supervisory authorities are not competent to supervise the processing operations of the courts acting in the exercise of their judicial function.

Art. 56: Competence of the main supervisory authority
(1) Without prejudice to Article 55, the supervisory authority of the main headquarters or the sole headquarters of the operator or the person authorized by the operator is competent to act as the main supervisory authority for the cross-border processing carried out by the respective operator or the respective authorized person in the case in accordance with the procedure provided for in article 60.
(2) By way of derogation from paragraph (1), each supervisory authority is competent to deal with a complaint brought to its attention or a possible violation of this regulation, if its object refers only to an office located in the state or member or significantly affects targeted persons only in its member state.
(3) In the cases mentioned in paragraph (2) of this article, the supervisory authority informs the main supervisory authority about this matter without delay. Within three weeks from the moment of the information, the main supervisory authority decides whether or not to treat the respective case in accordance with the procedure provided for in Article 60, taking into account whether or not there is a seat of the operator or the person authorized by the operator on the territory of the state member whose supervisory authority informed it.
(4) If the main supervisory authority decides to deal with the case, the procedure provided for in Article 60 shall be applied. The supervisory authority that informed the main supervisory authority may submit a draft decision to the latter. The main supervisory authority takes into account to the greatest extent possible the respective draft when preparing the draft decision provided for in Article 60 paragraph (3).
(5) If the main supervisory authority decides not to deal with the case, the supervisory authority that informed the main supervisory authority deals with the case in accordance with articles 61 and 62.
(6) The main supervisory authority is the only interlocutor of the operator or the person authorized by the operator regarding the cross-border processing carried out by the respective operator or the respective person authorized by the operator.
Art. 57: Tasks
(1) Without prejudice to other tasks established under this regulation, each supervisory authority, in its territory:
a) monitor and ensure the application of this regulation;
b) promotes actions to raise awareness and understanding among the public of the risks, rules, guarantees and rights in terms of processing. Special attention is paid to activities that are specifically aimed at children;
c) provides advice, in accordance with domestic law, to the national parliament, the government and other institutions and bodies regarding legislative and administrative measures related to the protection of the rights and freedoms of natural persons with regard to processing;
d) promotes actions to raise awareness of the operators and the persons empowered by them regarding their obligations under this regulation;
e) upon request, provides information to any person concerned in connection with the exercise of his rights in accordance with this regulation and, if necessary, cooperates with the supervisory authorities in other member states for this purpose;
f) deal with complaints submitted by a data subject, a body, an organization or an association in accordance with Article 80 and investigate to an appropriate extent the object of the complaint and inform the complainant about the progress and result of the investigation, within a reasonable time, in especially if it is necessary to carry out a more thorough investigation or coordinate with another supervisory authority;

g) cooperates, including by exchanging information, with other supervisory authorities and provides mutual assistance to ensure the consistency of application and compliance with this regulation;
h) carries out investigations regarding the application of this regulation, including on the basis of information received from another supervisory authority or from another public authority;

i) monitors the relevant developments, insofar as they have an impact on the protection of personal data, especially the evolution of information and communication technologies and commercial practices;
j) adopt standard contractual clauses mentioned in article 28 paragraph (8) and article 46 paragraph (2) letter (d);

k) draw up and keep up to date a list related to the requirement regarding the assessment of the impact on data protection, in accordance with article 35 paragraph (4);
l) offers advice on the processing operations referred to in Article 36 paragraph (2); m) encourages the development of codes of conduct in accordance with Article 40 paragraph (1), gives its opinion on them and approves those that offer sufficient guarantees, in accordance with Article 40 paragraph (5);

n) encourages the establishment of certification mechanisms, as well as seals and marks in the field of data protection in accordance with Article 42 paragraph (1) and approves the certification criteria in accordance with Article 42 paragraph (5);
o) where applicable, carry out a periodic review of the certifications granted, in accordance with article 42 paragraph (7);

p) elaborates and publishes the accreditation requirements of a code of conduct monitoring body

in accordance with Article 41 and of a certification body in accordance with Article 43;

(on May 23, 2018 Art. 57, paragraph (1), letter P. of chapter VI, section 2 rectified by point 16. of the Rectification of 23-

May-2018 )
q) coordinates the accreditation procedure of a code of conduct monitoring body in accordance with Article 41 and of a certification body in accordance with Article 43; r) authorizes the contractual clauses and provisions referred to in Article 46 paragraph (3);
s) approve the mandatory corporate rules in accordance with article 47;
t) contributes to the activities of the committee;
u) keep up-to-date internal records regarding the violations of this regulation and the measures taken, in particular the warnings issued and the sanctions imposed in accordance with Article 58 paragraph (2); and v) performs any other tasks related to the protection of personal data.
(2) Each supervisory authority facilitates the submission of the complaints referred to in paragraph (1) letter (f) by measures such as making available a complaint submission form that can be completed including in electronic format, without excluding other means of communication . (3) The fulfillment of the tasks of each supervisory authority is free for the data subject and, as the case may be, for the data protection officer.
(4) If the requests are clearly unfounded or excessive, especially due to their repetitive nature, the supervisory authority may charge a reasonable fee, based on administrative costs, or may refuse to process them. The burden of demonstrating the obviously unfounded or excessive nature of the request rests with the supervisory authority.
Art. 58: Powers
(1) Each supervisory authority has all the following powers of investigation:
a) to instruct the operator and the person authorized by the operator and, as the case may be, the representative of the operator or the person authorized by the operator to provide any information that the supervisory authority requests in order to fulfill its tasks;
b) to carry out investigations in the form of data protection audits;
c) to carry out a review of the certifications granted pursuant to Article 42 paragraph (7);
d) to notify the operator or the person authorized by the operator regarding the alleged violation of this regulation;
e) to obtain, from the operator and the person authorized by the operator, access to all personal data and to all information necessary for the performance of his tasks;

f) to obtain access to any of the premises of the operator and the person authorized by the operator, including any equipment and data processing means, in accordance with Union law or internal procedural law.
(2) Each supervisory authority has all the following corrective powers:

a) to issue warnings to an operator or a person authorized by the operator regarding the possibility that the provided processing operations violate the provisions of this regulation;

b) to issue warnings addressed to an operator or a person authorized by the operator in the case

in which the processing operations violated the provisions of this regulation;

(on 23-May-2018 Art. 58, paragraph (2), letter B. of chapter VI, section 2 rectified by point 17. of the Rectification of 23-

