[{"content":" Source: California Privacy Protection Agency (CPPA / CalPrivacy) official website\nCollected: 2026-09-24\nOfficial links:\nAnnouncement (2026-01-08): https://cppa.ca.gov/announcements/2026/20260108.html Decision (PDF): https://cppa.ca.gov/pdf/datamasters_order_signed.pdf Case Case/Matter number: Case No. ENF25-172-D-DA (body of the decision; verified 2026-09-24 against the archived original) Authority: California Privacy Protection Agency (CPPA / CalPrivacy) Board Date: announcement 2026-01-08; decision signed 2025-12-30 (signature page: template \u0026ldquo;IT IS SO ORDERED this ____ day of ____, 2025\u0026rdquo; + handwritten \u0026ldquo;30th December\u0026rdquo;; corroborated by the same-batch S\u0026amp;P Global digital signature of 2025-12-30; verified 2026-09-24) Applicable law: California Delete Act — annual data broker registration duty Holding (official text quoted): \u0026ldquo;The first decision requires Rickenbacher Data LLC, d/b/a Datamasters, a Texas-based reseller of personal information for targeted advertising, to pay a $45,000 fine for failing to register as a data broker in violation of California\u0026rsquo;s Delete Act. The decision also orders the company to stop selling all Californians\u0026rsquo; personal information.\u0026rdquo;\n\u0026ldquo;According to the decision, Datamasters bought and resold the names, addresses, phone numbers, and email addresses of millions of people with Alzheimer\u0026rsquo;s disease, drug addiction, bladder incontinence, and other health conditions for targeted advertising. In addition, Datamasters bought and resold lists of people based on age and perceived race, offering \u0026quot;Senior Lists\u0026quot; and \u0026quot;Hispanic Lists,\u0026quot; as well as lists based on political views, grocery store purchases, banking activity, and health-related purchases. The company engaged in these activities in 2024 without registering with the California Data Broker Registry.\u0026rdquo;\n\u0026ldquo;As a result of the Board\u0026rsquo;s decision, Datamasters will stop selling all forms of personal information about Californians, effectively removing it from the marketplace in California.\u0026rdquo;\nJurisdiction: United States (California) ","permalink":"https://ai.intlaws.com/en/cases/%E7%BE%8E%E5%9B%BD-calprivacy%E6%95%B0%E6%8D%AE%E7%BB%8F%E7%BA%AA%E6%89%A7%E6%B3%95-datamasters%E6%A1%88/","summary":"The California Privacy Protection Agency (CPPA / CalPrivacy) Board decided that Rickenbacher Data LLC (d/b/a Datamasters) violated the California Delete Act by failing to register as a data broker: a USD 45,000 fine and a ban on selling Californians\u0026rsquo; personal information. Case number and signature date verified against the archived original (2026-09-24).","title":"Case Collection — US CalPrivacy Data Broker Enforcement: Datamasters (Unregistered Data Broker)"},{"content":" Source: California Privacy Protection Agency (CPPA / CalPrivacy) official website\nCollected: 2026-09-24\nOfficial links:\nAnnouncement (2026-01-08): https://cppa.ca.gov/announcements/2026/20260108.html Decision (PDF): https://cppa.ca.gov/pdf/sp_global_inc_fo_signed.pdf Case Case/Matter number: Case No. ENF25-220-D-SP (body of the decision; verified 2026-09-24 against the archived original) Authority: California Privacy Protection Agency (CPPA / CalPrivacy) Board Date: decision signed 2025-12-30 — extracted verbatim from the PDF digital-signature text layer: Signed by: jill hamer / Date: 2025-12-30 18:45:17 (Jill Hamer, Board Member); announcement 2026-01-08 Applicable law: California Delete Act — annual data broker registration duty Holding (official text quoted): \u0026ldquo;The second decision requires S\u0026amp;P Global, Inc., a New York-based provider of data and technology, to pay a $62,600 fine for failing to register as a data broker due to an administrative error. In addition to the fine, the decision requires S\u0026amp;P Global to adopt procedures for registration and compliance auditing to prevent similar errors in the future.\u0026rdquo;\nJurisdiction: United States (California) ","permalink":"https://ai.intlaws.com/en/cases/%E7%BE%8E%E5%9B%BD-calprivacy%E6%95%B0%E6%8D%AE%E7%BB%8F%E7%BA%AA%E6%89%A7%E6%B3%95-spglobal%E6%A1%88/","summary":"The California Privacy Protection Agency (CPPA / CalPrivacy) Board decided that S\u0026amp;P Global, Inc. failed to register as a data broker due to an administrative error: a USD 62,600 fine plus registration and compliance-audit procedures. Digital signature date 2025-12-30 extracted from the decision\u0026rsquo;s signature panel; case number verified (2026-09-24).","title":"Case Collection — US CalPrivacy Data Broker Enforcement: S\u0026P Global (Unregistered Data Broker)"},{"content":" Source: Colorado General Assembly, official session law (Ch. 131, 2026)\nOfficial link: https://leg.colorado.gov/laws/session-laws/SB26-189/131/download Note: English original text. 本页为官方英文原文;中文译本整理中,发布后将在此链接。\nKey dates: Approved May 14, 2026; applies to consequential decisions made on or after January 1, 2027(义务适用日;生效日与义务适用日分列)\nCHAPTER 131\nCONSUMER AND COMMERCIAL TRANSACTIONS SENATE BILL 26-189\nBY SENATOR(S) Rodriguez and Coleman, Baisley, Amabile, Ball, Benavidez, Bridges, Cutter, Exum, Frizell, Kirkmeyer, Kolker, Lindstedt, Marchman, Pelton B., Pelton R., Rich, Simpson, Snyder; also REPRESENTATIVE(S) Duran and Bacon, Titone, Boesenecker, Brown, Caldwell, Carter, Clifford, English, Flanell, Goldstein, Gonzalez R., Hamrick, Jackson, Lieder, Lindsay, McCormick, Nguyen, Paschal, Rutinel, Slaugh, Smith, Story, Velasco, Winter T., McCluskie.\nAN ACT CONCERNING THE USE OF AUTOMATED DECISION-MAKING TECHNOLOGY IN CONSEQUENTIAL DECISIONS , AND , IN CONNECTION THEREWITH , MAKING AN APPROPRIATION .\nBe it enacted by the General Assembly of the State of Colorado:\nSECTION 1. In Colorado Revised Statutes, repeal and reenact, with amendments, part 17 of article 1 of title 6 as follows: PART 17 AUTOMATED DECISION-MAKING TECHNOLOGY IN CONSEQUENTIAL DECISIONS 6-1-1701. Definitions. AS USED IN THIS PART 17, UNLESS THE CONTEXT OTHERWISE REQUIRES : (1) \u0026ldquo;A DVERSE OUTCOME \u0026quot; MEANS :\n(a) A DECISION THAT DENIES , TERMINATES , REVOKES , OR MATERIALLY REDUCES OR RESTRICTS A CONSUMER \u0026lsquo;S ACCESS TO , ELIGIBILITY FOR , SELECTION FOR ,\nCOMPENSATION FOR , OR THE PROVISION OF AN OPPORTUNITY OR SERVICE ; OR\n(b) A DECISION THAT RESULTS IN MATERIALLY LESS FAVORABLE DIFFERENTIATED PRICE , COST , COMPENSATION , OR OTHER MATERIAL TERMS THAT ARE REASONABLY LIKELY TO MATERIALLY LIMIT , DELAY , OR EFFECTIVELY DENY , OR OTHERWISE FUNDAMENTALLY ALTER , A CONSUMER \u0026lsquo;S ACCESS TO , ELIGIBILITY FOR , SELECTION\n))))) Capital letters or bold \u0026amp; italic numbers indicate new material added to existing law; dashes through words or numbers indicate deletions from existing law and such material is not part of the act. FOR , COMPENSATION FOR , OR THE PROVISION OF AN OPPORTUNITY OR SERVICE COMPARED TO TERMS OFFERED TO SIMILARLY SITUATED CONSUMERS . IF A DECISION OUTCOME IMPOSES MATERIALLY LESS FAVORABLE DIFFERENTIATED PRICING OR TERMS , THE DECISION OUTCOME MATERIALLY INFLUENCES PRICE , COST SHARING ,\nCOMPENSATION , OR MATERIAL TERMS .\n(2)\n(a) \u0026ldquo;A UTOMATED DECISION-MAKING TECHNOLOGY \u0026quot; OR \u0026ldquo;ADMT\u0026rdquo; MEANS A TECHNOLOGY THAT PROCESSES PERSONAL DATA AND USES COMPUTATION TO GE N E R A TE O U T P U T , IN C L U D IN G P R E D IC T IO N S , R E C O M M E N D A TIO N S ,\nCLASSIFICATIONS , RANKINGS , SCORES , OR OTHER INFORMATION THAT IS USED TO MAKE , GUIDE , OR ASSIST A DECISION , JUDGMENT , OR DETERMINATION CONCERNING AN INDIVIDUAL .\n(b) \u0026ldquo;A UTOMATED DECISION-MAKING TECHNOLOGY \u0026quot; OR \u0026ldquo;ADMT\u0026rdquo; DOES NOT INCLUDE :(I) T HE FOLLOWING TECHNOLOGIES :(A) A NTI-MALWARE ;(B) A NTI-VIRUS ;(C) C ALCULATORS ;(D) D ATABASES ;(E) D ATA STORAGE ;(F) F IREWALLS ;(G) I NTERNET DOMAIN REGISTRATION ;(H) I NTERNET WEBSITE LOADING ;(I) N ETWORKING ;(J) S PAM - AND ROBOCALL-FILTERING ;(K) S PELL-CHECKING ;(L) S PREADSHEETS THAT REQUIRE HUMAN ANALYSIS AND DO NOT USE MACHINE LEARNING , FOUNDATION MODELS , OR LARGE LANGUAGE MODELS ;(M) W EB CACHING ; OR\n(N) W EB HOSTING ;(II) A TOOL USED BY AN INDIVIDUAL SOLELY TO SUMMARIZE , ORGANIZE ,\nTRANSLATE , DRAFT , ROUTE , OR PRESENT INFORMATION FOR HUMAN REVIEW OF ADMINISTRATIVE PROCESSING ; OR (III) TECHNOLOGY THAT COMMUNICATES WITH CONSUMERS IN NATURAL LANGUAGE OR OTHER MEANS READILY UNDERSTOOD BY AN AVERAGE CONSUMER FOR THE PURPOSE OF PROVIDING CONSUMERS WITH INFORMATION , MAKING REFERRALS OR RECOMMENDATIONS , ANSWERING QUESTIONS , OR GENERATING OTHER CONTENT , IF :(A) THE TECHNOLOGY IS NOT CONTRACTED , ADVERTISED , MARKETED ,\nCONFIGURED , OR INTENDED BY A PERSON TO BE USED IN A CONSEQUENTIAL DECISION ; AND\n(B) THE TECHNOLOGY IS SUBJECT TO AN ACCEPTABLE USE POLICY THAT PROHIBITS GENERATED CONTENT TO BE USED IN A CONSEQUENTIAL DECISION .\n(3)\n(a) \u0026ldquo;C ONSEQUENTIAL DECISION \u0026quot; MEANS :(I) A DECISION , DETERMINATION , OR ACTION MADE ABOUT A CONSUMER THAT RELATES TO THE PROVISION OF OR A CONSUMER \u0026lsquo;S ACCESS TO , ELIGIBILITY FOR ,\nSELECTION FOR , OR COMPENSATION FOR A COVERED DOMAIN ; OR\n(II) A DECISION , DETERMINATION , OR ACTION ABOUT A CONSUMER THAT RELATES TO A DIFFERENTIATED PRICE , COST SHARING , COMPENSATION , OR OTHER MATERIAL TERMS IN A MANNER THAT IS REASONABLY LIKELY TO MATERIALLY LIMIT , DELAY ,\nEFFECTIVELY DENY , OR OTHERWISE FUNDAMENTALLY ALTER THE CONSUMER \u0026lsquo;SACCESS , ELIGIBILITY , OR OPPORTUNITY FOR A COVERED DOMAIN .\n(b) \u0026ldquo;C ONSEQUENTIAL DECISION \u0026quot; DOES NOT INCLUDE :(I) LOW-STAKES OR ROUTINE DECISIONS , ACTIONS , AND BUSINESS PROCESSES THAT DO NOT MATERIALLY INFLUENCE ELIGIBILITY FOR , SELECTION FOR , DENIAL OF ,\nCOMPENSATION FOR , PRICING OF , OR ACCESS TO AN OPPORTUNITY OR SERVICE FOR A COVERED DOMAIN , INCLUDING ROUTINE SCHEDULING , CLASSROOM PERSONALIZATION , ADMINISTRATIVE ROUTING , CUSTOMER SERVICE TRIAGE ,\nCOMMUNICATION OF DECISIONS , OR WORKFLOW MANAGEMENT ;(II) A DVERTISING , MARKETING , DIFFERENTIATED PRODUCT RECOMMENDATIONS ,\nSEARCH , OR CONTENT MODERATION ;(III) S PREADSHEETS THAT REQUIRE MANUAL HUMAN ANALYSIS AND DO NOT USE MACHINE LEARNING , FOUNDATION MODELS , OR LARGE LANGUAGE MODELS ;(IV) ACTIONS IN WHICH AN ADMT IS USED TO SUMMARIZE , ORGANIZE , OR PRESENT INFORMATION FOR HUMAN REVIEW AND THE SYSTEM DOES NOT PRODUCE A SCORE , RANKING , RECOMMENDATION , CLASSIFICATION , PREDICTION , OR OTHER INFERENCE THAT MATERIALLY INFLUENCES AN OUTCOME OR A DECISION ;(V) N ARROW PROCEDURAL TASKS OR DATA-PROCESSING FUNCTIONS THAT DO NOT GENERATE A PREDICTION OR INFERENCE ABOUT A CONSUMER OR MATERIALLY INFLUENCE A CONSEQUENTIAL DECISION OR CONSEQUENTIAL DECISION PROCESS ;(VI) A CTIVITIES RELATING TO TECHNOLOGIES USED FOR CYBERSECURITY , SPAM- AND ROBO-CALL FILTERING , SYSTEM RELIABILITY , AND ANTI-MONEY LAUNDERING AND COUNTER-TERRORIST FINANCING CONTROLS ;(VII) A CTIVITIES RELATING TO TECHNOLOGIES USED FOR ECONOMIC SANCTIONS COMPLIANCE , INCLUDING UNDER THE FEDERAL \u0026ldquo;B ANK SECRECY ACT \u0026ldquo;, 12 U.S.C.\nSEC . 1951 ET SEQ .; THE FEDERAL \u0026ldquo;USA PATRIOT ACT \u0026ldquo;, PUB .L. 107-56; THE FEDERAL TRADE COMMISSION \u0026lsquo;S RED FLAGS RULE , 16 CFR 681, AS AMENDED ; AND SANCTIONS PROGRAMS ADMINISTERED BY THE UNITED STATES DEPARTMENT OF THE TREASURY , EXCLUDING FACIAL RECOGNITION UNLESS THE SOLE PURPOSE OF WHICH IS TO CONFIRM AN INDIVIDUAL \u0026lsquo;S IDENTITY ;(VIII) A CTIVITIES RELATING TO TECHNOLOGIES USED FOR FRAUD PREVENTION ,\nINCLUDING IDENTITY VERIFICATION , CONSUMER IDENTIFICATION , MONITORING , AND REPORTING CONTROLS REQUIRED UNDER STATE OR FEDERAL LAW ; OR\n(IX) R OUTINE ACADEMIC ADMINISTRATION AND STUDENT SUPPORT PROCESSES THAT DO NOT MATERIALLY INFLUENCE A CONSEQUENTIAL DECISION .\n(4)\n(a) \u0026ldquo;C ONSUMER \u0026quot; HAS THE MEANING SET FORTH IN SECTION 6-1-1303 (6)(a).\n(b) \u0026ldquo;C ONSUMER \u0026quot; INCLUDES AN EMPLOYEE , A JOB APPLICANT WHO IS A COLORADO RESIDENT , AND ANY INDIVIDUAL WHOSE ACCESS TO , ELIGIBILITY FOR , OR OPPORTUNITY IN COLORADO IS EVALUATED IN A CONSEQUENTIAL DECISION BY A PERSON DOING BUSINESS IN COLORADO .\n(5) \u0026ldquo;C OVERED ADMT\u0026rdquo; MEANS AUTOMATED DECISION-MAKING TECHNOLOGY THAT IS USED TO MATERIALLY INFLUENCE A CONSEQUENTIAL DECISION .\n(6) \u0026ldquo;C OVERED DOMAIN \u0026quot; MEANS :\n(a) A N EDUCATION ENROLLMENT OR AN EDUCATION OPPORTUNITY ;\n(b) E MPLOYMENT OR AN EMPLOYMENT OPPORTUNITY THAT CREATES OR MAY CREATE AN EMPLOYER-EMPLOYEE RELATIONSHIP ;\n(c) T HE LEASE OR PURCHASE OF RESIDENTIAL REAL ESTATE IN COLORADO ;\n(d) A FINANCIAL OR LENDING SERVICE ;\n(e) INSURANCE , INCLUDING UNDERWRITING , PRICING , COVERAGE , CLAIMS ADJUDICATION , OR OTHER DETERMINATIONS THAT MATERIALLY AFFECT ACCESS TO BENEFITS ;\n(f) H EALTH-CARE SERVICES ; OR\n(g) ESSENTIAL GOVERNMENT SERVICES AND PUBLIC BENEFITS , INCLUDING ELIGIBILITY AND RENEWAL DETERMINATIONS .\n(7) \u0026ldquo;D EPLOYER \u0026quot; MEANS A PERSON DOING BUSINESS IN COLORADO THAT DEPLOYS A COVERED ADMT. (8)\n(a) \u0026ldquo;D EVELOPER \u0026quot; MEANS A PERSON DOING BUSINESS IN COLORADO THAT :(I) DEVELOPS , OFFERS , SELLS , LEASES , LICENSES , OR OTHERWISE MAKES COMMERCIALLY AVAILABLE A COVERED ADMT; (II) DEVELOPS A COMPONENT THAT IS DESIGNED , MARKETED , INTENDED ,\nDOCUMENTED , ADVERTISED , CONFIGURED , OR CONTRACTED TO BE USED AS PART OF A COVERED ADMT; OR\n(III) I NTENTIONALLY AND SUBSTANTIALLY MODIFIES AN ADMT SUCH THAT IT BECOMES A COVERED ADMT.\n(b) \u0026ldquo;D EVELOPER \u0026quot; DOES NOT INCLUDE A PERSON THAT :(I) D EVELOPS AND USES AN ADMT: (A) SOLELY FOR RESEARCH PURPOSES AND THE ADMT IS NOT USED IN A CONSEQUENTIAL DECISION IN THE RESEARCH ; OR\n(B) F OR INTERNAL PURPOSES , SUCH AS USE AND DEVELOPMENT ACTIVITIES BY AFFILIATES AND COMMERCIAL SUPPORT FUNCTIONS , AND THAT DOES NOT MAKE THE SYSTEM AVAILABLE TO ANOTHER PERSON FOR USE IN A CONSEQUENTIAL DECISION ;(II) IS A PRECEDING DEVELOPER THAT MAKES AN ADMT COMMERCIALLY AVAILABLE AND AN UNAFFILIATED PERSON MODIFIES THE COVERED ADMT IN A MANNER THAT CHANGES THE SYSTEM \u0026lsquo;S INTENDED , DOCUMENTED , MARKETED ,\nADVERTISED , CONFIGURED , OR CONTRACTED USE ; OR\n(III) HAS DESIGNED , MARKETED , INTENDED , DOCUMENTED , ADVERTISED ,\nCONFIGURED , OR CONTRACTED A COMPONENT THAT IS USED AS PART OF AN ADMT,\nBUT THE COMPONENT IS INTEGRATED INTO A COVERED ADMT WITHOUT THE ACTUAL KNOWLEDGE OF THE PERSON .\n(9) \u0026ldquo;E MPLOYEE \u0026quot; HAS THE MEANING SET FORTH IN SECTION 8-4-101 (5).\n(10) \u0026ldquo;E MPLOYER \u0026quot; HAS THE MEANING SET FORTH IN SECTION 8-4-101 (6).\n(11) \u0026ldquo;FERPA\u0026rdquo; MEANS THE FEDERAL \u0026ldquo;F AMILY EDUCATIONAL RIGHTS AND\nPRIVACY ACT OF 1974\u0026rdquo;, 20 U.S.C. SEC . 1232g ET SEQ ., AND ITS IMPLEMENTING REGULATIONS . (12) \u0026ldquo;I NTENTIONAL AND SUBSTANTIAL MODIFICATION \u0026quot; MEANS A DELIBERATE CHANGE MADE TO AN ADMT THAT RESULTS IN A MATERIAL CHANGE TO THE SYSTEM \u0026lsquo;S INTENDED , DOCUMENTED , ADVERTISED , CONFIGURED , OR CONTRACTED USE .\n(13)\n(a) \u0026ldquo;M ATERIALLY INFLUENCE \u0026quot; MEANS :(I) A N ADMT OUTPUT IS A NON-DE MINIMIS FACTOR THAT IS USED IN MAKING A CONSEQUENTIAL DECISION ; AND (II) A N ADMT OUTPUT AFFECTS THE OUTCOME OF A CONSEQUENTIAL DECISION ,\nINCLUDING BY CONSTRAINING , RANKING , SCORING , RECOMMENDING , CLASSIFYING ,\nOR OTHERWISE MEANINGFULLY ALTERING HOW A CONSEQUENTIAL DECISION IS MADE .\n(b) \u0026ldquo;M ATERIALLY INFLUENCE \u0026quot; DOES NOT INCLUDE INCIDENTAL , TRIVIAL , OR CLERICAL USES .\n(14)\n(a) \u0026ldquo;M ATERIAL UPDATE \u0026quot; MEANS AN UPDATE , PATCH , RELEASE , REVISION , OR NEW VERSION OF A COVERED ADMT, INCLUDING ASSOCIATED SOFTWARE , MODEL PARAMETERS , DEFAULT SETTINGS , OR DOCUMENTATION , THAT A DEVELOPER KNOWS OR REASONABLY SHOULD KNOW IS LIKELY TO MATERIALLY AFFECT :(I) T HE COVERED ADMT\u0026rsquo; S OUTPUTS OR PERFORMANCE IN A MANNER RELEVANT TO ITS INTENDED USE ; OR\n(II) T HE DEVELOPER \u0026lsquo;S STATED INTENDED USE FOR THE COVERED ADMT.\n(b) \u0026ldquo;M ATERIAL UPDATE \u0026quot; DOES NOT INCLUDE ROUTINE MAINTENANCE , COSMETIC CHANGES , OR BUG FIXES THAT DO NOT MATERIALLY INFLUENCE :(I) A COVERED ADMT\u0026rsquo; S OUTPUTS OR PERFORMANCE IN A MANNER RELEVANT TO ITS INTENDED USE ; OR\n(II) A DEVELOPER \u0026lsquo;S STATED INTENDED USE FOR THE COVERED ADMT.\n(15) \u0026ldquo;M EANINGFUL HUMAN REVIEW \u0026quot; MEANS REVIEW BY A INDIVIDUAL DESIGNATED BY THE DEPLOYER WHO HAS AUTHORITY TO APPROVE , MODIFY , OR OVERRIDE A CONSEQUENTIAL DECISION AND WHO :\n(a) C ONSIDERS RELEVANT , AVAILABLE PRIMARY EVIDENCE ;\n(b) I S TRAINED TO CONDUCT THE REVIEW ;\n(c) D OES NOT DEFAULT TO THE SYSTEM OUTPUT ; AND\n(d) H AS ACCESS TO SUFFICIENT INFORMATION TO UNDERSTAND :(I) T HE OUTPUT \u0026lsquo;S:(A) I NTENDED USE ;(B) M ATERIAL LIMITATIONS ; AND\n(C) C ATEGORIES OF INPUTS ; AND\n(II) THE PRINCIPAL FACTORS USED TO GENERATE THE OUTPUT , WITHOUT REQUIRING DISCLOSURE OF PROPRIETARY SOURCE CODE , MODEL WEIGHTS , OR OTHER TRADE SECRETS .\n(16) \u0026ldquo;P ERSONAL DATA \u0026quot; HAS THE MEANING SET FORTH IN SECTION 6-1-1303 (17). (17) \u0026ldquo;T RADE SECRET \u0026quot; HAS THE MEANING SET FORTH IN SECTION 7-74-102 (4).\n6-1-1702. Developer responsibilities - documentation. (1) O N AND AFTER JANUARY 1, 2027, A DEVELOPER SHALL MAKE AVAILABLE TO EACH DEPLOYER OF A COVERED ADMT DEVELOPED BY THE DEVELOPER , IN A FORM AND MANNER THAT IS REASONABLY UNDERSTANDABLE TO A DEPLOYER AND THAT PROTECTS TRADE SECRETS OR INFORMATION PROTECTED FROM DISCLOSURE BY STATE OR FEDERAL LAW :\n(a) A GENERAL STATEMENT DESCRIBING THE INTENDED USES AND KNOWN HARMFUL OR INAPPROPRIATE USES OF THE COVERED ADMT;\n(b) A DESCRIPTION OF THE CATEGORIES OF DATA , INCLUDING PERSONAL DATA ,\nUSED TO TRAIN THE COVERED ADMT, TO THE EXTENT KNOWN ;\n(c) K NOWN LIMITATIONS OF THE COVERED ADMT, INCLUDING KNOWN RISKS AND CIRCUMSTANCES IN WHICH THE COVERED ADMT SHOULD NOT BE USED ;\n(d) INSTRUCTIONS FOR THE DEPLOYER \u0026lsquo;S APPROPRIATE USE , MONITORING , AND MEANINGFUL HUMAN REVIEW , WHERE APPLICABLE ;\n(e) I NFORMATION REASONABLY NECESSARY FOR THE DEPLOYER TO COMPLY WITH SECTION 6-1-1704. IF INFORMATION IS WITHHELD , THE DEVELOPER SHALL NOTIFY THE DEPLOYER .\n(2)\n(a) A DEVELOPER SHALL PROVIDE TO EACH DEPLOYER OF A COVERED ADMT\nDEVELOPED BY THE DEVELOPER A NOTICE OF MATERIAL UPDATES , INTENTIONAL AND SUBSTANTIAL MODIFICATIONS , AND CHANGES TO THE INTENDED USE OF , LIMITATIONS FOR , OR RISK MITIGATION FOR THE COVERED ADMT WITHIN A REASONABLE TIME .\n(b) A DEVELOPER MAY USE PUBLIC RELEASE NOTES CONTAINING THE INFORMATION REQUIRED BY SUBSECTION (2)\n(a) OF THIS SECTION TO COMPLY WITH THIS SUBSECTION\n(2) IF THE DEVELOPER PROVIDES DIRECT NOTICE OF THE PUBLIC RELEASE TO EACH DEPLOYER OF THE COVERED ADMT.\n(3) A DEVELOPER IS SUBJECT TO THE DISCLOSURE REQUIREMENTS DESCRIBED IN SUBSECTIONS\n(1) AND\n(2) OF THIS SECTION ONLY FOR A DEPLOYER \u0026lsquo;S USE OF A COVERED ADMT WHERE THE ADMT WAS MARKETED , ADVERTISED , CONFIGURED ,\nCONTRACTED , SOLD , OR LICENSED TO BE USED TO MATERIALLY INFLUENCE A CONSEQUENTIAL DECISION .\n(4) A DEVELOPER SHALL RETAIN , FOR NOT LESS THAN THREE YEARS AFTER THE CREATION OF A RECORD REQUIRED OR CREATED UNDER THIS SECTION OR FOR A LONGER PERIOD IF REQUIRED BY APPLICABLE STATE OR FEDERAL LAW , RECORDS REASONABLY NECESSARY TO DEMONSTRATE COMPLIANCE WITH THIS SECTION .RECORDS INCLUDE SYSTEM VERSION IDENTIFIERS , CHANGELOGS , AND DOCUMENTATION AND NOTICES OF MATERIAL UPDATES PROVIDED TO DEPLOYERS PURSUANT TO SUBSECTION\n(2) OF THIS SECTION .\n(5) T HIS SECTION APPLIES WHEN A DEVELOPER CREATES A COVERED ADMT THAT IS INTENDED , DOCUMENTED , MARKETED , ADVERTISED , CONFIGURED , OR CONTRACTED TO BE USED TO MAKE CONSEQUENTIAL DECISIONS OR WHEN THE DEVELOPER BECOMES AWARE THAT THE COVERED ADMT IS BEING USED TO MAKE CONSEQUENTIAL DECISIONS IN A MANNER CONSISTENT WITH THE INTENDED AND CONTRACTED USES .\n6-1-1703. Deployer record keeping. A DEPLOYER SHALL RETAIN , FOR NOT LESS THAN THREE YEARS AFTER THE DATE OF A CONSEQUENTIAL DECISION OR FOR A LONGER PERIOD IF REQUIRED BY APPLICABLE STATE OR FEDERAL LAW , RECORDS REASONABLY NECESSARY TO DEMONSTRATE COMPLIANCE WITH THIS PART 17. RECORDS MAY INCLUDE , AS APPLICABLE , COVERED ADMT VERSION IDENTIFIERS , CHANGELOGS , AND DOCUMENTATION OF MATERIAL MITIGATION CHANGES . 6-1-1704. Deployer disclosures - point-of-interaction notice - public posting option - post-adverse outcome disclosures - legislative declaration - trade secrets - compliance with other law - accessibility - rules. (1) P RIOR TO A DEPLOYER USING A COVERED ADMT TO MATERIALLY INFLUENCE A CONSEQUENTIAL DECISION , THE DEPLOYER SHALL PROVIDE A CLEAR AND CONSPICUOUS NOTICE TO A CONSUMER THAT THE DEPLOYER USED OR WILL USE A COVERED ADMT IN A CONSEQUENTIAL DECISION AFFECTING THE CONSUMER AND INSTRUCTIONS REGARDING HOW THE CONSUMER MAY OBTAIN THE ADDITIONAL INFORMATION DESCRIBED IN THIS SECTION .\n(2) A DEPLOYER COMPLIES WITH SUBSECTION\n(1) OF THIS SECTION BY MAINTAINING A PROMINENT PUBLIC NOTICE THAT IS REASONABLY ACCESSIBLE AT POINTS OF CONSUMER INTERACTION , INCLUDING THROUGH A LINK OR POSTING THAT IS REASONABLY PROXIMATE TO THE INTERACTION OR TRANSACTION IN WHICH A CONSEQUENTIAL DECISION MAY OCCUR .\n(3) IF A DEPLOYER USES A COVERED ADMT TO MATERIALLY INFLUENCE A CONSEQUENTIAL DECISION THAT RESULTS IN AN ADVERSE OUTCOME FOR ACONSUMER , THE DEPLOYER SHALL PROVIDE WITHIN THIRTY DAYS AFTER MAKING THE DECISION :\n(a) A PLAIN LANGUAGE DESCRIPTION OF THE CONSEQUENTIAL DECISION AND THE ROLE THE COVERED ADMT PLAYED IN THE CONSEQUENTIAL DECISION ;\n(b) I NSTRUCTIONS AND A SIMPLE-TO-FOLLOW PROCESS TO REQUEST ADDITIONAL INFORMATION ABOUT THE COVERED ADMT AND THE INPUTS , INCLUDING THE NAME OF THE COVERED ADMT, THE COVERED ADMT VERSION NUMBER , IF APPLICABLE ,\nTHE COVERED ADMT DEVELOPER , AND THE TYPES , CATEGORIES , AND SOURCES OF PERSONAL DATA USED , TO THE EXTENT THE DEPLOYER RECEIVES THE NECESSARY INFORMATION FROM THE DEVELOPER IN COMPLIANCE WITH SECTION 6-1-1702; AND\n(c) A N EXPLANATION OF THE CONSUMER RIGHTS DESCRIBED IN SECTION 6-1-1705\nAND HOW TO EXERCISE THEM .\n(4)\n(a) T HE GENERAL ASSEMBLY FINDS THAT THE SPECIFIC CONTENT AND FORMAT OF POST-ADVERSE OUTCOME DISCLOSURES MAY VARY ACROSS CONSEQUENTIAL DECISION DOMAINS . THE GENERAL ASSEMBLY INTENDS THAT THE SPECIFIC ELEMENTS OF POST-ADVERSE OUTCOME DISCLOSURES BE FURTHER CLARIFIED THROUGH RULE-MAKING THAT ACCOUNTS FOR SECTOR-SPECIFIC PRACTICES WHILE ENSURING THAT CONSUMERS RECEIVE MEANINGFUL AND UNDERSTANDABLE INFORMATION ABOUT CONSEQUENTIAL DECISIONS .\n(b) O N OR BEFORE JANUARY 1, 2027, THE ATTORNEY GENERAL SHALL ADOPT RULES TO CLARIFY AND IMPLEMENT THE POST-ADVERSE OUTCOME DISCLOSURE REQUIREMENTS SET FORTH IN SUBSECTION\n(3) OF THIS SECTION . RULES ADOPTED PURSUANT TO THIS SUBSECTION\n(4) MAY INCLUDE , AS APPROPRIATE :(I) R ULES CLARIFYING THE CONTENT OF REQUIRED DISCLOSURES RELATED TO THE TYPES , SOURCES , OR CATEGORIES OF PERSONAL DATA THAT A DEPLOYER MUST PROVIDE TO A CONSUMER FOLLOWING AN ADVERSE OUTCOME INVOLVING ACOVERED ADMT PURSUANT TO SUBSECTION\n(3) OF THIS SECTION ;(II) SECTOR-SPECIFIC GUIDANCE OR ILLUSTRATIVE EXAMPLES TAILORED TO DIFFERENT COVERED DOMAINS ;(III) STANDARDS FOR DESCRIBING THE ROLE OF THE COVERED ADMT IN A CONSEQUENTIAL DECISION IN A MANNER THAT IS REASONABLY UNDERSTANDABLE TO A CONSUMER ; AND\n(IV) G UIDANCE ADDRESSING HOW THE DISCLOSURE REQUIREMENTS DESCRIBED IN THIS SECTION INTERACT WITH FEDERAL OR STATE LAWS THAT REQUIRE OR GOVERN NOTICES , EXPLANATIONS , OR ADVERSE OUTCOME DISCLOSURES .\n(5) NOTHING IN THIS SECTION REQUIRES A DEPLOYER TO DISCLOSE A TRADE SECRET OR INFORMATION PROTECTED FROM DISCLOSURE BY STATE OR FEDERAL LAW .IF A DEPLOYER WITHHOLDS INFORMATION PURSUANT TO THIS SUBSECTION (5), THE DEPLOYER SHALL NOTIFY THE CONSUMER .\n(6)\n(a) A CREDITOR , WITH RESPECT TO A CONSEQUENTIAL DECISION INVOLVING THE OFFERING , THE DENIAL , THE PRICING , THE SERVICING , OR OTHER MATERIAL TERMS OF CREDIT , THAT IS REQUIRED TO PROVIDE AND THAT PROVIDES A NOTICE TO A CONSUMER PURSUANT TO THE FEDERAL \u0026ldquo;E QUAL CREDIT OPPORTUNITY ACT \u0026ldquo;, 15 U.S.C. SEC . 1691 ET SEQ ., AND ITS IMPLEMENTING REGULATIONS , INCLUDING\nREGULATION B, 12 CFR 1002, AND , WHEN APPLICABLE , THE FEDERAL \u0026ldquo;F AIR CREDIT REPORTING ACT \u0026ldquo;, 15 U.S.C. SEC . 1681 ET SEQ ., COMPLIES WITH THE NOTICE OR DISCLOSURE REQUIREMENTS OF THIS SECTION THAT RELATE TO THE SAME DECISION OR ADVERSE OUTCOME IF THE NOTICE PROVIDED TO THE CONSUMER PURSUANT TO THE FEDERAL LAWS AND REGULATIONS DESCRIBED IN THIS SUBSECTION (6) (a) ALSO SATISFIES THE NOTICE OR DISCLOSURE REQUIREMENTS OF THIS SECTION .\n(b) IF A CREDITOR COMPLIES WITH THE FEDERAL LAWS AND REGULATIONS DESCRIBED IN SUBSECTION (6)\n(a) OF THIS SECTION AND COMPLIES WITH SUBSECTION\n(6)\n(a) OF THIS SECTION , THE CREDITOR IS NOT REQUIRED TO PROVIDE A SEPARATE OR DUPLICATIVE NOTICE PURSUANT TO THIS SECTION .\n(c) NOTHING IN THIS SUBSECTION\n(6) SHALL BE CONSTRUED TO REQUIRE A CREDITOR TO PROVIDE ANY NOTICE OR DISCLOSURE IN A MANNER THAT IS PROHIBITED BY FEDERAL LAW .\n(d) F OR PURPOSES OF THIS SUBSECTION (6), A NOTICE THAT COMPLIES WITH THE FEDERAL LAWS AND REGULATIONS DESCRIBED IN SUBSECTION (6)\n(a) OF THIS SECTION AND COMPLIES WITH SUBSECTION (6)\n(a) OF THIS SECTION MAY INCLUDE A BRIEF STATEMENT INDICATING THAT A COVERED ADMT WAS USED TO MATERIALLY INFLUENCE THE CONSEQUENTIAL DECISION AND INSTRUCTIONS FOR HOW THE CONSUMER MAY OBTAIN ANY ADDITIONAL INFORMATION OR EXERCISE ANY RIGHTS PROVIDED UNDER THIS PART 17.\n(7) T HIS PART 17 SHALL NOT BE CONSTRUED TO REQUIRE A PERSON TO MAKE A DISCLOSURE , PROVIDE AN EXPLANATION , OR FURNISH INFORMATION TO A CONSUMER TO THE EXTENT DOING SO WOULD BE PROHIBITED BY FEDERAL LAW OR WOULD COMPROMISE THE CONFIDENTIALITY OR INTEGRITY OF CYBERSECURITY , FRAUD PREVENTION , ANTI-MONEY LAUNDERING , COUNTER-TERRORIST FINANCING , OR ECONOMIC SANCTIONS COMPLIANCE PROGRAMS REQUIRED BY LAW .\n(8) A DEPLOYER OR DEVELOPER SHALL PROVIDE THE NOTICES AND DISCLOSURES REQUIRED BY THIS PART 17 IN A MANNER THAT IS REASONABLY ACCESSIBLE TO CONSUMERS WITH DISABILITIES AND CONSUMERS WITH LIMITED ENGLISH PROFICIENCY , CONSISTENT WITH APPLICABLE STATE AND FEDERAL LAW .\n(9)\n(a) F OR A CONSEQUENTIAL DECISION RELATING TO EDUCATION , A DEPLOYER THAT IS SUBJECT TO FERPA SATISFIES THE NOTICE AND DISCLOSURE REQUIREMENTS OF THIS SECTION BY PROVIDING NOTICE AND DISCLOSURES THROUGH PROCESSES AND CHANNELS THAT ARE CONSISTENT WITH FERPA AND THE DEPLOYER \u0026lsquo;S FERPA\nNOTICES AND STUDENT RECORD ACCESS PROCEDURES , INCLUDING , WHERE APPLICABLE , NOTICE TO A PARENT OR GUARDIAN OR AN ELIGIBLE STUDENT .\n(b) A DEPLOYER THAT IS SUBJECT TO FERPA IS NOT REQUIRED TO ESTABLISH A SEPARATE OR DUPLICATIVE NOTICE OR DISCLOSURE PROCESS IF THE DEPLOYER HAS ESTABLISHED A NOTICE OR DISCLOSURE PROCESS TO COMPLY WITH FERPA.\n6-1-1705. Consumer rights - correction - human review and reconsideration - rules. (1)\n(a) WHEN A CONSUMER EXPERIENCES AN ADVERSE OUTCOME RESULTING FROM A CONSEQUENTIAL DECISION IN WHICH A COVERED ADMT MATERIALLY INFLUENCES THE CONSEQUENTIAL DECISION , THE CONSUMER MAY REQUEST AND THE DEPLOYER SHALL PROVIDE IN RESPONSE TO THE REQUEST :(I) INSTRUCTIONS FOR REQUESTING PERSONAL DATA AND CORRECTING FACTUALLY INCORRECT OR MATERIALLY INACCURATE PERSONAL DATA USED IN A CONSEQUENTIAL DECISION THAT USED A COVERED ADMT CONSISTENT WITH SECTION 6-1-1306; AND\n(II) A N OPPORTUNITY FOR MEANINGFUL HUMAN REVIEW AND RECONSIDERATION OF THE CONSEQUENTIAL DECISION , TO THE EXTENT COMMERCIALLY REASONABLE .\n(b) FOR THE PURPOSES OF THIS SUBSECTION (1), THE EXCEPTIONS TO THE DEFINITION OF \u0026ldquo;CONSUMER \u0026quot; IN SECTION 6-1-1303 (6)\n(b) AND THE EXCEPTIONS IN SECTION 6-1-1304 (2)(k), (2)(n), AND (2)\n(o) DO NOT APPLY TO THE RIGHT TO REQUEST CORRECTION OF FACTUALLY INCORRECT OR MATERIALLY INACCURATE PERSONAL DATA PURSUANT TO THIS SUBSECTION (1).\n(c) SUBSECTION (1)\n(a) OF THIS SECTION DOES NOT REQUIRE CORRECTION OF OPINIONS , PREDICTIONS , SCORES , OR PROTECTED EVALUATIONS .\n(2)\n(a) F OR A CONSEQUENTIAL DECISION RELATING TO EDUCATION , A DEPLOYER THAT IS SUBJECT TO FERPA COMPLIES WITH THE REQUIREMENTS OF SUBSECTION\n(1) OF THIS SECTION THROUGH THE DEPLOYER \u0026lsquo;S EXISTING STUDENT RECORD INSPECTION ,\nREVIEW , AND AMENDMENT PROCEDURES AND ANY APPLICABLE DISTRICT COMPLAINT OR APPEAL PROCESS , IF THE DEPLOYER OFFERS A REASONABLE MECHANISM FOR A PARENT , GUARDIAN , OR ELIGIBLE STUDENT TO REQUEST CORRECTION OF MATERIALLY INACCURATE PERSONAL DATA AND RECONSIDERATION WHERE APPLICABLE UNDER THIS PART 17.\n(b) A DEPLOYER THAT IS SUBJECT TO FERPA IS NOT REQUIRED TO ESTABLISH A SEPARATE OR DUPLICATIVE CORRECTION OR HUMAN REVIEW AND RECONSIDERATION PROCESS IF THE DEPLOYER HAS ESTABLISHED A CORRECTION OR HUMAN REVIEW AND RECONSIDERATION PROCESS TO COMPLY WITH FERPA.\n(3) O N OR BEFORE JANUARY 1, 2027, THE ATTORNEY GENERAL SHALL ADOPT RULES TO CLARIFY AND IMPLEMENT THE REQUIREMENTS OF THIS SECTION .\n6-1-1706. Enforcement by the attorney general - deceptive trade practice-right to cure - no private right of action - joinder rules - reporting - repeal. (1)\n(a) T HE ATTORNEY GENERAL SHALL ENFORCE THIS PART 17 THROUGH THE\n\u0026ldquo;C OLORADO CONSUMER PROTECTION ACT \u0026ldquo;, THIS ARTICLE 1. (b) VIOLATIONS OF THE DISCLOSURE REQUIREMENTS AND CONSUMER RIGHTS DESCRIBED IN SECTIONS 6-1-1702, 6-1-1703, 6-1-1704, AND 6-1-1705 ARE ENFORCEABLE EXCLUSIVELY BY THE ATTORNEY GENERAL WITHOUT REGARD TO ANY OTHER PROVISION IN THIS TITLE 6.\n(2)\n(a) A VIOLATION OF THIS PART 17 IS A DECEPTIVE TRADE PRACTICE AND IS SUBJECT TO THE PROVISIONS OF THE \u0026ldquo;C OLORADO CONSUMER PROTECTION ACT \u0026ldquo;,\nTHIS ARTICLE 1.\n(b) ANY PROVISION OF THE \u0026ldquo;C OLORADO CONSUMER PROTECTION ACT \u0026ldquo;, THIS ARTICLE 1, THAT IS INCONSISTENT WITH THE EXCLUSIVE ENFORCEMENT AUTHORITY GRANTED TO THE ATTORNEY GENERAL IN THIS SECTION FOR A VIOLATION OF THIS PART 17 DOES NOT APPLY TO ANY SUCH VIOLATION .\n(3)\n(a) P RIOR TO ANY ENFORCEMENT ACTION FOR A VIOLATION OF THIS PART 17,\nTHE ATTORNEY GENERAL SHALL ISSUE A NOTICE OF VIOLATION TO A DEVELOPER OR DEPLOYER IF A CURE IS DEEMED POSSIBLE BY THE ATTORNEY GENERAL .\n(b) I F THE DEVELOPER OR DEPLOYER FAILS TO CURE A VIOLATION WITHIN SIXTY DAYS AFTER RECEIPT OF A NOTICE OF VIOLATION , THE ATTORNEY GENERAL MAY BRING AN ACTION PURSUANT TO THIS SECTION .\n(c) IF THE ATTORNEY GENERAL FINDS AND CAN DEMONSTRATE THAT ADEVELOPER OR DEPLOYER KNOWINGLY VIOLATED THIS PART 17 OR A DEVELOPER OR DEPLOYER REPEATEDLY VIOLATED THIS PART 17, THE ATTORNEY GENERAL IS NOT REQUIRED TO PROVIDE A CURE PERIOD BEFORE SEEKING PENALTIES OR OTHER RELIEF .\n(d) I F A VIOLATION IS DISCOVERED IN THE COURSE OF AN ENFORCEMENT ACTION ,\nA COURT MAY CONSIDER THAT A DEVELOPER OR DEPLOYER CURED THE VIOLATION WITHIN SIXTY DAYS AFTER RECEIPT OF WRITTEN NOTICE AS A MITIGATING FACTOR IN DETERMINING CIVIL PENALTIES OR OTHER MONETARY RELIEF , IF ANY .\n(e) B EGINNING IN JANUARY 2028, AND IN JANUARY EVERY YEAR THEREAFTER ,\nTHE ATTORNEY GENERAL SHALL INCLUDE , AS PART OF THE DEPARTMENT OF LAW \u0026lsquo;SPRESENTATION DURING ITS \u0026ldquo;SMART ACT \u0026quot; HEARING REQUIRED BY SECTION 2-7-203,\nA REPORT CONCERNING ENFORCEMENT ACTIONS BROUGHT AND CURE PERIODS OFFERED BY THE ATTORNEY GENERAL RELATED TO VIOLATIONS OF THIS PART 17,\nINCLUDING :(I) THE NUMBER OF ACTIONS FILED BY THE ATTORNEY GENERAL AGAINST DEVELOPERS AND DEPLOYERS , RESPECTIVELY ;(II) THE NUMBER OF ACTIONS FILED BY THE ATTORNEY GENERAL AGAINST DEVELOPERS AND DEPLOYERS , RESPECTIVELY , THAT WERE COMPLETED ;(III) T HE NUMBER OF CURE PERIODS OFFERED BY THE ATTORNEY GENERAL TO DEVELOPERS AND DEPLOYERS , RESPECTIVELY ;(IV) T HE NUMBER OF CURE PERIODS OFFERED BY THE ATTORNEY GENERAL THAT WERE NOT MET BY DEVELOPERS AND DEPLOYERS , RESPECTIVELY ; AND\n(V) T HE NUMBER OF VIOLATIONS FILED BY THE ATTORNEY GENERAL AGAINST DEVELOPERS AND DEPLOYERS , RESPECTIVELY , WHERE A CURE PERIOD WAS NOT DEEMED POSSIBLE .\n(f) T HIS SUBSECTION\n(3) IS REPEALED , EFFECTIVE JANUARY 1, 2030.\n(4) NOTHING IN THIS PART 17 CREATES A NEW PRIVATE RIGHT OF ACTION .NOTHING IN THIS PART 17 LIMITS OR REDUCES ANY EXISTING RIGHTS OR REMEDIES AVAILABLE UNDER STATE OR FEDERAL LAW , INCLUDING THE \u0026ldquo;C OLORADO\nANTI-DISCRIMINATION ACT \u0026ldquo;, PARTS 3 TO 8 OF ARTICLE 34 OF TITLE 24; THE \u0026ldquo;C OLORADO CONSUMER PROTECTION ACT \u0026ldquo;, THIS ARTICLE 1; PRODUCT LIABILITY LAW ; OR OTHER APPLICABLE LAW . (5)\n(a) THE ATTORNEY GENERAL MAY ADOPT RULES AS NECESSARY TO IMPLEMENT AND CLARIFY THIS PART 17.\n(b) T HE ATTORNEY GENERAL MAY ADOPT RULES TO CLARIFY THE APPLICATION OF THE DEFINITION OF \u0026ldquo;MATERIALLY INFLUENCE \u0026ldquo;, AS DEFINED IN SECTION 6-1-1701 (13), INCLUDING PRESUMPTIONS , ILLUSTRATIVE EXAMPLES , AND OBJECTIVE INDICATORS .\n(c) I N ADOPTING RULES PURSUANT TO THIS PART 17, THE ATTORNEY GENERAL SHALL UTILIZE A PROCESS THAT MEANINGFULLY ENGAGES STAKEHOLDERS ,\nINCLUDING CONSUMER ADVOCATES , DEPLOYERS , DEVELOPERS , AND SECTOR REGULATORS , THROUGH PUBLIC NOTICE , OPPORTUNITY FOR WRITTEN COMMENT , AND AT LEAST ONE PUBLIC HEARING AND SHALL ADOPT RULES IN ACCORDANCE WITH SECTION 24-4-103.\n(6) N OTHING IN THIS PART 17 LIMITS THE ABILITY OF A PARTY TO JOIN NECESSARY OR PERMISSIVE PARTIES UNDER THE COLORADO RULES OF CIVIL PROCEDURE ,\nINCLUDING RULES 19 AND 20 OF THE COLORADO RULES OF CIVIL PROCEDURE , IN ANY ACTION ARISING UNDER EXISTING LAW .\n6-1-1707. Liability - fault - allocation - no joint and several liability-indemnification prohibited - effect on existing law. (1) A DEVELOPER OR DEPLOYER MAY BE HELD LIABLE IN AN ACTION ALLEGING UNLAWFUL DISCRIMINATION UNDER STATE ANTI-DISCRIMINATION LAWS , INCLUDING THE \u0026ldquo;C OLORADO ANTI-DISCRIMINATION ACT \u0026ldquo;, PARTS 3 TO 8 OF ARTICLE 34 OF TITLE\n24, ARISING FROM A CONSEQUENTIAL DECISION MATERIALLY INFLUENCED BY A COVERED ADMT. (2) I N AN ACTION DESCRIBED IN SUBSECTION\n(1) OF THIS SECTION , FAULT SHALL BE ALLOCATED AMONG DEPLOYERS AND DEVELOPERS BASED ON THEIR RELATIVE FAULT FOR THE VIOLATION .\n(3) N OTHING IN THIS SECTION SHALL BE CONSTRUED TO APPORTION LIABILITY TO A CLAIMANT WHERE SUCH APPORTIONMENT IS NOT PROVIDED FOR UNDER EXISTING LAW .\n(4) NOTHING IN THIS SECTION SHALL BE CONSTRUED TO CREATE JOINT AND SEVERAL LIABILITY , EXCEPT TO THE EXTENT PERMITTED UNDER EXISTING LAW .\n(5)\n(a) A DEVELOPER IS LIABLE IN AN ACTION DESCRIBED IN SUBSECTION\n(1) OF THIS SECTION ONLY TO THE EXTENT THAT :(I) T HE DEVELOPER \u0026lsquo;S COVERED ADMT WAS USED BY A DEPLOYER IN A MANNER THAT WAS INTENDED , DOCUMENTED , MARKETED , ADVERTISED , CONFIGURED , OR CONTRACTED FOR BY THE DEVELOPER ; AND\n(II) THE DEVELOPER \u0026lsquo;S COVERED ADMT MATERIALLY INFLUENCED ACONSEQUENTIAL DECISION THAT GAVE RISE TO THE VIOLATION OF EXISTING LAW .\n(b) A DEVELOPER IS NOT LIABLE UNDER THIS SECTION FOR VIOLATIONS OF EXISTING LAW ARISING FROM A DEPLOYER \u0026lsquo;S USE OF A COVERED ADMT IN A MANNER THAT WAS NOT INTENDED , DOCUMENTED , MARKETED , ADVERTISED , CONFIGURED ,\nOR CONTRACTED FOR BY THE DEVELOPER .\n(6) N OTHING IN THIS SECTION SHALL BE CONSTRUED TO LIMIT THE LIABILITY OF A DEPLOYER FOR THE DEPLOYER \u0026lsquo;S INDEPENDENT ACTS OR OMISSIONS IN ACONSEQUENTIAL DECISION MATERIALLY INFLUENCED BY A COVERED ADMT,\nINCLUDING USING AN ADMT IN A MANNER THAT WAS NOT INTENDED , DOCUMENTED ,\nMARKETED , ADVERTISED , CONFIGURED , OR CONTRACTED FOR BY THE DEVELOPER IF THE DEVELOPER OF THE COVERED ADMT COMPLIED WITH SECTION 6-1-1702.\n(7)\n(a) N OTWITHSTANDING ANY OTHER PROVISION OF LAW , IF A PROVISION OF A CONTRACT FOR THE USE OF AUTOMATED DECISION-MAKING TECHNOLOGY IN MAKING A CONSEQUENTIAL DECISION OR ANY OTHER CONTRACT BETWEEN A DEVELOPER AND DEPLOYER PURPORTS TO INDEMNIFY , DEFEND , OR HOLD HARMLESS OR HAS THE EFFECT OF INDEMNIFYING , DEFENDING , OR HOLDING HARMLESS THE INDEMNITEE FROM OR AGAINST ANY LIABILITY FOR DAMAGES PURSUANT TO THIS SECTION RESULTING FROM THE DEVELOPER \u0026lsquo;S OR DEPLOYER \u0026lsquo;S OWN ACTS OR OMISSIONS RELATED TO THE USE OF AUTOMATED DECISION-MAKING TECHNOLOGY IN MAKING C O N S E Q U E N T IA L D E C IS IO N S I N V I O L A T I O N O F T H E \u0026ldquo;C O L O R A D O\nANTI-DISCRIMINATION ACT \u0026ldquo;, PARTS 3 TO 8 OF ARTICLE 34 OF TITLE 24, OR OTHER COLORADO ANTI-DISCRIMINATION LAW , THE PROVISION IS CONTRARY TO PUBLIC POLICY AND VOID . (b) T HE LIMITATIONS OF SUBSECTION (7)\n(a) OF THIS SECTION DO NOT APPLY TO A DEVELOPER WHERE THE USE OF THE COVERED ADMT IN MAKING A CONSEQUENTIAL DECISION WAS NOT INTENDED , DOCUMENTED , MARKETED , ADVERTISED ,\nCONFIGURED , OR CONTRACTED FOR BY THE DEVELOPER IF THE DEVELOPER OF THE COVERED ADMT COMPLIED WITH SECTION 6-1-1702.\n(c) T HIS SUBSECTION\n(7) DOES NOT OTHERWISE LIMIT THE ENFORCEABILITY OF CONTRACT TERMS BETWEEN PARTIES ACTING IN A COMMERCIAL OR BUSINESS CAPACITY , EXCEPT TO THE EXTENT OTHERWISE PROVIDED BY APPLICABLE LAW .\n(d) THIS SUBSECTION\n(7) DOES NOT PROHIBIT OR LIMIT ANY PERSON FROM OBTAINING OR MAKING A CLAIM ON APPLICABLE INSURANCE FOR ANY APPLICABLE ALLEGED LIABILITIES OR RELATED LOSSES .\n(8) NOTHING IN THIS SECTION SHALL BE CONSTRUED TO LIMIT , DISPLACE , OR OTHERWISE AFFECT ANY LIABILITY THAT A DEVELOPER OR A DEPLOYER MAY HAVE ,\nSEPARATE AND APART FROM LIABILITY UNDER THIS SECTION , FOR A VIOLATION OF STATE LAW . COMPLIANCE WITH THE REQUIREMENTS OF THIS PART 17 IS NOT A DEFENSE TO AND DOES NOT OTHERWISE EXCUSE NONCOMPLIANCE WITH ANY APPLICABLE LAW .\n(9) T HE USE OF AN ADMT IN A CONSEQUENTIAL DECISION DOES NOT EXCUSE ,\nJUSTIFY , OR PROVIDE A DEFENSE TO ANY OBLIGATION OR LIABILITY UNDER STATE OR FEDERAL LAW , INCLUDING OBLIGATIONS AND LIABILITY RELATED TO DISCRIMINATION OR CONSUMER PROTECTION .\n6-1-1708. Compliance with other legal obligations - insurers - covered entities - disclosures. (1)\n(a) AN INSURER , AS DEFINED IN SECTION 10-1-102 (13), AND AFFILIATED ENTITIES THAT ARE SUBJECT TO THE REQUIREMENTS OF SECTION 10-3-1104.9 ARE IN COMPLIANCE WITH THIS PART 17 IN THE PRACTICE OF INSURANCE . (b) I F AN INSURER IS NOT DEEMED IN COMPLIANCE PURSUANT TO SUBSECTION\n(1)\n(a) OF THIS SECTION , THE INSURER SHALL PROVIDE NOTICE AND DISCLOSURE OF ITS USE OF A COVERED ADMT IN MATERIALLY INFLUENCING A CONSEQUENTIAL DECISION REGARDING THE PRACTICE OF INSURANCE PURSUANT TO THE DISCLOSURE REQUIREMENTS OF SECTION 6-1-1704 (3), TO THE EXTENT APPLICABLE .\n(2) T HIS SECTION DOES NOT LIMIT THE APPLICABILITY OF THIS PART 17 TO USES OF COVERED ADMT RELATED TO INSURER EMPLOYMENT OR INSURER EMPLOYMENT OPPORTUNITIES BY INSURERS AND AFFILIATED ENTITIES THAT ARE SUBJECT TO THE REQUIREMENTS OF SECTION 10-3-1104.9.\n(3)\n(a) SECTIONS 6-1-1701, 6-1-1702, 6-1-1703, 6-1-1704, 6-1-1705, AND\n6-1-1706 DO NOT APPLY TO A COVERED ENTITY WITHIN THE MEANING OF THE FEDERAL \u0026ldquo;H EALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996\u0026rdquo;, 42 U.S.C. SECS . 1320d TO 1320d-9, AND THE REGULATIONS PROMULGATED UNDER THE FEDERAL ACT , OR A COVERED ENTITY \u0026lsquo;S BUSINESS ASSOCIATES FOR ANY SERVICES RENDERED TO A COVERED ENTITY , TO THE EXTENT THE COVERED ENTITY IS DOING BUSINESS IN COLORADO , EXCEPT FOR A CONSEQUENTIAL DECISION RELATED TO EMPLOYMENT OR AN EMPLOYMENT OPPORTUNITY . (b) NOTWITHSTANDING SUBSECTION (3)\n(a) OF THIS SECTION , FOR A COVERED ENTITY THAT IS A HEALTH-CARE PROVIDER , AS DEFINED IN 45 CFR 160.103, THIS SUBSECTION\n(3) APPLIES ONLY IF THE HEALTH-CARE PROVIDER IS OPERATING FROM A LOCATION WITHIN COLORADO .\n(c) A COVERED ENTITY SHALL PROVIDE PATIENTS WITH A GENERAL NOTICE OF USE OF ADVANCED TECHNOLOGIES , INCLUDING A COVERED ADMT. THE NOTICE MAY BE INCORPORATED WITH OTHER NOTICES DESCRIBING PATIENT RIGHTS AND HOW THE COVERED ENTITY PROVIDES CARE .\n(d) N OTWITHSTANDING SUBSECTION (3)\n(a) OF THIS SECTION , A COVERED ENTITY THAT USES A COVERED ADMT TO DETERMINE A PATIENT \u0026lsquo;S ELIGIBILITY FOR FINANCIAL ASSISTANCE , INCLUDING DISCOUNTED CARE AS DESCRIBED IN SECTION\n25.5-3-502, SHALL PROVIDE A PATIENT THE FOLLOWING DISCLOSURES :(I) A PLAIN LANGUAGE DESCRIPTION OF THE CONSEQUENTIAL DECISION AND THE ROLE OF THE COVERED ADMT IN THE CONSEQUENTIAL DECISION ;(II) T HE TYPES OF INFORMATION ABOUT THE INDIVIDUAL THE COVERED ENTITY RELIED UPON IN MAKING ITS DETERMINATION OF ELIGIBILITY , EXCEPT FOR TRADE SECRETS AND OTHER CONFIDENTIAL OR LEGALLY PROTECTED INFORMATION ;(III) INFORMATION ON HOW TO REQUEST CORRECTION OF MATERIALLY INACCURATE PERSONAL DATA HELD BY THE COVERED ENTITY CONSISTENT WITH THE FEDERAL \u0026ldquo;H EALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996\u0026rdquo;, 42 U.S.C. SECS . 1320d TO 1320d-9 AND SECTION 25.5-3-502; AND (IV) INFORMATION ON HOW TO REQUEST MEANINGFUL HUMAN REVIEW OR RECONSIDERATION , WHERE APPLICABLE .\n(e) A COVERED ENTITY MAY COMPLY WITH SUBSECTION (3)\n(d) OF THIS SECTION THROUGH EITHER AN ADVANCE GENERAL DISCLOSURE OF THE INFORMATION REQUIRED BY SUBSECTION (3)\n(d) OF THIS SECTION OR THROUGH A NOTICE PROVIDED WITHIN THIRTY CALENDAR DAYS AFTER AN ADVERSE OUTCOME . THIS SECTION DOES NOT CREATE A SEPARATE AND DUPLICATIVE DISCLOSURE PROCESS OR APPEAL PROCESS IF THE REVIEW OPPORTUNITIES AND INFORMATION DESCRIBED IN SUBSECTION (3)\n(d) OF THIS SECTION ARE PROVIDED .\n(4) S ECTIONS 6-1-1701, 6-1-1702, 6-1-1703, 6-1-1704, 6-1-1705, AND 6-1-1706\nDO NOT APPLY TO A MEDICAL DEVICE SUBJECT TO OVERSIGHT BY THE UNITED\nSTATES FOOD AND DRUG ADMINISTRATION OR A PHARMACEUTICAL OR MEDICAL DEVICE MANUFACTURER \u0026lsquo;S RESEARCH AND DEVELOPMENT ACTIVITIES THAT ARE SUBJECT TO OVERSIGHT BY THE UNITED STATES FOOD AND DRUG ADMINISTRATION , INCLUDING CLINICAL INVESTIGATIONS CONDUCTED UNDER 21 CFR 312.\n(5) NOTHING IN THIS PART 17 REQUIRES A COVERED ENTITY OR BUSINESS ASSOCIATE , AS THOSE TERMS ARE DEFINED UNDER THE FEDERAL \u0026ldquo;H EALTH\nINSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996\u0026rdquo;, 42 U.S.C. SECS .1320d TO 1320d-9, TO DISCLOSE PROTECTED HEALTH INFORMATION OR OTHER INFORMATION IN A MANNER THAT WOULD VIOLATE FEDERAL LAW . TO THE EXTENT COMPLIANCE WITH SECTION 6-1-1704 OR 6-1-1705 WOULD CONFLICT WITH FEDERAL HEALTH PRIVACY REQUIREMENTS , THE DEPLOYER SHALL COMPLY WITH APPLICABLE FEDERAL LAW AND PROVIDE DISCLOSURES AND ACCESS CONSISTENT WITH THAT LAW . (6) THIS PART 17 DOES NOT REQUIRE A PERSON TO DISCLOSE NONPUBLIC PERSONAL INFORMATION IN A MANNER THAT WOULD VIOLATE THE FEDERAL\n\u0026ldquo;G RAMM-L EACH-B LILEY ACT \u0026ldquo;, 15 U.S.C. SEC . 6801 ET SEQ ., OR ITS IMPLEMENTING REGULATIONS . 6-1-1709. No new private right of action - application of other law. (1) N OTHING IN THIS PART 17 CREATES A NEW PRIVATE RIGHT OF ACTION .\n(2) C OMPLIANCE WITH THIS PART 17 DOES NOT CONSTITUTE A DEFENSE TO AND DOES NOT EXCUSE NONCOMPLIANCE WITH ANY APPLICABLE LAW .\nSECTION 2. In Colorado Revised Statutes, 6-1-105, add (1)(uuuu) as follows: 6-1-105. Unfair or deceptive trade practices. (1) A person engages in a deceptive trade practice when, in the course of the person\u0026rsquo;s business, vocation, or occupation, the person: (uuuu) V IOLATES PART 17 OF THIS ARTICLE 1.\nSECTION 3. In Colorado Revised Statutes, 10-3-1104.9, add (3) (e) as follows:\n10-3-1104.9. Insurers\u0026rsquo; use of external consumer data and information sources, algorithms, and predictive models - unfair discrimination prohibited - rules - stakeholder process required - investigations - definitions. (3) (e) T HE COMMISSIONER MAY ADOPT NEW RULES OR UPDATE EXISTING RULES REGARDING NOTICE AND DISCLOSURES FROM INSURERS TO CONSUMERS .\nSECTION 4. Appropriation. For the 2026-27 state fiscal year, $46,190 is appropriated to the department of law. This appropriation is from the general fund and is based on an assumption that the department will require an additional 0.4 FTE. To implement this act, the department may use this appropriation for consumer protection, antitrust, and civil rights. SECTION 5. Effective date - applicability. (1) Except as otherwise provided in subsection\n(2) of this section, this act takes effect January 1, 2027.\n(2) Sections 6-1-1704 (4), 6-1-1705 (3), and 6-1-1706 (6), Colorado Revised Statutes, as amended in section 1 of this act, section 10-3-1104.9 (3)(e), Colorado Revised Statutes, as enacted in section 3 of this act, section 4 of this act, this section, and section 6 of this act take effect upon passage.\n(3) This act applies to consequential decisions made on or after January 1, 2027.\nSECTION 6. Safety clause. The general assembly finds, determines, and declares that this act is necessary for the immediate preservation of the public peace, health, or safety or for appropriations for the support and maintenance of the departments of the state and state institutions. Approved: May 14, 2026 ","permalink":"https://ai.intlaws.com/en/compliance/us/%E7%A7%91%E7%BD%97%E6%8B%89%E5%A4%9Asb26-189/","summary":"Official session-law text of Colorado SB 26-189 (Chapter 131, Laws of 2026), approved May 14, 2026: an amendment to the Colorado Privacy Act governing the use of artificial intelligence in consequential decisions. Obligations apply to consequential decisions made on or after January 1, 2027. English original; Chinese translation available.","title":"Colorado SB 26-189 (Artificial Intelligence Amendment to the Colorado Privacy Act)"},{"content":" Source: EUR-Lex, Official Journal L 119, 4.5.2016, p. 1–88 — CELEX 32016R0679\nOfficial links:\nEUR-Lex (EN HTML): https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679 EUR-Lex (CELEX resource): https://publications.europa.eu/resource/celex/32016R0679 Structure: Recitals (1)–(173); Chapters I–XI; Articles 1–99; in force since 24 May 2016, applicable from 25 May 2018\nNote: 本页为《欧盟官方公报》刊登的英文原文;欧盟法仅以欧盟官方语言作准,无官方中文文本。中文导读见 中文页 。 REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL\nof 27 April 2016\non the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)\n(Text with EEA relevance)\nTHE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,\nHaving regard to the Treaty on the Functioning of the European Union, and in particular Article 16 thereof,\nHaving regard to the proposal from the European Commission,\nAfter transmission of the draft legislative act to the national parliaments,\nHaving regard to the opinion of the European Economic and Social Committee(1),\nHaving regard to the opinion of the Committee of the Regions(2),\nActing in accordance with the ordinary legislative procedure(3),\nWhereas:\n(1)The protection of natural persons in relation to the processing of personal data is a fundamental right. Article 8(1) of the Charter of Fundamental Rights of the European Union (the ‘Charter’) and Article 16(1) of the Treaty on the Functioning of the European Union (TFEU) provide that everyone has the right to the protection of personal data concerning him or her.\n(2)The principles of, and rules on the protection of natural persons with regard to the processing of their personal data should, whatever their nationality or residence, respect their fundamental rights and freedoms, in particular their right to the protection of personal data. This Regulation is intended to contribute to the accomplishment of an area of freedom, security and justice and of an economic union, to economic and social progress, to the strengthening and the convergence of the economies within the internal market, and to the well-being of natural persons.\n(3)Directive 95/46/EC of the European Parliament and of the Council(4) seeks to harmonise the protection of fundamental rights and freedoms of natural persons in respect of processing activities and to ensure the free flow of personal data between Member States.\n(4)The processing of personal data should be designed to serve mankind. The right to the protection of personal data is not an absolute right; it must be considered in relation to its function in society and be balanced against other fundamental rights, in accordance with the principle of proportionality. This Regulation respects all fundamental rights and observes the freedoms and principles recognised in the Charter as enshrined in the Treaties, in particular the respect for private and family life, home and communications, the protection of personal data, freedom of thought, conscience and religion, freedom of expression and information, freedom to conduct a business, the right to an effective remedy and to a fair trial, and cultural, religious and linguistic diversity.\n(5)The economic and social integration resulting from the functioning of the internal market has led to a substantial increase in cross-border flows of personal data. The exchange of personal data between public and private actors, including natural persons, associations and undertakings across the Union has increased. National authorities in the Member States are being called upon by Union law to cooperate and exchange personal data so as to be able to perform their duties or carry out tasks on behalf of an authority in another Member State.\n(6)Rapid technological developments and globalisation have brought new challenges for the protection of personal data. The scale of the collection and sharing of personal data has increased significantly. Technology allows both private companies and public authorities to make use of personal data on an unprecedented scale in order to pursue their activities. Natural persons increasingly make personal information available publicly and globally. Technology has transformed both the economy and social life, and should further facilitate the free flow of personal data within the Union and the transfer to third countries and international organisations, while ensuring a high level of the protection of personal data.\n(7)Those developments require a strong and more coherent data protection framework in the Union, backed by strong enforcement, given the importance of creating the trust that will allow the digital economy to develop across the internal market. Natural persons should have control of their own personal data. Legal and practical certainty for natural persons, economic operators and public authorities should be enhanced.\n(8)Where this Regulation provides for specifications or restrictions of its rules by Member State law, Member States may, as far as necessary for coherence and for making the national provisions comprehensible to the persons to whom they apply, incorporate elements of this Regulation into their national law.\n(9)The objectives and principles of Directive 95/46/EC remain sound, but it has not prevented fragmentation in the implementation of data protection across the Union, legal uncertainty or a widespread public perception that there are significant risks to the protection of natural persons, in particular with regard to online activity. Differences in the level of protection of the rights and freedoms of natural persons, in particular the right to the protection of personal data, with regard to the processing of personal data in the Member States may prevent the free flow of personal data throughout the Union. Those differences may therefore constitute an obstacle to the pursuit of economic activities at the level of the Union, distort competition and impede authorities in the discharge of their responsibilities under Union law. Such a difference in levels of protection is due to the existence of differences in the implementation and application of Directive 95/46/EC.\n(10)In order to ensure a consistent and high level of protection of natural persons and to remove the obstacles to flows of personal data within the Union, the level of protection of the rights and freedoms of natural persons with regard to the processing of such data should be equivalent in all Member States. Consistent and homogenous application of the rules for the protection of the fundamental rights and freedoms of natural persons with regard to the processing of personal data should be ensured throughout the Union. Regarding the processing of personal data for compliance with a legal obligation, for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, Member States should be allowed to maintain or introduce national provisions to further specify the application of the rules of this Regulation. In conjunction with the general and horizontal law on data protection implementing Directive 95/46/EC, Member States have several sector-specific laws in areas that need more specific provisions. This Regulation also provides a margin of manoeuvre for Member States to specify its rules, including for the processing of special categories of personal data (‘sensitive data’). To that extent, this Regulation does not exclude Member State law that sets out the circumstances for specific processing situations, including determining more precisely the conditions under which the processing of personal data is lawful.\n(11)Effective protection of personal data throughout the Union requires the strengthening and setting out in detail of the rights of data subjects and the obligations of those who process and determine the processing of personal data, as well as equivalent powers for monitoring and ensuring compliance with the rules for the protection of personal data and equivalent sanctions for infringements in the Member States.\n(12)Article 16(2) TFEU mandates the European Parliament and the Council to lay down the rules relating to the protection of natural persons with regard to the processing of personal data and the rules relating to the free movement of personal data.\n(13)In order to ensure a consistent level of protection for natural persons throughout the Union and to prevent divergences hampering the free movement of personal data within the internal market, a Regulation is necessary to provide legal certainty and transparency for economic operators, including micro, small and medium-sized enterprises, and to provide natural persons in all Member States with the same level of legally enforceable rights and obligations and responsibilities for controllers and processors, to ensure consistent monitoring of the processing of personal data, and equivalent sanctions in all Member States as well as effective cooperation between the supervisory authorities of different Member States. The proper functioning of the internal market requires that the free movement of personal data within the Union is not restricted or prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data. To take account of the specific situation of micro, small and medium-sized enterprises, this Regulation includes a derogation for organisations with fewer than 250 employees with regard to record-keeping. In addition, the Union institutions and bodies, and Member States and their supervisory authorities, are encouraged to take account of the specific needs of micro, small and medium-sized enterprises in the application of this Regulation. The notion of micro, small and medium-sized enterprises should draw from Article 2 of the Annex to Commission Recommendation 2003/361/EC(5).\n(14)The protection afforded by this Regulation should apply to natural persons, whatever their nationality or place of residence, in relation to the processing of their personal data. This Regulation does not cover the processing of personal data which concerns legal persons and in particular undertakings established as legal persons, including the name and the form of the legal person and the contact details of the legal person.\n(15)In order to prevent creating a serious risk of circumvention, the protection of natural persons should be technologically neutral and should not depend on the techniques used. The protection of natural persons should apply to the processing of personal data by automated means, as well as to manual processing, if the personal data are contained or are intended to be contained in a filing system. Files or sets of files, as well as their cover pages, which are not structured according to specific criteria should not fall within the scope of this Regulation.\n(16)This Regulation does not apply to issues of protection of fundamental rights and freedoms or the free flow of personal data related to activities which fall outside the scope of Union law, such as activities concerning national security. This Regulation does not apply to the processing of personal data by the Member States when carrying out activities in relation to the common foreign and security policy of the Union.\n(17)Regulation (EC) No 45/2001 of the European Parliament and of the Council(6) applies to the processing of personal data by the Union institutions, bodies, offices and agencies. Regulation (EC) No 45/2001 and other Union legal acts applicable to such processing of personal data should be adapted to the principles and rules established in this Regulation and applied in the light of this Regulation. In order to provide a strong and coherent data protection framework in the Union, the necessary adaptations of Regulation (EC) No 45/2001 should follow after the adoption of this Regulation, in order to allow application at the same time as this Regulation.\n(18)This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity. Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities. However, this Regulation applies to controllers or processors which provide the means for processing personal data for such personal or household activities.\n(19)The protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security and the free movement of such data, is the subject of a specific Union legal act. This Regulation should not, therefore, apply to processing activities for those purposes. However, personal data processed by public authorities under this Regulation should, when used for those purposes, be governed by a more specific Union legal act, namely Directive (EU) 2016/680 of the European Parliament and of the Council(7). Member States may entrust competent authorities within the meaning of Directive (EU) 2016/680 with tasks which are not necessarily carried out for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and prevention of threats to public security, so that the processing of personal data for those other purposes, in so far as it is within the scope of Union law, falls within the scope of this Regulation.\nWith regard to the processing of personal data by those competent authorities for purposes falling within scope of this Regulation, Member States should be able to maintain or introduce more specific provisions to adapt the application of the rules of this Regulation. Such provisions may determine more precisely specific requirements for the processing of personal data by those competent authorities for those other purposes, taking into account the constitutional, organisational and administrative structure of the respective Member State. When the processing of personal data by private bodies falls within the scope of this Regulation, this Regulation should provide for the possibility for Member States under specific conditions to restrict by law certain obligations and rights when such a restriction constitutes a necessary and proportionate measure in a democratic society to safeguard specific important interests including public security and the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security. This is relevant for instance in the framework of anti-money laundering or the activities of forensic laboratories.\n(20)While this Regulation applies, inter alia, to the activities of courts and other judicial authorities, Union or Member State law could specify the processing operations and processing procedures in relation to the processing of personal data by courts and other judicial authorities. The competence of the supervisory authorities should not cover the processing of personal data when courts are acting in their judicial capacity, in order to safeguard the independence of the judiciary in the performance of its judicial tasks, including decision-making. It should be possible to entrust supervision of such data processing operations to specific bodies within the judicial system of the Member State, which should, in particular ensure compliance with the rules of this Regulation, enhance awareness among members of the judiciary of their obligations under this Regulation and handle complaints in relation to such data processing operations.\n(21)This Regulation is without prejudice to the application of Directive 2000/31/EC of the European Parliament and of the Council(8), in particular of the liability rules of intermediary service providers in Articles 12 to 15 of that Directive. That Directive seeks to contribute to the proper functioning of the internal market by ensuring the free movement of information society services between Member States.\n(22)Any processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union should be carried out in accordance with this Regulation, regardless of whether the processing itself takes place within the Union. Establishment implies the effective and real exercise of activity through stable arrangements. The legal form of such arrangements, whether through a branch or a subsidiary with a legal personality, is not the determining factor in that respect.\n(23)In order to ensure that natural persons are not deprived of the protection to which they are entitled under this Regulation, the processing of personal data of data subjects who are in the Union by a controller or a processor not established in the Union should be subject to this Regulation where the processing activities are related to offering goods or services to such data subjects irrespective of whether connected to a payment. In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. Whereas the mere accessibility of the controller\u0026rsquo;s, processor\u0026rsquo;s or an intermediary\u0026rsquo;s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union.\n(24)The processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union should also be subject to this Regulation when it is related to the monitoring of the behaviour of such data subjects in so far as their behaviour takes place within the Union. In order to determine whether a processing activity can be considered to monitor the behaviour of data subjects, it should be ascertained whether natural persons are tracked on the internet including potential subsequent use of personal data processing techniques which consist of profiling a natural person, particularly in order to take decisions concerning her or him or for analysing or predicting her or his personal preferences, behaviours and attitudes.\n(25)Where Member State law applies by virtue of public international law, this Regulation should also apply to a controller not established in the Union, such as in a Member State\u0026rsquo;s diplomatic mission or consular post.\n(26)The principles of data protection should apply to any information concerning an identified or identifiable natural person. Personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable natural person. To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person to identify the natural person directly or indirectly. To ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments. The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable. This Regulation does not therefore concern the processing of such anonymous information, including for statistical or research purposes.\n(27)This Regulation does not apply to the personal data of deceased persons. Member States may provide for rules regarding the processing of personal data of deceased persons.\n(28)The application of pseudonymisation to personal data can reduce the risks to the data subjects concerned and help controllers and processors to meet their data-protection obligations. The explicit introduction of ‘pseudonymisation’ in this Regulation is not intended to preclude any other measures of data protection.\n(29)In order to create incentives to apply pseudonymisation when processing personal data, measures of pseudonymisation should, whilst allowing general analysis, be possible within the same controller when that controller has taken technical and organisational measures necessary to ensure, for the processing concerned, that this Regulation is implemented, and that additional information for attributing the personal data to a specific data subject is kept separately. The controller processing the personal data should indicate the authorised persons within the same controller.\n(30)Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.\n(31)Public authorities to which personal data are disclosed in accordance with a legal obligation for the exercise of their official mission, such as tax and customs authorities, financial investigation units, independent administrative authorities, or financial market authorities responsible for the regulation and supervision of securities markets should not be regarded as recipients if they receive personal data which are necessary to carry out a particular inquiry in the general interest, in accordance with Union or Member State law. The requests for disclosure sent by the public authorities should always be in writing, reasoned and occasional and should not concern the entirety of a filing system or lead to the interconnection of filing systems. The processing of personal data by those public authorities should comply with the applicable data-protection rules according to the purposes of the processing.\n(32)Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject\u0026rsquo;s agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement. This could include ticking a box when visiting an internet website, choosing technical settings for information society services or another statement or conduct which clearly indicates in this context the data subject\u0026rsquo;s acceptance of the proposed processing of his or her personal data. Silence, pre-ticked boxes or inactivity should not therefore constitute consent. Consent should cover all processing activities carried out for the same purpose or purposes. When the processing has multiple purposes, consent should be given for all of them. If the data subject\u0026rsquo;s consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided.\n(33)It is often not possible to fully identify the purpose of personal data processing for scientific research purposes at the time of data collection. Therefore, data subjects should be allowed to give their consent to certain areas of scientific research when in keeping with recognised ethical standards for scientific research. Data subjects should have the opportunity to give their consent only to certain areas of research or parts of research projects to the extent allowed by the intended purpose.\n(34)Genetic data should be defined as personal data relating to the inherited or acquired genetic characteristics of a natural person which result from the analysis of a biological sample from the natural person in question, in particular chromosomal, deoxyribonucleic acid (DNA) or ribonucleic acid (RNA) analysis, or from the analysis of another element enabling equivalent information to be obtained.\n(35)Personal data concerning health should include all data pertaining to the health status of a data subject which reveal information relating to the past, current or future physical or mental health status of the data subject. This includes information about the natural person collected in the course of the registration for, or the provision of, health care services as referred to in Directive 2011/24/EU of the European Parliament and of the Council(9) to that natural person; a number, symbol or particular assigned to a natural person to uniquely identify the natural person for health purposes; information derived from the testing or examination of a body part or bodily substance, including from genetic data and biological samples; and any information on, for example, a disease, disability, disease risk, medical history, clinical treatment or the physiological or biomedical state of the data subject independent of its source, for example from a physician or other health professional, a hospital, a medical device or an in vitro diagnostic test.\n(36)The main establishment of a controller in the Union should be the place of its central administration in the Union, unless the decisions on the purposes and means of the processing of personal data are taken in another establishment of the controller in the Union, in which case that other establishment should be considered to be the main establishment. The main establishment of a controller in the Union should be determined according to objective criteria and should imply the effective and real exercise of management activities determining the main decisions as to the purposes and means of processing through stable arrangements. That criterion should not depend on whether the processing of personal data is carried out at that location. The presence and use of technical means and technologies for processing personal data or processing activities do not, in themselves, constitute a main establishment and are therefore not determining criteria for a main establishment. The main establishment of the processor should be the place of its central administration in the Union or, if it has no central administration in the Union, the place where the main processing activities take place in the Union. In cases involving both the controller and the processor, the competent lead supervisory authority should remain the supervisory authority of the Member State where the controller has its main establishment, but the supervisory authority of the processor should be considered to be a supervisory authority concerned and that supervisory authority should participate in the cooperation procedure provided for by this Regulation. In any case, the supervisory authorities of the Member State or Member States where the processor has one or more establishments should not be considered to be supervisory authorities concerned where the draft decision concerns only the controller. Where the processing is carried out by a group of undertakings, the main establishment of the controlling undertaking should be considered to be the main establishment of the group of undertakings, except where the purposes and means of processing are determined by another undertaking.\n(37)A group of undertakings should cover a controlling undertaking and its controlled undertakings, whereby the controlling undertaking should be the undertaking which can exert a dominant influence over the other undertakings by virtue, for example, of ownership, financial participation or the rules which govern it or the power to have personal data protection rules implemented. An undertaking which controls the processing of personal data in undertakings affiliated to it should be regarded, together with those undertakings, as a group of undertakings.\n(38)Children merit specific protection with regard to their personal data, as they may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the processing of personal data. Such specific protection should, in particular, apply to the use of personal data of children for the purposes of marketing or creating personality or user profiles and the collection of personal data with regard to children when using services offered directly to a child. The consent of the holder of parental responsibility should not be necessary in the context of preventive or counselling services offered directly to a child.\n(39)Any processing of personal data should be lawful and fair. It should be transparent to natural persons that personal data concerning them are collected, used, consulted or otherwise processed and to what extent the personal data are or will be processed. The principle of transparency requires that any information and communication relating to the processing of those personal data be easily accessible and easy to understand, and that clear and plain language be used. That principle concerns, in particular, information to the data subjects on the identity of the controller and the purposes of the processing and further information to ensure fair and transparent processing in respect of the natural persons concerned and their right to obtain confirmation and communication of personal data concerning them which are being processed. Natural persons should be made aware of risks, rules, safeguards and rights in relation to the processing of personal data and how to exercise their rights in relation to such processing. In particular, the specific purposes for which personal data are processed should be explicit and legitimate and determined at the time of the collection of the personal data. The personal data should be adequate, relevant and limited to what is necessary for the purposes for which they are processed. This requires, in particular, ensuring that the period for which the personal data are stored is limited to a strict minimum. Personal data should be processed only if the purpose of the processing could not reasonably be fulfilled by other means. In order to ensure that the personal data are not kept longer than necessary, time limits should be established by the controller for erasure or for a periodic review. Every reasonable step should be taken to ensure that personal data which are inaccurate are rectified or deleted. Personal data should be processed in a manner that ensures appropriate security and confidentiality of the personal data, including for preventing unauthorised access to or use of personal data and the equipment used for the processing.\n(40)In order for processing to be lawful, personal data should be processed on the basis of the consent of the data subject concerned or some other legitimate basis, laid down by law, either in this Regulation or in other Union or Member State law as referred to in this Regulation, including the necessity for compliance with the legal obligation to which the controller is subject or the necessity for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.\n(41)Where this Regulation refers to a legal basis or a legislative measure, this does not necessarily require a legislative act adopted by a parliament, without prejudice to requirements pursuant to the constitutional order of the Member State concerned. However, such a legal basis or legislative measure should be clear and precise and its application should be foreseeable to persons subject to it, in accordance with the case-law of the Court of Justice of the European Union (the ‘Court of Justice’) and the European Court of Human Rights.\n(42)Where processing is based on the data subject\u0026rsquo;s consent, the controller should be able to demonstrate that the data subject has given consent to the processing operation. In particular in the context of a written declaration on another matter, safeguards should ensure that the data subject is aware of the fact that and the extent to which consent is given. In accordance with Council Directive 93/13/EEC(10) a declaration of consent pre-formulated by the controller should be provided in an intelligible and easily accessible form, using clear and plain language and it should not contain unfair terms. For consent to be informed, the data subject should be aware at least of the identity of the controller and the purposes of the processing for which the personal data are intended. Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment.\n(43)In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the data subject and the controller, in particular where the controller is a public authority and it is therefore unlikely that consent was freely given in all the circumstances of that specific situation. Consent is presumed not to be freely given if it does not allow separate consent to be given to different personal data processing operations despite it being appropriate in the individual case, or if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance.\n(44)Processing should be lawful where it is necessary in the context of a contract or the intention to enter into a contract.\n(45)Where processing is carried out in accordance with a legal obligation to which the controller is subject or where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, the processing should have a basis in Union or Member State law. This Regulation does not require a specific law for each individual processing. A law as a basis for several processing operations based on a legal obligation to which the controller is subject or where processing is necessary for the performance of a task carried out in the public interest or in the exercise of an official authority may be sufficient. It should also be for Union or Member State law to determine the purpose of processing. Furthermore, that law could specify the general conditions of this Regulation governing the lawfulness of personal data processing, establish specifications for determining the controller, the type of personal data which are subject to the processing, the data subjects concerned, the entities to which the personal data may be disclosed, the purpose limitations, the storage period and other measures to ensure lawful and fair processing. It should also be for Union or Member State law to determine whether the controller performing a task carried out in the public interest or in the exercise of official authority should be a public authority or another natural or legal person governed by public law, or, where it is in the public interest to do so, including for health purposes such as public health and social protection and the management of health care services, by private law, such as a professional association.\n(46)The processing of personal data should also be regarded to be lawful where it is necessary to protect an interest which is essential for the life of the data subject or that of another natural person. Processing of personal data based on the vital interest of another natural person should in principle take place only where the processing cannot be manifestly based on another legal basis. Some types of processing may serve both important grounds of public interest and the vital interests of the data subject as for instance when processing is necessary for humanitarian purposes, including for monitoring epidemics and their spread or in situations of humanitarian emergencies, in particular in situations of natural and man-made disasters.\n(47)The legitimate interests of a controller, including those of a controller to which the personal data may be disclosed, or of a third party, may provide a legal basis for processing, provided that the interests or the fundamental rights and freedoms of the data subject are not overriding, taking into consideration the reasonable expectations of data subjects based on their relationship with the controller. Such legitimate interest could exist for example where there is a relevant and appropriate relationship between the data subject and the controller in situations such as where the data subject is a client or in the service of the controller. At any rate the existence of a legitimate interest would need careful assessment including whether a data subject can reasonably expect at the time and in the context of the collection of the personal data that processing for that purpose may take place. The interests and fundamental rights of the data subject could in particular override the interest of the data controller where personal data are processed in circumstances where data subjects do not reasonably expect further processing. Given that it is for the legislator to provide by law for the legal basis for public authorities to process personal data, that legal basis should not apply to the processing by public authorities in the performance of their tasks. The processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned. The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.\n(48)Controllers that are part of a group of undertakings or institutions affiliated to a central body may have a legitimate interest in transmitting personal data within the group of undertakings for internal administrative purposes, including the processing of clients\u0026rsquo; or employees\u0026rsquo; personal data. The general principles for the transfer of personal data, within a group of undertakings, to an undertaking located in a third country remain unaffected.\n(49)The processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or an information system to resist, at a given level of confidence, accidental events or unlawful or malicious actions that compromise the availability, authenticity, integrity and confidentiality of stored or transmitted personal data, and the security of the related services offered by, or accessible via, those networks and systems, by public authorities, by computer emergency response teams (CERTs), computer security incident response teams (CSIRTs), by providers of electronic communications networks and services and by providers of security technologies and services, constitutes a legitimate interest of the data controller concerned. This could, for example, include preventing unauthorised access to electronic communications networks and malicious code distribution and stopping ‘denial of service’ attacks and damage to computer and electronic communication systems.\n(50)The processing of personal data for purposes other than those for which the personal data were initially collected should be allowed only where the processing is compatible with the purposes for which the personal data were initially collected. In such a case, no legal basis separate from that which allowed the collection of the personal data is required. If the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, Union or Member State law may determine and specify the tasks and purposes for which the further processing should be regarded as compatible and lawful. Further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be considered to be compatible lawful processing operations. The legal basis provided by Union or Member State law for the processing of personal data may also provide a legal basis for further processing. In order to ascertain whether a purpose of further processing is compatible with the purpose for which the personal data are initially collected, the controller, after having met all the requirements for the lawfulness of the original processing, should take into account, inter alia: any link between those purposes and the purposes of the intended further processing; the context in which the personal data have been collected, in particular the reasonable expectations of data subjects based on their relationship with the controller as to their further use; the nature of the personal data; the consequences of the intended further processing for data subjects; and the existence of appropriate safeguards in both the original and intended further processing operations.\nWhere the data subject has given consent or the processing is based on Union or Member State law which constitutes a necessary and proportionate measure in a democratic society to safeguard, in particular, important objectives of general public interest, the controller should be allowed to further process the personal data irrespective of the compatibility of the purposes. In any case, the application of the principles set out in this Regulation and in particular the information of the data subject on those other purposes and on his or her rights including the right to object, should be ensured. Indicating possible criminal acts or threats to public security by the controller and transmitting the relevant personal data in individual cases or in several cases relating to the same criminal act or threats to public security to a competent authority should be regarded as being in the legitimate interest pursued by the controller. However, such transmission in the legitimate interest of the controller or further processing of personal data should be prohibited if the processing is not compatible with a legal, professional or other binding obligation of secrecy.\n(51)Personal data which are, by their nature, particularly sensitive in relation to fundamental rights and freedoms merit specific protection as the context of their processing could create significant risks to the fundamental rights and freedoms. Those personal data should include personal data revealing racial or ethnic origin, whereby the use of the term ‘racial origin’ in this Regulation does not imply an acceptance by the Union of theories which attempt to determine the existence of separate human races. The processing of photographs should not systematically be considered to be processing of special categories of personal data as they are covered by the definition of biometric data only when processed through a specific technical means allowing the unique identification or authentication of a natural person. Such personal data should not be processed, unless processing is allowed in specific cases set out in this Regulation, taking into account that Member States law may lay down specific provisions on data protection in order to adapt the application of the rules of this Regulation for compliance with a legal obligation or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. In addition to the specific requirements for such processing, the general principles and other rules of this Regulation should apply, in particular as regards the conditions for lawful processing. Derogations from the general prohibition for processing such special categories of personal data should be explicitly provided, inter alia, where the data subject gives his or her explicit consent or in respect of specific needs in particular where the processing is carried out in the course of legitimate activities by certain associations or foundations the purpose of which is to permit the exercise of fundamental freedoms.\n(52)Derogating from the prohibition on processing special categories of personal data should also be allowed when provided for in Union or Member State law and subject to suitable safeguards, so as to protect personal data and other fundamental rights, where it is in the public interest to do so, in particular processing personal data in the field of employment law, social protection law including pensions and for health security, monitoring and alert purposes, the prevention or control of communicable diseases and other serious threats to health. Such a derogation may be made for health purposes, including public health and the management of health-care services, especially in order to ensure the quality and cost-effectiveness of the procedures used for settling claims for benefits and services in the health insurance system, or for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. A derogation should also allow the processing of such personal data where necessary for the establishment, exercise or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.\n(53)Special categories of personal data which merit higher protection should be processed for health-related purposes only where necessary to achieve those purposes for the benefit of natural persons and society as a whole, in particular in the context of the management of health or social care services and systems, including processing by the management and central national health authorities of such data for the purpose of quality control, management information and the general national and local supervision of the health or social care system, and ensuring continuity of health or social care and cross-border healthcare or health security, monitoring and alert purposes, or for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, based on Union or Member State law which has to meet an objective of public interest, as well as for studies conducted in the public interest in the area of public health. Therefore, this Regulation should provide for harmonised conditions for the processing of special categories of personal data concerning health, in respect of specific needs, in particular where the processing of such data is carried out for certain health-related purposes by persons subject to a legal obligation of professional secrecy. Union or Member State law should provide for specific and suitable measures so as to protect the fundamental rights and the personal data of natural persons. Member States should be allowed to maintain or introduce further conditions, including limitations, with regard to the processing of genetic data, biometric data or data concerning health. However, this should not hamper the free flow of personal data within the Union when those conditions apply to cross-border processing of such data.\n(54)The processing of special categories of personal data may be necessary for reasons of public interest in the areas of public health without consent of the data subject. Such processing should be subject to suitable and specific measures so as to protect the rights and freedoms of natural persons. In that context, ‘public health’ should be interpreted as defined in Regulation (EC) No 1338/2008 of the European Parliament and of the Council(11), namely all elements related to health, namely health status, including morbidity and disability, the determinants having an effect on that health status, health care needs, resources allocated to health care, the provision of, and universal access to, health care as well as health care expenditure and financing, and the causes of mortality. Such processing of data concerning health for reasons of public interest should not result in personal data being processed for other purposes by third parties such as employers or insurance and banking companies.\n(55)Moreover, the processing of personal data by official authorities for the purpose of achieving the aims, laid down by constitutional law or by international public law, of officially recognised religious associations, is carried out on grounds of public interest.\n(56)Where in the course of electoral activities, the operation of the democratic system in a Member State requires that political parties compile personal data on people\u0026rsquo;s political opinions, the processing of such data may be permitted for reasons of public interest, provided that appropriate safeguards are established.\n(57)If the personal data processed by a controller do not permit the controller to identify a natural person, the data controller should not be obliged to acquire additional information in order to identify the data subject for the sole purpose of complying with any provision of this Regulation. However, the controller should not refuse to take additional information provided by the data subject in order to support the exercise of his or her rights. Identification should include the digital identification of a data subject, for example through authentication mechanism such as the same credentials, used by the data subject to log-in to the on-line service offered by the data controller.\n(58)The principle of transparency requires that any information addressed to the public or to the data subject be concise, easily accessible and easy to understand, and that clear and plain language and, additionally, where appropriate, visualisation be used. Such information could be provided in electronic form, for example, when addressed to the public, through a website. This is of particular relevance in situations where the proliferation of actors and the technological complexity of practice make it difficult for the data subject to know and understand whether, by whom and for what purpose personal data relating to him or her are being collected, such as in the case of online advertising. Given that children merit specific protection, any information and communication, where processing is addressed to a child, should be in such a clear and plain language that the child can easily understand.\n(59)Modalities should be provided for facilitating the exercise of the data subject\u0026rsquo;s rights under this Regulation, including mechanisms to request and, if applicable, obtain, free of charge, in particular, access to and rectification or erasure of personal data and the exercise of the right to object. The controller should also provide means for requests to be made electronically, especially where personal data are processed by electronic means. The controller should be obliged to respond to requests from the data subject without undue delay and at the latest within one month and to give reasons where the controller does not intend to comply with any such requests.\n(60)The principles of fair and transparent processing require that the data subject be informed of the existence of the processing operation and its purposes. The controller should provide the data subject with any further information necessary to ensure fair and transparent processing taking into account the specific circumstances and context in which the personal data are processed. Furthermore, the data subject should be informed of the existence of profiling and the consequences of such profiling. Where the personal data are collected from the data subject, the data subject should also be informed whether he or she is obliged to provide the personal data and of the consequences, where he or she does not provide such data. That information may be provided in combination with standardised icons in order to give in an easily visible, intelligible and clearly legible manner, a meaningful overview of the intended processing. Where the icons are presented electronically, they should be machine-readable.\n(61)The information in relation to the processing of personal data relating to the data subject should be given to him or her at the time of collection from the data subject, or, where the personal data are obtained from another source, within a reasonable period, depending on the circumstances of the case. Where personal data can be legitimately disclosed to another recipient, the data subject should be informed when the personal data are first disclosed to the recipient. Where the controller intends to process the personal data for a purpose other than that for which they were collected, the controller should provide the data subject prior to that further processing with information on that other purpose and other necessary information. Where the origin of the personal data cannot be provided to the data subject because various sources have been used, general information should be provided.\n(62)However, it is not necessary to impose the obligation to provide information where the data subject already possesses the information, where the recording or disclosure of the personal data is expressly laid down by law or where the provision of information to the data subject proves to be impossible or would involve a disproportionate effort. The latter could in particular be the case where processing is carried out for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. In that regard, the number of data subjects, the age of the data and any appropriate safeguards adopted should be taken into consideration.\n(63)A data subject should have the right of access to personal data which have been collected concerning him or her, and to exercise that right easily and at reasonable intervals, in order to be aware of, and verify, the lawfulness of the processing. This includes the right for data subjects to have access to data concerning their health, for example the data in their medical records containing information such as diagnoses, examination results, assessments by treating physicians and any treatment or interventions provided. Every data subject should therefore have the right to know and obtain communication in particular with regard to the purposes for which the personal data are processed, where possible the period for which the personal data are processed, the recipients of the personal data, the logic involved in any automatic personal data processing and, at least when based on profiling, the consequences of such processing. Where possible, the controller should be able to provide remote access to a secure system which would provide the data subject with direct access to his or her personal data. That right should not adversely affect the rights or freedoms of others, including trade secrets or intellectual property and in particular the copyright protecting the software. However, the result of those considerations should not be a refusal to provide all information to the data subject. Where the controller processes a large quantity of information concerning the data subject, the controller should be able to request that, before the information is delivered, the data subject specify the information or processing activities to which the request relates.\n(64)The controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers. A controller should not retain personal data for the sole purpose of being able to react to potential requests.\n(65)A data subject should have the right to have personal data concerning him or her rectified and a ‘right to be forgotten’ where the retention of such data infringes this Regulation or Union or Member State law to which the controller is subject. In particular, a data subject should have the right to have his or her personal data erased and no longer processed where the personal data are no longer necessary in relation to the purposes for which they are collected or otherwise processed, where a data subject has withdrawn his or her consent or objects to the processing of personal data concerning him or her, or where the processing of his or her personal data does not otherwise comply with this Regulation. That right is relevant in particular where the data subject has given his or her consent as a child and is not fully aware of the risks involved by the processing, and later wants to remove such personal data, especially on the internet. The data subject should be able to exercise that right notwithstanding the fact that he or she is no longer a child. However, the further retention of the personal data should be lawful where it is necessary, for exercising the right of freedom of expression and information, for compliance with a legal obligation, for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, on the grounds of public interest in the area of public health, for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, or for the establishment, exercise or defence of legal claims.\n(66)To strengthen the right to be forgotten in the online environment, the right to erasure should also be extended in such a way that a controller who has made the personal data public should be obliged to inform the controllers which are processing such personal data to erase any links to, or copies or replications of those personal data. In doing so, that controller should take reasonable steps, taking into account available technology and the means available to the controller, including technical measures, to inform the controllers which are processing the personal data of the data subject\u0026rsquo;s request.\n(67)Methods by which to restrict the processing of personal data could include, inter alia, temporarily moving the selected data to another processing system, making the selected personal data unavailable to users, or temporarily removing published data from a website. In automated filing systems, the restriction of processing should in principle be ensured by technical means in such a manner that the personal data are not subject to further processing operations and cannot be changed. The fact that the processing of personal data is restricted should be clearly indicated in the system.\n(68)To further strengthen the control over his or her own data, where the processing of personal data is carried out by automated means, the data subject should also be allowed to receive personal data concerning him or her which he or she has provided to a controller in a structured, commonly used, machine-readable and interoperable format, and to transmit it to another controller. Data controllers should be encouraged to develop interoperable formats that enable data portability. That right should apply where the data subject provided the personal data on the basis of his or her consent or the processing is necessary for the performance of a contract. It should not apply where processing is based on a legal ground other than consent or contract. By its very nature, that right should not be exercised against controllers processing personal data in the exercise of their public duties. It should therefore not apply where the processing of the personal data is necessary for compliance with a legal obligation to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of an official authority vested in the controller. The data subject\u0026rsquo;s right to transmit or receive personal data concerning him or her should not create an obligation for the controllers to adopt or maintain processing systems which are technically compatible. Where, in a certain set of personal data, more than one data subject is concerned, the right to receive the personal data should be without prejudice to the rights and freedoms of other data subjects in accordance with this Regulation. Furthermore, that right should not prejudice the right of the data subject to obtain the erasure of personal data and the limitations of that right as set out in this Regulation and should, in particular, not imply the erasure of personal data concerning the data subject which have been provided by him or her for the performance of a contract to the extent that and for as long as the personal data are necessary for the performance of that contract. Where technically feasible, the data subject should have the right to have the personal data transmitted directly from one controller to another.\n(69)Where personal data might lawfully be processed because processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, or on grounds of the legitimate interests of a controller or a third party, a data subject should, nevertheless, be entitled to object to the processing of any personal data relating to his or her particular situation. It should be for the controller to demonstrate that its compelling legitimate interest overrides the interests or the fundamental rights and freedoms of the data subject.\n(70)Where personal data are processed for the purposes of direct marketing, the data subject should have the right to object to such processing, including profiling to the extent that it is related to such direct marketing, whether with regard to initial or further processing, at any time and free of charge. That right should be explicitly brought to the attention of the data subject and presented clearly and separately from any other information.\n(71)The data subject should have the right not to be subject to a decision, which may include a measure, evaluating personal aspects relating to him or her which is based solely on automated processing and which produces legal effects concerning him or her or similarly significantly affects him or her, such as automatic refusal of an online credit application or e-recruiting practices without any human intervention. Such processing includes ‘profiling’ that consists of any form of automated processing of personal data evaluating the personal aspects relating to a natural person, in particular to analyse or predict aspects concerning the data subject\u0026rsquo;s performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, where it produces legal effects concerning him or her or similarly significantly affects him or her. However, decision-making based on such processing, including profiling, should be allowed where expressly authorised by Union or Member State law to which the controller is subject, including for fraud and tax-evasion monitoring and prevention purposes conducted in accordance with the regulations, standards and recommendations of Union institutions or national oversight bodies and to ensure the security and reliability of a service provided by the controller, or necessary for the entering or performance of a contract between the data subject and a controller, or when the data subject has given his or her explicit consent. In any case, such processing should be subject to suitable safeguards, which should include specific information to the data subject and the right to obtain human intervention, to express his or her point of view, to obtain an explanation of the decision reached after such assessment and to challenge the decision. Such measure should not concern a child.