emendrix

GDPR

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural […]

32016R0679 · Digital · Atom feed · on EUR-Lex · reflects the consolidated version of 2026-08-11

32016R067902016R0679-20160504

in force not stated · detected 2026-08-11

9 provisions touched — 9 substantive, 0 date-only, 9 disputed · 0 sentences quoted verbatim by the gate, 0 changes shipped without an explanation

MODIFIED Art. 37 — Designation of the data protection officer · applies from unchanged

Disputed — seen by the structural diff, not by corpus metadata.

In point (c) of Article 37(1), the conjunction linking special categories of data under Article 9 and personal data relating to criminal convictions and offences under Article 10 was changed from 'and' to 'or'. Art. 37, v1 Art. 37, v2

text before / after

32016R067902016R0679-20160504

Article 37Designation of the data protection officer1.The controller and the processor shall designate a data protection officer in any case where:(a)the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;(b)the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or(c)the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and or personal data relating to criminal convictions and offences referred to in Article 10.2.A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment.3.Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size.4.In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors.5.The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.6.The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.7.The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority.

MODIFIED Art. 41 — Monitoring of approved codes of conduct · applies from unchanged

Disputed — seen by the structural diff, not by corpus metadata.

In paragraph 3, the word describing what the competent supervisory authority submits to the Board changed from 'criteria' for accreditation to 'requirements' for accreditation. Art. 41, v1 Art. 41, v2

In paragraph 5, the basis on which the competent supervisory authority revokes accreditation changed from unmet 'conditions' for accreditation to unmet 'requirements' for accreditation. Art. 41, v1 Art. 41, v2

text before / after

32016R067902016R0679-20160504

Article 41Monitoring of approved codes of conduct1.Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58, the monitoring of compliance with a code of conduct pursuant to Article 40 may be carried out by a body which has an appropriate level of expertise in relation to the subject-matter of the code and is accredited for that purpose by the competent supervisory authority.2.A body as referred to in paragraph 1 may be accredited to monitor compliance with a code of conduct where that body has:(a)demonstrated its independence and expertise in relation to the subject-matter of the code to the satisfaction of the competent supervisory authority;(b)established procedures which allow it to assess the eligibility of controllers and processors concerned to apply the code, to monitor their compliance with its provisions and to periodically review its operation;(c)established procedures and structures to handle complaints about infringements of the code or the manner in which the code has been, or is being, implemented by a controller or processor, and to make those procedures and structures transparent to data subjects and the public; and(d)demonstrated to the satisfaction of the competent supervisory authority that its tasks and duties do not result in a conflict of interests.3.The competent supervisory authority shall submit the draft criteria requirements for accreditation of a body as referred to in paragraph 1 of this Article to the Board pursuant to the consistency mechanism referred to in Article 63.4.Without prejudice to the tasks and powers of the competent supervisory authority and the provisions of Chapter VIII, a body as referred to in paragraph 1 of this Article shall, subject to appropriate safeguards, take appropriate action in cases of infringement of the code by a controller or processor, including suspension or exclusion of the controller or processor concerned from the code. It shall inform the competent supervisory authority of such actions and the reasons for taking them.5.The competent supervisory authority shall revoke the accreditation of a body as referred to in paragraph 1 if the conditions requirements for accreditation are not, or are no longer, met or where actions taken by the body infringe this Regulation.6.This Article shall not apply to processing carried out by public authorities and bodies.

MODIFIED Art. 42 — Certification · applies from unchanged

Disputed — seen by the structural diff, not by corpus metadata.

In paragraph 7, the phrase referring to whether the relevant requirements continue to be met was changed to refer instead to whether the relevant criteria continue to be met. Art. 42, v1 Art. 42, v2

Similarly, the later reference to requirements for the certification not being or no longer being met was changed to refer to criteria for the certification not being or no longer being met. Art. 42, v2

