83 Amendments of Sophia IN 'T VELD related to 2012/0010(COD)
Amendment 203 #
Proposal for a directive
Recital 27
Recital 27
(27) Every natural person should have the right not to be subject to a measure which is based solely onon partially or fully automated processing if it produces an adverse legal effect for that person, or significantly affects them, unless authorised by law and subject to suitable measures to safeguard the data subject's legitimate interests.
Amendment 212 #
Proposal for a directive
Recital 30
Recital 30
(30) The principle of fair and transparent processing requires that the data subjects should be informed in particular of the existence of the processing operation and its purposes, its legal ground, how long the data will be stored, on the existence of the right of access, rectification or erasure and on the right to lodge a complaint. Where the data are collected from the data subject, the data subject should also be informed whether they are obliged to provide the data and of the consequences, in cases they do not provide such data.
Amendment 222 #
Proposal for a directive
Recital 40 a (new)
Recital 40 a (new)
(40a) A data protection impact assessment should be carried out by the controller or processor, where the processing operations are likely to present specific risks to the rights and freedoms of data subjects by virtue of their nature, their scope or their purposes, which should include in particular the envisaged measures, safeguards and mechanisms to ensure the protection of personal data and for demonstrating compliance with this Directive.
Amendment 224 #
Proposal for a directive
Recital 41
Recital 41
(41) In order to ensure effective protection of the rights and freedoms of data subjects by way of preventive actions, the controller or processor should consult with the supervisory authority in certain cases prior to the processing. Moreover, where a data protection impact assessment indicates that processing operations are likely to present a high degree of specific risks to the rights and freedoms of data subjects, the supervisory authority should be in a position to prevent, prior to the start of operations, a risky processing which is not in compliance with this Directive.
Amendment 247 #
Proposal for a directive
Recital 65 a (new)
Recital 65 a (new)
(65a) Transmission of personal data to other authorities or private parties in the Union is prohibited unless the transmission is in compliance with law, and the recipient is established in a Member State, and no legitimate specific interests of the data subject prevent transmission, and the transmission is necessary in a specific case for the controller transmitting the data for either the performance of a task lawfully assigned to it, or the prevention of an immediate and serious danger to public security, or the prevention of serious harm to the rights of individuals. The controller should inform the recipient of the purpose of the processing. The recipient should also be informed of processing restrictions and ensure that they are met.
Amendment 270 #
Proposal for a directive
Article 2 – paragraph 3 – point b
Article 2 – paragraph 3 – point b
Amendment 274 #
Proposal for a directive
Article 3 – paragraph 1 – point 1
Article 3 – paragraph 1 – point 1
(1) ‘'data subject’' means an identified natural person or a natural person who can be identified or singled out, directly or indirectly, alone or in combination with associated data, by means reasonably likely to be used by the controller or by any other natural or legal person, in particular by reference to a unique identifier, an identification numbercode, location data, online identifiers or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or, social identityor gender identity or sexual orientation of that person;
Amendment 292 #
Proposal for a directive
Article 4 – paragraph 1 – point a
Article 4 – paragraph 1 – point a
(a) processed lawfully, fairly and lawfullyin a transparent manner in relation to the data subject;
Amendment 299 #
Proposal for a directive
Article 4 – paragraph 1 – point c
Article 4 – paragraph 1 – point c
(c) adequate, relevant, and not exlimited to the minimum necessiveary in relation to the purposes for which they are processed; they shall only be processed if, and as long as, the purpose could not be achieved by less intrusive means;
Amendment 300 #
Proposal for a directive
Article 4 – paragraph 1 – point d
Article 4 – paragraph 1 – point d
(d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;
Amendment 304 #
Proposal for a directive
Article 4 – paragraph 1 – point e
Article 4 – paragraph 1 – point e
(e) kept in a form which permits identification, or the singling out, of data subjects for no longer than it is necessary for the purposes for which the personal data are processed;
Amendment 306 #
Proposal for a directive
Article 4 – paragraph 1 – point f – introductory part
Article 4 – paragraph 1 – point f – introductory part
(f) processed under the responsibility and liability of the controller, who shall ensure and be able to demonstrate, for each processing operation, compliance with the provisions adopted pursuant to this Directive.