\nIn order to ensure fair and transparent processing in respect of the data subject, taking into account the specific circumstances and context in which the personal data are processed, the controller should use appropriate mathematical or statistical procedures for the profiling, implement technical and organisational measures appropriate to ensure, in particular, that factors which result in inaccuracies in personal data are corrected and the risk of errors is minimised, secure personal data in a manner that takes account of the potential risks involved for the interests and rights of the data subject and that prevents, inter alia, discriminatory effects on natural persons on the basis of racial or ethnic origin, political opinion, religion or beliefs, trade union membership, genetic or health status or sexual orientation, or that result in measures having such an effect. Automated decision-making and profiling based on special categories of personal data should be allowed only under specific conditions.\n(72)Profiling is subject to the rules of this Regulation governing the processing of personal data, such as the legal grounds for processing or data protection principles. The European Data Protection Board established by this Regulation (the ‘Board’) should be able to issue guidance in that context.\n(73)Restrictions concerning specific principles and the rights of information, access to and rectification or erasure of personal data, the right to data portability, the right to object, decisions based on profiling, as well as the communication of a personal data breach to a data subject and certain related obligations of the controllers may be imposed by Union or Member State law, as far as necessary and proportionate in a democratic society to safeguard public security, including the protection of human life especially in response to natural or manmade disasters, the prevention, investigation and prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security, or of breaches of ethics for regulated professions, other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, the keeping of public registers kept for reasons of general public interest, further processing of archived personal data to provide specific information related to the political behaviour under former totalitarian state regimes or the protection of the data subject or the rights and freedoms of others, including social protection, public health and humanitarian purposes. Those restrictions should be in accordance with the requirements set out in the Charter and in the European Convention for the Protection of Human Rights and Fundamental Freedoms.\n(74)The responsibility and liability of the controller for any processing of personal data carried out by the controller or on the controller\u0026rsquo;s behalf should be established. In particular, the controller should be obliged to implement appropriate and effective measures and be able to demonstrate the compliance of processing activities with this Regulation, including the effectiveness of the measures. Those measures should take into account the nature, scope, context and purposes of the processing and the risk to the rights and freedoms of natural persons.\n(75)The risk to the rights and freedoms of natural persons, of varying likelihood and severity, may result from personal data processing which could lead to physical, material or non-material damage, in particular: where the processing may give rise to discrimination, identity theft or fraud, financial loss, damage to the reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorised reversal of pseudonymisation, or any other significant economic or social disadvantage; where data subjects might be deprived of their rights and freedoms or prevented from exercising control over their personal data; where personal data are processed which reveal racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, and the processing of genetic data, data concerning health or data concerning sex life or criminal convictions and offences or related security measures; where personal aspects are evaluated, in particular analysing or predicting aspects concerning performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, in order to create or use personal profiles; where personal data of vulnerable natural persons, in particular of children, are processed; or where processing involves a large amount of personal data and affects a large number of data subjects.\n(76)The likelihood and severity of the risk to the rights and freedoms of the data subject should be determined by reference to the nature, scope, context and purposes of the processing. Risk should be evaluated on the basis of an objective assessment, by which it is established whether data processing operations involve a risk or a high risk.\n(77)Guidance on the implementation of appropriate measures and on the demonstration of compliance by the controller or the processor, especially as regards the identification of the risk related to the processing, their assessment in terms of origin, nature, likelihood and severity, and the identification of best practices to mitigate the risk, could be provided in particular by means of approved codes of conduct, approved certifications, guidelines provided by the Board or indications provided by a data protection officer. The Board may also issue guidelines on processing operations that are considered to be unlikely to result in a high risk to the rights and freedoms of natural persons and indicate what measures may be sufficient in such cases to address such risk.\n(78)The protection of the rights and freedoms of natural persons with regard to the processing of personal data require that appropriate technical and organisational measures be taken to ensure that the requirements of this Regulation are met. In order to be able to demonstrate compliance with this Regulation, the controller should adopt internal policies and implement measures which meet in particular the principles of data protection by design and data protection by default. Such measures could consist, inter alia, of minimising the processing of personal data, pseudonymising personal data as soon as possible, transparency with regard to the functions and processing of personal data, enabling the data subject to monitor the data processing, enabling the controller to create and improve security features. When developing, designing, selecting and using applications, services and products that are based on the processing of personal data or process personal data to fulfil their task, producers of the products, services and applications should be encouraged to take into account the right to data protection when developing and designing such products, services and applications and, with due regard to the state of the art, to make sure that controllers and processors are able to fulfil their data protection obligations. The principles of data protection by design and by default should also be taken into consideration in the context of public tenders.\n(79)The protection of the rights and freedoms of data subjects as well as the responsibility and liability of controllers and processors, also in relation to the monitoring by and measures of supervisory authorities, requires a clear allocation of the responsibilities under this Regulation, including where a controller determines the purposes and means of the processing jointly with other controllers or where a processing operation is carried out on behalf of a controller.\n(80)Where a controller or a processor not established in the Union is processing personal data of data subjects who are in the Union whose processing activities are related to the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union, or to the monitoring of their behaviour as far as their behaviour takes place within the Union, the controller or the processor should designate a representative, unless the processing is occasional, does not include processing, on a large scale, of special categories of personal data or the processing of personal data relating to criminal convictions and offences, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing or if the controller is a public authority or body. The representative should act on behalf of the controller or the processor and may be addressed by any supervisory authority. The representative should be explicitly designated by a written mandate of the controller or of the processor to act on its behalf with regard to its obligations under this Regulation. The designation of such a representative does not affect the responsibility or liability of the controller or of the processor under this Regulation. Such a representative should perform its tasks according to the mandate received from the controller or processor, including cooperating with the competent supervisory authorities with regard to any action taken to ensure compliance with this Regulation. The designated representative should be subject to enforcement proceedings in the event of non-compliance by the controller or processor.\n(81)To ensure compliance with the requirements of this Regulation in respect of the processing to be carried out by the processor on behalf of the controller, when entrusting a processor with processing activities, the controller should use only processors providing sufficient guarantees, in particular in terms of expert knowledge, reliability and resources, to implement technical and organisational measures which will meet the requirements of this Regulation, including for the security of processing. The adherence of the processor to an approved code of conduct or an approved certification mechanism may be used as an element to demonstrate compliance with the obligations of the controller. The carrying-out of processing by a processor should be governed by a contract or other legal act under Union or Member State law, binding the processor to the controller, setting out the subject-matter and duration of the processing, the nature and purposes of the processing, the type of personal data and categories of data subjects, taking into account the specific tasks and responsibilities of the processor in the context of the processing to be carried out and the risk to the rights and freedoms of the data subject. The controller and processor may choose to use an individual contract or standard contractual clauses which are adopted either directly by the Commission or by a supervisory authority in accordance with the consistency mechanism and then adopted by the Commission. After the completion of the processing on behalf of the controller, the processor should, at the choice of the controller, return or delete the personal data, unless there is a requirement to store the personal data under Union or Member State law to which the processor is subject.\n(82)In order to demonstrate compliance with this Regulation, the controller or processor should maintain records of processing activities under its responsibility. Each controller and processor should be obliged to cooperate with the supervisory authority and make those records, on request, available to it, so that it might serve for monitoring those processing operations.\n(83)In order to maintain security and to prevent processing in infringement of this Regulation, the controller or processor should evaluate the risks inherent in the processing and implement measures to mitigate those risks, such as encryption. Those measures should ensure an appropriate level of security, including confidentiality, taking into account the state of the art and the costs of implementation in relation to the risks and the nature of the personal data to be protected. In assessing data security risk, consideration should be given to the risks that are presented by personal data processing, such as accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed which may in particular lead to physical, material or non-material damage.\n(84)In order to enhance compliance with this Regulation where processing operations are likely to result in a high risk to the rights and freedoms of natural persons, the controller should be responsible for the carrying-out of a data protection impact assessment to evaluate, in particular, the origin, nature, particularity and severity of that risk. The outcome of the assessment should be taken into account when determining the appropriate measures to be taken in order to demonstrate that the processing of personal data complies with this Regulation. Where a data-protection impact assessment indicates that processing operations involve a high risk which the controller cannot mitigate by appropriate measures in terms of available technology and costs of implementation, a consultation of the supervisory authority should take place prior to the processing.\n(85)A personal data breach may, if not addressed in an appropriate and timely manner, result in physical, material or non-material damage to natural persons such as loss of control over their personal data or limitation of their rights, discrimination, identity theft or fraud, financial loss, unauthorised reversal of pseudonymisation, damage to reputation, loss of confidentiality of personal data protected by professional secrecy or any other significant economic or social disadvantage to the natural person concerned. Therefore, as soon as the controller becomes aware that a personal data breach has occurred, the controller should notify the personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the controller is able to demonstrate, in accordance with the accountability principle, that the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where such notification cannot be achieved within 72 hours, the reasons for the delay should accompany the notification and information may be provided in phases without undue further delay.\n(86)The controller should communicate to the data subject a personal data breach, without undue delay, where that personal data breach is likely to result in a high risk to the rights and freedoms of the natural person in order to allow him or her to take the necessary precautions. The communication should describe the nature of the personal data breach as well as recommendations for the natural person concerned to mitigate potential adverse effects. Such communications to data subjects should be made as soon as reasonably feasible and in close cooperation with the supervisory authority, respecting guidance provided by it or by other relevant authorities such as law-enforcement authorities. For example, the need to mitigate an immediate risk of damage would call for prompt communication with data subjects whereas the need to implement appropriate measures against continuing or similar personal data breaches may justify more time for communication.\n(87)It should be ascertained whether all appropriate technological protection and organisational measures have been implemented to establish immediately whether a personal data breach has taken place and to inform promptly the supervisory authority and the data subject. The fact that the notification was made without undue delay should be established taking into account in particular the nature and gravity of the personal data breach and its consequences and adverse effects for the data subject. Such notification may result in an intervention of the supervisory authority in accordance with its tasks and powers laid down in this Regulation.\n(88)In setting detailed rules concerning the format and procedures applicable to the notification of personal data breaches, due consideration should be given to the circumstances of that breach, including whether or not personal data had been protected by appropriate technical protection measures, effectively limiting the likelihood of identity fraud or other forms of misuse. Moreover, such rules and procedures should take into account the legitimate interests of law-enforcement authorities where early disclosure could unnecessarily hamper the investigation of the circumstances of a personal data breach.\n(89)Directive 95/46/EC provided for a general obligation to notify the processing of personal data to the supervisory authorities. While that obligation produces administrative and financial burdens, it did not in all cases contribute to improving the protection of personal data. Such indiscriminate general notification obligations should therefore be abolished, and replaced by effective procedures and mechanisms which focus instead on those types of processing operations which are likely to result in a high risk to the rights and freedoms of natural persons by virtue of their nature, scope, context and purposes. Such types of processing operations may be those which in, particular, involve using new technologies, or are of a new kind and where no data protection impact assessment has been carried out before by the controller, or where they become necessary in the light of the time that has elapsed since the initial processing.\n(90)In such cases, a data protection impact assessment should be carried out by the controller prior to the processing in order to assess the particular likelihood and severity of the high risk, taking into account the nature, scope, context and purposes of the processing and the sources of the risk. That impact assessment should include, in particular, the measures, safeguards and mechanisms envisaged for mitigating that risk, ensuring the protection of personal data and demonstrating compliance with this Regulation.\n(91)This should in particular apply to large-scale processing operations which aim to process a considerable amount of personal data at regional, national or supranational level and which could affect a large number of data subjects and which are likely to result in a high risk, for example, on account of their sensitivity, where in accordance with the achieved state of technological knowledge a new technology is used on a large scale as well as to other processing operations which result in a high risk to the rights and freedoms of data subjects, in particular where those operations render it more difficult for data subjects to exercise their rights. A data protection impact assessment should also be made where personal data are processed for taking decisions regarding specific natural persons following any systematic and extensive evaluation of personal aspects relating to natural persons based on profiling those data or following the processing of special categories of personal data, biometric data, or data on criminal convictions and offences or related security measures. A data protection impact assessment is equally required for monitoring publicly accessible areas on a large scale, especially when using optic-electronic devices or for any other operations where the competent supervisory authority considers that the processing is likely to result in a high risk to the rights and freedoms of data subjects, in particular because they prevent data subjects from exercising a right or using a service or a contract, or because they are carried out systematically on a large scale. The processing of personal data should not be considered to be on a large scale if the processing concerns personal data from patients or clients by an individual physician, other health care professional or lawyer. In such cases, a data protection impact assessment should not be mandatory.\n(92)There are circumstances under which it may be reasonable and economical for the subject of a data protection impact assessment to be broader than a single project, for example where public authorities or bodies intend to establish a common application or processing platform or where several controllers plan to introduce a common application or processing environment across an industry sector or segment or for a widely used horizontal activity.\n(93)In the context of the adoption of the Member State law on which the performance of the tasks of the public authority or public body is based and which regulates the specific processing operation or set of operations in question, Member States may deem it necessary to carry out such assessment prior to the processing activities.\n(94)Where a data protection impact assessment indicates that the processing would, in the absence of safeguards, security measures and mechanisms to mitigate the risk, result in a high risk to the rights and freedoms of natural persons and the controller is of the opinion that the risk cannot be mitigated by reasonable means in terms of available technologies and costs of implementation, the supervisory authority should be consulted prior to the start of processing activities. Such high risk is likely to result from certain types of processing and the extent and frequency of processing, which may result also in a realisation of damage or interference with the rights and freedoms of the natural person. The supervisory authority should respond to the request for consultation within a specified period. However, the absence of a reaction of the supervisory authority within that period should be without prejudice to any intervention of the supervisory authority in accordance with its tasks and powers laid down in this Regulation, including the power to prohibit processing operations. As part of that consultation process, the outcome of a data protection impact assessment carried out with regard to the processing at issue may be submitted to the supervisory authority, in particular the measures envisaged to mitigate the risk to the rights and freedoms of natural persons.\n(95)The processor should assist the controller, where necessary and upon request, in ensuring compliance with the obligations deriving from the carrying out of data protection impact assessments and from prior consultation of the supervisory authority.\n(96)A consultation of the supervisory authority should also take place in the course of the preparation of a legislative or regulatory measure which provides for the processing of personal data, in order to ensure compliance of the intended processing with this Regulation and in particular to mitigate the risk involved for the data subject.\n(97)Where the processing is carried out by a public authority, except for courts or independent judicial authorities when acting in their judicial capacity, where, in the private sector, processing is carried out by a controller whose core activities consist of processing operations that require regular and systematic monitoring of the data subjects on a large scale, or where the core activities of the controller or the processor consist of processing on a large scale of special categories of personal data and data relating to criminal convictions and offences, a person with expert knowledge of data protection law and practices should assist the controller or processor to monitor internal compliance with this Regulation. In the private sector, the core activities of a controller relate to its primary activities and do not relate to the processing of personal data as ancillary activities. The necessary level of expert knowledge should be determined in particular according to the data processing operations carried out and the protection required for the personal data processed by the controller or the processor. Such data protection officers, whether or not they are an employee of the controller, should be in a position to perform their duties and tasks in an independent manner.\n(98)Associations or other bodies representing categories of controllers or processors should be encouraged to draw up codes of conduct, within the limits of this Regulation, so as to facilitate the effective application of this Regulation, taking account of the specific characteristics of the processing carried out in certain sectors and the specific needs of micro, small and medium enterprises. In particular, such codes of conduct could calibrate the obligations of controllers and processors, taking into account the risk likely to result from the processing for the rights and freedoms of natural persons.\n(99)When drawing up a code of conduct, or when amending or extending such a code, associations and other bodies representing categories of controllers or processors should consult relevant stakeholders, including data subjects where feasible, and have regard to submissions received and views expressed in response to such consultations.\n(100)In order to enhance transparency and compliance with this Regulation, the establishment of certification mechanisms and data protection seals and marks should be encouraged, allowing data subjects to quickly assess the level of data protection of relevant products and services.\n(101)Flows of personal data to and from countries outside the Union and international organisations are necessary for the expansion of international trade and international cooperation. The increase in such flows has raised new challenges and concerns with regard to the protection of personal data. However, when personal data are transferred from the Union to controllers, processors or other recipients in third countries or to international organisations, the level of protection of natural persons ensured in the Union by this Regulation should not be undermined, including in cases of onward transfers of personal data from the third country or international organisation to controllers, processors in the same or another third country or international organisation. In any event, transfers to third countries and international organisations may only be carried out in full compliance with this Regulation. A transfer could take place only if, subject to the other provisions of this Regulation, the conditions laid down in the provisions of this Regulation relating to the transfer of personal data to third countries or international organisations are complied with by the controller or processor.\n(102)This Regulation is without prejudice to international agreements concluded between the Union and third countries regulating the transfer of personal data including appropriate safeguards for the data subjects. Member States may conclude international agreements which involve the transfer of personal data to third countries or international organisations, as far as such agreements do not affect this Regulation or any other provisions of Union law and include an appropriate level of protection for the fundamental rights of the data subjects.\n(103)The Commission may decide with effect for the entire Union that a third country, a territory or specified sector within a third country, or an international organisation, offers an adequate level of data protection, thus providing legal certainty and uniformity throughout the Union as regards the third country or international organisation which is considered to provide such level of protection. In such cases, transfers of personal data to that third country or international organisation may take place without the need to obtain any further authorisation. The Commission may also decide, having given notice and a full statement setting out the reasons to the third country or international organisation, to revoke such a decision.\n(104)In line with the fundamental values on which the Union is founded, in particular the protection of human rights, the Commission should, in its assessment of the third country, or of a territory or specified sector within a third country, take into account how a particular third country respects the rule of law, access to justice as well as international human rights norms and standards and its general and sectoral law, including legislation concerning public security, defence and national security as well as public order and criminal law. The adoption of an adequacy decision with regard to a territory or a specified sector in a third country should take into account clear and objective criteria, such as specific processing activities and the scope of applicable legal standards and legislation in force in the third country. The third country should offer guarantees ensuring an adequate level of protection essentially equivalent to that ensured within the Union, in particular where personal data are processed in one or several specific sectors. In particular, the third country should ensure effective independent data protection supervision and should provide for cooperation mechanisms with the Member States\u0026rsquo; data protection authorities, and the data subjects should be provided with effective and enforceable rights and effective administrative and judicial redress.\n(105)Apart from the international commitments the third country or international organisation has entered into, the Commission should take account of obligations arising from the third country\u0026rsquo;s or international organisation\u0026rsquo;s participation in multilateral or regional systems in particular in relation to the protection of personal data, as well as the implementation of such obligations. In particular, the third country\u0026rsquo;s accession to the Council of Europe Convention of 28 January 1981 for the Protection of Individuals with regard to the Automatic Processing of Personal Data and its Additional Protocol should be taken into account. The Commission should consult the Board when assessing the level of protection in third countries or international organisations.\n(106)The Commission should monitor the functioning of decisions on the level of protection in a third country, a territory or specified sector within a third country, or an international organisation, and monitor the functioning of decisions adopted on the basis of Article 25(6) or Article 26(4) of Directive 95/46/EC. In its adequacy decisions, the Commission should provide for a periodic review mechanism of their functioning. That periodic review should be conducted in consultation with the third country or international organisation in question and take into account all relevant developments in the third country or international organisation. For the purposes of monitoring and of carrying out the periodic reviews, the Commission should take into consideration the views and findings of the European Parliament and of the Council as well as of other relevant bodies and sources. The Commission should evaluate, within a reasonable time, the functioning of the latter decisions and report any relevant findings to the Committee within the meaning of Regulation (EU) No 182/2011 of the European Parliament and of the Council(12) as established under this Regulation, to the European Parliament and to the Council.\n(107)The Commission may recognise that a third country, a territory or a specified sector within a third country, or an international organisation no longer ensures an adequate level of data protection. Consequently the transfer of personal data to that third country or international organisation should be prohibited, unless the requirements in this Regulation relating to transfers subject to appropriate safeguards, including binding corporate rules, and derogations for specific situations are fulfilled. In that case, provision should be made for consultations between the Commission and such third countries or international organisations. The Commission should, in a timely manner, inform the third country or international organisation of the reasons and enter into consultations with it in order to remedy the situation.\n(108)In the absence of an adequacy decision, the controller or processor should take measures to compensate for the lack of data protection in a third country by way of appropriate safeguards for the data subject. Such appropriate safeguards may consist of making use of binding corporate rules, standard data protection clauses adopted by the Commission, standard data protection clauses adopted by a supervisory authority or contractual clauses authorised by a supervisory authority. Those safeguards should ensure compliance with data protection requirements and the rights of the data subjects appropriate to processing within the Union, including the availability of enforceable data subject rights and of effective legal remedies, including to obtain effective administrative or judicial redress and to claim compensation, in the Union or in a third country. They should relate in particular to compliance with the general principles relating to personal data processing, the principles of data protection by design and by default. Transfers may also be carried out by public authorities or bodies with public authorities or bodies in third countries or with international organisations with corresponding duties or functions, including on the basis of provisions to be inserted into administrative arrangements, such as a memorandum of understanding, providing for enforceable and effective rights for data subjects. Authorisation by the competent supervisory authority should be obtained when the safeguards are provided for in administrative arrangements that are not legally binding.\n(109)The possibility for the controller or processor to use standard data-protection clauses adopted by the Commission or by a supervisory authority should prevent controllers or processors neither from including the standard data-protection clauses in a wider contract, such as a contract between the processor and another processor, nor from adding other clauses or additional safeguards provided that they do not contradict, directly or indirectly, the standard contractual clauses adopted by the Commission or by a supervisory authority or prejudice the fundamental rights or freedoms of the data subjects. Controllers and processors should be encouraged to provide additional safeguards via contractual commitments that supplement standard protection clauses.\n(110)A group of undertakings, or a group of enterprises engaged in a joint economic activity, should be able to make use of approved binding corporate rules for its international transfers from the Union to organisations within the same group of undertakings, or group of enterprises engaged in a joint economic activity, provided that such corporate rules include all essential principles and enforceable rights to ensure appropriate safeguards for transfers or categories of transfers of personal data.\n(111)Provisions should be made for the possibility for transfers in certain circumstances where the data subject has given his or her explicit consent, where the transfer is occasional and necessary in relation to a contract or a legal claim, regardless of whether in a judicial procedure or whether in an administrative or any out-of-court procedure, including procedures before regulatory bodies. Provision should also be made for the possibility for transfers where important grounds of public interest laid down by Union or Member State law so require or where the transfer is made from a register established by law and intended for consultation by the public or persons having a legitimate interest. In the latter case, such a transfer should not involve the entirety of the personal data or entire categories of the data contained in the register and, when the register is intended for consultation by persons having a legitimate interest, the transfer should be made only at the request of those persons or, if they are to be the recipients, taking into full account the interests and fundamental rights of the data subject.\n(112)Those derogations should in particular apply to data transfers required and necessary for important reasons of public interest, for example in cases of international data exchange between competition authorities, tax or customs administrations, between financial supervisory authorities, between services competent for social security matters, or for public health, for example in the case of contact tracing for contagious diseases or in order to reduce and/or eliminate doping in sport. A transfer of personal data should also be regarded as lawful where it is necessary to protect an interest which is essential for the data subject\u0026rsquo;s or another person\u0026rsquo;s vital interests, including physical integrity or life, if the data subject is incapable of giving consent. In the absence of an adequacy decision, Union or Member State law may, for important reasons of public interest, expressly set limits to the transfer of specific categories of data to a third country or an international organisation. Member States should notify such provisions to the Commission. Any transfer to an international humanitarian organisation of personal data of a data subject who is physically or legally incapable of giving consent, with a view to accomplishing a task incumbent under the Geneva Conventions or to complying with international humanitarian law applicable in armed conflicts, could be considered to be necessary for an important reason of public interest or because it is in the vital interest of the data subject.\n(113)Transfers which can be qualified as not repetitive and that only concern a limited number of data subjects, could also be possible for the purposes of the compelling legitimate interests pursued by the controller, when those interests are not overridden by the interests or rights and freedoms of the data subject and when the controller has assessed all the circumstances surrounding the data transfer. The controller should give particular consideration to the nature of the personal data, the purpose and duration of the proposed processing operation or operations, as well as the situation in the country of origin, the third country and the country of final destination, and should provide suitable safeguards to protect fundamental rights and freedoms of natural persons with regard to the processing of their personal data. Such transfers should be possible only in residual cases where none of the other grounds for transfer are applicable. For scientific or historical research purposes or statistical purposes, the legitimate expectations of society for an increase of knowledge should be taken into consideration. The controller should inform the supervisory authority and the data subject about the transfer.\n(114)In any case, where the Commission has taken no decision on the adequate level of data protection in a third country, the controller or processor should make use of solutions that provide data subjects with enforceable and effective rights as regards the processing of their data in the Union once those data have been transferred so that that they will continue to benefit from fundamental rights and safeguards.\n(115)Some third countries adopt laws, regulations and other legal acts which purport to directly regulate the processing activities of natural and legal persons under the jurisdiction of the Member States. This may include judgments of courts or tribunals or decisions of administrative authorities in third countries requiring a controller or processor to transfer or disclose personal data, and which are not based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State. The extraterritorial application of those laws, regulations and other legal acts may be in breach of international law and may impede the attainment of the protection of natural persons ensured in the Union by this Regulation. Transfers should only be allowed where the conditions of this Regulation for a transfer to third countries are met. This may be the case, inter alia, where disclosure is necessary for an important ground of public interest recognised in Union or Member State law to which the controller is subject.\n(116)When personal data moves across borders outside the Union it may put at increased risk the ability of natural persons to exercise data protection rights in particular to protect themselves from the unlawful use or disclosure of that information. At the same time, supervisory authorities may find that they are unable to pursue complaints or conduct investigations relating to the activities outside their borders. Their efforts to work together in the cross-border context may also be hampered by insufficient preventative or remedial powers, inconsistent legal regimes, and practical obstacles like resource constraints. Therefore, there is a need to promote closer cooperation among data protection supervisory authorities to help them exchange information and carry out investigations with their international counterparts. For the purposes of developing international cooperation mechanisms to facilitate and provide international mutual assistance for the enforcement of legislation for the protection of personal data, the Commission and the supervisory authorities should exchange information and cooperate in activities related to the exercise of their powers with competent authorities in third countries, based on reciprocity and in accordance with this Regulation.\n(117)The establishment of supervisory authorities in Member States, empowered to perform their tasks and exercise their powers with complete independence, is an essential component of the protection of natural persons with regard to the processing of their personal data. Member States should be able to establish more than one supervisory authority, to reflect their constitutional, organisational and administrative structure.\n(118)The independence of supervisory authorities should not mean that the supervisory authorities cannot be subject to control or monitoring mechanisms regarding their financial expenditure or to judicial review.\n(119)Where a Member State establishes several supervisory authorities, it should establish by law mechanisms for ensuring the effective participation of those supervisory authorities in the consistency mechanism. That Member State should in particular designate the supervisory authority which functions as a single contact point for the effective participation of those authorities in the mechanism, to ensure swift and smooth cooperation with other supervisory authorities, the Board and the Commission.\n(120)Each supervisory authority should be provided with the financial and human resources, premises and infrastructure necessary for the effective performance of their tasks, including those related to mutual assistance and cooperation with other supervisory authorities throughout the Union. Each supervisory authority should have a separate, public annual budget, which may be part of the overall state or national budget.\n(121)The general conditions for the member or members of the supervisory authority should be laid down by law in each Member State and should in particular provide that those members are to be appointed, by means of a transparent procedure, either by the parliament, government or the head of State of the Member State on the basis of a proposal from the government, a member of the government, the parliament or a chamber of the parliament, or by an independent body entrusted under Member State law. In order to ensure the independence of the supervisory authority, the member or members should act with integrity, refrain from any action that is incompatible with their duties and should not, during their term of office, engage in any incompatible occupation, whether gainful or not. The supervisory authority should have its own staff, chosen by the supervisory authority or an independent body established by Member State law, which should be subject to the exclusive direction of the member or members of the supervisory authority.\n(122)Each supervisory authority should be competent on the territory of its own Member State to exercise the powers and to perform the tasks conferred on it in accordance with this Regulation. This should cover in particular the processing in the context of the activities of an establishment of the controller or processor on the territory of its own Member State, the processing of personal data carried out by public authorities or private bodies acting in the public interest, processing affecting data subjects on its territory or processing carried out by a controller or processor not established in the Union when targeting data subjects residing on its territory. This should include handling complaints lodged by a data subject, conducting investigations on the application of this Regulation and promoting public awareness of the risks, rules, safeguards and rights in relation to the processing of personal data.\n(123)The supervisory authorities should monitor the application of the provisions pursuant to this Regulation and contribute to its consistent application throughout the Union, in order to protect natural persons in relation to the processing of their personal data and to facilitate the free flow of personal data within the internal market. For that purpose, the supervisory authorities should cooperate with each other and with the Commission, without the need for any agreement between Member States on the provision of mutual assistance or on such cooperation.\n(124)Where the processing of personal data takes place in the context of the activities of an establishment of a controller or a processor in the Union and the controller or processor is established in more than one Member State, or where processing taking place in the context of the activities of a single establishment of a controller or processor in the Union substantially affects or is likely to substantially affect data subjects in more than one Member State, the supervisory authority for the main establishment of the controller or processor or for the single establishment of the controller or processor should act as lead authority. It should cooperate with the other authorities concerned, because the controller or processor has an establishment on the territory of their Member State, because data subjects residing on their territory are substantially affected, or because a complaint has been lodged with them. Also where a data subject not residing in that Member State has lodged a complaint, the supervisory authority with which such complaint has been lodged should also be a supervisory authority concerned. Within its tasks to issue guidelines on any question covering the application of this Regulation, the Board should be able to issue guidelines in particular on the criteria to be taken into account in order to ascertain whether the processing in question substantially affects data subjects in more than one Member State and on what constitutes a relevant and reasoned objection.\n(125)The lead authority should be competent to adopt binding decisions regarding measures applying the powers conferred on it in accordance with this Regulation. In its capacity as lead authority, the supervisory authority should closely involve and coordinate the supervisory authorities concerned in the decision-making process. Where the decision is to reject the complaint by the data subject in whole or in part, that decision should be adopted by the supervisory authority with which the complaint has been lodged.\n(126)The decision should be agreed jointly by the lead supervisory authority and the supervisory authorities concerned and should be directed towards the main or single establishment of the controller or processor and be binding on the controller and processor. The controller or processor should take the necessary measures to ensure compliance with this Regulation and the implementation of the decision notified by the lead supervisory authority to the main establishment of the controller or processor as regards the processing activities in the Union.\n(127)Each supervisory authority not acting as the lead supervisory authority should be competent to handle local cases where the controller or processor is established in more than one Member State, but the subject matter of the specific processing concerns only processing carried out in a single Member State and involves only data subjects in that single Member State, for example, where the subject matter concerns the processing of employees\u0026rsquo; personal data in the specific employment context of a Member State. In such cases, the supervisory authority should inform the lead supervisory authority without delay about the matter. After being informed, the lead supervisory authority should decide, whether it will handle the case pursuant to the provision on cooperation between the lead supervisory authority and other supervisory authorities concerned (‘one-stop-shop mechanism’), or whether the supervisory authority which informed it should handle the case at local level. When deciding whether it will handle the case, the lead supervisory authority should take into account whether there is an establishment of the controller or processor in the Member State of the supervisory authority which informed it in order to ensure effective enforcement of a decision vis-à-vis the controller or processor. Where the lead supervisory authority decides to handle the case, the supervisory authority which informed it should have the possibility to submit a draft for a decision, of which the lead supervisory authority should take utmost account when preparing its draft decision in that one-stop-shop mechanism.\n(128)The rules on the lead supervisory authority and the one-stop-shop mechanism should not apply where the processing is carried out by public authorities or private bodies in the public interest. In such cases the only supervisory authority competent to exercise the powers conferred to it in accordance with this Regulation should be the supervisory authority of the Member State where the public authority or private body is established.\n(129)In order to ensure consistent monitoring and enforcement of this Regulation throughout the Union, the supervisory authorities should have in each Member State the same tasks and effective powers, including powers of investigation, corrective powers and sanctions, and authorisation and advisory powers, in particular in cases of complaints from natural persons, and without prejudice to the powers of prosecutorial authorities under Member State law, to bring infringements of this Regulation to the attention of the judicial authorities and engage in legal proceedings. Such powers should also include the power to impose a temporary or definitive limitation, including a ban, on processing. Member States may specify other tasks related to the protection of personal data under this Regulation. The powers of supervisory authorities should be exercised in accordance with appropriate procedural safeguards set out in Union and Member State law, impartially, fairly and within a reasonable time. In particular each measure should be appropriate, necessary and proportionate in view of ensuring compliance with this Regulation, taking into account the circumstances of each individual case, respect the right of every person to be heard before any individual measure which would affect him or her adversely is taken and avoid superfluous costs and excessive inconveniences for the persons concerned. Investigatory powers as regards access to premises should be exercised in accordance with specific requirements in Member State procedural law, such as the requirement to obtain a prior judicial authorisation. Each legally binding measure of the supervisory authority should be in writing, be clear and unambiguous, indicate the supervisory authority which has issued the measure, the date of issue of the measure, bear the signature of the head, or a member of the supervisory authority authorised by him or her, give the reasons for the measure, and refer to the right of an effective remedy. This should not preclude additional requirements pursuant to Member State procedural law. The adoption of a legally binding decision implies that it may give rise to judicial review in the Member State of the supervisory authority that adopted the decision.\n(130)Where the supervisory authority with which the complaint has been lodged is not the lead supervisory authority, the lead supervisory authority should closely cooperate with the supervisory authority with which the complaint has been lodged in accordance with the provisions on cooperation and consistency laid down in this Regulation. In such cases, the lead supervisory authority should, when taking measures intended to produce legal effects, including the imposition of administrative fines, take utmost account of the view of the supervisory authority with which the complaint has been lodged and which should remain competent to carry out any investigation on the territory of its own Member State in liaison with the competent supervisory authority.\n(131)Where another supervisory authority should act as a lead supervisory authority for the processing activities of the controller or processor but the concrete subject matter of a complaint or the possible infringement concerns only processing activities of the controller or processor in the Member State where the complaint has been lodged or the possible infringement detected and the matter does not substantially affect or is not likely to substantially affect data subjects in other Member States, the supervisory authority receiving a complaint or detecting or being informed otherwise of situations that entail possible infringements of this Regulation should seek an amicable settlement with the controller and, if this proves unsuccessful, exercise its full range of powers. This should include: specific processing carried out in the territory of the Member State of the supervisory authority or with regard to data subjects on the territory of that Member State; processing that is carried out in the context of an offer of goods or services specifically aimed at data subjects in the territory of the Member State of the supervisory authority; or processing that has to be assessed taking into account relevant legal obligations under Member State law.\n(132)Awareness-raising activities by supervisory authorities addressed to the public should include specific measures directed at controllers and processors, including micro, small and medium-sized enterprises, as well as natural persons in particular in the educational context.\n(133)The supervisory authorities should assist each other in performing their tasks and provide mutual assistance, so as to ensure the consistent application and enforcement of this Regulation in the internal market. A supervisory authority requesting mutual assistance may adopt a provisional measure if it receives no response to a request for mutual assistance within one month of the receipt of that request by the other supervisory authority.\n(134)Each supervisory authority should, where appropriate, participate in joint operations with other supervisory authorities. The requested supervisory authority should be obliged to respond to the request within a specified time period.\n(135)In order to ensure the consistent application of this Regulation throughout the Union, a consistency mechanism for cooperation between the supervisory authorities should be established. That mechanism should in particular apply where a supervisory authority intends to adopt a measure intended to produce legal effects as regards processing operations which substantially affect a significant number of data subjects in several Member States. It should also apply where any supervisory authority concerned or the Commission requests that such matter should be handled in the consistency mechanism. That mechanism should be without prejudice to any measures that the Commission may take in the exercise of its powers under the Treaties.\n(136)In applying the consistency mechanism, the Board should, within a determined period of time, issue an opinion, if a majority of its members so decides or if so requested by any supervisory authority concerned or the Commission. The Board should also be empowered to adopt legally binding decisions where there are disputes between supervisory authorities. For that purpose, it should issue, in principle by a two-thirds majority of its members, legally binding decisions in clearly specified cases where there are conflicting views among supervisory authorities, in particular in the cooperation mechanism between the lead supervisory authority and supervisory authorities concerned on the merits of the case, in particular whether there is an infringement of this Regulation.\n(137)There may be an urgent need to act in order to protect the rights and freedoms of data subjects, in particular when the danger exists that the enforcement of a right of a data subject could be considerably impeded. A supervisory authority should therefore be able to adopt duly justified provisional measures on its territory with a specified period of validity which should not exceed three months.\n(138)The application of such mechanism should be a condition for the lawfulness of a measure intended to produce legal effects by a supervisory authority in those cases where its application is mandatory. In other cases of cross-border relevance, the cooperation mechanism between the lead supervisory authority and supervisory authorities concerned should be applied and mutual assistance and joint operations might be carried out between the supervisory authorities concerned on a bilateral or multilateral basis without triggering the consistency mechanism.\n(139)In order to promote the consistent application of this Regulation, the Board should be set up as an independent body of the Union. To fulfil its objectives, the Board should have legal personality. The Board should be represented by its Chair. It should replace the Working Party on the Protection of Individuals with Regard to the Processing of Personal Data established by Directive 95/46/EC. It should consist of the head of a supervisory authority of each Member State and the European Data Protection Supervisor or their respective representatives. The Commission should participate in the Board\u0026rsquo;s activities without voting rights and the European Data Protection Supervisor should have specific voting rights. The Board should contribute to the consistent application of this Regulation throughout the Union, including by advising the Commission, in particular on the level of protection in third countries or international organisations, and promoting cooperation of the supervisory authorities throughout the Union. The Board should act independently when performing its tasks.\n(140)The Board should be assisted by a secretariat provided by the European Data Protection Supervisor. The staff of the European Data Protection Supervisor involved in carrying out the tasks conferred on the Board by this Regulation should perform its tasks exclusively under the instructions of, and report to, the Chair of the Board.\n(141)Every data subject should have the right to lodge a complaint with a single supervisory authority, in particular in the Member State of his or her habitual residence, and the right to an effective judicial remedy in accordance with Article 47 of the Charter if the data subject considers that his or her rights under this Regulation are infringed or where the supervisory authority does not act on a complaint, partially or wholly rejects or dismisses a complaint or does not act where such action is necessary to protect the rights of the data subject. The investigation following a complaint should be carried out, subject to judicial review, to the extent that is appropriate in the specific case. The supervisory authority should inform the data subject of the progress and the outcome of the complaint within a reasonable period. If the case requires further investigation or coordination with another supervisory authority, intermediate information should be given to the data subject. In order to facilitate the submission of complaints, each supervisory authority should take measures such as providing a complaint submission form which can also be completed electronically, without excluding other means of communication.\n(142)Where a data subject considers that his or her rights under this Regulation are infringed, he or she should have the right to mandate a not-for-profit body, organisation or association which is constituted in accordance with the law of a Member State, has statutory objectives which are in the public interest and is active in the field of the protection of personal data to lodge a complaint on his or her behalf with a supervisory authority, exercise the right to a judicial remedy on behalf of data subjects or, if provided for in Member State law, exercise the right to receive compensation on behalf of data subjects. A Member State may provide for such a body, organisation or association to have the right to lodge a complaint in that Member State, independently of a data subject\u0026rsquo;s mandate, and the right to an effective judicial remedy where it has reasons to consider that the rights of a data subject have been infringed as a result of the processing of personal data which infringes this Regulation. That body, organisation or association may not be allowed to claim compensation on a data subject\u0026rsquo;s behalf independently of the data subject\u0026rsquo;s mandate.\n(143)Any natural or legal person has the right to bring an action for annulment of decisions of the Board before the Court of Justice under the conditions provided for in Article 263 TFEU. As addressees of such decisions, the supervisory authorities concerned which wish to challenge them have to bring action within two months of being notified of them, in accordance with Article 263 TFEU. Where decisions of the Board are of direct and individual concern to a controller, processor or complainant, the latter may bring an action for annulment against those decisions within two months of their publication on the website of the Board, in accordance with Article 263 TFEU. Without prejudice to this right under Article 263 TFEU, each natural or legal person should have an effective judicial remedy before the competent national court against a decision of a supervisory authority which produces legal effects concerning that person. Such a decision concerns in particular the exercise of investigative, corrective and authorisation powers by the supervisory authority or the dismissal or rejection of complaints. However, the right to an effective judicial remedy does not encompass measures taken by supervisory authorities which are not legally binding, such as opinions issued by or advice provided by the supervisory authority. Proceedings against a supervisory authority should be brought before the courts of the Member State where the supervisory authority is established and should be conducted in accordance with that Member State\u0026rsquo;s procedural law. Those courts should exercise full jurisdiction, which should include jurisdiction to examine all questions of fact and law relevant to the dispute before them.\nWhere a complaint has been rejected or dismissed by a supervisory authority, the complainant may bring proceedings before the courts in the same Member State. In the context of judicial remedies relating to the application of this Regulation, national courts which consider a decision on the question necessary to enable them to give judgment, may, or in the case provided for in Article 267 TFEU, must, request the Court of Justice to give a preliminary ruling on the interpretation of Union law, including this Regulation. Furthermore, where a decision of a supervisory authority implementing a decision of the Board is challenged before a national court and the validity of the decision of the Board is at issue, that national court does not have the power to declare the Board\u0026rsquo;s decision invalid but must refer the question of validity to the Court of Justice in accordance with Article 267 TFEU as interpreted by the Court of Justice, where it considers the decision invalid. However, a national court may not refer a question on the validity of the decision of the Board at the request of a natural or legal person which had the opportunity to bring an action for annulment of that decision, in particular if it was directly and individually concerned by that decision, but had not done so within the period laid down in Article 263 TFEU.\n(144)Where a court seized of proceedings against a decision by a supervisory authority has reason to believe that proceedings concerning the same processing, such as the same subject matter as regards processing by the same controller or processor, or the same cause of action, are brought before a competent court in another Member State, it should contact that court in order to confirm the existence of such related proceedings. If related proceedings are pending before a court in another Member State, any court other than the court first seized may stay its proceedings or may, on request of one of the parties, decline jurisdiction in favour of the court first seized if that court has jurisdiction over the proceedings in question and its law permits the consolidation of such related proceedings. Proceedings are deemed to be related where they are so closely connected that it is expedient to hear and determine them together in order to avoid the risk of irreconcilable judgments resulting from separate proceedings.\n(145)For proceedings against a controller or processor, the plaintiff should have the choice to bring the action before the courts of the Member States where the controller or processor has an establishment or where the data subject resides, unless the controller is a public authority of a Member State acting in the exercise of its public powers.\n(146)The controller or processor should compensate any damage which a person may suffer as a result of processing that infringes this Regulation. The controller or processor should be exempt from liability if it proves that it is not in any way responsible for the damage. The concept of damage should be broadly interpreted in the light of the case-law of the Court of Justice in a manner which fully reflects the objectives of this Regulation. This is without prejudice to any claims for damage deriving from the violation of other rules in Union or Member State law. Processing that infringes this Regulation also includes processing that infringes delegated and implementing acts adopted in accordance with this Regulation and Member State law specifying rules of this Regulation. Data subjects should receive full and effective compensation for the damage they have suffered. Where controllers or processors are involved in the same processing, each controller or processor should be held liable for the entire damage. However, where they are joined to the same judicial proceedings, in accordance with Member State law, compensation may be apportioned according to the responsibility of each controller or processor for the damage caused by the processing, provided that full and effective compensation of the data subject who suffered the damage is ensured. Any controller or processor which has paid full compensation may subsequently institute recourse proceedings against other controllers or processors involved in the same processing.\n(147)Where specific rules on jurisdiction are contained in this Regulation, in particular as regards proceedings seeking a judicial remedy including compensation, against a controller or processor, general jurisdiction rules such as those of Regulation (EU) No 1215/2012 of the European Parliament and of the Council(13) should not prejudice the application of such specific rules.\n(148)In order to strengthen the enforcement of the rules of this Regulation, penalties including administrative fines should be imposed for any infringement of this Regulation, in addition to, or instead of appropriate measures imposed by the supervisory authority pursuant to this Regulation. In a case of a minor infringement or if the fine likely to be imposed would constitute a disproportionate burden to a natural person, a reprimand may be issued instead of a fine. Due regard should however be given to the nature, gravity and duration of the infringement, the intentional character of the infringement, actions taken to mitigate the damage suffered, degree of responsibility or any relevant previous infringements, the manner in which the infringement became known to the supervisory authority, compliance with measures ordered against the controller or processor, adherence to a code of conduct and any other aggravating or mitigating factor. The imposition of penalties including administrative fines should be subject to appropriate procedural safeguards in accordance with the general principles of Union law and the Charter, including effective judicial protection and due process.\n(149)Member States should be able to lay down the rules on criminal penalties for infringements of this Regulation, including for infringements of national rules adopted pursuant to and within the limits of this Regulation. Those criminal penalties may also allow for the deprivation of the profits obtained through infringements of this Regulation. However, the imposition of criminal penalties for infringements of such national rules and of administrative penalties should not lead to a breach of the principle of ne bis in idem, as interpreted by the Court of Justice.\n(150)In order to strengthen and harmonise administrative penalties for infringements of this Regulation, each supervisory authority should have the power to impose administrative fines. This Regulation should indicate infringements and the upper limit and criteria for setting the related administrative fines, which should be determined by the competent supervisory authority in each individual case, taking into account all relevant circumstances of the specific situation, with due regard in particular to the nature, gravity and duration of the infringement and of its consequences and the measures taken to ensure compliance with the obligations under this Regulation and to prevent or mitigate the consequences of the infringement. Where administrative fines are imposed on an undertaking, an undertaking should be understood to be an undertaking in accordance with Articles 101 and 102 TFEU for those purposes. Where administrative fines are imposed on persons that are not an undertaking, the supervisory authority should take account of the general level of income in the Member State as well as the economic situation of the person in considering the appropriate amount of the fine. The consistency mechanism may also be used to promote a consistent application of administrative fines. It should be for the Member States to determine whether and to which extent public authorities should be subject to administrative fines. Imposing an administrative fine or giving a warning does not affect the application of other powers of the supervisory authorities or of other penalties under this Regulation.\n(151)The legal systems of Denmark and Estonia do not allow for administrative fines as set out in this Regulation. The rules on administrative fines may be applied in such a manner that in Denmark the fine is imposed by competent national courts as a criminal penalty and in Estonia the fine is imposed by the supervisory authority in the framework of a misdemeanour procedure, provided that such an application of the rules in those Member States has an equivalent effect to administrative fines imposed by supervisory authorities. Therefore the competent national courts should take into account the recommendation by the supervisory authority initiating the fine. In any event, the fines imposed should be effective, proportionate and dissuasive.\n(152)Where this Regulation does not harmonise administrative penalties or where necessary in other cases, for example in cases of serious infringements of this Regulation, Member States should implement a system which provides for effective, proportionate and dissuasive penalties. The nature of such penalties, criminal or administrative, should be determined by Member State law.\n(153)Member States law should reconcile the rules governing freedom of expression and information, including journalistic, academic, artistic and or literary expression with the right to the protection of personal data pursuant to this Regulation. The processing of personal data solely for journalistic purposes, or for the purposes of academic, artistic or literary expression should be subject to derogations or exemptions from certain provisions of this Regulation if necessary to reconcile the right to the protection of personal data with the right to freedom of expression and information, as enshrined in Article 11 of the Charter. This should apply in particular to the processing of personal data in the audiovisual field and in news archives and press libraries. Therefore, Member States should adopt legislative measures which lay down the exemptions and derogations necessary for the purpose of balancing those fundamental rights. Member States should adopt such exemptions and derogations on general principles, the rights of the data subject, the controller and the processor, the transfer of personal data to third countries or international organisations, the independent supervisory authorities, cooperation and consistency, and specific data-processing situations. Where such exemptions or derogations differ from one Member State to another, the law of the Member State to which the controller is subject should apply. In order to take account of the importance of the right to freedom of expression in every democratic society, it is necessary to interpret notions relating to that freedom, such as journalism, broadly.\n(154)This Regulation allows the principle of public access to official documents to be taken into account when applying this Regulation. Public access to official documents may be considered to be in the public interest. Personal data in documents held by a public authority or a public body should be able to be publicly disclosed by that authority or body if the disclosure is provided for by Union or Member State law to which the public authority or public body is subject. Such laws should reconcile public access to official documents and the reuse of public sector information with the right to the protection of personal data and may therefore provide for the necessary reconciliation with the right to the protection of personal data pursuant to this Regulation. The reference to public authorities and bodies should in that context include all authorities or other bodies covered by Member State law on public access to documents. Directive 2003/98/EC of the European Parliament and of the Council(14) leaves intact and in no way affects the level of protection of natural persons with regard to the processing of personal data under the provisions of Union and Member State law, and in particular does not alter the obligations and rights set out in this Regulation. In particular, that Directive should not apply to documents to which access is excluded or restricted by virtue of the access regimes on the grounds of protection of personal data, and parts of documents accessible by virtue of those regimes which contain personal data the re-use of which has been provided for by law as being incompatible with the law concerning the protection of natural persons with regard to the processing of personal data.\n(155)Member State law or collective agreements, including ‘works agreements’, may provide for specific rules on the processing of employees\u0026rsquo; personal data in the employment context, in particular for the conditions under which personal data in the employment context may be processed on the basis of the consent of the employee, the purposes of the recruitment, the performance of the contract of employment, including discharge of obligations laid down by law or by collective agreements, management, planning and organisation of work, equality and diversity in the workplace, health and safety at work, and for the purposes of the exercise and enjoyment, on an individual or collective basis, of rights and benefits related to employment, and for the purpose of the termination of the employment relationship.\n(156)The processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be subject to appropriate safeguards for the rights and freedoms of the data subject pursuant to this Regulation. Those safeguards should ensure that technical and organisational measures are in place in order to ensure, in particular, the principle of data minimisation. The further processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is to be carried out when the controller has assessed the feasibility to fulfil those purposes by processing data which do not permit or no longer permit the identification of data subjects, provided that appropriate safeguards exist (such as, for instance, pseudonymisation of the data). Member States should provide for appropriate safeguards for the processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. Member States should be authorised to provide, under specific conditions and subject to appropriate safeguards for data subjects, specifications and derogations with regard to the information requirements and rights to rectification, to erasure, to be forgotten, to restriction of processing, to data portability, and to object when processing personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. The conditions and safeguards in question may entail specific procedures for data subjects to exercise those rights if this is appropriate in the light of the purposes sought by the specific processing along with technical and organisational measures aimed at minimising the processing of personal data in pursuance of the proportionality and necessity principles. The processing of personal data for scientific purposes should also comply with other relevant legislation such as on clinical trials.\n(157)By coupling information from registries, researchers can obtain new knowledge of great value with regard to widespread medical conditions such as cardiovascular disease, cancer and depression. On the basis of registries, research results can be enhanced, as they draw on a larger population. Within social science, research on the basis of registries enables researchers to obtain essential knowledge about the long-term correlation of a number of social conditions such as unemployment and education with other life conditions. Research results obtained through registries provide solid, high-quality knowledge which can provide the basis for the formulation and implementation of knowledge-based policy, improve the quality of life for a number of people and improve the efficiency of social services. In order to facilitate scientific research, personal data can be processed for scientific research purposes, subject to appropriate conditions and safeguards set out in Union or Member State law.\n(158)Where personal data are processed for archiving purposes, this Regulation should also apply to that processing, bearing in mind that this Regulation should not apply to deceased persons. Public authorities or public or private bodies that hold records of public interest should be services which, pursuant to Union or Member State law, have a legal obligation to acquire, preserve, appraise, arrange, describe, communicate, promote, disseminate and provide access to records of enduring value for general public interest. Member States should also be authorised to provide for the further processing of personal data for archiving purposes, for example with a view to providing specific information related to the political behaviour under former totalitarian state regimes, genocide, crimes against humanity, in particular the Holocaust, or war crimes.\n(159)Where personal data are processed for scientific research purposes, this Regulation should also apply to that processing. For the purposes of this Regulation, the processing of personal data for scientific research purposes should be interpreted in a broad manner including for example technological development and demonstration, fundamental research, applied research and privately funded research. In addition, it should take into account the Union\u0026rsquo;s objective under Article 179(1) TFEU of achieving a European Research Area. Scientific research purposes should also include studies conducted in the public interest in the area of public health. To meet the specificities of processing personal data for scientific research purposes, specific conditions should apply in particular as regards the publication or otherwise disclosure of personal data in the context of scientific research purposes. If the result of scientific research in particular in the health context gives reason for further measures in the interest of the data subject, the general rules of this Regulation should apply in view of those measures.\n(160)Where personal data are processed for historical research purposes, this Regulation should also apply to that processing. This should also include historical research and research for genealogical purposes, bearing in mind that this Regulation should not apply to deceased persons.\n(161)For the purpose of consenting to the participation in scientific research activities in clinical trials, the relevant provisions of Regulation (EU) No 536/2014 of the European Parliament and of the Council(15) should apply.\n(162)Where personal data are processed for statistical purposes, this Regulation should apply to that processing. Union or Member State law should, within the limits of this Regulation, determine statistical content, control of access, specifications for the processing of personal data for statistical purposes and appropriate measures to safeguard the rights and freedoms of the data subject and for ensuring statistical confidentiality. Statistical purposes mean any operation of collection and the processing of personal data necessary for statistical surveys or for the production of statistical results. Those statistical results may further be used for different purposes, including a scientific research purpose. The statistical purpose implies that the result of processing for statistical purposes is not personal data, but aggregate data, and that this result or the personal data are not used in support of measures or decisions regarding any particular natural person.\n(163)The confidential information which the Union and national statistical authorities collect for the production of official European and official national statistics should be protected. European statistics should be developed, produced and disseminated in accordance with the statistical principles as set out in Article 338(2) TFEU, while national statistics should also comply with Member State law. Regulation (EC) No 223/2009 of the European Parliament and of the Council(16) provides further specifications on statistical confidentiality for European statistics.\n(164)As regards the powers of the supervisory authorities to obtain from the controller or processor access to personal data and access to their premises, Member States may adopt by law, within the limits of this Regulation, specific rules in order to safeguard the professional or other equivalent secrecy obligations, in so far as necessary to reconcile the right to the protection of personal data with an obligation of professional secrecy. This is without prejudice to existing Member State obligations to adopt rules on professional secrecy where required by Union law.\n(165)This Regulation respects and does not prejudice the status under existing constitutional law of churches and religious associations or communities in the Member States, as recognised in Article 17 TFEU.\n(166)In order to fulfil the objectives of this Regulation, namely to protect the fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data and to ensure the free movement of personal data within the Union, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission. In particular, delegated acts should be adopted in respect of criteria and requirements for certification mechanisms, information to be presented by standardised icons and procedures for providing such icons. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level. The Commission, when preparing and drawing-up delegated acts, should ensure a simultaneous, timely and appropriate transmission of relevant documents to the European Parliament and to the Council.\n(167)In order to ensure uniform conditions for the implementation of this Regulation, implementing powers should be conferred on the Commission when provided for by this Regulation. Those powers should be exercised in accordance with Regulation (EU) No 182/2011. In that context, the Commission should consider specific measures for micro, small and medium-sized enterprises.\n(168)The examination procedure should be used for the adoption of implementing acts on standard contractual clauses between controllers and processors and between processors; codes of conduct; technical standards and mechanisms for certification; the adequate level of protection afforded by a third country, a territory or a specified sector within that third country, or an international organisation; standard protection clauses; formats and procedures for the exchange of information by electronic means between controllers, processors and supervisory authorities for binding corporate rules; mutual assistance; and arrangements for the exchange of information by electronic means between supervisory authorities, and between supervisory authorities and the Board.\n(169)The Commission should adopt immediately applicable implementing acts where available evidence reveals that a third country, a territory or a specified sector within that third country, or an international organisation does not ensure an adequate level of protection, and imperative grounds of urgency so require.\n(170)Since the objective of this Regulation, namely to ensure an equivalent level of protection of natural persons and the free flow of personal data throughout the Union, cannot be sufficiently achieved by the Member States and can rather, by reason of the scale or effects of the action, be better achieved at Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on European Union (TEU). In accordance with the principle of proportionality as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve that objective.\n(171)Directive 95/46/EC should be repealed by this Regulation. Processing already under way on the date of application of this Regulation should be brought into conformity with this Regulation within the period of two years after which this Regulation enters into force. Where processing is based on consent pursuant to Directive 95/46/EC, it is not necessary for the data subject to give his or her consent again if the manner in which the consent has been given is in line with the conditions of this Regulation, so as to allow the controller to continue such processing after the date of application of this Regulation. Commission decisions adopted and authorisations by supervisory authorities based on Directive 95/46/EC remain in force until amended, replaced or repealed.\n(172)The European Data Protection Supervisor was consulted in accordance with Article 28(2) of Regulation (EC) No 45/2001 and delivered an opinion on 7 March 2012(17).\n(173)This Regulation should apply to all matters concerning the protection of fundamental rights and freedoms vis-à-vis the processing of personal data which are not subject to specific obligations with the same objective set out in Directive 2002/58/EC of the European Parliament and of the Council(18), including the obligations on the controller and the rights of natural persons. In order to clarify the relationship between this Regulation and Directive 2002/58/EC, that Directive should be amended accordingly. Once this Regulation is adopted, Directive 2002/58/EC should be reviewed in particular in order to ensure consistency with this Regulation,\nHAVE ADOPTED THIS REGULATION:\nCHAPTER I General provisions\nArticle 1 Subject-matter and objectives\n1.This Regulation lays down rules relating to the protection of natural persons with regard to the processing of personal data and rules relating to the free movement of personal data.\n2.This Regulation protects fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data.\n3.The free movement of personal data within the Union shall be neither restricted nor prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data.\nArticle 2 Material scope\n1.This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.\n2.This Regulation does not apply to the processing of personal data:\n(a)in the course of an activity which falls outside the scope of Union law;\n(b)by the Member States when carrying out activities which fall within the scope of Chapter 2 of Title V of the TEU;\n(c)by a natural person in the course of a purely personal or household activity;\n(d)by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.\n3.For the processing of personal data by the Union institutions, bodies, offices and agencies, Regulation (EC) No 45/2001 applies. Regulation (EC) No 45/2001 and other Union legal acts applicable to such processing of personal data shall be adapted to the principles and rules of this Regulation in accordance with Article 98.\n4.This Regulation shall be without prejudice to the application of Directive 2000/31/EC, in particular of the liability rules of intermediary service providers in Articles 12 to 15 of that Directive.\nArticle 3 Territorial scope\n1.This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.\n2.This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:\n(a)the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or\n(b)the monitoring of their behaviour as far as their behaviour takes place within the Union.\n3.This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.\nArticle 4 Definitions\nFor the purposes of this Regulation:\n(1)‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;\n(2)‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;\n(3)‘restriction of processing’ means the marking of stored personal data with the aim of limiting their processing in the future;\n(4)‘profiling’ means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person\u0026rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;\n(5)‘pseudonymisation’ means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person;\n(6)‘filing system’ means any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis;\n(7)‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;\n(8)‘processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;\n(9)‘recipient’ means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;\n(10)‘third party’ means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data;\n(11)‘consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject\u0026rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;\n(12)‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;\n(13)‘genetic data’ means personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question;\n(14)‘biometric data’ means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data;\n(15)‘data concerning health’ means personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status;\n(16)‘main establishment’ means: (a)as regards a controller with establishments in more than one Member State, the place of its central administration in the Union, unless the decisions on the purposes and means of the processing of personal data are taken in another establishment of the controller in the Union and the latter establishment has the power to have such decisions implemented, in which case the establishment having taken such decisions is to be considered to be the main establishment; (b)as regards a processor with establishments in more than one Member State, the place of its central administration in the Union, or, if the processor has no central administration in the Union, the establishment of the processor in the Union where the main processing activities in the context of the activities of an establishment of the processor take place to the extent that the processor is subject to specific obligations under this Regulation;\n(17)‘representative’ means a natural or legal person established in the Union who, designated by the controller or processor in writing pursuant to Article 27, represents the controller or processor with regard to their respective obligations under this Regulation;\n(18)‘enterprise’ means a natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity;\n(19)‘group of undertakings’ means a controlling undertaking and its controlled undertakings;\n(20)‘binding corporate rules’ means personal data protection policies which are adhered to by a controller or processor established on the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings, or group of enterprises engaged in a joint economic activity;\n(21)‘supervisory authority’ means an independent public authority which is established by a Member State pursuant to Article 51;\n(22)‘supervisory authority concerned’ means a supervisory authority which is concerned by the processing of personal data because: (a)the controller or processor is established on the territory of the Member State of that supervisory authority; (b)data subjects residing in the Member State of that supervisory authority are substantially affected or likely to be substantially affected by the processing; or (c)a complaint has been lodged with that supervisory authority;\n(23)‘cross-border processing’ means either: (a)processing of personal data which takes place in the context of the activities of establishments in more than one Member State of a controller or processor in the Union where the controller or processor is established in more than one Member State; or (b)processing of personal data which takes place in the context of the activities of a single establishment of a controller or processor in the Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State.\n(24)‘relevant and reasoned objection’ means an objection to a draft decision as to whether there is an infringement of this Regulation, or whether envisaged action in relation to the controller or processor complies with this Regulation, which clearly demonstrates the significance of the risks posed by the draft decision as regards the fundamental rights and freedoms of data subjects and, where applicable, the free flow of personal data within the Union;\n(25)‘information society service’ means a service as defined in point(b) of Article 1(1) of Directive (EU) 2015/1535 of the European Parliament and of the Council(19);\n(26)‘international organisation’ means an organisation and its subordinate bodies governed by public international law, or any other body which is set up by, or on the basis of, an agreement between two or more countries.\nCHAPTER II Principles\nArticle 5 Principles relating to processing of personal data\n1.Personal data shall be:\n(a)processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);\n(b)collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’);\n(c)adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);\n(d)accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);\n(e)kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’);\n(f)processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).\n2.The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).\nArticle 6 Lawfulness of processing\n1.Processing shall be lawful only if and to the extent that at least one of the following applies:\n(a)the data subject has given consent to the processing of his or her personal data for one or more specific purposes;\n(b)processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;\n(c)processing is necessary for compliance with a legal obligation to which the controller is subject;\n(d)processing is necessary in order to protect the vital interests of the data subject or of another natural person;\n(e)processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;\n(f)processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.\nPoint (f) of the first subparagraph shall not apply to processing carried out by public authorities in the performance of their tasks.\n2.Member States may maintain or introduce more specific provisions to adapt the application of the rules of this Regulation with regard to processing for compliance with points(c) and(e) of paragraph 1 by determining more precisely specific requirements for the processing and other measures to ensure lawful and fair processing including for other specific processing situations as provided for in Chapter IX.\n3.The basis for the processing referred to in point (c) and (e) of paragraph 1 shall be laid down by:\n(a)Union law; or\n(b)Member State law to which the controller is subject.\nThe purpose of the processing shall be determined in that legal basis or, as regards the processing referred to in point (e) of paragraph 1, shall be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. That legal basis may contain specific provisions to adapt the application of rules of this Regulation, inter alia: the general conditions governing the lawfulness of processing by the controller; the types of data which are subject to the processing; the data subjects concerned; the entities to, and the purposes for which, the personal data may be disclosed; the purpose limitation; storage periods; and processing operations and processing procedures, including measures to ensure lawful and fair processing such as those for other specific processing situations as provided for in Chapter IX. The Union or the Member State law shall meet an objective of public interest and be proportionate to the legitimate aim pursued.\n4.Where the processing for a purpose other than that for which the personal data have been collected is not based on the data subject\u0026rsquo;s consent or on a Union or Member State law which constitutes a necessary and proportionate measure in a democratic society to safeguard the objectives referred to in Article 23(1), the controller shall, in order to ascertain whether processing for another purpose is compatible with the purpose for which the personal data are initially collected, take into account, inter alia:\n(a)any link between the purposes for which the personal data have been collected and the purposes of the intended further processing;\n(b)the context in which the personal data have been collected, in particular regarding the relationship between data subjects and the controller;\n(c)the nature of the personal data, in particular whether special categories of personal data are processed, pursuant to Article 9, or whether personal data related to criminal convictions and offences are processed, pursuant to Article 10;\n(d)the possible consequences of the intended further processing for data subjects;\n(e)the existence of appropriate safeguards, which may include encryption or pseudonymisation.\nArticle 7 Conditions for consent\n1.Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.\n2.If the data subject\u0026rsquo;s consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration which constitutes an infringement of this Regulation shall not be binding.\n3.The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent.\n4.When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.\nArticle 8 Conditions applicable to child\u0026rsquo;s consent in relation to information society services\n1.Where point (a) of Article 6(1) applies, in relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child.\nMember States may provide by law for a lower age for those purposes provided that such lower age is not below 13 years.\n2.The controller shall make reasonable efforts to verify in such cases that consent is given or authorised by the holder of parental responsibility over the child, taking into consideration available technology.\n3.Paragraph 1 shall not affect the general contract law of Member States such as the rules on the validity, formation or effect of a contract in relation to a child.\nArticle 9 Processing of special categories of personal data\n1.Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person\u0026rsquo;s sex life or sexual orientation shall be prohibited.\n2.Paragraph 1 shall not apply if one of the following applies:\n(a)the data subject has given explicit consent to the processing of those personal data for one or more specified purposes, except where Union or Member State law provide that the prohibition referred to in paragraph 1 may not be lifted by the data subject;\n(b)processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law in so far as it is authorised by Union or Member State law or a collective agreement pursuant to Member State law providing for appropriate safeguards for the fundamental rights and the interests of the data subject;\n(c)processing is necessary to protect the vital interests of the data subject or of another natural person where the data subject is physically or legally incapable of giving consent;\n(d)processing is carried out in the course of its legitimate activities with appropriate safeguards by a foundation, association or any other not-for-profit body with a political, philosophical, religious or trade union aim and on condition that the processing relates solely to the members or to former members of the body or to persons who have regular contact with it in connection with its purposes and that the personal data are not disclosed outside that body without the consent of the data subjects;\n(e)processing relates to personal data which are manifestly made public by the data subject;\n(f)processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity;\n(g)processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject;\n(h)processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards referred to in paragraph 3;\n(i)processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices, on the basis of Union or Member State law which provides for suitable and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy;\n(j)processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) based on Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject.\n3.Personal data referred to in paragraph 1 may be processed for the purposes referred to in point(h) of paragraph 2 when those data are processed by or under the responsibility of a professional subject to the obligation of professional secrecy under Union or Member State law or rules established by national competent bodies or by another person also subject to an obligation of secrecy under Union or Member State law or rules established by national competent bodies.\n4.Member States may maintain or introduce further conditions, including limitations, with regard to the processing of genetic data, biometric data or data concerning health.\nArticle 10 Processing of personal data relating to criminal convictions and offences\nProcessing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects. Any comprehensive register of criminal convictions shall be kept only under the control of official authority.\nArticle 11 Processing which does not require identification\n1.If the purposes for which a controller processes personal data do not or do no longer require the identification of a data subject by the controller, the controller shall not be obliged to maintain, acquire or process additional information in order to identify the data subject for the sole purpose of complying with this Regulation.\n2.Where, in cases referred to in paragraph 1 of this Article, the controller is able to demonstrate that it is not in a position to identify the data subject, the controller shall inform the data subject accordingly, if possible. In such cases, Articles 15 to 20 shall not apply except where the data subject, for the purpose of exercising his or her rights under those articles, provides additional information enabling his or her identification.