text before / after

32016R067902016R0679-20160504

Article 42Certification1.The Member States, the supervisory authorities, the Board and the Commission shall encourage, in particular at Union level, the establishment of data protection certification mechanisms and of data protection seals and marks, for the purpose of demonstrating compliance with this Regulation of processing operations by controllers and processors. The specific needs of micro, small and medium-sized enterprises shall be taken into account.2.In addition to adherence by controllers or processors subject to this Regulation, data protection certification mechanisms, seals or marks approved pursuant to paragraph 5 of this Article may be established for the purpose of demonstrating the existence of appropriate safeguards provided by controllers or processors that are not subject to this Regulation pursuant to Article 3 within the framework of personal data transfers to third countries or international organisations under the terms referred to in point (f) of Article 46(2). Such controllers or processors shall make binding and enforceable commitments, via contractual or other legally binding instruments, to apply those appropriate safeguards, including with regard to the rights of data subjects.3.The certification shall be voluntary and available via a process that is transparent.4.A certification pursuant to this Article does not reduce the responsibility of the controller or the processor for compliance with this Regulation and is without prejudice to the tasks and powers of the supervisory authorities which are competent pursuant to Article 55 or 56.5.A certification pursuant to this Article shall be issued by the certification bodies referred to in Article 43 or by the competent supervisory authority, on the basis of criteria approved by that competent supervisory authority pursuant to Article 58(3) or by the Board pursuant to Article 63. Where the criteria are approved by the Board, this may result in a common certification, the European Data Protection Seal.6.The controller or processor which submits its processing to the certification mechanism shall provide the certification body referred to in Article 43, or where applicable, the competent supervisory authority, with all information and access to its processing activities which are necessary to conduct the certification procedure.7.Certification shall be issued to a controller or processor for a maximum period of three years and may be renewed, under the same conditions, provided that the relevant requirements criteria continue to be met. Certification shall be withdrawn, as applicable, by the certification bodies referred to in Article 43 or by the competent supervisory authority where the requirements criteria for the certification are not or are no longer met.8.The Board shall collate all certification mechanisms and data protection seals and marks in a register and shall make them publicly available by any appropriate means.

MODIFIED Art. 43 — Certification bodies · applies from unchanged

Disputed — seen by the structural diff, not by corpus metadata.

In paragraph 3, the word describing what the accreditation is based on was changed from 'criteria' to 'requirements' approved by the competent supervisory authority or the Board. Art. 43, v1 Art. 43, v2

In paragraph 6, the sentence stating that the Board shall collate all certification mechanisms and data protection seals in a register and make them publicly available was removed, leaving only the sentence on transmitting requirements and criteria to the Board. Art. 43, v1 Art. 43, v2

text before / after

32016R067902016R0679-20160504

Article 43Certification bodies1.Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58, certification bodies which have an appropriate level of expertise in relation to data protection shall, after informing the supervisory authority in order to allow it to exercise its powers pursuant to point (h) of Article 58(2) where necessary, issue and renew certification. Member States shall ensure that those certification bodies are accredited by one or both of the following:(a)the supervisory authority which is competent pursuant to Article 55 or 56;(b)the national accreditation body named in accordance with Regulation (EC) No 765/2008 of the European Parliament and of the CouncilRegulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July 2008 setting out the requirements for accreditation and market surveillance relating to the marketing of products and repealing Regulation (EEC) No 339/93 (OJ L 218, 13.8.2008, p. 30). in accordance with EN-ISO/IEC 17065/2012 and with the additional requirements established by the supervisory authority which is competent pursuant to Article 55 or 56.2.Certification bodies referred to in paragraph 1 shall be accredited in accordance with that paragraph only where they have:(a)demonstrated their independence and expertise in relation to the subject-matter of the certification to the satisfaction of the competent supervisory authority;(b)undertaken to respect the criteria referred to in Article 42(5) and approved by the supervisory authority which is competent pursuant to Article 55 or 56 or by the Board pursuant to Article 63;(c)established procedures for the issuing, periodic review and withdrawal of data protection certification, seals and marks;(d)established procedures and structures to handle complaints about infringements of the certification or the manner in which the certification has been, or is being, implemented by the controller or processor, and to make those procedures and structures transparent to data subjects and the public; and(e)demonstrated, to the satisfaction of the competent supervisory authority, that their tasks and duties do not result in a conflict of interests.3.The accreditation of certification bodies as referred to in paragraphs 1 and 2 of this Article shall take place on the basis of criteria requirements approved by the supervisory authority which is competent pursuant to Article 55 or 56 or by the Board pursuant to Article 63. In the case of accreditation pursuant to point (b) of paragraph 1 of this Article, those requirements shall complement those envisaged in Regulation (EC) No 765/2008 and the technical rules that describe the methods and procedures of the certification bodies.4.The certification bodies referred to in paragraph 1 shall be responsible for the proper assessment leading to the certification or the withdrawal of such certification without prejudice to the responsibility of the controller or processor for compliance with this Regulation. The accreditation shall be issued for a maximum period of five years and may be renewed on the same conditions provided that the certification body meets the requirements set out in this Article.5.The certification bodies referred to in paragraph 1 shall provide the competent supervisory authorities with the reasons for granting or withdrawing the requested certification.6.The requirements referred to in paragraph 3 of this Article and the criteria referred to in Article 42(5) shall be made public by the supervisory authority in an easily accessible form. The supervisory authorities shall also transmit those requirements and criteria to the Board. The Board shall collate all certification mechanisms and data protection seals in a register and shall make them publicly available by any appropriate means.7.Without Board.7.Without prejudice to Chapter VIII, the competent supervisory authority or the national accreditation body shall revoke an accreditation of a certification body pursuant to paragraph 1 of this Article where the conditions for the accreditation are not, or are no longer, met or where actions taken by a certification body infringe this Regulation.8.The Commission shall be empowered to adopt delegated acts in accordance with Article 92 for the purpose of specifying the requirements to be taken into account for the data protection certification mechanisms referred to in Article 42(1).9.The Commission may adopt implementing acts laying down technical standards for certification mechanisms and data protection seals and marks, and mechanisms to promote and recognise those certification mechanisms, seals and marks. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2).