Amendment 311 #
Proposal for a directive
Article 4 – subparagraph 1 a (new)
Article 4 – subparagraph 1 a (new)
Member States shall provide that competent authorities may only have access to personal data initially processed for purposes other than those referred to in Article 1(1) if they are specifically authorised by Union or national law which must meet the requirements set out in Article 7(1a) and must provide that: (a) access is allowed only by duly authorised staff of the competent authorities in the performance of their tasks where, in a specific case, the competent authority can demonstrate that the processing of the personal data is necessary and proportionate for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties; (b) requests for access must be in writing, reasoned and refer to the legal ground for the request; and (c) the written request must documented; and (d) appropriate safeguards are implemented to ensure the protection of fundamental rights and freedoms in relation to the processing of personal data. Those safeguards shall be without prejudice to and complementary to specific conditions of access to personal data such as judicial authorisation in accordance with national law.
Amendment 318 #
Proposal for a directive
Article 5 – paragraph 1 – introductory part
Article 5 – paragraph 1 – introductory part
1. Member States shall provide that, as far as possible, the controller makes a clear distinction between personal data of different categories of data subjects, such as:
Amendment 323 #
Proposal for a directive
Article 5 – paragraph 1 – point d
Article 5 – paragraph 1 – point d
(d) third parties to the criminal offence, such as persons who might be called on to testify in investigations in connection with criminal offences or subsequent criminal proceedings, or a person who can provide information on criminal offences, or a contact or associate to one of the persons mentioned in (a) and (b); and
Amendment 327 #
Proposal for a directive
Article 5 – paragraph 1 – point e
Article 5 – paragraph 1 – point e
Amendment 349 #
Proposal for a directive
Article 7 a (new)
Article 7 a (new)
Article 7a Member States shall prohibit the processing of personal data of other persons than those referred to in paragraph 1 when such processing is done for preventive purposes or in order to have data available for possible further use, unless: (a) the purpose is indispensable for a legitimate, well-defined and specific purpose; (b) the processing is strictly limited to a period not exceeding the time needed for the specific data processing operation; (c) any further use for other purposes is prohibited; (d) the controller is able to demonstrate the fulfilment of the requirements set out in (a) and (b) of this paragraph; and (e) the purpose cannot be achieved by less intrusive means.
Amendment 364 #
Proposal for a directive
Article 9 – paragraph 1
Article 9 – paragraph 1
1. Member States shall provide that every data subject has the right not to be subject to a measures which produces an adverse legal effect for the data subjectconcerning this natural person, or significantly affects themis natural person, and which areis based solely onon partially or fully automated processing of personal data intended to evaluate certain personal aspects relating to the data subject shall be prohibited unless authorised by a law which also lays down measures to safeguard the data subject's legitimate interestsis natural person.
Amendment 366 #
Proposal for a directive
Article 9 – paragraph 1 a (new)
Article 9 – paragraph 1 a (new)
1a. Subject to the other provisions of this Directive, a natural person may be subjected to a measure of the kind referred to in paragraph 1 only if the processing is expressly authorized by a Union or Member State law which also lays down suitable measures to safeguard the data subject's legitimate interest.
Amendment 400 #
Proposal for a directive
Article 11 – paragraph 5
Article 11 – paragraph 5
5. Member States may determine categories of data processing which may wholly or partly fall under the exemptions ofshall provide that the controller shall assess, in each specific case, by means of a concrete and individual examination, whether a partial or complete restriction for one of the reasons referred to in paragraph 4 applies.
Amendment 410 #
Proposal for a directive
Article 12 – paragraph 1 – point g a (new)
Article 12 – paragraph 1 – point g a (new)
(ga) the significance and envisaged consequences of such processing, at least in the case of the measures referred to in Article 9.