\nCHAPTER III Rights of the data subject\nSection 1\nTransparency and modalities\nArticle 12 Transparent information, communication and modalities for the exercise of the rights of the data subject\n1.The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14 and any communication under Articles 15 to 22 and 34 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child. The information shall be provided in writing, or by other means, including, where appropriate, by electronic means. When requested by the data subject, the information may be provided orally, provided that the identity of the data subject is proven by other means.\n2.The controller shall facilitate the exercise of data subject rights under Articles 15 to 22. In the cases referred to in Article 11(2), the controller shall not refuse to act on the request of the data subject for exercising his or her rights under Articles 15 to 22, unless the controller demonstrates that it is not in a position to identify the data subject.\n3.The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. The controller shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay. Where the data subject makes the request by electronic form means, the information shall be provided by electronic means where possible, unless otherwise requested by the data subject.\n4.If the controller does not take action on the request of the data subject, the controller shall inform the data subject without delay and at the latest within one month of receipt of the request of the reasons for not taking action and on the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.\n5.Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may either:\n(a)charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or\n(b)refuse to act on the request.\nThe controller shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request.\n6.Without prejudice to Article 11, where the controller has reasonable doubts concerning the identity of the natural person making the request referred to in Articles 15 to 21, the controller may request the provision of additional information necessary to confirm the identity of the data subject.\n7.The information to be provided to data subjects pursuant to Articles 13 and 14 may be provided in combination with standardised icons in order to give in an easily visible, intelligible and clearly legible manner a meaningful overview of the intended processing. Where the icons are presented electronically they shall be machine-readable.\n8.The Commission shall be empowered to adopt delegated acts in accordance with Article 92 for the purpose of determining the information to be presented by the icons and the procedures for providing standardised icons.\nSection 2\nInformation and access to personal data\nArticle 13 Information to be provided where personal data are collected from the data subject\n1.Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information:\n(a)the identity and the contact details of the controller and, where applicable, of the controller\u0026rsquo;s representative;\n(b)the contact details of the data protection officer, where applicable;\n(c)the purposes of the processing for which the personal data are intended as well as the legal basis for the processing;\n(d)where the processing is based on point (f) of Article 6(1), the legitimate interests pursued by the controller or by a third party;\n(e)the recipients or categories of recipients of the personal data, if any;\n(f)where applicable, the fact that the controller intends to transfer personal data to a third country or international organisation and the existence or absence of an adequacy decision by the Commission, or in the case of transfers referred to in Article 46 or 47, or the second subparagraph of Article 49(1), reference to the appropriate or suitable safeguards and the means by which to obtain a copy of them or where they have been made available.\n2.In addition to the information referred to in paragraph 1, the controller shall, at the time when personal data are obtained, provide the data subject with the following further information necessary to ensure fair and transparent processing:\n(a)the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period;\n(b)the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject or to object to processing as well as the right to data portability;\n(c)where the processing is based on point (a) of Article 6(1) or point (a) of Article 9(2), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;\n(d)the right to lodge a complaint with a supervisory authority;\n(e)whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether the data subject is obliged to provide the personal data and of the possible consequences of failure to provide such data;\n(f)the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.\n3.Where the controller intends to further process the personal data for a purpose other than that for which the personal data were collected, the controller shall provide the data subject prior to that further processing with information on that other purpose and with any relevant further information as referred to in paragraph 2.\n4.Paragraphs 1, 2 and 3 shall not apply where and insofar as the data subject already has the information.\nArticle 14 Information to be provided where personal data have not been obtained from the data subject\n1.Where personal data have not been obtained from the data subject, the controller shall provide the data subject with the following information:\n(a)the identity and the contact details of the controller and, where applicable, of the controller\u0026rsquo;s representative;\n(b)the contact details of the data protection officer, where applicable;\n(c)the purposes of the processing for which the personal data are intended as well as the legal basis for the processing;\n(d)the categories of personal data concerned;\n(e)the recipients or categories of recipients of the personal data, if any;\n(f)where applicable, that the controller intends to transfer personal data to a recipient in a third country or international organisation and the existence or absence of an adequacy decision by the Commission, or in the case of transfers referred to in Article 46 or 47, or the second subparagraph of Article 49(1), reference to the appropriate or suitable safeguards and the means to obtain a copy of them or where they have been made available.\n2.In addition to the information referred to in paragraph 1, the controller shall provide the data subject with the following information necessary to ensure fair and transparent processing in respect of the data subject:\n(a)the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period;\n(b)where the processing is based on point (f) of Article 6(1), the legitimate interests pursued by the controller or by a third party;\n(c)the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject and to object to processing as well as the right to data portability;\n(d)where processing is based on point (a) of Article 6(1) or point (a) of Article 9(2), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;\n(e)the right to lodge a complaint with a supervisory authority;\n(f)from which source the personal data originate, and if applicable, whether it came from publicly accessible sources;\n(g)the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.\n3.The controller shall provide the information referred to in paragraphs 1 and 2:\n(a)within a reasonable period after obtaining the personal data, but at the latest within one month, having regard to the specific circumstances in which the personal data are processed;\n(b)if the personal data are to be used for communication with the data subject, at the latest at the time of the first communication to that data subject; or\n(c)if a disclosure to another recipient is envisaged, at the latest when the personal data are first disclosed.\n4.Where the controller intends to further process the personal data for a purpose other than that for which the personal data were obtained, the controller shall provide the data subject prior to that further processing with information on that other purpose and with any relevant further information as referred to in paragraph 2.\n5.Paragraphs 1 to 4 shall not apply where and insofar as:\n(a)the data subject already has the information;\n(b)the provision of such information proves impossible or would involve a disproportionate effort, in particular for processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing. In such cases the controller shall take appropriate measures to protect the data subject\u0026rsquo;s rights and freedoms and legitimate interests, including making the information publicly available;\n(c)obtaining or disclosure is expressly laid down by Union or Member State law to which the controller is subject and which provides appropriate measures to protect the data subject\u0026rsquo;s legitimate interests; or\n(d)where the personal data must remain confidential subject to an obligation of professional secrecy regulated by Union or Member State law, including a statutory obligation of secrecy.\nArticle 15 Right of access by the data subject\n1.The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:\n(a)the purposes of the processing;\n(b)the categories of personal data concerned;\n(c)the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;\n(d)where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;\n(e)the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;\n(f)the right to lodge a complaint with a supervisory authority;\n(g)where the personal data are not collected from the data subject, any available information as to their source;\n(h)the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.\n2.Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be informed of the appropriate safeguards pursuant to Article 46 relating to the transfer.\n3.The controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs. Where the data subject makes the request by electronic means, and unless otherwise requested by the data subject, the information shall be provided in a commonly used electronic form.\n4.The right to obtain a copy referred to in paragraph 3 shall not adversely affect the rights and freedoms of others.\nSection 3\nRectification and erasure\nArticle 16 Right to rectification\nThe data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.\nArticle 17 Right to erasure (‘right to be forgotten’)\n1.The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:\n(a)the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;\n(b)the data subject withdraws consent on which the processing is based according to point(a) of Article 6(1), or point(a) of Article 9(2), and where there is no other legal ground for the processing;\n(c)the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2);\n(d)the personal data have been unlawfully processed;\n(e)the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;\n(f)the personal data have been collected in relation to the offer of information society services referred to in Article 8(1).\n2.Where the controller has made the personal data public and is obliged pursuant to paragraph 1 to erase the personal data, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.\n3.Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:\n(a)for exercising the right of freedom of expression and information;\n(b)for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;\n(c)for reasons of public interest in the area of public health in accordance with points(h) and (i) of Article 9(2) as well as Article 9(3);\n(d)for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or\n(e)for the establishment, exercise or defence of legal claims.\nArticle 18 Right to restriction of processing\n1.The data subject shall have the right to obtain from the controller restriction of processing where one of the following applies:\n(a)the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data;\n(b)the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;\n(c)the controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims;\n(d)the data subject has objected to processing pursuant to Article 21(1) pending the verification whether the legitimate grounds of the controller override those of the data subject.\n2.Where processing has been restricted under paragraph 1, such personal data shall, with the exception of storage, only be processed with the data subject\u0026rsquo;s consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.\n3.A data subject who has obtained restriction of processing pursuant to paragraph 1 shall be informed by the controller before the restriction of processing is lifted.\nArticle 19 Notification obligation regarding rectification or erasure of personal data or restriction of processing\nThe controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it.\nArticle 20 Right to data portability\n1.The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where:\n(a)the processing is based on consent pursuant to point (a) of Article 6(1) or point(a) of Article 9(2) or on a contract pursuant to point (b) of Article 6(1); and\n(b)the processing is carried out by automated means.\n2.In exercising his or her right to data portability pursuant to paragraph 1, the data subject shall have the right to have the personal data transmitted directly from one controller to another, where technically feasible.\n3.The exercise of the right referred to in paragraph 1 of this Article shall be without prejudice to Article 17. That right shall not apply to processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.\n4.The right referred to in paragraph 1 shall not adversely affect the rights and freedoms of others.\nSection 4\nRight to object and automated individual decision-making\nArticle 21 Right to object\n1.The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1), including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.\n2.Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.\n3.Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.\n4.At the latest at the time of the first communication with the data subject, the right referred to in paragraphs 1 and 2 shall be explicitly brought to the attention of the data subject and shall be presented clearly and separately from any other information.\n5.In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, the data subject may exercise his or her right to object by automated means using technical specifications.\n6.Where personal data are processed for scientific or historical research purposes or statistical purposes pursuant to Article 89(1), the data subject, on grounds relating to his or her particular situation, shall have the right to object to processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.\nArticle 22 Automated individual decision-making, including profiling\n1.The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.\n2.Paragraph 1 shall not apply if the decision:\n(a)is necessary for entering into, or performance of, a contract between the data subject and a data controller;\n(b)is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject\u0026rsquo;s rights and freedoms and legitimate interests; or\n(c)is based on the data subject\u0026rsquo;s explicit consent.\n3.In the cases referred to in points (a) and (c) of paragraph 2, the data controller shall implement suitable measures to safeguard the data subject\u0026rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.\n4.Decisions referred to in paragraph 2 shall not be based on special categories of personal data referred to in Article 9(1), unless point (a) or (g) of Article 9(2) applies and suitable measures to safeguard the data subject\u0026rsquo;s rights and freedoms and legitimate interests are in place.\nSection 5\nRestrictions\nArticle 23 Restrictions\n1.Union or Member State law to which the data controller or processor is subject may restrict by way of a legislative measure the scope of the obligations and rights provided for in Articles 12 to 22 and Article 34, as well as Article 5 in so far as its provisions correspond to the rights and obligations provided for in Articles 12 to 22, when such a restriction respects the essence of the fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to safeguard:\n(a)national security;\n(b)defence;\n(c)public security;\n(d)the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security;\n(e)other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, including monetary, budgetary and taxation a matters, public health and social security;\n(f)the protection of judicial independence and judicial proceedings;\n(g)the prevention, investigation, detection and prosecution of breaches of ethics for regulated professions;\n(h)a monitoring, inspection or regulatory function connected, even occasionally, to the exercise of official authority in the cases referred to in points (a) to (e) and(g);\n(i)the protection of the data subject or the rights and freedoms of others;\n(j)the enforcement of civil law claims.\n2.In particular, any legislative measure referred to in paragraph 1 shall contain specific provisions at least, where relevant, as to:\n(a)the purposes of the processing or categories of processing;\n(b)the categories of personal data;\n(c)the scope of the restrictions introduced;\n(d)the safeguards to prevent abuse or unlawful access or transfer;\n(e)the specification of the controller or categories of controllers;\n(f)the storage periods and the applicable safeguards taking into account the nature, scope and purposes of the processing or categories of processing;\n(g)the risks to the rights and freedoms of data subjects; and\n(h)the right of data subjects to be informed about the restriction, unless that may be prejudicial to the purpose of the restriction.\nCHAPTER IV Controller and processor\nSection 1\nGeneral obligations\nArticle 24 Responsibility of the controller\n1.Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. Those measures shall be reviewed and updated where necessary.\n2.Where proportionate in relation to processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller.\n3.Adherence to approved codes of conduct as referred to in Article 40 or approved certification mechanisms as referred to in Article 42 may be used as an element by which to demonstrate compliance with the obligations of the controller.\nArticle 25 Data protection by design and by default\n1.Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.\n2.The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual\u0026rsquo;s intervention to an indefinite number of natural persons.\n3.An approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2 of this Article.\nArticle 26 Joint controllers\n1.Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers. They shall in a transparent manner determine their respective responsibilities for compliance with the obligations under this Regulation, in particular as regards the exercising of the rights of the data subject and their respective duties to provide the information referred to in Articles 13 and 14, by means of an arrangement between them unless, and in so far as, the respective responsibilities of the controllers are determined by Union or Member State law to which the controllers are subject. The arrangement may designate a contact point for data subjects.\n2.The arrangement referred to in paragraph 1 shall duly reflect the respective roles and relationships of the joint controllers vis-à-vis the data subjects. The essence of the arrangement shall be made available to the data subject.\n3.Irrespective of the terms of the arrangement referred to in paragraph 1, the data subject may exercise his or her rights under this Regulation in respect of and against each of the controllers.\nArticle 27 Representatives of controllers or processors not established in the Union\n1.Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union.\n2.The obligation laid down in paragraph 1 of this Article shall not apply to:\n(a)processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or\n(b)a public authority or body.\n3.The representative shall be established in one of the Member States where the data subjects, whose personal data are processed in relation to the offering of goods or services to them, or whose behaviour is monitored, are.\n4.The representative shall be mandated by the controller or processor to be addressed in addition to or instead of the controller or the processor by, in particular, supervisory authorities and data subjects, on all issues related to processing, for the purposes of ensuring compliance with this Regulation.\n5.The designation of a representative by the controller or processor shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves.\nArticle 28 Processor\n1.Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.\n2.The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes.\n3.Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. That contract or other legal act shall stipulate, in particular, that the processor:\n(a)processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the processor is subject; in such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;\n(b)ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;\n(c)takes all measures required pursuant to Article 32;\n(d)respects the conditions referred to in paragraphs 2 and 4 for engaging another processor;\n(e)taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller\u0026rsquo;s obligation to respond to requests for exercising the data subject\u0026rsquo;s rights laid down in Chapter III;\n(f)assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 taking into account the nature of processing and the information available to the processor;\n(g)at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data;\n(h)makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.\nWith regard to point(h) of the first subparagraph, the processor shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation or other Union or Member State data protection provisions.\n4.Where a processor engages another processor for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in the contract or other legal act between the controller and the processor as referred to in paragraph 3 shall be imposed on that other processor by way of a contract or other legal act under Union or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of this Regulation. Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor\u0026rsquo;s obligations.\n5.Adherence of a processor to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate sufficient guarantees as referred to in paragraphs 1 and 4 of this Article.\n6.Without prejudice to an individual contract between the controller and the processor, the contract or the other legal act referred to in paragraphs 3 and 4 of this Article may be based, in whole or in part, on standard contractual clauses referred to in paragraphs 7 and 8 of this Article, including when they are part of a certification granted to the controller or processor pursuant to Articles 42 and 43.\n7.The Commission may lay down standard contractual clauses for the matters referred to in paragraph 3 and 4 of this Article and in accordance with the examination procedure referred to in Article 93(2).\n8.A supervisory authority may adopt standard contractual clauses for the matters referred to in paragraph 3 and 4 of this Article and in accordance with the consistency mechanism referred to in Article 63.\n9.The contract or the other legal act referred to in paragraphs 3 and 4 shall be in writing, including in electronic form.\n10.Without prejudice to Articles 82, 83 and 84, if a processor infringes this Regulation by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing.\nArticle 29 Processing under the authority of the controller or processor\nThe processor and any person acting under the authority of the controller or of the processor, who has access to personal data, shall not process those data except on instructions from the controller, unless required to do so by Union or Member State law.\nArticle 30 Records of processing activities\n1.Each controller and, where applicable, the controller\u0026rsquo;s representative, shall maintain a record of processing activities under its responsibility. That record shall contain all of the following information:\n(a)the name and contact details of the controller and, where applicable, the joint controller, the controller\u0026rsquo;s representative and the data protection officer;\n(b)the purposes of the processing;\n(c)a description of the categories of data subjects and of the categories of personal data;\n(d)the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or international organisations;\n(e)where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards;\n(f)where possible, the envisaged time limits for erasure of the different categories of data;\n(g)where possible, a general description of the technical and organisational security measures referred to in Article 32(1).\n2.Each processor and, where applicable, the processor\u0026rsquo;s representative shall maintain a record of all categories of processing activities carried out on behalf of a controller, containing:\n(a)the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller\u0026rsquo;s or the processor\u0026rsquo;s representative, and the data protection officer;\n(b)the categories of processing carried out on behalf of each controller;\n(c)where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards;\n(d)where possible, a general description of the technical and organisational security measures referred to in Article 32(1).\n3.The records referred to in paragraphs 1 and 2 shall be in writing, including in electronic form.\n4.The controller or the processor and, where applicable, the controller\u0026rsquo;s or the processor\u0026rsquo;s representative, shall make the record available to the supervisory authority on request.\n5.The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.\nArticle 31 Cooperation with the supervisory authority\nThe controller and the processor and, where applicable, their representatives, shall cooperate, on request, with the supervisory authority in the performance of its tasks.\nSection 2\nSecurity of personal data\nArticle 32 Security of processing\n1.Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:\n(a)the pseudonymisation and encryption of personal data;\n(b)the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;\n(c)the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;\n(d)a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.\n2.In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.\n3.Adherence to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate compliance with the requirements set out in paragraph 1 of this Article.\n4.The controller and processor shall take steps to ensure that any natural person acting under the authority of the controller or the processor who has access to personal data does not process them except on instructions from the controller, unless he or she is required to do so by Union or Member State law.\nArticle 33 Notification of a personal data breach to the supervisory authority\n1.In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.\n2.The processor shall notify the controller without undue delay after becoming aware of a personal data breach.\n3.The notification referred to in paragraph 1 shall at least:\n(a)describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;\n(b)communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;\n(c)describe the likely consequences of the personal data breach;\n(d)describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.\n4.Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.\n5.The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.\nArticle 34 Communication of a personal data breach to the data subject\n1.When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.\n2.The communication to the data subject referred to in paragraph 1 of this Article shall describe in clear and plain language the nature of the personal data breach and contain at least the information and measures referred to in points(b), (c) and (d) of Article 33(3).\n3.The communication to the data subject referred to in paragraph 1 shall not be required if any of the following conditions are met:\n(a)the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;\n(b)the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects referred to in paragraph 1 is no longer likely to materialise;\n(c)it would involve disproportionate effort. In such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.\n4.If the controller has not already communicated the personal data breach to the data subject, the supervisory authority, having considered the likelihood of the personal data breach resulting in a high risk, may require it to do so or may decide that any of the conditions referred to in paragraph 3 are met.\nSection 3\nData protection impact assessment and prior consultation\nArticle 35 Data protection impact assessment\n1.Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.\n2.The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.\n3.A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:\n(a)a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;\n(b)processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or\n(c)a systematic monitoring of a publicly accessible area on a large scale.\n4.The supervisory authority shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. The supervisory authority shall communicate those lists to the Board referred to in Article 68.\n5.The supervisory authority may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. The supervisory authority shall communicate those lists to the Board.\n6.Prior to the adoption of the lists referred to in paragraphs 4 and 5, the competent supervisory authority shall apply the consistency mechanism referred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services to data subjects or to the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Union.\n7.The assessment shall contain at least:\n(a)a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;\n(b)an assessment of the necessity and proportionality of the processing operations in relation to the purposes;\n(c)an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and\n(d)the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.\n8.Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.\n9.Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.\n10.Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.\n11.Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.\nArticle 36 Prior consultation\n1.The controller shall consult the supervisory authority prior to processing where a data protection impact assessment under Article 35 indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk.\n2.Where the supervisory authority is of the opinion that the intended processing referred to in paragraph 1 would infringe this Regulation, in particular where the controller has insufficiently identified or mitigated the risk, the supervisory authority shall, within period of up to eight weeks of receipt of the request for consultation, provide written advice to the controller and, where applicable to the processor, and may use any of its powers referred to in Article 58. That period may be extended by six weeks, taking into account the complexity of the intended processing. The supervisory authority shall inform the controller and, where applicable, the processor, of any such extension within one month of receipt of the request for consultation together with the reasons for the delay. Those periods may be suspended until the supervisory authority has obtained information it has requested for the purposes of the consultation.\n3.When consulting the supervisory authority pursuant to paragraph 1, the controller shall provide the supervisory authority with:\n(a)where applicable, the respective responsibilities of the controller, joint controllers and processors involved in the processing, in particular for processing within a group of undertakings;\n(b)the purposes and means of the intended processing;\n(c)the measures and safeguards provided to protect the rights and freedoms of data subjects pursuant to this Regulation;\n(d)where applicable, the contact details of the data protection officer;\n(e)the data protection impact assessment provided for in Article 35; and\n(f)any other information requested by the supervisory authority.\n4.Member States shall consult the supervisory authority during the preparation of a proposal for a legislative measure to be adopted by a national parliament, or of a regulatory measure based on such a legislative measure, which relates to processing.\n5.Notwithstanding paragraph 1, Member State law may require controllers to consult with, and obtain prior authorisation from, the supervisory authority in relation to processing by a controller for the performance of a task carried out by the controller in the public interest, including processing in relation to social protection and public health.\nSection 4\nData protection officer\nArticle 37 Designation of the data protection officer\n1.The controller and the processor shall designate a data protection officer in any case where:\n(a)the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;\n(b)the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or\n(c)the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10.\n2.A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment.\n3.Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size.\n4.In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors.\n5.The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.\n6.The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.\n7.The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority.\nArticle 38 Position of the data protection officer\n1.The controller and the processor shall ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal data.\n2.The controller and processor shall support the data protection officer in performing the tasks referred to in Article 39 by providing resources necessary to carry out those tasks and access to personal data and processing operations, and to maintain his or her expert knowledge.\n3.The controller and processor shall ensure that the data protection officer does not receive any instructions regarding the exercise of those tasks. He or she shall not be dismissed or penalised by the controller or the processor for performing his tasks. The data protection officer shall directly report to the highest management level of the controller or the processor.\n4.Data subjects may contact the data protection officer with regard to all issues related to processing of their personal data and to the exercise of their rights under this Regulation.\n5.The data protection officer shall be bound by secrecy or confidentiality concerning the performance of his or her tasks, in accordance with Union or Member State law.\n6.The data protection officer may fulfil other tasks and duties. The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests.\nArticle 39 Tasks of the data protection officer\n1.The data protection officer shall have at least the following tasks:\n(a)to inform and advise the controller or the processor and the employees who carry out processing of their obligations pursuant to this Regulation and to other Union or Member State data protection provisions;\n(b)to monitor compliance with this Regulation, with other Union or Member State data protection provisions and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits;\n(c)to provide advice where requested as regards the data protection impact assessment and monitor its performance pursuant to Article 35;\n(d)to cooperate with the supervisory authority;\n(e)to act as the contact point for the supervisory authority on issues relating to processing, including the prior consultation referred to in Article 36, and to consult, where appropriate, with regard to any other matter.\n2.The data protection officer shall in the performance of his or her tasks have due regard to the risk associated with processing operations, taking into account the nature, scope, context and purposes of processing.\nSection 5\nCodes of conduct and certification\nArticle 40 Codes of conduct\n1.The Member States, the supervisory authorities, the Board and the Commission shall encourage the drawing up of codes of conduct intended to contribute to the proper application of this Regulation, taking account of the specific features of the various processing sectors and the specific needs of micro, small and medium-sized enterprises.\n2.Associations and other bodies representing categories of controllers or processors may prepare codes of conduct, or amend or extend such codes, for the purpose of specifying the application of this Regulation, such as with regard to:\n(a)fair and transparent processing;\n(b)the legitimate interests pursued by controllers in specific contexts;\n(c)the collection of personal data;\n(d)the pseudonymisation of personal data;\n(e)the information provided to the public and to data subjects;\n(f)the exercise of the rights of data subjects;\n(g)the information provided to, and the protection of, children, and the manner in which the consent of the holders of parental responsibility over children is to be obtained;\n(h)the measures and procedures referred to in Articles 24 and 25 and the measures to ensure security of processing referred to in Article 32;\n(i)the notification of personal data breaches to supervisory authorities and the communication of such personal data breaches to data subjects;\n(j)the transfer of personal data to third countries or international organisations; or\n(k)out-of-court proceedings and other dispute resolution procedures for resolving disputes between controllers and data subjects with regard to processing, without prejudice to the rights of data subjects pursuant to Articles 77 and 79.\n3.In addition to adherence by controllers or processors subject to this Regulation, codes of conduct approved pursuant to paragraph 5 of this Article and having general validity pursuant to paragraph 9 of this Article may also be adhered to by controllers or processors that are not subject to this Regulation pursuant to Article 3 in order to provide appropriate safeguards within the framework of personal data transfers to third countries or international organisations under the terms referred to in point (e) of Article 46(2). Such controllers or processors shall make binding and enforceable commitments, via contractual or other legally binding instruments, to apply those appropriate safeguards including with regard to the rights of data subjects.\n4.A code of conduct referred to in paragraph 2 of this Article shall contain mechanisms which enable the body referred to in Article 41(1) to carry out the mandatory monitoring of compliance with its provisions by the controllers or processors which undertake to apply it, without prejudice to the tasks and powers of supervisory authorities competent pursuant to Article 55 or 56.\n5.Associations and other bodies referred to in paragraph 2 of this Article which intend to prepare a code of conduct or to amend or extend an existing code shall submit the draft code, amendment or extension to the supervisory authority which is competent pursuant to Article 55. The supervisory authority shall provide an opinion on whether the draft code, amendment or extension complies with this Regulation and shall approve that draft code, amendment or extension if it finds that it provides sufficient appropriate safeguards.\n6.Where the draft code, or amendment or extension is approved in accordance with paragraph 5, and where the code of conduct concerned does not relate to processing activities in several Member States, the supervisory authority shall register and publish the code.\n7.Where a draft code of conduct relates to processing activities in several Member States, the supervisory authority which is competent pursuant to Article 55 shall, before approving the draft code, amendment or extension, submit it in the procedure referred to in Article 63 to the Board which shall provide an opinion on whether the draft code, amendment or extension complies with this Regulation or, in the situation referred to in paragraph 3 of this Article, provides appropriate safeguards.\n8.Where the opinion referred to in paragraph 7 confirms that the draft code, amendment or extension complies with this Regulation, or, in the situation referred to in paragraph 3, provides appropriate safeguards, the Board shall submit its opinion to the Commission.\n9.The Commission may, by way of implementing acts, decide that the approved code of conduct, amendment or extension submitted to it pursuant to paragraph 8 of this Article have general validity within the Union. Those implementing acts shall be adopted in accordance with the examination procedure set out in Article 93(2).\n10.The Commission shall ensure appropriate publicity for the approved codes which have been decided as having general validity in accordance with paragraph 9.\n11.The Board shall collate all approved codes of conduct, amendments and extensions in a register and shall make them publicly available by way of appropriate means.\nArticle 41 Monitoring of approved codes of conduct\n1.Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58, the monitoring of compliance with a code of conduct pursuant to Article 40 may be carried out by a body which has an appropriate level of expertise in relation to the subject-matter of the code and is accredited for that purpose by the competent supervisory authority.\n2.A body as referred to in paragraph 1 may be accredited to monitor compliance with a code of conduct where that body has:\n(a)demonstrated its independence and expertise in relation to the subject-matter of the code to the satisfaction of the competent supervisory authority;\n(b)established procedures which allow it to assess the eligibility of controllers and processors concerned to apply the code, to monitor their compliance with its provisions and to periodically review its operation;\n(c)established procedures and structures to handle complaints about infringements of the code or the manner in which the code has been, or is being, implemented by a controller or processor, and to make those procedures and structures transparent to data subjects and the public; and\n(d)demonstrated to the satisfaction of the competent supervisory authority that its tasks and duties do not result in a conflict of interests.\n3.The competent supervisory authority shall submit the draft criteria for accreditation of a body as referred to in paragraph 1 of this Article to the Board pursuant to the consistency mechanism referred to in Article 63.\n4.Without prejudice to the tasks and powers of the competent supervisory authority and the provisions of Chapter VIII, a body as referred to in paragraph 1 of this Article shall, subject to appropriate safeguards, take appropriate action in cases of infringement of the code by a controller or processor, including suspension or exclusion of the controller or processor concerned from the code. It shall inform the competent supervisory authority of such actions and the reasons for taking them.\n5.The competent supervisory authority shall revoke the accreditation of a body as referred to in paragraph 1 if the conditions for accreditation are not, or are no longer, met or where actions taken by the body infringe this Regulation.\n6.This Article shall not apply to processing carried out by public authorities and bodies.\nArticle 42 Certification\n1.The Member States, the supervisory authorities, the Board and the Commission shall encourage, in particular at Union level, the establishment of data protection certification mechanisms and of data protection seals and marks, for the purpose of demonstrating compliance with this Regulation of processing operations by controllers and processors. The specific needs of micro, small and medium-sized enterprises shall be taken into account.\n2.In addition to adherence by controllers or processors subject to this Regulation, data protection certification mechanisms, seals or marks approved pursuant to paragraph 5 of this Article may be established for the purpose of demonstrating the existence of appropriate safeguards provided by controllers or processors that are not subject to this Regulation pursuant to Article 3 within the framework of personal data transfers to third countries or international organisations under the terms referred to in point(f) of Article 46(2). Such controllers or processors shall make binding and enforceable commitments, via contractual or other legally binding instruments, to apply those appropriate safeguards, including with regard to the rights of data subjects.\n3.The certification shall be voluntary and available via a process that is transparent.\n4.A certification pursuant to this Article does not reduce the responsibility of the controller or the processor for compliance with this Regulation and is without prejudice to the tasks and powers of the supervisory authorities which are competent pursuant to Article 55 or 56.\n5.A certification pursuant to this Article shall be issued by the certification bodies referred to in Article 43 or by the competent supervisory authority, on the basis of criteria approved by that competent supervisory authority pursuant to Article 58(3) or by the Board pursuant to Article 63. Where the criteria are approved by the Board, this may result in a common certification, the European Data Protection Seal.\n6.The controller or processor which submits its processing to the certification mechanism shall provide the certification body referred to in Article 43, or where applicable, the competent supervisory authority, with all information and access to its processing activities which are necessary to conduct the certification procedure.\n7.Certification shall be issued to a controller or processor for a maximum period of three years and may be renewed, under the same conditions, provided that the relevant requirements continue to be met. Certification shall be withdrawn, as applicable, by the certification bodies referred to in Article 43 or by the competent supervisory authority where the requirements for the certification are not or are no longer met.\n8.The Board shall collate all certification mechanisms and data protection seals and marks in a register and shall make them publicly available by any appropriate means.\nArticle 43 Certification bodies\n1.Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58, certification bodies which have an appropriate level of expertise in relation to data protection shall, after informing the supervisory authority in order to allow it to exercise its powers pursuant to point (h) of Article 58(2) where necessary, issue and renew certification. Member States shall ensure that those certification bodies are accredited by one or both of the following:\n(a)the supervisory authority which is competent pursuant to Article 55 or 56;\n(b)the national accreditation body named in accordance with Regulation (EC) No 765/2008 of the European Parliament and of the Council(20) in accordance with EN-ISO/IEC 17065/2012 and with the additional requirements established by the supervisory authority which is competent pursuant to Article 55 or 56.\n2.Certification bodies referred to in paragraph 1 shall be accredited in accordance with that paragraph only where they have:\n(a)demonstrated their independence and expertise in relation to the subject-matter of the certification to the satisfaction of the competent supervisory authority;\n(b)undertaken to respect the criteria referred to in Article 42(5) and approved by the supervisory authority which is competent pursuant to Article 55 or 56 or by the Board pursuant to Article 63;\n(c)established procedures for the issuing, periodic review and withdrawal of data protection certification, seals and marks;\n(d)established procedures and structures to handle complaints about infringements of the certification or the manner in which the certification has been, or is being, implemented by the controller or processor, and to make those procedures and structures transparent to data subjects and the public; and\n(e)demonstrated, to the satisfaction of the competent supervisory authority, that their tasks and duties do not result in a conflict of interests.\n3.The accreditation of certification bodies as referred to in paragraphs 1 and 2 of this Article shall take place on the basis of criteria approved by the supervisory authority which is competent pursuant to Article 55 or 56 or by the Board pursuant to Article 63. In the case of accreditation pursuant to point(b) of paragraph 1 of this Article, those requirements shall complement those envisaged in Regulation (EC) No 765/2008 and the technical rules that describe the methods and procedures of the certification bodies.\n4.The certification bodies referred to in paragraph 1 shall be responsible for the proper assessment leading to the certification or the withdrawal of such certification without prejudice to the responsibility of the controller or processor for compliance with this Regulation. The accreditation shall be issued for a maximum period of five years and may be renewed on the same conditions provided that the certification body meets the requirements set out in this Article.\n5.The certification bodies referred to in paragraph 1 shall provide the competent supervisory authorities with the reasons for granting or withdrawing the requested certification.\n6.The requirements referred to in paragraph 3 of this Article and the criteria referred to in Article 42(5) shall be made public by the supervisory authority in an easily accessible form. The supervisory authorities shall also transmit those requirements and criteria to the Board. The Board shall collate all certification mechanisms and data protection seals in a register and shall make them publicly available by any appropriate means.\n7.Without prejudice to Chapter VIII, the competent supervisory authority or the national accreditation body shall revoke an accreditation of a certification body pursuant to paragraph 1 of this Article where the conditions for the accreditation are not, or are no longer, met or where actions taken by a certification body infringe this Regulation.\n8.The Commission shall be empowered to adopt delegated acts in accordance with Article 92 for the purpose of specifying the requirements to be taken into account for the data protection certification mechanisms referred to in Article 42(1).\n9.The Commission may adopt implementing acts laying down technical standards for certification mechanisms and data protection seals and marks, and mechanisms to promote and recognise those certification mechanisms, seals and marks. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2).\nCHAPTER V Transfers of personal data to third countries or international organisations\nArticle 44 General principle for transfers\nAny transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation. All provisions in this Chapter shall be applied in order to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined.\nArticle 45 Transfers on the basis of an adequacy decision\n1.A transfer of personal data to a third country or an international organisation may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question ensures an adequate level of protection. Such a transfer shall not require any specific authorisation.\n2.When assessing the adequacy of the level of protection, the Commission shall, in particular, take account of the following elements:\n(a)the rule of law, respect for human rights and fundamental freedoms, relevant legislation, both general and sectoral, including concerning public security, defence, national security and criminal law and the access of public authorities to personal data, as well as the implementation of such legislation, data protection rules, professional rules and security measures, including rules for the onward transfer of personal data to another third country or international organisation which are complied with in that country or international organisation, case-law, as well as effective and enforceable data subject rights and effective administrative and judicial redress for the data subjects whose personal data are being transferred;\n(b)the existence and effective functioning of one or more independent supervisory authorities in the third country or to which an international organisation is subject, with responsibility for ensuring and enforcing compliance with the data protection rules, including adequate enforcement powers, for assisting and advising the data subjects in exercising their rights and for cooperation with the supervisory authorities of the Member States; and\n(c)the international commitments the third country or international organisation concerned has entered into, or other obligations arising from legally binding conventions or instruments as well as from its participation in multilateral or regional systems, in particular in relation to the protection of personal data.\n3.The Commission, after assessing the adequacy of the level of protection, may decide, by means of implementing act, that a third country, a territory or one or more specified sectors within a third country, or an international organisation ensures an adequate level of protection within the meaning of paragraph 2 of this Article. The implementing act shall provide for a mechanism for a periodic review, at least every four years, which shall take into account all relevant developments in the third country or international organisation. The implementing act shall specify its territorial and sectoral application and, where applicable, identify the supervisory authority or authorities referred to in point (b) of paragraph 2 of this Article. The implementing act shall be adopted in accordance with the examination procedure referred to in Article 93(2).\n4.The Commission shall, on an ongoing basis, monitor developments in third countries and international organisations that could affect the functioning of decisions adopted pursuant to paragraph 3 of this Article and decisions adopted on the basis of Article 25(6) of Directive 95/46/EC.\n5.The Commission shall, where available information reveals, in particular following the review referred to in paragraph 3 of this Article, that a third country, a territory or one or more specified sectors within a third country, or an international organisation no longer ensures an adequate level of protection within the meaning of paragraph 2 of this Article, to the extent necessary, repeal, amend or suspend the decision referred to in paragraph 3 of this Article by means of implementing acts without retro-active effect. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2).\nOn duly justified imperative grounds of urgency, the Commission shall adopt immediately applicable implementing acts in accordance with the procedure referred to in Article 93(3).\n6.The Commission shall enter into consultations with the third country or international organisation with a view to remedying the situation giving rise to the decision made pursuant to paragraph 5.\n7.A decision pursuant to paragraph 5 of this Article is without prejudice to transfers of personal data to the third country, a territory or one or more specified sectors within that third country, or the international organisation in question pursuant to Articles 46 to 49.\n8.The Commission shall publish in the Official Journal of the European Union and on its website a list of the third countries, territories and specified sectors within a third country and international organisations for which it has decided that an adequate level of protection is or is no longer ensured.\n9.Decisions adopted by the Commission on the basis of Article 25(6) of Directive 95/46/EC shall remain in force until amended, replaced or repealed by a Commission Decision adopted in accordance with paragraph 3 or 5 of this Article.\nArticle 46 Transfers subject to appropriate safeguards\n1.In the absence of a decision pursuant to Article 45(3), a controller or processor may transfer personal data to a third country or an international organisation only if the controller or processor has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available.\n2.The appropriate safeguards referred to in paragraph 1 may be provided for, without requiring any specific authorisation from a supervisory authority, by:\n(a)a legally binding and enforceable instrument between public authorities or bodies;\n(b)binding corporate rules in accordance with Article 47;\n(c)standard data protection clauses adopted by the Commission in accordance with the examination procedure referred to in Article 93(2);\n(d)standard data protection clauses adopted by a supervisory authority and approved by the Commission pursuant to the examination procedure referred to in Article 93(2);\n(e)an approved code of conduct pursuant to Article 40 together with binding and enforceable commitments of the controller or processor in the third country to apply the appropriate safeguards, including as regards data subjects\u0026rsquo; rights; or\n(f)an approved certification mechanism pursuant to Article 42 together with binding and enforceable commitments of the controller or processor in the third country to apply the appropriate safeguards, including as regards data subjects\u0026rsquo; rights.\n3.Subject to the authorisation from the competent supervisory authority, the appropriate safeguards referred to in paragraph 1 may also be provided for, in particular, by:\n(a)contractual clauses between the controller or processor and the controller, processor or the recipient of the personal data in the third country or international organisation; or\n(b)provisions to be inserted into administrative arrangements between public authorities or bodies which include enforceable and effective data subject rights.\n4.The supervisory authority shall apply the consistency mechanism referred to in Article 63 in the cases referred to in paragraph 3 of this Article.\n5.Authorisations by a Member State or supervisory authority on the basis of Article 26(2) of Directive 95/46/EC shall remain valid until amended, replaced or repealed, if necessary, by that supervisory authority. Decisions adopted by the Commission on the basis of Article 26(4) of Directive 95/46/EC shall remain in force until amended, replaced or repealed, if necessary, by a Commission Decision adopted in accordance with paragraph 2 of this Article.\nArticle 47 Binding corporate rules\n1.The competent supervisory authority shall approve binding corporate rules in accordance with the consistency mechanism set out in Article 63, provided that they:\n(a)are legally binding and apply to and are enforced by every member concerned of the group of undertakings, or group of enterprises engaged in a joint economic activity, including their employees;\n(b)expressly confer enforceable rights on data subjects with regard to the processing of their personal data; and\n(c)fulfil the requirements laid down in paragraph 2.\n2.The binding corporate rules referred to in paragraph 1 shall specify at least:\n(a)the structure and contact details of the group of undertakings, or group of enterprises engaged in a joint economic activity and of each of its members;\n(b)the data transfers or set of transfers, including the categories of personal data, the type of processing and its purposes, the type of data subjects affected and the identification of the third country or countries in question;\n(c)their legally binding nature, both internally and externally;\n(d)the application of the general data protection principles, in particular purpose limitation, data minimisation, limited storage periods, data quality, data protection by design and by default, legal basis for processing, processing of special categories of personal data, measures to ensure data security, and the requirements in respect of onward transfers to bodies not bound by the binding corporate rules;\n(e)the rights of data subjects in regard to processing and the means to exercise those rights, including the right not to be subject to decisions based solely on automated processing, including profiling in accordance with Article 22, the right to lodge a complaint with the competent supervisory authority and before the competent courts of the Member States in accordance with Article 79, and to obtain redress and, where appropriate, compensation for a breach of the binding corporate rules;\n(f)the acceptance by the controller or processor established on the territory of a Member State of liability for any breaches of the binding corporate rules by any member concerned not established in the Union; the controller or the processor shall be exempt from that liability, in whole or in part, only if it proves that that member is not responsible for the event giving rise to the damage;\n(g)how the information on the binding corporate rules, in particular on the provisions referred to in points (d), (e) and(f) of this paragraph is provided to the data subjects in addition to Articles 13 and 14;\n(h)the tasks of any data protection officer designated in accordance with Article 37 or any other person or entity in charge of the monitoring compliance with the binding corporate rules within the group of undertakings, or group of enterprises engaged in a joint economic activity, as well as monitoring training and complaint-handling;\n(i)the complaint procedures;\n(j)the mechanisms within the group of undertakings, or group of enterprises engaged in a joint economic activity for ensuring the verification of compliance with the binding corporate rules. Such mechanisms shall include data protection audits and methods for ensuring corrective actions to protect the rights of the data subject. Results of such verification should be communicated to the person or entity referred to in point(h) and to the board of the controlling undertaking of a group of undertakings, or of the group of enterprises engaged in a joint economic activity, and should be available upon request to the competent supervisory authority;\n(k)the mechanisms for reporting and recording changes to the rules and reporting those changes to the supervisory authority;\n(l)the cooperation mechanism with the supervisory authority to ensure compliance by any member of the group of undertakings, or group of enterprises engaged in a joint economic activity, in particular by making available to the supervisory authority the results of verifications of the measures referred to in point (j);\n(m)the mechanisms for reporting to the competent supervisory authority any legal requirements to which a member of the group of undertakings, or group of enterprises engaged in a joint economic activity is subject in a third country which are likely to have a substantial adverse effect on the guarantees provided by the binding corporate rules; and\n(n)the appropriate data protection training to personnel having permanent or regular access to personal data.\n3.The Commission may specify the format and procedures for the exchange of information between controllers, processors and supervisory authorities for binding corporate rules within the meaning of this Article. Those implementing acts shall be adopted in accordance with the examination procedure set out in Article 93(2).\nArticle 48 Transfers or disclosures not authorised by Union law\nAny judgment of a court or tribunal and any decision of an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data may only be recognised or enforceable in any manner if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State, without prejudice to other grounds for transfer pursuant to this Chapter.\nArticle 49 Derogations for specific situations\n1.In the absence of an adequacy decision pursuant to Article 45(3), or of appropriate safeguards pursuant to Article 46, including binding corporate rules, a transfer or a set of transfers of personal data to a third country or an international organisation shall take place only on one of the following conditions:\n(a)the data subject has explicitly consented to the proposed transfer, after having been informed of the possible risks of such transfers for the data subject due to the absence of an adequacy decision and appropriate safeguards;\n(b)the transfer is necessary for the performance of a contract between the data subject and the controller or the implementation of pre-contractual measures taken at the data subject\u0026rsquo;s request;\n(c)the transfer is necessary for the conclusion or performance of a contract concluded in the interest of the data subject between the controller and another natural or legal person;\n(d)the transfer is necessary for important reasons of public interest;\n(e)the transfer is necessary for the establishment, exercise or defence of legal claims;\n(f)the transfer is necessary in order to protect the vital interests of the data subject or of other persons, where the data subject is physically or legally incapable of giving consent;\n(g)the transfer is made from a register which according to Union or Member State law is intended to provide information to the public and which is open to consultation either by the public in general or by any person who can demonstrate a legitimate interest, but only to the extent that the conditions laid down by Union or Member State law for consultation are fulfilled in the particular case.\nWhere a transfer could not be based on a provision in Article 45 or 46, including the provisions on binding corporate rules, and none of the derogations for a specific situation referred to in the first subparagraph of this paragraph is applicable, a transfer to a third country or an international organisation may take place only if the transfer is not repetitive, concerns only a limited number of data subjects, is necessary for the purposes of compelling legitimate interests pursued by the controller which are not overridden by the interests or rights and freedoms of the data subject, and the controller has assessed all the circumstances surrounding the data transfer and has on the basis of that assessment provided suitable safeguards with regard to the protection of personal data. The controller shall inform the supervisory authority of the transfer. The controller shall, in addition to providing the information referred to in Articles 13 and 14, inform the data subject of the transfer and on the compelling legitimate interests pursued.\n2.A transfer pursuant to point (g) of the first subparagraph of paragraph 1 shall not involve the entirety of the personal data or entire categories of the personal data contained in the register. Where the register is intended for consultation by persons having a legitimate interest, the transfer shall be made only at the request of those persons or if they are to be the recipients.\n3.Points (a), (b) and (c) of the first subparagraph of paragraph 1 and the second subparagraph thereof shall not apply to activities carried out by public authorities in the exercise of their public powers.\n4.The public interest referred to in point (d) of the first subparagraph of paragraph 1 shall be recognised in Union law or in the law of the Member State to which the controller is subject.\n5.In the absence of an adequacy decision, Union or Member State law may, for important reasons of public interest, expressly set limits to the transfer of specific categories of personal data to a third country or an international organisation. Member States shall notify such provisions to the Commission.\n6.The controller or processor shall document the assessment as well as the suitable safeguards referred to in the second subparagraph of paragraph 1 of this Article in the records referred to in Article 30.\nArticle 50 International cooperation for the protection of personal data\nIn relation to third countries and international organisations, the Commission and supervisory authorities shall take appropriate steps to:\n(a)develop international cooperation mechanisms to facilitate the effective enforcement of legislation for the protection of personal data;\n(b)provide international mutual assistance in the enforcement of legislation for the protection of personal data, including through notification, complaint referral, investigative assistance and information exchange, subject to appropriate safeguards for the protection of personal data and other fundamental rights and freedoms;\n(c)engage relevant stakeholders in discussion and activities aimed at furthering international cooperation in the enforcement of legislation for the protection of personal data;\n(d)promote the exchange and documentation of personal data protection legislation and practice, including on jurisdictional conflicts with third countries.\nCHAPTER VI Independent supervisory authorities\nSection 1\nIndependent status\nArticle 51 Supervisory authority\n1.Each Member State shall provide for one or more independent public authorities to be responsible for monitoring the application of this Regulation, in order to protect the fundamental rights and freedoms of natural persons in relation to processing and to facilitate the free flow of personal data within the Union (‘supervisory authority’).\n2.Each supervisory authority shall contribute to the consistent application of this Regulation throughout the Union. For that purpose, the supervisory authorities shall cooperate with each other and the Commission in accordance with Chapter VII.\n3.Where more than one supervisory authority is established in a Member State, that Member State shall designate the supervisory authority which is to represent those authorities in the Board and shall set out the mechanism to ensure compliance by the other authorities with the rules relating to the consistency mechanism referred to in Article 63.\n4.Each Member State shall notify to the Commission the provisions of its law which it adopts pursuant to this Chapter, by 25 May 2018 and, without delay, any subsequent amendment affecting them.\nArticle 52 Independence\n1.Each supervisory authority shall act with complete independence in performing its tasks and exercising its powers in accordance with this Regulation.\n2.The member or members of each supervisory authority shall, in the performance of their tasks and exercise of their powers in accordance with this Regulation, remain free from external influence, whether direct or indirect, and shall neither seek nor take instructions from anybody.\n3.Member or members of each supervisory authority shall refrain from any action incompatible with their duties and shall not, during their term of office, engage in any incompatible occupation, whether gainful or not.\n4.Each Member State shall ensure that each supervisory authority is provided with the human, technical and financial resources, premises and infrastructure necessary for the effective performance of its tasks and exercise of its powers, including those to be carried out in the context of mutual assistance, cooperation and participation in the Board.\n5.Each Member State shall ensure that each supervisory authority chooses and has its own staff which shall be subject to the exclusive direction of the member or members of the supervisory authority concerned.\n6.Each Member State shall ensure that each supervisory authority is subject to financial control which does not affect its independence and that it has separate, public annual budgets, which may be part of the overall state or national budget.\nArticle 53 General conditions for the members of the supervisory authority\n1.Member States shall provide for each member of their supervisory authorities to be appointed by means of a transparent procedure by:\n—their parliament;\n—their government;\n—their head of State; or\n—an independent body entrusted with the appointment under Member State law.\n2.Each member shall have the qualifications, experience and skills, in particular in the area of the protection of personal data, required to perform its duties and exercise its powers.\n3.The duties of a member shall end in the event of the expiry of the term of office, resignation or compulsory retirement, in accordance with the law of the Member State concerned.\n4.A member shall be dismissed only in cases of serious misconduct or if the member no longer fulfils the conditions required for the performance of the duties.\nArticle 54 Rules on the establishment of the supervisory authority\n1.Each Member State shall provide by law for all of the following:\n(a)the establishment of each supervisory authority;\n(b)the qualifications and eligibility conditions required to be appointed as member of each supervisory authority;\n(c)the rules and procedures for the appointment of the member or members of each supervisory authority;\n(d)the duration of the term of the member or members of each supervisory authority of no less than four years, except for the first appointment after 24 May 2016, part of which may take place for a shorter period where that is necessary to protect the independence of the supervisory authority by means of a staggered appointment procedure;\n(e)whether and, if so, for how many terms the member or members of each supervisory authority is eligible for reappointment;\n(f)the conditions governing the obligations of the member or members and staff of each supervisory authority, prohibitions on actions, occupations and benefits incompatible therewith during and after the term of office and rules governing the cessation of employment.\n2.The member or members and the staff of each supervisory authority shall, in accordance with Union or Member State law, be subject to a duty of professional secrecy both during and after their term of office, with regard to any confidential information which has come to their knowledge in the course of the performance of their tasks or exercise of their powers. During their term of office, that duty of professional secrecy shall in particular apply to reporting by natural persons of infringements of this Regulation.\nSection 2\nCompetence, tasks and powers\nArticle 55 Competence\n1.Each supervisory authority shall be competent for the performance of the tasks assigned to and the exercise of the powers conferred on it in accordance with this Regulation on the territory of its own Member State.\n2.Where processing is carried out by public authorities or private bodies acting on the basis of point(c) or (e) of Article 6(1), the supervisory authority of the Member State concerned shall be competent. In such cases Article 56 does not apply.\n3.Supervisory authorities shall not be competent to supervise processing operations of courts acting in their judicial capacity.\nArticle 56 Competence of the lead supervisory authority\n1.Without prejudice to Article 55, the supervisory authority of the main establishment or of the single establishment of the controller or processor shall be competent to act as lead supervisory authority for the cross-border processing carried out by that controller or processor in accordance with the procedure provided in Article 60.\n2.By derogation from paragraph 1, each supervisory authority shall be competent to handle a complaint lodged with it or a possible infringement of this Regulation, if the subject matter relates only to an establishment in its Member State or substantially affects data subjects only in its Member State.\n3.In the cases referred to in paragraph 2 of this Article, the supervisory authority shall inform the lead supervisory authority without delay on that matter. Within a period of three weeks after being informed the lead supervisory authority shall decide whether or not it will handle the case in accordance with the procedure provided in Article 60, taking into account whether or not there is an establishment of the controller or processor in the Member State of which the supervisory authority informed it.\n4.Where the lead supervisory authority decides to handle the case, the procedure provided in Article 60 shall apply. The supervisory authority which informed the lead supervisory authority may submit to the lead supervisory authority a draft for a decision. The lead supervisory authority shall take utmost account of that draft when preparing the draft decision referred to in Article 60(3).\n5.Where the lead supervisory authority decides not to handle the case, the supervisory authority which informed the lead supervisory authority shall handle it according to Articles 61 and 62.\n6.The lead supervisory authority shall be the sole interlocutor of the controller or processor for the cross-border processing carried out by that controller or processor.\nArticle 57 Tasks\n1.Without prejudice to other tasks set out under this Regulation, each supervisory authority shall on its territory:\n(a)monitor and enforce the application of this Regulation;\n(b)promote public awareness and understanding of the risks, rules, safeguards and rights in relation to processing. Activities addressed specifically to children shall receive specific attention;\n(c)advise, in accordance with Member State law, the national parliament, the government, and other institutions and bodies on legislative and administrative measures relating to the protection of natural persons\u0026rsquo; rights and freedoms with regard to processing;\n(d)promote the awareness of controllers and processors of their obligations under this Regulation;\n(e)upon request, provide information to any data subject concerning the exercise of their rights under this Regulation and, if appropriate, cooperate with the supervisory authorities in other Member States to that end;\n(f)handle complaints lodged by a data subject, or by a body, organisation or association in accordance with Article 80, and investigate, to the extent appropriate, the subject matter of the complaint and inform the complainant of the progress and the outcome of the investigation within a reasonable period, in particular if further investigation or coordination with another supervisory authority is necessary;\n(g)cooperate with, including sharing information and provide mutual assistance to, other supervisory authorities with a view to ensuring the consistency of application and enforcement of this Regulation;\n(h)conduct investigations on the application of this Regulation, including on the basis of information received from another supervisory authority or other public authority;\n(i)monitor relevant developments, insofar as they have an impact on the protection of personal data, in particular the development of information and communication technologies and commercial practices;\n(j)adopt standard contractual clauses referred to in Article 28(8) and in point(d) of Article 46(2);\n(k)establish and maintain a list in relation to the requirement for data protection impact assessment pursuant to Article 35(4);\n(l)give advice on the processing operations referred to in Article 36(2);\n(m)encourage the drawing up of codes of conduct pursuant to Article 40(1) and provide an opinion and approve such codes of conduct which provide sufficient safeguards, pursuant to Article 40(5);\n(n)encourage the establishment of data protection certification mechanisms and of data protection seals and marks pursuant to Article 42(1), and approve the criteria of certification pursuant to Article 42(5);\n(o)where applicable, carry out a periodic review of certifications issued in accordance with Article 42(7);\n(p)draft and publish the criteria for accreditation of a body for monitoring codes of conduct pursuant to Article 41 and of a certification body pursuant to Article 43;\n(q)conduct the accreditation of a body for monitoring codes of conduct pursuant to Article 41 and of a certification body pursuant to Article 43;\n(r)authorise contractual clauses and provisions referred to in Article 46(3);\n(s)approve binding corporate rules pursuant to Article 47;\n(t)contribute to the activities of the Board;\n(u)keep internal records of infringements of this Regulation and of measures taken in accordance with Article 58(2); and\n(v)fulfil any other tasks related to the protection of personal data.\n2.Each supervisory authority shall facilitate the submission of complaints referred to in point(f) of paragraph 1 by measures such as a complaint submission form which can also be completed electronically, without excluding other means of communication.\n3.The performance of the tasks of each supervisory authority shall be free of charge for the data subject and, where applicable, for the data protection officer.\n4.Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, the supervisory authority may charge a reasonable fee based on administrative costs, or refuse to act on the request. The supervisory authority shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request.\nArticle 58 Powers\n1.Each supervisory authority shall have all of the following investigative powers:\n(a)to order the controller and the processor, and, where applicable, the controller\u0026rsquo;s or the processor\u0026rsquo;s representative to provide any information it requires for the performance of its tasks;\n(b)to carry out investigations in the form of data protection audits;\n(c)to carry out a review on certifications issued pursuant to Article 42(7);\n(d)to notify the controller or the processor of an alleged infringement of this Regulation;\n(e)to obtain, from the controller and the processor, access to all personal data and to all information necessary for the performance of its tasks;\n(f)to obtain access to any premises of the controller and the processor, including to any data processing equipment and means, in accordance with Union or Member State procedural law.\n2.Each supervisory authority shall have all of the following corrective powers:\n(a)to issue warnings to a controller or processor that intended processing operations are likely to infringe provisions of this Regulation;\n(b)to issue reprimands to a controller or a processor where processing operations have infringed provisions of this Regulation;\n(c)to order the controller or the processor to comply with the data subject\u0026rsquo;s requests to exercise his or her rights pursuant to this Regulation;\n(d)to order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period;\n(e)to order the controller to communicate a personal data breach to the data subject;\n(f)to impose a temporary or definitive limitation including a ban on processing;\n(g)to order the rectification or erasure of personal data or restriction of processing pursuant to Articles 16, 17 and 18 and the notification of such actions to recipients to whom the personal data have been disclosed pursuant to Article 17(2) and Article 19;\n(h)to withdraw a certification or to order the certification body to withdraw a certification issued pursuant to Articles 42 and 43, or to order the certification body not to issue certification if the requirements for the certification are not or are no longer met;\n(i)to impose an administrative fine pursuant to Article 83, in addition to, or instead of measures referred to in this paragraph, depending on the circumstances of each individual case;\n(j)to order the suspension of data flows to a recipient in a third country or to an international organisation.\n3.Each supervisory authority shall have all of the following authorisation and advisory powers:\n(a)to advise the controller in accordance with the prior consultation procedure referred to in Article 36;\n(b)to issue, on its own initiative or on request, opinions to the national parliament, the Member State government or, in accordance with Member State law, to other institutions and bodies as well as to the public on any issue related to the protection of personal data;\n(c)to authorise processing referred to in Article 36(5), if the law of the Member State requires such prior authorisation;\n(d)to issue an opinion and approve draft codes of conduct pursuant to Article 40(5);\n(e)to accredit certification bodies pursuant to Article 43;\n(f)to issue certifications and approve criteria of certification in accordance with Article 42(5);\n(g)to adopt standard data protection clauses referred to in Article 28(8) and in point(d) of Article 46(2);\n(h)to authorise contractual clauses referred to in point (a) of Article 46(3);\n(i)to authorise administrative arrangements referred to in point (b) of Article 46(3);\n(j)to approve binding corporate rules pursuant to Article 47.\n4.The exercise of the powers conferred on the supervisory authority pursuant to this Article shall be subject to appropriate safeguards, including effective judicial remedy and due process, set out in Union and Member State law in accordance with the Charter.\n5.Each Member State shall provide by law that its supervisory authority shall have the power to bring infringements of this Regulation to the attention of the judicial authorities and where appropriate, to commence or engage otherwise in legal proceedings, in order to enforce the provisions of this Regulation.\n6.Each Member State may provide by law that its supervisory authority shall have additional powers to those referred to in paragraphs 1, 2 and 3. The exercise of those powers shall not impair the effective operation of Chapter VII.\nArticle 59 Activity reports\nEach supervisory authority shall draw up an annual report on its activities, which may include a list of types of infringement notified and types of measures taken in accordance with Article 58(2). Those reports shall be transmitted to the national parliament, the government and other authorities as designated by Member State law. They shall be made available to the public, to the Commission and to the Board.\nCHAPTER VII Cooperation and consistency\nSection 1\nCooperation\nArticle 60 Cooperation between the lead supervisory authority and the other supervisory authorities concerned\n1.The lead supervisory authority shall cooperate with the other supervisory authorities concerned in accordance with this Article in an endeavour to reach consensus. The lead supervisory authority and the supervisory authorities concerned shall exchange all relevant information with each other.\n2.The lead supervisory authority may request at any time other supervisory authorities concerned to provide mutual assistance pursuant to Article 61 and may conduct joint operations pursuant to Article 62, in particular for carrying out investigations or for monitoring the implementation of a measure concerning a controller or processor established in another Member State.\n3.The lead supervisory authority shall, without delay, communicate the relevant information on the matter to the other supervisory authorities concerned. It shall without delay submit a draft decision to the other supervisory authorities concerned for their opinion and take due account of their views.\n4.Where any of the other supervisory authorities concerned within a period of four weeks after having been consulted in accordance with paragraph 3 of this Article, expresses a relevant and reasoned objection to the draft decision, the lead supervisory authority shall, if it does not follow the relevant and reasoned objection or is of the opinion that the objection is not relevant or reasoned, submit the matter to the consistency mechanism referred to in Article 63.\n5.Where the lead supervisory authority intends to follow the relevant and reasoned objection made, it shall submit to the other supervisory authorities concerned a revised draft decision for their opinion. That revised draft decision shall be subject to the procedure referred to in paragraph 4 within a period of two weeks.\n6.Where none of the other supervisory authorities concerned has objected to the draft decision submitted by the lead supervisory authority within the period referred to in paragraphs 4 and 5, the lead supervisory authority and the supervisory authorities concerned shall be deemed to be in agreement with that draft decision and shall be bound by it.\n7.The lead supervisory authority shall adopt and notify the decision to the main establishment or single establishment of the controller or processor, as the case may be and inform the other supervisory authorities concerned and the Board of the decision in question, including a summary of the relevant facts and grounds. The supervisory authority with which a complaint has been lodged shall inform the complainant on the decision.\n8.By derogation from paragraph 7, where a complaint is dismissed or rejected, the supervisory authority with which the complaint was lodged shall adopt the decision and notify it to the complainant and shall inform the controller thereof.\n9.Where the lead supervisory authority and the supervisory authorities concerned agree to dismiss or reject parts of a complaint and to act on other parts of that complaint, a separate decision shall be adopted for each of those parts of the matter. The lead supervisory authority shall adopt the decision for the part concerning actions in relation to the controller, shall notify it to the main establishment or single establishment of the controller or processor on the territory of its Member State and shall inform the complainant thereof, while the supervisory authority of the complainant shall adopt the decision for the part concerning dismissal or rejection of that complaint, and shall notify it to that complainant and shall inform the controller or processor thereof.\n10.After being notified of the decision of the lead supervisory authority pursuant to paragraphs 7 and 9, the controller or processor shall take the necessary measures to ensure compliance with the decision as regards processing activities in the context of all its establishments in the Union. The controller or processor shall notify the measures taken for complying with the decision to the lead supervisory authority, which shall inform the other supervisory authorities concerned.\n11.Where, in exceptional circumstances, a supervisory authority concerned has reasons to consider that there is an urgent need to act in order to protect the interests of data subjects, the urgency procedure referred to in Article 66 shall apply.\n12.The lead supervisory authority and the other supervisory authorities concerned shall supply the information required under this Article to each other by electronic means, using a standardised format.\nArticle 61 Mutual assistance\n1.Supervisory authorities shall provide each other with relevant information and mutual assistance in order to implement and apply this Regulation in a consistent manner, and shall put in place measures for effective cooperation with one another. Mutual assistance shall cover, in particular, information requests and supervisory measures, such as requests to carry out prior authorisations and consultations, inspections and investigations.\n2.Each supervisory authority shall take all appropriate measures required to reply to a request of another supervisory authority without undue delay and no later than one month after receiving the request. Such measures may include, in particular, the transmission of relevant information on the conduct of an investigation.\n3.Requests for assistance shall contain all the necessary information, including the purpose of and reasons for the request. Information exchanged shall be used only for the purpose for which it was requested.\n4.The requested supervisory authority shall not refuse to comply with the request unless:\n(a)it is not competent for the subject-matter of the request or for the measures it is requested to execute; or\n(b)compliance with the request would infringe this Regulation or Union or Member State law to which the supervisory authority receiving the request is subject.\n5.The requested supervisory authority shall inform the requesting supervisory authority of the results or, as the case may be, of the progress of the measures taken in order to respond to the request. The requested supervisory authority shall provide reasons for any refusal to comply with a request pursuant to paragraph 4.\n6.Requested supervisory authorities shall, as a rule, supply the information requested by other supervisory authorities by electronic means, using a standardised format.\n7.Requested supervisory authorities shall not charge a fee for any action taken by them pursuant to a request for mutual assistance. Supervisory authorities may agree on rules to indemnify each other for specific expenditure arising from the provision of mutual assistance in exceptional circumstances.\n8.Where a supervisory authority does not provide the information referred to in paragraph 5 of this Article within one month of receiving the request of another supervisory authority, the requesting supervisory authority may adopt a provisional measure on the territory of its Member State in accordance with Article 55(1). In that case, the urgent need to act under Article 66(1) shall be presumed to be met and require an urgent binding decision from the Board pursuant to Article 66(2).\n9.The Commission may, by means of implementing acts, specify the format and procedures for mutual assistance referred to in this Article and the arrangements for the exchange of information by electronic means between supervisory authorities, and between supervisory authorities and the Board, in particular the standardised format referred to in paragraph 6 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2).\nArticle 62 Joint operations of supervisory authorities\n1.The supervisory authorities shall, where appropriate, conduct joint operations including joint investigations and joint enforcement measures in which members or staff of the supervisory authorities of other Member States are involved.\n2.Where the controller or processor has establishments in several Member States or where a significant number of data subjects in more than one Member State are likely to be substantially affected by processing operations, a supervisory authority of each of those Member States shall have the right to participate in joint operations. The supervisory authority which is competent pursuant to Article 56(1) or (4) shall invite the supervisory authority of each of those Member States to take part in the joint operations and shall respond without delay to the request of a supervisory authority to participate.\n3.A supervisory authority may, in accordance with Member State law, and with the seconding supervisory authority\u0026rsquo;s authorisation, confer powers, including investigative powers on the seconding supervisory authority\u0026rsquo;s members or staff involved in joint operations or, in so far as the law of the Member State of the host supervisory authority permits, allow the seconding supervisory authority\u0026rsquo;s members or staff to exercise their investigative powers in accordance with the law of the Member State of the seconding supervisory authority. Such investigative powers may be exercised only under the guidance and in the presence of members or staff of the host supervisory authority. The seconding supervisory authority\u0026rsquo;s members or staff shall be subject to the Member State law of the host supervisory authority.\n4.Where, in accordance with paragraph 1, staff of a seconding supervisory authority operate in another Member State, the Member State of the host supervisory authority shall assume responsibility for their actions, including liability, for any damage caused by them during their operations, in accordance with the law of the Member State in whose territory they are operating.\n5.The Member State in whose territory the damage was caused shall make good such damage under the conditions applicable to damage caused by its own staff. The Member State of the seconding supervisory authority whose staff has caused damage to any person in the territory of another Member State shall reimburse that other Member State in full any sums it has paid to the persons entitled on their behalf.\n6.Without prejudice to the exercise of its rights vis-à-vis third parties and with the exception of paragraph 5, each Member State shall refrain, in the case provided for in paragraph 1, from requesting reimbursement from another Member State in relation to damage referred to in paragraph 4.\n7.Where a joint operation is intended and a supervisory authority does not, within one month, comply with the obligation laid down in the second sentence of paragraph 2 of this Article, the other supervisory authorities may adopt a provisional measure on the territory of its Member State in accordance with Article 55. In that case, the urgent need to act under Article 66(1) shall be presumed to be met and require an opinion or an urgent binding decision from the Board pursuant to Article 66(2).\nSection 2\nConsistency\nArticle 63 Consistency mechanism\nIn order to contribute to the consistent application of this Regulation throughout the Union, the supervisory authorities shall cooperate with each other and, where relevant, with the Commission, through the consistency mechanism as set out in this Section.\nArticle 64 Opinion of the Board\n1.The Board shall issue an opinion where a competent supervisory authority intends to adopt any of the measures below. To that end, the competent supervisory authority shall communicate the draft decision to the Board, when it:\n(a)aims to adopt a list of the processing operations subject to the requirement for a data protection impact assessment pursuant to Article 35(4);\n(b)concerns a matter pursuant to Article 40(7) whether a draft code of conduct or an amendment or extension to a code of conduct complies with this Regulation;\n(c)aims to approve the criteria for accreditation of a body pursuant to Article 41(3) or a certification body pursuant to Article 43(3);\n(d)aims to determine standard data protection clauses referred to in point(d) of Article 46(2) and in Article 28(8);\n(e)aims to authorise contractual clauses referred to in point (a) of Article 46(3); or\n(f)aims to approve binding corporate rules within the meaning of Article 47.\n2.Any supervisory authority, the Chair of the Board or the Commission may request that any matter of general application or producing effects in more than one Member State be examined by the Board with a view to obtaining an opinion, in particular where a competent supervisory authority does not comply with the obligations for mutual assistance in accordance with Article 61 or for joint operations in accordance with Article 62.\n3.In the cases referred to in paragraphs 1 and 2, the Board shall issue an opinion on the matter submitted to it provided that it has not already issued an opinion on the same matter. That opinion shall be adopted within eight weeks by simple majority of the members of the Board. That period may be extended by a further six weeks, taking into account the complexity of the subject matter. Regarding the draft decision referred to in paragraph 1 circulated to the members of the Board in accordance with paragraph 5, a member which has not objected within a reasonable period indicated by the Chair, shall be deemed to be in agreement with the draft decision.\n4.Supervisory authorities and the Commission shall, without undue delay, communicate by electronic means to the Board, using a standardised format any relevant information, including as the case may be a summary of the facts, the draft decision, the grounds which make the enactment of such measure necessary, and the views of other supervisory authorities concerned.\n5.The Chair of the Board shall, without undue, delay inform by electronic means:\n(a)the members of the Board and the Commission of any relevant information which has been communicated to it using a standardised format. The secretariat of the Board shall, where necessary, provide translations of relevant information; and\n(b)the supervisory authority referred to, as the case may be, in paragraphs 1 and 2, and the Commission of the opinion and make it public.\n6.The competent supervisory authority shall not adopt its draft decision referred to in paragraph 1 within the period referred to in paragraph 3.\n7.The supervisory authority referred to in paragraph 1 shall take utmost account of the opinion of the Board and shall, within two weeks after receiving the opinion, communicate to the Chair of the Board by electronic means whether it will maintain or amend its draft decision and, if any, the amended draft decision, using a standardised format.\n8.Where the supervisory authority concerned informs the Chair of the Board within the period referred to in paragraph 7 of this Article that it does not intend to follow the opinion of the Board, in whole or in part, providing the relevant grounds, Article 65(1) shall apply.\nArticle 65 Dispute resolution by the Board\n1.In order to ensure the correct and consistent application of this Regulation in individual cases, the Board shall adopt a binding decision in the following cases:\n(a)where, in a case referred to in Article 60(4), a supervisory authority concerned has raised a relevant and reasoned objection to a draft decision of the lead authority or the lead authority has rejected such an objection as being not relevant or reasoned. The binding decision shall concern all the matters which are the subject of the relevant and reasoned objection, in particular whether there is an infringement of this Regulation;\n(b)where there are conflicting views on which of the supervisory authorities concerned is competent for the main establishment;\n(c)where a competent supervisory authority does not request the opinion of the Board in the cases referred to in Article 64(1), or does not follow the opinion of the Board issued under Article 64. In that case, any supervisory authority concerned or the Commission may communicate the matter to the Board.\n2.The decision referred to in paragraph 1 shall be adopted within one month from the referral of the subject-matter by a two-thirds majority of the members of the Board. That period may be extended by a further month on account of the complexity of the subject-matter. The decision referred to in paragraph 1 shall be reasoned and addressed to the lead supervisory authority and all the supervisory authorities concerned and binding on them.\n3.Where the Board has been unable to adopt a decision within the periods referred to in paragraph 2, it shall adopt its decision within two weeks following the expiration of the second month referred to in paragraph 2 by a simple majority of the members of the Board. Where the members of the Board are split, the decision shall by adopted by the vote of its Chair.\n4.The supervisory authorities concerned shall not adopt a decision on the subject matter submitted to the Board under paragraph 1 during the periods referred to in paragraphs 2 and 3.\n5.The Chair of the Board shall notify, without undue delay, the decision referred to in paragraph 1 to the supervisory authorities concerned. It shall inform the Commission thereof. The decision shall be published on the website of the Board without delay after the supervisory authority has notified the final decision referred to in paragraph 6.\n6.The lead supervisory authority or, as the case may be, the supervisory authority with which the complaint has been lodged shall adopt its final decision on the basis of the decision referred to in paragraph 1 of this Article, without undue delay and at the latest by one month after the Board has notified its decision. The lead supervisory authority or, as the case may be, the supervisory authority with which the complaint has been lodged, shall inform the Board of the date when its final decision is notified respectively to the controller or the processor and to the data subject. The final decision of the supervisory authorities concerned shall be adopted under the terms of Article 60(7), (8) and(9). The final decision shall refer to the decision referred to in paragraph 1 of this Article and shall specify that the decision referred to in that paragraph will be published on the website of the Board in accordance with paragraph 5 of this Article. The final decision shall attach the decision referred to in paragraph 1 of this Article.