MODIFIED Art. 57 — Tasks · applies from unchanged

Disputed — seen by the structural diff, not by corpus metadata.

In point (p) of Article 57(1), the word describing what supervisory authorities draft and publish for accreditation of monitoring bodies and certification bodies changed from "criteria" to "requirements". Art. 57, v1 Art. 57, v2

text before / after

32016R067902016R0679-20160504

Article 57Tasks1.Without prejudice to other tasks set out under this Regulation, each supervisory authority shall on its territory:(a)monitor and enforce the application of this Regulation;(b)promote public awareness and understanding of the risks, rules, safeguards and rights in relation to processing. Activities addressed specifically to children shall receive specific attention;(c)advise, in accordance with Member State law, the national parliament, the government, and other institutions and bodies on legislative and administrative measures relating to the protection of natural persons' rights and freedoms with regard to processing;(d)promote the awareness of controllers and processors of their obligations under this Regulation;(e)upon request, provide information to any data subject concerning the exercise of their rights under this Regulation and, if appropriate, cooperate with the supervisory authorities in other Member States to that end;(f)handle complaints lodged by a data subject, or by a body, organisation or association in accordance with Article 80, and investigate, to the extent appropriate, the subject matter of the complaint and inform the complainant of the progress and the outcome of the investigation within a reasonable period, in particular if further investigation or coordination with another supervisory authority is necessary;(g)cooperate with, including sharing information and provide mutual assistance to, other supervisory authorities with a view to ensuring the consistency of application and enforcement of this Regulation;(h)conduct investigations on the application of this Regulation, including on the basis of information received from another supervisory authority or other public authority;(i)monitor relevant developments, insofar as they have an impact on the protection of personal data, in particular the development of information and communication technologies and commercial practices;(j)adopt standard contractual clauses referred to in Article 28(8) and in point (d) of Article 46(2);(k)establish and maintain a list in relation to the requirement for data protection impact assessment pursuant to Article 35(4);(l)give advice on the processing operations referred to in Article 36(2);(m)encourage the drawing up of codes of conduct pursuant to Article 40(1) and provide an opinion and approve such codes of conduct which provide sufficient safeguards, pursuant to Article 40(5);(n)encourage the establishment of data protection certification mechanisms and of data protection seals and marks pursuant to Article 42(1), and approve the criteria of certification pursuant to Article 42(5);(o)where applicable, carry out a periodic review of certifications issued in accordance with Article 42(7);(p)draft and publish the criteria requirements for accreditation of a body for monitoring codes of conduct pursuant to Article 41 and of a certification body pursuant to Article 43;(q)conduct the accreditation of a body for monitoring codes of conduct pursuant to Article 41 and of a certification body pursuant to Article 43;(r)authorise contractual clauses and provisions referred to in Article 46(3);(s)approve binding corporate rules pursuant to Article 47;(t)contribute to the activities of the Board;(u)keep internal records of infringements of this Regulation and of measures taken in accordance with Article 58(2); and(v)fulfil any other tasks related to the protection of personal data.2.Each supervisory authority shall facilitate the submission of complaints referred to in point (f) of paragraph 1 by measures such as a complaint submission form which can also be completed electronically, without excluding other means of communication.3.The performance of the tasks of each supervisory authority shall be free of charge for the data subject and, where applicable, for the data protection officer.4.Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, the supervisory authority may charge a reasonable fee based on administrative costs, or refuse to act on the request. The supervisory authority shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request.