Amendment 415 #
Proposal for a directive
Article 13 – paragraph 1 – introductory part
Article 13 – paragraph 1 – introductory part
1. Member States may adopt legislative measures restricting, wholly or partly, the data subject's right of access to the extent that such partial or complete restriction constitutes a necessary and proportionate measure in a democratic society with due regard for the fundamental rights and legitimate interests of the person concerned:
Amendment 432 #
Proposal for a directive
Article 13 – paragraph 2 a (new)
Article 13 – paragraph 2 a (new)
2a. Member States shall apply the exemptions of paragraphs 1 and 2 in a restrictive way, allowing the right of access to be applied to the fullest in each specific restrictive measure. The exceptions set out in paragraph 1 shall not be applied in a general way, but shall be invoked specifically and accompanied by a reasoned justification.
Amendment 433 #
Proposal for a directive
Article 13 – paragraph 2 b (new)
Article 13 – paragraph 2 b (new)
2b. Member States shall provide that the controller assesses, in each specific case, by means of an individual, concrete and reasoned examination whether a partial or complete restriction on the basis of paragraph 1 or 2 applies.
Amendment 438 #
Proposal for a directive
Article 14 – paragraph 1
Article 14 – paragraph 1
1. Member States shall provide for the right of the data subject to request, at all times, in particular in cases referred to in Article 13, that the supervisory authority checks the lawfulness of the processing.
Amendment 441 #
Proposal for a directive
Article 14 – paragraph 3
Article 14 – paragraph 3
3. When the right referred to in paragraph 1 is exercised, the supervisory authority shall inform the data subject at least that all necessary verifications by the supervisory authority have taken place, and of the result as regards the lawfulness of the processing in question. The supervisory authority shall also inform the data subject of the conditions of his or her right to seek a judicial remedy.
Amendment 443 #
Proposal for a directive
Article 15 – paragraph 1
Article 15 – paragraph 1
1. Member States shall provide for the right of the data subject to obtain from the controller the rectification or completion of personal data relating to them which are inaccurate or incomplete. The data subject shall have the right to obtain completion ofrectification or completion of inaccurate or incomplete personal data, in particular by way of a corrective or completing statement.
Amendment 445 #
Proposal for a directive
Article 15 – paragraph 1 a (new)
Article 15 – paragraph 1 a (new)
1a. Member States shall ensure that if a controller refuses the rectification or completion of personal data, the burden of proof of the necessity and proportionality of this refusal lies with the controller.
Amendment 452 #
Proposal for a directive
Article 16 – paragraph 1
Article 16 – paragraph 1
1. Member States shall provide for the right of the data subject to obtain from the controller the erasure of personal data relating to them and the abstention from further dissemination of such data where the processing does not comply with the provisions adopted pursuant to Articles 4 (a) to (e), 7 and 8 of this Directive.
Amendment 456 #
Proposal for a directive
Article 16 – paragraph 3 – introductory part
Article 16 – paragraph 3 – introductory part
3. Instead of erasure, the controller shall mark and restrict the processing of the personal data where:
Amendment 469 #
Proposal for a directive
Article 16 – paragraph 3 a (new)
Article 16 – paragraph 3 a (new)
3a. The personal data referred to in paragraph 3 may only be processed for purposes of proof. The processing of contested personal data for the purposes of proof is only allowed on the condition that the markation is maintained as long as the accuracy of the personal data is contested.
Amendment 470 #
Proposal for a directive
Article 16 – paragraph 3 b (new)
Article 16 – paragraph 3 b (new)
3b. Where processing of personal data is marked and restricted pursuant to paragraph 3, the controller shall inform the data subject before lifting the markation of, and restriction on, the processing of this personal data.
Amendment 476 #
Proposal for a directive
Article 16 – paragraph 4 a (new)
Article 16 – paragraph 4 a (new)
4a. The controller shall communicate any erasure or markation carried out to each recipient to whom the data have been disclosed.