\nArticle 66 Urgency procedure\n1.In exceptional circumstances, where a supervisory authority concerned considers that there is an urgent need to act in order to protect the rights and freedoms of data subjects, it may, by way of derogation from the consistency mechanism referred to in Articles 63, 64 and 65 or the procedure referred to in Article 60, immediately adopt provisional measures intended to produce legal effects on its own territory with a specified period of validity which shall not exceed three months. The supervisory authority shall, without delay, communicate those measures and the reasons for adopting them to the other supervisory authorities concerned, to the Board and to the Commission.\n2.Where a supervisory authority has taken a measure pursuant to paragraph 1 and considers that final measures need urgently be adopted, it may request an urgent opinion or an urgent binding decision from the Board, giving reasons for requesting such opinion or decision.\n3.Any supervisory authority may request an urgent opinion or an urgent binding decision, as the case may be, from the Board where a competent supervisory authority has not taken an appropriate measure in a situation where there is an urgent need to act, in order to protect the rights and freedoms of data subjects, giving reasons for requesting such opinion or decision, including for the urgent need to act.\n4.By derogation from Article 64(3) and Article 65(2), an urgent opinion or an urgent binding decision referred to in paragraphs 2 and 3 of this Article shall be adopted within two weeks by simple majority of the members of the Board.\nArticle 67 Exchange of information\nThe Commission may adopt implementing acts of general scope in order to specify the arrangements for the exchange of information by electronic means between supervisory authorities, and between supervisory authorities and the Board, in particular the standardised format referred to in Article 64.\nThose implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2).\nSection 3\nEuropean data protection board\nArticle 68 European Data Protection Board\n1.The European Data Protection Board (the ‘Board’) is hereby established as a body of the Union and shall have legal personality.\n2.The Board shall be represented by its Chair.\n3.The Board shall be composed of the head of one supervisory authority of each Member State and of the European Data Protection Supervisor, or their respective representatives.\n4.Where in a Member State more than one supervisory authority is responsible for monitoring the application of the provisions pursuant to this Regulation, a joint representative shall be appointed in accordance with that Member State\u0026rsquo;s law.\n5.The Commission shall have the right to participate in the activities and meetings of the Board without voting right. The Commission shall designate a representative. The Chair of the Board shall communicate to the Commission the activities of the Board.\n6.In the cases referred to in Article 65, the European Data Protection Supervisor shall have voting rights only on decisions which concern principles and rules applicable to the Union institutions, bodies, offices and agencies which correspond in substance to those of this Regulation.\nArticle 69 Independence\n1.The Board shall act independently when performing its tasks or exercising its powers pursuant to Articles 70 and 71.\n2.Without prejudice to requests by the Commission referred to in point (b) of Article 70(1) and in Article 70(2), the Board shall, in the performance of its tasks or the exercise of its powers, neither seek nor take instructions from anybody.\nArticle 70 Tasks of the Board\n1.The Board shall ensure the consistent application of this Regulation. To that end, the Board shall, on its own initiative or, where relevant, at the request of the Commission, in particular:\n(a)monitor and ensure the correct application of this Regulation in the cases provided for in Articles 64 and 65 without prejudice to the tasks of national supervisory authorities;\n(b)advise the Commission on any issue related to the protection of personal data in the Union, including on any proposed amendment of this Regulation;\n(c)advise the Commission on the format and procedures for the exchange of information between controllers, processors and supervisory authorities for binding corporate rules;\n(d)issue guidelines, recommendations, and best practices on procedures for erasing links, copies or replications of personal data from publicly available communication services as referred to in Article 17(2);\n(e)examine, on its own initiative, on request of one of its members or on request of the Commission, any question covering the application of this Regulation and issue guidelines, recommendations and best practices in order to encourage consistent application of this Regulation;\n(f)issue guidelines, recommendations and best practices in accordance with point(e) of this paragraph for further specifying the criteria and conditions for decisions based on profiling pursuant to Article 22(2);\n(g)issue guidelines, recommendations and best practices in accordance with point(e) of this paragraph for establishing the personal data breaches and determining the undue delay referred to in Article 33(1) and (2) and for the particular circumstances in which a controller or a processor is required to notify the personal data breach;\n(h)issue guidelines, recommendations and best practices in accordance with point(e) of this paragraph as to the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of the natural persons referred to in Article 34(1).\n(i)issue guidelines, recommendations and best practices in accordance with point(e) of this paragraph for the purpose of further specifying the criteria and requirements for personal data transfers based on binding corporate rules adhered to by controllers and binding corporate rules adhered to by processors and on further necessary requirements to ensure the protection of personal data of the data subjects concerned referred to in Article 47;\n(j)issue guidelines, recommendations and best practices in accordance with point(e) of this paragraph for the purpose of further specifying the criteria and requirements for the personal data transfers on the basis of Article 49(1);\n(k)draw up guidelines for supervisory authorities concerning the application of measures referred to in Article 58(1), (2) and (3) and the setting of administrative fines pursuant to Article 83;\n(l)review the practical application of the guidelines, recommendations and best practices referred to in points (e) and(f);\n(m)issue guidelines, recommendations and best practices in accordance with point(e) of this paragraph for establishing common procedures for reporting by natural persons of infringements of this Regulation pursuant to Article 54(2);\n(n)encourage the drawing-up of codes of conduct and the establishment of data protection certification mechanisms and data protection seals and marks pursuant to Articles 40 and 42;\n(o)carry out the accreditation of certification bodies and its periodic review pursuant to Article 43 and maintain a public register of accredited bodies pursuant to Article 43(6) and of the accredited controllers or processors established in third countries pursuant to Article 42(7);\n(p)specify the requirements referred to in Article 43(3) with a view to the accreditation of certification bodies under Article 42;\n(q)provide the Commission with an opinion on the certification requirements referred to in Article 43(8);\n(r)provide the Commission with an opinion on the icons referred to in Article 12(7);\n(s)provide the Commission with an opinion for the assessment of the adequacy of the level of protection in a third country or international organisation, including for the assessment whether a third country, a territory or one or more specified sectors within that third country, or an international organisation no longer ensures an adequate level of protection. To that end, the Commission shall provide the Board with all necessary documentation, including correspondence with the government of the third country, with regard to that third country, territory or specified sector, or with the international organisation.\n(t)issue opinions on draft decisions of supervisory authorities pursuant to the consistency mechanism referred to in Article 64(1), on matters submitted pursuant to Article 64(2) and to issue binding decisions pursuant to Article 65, including in cases referred to in Article 66;\n(u)promote the cooperation and the effective bilateral and multilateral exchange of information and best practices between the supervisory authorities;\n(v)promote common training programmes and facilitate personnel exchanges between the supervisory authorities and, where appropriate, with the supervisory authorities of third countries or with international organisations;\n(w)promote the exchange of knowledge and documentation on data protection legislation and practice with data protection supervisory authorities worldwide.\n(x)issue opinions on codes of conduct drawn up at Union level pursuant to Article 40(9); and\n(y)maintain a publicly accessible electronic register of decisions taken by supervisory authorities and courts on issues handled in the consistency mechanism.\n2.Where the Commission requests advice from the Board, it may indicate a time limit, taking into account the urgency of the matter.\n3.The Board shall forward its opinions, guidelines, recommendations, and best practices to the Commission and to the committee referred to in Article 93 and make them public.\n4.The Board shall, where appropriate, consult interested parties and give them the opportunity to comment within a reasonable period. The Board shall, without prejudice to Article 76, make the results of the consultation procedure publicly available.\nArticle 71 Reports\n1.The Board shall draw up an annual report regarding the protection of natural persons with regard to processing in the Union and, where relevant, in third countries and international organisations. The report shall be made public and be transmitted to the European Parliament, to the Council and to the Commission.\n2.The annual report shall include a review of the practical application of the guidelines, recommendations and best practices referred to in point (l) of Article 70(1) as well as of the binding decisions referred to in Article 65.\nArticle 72 Procedure\n1.The Board shall take decisions by a simple majority of its members, unless otherwise provided for in this Regulation.\n2.The Board shall adopt its own rules of procedure by a two-thirds majority of its members and organise its own operational arrangements.\nArticle 73 Chair\n1.The Board shall elect a chair and two deputy chairs from amongst its members by simple majority.\n2.The term of office of the Chair and of the deputy chairs shall be five years and be renewable once.\nArticle 74 Tasks of the Chair\n1.The Chair shall have the following tasks:\n(a)to convene the meetings of the Board and prepare its agenda;\n(b)to notify decisions adopted by the Board pursuant to Article 65 to the lead supervisory authority and the supervisory authorities concerned;\n(c)to ensure the timely performance of the tasks of the Board, in particular in relation to the consistency mechanism referred to in Article 63.\n2.The Board shall lay down the allocation of tasks between the Chair and the deputy chairs in its rules of procedure.\nArticle 75 Secretariat\n1.The Board shall have a secretariat, which shall be provided by the European Data Protection Supervisor.\n2.The secretariat shall perform its tasks exclusively under the instructions of the Chair of the Board.\n3.The staff of the European Data Protection Supervisor involved in carrying out the tasks conferred on the Board by this Regulation shall be subject to separate reporting lines from the staff involved in carrying out tasks conferred on the European Data Protection Supervisor.\n4.Where appropriate, the Board and the European Data Protection Supervisor shall establish and publish a Memorandum of Understanding implementing this Article, determining the terms of their cooperation, and applicable to the staff of the European Data Protection Supervisor involved in carrying out the tasks conferred on the Board by this Regulation.\n5.The secretariat shall provide analytical, administrative and logistical support to the Board.\n6.The secretariat shall be responsible in particular for:\n(a)the day-to-day business of the Board;\n(b)communication between the members of the Board, its Chair and the Commission;\n(c)communication with other institutions and the public;\n(d)the use of electronic means for the internal and external communication;\n(e)the translation of relevant information;\n(f)the preparation and follow-up of the meetings of the Board;\n(g)the preparation, drafting and publication of opinions, decisions on the settlement of disputes between supervisory authorities and other texts adopted by the Board.\nArticle 76 Confidentiality\n1.The discussions of the Board shall be confidential where the Board deems it necessary, as provided for in its rules of procedure.\n2.Access to documents submitted to members of the Board, experts and representatives of third parties shall be governed by Regulation (EC) No 1049/2001 of the European Parliament and of the Council(21).\nCHAPTER VIII Remedies, liability and penalties\nArticle 77 Right to lodge a complaint with a supervisory authority\n1.Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation.\n2.The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Article 78.\nArticle 78 Right to an effective judicial remedy against a supervisory authority\n1.Without prejudice to any other administrative or non-judicial remedy, each natural or legal person shall have the right to an effective judicial remedy against a legally binding decision of a supervisory authority concerning them.\n2.Without prejudice to any other administrative or non-judicial remedy, each data subject shall have the right to a an effective judicial remedy where the supervisory authority which is competent pursuant to Articles 55 and 56 does not handle a complaint or does not inform the data subject within three months on the progress or outcome of the complaint lodged pursuant to Article 77.\n3.Proceedings against a supervisory authority shall be brought before the courts of the Member State where the supervisory authority is established.\n4.Where proceedings are brought against a decision of a supervisory authority which was preceded by an opinion or a decision of the Board in the consistency mechanism, the supervisory authority shall forward that opinion or decision to the court.\nArticle 79 Right to an effective judicial remedy against a controller or processor\n1.Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation.\n2.Proceedings against a controller or a processor shall be brought before the courts of the Member State where the controller or processor has an establishment. Alternatively, such proceedings may be brought before the courts of the Member State where the data subject has his or her habitual residence, unless the controller or processor is a public authority of a Member State acting in the exercise of its public powers.\nArticle 80 Representation of data subjects\n1.The data subject shall have the right to mandate a not-for-profit body, organisation or association which has been properly constituted in accordance with the law of a Member State, has statutory objectives which are in the public interest, and is active in the field of the protection of data subjects\u0026rsquo; rights and freedoms with regard to the protection of their personal data to lodge the complaint on his or her behalf, to exercise the rights referred to in Articles 77, 78 and 79 on his or her behalf, and to exercise the right to receive compensation referred to in Article 82 on his or her behalf where provided for by Member State law.\n2.Member States may provide that any body, organisation or association referred to in paragraph 1 of this Article, independently of a data subject\u0026rsquo;s mandate, has the right to lodge, in that Member State, a complaint with the supervisory authority which is competent pursuant to Article 77 and to exercise the rights referred to in Articles 78 and 79 if it considers that the rights of a data subject under this Regulation have been infringed as a result of the processing.\nArticle 81 Suspension of proceedings\n1.Where a competent court of a Member State has information on proceedings, concerning the same subject matter as regards processing by the same controller or processor, that are pending in a court in another Member State, it shall contact that court in the other Member State to confirm the existence of such proceedings.\n2.Where proceedings concerning the same subject matter as regards processing of the same controller or processor are pending in a court in another Member State, any competent court other than the court first seized may suspend its proceedings.\n3.Where those proceedings are pending at first instance, any court other than the court first seized may also, on the application of one of the parties, decline jurisdiction if the court first seized has jurisdiction over the actions in question and its law permits the consolidation thereof.\nArticle 82 Right to compensation and liability\n1.Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered.\n2.Any controller involved in processing shall be liable for the damage caused by processing which infringes this Regulation. A processor shall be liable for the damage caused by processing only where it has not complied with obligations of this Regulation specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller.\n3.A controller or processor shall be exempt from liability under paragraph 2 if it proves that it is not in any way responsible for the event giving rise to the damage.\n4.Where more than one controller or processor, or both a controller and a processor, are involved in the same processing and where they are, under paragraphs 2 and 3, responsible for any damage caused by processing, each controller or processor shall be held liable for the entire damage in order to ensure effective compensation of the data subject.\n5.Where a controller or processor has, in accordance with paragraph 4, paid full compensation for the damage suffered, that controller or processor shall be entitled to claim back from the other controllers or processors involved in the same processing that part of the compensation corresponding to their part of responsibility for the damage, in accordance with the conditions set out in paragraph 2.\n6.Court proceedings for exercising the right to receive compensation shall be brought before the courts competent under the law of the Member State referred to in Article 79(2).\nArticle 83 General conditions for imposing administrative fines\n1.Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.\n2.Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j) of Article 58(2). When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:\n(a)the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them;\n(b)the intentional or negligent character of the infringement;\n(c)any action taken by the controller or processor to mitigate the damage suffered by data subjects;\n(d)the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32;\n(e)any relevant previous infringements by the controller or processor;\n(f)the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;\n(g)the categories of personal data affected by the infringement;\n(h)the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement;\n(i)where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures;\n(j)adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and\n(k)any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement.\n3.If a controller or processor intentionally or negligently, for the same or linked processing operations, infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the gravest infringement.\n4.Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:\n(a)the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43;\n(b)the obligations of the certification body pursuant to Articles 42 and 43;\n(c)the obligations of the monitoring body pursuant to Article 41(4).\n5.Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:\n(a)the basic principles for processing, including conditions for consent, pursuant to Articles 5, 6, 7 and 9;\n(b)the data subjects\u0026rsquo; rights pursuant to Articles 12 to 22;\n(c)the transfers of personal data to a recipient in a third country or an international organisation pursuant to Articles 44 to 49;\n(d)any obligations pursuant to Member State law adopted under Chapter IX;\n(e)non-compliance with an order or a temporary or definitive limitation on processing or the suspension of data flows by the supervisory authority pursuant to Article 58(2) or failure to provide access in violation of Article 58(1).\n6.Non-compliance with an order by the supervisory authority as referred to in Article 58(2) shall, in accordance with paragraph 2 of this Article, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher.\n7.Without prejudice to the corrective powers of supervisory authorities pursuant to Article 58(2), each Member State may lay down the rules on whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State.\n8.The exercise by the supervisory authority of its powers under this Article shall be subject to appropriate procedural safeguards in accordance with Union and Member State law, including effective judicial remedy and due process.\n9.Where the legal system of the Member State does not provide for administrative fines, this Article may be applied in such a manner that the fine is initiated by the competent supervisory authority and imposed by competent national courts, while ensuring that those legal remedies are effective and have an equivalent effect to the administrative fines imposed by supervisory authorities. In any event, the fines imposed shall be effective, proportionate and dissuasive. Those Member States shall notify to the Commission the provisions of their laws which they adopt pursuant to this paragraph by 25 May 2018 and, without delay, any subsequent amendment law or amendment affecting them.\nArticle 84 Penalties\n1.Member States shall lay down the rules on other penalties applicable to infringements of this Regulation in particular for infringements which are not subject to administrative fines pursuant to Article 83, and shall take all measures necessary to ensure that they are implemented. Such penalties shall be effective, proportionate and dissuasive.\n2.Each Member State shall notify to the Commission the provisions of its law which it adopts pursuant to paragraph 1, by 25 May 2018 and, without delay, any subsequent amendment affecting them.\nCHAPTER IX Provisions relating to specific processing situations\nArticle 85 Processing and freedom of expression and information\n1.Member States shall by law reconcile the right to the protection of personal data pursuant to this Regulation with the right to freedom of expression and information, including processing for journalistic purposes and the purposes of academic, artistic or literary expression.\n2.For processing carried out for journalistic purposes or the purpose of academic artistic or literary expression, Member States shall provide for exemptions or derogations from Chapter II (principles), Chapter III (rights of the data subject), Chapter IV (controller and processor), Chapter V (transfer of personal data to third countries or international organisations), Chapter VI (independent supervisory authorities), Chapter VII (cooperation and consistency) and Chapter IX (specific data processing situations) if they are necessary to reconcile the right to the protection of personal data with the freedom of expression and information.\n3.Each Member State shall notify to the Commission the provisions of its law which it has adopted pursuant to paragraph 2 and, without delay, any subsequent amendment law or amendment affecting them.\nArticle 86 Processing and public access to official documents\nPersonal data in official documents held by a public authority or a public body or a private body for the performance of a task carried out in the public interest may be disclosed by the authority or body in accordance with Union or Member State law to which the public authority or body is subject in order to reconcile public access to official documents with the right to the protection of personal data pursuant to this Regulation.\nArticle 87 Processing of the national identification number\nMember States may further determine the specific conditions for the processing of a national identification number or any other identifier of general application. In that case the national identification number or any other identifier of general application shall be used only under appropriate safeguards for the rights and freedoms of the data subject pursuant to this Regulation.\nArticle 88 Processing in the context of employment\n1.Member States may, by law or by collective agreements, provide for more specific rules to ensure the protection of the rights and freedoms in respect of the processing of employees\u0026rsquo; personal data in the employment context, in particular for the purposes of the recruitment, the performance of the contract of employment, including discharge of obligations laid down by law or by collective agreements, management, planning and organisation of work, equality and diversity in the workplace, health and safety at work, protection of employer\u0026rsquo;s or customer\u0026rsquo;s property and for the purposes of the exercise and enjoyment, on an individual or collective basis, of rights and benefits related to employment, and for the purpose of the termination of the employment relationship.\n2.Those rules shall include suitable and specific measures to safeguard the data subject\u0026rsquo;s human dignity, legitimate interests and fundamental rights, with particular regard to the transparency of processing, the transfer of personal data within a group of undertakings, or a group of enterprises engaged in a joint economic activity and monitoring systems at the work place.\n3.Each Member State shall notify to the Commission those provisions of its law which it adopts pursuant to paragraph 1, by 25 May 2018 and, without delay, any subsequent amendment affecting them.\nArticle 89 Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes\n1.Processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, shall be subject to appropriate safeguards, in accordance with this Regulation, for the rights and freedoms of the data subject. Those safeguards shall ensure that technical and organisational measures are in place in particular in order to ensure respect for the principle of data minimisation. Those measures may include pseudonymisation provided that those purposes can be fulfilled in that manner. Where those purposes can be fulfilled by further processing which does not permit or no longer permits the identification of data subjects, those purposes shall be fulfilled in that manner.\n2.Where personal data are processed for scientific or historical research purposes or statistical purposes, Union or Member State law may provide for derogations from the rights referred to in Articles 15, 16, 18 and 21 subject to the conditions and safeguards referred to in paragraph 1 of this Article in so far as such rights are likely to render impossible or seriously impair the achievement of the specific purposes, and such derogations are necessary for the fulfilment of those purposes.\n3.Where personal data are processed for archiving purposes in the public interest, Union or Member State law may provide for derogations from the rights referred to in Articles 15, 16, 18, 19, 20 and 21 subject to the conditions and safeguards referred to in paragraph 1 of this Article in so far as such rights are likely to render impossible or seriously impair the achievement of the specific purposes, and such derogations are necessary for the fulfilment of those purposes.\n4.Where processing referred to in paragraphs 2 and 3 serves at the same time another purpose, the derogations shall apply only to processing for the purposes referred to in those paragraphs.\nArticle 90 Obligations of secrecy\n1.Member States may adopt specific rules to set out the powers of the supervisory authorities laid down in points (e) and (f) of Article 58(1) in relation to controllers or processors that are subject, under Union or Member State law or rules established by national competent bodies, to an obligation of professional secrecy or other equivalent obligations of secrecy where this is necessary and proportionate to reconcile the right of the protection of personal data with the obligation of secrecy. Those rules shall apply only with regard to personal data which the controller or processor has received as a result of or has obtained in an activity covered by that obligation of secrecy.\n2.Each Member State shall notify to the Commission the rules adopted pursuant to paragraph 1, by 25 May 2018 and, without delay, any subsequent amendment affecting them.\nArticle 91 Existing data protection rules of churches and religious associations\n1.Where in a Member State, churches and religious associations or communities apply, at the time of entry into force of this Regulation, comprehensive rules relating to the protection of natural persons with regard to processing, such rules may continue to apply, provided that they are brought into line with this Regulation.\n2.Churches and religious associations which apply comprehensive rules in accordance with paragraph 1 of this Article shall be subject to the supervision of an independent supervisory authority, which may be specific, provided that it fulfils the conditions laid down in Chapter VI of this Regulation.\nCHAPTER X Delegated acts and implementing acts\nArticle 92 Exercise of the delegation\n1.The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.\n2.The delegation of power referred to in Article 12(8) and Article 43(8) shall be conferred on the Commission for an indeterminate period of time from 24 May 2016.\n3.The delegation of power referred to in Article 12(8) and Article 43(8) may be revoked at any time by the European Parliament or by the Council. A decision of revocation shall put an end to the delegation of power specified in that decision. It shall take effect the day following that of its publication in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.\n4.As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council.\n5.A delegated act adopted pursuant to Article 12(8) and Article 43(8) shall enter into force only if no objection has been expressed by either the European Parliament or the Council within a period of three months of notification of that act to the European Parliament and the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by three months at the initiative of the European Parliament or of the Council.\nArticle 93 Committee procedure\n1.The Commission shall be assisted by a committee. That committee shall be a committee within the meaning of Regulation (EU) No 182/2011.\n2.Where reference is made to this paragraph, Article 5 of Regulation (EU) No 182/2011 shall apply.\n3.Where reference is made to this paragraph, Article 8 of Regulation (EU) No 182/2011, in conjunction with Article 5 thereof, shall apply.\nCHAPTER XI Final provisions\nArticle 94 Repeal of Directive 95/46/EC\n1.Directive 95/46/EC is repealed with effect from 25 May 2018.\n2.References to the repealed Directive shall be construed as references to this Regulation. References to the Working Party on the Protection of Individuals with regard to the Processing of Personal Data established by Article 29 of Directive 95/46/EC shall be construed as references to the European Data Protection Board established by this Regulation.\nArticle 95 Relationship with Directive 2002/58/EC\nThis Regulation shall not impose additional obligations on natural or legal persons in relation to processing in connection with the provision of publicly available electronic communications services in public communication networks in the Union in relation to matters for which they are subject to specific obligations with the same objective set out in Directive 2002/58/EC.\nArticle 96 Relationship with previously concluded Agreements\nInternational agreements involving the transfer of personal data to third countries or international organisations which were concluded by Member States prior to 24 May 2016, and which comply with Union law as applicable prior to that date, shall remain in force until amended, replaced or revoked.\nArticle 97 Commission reports\n1.By 25 May 2020 and every four years thereafter, the Commission shall submit a report on the evaluation and review of this Regulation to the European Parliament and to the Council. The reports shall be made public.\n2.In the context of the evaluations and reviews referred to in paragraph 1, the Commission shall examine, in particular, the application and functioning of:\n(a)Chapter V on the transfer of personal data to third countries or international organisations with particular regard to decisions adopted pursuant to Article 45(3) of this Regulation and decisions adopted on the basis of Article 25(6) of Directive 95/46/EC;\n(b)Chapter VII on cooperation and consistency.\n3.For the purpose of paragraph 1, the Commission may request information from Member States and supervisory authorities.\n4.In carrying out the evaluations and reviews referred to in paragraphs 1 and 2, the Commission shall take into account the positions and findings of the European Parliament, of the Council, and of other relevant bodies or sources.\n5.The Commission shall, if necessary, submit appropriate proposals to amend this Regulation, in particular taking into account of developments in information technology and in the light of the state of progress in the information society.\nArticle 98 Review of other Union legal acts on data protection\nThe Commission shall, if appropriate, submit legislative proposals with a view to amending other Union legal acts on the protection of personal data, in order to ensure uniform and consistent protection of natural persons with regard to processing. This shall in particular concern the rules relating to the protection of natural persons with regard to processing by Union institutions, bodies, offices and agencies and on the free movement of such data.\nArticle 99 Entry into force and application\n1.This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.\n2.It shall apply from 25 May 2018.\nThis Regulation shall be binding in its entirety and directly applicable in all Member States.\nDone at Brussels, 27 April 2016.\nFor the European Parliament\nThe President\nM. SCHULZ\nFor the Council\nThe President\nJ.A. HENNIS-PLASSCHAERT\n(1)OJ C 229, 31.7.2012, p. 90.\n(2)OJ C 391, 18.12.2012, p. 127.\n(3)Position of the European Parliament of 12 March 2014 (not yet published in the Official Journal) and position of the Council at first reading of 8 April 2016 (not yet published in the Official Journal). Position of the European Parliament of 14 April 2016.\n(4)Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (OJ L 281, 23.11.1995, p. 31).\n(5)Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises (C(2003) 1422) (OJ L 124, 20.5.2003, p. 36).\n(6)Regulation (EC) No 45/2001 of the European Parliament and of the Council of 18 December 2000 on the protection of individuals with regard to the processing of personal data by the Community institutions and bodies and on the free movement of such data (OJ L 8, 12.1.2001, p. 1).\n(7)Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and the free movement of such data and repealing Council Framework Decision 2008/977/JHA (see page 89 of this Official Journal).\n(8)Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000 on certain legal aspects of information society services, in particular electronic commerce, in the Internal Market (‘Directive on electronic commerce’) (OJ L 178, 17.7.2000, p. 1).\n(9)Directive 2011/24/EU of the European Parliament and of the Council of 9 March 2011 on the application of patients\u0026rsquo; rights in cross-border healthcare (OJ L 88, 4.4.2011, p. 45).\n(10)Council Directive 93/13/EEC of 5 April 1993 on unfair terms in consumer contracts (OJ L 95, 21.4.1993, p. 29).\n(11)Regulation (EC) No 1338/2008 of the European Parliament and of the Council of 16 December 2008 on Community statistics on public health and health and safety at work (OJ L 354, 31.12.2008, p. 70).\n(12)Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general principles concerning mechanisms for control by Member States of the Commission\u0026rsquo;s exercise of implementing powers (OJ L 55, 28.2.2011, p.13).\n(13)Regulation (EU) No 1215/2012 of the European Parliament and of the Council of 12 December 2012 on jurisdiction and the recognition and enforcement of judgments in civil and commercial matters (OJ L 351, 20.12.2012, p. 1).\n(14)Directive 2003/98/EC of the European Parliament and of the Council of 17 November 2003 on the re-use of public sector information (OJ L 345, 31.12.2003, p. 90).\n(15)Regulation (EU) No 536/2014 of the European Parliament and of the Council of 16 April 2014 on clinical trials on medicinal products for human use, and repealing Directive 2001/20/EC (OJ L 158, 27.5.2014, p. 1).\n(16)Regulation (EC) No 223/2009 of the European Parliament and of the Council of 11 March 2009 on European statistics and repealing Regulation (EC, Euratom) No 1101/2008 of the European Parliament and of the Council on the transmission of data subject to statistical confidentiality to the Statistical Office of the European Communities, Council Regulation (EC) No 322/97 on Community Statistics, and Council Decision 89/382/EEC, Euratom establishing a Committee on the Statistical Programmes of the European Communities (OJ L 87, 31.3.2009, p. 164).\n(17)OJ C 192, 30.6.2012, p. 7.\n(18)Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) (OJ L 201, 31.7.2002, p. 37).\n(19)Directive (EU) 2015/1535 of the European Parliament and of the Council of 9 September 2015 laying down a procedure for the provision of information in the field of technical regulations and of rules on Information Society services (OJ L 241, 17.9.2015, p.1).\n(20)Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July 2008 setting out the requirements for accreditation and market surveillance relating to the marketing of products and repealing Regulation (EEC) No 339/93 (OJ L 218, 13.8.2008, p.30).\n(21)Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43).\n","permalink":"https://ai.intlaws.com/en/compliance/eu/gdpr/","summary":"Official English text of Regulation (EU) 2016/679 (General Data Protection Regulation), as published in the Official Journal: 11 chapters, 99 articles and 173 recitals. The authentic languages of EU law are the official EU languages; there is no official Chinese text.","title":"General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679"},{"content":" Source: legislation.gov.uk (The National Archives), Data (Use and Access) Act 2025, Part 5\nOfficial link: https://www.legislation.gov.uk/ukpga/2025/18/part/5 Note: English original text. 本页为官方英文原文;中文译本整理中,发布后将在此链接。\nStructure: Chapter 1 — Data protection(第 66–108 条);Chapter 2 — PEC Regulations(第 109–116 条)\nPart 5 U.K.Data protection and privacy\nChapter 1 U.K.Data protection Terms used in this Chapter U.K. 66 The 2018 Act and the UK GDPR U.K. In this Chapter—\n“the 2018 Act” means the Data Protection Act 2018;\n“” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.\nCommencement Information\nDefinitions in the UK GDPR and the 2018 Act U.K. 67 Meaning of research and statistical purposes U.K. (1)In Article 4 of the UK GDPR (definitions)—\n(a)the existing text becomes paragraph 1, and\n(b)after that paragraph insert—\n“2.References in this Regulation to the processing of personal data for the purposes of scientific research (including references to processing for “scientific research purposes”) are references to processing for the purposes of any research that can reasonably be described as scientific, whether publicly or privately funded and whether carried out as a commercial or non-commercial activity.\n3.Such references—\n(a)include processing for the purposes of technological development or demonstration, fundamental research or applied research, so far as those activities can reasonably be described as scientific, but\n(b)only include processing for the purposes of a study in the area of public health that can reasonably be described as scientific where the study is conducted in the public interest.\n4.References in this Regulation to the processing of personal data for the purposes of historical research (including references to processing for “historical research purposes”) include processing for the purposes of genealogical research.\n5.References in this Regulation to the processing of personal data for statistical purposes are references to processing for statistical surveys or for the production of statistical results where—\n(a)the information that results from the processing is aggregate data that is not personal data, and\n(b)the controller does not use the personal data processed, or the information that results from the processing, in support of measures or decisions with respect to a particular data subject to whom the personal data relates.”\n(2)In consequence of the amendment made by subsection (1)(a), in section 6 of the 2018 Act (meaning of “controller”), for “4(7)” substitute “4(1)(7)”.\nCommencement Information\n68 Consent to processing for the purposes of scientific research U.K. (1)Article 4 of the UK GDPR (definitions) is amended as follows.\n(2)In point (11) of paragraph 1 (definition of “consent”), at the end insert “(and see paragraphs 6 and 7 of this Article)”.\n(3)After paragraph 5 (inserted by section 67 of this Act) insert—\n“6.A data subject’s consent is to be treated as falling within the definition of “consent” in point (11) of paragraph 1 if—\n(a)it does not fall within that definition because (and only because) the consent is given to the processing of personal data for the purposes of an area of scientific research,\n(b)at the time the consent is sought, it is not possible to identify fully the purposes for which personal data is to be processed,\n(c)seeking consent in relation to the area of scientific research is consistent with generally recognised ethical standards relevant to the area of research, and\n(d)so far as the intended purposes of the processing allow, the data subject is given the opportunity to consent only to processing for part of the research.\n7.References in this Regulation to consent given for a specific purpose (however expressed) include consent described in paragraph 6.”\nCommencement Information\n69 Consent to law enforcement processing U.K. (1)The 2018 Act is amended as follows.\n(2)In section 33 (definitions), after subsection (1) insert—\n“(1A)“Consent” of the data subject to the processing of personal data means a freely given, specific, informed and unambiguous indication of the data subject’s wishes by which the data subject, by a statement or by a clear affirmative action, signifies agreement to the processing of the personal data (and see section 40A).”\n(3)In section 34(2) (overview of Chapter 2 of Part 3), after paragraph (a) (but before the “and” at the end of that paragraph) insert—\n“(aa)section 40A makes provision about processing carried out in reliance on the consent of the data subject,”.\n(4)After section 40 insert—\n“40A Conditions for consent (1)This section is about processing of personal data that is carried out in reliance on the consent of the data subject.\n(2)The controller must be able to demonstrate that the data subject consented to the processing.\n(3)If the data subject’s consent is given in writing as part of a document which also concerns other matters, the request for consent must be made—\n(a)in a manner which clearly distinguishes the request from the other matters,\n(b)in an intelligible and easily accessible form, and\n(c)in clear and plain language.\n(4)Any part of a document described in subsection (3) which constitutes an infringement of this Part is not binding.\n(5)The data subject may withdraw the consent at any time (but the withdrawal of consent does not affect the lawfulness of processing in reliance on the consent before its withdrawal).\n(6)Processing may only be carried out in reliance on consent if—\n(a)before the consent is given, the controller or processor informs the data subject of the right to withdraw it, and\n(b)it is as easy for the data subject to withdraw the consent as to give it.\n(7)When assessing whether consent is freely given, account must be taken of, among other things, whether the provision of a service is conditional on consent to the processing of personal data that is not necessary for the provision of that service.”\n(5)In section 206 (index of defined expressions), in the Table, in the entry for “consent”—\n(a)after “consent” insert “(to processing of personal data)”,\n(b)for “Part” substitute “Parts 3 and”, and\n(c)for “section” substitute “sections 33, 40A and”.\nCommencement Information\nData protection principles U.K. 70 Lawfulness of processing U.K. (1)The UK GDPR is amended in accordance with subsections (2) to (5).\n(2)In Article 6(1) (lawful processing)—\n(a)in point (e)—\n(i)after “task” insert “of the controller”, and\n(ii)after “or” insert “a task carried out”,\n(b)after that point insert—\n“(ea)processing is necessary for the purposes of a recognised legitimate interest;”, and\n(c)in the words after point (f), for “Point (f)” substitute “Points (ea) and (f)”.\n(3)In Article 6(3) (basis for processing etc), in the last subparagraph, in the first sentence—\n(a)after “task” insert “of the controller”, and\n(b)after “interest or” insert “a task carried out”.\n(4)In Article 6, at the end insert—\n“5.For the purposes of paragraph 1(ea), processing is necessary for the purposes of a recognised legitimate interest only if it meets a condition in Annex 1.\n6.The Secretary of State may by regulations amend Annex 1 by—\n(a)adding or varying provisions, or\n(b)omitting provisions added by regulations made under this paragraph.\n7.The Secretary of State may only make regulations under paragraph 6 where—\n(a)the requirement in paragraph 8 is satisfied, and\n(b)if the regulations add a case to Annex 1, the requirement in paragraph 9 is also satisfied.\n8.The requirement in this paragraph is that the Secretary of State considers it appropriate to make the regulations having regard to, among other things—\n(a)the interests and fundamental rights and freedoms of data subjects which require protection of personal data, and\n(b)where relevant, the fact that children merit specific protection with regard to their personal data because they may be less aware of the risks and consequences associated with processing of personal data and of their rights in relation to such processing.\n9.The requirement in this paragraph is that the Secretary of State considers that processing in the case to be added to Annex 1 is necessary to safeguard an objective listed in Article 23(1)(c) to (j).\n10.Regulations under paragraph 6 are subject to the affirmative resolution procedure.\n11.For the purposes of paragraph 1(f), examples of types of processing that may be processing that is necessary for the purposes of a legitimate interest include—\n(a)processing that is necessary for the purposes of direct marketing,\n(b)intra-group transmission of personal data (whether relating to clients, employees or other individuals) where that is necessary for internal administrative purposes, and\n(c)processing that is necessary for the purposes of ensuring the security of network and information systems.\n12.In paragraph 11—\n“intra-group transmission” means transmission between members of a group of undertakings or between members of a group of institutions affiliated to a central body;\n“security of network and information systems” has the same meaning as in the Network and Information Systems Regulations 2018 (S.I. 2018/506 ) (see regulation 1(3)(g)).”\n(5)In Article 21(1) (right to object), after “point (e)” insert “, (ea)”.\n(6)Schedule 4 to this Act inserts Annex 1 to the UK GDPR.\n(7)In section 8 of the 2018 Act (lawfulness of processing: public interest etc), omit “the controller’s”.\n(8)In the provisions listed in subsection (9)—\n(a)for “gateway” substitute “gateways”, and\n(b)for “were omitted” substitute “disapplied only the gateway in point (ea) (recognised legitimate interests)”.\n(9)The provisions are—\n(a)section 40(8) of the Freedom of Information Act 2000 (personal data which is exempt information);\n(b)section 38(5A) of the Freedom of Information (Scotland) Act 2002 (asp 13) (personal data which is exempt information);\n(c)regulation 13(6) of the Environmental Information Regulations 2004 (S.I. 2004/3391 ) (restriction on disclosure of personal data);\n(d)regulation 11(7) of the Environmental Information (Scotland) Regulations 2004 (S.S.I. 2004/520 ) (restriction on disclosure of personal data);\n(e)regulation 45(1E) of the Civil Contingencies Act 2004 (Contingency Planning) Regulations 2005 (S.I. 2005/2042 ) (personal data which is sensitive information);\n(f)regulation 39(1E) of the Civil Contingencies Act 2004 (Contingency Planning) (Scotland) Regulations 2005 (S.S.I. 2005/494 ) (personal data which is sensitive information);\n(g)regulation 9(9) of the INSPIRE Regulations 2009 (S.I. 2009/3157 ) (limitation of public access to personal data included in a spatial data set);\n(h)regulation 10(8) of the INSPIRE (Scotland) Regulations 2009 (S.S.I. 2009/440 ) (limitation of public access to personal data included in a spatial data set).\nCommencement Information\n71 The purpose limitation U.K. (1)The UK GDPR is amended in accordance with subsections (2) to (5).\n(2)In Article 5(1)(b) (purpose limitation)—\n(a)after “collected” insert “(whether from the data subject or otherwise)”,\n(b)after “further processed” insert “by or on behalf of a controller”, and\n(c)for the words from “those purposes;” to “initial purposes” substitute “the purposes for which the controller collected the data”.\n(3)In Article 5, at the end insert—\n“3.For the avoidance of doubt, processing is not lawful by virtue only of being processing in a manner that is compatible with the purposes for which the personal data was collected.”\n(4)In Article 6 (lawfulness of processing), omit paragraph 4.\n(5)After Article 8 insert—\n“Article 8A Purpose limitation: further processing 1.This Article is about the determination, for the purposes of Article 5(1)(b) (purpose limitation), of whether processing of personal data by or on behalf of a controller for a purpose (a “new purpose”) other than the purpose for which the controller collected the data (“the original purpose”) is processing in a manner compatible with the original purpose.\n2.In making the determination, a person must take into account, among other things—\n(a)any link between the original purpose and the new purpose;\n(b)the context in which the personal data was collected, including the relationship between the data subject and the controller;\n(c)the nature of the processing, including whether it is processing described in Article 9(1) (processing of special categories of personal data) or Article 10(1) (processing of personal data relating to criminal convictions etc);\n(d)the possible consequences of the intended processing for data subjects;\n(e)the existence of appropriate safeguards (for example, encryption or pseudonymisation).\n3.Processing of personal data for a new purpose is to be treated as processing in a manner compatible with the original purpose where—\n(a)the data subject consents to the processing of personal data for the new purpose and the new purpose is specified, explicit and legitimate,\n(b)the processing is carried out in accordance with Article 84B—\n(i)for the purposes of scientific research or historical research,\n(ii)for the purposes of archiving in the public interest, or\n(iii)for statistical purposes,\n(c)the processing is carried out for the purposes of ensuring that processing of personal data complies with Article 5(1) or demonstrating that it does so,\n(d)the processing meets a condition in Annex 2, or\n(e)the processing is necessary to safeguard an objective listed in Article 23(1)(c) to (j) and is authorised by an enactment or rule of law.\n4.Where the controller collected the personal data based on Article 6(1)(a) (data subject’s consent), processing for a new purpose is only processing in a manner compatible with the original purpose if—\n(a)it falls within paragraph 3(a) or (c), or\n(b)it falls within paragraph 3(d) or (e) and the controller cannot reasonably be expected to obtain the data subject’s consent.\n5.The Secretary of State may by regulations amend Annex 2 by—\n(a)adding or varying provisions, or\n(b)omitting provisions added by regulations made under this paragraph.\n6.The Secretary of State may only make regulations under paragraph 5 adding a case to Annex 2 where the Secretary of State considers that processing in that case is necessary to safeguard an objective listed in Article 23(1)(c) to (j).\n7.Regulations under paragraph 5 may make provision identifying processing by any means, including by reference to the controller, the data subject, the personal data or the provision of Article 6(1) relied on for the purposes of the processing.\n8.Regulations under paragraph 5 are subject to the affirmative resolution procedure.”\n(6)Schedule 5 to this Act inserts Annex 2 to the UK GDPR.\n(7)The 2018 Act is amended in accordance with subsections (8) to (10).\n(8)In section 36(1) (the second data protection principle)—\n(a)in paragraph (a), for “on any occasion” substitute “(whether from the data subject or otherwise)”, and\n(b)in paragraph (b)—\n(i)after “processed” insert “by or on behalf of a controller”, and\n(ii)for “it was collected” substitute “the controller collected it”.\n(9)In section 87(1) (the second data protection principle)—\n(a)in paragraph (a), for “on any occasion” substitute “(whether from the data subject or otherwise)”, and\n(b)in paragraph (b)—\n(i)after “processed” insert “by or on behalf of a controller”, and\n(ii)for “it was collected” substitute “the controller collected it”.\n(10)In paragraph 1 of Schedule 2 (exemptions etc from the UK GDPR: provisions to be adapted or restricted), omit sub-paragraph (b)(ii).\nCommencement Information\n72 Processing in reliance on relevant international law U.K. (1)The UK GDPR is amended in accordance with subsections (2) to (5).\n(2)In Article 6(3) (lawfulness of processing: basis in domestic law)—\n(a)in the first subparagraph, omit “and (e)”,\n(b)after that subparagraph insert—\n“The basis for the processing referred to in point (e) of paragraph 1 must be laid down by domestic law or relevant international law (see section 9A of the 2018 Act).”, and\n(c)in the last subparagraph, in the last sentence, after “domestic law” insert “or relevant international law”.\n(3)In Article 8A(3)(e) (purpose limitation: further processing necessary to safeguard an objective listed in Article 23(1)) (inserted by section 71 of this Act), at the end insert “or by relevant international law (see section 9A of the 2018 Act)”.\n(4)In Article 9 (processing of special categories of personal data)—\n(a)in paragraph 2(g) (substantial public interest), after “domestic law” insert “, or relevant international law,”, and\n(b)in paragraph 5, before point (a) insert—\n“(za)section 9A makes provision about when the requirement in paragraph 2(g) of this Article for a basis in relevant international law is met;”.\n(5)In Article 10 (processing of personal data relating to criminal convictions and offences)—\n(a)in paragraph 1, after “domestic law” insert “, or relevant international law,”, and\n(b)in paragraph 2, before point (a) insert—\n“(za)section 9A makes provision about when the requirement in paragraph 1 of this Article for authorisation by relevant international law is met;”.\n(6)The 2018 Act is amended in accordance with subsections (7) and (8).\n(7)Before section 10 (and the italic heading before that section) insert—\n“Relevant international law U.K. 9A Processing in reliance on relevant international law (1)Processing of personal data meets the requirement in Article 6(3), 8A(3)(e), 9(2)(g) or 10(1) of the UK GDPR for a basis in, or authorisation by, relevant international law only if it meets a condition in Schedule A1.\n(2)A condition in Schedule A1 may be relied on for the purposes of any of those provisions, unless that Schedule provides otherwise.\n(3)The Secretary of State may by regulations amend Schedule A1 by adding, varying or omitting—\n(a)conditions,\n(b)provision about the purposes for which a condition may be relied on, and\n(c)safeguards in connection with processing carried out in reliance on a condition in the Schedule.\n(4)Regulations under this section may only add a condition relating entirely or partly to a treaty ratified by the United Kingdom.\n(5)Regulations under this section are subject to the affirmative resolution procedure.\n(6)In this section, “treaty” and “ratified” have the same meaning as in Part 2 of the Constitutional Reform and Governance Act 2010 (see section 25 of that Act).”\n(8)Before Schedule 1 insert—\nSection 9A\n“Schedule A1 U.K.Processing in reliance on relevant international law This condition is met where the processing is necessary for the purposes of responding to a request made in accordance with the Agreement between the Government of the United Kingdom of Great Britain and Northern Ireland and the Government of the United States of America on Access to Electronic Data for the Purpose of Countering Serious Crime, signed on 3 October 2019.”\nCommencement Information\nProcessing of special categories of personal data U.K. 73 Elected representatives responding to requests U.K. In paragraph 23 of Schedule 1 to the 2018 Act (processing of special categories of personal data: elected representatives responding to requests), in sub-paragraph (4), for “fourth day after” substitute “period of 30 days beginning with the day after”.\nCommencement Information\n74 Processing of special categories of personal data U.K. (1)In Chapter 2 of the UK GDPR, after Article 11 insert—\n“Article 11A Further provision about processing of special categories of personal data 1.The Secretary of State may by regulations—\n(a)make provision so that an additional description of processing of personal data is subject to the prohibition in Article 9(1),\n(b)make provision so that added processing is not subject to that prohibition,\n(c)make provision so that an exception in Article 9(2) may or may not be relied on in connection with added processing, and\n(d)make provision varying such an exception as it applies in connection with added processing.\n2.In paragraph 1, “added processing” means a description of processing which is subject to the prohibition in Article 9(1) by virtue of provision made under paragraph 1(a).\n3.Regulations made under this Article (in reliance on Article 91A(4)(b)) may amend section 5, 205 or 206 of the 2018 Act (interpretation).\n4.Regulations under this Article are subject to the affirmative resolution procedure.”\n(2)The 2018 Act is amended in accordance with subsections (3) to (9).\n(3)In section 33 (definitions of expressions used in Part 3), after subsection (6) insert—\n“(6A)“Sensitive processing” has the meaning given in section 35(8).”\n(4)In section 35 (the first data protection principle)—\n(a)in subsection (6)(b) (power to omit conditions added to Schedule 8 by regulations), after “by”, in the first place it occurs, insert “varying or”, and\n(b)in subsection (8) (definition of “sensitive processing”), for “section” substitute “Part”.\n(5)After section 42 insert—\n“42A Further provision about sensitive processing (1)The Secretary of State may by regulations—\n(a)make provision so that an additional description of processing of personal data is sensitive processing for the purposes of this Part,\n(b)make provision so that added processing is not sensitive processing for the purposes of this Part,\n(c)make provision so that a protected condition in Schedule 8 may or may not be relied on in connection with added processing, and\n(d)make provision varying such a condition as it relates to added processing.\n(2)In subsection (1)—\n“added processing” means a description of processing which is sensitive processing by virtue of provision made under subsection (1)(a);\n“protected condition in Schedule 8” means a condition in that Schedule other than one that was added to the Schedule by regulations under section 35(6).\n(3)Regulations under this section may amend this Part and sections 205 and 206.\n(4)Regulations under this section are subject to the affirmative resolution procedure.”\n(6)In section 84 (definitions of expressions used in Part 4), after subsection (6) insert—\n“(6A)“Sensitive processing” has the meaning given in section 86(7).”\n(7)In section 86 (the first data protection principle)—\n(a)in subsection (3)(b) (power to omit conditions added to Schedule 10 by regulations), after “by”, in the first place it occurs, insert “varying or”, and\n(b)in subsection (7) (definition of “sensitive processing”), for “section” substitute “Part”.\n(8)After section 91 insert—\n“91A Further provision about sensitive processing (1)The Secretary of State may by regulations—\n(a)make provision so that an additional description of processing of personal data is sensitive processing for the purposes of this Part,\n(b)make provision so that added processing is not sensitive processing for the purposes of this Part,\n(c)make provision so that a protected condition in Schedule 10 may or may not be relied on in connection with added processing, and\n(d)make provision varying such a condition as it relates to added processing.\n(2)In subsection (1)—\n“added processing” means a description of processing which is sensitive processing by virtue of provision made under subsection (1)(a);\n“protected condition in Schedule 10” means a condition in that Schedule other than one that was added to the Schedule by regulations under section 86(3).\n(3)Regulations under this section may amend this Part and sections 205 and 206.\n(4)Regulations under this section are subject to the affirmative resolution procedure.”\n(9)In section 206 (index of defined expressions), in the Table, at the appropriate place insert—\n“sensitive processing (in Parts 3 and 4)sections 35 and 86”.\n(10)The Investigatory Powers Act 2016 is amended in accordance with subsections (11) to (13).\n(11)In section 202(4) (restrictions on use of class BPD warrants: definitions), omit the definition of “sensitive personal data” and insert—\n““sensitive personal data” means personal data whose retention, or (as appropriate) retention and examination, would be sensitive processing;\n“sensitive processing” means—\n(a)\nprocessing of personal data relating to a living individual that is processing of a kind described in section 86(7)(a) to (e) of the Data Protection Act 2018, or (b)\nprocessing of personal data relating to a deceased individual that would be that kind of processing if the personal data related to a living individual.”\n(12)After that section insert—\n“202A Further provision about sensitive processing (1)The Secretary of State may by regulations—\n(a)make provision so that a description of Part 4 sensitive processing, or of processing that would be such processing if the information processed related to a living individual, is sensitive processing for the purposes of section 202, and\n(b)make provision so that added processing is not sensitive processing for the purposes of that section.\n(2)In this section—\n“added processing” means a description of processing that is sensitive processing for the purposes of section 202 by virtue of provision made under subsection (1)(a);\n“Part 4 sensitive processing” means processing of personal data that, at the time the regulations are made, is sensitive processing for the purposes of Part 4 of the Data Protection Act 2018 by virtue of regulations made under section 91A of that Act.\n(3)Regulations under this section may amend section 202.”\n(13)In section 267(3) (regulations subject to the affirmative procedure), after paragraph (e) insert—\n“(ea)section 202A,”.\nCommencement Information\nData subject’s rights U.K. 75 Fees and reasons for responses to data subjects’ requests about law enforcement processing U.K. (1)The 2018 Act is amended as follows.\n(2)In section 53 (manifestly unfounded or excessive requests by the data subject under Part 3)—\n(a)after subsection (4) insert—\n“(4A)The Secretary of State may by regulations—\n(a)require controllers of a description specified in the regulations to produce and publish guidance about the fees that they charge in accordance with subsection (1)(a), and\n(b)specify what the guidance must include.”,\n(b)in subsection (5), for “subsection (4)” substitute “this section”, and\n(c)after subsection (5) insert—\n“(6)If, in reliance on subsection (1)(b), the controller does not take action on the request, the controller must inform the data subject of—\n(a)the reasons for not doing so, and\n(b)the data subject’s right to lodge a complaint with the Commissioner.\n(7)The controller must comply with subsection (6)—\n(a)without undue delay, and\n(b)in any event, before the end of the applicable time period (as to which see section 54).”\n(3)In section 54(1) (meaning of “applicable time period”), for “and 48(2)(b)” substitute “, 48(2)(b) and 53(7)”.\nCommencement Information\n76 Time limits for responding to data subjects’ requests U.K. (1)The UK GDPR is amended in accordance with subsections (2) and (3).\n(2)In Article 12 (transparent information, communication and modalities for the exercise of rights of the data subject)—\n(a)in paragraph 3—\n(i)for “within one month of receipt of the request” substitute “before the end of the applicable time period (see Article 12A)”, and\n(ii)omit the second and third sentences,\n(b)in paragraph 4, for “without delay and at the latest within one month of receipt of the request” substitute “without undue delay, and in any event before the end of the applicable time period (see Article 12A),”, and\n(c)in paragraph 6—\n(i)after “may” insert “—\n(a)”, and\n(ii)at the end insert “, and\n(b)delay dealing with the request until the identity is confirmed.”\n(3)After Article 12 insert—\n“Article 12A Meaning of “applicable time period” 1.In Article 12, “the applicable time period” means the period of one month beginning with the relevant time, subject to paragraph 3.\n2.“The relevant time” means the latest of the following—\n(a)when the controller receives the request in question;\n(b)when the controller receives the information (if any) requested in connection with a request under Article 12(6);\n(c)when the fee (if any) charged in connection with the request under Article 12(5) is paid.\n3.The controller may, by giving notice to the data subject, extend the applicable time period by two further months where that is necessary by reason of—\n(a)the complexity of requests made by the data subject, or\n(b)the number of such requests.\n4.A notice under paragraph 3 must—\n(a)be given before the end of the period of one month beginning with the relevant time, and\n(b)state the reasons for the delay.\n5.Where the controller reasonably requires further information in order to identify the information or processing activities to which a request under Article 15 relates—\n(a)the controller may ask the data subject to provide the further information, and\n(b)the period beginning with the day on which the controller makes the request and ending with the day on which the controller receives the information does not count towards—\n(i)the applicable time period, or\n(ii)the period described in paragraph 4(a).\n6.An example of a case in which a controller may reasonably require further information is where the controller processes a large amount of information concerning the data subject.”\n(4)The 2018 Act is amended in accordance with subsections (5) to (7).\n(5)In section 45(5) (right of access by the data subject), after “delay” insert “and in any event before the end of the applicable time period (as to which see section 54)”.\n(6)In section 54 (meaning of “applicable time period” for responding to data subjects’ requests)—\n(a)in subsection (1), after “45(3)(b)” insert “and (5)”,\n(b)in subsection (2)—\n(i)for “1 month, or such longer period as may be specified in regulations,” substitute “one month”, and\n(ii)at the end insert “, subject to subsection (3A)”,\n(c)after subsection (3) insert—\n“(3A)The controller may, by giving notice to the data subject, extend the applicable time period by two further months where that is necessary by reason of—\n(a)the complexity of requests made by the data subject, or\n(b)the number of such requests.\n(3B)A notice under subsection (3A) must—\n(a)be given before the end of the period of one month beginning with the relevant time, and\n(b)state the reasons for the delay.\n(3C)Where the controller reasonably requires further information in order to identify the information or processing activities to which a request under section 45(1) relates—\n(a)the controller may ask the data subject to provide the further information, and\n(b)the period beginning with the day on which the controller makes the request and ending with the day on which the controller receives the information does not count towards—\n(i)the applicable time period, or\n(ii)the period described in subsection (3B)(a).\n(3D)An example of a case in which a controller may reasonably require further information is where the controller processes a large amount of information concerning the data subject.”, and\n(d)omit subsections (4) to (6).\n(7)In section 94 (right of access under Part 4)—\n(a)in subsection (14), for the definition of “the applicable time period” substitute—\n““the applicable time period” means the period of one month beginning with the relevant time, subject to subsection (14A);”, and (b)after subsection (14) insert—\n“(14A)The controller may, by giving notice to the data subject, extend the applicable time period by two further months where that is necessary by reason of—\n(a)the complexity of requests made by the data subject, or\n(b)the number of such requests.\n(14B)A notice under subsection (14A) must—\n(a)be given before the end of the period of one month beginning with the relevant time, and\n(b)state the reasons for the delay.”\nCommencement Information\n77 Information to be provided to data subjects U.K. (1)In Article 13 of the UK GDPR (information to be provided where personal data is collected from the data subject)—\n(a)in paragraph 4, for “shall not apply where and insofar as” substitute “do not apply to the extent that”, and\n(b)at the end insert—\n“5.Paragraph 3 does not apply to the extent that—\n(a)the controller intends to further process the personal data—\n(i)for (and only for) the purposes of scientific or historical research, the purposes of archiving in the public interest or statistical purposes, and\n(ii)in accordance with Article 84B, and\n(b)providing the information is impossible or would involve a disproportionate effort.\n6.For the purposes of paragraph 5(b), whether providing the information would involve a disproportionate effort depends on, among other things, the number of data subjects, the age of the personal data and any appropriate safeguards applied to the processing.\n7.A controller relying on paragraph 5 must take appropriate measures to protect the data subject’s rights, freedoms and legitimate interests, including by making the information available publicly.”\n(2)In Article 14 of the UK GDPR (information to be provided where personal data is not obtained from the data subject)—\n(a)in paragraph 5—\n(i)for “shall not apply where and insofar as” substitute “do not apply to the extent that”,\n(ii)omit point (b),\n(iii)omit the “or” at the end of point (c),\n(iv)in point (d), omit “where”, and\n(v)after that point insert—\n“(e)providing the information is impossible or would involve a disproportionate effort, or\n(f)the obligation referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of the processing for which the personal data are intended.”, and\n(b)at the end insert—\n“6.For the purposes of paragraph 5(e), whether providing the information would involve a disproportionate effort depends on, among other things, the number of data subjects, the age of the personal data and any appropriate safeguards applied to the processing.\n7.A controller relying on paragraph 5(e) or (f) must take appropriate measures to protect the data subject’s rights, freedoms and legitimate interests, including by making the information available publicly.”\nCommencement Information\n78 Searches in response to data subjects’ requests U.K. (1)In Article 15 of the UK GDPR (right of access by the data subject)—\n(a)after paragraph 1 insert—\n“1A.Under paragraph 1, the data subject is only entitled to such confirmation, personal data and other information as the controller is able to provide based on a reasonable and proportionate search for the personal data and other information described in that paragraph.”, and\n(b)in paragraph 3, after “processing” insert “to which the data subject is entitled under paragraph 1”.\n(2)The 2018 Act is amended in accordance with subsections (3) and (4).\n(3)In section 45 (law enforcement processing: right of access by the data subject), after subsection (2) insert—\n“(2A)Under subsection (1), the data subject is only entitled to such confirmation, personal data and other information as the controller is able to provide based on a reasonable and proportionate search for the personal data and other information described in that subsection.”\n(4)In section 94 (intelligence services processing: right of access by the data subject), after subsection (2) insert—\n“(2A)Under subsection (1), the data subject is only entitled to such confirmation, personal data and other information as the controller is able to provide based on a reasonable and proportionate search for the personal data and other information described in that subsection.”\n(5)The amendments made by this section are to be treated as having come into force on 1 January 2024.\nCommencement Information\n79 Data subjects’ rights to information: legal professional privilege exemption U.K. (1)The 2018 Act is amended as follows.\n(2)In section 43 (overview and scope of Chapter 3 of Part 3: rights of the data subject in connection with law enforcement processing)—\n(a)in subsection (1)(a), for “section 44” substitute “sections 44 and 45A”, and\n(b)in subsection (1)(b), for “section 45” substitute “sections 45 and 45A”.\n(3)For the italic heading before section 44 substitute—\n“Data subject’s rights to information”. (4)In the heading of section 44, omit “Information:”.\n(5)Omit the italic heading before section 45.\n(6)After that section insert—\n“45A Exemption from sections 44 and 45: legal professional privilege (1)Sections 44(2) and 45(1) do not require the controller to give the data subject—\n(a)information in respect of which a claim to legal professional privilege or, in Scotland, confidentiality of communications could be maintained in legal proceedings, or\n(b)information in respect of which a duty of confidentiality is owed by a professional legal adviser to a client of the adviser.\n(2)A controller relying on the exemption in subsection (1) must inform the data subject in writing without undue delay of—\n(a)the decision to rely on the exemption,\n(b)the reason for the decision,\n(c)the data subject’s right to make a request to the Commissioner under section 51,\n(d)the data subject’s right to lodge a complaint with the Commissioner under section 165, and\n(e)the data subject’s right to apply to a court under section 167.\n(3)Subsection (2)(a) and (b) do not apply to the extent that complying with them would—\n(a)undermine a claim described in subsection (1)(a), or\n(b)conflict with a duty described in subsection (1)(b).\n(4)The controller must—\n(a)record the reason for a decision to rely on the exemption in subsection (1), and\n(b)if requested to do so by the Commissioner, make the record available to the Commissioner.\n(5)The reference in subsection (1) to sections 44(2) and 45(1) includes sections 35 to 40 so far as their provisions correspond to the rights and obligations provided for in sections 44(2) and 45(1).”\n(7)In section 51 (exercise of rights through the Commissioner)—\n(a)in subsection (1), after paragraph (b) (but before the “or” at the end of that paragraph) insert—\n“(ba)relies on the exemption from sections 44(2) and 45(1) in section 45A (legal professional privilege),”,\n(b)in subsection (2), after paragraph (a) insert—\n“(aa)where subsection (1)(ba) applies, request the Commissioner to check that the controller was entitled to rely on the exemption;”,\n(c)in subsection (4), after paragraph (a) insert—\n“(aa)where subsection (1)(ba) applies, whether the Commissioner is satisfied that the controller was entitled to rely on the exemption;”, and\n(d)in subsection (6), after “(a)” insert “, (aa)”.\nCommencement Information\nAutomated decision-making U.K. 80 Automated decision-making U.K. (1)For Article 22 of the UK GDPR (automated individual decision-making, including profiling) substitute—\n“Section 4A U.K.Automated individual decision-making Article 22A Automated processing and significant decisions 1.For the purposes of Articles 22B and 22C—\n(a)a decision is based solely on automated processing if there is no meaningful human involvement in the taking of the decision, and\n(b)a decision is a significant decision, in relation to a data subject, if—\n(i)it produces a legal effect for the data subject, or\n(ii)it has a similarly significant effect for the data subject.\n2.When considering whether there is meaningful human involvement in the taking of a decision, a person must consider, among other things, the extent to which the decision is reached by means of profiling.\nArticle 22B Restrictions on automated decision-making 1.A significant decision based entirely or partly on processing described in Article 9(1) (processing of special categories of personal data) may not be taken based solely on automated processing, unless one of the following conditions is met.\n2.The first condition is that the decision is based entirely on processing of personal data to which the data subject has given explicit consent.\n3.The second condition is that—\n(a)the decision is—\n(i)necessary for entering into, or performing, a contract between the data subject and a controller, or\n(ii)required or authorised by law, and\n(b)point (g) of Article 9(2) applies.\n4.A significant decision may not be taken based solely on automated processing if the processing of personal data carried out by, or on behalf of, the decision-maker for the purposes of the decision is carried out entirely or partly in reliance on Article 6(1)(ea).\nArticle 22C Safeguards for automated decision-making 1.Where a significant decision taken by or on behalf of a controller in relation to a data subject is—\n(a)based entirely or partly on personal data, and\n(b)based solely on automated processing,\nthe controller must ensure that safeguards for the data subject’s rights, freedoms and legitimate interests are in place which comply with paragraph 2 and any regulations under Article 22D(3).\n2.The safeguards must consist of or include measures which—\n(a)provide the data subject with information about decisions described in paragraph 1 taken in relation to the data subject;\n(b)enable the data subject to make representations about such decisions;\n(c)enable the data subject to obtain human intervention on the part of the controller in relation to such decisions;\n(d)enable the data subject to contest such decisions.\nArticle 22D Further provision about automated decision-making 1.The Secretary of State may by regulations provide that, for the purposes of Article 22A(1)(a), there is, or is not, to be taken to be meaningful human involvement in the taking of a decision in cases described in the regulations.\n2.The Secretary of State may by regulations provide that, for the purposes of Article 22A(1)(b)(ii), a description of decision is, or is not, to be taken to have a similarly significant effect for the data subject.\n3.The Secretary of State may by regulations make the following types of provision about the safeguards required under Article 22C(1)—\n(a)provision requiring the safeguards to include measures in addition to those described in Article 22C(2),\n(b)provision imposing requirements which supplement what Article 22C(2) requires the safeguards to consist of or include (including, for example, provision about how and when things described in Article 22C(2) must be done or be capable of being done), and\n(c)provision about measures which are not to be taken to satisfy one or more of points (a) to (d) of Article 22C(2).\n4.Regulations under paragraph 3 may not amend Article 22C.\n5.Regulations under this Article are subject to the affirmative resolution procedure.”\n(2)The 2018 Act is amended in accordance with subsections (3) to (5).\n(3)For sections 49 and 50 (law enforcement processing: automated individual decision-making) substitute—\n“50A Automated processing and significant decisions (1)For the purposes of sections 50B and 50C—\n(a)a decision is based solely on automated processing if there is no meaningful human involvement in the taking of the decision, and\n(b)a decision is a significant decision, in relation to a data subject, if—\n(i)it produces an adverse legal effect for the data subject, or\n(ii)it has a similarly significant adverse effect for the data subject.\n(2)When considering whether there is meaningful human involvement in the taking of a decision, a person must consider, among other things, the extent to which the decision is reached by means of profiling.\n50B Restrictions on automated decision-making based on sensitive processing (1)A significant decision based entirely or partly on sensitive processing may not be taken based solely on automated processing, unless one of the following conditions is met.\n(2)The first condition is that the decision is based entirely on processing of personal data to which the data subject has given explicit consent.\n(3)The second condition is that the decision is required or authorised by law.\n50C Safeguards for automated decision-making (1)Subject to subsection (3), where a significant decision taken by or on behalf of a controller in relation to a data subject is—\n(a)based entirely or partly on personal data, and\n(b)based solely on automated processing,\nthe controller must ensure that safeguards for the data subject’s rights, freedoms and legitimate interests are in place which comply with subsection (2) and any regulations under section 50D(4).\n(2)The safeguards must consist of or include measures which—\n(a)provide the data subject with information about decisions described in subsection (1) taken in relation to the data subject;\n(b)enable the data subject to make representations about such decisions;\n(c)enable the data subject to obtain human intervention on the part of the controller in relation to such decisions;\n(d)enable the data subject to contest such decisions.\n(3)Subsections (1) and (2) do not apply in relation to a significant decision if—\n(a)exemption from those provisions is required for a reason listed in subsection (4),\n(b)the controller reconsiders the decision as soon as reasonably practicable, and\n(c)there is meaningful human involvement in the reconsideration of the decision.\n(4)Those reasons are—\n(a)to avoid obstructing an official or legal inquiry, investigation or procedure;\n(b)to avoid prejudicing the prevention, detection, investigation or prosecution of criminal offences or the execution of criminal penalties;\n(c)to protect public security;\n(d)to safeguard national security;\n(e)to protect the rights and freedoms of others.\n(5)When considering whether there is meaningful human involvement in the reconsideration of a decision, a person must consider, among other things, the extent to which the conclusion reached on reconsideration is reached by means of profiling.\n50D Further provision about automated decision-making (1)The Secretary of State may by regulations provide that, for the purposes of sections 50A(1)(a) and 50C(3)(c), there is, or is not, to be taken to be meaningful human involvement in the taking or reconsideration of a decision in cases described in the regulations.\n(2)The Secretary of State may by regulations provide that, for the purposes of section 50A(1)(b)(ii), a description of decision is, or is not, to be taken to have a similarly significant adverse effect for the data subject.\n(3)Regulations under subsection (1) or (2) may amend section 50A.\n(4)The Secretary of State may by regulations make the following types of provision about the safeguards required under section 50C(1)—\n(a)provision requiring the safeguards to include measures in addition to those described in section 50C(2),\n(b)provision imposing requirements which supplement what section 50C(2) requires the safeguards to consist of or include (including, for example, provision about how and when things described in section 50C(2) must be done or be capable of being done), and\n(c)provision about measures which are not to be taken to satisfy one or more of paragraphs (a) to (d) of section 50C(2).\n(5)Regulations under this section are subject to the affirmative resolution procedure.”\n(4)In section 96 (intelligence services processing: right not to be subject to automated decision-making)—\n(a)in subsection (1), for “solely on” substitute “on entirely”,\n(b)in subsection (3), after “section” insert “and section 97”, and\n(c)at the end insert—\n“(4)For the purposes of this section and section 97, a decision is based on entirely automated processing if the decision-making process does not include an opportunity for a human being to accept, reject or influence the decision.”\n(5)In section 97 (intelligence services processing: right to intervene in automated decision-making)—\n(a)in subsection (1)(a), for “solely on” substitute “on entirely”,\n(b)in subsection (4)(b), for “solely on” substitute “on entirely”, and\n(c)omit subsection (6).\n(6)Schedule 6 to this Act contains minor and consequential amendments.\nCommencement Information\nObligations of controllers U.K. 81 Data protection by design: children’s higher protection matters U.K. (1)Article 25 of the UK GDPR (data protection by design and by default) is amended as follows.\n(2)After paragraph 1 insert—\n“1A.In the case of processing carried out in the course of providing information society services which are likely to be accessed by children, when assessing what are appropriate technical and organisational measures in accordance with paragraph 1, the controller must take into account the children’s higher protection matters.\n1B.The children’s higher protection matters are—\n(a)how children can best be protected and supported when using the services, and\n(b)the fact that children—\n(i)merit specific protection with regard to their personal data because they may be less aware of the risks and consequences associated with processing of personal data and of their rights in relation to such processing, and\n(ii)have different needs at different ages and at different stages of development.”\n(3)In paragraph 3, for “1 and 2” substitute “1 to 2”.\n(4)At the end insert—\n“4.Paragraphs 1A and 1B are not to be read as implying anything about the matters that may be relevant to the assessment of what are appropriate technical and organisational measures for the purposes of paragraph 1 in cases other than those described in paragraph 1A.\n5.In this Article, “information society services” does not include preventive or counselling services.”\nCommencement Information\nLogging of law enforcement processing U.K. 82 Logging of law enforcement processing U.K. In section 62 of the 2018 Act (logging of law enforcement processing)—\n(a)in subsection (2)(a), omit “justification for, and”, and\n(b)in subsection (3)(a), omit “justification for, and”.\nCommencement Information\nCodes of conduct U.K. 83 General processing and codes of conduct U.K. In Article 41 of the UK GDPR (monitoring of approved codes of conduct)—\n(a)in paragraph 4, omit the words from “, including suspension” to the end, and\n(b)after that paragraph insert—\n“4A.If the action taken by a body under paragraph 4 consists of suspending or excluding a controller or processor from the code, the body must inform the Commissioner, giving reasons for taking that action.”\nCommencement Information\n84 Law enforcement processing and codes of conduct U.K. (1)The 2018 Act is amended as follows.\n(2)In section 55(1) (overview and scope of provisions about controllers and processors), at the end insert—\n“(e)makes provision about codes of conduct (see section 71A).”\n(3)In section 56 (general obligations of the controller), at the end insert—\n“(4)Adherence to a code of conduct approved under section 71A may be used by a controller as a means of demonstrating compliance with the requirements of this Part.”\n(4)In section 59 (processors), after subsection (7) insert—\n“(7A)Adherence to a code of conduct approved under section 71A may be used by a processor as a means of demonstrating sufficient guarantees as described in subsection (2).”\n(5)In section 66 (security of processing), at the end insert—\n“(3)Adherence to a code of conduct approved under section 71A may be used by a controller or processor as a means of demonstrating compliance with subsection (1).”\n(6)After section 71 insert—\n“Codes of conduct U.K. 71A Codes of conduct (1)The Commissioner must encourage expert public bodies to produce codes of conduct intended to contribute to compliance with this Part.\n(2)Under subsection (1), the Commissioner must, among other things, encourage the production of codes which take account of the specific features of the various processing sectors.\n(3)For the purposes of this section—\n(a)“public body” means a body or other person whose functions are, or include, functions of a public nature, and\n(b)a public body is “expert” if, in the Commissioner’s opinion, the body has the knowledge and experience needed to produce a code of conduct described in subsection (1).\n(4)A code of conduct described in subsection (1) may, for example, make provision with regard to—\n(a)lawful and fair processing;\n(b)the collection of personal data;\n(c)the information provided to the public and to data subjects;\n(d)the exercise of the rights of data subjects;\n(e)the measures and procedures referred to in sections 56, 57 and 62;\n(f)the notification of personal data breaches to the Commissioner and the communication of personal data breaches to data subjects;\n(g)the transfer of personal data to third countries or international organisations;\n(h)out-of-court proceedings and other dispute resolution procedures for resolving disputes between controllers and data subjects with regard to processing.\n(5)The Commissioner must encourage expert public bodies to submit codes of conduct described in subsection (1) to the Commissioner in draft.\n(6)Where an expert public body does so, the Commissioner must—\n(a)provide the body with an opinion on whether the code correctly reflects the requirements of this Part,\n(b)decide whether to approve the code, and\n(c)if the code is approved, register and publish the code.\n(7)Subsections (5) and (6) apply in relation to amendments of a code of conduct that is for the time being approved under this section as they apply in relation to a code.”\nCommencement Information\nInternational transfers of personal data U.K. 85 Transfers of personal data to third countries and international organisations U.K. (1)Schedule 7 amends Chapter 5 of the UK GDPR (general processing and transfers of personal data to third countries and international organisations).\n(2)Schedule 8 amends Chapter 5 of Part 3 of the 2018 Act (law enforcement processing and transfers of personal data to third countries and international organisations).\n(3)In Schedule 9—\n(a)Part 1 contains minor and consequential amendments, and\n(b)Part 2 contains transitional provision.\nCommencement Information\nSafeguards for processing for research etc purposes U.K. 86 Safeguards for processing for research etc purposes U.K. (1)The UK GDPR is amended in accordance with subsections (2) to (4).\n(2)After Chapter 8 insert—\n“CHAPTER 8A U.K.Safeguards for processing for research, archiving or statistical purposes Article 84A Research, archives and statistics 1.This Chapter makes provision about the processing of personal data—\n(a)for the purposes of scientific research or historical research,\n(b)for the purposes of archiving in the public interest, or\n(c)for statistical purposes.\n2.Those purposes are referred to in this Chapter as “RAS purposes”.\nArticle 84B Additional requirements when processing for RAS purposes 1.Personal data may only be processed for RAS purposes if—\n(a)the processing consists of the collection of the personal data (whether from the data subject or otherwise),\n(b)the processing is carried out in order to convert the personal data into information which can be processed in a manner which does not permit the identification of a data subject, or\n(c)without the processing, the RAS purposes cannot be fulfilled.\n2.Processing of personal data for RAS purposes must be carried out subject to appropriate safeguards for the rights and freedoms of the data subject.\nArticle 84C Appropriate safeguards 1.This Article makes provision about when the requirement under Article 84B(2) for processing of personal data to be carried out subject to appropriate safeguards is satisfied.\n2.The requirement is not satisfied if the processing is likely to cause substantial damage or substantial distress to a data subject to whom the personal data relates.\n3.The requirement is not satisfied if the processing is carried out for the purposes of measures or decisions with respect to a particular data subject to whom the personal data relates, except where the purposes for which the processing is carried out include the purposes of approved medical research.\n4.The requirement is only satisfied if the safeguards include technical and organisational measures for the purpose of ensuring respect for the principle of data minimisation (see Article 5(1)(c)), such as, for example, pseudonymisation.\n5.In this Article—\n“approved medical research” means medical research carried out by a person who has approval to carry out that research from— (a)\na research ethics committee recognised or established by the Health Research Authority under Chapter 2 of Part 3 of the Care Act 2014, or (b)\na body appointed by any of the following for the purpose of assessing the ethics of research involving individuals—\n(i)\nthe Secretary of State, the Scottish Ministers, the Welsh Ministers or a Northern Ireland department; (ii)\na relevant NHS body; (iii)\nUnited Kingdom Research and Innovation or a body that is a Research Council for the purposes of the Science and Technology Act 1965; (iv)\nan institution that is a research institution for the purposes of Chapter 4A of Part 7 of the Income Tax (Earnings and Pensions) Act 2003 (see section 457 of that Act);\n“relevant NHS body” means— (a)\nan NHS trust or NHS foundation trust in England, (b)\nan NHS trust or Local Health Board in Wales, (c)\na Health Board or Special Health Board constituted under section 2 of the National Health Service (Scotland) Act 1978, (d)\nthe Common Services Agency for the Scottish Health Service, or (e)\nany of the health and social care bodies in Northern Ireland falling within paragraphs (b) to (e) of section 1(5) of the Health and Social Care (Reform) Act (Northern Ireland) 2009 (c. 1 (N.I.)) .\nArticle 84D Appropriate safeguards: further provision 1.The Secretary of State may by regulations make further provision about when the requirement for appropriate safeguards under Article 84B(2) is, or is not, satisfied.\n2.Regulations under this Article may not amend or revoke Article 84C(2), (3) or (4) (but may change the meaning of “approved medical research” for the purposes of Article 84C).\n3.Regulations under this Article are subject to the affirmative resolution procedure.”\n(3)In the heading of Chapter 9, after “relating to” insert “other”.\n(4)Omit Article 89 (safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes).\n(5)The 2018 Act is amended in accordance with subsections (6) and (7).\n(6)Omit section 19 (processing for archiving, research and statistical purposes: safeguards) and the italic heading before it.\n(7)In section 41(1) (safeguards: archiving), for “necessary” substitute “carried out”.\nCommencement Information\n87 Section 86: consequential provision U.K. (1)In the UK GDPR—\n(a)in Article 5(1)(e) (storage limitation), for “Article 89(1)” to “data subject” substitute “Article 84B”,\n(b)in Article 9(2)(j) (processing of special categories of personal data), for “in accordance with Article 89(1) (as supplemented by section 19 of the 2018 Act)” substitute “, is carried out in accordance with Article 84B and is”,\n(c)in Article 17(3)(d) (right to erasure), for “Article 89(1)” substitute “Article 84B”, and\n(d)in Article 21(6) (right to object), omit “pursuant to Article 89(1)”.\n(2)In the 2018 Act—\n(a)in section 24(4) (manual unstructured data held by FOI public authorities), after paragraph (b) insert—\n“(ba)Chapter 8A (safeguards for processing for research, archiving or statistical purposes);”,\n(b)in paragraph 4(b) of Schedule 1 (special categories of personal data and criminal convictions etc data: research etc), for “Article 89(1) of the UK GDPR (as supplemented by section 19)” substitute “Article 84B of the UK GDPR”, and\n(c)in Schedule 2 (exemptions etc from the UK GDPR)—\n(i)in paragraph 27(3)(a) (research and statistics), for “Article 89(1) of the UK GDPR (as supplemented by section 19)” substitute “Article 84B of the UK GDPR”, and\n(ii)in paragraph 28(3) (archiving), for “Article 89(1) of the UK GDPR (as supplemented by section 19)” substitute “Article 84B of the UK GDPR”.\n(3)In section 279(2) of the Mental Health (Care and Treatment) (Scotland) Act 2003 (asp 13) (information for research), for “Article 89(1) of the UK GDPR (archiving in the public interest, scientific or historical research and statistics)” substitute “Article 84A of the UK GDPR (research, archives and statistics)”.\nCommencement Information\nNational security U.K. 88 National security exemption U.K. (1)The 2018 Act is amended in accordance with subsections (2) to (10).\n(2)In section 26(2)(f) (national security and defence exemption), before sub-paragraph (i) insert—\n“(ai)Article 77 (right to lodge a complaint with the Commissioner);”.\n(3)In section 44 (controller’s general duties to provide information to data subject)—\n(a)in subsection (4), omit paragraph (d) (grounds for restricting information provided: national security),\n(b)in subsection (5), after “restricted” insert “under subsection (4)”, and\n(c)in subsection (7)(a), after “subsection (2)” insert “in reliance on subsection (4)”.\n(4)In section 45 (right of access by the data subject)—\n(a)in subsection (4), omit paragraph (d) (grounds for restricting information provided: national security),\n(b)in subsection (5), after “restricted” insert “under subsection (4)”, and\n(c)in subsection (7)(a), after “subsection (1)” insert “in reliance on subsection (4)”.\n(5)In section 48 (requests by data subject for rectification or erasure of personal data)—\n(a)in subsection (3), omit paragraph (d) (grounds for restricting information provided: national security),\n(b)in subsection (4)—\n(i)for “(1)” substitute “(1)(b)(i)”, and\n(ii)after “restricted” insert “under subsection (3)”, and\n(c)in subsection (6)(a), after “subsection (1)(b)(i)” insert “in reliance on subsection (3)”.\n(6)In section 68(7) (communication of a personal data breach to the data subject: grounds for restricting information provided), omit paragraph (d) (national security).\n(7)In Chapter 6 of Part 3 (law enforcement processing: supplementary), before section 79 insert—\n“78A National security exemption (1)A provision mentioned in subsection (2) does not apply to personal data processed for law enforcement purposes if exemption from the provision is required for the purposes of safeguarding national security.\n(2)The provisions are—\n(a)Chapter 2 of this Part (principles), except for the provisions listed in subsection (3);\n(b)Chapter 3 of this Part (rights of the data subject);\n(c)in Chapter 4 of this Part—\n(i)section 67 (notification of personal data breach to the Commissioner);\n(ii)section 68 (communication of personal data breach to the data subject);\n(d)Chapter 5 of this Part (transfers of personal data to third countries etc), except for the provisions listed in subsection (4);\n(e)in Part 5—\n(i)section 119 (inspection in accordance with international obligations);\n(ii)in Schedule 13 (other general functions of the Commissioner), paragraphs 1(1)(a) and (g) and 2;\n(f)in Part 6—\n(i)sections 142 to 154 and Schedule 15 (Commissioner’s notices and powers of entry and inspection);\n(ii)sections 170 to 173 (offences relating to personal data);\n(g)in Part 7, section 187 (representation of data subjects).\n(3)The provisions of Chapter 2 of this Part (principles) which are excepted from the list in subsection (2) are—\n(a)section 35(1) (the first data protection principle) so far as it requires processing of personal data to be lawful;\n(b)section 35(2) to (5) (lawfulness of processing and restrictions on sensitive processing);\n(c)section 42 (safeguards: sensitive processing);\n(d)Schedule 8 (conditions for sensitive processing).\n(4)The provisions of Chapter 5 of this Part (transfers of personal data to third countries etc) which are excepted from the list in subsection (2) are—\n(a)the following provisions of section 73—\n(i)subsection (1)(a) (conditions for transfer), so far as it relates to the condition in subsection (2) of that section, and subsection (2) (transfer must be necessary for a law enforcement purpose);\n(ii)subsections (1)(b), (5) and (6) (conditions for transfer of personal data originally made available by a member State);\n(b)section 78 (subsequent transfers).”\n(8)In section 79 (national security: certificate)—\n(a)omit subsections (1) to (3),\n(b)after subsection (3) insert—\n“(3A)Subject to subsection (5), a certificate signed by a Minister of the Crown certifying that exemption from all or any of the provisions listed in section 78A(2) is, or at any time was, required in relation to any personal data for the purposes of safeguarding national security is conclusive evidence of that fact.”,\n(c)in subsection (4), for “subsection (1)” substitute “subsection (3A)—\n“(a)may identify the personal data to which it applies by means of a general description, and\n(b)”,\n(d)in subsection (5), for “subsection (1)” substitute “subsection (3A)”,\n(e)in subsection (7)—\n(i)for “a restriction falls within a general description in a certificate issued under subsection (1)” substitute “a certificate under subsection (3A) which identifies the personal data to which it applies by means of a general description applies to any personal data”, and\n(ii)for “the restriction does not fall within that description” substitute “the certificate does not apply to the personal data in question”,\n(f)in subsection (8)—\n(i)for “the restriction” substitute “the certificate”, and\n(ii)for “to fall within the general description” substitute “so to apply”,\n(g)in subsection (10), for “subsection (1)” substitute “subsection (3A)”,\n(h)in subsection (11), for “subsection (1)” substitute “subsection (3A)”,\n(i)in subsection (12), for “subsection (1)” substitute “subsection (3A)”, and\n(j)omit subsection (13).