MODIFIED Art. 64 — Opinion of the Board · applies from unchanged

Disputed — seen by the structural diff, not by corpus metadata.

Point (c) of paragraph 1 now refers to approving requirements for accreditation of a body under Article 41(3) and of a certification body under Article 43(3), and adds a reference to the criteria for certification referred to in Article 42(5), replacing the earlier wording that spoke of approving accreditation criteria for both types of bodies. Art. 64, v1 Art. 64, v2

Paragraphs 6, 7 and 8 each now identify the acting authority as "the competent supervisory authority referred to in paragraph 1" instead of the previous "the competent supervisory authority" (paragraph 6) or "the supervisory authority" (paragraphs 7 and 8). Art. 64, v1 Art. 64, v2

text before / after

32016R067902016R0679-20160504

Article 64Opinion of the Board1.The Board shall issue an opinion where a competent supervisory authority intends to adopt any of the measures below. To that end, the competent supervisory authority shall communicate the draft decision to the Board, when it:(a)aims to adopt a list of the processing operations subject to the requirement for a data protection impact assessment pursuant to Article 35(4);(b)concerns a matter pursuant to Article 40(7) whether a draft code of conduct or an amendment or extension to a code of conduct complies with this Regulation;(c)aims to approve the criteria requirements for accreditation of a body pursuant to Article 41(3) or 41(3), of a certification body pursuant to Article 43(3);(d)aims 43(3) or the criteria for certification referred to in Article 42(5);(d)aims to determine standard data protection clauses referred to in point (d) of Article 46(2) and in Article 28(8);(e)aims to authorise contractual clauses referred to in point (a) of Article 46(3); or(f)aims to approve binding corporate rules within the meaning of Article 47.2.Any supervisory authority, the Chair of the Board or the Commission may request that any matter of general application or producing effects in more than one Member State be examined by the Board with a view to obtaining an opinion, in particular where a competent supervisory authority does not comply with the obligations for mutual assistance in accordance with Article 61 or for joint operations in accordance with Article 62.3.In the cases referred to in paragraphs 1 and 2, the Board shall issue an opinion on the matter submitted to it provided that it has not already issued an opinion on the same matter. That opinion shall be adopted within eight weeks by simple majority of the members of the Board. That period may be extended by a further six weeks, taking into account the complexity of the subject matter. Regarding the draft decision referred to in paragraph 1 circulated to the members of the Board in accordance with paragraph 5, a member which has not objected within a reasonable period indicated by the Chair, shall be deemed to be in agreement with the draft decision.4.Supervisory authorities and the Commission shall, without undue delay, communicate by electronic means to the Board, using a standardised format any relevant information, including as the case may be a summary of the facts, the draft decision, the grounds which make the enactment of such measure necessary, and the views of other supervisory authorities concerned.5.The Chair of the Board shall, without undue, delay inform by electronic means:(a)the members of the Board and the Commission of any relevant information which has been communicated to it using a standardised format. The secretariat of the Board shall, where necessary, provide translations of relevant information; and(b)the supervisory authority referred to, as the case may be, in paragraphs 1 and 2, and the Commission of the opinion and make it public.6.The competent supervisory authority referred to in paragraph 1 shall not adopt its draft decision referred to in paragraph 1 within the period referred to in paragraph 3.7.The competent supervisory authority referred to in paragraph 1 shall take utmost account of the opinion of the Board and shall, within two weeks after receiving the opinion, communicate to the Chair of the Board by electronic means whether it will maintain or amend its draft decision and, if any, the amended draft decision, using a standardised format.8.Where the competent supervisory authority concerned referred to in paragraph 1 informs the Chair of the Board within the period referred to in paragraph 7 of this Article that it does not intend to follow the opinion of the Board, in whole or in part, providing the relevant grounds, Article 65(1) shall apply.

MODIFIED Art. 65 — Dispute resolution by the Board · applies from unchanged

Disputed — seen by the structural diff, not by corpus metadata.