May-2018 )
c) to instruct the operator or the person authorized by the operator to comply with the requests of the person concerned to exercise his rights under this regulation;
d) to instruct the operator or the person authorized by the operator to ensure compliance of the processing operations with the provisions of this regulation, specifying, as the case may be, the method and the deadline for this;
e) to oblige the operator to inform the person concerned about a violation of the protection of personal data;
f) to impose a temporary or definitive limitation, including a ban on processing;
g) to order the rectification or deletion of personal data or the restriction of processing, pursuant to articles 16, 17 and 18, as well as the notification of these actions to the recipients to whom the personal data were disclosed, in accordance with article 17 paragraph (2 ) and with article 19; h) to withdraw a certification or to oblige the certification body to withdraw a certification issued pursuant to articles 42 and 43 or to oblige the certification body not to issue a certification if the certification requirements are not or no longer are fulfilled;
i) to impose administrative fines in accordance with article 83, in addition to or instead of the measures mentioned in this paragraph, depending on the circumstances of each individual case;
j) to order the suspension of data flows to a recipient from a third country or to an international organization.
(3) Each supervisory authority has all the following authorization and advisory powers: a) to offer advice to the operator in accordance with the prior consultation procedure referred to in Article 36;
b) to issue opinions, on its own initiative or upon request, to the national parliament, the government of the member state or, in accordance with domestic law, to other institutions and bodies, as well as to the public, regarding any aspect related to the protection of personal data;
c) to authorize the processing referred to in Article 36 paragraph (5), if the law of the member state provides for such prior authorization;
d) to issue an opinion and approve draft codes of conduct, in accordance with Article 40 paragraph (5);
e) to accredit the certification bodies in accordance with article 43;
f) to issue certifications and approve certification criteria in accordance with article 42 paragraph (5); g) to adopt the standard data protection clauses referred to in Article 28 paragraph (8) and Article 46 paragraph (2) letter (d);
h) to authorize the contractual clauses referred to in article 46 paragraph (3) letter (a);
i) to authorize the administrative agreements referred to in article 46 paragraph (3) letter (b); and
j) to approve mandatory corporate rules in accordance with article 47.
(4) The exercise of the powers conferred on the supervisory authority under this article is subject to adequate guarantees, including effective judicial appeals and fair processes, provided for in Union law and in domestic law in accordance with the charter.
(5) Each member state provides, through legislation, the fact that its supervisory authority has the competence to bring before the judicial authorities cases of violation of this regulation and,

as the case may be, to initiate or otherwise get involved in legal proceedings, in order to ensure the application of the provisions of this regulation.
(6) Each member state can provide in its law or fact that its supervisory authority has additional powers, apart from those mentioned in paragraphs (1), (2) and (3). The exercise of these powers does not affect the efficient operation of Chapter VII.

Art. 59: Activity reports
Each supervisory authority shall draw up an annual report on its activities, which may include a list of the types of infringements notified and the types of measures taken in accordance with Article 58(2). The reports are submitted to the national parliament, the government and other authorities designated by domestic law. They are made available to the public, the Commission and the committee.
CHAPTER VII: Cooperation and coherence
Section 1: Cooperation
Art. 60: Cooperation between the main supervisory authority and the other supervisory authorities concerned
(1) The main supervisory authority cooperates with the other supervisory authorities concerned, in accordance with this article, in an attempt to reach a consensus. The main supervisory authority and the concerned supervisory authorities shall communicate all relevant information to each other. (2) The main supervisory authority may at any time request other concerned supervisory authorities to provide mutual assistance pursuant to Article 61 and may carry out joint operations pursuant to Article 62, in particular with a view to carrying out investigations or monitoring the implementation of a measures related to an operator or a person authorized by the operator, established in another member state.
(3) The main supervisory authority communicates without delay the relevant information regarding this matter to the other concerned supervisory authorities. The main supervisory authority shall without delay forward a draft decision to the other supervisory authorities concerned, in order to obtain their opinion, and shall duly take into account their opinions.
(4) If any of the other supervisory authorities concerned expresses, within four weeks after being consulted in accordance with paragraph (3) of this article, a relevant and reasoned objection to the draft decision, the supervisory authority the main body, if it does not comply with the relevant and reasoned objection or considers that the objection is not relevant or reasoned, it shall notify the mechanism for ensuring consistency referred to in article 63.
(5) If it intends to comply with the relevant and reasoned objection, the main supervisory authority shall send a revised draft decision to the other supervisory authorities concerned in order to obtain their opinion. This revised draft decision is subject to the procedure referred to in paragraph (4) during a period of two weeks.
(6) In the event that none of the other supervisory authorities concerned has raised objections to the draft decision submitted by the main supervisory authority within the term referred to in paragraphs (4) and (5), it is considered that the main supervisory authority and the authorities of supervision concerned agree with the respective draft decision, which becomes binding for them.
(7) The main supervisory authority adopts the decision and a notification to the main headquarters or the sole headquarters of the operator or the person authorized by the operator, as the case may be, and informs the other supervisory authorities concerned and the committee regarding the decision in question, including a summary of the elements and relevant reasons. The supervisory authority to which the complaint was submitted informs the complainant about the decision.
(8) By derogation from paragraph (7), if a complaint is refused or rejected, the supervisory authority to which the complaint was submitted adopts the decision, notifies the complainant and informs the operator about this.
(9) If the main supervisory authority and the concerned supervisory authorities agree to refuse or reject certain parts of a complaint and to proceed with other parts of the respective complaint, a separate decision is adopted for each of these parts. The main supervisory authority adopts the decision for the party concerned with actions related to the operator, a notification to the headquarters

principal or sole headquarters of the operator or the person authorized by the operator in the territory of the Member State in question and informs the complainant about this, while the supervisory authority of the complainant adopts the decision for the party concerned with the refusal or rejection of the respective complaint, a notification the complainant and informs the operator or the person authorized by the operator about this.

(10) Following the notification of the decision of the main supervisory authority pursuant to paragraphs (7) and (9), the operator or the person authorized by the operator takes the necessary measures to ensure that the processing activities are in accordance with the decision in all its premises in the Union . The operator or the person authorized by the operator notifies the measures taken in order to comply with the decision of the main supervisory authority, which informs the other supervisory authorities concerned.

(11) If, in exceptional circumstances, a concerned supervisory authority has reasons to consider that there is an urgent need to act in order to protect the interests of the concerned persons, the emergency procedure provided for in article 66 shall be applied.
(12) The main supervisory authority and the other concerned supervisory authorities provide each other with the information requested under this article, electronically, using a standard form.

Art. 61: Mutual assistance
(1) The supervisory authorities shall provide each other with relevant information and assistance to implement this regulation in a coherent manner and establish effective cooperation measures between them. Mutual assistance refers, in particular, to requests for information and surveillance measures, such as requests for authorizations and prior consultations, inspections and investigations.
(2) Each supervisory authority takes all appropriate measures necessary to respond to a request of another supervisory authority, without undue delay and at the latest within one month from the date of receipt of the request. These measures may include, in particular, the transmission of relevant information regarding the conduct of an investigation.
(3) Requests for assistance include all the necessary information, including the purpose of the request and the reasons underlying it. The information that is the subject of the exchange is used only for the purpose for which it was requested.