Amendment 480 #
Proposal for a directive
Article 18 – paragraph 1
Article 18 – paragraph 1
1. Member States shall provide that the controller adopts policies and implements appropriate measures to ensure and be able to demonstrate, for each processing operation, that the processing of personal data is performed in compliance with the provisions adopted pursuant to this Directive.
Amendment 483 #
Proposal for a directive
Article 19 – paragraph 1
Article 19 – paragraph 1
1. Member States shall provide that, having regard to the state of the art and the cost of implementation, the controller shall implement, both at the time of the determination of the means for processing and at the time of the processing itself, appropriate technical and organisational measures and procedures in such a way that the processing will meet the requirements of provisions adopted pursuant to this Directive and ensure the protection of the rights of the data subject.
Amendment 486 #
Proposal for a directive
Article 19 – paragraph 2
Article 19 – paragraph 2
2. The controller shall implement mechanisms for ensuring that, by default, only those personal data which are necessary for theeach specific purposes of the processing are processed.
Amendment 490 #
Proposal for a directive
Article 19 – paragraph 2 a (new)
Article 19 – paragraph 2 a (new)
2a. The controller shall implement mechanisms for ensuring that personal data are not collected or retained beyond the minimum necessary for those purposes, both in terms of the volume of the data and the time during which they are stored. Those mechanisms shall, by default, ensure that the access to personal data is limited.
Amendment 492 #
Proposal for a directive
Article 20 – paragraph 1
Article 20 – paragraph 1
Member States shall provide that where a controller determines the purposes, conditions and means of the processing of personal data jointly with others, the joint controllers must determine the respective responsibilities for compliance with the provisions adopted pursuant to this Directive, in particular as regards the procedures and mechanisms for exercising the rights of the data subject, by means of a written arrangement between themor a legal act.
Amendment 494 #
Proposal for a directive
Article 20 – paragraph 1 a (new)
Article 20 – paragraph 1 a (new)
Member States shall provide that the data subject may exercise his or her rights in respect of, and against, each of the joint controllers.
Amendment 497 #
Proposal for a directive
Article 21 – paragraph 1
Article 21 – paragraph 1
1. Member States shall provide that where a processing operation is carried out on behalf of a controller, the controller mustshall choose a processor providing sufficient guarantees to implement appropriate technical and organisational measures and procedures in such a way that the processing will meet the requirements of the provisions adopted pursuant to this Directive and ensure the protection of the rights of the data subject, in particular in respect of the technical security measures and organizational measures governing the processing to be carried out and to ensure compliance with those measures.
Amendment 500 #
Proposal for a directive
Article 21 – paragraph 2
Article 21 – paragraph 2
2. Member States shall provide that the carrying out of processing by a processor must be governed by a legal act binding the processor to the controller and stipulating in particular that the processor shall: (a) act only on instructions from the controller, in particular, where the transfer of the personal data used is prohibited. s; (b) employ only staff who have agreed to be bound by an obligation of confidentiality or are under a statutory obligation of confidentiality; (c) take all required measures pursuant to Article 28; (d) engage another processor only with the permission of the controller and therefore inform the controller of the intention to engage another processor in such a timely fashion that the controller has the possibility to object; (e) insofar as it is possible given the nature of the processing, adopt in agreement with controller the necessary technical and organisational requirements for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III; (f) assist the controller in ensuring compliance with the obligations pursuant to Articles 28 to 32; (g) hand all results over to the controller after the end of the processing and not otherwise process the personal data; (h) make available to the controller and the supervisory authority all the information necessary to verify compliance with the obligations laid down in this Article; (i) take into account the principle of data protection by design and default.
Amendment 502 #
Proposal for a directive
Article 21 – paragraph 2 a (new)
Article 21 – paragraph 2 a (new)
2a. The controller and the processor need to be able to demonstrate compliance with the obligations as referred to in paragraph 2.