In Article 65(1)(a), the earlier text referred to the lead authority having raised or rejected the objection, while the later text describes the lead supervisory authority as either not having followed the objection or having rejected it as not relevant or reasoned. Art. 65, v1 Art. 65, v2

text before / after

32016R067902016R0679-20160504

Article 65Dispute resolution by the Board1.In order to ensure the correct and consistent application of this Regulation in individual cases, the Board shall adopt a binding decision in the following cases:(a)where, in a case referred to in Article 60(4), a supervisory authority concerned has raised a relevant and reasoned objection to a draft decision of the lead supervisory authority or and the lead supervisory authority has not followed the objection or has rejected such an objection as being not relevant or reasoned. The binding decision shall concern all the matters which are the subject of the relevant and reasoned objection, in particular whether there is an infringement of this Regulation;(b)where there are conflicting views on which of the supervisory authorities concerned is competent for the main establishment;(c)where a competent supervisory authority does not request the opinion of the Board in the cases referred to in Article 64(1), or does not follow the opinion of the Board issued under Article 64. In that case, any supervisory authority concerned or the Commission may communicate the matter to the Board.2.The decision referred to in paragraph 1 shall be adopted within one month from the referral of the subject-matter by a two-thirds majority of the members of the Board. That period may be extended by a further month on account of the complexity of the subject-matter. The decision referred to in paragraph 1 shall be reasoned and addressed to the lead supervisory authority and all the supervisory authorities concerned and binding on them.3.Where the Board has been unable to adopt a decision within the periods referred to in paragraph 2, it shall adopt its decision within two weeks following the expiration of the second month referred to in paragraph 2 by a simple majority of the members of the Board. Where the members of the Board are split, the decision shall by adopted by the vote of its Chair.4.The supervisory authorities concerned shall not adopt a decision on the subject matter submitted to the Board under paragraph 1 during the periods referred to in paragraphs 2 and 3.5.The Chair of the Board shall notify, without undue delay, the decision referred to in paragraph 1 to the supervisory authorities concerned. It shall inform the Commission thereof. The decision shall be published on the website of the Board without delay after the supervisory authority has notified the final decision referred to in paragraph 6.6.The lead supervisory authority or, as the case may be, the supervisory authority with which the complaint has been lodged shall adopt its final decision on the basis of the decision referred to in paragraph 1 of this Article, without undue delay and at the latest by one month after the Board has notified its decision. The lead supervisory authority or, as the case may be, the supervisory authority with which the complaint has been lodged, shall inform the Board of the date when its final decision is notified respectively to the controller or the processor and to the data subject. The final decision of the supervisory authorities concerned shall be adopted under the terms of Article 60(7), (8) and (9). The final decision shall refer to the decision referred to in paragraph 1 of this Article and shall specify that the decision referred to in that paragraph will be published on the website of the Board in accordance with paragraph 5 of this Article. The final decision shall attach the decision referred to in paragraph 1 of this Article.

MODIFIED Art. 69 — Independence · applies from unchanged

Disputed — seen by the structural diff, not by corpus metadata.

The reference to the Commission's requests changes from citing point (b) of Article 70(1) and Article 70(2) to citing Article 70(1) and (2) as a whole. Art. 69, v1 Art. 69, v2

text before / after

32016R067902016R0679-20160504

Article 69Independence1.The Board shall act independently when performing its tasks or exercising its powers pursuant to Articles 70 and 71.2.Without prejudice to requests by the Commission referred to in point (b) of Article 70(1) and in Article 70(2), (2), the Board shall, in the performance of its tasks or the exercise of its powers, neither seek nor take instructions from anybody.

MODIFIED Art. 70 — Tasks of the Board · applies from unchanged

Disputed — seen by the structural diff, not by corpus metadata.

Point (l) no longer limits the review of practical application to guidelines, recommendations and best practices referred to in points (e) and (f), instead referring to guidelines, recommendations and best practices generally. Art. 70, v1 Art. 70, v2

Point (o) changes from a task of carrying out accreditation of certification bodies and its periodic review under Article 43, and maintaining a register of accredited bodies under Article 43(6) and accredited controllers or processors under Article 42(7), to a task of approving the criteria of certification under Article 42(5) and maintaining a register of certification mechanisms and seals and marks under Article 42(8) and of certified controllers or processors under Article 42(7). Art. 70, v1 Art. 70, v2

Point (p) changes from specifying the requirements referred to in Article 43(3) for accreditation of certification bodies under Article 42, to approving those requirements for accreditation of certification bodies referred to in Article 43. Art. 70, v1 Art. 70, v2