(4) The requested supervisory authority cannot refuse to comply with the request, unless:

a) does not have the competence regarding the object of the request or the measures it is requested to execute; or
b) complying with the request would violate this regulation or the Union law or the internal law under which the supervisory authority that received the request falls.
(5) The supervisory authority to which the request was addressed informs the supervisory authority that sent the request about the results or, as the case may be, the progress made or the measures taken to respond to the request. The requested supervisory authority shall give reasons for each refusal to comply with the request pursuant to paragraph (4).
(6) As a rule, the requested supervisory authorities provide the information requested by other supervisory authorities electronically, using a standard form.
(7) The requested supervisory authorities do not charge any fee for the actions taken by them based on a request for mutual assistance. The supervisory authorities can agree on some rules regarding mutual remuneration in the case of specific expenses resulting from the granting of mutual assistance in exceptional situations.
(8) If a supervisory authority does not provide the information referred to in paragraph (5) of this article within one month of receiving the request from another supervisory authority, the latter may adopt a provisional measure on the territory of its own member state, in accordance with Article 55 paragraph (1). In this case, the urgent need to act under Article 66(1) is deemed to be met and requires an urgent binding decision by the committee in accordance with Article 66(2).
(9) The commission, through an implementing act, may specify the form and procedures for the mutual assistance mentioned in this article, as well as the methods of exchanging information electronically between the supervisory authorities and between the supervisory authorities and the committee, in special

the standard form mentioned in paragraph (6) of this article. The respective implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93 paragraph (2).
Art. 62: Joint operations of the supervisory authorities

(1) As the case may be, the supervisory authorities carry out joint operations, including joint investigations and joint law enforcement measures, in which members or staff from the supervisory authorities of other member states are involved.
(2) If the operator or the person authorized by the operator has offices in several member states or if a significant number of data subjects from several member states are likely to be significantly affected by processing operations, an authority supervision from each of the respective member states has the right to participate in joint operations. The supervisory authority which is competent in accordance with Article 56(1) or (4) shall invite the supervisory authorities of each of those Member States to take part in those joint operations and shall respond without delay to the request of a supervisory authority to participate. .

(3) A supervisory authority may, in accordance with domestic law and with the agreement of the supervisory authority of the home Member State, grant powers, including powers of investigation, to members or staff of the supervisory authority of the home Member State involved in joint operations or, to the extent that the law of the Member State of the supervisory authority of the receiving Member State allows it, may authorize members or staff of the supervisory authority of the home Member State to exercise its powers of investigation in accordance with the law of that Member State of following authorities. Such powers of investigation can only be exercised under the coordination and in the presence of members or staff of the supervisory authority in the host Member State. The members or staff of the supervisory authority in the home Member State are subject to the domestic law under which the supervisory authority in the receiving Member State falls.

(4) If, in accordance with paragraph (1), the staff of a supervisory authority from the home Member State carries out its activity in another Member State, the receiving Member State assumes responsibility for the actions of the respective staff, including liability for any damages caused by the respective staff members in the course of their operations, in accordance with the law of the member state on whose territory they carry out their operations.

(5) The Member State on whose territory the damages occurred shall repair these damages under the conditions applicable to damages caused by its own personnel. The Member State of origin of the supervisory authority whose personnel caused damage to a person on the territory of another Member State reimburses this other Member State all the sums it paid to the entitled persons on their behalf.

(6) Without prejudice to the exercise of its rights vis-à-vis third parties and with the exception of paragraph (5), each member state refrains, in the case provided for in paragraph (1), from claiming from another member state the reimbursement of compensation for the damages mentioned in paragraph (4).
(7) If a joint operation is planned, and a supervisory authority does not comply, within one month, with the obligation provided for in the second sentence of paragraph (2) of this article, the other supervisory authorities may adopt a the provisional measure on the territory of the member state of that authority, in accordance with Article 55. In this case, the urgent need to act under Article 66 paragraph (1) is considered to be fulfilled and requires an urgent notice or an urgent binding decision from part of the committee, in accordance with Article 66 paragraph (2).

Section 2: Ensuring consistency
Art. 63: The mechanism for ensuring coherence
In order to contribute to the consistent application of this regulation throughout the Union, the supervisory authorities shall cooperate with each other and, as the case may be, with the Commission through the mechanism for ensuring consistency, as provided for in this section.

Art. 64: The opinion of the committee
(1) The committee issues an opinion every time a competent supervisory authority intends to adopt any of the measures below. For this purpose, the competent supervisory authority communicates the draft decision to the committee, when:
a) aims at the adoption of a list of processing operations that are subject to the requirement to carry out an impact assessment on data protection, in accordance with Article 35 paragraph (4);
b) in accordance with Article 40 paragraph (7), it refers to the compliance with this regulation of a draft code of conduct or of a modification or extension of a code of conduct;

c) aims to approve the requirements for the accreditation of a body in accordance with Article 41

paragraph (3), of a certification body in accordance with article 43 paragraph (3) or the criteria

of certification referred to in article 42 paragraph (5);

(as of May 23, 2018, Art. 64, paragraph (1), letter C. of the chapter

VII, section 2 rectified by point 18. of Rectification from

23-May-2018 )
d) aims to determine the standard data protection clauses referred to in Article 46 paragraph (2) letter (d) or in Article 28 paragraph (8);
e) aims to authorize the contractual clauses mentioned in Article 46 paragraph (3) letter (a); or f) refers to the approval of mandatory corporate rules in the sense of article 47.
(2) Any supervisory authority, the chairman of the committee or the Commission may request that any matter of general application or that produces effects in more than one member state be examined by the committee in order to obtain an opinion, especially if an authority competent supervisory authority does not respect the obligations regarding mutual assistance in accordance with Article 61 or regarding joint operations in accordance with Article 62.
(3) In the cases referred to in paragraphs (1) and (2), the committee issues an opinion regarding the issue presented to it, provided that an opinion has not already been issued regarding the same issue. The respective opinion is adopted within eight weeks with a simple majority of the committee members. This period can be extended by six weeks, taking into account the complexity of the matter. Regarding the draft decision referred to in paragraph (1) sent to the members of the committee in accordance with paragraph (5), a member who has not raised objections within a reasonable period indicated by the president is considered to agree with the draft decision.
(4) The supervisory authorities and the Commission communicate electronically to the committee, without undue delay, through a standard form, any relevant information, including, as the case may be, a summary of the facts, the draft decision, the reasons that make it necessary to adopt such a measures, as well as the opinions of other concerned supervisory authorities.

(5) The chairman of the committee informs electronically, without undue delay:
a) committee members and the Commission regarding any relevant information that was communicated to them, using a standard form. The secretariat of the committee provides translations of relevant information, where necessary; and
b) the supervisory authority mentioned, as the case may be, in paragraphs (1) and (2), and the Commission regarding the opinion and publishes it.

(6) The competent supervisory authority referred to in paragraph (1) does not adopt its draft

decision referred to in paragraph (1) within the term referred to in paragraph (3).