Amendment 506 #
Proposal for a directive
Article 21 – paragraph 3
Article 21 – paragraph 3
3. If a processor processes personal data other than as instructed by the controlleris instructed by the controller to make certain independent decisions regarding the personal data, the processor shall be considered to be a controller in respect of that processing and shall be subject to the rules on joint controllers laid down in Article 20.
Amendment 509 #
Proposal for a directive
Article 22 – paragraph 1 a (new)
Article 22 – paragraph 1 a (new)
Where the processor is or becomes the determining part in relation to the purposes, means, or methods of data processing or does not act exclusively on the instructions, it shall be considered as a joint controller pursuant to Article 20.
Amendment 513 #
Proposal for a directive
Article 23 – paragraph 2 – point a
Article 23 – paragraph 2 – point a
(a) the name and contact details of the controller, or and its data protection officer, and those of any joint controller or processor;
Amendment 517 #
Proposal for a directive
Article 23 – paragraph 2 – point d
Article 23 – paragraph 2 – point d
(d) transfers of data to a third country or an international organisation, including the identification of the requesting competent authority of at third country or international organisation. and the legal grounds on which the data are transferred;
Amendment 518 #
Proposal for a directive
Article 23 – paragraph 2 – point d a (new)
Article 23 – paragraph 2 – point d a (new)
(da) the time limits for erasure of the different categories of data;
Amendment 522 #
Proposal for a directive
Article 24 – paragraph 1
Article 24 – paragraph 1
1. Member States shall ensure that records are kept of at least the following processing operations: collection, alteration, consultation, disclosure, combination or erasure. The records of consultation and disclosure shall show in particular the purpose, date and time of such operations and as far as possible the identification of the person who consulted or disclosed personal data, and the identity of the recipients of such data.
Amendment 526 #
Proposal for a directive
Article 24 – paragraph 1 a (new)
Article 24 – paragraph 1 a (new)
1a. The controller and the processor shall make the records available to the supervisory authority upon request.
Amendment 536 #
Proposal for a directive
Article 25 a (new)
Article 25 a (new)
Amendment 541 #
Proposal for a directive
Article 26 – paragraph 2
Article 26 – paragraph 2
2. Member States may provide that the supervisory authority shall establishes a list of the processing operations which are subject to prior consultation pursuant to paragraph 1oint (b) of paragraph 1. The supervisory authority shall publicly communicate that list and forward it to the European Data Protection Board. The European Data Protection Board shall work on the convergence of those lists.
Amendment 542 #
Proposal for a directive
Article 26 – paragraph 2 a (new)
Article 26 – paragraph 2 a (new)
2a. Member States ensure that the controller or processor shall provide the supervisory authority with the data protection impact assessment provided for in Article 25a and, on request, with any other information to allow the supervisory authority to make an assessment of the compliance of the processing and in particular of the risks for the protection of personal data of the data subject and of the related safeguards.
Amendment 543 #
Proposal for a directive
Article 26 – paragraph 2 b (new)
Article 26 – paragraph 2 b (new)
2b. Member States shall consult the supervisory authority in the preparation of a legislative measure to be adopted by the national parliament or of a measure based on such a legislative measure, which defines the nature of the processing, in order to ensure the compliance of the intended processing under this Directive, and in particular to mitigate the risks involved for the data subjects.
Amendment 546 #
Proposal for a directive
Article 27 – paragraph 1
Article 27 – paragraph 1
1. Member States shall provide that the controller and the processor implements appropriate technical and organisational measures and procedures to ensure a level of security appropriate to the risks represented by the processing and the nature of the data to be protected, having regard to the state of the art and the cost of their implementation.
Amendment 551 #
Proposal for a directive
Article 27 – paragraph 2 a (new)
Article 27 – paragraph 2 a (new)
2a. Member States shall provide that processors may be appointed only if they guarantee and are able to demonstrate that they observe the requisite technical and organisational measures under paragraph 1 and comply with the instructions under Article 21(2)(a). The competent authority shall monitor the processor in those respects.