text before / after

32016R067902016R0679-20160504

Article 70Tasks of the Board1.The Board shall ensure the consistent application of this Regulation. To that end, the Board shall, on its own initiative or, where relevant, at the request of the Commission, in particular:(a)monitor and ensure the correct application of this Regulation in the cases provided for in Articles 64 and 65 without prejudice to the tasks of national supervisory authorities;(b)advise the Commission on any issue related to the protection of personal data in the Union, including on any proposed amendment of this Regulation;(c)advise the Commission on the format and procedures for the exchange of information between controllers, processors and supervisory authorities for binding corporate rules;(d)issue guidelines, recommendations, and best practices on procedures for erasing links, copies or replications of personal data from publicly available communication services as referred to in Article 17(2);(e)examine, on its own initiative, on request of one of its members or on request of the Commission, any question covering the application of this Regulation and issue guidelines, recommendations and best practices in order to encourage consistent application of this Regulation;(f)issue guidelines, recommendations and best practices in accordance with point (e) of this paragraph for further specifying the criteria and conditions for decisions based on profiling pursuant to Article 22(2);(g)issue guidelines, recommendations and best practices in accordance with point (e) of this paragraph for establishing the personal data breaches and determining the undue delay referred to in Article 33(1) and (2) and for the particular circumstances in which a controller or a processor is required to notify the personal data breach;(h)issue guidelines, recommendations and best practices in accordance with point (e) of this paragraph as to the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of the natural persons referred to in Article 34(1).(i)issue guidelines, recommendations and best practices in accordance with point (e) of this paragraph for the purpose of further specifying the criteria and requirements for personal data transfers based on binding corporate rules adhered to by controllers and binding corporate rules adhered to by processors and on further necessary requirements to ensure the protection of personal data of the data subjects concerned referred to in Article 47;(j)issue guidelines, recommendations and best practices in accordance with point (e) of this paragraph for the purpose of further specifying the criteria and requirements for the personal data transfers on the basis of Article 49(1);(k)draw up guidelines for supervisory authorities concerning the application of measures referred to in Article 58(1), (2) and (3) and the setting of administrative fines pursuant to Article 83;(l)review the practical application of the guidelines, recommendations and best practices referred to in points (e) and (f);(m)issue practices;(m)issue guidelines, recommendations and best practices in accordance with point (e) of this paragraph for establishing common procedures for reporting by natural persons of infringements of this Regulation pursuant to Article 54(2);(n)encourage the drawing-up of codes of conduct and the establishment of data protection certification mechanisms and data protection seals and marks pursuant to Articles 40 and 42;(o)carry out 42;(o)approve the accreditation criteria of certification bodies and its periodic review pursuant to Article 43 42(5) and maintain a public register of accredited bodies certification mechanisms and data protection seals and marks pursuant to Article 43(6) 42(8) and of the accredited certified controllers or processors established in third countries pursuant to Article 42(7);(p)specify 42(7);(p)approve the requirements referred to in Article 43(3) with a view to the accreditation of certification bodies under referred to in Article 42;(q)provide 43;(q)provide the Commission with an opinion on the certification requirements referred to in Article 43(8);(r)provide the Commission with an opinion on the icons referred to in Article 12(7);(s)provide the Commission with an opinion for the assessment of the adequacy of the level of protection in a third country or international organisation, including for the assessment whether a third country, a territory or one or more specified sectors within that third country, or an international organisation no longer ensures an adequate level of protection. To that end, the Commission shall provide the Board with all necessary documentation, including correspondence with the government of the third country, with regard to that third country, territory or specified sector, or with the international organisation.(t)issue opinions on draft decisions of supervisory authorities pursuant to the consistency mechanism referred to in Article 64(1), on matters submitted pursuant to Article 64(2) and to issue binding decisions pursuant to Article 65, including in cases referred to in Article 66;(u)promote the cooperation and the effective bilateral and multilateral exchange of information and best practices between the supervisory authorities;(v)promote common training programmes and facilitate personnel exchanges between the supervisory authorities and, where appropriate, with the supervisory authorities of third countries or with international organisations;(w)promote the exchange of knowledge and documentation on data protection legislation and practice with data protection supervisory authorities worldwide.(x)issue opinions on codes of conduct drawn up at Union level pursuant to Article 40(9); and(y)maintain a publicly accessible electronic register of decisions taken by supervisory authorities and courts on issues handled in the consistency mechanism.2.Where the Commission requests advice from the Board, it may indicate a time limit, taking into account the urgency of the matter.3.The Board shall forward its opinions, guidelines, recommendations, and best practices to the Commission and to the committee referred to in Article 93 and make them public.4.The Board shall, where appropriate, consult interested parties and give them the opportunity to comment within a reasonable period. The Board shall, without prejudice to Article 76, make the results of the consultation procedure publicly available.

The full entry, with the citation mapping v1 = 32016R0679, v2 = 02016R0679-20160504, is committed at eu/32016R0679/CHANGELOG.md.