(on May 23, 2018 Art. 64, paragraph (6) of Chapter VII, Section 2 amended by

(7) The competent supervisory authority referred to in paragraph (1) takes full account of the opinion

item 19. of the Rectification of May 23

2018)

the committee and communicate electronically to the chairman of the committee, within two weeks of receiving the opinion, if he will keep or modify his draft decision and, if necessary,

submit the amended draft decision, using a standard form.

(on May 23, 2018 Art. 64, paragraph (7) of Chapter VII, Section 2 amended by

(8) If the competent supervisory authority referred to in paragraph (1) informs the chairman of the committee, within the term referred to in paragraph (7) of this article, that it intends not to comply with the committee's opinion, in whole or in part, giving the relevant reasons, the article applies

item 19. of the Rectification of May 23

2018)

65 paragraph (1).

(as of May 23, 2018, Art. 64, paragraph (8) of Chapter VII, Section 2, amended by point 19 of the Amendment of May 23, 2018)
Art. 65: Settlement of disputes by the committee
(1) To ensure the correct and coherent application of this regulation in individual cases, the committee adopts a binding decision in the following cases:

a) when, in one of the cases mentioned in Article 60 paragraph (4), a concerned supervisory authority has formulated a relevant and reasoned objection to a draft decision of the authority

main supervision and the main supervisory authority did not respond to the objection or rejected such an objection as not being relevant or motivated. The binding decision refers to all the issues covered by the relevant and reasoned objection, in particular to the issue of whether this regulation was

violated;

(to date

23-May-2018 Art. 65, para. (1), letter A. of chapter VII, section 2 rectified by point 20. of the Corrigendum of May 23, 2018)

b) in case there are divergent opinions regarding which of the supervisory authorities concerned holds the competence for the main headquarters;
c) if a competent supervisory authority does not request the opinion of the committee in the cases referred to in Article 64 paragraph (1) or does not take into account the opinion of the committee issued pursuant to Article 64. In this case, any supervisory authority concerned or the Commission may communicate the matter to the committee.

(2) The decision referred to in paragraph (1) shall be adopted within one month from the presentation of the matter, with a two-thirds majority of the committee members. This term can be extended by one month, taking into account the complexity of the matter. The decision referred to in paragraph (1) is motivated and addressed to the main supervisory authority and all the supervisory authorities concerned, being binding for them.

(3) If the committee was not able to adopt a decision within the terms mentioned in paragraph (2), it adopts its decision within two weeks from the date of expiry of the second month mentioned in paragraph (2) , with a simple majority of its members. If the members of the committee have divergent opinions in equal proportions, the decision is adopted by the vote of the president. (4) The concerned supervisory authorities do not adopt a decision on the matter presented to the committee in accordance with paragraph (1) within the terms mentioned in paragraphs (2) and (3).

(5) The chairman of the committee shall notify, without undue delay, the decision referred to in paragraph (1) to the concerned supervisory authorities. The Committee informs the Commission about this. The decision is published on the committee's website, without delay, after notification by the supervisory authority of the final decision referred to in paragraph (6).

(6) The main supervisory authority or, if applicable, the supervisory authority to which the complaint was submitted shall adopt its final decision based on the decision referred to in paragraph (1) of this article, without undue delay and within no more than a month from the notification by the committee of its decision. The main supervisory authority or, if applicable, the supervisory authority to which the complaint was submitted informs the committee about the date on which its final decision is notified to the operator or the person authorized by the operator and, respectively, the person concerned. The final decision of the concerned supervisory authorities is adopted in accordance with the conditions stipulated in Article 60 paragraphs (7), (8) and (9). The final decision refers to the decision referred to in paragraph (1) of this article and states that the decision referred to in that paragraph will be published on the website of the committee, in accordance with paragraph (5). The decision referred to in paragraph (1) of this article is attached to the final decision.

Art. 66: Emergency procedure
(1) In exceptional circumstances, when a concerned supervisory authority considers that there is an urgent need to act in order to protect the rights and freedoms of the concerned persons, it may, by way of derogation from the mechanism for ensuring coherence referred to in articles 63, 64 and 65 or from the procedure referred to in article 60, to immediately adopt provisional measures intended to produce legal effects on its own territory, with a determined period of validity, not to exceed three months. The supervisory authority communicates without delay these measures and the reasons for their adoption to the other supervisory authorities concerned, the committee and the Commission.

(2) If a supervisory authority has adopted a measure pursuant to paragraph (1) and considers that it is necessary to urgently adopt definitive measures, it may request an urgent opinion or an urgent binding decision from the committee, indicating the reasons for this request.

(3) Any supervisory authority may request an urgent opinion or an urgent binding decision, as the case may be, from the committee if a competent supervisory authority has not taken an appropriate measure in a situation where there is an urgent need to act to protect the rights and freedoms of the persons concerned, indicating the reasons for requesting such an opinion or such a decision, including the urgent need to act.

(4) By way of derogation from Article 64, paragraph (3) and from Article 65, paragraph (2), an urgent notice or an urgent binding decision referred to in paragraphs (2) and (3) of this article is adopted within two weeks with a simple majority of the committee members.
Art. 67: Exchange of information

The Commission may adopt implementing acts with a general scope to define the modalities for the electronic exchange of information between the supervisory authorities, as well as between the supervisory authorities and the committee, in particular the standard form referred to in Article 64. respective implementation are adopted in accordance with the examination procedure referred to in Article 93 paragraph (2).

Section 3: European Data Protection Board
Art. 68: European Committee for Data Protection
(1) The European Committee for Data Protection (the "Committee") is established as a body of the Union and has legal personality.
(2) The committee is represented by its president.
(3) The Committee is composed of the head of a supervisory authority from each member state and the European Data Protection Authority or their respective representatives.
(4) If in a member state several supervisory authorities are responsible for monitoring the application of the provisions adopted under this regulation, a common representative is appointed in accordance with the internal law of the respective member state.
(5) The commission has the right to participate in the committee's activities and meetings without having the right to vote. The commission appoints a representative. The chairman of the committee communicates the activities of the committee to the Commission. (6) In the cases referred to in article 65, the European Data Protection Authority has the right to vote only on the decisions that concern the principles and applicable rules regarding the institutions, bodies, offices and agencies of the Union that correspond in substance to those of the present regulations.
Art. 69: Independence
(1) The committee acts independently in fulfilling its tasks or exercising its powers in accordance with articles 70 and 71.

(2) Without prejudice to the requests from the Commission mentioned in Article 70 paragraphs (1) and (2), the committee, in fulfilling its tasks or exercising its powers, does not request or accept

instructions from any outside party.