\n(9)In section 110(2) (intelligence services processing: national security)—\n(a)in paragraph (a), after “Chapter 2” insert “of this Part”,\n(b)in paragraph (b), after “Chapter 3” insert “of this Part”, and\n(c)in paragraph (c), after “Chapter 4” insert “of this Part”.\n(10)In section 186(3) (data subject’s rights etc: exceptions), after paragraph (c) insert—\n“(ca)in Part 3 of this Act, section 78A, and”.\n(11)In the provisions listed in subsection (12), for “subsection (4) of that section” substitute “section 45(4) or 78A of that Act”.\n(12)The provisions are—\n(a)section 40(4A)(b) and (5B)(d) of the Freedom of Information Act 2000 (personal data which is exempt information);\n(b)section 38(3A)(b) of the Freedom of Information (Scotland) Act 2002 (asp 13) (personal data which is exempt information);\n(c)regulation 13(3A)(b) and (5B)(d) of the Environmental Information Regulations 2004 (S.I. 2004/3391 ) (restriction on disclosure of personal data);\n(d)regulation 11(4A)(b) of the Environmental Information (Scotland) Regulations 2004 (S.S.I. 2004/520 ) (restriction on disclosure of personal data);\n(e)regulation 45(1C)(b) of the Civil Contingencies Act 2004 (Contingency Planning) Regulations 2005 (S.I. 2005/2042 ) (personal data which is sensitive information);\n(f)regulation 39(1C)(b) of the Civil Contingencies Act 2004 (Contingency Planning) (Scotland) Regulations 2005 (S.S.I. 2005/494 ) (personal data which is sensitive information).\nCommencement Information\nIntelligence services U.K. 89 Joint processing by intelligence services and competent authorities U.K. (1)Part 4 of the 2018 Act (intelligence services processing) is amended as follows.\n(2)In section 82 (processing to which Part 4 applies)—\n(a)before subsection (1) insert—\n“(A1)This Part—\n(a)applies to processing of personal data by an intelligence service, and\n(b)applies to processing of personal data by a qualifying competent authority where the processing is the subject of a designation notice that is for the time being in force (see sections 82A to 82E).”,\n(b)in subsection (1)—\n(i)after “applies” insert “only”,\n(ii)in paragraph (a), for “the processing by an intelligence service” substitute “processing”, and\n(iii)in paragraph (b), for “the processing by an intelligence service” substitute “processing”,\n(c)after subsection (2) insert—\n“(2A)In this Part—\n“competent authority” has the same meaning as in Part 3;\n“qualifying competent authority” means a competent authority specified or described in regulations made by the Secretary of State.”, and\n(d)after subsection (3) insert—\n“(4)Regulations under this section are subject to the affirmative resolution procedure.”\n(3)After section 82 insert—\n“82A Designation of processing by a qualifying competent authority (1)For the purposes of this Part, the Secretary of State may give a notice designating processing of personal data by a qualifying competent authority (a “designation notice”) where—\n(a)an application for designation of the processing is made in accordance with this section, and\n(b)the Secretary of State considers that designation of the processing is required for the purposes of safeguarding national security.\n(2)The Secretary of State may only designate processing by a qualifying competent authority that is carried out by the authority as a joint controller with at least one intelligence service.\n(3)The Secretary of State may not designate processing by a qualifying competent authority that consists of the transfer of personal data to—\n(a)a country or territory outside the United Kingdom, or\n(b)an international organisation.\n(4)A designation notice must—\n(a)specify or describe the processing and qualifying competent authority that are designated, and\n(b)be given to the applicants for the designation (and see also section 82D).\n(5)An application for designation of processing of personal data by a qualifying competent authority must be made jointly by—\n(a)the qualifying competent authority, and\n(b)the intelligence service with which the processing is to be carried out.\n(6)An application may be made in respect of more than one qualifying competent authority and in respect of processing with more than one intelligence service.\n(7)The application must—\n(a)describe the processing, including the intended purposes and means of processing, and\n(b)explain why the applicants consider that designation is required for the purposes of safeguarding national security.\n(8)Before giving a designation notice, the Secretary of State must consult the Commissioner.\n(9)In this section, “joint controller”, in relation to processing of personal data, means a controller whose responsibilities for compliance with this Part in relation to the processing are determined in an arrangement under section 104.\n82B Duration of designation notice (1)A designation notice must state when it comes into force.\n(2)A designation notice ceases to be in force at the earliest of the following times—\n(a)at the end of the period of 5 years beginning when the notice comes into force;\n(b)(if relevant) at the end of a shorter period specified in the notice;\n(c)when the notice is withdrawn under section 82C.\n(3)The Secretary of State may give a further designation notice in respect of processing that is, or has been, the subject of a previous designation notice.\n82C Review and withdrawal of designation notice (1)Subsections (2) to (4) apply where processing is the subject of a designation notice for the time being in force.\n(2)A person who applied for the designation of the processing must notify the Secretary of State without undue delay if the person considers that the designation is no longer required for the purposes of safeguarding national security.\n(3)A person who applied for the designation of the processing must, on a request from the Secretary of State, provide—\n(a)a description of the processing that is being, or is intended to be, carried out in reliance on the notice, and\n(b)an explanation of why the person considers that designation of the processing continues to be required for the purposes of safeguarding national security.\n(4)The Secretary of State must at least annually—\n(a)review each designation notice that is for the time being in force, and\n(b)consider whether designation of the processing which is the subject of the notice continues to be required for the purposes of safeguarding national security.\n(5)The Secretary of State—\n(a)may withdraw a designation notice by giving a further notice (a “withdrawal notice”) to the persons who applied for the designation, and\n(b)must give a withdrawal notice if the Secretary of State considers that designation of some or all of the processing to which the notice applies is no longer required for the purposes of safeguarding national security (whether as a result of a review required under subsection (4) or otherwise).\n(6)A withdrawal notice must—\n(a)withdraw the designation notice completely, and\n(b)state when it comes into force.\n(7)In determining when a withdrawal notice required under subsection (5)(b) comes into force, the Secretary of State must consider—\n(a)the desirability of the processing ceasing to be designated as soon as possible, and\n(b)where relevant, the time needed to effect an orderly transition to new arrangements for the processing of personal data.\n82D Records of designation notices (1)Where the Secretary of State gives a designation notice—\n(a)the Secretary of State must send a copy of the notice to the Commissioner, and\n(b)the Commissioner must publish a record of the notice.\n(2)The record must contain—\n(a)the Secretary of State’s name,\n(b)the date on which the notice was given,\n(c)the date on which the notice ceases to have effect (if not previously withdrawn), and\n(d)subject to subsection (3), the rest of the text of the notice.\n(3)The Commissioner must not publish the text, or a part of the text, of the notice if—\n(a)the Secretary of State has determined that publishing the text or that part of the text—\n(i)would be against the interests of national security,\n(ii)would be contrary to the public interest, or\n(iii)might jeopardise the safety of any person, and\n(b)the Secretary of State has notified the Commissioner of that determination.\n(4)The Commissioner must keep the record of the notice available to the public while the notice is in force.\n(5)Where the Secretary of State gives a withdrawal notice, the Secretary of State must send a copy of the notice to the Commissioner.\n82E Appeal against designation notice (1)A person directly affected by a designation notice may appeal to the Tribunal against the notice.\n(2)If, on an appeal under this section, the Tribunal finds that, applying the principles applied by a court on an application for judicial review, the Secretary of State did not have reasonable grounds for giving the notice, the Tribunal may—\n(a)allow the appeal, and\n(b)quash the notice.”\nCommencement Information\n90 Joint processing: consequential amendments U.K. (1)The 2018 Act is amended in accordance with subsections (2) to (9).\n(2)In section 1(5) (overview: Part 4), at the end insert “(and certain processing carried out by competent authorities jointly with the intelligence services)”.\n(3)In section 29 (processing to which Part 3 applies), after subsection (1) insert—\n“(1A)This Part does not apply to processing to which Part 4 applies by virtue of a designation notice (see section 82A).”\n(4)In section 83 (meaning of “controller” and “processor” in Part 4)—\n(a)before subsection (1) insert—\n“(A1)For the purposes of this Part—\n(a)an intelligence service is the “controller” in relation to the processing of personal data if it satisfies subsection (1) alone or jointly with others, and\n(b)a qualifying competent authority is the “controller” in relation to the processing of personal data that is the subject of a designation notice that is for the time being in force if the authority satisfies subsection (1) jointly with others.”,\n(b)in subsection (1), for the words before paragraph (a) substitute “This subsection is satisfied by a person who—”, and\n(c)in subsection (2), for “intelligence service on which” substitute “person on whom”.\n(5)In section 84 (other definitions)—\n(a)after subsection (2) insert—\n“(2A)“Designation notice” has the meaning given in section 82A.”, and\n(b)before subsection (7) insert—\n“(6B)“Withdrawal notice” has the meaning given in section 82C.”\n(6)In section 104(1) (joint controllers), for “intelligence services” substitute “controllers”.\n(7)In section 202(1)(a)(i) (proceedings in the First-tier Tribunal: contempt) after “79,” insert “82E,”.\n(8)In section 203(1) (Tribunal Procedure Rules), after “79,” insert “82E,”.\n(9)In section 206 (index of defined expressions), in the Table—\n(a)in the entry for “competent authority”—\n(i)for “Part 3” substitute “Parts 3 and 4”, and\n(ii)for “section 30” substitute “sections 30 and 82”, and\n(b)at the appropriate places insert—\n“designation notice (in Part 4)section 84”;\n“qualifying competent authority (in Part 4)section 82”;\n“withdrawal notice (in Part 4)section 84”.\n(10)In section 199(2)(a) of the Investigatory Powers Act 2016 (bulk personal datasets: meaning of “personal data”), after “section 82(1) of that Act” insert “by an intelligence service”.\nCommencement Information\nInformation Commissioner’s role U.K. 91 Duties of the Commissioner in carrying out functions U.K. (1)The 2018 Act is amended in accordance with subsections (2) to (4).\n(2)Omit section 2(2) (duty of Commissioner when carrying out functions).\n(3)After section 120 insert—\n“Duties in carrying out functions U.K. 120A Principal objective It is the principal objective of the Commissioner, in carrying out functions under the data protection legislation—\n(a)to secure an appropriate level of protection for personal data, having regard to the interests of data subjects, controllers and others and matters of general public interest, and\n(b)to promote public trust and confidence in the processing of personal data.\n120B Duties in relation to functions under the data protection legislation In carrying out functions under the data protection legislation, the Commissioner must have regard to such of the following as appear to the Commissioner to be relevant in the circumstances—\n(a)the desirability of promoting innovation;\n(b)the desirability of promoting competition;\n(c)the importance of the prevention, investigation, detection and prosecution of criminal offences;\n(d)the need to safeguard public security and national security;\n(e)the fact that children merit specific protection with regard to their personal data because they may be less aware of the risks and consequences associated with processing of personal data and of their rights in relation to such processing.\n120C Strategy (1)The Commissioner must prepare a strategy for carrying out the Commissioner’s functions under the data protection legislation in accordance with the Commissioner’s duties under—\n(a)sections 120A and 120B,\n(b)section 108 of the Deregulation Act 2015 (exercise of regulatory functions: economic growth), and\n(c)section 21 of the Legislative and Regulatory Reform Act 2006 (exercise of regulatory functions: principles).\n(2)The Commissioner must—\n(a)review the strategy from time to time, and\n(b)revise the strategy as appropriate.\n(3)The Commissioner must publish the strategy and any revised strategy.\n120D Duty to consult other regulators (1)The Commissioner must, at such times as the Commissioner considers appropriate, consult the persons mentioned in subsection (2) about how the manner in which the Commissioner exercises functions under the data protection legislation may affect economic growth, innovation and competition.\n(2)The persons are—\n(a)such persons exercising regulatory functions as the Commissioner considers appropriate;\n(b)such other persons as the Commissioner considers appropriate.\n(3)In this section, “regulatory function” has the meaning given by section 111 of the Deregulation Act 2015.”\n(4)In section 139 (reporting to Parliament), after subsection (1) insert—\n“(1A)In connection with the Commissioner’s functions under the data protection legislation, the report must contain (among other things)—\n(a)a review of what the Commissioner has done during the reporting period to comply with the duties under—\n(i)sections 120A and 120B,\n(ii)section 108 of the Deregulation Act 2015, and\n(iii)section 21 of the Legislative and Regulatory Reform Act 2006,\nincluding a review of the operation of the strategy prepared and published under section 120C;\n(b)a review of what the Commissioner has done during the reporting period to comply with the duty under section 120D.\n(1B)In subsection (1A), “the reporting period” means the period to which the report relates.”\n(5)The Information Commissioner must prepare and publish a strategy in accordance with section 120C of the 2018 Act before the end of the period of 18 months beginning with the day on which this section comes into force.\nCommencement Information\n92 Codes of practice for the processing of personal data U.K. (1)The 2018 Act is amended in accordance with subsections (2) to (6).\n(2)After section 124 insert—\n“124A Other codes of practice (1)The Commissioner must prepare appropriate codes of practice giving guidance as to good practice in the processing of personal data if required to do so by regulations made by the Secretary of State.\n(2)Regulations under this section—\n(a)must describe the personal data or processing to which the code of practice is to relate, and\n(b)may describe the persons or classes of person to whom it is to relate.\n(3)Where a code under this section is in force, the Commissioner may prepare amendments of the code or a replacement code.\n(4)Before preparing a code or amendments under this section, the Commissioner must consult the Secretary of State and such of the following as the Commissioner considers appropriate—\n(a)trade associations;\n(b)data subjects;\n(c)persons who appear to the Commissioner to represent the interests of data subjects.\n(5)A code under this section may include transitional provision or savings.\n(6)Regulations under this section are subject to the negative resolution procedure.\n(7)In this section—\n“good practice in the processing of personal data” means such practice in the processing of personal data as appears to the Commissioner to be desirable having regard to the interests of data subjects and others, including compliance with the requirements of the data protection legislation;\n“trade association” includes a body representing controllers or processors.”\n(3)In section 125 (approval of codes prepared under sections 121 to 124)—\n(a)in the heading, for “124” substitute “124A”,\n(b)in subsection (1), for “or 124” substitute “, 124 or 124A”,\n(c)in subsection (3), for “or 124” substitute “, 124 or 124A”,\n(d)for subsection (5) substitute—\n“(5)If the Commissioner is prevented by subsection (3) from issuing a code that is not a replacement code, the Commissioner must prepare another version of the code.”, and\n(e)in subsection (9), for “or 124” substitute “, 124 or 124A”.\n(4)In section 126 (publication and review of codes issued under section 125(4)), in subsection (4), for “or 124(2)” substitute “, 124(2) or 124A(3)”.\n(5)Omit section 128 (other codes of practice).\n(6)In section 129 (consensual audits), in subsection (3), for “128” substitute “124A”.\n(7)In section 19AC of the Registration Service Act 1953 (code of practice), in subsection (11), for “128” substitute “124A”.\n(8)In the Statistics and Registration Service Act 2007—\n(a)in section 45 (information held by HMRC), in subsection (4A), for “128” substitute “124A”,\n(b)in section 45A (information held by other public authorities), in subsection (8), for “128” substitute “124A”,\n(c)in section 45E (further provisions about powers in sections 45B, 45C and 45D), in subsection (16), for “128” substitute “124A”, and\n(d)in section 53A (disclosure by the Board to devolved administrations), in subsection (9), for “128” substitute “124A”.\n(9)In the Digital Economy Act 2017—\n(a)in section 43 (code of practice), in subsection (13), for “128” substitute “124A”,\n(b)in section 52 (code of practice), in subsection (13), for “128” substitute “124A”,\n(c)in section 60 (code of practice), in subsection (13), for “128” substitute “124A”, and\n(d)in section 70 (code of practice), in subsection (15), for “128” substitute “124A”.\nCommencement Information\n93 Codes of practice: panels and impact assessments U.K. In the 2018 Act, after section 124A (inserted by section 92 of this Act) insert—\n“124B Panels to consider codes of practice (1)This section applies where a code is prepared under section 121, 122, 123, 124 or 124A, subject to subsection (11).\n(2)The Commissioner must establish a panel of individuals to consider the code.\n(3)The panel must consist of—\n(a)individuals the Commissioner considers have expertise in the subject matter of the code, and\n(b)individuals the Commissioner considers—\n(i)are likely to be affected by the code, or\n(ii)represent persons likely to be affected by the code.\n(4)Before the panel begins to consider the code, the Commissioner must—\n(a)publish the code in draft, and\n(b)publish a statement that—\n(i)states that a panel has been established to consider the code,\n(ii)identifies the members of the panel,\n(iii)explains the process by which they were selected, and\n(iv)explains the reasons for their selection.\n(5)Where at any time it appears to the Commissioner that a member of the panel is not willing or able to serve as a member of the panel, the Commissioner may select another individual to be a member of the panel.\n(6)Where the Commissioner selects an individual to be a member of the panel under subsection (5), the Commissioner must publish a statement that—\n(a)identifies the member of the panel,\n(b)explains the process by which the member was selected, and\n(c)explains the reasons for the member’s selection.\n(7)The Commissioner must make arrangements—\n(a)for the members of the panel to consider the code with one another (whether in person or otherwise), and\n(b)for the panel to prepare and submit to the Commissioner a report on the code within such reasonable period as is determined by the Commissioner.\n(8)If the panel submits to the Commissioner a report on the code within the period determined by the Commissioner, the Commissioner must as soon as reasonably practicable—\n(a)make any alterations to the code that the Commissioner considers appropriate in the light of the report, and\n(b)publish—\n(i)the code in draft,\n(ii)the report or a summary of it, and\n(iii)in a case where a recommendation in the report to alter the code has not been accepted by the Commissioner, an explanation of why it has not been accepted.\n(9)The Commissioner may pay remuneration and expenses to the members of the panel.\n(10)This section applies in relation to amendments prepared under section 121, 122, 123, 124 or 124A as it applies in relation to codes prepared under those sections, subject to subsection (11).\n(11)The Secretary of State may by regulations provide that this section does not apply, or applies with modifications, in the case of—\n(a)a code prepared under section 124A, or\n(b)an amendment of such a code,\nthat is specified or described in the regulations.\n(12)Regulations under this section are subject to the negative resolution procedure.\n124C Impact assessments for codes of practice (1)Where a code is prepared under section 121, 122, 123, 124 or 124A, the Commissioner must carry out and publish an assessment of—\n(a)who would be likely to be affected by the code, and\n(b)the effect the code would be likely to have on them.\n(2)This section applies in relation to amendments prepared under section 121, 122, 123, 124 or 124A as it applies in relation to codes prepared under those sections.”\nCommencement Information\n94 Manifestly unfounded or excessive requests to the Commissioner U.K. (1)The 2018 Act is amended in accordance with subsections (2) and (3).\n(2)In section 135 (manifestly unfounded or excessive requests made to the Commissioner)—\n(a)before subsection (1) insert—\n“(A1)This section makes provision about cases in which a request made to the Commissioner, to which the Commissioner is required or authorised to respond under the data protection legislation, is manifestly unfounded or excessive.”,\n(b)in subsection (1) omit the words from the beginning to “excessive,”,\n(c)after subsection (1) insert—\n“(1A)In subsection (1)—\n(a)the reference in paragraph (a) to charging a reasonable fee is, in a case in which section 134 is relevant, a reference to doing so under that section, and\n(b)paragraph (b) is not to be read as implying anything about whether the Commissioner may refuse to act on requests that are neither manifestly unfounded nor excessive.”,\n(d)in subsection (3), for “(1)” substitute “(A1)”,\n(e)omit subsection (4), and\n(f)after that subsection insert—\n“(5)Article 57(3) of the UK GDPR (performance of Commissioner’s tasks generally to be free of charge for data subject) has effect subject to this section.”\n(3)In section 136(1) (guidance about fees), omit paragraph (b) and the “or” before it.\n(4)In Article 57 of the UK GDPR (Commissioner’s tasks), omit paragraph 4.\nCommencement Information\n95 Analysis of performance U.K. In the 2018 Act, after section 139 insert—\n“139A Analysis of performance (1)The Commissioner must prepare and publish an analysis of the Commissioner’s performance using key performance indicators.\n(2)The analysis must be prepared and published at least annually.\n(3)In this section, “key performance indicators” means factors by reference to which the Commissioner’s performance can be measured most effectively.\nDocuments and notices”. Commencement Information\n96 Notices from the Commissioner U.K. (1)The 2018 Act is amended in accordance with subsections (2) and (3).\n(2)Omit section 141 (notices from the Commissioner).\n(3)After that section insert—\n“141A Notices from the Commissioner (1)This section applies in relation to a notice authorised or required by this Act to be given to a person by the Commissioner.\n(2)The notice may be given to the person by—\n(a)delivering it by hand to a relevant individual,\n(b)leaving it at the person’s proper address,\n(c)sending it by post to the person at that address, or\n(d)sending it by email to the person’s email address.\n(3)A “relevant individual” means—\n(a)in the case of a notice to an individual, that individual;\n(b)in the case of a notice to a body corporate (other than a partnership), an officer of that body;\n(c)in the case of a notice to a partnership, a partner in the partnership or a person who has the control or management of the partnership business;\n(d)in the case of a notice to an unincorporated body (other than a partnership), a member of its governing body.\n(4)For the purposes of subsection (2)(b) and (c), and section 7 of the Interpretation Act 1978 (services of documents by post) in its application to those provisions, a person’s proper address is—\n(a)in a case where the person has specified an address as one at which the person, or someone acting on the person’s behalf, will accept service of notices or other documents, that address;\n(b)in any other case, the address determined in accordance with subsection (5).\n(5)The address is—\n(a)in a case where the person is a body corporate with a registered office in the United Kingdom, that office;\n(b)in a case where paragraph (a) does not apply and the person is a body corporate, partnership or unincorporated body with a principal office in the United Kingdom, that office;\n(c)in any other case, an address in the United Kingdom at which the Commissioner believes, on reasonable grounds, that the notice will come to the attention of the person.\n(6)A person’s email address is—\n(a)an email address published for the time being by that person as an address for contacting that person, or\n(b)if there is no such published address, an email address by means of which the Commissioner believes, on reasonable grounds, that the notice will come to the attention of that person.\n(7)A notice sent by email is treated as given 48 hours after it was sent, unless the contrary is proved.\n(8)In this section, “officer”, in relation to a body corporate, means a director, manager, secretary or other similar officer of the body.\n(9)This section does not limit other lawful means of giving a notice.”\n(4)In Schedule 2 to the Electronic Identification and Trust Services for Electronic Transactions Regulations 2016 (S.I. 2016/696 ) (Commissioner’s enforcement powers), in paragraph 1(b), for “141” substitute “141A”.\nCommencement Information\nEnforcement U.K. 97 Power of the Commissioner to require documents U.K. (1)The 2018 Act is amended as follows.\n(2)In section 142 (information notices)—\n(a)in subsection (1)—\n(i)in paragraph (a), after “information” insert “or documents”, and\n(ii)in paragraph (b), after “information” insert “or documents”,\n(b)in subsection (2)(b), after “information” insert “or documents”,\n(c)in subsection (3)—\n(i)in paragraph (a), after “information”, in both places it occurs, insert “or documents”,\n(ii)in paragraph (b), after “information” insert “or documents”,\n(iii)in paragraph (c), after “information” insert “or documents”, and\n(iv)in paragraph (d), after “information” insert “or documents”,\n(d)in subsection (5), after “information”, in the second place it occurs, insert “or documents”,\n(e)in subsection (6), after “information”, in the second place it occurs, insert “or documents”, and\n(f)in subsection (7)—\n(i)in paragraph (a), for “is” substitute “or documents are”, and\n(ii)in the words after paragraph (b), after “information” insert “or documents”.\n(3)In section 143 (information notices: restrictions)—\n(a)in subsection (1)(b)(ii), for “is” substitute “or documents are”,\n(b)in subsection (2), after “information”, in the second place it occurs, insert “or documents”,\n(c)in subsection (3), for “in respect” substitute “or documents to the extent that requiring the person to do so would result in the disclosure”,\n(d)in subsection (4), for “in respect” substitute “or documents to the extent that requiring the person to do so would result in the disclosure”, and\n(e)in subsection (6), after “information”, in the second place it occurs, insert “or documents”.\n(4)In section 145 (information orders)—\n(a)in subsection (2)—\n(i)in paragraph (a), after “information”, in the first place it occurs, insert “or documents”, and\n(ii)in paragraph (b), after “information” insert “or documents”, and\n(b)in subsection (3)—\n(i)in paragraph (a), after “information” insert “or documents”,\n(ii)in paragraph (b), after “information” insert “or documents”, and\n(iii)in paragraph (c), after “information” insert “or documents”.\n(5)In section 148(1) (destroying or falsifying information and documents etc), in paragraph (a), after “information”, in the second place it occurs, insert “or a document”.\n(6)In section 160 (guidance about regulatory action), in subsection (3)(a), for “is” substitute “or documents are”.\n(7)In Schedule 17 (review of processing of personal data for the purposes of journalism), in paragraph 2(2) (information notices)—\n(a)in paragraph (a), for “is” substitute “or documents are”, and\n(b)in the words after paragraph (b), after “information” insert “or documents”.\nCommencement Information\n98 Power of the Commissioner to require a report U.K. (1)The 2018 Act is amended as follows.\n(2)In section 146 (assessment notices)—\n(a)in subsection (2), after paragraph (i), insert—\n“(j)make arrangements for an approved person to prepare a report on a specified matter;\n(k)provide to the Commissioner a report prepared in pursuance of such arrangements.”,\n(b)after subsection (3) insert—\n“(3A)An assessment notice that requires a controller or processor to make arrangements for an approved person to prepare a report may require the arrangements to include specified terms as to—\n(a)the preparation of the report;\n(b)the contents of the report;\n(c)the form in which the report is to be provided;\n(d)the date by which the report is to be completed.”,\n(c)after subsection (11) insert—\n“(11A)Where the Commissioner gives an assessment notice that requires the controller or processor to make arrangements for an approved person to prepare a report, the controller or processor is liable for the payment of the approved person’s remuneration and expenses under the arrangements.”, and\n(d)in subsection (12), before the definition of “domestic premises” insert—\n““approved person”, in relation to a report, means a person approved to prepare the report in accordance with section 146A;”. (3)After section 146 insert—\n“146A Assessment notices: approval of person to prepare report etc (1)This section applies where an assessment notice requires a controller or processor to make arrangements for an approved person to prepare a report.\n(2)The controller or processor must, within such period as is specified in the assessment notice, nominate to the Commissioner a person to prepare the report.\n(3)If the Commissioner is satisfied that the nominated person is a suitable person to prepare the report, the Commissioner must by written notice to the controller or processor approve the nominated person to prepare the report.\n(4)If the Commissioner is not satisfied that the nominated person is a suitable person to prepare the report, the Commissioner must by written notice to the controller or processor—\n(a)inform the controller or processor that the Commissioner has decided not to approve the nominated person to prepare the report,\n(b)inform the controller or processor of the reasons for that decision, and\n(c)approve a person who the Commissioner is satisfied is a suitable person to prepare the report to do so.\n(5)If the controller or processor does not nominate a person within the period specified in the assessment notice, the Commissioner must by written notice to the controller or processor approve a person who the Commissioner is satisfied is a suitable person to prepare the report to do so.\n(6)It is the duty of the controller or processor to give the person approved to prepare the report all such assistance as the person may reasonably require to prepare the report.”\n(4)In section 155 (penalty notices), in subsection (1)—\n(a)omit the “or” at the end of paragraph (a), and\n(b)at the end of paragraph (b) insert “, or\n(c)has failed to comply with a duty imposed on the person by section 146A(6).”\n(5)In section 160 (guidance about regulatory action), in subsection (4), after paragraph (a) insert—\n“(aa)provision specifying factors to be considered in determining whether to give an assessment notice to a person that imposes a requirement of a sort mentioned in section 146(2)(j);\n(ab)provision about the factors the Commissioner may take into account when determining the suitability of a person to prepare a report of a sort mentioned in section 146(2)(j);”.\nCommencement Information\n99 Assessment notices: removal of OFSTED restriction U.K. In section 147 of the 2018 Act (assessment notices: restrictions), in subsection (6), omit paragraph (b) and the “or” before it.\nCommencement Information\n100 Interview notices U.K. (1)The 2018 Act is amended as follows.\n(2)After section 148 insert—\n“Interview notices U.K. 148A Interview notices (1)This section applies where the Commissioner suspects that a controller or processor—\n(a)has failed or is failing as described in section 149(2), or\n(b)has committed or is committing an offence under this Act.\n(2)For the purpose of investigating the suspected failure or offence, the Commissioner may, by written notice (an “interview notice”), require an individual within subsection (3) to—\n(a)attend at a place specified in the notice, and\n(b)answer questions with respect to any matter relevant to the investigation.\n(3)An individual is within this subsection if the individual—\n(a)is the controller or processor,\n(b)is or was at any time employed by, or otherwise working for, the controller or processor, or\n(c)is or was at any time concerned in the management or control of the controller or processor.\n(4)An interview notice must specify the time at which the individual must attend at the specified place and answer questions (but see the restrictions in subsections (6) and (7)).\n(5)An interview notice must—\n(a)indicate the nature of the suspected failure or offence that is the subject of the investigation,\n(b)provide information about the consequences of failure to comply with the notice, and\n(c)provide information about the rights under sections 162 and 164 (appeals etc).\n(6)An interview notice may not require an individual to attend at the specified place and answer questions before the end of the period within which an appeal can be brought against the notice.\n(7)If an appeal is brought against an interview notice, the individual to whom the notice is given need not attend at the specified place and answer questions pending the determination or withdrawal of the appeal.\n(8)If an interview notice—\n(a)states that, in the Commissioner’s opinion, it is necessary for the individual to attend at the specified place and answer questions urgently, and\n(b)gives the Commissioner’s reasons for reaching that opinion,\nsubsections (6) and (7) do not apply but the notice must not require the individual to attend at the specified place and answer questions before the end of the period of 24 hours beginning when the notice is given.\n(9)The Commissioner may cancel or vary an interview notice by written notice to the individual to whom it was given.\n148B Interview notices: restrictions (1)An interview notice does not require an individual to answer questions to the extent that requiring the person to do so would involve an infringement of the privileges of either House of Parliament.\n(2)An interview notice does not require an individual to answer questions in respect of a communication which is made—\n(a)between a professional legal adviser and the adviser’s client, and\n(b)in connection with the giving of legal advice to the client with respect to obligations, liabilities or rights under the data protection legislation.\n(3)An interview notice does not require an individual to answer questions in respect of a communication which is made—\n(a)between a professional legal adviser and the adviser’s client or between such an adviser or client and another person,\n(b)in connection with or in contemplation of proceedings under or arising out of the data protection legislation, and\n(c)for the purposes of such proceedings.\n(4)In subsections (2) and (3), references to the client of a professional legal adviser include references to a person acting on behalf of the client.\n(5)An interview notice does not require an individual to answer questions if doing so would, by revealing evidence of the commission of an offence, expose the individual to proceedings for that offence.\n(6)The reference to an offence in subsection (5) does not include an offence under—\n(a)this Act;\n(b)section 5 of the Perjury Act 1911 (false statements made otherwise than on oath);\n(c)section 44(2) of the Criminal Law (Consolidation) (Scotland) Act 1995 (false statements made otherwise than on oath);\n(d)Article 10 of the Perjury (Northern Ireland) Order 1979 (S.I. 1979/1714 (N.I. 19)) (false statutory declarations and other false unsworn statements).\n(7)A statement made by an individual in response to an interview notice may not be used in evidence against that individual on a prosecution for an offence under this Act (other than an offence under section 148C) unless in the proceedings—\n(a)in giving evidence the individual provides information inconsistent with the statement, and\n(b)evidence relating to the statement is adduced, or a question relating to it is asked, by that individual or on that individual’s behalf.\n(8)The Commissioner may not give an interview notice with respect to the processing of personal data for the special purposes.\n(9)The Commissioner may not give an interview notice to an individual for the purpose of investigating a suspected failure or offence if the controller or processor suspected of the failure or offence is a body specified in section 23(3) of the Freedom of Information Act 2000 (bodies dealing with security matters).\n148C False statements made in response to interview notices It is an offence for an individual, in response to an interview notice—\n(a)to make a statement which the individual knows to be false in a material respect, or\n(b)recklessly to make a statement which is false in a material respect.”\n(3)In section 149 (enforcement notices), in subsection (9)(b)—\n(a)after “an assessment notice” insert “, an interview notice”, and\n(b)after “147” insert “, 148A, 148B”.\n(4)In section 155 (penalty notices), in subsection (1)(b), after “assessment notice” insert “, an interview notice”.\n(5)In section 157 (maximum amount of penalty), in subsection (4), after “assessment notice” insert “, an interview notice”.\n(6)In section 160 (guidance about regulatory action)—\n(a)in subsection (1), after paragraph (b) insert—\n“(ba)interview notices,”, and\n(b)after subsection (5) insert—\n“(5A)In relation to interview notices, the guidance must include—\n(a)provision specifying factors to be considered in determining whether to give an interview notice to an individual;\n(b)provision about the circumstances in which the Commissioner would consider it appropriate to give an interview notice to an individual in reliance on section 148A(8) (urgent cases);\n(c)provision about the circumstances in which the Commissioner would consider it appropriate to vary the place or time specified in an interview notice at the request of the individual to whom the notice is given;\n(d)provision about the nature of interviews carried out in accordance with an interview notice;\n(e)provision about how the Commissioner will determine how to proceed if an individual does not comply with an interview notice.”\n(7)In section 162 (rights of appeal), in subsection (1), after paragraph (b) insert—\n“(ba)an interview notice;”.\n(8)In section 164 (applications in respect of urgent notices)—\n(a)in subsection (1), after “assessment notice” insert “, an interview notice”, and\n(b)in subsection (5), after paragraph (b) (but before the “and” at the end of that paragraph) insert—\n“(ba)in relation to an interview notice, a statement under section 148A(8)(a),”.\n(9)In section 181 (interpretation of Part 6), at the appropriate place, insert—\n““interview notice” has the meaning given in section 148A;”. (10)In section 196 (penalties for offences), in subsection (2), after “148,” insert “148C,”.\n(11)In section 206 (index of defined expressions), at the appropriate place, insert—\n“interview notice (in Part 6)section 181”.\n(12)In Schedule 17 (review of processing of personal data for the purposes of journalism)—\n(a)after paragraph 3 insert—\nInterview notices 3A(1)Sub-paragraph (2) applies where the Commissioner gives an interview notice to an individual during a relevant period.\n(2)If the interview notice—\n(a)states that, in the Commissioner’s opinion, it is necessary for the individual to comply with a requirement in the notice for the purposes of the relevant review, and\n(b)gives the Commissioner’s reasons for reaching that opinion,\nsubsections (6) and (7) of section 148A do not apply but the notice must not require the individual to comply with the requirement before the end of the period of 24 hours beginning when the notice is given.\n(3)During a relevant period, section 148B has effect as if for subsection (8) there were substituted—\n“(8)The Commissioner may not give an individual an interview notice with respect to the processing of personal data for the special purposes unless a determination under section 174 with respect to the data or the processing has taken effect.””, and\n(b)in paragraph 4 (applications in respect of urgent notices)—\n(i)for “or assessment notice” substitute “, assessment notice or interview notice”,\n(ii)for “or 3(2)(a)” substitute “, 3(2)(a) or 3A(2)(a)”, and\n(iii)for “or 146(8)(a)” substitute “, 146(8)(a) or 148A(8)(a)”.\nCommencement Information\n101 Penalty notices U.K. (1)The 2018 Act is amended as follows.\n(2)In paragraph 2 of Schedule 16 (notice of intent to impose penalty), omit sub-paragraphs (2) and (3).\n(3)In paragraph 4 of that Schedule (giving a penalty notice)—\n(a)before sub-paragraph (1) insert—\n“(A1)This paragraph applies where the Commissioner gives a notice of intent to a person.\n(A2)Within the period of 6 months beginning when the notice is given, or as soon as reasonably practicable thereafter, the Commission must give to the person—\n(a)a penalty notice, or\n(b)written notice that the Commissioner has decided not to give a penalty notice to the person.”,\n(b)in sub-paragraph (1)—\n(i)at the beginning, insert “But”, and\n(ii)after “penalty notice” insert “to the person”, and\n(c)in sub-paragraph (2), for “a person” substitute “the person”.\n(4)In section 160 (guidance about regulatory action), in subsection (7), after paragraph (d) insert—\n“(e)provision about the circumstances in which the Commissioner would consider it necessary to comply with the duty in paragraph 4(A2) of Schedule 16 after the period of 6 months mentioned in that paragraph.”\nCommencement Information\n102 Annual report on regulatory action U.K. (1)The 2018 Act is amended as follows.\n(2)In section 139 (reporting to Parliament), before subsection (3) insert—\n“(2A)The report under this section may include the annual report under section 161A.”\n(3)In the italic heading before section 160, at the end insert “and report”.\n(4)After section 161 insert—\n“161A Annual report on regulatory action (1)The Commissioner must produce and publish an annual report containing the information described in subsections (2) to (5).\n(2)The report must include the following information about UK GDPR investigations—\n(a)the number of investigations begun, continued or completed by the Commissioner during the reporting period,\n(b)the different types of act and omission that were the subject matter of the investigations,\n(c)the enforcement powers exercised by the Commissioner in the reporting period in connection with the investigations,\n(d)the duration of investigations that ended in the reporting period, and\n(e)the different types of outcome in investigations that ended in that period.\n(3)The report must include information about the enforcement powers exercised by the Commissioner in the reporting period in connection with—\n(a)processing of personal data by a competent authority for any of the law enforcement purposes, and\n(b)processing of personal data to which Part 4 applies.\n(4)The information included in the report in accordance with subsections (2) and (3) must include information about—\n(a)the number of penalty notices given in the reporting period that were given more than 6 months after the notice of intent was given under paragraph 2 of Schedule 16, and\n(b)the reasons why that happened.\n(5)The report must include a review of how the Commissioner had regard to the guidance published under section 160 when exercising the Commissioner’s enforcement powers as described in subsections (2)(c) and (3).\n(6)In this section—\n“enforcement powers” means the powers under— (a)\nArticle 58(1)(c) and (d) and (2)(a) and (b) of the UK GDPR, (b)\nsections 142 to 159 of this Act, (c)\nparagraph 2(a), (b) and (c) of Schedule 13 to this Act, and (d)\nSchedules 15 and 16 to this Act;\n“the law enforcement purposes” has the meaning given in section 31 of this Act;\n“the reporting period” means the period to which the report relates;\n“UK GDPR investigation” means an investigation required under Article 57(1)(h) of the UK GDPR (investigations on the application of the UK GDPR).”\nCommencement Information\n103 Complaints by data subjects U.K. (1)The 2018 Act is amended in accordance with subsections (2) and (3).\n(2)Before section 165 (but after the italic heading before it) insert—\n“164A Complaints by data subjects to controllers (1)A data subject may make a complaint to the controller if the data subject considers that, in connection with personal data relating to the data subject, there is an infringement of the UK GDPR or Part 3 of this Act.\n(2)A controller must facilitate the making of complaints under this section by taking steps such as providing a complaint form which can be completed electronically and by other means.\n(3)If a controller receives a complaint under this section, the controller must acknowledge receipt of the complaint within the period of 30 days beginning when the complaint is received.\n(4)If a controller receives a complaint under this section, the controller must without undue delay—\n(a)take appropriate steps to respond to the complaint, and\n(b)inform the complainant of the outcome of the complaint.\n(5)The reference in subsection (4)(a) to taking appropriate steps to respond to the complaint includes—\n(a)making enquiries into the subject matter of the complaint, to the extent appropriate, and\n(b)informing the complainant about progress on the complaint.\n164B Controllers to notify the Commissioner of the number of complaints (1)The Secretary of State may by regulations require a controller to notify the Commissioner of the number of complaints made to the controller under section 164A in periods specified or described in the regulations.\n(2)Regulations under this section may provide that a controller is required to make a notification to the Commissioner in respect of a period only in circumstances specified in the regulations.\n(3)Regulations under this section may include—\n(a)provision about a matter listed in subsection (4), or\n(b)provision conferring power on the Commissioner to determine those matters.\n(4)The matters are—\n(a)the form and manner in which a notification must be made,\n(b)the time at which, or period within which, a notification must be made, and\n(c)how the number of complaints made to a controller during a period is to be calculated.\n(5)Regulations under this section are subject to the negative resolution procedure.”\n(3)In section 165 (complaints by data subjects to the Commissioner)—\n(a)omit subsection (1), and\n(b)in subsection (2), after “infringement of” insert “the UK GDPR or”.\n(4)The UK GDPR is amended in accordance with subsections (5) and (6).\n(5)In Article 57 (Commissioner’s tasks)—\n(a)in paragraph 1, omit point (f), and\n(b)omit paragraph 2.\n(6)Omit Article 77 (right to lodge a complaint with the Commissioner).\n(7)Schedule 10 to this Act contains minor and consequential amendments.\nCommencement Information\n104 Court procedure in connection with subject access requests U.K. (1)The 2018 Act is amended as follows.\n(2)For the italic heading before section 180 substitute—\n“Jurisdiction and court procedure”. (3)After section 180 insert—\n“180A Procedure in connection with subject access requests (1)This section applies where a court is required to determine whether a data subject is entitled to information by virtue of a right under—\n(a)Article 15 of the UK GDPR (right of access by the data subject);\n(b)Article 20 of the UK GDPR (right to data portability);\n(c)section 45 of this Act (law enforcement processing: right of access by the data subject);\n(d)section 94 of this Act (intelligence services processing: right of access by the data subject).\n(2)The court may require the controller to make available for inspection by the court so much of the information as is available to the controller.\n(3)But, unless and until the question in subsection (1) has been determined in the data subject’s favour, the court may not require the information to be disclosed to the data subject or the data subject’s representatives, whether by discovery (or, in Scotland, recovery) or otherwise.\n(4)Where the question in subsection (1) relates to a right under a provision listed in subsection (1)(a), (c) or (d), this section does not confer power on the court to require the controller to carry out a search for information that is more extensive than the reasonable and proportionate search required by that provision.”\nCommencement Information\n105 Consequential amendments to the EITSET Regulations U.K. (1)Schedule 2 to the Electronic Identification and Trust Services for Electronic Transactions Regulations 2016 (S.I. 2016/696 ) (Commissioner’s enforcement powers) is amended as follows.\n(2)In paragraph 1 (provisions of the 2018 Act applied for enforcement purposes)—\n(a)after paragraph (g) insert—\n“(ga)section 146A (assessment notices: approval of person to prepare report etc);”, and\n(b)after paragraph (i) insert—\n“(ia)section 148A (interview notices);\n(ib)section 148B (interview notices: restrictions);\n(ic)section 148C (false statements made in response to interview notices);”.\n(3)In paragraph 4(2) (modification of section 143 (information notices: restrictions))—\n(a)in paragraph (b), for “or 148” substitute “, 148 or 148C”, and\n(b)in paragraph (c), after “148” insert “or 148C”.\n(4)In paragraph 6 (modification of section 146 (assessment notices)), in sub-paragraph (2)—\n(a)for paragraph (b) substitute—\n“(b)subsection (2) has effect as if—\n(i)for “controller or processor” there were substituted “trust service provider”;\n(ii)paragraphs (h) and (i) were omitted;”,\n(b)in paragraph (c), for “subsections (7), (8), (9) and (10)” substitute “subsections (3A), (7), (8), (9), (10) and (11A)”, and\n(c)in paragraph (d), for “or 148” substitute “, 148 or 148C”.\n(5)After paragraph 6 insert—\nModification of section 146A (assessment notices: approval of person to prepare report etc) 6A Section 146A has effect as if for “controller or processor” (in each place) there were substituted “trust service provider”.”\n(6)After paragraph 7 insert—\nModification of section 148A (interview notices) 7A Section 148A has effect as if—\n(a)in subsection (1)—\n(i)for “controller or processor” there were substituted “trust service provider”;\n(ii)in paragraph (a), for “as described in section 149(2)” there were substituted “to comply with the eIDAS requirements”;\n(iii)in paragraph (b), for “this Act” there were substituted “section 144, 148 or 148C or paragraph 15 of Schedule 15”;\n(b)in subsection (3), for “controller or processor” (in each place) there were substituted “trust service provider”.\nModification of section 148B (interview notices: restrictions) 7B(1)Section 148B has effect as if subsections (8) and (9) were omitted.\n(2)In that section—\n(a)subsections (2)(b) and (3)(b) have effect as if for “the data protection legislation” there were substituted “the eIDAS Regulation or the EITSET Regulations”;\n(b)subsection (6)(a) has effect as if for “this Act” there were substituted “section 144, 148 or 148C or paragraph 15 of Schedule 15”;\n(c)subsection (7) has effect as if for “this Act (other than an offence under section 148C)” there were substituted “section 144 or 148 or paragraph 15 of Schedule 15”.”\n(7)In paragraph 12 (modification of Schedule 15 (powers of entry and inspection)), in sub-paragraph (2), in the substituted paragraph (a), for “or 148” substitute “, 148 or 148C”.\n(8)In paragraph 13 (modification of section 155 (penalty notices)), in sub-paragraph (3)(c), for “for “data subjects”” there were substituted “for the words from “data subjects” to the end”.\n(9)Omit paragraph 21 (modification of section 182 (regulations and consultation)) and the heading before it.\n(10)In paragraph 22 (modification of section 196 (penalties for offences)), in sub-paragraph (2)(b)—\n(a)after “148”, in the first place it occurs, insert “, 148C”, and\n(b)for “or 148” substitute “, 148 or 148C”.\nCommencement Information\nProtection of prohibitions, restrictions and data subject’s rights U.K. 106 Protection of prohibitions, restrictions and data subject’s rights U.K. (1)The 2018 Act is amended in accordance with subsections (2) to (5).\n(2)After section 183 insert—\n“Prohibitions and restrictions etc on processing U.K. 183A Protection of prohibitions and restrictions etc on processing: relevant enactments (1)A relevant enactment or rule of law which imposes a duty, or confers a power, to process personal data does not override a requirement under the main data protection legislation relating to the processing of personal data.\n(2)Subsection (1) does not apply—\n(a)to a relevant enactment forming part of the main data protection legislation, or\n(b)to the extent that an enactment makes express provision to the contrary referring to this section or to the main data protection legislation (or a provision of that legislation).\n(3)Subsection (1) does not prevent a duty or power to process personal data from being taken into account for the purpose of determining whether it is possible to rely on an exception to a requirement under the main data protection legislation that is available where there is such a duty or power.\n(4)In this section—\n“the main data protection legislation” means the data protection legislation other than provision of or made under— (a)\nChapter 6 or 8 of the UK GDPR, or (b)\nParts 5 to 7 of this Act;\n“relevant enactment” means an enactment so far as passed or made on or after the day on which section 106(2) of the Data (Use and Access) Act 2025 comes into force;\n“requirement” includes a prohibition or restriction.\n(5)The reference in subsection (1) to an enactment or rule of law which imposes a duty, or confers a power, to process personal data is a reference to an enactment or rule of law which, directly or indirectly, requires or authorises the processing of personal data, including (for example)—\n(a)by authorising one person to require another person to process personal data, or\n(b)by removing restrictions on processing personal data,\nand the references in subsection (3) to a duty or power are to be read accordingly.”\n(3)Before section 184 (and the italic heading before it) insert—\n“183B Protection of prohibitions and restrictions etc on processing: other enactments (1)This section is about the relationship between—\n(a)a pre-commencement enactment which imposes a duty, or confers a power, to process personal data, and\n(b)a provision of the main data protection legislation containing a requirement relating to the processing of personal data.\n(2)The relationship is not changed by section 5(A1) of the European Union (Withdrawal) Act 2018 (removal of the principle of supremacy of EU law) (or the repeal of section 5(1) to (3) of that Act).\n(3)Where the provision described in subsection (1)(b) is a provision of, or made under, the UK GDPR, section 5(A2) of the European Union (Withdrawal) Act 2018 (assimilated direct legislation subject to domestic enactments) does not apply to the relationship.\n(4)Nothing is to be implied about a relationship described in subsection (1) merely due to the fact that express provision with similar effect to section 183A(1) (or applying that provision) is made in connection with one such relationship but not another.\n(5)In this section—\n(a)“the main data protection legislation” and “requirement” have the same meaning as in section 183A, and\n(b)“pre-commencement enactment” means an enactment so far as passed or made before the day on which section 106(2) of the Data (Use and Access) Act 2025 comes into force.\n(6)Section 183A(5) applies for the purposes of subsection (1)(a) of this section as it applies for the purposes of section 183A(1).”\n(4)In section 186 (data subject’s rights and other prohibitions and restrictions)—\n(a)for the heading substitute “Protection of data subject’s rights”,\n(b)in subsection (1) omit “, except as provided by or under the provisions listed in subsection (3)”,\n(c)after subsection (2) insert—\n“(2A)Subsection (1) does not apply—\n(a)to an enactment contained in, or made under, a provision listed in subsection (2),\n(b)to an enactment contained in, or made under, a provision listed in subsection (3),\n(c)to the extent that an enactment makes express provision to the contrary referring to this section or to a provision listed in subsection (2), or\n(d)to the extent that subsection (1) is disapplied by section 186A(3).”, and\n(d)in subsection (3)—\n(i)for “provisions providing exceptions” substitute “provisions referred to in subsection (2A)(b)”, and\n(ii)omit paragraph (c) (and the “and” after it).\n(5)After section 186 insert—\n“186A Protection of data subject’s rights: further provision (1)This section is about the relationship between—\n(a)a pre-commencement enactment which prohibits or restricts the disclosure of information or authorises the withholding of information, and\n(b)a provision of the UK GDPR or this Act listed in section 186(2).\n(2)The relationship is not changed by section 5(A1) of the European Union (Withdrawal) Act 2018 (removal of the principle of supremacy of EU law) (or the repeal of section 5(1) to (3) of that Act).\n(3)Subsection (1) of section 186 does not apply to the relationship so far as there is a contrary intention, whether express or implied (taking account of, among other things, subsection (2) of this section).\n(4)Nothing is to be implied about a relationship described in subsection (1) merely due to the fact that express provision stating that section 186(1) applies (or with similar effect) is made in connection with one such relationship but not another.\n(5)In this section, “pre-commencement enactment” means an enactment so far as passed or made before the day on which section 106(4) of the Data (Use and Access) Act 2025 comes into force, other than an enactment contained in, or made under, a provision listed in section 186(2) or (3).”\n(6)In section 5 of the European Union (Withdrawal) Act 2018 (exceptions to savings and incorporation), in subsection (A3)(a)—\n(a)for “section” substitute “sections 183A and”,\n(b)for “(data subject’s rights and other prohibitions and restrictions)” substitute “(protection of prohibitions, restrictions and data subject’s rights)”, and\n(c)at the end insert “(and see also section 183B(3) of that Act)”.\n(7)Subsections (3), (5) and (6)(c) are to be treated as having come into force on 1 January 2024.\nCommencement Information\nMiscellaneous U.K. 107 Regulations under the UK GDPR U.K. (1)In the UK GDPR, after Chapter 9 insert—\n“CHAPTER 9A U.K.Regulations Article 91A Regulations made by Secretary of State 1.This Article makes provision about regulations made by the Secretary of State under this Regulation (“UK GDPR regulations”).\n2.Before making UK GDPR regulations, the Secretary of State must consult—\n(a)the Commissioner, and\n(b)such other persons as the Secretary of State considers appropriate.\n3.Paragraph 2 does not apply to regulations made under Article 49 or 49A where the Secretary of State has made an urgency statement in respect of them.\n4.UK GDPR regulations may—\n(a)make different provision for different purposes;\n(b)include consequential, supplementary, incidental, transitional, transitory or saving provision.\n5.UK GDPR regulations are to be made by statutory instrument.\n6.For the purposes of this Regulation, where regulations are subject to “the negative resolution procedure”, the statutory instrument containing the regulations is subject to annulment in pursuance of a resolution of either House of Parliament.\n7.For the purposes of this Regulation, where regulations are subject to “the affirmative resolution procedure”, the regulations may not be made unless a draft of the statutory instrument containing them has been laid before Parliament and approved by a resolution of each House of Parliament.\n8.For the purposes of this Regulation, where regulations are subject to “the made affirmative resolution procedure”—\n(a)the statutory instrument containing the regulations must be laid before Parliament after being made, together with the urgency statement in respect of them, and\n(b)the regulations cease to have effect at the end of the period of 120 days beginning with the day on which the instrument is made, unless within that period the instrument is approved by a resolution of each House of Parliament.\n9.In calculating the period of 120 days, no account is to be taken of any whole days that fall within a period during which—\n(a)Parliament is dissolved or prorogued, or\n(b)both Houses of Parliament are adjourned for more than 4 days.\n10.Where regulations cease to have effect as a result of paragraph 8, that does not—\n(a)affect anything previously done under the regulations, or\n(b)prevent the making of new regulations.\n11.Any provision that may be included in UK GDPR regulations subject to the negative resolution procedure may be made by regulations made under this Regulation or another enactment that are subject to the affirmative resolution procedure or the made affirmative resolution procedure.\n12.A requirement under this Article to consult may be satisfied by consultation before, as well as by consultation after, the provision conferring the power to make regulations comes into force.\n13.In this Article, “urgency statement”, in relation to regulations, means a reasoned statement that the Secretary of State considers it desirable for the regulations to come into force without delay.”\n(2)In section 3(9) of the 2018 Act (definition of “data protection legislation”), in paragraph (d), after “Act” insert “or the UK GDPR”.\nCommencement Information\n108 Further minor provision about data protection U.K. Schedule 11 contains further minor provision about data protection.\nCommencement Information\nChapter 2 U.K.Privacy and electronic communications 109 The PEC Regulations U.K. In this Chapter, “the PEC Regulations” means the Privacy and Electronic Communications (EC Directive) Regulations 2003 (S.I. 2003/2426 ).\nCommencement Information\n110 Interpretation of the PEC Regulations U.K. (1)Regulation 2 of the PEC Regulations (interpretation) is amended as follows.\n(2)In paragraph (1)—\n(a)in the definition of “call”, at the end insert “, and a reference to making a call includes a reference to attempting to establish such a connection”,\n(b)in the definition of “communication”—\n(i)for “exchanged or conveyed between” substitute “transmitted to”, and\n(ii)for “conveyed”, in the second place it occurs, substitute “transmitted”, and\n(c)at the appropriate place insert—\n““direct marketing” means the communication (by whatever means) of advertising or marketing material which is directed to particular individuals;”. (3)After paragraph (1) insert—\n“(1A)In the application of these Regulations in relation to—\n(a)information that is sent but not received,\n(b)a communication that is transmitted but not received,\n(c)an electronic mail that is sent but not received, or\n(d)an unsuccessful attempt to make a call,\na reference to the recipient of the information, communication, electronic mail or call is to be read as a reference to the intended recipient.”\n(4)In paragraph (4) omit “, without prejudice to paragraph (3),”.\n(5)After that paragraph insert—\n“(5)References in these Regulations to a period expressed in hours, days, weeks, months or years are to be interpreted in accordance with Article 3 of the Periods of Time Regulation, except that Article 3(4) of that Regulation does not apply to the interpretation of a reference to a period in regulation 16A.\n(6)In paragraph (5), “the Periods of Time Regulation” means Regulation (EEC, Euratom) No. 1182/71 of the Council of 3 June 1971 determining the rules applicable to periods, dates and time limits.”\nCommencement Information\n111 Duty to notify the Commissioner of personal data breach: time periods U.K. (1)In regulation 5A of the PEC Regulations (personal data breach)—\n(a)in paragraph (2), after “delay” insert “and, where feasible, not later than 72 hours after having become aware of it”, and\n(b)after paragraph (3) insert—\n“(3A)Where notification under paragraph (2) is not made within 72 hours, it must be accompanied by reasons for the delay.”\n(2)In regulation 5C of the PEC Regulations (personal data breach: fixed monetary penalty)—\n(a)in paragraph (4)(f), for “from the service of the notice of intent” substitute “beginning when the notice of intent is served”, and\n(b)in paragraph (5), for “21 days of receipt of the notice of intent” substitute “the period of 21 days beginning when the notice of intent is received”.\n(3)In Article 2 of Commission Regulation (EU) No 611/2013 of 24 June 2013 on the measures applicable to the notification of personal data breaches under Directive 2002/58/EC of the European Parliament and of the Council on privacy and electronic communications (notification to the Commissioner)—\n(a)in paragraph 2—\n(i)in the first subparagraph, for the words from “no” to “feasible” substitute “without undue delay and, where feasible, not later than 72 hours after having become aware of it”,\n(ii)in the second subparagraph, after “shall” insert “, subject to paragraph 3,”, and\n(iii)after the third subparagraph insert—\n“This paragraph is to be interpreted in accordance with Article 3 of Regulation (EEC, Euratom) No. 1182/71 of the Council of 3 June 1971 determining the rules applicable to periods, dates and time limits.”, and\n(b)for paragraph 3 substitute—\n“3.To the extent that the information set out in Annex 1 is not available to be included in the notification, it may be provided in phases without undue further delay.”\nCommencement Information\n112 Storing information in the terminal equipment of a subscriber or user U.K. (1)The PEC Regulations are amended in accordance with subsections (2) and (3).\n(2)For regulation 6 (storing information, or gaining access to information stored, in the terminal equipment of a subscriber or user) substitute—\n“6.Storing information in the terminal equipment of a subscriber or user (1)Subject to Schedule A1, a person must not store information, or gain access to information stored, in the terminal equipment of a subscriber or user.\n(2)In paragraph (1) and Schedule A1—\n(a)a reference (however expressed) to storing information, or gaining access to information stored, in the terminal equipment of a subscriber or user includes a reference to instigating the storage or access, and\n(b)except as otherwise provided, a reference (however expressed) to gaining access to information stored in the terminal equipment of a subscriber or user includes a reference to collecting or monitoring information automatically emitted by the terminal equipment.”\n(3)After regulation 6 insert—\n“6A.Power to provide exceptions to regulation 6(1) (1)The Secretary of State may by regulations made by statutory instrument—\n(a)amend these Regulations—\n(i)by adding an exception to the prohibition in regulation 6(1), or\n(ii)by omitting or varying an exception to that prohibition, and\n(b)make consequential, supplementary, incidental, transitional, transitory or saving provision, including provision amending these Regulations.\n(2)Regulations under paragraph (1) may make different provision for different purposes.\n(3)Before making regulations under paragraph (1), the Secretary of State must consult—\n(a)the Information Commissioner, and\n(b)such other persons as the Secretary of State considers appropriate.\n(4)A statutory instrument containing regulations under paragraph (1) may not be made unless a draft of the instrument has been laid before, and approved by a resolution of, each House of Parliament.”\n(4)Schedule 12 to this Act inserts Schedule A1 to the PEC Regulations.\n(5)A requirement to consult under regulation 6A of the PEC Regulations (inserted by subsection (3) of this section) may be satisfied by consultation undertaken before the day on which this Act is passed.\nCommencement Information\n113 Emergency alerts: interpretation of time periods U.K. In regulation 16A of the PEC Regulations (emergency alerts), in paragraph (6), for the words from “7 days” to “paragraph (3)(b)” substitute “the period of 7 days beginning with the day on which the time period specified by the relevant public authority pursuant to paragraph (3)(b) expires”.\nCommencement Information\n114 Use of electronic mail for direct marketing by charities U.K. (1)Regulation 22 of the PEC Regulations (use of electronic mail for direct marketing purposes) is amended as follows.\n(2)In paragraph (2), after “paragraph (3)” insert “or (3A)”.\n(3)After paragraph (3) insert—\n“(3A)A charity may send or instigate the sending of electronic mail for the purposes of direct marketing where—\n(a)the sole purpose of the direct marketing is to further one or more of the charity’s charitable purposes;\n(b)the charity obtained the contact details of the recipient of the electronic mail in the course of the recipient—\n(i)expressing an interest in one or more of the purposes that were the charity’s charitable purposes at that time; or\n(ii)offering or providing support to further one or more of those purposes; and\n(c)the recipient has been given a simple means of refusing (free of charge except for the costs of the transmission of the refusal) the use of their contact details for the purposes of direct marketing by the charity, at the time that the details were initially collected, and, where the recipient did not initially refuse the use of the details, at the time of each subsequent communication.”\n(4)After paragraph (4) insert—\n“(5)In this regulation, “charity” means—\n(a)a charity as defined in section 1(1) of the Charities Act 2011,\n(b)a charity as defined in section 1(1) of the Charities Act (Northern Ireland) 2008 (c.12 (N.I.)) , including an institution treated as such a charity for the purposes of that Act by virtue of the Charities Act 2008 (Transitional Provision) Order (Northern Ireland) 2013 (S.R. (N.I.) 2013 No. 211 ), and\n(c)a body entered in the Scottish Charity Register, other than a body which no longer meets the charity test in section 7 of the Charities and Trustee Investment (Scotland) Act 2005 (asp 10) ,\nand, in relation to such a charity, institution or body, “charitable purpose” has the meaning given in the relevant Act.”\nCommencement Information\n115 Commissioner’s enforcement powers U.K. (1)The PEC Regulations are amended in accordance with subsections (2) to (8).\n(2)In regulation 5 (security of public electronic communications services), omit paragraph (6).\n(3)Omit regulation 5B (personal data breach: audit).\n(4)In regulation 5C (personal data breach: fixed monetary penalty)—\n(a)in paragraph (10)—\n(i)omit “and Northern Ireland”, and\n(ii)in paragraph (a), for “a county court” substitute “the county court”, and\n(b)after paragraph (11) insert—\n“(12)In Northern Ireland, the penalty is recoverable—\n(a)if a county court so orders, as if it were payable under an order of that court;\n(b)if the High Court so orders, as if it were payable under an order of that court.\n(13)The Secretary of State may by regulations made by statutory instrument amend this regulation so as to substitute a different amount for the amount for the time being specified in paragraph (2) or (5).\n(14)Regulations under paragraph (13) may make transitional provision.\n(15)Before making regulations under paragraph (13), the Secretary of State must consult—\n(a)the Information Commissioner, and\n(b)such other persons as the Secretary of State considers appropriate.\n(16)A statutory instrument containing regulations under this regulation may not be made unless a draft of the instrument has been laid before, and approved by a resolution of, each House of Parliament.”\n(5)For regulation 31 substitute—\n“31.Information Commissioner’s enforcement powers (1)Schedule 1 provides for certain provisions of Parts 5 to 7 of the Data Protection Act 2018 to apply with modifications for the purposes of enforcing these Regulations.\n(2)In regulations 32 and 33, “enforcement functions” means the functions of the Information Commissioner under those provisions, as applied by that Schedule.”\n(6)Omit regulation 31A (third party information notices).\n(7)Omit regulation 31B (appeals against third party information notices).\n(8)For Schedule 1 substitute the Schedule set out in Schedule 13 to this Act.\n(9)In paragraph 58(1) of Schedule 20 to the Data Protection Act 2018 (transitional provision relating to the PEC Regulations) for “regulations 2, 31 and 31B of, and Schedule 1 to,” substitute “regulation 2 of”.\n(10)A requirement to consult under regulation 5C(15) of the PEC Regulations (inserted by subsection (4)(b) of this section) may be satisfied by consultation undertaken before the day on which this Act is passed.\nCommencement Information\n116 Codes of conduct U.K. (1)The PEC Regulations are amended as follows.\n(2)After regulation 32 insert—\n“32A.Codes of conduct (1)The Commissioner must encourage representative bodies to produce codes of conduct intended to contribute to compliance with these Regulations.\n(2)Under paragraph (1), the Commissioner must encourage representative bodies to produce codes which take account of, among other things, the specific features of different sectors.\n(3)A code of conduct described in paragraph (1) may, for example, make provision with regard to—\n(a)rights and obligations under these Regulations;\n(b)out-of-court proceedings and other dispute resolution procedures for resolving disputes arising in connection with these Regulations.\n(4)The Commissioner must encourage representative bodies to submit codes of conduct described in paragraph (1) to the Commissioner in draft.\n(5)Where a representative body does so, the Commissioner must—\n(a)provide the representative body with an opinion on whether the code correctly reflects the requirements of these Regulations,\n(b)decide whether to approve the code, and\n(c)if the code is approved, register and publish the code.\n(6)The Commissioner may only approve a code if, among other things—\n(a)the code contains a mechanism for monitoring whether persons who undertake to apply the code comply with its provisions, and\n(b)in relation to persons other than public bodies, the mechanism involves monitoring by a body which is accredited for that purpose by the Commissioner under regulation 32B.\n(7)In relation to amendments of a code of conduct that is for the time being approved under this regulation—\n(a)paragraphs (4) and (5) apply as they apply in relation to a code, and\n(b)the requirements in paragraph (6) must be satisfied by the code as amended.\n(8)A code of conduct described in paragraph (1) may be contained in the same document as a code of conduct described in Article 40 of the UK GDPR (and a provision contained in such a document may be a provision of both codes).\n(9)In this regulation—\n“public body” has the meaning given in section 7 of the Data Protection Act 2018 (for the purposes of the UK GDPR);\n“representative body” means an association or other body representing categories of—\n(a)\ncommunications providers, or (b)\nother persons engaged in activities regulated by these Regulations;\n“the UK GDPR” has the meaning given in section 3(10) of the Data Protection Act 2018. 32B.Accreditation of bodies monitoring compliance with codes of conduct (1)The Commissioner may, in accordance with this regulation, accredit a body for the purpose of monitoring whether persons other than public bodies comply with a code of conduct described in regulation 32A(1).\n(2)The Commissioner may accredit a body only where the Commissioner is satisfied that the body has—\n(a)demonstrated its independence,\n(b)demonstrated that it has an appropriate level of expertise in relation to the subject matter of the code,\n(c)established procedures which allow it—\n(i)to assess a person’s eligibility to apply the code,\n(ii)to monitor compliance with the code, and\n(iii)to review the operation of the code periodically,\n(d)established procedures and structures to handle complaints about infringements of the code or about the manner in which the code has been, or is being, implemented by a person,\n(e)made arrangements to publish information about the procedures and structures described in sub-paragraph (d), and\n(f)demonstrated that it does not have a conflict of interest.\n(3)The Commissioner must prepare and publish guidance about how the Commissioner proposes to take decisions about accreditation under this regulation.\n(4)A body accredited under this regulation in relation to a code must take appropriate action where a person infringes the code.\n(5)If the action taken by a body under paragraph (4) consists of suspending or excluding a person from the code, the body must inform the Commissioner, giving reasons for taking that action.\n(6)The Commissioner must revoke the accreditation of a body under this regulation if the Commissioner considers that the body—\n(a)no longer meets the requirements for accreditation, or\n(b)has failed, or is failing, to comply with paragraph (4) or (5).\n(7)In this regulation, “public body” has the same meaning as in regulation 32A.\n32C.Effect of codes of conduct Adherence to a code of conduct approved under regulation 32A may be used by a person as a means of demonstrating compliance with these Regulations.”\n(3)In regulation 33 (technical advice to the Commissioner)—\n(a)omit “, in connection with his enforcement functions,” and\n(b)at the end insert “where the request is made in connection with—\n(a)the Commissioner’s enforcement functions, or\n(b)the Commissioner’s functions under regulation 32A or 32B (codes of conduct).”\n(4)In Schedule 1 (Commissioner’s enforcement powers) (inserted by Schedule 13 to this Act), in paragraph 18(b)(ii) (maximum amount of penalty), for “or 24” substitute “, 24 or 32B(4) or (5)”.\nCommencement Information\n","permalink":"https://ai.intlaws.com/en/compliance/other/%E8%8B%B1%E5%9B%BD-duaa2025-part5/","summary":"Official text of Part 5 (Data Protection and Privacy) of the UK Data (Use and Access) Act 2025, comprising Chapter 1 (Data protection, sections 66–108) and Chapter 2 (PECR reform, sections 109–116): 51 sections in total. English original from legislation.gov.uk; Chinese translation in progress.","title":"UK Data (Use and Access) Act 2025 — Part 5 (Data Protection and Privacy)"},{"content":" Sources: U.S. Federal Trade Commission (FTC) official website; California Privacy Protection Agency (CalPrivacy / CPPA) official website\nDate collected: 2026-09-23\nOfficial links: listed under each entry; all are directly accessible official pages (not home pages, not search-result pages)\nVerification: every holding below is quoted verbatim from the official English text; the quotations were checked sentence by sentence against the official pages\nJurisdiction: United States (federal / California)\nCase 1: Workado, LLC (f/k/a Content at Scale AI) — accuracy claims for an AI content-detection product Case/Matter number: FTC Matter/File No. 2323092 (from the \u0026ldquo;FTC Matter/File Number\u0026rdquo; field on the official case page) Authority: U.S. Federal Trade Commission (FTC) Date: final order approved and made final on 2025-08-28 (date of the official press release; the complaint was issued in April 2025) Applicable law: Section 5 of the FTC Act (unfair or deceptive acts or practices) [to verify] — the official press release does not cite the section; the official case page is tagged \u0026ldquo;deceptive/misleading conduct\u0026rdquo; Holding (official text): \u0026ldquo;The Federal Trade Commission has given final approval to an order against Workado, LLC, requiring the company to stop advertising the accuracy or efficacy of its artificial intelligence (AI) content detection products unless it has competent and reliable evidence showing those products are as accurate as claimed.\u0026rdquo;\n\u0026ldquo;Workado markets its AI Content Detector to consumers seeking to determine whether written content was developed using generative AI technology or if it was written by a human being. The company claimed that its AI Content Detector was developed using a wide range of material, including blog posts and Wikipedia entries, to make it more accurate for average users. The FTC\u0026rsquo;s April 2025 complaint alleges, however, that the AI model powering the AI Content Detector was trained or fine-tuned to effect…\u0026rdquo;\n\u0026ldquo;The final order is designed to ensure Workado does not engage in similar false, misleading, or unsupported advertising. Under the order, Workado: Is prohibited from making any representations about the effectiveness of any AI content detection product unless it is not misleading, and the company has competent and reliable evidence to support the claim at the time it is made; …\u0026rdquo;\nOfficial links: Case page (matter number, status): https://www.ftc.gov/legal-library/browse/cases-proceedings/2323092-content-scale-ai Press release (final order approved, 2025-08-28): https://www.ftc.gov/news-events/news/press-releases/2025/08/ftc-approves-final-order-against-workado-llc-which-misrepresented-accuracy-its-artificial Press release (April 2025 order requiring substantiation): https://www.ftc.gov/news-events/news/press-releases/2025/04/ftc-order-requires-workado-back-artificial-intelligence-detection-claims Jurisdiction: United States (federal) To verify: ① the exact signing/effective date of the final order (this entry uses the press-release date 2025-08-28 as the \u0026ldquo;final approval\u0026rdquo; milestone); ② the official case page shows \u0026ldquo;Case Status: Pending\u0026rdquo; alongside the fact that the final order was approved — the status field needs confirmation against the source; ③ the statutory provision (FTC Act §5) is not stated in the press release; ④ the last sentence of the second quotation is truncated on the official page. Case 2: GGL Projects, Inc. (d/b/a Sitejabber) — misleading ratings and reviews on an AI-enabled review platform Case/Matter number: [to verify] — the official case page does not list an \u0026ldquo;FTC Matter/File Number\u0026rdquo; field; case name: In the Matter of GGL Projects, Inc., a Corporation, also d/b/a Sitejabber. Authority: U.S. Federal Trade Commission (FTC) Date: complaint issued in November 2024 (official case page: \u0026ldquo;In a complaint issued in November 2024\u0026rdquo;); the date the final order was approved is [to verify] (the \u0026ldquo;Last Updated\u0026rdquo; field showing 2025-01-03 is a page-update date, not the order date) Applicable law: Section 5 of the FTC Act (deceptive acts or practices) [to verify] — to be confirmed against the order text Holding (official text): \u0026ldquo;In a complaint issued in November 2024, the FTC charged that Sitejabber deceived consumers by misrepresenting that ratings and reviews it published came from customers who experienced the reviewed product or service, artificially inflating average ratings and review counts. Under a proposed order settling the agency\u0026rsquo;s complaint, Sitejabber will be prohibited from making such misrepresentations and from making other misrepresentations about consumer ratings or reviews. The Commission approved the…\u0026rdquo;\nOfficial link: Case page (full description and press-release links): https://www.ftc.gov/legal-library/browse/cases-proceedings/sitejabber Jurisdiction: United States (federal) To verify: ① the FTC Matter/File Number (not listed on the case page); ② the date the final order was approved; ③ the \u0026ldquo;Case Status\u0026rdquo; field; ④ the final sentence is truncated on the official page. Case 3: FTC v. Evolv Technologies Holdings, Inc. — unsupported claims about an AI security-screening system Case/Matter number: Federal Trade Commission, Plaintiff, v. Evolv Technologies Holdings, Inc., a Corporation, Defendant.; docket number [to verify] (not listed on the case page) Authority: U.S. Federal Trade Commission (FTC, as plaintiff) Date: 2024-11-26 (date of the official press release) Applicable law: Section 5 of the FTC Act (deceptive acts or practices) [to verify] — to be confirmed against the order/complaint text Holding (official text): \u0026ldquo;The Federal Trade Commission is taking action against Evolv Technologies over allegations that the company made false claims about the extent to which its AI-powered security screening system can detect weapons and ignore harmless personal items, including in school settings.\u0026rdquo;\n\u0026ldquo;In the proposed FTC settlement order, Evolv would be banned from making unsupported claims about its products\u0026rsquo; ability…\u0026rdquo;\n(press-release subheading) \u0026ldquo;Proposed settlement would prohibit misrepresentations and allow affected schools to opt out of current contracts for security screening systems\u0026rdquo;\nOfficial links: Case page: https://www.ftc.gov/legal-library/browse/cases-proceedings/evolv-technologies Press release (2024-11-26): https://www.ftc.gov/news-events/news/press-releases/2024/11/ftc-takes-action-against-evolv-technologies-deceiving-users-about-its-ai-powered-security-screening Jurisdiction: United States (federal) To verify: ① docket/case number; ② final approval status and date of the proposed order; ③ the \u0026ldquo;Case Status\u0026rdquo; field; ④ the second quotation is truncated on the official page. Case 4: Tractor Supply Company — CCPA privacy-notice and job-applicant notice violations (largest fine in the agency\u0026rsquo;s history) Case/Matter number: Case No. ENF24-M-TR-04 (body of the decision; verified 2026-09-24 against the archived original) Authority: California Privacy Protection Agency (CPPA / CalPrivacy) Board Date: announcement date 2025-09-30; decision signed 2025-09-26 (\u0026ldquo;this 26th day of September, 2025\u0026rdquo; on the signature page; verified 2026-09-24) Applicable law: California Consumer Privacy Act (CCPA) — privacy-notice obligations and the obligation to inform consumers and job applicants of their rights Holding (official text): \u0026ldquo;SACRAMENTO – The California Privacy Protection Agency (CPPA) Board has issued a decision requiring Tractor Supply Company, the nation\u0026rsquo;s largest rural lifestyle retailer with more than 2,500 stores in 49 states, to change its business practices and pay a $1,350,000 fine to resolve claims that the company violated the California Consumer Privacy Act (CCPA). The fine is the largest in the CPPA\u0026rsquo;s history, and the decision is the first to address the importance of CCPA privacy notices and privacy rig…\u0026rdquo;\n\u0026ldquo;According to the Board\u0026rsquo;s decision, Tractor Supply violated Californians\u0026rsquo; privacy rights by: Failing to maintain a privacy policy that notified consumers of their rights; Failing to notify California job applicants of their privacy rights and how to exercise them; …\u0026rdquo;\n\u0026ldquo;To resolve the allegations, Tractor Supply agreed to pay $1,350,000, implement broad remedial measures, such as scanning its digital properties to inventory tracking technologies, and require a corporate officer or director to certify compliance annually for the next four years.\u0026rdquo;\nOfficial links: Announcement: https://cppa.ca.gov/announcements/2025/20250930.html Decision (linked from the announcement): https://cppa.ca.gov/pdf/20250930_tractor_supply_bd_sfo.pdf Jurisdiction: United States (California) To verify: ① the signature date and case number on the decision (the PDF is a scanned document; the text layer could not be extracted); ② the first quotation and the list of violations are truncated on the official page; ③ \u0026ldquo;largest fine in the CPPA\u0026rsquo;s history\u0026rdquo; is the agency\u0026rsquo;s own statement, not a comparison across decisions. Case 5: ROR Partners LLC — failure to register as a data broker under California\u0026rsquo;s Delete Act Case/Matter number: Case No. ENF25-245-D-RO (body of the decision; verified 2026-09-24 against the archived original) Authority: California Privacy Protection Agency (CPPA / CalPrivacy) Board Date: announcement date 2025-12-03; decision signed 2025-11-26 (template year 2025 + handwritten \u0026ldquo;26th November\u0026rdquo; on the signature page; verified 2026-09-24. The page\u0026rsquo;s \u0026lt;time\u0026gt; attribute 2025-11-20 is page metadata, a different node — conflict resolved). the date of signature on the decision governs) Applicable law: California Delete Act — annual registration obligation for data brokers Holding (official text): \u0026ldquo;SACRAMENTO, CA – The California Privacy Protection Agency Board has issued a decision requiring ROR Partners LLC, a Nevada-based marketing firm catering to fitness and wellness brands, to pay $56,600 in fines and past-due fees for failing to register as a data broker in violation of California\u0026rsquo;s Delete Act. The Enforcement Division brought the case as part of its …\u0026rdquo;\nOfficial links: Announcement: https://cppa.ca.gov/announcements/2025/20251203.html Decision (linked from the announcement): https://cppa.ca.gov/pdf/ror_partners_ood.pdf Jurisdiction: United States (California) To verify: ① the conflict between the announcement body date (2025-12-03) and the page\u0026rsquo;s \u0026lt;time datetime\u0026gt; value (2025-11-20) — the decision\u0026rsquo;s signature date governs; ② the decision PDF is a scanned document (no text layer); ③ case number. Appendix 1: two further verified entries that can be added Both entries below belong to the same CalPrivacy enforcement announcement of 2026-01-08 on data brokers. Because they share the same source and date as Case 5, and to avoid splitting a single enforcement announcement into multiple entries, they are listed here in tabular form pending separate entries per respondent.\n# Respondent Penalty Grounds Applicable law Announcement date Official link A Rickenbacher Data LLC (d/b/a Datamasters, Texas) $45,000 Failure to register as a data broker; resale of names, addresses, phone numbers and emails of individuals with health conditions including Alzheimer\u0026rsquo;s disease, drug addiction and bladder incontinence California Delete Act 2026-01-08 https://cppa.ca.gov/announcements/2026/20260108.html ; decision https://cppa.ca.gov/pdf/datamasters_order_signed.pdf B S\u0026amp;P Global, Inc. (New York) $62,600 Failure to register as a data broker owing to an administrative error; required to establish registration and compliance-audit procedures California Delete Act 2026-01-08 https://cppa.ca.gov/announcements/2026/20260108.html ; decision https://cppa.ca.gov/pdf/sp_global_inc_fo_signed.pdf The decisions for these two entries were not downloaded in this round; [to verify]: decision date and case number.\nAppendix 2: scope and limitations of this batch Change of authority name: the California Privacy Protection Agency (CPPA) moved all announcements to privacy.ca.gov as of 2026-01-26 and now uses the name CalPrivacy. Announcements from 2025 and earlier remain at cppa.ca.gov/announcements/ and those links remain valid. Date conventions: this batch consists of enforcement/penalty cases and therefore does not involve the \u0026ldquo;entry into force vs. date of application of compliance obligations\u0026rdquo; distinction. Note, however, that the annual data-broker registration obligation under the Delete Act falls due each January, a different kind of milestone from the announcement dates of each penalty; the two are labelled separately where listed together in this section. Sources used: all fields are taken solely from first-hand pages on the FTC and CalPrivacy/CPPA official websites and from official PDFs — no third-party republication and no law-firm commentary is used in the body text. ","permalink":"https://ai.intlaws.com/en/cases/us-enforcement-first-batch/","summary":"First batch of five enforcement/penalty cases from U.S. federal and California regulators in the fields of artificial intelligence, data privacy and data brokerage: three from the Federal Trade Commission (FTC) — accuracy claims for AI content detection, an AI-enabled review platform, and an AI security-screening system — and two from the California Privacy Protection Agency (CalPrivacy, formerly CPPA) — CCPA privacy-notice violations and data-broker registration violations. Each entry carries the four required elements, with holdings quoted verbatim from official documents and direct official links.","title":"Case Collection | AI and Data Protection Enforcement in the United States (First Batch: FTC and CalPrivacy)"},{"content":" Version \u0026amp; sources (verifiable)\nItem Content Adoption \u0026amp; promulgation 24 February 2023 (CAC Order No. 13) Effective date 1 June 2023 Currently in force Yes (as of 2026-09-23) Chinese original Official website of the Cyberspace Administration of China English translation No official English version. Translated by this journal from the official Chinese text and cross-checked article by article — unofficial translation, for reference only → 中文全文 Order of the Cyberspace Administration of China No. 13: The Measures for Standard Contract for Outbound Transfer of Personal Information, as adopted at the 2nd executive meeting of the Cyberspace Administration of China on 3 February 2023, are hereby promulgated and shall come into force on 1 June 2023.\nArticle 1 These Measures are formulated in accordance with the Personal Information Protection Law of the People\u0026rsquo;s Republic of China and other laws and regulations for the purpose of protecting the rights and interests of personal information and regulating the outbound transfer of personal information.\nArticle 2 Where a personal information handler provides personal information abroad by entering into a standard contract with the overseas recipient in accordance with Article 38, paragraph 1, item 3 of the Personal Information Protection Law of the People\u0026rsquo;s Republic of China, these Measures shall apply.\nArticle 3 Outbound transfer of personal information by way of concluding a standard contract shall adhere to the combination of independent contracting and record-filing administration, and the combination of protecting rights and interests with preventing risks, so as to ensure the secure and free cross-border flow of personal information.\nArticle 4 Where a personal information handler provides personal information abroad by way of concluding a standard contract, it shall meet all of the following circumstances:\n(1) it is not a critical information infrastructure operator;\n(2) it processes the personal information of fewer than 1,000,000 individuals;\n(3) it has cumulatively provided abroad, since 1 January of the previous year, the personal information of fewer than 100,000 individuals; and\n(4) it has cumulatively provided abroad, since 1 January of the previous year, the sensitive personal information of fewer than 10,000 individuals.\nWhere laws, administrative regulations or the national cyberspace administration provide otherwise, those provisions shall prevail.\nA personal information handler shall not resort to means such as splitting quantities to provide abroad, by way of concluding a standard contract, personal information for which a security assessment of data export is required by law.\nArticle 5 Before providing personal information abroad, a personal information handler shall conduct a personal information protection impact assessment, focusing on the following matters:\n(1) the lawfulness, legitimacy and necessity of the purposes, scope and methods of the processing of personal information by the personal information handler and the overseas recipient;\n(2) the scale, scope, categories and sensitivity of the personal information to be exported, and the risks that the outbound transfer of personal information may pose to the rights and interests of individuals;\n(3) the obligations undertaken by the overseas recipient, and whether its management and technical measures, capabilities and the like for performing those obligations can guarantee the security of the personal information to be exported;\n(4) the risks of the personal information, after export, being tampered with, destroyed, leaked, lost, or illegally used, and whether the channels for safeguarding the rights and interests of individuals are unobstructed;\n(5) the impact of the personal information protection policies, laws and regulations of the country or region where the overseas recipient is located on the performance of the standard contract; and\n(6) other matters that may affect the security of the outbound transfer of personal information.\nArticle 6 The standard contract shall be concluded in strict accordance with the annex to these Measures. The national cyberspace administration may adjust the annex in light of actual circumstances.\nA personal information handler may agree with the overseas recipient on other terms, provided that such terms do not conflict with the standard contract.\nOutbound transfer of personal information may be carried out only after the standard contract takes effect.\nArticle 7 A personal information handler shall, within 10 working days from the date on which the standard contract takes effect, file the standard contract with the cyberspace administration of the province where it is located. The filing shall be accompanied by the following materials:\n(1) the standard contract; and\n(2) the personal information protection impact assessment report.\nA personal information handler shall be responsible for the authenticity of the materials filed.\nArticle 8 During the validity period of the standard contract, where any of the following circumstances occurs, the personal information handler shall conduct a personal information protection impact assessment anew, supplement or re-conclude the standard contract, and perform the corresponding filing procedures:\n(1) the purpose, scope, type, sensitivity, method, place of storage or retention period of the personal information provided abroad changes, or the purpose or method of processing by the overseas recipient changes, in a manner that may increase the risk to the rights and interests of individuals;\n(2) the laws, regulations or cybersecurity environment of the country or region where the overseas recipient is located changes in a manner that may increase the risk to the rights and interests of individuals; or\n(3) any other circumstance arises that may affect the rights and interests of individuals.\nArticle 9 Cyberspace administrations and their staff shall keep confidential the personal privacy, personal information, trade secrets and confidential business information obtained in the performance of their duties, and shall not disclose such information or provide it to others illegally, nor use it illegally.\nArticle 10 Any organisation or individual that discovers a personal information handler providing personal information abroad in violation of these Measures may report it to a cyberspace administration at or above the provincial level.\nArticle 11 Where a cyberspace administration at or above the provincial level discovers that an outbound personal information activity involves relatively large risks or that a personal information security incident has occurred, it may conduct regulatory talks with the personal information handler in accordance with the law. The personal information handler shall rectify as required and eliminate the risks.\nArticle 12 Where these Measures are violated, the case shall be handled in accordance with the Personal Information Protection Law of the People\u0026rsquo;s Republic of China and other laws and regulations; where a crime is constituted, criminal responsibility shall be pursued according to law.\nArticle 13 These Measures shall come into force on 1 June 2023. Outbound personal information activities that have already been carried out before these Measures come into force and do not comply with the provisions of these Measures shall be rectified within 6 months from the date on which these Measures come into force.\n","permalink":"https://ai.intlaws.com/en/compliance/china/personal-information-exit-standard-contract/","summary":"English translation of China\u0026rsquo;s Measures for Standard Contract for Outbound Transfer of Personal Information (CAC Order No. 13, adopted 3 February 2023, effective 1 June 2023). Unofficial translation, for reference only.","title":"Measures for Standard Contract for Outbound Transfer of Personal Information"},{"content":" Version \u0026amp; sources (verifiable)\nItem Content Regulation Regulation (EU) 2024/1689 (Artificial Intelligence Act) Adopted 13 June 2024; OJ L series, 12.7.2024 Entry into force 1 August 2024 (staged application) Official text EUR-Lex OJ HTML · ELI Structure 13 chapters · 113 articles · 13 annexes (reproduced in full) Note Official EU languages only — no official Chinese version; 中文译本将据本官方文本另行译校并单独发布 Verification 2026-09-23 reproduced verbatim from EUR-Lex; article numbers 1–113 complete, no gaps REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL\nof 13 June 2024\nlaying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act)\n(Text with EEA relevance)\nTHE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,\nHaving regard to the Treaty on the Functioning of the European Union, and in particular Articles 16 and 114 thereof,\nHaving regard to the proposal from the European Commission,\nAfter transmission of the draft legislative act to the national parliaments,\nHaving regard to the opinion of the European Economic and Social Committee (1),\nHaving regard to the opinion of the European Central Bank (2),\nHaving regard to the opinion of the Committee of the Regions (3),\nActing in accordance with the ordinary legislative procedure (4),\nWhereas:\n(1)\nThe purpose of this Regulation is to improve the functioning of the internal market by laying down a uniform legal framework in particular for the development, the placing on the market, the putting into service and the use of artificial intelligence systems (AI systems) in the Union, in accordance with Union values, to promote the uptake of human centric and trustworthy artificial intelligence (AI) while ensuring a high level of protection of health, safety, fundamental rights as enshrined in the Charter of Fundamental Rights of the European Union (the ‘Charter’), including democracy, the rule of law and environmental protection, to protect against the harmful effects of AI systems in the Union, and to support innovation. This Regulation ensures the free movement, cross-border, of AI-based goods and services, thus preventing Member States from imposing restrictions on the development, marketing and use of AI systems, unless explicitly authorised by this Regulation.