Amendment 556 #
Proposal for a directive
Article 28 – paragraph 5
Article 28 – paragraph 5
5. The Commission shall be empowered to adopt, after requesting an opinion of the European Data Protection Board, delegated acts in accordance with Article 56 for the purpose of specifying further the criteria and requirements for establishing the data breach referred to in paragraphs 1 and 2 and for the particular circumstances in which a controller and a processor is required to notify the personal data breach.
Amendment 560 #
Proposal for a directive
Article 28 a (new)
Article 28 a (new)
Article 28a The supervisory authority shall keep a public register of the types, scope and numbers of the breaches notified.
Amendment 563 #
Proposal for a directive
Article 29 – paragraph 3 a (new)
Article 29 – paragraph 3 a (new)
3a. Without prejudice to the controller's obligation to notify the personal data breach to the data subject, if the controller has not already communicated the personal data breach to the data subject, the supervisory authority, having considered the likely adverse effects of the breach, may require it to do so.
Amendment 570 #
Proposal for a directive
Article 30 – paragraph 2 a (new)
Article 30 – paragraph 2 a (new)
2a. Member States shall provide that the controller or the processor ensures that any other professional duties of the data protection officer are compatible with that person's tasks and duties as data protection officer and do not result in a conflict of interests.
Amendment 572 #
Proposal for a directive
Article 30 – paragraph 2 b (new)
Article 30 – paragraph 2 b (new)
2b. The data protection officer shall be appointed for a period of at least four years. The data protection officer may be reappointed for further terms. During the term of office, the data protection officer may only be dismissed from that function, if he or she no longer fulfils the conditions required for the performance of his or her duties, in particular ensuring the compliance with the provisions of this Directive.
Amendment 575 #
Proposal for a directive
Article 31 – paragraph 2
Article 31 – paragraph 2
2. The controller or processor shall ensure that the data protection officer is provided with the means to perform duties and tasks referred to under Article 32 effectively andperforms the duties and tasks independently, and does not receive any instructions as regards the exercise of the function. The data protection officer shall directly report to the management of the controller or the processor.
Amendment 576 #
Proposal for a directive
Article 31 – paragraph 2 a (new)
Article 31 – paragraph 2 a (new)
2a. The controller or the processor shall support the data protection officer in performing the tasks and shall provide all means, including staff, premises, equipment and any other resources necessary to carry out the duties and referred to in Article 32, and to maintain his or her professional knowledge.
Amendment 577 #
Proposal for a directive
Article 32 – paragraph 1 – point a
Article 32 – paragraph 1 – point a
(a) to inform and advise the controller or the processor of their obligations in accordance with the provisions adopted pursuant to this Directive, in particular with regards to technical and organisational measures and procedures, and to document this activity and the responses received;
Amendment 578 #
Proposal for a directive
Article 32 – paragraph 1 – point h a (new)
Article 32 – paragraph 1 – point h a (new)
(ha) to monitor the performance of the data protection impact assessment by the controller or processor;
Amendment 579 #
Proposal for a directive
Article 32 a (new)
Article 32 a (new)
Article 32a BOARD RESPONSABILITY 1. The controller and the processor shall designate a board member responsible for data protection. 2. The board member referred to in paragraph 1 shall bear the final responsibility for the compliance with the provisions of this Directive as implemented by Member State law.
Amendment 583 #
Proposal for a directive
Article 33 – paragraph 1 – point a
Article 33 – paragraph 1 – point a
(a) the specific transfer is necessary for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties; and
Amendment 584 #
Proposal for a directive
Article 33 – paragraph 1 – point a a (new)
Article 33 – paragraph 1 – point a a (new)
(aa) the data are transferred to a controller in a third country or international organisation that is a public authority competent for the purposes referred in Article 1(1);
Amendment 585 #
Proposal for a directive
Article 33 – paragraph 1 – point a b (new)
Article 33 – paragraph 1 – point a b (new)
(ab) the conditions laid down in this Chapter are complied with by the controller and the processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation;
Amendment 587 #
Proposal for a directive
Article 33 – paragraph 1 – point b
Article 33 – paragraph 1 – point b
(b) the conditions laid down in this Chapterother provisions adopted pursuant to this Directive are complied with by the controller and processor.; and
Amendment 588 #
Proposal for a directive
Article 33 – paragraph 1 – point b a (new)
Article 33 – paragraph 1 – point b a (new)
(ba) the level of protection of the personal data guaranteed by this Directive is not undermined.