(on May 23, 2018, Art. 69, paragraph (2) of

chapter VII, section 3 corrected by point 21. of the Correction of May 23

2018)
Art. 70: Tasks of the committee
(1) The committee ensures the consistent application of this regulation. For this purpose, on its own initiative or, as the case may be, at the request of the Commission, the committee has, in particular, the following tasks:
a) to monitor and ensure the correct application of this regulation, in the cases provided for in articles 64 and 65, without prejudice to the tasks of the national supervisory authorities;
b) to provide advice to the Commission on any aspect related to the protection of personal data within the Union, including any proposal to amend this regulation;
c) to provide advice to the Commission on the format and procedures for the exchange of information between operators, persons authorized by operators and supervisory authorities for mandatory corporate rules;

d) to issue guidelines, recommendations and best practices regarding the procedures for deleting links to personal data, their copies or reproductions available to publicly accessible communications services, as mentioned in Article 17 paragraph (2);
e) to examine, on its own initiative, at the request of one of its members or at the request of the Commission, any issue related to the application of this regulation and to issue guidelines, recommendations and best practices to encourage the consistent application of this regulation;

f) to issue guidelines, recommendations and best practices in accordance with this paragraph letter (e) in order to detail the criteria and conditions for decisions based on the creation of profiles referred to in Article 22 paragraph (2);
g) to issue guidelines, recommendations and best practices in accordance with letter (e) of this paragraph for the determination of personal data security breaches and the determination of unjustified delays referred to in Article 33 paragraphs (1) and (2), as well as for special circumstances in which an operator or a person authorized by the operator has the obligation to notify the breach of personal data security;

h) to issue guidelines, recommendations and good practices in accordance with letter (e) of this paragraph regarding the circumstances in which a breach of the security of personal data is likely to generate a high risk for the rights and freedoms of natural persons, mentioned in article 34 paragraph (1);

i) to issue guidelines, recommendations and best practices in accordance with letter (e) of this paragraph in order to detail the criteria and requirements applicable to transfers of personal data based on the mandatory corporate rules that must be respected by operators and those that must be respected by individuals authorized by the operators, as well as regarding the additional requirements necessary to ensure the protection of the personal data of the data subjects referred to in article 47;

j) to issue guidelines, recommendations and best practices in accordance with letter (e) of this paragraph in order to detail the criteria and requirements for the transfers of personal data referred to in Article 49 paragraph (1);
k) to develop guidelines for the supervisory authorities, regarding the application of the measures mentioned in Article 58 paragraphs (1), (2) and (3) and to establish administrative fines in accordance with Article 83;

l 22. from Correction from

23-May-2018 )
m) to issue guidelines, recommendations and good practices in accordance with letter (e) of this paragraph in order to establish common reporting procedures by natural persons of violations of this regulation in accordance with Article 54 paragraph (2);
n) to encourage the development of codes of conduct and the establishment of certification mechanisms, as well as seals and marks in the field of data protection, in accordance with articles 40 and 42;

l) to review the practical application of guidelines, recommendations and good practices; (on May 23, 2018 Art. 70, paragraph (1), letter L. of chapter VII, section 3 amended by point

o) to approve the certification criteria pursuant to Article 42 paragraph (5) and to keep a public register of

certification mechanisms and data protection seals and marks, pursuant to Article 42 paragraph (8), and certified operators or persons authorized by operators

certificates, established (established) in third countries, pursuant to Article 42 paragraph (7);

(on May 23, 2018 Art. 70, paragraph (1), letter O. of chapter VII, section 3 rectified by p

unctul 23. from Rectification from

23-May-2018 )

p) to approve the requirements mentioned in article 43 paragraph (3), in order to accredit the bodies of

certification referred to in article 43;

(as of May 23, 2018, Art. 70, paragraph (1), lit

ra P. from chapter VII, section 3 rectified by point 24. from Rectification from

23-May-2018 )
q) to submit an opinion to the Commission regarding the certification requirements referred to in Article 43 paragraph (8); r) to submit an opinion to the Commission regarding the pictograms referred to in Article 12 paragraph (7);
s) to submit an opinion to the Commission for the assessment of the adequacy of the level of protection in a third country or an international organization, including to determine whether a third country, a territory, or one or more specified sectors of that third country, or an international organization no longer ensures an adequate level of protection. For this purpose, the Commission makes available to the committee all

the necessary documentation, including the correspondence carried out with the public authorities of the third country, regarding that third country, that territory or that sector, or with the international organization;
t) to issue opinions on the draft decisions of the supervisory authorities in accordance with the mechanism for ensuring consistency referred to in Article 64 paragraph (1) regarding matters presented in accordance with Article 64 paragraph (2) and to issue binding decisions pursuant to Article 65, including in the cases mentioned in article 66;

u) to promote cooperation and efficient bilateral and multilateral exchange of information and best practices between supervisory authorities;
v) to promote joint training programs and facilitate personnel exchanges between supervisory authorities, as well as, as the case may be, with supervisory authorities of third countries or international organizations;

w) to promote the exchange of knowledge and documents regarding data protection legislation and practices with data protection supervisory authorities worldwide;
x) to issue opinions regarding the codes of conduct developed at the Union level pursuant to Article 40 paragraph (9); and

y) to keep an electronic register accessible to the public with the decisions taken by the supervisory authorities and the courts regarding matters dealt with within the mechanism for ensuring coherence.
(2) If the Commission consults the committee, it may indicate a deadline, taking into account the urgent nature of the matter.

(3) The committee transmits its opinions, guidelines, recommendations and good practices to the Commission and the committee referred to in article 93 and makes them public.
(4) If necessary, the committee consults the interested parties and offers them the opportunity to make observations within a reasonable time. Without prejudice to the provisions of article 76, the committee publishes the results of the consultation procedure.

Art. 71: Reports
(1) The Committee prepares an annual report on the protection of natural persons with regard to processing in the Union and, if relevant, in third countries and international organizations. The report is made available to the public and sent to the European Parliament, the Council and the Commission.
(2) The annual report includes a review of the practical application of the guidelines, recommendations and good practices referred to in Article 70 paragraph (1) letter (l), as well as the mandatory decisions referred to in Article 65.
Art. 72: Procedure
(1) The Committee adopts decisions by a simple majority of its members, unless otherwise provided in this regulation.
(2) The committee adopts its own rules of procedure with a two-thirds majority of its members and organizes its own functioning mechanisms.
Art. 73: The President
(1) The committee elects a president and two vice-presidents from among its members, with a simple majority. (2) The mandate of the president and the vice-presidents is five years and can be renewed only once.
Art. 74: Duties of the president
(1) The President has the following duties:
a) to convene committee meetings and establish the agenda;
b) to notify the decisions adopted by the committee, in accordance with Article 65, to the main supervisory authorities and the concerned supervisory authorities;
c) to ensure the timely fulfillment of the committee's tasks, especially with regard to the mechanism for ensuring coherence referred to in article 63.
(2) The committee establishes in its regulation and procedure the distribution of tasks between the president and vice-presidents.
Art. 75: The Secretariat
(1) The committee has a secretariat, which is ensured by the European Data Protection Authority.
(2) The secretariat performs its tasks exclusively based on the instructions of the committee president.