\n(2)\nThis Regulation should be applied in accordance with the values of the Union enshrined as in the Charter, facilitating the protection of natural persons, undertakings, democracy, the rule of law and environmental protection, while boosting innovation and employment and making the Union a leader in the uptake of trustworthy AI.\n(3)\nAI systems can be easily deployed in a large variety of sectors of the economy and many parts of society, including across borders, and can easily circulate throughout the Union. Certain Member States have already explored the adoption of national rules to ensure that AI is trustworthy and safe and is developed and used in accordance with fundamental rights obligations. Diverging national rules may lead to the fragmentation of the internal market and may decrease legal certainty for operators that develop, import or use AI systems. A consistent and high level of protection throughout the Union should therefore be ensured in order to achieve trustworthy AI, while divergences hampering the free circulation, innovation, deployment and the uptake of AI systems and related products and services within the internal market should be prevented by laying down uniform obligations for operators and guaranteeing the uniform protection of overriding reasons of public interest and of rights of persons throughout the internal market on the basis of Article 114 of the Treaty on the Functioning of the European Union (TFEU). To the extent that this Regulation contains specific rules on the protection of individuals with regard to the processing of personal data concerning restrictions of the use of AI systems for remote biometric identification for the purpose of law enforcement, of the use of AI systems for risk assessments of natural persons for the purpose of law enforcement and of the use of AI systems of biometric categorisation for the purpose of law enforcement, it is appropriate to base this Regulation, in so far as those specific rules are concerned, on Article 16 TFEU. In light of those specific rules and the recourse to Article 16 TFEU, it is appropriate to consult the European Data Protection Board.\n(4)\nAI is a fast evolving family of technologies that contributes to a wide array of economic, environmental and societal benefits across the entire spectrum of industries and social activities. By improving prediction, optimising operations and resource allocation, and personalising digital solutions available for individuals and organisations, the use of AI can provide key competitive advantages to undertakings and support socially and environmentally beneficial outcomes, for example in healthcare, agriculture, food safety, education and training, media, sports, culture, infrastructure management, energy, transport and logistics, public services, security, justice, resource and energy efficiency, environmental monitoring, the conservation and restoration of biodiversity and ecosystems and climate change mitigation and adaptation.\n(5)\nAt the same time, depending on the circumstances regarding its specific application, use, and level of technological development, AI may generate risks and cause harm to public interests and fundamental rights that are protected by Union law. Such harm might be material or immaterial, including physical, psychological, societal or economic harm.\n(6)\nGiven the major impact that AI can have on society and the need to build trust, it is vital for AI and its regulatory framework to be developed in accordance with Union values as enshrined in Article 2 of the Treaty on European Union (TEU), the fundamental rights and freedoms enshrined in the Treaties and, pursuant to Article 6 TEU, the Charter. As a prerequisite, AI should be a human-centric technology. It should serve as a tool for people, with the ultimate aim of increasing human well-being.\n(7)\nIn order to ensure a consistent and high level of protection of public interests as regards health, safety and fundamental rights, common rules for high-risk AI systems should be established. Those rules should be consistent with the Charter, non-discriminatory and in line with the Union’s international trade commitments. They should also take into account the European Declaration on Digital Rights and Principles for the Digital Decade and the Ethics guidelines for trustworthy AI of the High-Level Expert Group on Artificial Intelligence (AI HLEG).\n(8)\nA Union legal framework laying down harmonised rules on AI is therefore needed to foster the development, use and uptake of AI in the internal market that at the same time meets a high level of protection of public interests, such as health and safety and the protection of fundamental rights, including democracy, the rule of law and environmental protection as recognised and protected by Union law. To achieve that objective, rules regulating the placing on the market, the putting into service and the use of certain AI systems should be laid down, thus ensuring the smooth functioning of the internal market and allowing those systems to benefit from the principle of free movement of goods and services. Those rules should be clear and robust in protecting fundamental rights, supportive of new innovative solutions, enabling a European ecosystem of public and private actors creating AI systems in line with Union values and unlocking the potential of the digital transformation across all regions of the Union. By laying down those rules as well as measures in support of innovation with a particular focus on small and medium enterprises (SMEs), including startups, this Regulation supports the objective of promoting the European human-centric approach to AI and being a global leader in the development of secure, trustworthy and ethical AI as stated by the European Council (5), and it ensures the protection of ethical principles, as specifically requested by the European Parliament (6).\n(9)\nHarmonised rules applicable to the placing on the market, the putting into service and the use of high-risk AI systems should be laid down consistently with Regulation (EC) No 765/2008 of the European Parliament and of the Council (7), Decision No 768/2008/EC of the European Parliament and of the Council (8) and Regulation (EU) 2019/1020 of the European Parliament and of the Council (9) (New Legislative Framework). The harmonised rules laid down in this Regulation should apply across sectors and, in line with the New Legislative Framework, should be without prejudice to existing Union law, in particular on data protection, consumer protection, fundamental rights, employment, and protection of workers, and product safety, to which this Regulation is complementary. As a consequence, all rights and remedies provided for by such Union law to consumers, and other persons on whom AI systems may have a negative impact, including as regards the compensation of possible damages pursuant to Council Directive 85/374/EEC (10) remain unaffected and fully applicable. Furthermore, in the context of employment and protection of workers, this Regulation should therefore not affect Union law on social policy and national labour law, in compliance with Union law, concerning employment and working conditions, including health and safety at work and the relationship between employers and workers. This Regulation should also not affect the exercise of fundamental rights as recognised in the Member States and at Union level, including the right or freedom to strike or to take other action covered by the specific industrial relations systems in Member States as well as the right to negotiate, to conclude and enforce collective agreements or to take collective action in accordance with national law. This Regulation should not affect the provisions aiming to improve working conditions in platform work laid down in a Directive of the European Parliament and of the Council on improving working conditions in platform work. Moreover, this Regulation aims to strengthen the effectiveness of such existing rights and remedies by establishing specific requirements and obligations, including in respect of the transparency, technical documentation and record-keeping of AI systems. Furthermore, the obligations placed on various operators involved in the AI value chain under this Regulation should apply without prejudice to national law, in compliance with Union law, having the effect of limiting the use of certain AI systems where such law falls outside the scope of this Regulation or pursues legitimate public interest objectives other than those pursued by this Regulation. For example, national labour law and law on the protection of minors, namely persons below the age of 18, taking into account the UNCRC General Comment No 25 (2021) on children’s rights in relation to the digital environment, insofar as they are not specific to AI systems and pursue other legitimate public interest objectives, should not be affected by this Regulation.\n(10)\nThe fundamental right to the protection of personal data is safeguarded in particular by Regulations (EU) 2016/679 (11) and (EU) 2018/1725 (12) of the European Parliament and of the Council and Directive (EU) 2016/680 of the European Parliament and of the Council (13). Directive 2002/58/EC of the European Parliament and of the Council (14) additionally protects private life and the confidentiality of communications, including by way of providing conditions for any storing of personal and non-personal data in, and access from, terminal equipment. Those Union legal acts provide the basis for sustainable and responsible data processing, including where data sets include a mix of personal and non-personal data. This Regulation does not seek to affect the application of existing Union law governing the processing of personal data, including the tasks and powers of the independent supervisory authorities competent to monitor compliance with those instruments. It also does not affect the obligations of providers and deployers of AI systems in their role as data controllers or processors stemming from Union or national law on the protection of personal data in so far as the design, the development or the use of AI systems involves the processing of personal data. It is also appropriate to clarify that data subjects continue to enjoy all the rights and guarantees awarded to them by such Union law, including the rights related to solely automated individual decision-making, including profiling. Harmonised rules for the placing on the market, the putting into service and the use of AI systems established under this Regulation should facilitate the effective implementation and enable the exercise of the data subjects’ rights and other remedies guaranteed under Union law on the protection of personal data and of other fundamental rights.\n(11)\nThis Regulation should be without prejudice to the provisions regarding the liability of providers of intermediary services as set out in Regulation (EU) 2022/2065 of the European Parliament and of the Council (15).\n(12)\nThe notion of ‘AI system’ in this Regulation should be clearly defined and should be closely aligned with the work of international organisations working on AI to ensure legal certainty, facilitate international convergence and wide acceptance, while providing the flexibility to accommodate the rapid technological developments in this field. Moreover, the definition should be based on key characteristics of AI systems that distinguish it from simpler traditional software systems or programming approaches and should not cover systems that are based on the rules defined solely by natural persons to automatically execute operations. A key characteristic of AI systems is their capability to infer. This capability to infer refers to the process of obtaining the outputs, such as predictions, content, recommendations, or decisions, which can influence physical and virtual environments, and to a capability of AI systems to derive models or algorithms, or both, from inputs or data. The techniques that enable inference while building an AI system include machine learning approaches that learn from data how to achieve certain objectives, and logic- and knowledge-based approaches that infer from encoded knowledge or symbolic representation of the task to be solved. The capacity of an AI system to infer transcends basic data processing by enabling learning, reasoning or modelling. The term ‘machine-based’ refers to the fact that AI systems run on machines. The reference to explicit or implicit objectives underscores that AI systems can operate according to explicit defined objectives or to implicit objectives. The objectives of the AI system may be different from the intended purpose of the AI system in a specific context. For the purposes of this Regulation, environments should be understood to be the contexts in which the AI systems operate, whereas outputs generated by the AI system reflect different functions performed by AI systems and include predictions, content, recommendations or decisions. AI systems are designed to operate with varying levels of autonomy, meaning that they have some degree of independence of actions from human involvement and of capabilities to operate without human intervention. The adaptiveness that an AI system could exhibit after deployment, refers to self-learning capabilities, allowing the system to change while in use. AI systems can be used on a stand-alone basis or as a component of a product, irrespective of whether the system is physically integrated into the product (embedded) or serves the functionality of the product without being integrated therein (non-embedded).\n(13)\nThe notion of ‘deployer’ referred to in this Regulation should be interpreted as any natural or legal person, including a public authority, agency or other body, using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity. Depending on the type of AI system, the use of the system may affect persons other than the deployer.\n(14)\nThe notion of ‘biometric data’ used in this Regulation should be interpreted in light of the notion of biometric data as defined in Article 4, point (14) of Regulation (EU) 2016/679, Article 3, point (18) of Regulation (EU) 2018/1725 and Article 3, point (13) of Directive (EU) 2016/680. Biometric data can allow for the authentication, identification or categorisation of natural persons and for the recognition of emotions of natural persons.\n(15)\nThe notion of ‘biometric identification’ referred to in this Regulation should be defined as the automated recognition of physical, physiological and behavioural human features such as the face, eye movement, body shape, voice, prosody, gait, posture, heart rate, blood pressure, odour, keystrokes characteristics, for the purpose of establishing an individual’s identity by comparing biometric data of that individual to stored biometric data of individuals in a reference database, irrespective of whether the individual has given its consent or not. This excludes AI systems intended to be used for biometric verification, which includes authentication, whose sole purpose is to confirm that a specific natural person is the person he or she claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having security access to premises.\n(16)\nThe notion of ‘biometric categorisation’ referred to in this Regulation should be defined as assigning natural persons to specific categories on the basis of their biometric data. Such specific categories can relate to aspects such as sex, age, hair colour, eye colour, tattoos, behavioural or personality traits, language, religion, membership of a national minority, sexual or political orientation. This does not include biometric categorisation systems that are a purely ancillary feature intrinsically linked to another commercial service, meaning that the feature cannot, for objective technical reasons, be used without the principal service, and the integration of that feature or functionality is not a means to circumvent the applicability of the rules of this Regulation. For example, filters categorising facial or body features used on online marketplaces could constitute such an ancillary feature as they can be used only in relation to the principal service which consists in selling a product by allowing the consumer to preview the display of the product on him or herself and help the consumer to make a purchase decision. Filters used on online social network services which categorise facial or body features to allow users to add or modify pictures or videos could also be considered to be ancillary feature as such filter cannot be used without the principal service of the social network services consisting in the sharing of content online.\n(17)\nThe notion of ‘remote biometric identification system’ referred to in this Regulation should be defined functionally, as an AI system intended for the identification of natural persons without their active involvement, typically at a distance, through the comparison of a person’s biometric data with the biometric data contained in a reference database, irrespectively of the particular technology, processes or types of biometric data used. Such remote biometric identification systems are typically used to perceive multiple persons or their behaviour simultaneously in order to facilitate significantly the identification of natural persons without their active involvement. This excludes AI systems intended to be used for biometric verification, which includes authentication, the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having security access to premises. That exclusion is justified by the fact that such systems are likely to have a minor impact on fundamental rights of natural persons compared to the remote biometric identification systems which may be used for the processing of the biometric data of a large number of persons without their active involvement. In the case of ‘real-time’ systems, the capturing of the biometric data, the comparison and the identification occur all instantaneously, near-instantaneously or in any event without a significant delay. In this regard, there should be no scope for circumventing the rules of this Regulation on the ‘real-time’ use of the AI systems concerned by providing for minor delays. ‘Real-time’ systems involve the use of ‘live’ or ‘near-live’ material, such as video footage, generated by a camera or other device with similar functionality. In the case of ‘post’ systems, in contrast, the biometric data has already been captured and the comparison and identification occur only after a significant delay. This involves material, such as pictures or video footage generated by closed circuit television cameras or private devices, which has been generated before the use of the system in respect of the natural persons concerned.\n(18)\nThe notion of ‘emotion recognition system’ referred to in this Regulation should be defined as an AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data. The notion refers to emotions or intentions such as happiness, sadness, anger, surprise, disgust, embarrassment, excitement, shame, contempt, satisfaction and amusement. It does not include physical states, such as pain or fatigue, including, for example, systems used in detecting the state of fatigue of professional pilots or drivers for the purpose of preventing accidents. This does also not include the mere detection of readily apparent expressions, gestures or movements, unless they are used for identifying or inferring emotions. Those expressions can be basic facial expressions, such as a frown or a smile, or gestures such as the movement of hands, arms or head, or characteristics of a person’s voice, such as a raised voice or whispering.\n(19)\nFor the purposes of this Regulation the notion of ‘publicly accessible space’ should be understood as referring to any physical space that is accessible to an undetermined number of natural persons, and irrespective of whether the space in question is privately or publicly owned, irrespective of the activity for which the space may be used, such as for commerce, for example, shops, restaurants, cafés; for services, for example, banks, professional activities, hospitality; for sport, for example, swimming pools, gyms, stadiums; for transport, for example, bus, metro and railway stations, airports, means of transport; for entertainment, for example, cinemas, theatres, museums, concert and conference halls; or for leisure or otherwise, for example, public roads and squares, parks, forests, playgrounds. A space should also be classified as being publicly accessible if, regardless of potential capacity or security restrictions, access is subject to certain predetermined conditions which can be fulfilled by an undetermined number of persons, such as the purchase of a ticket or title of transport, prior registration or having a certain age. In contrast, a space should not be considered to be publicly accessible if access is limited to specific and defined natural persons through either Union or national law directly related to public safety or security or through the clear manifestation of will by the person having the relevant authority over the space. The factual possibility of access alone, such as an unlocked door or an open gate in a fence, does not imply that the space is publicly accessible in the presence of indications or circumstances suggesting the contrary, such as. signs prohibiting or restricting access. Company and factory premises, as well as offices and workplaces that are intended to be accessed only by relevant employees and service providers, are spaces that are not publicly accessible. Publicly accessible spaces should not include prisons or border control. Some other spaces may comprise both publicly accessible and non-publicly accessible spaces, such as the hallway of a private residential building necessary to access a doctor’s office or an airport. Online spaces are not covered, as they are not physical spaces. Whether a given space is accessible to the public should however be determined on a case-by-case basis, having regard to the specificities of the individual situation at hand.\n(20)\nIn order to obtain the greatest benefits from AI systems while protecting fundamental rights, health and safety and to enable democratic control, AI literacy should equip providers, deployers and affected persons with the necessary notions to make informed decisions regarding AI systems. Those notions may vary with regard to the relevant context and can include understanding the correct application of technical elements during the AI system’s development phase, the measures to be applied during its use, the suitable ways in which to interpret the AI system’s output, and, in the case of affected persons, the knowledge necessary to understand how decisions taken with the assistance of AI will have an impact on them. In the context of the application this Regulation, AI literacy should provide all relevant actors in the AI value chain with the insights required to ensure the appropriate compliance and its correct enforcement. Furthermore, the wide implementation of AI literacy measures and the introduction of appropriate follow-up actions could contribute to improving working conditions and ultimately sustain the consolidation, and innovation path of trustworthy AI in the Union. The European Artificial Intelligence Board (the ‘Board’) should support the Commission, to promote AI literacy tools, public awareness and understanding of the benefits, risks, safeguards, rights and obligations in relation to the use of AI systems. In cooperation with the relevant stakeholders, the Commission and the Member States should facilitate the drawing up of voluntary codes of conduct to advance AI literacy among persons dealing with the development, operation and use of AI.\n(21)\nIn order to ensure a level playing field and an effective protection of rights and freedoms of individuals across the Union, the rules established by this Regulation should apply to providers of AI systems in a non-discriminatory manner, irrespective of whether they are established within the Union or in a third country, and to deployers of AI systems established within the Union.\n(22)\nIn light of their digital nature, certain AI systems should fall within the scope of this Regulation even when they are not placed on the market, put into service, or used in the Union. This is the case, for example, where an operator established in the Union contracts certain services to an operator established in a third country in relation to an activity to be performed by an AI system that would qualify as high-risk. In those circumstances, the AI system used in a third country by the operator could process data lawfully collected in and transferred from the Union, and provide to the contracting operator in the Union the output of that AI system resulting from that processing, without that AI system being placed on the market, put into service or used in the Union. To prevent the circumvention of this Regulation and to ensure an effective protection of natural persons located in the Union, this Regulation should also apply to providers and deployers of AI systems that are established in a third country, to the extent the output produced by those systems is intended to be used in the Union. Nonetheless, to take into account existing arrangements and special needs for future cooperation with foreign partners with whom information and evidence is exchanged, this Regulation should not apply to public authorities of a third country and international organisations when acting in the framework of cooperation or international agreements concluded at Union or national level for law enforcement and judicial cooperation with the Union or the Member States, provided that the relevant third country or international organisation provides adequate safeguards with respect to the protection of fundamental rights and freedoms of individuals. Where relevant, this may cover activities of entities entrusted by the third countries to carry out specific tasks in support of such law enforcement and judicial cooperation. Such framework for cooperation or agreements have been established bilaterally between Member States and third countries or between the European Union, Europol and other Union agencies and third countries and international organisations. The authorities competent for supervision of the law enforcement and judicial authorities under this Regulation should assess whether those frameworks for cooperation or international agreements include adequate safeguards with respect to the protection of fundamental rights and freedoms of individuals. Recipient national authorities and Union institutions, bodies, offices and agencies making use of such outputs in the Union remain accountable to ensure their use complies with Union law. When those international agreements are revised or new ones are concluded in the future, the contracting parties should make utmost efforts to align those agreements with the requirements of this Regulation.\n(23)\nThis Regulation should also apply to Union institutions, bodies, offices and agencies when acting as a provider or deployer of an AI system.\n(24)\nIf, and insofar as, AI systems are placed on the market, put into service, or used with or without modification of such systems for military, defence or national security purposes, those should be excluded from the scope of this Regulation regardless of which type of entity is carrying out those activities, such as whether it is a public or private entity. As regards military and defence purposes, such exclusion is justified both by Article 4(2) TEU and by the specificities of the Member States’ and the common Union defence policy covered by Chapter 2 of Title V TEU that are subject to public international law, which is therefore the more appropriate legal framework for the regulation of AI systems in the context of the use of lethal force and other AI systems in the context of military and defence activities. As regards national security purposes, the exclusion is justified both by the fact that national security remains the sole responsibility of Member States in accordance with Article 4(2) TEU and by the specific nature and operational needs of national security activities and specific national rules applicable to those activities. Nonetheless, if an AI system developed, placed on the market, put into service or used for military, defence or national security purposes is used outside those temporarily or permanently for other purposes, for example, civilian or humanitarian purposes, law enforcement or public security purposes, such a system would fall within the scope of this Regulation. In that case, the entity using the AI system for other than military, defence or national security purposes should ensure the compliance of the AI system with this Regulation, unless the system is already compliant with this Regulation. AI systems placed on the market or put into service for an excluded purpose, namely military, defence or national security, and one or more non-excluded purposes, such as civilian purposes or law enforcement, fall within the scope of this Regulation and providers of those systems should ensure compliance with this Regulation. In those cases, the fact that an AI system may fall within the scope of this Regulation should not affect the possibility of entities carrying out national security, defence and military activities, regardless of the type of entity carrying out those activities, to use AI systems for national security, military and defence purposes, the use of which is excluded from the scope of this Regulation. An AI system placed on the market for civilian or law enforcement purposes which is used with or without modification for military, defence or national security purposes should not fall within the scope of this Regulation, regardless of the type of entity carrying out those activities.\n(25)\nThis Regulation should support innovation, should respect freedom of science, and should not undermine research and development activity. It is therefore necessary to exclude from its scope AI systems and models specifically developed and put into service for the sole purpose of scientific research and development. Moreover, it is necessary to ensure that this Regulation does not otherwise affect scientific research and development activity on AI systems or models prior to being placed on the market or put into service. As regards product-oriented research, testing and development activity regarding AI systems or models, the provisions of this Regulation should also not apply prior to those systems and models being put into service or placed on the market. That exclusion is without prejudice to the obligation to comply with this Regulation where an AI system falling into the scope of this Regulation is placed on the market or put into service as a result of such research and development activity and to the application of provisions on AI regulatory sandboxes and testing in real world conditions. Furthermore, without prejudice to the exclusion of AI systems specifically developed and put into service for the sole purpose of scientific research and development, any other AI system that may be used for the conduct of any research and development activity should remain subject to the provisions of this Regulation. In any event, any research and development activity should be carried out in accordance with recognised ethical and professional standards for scientific research and should be conducted in accordance with applicable Union law.\n(26)\nIn order to introduce a proportionate and effective set of binding rules for AI systems, a clearly defined risk-based approach should be followed. That approach should tailor the type and content of such rules to the intensity and scope of the risks that AI systems can generate. It is therefore necessary to prohibit certain unacceptable AI practices, to lay down requirements for high-risk AI systems and obligations for the relevant operators, and to lay down transparency obligations for certain AI systems.\n(27)\nWhile the risk-based approach is the basis for a proportionate and effective set of binding rules, it is important to recall the 2019 Ethics guidelines for trustworthy AI developed by the independent AI HLEG appointed by the Commission. In those guidelines, the AI HLEG developed seven non-binding ethical principles for AI which are intended to help ensure that AI is trustworthy and ethically sound. The seven principles include human agency and oversight; technical robustness and safety; privacy and data governance; transparency; diversity, non-discrimination and fairness; societal and environmental well-being and accountability. Without prejudice to the legally binding requirements of this Regulation and any other applicable Union law, those guidelines contribute to the design of coherent, trustworthy and human-centric AI, in line with the Charter and with the values on which the Union is founded. According to the guidelines of the AI HLEG, human agency and oversight means that AI systems are developed and used as a tool that serves people, respects human dignity and personal autonomy, and that is functioning in a way that can be appropriately controlled and overseen by humans. Technical robustness and safety means that AI systems are developed and used in a way that allows robustness in the case of problems and resilience against attempts to alter the use or performance of the AI system so as to allow unlawful use by third parties, and minimise unintended harm. Privacy and data governance means that AI systems are developed and used in accordance with privacy and data protection rules, while processing data that meets high standards in terms of quality and integrity. Transparency means that AI systems are developed and used in a way that allows appropriate traceability and explainability, while making humans aware that they communicate or interact with an AI system, as well as duly informing deployers of the capabilities and limitations of that AI system and affected persons about their rights. Diversity, non-discrimination and fairness means that AI systems are developed and used in a way that includes diverse actors and promotes equal access, gender equality and cultural diversity, while avoiding discriminatory impacts and unfair biases that are prohibited by Union or national law. Social and environmental well-being means that AI systems are developed and used in a sustainable and environmentally friendly manner as well as in a way to benefit all human beings, while monitoring and assessing the long-term impacts on the individual, society and democracy. The application of those principles should be translated, when possible, in the design and use of AI models. They should in any case serve as a basis for the drafting of codes of conduct under this Regulation. All stakeholders, including industry, academia, civil society and standardisation organisations, are encouraged to take into account, as appropriate, the ethical principles for the development of voluntary best practices and standards.\n(28)\nAside from the many beneficial uses of AI, it can also be misused and provide novel and powerful tools for manipulative, exploitative and social control practices. Such practices are particularly harmful and abusive and should be prohibited because they contradict Union values of respect for human dignity, freedom, equality, democracy and the rule of law and fundamental rights enshrined in the Charter, including the right to non-discrimination, to data protection and to privacy and the rights of the child.\n(29)\nAI-enabled manipulative techniques can be used to persuade persons to engage in unwanted behaviours, or to deceive them by nudging them into decisions in a way that subverts and impairs their autonomy, decision-making and free choices. The placing on the market, the putting into service or the use of certain AI systems with the objective to or the effect of materially distorting human behaviour, whereby significant harms, in particular having sufficiently important adverse impacts on physical, psychological health or financial interests are likely to occur, are particularly dangerous and should therefore be prohibited. Such AI systems deploy subliminal components such as audio, image, video stimuli that persons cannot perceive, as those stimuli are beyond human perception, or other manipulative or deceptive techniques that subvert or impair person’s autonomy, decision-making or free choice in ways that people are not consciously aware of those techniques or, where they are aware of them, can still be deceived or are not able to control or resist them. This could be facilitated, for example, by machine-brain interfaces or virtual reality as they allow for a higher degree of control of what stimuli are presented to persons, insofar as they may materially distort their behaviour in a significantly harmful manner. In addition, AI systems may also otherwise exploit the vulnerabilities of a person or a specific group of persons due to their age, disability within the meaning of Directive (EU) 2019/882 of the European Parliament and of the Council (16), or a specific social or economic situation that is likely to make those persons more vulnerable to exploitation such as persons living in extreme poverty, ethnic or religious minorities. Such AI systems can be placed on the market, put into service or used with the objective to or the effect of materially distorting the behaviour of a person and in a manner that causes or is reasonably likely to cause significant harm to that or another person or groups of persons, including harms that may be accumulated over time and should therefore be prohibited. It may not be possible to assume that there is an intention to distort behaviour where the distortion results from factors external to the AI system which are outside the control of the provider or the deployer, namely factors that may not be reasonably foreseeable and therefore not possible for the provider or the deployer of the AI system to mitigate. In any case, it is not necessary for the provider or the deployer to have the intention to cause significant harm, provided that such harm results from the manipulative or exploitative AI-enabled practices. The prohibitions for such AI practices are complementary to the provisions contained in Directive 2005/29/EC of the European Parliament and of the Council (17), in particular unfair commercial practices leading to economic or financial harms to consumers are prohibited under all circumstances, irrespective of whether they are put in place through AI systems or otherwise. The prohibitions of manipulative and exploitative practices in this Regulation should not affect lawful practices in the context of medical treatment such as psychological treatment of a mental disease or physical rehabilitation, when those practices are carried out in accordance with the applicable law and medical standards, for example explicit consent of the individuals or their legal representatives. In addition, common and legitimate commercial practices, for example in the field of advertising, that comply with the applicable law should not, in themselves, be regarded as constituting harmful manipulative AI-enabled practices.\n(30)\nBiometric categorisation systems that are based on natural persons’ biometric data, such as an individual person’s face or fingerprint, to deduce or infer an individuals’ political opinions, trade union membership, religious or philosophical beliefs, race, sex life or sexual orientation should be prohibited. That prohibition should not cover the lawful labelling, filtering or categorisation of biometric data sets acquired in line with Union or national law according to biometric data, such as the sorting of images according to hair colour or eye colour, which can for example be used in the area of law enforcement.\n(31)\nAI systems providing social scoring of natural persons by public or private actors may lead to discriminatory outcomes and the exclusion of certain groups. They may violate the right to dignity and non-discrimination and the values of equality and justice. Such AI systems evaluate or classify natural persons or groups thereof on the basis of multiple data points related to their social behaviour in multiple contexts or known, inferred or predicted personal or personality characteristics over certain periods of time. The social score obtained from such AI systems may lead to the detrimental or unfavourable treatment of natural persons or whole groups thereof in social contexts, which are unrelated to the context in which the data was originally generated or collected or to a detrimental treatment that is disproportionate or unjustified to the gravity of their social behaviour. AI systems entailing such unacceptable scoring practices and leading to such detrimental or unfavourable outcomes should therefore be prohibited. That prohibition should not affect lawful evaluation practices of natural persons that are carried out for a specific purpose in accordance with Union and national law.\n(32)\nThe use of AI systems for ‘real-time’ remote biometric identification of natural persons in publicly accessible spaces for the purpose of law enforcement is particularly intrusive to the rights and freedoms of the concerned persons, to the extent that it may affect the private life of a large part of the population, evoke a feeling of constant surveillance and indirectly dissuade the exercise of the freedom of assembly and other fundamental rights. Technical inaccuracies of AI systems intended for the remote biometric identification of natural persons can lead to biased results and entail discriminatory effects. Such possible biased results and discriminatory effects are particularly relevant with regard to age, ethnicity, race, sex or disabilities. In addition, the immediacy of the impact and the limited opportunities for further checks or corrections in relation to the use of such systems operating in real-time carry heightened risks for the rights and freedoms of the persons concerned in the context of, or impacted by, law enforcement activities.\n(33)\nThe use of those systems for the purpose of law enforcement should therefore be prohibited, except in exhaustively listed and narrowly defined situations, where the use is strictly necessary to achieve a substantial public interest, the importance of which outweighs the risks. Those situations involve the search for certain victims of crime including missing persons; certain threats to the life or to the physical safety of natural persons or of a terrorist attack; and the localisation or identification of perpetrators or suspects of the criminal offences listed in an annex to this Regulation, where those criminal offences are punishable in the Member State concerned by a custodial sentence or a detention order for a maximum period of at least four years and as they are defined in the law of that Member State. Such a threshold for the custodial sentence or detention order in accordance with national law contributes to ensuring that the offence should be serious enough to potentially justify the use of ‘real-time’ remote biometric identification systems. Moreover, the list of criminal offences provided in an annex to this Regulation is based on the 32 criminal offences listed in the Council Framework Decision 2002/584/JHA (18), taking into account that some of those offences are, in practice, likely to be more relevant than others, in that the recourse to ‘real-time’ remote biometric identification could, foreseeably, be necessary and proportionate to highly varying degrees for the practical pursuit of the localisation or identification of a perpetrator or suspect of the different criminal offences listed and having regard to the likely differences in the seriousness, probability and scale of the harm or possible negative consequences. An imminent threat to life or the physical safety of natural persons could also result from a serious disruption of critical infrastructure, as defined in Article 2, point (4) of Directive (EU) 2022/2557 of the European Parliament and of the Council (19), where the disruption or destruction of such critical infrastructure would result in an imminent threat to life or the physical safety of a person, including through serious harm to the provision of basic supplies to the population or to the exercise of the core function of the State. In addition, this Regulation should preserve the ability for law enforcement, border control, immigration or asylum authorities to carry out identity checks in the presence of the person concerned in accordance with the conditions set out in Union and national law for such checks. In particular, law enforcement, border control, immigration or asylum authorities should be able to use information systems, in accordance with Union or national law, to identify persons who, during an identity check, either refuse to be identified or are unable to state or prove their identity, without being required by this Regulation to obtain prior authorisation. This could be, for example, a person involved in a crime, being unwilling, or unable due to an accident or a medical condition, to disclose their identity to law enforcement authorities.\n(34)\nIn order to ensure that those systems are used in a responsible and proportionate manner, it is also important to establish that, in each of those exhaustively listed and narrowly defined situations, certain elements should be taken into account, in particular as regards the nature of the situation giving rise to the request and the consequences of the use for the rights and freedoms of all persons concerned and the safeguards and conditions provided for with the use. In addition, the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement should be deployed only to confirm the specifically targeted individual’s identity and should be limited to what is strictly necessary concerning the period of time, as well as the geographic and personal scope, having regard in particular to the evidence or indications regarding the threats, the victims or perpetrator. The use of the real-time remote biometric identification system in publicly accessible spaces should be authorised only if the relevant law enforcement authority has completed a fundamental rights impact assessment and, unless provided otherwise in this Regulation, has registered the system in the database as set out in this Regulation. The reference database of persons should be appropriate for each use case in each of the situations mentioned above.\n(35)\nEach use of a ‘real-time’ remote biometric identification system in publicly accessible spaces for the purpose of law enforcement should be subject to an express and specific authorisation by a judicial authority or by an independent administrative authority of a Member State whose decision is binding. Such authorisation should, in principle, be obtained prior to the use of the AI system with a view to identifying a person or persons. Exceptions to that rule should be allowed in duly justified situations on grounds of urgency, namely in situations where the need to use the systems concerned is such as to make it effectively and objectively impossible to obtain an authorisation before commencing the use of the AI system. In such situations of urgency, the use of the AI system should be restricted to the absolute minimum necessary and should be subject to appropriate safeguards and conditions, as determined in national law and specified in the context of each individual urgent use case by the law enforcement authority itself. In addition, the law enforcement authority should in such situations request such authorisation while providing the reasons for not having been able to request it earlier, without undue delay and at the latest within 24 hours. If such an authorisation is rejected, the use of real-time biometric identification systems linked to that authorisation should cease with immediate effect and all the data related to such use should be discarded and deleted. Such data includes input data directly acquired by an AI system in the course of the use of such system as well as the results and outputs of the use linked to that authorisation. It should not include input that is legally acquired in accordance with another Union or national law. In any case, no decision producing an adverse legal effect on a person should be taken based solely on the output of the remote biometric identification system.\n(36)\nIn order to carry out their tasks in accordance with the requirements set out in this Regulation as well as in national rules, the relevant market surveillance authority and the national data protection authority should be notified of each use of the real-time biometric identification system. Market surveillance authorities and the national data protection authorities that have been notified should submit to the Commission an annual report on the use of real-time biometric identification systems.\n(37)\nFurthermore, it is appropriate to provide, within the exhaustive framework set by this Regulation that such use in the territory of a Member State in accordance with this Regulation should only be possible where and in as far as the Member State concerned has decided to expressly provide for the possibility to authorise such use in its detailed rules of national law. Consequently, Member States remain free under this Regulation not to provide for such a possibility at all or to only provide for such a possibility in respect of some of the objectives capable of justifying authorised use identified in this Regulation. Such national rules should be notified to the Commission within 30 days of their adoption.\n(38)\nThe use of AI systems for real-time remote biometric identification of natural persons in publicly accessible spaces for the purpose of law enforcement necessarily involves the processing of biometric data. The rules of this Regulation that prohibit, subject to certain exceptions, such use, which are based on Article 16 TFEU, should apply as lex specialis in respect of the rules on the processing of biometric data contained in Article 10 of Directive (EU) 2016/680, thus regulating such use and the processing of biometric data involved in an exhaustive manner. Therefore, such use and processing should be possible only in as far as it is compatible with the framework set by this Regulation, without there being scope, outside that framework, for the competent authorities, where they act for purpose of law enforcement, to use such systems and process such data in connection thereto on the grounds listed in Article 10 of Directive (EU) 2016/680. In that context, this Regulation is not intended to provide the legal basis for the processing of personal data under Article 8 of Directive (EU) 2016/680. However, the use of real-time remote biometric identification systems in publicly accessible spaces for purposes other than law enforcement, including by competent authorities, should not be covered by the specific framework regarding such use for the purpose of law enforcement set by this Regulation. Such use for purposes other than law enforcement should therefore not be subject to the requirement of an authorisation under this Regulation and the applicable detailed rules of national law that may give effect to that authorisation.\n(39)\nAny processing of biometric data and other personal data involved in the use of AI systems for biometric identification, other than in connection to the use of real-time remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement as regulated by this Regulation, should continue to comply with all requirements resulting from Article 10 of Directive (EU) 2016/680. For purposes other than law enforcement, Article 9(1) of Regulation (EU) 2016/679 and Article 10(1) of Regulation (EU) 2018/1725 prohibit the processing of biometric data subject to limited exceptions as provided in those Articles. In the application of Article 9(1) of Regulation (EU) 2016/679, the use of remote biometric identification for purposes other than law enforcement has already been subject to prohibition decisions by national data protection authorities.\n(40)\nIn accordance with Article 6a of Protocol No 21 on the position of the United Kingdom and Ireland in respect of the area of freedom, security and justice, as annexed to the TEU and to the TFEU, Ireland is not bound by the rules laid down in Article 5(1), first subparagraph, point (g), to the extent it applies to the use of biometric categorisation systems for activities in the field of police cooperation and judicial cooperation in criminal matters, Article 5(1), first subparagraph, point (d), to the extent it applies to the use of AI systems covered by that provision, Article 5(1), first subparagraph, point (h), Article 5(2) to (6) and Article 26(10) of this Regulation adopted on the basis of Article 16 TFEU which relate to the processing of personal data by the Member States when carrying out activities falling within the scope of Chapter 4 or Chapter 5 of Title V of Part Three of the TFEU, where Ireland is not bound by the rules governing the forms of judicial cooperation in criminal matters or police cooperation which require compliance with the provisions laid down on the basis of Article 16 TFEU.\n(41)\nIn accordance with Articles 2 and 2a of Protocol No 22 on the position of Denmark, annexed to the TEU and to the TFEU, Denmark is not bound by rules laid down in Article 5(1), first subparagraph, point (g), to the extent it applies to the use of biometric categorisation systems for activities in the field of police cooperation and judicial cooperation in criminal matters, Article 5(1), first subparagraph, point (d), to the extent it applies to the use of AI systems covered by that provision, Article 5(1), first subparagraph, point (h), (2) to (6) and Article 26(10) of this Regulation adopted on the basis of Article 16 TFEU, or subject to their application, which relate to the processing of personal data by the Member States when carrying out activities falling within the scope of Chapter 4 or Chapter 5 of Title V of Part Three of the TFEU.\n(42)\nIn line with the presumption of innocence, natural persons in the Union should always be judged on their actual behaviour. Natural persons should never be judged on AI-predicted behaviour based solely on their profiling, personality traits or characteristics, such as nationality, place of birth, place of residence, number of children, level of debt or type of car, without a reasonable suspicion of that person being involved in a criminal activity based on objective verifiable facts and without human assessment thereof. Therefore, risk assessments carried out with regard to natural persons in order to assess the likelihood of their offending or to predict the occurrence of an actual or potential criminal offence based solely on profiling them or on assessing their personality traits and characteristics should be prohibited. In any case, that prohibition does not refer to or touch upon risk analytics that are not based on the profiling of individuals or on the personality traits and characteristics of individuals, such as AI systems using risk analytics to assess the likelihood of financial fraud by undertakings on the basis of suspicious transactions or risk analytic tools to predict the likelihood of the localisation of narcotics or illicit goods by customs authorities, for example on the basis of known trafficking routes.\n(43)\nThe placing on the market, the putting into service for that specific purpose, or the use of AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage, should be prohibited because that practice adds to the feeling of mass surveillance and can lead to gross violations of fundamental rights, including the right to privacy.\n(44)\nThere are serious concerns about the scientific basis of AI systems aiming to identify or infer emotions, particularly as expression of emotions vary considerably across cultures and situations, and even within a single individual. Among the key shortcomings of such systems are the limited reliability, the lack of specificity and the limited generalisability. Therefore, AI systems identifying or inferring emotions or intentions of natural persons on the basis of their biometric data may lead to discriminatory outcomes and can be intrusive to the rights and freedoms of the concerned persons. Considering the imbalance of power in the context of work or education, combined with the intrusive nature of these systems, such systems could lead to detrimental or unfavourable treatment of certain natural persons or whole groups thereof. Therefore, the placing on the market, the putting into service, or the use of AI systems intended to be used to detect the emotional state of individuals in situations related to the workplace and education should be prohibited. That prohibition should not cover AI systems placed on the market strictly for medical or safety reasons, such as systems intended for therapeutical use.\n(45)\nPractices that are prohibited by Union law, including data protection law, non-discrimination law, consumer protection law, and competition law, should not be affected by this Regulation.\n(46)\nHigh-risk AI systems should only be placed on the Union market, put into service or used if they comply with certain mandatory requirements. Those requirements should ensure that high-risk AI systems available in the Union or whose output is otherwise used in the Union do not pose unacceptable risks to important Union public interests as recognised and protected by Union law. On the basis of the New Legislative Framework, as clarified in the Commission notice ‘The “Blue Guide” on the implementation of EU product rules 2022’ (20), the general rule is that more than one legal act of Union harmonisation legislation, such as Regulations (EU) 2017/745 (21) and (EU) 2017/746 (22) of the European Parliament and of the Council or Directive 2006/42/EC of the European Parliament and of the Council (23), may be applicable to one product, since the making available or putting into service can take place only when the product complies with all applicable Union harmonisation legislation. To ensure consistency and avoid unnecessary administrative burdens or costs, providers of a product that contains one or more high-risk AI systems, to which the requirements of this Regulation and of the Union harmonisation legislation listed in an annex to this Regulation apply, should have flexibility with regard to operational decisions on how to ensure compliance of a product that contains one or more AI systems with all applicable requirements of the Union harmonisation legislation in an optimal manner. AI systems identified as high-risk should be limited to those that have a significant harmful impact on the health, safety and fundamental rights of persons in the Union and such limitation should minimise any potential restriction to international trade.\n(47)\nAI systems could have an adverse impact on the health and safety of persons, in particular when such systems operate as safety components of products. Consistent with the objectives of Union harmonisation legislation to facilitate the free movement of products in the internal market and to ensure that only safe and otherwise compliant products find their way into the market, it is important that the safety risks that may be generated by a product as a whole due to its digital components, including AI systems, are duly prevented and mitigated. For instance, increasingly autonomous robots, whether in the context of manufacturing or personal assistance and care should be able to safely operate and performs their functions in complex environments. Similarly, in the health sector where the stakes for life and health are particularly high, increasingly sophisticated diagnostics systems and systems supporting human decisions should be reliable and accurate.\n(48)\nThe extent of the adverse impact caused by the AI system on the fundamental rights protected by the Charter is of particular relevance when classifying an AI system as high risk. Those rights include the right to human dignity, respect for private and family life, protection of personal data, freedom of expression and information, freedom of assembly and of association, the right to non-discrimination, the right to education, consumer protection, workers’ rights, the rights of persons with disabilities, gender equality, intellectual property rights, the right to an effective remedy and to a fair trial, the right of defence and the presumption of innocence, and the right to good administration. In addition to those rights, it is important to highlight the fact that children have specific rights as enshrined in Article 24 of the Charter and in the United Nations Convention on the Rights of the Child, further developed in the UNCRC General Comment No 25 as regards the digital environment, both of which require consideration of the children’s vulnerabilities and provision of such protection and care as necessary for their well-being. The fundamental right to a high level of environmental protection enshrined in the Charter and implemented in Union policies should also be considered when assessing the severity of the harm that an AI system can cause, including in relation to the health and safety of persons.\n(49)\nAs regards high-risk AI systems that are safety components of products or systems, or which are themselves products or systems falling within the scope of Regulation (EC) No 300/2008 of the European Parliament and of the Council (24), Regulation (EU) No 167/2013 of the European Parliament and of the Council (25), Regulation (EU) No 168/2013 of the European Parliament and of the Council (26), Directive 2014/90/EU of the European Parliament and of the Council (27), Directive (EU) 2016/797 of the European Parliament and of the Council (28), Regulation (EU) 2018/858 of the European Parliament and of the Council (29), Regulation (EU) 2018/1139 of the European Parliament and of the Council (30), and Regulation (EU) 2019/2144 of the European Parliament and of the Council (31), it is appropriate to amend those acts to ensure that the Commission takes into account, on the basis of the technical and regulatory specificities of each sector, and without interfering with existing governance, conformity assessment and enforcement mechanisms and authorities established therein, the mandatory requirements for high-risk AI systems laid down in this Regulation when adopting any relevant delegated or implementing acts on the basis of those acts.\n(50)\nAs regards AI systems that are safety components of products, or which are themselves products, falling within the scope of certain Union harmonisation legislation listed in an annex to this Regulation, it is appropriate to classify them as high-risk under this Regulation if the product concerned undergoes the conformity assessment procedure with a third-party conformity assessment body pursuant to that relevant Union harmonisation legislation. In particular, such products are machinery, toys, lifts, equipment and protective systems intended for use in potentially explosive atmospheres, radio equipment, pressure equipment, recreational craft equipment, cableway installations, appliances burning gaseous fuels, medical devices, in vitro diagnostic medical devices, automotive and aviation.\n(51)\nThe classification of an AI system as high-risk pursuant to this Regulation should not necessarily mean that the product whose safety component is the AI system, or the AI system itself as a product, is considered to be high-risk under the criteria established in the relevant Union harmonisation legislation that applies to the product. This is, in particular, the case for Regulations (EU) 2017/745 and (EU) 2017/746, where a third-party conformity assessment is provided for medium-risk and high-risk products.\n(52)\nAs regards stand-alone AI systems, namely high-risk AI systems other than those that are safety components of products, or that are themselves products, it is appropriate to classify them as high-risk if, in light of their intended purpose, they pose a high risk of harm to the health and safety or the fundamental rights of persons, taking into account both the severity of the possible harm and its probability of occurrence and they are used in a number of specifically pre-defined areas specified in this Regulation. The identification of those systems is based on the same methodology and criteria envisaged also for any future amendments of the list of high-risk AI systems that the Commission should be empowered to adopt, via delegated acts, to take into account the rapid pace of technological development, as well as the potential changes in the use of AI systems.\n(53)\nIt is also important to clarify that there may be specific cases in which AI systems referred to in pre-defined areas specified in this Regulation do not lead to a significant risk of harm to the legal interests protected under those areas because they do not materially influence the decision-making or do not harm those interests substantially. For the purposes of this Regulation, an AI system that does not materially influence the outcome of decision-making should be understood to be an AI system that does not have an impact on the substance, and thereby the outcome, of decision-making, whether human or automated. An AI system that does not materially influence the outcome of decision-making could include situations in which one or more of the following conditions are fulfilled. The first such condition should be that the AI system is intended to perform a narrow procedural task, such as an AI system that transforms unstructured data into structured data, an AI system that classifies incoming documents into categories or an AI system that is used to detect duplicates among a large number of applications. Those tasks are of such narrow and limited nature that they pose only limited risks which are not increased through the use of an AI system in a context that is listed as a high-risk use in an annex to this Regulation. The second condition should be that the task performed by the AI system is intended to improve the result of a previously completed human activity that may be relevant for the purposes of the high-risk uses listed in an annex to this Regulation. Considering those characteristics, the AI system provides only an additional layer to a human activity with consequently lowered risk. That condition would, for example, apply to AI systems that are intended to improve the language used in previously drafted documents, for example in relation to professional tone, academic style of language or by aligning text to a certain brand messaging. The third condition should be that the AI system is intended to detect decision-making patterns or deviations from prior decision-making patterns. The risk would be lowered because the use of the AI system follows a previously completed human assessment which it is not meant to replace or influence, without proper human review. Such AI systems include for instance those that, given a certain grading pattern of a teacher, can be used to check ex post whether the teacher may have deviated from the grading pattern so as to flag potential inconsistencies or anomalies. The fourth condition should be that the AI system is intended to perform a task that is only preparatory to an assessment relevant for the purposes of the AI systems listed in an annex to this Regulation, thus making the possible impact of the output of the system very low in terms of representing a risk for the assessment to follow. That condition covers, inter alia, smart solutions for file handling, which include various functions from indexing, searching, text and speech processing or linking data to other data sources, or AI systems used for translation of initial documents. In any case, AI systems used in high-risk use-cases listed in an annex to this Regulation should be considered to pose significant risks of harm to the health, safety or fundamental rights if the AI system implies profiling within the meaning of Article 4, point (4) of Regulation (EU) 2016/679 or Article 3, point (4) of Directive (EU) 2016/680 or Article 3, point (5) of Regulation (EU) 2018/1725. To ensure traceability and transparency, a provider who considers that an AI system is not high-risk on the basis of the conditions referred to above should draw up documentation of the assessment before that system is placed on the market or put into service and should provide that documentation to national competent authorities upon request. Such a provider should be obliged to register the AI system in the EU database established under this Regulation. With a view to providing further guidance for the practical implementation of the conditions under which the AI systems listed in an annex to this Regulation are, on an exceptional basis, non-high-risk, the Commission should, after consulting the Board, provide guidelines specifying that practical implementation, completed by a comprehensive list of practical examples of use cases of AI systems that are high-risk and use cases that are not.\n(54)\nAs biometric data constitutes a special category of personal data, it is appropriate to classify as high-risk several critical-use cases of biometric systems, insofar as their use is permitted under relevant Union and national law. Technical inaccuracies of AI systems intended for the remote biometric identification of natural persons can lead to biased results and entail discriminatory effects. The risk of such biased results and discriminatory effects is particularly relevant with regard to age, ethnicity, race, sex or disabilities. Remote biometric identification systems should therefore be classified as high-risk in view of the risks that they pose. Such a classification excludes AI systems intended to be used for biometric verification, including authentication, the sole purpose of which is to confirm that a specific natural person is who that person claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having secure access to premises. In addition, AI systems intended to be used for biometric categorisation according to sensitive attributes or characteristics protected under Article 9(1) of Regulation (EU) 2016/679 on the basis of biometric data, in so far as these are not prohibited under this Regulation, and emotion recognition systems that are not prohibited under this Regulation, should be classified as high-risk. Biometric systems which are intended to be used solely for the purpose of enabling cybersecurity and personal data protection measures should not be considered to be high-risk AI systems.\n(55)\nAs regards the management and operation of critical infrastructure, it is appropriate to classify as high-risk the AI systems intended to be used as safety components in the management and operation of critical digital infrastructure as listed in point (8) of the Annex to Directive (EU) 2022/2557, road traffic and the supply of water, gas, heating and electricity, since their failure or malfunctioning may put at risk the life and health of persons at large scale and lead to appreciable disruptions in the ordinary conduct of social and economic activities. Safety components of critical infrastructure, including critical digital infrastructure, are systems used to directly protect the physical integrity of critical infrastructure or the health and safety of persons and property but which are not necessary in order for the system to function. The failure or malfunctioning of such components might directly lead to risks to the physical integrity of critical infrastructure and thus to risks to health and safety of persons and property. Components intended to be used solely for cybersecurity purposes should not qualify as safety components. Examples of safety components of such critical infrastructure may include systems for monitoring water pressure or fire alarm controlling systems in cloud computing centres.\n(56)\nThe deployment of AI systems in education is important to promote high-quality digital education and training and to allow all learners and teachers to acquire and share the necessary digital skills and competences, including media literacy, and critical thinking, to take an active part in the economy, society, and in democratic processes. However, AI systems used in education or vocational training, in particular for determining access or admission, for assigning persons to educational and vocational training institutions or programmes at all levels, for evaluating learning outcomes of persons, for assessing the appropriate level of education for an individual and materially influencing the level of education and training that individuals will receive or will be able to access or for monitoring and detecting prohibited behaviour of students during tests should be classified as high-risk AI systems, since they may determine the educational and professional course of a person’s life and therefore may affect that person’s ability to secure a livelihood. When improperly designed and used, such systems may be particularly intrusive and may violate the right to education and training as well as the right not to be discriminated against and perpetuate historical patterns of discrimination, for example against women, certain age groups, persons with disabilities, or persons of certain racial or ethnic origins or sexual orientation.\n(57)\nAI systems used in employment, workers management and access to self-employment, in particular for the recruitment and selection of persons, for making decisions affecting terms of the work-related relationship, promotion and termination of work-related contractual relationships, for allocating tasks on the basis of individual behaviour, personal traits or characteristics and for monitoring or evaluation of persons in work-related contractual relationships, should also be classified as high-risk, since those systems may have an appreciable impact on future career prospects, livelihoods of those persons and workers’ rights. Relevant work-related contractual relationships should, in a meaningful manner, involve employees and persons providing services through platforms as referred to in the Commission Work Programme 2021. Throughout the recruitment process and in the evaluation, promotion, or retention of persons in work-related contractual relationships, such systems may perpetuate historical patterns of discrimination, for example against women, certain age groups, persons with disabilities, or persons of certain racial or ethnic origins or sexual orientation. AI systems used to monitor the performance and behaviour of such persons may also undermine their fundamental rights to data protection and privacy.\n(58)\nAnother area in which the use of AI systems deserves special consideration is the access to and enjoyment of certain essential private and public services and benefits necessary for people to fully participate in society or to improve one’s standard of living. In particular, natural persons applying for or receiving essential public assistance benefits and services from public authorities namely healthcare services, social security benefits, social services providing protection in cases such as maternity, illness, industrial accidents, dependency or old age and loss of employment and social and housing assistance, are typically dependent on those benefits and services and in a vulnerable position in relation to the responsible authorities. If AI systems are used for determining whether such benefits and services should be granted, denied, reduced, revoked or reclaimed by authorities, including whether beneficiaries are legitimately entitled to such benefits or services, those systems may have a significant impact on persons’ livelihood and may infringe their fundamental rights, such as the right to social protection, non-discrimination, human dignity or an effective remedy and should therefore be classified as high-risk. Nonetheless, this Regulation should not hamper the development and use of innovative approaches in the public administration, which would stand to benefit from a wider use of compliant and safe AI systems, provided that those systems do not entail a high risk to legal and natural persons. In addition, AI systems used to evaluate the credit score or creditworthiness of natural persons should be classified as high-risk AI systems, since they determine those persons’ access to financial resources or essential services such as housing, electricity, and telecommunication services. AI systems used for those purposes may lead to discrimination between persons or groups and may perpetuate historical patterns of discrimination, such as that based on racial or ethnic origins, gender, disabilities, age or sexual orientation, or may create new forms of discriminatory impacts. However, AI systems provided for by Union law for the purpose of detecting fraud in the offering of financial services and for prudential purposes to calculate credit institutions’ and insurance undertakings’ capital requirements should not be considered to be high-risk under this Regulation. Moreover, AI systems intended to be used for risk assessment and pricing in relation to natural persons for health and life insurance can also have a significant impact on persons’ livelihood and if not duly designed, developed and used, can infringe their fundamental rights and can lead to serious consequences for people’s life and health, including financial exclusion and discrimination. Finally, AI systems used to evaluate and classify emergency calls by natural persons or to dispatch or establish priority in the dispatching of emergency first response services, including by police, firefighters and medical aid, as well as of emergency healthcare patient triage systems, should also be classified as high-risk since they make decisions in very critical situations for the life and health of persons and their property.\n(59)\nGiven their role and responsibility, actions by law enforcement authorities involving certain uses of AI systems are characterised by a significant degree of power imbalance and may lead to surveillance, arrest or deprivation of a natural person’s liberty as well as other adverse impacts on fundamental rights guaranteed in the Charter. In particular, if the AI system is not trained with high-quality data, does not meet adequate requirements in terms of its performance, its accuracy or robustness, or is not properly designed and tested before being put on the market or otherwise put into service, it may single out people in a discriminatory or otherwise incorrect or unjust manner. Furthermore, the exercise of important procedural fundamental rights, such as the right to an effective remedy and to a fair trial as well as the right of defence and the presumption of innocence, could be hampered, in particular, where such AI systems are not sufficiently transparent, explainable and documented. It is therefore appropriate to classify as high-risk, insofar as their use is permitted under relevant Union and national law, a number of AI systems intended to be used in the law enforcement context where accuracy, reliability and transparency is particularly important to avoid adverse impacts, retain public trust and ensure accountability and effective redress. In view of the nature of the activities and the risks relating thereto, those high-risk AI systems should include in particular AI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices, or agencies in support of law enforcement authorities for assessing the risk of a natural person to become a victim of criminal offences, as polygraphs and similar tools, for the evaluation of the reliability of evidence in in the course of investigation or prosecution of criminal offences, and, insofar as not prohibited under this Regulation, for assessing the risk of a natural person offending or reoffending not solely on the basis of the profiling of natural persons or the assessment of personality traits and characteristics or the past criminal behaviour of natural persons or groups, for profiling in the course of detection, investigation or prosecution of criminal offences. AI systems specifically intended to be used for administrative proceedings by tax and customs authorities as well as by financial intelligence units carrying out administrative tasks analysing information pursuant to Union anti-money laundering law should not be classified as high-risk AI systems used by law enforcement authorities for the purpose of prevention, detection, investigation and prosecution of criminal offences. The use of AI tools by law enforcement and other relevant authorities should not become a factor of inequality, or exclusion. The impact of the use of AI tools on the defence rights of suspects should not be ignored, in particular the difficulty in obtaining meaningful information on the functioning of those systems and the resulting difficulty in challenging their results in court, in particular by natural persons under investigation.\n(60)\nAI systems used in migration, asylum and border control management affect persons who are often in particularly vulnerable position and who are dependent on the outcome of the actions of the competent public authorities. The accuracy, non-discriminatory nature and transparency of the AI systems used in those contexts are therefore particularly important to guarantee respect for the fundamental rights of the affected persons, in particular their rights to free movement, non-discrimination, protection of private life and personal data, international protection and good administration. It is therefore appropriate to classify as high-risk, insofar as their use is permitted under relevant Union and national law, AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies charged with tasks in the fields of migration, asylum and border control management as polygraphs and similar tools, for assessing certain risks posed by natural persons entering the territory of a Member State or applying for visa or asylum, for assisting competent public authorities for the examination, including related assessment of the reliability of evidence, of applications for asylum, visa and residence permits and associated complaints with regard to the objective to establish the eligibility of the natural persons applying for a status, for the purpose of detecting, recognising or identifying natural persons in the context of migration, asylum and border control management, with the exception of verification of travel documents. AI systems in the area of migration, asylum and border control management covered by this Regulation should comply with the relevant procedural requirements set by the Regulation (EC) No 810/2009 of the European Parliament and of the Council (32), the Directive 2013/32/EU of the European Parliament and of the Council (33), and other relevant Union law. The use of AI systems in migration, asylum and border control management should, in no circumstances, be used by Member States or Union institutions, bodies, offices or agencies as a means to circumvent their international obligations under the UN Convention relating to the Status of Refugees done at Geneva on 28 July 1951 as amended by the Protocol of 31 January 1967. Nor should they be used to in any way infringe on the principle of non-refoulement, or to deny safe and effective legal avenues into the territory of the Union, including the right to international protection.\n(61)\nCertain AI systems intended for the administration of justice and democratic processes should be classified as high-risk, considering their potentially significant impact on democracy, the rule of law, individual freedoms as well as the right to an effective remedy and to a fair trial. In particular, to address the risks of potential biases, errors and opacity, it is appropriate to qualify as high-risk AI systems intended to be used by a judicial authority or on its behalf to assist judicial authorities in researching and interpreting facts and the law and in applying the law to a concrete set of facts. AI systems intended to be used by alternative dispute resolution bodies for those purposes should also be considered to be high-risk when the outcomes of the alternative dispute resolution proceedings produce legal effects for the parties. The use of AI tools can support the decision-making power of judges or judicial independence, but should not replace it: the final decision-making must remain a human-driven activity. The classification of AI systems as high-risk should not, however, extend to AI systems intended for purely ancillary administrative activities that do not affect the actual administration of justice in individual cases, such as anonymisation or pseudonymisation of judicial decisions, documents or data, communication between personnel, administrative tasks.\n(62)\nWithout prejudice to the rules provided for in Regulation (EU) 2024/900 of the European Parliament and of the Council (34), and in order to address the risks of undue external interference with the right to vote enshrined in Article 39 of the Charter, and of adverse effects on democracy and the rule of law, AI systems intended to be used to influence the outcome of an election or referendum or the voting behaviour of natural persons in the exercise of their vote in elections or referenda should be classified as high-risk AI systems with the exception of AI systems whose output natural persons are not directly exposed to, such as tools used to organise, optimise and structure political campaigns from an administrative and logistical point of view.\n(63)\nThe fact that an AI system is classified as a high-risk AI system under this Regulation should not be interpreted as indicating that the use of the system is lawful under other acts of Union law or under national law compatible with Union law, such as on the protection of personal data, on the use of polygraphs and similar tools or other systems to detect the emotional state of natural persons. Any such use should continue to occur solely in accordance with the applicable requirements resulting from the Charter and from the applicable acts of secondary Union law and national law. This Regulation should not be understood as providing for the legal ground for processing of personal data, including special categories of personal data, where relevant, unless it is specifically otherwise provided for in this Regulation.\n(64)\nTo mitigate the risks from high-risk AI systems placed on the market or put into service and to ensure a high level of trustworthiness, certain mandatory requirements should apply to high-risk AI systems, taking into account the intended purpose and the context of use of the AI system and according to the risk-management system to be established by the provider. The measures adopted by the providers to comply with the mandatory requirements of this Regulation should take into account the generally acknowledged state of the art on AI, be proportionate and effective to meet the objectives of this Regulation. Based on the New Legislative Framework, as clarified in Commission notice ‘The “Blue Guide” on the implementation of EU product rules 2022’, the general rule is that more than one legal act of Union harmonisation legislation may be applicable to one product, since the making available or putting into service can take place only when the product complies with all applicable Union harmonisation legislation. The hazards of AI systems covered by the requirements of this Regulation concern different aspects than the existing Union harmonisation legislation and therefore the requirements of this Regulation would complement the existing body of the Union harmonisation legislation. For example, machinery or medical devices products incorporating an AI system might present risks not addressed by the essential health and safety requirements set out in the relevant Union harmonised legislation, as that sectoral law does not deal with risks specific to AI systems. This calls for a simultaneous and complementary application of the various legislative acts. To ensure consistency and to avoid an unnecessary administrative burden and unnecessary costs, providers of a product that contains one or more high-risk AI system, to which the requirements of this Regulation and of the Union harmonisation legislation based on the New Legislative Framework and listed in an annex to this Regulation apply, should have flexibility with regard to operational decisions on how to ensure compliance of a product that contains one or more AI systems with all the applicable requirements of that Union harmonised legislation in an optimal manner. That flexibility could mean, for example a decision by the provider to integrate a part of the necessary testing and reporting processes, information and documentation required under this Regulation into already existing documentation and procedures required under existing Union harmonisation legislation based on the New Legislative Framework and listed in an annex to this Regulation. This should not, in any way, undermine the obligation of the provider to comply with all the applicable requirements.\n(65)\nThe risk-management system should consist of a continuous, iterative process that is planned and run throughout the entire lifecycle of a high-risk AI system. That process should be aimed at identifying and mitigating the relevant risks of AI systems on health, safety and fundamental rights. The risk-management system should be regularly reviewed and updated to ensure its continuing effectiveness, as well as justification and documentation of any significant decisions and actions taken subject to this Regulation. This process should ensure that the provider identifies risks or adverse impacts and implements mitigation measures for the known and reasonably foreseeable risks of AI systems to the health, safety and fundamental rights in light of their intended purpose and reasonably foreseeable misuse, including the possible risks arising from the interaction between the AI system and the environment within which it operates. The risk-management system should adopt the most appropriate risk-management measures in light of the state of the art in AI. When identifying the most appropriate risk-management measures, the provider should document and explain the choices made and, when relevant, involve experts and external stakeholders. In identifying the reasonably foreseeable misuse of high-risk AI systems, the provider should cover uses of AI systems which, while not directly covered by the intended purpose and provided for in the instruction for use may nevertheless be reasonably expected to result from readily predictable human behaviour in the context of the specific characteristics and use of a particular AI system. Any known or foreseeable circumstances related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety or fundamental rights should be included in the instructions for use that are provided by the provider. This is to ensure that the deployer is aware and takes them into account when using the high-risk AI system. Identifying and implementing risk mitigation measures for foreseeable misuse under this Regulation should not require specific additional training for the high-risk AI system by the provider to address foreseeable misuse. The providers however are encouraged to consider such additional training measures to mitigate reasonable foreseeable misuses as necessary and appropriate.\n(66)\nRequirements should apply to high-risk AI systems as regards risk management, the quality and relevance of data sets used, technical documentation and record-keeping, transparency and the provision of information to deployers, human oversight, and robustness, accuracy and cybersecurity. Those requirements are necessary to effectively mitigate the risks for health, safety and fundamental rights. As no other less trade restrictive measures are reasonably available those requirements are not unjustified restrictions to trade.\n(67)\nHigh-quality data and access to high-quality data plays a vital role in providing structure and in ensuring the performance of many AI systems, especially when techniques involving the training of models are used, with a view to ensure that the high-risk AI system performs as intended and safely and it does not become a source of discrimination prohibited by Union law. High-quality data sets for training, validation and testing require the implementation of appropriate data governance and management practices. Data sets for training, validation and testing, including the labels, should be relevant, sufficiently representative, and to the best extent possible free of errors and complete in view of the intended purpose of the system. In order to facilitate compliance with Union data protection law, such as Regulation (EU) 2016/679, data governance and management practices should include, in the case of personal data, transparency about the original purpose of the data collection. The data sets should also have the appropriate statistical properties, including as regards the persons or groups of persons in relation to whom the high-risk AI system is intended to be used, with specific attention to the mitigation of possible biases in the data sets, that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations (feedback loops). Biases can for example be inherent in underlying data sets, especially when historical data is being used, or generated when the systems are implemented in real world settings. Results provided by AI systems could be influenced by such inherent biases that are inclined to gradually increase and thereby perpetuate and amplify existing discrimination, in particular for persons belonging to certain vulnerable groups, including racial or ethnic groups. The requirement for the data sets to be to the best extent possible complete and free of errors should not affect the use of privacy-preserving techniques in the context of the development and testing of AI systems. In particular, data sets should take into account, to the extent required by their intended purpose, the features, characteristics or elements that are particular to the specific geographical, contextual, behavioural or functional setting which the AI system is intended to be used. The requirements related to data governance can be complied with by having recourse to third parties that offer certified compliance services including verification of data governance, data set integrity, and data training, validation and testing practices, as far as compliance with the data requirements of this Regulation are ensured.\n(68)\nFor the development and assessment of high-risk AI systems, certain actors, such as providers, notified bodies and other relevant entities, such as European Digital Innovation Hubs, testing experimentation facilities and researchers, should be able to access and use high-quality data sets within the fields of activities of those actors which are related to this Regulation. European common data spaces established by the Commission and the facilitation of data sharing between businesses and with government in the public interest will be instrumental to provide trustful, accountable and non-discriminatory access to high-quality data for the training, validation and testing of AI systems. For example, in health, the European health data space will facilitate non-discriminatory access to health data and the training of AI algorithms on those data sets, in a privacy-preserving, secure, timely, transparent and trustworthy manner, and with an appropriate institutional governance. Relevant competent authorities, including sectoral ones, providing or supporting the access to data may also support the provision of high-quality data for the training, validation and testing of AI systems.\n(69)\nThe right to privacy and to protection of personal data must be guaranteed throughout the entire lifecycle of the AI system. In this regard, the principles of data minimisation and data protection by design and by default, as set out in Union data protection law, are applicable when personal data are processed. Measures taken by providers to ensure compliance with those principles may include not only anonymisation and encryption, but also the use of technology that permits algorithms to be brought to the data and allows training of AI systems without the transmission between parties or copying of the raw or structured data themselves, without prejudice to the requirements on data governance provided for in this Regulation.\n(70)\nIn order to protect the right of others from the discrimination that might result from the bias in AI systems, the providers should, exceptionally, to the extent that it is strictly necessary for the purpose of ensuring bias detection and correction in relation to the high-risk AI systems, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons and following the application of all applicable conditions laid down under this Regulation in addition to the conditions laid down in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, be able to process also special categories of personal data, as a matter of substantial public interest within the meaning of Article 9(2), point (g) of Regulation (EU) 2016/679 and Article 10(2), point (g) of Regulation (EU) 2018/1725.\n(71)\nHaving comprehensible information on how high-risk AI systems have been developed and how they perform throughout their lifetime is essential to enable traceability of those systems, verify compliance with the requirements under this Regulation, as well as monitoring of their operations and post market monitoring. This requires keeping records and the availability of technical documentation, containing information which is necessary to assess the compliance of the AI system with the relevant requirements and facilitate post market monitoring. Such information should include the general characteristics, capabilities and limitations of the system, algorithms, data, training, testing and validation processes used as well as documentation on the relevant risk-management system and drawn in a clear and comprehensive form. The technical documentation should be kept up to date, appropriately throughout the lifetime of the AI system. Furthermore, high-risk AI systems should technically allow for the automatic recording of events, by means of logs, over the duration of the lifetime of the system.\n(72)\nTo address concerns related to opacity and complexity of certain AI systems and help deployers to fulfil their obligations under this Regulation, transparency should be required for high-risk AI systems before they are placed on the market or put it into service. High-risk AI systems should be designed in a manner to enable deployers to understand how the AI system works, evaluate its functionality, and comprehend its strengths and limitations. High-risk AI systems should be accompanied by appropriate information in the form of instructions of use. Such information should include the characteristics, capabilities and limitations of performance of the AI system. Those would cover information on possible known and foreseeable circumstances related to the use of the high-risk AI system, including deployer action that may influence system behaviour and performance, under which the AI system can lead to risks to health, safety, and fundamental rights, on the changes that have been pre-determined and assessed for conformity by the provider and on the relevant human oversight measures, including the measures to facilitate the interpretation of the outputs of the AI system by the deployers. Transparency, including the accompanying instructions for use, should assist deployers in the use of the system and support informed decision making by them. Deployers should, inter alia, be in a better position to make the correct choice of the system that they intend to use in light of the obligations applicable to them, be educated about the intended and precluded uses, and use the AI system correctly and as appropriate. In order to enhance legibility and accessibility of the information included in the instructions of use, where appropriate, illustrative examples, for instance on the limitations and on the intended and precluded uses of the AI system, should be included. Providers should ensure that all documentation, including the instructions for use, contains meaningful, comprehensive, accessible and understandable information, taking into account the needs and foreseeable knowledge of the target deployers. Instructions for use should be made available in a language which can be easily understood by target deployers, as determined by the Member State concerned.\n(73)\nHigh-risk AI systems should be designed and developed in such a way that natural persons can oversee their functioning, ensure that they are used as intended and that their impacts are addressed over the system’s lifecycle. To that end, appropriate human oversight measures should be identified by the provider of the system before its placing on the market or putting into service. In particular, where appropriate, such measures should guarantee that the system is subject to in-built operational constraints that cannot be overridden by the system itself and is responsive to the human operator, and that the natural persons to whom human oversight has been assigned have the necessary competence, training and authority to carry out that role. It is also essential, as appropriate, to ensure that high-risk AI systems include mechanisms to guide and inform a natural person to whom human oversight has been assigned to make informed decisions if, when and how to intervene in order to avoid negative consequences or risks, or stop the system if it does not perform as intended. Considering the significant consequences for persons in the case of an incorrect match by certain biometric identification systems, it is appropriate to provide for an enhanced human oversight requirement for those systems so that no action or decision may be taken by the deployer on the basis of the identification resulting from the system unless this has been separately verified and confirmed by at least two natural persons. Those persons could be from one or more entities and include the person operating or using the system. This requirement should not pose unnecessary burden or delays and it could be sufficient that the separate verifications by the different persons are automatically recorded in the logs generated by the system. Given the specificities of the areas of law enforcement, migration, border control and asylum, this requirement should not apply where Union or national law considers the application of that requirement to be disproportionate.\n(74)\nHigh-risk AI systems should perform consistently throughout their lifecycle and meet an appropriate level of accuracy, robustness and cybersecurity, in light of their intended purpose and in accordance with the generally acknowledged state of the art. The Commission and relevant organisations and stakeholders are encouraged to take due consideration of the mitigation of risks and the negative impacts of the AI system. The expected level of performance metrics should be declared in the accompanying instructions of use. Providers are urged to communicate that information to deployers in a clear and easily understandable way, free of misunderstandings or misleading statements. Union law on legal metrology, including Directives 2014/31/EU (35) and 2014/32/EU (36) of the European Parliament and of the Council, aims to ensure the accuracy of measurements and to help the transparency and fairness of commercial transactions. In that context, in cooperation with relevant stakeholders and organisation, such as metrology and benchmarking authorities, the Commission should encourage, as appropriate, the development of benchmarks and measurement methodologies for AI systems. In doing so, the Commission should take note and collaborate with international partners working on metrology and relevant measurement indicators relating to AI.