Amendment 594 #
Proposal for a directive
Article 34 – paragraph 2 – point b
Article 34 – paragraph 2 – point b
(b) the existence and effective functioning of one or more independent supervisory authorities in the third country or international organisation in question responsible for ensuring compliance with the data protection rules, including sufficient sanctioning powers, for assisting and advising the data subject in exercising their rights and for co-operation with the supervisory authorities of the Union and of Member States; and
Amendment 601 #
Proposal for a directive
Article 35 – paragraph 1 – introductory part
Article 35 – paragraph 1 – introductory part
1. Where the Commission has taken no decision pursuant to Article 34, Member States shall provide that a transfer of personal data to a recipient in a third country or an international organisation may only take place where:
Amendment 603 #
Proposal for a directive
Article 35 – paragraph 1 – point a
Article 35 – paragraph 1 – point a
(a) appropriate safeguards with respect to the protection of personal data have been adduced in a legally binding instrument; orand
Amendment 604 #
Proposal for a directive
Article 35 – paragraph 1 – point a a (new)
Article 35 – paragraph 1 – point a a (new)
(aa) the supervisory authority gave prior authorisation for the transfer.
Amendment 605 #
Proposal for a directive
Article 35 – paragraph 1 – point b
Article 35 – paragraph 1 – point b
Amendment 609 #
Proposal for a directive
Article 35 – paragraph 2
Article 35 – paragraph 2
Amendment 614 #
Proposal for a directive
Article 36
Article 36
Amendment 628 #
Proposal for a directive
Article 38 a (new)
Article 38 a (new)
Chapter Va Article 38a 1. Member States shall ensure that the controller does not transmit personal data to a natural or legal person not subject to the provisions adopted pursuant to this Directive, unless: (a) the transmission complies with Union or national law; and (b) the recipient is established in a Member State of the European Union; and (c) no legitimate specific interests of the data subject prevent transmission; and (d) the transmission is necessary in a specific case for the controller transmitting the personal data for: (i) the performance of a task lawfully assigned to it; or (ii) the prevention of an immediate and serious danger to public security; or (iii) the prevention of serious harm to the rights of individuals. 2. The controller shall inform the recipient of the purpose for which the personal data may exclusively be processed. 3. The controller shall inform the recipient of processing restrictions and ensure that these restrictions are met.
Amendment 640 #
Proposal for a directive
Article 45 – paragraph 6
Article 45 – paragraph 6
6. Where requests are vexatious, in particular due to their repetitive character, tThe supervisory authority may charge a fee or notonly refuse to take the action required by the data subject when the request is flagrantly excessive. The supervisory authority shall bear the burden of proving of the vexatiousflagrantly excessive character of the request.
Amendment 644 #
Proposal for a directive
Article 46 – paragraph 1
Article 46 – paragraph 1
Amendment 645 #
Proposal for a directive
Article 46 – paragraph 1 a (new)
Article 46 – paragraph 1 a (new)
Amendment 648 #
Proposal for a directive
Article 46 a (new)
Article 46 a (new)
Article 46a Whistleblower The Commission shall bring forward a legislative proposal for the purpose of specifying the conditions and criteria to guarantee the legal protection of whistleblowers, reporting non-compliance with the provisions of this Directive by a controller or a processor, within one year after the entry into force of this Directive.
Amendment 651 #
Proposal for a directive
Article 47 – paragraph 1
Article 47 – paragraph 1
Member States shall provide that each supervisory authority draws up an annual report on its activities. The report shall be made available to the public, the national parliament, the Commission and the European Data Protection Board.