(3) The staff of the European Data Protection Authority involved in the performance of the tasks assigned to the committee under this regulation are the subject of separate reporting lines in relation to the staff involved in the performance of the tasks assigned to the European Data Protection Authority. (4) If appropriate, the committee and the European Data Protection Authority draw up and publish a memorandum of understanding for the implementation of this article, which will establish the conditions of cooperation and apply to the staff of the European Data Protection Authority involved in fulfilling the tasks assigned to the committee under this regulation. (5) The secretariat provides analytical, administrative and logistical support to the committee.

(6) The Secretariat is particularly responsible for the following:
a) the current management of the committee's activities;
b) communication between the members of the committee, its president and the Commission;
c) communication with other institutions and the public;
d) the use of electronic means for internal and external communication;
e) translation of relevant information;
f) preparing and monitoring the actions following the committee meetings;
g) preparing, drafting and publishing opinions, decisions regarding the settlement of disputes between supervisory authorities and other texts adopted by the committee.
Art. 76: Confidentiality
(1) Discussions within the committee are confidential if the committee considers this to be necessary in accordance with the regulation or procedure.

(2) Access to the documents presented to committee members, experts and representatives of third parties is regulated by Regulation (EC) no. 1049/2001 of the European Parliament and of the Council (1).
(1) Regulation (EC) no. 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43).

CHAPTER VIII: Remedies, liability and sanctions
Art. 77: The right to file a complaint with a supervisory authority
(1) Without prejudice to any other administrative or judicial remedies, any data subject has the right to file a complaint with a supervisory authority, in particular in the Member State in which he has his usual residence, in which his place of business is located of work or where the alleged violation took place, if it considers that the processing of personal data concerning it violates this regulation.
(2) The supervisory authority to which the complaint was submitted informs the complainant about the progress and outcome of the complaint, including the possibility of exercising a judicial appeal pursuant to Article 78.
Art. 78: The right to an effective judicial appeal against a supervisory authority
(1) Without prejudice to any other administrative or non-judicial remedies, every natural or legal person has the right to exercise an effective judicial remedy against a legally binding decision of a supervisory authority that concerns him.
(2) Without prejudice to any other administrative or non-judicial remedies, each data subject has the right to exercise an effective judicial remedy if the supervisory authority which is competent under Articles 55 and 56 does not deal with a complaint or does not inform the person concerned within three months about the progress or the resolution of the complaint submitted under Article 77.
(3) Actions brought against a supervisory authority are brought before the courts of the member state in which the supervisory authority is established.
(4) If the actions are brought against a decision of a supervisory authority that was preceded by an opinion or a decision of the committee within the mechanism for ensuring coherence, the supervisory authority submits the respective opinion or decision to the court.

Art. 79: The right to an effective judicial appeal against an operator or a person authorized by the operator
(1) Without prejudice to any available administrative or non-judicial remedy, including the right to file a complaint with a supervisory authority under Article 77, each data subject has the right to an effective judicial remedy if who considers that the rights he benefits from under this regulation have been violated as a result of the processing of his personal data without complying with this regulation.

(2) Actions brought against an operator or a person authorized by the operator are presented before the courts of the member state where the operator or person authorized by the operator has its headquarters. Alternatively, such an action can be brought before the courts of the member state where the person concerned has his or her habitual residence, unless the operator or the person authorized by the operator is a public authority of a member state acting in the exercise of its public powers .

Art. 80: Representation of the concerned persons
(1) The person concerned has the right to mandate a non-profit body, organization or association, which have been properly established in accordance with domestic law, whose statutory objectives are of public interest, which are active in the field of protection the rights and freedoms of the data subjects regarding the protection of their personal data, to file the complaint on their behalf, to exercise on their behalf the rights mentioned in articles 77, 78 and 79, as well as to exercise the right to receive compensation mentioned in the article 82 in the name of the person concerned, if this is provided for in domestic law.
(2) The member states may provide that any body, organization or association referred to in paragraph (1) of this article, independent of the mandate of a concerned person, has the right to submit a complaint in the respective member state to the supervisory authority that is competent in pursuant to Article 77 and to exercise the rights referred to in Articles 78 and 79, if it considers that the rights of a data subject pursuant to this regulation have been violated as a result of the processing.
Art. 81: Suspension of proceedings
(1) If a competent court of a member state has information that an action with the same object is pending before a court from another member state regarding the processing activities of the same operator or of the same person authorized by operator, the respective court contacts the court in the other member state to confirm the existence of such actions.
(2) When an action with the same object is pending before a court from another member state regarding the processing activities of the same operator or of the same person authorized by the operator, any other competent court than the initially notified court may suspend the action pending with her.
(3) If such an action is tried in the first court, any court subsequently referred may also, at the request of one of the parties, decline its jurisdiction, provided that the said action falls under the jurisdiction of the first court referred and that the law applicable to it allows the connection of actions.
Art. 82: The right to compensation and liability
(1) Any person who has suffered material or moral damage as a result of a violation of this regulation has the right to obtain compensation from the operator or from the person authorized by the operator for the damage suffered.
(2) Any operator involved in the processing operations is responsible for the damage caused by his processing operations that violate this regulation. The person authorized by the operator is responsible for the damage caused by the processing only if he did not comply with the obligations of this regulation that fall specifically to the persons authorized by the operator or acted outside of or in contradiction with the legal instructions of the operator.

(3) The operator or the person authorized by the operator is exonerated from liability pursuant to paragraph (2) if he proves that he is not responsible in any way for the event that caused the damage.
(4) If several operators or several persons authorized by the operator, or an operator and a person authorized by the operator are involved (involved) in the same processing operation and answer, pursuant to paragraphs (2) and (3) , for any damage caused by the processing, each operator or person authorized by the operator is responsible (responsible) for the entire damage to ensure the effective compensation of the person concerned.

(5) In the event that an operator or a person authorized by the operator has paid, in accordance with paragraph (4), in full the compensation for the damage caused, the respective operator or the respective person authorized by the operator has the right to request from the other operators or the other persons authorized by the operator involved in the same processing operation to recover that part of the compensation that corresponds to their part of responsibility for the damage, in accordance with the conditions established in paragraph (2).

(6) Actions for the exercise of the right to recover the compensations paid are submitted to the competent courts based on the law of the member state referred to in Article 79 paragraph (2).
Art. 83: General conditions for imposing administrative fines
(1) Each supervisory authority ensures that the imposition of administrative fines in accordance with this article for the violations of this regulation referred to in paragraphs (4), (5) and (6) is, in each case, effective, proportionate and dissuasive.