\n(75)\nTechnical robustness is a key requirement for high-risk AI systems. They should be resilient in relation to harmful or otherwise undesirable behaviour that may result from limitations within the systems or the environment in which the systems operate (e.g. errors, faults, inconsistencies, unexpected situations). Therefore, technical and organisational measures should be taken to ensure robustness of high-risk AI systems, for example by designing and developing appropriate technical solutions to prevent or minimise harmful or otherwise undesirable behaviour. Those technical solution may include for instance mechanisms enabling the system to safely interrupt its operation (fail-safe plans) in the presence of certain anomalies or when operation takes place outside certain predetermined boundaries. Failure to protect against these risks could lead to safety impacts or negatively affect the fundamental rights, for example due to erroneous decisions or wrong or biased outputs generated by the AI system.\n(76)\nCybersecurity plays a crucial role in ensuring that AI systems are resilient against attempts to alter their use, behaviour, performance or compromise their security properties by malicious third parties exploiting the system’s vulnerabilities. Cyberattacks against AI systems can leverage AI specific assets, such as training data sets (e.g. data poisoning) or trained models (e.g. adversarial attacks or membership inference), or exploit vulnerabilities in the AI system’s digital assets or the underlying ICT infrastructure. To ensure a level of cybersecurity appropriate to the risks, suitable measures, such as security controls, should therefore be taken by the providers of high-risk AI systems, also taking into account as appropriate the underlying ICT infrastructure.\n(77)\nWithout prejudice to the requirements related to robustness and accuracy set out in this Regulation, high-risk AI systems which fall within the scope of a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, in accordance with that regulation may demonstrate compliance with the cybersecurity requirements of this Regulation by fulfilling the essential cybersecurity requirements set out in that regulation. When high-risk AI systems fulfil the essential requirements of a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, they should be deemed compliant with the cybersecurity requirements set out in this Regulation in so far as the achievement of those requirements is demonstrated in the EU declaration of conformity or parts thereof issued under that regulation. To that end, the assessment of the cybersecurity risks, associated to a product with digital elements classified as high-risk AI system according to this Regulation, carried out under a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, should consider risks to the cyber resilience of an AI system as regards attempts by unauthorised third parties to alter its use, behaviour or performance, including AI specific vulnerabilities such as data poisoning or adversarial attacks, as well as, as relevant, risks to fundamental rights as required by this Regulation.\n(78)\nThe conformity assessment procedure provided by this Regulation should apply in relation to the essential cybersecurity requirements of a product with digital elements covered by a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and classified as a high-risk AI system under this Regulation. However, this rule should not result in reducing the necessary level of assurance for critical products with digital elements covered by a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements. Therefore, by way of derogation from this rule, high-risk AI systems that fall within the scope of this Regulation and are also qualified as important and critical products with digital elements pursuant to a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and to which the conformity assessment procedure based on internal control set out in an annex to this Regulation applies, are subject to the conformity assessment provisions of a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements insofar as the essential cybersecurity requirements of that regulation are concerned. In this case, for all the other aspects covered by this Regulation the respective provisions on conformity assessment based on internal control set out in an annex to this Regulation should apply. Building on the knowledge and expertise of ENISA on the cybersecurity policy and tasks assigned to ENISA under the Regulation (EU) 2019/881 of the European Parliament and of the Council (37), the Commission should cooperate with ENISA on issues related to cybersecurity of AI systems.\n(79)\nIt is appropriate that a specific natural or legal person, defined as the provider, takes responsibility for the placing on the market or the putting into service of a high-risk AI system, regardless of whether that natural or legal person is the person who designed or developed the system.\n(80)\nAs signatories to the United Nations Convention on the Rights of Persons with Disabilities, the Union and the Member States are legally obliged to protect persons with disabilities from discrimination and promote their equality, to ensure that persons with disabilities have access, on an equal basis with others, to information and communications technologies and systems, and to ensure respect for privacy for persons with disabilities. Given the growing importance and use of AI systems, the application of universal design principles to all new technologies and services should ensure full and equal access for everyone potentially affected by or using AI technologies, including persons with disabilities, in a way that takes full account of their inherent dignity and diversity. It is therefore essential that providers ensure full compliance with accessibility requirements, including Directive (EU) 2016/2102 of the European Parliament and of the Council (38) and Directive (EU) 2019/882. Providers should ensure compliance with these requirements by design. Therefore, the necessary measures should be integrated as much as possible into the design of the high-risk AI system.\n(81)\nThe provider should establish a sound quality management system, ensure the accomplishment of the required conformity assessment procedure, draw up the relevant documentation and establish a robust post-market monitoring system. Providers of high-risk AI systems that are subject to obligations regarding quality management systems under relevant sectoral Union law should have the possibility to include the elements of the quality management system provided for in this Regulation as part of the existing quality management system provided for in that other sectoral Union law. The complementarity between this Regulation and existing sectoral Union law should also be taken into account in future standardisation activities or guidance adopted by the Commission. Public authorities which put into service high-risk AI systems for their own use may adopt and implement the rules for the quality management system as part of the quality management system adopted at a national or regional level, as appropriate, taking into account the specificities of the sector and the competences and organisation of the public authority concerned.\n(82)\nTo enable enforcement of this Regulation and create a level playing field for operators, and, taking into account the different forms of making available of digital products, it is important to ensure that, under all circumstances, a person established in the Union can provide authorities with all the necessary information on the compliance of an AI system. Therefore, prior to making their AI systems available in the Union, providers established in third countries should, by written mandate, appoint an authorised representative established in the Union. This authorised representative plays a pivotal role in ensuring the compliance of the high-risk AI systems placed on the market or put into service in the Union by those providers who are not established in the Union and in serving as their contact person established in the Union.\n(83)\nIn light of the nature and complexity of the value chain for AI systems and in line with the New Legislative Framework, it is essential to ensure legal certainty and facilitate the compliance with this Regulation. Therefore, it is necessary to clarify the role and the specific obligations of relevant operators along that value chain, such as importers and distributors who may contribute to the development of AI systems. In certain situations those operators could act in more than one role at the same time and should therefore fulfil cumulatively all relevant obligations associated with those roles. For example, an operator could act as a distributor and an importer at the same time.\n(84)\nTo ensure legal certainty, it is necessary to clarify that, under certain specific conditions, any distributor, importer, deployer or other third-party should be considered to be a provider of a high-risk AI system and therefore assume all the relevant obligations. This would be the case if that party puts its name or trademark on a high-risk AI system already placed on the market or put into service, without prejudice to contractual arrangements stipulating that the obligations are allocated otherwise. This would also be the case if that party makes a substantial modification to a high-risk AI system that has already been placed on the market or has already been put into service in a way that it remains a high-risk AI system in accordance with this Regulation, or if it modifies the intended purpose of an AI system, including a general-purpose AI system, which has not been classified as high-risk and has already been placed on the market or put into service, in a way that the AI system becomes a high-risk AI system in accordance with this Regulation. Those provisions should apply without prejudice to more specific provisions established in certain Union harmonisation legislation based on the New Legislative Framework, together with which this Regulation should apply. For example, Article 16(2) of Regulation (EU) 2017/745, establishing that certain changes should not be considered to be modifications of a device that could affect its compliance with the applicable requirements, should continue to apply to high-risk AI systems that are medical devices within the meaning of that Regulation.\n(85)\nGeneral-purpose AI systems may be used as high-risk AI systems by themselves or be components of other high-risk AI systems. Therefore, due to their particular nature and in order to ensure a fair sharing of responsibilities along the AI value chain, the providers of such systems should, irrespective of whether they may be used as high-risk AI systems as such by other providers or as components of high-risk AI systems and unless provided otherwise under this Regulation, closely cooperate with the providers of the relevant high-risk AI systems to enable their compliance with the relevant obligations under this Regulation and with the competent authorities established under this Regulation.\n(86)\nWhere, under the conditions laid down in this Regulation, the provider that initially placed the AI system on the market or put it into service should no longer be considered to be the provider for the purposes of this Regulation, and when that provider has not expressly excluded the change of the AI system into a high-risk AI system, the former provider should nonetheless closely cooperate and make available the necessary information and provide the reasonably expected technical access and other assistance that are required for the fulfilment of the obligations set out in this Regulation, in particular regarding the compliance with the conformity assessment of high-risk AI systems.\n(87)\nIn addition, where a high-risk AI system that is a safety component of a product which falls within the scope of Union harmonisation legislation based on the New Legislative Framework is not placed on the market or put into service independently from the product, the product manufacturer defined in that legislation should comply with the obligations of the provider established in this Regulation and should, in particular, ensure that the AI system embedded in the final product complies with the requirements of this Regulation.\n(88)\nAlong the AI value chain multiple parties often supply AI systems, tools and services but also components or processes that are incorporated by the provider into the AI system with various objectives, including the model training, model retraining, model testing and evaluation, integration into software, or other aspects of model development. Those parties have an important role to play in the value chain towards the provider of the high-risk AI system into which their AI systems, tools, services, components or processes are integrated, and should provide by written agreement this provider with the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, in order to enable the provider to fully comply with the obligations set out in this Regulation, without compromising their own intellectual property rights or trade secrets.\n(89)\nThird parties making accessible to the public tools, services, processes, or AI components other than general-purpose AI models, should not be mandated to comply with requirements targeting the responsibilities along the AI value chain, in particular towards the provider that has used or integrated them, when those tools, services, processes, or AI components are made accessible under a free and open-source licence. Developers of free and open-source tools, services, processes, or AI components other than general-purpose AI models should be encouraged to implement widely adopted documentation practices, such as model cards and data sheets, as a way to accelerate information sharing along the AI value chain, allowing the promotion of trustworthy AI systems in the Union.\n(90)\nThe Commission could develop and recommend voluntary model contractual terms between providers of high-risk AI systems and third parties that supply tools, services, components or processes that are used or integrated in high-risk AI systems, to facilitate the cooperation along the value chain. When developing voluntary model contractual terms, the Commission should also take into account possible contractual requirements applicable in specific sectors or business cases.\n(91)\nGiven the nature of AI systems and the risks to safety and fundamental rights possibly associated with their use, including as regards the need to ensure proper monitoring of the performance of an AI system in a real-life setting, it is appropriate to set specific responsibilities for deployers. Deployers should in particular take appropriate technical and organisational measures to ensure they use high-risk AI systems in accordance with the instructions of use and certain other obligations should be provided for with regard to monitoring of the functioning of the AI systems and with regard to record-keeping, as appropriate. Furthermore, deployers should ensure that the persons assigned to implement the instructions for use and human oversight as set out in this Regulation have the necessary competence, in particular an adequate level of AI literacy, training and authority to properly fulfil those tasks. Those obligations should be without prejudice to other deployer obligations in relation to high-risk AI systems under Union or national law.\n(92)\nThis Regulation is without prejudice to obligations for employers to inform or to inform and consult workers or their representatives under Union or national law and practice, including Directive 2002/14/EC of the European Parliament and of the Council (39), on decisions to put into service or use AI systems. It remains necessary to ensure information of workers and their representatives on the planned deployment of high-risk AI systems at the workplace where the conditions for those information or information and consultation obligations in other legal instruments are not fulfilled. Moreover, such information right is ancillary and necessary to the objective of protecting fundamental rights that underlies this Regulation. Therefore, an information requirement to that effect should be laid down in this Regulation, without affecting any existing rights of workers.\n(93)\nWhilst risks related to AI systems can result from the way such systems are designed, risks can as well stem from how such AI systems are used. Deployers of high-risk AI system therefore play a critical role in ensuring that fundamental rights are protected, complementing the obligations of the provider when developing the AI system. Deployers are best placed to understand how the high-risk AI system will be used concretely and can therefore identify potential significant risks that were not foreseen in the development phase, due to a more precise knowledge of the context of use, the persons or groups of persons likely to be affected, including vulnerable groups. Deployers of high-risk AI systems listed in an annex to this Regulation also play a critical role in informing natural persons and should, when they make decisions or assist in making decisions related to natural persons, where applicable, inform the natural persons that they are subject to the use of the high-risk AI system. This information should include the intended purpose and the type of decisions it makes. The deployer should also inform the natural persons about their right to an explanation provided under this Regulation. With regard to high-risk AI systems used for law enforcement purposes, that obligation should be implemented in accordance with Article 13 of Directive (EU) 2016/680.\n(94)\nAny processing of biometric data involved in the use of AI systems for biometric identification for the purpose of law enforcement needs to comply with Article 10 of Directive (EU) 2016/680, that allows such processing only where strictly necessary, subject to appropriate safeguards for the rights and freedoms of the data subject, and where authorised by Union or Member State law. Such use, when authorised, also needs to respect the principles laid down in Article 4 (1) of Directive (EU) 2016/680 including lawfulness, fairness and transparency, purpose limitation, accuracy and storage limitation.\n(95)\nWithout prejudice to applicable Union law, in particular Regulation (EU) 2016/679 and Directive (EU) 2016/680, considering the intrusive nature of post-remote biometric identification systems, the use of post-remote biometric identification systems should be subject to safeguards. Post-remote biometric identification systems should always be used in a way that is proportionate, legitimate and strictly necessary, and thus targeted, in terms of the individuals to be identified, the location, temporal scope and based on a closed data set of legally acquired video footage. In any case, post-remote biometric identification systems should not be used in the framework of law enforcement to lead to indiscriminate surveillance. The conditions for post-remote biometric identification should in any case not provide a basis to circumvent the conditions of the prohibition and strict exceptions for real time remote biometric identification.\n(96)\nIn order to efficiently ensure that fundamental rights are protected, deployers of high-risk AI systems that are bodies governed by public law, or private entities providing public services and deployers of certain high-risk AI systems listed in an annex to this Regulation, such as banking or insurance entities, should carry out a fundamental rights impact assessment prior to putting it into use. Services important for individuals that are of public nature may also be provided by private entities. Private entities providing such public services are linked to tasks in the public interest such as in the areas of education, healthcare, social services, housing, administration of justice. The aim of the fundamental rights impact assessment is for the deployer to identify the specific risks to the rights of individuals or groups of individuals likely to be affected, identify measures to be taken in the case of a materialisation of those risks. The impact assessment should be performed prior to deploying the high-risk AI system, and should be updated when the deployer considers that any of the relevant factors have changed. The impact assessment should identify the deployer’s relevant processes in which the high-risk AI system will be used in line with its intended purpose, and should include a description of the period of time and frequency in which the system is intended to be used as well as of specific categories of natural persons and groups who are likely to be affected in the specific context of use. The assessment should also include the identification of specific risks of harm likely to have an impact on the fundamental rights of those persons or groups. While performing this assessment, the deployer should take into account information relevant to a proper assessment of the impact, including but not limited to the information given by the provider of the high-risk AI system in the instructions for use. In light of the risks identified, deployers should determine measures to be taken in the case of a materialisation of those risks, including for example governance arrangements in that specific context of use, such as arrangements for human oversight according to the instructions of use or, complaint handling and redress procedures, as they could be instrumental in mitigating risks to fundamental rights in concrete use-cases. After performing that impact assessment, the deployer should notify the relevant market surveillance authority. Where appropriate, to collect relevant information necessary to perform the impact assessment, deployers of high-risk AI system, in particular when AI systems are used in the public sector, could involve relevant stakeholders, including the representatives of groups of persons likely to be affected by the AI system, independent experts, and civil society organisations in conducting such impact assessments and designing measures to be taken in the case of materialisation of the risks. The European Artificial Intelligence Office (AI Office) should develop a template for a questionnaire in order to facilitate compliance and reduce the administrative burden for deployers.\n(97)\nThe notion of general-purpose AI models should be clearly defined and set apart from the notion of AI systems to enable legal certainty. The definition should be based on the key functional characteristics of a general-purpose AI model, in particular the generality and the capability to competently perform a wide range of distinct tasks. These models are typically trained on large amounts of data, through various methods, such as self-supervised, unsupervised or reinforcement learning. General-purpose AI models may be placed on the market in various ways, including through libraries, application programming interfaces (APIs), as direct download, or as physical copy. These models may be further modified or fine-tuned into new models. Although AI models are essential components of AI systems, they do not constitute AI systems on their own. AI models require the addition of further components, such as for example a user interface, to become AI systems. AI models are typically integrated into and form part of AI systems. This Regulation provides specific rules for general-purpose AI models and for general-purpose AI models that pose systemic risks, which should apply also when these models are integrated or form part of an AI system. It should be understood that the obligations for the providers of general-purpose AI models should apply once the general-purpose AI models are placed on the market. When the provider of a general-purpose AI model integrates an own model into its own AI system that is made available on the market or put into service, that model should be considered to be placed on the market and, therefore, the obligations in this Regulation for models should continue to apply in addition to those for AI systems. The obligations laid down for models should in any case not apply when an own model is used for purely internal processes that are not essential for providing a product or a service to third parties and the rights of natural persons are not affected. Considering their potential significantly negative effects, the general-purpose AI models with systemic risk should always be subject to the relevant obligations under this Regulation. The definition should not cover AI models used before their placing on the market for the sole purpose of research, development and prototyping activities. This is without prejudice to the obligation to comply with this Regulation when, following such activities, a model is placed on the market.\n(98)\nWhereas the generality of a model could, inter alia, also be determined by a number of parameters, models with at least a billion of parameters and trained with a large amount of data using self-supervision at scale should be considered to display significant generality and to competently perform a wide range of distinctive tasks.\n(99)\nLarge generative AI models are a typical example for a general-purpose AI model, given that they allow for flexible generation of content, such as in the form of text, audio, images or video, that can readily accommodate a wide range of distinctive tasks.\n(100)\nWhen a general-purpose AI model is integrated into or forms part of an AI system, this system should be considered to be general-purpose AI system when, due to this integration, this system has the capability to serve a variety of purposes. A general-purpose AI system can be used directly, or it may be integrated into other AI systems.\n(101)\nProviders of general-purpose AI models have a particular role and responsibility along the AI value chain, as the models they provide may form the basis for a range of downstream systems, often provided by downstream providers that necessitate a good understanding of the models and their capabilities, both to enable the integration of such models into their products, and to fulfil their obligations under this or other regulations. Therefore, proportionate transparency measures should be laid down, including the drawing up and keeping up to date of documentation, and the provision of information on the general-purpose AI model for its usage by the downstream providers. Technical documentation should be prepared and kept up to date by the general-purpose AI model provider for the purpose of making it available, upon request, to the AI Office and the national competent authorities. The minimal set of elements to be included in such documentation should be set out in specific annexes to this Regulation. The Commission should be empowered to amend those annexes by means of delegated acts in light of evolving technological developments.\n(102)\nSoftware and data, including models, released under a free and open-source licence that allows them to be openly shared and where users can freely access, use, modify and redistribute them or modified versions thereof, can contribute to research and innovation in the market and can provide significant growth opportunities for the Union economy. General-purpose AI models released under free and open-source licences should be considered to ensure high levels of transparency and openness if their parameters, including the weights, the information on the model architecture, and the information on model usage are made publicly available. The licence should be considered to be free and open-source also when it allows users to run, copy, distribute, study, change and improve software and data, including models under the condition that the original provider of the model is credited, the identical or comparable terms of distribution are respected.\n(103)\nFree and open-source AI components covers the software and data, including models and general-purpose AI models, tools, services or processes of an AI system. Free and open-source AI components can be provided through different channels, including their development on open repositories. For the purposes of this Regulation, AI components that are provided against a price or otherwise monetised, including through the provision of technical support or other services, including through a software platform, related to the AI component, or the use of personal data for reasons other than exclusively for improving the security, compatibility or interoperability of the software, with the exception of transactions between microenterprises, should not benefit from the exceptions provided to free and open-source AI components. The fact of making AI components available through open repositories should not, in itself, constitute a monetisation.\n(104)\nThe providers of general-purpose AI models that are released under a free and open-source licence, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available should be subject to exceptions as regards the transparency-related requirements imposed on general-purpose AI models, unless they can be considered to present a systemic risk, in which case the circumstance that the model is transparent and accompanied by an open-source license should not be considered to be a sufficient reason to exclude compliance with the obligations under this Regulation. In any case, given that the release of general-purpose AI models under free and open-source licence does not necessarily reveal substantial information on the data set used for the training or fine-tuning of the model and on how compliance of copyright law was thereby ensured, the exception provided for general-purpose AI models from compliance with the transparency-related requirements should not concern the obligation to produce a summary about the content used for model training and the obligation to put in place a policy to comply with Union copyright law, in particular to identify and comply with the reservation of rights pursuant to Article 4(3) of Directive (EU) 2019/790 of the European Parliament and of the Council (40).\n(105)\nGeneral-purpose AI models, in particular large generative AI models, capable of generating text, images, and other content, present unique innovation opportunities but also challenges to artists, authors, and other creators and the way their creative content is created, distributed, used and consumed. The development and training of such models require access to vast amounts of text, images, videos and other data. Text and data mining techniques may be used extensively in this context for the retrieval and analysis of such content, which may be protected by copyright and related rights. Any use of copyright protected content requires the authorisation of the rightsholder concerned unless relevant copyright exceptions and limitations apply. Directive (EU) 2019/790 introduced exceptions and limitations allowing reproductions and extractions of works or other subject matter, for the purpose of text and data mining, under certain conditions. Under these rules, rightsholders may choose to reserve their rights over their works or other subject matter to prevent text and data mining, unless this is done for the purposes of scientific research. Where the rights to opt out has been expressly reserved in an appropriate manner, providers of general-purpose AI models need to obtain an authorisation from rightsholders if they want to carry out text and data mining over such works.\n(106)\nProviders that place general-purpose AI models on the Union market should ensure compliance with the relevant obligations in this Regulation. To that end, providers of general-purpose AI models should put in place a policy to comply with Union law on copyright and related rights, in particular to identify and comply with the reservation of rights expressed by rightsholders pursuant to Article 4(3) of Directive (EU) 2019/790. Any provider placing a general-purpose AI model on the Union market should comply with this obligation, regardless of the jurisdiction in which the copyright-relevant acts underpinning the training of those general-purpose AI models take place. This is necessary to ensure a level playing field among providers of general-purpose AI models where no provider should be able to gain a competitive advantage in the Union market by applying lower copyright standards than those provided in the Union.\n(107)\nIn order to increase transparency on the data that is used in the pre-training and training of general-purpose AI models, including text and data protected by copyright law, it is adequate that providers of such models draw up and make publicly available a sufficiently detailed summary of the content used for training the general-purpose AI model. While taking into due account the need to protect trade secrets and confidential business information, this summary should be generally comprehensive in its scope instead of technically detailed to facilitate parties with legitimate interests, including copyright holders, to exercise and enforce their rights under Union law, for example by listing the main data collections or sets that went into training the model, such as large private or public databases or data archives, and by providing a narrative explanation about other data sources used. It is appropriate for the AI Office to provide a template for the summary, which should be simple, effective, and allow the provider to provide the required summary in narrative form.\n(108)\nWith regard to the obligations imposed on providers of general-purpose AI models to put in place a policy to comply with Union copyright law and make publicly available a summary of the content used for the training, the AI Office should monitor whether the provider has fulfilled those obligations without verifying or proceeding to a work-by-work assessment of the training data in terms of copyright compliance. This Regulation does not affect the enforcement of copyright rules as provided for under Union law.\n(109)\nCompliance with the obligations applicable to the providers of general-purpose AI models should be commensurate and proportionate to the type of model provider, excluding the need for compliance for persons who develop or use models for non-professional or scientific research purposes, who should nevertheless be encouraged to voluntarily comply with these requirements. Without prejudice to Union copyright law, compliance with those obligations should take due account of the size of the provider and allow simplified ways of compliance for SMEs, including start-ups, that should not represent an excessive cost and not discourage the use of such models. In the case of a modification or fine-tuning of a model, the obligations for providers of general-purpose AI models should be limited to that modification or fine-tuning, for example by complementing the already existing technical documentation with information on the modifications, including new training data sources, as a means to comply with the value chain obligations provided in this Regulation.\n(110)\nGeneral-purpose AI models could pose systemic risks which include, but are not limited to, any actual or reasonably foreseeable negative effects in relation to major accidents, disruptions of critical sectors and serious consequences to public health and safety; any actual or reasonably foreseeable negative effects on democratic processes, public and economic security; the dissemination of illegal, false, or discriminatory content. Systemic risks should be understood to increase with model capabilities and model reach, can arise along the entire lifecycle of the model, and are influenced by conditions of misuse, model reliability, model fairness and model security, the level of autonomy of the model, its access to tools, novel or combined modalities, release and distribution strategies, the potential to remove guardrails and other factors. In particular, international approaches have so far identified the need to pay attention to risks from potential intentional misuse or unintended issues of control relating to alignment with human intent; chemical, biological, radiological, and nuclear risks, such as the ways in which barriers to entry can be lowered, including for weapons development, design acquisition, or use; offensive cyber capabilities, such as the ways in vulnerability discovery, exploitation, or operational use can be enabled; the effects of interaction and tool use, including for example the capacity to control physical systems and interfere with critical infrastructure; risks from models of making copies of themselves or ‘self-replicating’ or training other models; the ways in which models can give rise to harmful bias and discrimination with risks to individuals, communities or societies; the facilitation of disinformation or harming privacy with threats to democratic values and human rights; risk that a particular event could lead to a chain reaction with considerable negative effects that could affect up to an entire city, an entire domain activity or an entire community.\n(111)\nIt is appropriate to establish a methodology for the classification of general-purpose AI models as general-purpose AI model with systemic risks. Since systemic risks result from particularly high capabilities, a general-purpose AI model should be considered to present systemic risks if it has high-impact capabilities, evaluated on the basis of appropriate technical tools and methodologies, or significant impact on the internal market due to its reach. High-impact capabilities in general-purpose AI models means capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models. The full range of capabilities in a model could be better understood after its placing on the market or when deployers interact with the model. According to the state of the art at the time of entry into force of this Regulation, the cumulative amount of computation used for the training of the general-purpose AI model measured in floating point operations is one of the relevant approximations for model capabilities. The cumulative amount of computation used for training includes the computation used across the activities and methods that are intended to enhance the capabilities of the model prior to deployment, such as pre-training, synthetic data generation and fine-tuning. Therefore, an initial threshold of floating point operations should be set, which, if met by a general-purpose AI model, leads to a presumption that the model is a general-purpose AI model with systemic risks. This threshold should be adjusted over time to reflect technological and industrial changes, such as algorithmic improvements or increased hardware efficiency, and should be supplemented with benchmarks and indicators for model capability. To inform this, the AI Office should engage with the scientific community, industry, civil society and other experts. Thresholds, as well as tools and benchmarks for the assessment of high-impact capabilities, should be strong predictors of generality, its capabilities and associated systemic risk of general-purpose AI models, and could take into account the way the model will be placed on the market or the number of users it may affect. To complement this system, there should be a possibility for the Commission to take individual decisions designating a general-purpose AI model as a general-purpose AI model with systemic risk if it is found that such model has capabilities or an impact equivalent to those captured by the set threshold. That decision should be taken on the basis of an overall assessment of the criteria for the designation of a general-purpose AI model with systemic risk set out in an annex to this Regulation, such as quality or size of the training data set, number of business and end users, its input and output modalities, its level of autonomy and scalability, or the tools it has access to. Upon a reasoned request of a provider whose model has been designated as a general-purpose AI model with systemic risk, the Commission should take the request into account and may decide to reassess whether the general-purpose AI model can still be considered to present systemic risks.\n(112)\nIt is also necessary to clarify a procedure for the classification of a general-purpose AI model with systemic risks. A general-purpose AI model that meets the applicable threshold for high-impact capabilities should be presumed to be a general-purpose AI models with systemic risk. The provider should notify the AI Office at the latest two weeks after the requirements are met or it becomes known that a general-purpose AI model will meet the requirements that lead to the presumption. This is especially relevant in relation to the threshold of floating point operations because training of general-purpose AI models takes considerable planning which includes the upfront allocation of compute resources and, therefore, providers of general-purpose AI models are able to know if their model would meet the threshold before the training is completed. In the context of that notification, the provider should be able to demonstrate that, because of its specific characteristics, a general-purpose AI model exceptionally does not present systemic risks, and that it thus should not be classified as a general-purpose AI model with systemic risks. That information is valuable for the AI Office to anticipate the placing on the market of general-purpose AI models with systemic risks and the providers can start to engage with the AI Office early on. That information is especially important with regard to general-purpose AI models that are planned to be released as open-source, given that, after the open-source model release, necessary measures to ensure compliance with the obligations under this Regulation may be more difficult to implement.\n(113)\nIf the Commission becomes aware of the fact that a general-purpose AI model meets the requirements to classify as a general-purpose AI model with systemic risk, which previously had either not been known or of which the relevant provider has failed to notify the Commission, the Commission should be empowered to designate it so. A system of qualified alerts should ensure that the AI Office is made aware by the scientific panel of general-purpose AI models that should possibly be classified as general-purpose AI models with systemic risk, in addition to the monitoring activities of the AI Office.\n(114)\nThe providers of general-purpose AI models presenting systemic risks should be subject, in addition to the obligations provided for providers of general-purpose AI models, to obligations aimed at identifying and mitigating those risks and ensuring an adequate level of cybersecurity protection, regardless of whether it is provided as a standalone model or embedded in an AI system or a product. To achieve those objectives, this Regulation should require providers to perform the necessary model evaluations, in particular prior to its first placing on the market, including conducting and documenting adversarial testing of models, also, as appropriate, through internal or independent external testing. In addition, providers of general-purpose AI models with systemic risks should continuously assess and mitigate systemic risks, including for example by putting in place risk-management policies, such as accountability and governance processes, implementing post-market monitoring, taking appropriate measures along the entire model’s lifecycle and cooperating with relevant actors along the AI value chain.\n(115)\nProviders of general-purpose AI models with systemic risks should assess and mitigate possible systemic risks. If, despite efforts to identify and prevent risks related to a general-purpose AI model that may present systemic risks, the development or use of the model causes a serious incident, the general-purpose AI model provider should without undue delay keep track of the incident and report any relevant information and possible corrective measures to the Commission and national competent authorities. Furthermore, providers should ensure an adequate level of cybersecurity protection for the model and its physical infrastructure, if appropriate, along the entire model lifecycle. Cybersecurity protection related to systemic risks associated with malicious use or attacks should duly consider accidental model leakage, unauthorised releases, circumvention of safety measures, and defence against cyberattacks, unauthorised access or model theft. That protection could be facilitated by securing model weights, algorithms, servers, and data sets, such as through operational security measures for information security, specific cybersecurity policies, adequate technical and established solutions, and cyber and physical access controls, appropriate to the relevant circumstances and the risks involved.\n(116)\nThe AI Office should encourage and facilitate the drawing up, review and adaptation of codes of practice, taking into account international approaches. All providers of general-purpose AI models could be invited to participate. To ensure that the codes of practice reflect the state of the art and duly take into account a diverse set of perspectives, the AI Office should collaborate with relevant national competent authorities, and could, where appropriate, consult with civil society organisations and other relevant stakeholders and experts, including the Scientific Panel, for the drawing up of such codes. Codes of practice should cover obligations for providers of general-purpose AI models and of general-purpose AI models presenting systemic risks. In addition, as regards systemic risks, codes of practice should help to establish a risk taxonomy of the type and nature of the systemic risks at Union level, including their sources. Codes of practice should also be focused on specific risk assessment and mitigation measures.\n(117)\nThe codes of practice should represent a central tool for the proper compliance with the obligations provided for under this Regulation for providers of general-purpose AI models. Providers should be able to rely on codes of practice to demonstrate compliance with the obligations. By means of implementing acts, the Commission may decide to approve a code of practice and give it a general validity within the Union, or, alternatively, to provide common rules for the implementation of the relevant obligations, if, by the time this Regulation becomes applicable, a code of practice cannot be finalised or is not deemed adequate by the AI Office. Once a harmonised standard is published and assessed as suitable to cover the relevant obligations by the AI Office, compliance with a European harmonised standard should grant providers the presumption of conformity. Providers of general-purpose AI models should furthermore be able to demonstrate compliance using alternative adequate means, if codes of practice or harmonised standards are not available, or they choose not to rely on those.\n(118)\nThis Regulation regulates AI systems and AI models by imposing certain requirements and obligations for relevant market actors that are placing them on the market, putting into service or use in the Union, thereby complementing obligations for providers of intermediary services that embed such systems or models into their services regulated by Regulation (EU) 2022/2065. To the extent that such systems or models are embedded into designated very large online platforms or very large online search engines, they are subject to the risk-management framework provided for in Regulation (EU) 2022/2065. Consequently, the corresponding obligations of this Regulation should be presumed to be fulfilled, unless significant systemic risks not covered by Regulation (EU) 2022/2065 emerge and are identified in such models. Within this framework, providers of very large online platforms and very large online search engines are obliged to assess potential systemic risks stemming from the design, functioning and use of their services, including how the design of algorithmic systems used in the service may contribute to such risks, as well as systemic risks stemming from potential misuses. Those providers are also obliged to take appropriate mitigating measures in observance of fundamental rights.\n(119)\nConsidering the quick pace of innovation and the technological evolution of digital services in scope of different instruments of Union law in particular having in mind the usage and the perception of their recipients, the AI systems subject to this Regulation may be provided as intermediary services or parts thereof within the meaning of Regulation (EU) 2022/2065, which should be interpreted in a technology-neutral manner. For example, AI systems may be used to provide online search engines, in particular, to the extent that an AI system such as an online chatbot performs searches of, in principle, all websites, then incorporates the results into its existing knowledge and uses the updated knowledge to generate a single output that combines different sources of information.\n(120)\nFurthermore, obligations placed on providers and deployers of certain AI systems in this Regulation to enable the detection and disclosure that the outputs of those systems are artificially generated or manipulated are particularly relevant to facilitate the effective implementation of Regulation (EU) 2022/2065. This applies in particular as regards the obligations of providers of very large online platforms or very large online search engines to identify and mitigate systemic risks that may arise from the dissemination of content that has been artificially generated or manipulated, in particular risk of the actual or foreseeable negative effects on democratic processes, civic discourse and electoral processes, including through disinformation.\n(121)\nStandardisation should play a key role to provide technical solutions to providers to ensure compliance with this Regulation, in line with the state of the art, to promote innovation as well as competitiveness and growth in the single market. Compliance with harmonised standards as defined in Article 2, point (1)(c), of Regulation (EU) No 1025/2012 of the European Parliament and of the Council (41), which are normally expected to reflect the state of the art, should be a means for providers to demonstrate conformity with the requirements of this Regulation. A balanced representation of interests involving all relevant stakeholders in the development of standards, in particular SMEs, consumer organisations and environmental and social stakeholders in accordance with Articles 5 and 6 of Regulation (EU) No 1025/2012 should therefore be encouraged. In order to facilitate compliance, the standardisation requests should be issued by the Commission without undue delay. When preparing the standardisation request, the Commission should consult the advisory forum and the Board in order to collect relevant expertise. However, in the absence of relevant references to harmonised standards, the Commission should be able to establish, via implementing acts, and after consultation of the advisory forum, common specifications for certain requirements under this Regulation. The common specification should be an exceptional fall back solution to facilitate the provider’s obligation to comply with the requirements of this Regulation, when the standardisation request has not been accepted by any of the European standardisation organisations, or when the relevant harmonised standards insufficiently address fundamental rights concerns, or when the harmonised standards do not comply with the request, or when there are delays in the adoption of an appropriate harmonised standard. Where such a delay in the adoption of a harmonised standard is due to the technical complexity of that standard, this should be considered by the Commission before contemplating the establishment of common specifications. When developing common specifications, the Commission is encouraged to cooperate with international partners and international standardisation bodies.\n(122)\nIt is appropriate that, without prejudice to the use of harmonised standards and common specifications, providers of a high-risk AI system that has been trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which the AI system is intended to be used, should be presumed to comply with the relevant measure provided for under the requirement on data governance set out in this Regulation. Without prejudice to the requirements related to robustness and accuracy set out in this Regulation, in accordance with Article 54(3) of Regulation (EU) 2019/881, high-risk AI systems that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to that Regulation and the references of which have been published in the Official Journal of the European Union should be presumed to comply with the cybersecurity requirement of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover the cybersecurity requirement of this Regulation. This remains without prejudice to the voluntary nature of that cybersecurity scheme.\n(123)\nIn order to ensure a high level of trustworthiness of high-risk AI systems, those systems should be subject to a conformity assessment prior to their placing on the market or putting into service.\n(124)\nIt is appropriate that, in order to minimise the burden on operators and avoid any possible duplication, for high-risk AI systems related to products which are covered by existing Union harmonisation legislation based on the New Legislative Framework, the compliance of those AI systems with the requirements of this Regulation should be assessed as part of the conformity assessment already provided for in that law. The applicability of the requirements of this Regulation should thus not affect the specific logic, methodology or general structure of conformity assessment under the relevant Union harmonisation legislation.\n(125)\nGiven the complexity of high-risk AI systems and the risks that are associated with them, it is important to develop an adequate conformity assessment procedure for high-risk AI systems involving notified bodies, so-called third party conformity assessment. However, given the current experience of professional pre-market certifiers in the field of product safety and the different nature of risks involved, it is appropriate to limit, at least in an initial phase of application of this Regulation, the scope of application of third-party conformity assessment for high-risk AI systems other than those related to products. Therefore, the conformity assessment of such systems should be carried out as a general rule by the provider under its own responsibility, with the only exception of AI systems intended to be used for biometrics.\n(126)\nIn order to carry out third-party conformity assessments when so required, notified bodies should be notified under this Regulation by the national competent authorities, provided that they comply with a set of requirements, in particular on independence, competence, absence of conflicts of interests and suitable cybersecurity requirements. Notification of those bodies should be sent by national competent authorities to the Commission and the other Member States by means of the electronic notification tool developed and managed by the Commission pursuant to Article R23 of Annex I to Decision No 768/2008/EC.\n(127)\nIn line with Union commitments under the World Trade Organization Agreement on Technical Barriers to Trade, it is adequate to facilitate the mutual recognition of conformity assessment results produced by competent conformity assessment bodies, independent of the territory in which they are established, provided that those conformity assessment bodies established under the law of a third country meet the applicable requirements of this Regulation and the Union has concluded an agreement to that extent. In this context, the Commission should actively explore possible international instruments for that purpose and in particular pursue the conclusion of mutual recognition agreements with third countries.\n(128)\nIn line with the commonly established notion of substantial modification for products regulated by Union harmonisation legislation, it is appropriate that whenever a change occurs which may affect the compliance of a high-risk AI system with this Regulation (e.g. change of operating system or software architecture), or when the intended purpose of the system changes, that AI system should be considered to be a new AI system which should undergo a new conformity assessment. However, changes occurring to the algorithm and the performance of AI systems which continue to ‘learn’ after being placed on the market or put into service, namely automatically adapting how functions are carried out, should not constitute a substantial modification, provided that those changes have been pre-determined by the provider and assessed at the moment of the conformity assessment.\n(129)\nHigh-risk AI systems should bear the CE marking to indicate their conformity with this Regulation so that they can move freely within the internal market. For high-risk AI systems embedded in a product, a physical CE marking should be affixed, and may be complemented by a digital CE marking. For high-risk AI systems only provided digitally, a digital CE marking should be used. Member States should not create unjustified obstacles to the placing on the market or the putting into service of high-risk AI systems that comply with the requirements laid down in this Regulation and bear the CE marking.\n(130)\nUnder certain conditions, rapid availability of innovative technologies may be crucial for health and safety of persons, the protection of the environment and climate change and for society as a whole. It is thus appropriate that under exceptional reasons of public security or protection of life and health of natural persons, environmental protection and the protection of key industrial and infrastructural assets, market surveillance authorities could authorise the placing on the market or the putting into service of AI systems which have not undergone a conformity assessment. In duly justified situations, as provided for in this Regulation, law enforcement authorities or civil protection authorities may put a specific high-risk AI system into service without the authorisation of the market surveillance authority, provided that such authorisation is requested during or after the use without undue delay.\n(131)\nIn order to facilitate the work of the Commission and the Member States in the AI field as well as to increase the transparency towards the public, providers of high-risk AI systems other than those related to products falling within the scope of relevant existing Union harmonisation legislation, as well as providers who consider that an AI system listed in the high-risk use cases in an annex to this Regulation is not high-risk on the basis of a derogation, should be required to register themselves and information about their AI system in an EU database, to be established and managed by the Commission. Before using an AI system listed in the high-risk use cases in an annex to this Regulation, deployers of high-risk AI systems that are public authorities, agencies or bodies, should register themselves in such database and select the system that they envisage to use. Other deployers should be entitled to do so voluntarily. This section of the EU database should be publicly accessible, free of charge, the information should be easily navigable, understandable and machine-readable. The EU database should also be user-friendly, for example by providing search functionalities, including through keywords, allowing the general public to find relevant information to be submitted upon the registration of high-risk AI systems and on the use case of high-risk AI systems, set out in an annex to this Regulation, to which the high-risk AI systems correspond. Any substantial modification of high-risk AI systems should also be registered in the EU database. For high-risk AI systems in the area of law enforcement, migration, asylum and border control management, the registration obligations should be fulfilled in a secure non-public section of the EU database. Access to the secure non-public section should be strictly limited to the Commission as well as to market surveillance authorities with regard to their national section of that database. High-risk AI systems in the area of critical infrastructure should only be registered at national level. The Commission should be the controller of the EU database, in accordance with Regulation (EU) 2018/1725. In order to ensure the full functionality of the EU database, when deployed, the procedure for setting the database should include the development of functional specifications by the Commission and an independent audit report. The Commission should take into account cybersecurity risks when carrying out its tasks as data controller on the EU database. In order to maximise the availability and use of the EU database by the public, the EU database, including the information made available through it, should comply with requirements under the Directive (EU) 2019/882.\n(132)\nCertain AI systems intended to interact with natural persons or to generate content may pose specific risks of impersonation or deception irrespective of whether they qualify as high-risk or not. In certain circumstances, the use of these systems should therefore be subject to specific transparency obligations without prejudice to the requirements and obligations for high-risk AI systems and subject to targeted exceptions to take into account the special need of law enforcement. In particular, natural persons should be notified that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect taking into account the circumstances and the context of use. When implementing that obligation, the characteristics of natural persons belonging to vulnerable groups due to their age or disability should be taken into account to the extent the AI system is intended to interact with those groups as well. Moreover, natural persons should be notified when they are exposed to AI systems that, by processing their biometric data, can identify or infer the emotions or intentions of those persons or assign them to specific categories. Such specific categories can relate to aspects such as sex, age, hair colour, eye colour, tattoos, personal traits, ethnic origin, personal preferences and interests. Such information and notifications should be provided in accessible formats for persons with disabilities.\n(133)\nA variety of AI systems can generate large quantities of synthetic content that becomes increasingly hard for humans to distinguish from human-generated and authentic content. The wide availability and increasing capabilities of those systems have a significant impact on the integrity and trust in the information ecosystem, raising new risks of misinformation and manipulation at scale, fraud, impersonation and consumer deception. In light of those impacts, the fast technological pace and the need for new methods and techniques to trace origin of information, it is appropriate to require providers of those systems to embed technical solutions that enable marking in a machine readable format and detection that the output has been generated or manipulated by an AI system and not a human. Such techniques and methods should be sufficiently reliable, interoperable, effective and robust as far as this is technically feasible, taking into account available techniques or a combination of such techniques, such as watermarks, metadata identifications, cryptographic methods for proving provenance and authenticity of content, logging methods, fingerprints or other techniques, as may be appropriate. When implementing this obligation, providers should also take into account the specificities and the limitations of the different types of content and the relevant technological and market developments in the field, as reflected in the generally acknowledged state of the art. Such techniques and methods can be implemented at the level of the AI system or at the level of the AI model, including general-purpose AI models generating content, thereby facilitating fulfilment of this obligation by the downstream provider of the AI system. To remain proportionate, it is appropriate to envisage that this marking obligation should not cover AI systems performing primarily an assistive function for standard editing or AI systems not substantially altering the input data provided by the deployer or the semantics thereof.\n(134)\nFurther to the technical solutions employed by the providers of the AI system, deployers who use an AI system to generate or manipulate image, audio or video content that appreciably resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful (deep fakes), should also clearly and distinguishably disclose that the content has been artificially created or manipulated by labelling the AI output accordingly and disclosing its artificial origin. Compliance with this transparency obligation should not be interpreted as indicating that the use of the AI system or its output impedes the right to freedom of expression and the right to freedom of the arts and sciences guaranteed in the Charter, in particular where the content is part of an evidently creative, satirical, artistic, fictional or analogous work or programme, subject to appropriate safeguards for the rights and freedoms of third parties. In those cases, the transparency obligation for deep fakes set out in this Regulation is limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work, including its normal exploitation and use, while maintaining the utility and quality of the work. In addition, it is also appropriate to envisage a similar disclosure obligation in relation to AI-generated or manipulated text to the extent it is published with the purpose of informing the public on matters of public interest unless the AI-generated content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for the publication of the content.\n(135)\nWithout prejudice to the mandatory nature and full applicability of the transparency obligations, the Commission may also encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection and labelling of artificially generated or manipulated content, including to support practical arrangements for making, as appropriate, the detection mechanisms accessible and facilitating cooperation with other actors along the value chain, disseminating content or checking its authenticity and provenance to enable the public to effectively distinguish AI-generated content.\n(136)\nThe obligations placed on providers and deployers of certain AI systems in this Regulation to enable the detection and disclosure that the outputs of those systems are artificially generated or manipulated are particularly relevant to facilitate the effective implementation of Regulation (EU) 2022/2065. This applies in particular as regards the obligations of providers of very large online platforms or very large online search engines to identify and mitigate systemic risks that may arise from the dissemination of content that has been artificially generated or manipulated, in particular the risk of the actual or foreseeable negative effects on democratic processes, civic discourse and electoral processes, including through disinformation. The requirement to label content generated by AI systems under this Regulation is without prejudice to the obligation in Article 16(6) of Regulation (EU) 2022/2065 for providers of hosting services to process notices on illegal content received pursuant to Article 16(1) of that Regulation and should not influence the assessment and the decision on the illegality of the specific content. That assessment should be performed solely with reference to the rules governing the legality of the content.\n(137)\nCompliance with the transparency obligations for the AI systems covered by this Regulation should not be interpreted as indicating that the use of the AI system or its output is lawful under this Regulation or other Union and Member State law and should be without prejudice to other transparency obligations for deployers of AI systems laid down in Union or national law.\n(138)\nAI is a rapidly developing family of technologies that requires regulatory oversight and a safe and controlled space for experimentation, while ensuring responsible innovation and integration of appropriate safeguards and risk mitigation measures. To ensure a legal framework that promotes innovation, is future-proof and resilient to disruption, Member States should ensure that their national competent authorities establish at least one AI regulatory sandbox at national level to facilitate the development and testing of innovative AI systems under strict regulatory oversight before these systems are placed on the market or otherwise put into service. Member States could also fulfil this obligation through participating in already existing regulatory sandboxes or establishing jointly a sandbox with one or more Member States’ competent authorities, insofar as this participation provides equivalent level of national coverage for the participating Member States. AI regulatory sandboxes could be established in physical, digital or hybrid form and may accommodate physical as well as digital products. Establishing authorities should also ensure that the AI regulatory sandboxes have the adequate resources for their functioning, including financial and human resources.\n(139)\nThe objectives of the AI regulatory sandboxes should be to foster AI innovation by establishing a controlled experimentation and testing environment in the development and pre-marketing phase with a view to ensuring compliance of the innovative AI systems with this Regulation and other relevant Union and national law. Moreover, the AI regulatory sandboxes should aim to enhance legal certainty for innovators and the competent authorities’ oversight and understanding of the opportunities, emerging risks and the impacts of AI use, to facilitate regulatory learning for authorities and undertakings, including with a view to future adaptions of the legal framework, to support cooperation and the sharing of best practices with the authorities involved in the AI regulatory sandbox, and to accelerate access to markets, including by removing barriers for SMEs, including start-ups. AI regulatory sandboxes should be widely available throughout the Union, and particular attention should be given to their accessibility for SMEs, including start-ups. The participation in the AI regulatory sandbox should focus on issues that raise legal uncertainty for providers and prospective providers to innovate, experiment with AI in the Union and contribute to evidence-based regulatory learning. The supervision of the AI systems in the AI regulatory sandbox should therefore cover their development, training, testing and validation before the systems are placed on the market or put into service, as well as the notion and occurrence of substantial modification that may require a new conformity assessment procedure. Any significant risks identified during the development and testing of such AI systems should result in adequate mitigation and, failing that, in the suspension of the development and testing process. Where appropriate, national competent authorities establishing AI regulatory sandboxes should cooperate with other relevant authorities, including those supervising the protection of fundamental rights, and could allow for the involvement of other actors within the AI ecosystem such as national or European standardisation organisations, notified bodies, testing and experimentation facilities, research and experimentation labs, European Digital Innovation Hubs and relevant stakeholder and civil society organisations. To ensure uniform implementation across the Union and economies of scale, it is appropriate to establish common rules for the AI regulatory sandboxes’ implementation and a framework for cooperation between the relevant authorities involved in the supervision of the sandboxes. AI regulatory sandboxes established under this Regulation should be without prejudice to other law allowing for the establishment of other sandboxes aiming to ensure compliance with law other than this Regulation. Where appropriate, relevant competent authorities in charge of those other regulatory sandboxes should consider the benefits of using those sandboxes also for the purpose of ensuring compliance of AI systems with this Regulation. Upon agreement between the national competent authorities and the participants in the AI regulatory sandbox, testing in real world conditions may also be operated and supervised in the framework of the AI regulatory sandbox.\n(140)\nThis Regulation should provide the legal basis for the providers and prospective providers in the AI regulatory sandbox to use personal data collected for other purposes for developing certain AI systems in the public interest within the AI regulatory sandbox, only under specified conditions, in accordance with Article 6(4) and Article 9(2), point (g), of Regulation (EU) 2016/679, and Articles 5, 6 and 10 of Regulation (EU) 2018/1725, and without prejudice to Article 4(2) and Article 10 of Directive (EU) 2016/680. All other obligations of data controllers and rights of data subjects under Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680 remain applicable. In particular, this Regulation should not provide a legal basis in the meaning of Article 22(2), point (b) of Regulation (EU) 2016/679 and Article 24(2), point (b) of Regulation (EU) 2018/1725. Providers and prospective providers in the AI regulatory sandbox should ensure appropriate safeguards and cooperate with the competent authorities, including by following their guidance and acting expeditiously and in good faith to adequately mitigate any identified significant risks to safety, health, and fundamental rights that may arise during the development, testing and experimentation in that sandbox.\n(141)\nIn order to accelerate the process of development and the placing on the market of the high-risk AI systems listed in an annex to this Regulation, it is important that providers or prospective providers of such systems may also benefit from a specific regime for testing those systems in real world conditions, without participating in an AI regulatory sandbox. However, in such cases, taking into account the possible consequences of such testing on individuals, it should be ensured that appropriate and sufficient guarantees and conditions are introduced by this Regulation for providers or prospective providers. Such guarantees should include, inter alia, requesting informed consent of natural persons to participate in testing in real world conditions, with the exception of law enforcement where the seeking of informed consent would prevent the AI system from being tested. Consent of subjects to participate in such testing under this Regulation is distinct from, and without prejudice to, consent of data subjects for the processing of their personal data under the relevant data protection law. It is also important to minimise the risks and enable oversight by competent authorities and therefore require prospective providers to have a real-world testing plan submitted to competent market surveillance authority, register the testing in dedicated sections in the EU database subject to some limited exceptions, set limitations on the period for which the testing can be done and require additional safeguards for persons belonging to certain vulnerable groups, as well as a written agreement defining the roles and responsibilities of prospective providers and deployers and effective oversight by competent personnel involved in the real world testing. Furthermore, it is appropriate to envisage additional safeguards to ensure that the predictions, recommendations or decisions of the AI system can be effectively reversed and disregarded and that personal data is protected and is deleted when the subjects have withdrawn their consent to participate in the testing without prejudice to their rights as data subjects under the Union data protection law. As regards transfer of data, it is also appropriate to envisage that data collected and processed for the purpose of testing in real-world conditions should be transferred to third countries only where appropriate and applicable safeguards under Union law are implemented, in particular in accordance with bases for transfer of personal data under Union law on data protection, while for non-personal data appropriate safeguards are put in place in accordance with Union law, such as Regulations (EU) 2022/868 (42) and (EU) 2023/2854 (43) of the European Parliament and of the Council.\n(142)\nTo ensure that AI leads to socially and environmentally beneficial outcomes, Member States are encouraged to support and promote research and development of AI solutions in support of socially and environmentally beneficial outcomes, such as AI-based solutions to increase accessibility for persons with disabilities, tackle socio-economic inequalities, or meet environmental targets, by allocating sufficient resources, including public and Union funding, and, where appropriate and provided that the eligibility and selection criteria are fulfilled, considering in particular projects which pursue such objectives. Such projects should be based on the principle of interdisciplinary cooperation between AI developers, experts on inequality and non-discrimination, accessibility, consumer, environmental, and digital rights, as well as academics.\n(143)\nIn order to promote and protect innovation, it is important that the interests of SMEs, including start-ups, that are providers or deployers of AI systems are taken into particular account. To that end, Member States should develop initiatives, which are targeted at those operators, including on awareness raising and information communication. Member States should provide SMEs, including start-ups, that have a registered office or a branch in the Union, with priority access to the AI regulatory sandboxes provided that they fulfil the eligibility conditions and selection criteria and without precluding other providers and prospective providers to access the sandboxes provided the same conditions and criteria are fulfilled. Member States should utilise existing channels and where appropriate, establish new dedicated channels for communication with SMEs, including start-ups, deployers, other innovators and, as appropriate, local public authorities, to support SMEs throughout their development path by providing guidance and responding to queries about the implementation of this Regulation. Where appropriate, these channels should work together to create synergies and ensure homogeneity in their guidance to SMEs, including start-ups, and deployers. Additionally, Member States should facilitate the participation of SMEs and other relevant stakeholders in the standardisation development processes. Moreover, the specific interests and needs of providers that are SMEs, including start-ups, should be taken into account when notified bodies set conformity assessment fees. The Commission should regularly assess the certification and compliance costs for SMEs, including start-ups, through transparent consultations and should work with Member States to lower such costs. For example, translation costs related to mandatory documentation and communication with authorities may constitute a significant cost for providers and other operators, in particular those of a smaller scale. Member States should possibly ensure that one of the languages determined and accepted by them for relevant providers’ documentation and for communication with operators is one which is broadly understood by the largest possible number of cross-border deployers. In order to address the specific needs of SMEs, including start-ups, the Commission should provide standardised templates for the areas covered by this Regulation, upon request of the Board. Additionally, the Commission should complement Member States’ efforts by providing a single information platform with easy-to-use information with regards to this Regulation for all providers and deployers, by organising appropriate communication campaigns to raise awareness about the obligations arising from this Regulation, and by evaluating and promoting the convergence of best practices in public procurement procedures in relation to AI systems. Medium-sized enterprises which until recently qualified as small enterprises within the meaning of the Annex to Commission Recommendation 2003/361/EC (44) should have access to those support measures, as those new medium-sized enterprises may sometimes lack the legal resources and training necessary to ensure proper understanding of, and compliance with, this Regulation.\n(144)\nIn order to promote and protect innovation, the AI-on-demand platform, all relevant Union funding programmes and projects, such as Digital Europe Programme, Horizon Europe, implemented by the Commission and the Member States at Union or national level should, as appropriate, contribute to the achievement of the objectives of this Regulation.\n(145)\nIn order to minimise the risks to implementation resulting from lack of knowledge and expertise in the market as well as to facilitate compliance of providers, in particular SMEs, including start-ups, and notified bodies with their obligations under this Regulation, the AI-on-demand platform, the European Digital Innovation Hubs and the testing and experimentation facilities established by the Commission and the Member States at Union or national level should contribute to the implementation of this Regulation. Within their respective mission and fields of competence, the AI-on-demand platform, the European Digital Innovation Hubs and the testing and experimentation Facilities are able to provide in particular technical and scientific support to providers and notified bodies.\n(146)\nMoreover, in light of the very small size of some operators and in order to ensure proportionality regarding costs of innovation, it is appropriate to allow microenterprises to fulfil one of the most costly obligations, namely to establish a quality management system, in a simplified manner which would reduce the administrative burden and the costs for those enterprises without affecting the level of protection and the need for compliance with the requirements for high-risk AI systems. The Commission should develop guidelines to specify the elements of the quality management system to be fulfilled in this simplified manner by microenterprises.\n(147)\nIt is appropriate that the Commission facilitates, to the extent possible, access to testing and experimentation facilities to bodies, groups or laboratories established or accredited pursuant to any relevant Union harmonisation legislation and which fulfil tasks in the context of conformity assessment of products or devices covered by that Union harmonisation legislation. This is, in particular, the case as regards expert panels, expert laboratories and reference laboratories in the field of medical devices pursuant to Regulations (EU) 2017/745 and (EU) 2017/746.\n(148)\nThis Regulation should establish a governance framework that both allows to coordinate and support the application of this Regulation at national level, as well as build capabilities at Union level and integrate stakeholders in the field of AI. The effective implementation and enforcement of this Regulation require a governance framework that allows to coordinate and build up central expertise at Union level. The AI Office was established by Commission Decision (45) and has as its mission to develop Union expertise and capabilities in the field of AI and to contribute to the implementation of Union law on AI. Member States should facilitate the tasks of the AI Office with a view to support the development of Union expertise and capabilities at Union level and to strengthen the functioning of the digital single market. Furthermore, a Board composed of representatives of the Member States, a scientific panel to integrate the scientific community and an advisory forum to contribute stakeholder input to the implementation of this Regulation, at Union and national level, should be established. The development of Union expertise and capabilities should also include making use of existing resources and expertise, in particular through synergies with structures built up in the context of the Union level enforcement of other law and synergies with related initiatives at Union level, such as the EuroHPC Joint Undertaking and the AI testing and experimentation facilities under the Digital Europe Programme.\n(149)\nIn order to facilitate a smooth, effective and harmonised implementation of this Regulation a Board should be established. The Board should reflect the various interests of the AI eco-system and be composed of representatives of the Member States. The Board should be responsible for a number of advisory tasks, including issuing opinions, recommendations, advice or contributing to guidance on matters related to the implementation of this Regulation, including on enforcement matters, technical specifications or existing standards regarding the requirements established in this Regulation and providing advice to the Commission and the Member States and their national competent authorities on specific questions related to AI. In order to give some flexibility to Member States in the designation of their representatives in the Board, such representatives may be any persons belonging to public entities who should have the relevant competences and powers to facilitate coordination at national level and contribute to the achievement of the Board’s tasks. The Board should establish two standing sub-groups to provide a platform for cooperation and exchange among market surveillance authorities and notifying authorities on issues related, respectively, to market surveillance and notified bodies. The standing subgroup for market surveillance should act as the administrative cooperation group (ADCO) for this Regulation within the meaning of Article 30 of Regulation (EU) 2019/1020. In accordance with Article 33 of that Regulation, the Commission should support the activities of the standing subgroup for market surveillance by undertaking market evaluations or studies, in particular with a view to identifying aspects of this Regulation requiring specific and urgent coordination among market surveillance authorities. The Board may establish other standing or temporary sub-groups as appropriate for the purpose of examining specific issues. The Board should also cooperate, as appropriate, with relevant Union bodies, experts groups and networks active in the context of relevant Union law, including in particular those active under relevant Union law on data, digital products and services.\n(150)\nWith a view to ensuring the involvement of stakeholders in the implementation and application of this Regulation, an advisory forum should be established to advise and provide technical expertise to the Board and the Commission. To ensure a varied and balanced stakeholder representation between commercial and non-commercial interest and, within the category of commercial interests, with regards to SMEs and other undertakings, the advisory forum should comprise inter alia industry, start-ups, SMEs, academia, civil society, including the social partners, as well as the Fundamental Rights Agency, ENISA, the European Committee for Standardization (CEN), the European Committee for Electrotechnical Standardization (CENELEC) and the European Telecommunications Standards Institute (ETSI).\n(151)\nTo support the implementation and enforcement of this Regulation, in particular the monitoring activities of the AI Office as regards general-purpose AI models, a scientific panel of independent experts should be established. The independent experts constituting the scientific panel should be selected on the basis of up-to-date scientific or technical expertise in the field of AI and should perform their tasks with impartiality, objectivity and ensure the confidentiality of information and data obtained in carrying out their tasks and activities. To allow the reinforcement of national capacities necessary for the effective enforcement of this Regulation, Member States should be able to request support from the pool of experts constituting the scientific panel for their enforcement activities.\n(152)\nIn order to support adequate enforcement as regards AI systems and reinforce the capacities of the Member States, Union AI testing support structures should be established and made available to the Member States.\n(153)\nMember States hold a key role in the application and enforcement of this Regulation. In that respect, each Member State should designate at least one notifying authority and at least one market surveillance authority as national competent authorities for the purpose of supervising the application and implementation of this Regulation. Member States may decide to appoint any kind of public entity to perform the tasks of the national competent authorities within the meaning of this Regulation, in accordance with their specific national organisational characteristics and needs. In order to increase organisation efficiency on the side of Member States and to set a single point of contact vis-à-vis the public and other counterparts at Member State and Union levels, each Member State should designate a market surveillance authority to act as a single point of contact.\n(154)\nThe national competent authorities should exercise their powers independently, impartially and without bias, so as to safeguard the principles of objectivity of their activities and tasks and to ensure the application and implementation of this Regulation. The members of these authorities should refrain from any action incompatible with their duties and should be subject to confidentiality rules under this Regulation.\n(155)\nIn order to ensure that providers of high-risk AI systems can take into account the experience on the use of high-risk AI systems for improving their systems and the design and development process or can take any possible corrective action in a timely manner, all providers should have a post-market monitoring system in place. Where relevant, post-market monitoring should include an analysis of the interaction with other AI systems including other devices and software. Post-market monitoring should not cover sensitive operational data of deployers which are law enforcement authorities. This system is also key to ensure that the possible risks emerging from AI systems which continue to ‘learn’ after being placed on the market or put into service can be more efficiently and timely addressed. In this context, providers should also be required to have a system in place to report to the relevant authorities any serious incidents resulting from the use of their AI systems, meaning incident or malfunctioning leading to death or serious damage to health, serious and irreversible disruption of the management and operation of critical infrastructure, infringements of obligations under Union law intended to protect fundamental rights or serious damage to property or the environment.\n(156)\nIn order to ensure an appropriate and effective enforcement of the requirements and obligations set out by this Regulation, which is Union harmonisation legislation, the system of market surveillance and compliance of products established by Regulation (EU) 2019/1020 should apply in its entirety. Market surveillance authorities designated pursuant to this Regulation should have all enforcement powers laid down in this Regulation and in Regulation (EU) 2019/1020 and should exercise their powers and carry out their duties independently, impartially and without bias. Although the majority of AI systems are not subject to specific requirements and obligations under this Regulation, market surveillance authorities may take measures in relation to all AI systems when they present a risk in accordance with this Regulation. Due to the specific nature of Union institutions, agencies and bodies falling within the scope of this Regulation, it is appropriate to designate the European Data Protection Supervisor as a competent market surveillance authority for them. This should be without prejudice to the designation of national competent authorities by the Member States. Market surveillance activities should not affect the ability of the supervised entities to carry out their tasks independently, when such independence is required by Union law.\n(157)\nThis Regulation is without prejudice to the competences, tasks, powers and independence of relevant national public authorities or bodies which supervise the application of Union law protecting fundamental rights, including equality bodies and data protection authorities. Where necessary for their mandate, those national public authorities or bodies should also have access to any documentation created under this Regulation. A specific safeguard procedure should be set for ensuring adequate and timely enforcement against AI systems presenting a risk to health, safety and fundamental rights. The procedure for such AI systems presenting a risk should be applied to high-risk AI systems presenting a risk, prohibited systems which have been placed on the market, put into service or used in violation of the prohibited practices laid down in this Regulation and AI systems which have been made available in violation of the transparency requirements laid down in this Regulation and present a risk.\n(158)\nUnion financial services law includes internal governance and risk-management rules and requirements which are applicable to regulated financial institutions in the course of provision of those services, including when they make use of AI systems. In order to ensure coherent application and enforcement of the obligations under this Regulation and relevant rules and requirements of the Union financial services legal acts, the competent authorities for the supervision and enforcement of those legal acts, in particular competent authorities as defined in Regulation (EU) No 575/2013 of the European Parliament and of the Council (46) and Directives 2008/48/EC (47), 2009/138/EC (48), 2013/36/EU (49), 2014/17/EU (50) and (EU) 2016/97 (51) of the European Parliament and of the Council, should be designated, within their respective competences, as competent authorities for the purpose of supervising the implementation of this Regulation, including for market surveillance activities, as regards AI systems provided or used by regulated and supervised financial institutions unless Member States decide to designate another authority to fulfil these market surveillance tasks. Those competent authorities should have all powers under this Regulation and Regulation (EU) 2019/1020 to enforce the requirements and obligations of this Regulation, including powers to carry our ex post market surveillance activities that can be integrated, as appropriate, into their existing supervisory mechanisms and procedures under the relevant Union financial services law. It is appropriate to envisage that, when acting as market surveillance authorities under this Regulation, the national authorities responsible for the supervision of credit institutions regulated under Directive 2013/36/EU, which are participating in the Single Supervisory Mechanism established by Council Regulation (EU) No 1024/2013 (52), should report, without delay, to the European Central Bank any information identified in the course of their market surveillance activities that may be of potential interest for the European Central Bank’s prudential supervisory tasks as specified in that Regulation. To further enhance the consistency between this Regulation and the rules applicable to credit institutions regulated under Directive 2013/36/EU, it is also appropriate to integrate some of the providers’ procedural obligations in relation to risk management, post marketing monitoring and documentation into the existing obligations and procedures under Directive 2013/36/EU. In order to avoid overlaps, limited derogations should also be envisaged in relation to the quality management system of providers and the monitoring obligation placed on deployers of high-risk AI systems to the extent that these apply to credit institutions regulated by Directive 2013/36/EU. The same regime should apply to insurance and re-insurance undertakings and insurance holding companies under Directive 2009/138/EC and the insurance intermediaries under Directive (EU) 2016/97 and other types of financial institutions subject to requirements regarding internal governance, arrangements or processes established pursuant to the relevant Union financial services law to ensure consistency and equal treatment in the financial sector.\n(159)\nEach market surveillance authority for high-risk AI systems in the area of biometrics, as listed in an annex to this Regulation insofar as those systems are used for the purposes of law enforcement, migration, asylum and border control management, or the administration of justice and democratic processes, should have effective investigative and corrective powers, including at least the power to obtain access to all personal data that are being processed and to all information necessary for the performance of its tasks. The market surveillance authorities should be able to exercise their powers by acting with complete independence. Any limitations of their access to sensitive operational data under this Regulation should be without prejudice to the powers conferred to them by Directive (EU) 2016/680. No exclusion on disclosing data to national data protection authorities under this Regulation should affect the current or future powers of those authorities beyond the scope of this Regulation.\n(160)\nThe market surveillance authorities and the Commission should be able to propose joint activities, including joint investigations, to be conducted by market surveillance authorities or market surveillance authorities jointly with the Commission, that have the aim of promoting compliance, identifying non-compliance, raising awareness and providing guidance in relation to this Regulation with respect to specific categories of high-risk AI systems that are found to present a serious risk across two or more Member States. Joint activities to promote compliance should be carried out in accordance with Article 9 of Regulation (EU) 2019/1020. The AI Office should provide coordination support for joint investigations.\n(161)\nIt is necessary to clarify the responsibilities and competences at Union and national level as regards AI systems that are built on general-purpose AI models. To avoid overlapping competences, where an AI system is based on a general-purpose AI model and the model and system are provided by the same provider, the supervision should take place at Union level through the AI Office, which should have the powers of a market surveillance authority within the meaning of Regulation (EU) 2019/1020 for this purpose. In all other cases, national market surveillance authorities remain responsible for the supervision of AI systems. However, for general-purpose AI systems that can be used directly by deployers for at least one purpose that is classified as high-risk, market surveillance authorities should cooperate with the AI Office to carry out evaluations of compliance and inform the Board and other market surveillance authorities accordingly. Furthermore, market surveillance authorities should be able to request assistance from the AI Office where the market surveillance authority is unable to conclude an investigation on a high-risk AI system because of its inability to access certain information related to the general-purpose AI model on which the high-risk AI system is built. In such cases, the procedure regarding mutual assistance in cross-border cases in Chapter VI of Regulation (EU) 2019/1020 should apply mutatis mutandis.\n(162)\nTo make best use of the centralised Union expertise and synergies at Union level, the powers of supervision and enforcement of the obligations on providers of general-purpose AI models should be a competence of the Commission. The AI Office should be able to carry out all necessary actions to monitor the effective implementation of this Regulation as regards general-purpose AI models. It should be able to investigate possible infringements of the rules on providers of general-purpose AI models both on its own initiative, following the results of its monitoring activities, or upon request from market surveillance authorities in line with the conditions set out in this Regulation. To support effective monitoring of the AI Office, it should provide for the possibility that downstream providers lodge complaints about possible infringements of the rules on providers of general-purpose AI models and systems.\n(163)\nWith a view to complementing the governance systems for general-purpose AI models, the scientific panel should support the monitoring activities of the AI Office and may, in certain cases, provide qualified alerts to the AI Office which trigger follow-ups, such as investigations. This should be the case where the scientific panel has reason to suspect that a general-purpose AI model poses a concrete and identifiable risk at Union level. Furthermore, this should be the case where the scientific panel has reason to suspect that a general-purpose AI model meets the criteria that would lead to a classification as general-purpose AI model with systemic risk. To equip the scientific panel with the information necessary for the performance of those tasks, there should be a mechanism whereby the scientific panel can request the Commission to require documentation or information from a provider.\n(164)\nThe AI Office should be able to take the necessary actions to monitor the effective implementation of and compliance with the obligations for providers of general-purpose AI models laid down in this Regulation. The AI Office should be able to investigate possible infringements in accordance with the powers provided for in this Regulation, including by requesting documentation and information, by conducting evaluations, as well as by requesting measures from providers of general-purpose AI models. When conducting evaluations, in order to make use of independent expertise, the AI Office should be able to involve independent experts to carry out the evaluations on its behalf. Compliance with the obligations should be enforceable, inter alia, through requests to take appropriate measures, including risk mitigation measures in the case of identified systemic risks as well as restricting the making available on the market, withdrawing or recalling the model. As a safeguard, where needed beyond the procedural rights provided for in this Regulation, providers of general-purpose AI models should have the procedural rights provided for in Article 18 of Regulation (EU) 2019/1020, which should apply mutatis mutandis, without prejudice to more specific procedural rights provided for by this Regulation.