(2) Depending on the circumstances of each individual case, administrative fines are imposed in addition to or instead of the measures mentioned in Article 58 paragraph (2), letters (a)-(h) and (j). When the decision is made whether to impose an administrative fine and the decision regarding the amount of the administrative fine in each individual case, due attention is paid to the following aspects:

a) the nature, seriousness and duration of the violation, taking into account the nature, scope or purpose of the processing in question, as well as the number of data subjects affected and the level of damages suffered by them;
b) if the violation was committed intentionally or through negligence;

c) any actions taken by the operator or the person authorized by the operator to reduce the damage suffered by the person concerned;
d) the degree of responsibility of the operator or the person authorized by the operator, taking into account the technical and organizational measures implemented by them pursuant to articles 25 and 32; e) any previous relevant violations committed by the operator or the person authorized by the operator;

f) the degree of cooperation with the supervisory authority to remedy the violation and mitigate the possible negative effects of the violation;
g) the categories of personal data affected by the breach;
h) the way in which the violation was brought to the attention of the supervisory authority, especially if and to what extent the operator or the person authorized by the operator notified the violation;

i) if the measures referred to in Article 58 paragraph (2) were previously ordered against the operator or the person authorized by the operator in the case with regard to the same object, compliance with those measures;
j) adherence to approved codes of conduct, in accordance with article 40, or to approved certification mechanisms, in accordance with article 42; and

k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as the financial benefits acquired or losses avoided directly or indirectly as a result of the violation.
(3) If an operator or a person authorized by the operator violates intentionally or through negligence, for the same processing operation or for related processing operations, several provisions of this regulation, the total amount of the administrative fine cannot exceed the amount provided for the most serious violation.

(4) For violations of the following provisions, in accordance with paragraph (2), administrative fines of up to EUR 10 or, in the case of an enterprise, up to 000% of the figure of

total annual worldwide business corresponding to the previous financial year, taking into account the highest value:
a) the obligations of the operator and the person authorized by the operator in accordance with articles 8, 11, 25-39, 42 and 43;

b) the certification body's obligations in accordance with articles 42 and 43;
c) the obligations of the monitoring body in accordance with Article 41 paragraph (4).
(5) For violations of the following provisions, in accordance with paragraph (2), administrative fines of up to EUR 20 or, in the case of an enterprise, up to 000% of the total annual worldwide turnover corresponding to the previous financial year are applied , taking into account the highest value:
a) the basic principles for processing, including the conditions regarding consent, in accordance with articles 5, 6, 7 and 9;
b) the rights of the persons concerned in accordance with articles 12-22;
c) transfers of personal data to a recipient from a third country or an international organization, in accordance with articles 44-49;
d) any obligations under the national legislation adopted under Chapter IX;
e) failure to comply with an order or a temporary or definitive limitation on processing, or suspension of data flows, issued by the supervisory authority pursuant to Article 58 paragraph (2), or failure to grant access, in violation of Article 58 paragraph (1).
(6) Administrative fines of up to EUR 58 shall be applied in accordance with paragraph (2) of this article for the violation of an order issued by the supervisory authority in accordance with Article 2 paragraph (20) or, in the case of an enterprise , up to 000% of the total annual worldwide turnover corresponding to the previous financial year, taking into account the highest value. (000) Without prejudice to the corrective powers of the supervisory authorities referred to in Article 4 paragraph (7), each member state may provide rules to establish whether and to what extent administrative fines may be imposed on public authorities and public bodies established in the respective member state.
(8) The exercise by the supervisory authority of its powers under this article takes place on condition of the existence of adequate procedural guarantees in accordance with Union law and domestic law, including effective judicial appeals and the right to a fair trial.
(9) If the legal system of the member state does not provide for administrative fines, this article can be applied so that the fine is initiated by the competent supervisory authority and imposed by the competent national courts, guaranteeing, at the same time, the fact that these appeals are effective and have an effect equivalent to that of the administrative fines imposed by the supervisory authorities. In any case, the fines imposed must be effective, proportionate and dissuasive. The respective member states shall inform the Commission of the provisions of domestic law that they adopt pursuant to this paragraph by May 25, 2018, as well as, without delay, of any amending legislative act or any subsequent amendment thereof.

Art. 84: Sanctions
(on Dec. 29, 2017, Art. 84 of Chapter VIII was related to Regulation 2226/Nov. 30, 2017)

(1) Member States shall lay down the rules on other sanctions applicable in case of infringement of this Regulation, in particular for infringements which are not subject to administrative fines under Article 83, and shall take all necessary measures to guarantee that they are implemented . The respective sanctions are effective, proportionate and dissuasive.

(2) Each member state informs the Commission about the provisions of domestic law that it adopts pursuant to paragraph (1) until May 25, 2018, as well as, without delay, about any subsequent modification thereof.
CHAPTER IX: Provisions regarding specific processing situations

Art. 85: Processing and freedom of expression and information
(1) Through internal law, the member states ensure a balance between the right to the protection of personal data under this regulation and the right to freedom of expression and

of information, including processing for journalistic purposes or for the purpose of academic, artistic or literary expression.
(2) For the processing carried out for journalistic purposes or for the purpose of academic, artistic or literary expression, the member states provide exemptions or derogations from the provisions of chapter II (principles), of chapter III (the rights of the data subject), of chapter IV (the operator and the person authorized by the operator), of chapter V (transfer of personal data to third countries or international organizations), of chapter VI (independent supervisory authorities), of chapter VII (cooperation and coherence) and of chapter IX (specific situations of data processing data) if they are necessary to ensure a balance between the right to the protection of personal data and the freedom of expression and information.

(3) Each member state informs the Commission about the provisions of domestic law that it has adopted pursuant to paragraph (2) as well as, without delay, about any legislative act amending or any subsequent amendment thereof.
Art. 86: Processing and public access to official documents

Personal data from official documents held by a public authority or a public or private body for the performance of a task that serves the public interest may be disclosed by that authority or body in accordance with Union law or with the internal law under which the authority or the body, in order to establish a balance between public access to official documents and the right to the protection of personal data under this regulation.

Art. 87: Processing of a national identification number
Member States may further detail the specific conditions for processing a national identification number or any other identifier with general applicability. In this case, the national identification number or any other identifier with general applicability is used only on the basis of appropriate guarantees for the rights and freedoms of the person concerned under this regulation.
rt. 88: Processing in the context of employment
(1) By law or through collective agreements, member states may provide more detailed rules to ensure the protection of rights and freedoms regarding the processing of personal data of employees in the context of employment, especially for the purpose of recruitment, of the fulfillment of the clauses of the employment contract, including the discharge of the obligations established by law or by collective agreements, of the management, planning and organization of work, of equality and diversity at the workplace, of ensuring health and safety at the workplace, of protecting the employer's property or of the client, as well as for the purpose of exercising and benefiting, individually or collectively, from the rights and benefits related to employment, as well as for the termination of employment relationships.
(2) These rules include appropriate and specific measures to guarantee the human dignity, legitimate interests and fundamental rights of the persons concerned, especially with regard to the transparency of the processing, the transfer of personal data within a group of companies or a group of enterprises involved in a common economic activity and monitoring systems at the workplace.
(3) Each member state informs the Commission about the provisions of domestic law that it adopts pursuant to paragraph (1) until May 25, 2018, as well as, without delay, about any subsequent modification thereof.
Art. 89: Guarantees and waivers regarding processing for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes
(1) Processing for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes takes place under the condition of the existence of appropriate guarantees, in accordance with this regulation, for the rights and freedoms of the persons concerned. The respective guarantees ensure that the necessary technical and organizational measures have been established to ensure, in particular, compliance with the principle of data minimization. These measures may include pseudonymization, provided that the respective purposes are fulfilled in this way. When the respective purposes can be fulfilled through a subsequent processing that does not allow or no longer allows the identification of the persons concerned, the respective purposes are fulfilled in this way.

(2) In the event that personal data are processed for scientific or historical research purposes or for statistical purposes, Union law or domestic law may provide for exemptions from the rights mentioned in articles 15, 16, 18 and 21, subject to the conditions and guarantees provided in paragraph (1) of this article, to the extent that the respective rights are of a nature to make it impossible or to seriously affect the achievement of the specific goals, and the respective derogations are necessary for the fulfillment of these goals.

(3) If personal data are processed for archiving purposes in the public interest, Union law or domestic law may provide for exemptions from the rights mentioned in articles 15, 16, 18, 19, 20 and 21, subject to the conditions and guarantees provided in paragraph (1) of this article, to the extent that the respective rights are of a nature to make it impossible or to seriously affect the achievement of the specific goals, and the respective derogations are necessary for the fulfillment of these goals.

(4) If the processing mentioned in paragraphs (2) and (3) serves another purpose at the same time, the derogations apply only to the processing for the purposes mentioned in the respective paragraphs.
Art. 90: Obligations regarding confidentiality
(1) Member States may adopt specific rules to establish the powers of the supervisory authorities, provided for in Article 58 paragraph (1) letters (e) and (f), in relation to operators or persons authorized by operators who, under Union law or of domestic law or under the rules established by the competent national bodies, have the obligation to maintain professional secrecy or other equivalent obligations of confidentiality, if this is necessary and proportionate to establish a balance between the right to the protection of personal data personal and the obligation to maintain confidentiality. The respective rules apply only with regard to the personal data that the operator or the person authorized by the operator received as a result of or in the context of an activity that falls under this confidentiality obligation. (2) Each member state shall notify the Commission of the rules adopted pursuant to paragraph (1) by May 25, 2018, as well as, without delay, any subsequent modification thereof.

Art. 91: Existing norms in the field of data protection for churches and religious associations
(1) If, in a member state, churches and religious associations or communities apply, at the date of entry into force of this regulation, a comprehensive set of rules for the protection of natural persons with regard to processing, these rules may continue to apply, provided they are aligned with this regulation.

(2) Churches and religious associations that apply a comprehensive set of rules in accordance with paragraph (1) of this article are subject to the supervision of an independent supervisory authority that may be specified, provided that they meet the conditions established in Chapter VI of this regulation.

CHAPTER X: Delegated acts and implementing acts
Art. 92: Exercise of delegation
(1) The competence to adopt delegated acts is conferred on the Commission under the conditions provided by this article.
(2) The delegation of powers provided for in Article 12 paragraph (8) and Article 43 paragraph (8) is conferred on the Commission for an indefinite period from May 24, 2016.
(3) The delegation of powers referred to in Article 12 paragraph (8) and Article 43 paragraph (8) may be revoked at any time by the European Parliament or the Council. A revocation decision puts an end to the delegation of powers specified in the respective decision. The decision takes effect from the day following its publication in the Official Journal of the European Union or from a later date mentioned in the decision. The decision does not affect the validity of the delegated acts that are already in force.
(4) As soon as it adopts a delegated act, the Commission shall simultaneously notify the European Parliament and the Council.
(5) A delegated act adopted in accordance with Article 12(8) and Article 43(8) shall enter into force only if neither the European Parliament nor the Council has raised objections within three months of notification of it to the European Parliament and the Council, or in

if, before the expiry of the respective term, the European Parliament and the Council have informed the Commission that they will not raise objections. The respective term is extended by three months at the initiative of the European Parliament or the Council.
Art. 93: Committee procedure

(1) The commission is assisted by a committee. The respective committee is a committee within the meaning of Regulation (EU) no. 182/2011.
(2) If reference is made to this paragraph, Article 5 of Regulation (EU) no. 182/2011.

(3) If reference is made to this paragraph, Article 8 of Regulation (EU) no. 182/2011 in conjunction with article 5 of that regulation.
CHAPTER XI: Final provisions
Art. 94: Repeal of Directive 95/46/CE

(1) Decision 95/46/EC is repealed with effect from May 25, 2018.
(2) References to the repealed directive are interpreted as references to this regulation. References to the Working Group for the protection of individuals with regard to the processing of personal data established by Article 29 of Directive 95/46/EC are interpreted as references to the European Data Protection Committee established by this regulation.
Art. 95: Relationship with Directive 2002/58/EC
This regulation does not impose additional obligations on natural or legal persons with regard to processing in connection with the provision of electronic communications services intended for the public in public communications networks in the Union, with regard to the aspects for which they have specific obligations with the same intended objective in Directive 2002/58/EC.
Art. 96: Relationship with previously concluded agreements
International agreements involving the transfer of personal data to third countries or international organizations, which were concluded by the member states before May 24, 2016 and which are in accordance with the Union law applicable before that date, remain in force until they are modified, replaced or revoked.
Art. 97: Commission reports
(1) Until May 25, 2020 and, thereafter, every four years, the Commission shall submit to the European Parliament and the Council a report on the evaluation and revision of this regulation. The reports are made public.
(2) In the context of the evaluations and revisions referred to in paragraph (1), the Commission examines in particular the application and operation of:
a) chapter V regarding the transfer of personal data to third countries or international organizations, taking into account in particular the decisions adopted pursuant to article 45 paragraph (3) of this regulation and the decisions adopted pursuant to article 25 paragraph (6) of Directive 95/ 46/CE;
b) chapter VII regarding cooperation and coherence.
(3) For the purpose of paragraph (1), the Commission may request information from the member states and from the supervisory authorities.
(4) When carrying out the evaluations and revisions referred to in paragraphs (1) and (2), the Commission takes into account the positions and findings of the European Parliament, the Council, as well as other relevant bodies or sources.
(5) The commission submits, if necessary, appropriate proposals to amend this regulation, especially taking into account developments in the field of information technology and taking into account the progress of the information society.
Art. 98: Revision of other legal acts of the Union in matters of data protection
If necessary, the Commission presents legislative proposals in order to modify other legal acts of the Union regarding the protection of personal data, in order to ensure a uniform and consistent protection of natural persons in terms of processing. This concerns in particular the rules relating to the protection of natural persons in terms of processing by the institutions, bodies, offices and agencies of the Union, as well as the rules relating to the free circulation of these data.

Art. 99: Entry into force and application
(1) This regulation enters into force on the twentieth day from the date of publication in the Official Journal of the European Union.
(2) This regulation applies from May 25, 2018.
This regulation is mandatory in all its elements and applies directly in all member states.
-****-
Done at Brussels, 27 April 2016.

JA HENNIS-PLASSCHAERT

Published in the Official Journal number 119L of May 4, 2016

For the European Parliament the President
M SCHULZ
For the Council the President