\n(165)\nThe development of AI systems other than high-risk AI systems in accordance with the requirements of this Regulation may lead to a larger uptake of ethical and trustworthy AI in the Union. Providers of AI systems that are not high-risk should be encouraged to create codes of conduct, including related governance mechanisms, intended to foster the voluntary application of some or all of the mandatory requirements applicable to high-risk AI systems, adapted in light of the intended purpose of the systems and the lower risk involved and taking into account the available technical solutions and industry best practices such as model and data cards. Providers and, as appropriate, deployers of all AI systems, high-risk or not, and AI models should also be encouraged to apply on a voluntary basis additional requirements related, for example, to the elements of the Union’s Ethics Guidelines for Trustworthy AI, environmental sustainability, AI literacy measures, inclusive and diverse design and development of AI systems, including attention to vulnerable persons and accessibility to persons with disability, stakeholders’ participation with the involvement, as appropriate, of relevant stakeholders such as business and civil society organisations, academia, research organisations, trade unions and consumer protection organisations in the design and development of AI systems, and diversity of the development teams, including gender balance. To ensure that the voluntary codes of conduct are effective, they should be based on clear objectives and key performance indicators to measure the achievement of those objectives. They should also be developed in an inclusive way, as appropriate, with the involvement of relevant stakeholders such as business and civil society organisations, academia, research organisations, trade unions and consumer protection organisation. The Commission may develop initiatives, including of a sectoral nature, to facilitate the lowering of technical barriers hindering cross-border exchange of data for AI development, including on data access infrastructure, semantic and technical interoperability of different types of data.\n(166)\nIt is important that AI systems related to products that are not high-risk in accordance with this Regulation and thus are not required to comply with the requirements set out for high-risk AI systems are nevertheless safe when placed on the market or put into service. To contribute to this objective, Regulation (EU) 2023/988 of the European Parliament and of the Council (53) would apply as a safety net.\n(167)\nIn order to ensure trustful and constructive cooperation of competent authorities on Union and national level, all parties involved in the application of this Regulation should respect the confidentiality of information and data obtained in carrying out their tasks, in accordance with Union or national law. They should carry out their tasks and activities in such a manner as to protect, in particular, intellectual property rights, confidential business information and trade secrets, the effective implementation of this Regulation, public and national security interests, the integrity of criminal and administrative proceedings, and the integrity of classified information.\n(168)\nCompliance with this Regulation should be enforceable by means of the imposition of penalties and other enforcement measures. Member States should take all necessary measures to ensure that the provisions of this Regulation are implemented, including by laying down effective, proportionate and dissuasive penalties for their infringement, and to respect the ne bis in idem principle. In order to strengthen and harmonise administrative penalties for infringement of this Regulation, the upper limits for setting the administrative fines for certain specific infringements should be laid down. When assessing the amount of the fines, Member States should, in each individual case, take into account all relevant circumstances of the specific situation, with due regard in particular to the nature, gravity and duration of the infringement and of its consequences and to the size of the provider, in particular if the provider is an SME, including a start-up. The European Data Protection Supervisor should have the power to impose fines on Union institutions, agencies and bodies falling within the scope of this Regulation.\n(169)\nCompliance with the obligations on providers of general-purpose AI models imposed under this Regulation should be enforceable, inter alia, by means of fines. To that end, appropriate levels of fines should also be laid down for infringement of those obligations, including the failure to comply with measures requested by the Commission in accordance with this Regulation, subject to appropriate limitation periods in accordance with the principle of proportionality. All decisions taken by the Commission under this Regulation are subject to review by the Court of Justice of the European Union in accordance with the TFEU, including the unlimited jurisdiction of the Court of Justice with regard to penalties pursuant to Article 261 TFEU.\n(170)\nUnion and national law already provide effective remedies to natural and legal persons whose rights and freedoms are adversely affected by the use of AI systems. Without prejudice to those remedies, any natural or legal person that has grounds to consider that there has been an infringement of this Regulation should be entitled to lodge a complaint to the relevant market surveillance authority.\n(171)\nAffected persons should have the right to obtain an explanation where a deployer’s decision is based mainly upon the output from certain high-risk AI systems that fall within the scope of this Regulation and where that decision produces legal effects or similarly significantly affects those persons in a way that they consider to have an adverse impact on their health, safety or fundamental rights. That explanation should be clear and meaningful and should provide a basis on which the affected persons are able to exercise their rights. The right to obtain an explanation should not apply to the use of AI systems for which exceptions or restrictions follow from Union or national law and should apply only to the extent this right is not already provided for under Union law.\n(172)\nPersons acting as whistleblowers on the infringements of this Regulation should be protected under the Union law. Directive (EU) 2019/1937 of the European Parliament and of the Council (54) should therefore apply to the reporting of infringements of this Regulation and the protection of persons reporting such infringements.\n(173)\nIn order to ensure that the regulatory framework can be adapted where necessary, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission to amend the conditions under which an AI system is not to be considered to be high-risk, the list of high-risk AI systems, the provisions regarding technical documentation, the content of the EU declaration of conformity the provisions regarding the conformity assessment procedures, the provisions establishing the high-risk AI systems to which the conformity assessment procedure based on assessment of the quality management system and assessment of the technical documentation should apply, the threshold, benchmarks and indicators, including by supplementing those benchmarks and indicators, in the rules for the classification of general-purpose AI models with systemic risk, the criteria for the designation of general-purpose AI models with systemic risk, the technical documentation for providers of general-purpose AI models and the transparency information for providers of general-purpose AI models. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making (55). In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.\n(174)\nGiven the rapid technological developments and the technical expertise required to effectively apply this Regulation, the Commission should evaluate and review this Regulation by 2 August 2029 and every four years thereafter and report to the European Parliament and the Council. In addition, taking into account the implications for the scope of this Regulation, the Commission should carry out an assessment of the need to amend the list of high-risk AI systems and the list of prohibited practices once a year. Moreover, by 2 August 2028 and every four years thereafter, the Commission should evaluate and report to the European Parliament and to the Council on the need to amend the list of high-risk areas headings in the annex to this Regulation, the AI systems within the scope of the transparency obligations, the effectiveness of the supervision and governance system and the progress on the development of standardisation deliverables on energy efficient development of general-purpose AI models, including the need for further measures or actions. Finally, by 2 August 2028 and every three years thereafter, the Commission should evaluate the impact and effectiveness of voluntary codes of conduct to foster the application of the requirements provided for high-risk AI systems in the case of AI systems other than high-risk AI systems and possibly other additional requirements for such AI systems.\n(175)\nIn order to ensure uniform conditions for the implementation of this Regulation, implementing powers should be conferred on the Commission. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of the Council (56).\n(176)\nSince the objective of this Regulation, namely to improve the functioning of the internal market and to promote the uptake of human centric and trustworthy AI, while ensuring a high level of protection of health, safety, fundamental rights enshrined in the Charter, including democracy, the rule of law and environmental protection against harmful effects of AI systems in the Union and supporting innovation, cannot be sufficiently achieved by the Member States and can rather, by reason of the scale or effects of the action, be better achieved at Union level, the Union may adopt measures in accordance with the principle of subsidiarity as set out in Article 5 TEU. In accordance with the principle of proportionality as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve that objective.\n(177)\nIn order to ensure legal certainty, ensure an appropriate adaptation period for operators and avoid disruption to the market, including by ensuring continuity of the use of AI systems, it is appropriate that this Regulation applies to the high-risk AI systems that have been placed on the market or put into service before the general date of application thereof, only if, from that date, those systems are subject to significant changes in their design or intended purpose. It is appropriate to clarify that, in this respect, the concept of significant change should be understood as equivalent in substance to the notion of substantial modification, which is used with regard only to high-risk AI systems pursuant to this Regulation. On an exceptional basis and in light of public accountability, operators of AI systems which are components of the large-scale IT systems established by the legal acts listed in an annex to this Regulation and operators of high-risk AI systems that are intended to be used by public authorities should, respectively, take the necessary steps to comply with the requirements of this Regulation by end of 2030 and by 2 August 2030.\n(178)\nProviders of high-risk AI systems are encouraged to start to comply, on a voluntary basis, with the relevant obligations of this Regulation already during the transitional period.\n(179)\nThis Regulation should apply from 2 August 2026. However, taking into account the unacceptable risk associated with the use of AI in certain ways, the prohibitions as well as the general provisions of this Regulation should already apply from 2 February 2025. While the full effect of those prohibitions follows with the establishment of the governance and enforcement of this Regulation, anticipating the application of the prohibitions is important to take account of unacceptable risks and to have an effect on other procedures, such as in civil law. Moreover, the infrastructure related to the governance and the conformity assessment system should be operational before 2 August 2026, therefore the provisions on notified bodies and governance structure should apply from 2 August 2025. Given the rapid pace of technological advancements and adoption of general-purpose AI models, obligations for providers of general-purpose AI models should apply from 2 August 2025. Codes of practice should be ready by 2 May 2025 in view of enabling providers to demonstrate compliance on time. The AI Office should ensure that classification rules and procedures are up to date in light of technological developments. In addition, Member States should lay down and notify to the Commission the rules on penalties, including administrative fines, and ensure that they are properly and effectively implemented by the date of application of this Regulation. Therefore the provisions on penalties should apply from 2 August 2025.\n(180)\nThe European Data Protection Supervisor and the European Data Protection Board were consulted in accordance with Article 42(1) and (2) of Regulation (EU) 2018/1725 and delivered their joint opinion on 18 June 2021,\nHAVE ADOPTED THIS REGULATION:\nCHAPTER I GENERAL PROVISIONS\nArticle 1 Subject matter The purpose of this Regulation is to improve the functioning of the internal market and promote the uptake of human-centric and trustworthy artificial intelligence (AI), while ensuring a high level of protection of health, safety, fundamental rights enshrined in the Charter, including democracy, the rule of law and environmental protection, against the harmful effects of AI systems in the Union and supporting innovation.\nThis Regulation lays down:\n(a)\nharmonised rules for the placing on the market, the putting into service, and the use of AI systems in the Union;\n(b)\nprohibitions of certain AI practices;\n(c)\nspecific requirements for high-risk AI systems and obligations for operators of such systems;\n(d)\nharmonised transparency rules for certain AI systems;\n(e)\nharmonised rules for the placing on the market of general-purpose AI models;\n(f)\nrules on market monitoring, market surveillance, governance and enforcement;\n(g)\nmeasures to support innovation, with a particular focus on SMEs, including start-ups.\nArticle 2 Scope This Regulation applies to: (a)\nproviders placing on the market or putting into service AI systems or placing on the market general-purpose AI models in the Union, irrespective of whether those providers are established or located within the Union or in a third country;\n(b)\ndeployers of AI systems that have their place of establishment or are located within the Union;\n(c)\nproviders and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union;\n(d)\nimporters and distributors of AI systems;\n(e)\nproduct manufacturers placing on the market or putting into service an AI system together with their product and under their own name or trademark;\n(f)\nauthorised representatives of providers, which are not established in the Union;\n(g)\naffected persons that are located in the Union.\nFor AI systems classified as high-risk AI systems in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Articles 102 to 109 and Article 112 apply. Article 57 applies only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation.\nThis Regulation does not apply to areas outside the scope of Union law, and shall not, in any event, affect the competences of the Member States concerning national security, regardless of the type of entity entrusted by the Member States with carrying out tasks in relation to those competences.\nThis Regulation does not apply to AI systems where and in so far they are placed on the market, put into service, or used with or without modification exclusively for military, defence or national security purposes, regardless of the type of entity carrying out those activities.\nThis Regulation does not apply to AI systems which are not placed on the market or put into service in the Union, where the output is used in the Union exclusively for military, defence or national security purposes, regardless of the type of entity carrying out those activities.\nThis Regulation applies neither to public authorities in a third country nor to international organisations falling within the scope of this Regulation pursuant to paragraph 1, where those authorities or organisations use AI systems in the framework of international cooperation or agreements for law enforcement and judicial cooperation with the Union or with one or more Member States, provided that such a third country or international organisation provides adequate safeguards with respect to the protection of fundamental rights and freedoms of individuals.\nThis Regulation shall not affect the application of the provisions on the liability of providers of intermediary services as set out in Chapter II of Regulation (EU) 2022/2065.\nThis Regulation does not apply to AI systems or AI models, including their output, specifically developed and put into service for the sole purpose of scientific research and development.\nUnion law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation. This Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680, without prejudice to Article 10(5) and Article 59 of this Regulation.\nThis Regulation does not apply to any research, testing or development activity regarding AI systems or AI models prior to their being placed on the market or put into service. Such activities shall be conducted in accordance with applicable Union law. Testing in real world conditions shall not be covered by that exclusion.\nThis Regulation is without prejudice to the rules laid down by other Union legal acts related to consumer protection and product safety.\nThis Regulation does not apply to obligations of deployers who are natural persons using AI systems in the course of a purely personal non-professional activity.\nThis Regulation does not preclude the Union or Member States from maintaining or introducing laws, regulations or administrative provisions which are more favourable to workers in terms of protecting their rights in respect of the use of AI systems by employers, or from encouraging or allowing the application of collective agreements which are more favourable to workers.\nThis Regulation does not apply to AI systems released under free and open-source licences, unless they are placed on the market or put into service as high-risk AI systems or as an AI system that falls under Article 5 or 50.\nArticle 3 Definitions For the purposes of this Regulation, the following definitions apply:\n(1)\n‘AI system’ means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments;\n(2)\n‘risk’ means the combination of the probability of an occurrence of harm and the severity of that harm;\n(3)\n‘provider’ means a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge;\n(4)\n‘deployer’ means a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity;\n(5)\n‘authorised representative’ means a natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general-purpose AI model to, respectively, perform and carry out on its behalf the obligations and procedures established by this Regulation;\n(6)\n‘importer’ means a natural or legal person located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country;\n(7)\n‘distributor’ means a natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market;\n(8)\n‘operator’ means a provider, product manufacturer, deployer, authorised representative, importer or distributor;\n(9)\n‘placing on the market’ means the first making available of an AI system or a general-purpose AI model on the Union market;\n(10)\n‘making available on the market’ means the supply of an AI system or a general-purpose AI model for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge;\n(11)\n‘putting into service’ means the supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose;\n(12)\n‘intended purpose’ means the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation;\n(13)\n‘reasonably foreseeable misuse’ means the use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems;\n(14)\n‘safety component’ means a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property;\n(15)\n‘instructions for use’ means the information provided by the provider to inform the deployer of, in particular, an AI system’s intended purpose and proper use;\n(16)\n‘recall of an AI system’ means any measure aiming to achieve the return to the provider or taking out of service or disabling the use of an AI system made available to deployers;\n(17)\n‘withdrawal of an AI system’ means any measure aiming to prevent an AI system in the supply chain being made available on the market;\n(18)\n‘performance of an AI system’ means the ability of an AI system to achieve its intended purpose;\n(19)\n‘notifying authority’ means the national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring;\n(20)\n‘conformity assessment’ means the process of demonstrating whether the requirements set out in Chapter III, Section 2 relating to a high-risk AI system have been fulfilled;\n(21)\n‘conformity assessment body’ means a body that performs third-party conformity assessment activities, including testing, certification and inspection;\n(22)\n‘notified body’ means a conformity assessment body notified in accordance with this Regulation and other relevant Union harmonisation legislation;\n(23)\n‘substantial modification’ means a change to an AI system after its placing on the market or putting into service which is not foreseen or planned in the initial conformity assessment carried out by the provider and as a result of which the compliance of the AI system with the requirements set out in Chapter III, Section 2 is affected or results in a modification to the intended purpose for which the AI system has been assessed;\n(24)\n‘CE marking’ means a marking by which a provider indicates that an AI system is in conformity with the requirements set out in Chapter III, Section 2 and other applicable Union harmonisation legislation providing for its affixing;\n(25)\n‘post-market monitoring system’ means all activities carried out by providers of AI systems to collect and review experience gained from the use of AI systems they place on the market or put into service for the purpose of identifying any need to immediately apply any necessary corrective or preventive actions;\n(26)\n‘market surveillance authority’ means the national authority carrying out the activities and taking the measures pursuant to Regulation (EU) 2019/1020;\n(27)\n‘harmonised standard’ means a harmonised standard as defined in Article 2(1), point (c), of Regulation (EU) No 1025/2012;\n(28)\n‘common specification’ means a set of technical specifications as defined in Article 2, point (4) of Regulation (EU) No 1025/2012, providing means to comply with certain requirements established under this Regulation;\n(29)\n‘training data’ means data used for training an AI system through fitting its learnable parameters;\n(30)\n‘validation data’ means data used for providing an evaluation of the trained AI system and for tuning its non-learnable parameters and its learning process in order, inter alia, to prevent underfitting or overfitting;\n(31)\n‘validation data set’ means a separate data set or part of the training data set, either as a fixed or variable split;\n(32)\n‘testing data’ means data used for providing an independent evaluation of the AI system in order to confirm the expected performance of that system before its placing on the market or putting into service;\n(33)\n‘input data’ means data provided to or directly acquired by an AI system on the basis of which the system produces an output;\n(34)\n‘biometric data’ means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, such as facial images or dactyloscopic data;\n(35)\n‘biometric identification’ means the automated recognition of physical, physiological, behavioural, or psychological human features for the purpose of establishing the identity of a natural person by comparing biometric data of that individual to biometric data of individuals stored in a database;\n(36)\n‘biometric verification’ means the automated, one-to-one verification, including authentication, of the identity of natural persons by comparing their biometric data to previously provided biometric data;\n(37)\n‘special categories of personal data’ means the categories of personal data referred to in Article 9(1) of Regulation (EU) 2016/679, Article 10 of Directive (EU) 2016/680 and Article 10(1) of Regulation (EU) 2018/1725;\n(38)\n‘sensitive operational data’ means operational data related to activities of prevention, detection, investigation or prosecution of criminal offences, the disclosure of which could jeopardise the integrity of criminal proceedings;\n(39)\n‘emotion recognition system’ means an AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data;\n(40)\n‘biometric categorisation system’ means an AI system for the purpose of assigning natural persons to specific categories on the basis of their biometric data, unless it is ancillary to another commercial service and strictly necessary for objective technical reasons;\n(41)\n‘remote biometric identification system’ means an AI system for the purpose of identifying natural persons, without their active involvement, typically at a distance through the comparison of a person’s biometric data with the biometric data contained in a reference database;\n(42)\n‘real-time remote biometric identification system’ means a remote biometric identification system, whereby the capturing of biometric data, the comparison and the identification all occur without a significant delay, comprising not only instant identification, but also limited short delays in order to avoid circumvention;\n(43)\n‘post-remote biometric identification system’ means a remote biometric identification system other than a real-time remote biometric identification system;\n(44)\n‘publicly accessible space’ means any publicly or privately owned physical place accessible to an undetermined number of natural persons, regardless of whether certain conditions for access may apply, and regardless of the potential capacity restrictions;\n(45)\n‘law enforcement authority’ means:\n(a)\nany public authority competent for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security; or\n(b)\nany other body or entity entrusted by Member State law to exercise public authority and public powers for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security;\n(46)\n‘law enforcement’ means activities carried out by law enforcement authorities or on their behalf for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security;\n(47)\n‘AI Office’ means the Commission’s function of contributing to the implementation, monitoring and supervision of AI systems and general-purpose AI models, and AI governance, provided for in Commission Decision of 24 January 2024; references in this Regulation to the AI Office shall be construed as references to the Commission;\n(48)\n‘national competent authority’ means a notifying authority or a market surveillance authority; as regards AI systems put into service or used by Union institutions, agencies, offices and bodies, references to national competent authorities or market surveillance authorities in this Regulation shall be construed as references to the European Data Protection Supervisor;\n(49)\n‘serious incident’ means an incident or malfunctioning of an AI system that directly or indirectly leads to any of the following:\n(a)\nthe death of a person, or serious harm to a person’s health;\n(b)\na serious and irreversible disruption of the management or operation of critical infrastructure;\n(c)\nthe infringement of obligations under Union law intended to protect fundamental rights;\n(d)\nserious harm to property or the environment;\n(50)\n‘personal data’ means personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679;\n(51)\n‘non-personal data’ means data other than personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679;\n(52)\n‘profiling’ means profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679;\n(53)\n‘real-world testing plan’ means a document that describes the objectives, methodology, geographical, population and temporal scope, monitoring, organisation and conduct of testing in real-world conditions;\n(54)\n‘sandbox plan’ means a document agreed between the participating provider and the competent authority describing the objectives, conditions, timeframe, methodology and requirements for the activities carried out within the sandbox;\n(55)\n‘AI regulatory sandbox’ means a controlled framework set up by a competent authority which offers providers or prospective providers of AI systems the possibility to develop, train, validate and test, where appropriate in real-world conditions, an innovative AI system, pursuant to a sandbox plan for a limited time under regulatory supervision;\n(56)\n‘AI literacy’ means skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause;\n(57)\n‘testing in real-world conditions’ means the temporary testing of an AI system for its intended purpose in real-world conditions outside a laboratory or otherwise simulated environment, with a view to gathering reliable and robust data and to assessing and verifying the conformity of the AI system with the requirements of this Regulation and it does not qualify as placing the AI system on the market or putting it into service within the meaning of this Regulation, provided that all the conditions laid down in Article 57 or 60 are fulfilled;\n(58)\n‘subject’, for the purpose of real-world testing, means a natural person who participates in testing in real-world conditions;\n(59)\n‘informed consent’ means a subject’s freely given, specific, unambiguous and voluntary expression of his or her willingness to participate in a particular testing in real-world conditions, after having been informed of all aspects of the testing that are relevant to the subject’s decision to participate;\n(60)\n‘deep fake’ means AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful;\n(61)\n‘widespread infringement’ means any act or omission contrary to Union law protecting the interest of individuals, which:\n(a)\nhas harmed or is likely to harm the collective interests of individuals residing in at least two Member States other than the Member State in which:\n(i)\nthe act or omission originated or took place;\n(ii)\nthe provider concerned, or, where applicable, its authorised representative is located or established; or\n(iii)\nthe deployer is established, when the infringement is committed by the deployer;\n(b)\nhas caused, causes or is likely to cause harm to the collective interests of individuals and has common features, including the same unlawful practice or the same interest being infringed, and is occurring concurrently, committed by the same operator, in at least three Member States;\n(62)\n‘critical infrastructure’ means critical infrastructure as defined in Article 2, point (4), of Directive (EU) 2022/2557;\n(63)\n‘general-purpose AI model’ means an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market;\n(64)\n‘high-impact capabilities’ means capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models;\n(65)\n‘systemic risk’ means a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain;\n(66)\n‘general-purpose AI system’ means an AI system which is based on a general-purpose AI model and which has the capability to serve a variety of purposes, both for direct use as well as for integration in other AI systems;\n(67)\n‘floating-point operation’ means any mathematical operation or assignment involving floating-point numbers, which are a subset of the real numbers typically represented on computers by an integer of fixed precision scaled by an integer exponent of a fixed base;\n(68)\n‘downstream provider’ means a provider of an AI system, including a general-purpose AI system, which integrates an AI model, regardless of whether the AI model is provided by themselves and vertically integrated or provided by another entity based on contractual relations.\nArticle 4 AI literacy Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.\nCHAPTER II PROHIBITED AI PRACTICES\nArticle 5 Prohibited AI practices The following AI practices shall be prohibited: (a)\nthe placing on the market, the putting into service or the use of an AI system that deploys subliminal techniques beyond a person’s consciousness or purposefully manipulative or deceptive techniques, with the objective, or the effect of materially distorting the behaviour of a person or a group of persons by appreciably impairing their ability to make an informed decision, thereby causing them to take a decision that they would not have otherwise taken in a manner that causes or is reasonably likely to cause that person, another person or group of persons significant harm;\n(b)\nthe placing on the market, the putting into service or the use of an AI system that exploits any of the vulnerabilities of a natural person or a specific group of persons due to their age, disability or a specific social or economic situation, with the objective, or the effect, of materially distorting the behaviour of that person or a person belonging to that group in a manner that causes or is reasonably likely to cause that person or another person significant harm;\n(c)\nthe placing on the market, the putting into service or the use of AI systems for the evaluation or classification of natural persons or groups of persons over a certain period of time based on their social behaviour or known, inferred or predicted personal or personality characteristics, with the social score leading to either or both of the following:\n(i)\ndetrimental or unfavourable treatment of certain natural persons or groups of persons in social contexts that are unrelated to the contexts in which the data was originally generated or collected;\n(ii)\ndetrimental or unfavourable treatment of certain natural persons or groups of persons that is unjustified or disproportionate to their social behaviour or its gravity;\n(d)\nthe placing on the market, the putting into service for this specific purpose, or the use of an AI system for making risk assessments of natural persons in order to assess or predict the risk of a natural person committing a criminal offence, based solely on the profiling of a natural person or on assessing their personality traits and characteristics; this prohibition shall not apply to AI systems used to support the human assessment of the involvement of a person in a criminal activity, which is already based on objective and verifiable facts directly linked to a criminal activity;\n(e)\nthe placing on the market, the putting into service for this specific purpose, or the use of AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage;\n(f)\nthe placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons;\n(g)\nthe placing on the market, the putting into service for this specific purpose, or the use of biometric categorisation systems that categorise individually natural persons based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation; this prohibition does not cover any labelling or filtering of lawfully acquired biometric datasets, such as images, based on biometric data or categorizing of biometric data in the area of law enforcement;\n(h)\nthe use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement, unless and in so far as such use is strictly necessary for one of the following objectives:\n(i)\nthe targeted search for specific victims of abduction, trafficking in human beings or sexual exploitation of human beings, as well as the search for missing persons;\n(ii)\nthe prevention of a specific, substantial and imminent threat to the life or physical safety of natural persons or a genuine and present or genuine and foreseeable threat of a terrorist attack;\n(iii)\nthe localisation or identification of a person suspected of having committed a criminal offence, for the purpose of conducting a criminal investigation or prosecution or executing a criminal penalty for offences referred to in Annex II and punishable in the Member State concerned by a custodial sentence or a detention order for a maximum period of at least four years.\nPoint (h) of the first subparagraph is without prejudice to Article 9 of Regulation (EU) 2016/679 for the processing of biometric data for purposes other than law enforcement.\nThe use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement for any of the objectives referred to in paragraph 1, first subparagraph, point (h), shall be deployed for the purposes set out in that point only to confirm the identity of the specifically targeted individual, and it shall take into account the following elements: (a)\nthe nature of the situation giving rise to the possible use, in particular the seriousness, probability and scale of the harm that would be caused if the system were not used;\n(b)\nthe consequences of the use of the system for the rights and freedoms of all persons concerned, in particular the seriousness, probability and scale of those consequences.\nIn addition, the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement for any of the objectives referred to in paragraph 1, first subparagraph, point (h), of this Article shall comply with necessary and proportionate safeguards and conditions in relation to the use in accordance with the national law authorising the use thereof, in particular as regards the temporal, geographic and personal limitations. The use of the ‘real-time’ remote biometric identification system in publicly accessible spaces shall be authorised only if the law enforcement authority has completed a fundamental rights impact assessment as provided for in Article 27 and has registered the system in the EU database according to Article 49. However, in duly justified cases of urgency, the use of such systems may be commenced without the registration in the EU database, provided that such registration is completed without undue delay.\nFor the purposes of paragraph 1, first subparagraph, point (h) and paragraph 2, each use for the purposes of law enforcement of a ‘real-time’ remote biometric identification system in publicly accessible spaces shall be subject to a prior authorisation granted by a judicial authority or an independent administrative authority whose decision is binding of the Member State in which the use is to take place, issued upon a reasoned request and in accordance with the detailed rules of national law referred to in paragraph 5. However, in a duly justified situation of urgency, the use of such system may be commenced without an authorisation provided that such authorisation is requested without undue delay, at the latest within 24 hours. If such authorisation is rejected, the use shall be stopped with immediate effect and all the data, as well as the results and outputs of that use shall be immediately discarded and deleted. The competent judicial authority or an independent administrative authority whose decision is binding shall grant the authorisation only where it is satisfied, on the basis of objective evidence or clear indications presented to it, that the use of the ‘real-time’ remote biometric identification system concerned is necessary for, and proportionate to, achieving one of the objectives specified in paragraph 1, first subparagraph, point (h), as identified in the request and, in particular, remains limited to what is strictly necessary concerning the period of time as well as the geographic and personal scope. In deciding on the request, that authority shall take into account the elements referred to in paragraph 2. No decision that produces an adverse legal effect on a person may be taken based solely on the output of the ‘real-time’ remote biometric identification system.\nWithout prejudice to paragraph 3, each use of a ‘real-time’ remote biometric identification system in publicly accessible spaces for law enforcement purposes shall be notified to the relevant market surveillance authority and the national data protection authority in accordance with the national rules referred to in paragraph 5. The notification shall, as a minimum, contain the information specified under paragraph 6 and shall not include sensitive operational data.\nA Member State may decide to provide for the possibility to fully or partially authorise the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement within the limits and under the conditions listed in paragraph 1, first subparagraph, point (h), and paragraphs 2 and 3. Member States concerned shall lay down in their national law the necessary detailed rules for the request, issuance and exercise of, as well as supervision and reporting relating to, the authorisations referred to in paragraph 3. Those rules shall also specify in respect of which of the objectives listed in paragraph 1, first subparagraph, point (h), including which of the criminal offences referred to in point (h)(iii) thereof, the competent authorities may be authorised to use those systems for the purposes of law enforcement. Member States shall notify those rules to the Commission at the latest 30 days following the adoption thereof. Member States may introduce, in accordance with Union law, more restrictive laws on the use of remote biometric identification systems.\nNational market surveillance authorities and the national data protection authorities of Member States that have been notified of the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for law enforcement purposes pursuant to paragraph 4 shall submit to the Commission annual reports on such use. For that purpose, the Commission shall provide Member States and national market surveillance and data protection authorities with a template, including information on the number of the decisions taken by competent judicial authorities or an independent administrative authority whose decision is binding upon requests for authorisations in accordance with paragraph 3 and their result.\nThe Commission shall publish annual reports on the use of real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes, based on aggregated data in Member States on the basis of the annual reports referred to in paragraph 6. Those annual reports shall not include sensitive operational data of the related law enforcement activities.\nThis Article shall not affect the prohibitions that apply where an AI practice infringes other Union law.\nCHAPTER III HIGH-RISK AI SYSTEMS\nSECTION 1\nClassification of AI systems as high-risk\nArticle 6 Classification rules for high-risk AI systems Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled: (a)\nthe AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I;\n(b)\nthe product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.\nIn addition to the high-risk AI systems referred to in paragraph 1, AI systems referred to in Annex III shall be considered to be high-risk.\nBy derogation from paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making.\nThe first subparagraph shall apply where any of the following conditions is fulfilled:\n(a)\nthe AI system is intended to perform a narrow procedural task;\n(b)\nthe AI system is intended to improve the result of a previously completed human activity;\n(c)\nthe AI system is intended to detect decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the previously completed human assessment, without proper human review; or\n(d)\nthe AI system is intended to perform a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III.\nNotwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons.\nA provider who considers that an AI system referred to in Annex III is not high-risk shall document its assessment before that system is placed on the market or put into service. Such provider shall be subject to the registration obligation set out in Article 49(2). Upon request of national competent authorities, the provider shall provide the documentation of the assessment.\nThe Commission shall, after consulting the European Artificial Intelligence Board (the ‘Board’), and no later than 2 February 2026, provide guidelines specifying the practical implementation of this Article in line with Article 96 together with a comprehensive list of practical examples of use cases of AI systems that are high-risk and not high-risk.\nThe Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend paragraph 3, second subparagraph, of this Article by adding new conditions to those laid down therein, or by modifying them, where there is concrete and reliable evidence of the existence of AI systems that fall under the scope of Annex III, but do not pose a significant risk of harm to the health, safety or fundamental rights of natural persons.\nThe Commission shall adopt delegated acts in accordance with Article 97 in order to amend paragraph 3, second subparagraph, of this Article by deleting any of the conditions laid down therein, where there is concrete and reliable evidence that this is necessary to maintain the level of protection of health, safety and fundamental rights provided for by this Regulation.\nAny amendment to the conditions laid down in paragraph 3, second subparagraph, adopted in accordance with paragraphs 6 and 7 of this Article shall not decrease the overall level of protection of health, safety and fundamental rights provided for by this Regulation and shall ensure consistency with the delegated acts adopted pursuant to Article 7(1), and take account of market and technological developments.\nArticle 7 Amendments to Annex III The Commission is empowered to adopt delegated acts in accordance with Article 97 to amend Annex III by adding or modifying use-cases of high-risk AI systems where both of the following conditions are fulfilled: (a)\nthe AI systems are intended to be used in any of the areas listed in Annex III;\n(b)\nthe AI systems pose a risk of harm to health and safety, or an adverse impact on fundamental rights, and that risk is equivalent to, or greater than, the risk of harm or of adverse impact posed by the high-risk AI systems already referred to in Annex III.\nWhen assessing the condition under paragraph 1, point (b), the Commission shall take into account the following criteria: (a)\nthe intended purpose of the AI system;\n(b)\nthe extent to which an AI system has been used or is likely to be used;\n(c)\nthe nature and amount of the data processed and used by the AI system, in particular whether special categories of personal data are processed;\n(d)\nthe extent to which the AI system acts autonomously and the possibility for a human to override a decision or recommendations that may lead to potential harm;\n(e)\nthe extent to which the use of an AI system has already caused harm to health and safety, has had an adverse impact on fundamental rights or has given rise to significant concerns in relation to the likelihood of such harm or adverse impact, as demonstrated, for example, by reports or documented allegations submitted to national competent authorities or by other reports, as appropriate;\n(f)\nthe potential extent of such harm or such adverse impact, in particular in terms of its intensity and its ability to affect multiple persons or to disproportionately affect a particular group of persons;\n(g)\nthe extent to which persons who are potentially harmed or suffer an adverse impact are dependent on the outcome produced with an AI system, in particular because for practical or legal reasons it is not reasonably possible to opt-out from that outcome;\n(h)\nthe extent to which there is an imbalance of power, or the persons who are potentially harmed or suffer an adverse impact are in a vulnerable position in relation to the deployer of an AI system, in particular due to status, authority, knowledge, economic or social circumstances, or age;\n(i)\nthe extent to which the outcome produced involving an AI system is easily corrigible or reversible, taking into account the technical solutions available to correct or reverse it, whereby outcomes having an adverse impact on health, safety or fundamental rights, shall not be considered to be easily corrigible or reversible;\n(j)\nthe magnitude and likelihood of benefit of the deployment of the AI system for individuals, groups, or society at large, including possible improvements in product safety;\n(k)\nthe extent to which existing Union law provides for:\n(i)\neffective measures of redress in relation to the risks posed by an AI system, with the exclusion of claims for damages;\n(ii)\neffective measures to prevent or substantially minimise those risks.\nThe Commission is empowered to adopt delegated acts in accordance with Article 97 to amend the list in Annex III by removing high-risk AI systems where both of the following conditions are fulfilled: (a)\nthe high-risk AI system concerned no longer poses any significant risks to fundamental rights, health or safety, taking into account the criteria listed in paragraph 2;\n(b)\nthe deletion does not decrease the overall level of protection of health, safety and fundamental rights under Union law.\nSECTION 2\nRequirements for high-risk AI systems\nArticle 8 Compliance with the requirements High-risk AI systems shall comply with the requirements laid down in this Section, taking into account their intended purpose as well as the generally acknowledged state of the art on AI and AI-related technologies. The risk management system referred to in Article 9 shall be taken into account when ensuring compliance with those requirements.\nWhere a product contains an AI system, to which the requirements of this Regulation as well as requirements of the Union harmonisation legislation listed in Section A of Annex I apply, providers shall be responsible for ensuring that their product is fully compliant with all applicable requirements under applicable Union harmonisation legislation. In ensuring the compliance of high-risk AI systems referred to in paragraph 1 with the requirements set out in this Section, and in order to ensure consistency, avoid duplication and minimise additional burdens, providers shall have a choice of integrating, as appropriate, the necessary testing and reporting processes, information and documentation they provide with regard to their product into documentation and procedures that already exist and are required under the Union harmonisation legislation listed in Section A of Annex I.\nArticle 9 Risk management system A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems.\nThe risk management system shall be understood as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, requiring regular systematic review and updating. It shall comprise the following steps:\n(a)\nthe identification and analysis of the known and the reasonably foreseeable risks that the high-risk AI system can pose to health, safety or fundamental rights when the high-risk AI system is used in accordance with its intended purpose;\n(b)\nthe estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse;\n(c)\nthe evaluation of other risks possibly arising, based on the analysis of data gathered from the post-market monitoring system referred to in Article 72;\n(d)\nthe adoption of appropriate and targeted risk management measures designed to address the risks identified pursuant to point (a).\nThe risks referred to in this Article shall concern only those which may be reasonably mitigated or eliminated through the development or design of the high-risk AI system, or the provision of adequate technical information.\nThe risk management measures referred to in paragraph 2, point (d), shall give due consideration to the effects and possible interaction resulting from the combined application of the requirements set out in this Section, with a view to minimising risks more effectively while achieving an appropriate balance in implementing the measures to fulfil those requirements.\nThe risk management measures referred to in paragraph 2, point (d), shall be such that the relevant residual risk associated with each hazard, as well as the overall residual risk of the high-risk AI systems is judged to be acceptable.\nIn identifying the most appropriate risk management measures, the following shall be ensured:\n(a)\nelimination or reduction of risks identified and evaluated pursuant to paragraph 2 in as far as technically feasible through adequate design and development of the high-risk AI system;\n(b)\nwhere appropriate, implementation of adequate mitigation and control measures addressing risks that cannot be eliminated;\n(c)\nprovision of information required pursuant to Article 13 and, where appropriate, training to deployers.\nWith a view to eliminating or reducing risks related to the use of the high-risk AI system, due consideration shall be given to the technical knowledge, experience, education, the training to be expected by the deployer, and the presumable context in which the system is intended to be used.\nHigh-risk AI systems shall be tested for the purpose of identifying the most appropriate and targeted risk management measures. Testing shall ensure that high-risk AI systems perform consistently for their intended purpose and that they are in compliance with the requirements set out in this Section.\nTesting procedures may include testing in real-world conditions in accordance with Article 60.\nThe testing of high-risk AI systems shall be performed, as appropriate, at any time throughout the development process, and, in any event, prior to their being placed on the market or put into service. Testing shall be carried out against prior defined metrics and probabilistic thresholds that are appropriate to the intended purpose of the high-risk AI system.\nWhen implementing the risk management system as provided for in paragraphs 1 to 7, providers shall give consideration to whether in view of its intended purpose the high-risk AI system is likely to have an adverse impact on persons under the age of 18 and, as appropriate, other vulnerable groups.\nFor providers of high-risk AI systems that are subject to requirements regarding internal risk management processes under other relevant provisions of Union law, the aspects provided in paragraphs 1 to 9 may be part of, or combined with, the risk management procedures established pursuant to that law.\nArticle 10 Data and data governance High-risk AI systems which make use of techniques involving the training of AI models with data shall be developed on the basis of training, validation and testing data sets that meet the quality criteria referred to in paragraphs 2 to 5 whenever such data sets are used.\nTraining, validation and testing data sets shall be subject to data governance and management practices appropriate for the intended purpose of the high-risk AI system. Those practices shall concern in particular:\n(a)\nthe relevant design choices;\n(b)\ndata collection processes and the origin of data, and in the case of personal data, the original purpose of the data collection;\n(c)\nrelevant data-preparation processing operations, such as annotation, labelling, cleaning, updating, enrichment and aggregation;\n(d)\nthe formulation of assumptions, in particular with respect to the information that the data are supposed to measure and represent;\n(e)\nan assessment of the availability, quantity and suitability of the data sets that are needed;\n(f)\nexamination in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations;\n(g)\nappropriate measures to detect, prevent and mitigate possible biases identified according to point (f);\n(h)\nthe identification of relevant data gaps or shortcomings that prevent compliance with this Regulation, and how those gaps and shortcomings can be addressed.\nTraining, validation and testing data sets shall be relevant, sufficiently representative, and to the best extent possible, free of errors and complete in view of the intended purpose. They shall have the appropriate statistical properties, including, where applicable, as regards the persons or groups of persons in relation to whom the high-risk AI system is intended to be used. Those characteristics of the data sets may be met at the level of individual data sets or at the level of a combination thereof.\nData sets shall take into account, to the extent required by the intended purpose, the characteristics or elements that are particular to the specific geographical, contextual, behavioural or functional setting within which the high-risk AI system is intended to be used.\nTo the extent that it is strictly necessary for the purpose of ensuring bias detection and correction in relation to the high-risk AI systems in accordance with paragraph (2), points (f) and (g) of this Article, the providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the provisions set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, all the following conditions must be met in order for such processing to occur:\n(a)\nthe bias detection and correction cannot be effectively fulfilled by processing other data, including synthetic or anonymised data;\n(b)\nthe special categories of personal data are subject to technical limitations on the re-use of the personal data, and state-of-the-art security and privacy-preserving measures, including pseudonymisation;\n(c)\nthe special categories of personal data are subject to measures to ensure that the personal data processed are secured, protected, subject to suitable safeguards, including strict controls and documentation of the access, to avoid misuse and ensure that only authorised persons have access to those personal data with appropriate confidentiality obligations;\n(d)\nthe special categories of personal data are not to be transmitted, transferred or otherwise accessed by other parties;\n(e)\nthe special categories of personal data are deleted once the bias has been corrected or the personal data has reached the end of its retention period, whichever comes first;\n(f)\nthe records of processing activities pursuant to Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680 include the reasons why the processing of special categories of personal data was strictly necessary to detect and correct biases, and why that objective could not be achieved by processing other data.\nFor the development of high-risk AI systems not using techniques involving the training of AI models, paragraphs 2 to 5 apply only to the testing data sets. Article 11 Technical documentation The technical documentation of a high-risk AI system shall be drawn up before that system is placed on the market or put into service and shall be kept up-to date. The technical documentation shall be drawn up in such a way as to demonstrate that the high-risk AI system complies with the requirements set out in this Section and to provide national competent authorities and notified bodies with the necessary information in a clear and comprehensive form to assess the compliance of the AI system with those requirements. It shall contain, at a minimum, the elements set out in Annex IV. SMEs, including start-ups, may provide the elements of the technical documentation specified in Annex IV in a simplified manner. To that end, the Commission shall establish a simplified technical documentation form targeted at the needs of small and microenterprises. Where an SME, including a start-up, opts to provide the information required in Annex IV in a simplified manner, it shall use the form referred to in this paragraph. Notified bodies shall accept the form for the purposes of the conformity assessment.\nWhere a high-risk AI system related to a product covered by the Union harmonisation legislation listed in Section A of Annex I is placed on the market or put into service, a single set of technical documentation shall be drawn up containing all the information set out in paragraph 1, as well as the information required under those legal acts.\nThe Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend Annex IV, where necessary, to ensure that, in light of technical progress, the technical documentation provides all the information necessary to assess the compliance of the system with the requirements set out in this Section.\nArticle 12 Record-keeping High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system.\nIn order to ensure a level of traceability of the functioning of a high-risk AI system that is appropriate to the intended purpose of the system, logging capabilities shall enable the recording of events relevant for:\n(a)\nidentifying situations that may result in the high-risk AI system presenting a risk within the meaning of Article 79(1) or in a substantial modification;\n(b)\nfacilitating the post-market monitoring referred to in Article 72; and\n(c)\nmonitoring the operation of high-risk AI systems referred to in Article 26(5).\nFor high-risk AI systems referred to in point 1 (a), of Annex III, the logging capabilities shall provide, at a minimum: (a)\nrecording of the period of each use of the system (start date and time and end date and time of each use);\n(b)\nthe reference database against which input data has been checked by the system;\n(c)\nthe input data for which the search has led to a match;\n(d)\nthe identification of the natural persons involved in the verification of the results, as referred to in Article 14(5).\nArticle 13 Transparency and provision of information to deployers High-risk AI systems shall be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret a system’s output and use it appropriately. An appropriate type and degree of transparency shall be ensured with a view to achieving compliance with the relevant obligations of the provider and deployer set out in Section 3.\nHigh-risk AI systems shall be accompanied by instructions for use in an appropriate digital format or otherwise that include concise, complete, correct and clear information that is relevant, accessible and comprehensible to deployers.\nThe instructions for use shall contain at least the following information:\n(a)\nthe identity and the contact details of the provider and, where applicable, of its authorised representative;\n(b)\nthe characteristics, capabilities and limitations of performance of the high-risk AI system, including:\n(i)\nits intended purpose;\n(ii)\nthe level of accuracy, including its metrics, robustness and cybersecurity referred to in Article 15 against which the high-risk AI system has been tested and validated and which can be expected, and any known and foreseeable circumstances that may have an impact on that expected level of accuracy, robustness and cybersecurity;\n(iii)\nany known or foreseeable circumstance, related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety or fundamental rights referred to in Article 9(2);\n(iv)\nwhere applicable, the technical capabilities and characteristics of the high-risk AI system to provide information that is relevant to explain its output;\n(v)\nwhen appropriate, its performance regarding specific persons or groups of persons on which the system is intended to be used;\n(vi)\nwhen appropriate, specifications for the input data, or any other relevant information in terms of the training, validation and testing data sets used, taking into account the intended purpose of the high-risk AI system;\n(vii)\nwhere applicable, information to enable deployers to interpret the output of the high-risk AI system and use it appropriately;\n(c)\nthe changes to the high-risk AI system and its performance which have been pre-determined by the provider at the moment of the initial conformity assessment, if any;\n(d)\nthe human oversight measures referred to in Article 14, including the technical measures put in place to facilitate the interpretation of the outputs of the high-risk AI systems by the deployers;\n(e)\nthe computational and hardware resources needed, the expected lifetime of the high-risk AI system and any necessary maintenance and care measures, including their frequency, to ensure the proper functioning of that AI system, including as regards software updates;\n(f)\nwhere relevant, a description of the mechanisms included within the high-risk AI system that allows deployers to properly collect, store and interpret the logs in accordance with Article 12.\nArticle 14 Human oversight High-risk AI systems shall be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which they are in use.\nHuman oversight shall aim to prevent or minimise the risks to health, safety or fundamental rights that may emerge when a high-risk AI system is used in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, in particular where such risks persist despite the application of other requirements set out in this Section.\nThe oversight measures shall be commensurate with the risks, level of autonomy and context of use of the high-risk AI system, and shall be ensured through either one or both of the following types of measures:\n(a)\nmeasures identified and built, when technically feasible, into the high-risk AI system by the provider before it is placed on the market or put into service;\n(b)\nmeasures identified by the provider before placing the high-risk AI system on the market or putting it into service and that are appropriate to be implemented by the deployer.\nFor the purpose of implementing paragraphs 1, 2 and 3, the high-risk AI system shall be provided to the deployer in such a way that natural persons to whom human oversight is assigned are enabled, as appropriate and proportionate: (a)\nto properly understand the relevant capacities and limitations of the high-risk AI system and be able to duly monitor its operation, including in view of detecting and addressing anomalies, dysfunctions and unexpected performance;\n(b)\nto remain aware of the possible tendency of automatically relying or over-relying on the output produced by a high-risk AI system (automation bias), in particular for high-risk AI systems used to provide information or recommendations for decisions to be taken by natural persons;\n(c)\nto correctly interpret the high-risk AI system’s output, taking into account, for example, the interpretation tools and methods available;\n(d)\nto decide, in any particular situation, not to use the high-risk AI system or to otherwise disregard, override or reverse the output of the high-risk AI system;\n(e)\nto intervene in the operation of the high-risk AI system or interrupt the system through a ‘stop’ button or a similar procedure that allows the system to come to a halt in a safe state.\nFor high-risk AI systems referred to in point 1(a) of Annex III, the measures referred to in paragraph 3 of this Article shall be such as to ensure that, in addition, no action or decision is taken by the deployer on the basis of the identification resulting from the system unless that identification has been separately verified and confirmed by at least two natural persons with the necessary competence, training and authority. The requirement for a separate verification by at least two natural persons shall not apply to high-risk AI systems used for the purposes of law enforcement, migration, border control or asylum, where Union or national law considers the application of this requirement to be disproportionate.\nArticle 15 Accuracy, robustness and cybersecurity High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and that they perform consistently in those respects throughout their lifecycle.\nTo address the technical aspects of how to measure the appropriate levels of accuracy and robustness set out in paragraph 1 and any other relevant performance metrics, the Commission shall, in cooperation with relevant stakeholders and organisations such as metrology and benchmarking authorities, encourage, as appropriate, the development of benchmarks and measurement methodologies.\nThe levels of accuracy and the relevant accuracy metrics of high-risk AI systems shall be declared in the accompanying instructions of use.\nHigh-risk AI systems shall be as resilient as possible regarding errors, faults or inconsistencies that may occur within the system or the environment in which the system operates, in particular due to their interaction with natural persons or other systems. Technical and organisational measures shall be taken in this regard.\nThe robustness of high-risk AI systems may be achieved through technical redundancy solutions, which may include backup or fail-safe plans.\nHigh-risk AI systems that continue to learn after being placed on the market or put into service shall be developed in such a way as to eliminate or reduce as far as possible the risk of possibly biased outputs influencing input for future operations (feedback loops), and as to ensure that any such feedback loops are duly addressed with appropriate mitigation measures.\nHigh-risk AI systems shall be resilient against attempts by unauthorised third parties to alter their use, outputs or performance by exploiting system vulnerabilities. The technical solutions aiming to ensure the cybersecurity of high-risk AI systems shall be appropriate to the relevant circumstances and the risks.\nThe technical solutions to address AI specific vulnerabilities shall include, where appropriate, measures to prevent, detect, respond to, resolve and control for attacks trying to manipulate the training data set (data poisoning), or pre-trained components used in training (model poisoning), inputs designed to cause the AI model to make a mistake (adversarial examples or model evasion), confidentiality attacks or model flaws.\nSECTION 3\nObligations of providers and deployers of high-risk AI systems and other parties\nArticle 16 Obligations of providers of high-risk AI systems Providers of high-risk AI systems shall:\n(a)\nensure that their high-risk AI systems are compliant with the requirements set out in Section 2;\n(b)\nindicate on the high-risk AI system or, where that is not possible, on its packaging or its accompanying documentation, as applicable, their name, registered trade name or registered trade mark, the address at which they can be contacted;\n(c)\nhave a quality management system in place which complies with Article 17;\n(d)\nkeep the documentation referred to in Article 18;\n(e)\nwhen under their control, keep the logs automatically generated by their high-risk AI systems as referred to in Article 19;\n(f)\nensure that the high-risk AI system undergoes the relevant conformity assessment procedure as referred to in Article 43, prior to its being placed on the market or put into service;\n(g)\ndraw up an EU declaration of conformity in accordance with Article 47;\n(h)\naffix the CE marking to the high-risk AI system or, where that is not possible, on its packaging or its accompanying documentation, to indicate conformity with this Regulation, in accordance with Article 48;\n(i)\ncomply with the registration obligations referred to in Article 49(1);\n(j)\ntake the necessary corrective actions and provide information as required in Article 20;\n(k)\nupon a reasoned request of a national competent authority, demonstrate the conformity of the high-risk AI system with the requirements set out in Section 2;\n(l)\nensure that the high-risk AI system complies with accessibility requirements in accordance with Directives (EU) 2016/2102 and (EU) 2019/882.\nArticle 17 Quality management system Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation. That system shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions, and shall include at least the following aspects: (a)\na strategy for regulatory compliance, including compliance with conformity assessment procedures and procedures for the management of modifications to the high-risk AI system;\n(b)\ntechniques, procedures and systematic actions to be used for the design, design control and design verification of the high-risk AI system;\n(c)\ntechniques, procedures and systematic actions to be used for the development, quality control and quality assurance of the high-risk AI system;\n(d)\nexamination, test and validation procedures to be carried out before, during and after the development of the high-risk AI system, and the frequency with which they have to be carried out;\n(e)\ntechnical specifications, including standards, to be applied and, where the relevant harmonised standards are not applied in full or do not cover all of the relevant requirements set out in Section 2, the means to be used to ensure that the high-risk AI system complies with those requirements;\n(f)\nsystems and procedures for data management, including data acquisition, data collection, data analysis, data labelling, data storage, data filtration, data mining, data aggregation, data retention and any other operation regarding the data that is performed before and for the purpose of the placing on the market or the putting into service of high-risk AI systems;\n(g)\nthe risk management system referred to in Article 9;\n(h)\nthe setting-up, implementation and maintenance of a post-market monitoring system, in accordance with Article 72;\n(i)\nprocedures related to the reporting of a serious incident in accordance with Article 73;\n(j)\nthe handling of communication with national competent authorities, other relevant authorities, including those providing or supporting the access to data, notified bodies, other operators, customers or other interested parties;\n(k)\nsystems and procedures for record-keeping of all relevant documentation and information;\n(l)\nresource management, including security-of-supply related measures;\n(m)\nan accountability framework setting out the responsibilities of the management and other staff with regard to all the aspects listed in this paragraph.\nThe implementation of the aspects referred to in paragraph 1 shall be proportionate to the size of the provider’s organisation. Providers shall, in any event, respect the degree of rigour and the level of protection required to ensure the compliance of their high-risk AI systems with this Regulation.\nProviders of high-risk AI systems that are subject to obligations regarding quality management systems or an equivalent function under relevant sectoral Union law may include the aspects listed in paragraph 1 as part of the quality management systems pursuant to that law.\nFor providers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law, the obligation to put in place a quality management system, with the exception of paragraph 1, points (g), (h) and (i) of this Article, shall be deemed to be fulfilled by complying with the rules on internal governance arrangements or processes pursuant to the relevant Union financial services law. To that end, any harmonised standards referred to in Article 40 shall be taken into account.\nArticle 18 Documentation keeping The provider shall, for a period ending 10 years after the high-risk AI system has been placed on the market or put into service, keep at the disposal of the national competent authorities: (a)\nthe technical documentation referred to in Article 11;\n(b)\nthe documentation concerning the quality management system referred to in Article 17;\n(c)\nthe documentation concerning the changes approved by notified bodies, where applicable;\n(d)\nthe decisions and other documents issued by the notified bodies, where applicable;\n(e)\nthe EU declaration of conformity referred to in Article 47.\nEach Member State shall determine conditions under which the documentation referred to in paragraph 1 remains at the disposal of the national competent authorities for the period indicated in that paragraph for the cases when a provider or its authorised representative established on its territory goes bankrupt or ceases its activity prior to the end of that period.\nProviders that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law shall maintain the technical documentation as part of the documentation kept under the relevant Union financial services law.\nArticle 19 Automatically generated logs Providers of high-risk AI systems shall keep the logs referred to in Article 12(1), automatically generated by their high-risk AI systems, to the extent such logs are under their control. Without prejudice to applicable Union or national law, the logs shall be kept for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in the applicable Union or national law, in particular in Union law on the protection of personal data.\nProviders that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law shall maintain the logs automatically generated by their high-risk AI systems as part of the documentation kept under the relevant financial services law.\nArticle 20 Corrective actions and duty of information Providers of high-risk AI systems which consider or have reason to consider that a high-risk AI system that they have placed on the market or put into service is not in conformity with this Regulation shall immediately take the necessary corrective actions to bring that system into conformity, to withdraw it, to disable it, or to recall it, as appropriate. They shall inform the distributors of the high-risk AI system concerned and, where applicable, the deployers, the authorised representative and importers accordingly.\nWhere the high-risk AI system presents a risk within the meaning of Article 79(1) and the provider becomes aware of that risk, it shall immediately investigate the causes, in collaboration with the reporting deployer, where applicable, and inform the market surveillance authorities competent for the high-risk AI system concerned and, where applicable, the notified body that issued a certificate for that high-risk AI system in accordance with Article 44, in particular, of the nature of the non-compliance and of any relevant corrective action taken.\nArticle 21 Cooperation with competent authorities Providers of high-risk AI systems shall, upon a reasoned request by a competent authority, provide that authority all the information and documentation necessary to demonstrate the conformity of the high-risk AI system with the requirements set out in Section 2, in a language which can be easily understood by the authority in one of the official languages of the institutions of the Union as indicated by the Member State concerned.\nUpon a reasoned request by a competent authority, providers shall also give the requesting competent authority, as applicable, access to the automatically generated logs of the high-risk AI system referred to in Article 12(1), to the extent such logs are under their control.\nAny information obtained by a competent authority pursuant to this Article shall be treated in accordance with the confidentiality obligations set out in Article 78.\nArticle 22 Authorised representatives of providers of high-risk AI systems Prior to making their high-risk AI systems available on the Union market, providers established in third countries shall, by written mandate, appoint an authorised representative which is established in the Union.\nThe provider shall enable its authorised representative to perform the tasks specified in the mandate received from the provider.\nThe authorised representative shall perform the tasks specified in the mandate received from the provider. It shall provide a copy of the mandate to the market surveillance authorities upon request, in one of the official languages of the institutions of the Union, as indicated by the competent authority. For the purposes of this Regulation, the mandate shall empower the authorised representative to carry out the following tasks:\n(a)\nverify that the EU declaration of conformity referred to in Article 47 and the technical documentation referred to in Article 11 have been drawn up and that an appropriate conformity assessment procedure has been carried out by the provider;\n(b)\nkeep at the disposal of the competent authorities and national authorities or bodies referred to in Article 74(10), for a period of 10 years after the high-risk AI system has been placed on the market or put into service, the contact details of the provider that appointed the authorised representative, a copy of the EU declaration of conformity referred to in Article 47, the technical documentation and, if applicable, the certificate issued by the notified body;\n(c)\nprovide a competent authority, upon a reasoned request, with all the information and documentation, including that referred to in point (b) of this subparagraph, necessary to demonstrate the conformity of a high-risk AI system with the requirements set out in Section 2, including access to the logs, as referred to in Article 12(1), automatically generated by the high-risk AI system, to the extent such logs are under the control of the provider;\n(d)\ncooperate with competent authorities, upon a reasoned request, in any action the latter take in relation to the high-risk AI system, in particular to reduce and mitigate the risks posed by the high-risk AI system;\n(e)\nwhere applicable, comply with the registration obligations referred to in Article 49(1), or, if the registration is carried out by the provider itself, ensure that the information referred to in point 3 of Section A of Annex VIII is correct.\nThe mandate shall empower the authorised representative to be addressed, in addition to or instead of the provider, by the competent authorities, on all issues related to ensuring compliance with this Regulation.\nThe authorised representative shall terminate the mandate if it considers or has reason to consider the provider to be acting contrary to its obligations pursuant to this Regulation. In such a case, it shall immediately inform the relevant market surveillance authority, as well as, where applicable, the relevant notified body, about the termination of the mandate and the reasons therefor. Article 23 Obligations of importers Before placing a high-risk AI system on the market, importers shall ensure that the system is in conformity with this Regulation by verifying that: (a)\nthe relevant conformity assessment procedure referred to in Article 43 has been carried out by the provider of the high-risk AI system;\n(b)\nthe provider has drawn up the technical documentation in accordance with Article 11 and Annex IV;\n(c)\nthe system bears the required CE marking and is accompanied by the EU declaration of conformity referred to in Article 47 and instructions for use;\n(d)\nthe provider has appointed an authorised representative in accordance with Article 22(1).\nWhere an importer has sufficient reason to consider that a high-risk AI system is not in conformity with this Regulation, or is falsified, or accompanied by falsified documentation, it shall not place the system on the market until it has been brought into conformity. Where the high-risk AI system presents a risk within the meaning of Article 79(1), the importer shall inform the provider of the system, the authorised representative and the market surveillance authorities to that effect.\nImporters shall indicate their name, registered trade name or registered trade mark, and the address at which they can be contacted on the high-risk AI system and on its packaging or its accompanying documentation, where applicable.\nImporters shall ensure that, while a high-risk AI system is under their responsibility, storage or transport conditions, where applicable, do not jeopardise its compliance with the requirements set out in Section 2.\nImporters shall keep, for a period of 10 years after the high-risk AI system has been placed on the market or put into service, a copy of the certificate issued by the notified body, where applicable, of the instructions for use, and of the EU declaration of conformity referred to in Article 47.\nImporters shall provide the relevant competent authorities, upon a reasoned request, with all the necessary information and documentation, including that referred to in paragraph 5, to demonstrate the conformity of a high-risk AI system with the requirements set out in Section 2 in a language which can be easily understood by them. For this purpose, they shall also ensure that the technical documentation can be made available to those authorities.\nImporters shall cooperate with the relevant competent authorities in any action those authorities take in relation to a high-risk AI system placed on the market by the importers, in particular to reduce and mitigate the risks posed by it.\nArticle 24 Obligations of distributors Before making a high-risk AI system available on the market, distributors shall verify that it bears the required CE marking, that it is accompanied by a copy of the EU declaration of conformity referred to in Article 47 and instructions for use, and that the provider and the importer of that system, as applicable, have complied with their respective obligations as laid down in Article 16, points (b) and (c) and Article 23(3).\nWhere a distributor considers or has reason to consider, on the basis of the information in its possession, that a high-risk AI system is not in conformity with the requirements set out in Section 2, it shall not make the high-risk AI system available on the market until the system has been brought into conformity with those requirements. Furthermore, where the high-risk AI system presents a risk within the meaning of Article 79(1), the distributor shall inform the provider or the importer of the system, as applicable, to that effect.\nDistributors shall ensure that, while a high-risk AI system is under their responsibility, storage or transport conditions, where applicable, do not jeopardise the compliance of the system with the requirements set out in Section 2.\nA distributor that considers or has reason to consider, on the basis of the information in its possession, a high-risk AI system which it has made available on the market not to be in conformity with the requirements set out in Section 2, shall take the corrective actions necessary to bring that system into conformity with those requirements, to withdraw it or recall it, or shall ensure that the provider, the importer or any relevant operator, as appropriate, takes those corrective actions. Where the high-risk AI system presents a risk within the meaning of Article 79(1), the distributor shall immediately inform the provider or importer of the system and the authorities competent for the high-risk AI system concerned, giving details, in particular, of the non-compliance and of any corrective actions taken.\nUpon a reasoned request from a relevant competent authority, distributors of a high-risk AI system shall provide that authority with all the information and documentation regarding their actions pursuant to paragraphs 1 to 4 necessary to demonstrate the conformity of that system with the requirements set out in Section 2.\nDistributors shall cooperate with the relevant competent authorities in any action those authorities take in relation to a high-risk AI system made available on the market by the distributors, in particular to reduce or mitigate the risk posed by it.\nArticle 25 Responsibilities along the AI value chain Any distributor, importer, deployer or other third-party shall be considered to be a provider of a high-risk AI system for the purposes of this Regulation and shall be subject to the obligations of the provider under Article 16, in any of the following circumstances: (a)\nthey put their name or trademark on a high-risk AI system already placed on the market or put into service, without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated;\n(b)\nthey make a substantial modification to a high-risk AI system that has already been placed on the market or has already been put into service in such a way that it remains a high-risk AI system pursuant to Article 6;\n(c)\nthey modify the intended purpose of an AI system, including a general-purpose AI system, which has not been classified as high-risk and has already been placed on the market or put into service in such a way that the AI system concerned becomes a high-risk AI system in accordance with Article 6.\nWhere the circumstances referred to in paragraph 1 occur, the provider that initially placed the AI system on the market or put it into service shall no longer be considered to be a provider of that specific AI system for the purposes of this Regulation. That initial provider shall closely cooperate with new providers and shall make available the necessary information and provide the reasonably expected technical access and other assistance that are required for the fulfilment of the obligations set out in this Regulation, in particular regarding the compliance with the conformity assessment of high-risk AI systems. This paragraph shall not apply in cases where the initial provider has clearly specified that its AI system is not to be changed into a high-risk AI system and therefore does not fall under the obligation to hand over the documentation.\nIn the case of high-risk AI systems that are safety components of products covered by the Union harmonisation legislation listed in Section A of Annex I, the product manufacturer shall be considered to be the provider of the high-risk AI system, and shall be subject to the obligations under Article 16 under either of the following circumstances:\n(a)\nthe high-risk AI system is placed on the market together with the product under the name or trademark of the product manufacturer;\n(b)\nthe high-risk AI system is put into service under the name or trademark of the product manufacturer after the product has been placed on the market.\nThe provider of a high-risk AI system and the third party that supplies an AI system, tools, services, components, or processes that are used or integrated in a high-risk AI system shall, by written agreement, specify the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, in order to enable the provider of the high-risk AI system to fully comply with the obligations set out in this Regulation. This paragraph shall not apply to third parties making accessible to the public tools, services, processes, or components, other than general-purpose AI models, under a free and open-source licence. The AI Office may develop and recommend voluntary model terms for contracts between providers of high-risk AI systems and third parties that supply tools, services, components or processes that are used for or integrated into high-risk AI systems. When developing those voluntary model terms, the AI Office shall take into account possible contractual requirements applicable in specific sectors or business cases. The voluntary model terms shall be published and be available free of charge in an easily usable electronic format.\nParagraphs 2 and 3 are without prejudice to the need to observe and protect intellectual property rights, confidential business information and trade secrets in accordance with Union and national law. Article 26 Obligations of deployers of high-risk AI systems Deployers of high-risk AI systems shall take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systems, pursuant to paragraphs 3 and 6.\nDeployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.\nThe obligations set out in paragraphs 1 and 2, are without prejudice to other deployer obligations under Union or national law and to the deployer’s freedom to organise its own resources and activities for the purpose of implementing the human oversight measures indicated by the provider.\nWithout prejudice to paragraphs 1 and 2, to the extent the deployer exercises control over the input data, that deployer shall ensure that input data is relevant and sufficiently representative in view of the intended purpose of the high-risk AI system.\nDeployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. Where deployers have reason to consider that the use of the high-risk AI system in accordance with the instructions may result in that AI system presenting a risk within the meaning of Article 79(1), they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system. Where deployers have identified a serious incident, they shall also immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities of that incident. If the deployer is not able to reach the provider, Article 73 shall apply mutatis mutandis. This obligation shall not cover sensitive operational data of deployers of AI systems which are law enforcement authorities.\nFor deployers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law, the monitoring obligation set out in the first subparagraph shall be deemed to be fulfilled by complying with the rules on internal governance arrangements, processes and mechanisms pursuant to the relevant financial service law.\nDeployers of high-risk AI systems shall keep the logs automatically generated by that high-risk AI system to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in applicable Union or national law, in particular in Union law on the protection of personal data. Deployers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law shall maintain the logs as part of the documentation kept pursuant to the relevant Union financial service law.\nBefore putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers’ representatives and the affected workers that they will be subject to the use of the high-risk AI system. This information shall be provided, where applicable, in accordance with the rules and procedures laid down in Union and national law and practice on information of workers and their representatives.\nDeployers of high-risk AI systems that are public authorities, or Union institutions, bodies, offices or agencies shall comply with the registration obligations referred to in Article 49. When such deployers find that the high-risk AI system that they envisage using has not been registered in the EU database referred to in Article 71, they shall not use that system and shall inform the provider or the distributor.\nWhere applicable, deployers of high-risk AI systems shall use the information provided under Article 13 of this Regulation to comply with their obligation to carry out a data protection impact assessment under Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680.\nWithout prejudice to Directive (EU) 2016/680, in the framework of an investigation for the targeted search of a person suspected or convicted of having committed a criminal offence, the deployer of a high-risk AI system for post-remote biometric identification shall request an authorisation, ex ante, or without undue delay and no later than 48 hours, by a judicial authority or an administrative authority whose decision is binding and subject to judicial review, for the use of that system, except when it is used for the initial identification of a potential suspect based on objective and verifiable facts directly linked to the offence. Each use shall be limited to what is strictly necessary for the investigation of a specific criminal offence.\nIf the authorisation requested pursuant to the first subparagraph is rejected, the use of the post-remote biometric identification system linked to that requested authorisation shall be stopped with immediate effect and the personal data linked to the use of the high-risk AI system for which the authorisation was requested shall be deleted.\nIn no case shall such high-risk AI system for post-remote biometric identification be used for law enforcement purposes in an untargeted way, without any link to a criminal offence, a criminal proceeding, a genuine and present or genuine and foreseeable threat of a criminal offence, or the search for a specific missing person. It shall be ensured that no decision that produces an adverse legal effect on a person may be taken by the law enforcement authorities based solely on the output of such post-remote biometric identification systems.\nThis paragraph is without prejudice to Article 9 of Regulation (EU) 2016/679 and Article 10 of Directive (EU) 2016/680 for the processing of biometric data.\nRegardless of the purpose or deployer, each use of such high-risk AI systems shall be documented in the relevant police file and shall be made available to the relevant market surveillance authority and the national data protection authority upon request, excluding the disclosure of sensitive operational data related to law enforcement. This subparagraph shall be without prejudice to the powers conferred by Directive (EU) 2016/680 on supervisory authorities.\nDeployers shall submit annual reports to the relevant market surveillance and national data protection authorities on their use of post-remote biometric identification systems, excluding the disclosure of sensitive operational data related to law enforcement. The reports may be aggregated to cover more than one deployment.\nMember States may introduce, in accordance with Union law, more restrictive laws on the use of post-remote biometric identification systems.\nWithout prejudice to Article 50 of this Regulation, deployers of high-risk AI systems referred to in Annex III that make decisions or assist in making decisions related to natural persons shall inform the natural persons that they are subject to the use of the high-risk AI system. For high-risk AI systems used for law enforcement purposes Article 13 of Directive (EU) 2016/680 shall apply.\nDeployers shall cooperate with the relevant competent authorities in any action those authorities take in relation to the high-risk AI system in order to implement this Regulation.\nArticle 27 Fundamental rights impact assessment for high-risk AI systems Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights that the use of such system may produce. For that purpose, deployers shall perform an assessment consisting of: (a)\na description of the deployer’s processes in which the high-risk AI system will be used in line with its intended purpose;\n(b)\na description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used;\n(c)\nthe categories of natural persons and groups likely to be affected by its use in the specific context;\n(d)\nthe specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified pursuant to point (c) of this paragraph, taking into account the information given by the provider pursuant to Article 13;\n(e)\na description of the implementation of human oversight measures, according to the instructions for use;\n(f)\nthe measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms.\nThe obligation laid down in paragraph 1 applies to the first use of the high-risk AI system. The deployer may, in similar cases, rely on previously conducted fundamental rights impact assessments or existing impact assessments carried out by provider. If, during the use of the high-risk AI system, the deployer considers that any of the elements listed in paragraph 1 has changed or is no longer up to date, the deployer shall take the necessary steps to update the information.\nOnce the assessment referred to in paragraph 1 of this Article has been performed, the deployer shall notify the market surveillance authority of its results, submitting the filled-out template referred to in paragraph 5 of this Article as part of the notification. In the case referred to in Article 46(1), deployers may be exempt from that obligation to notify.\nIf any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the fundamental rights impact assessment referred to in paragraph 1 of this Article shall complement that data protection impact assessment.\nThe AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner.\nSECTION 4\nNotifying authorities and notified bodies\nArticle 28 Notifying authorities Each Member State shall designate or establish at least one notifying authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring. Those procedures shall be developed in cooperation between the notifying authorities of all Member States.\nMember States may decide that the assessment and monitoring referred to in paragraph 1 is to be carried out by a national accreditation body within the meaning of, and in accordance with, Regulation (EC) No 765/2008.\nNotifying authorities shall be established, organised and operated in such a way that no conflict of interest arises with conformity assessment bodies, and that the objectivity and impartiality of their activities are safeguarded.\nNotifying authorities shall be organised in such a way that decisions relating to the notification of conformity assessment bodies are taken by competent persons different from those who carried out the assessment of those bodies.\nNotifying authorities shall offer or provide neither any activities that conformity assessment bodies perform, nor any consultancy services on a commercial or competitive basis.\nNotifying authorities shall safeguard the confidentiality of the information that they obtain, in accordance with Article 78.\nNotifying authorities shall have an adequate number of competent personnel at their disposal for the proper performance of their tasks. Competent personnel shall have the necessary expertise, where applicable, for their function, in fields such as information technologies, AI and law, including the supervision of fundamental rights.\nArticle 29 Application of a conformity assessment body for notification Conformity assessment bodies shall submit an application for notification to the notifying authority of the Member State in which they are established.\nThe application for notification shall be accompanied by a description of the conformity assessment activities, the conformity assessment module or modules and the types of AI systems for which the conformity assessment body claims to be competent, as well as by an accreditation certificate, where one exists, issued by a national accreditation body attesting that the conformity assessment body fulfils the requirements laid down in Article 31.\nAny valid document related to existing designations of the applicant notified body under any other Union harmonisation legislation shall be added.\nWhere the conformity assessment body concerned cannot provide an accreditation certificate, it shall provide the notifying authority with all the documentary evidence necessary for the verification, recognition and regular monitoring of its compliance with the requirements laid down in Article 31.\nFor notified bodies which are designated under any other Union harmonisation legislation, all documents and certificates linked to those designations may be used to support their designation procedure under this Regulation, as appropriate. The notified body shall update the documentation referred to in paragraphs 2 and 3 of this Article whenever relevant changes occur, in order to enable the authority responsible for notified bodies to monitor and verify continuous compliance with all the requirements laid down in Article 31.\nArticle 30 Notification procedure Notifying authorities may notify only conformity assessment bodies which have satisfied the requirements laid down in Article 31.\nNotifying authorities shall notify the Commission and the other Member States, using the electronic notification tool developed and managed by the Commission, of each conformity assessment body referred to in paragraph 1.\nThe notification referred to in paragraph 2 of this Article shall include full details of the conformity assessment activities, the conformity assessment module or modules, the types of AI systems concerned, and the relevant attestation of competence. Where a notification is not based on an accreditation certificate as referred to in Article 29(2), the notifying authority shall provide the Commission and the other Member States with documentary evidence which attests to the competence of the conformity assessment body and to the arrangements in place to ensure that that body will be monitored regularly and will continue to satisfy the requirements laid down in Article 31.\nThe conformity assessment body concerned may perform the activities of a notified body only where no objections are raised by the Commission or the other Member States within two weeks of a notification by a notifying authority where it includes an accreditation certificate referred to in Article 29(2), or within two months of a notification by the notifying authority where it includes documentary evidence referred to in Article 29(3).\nWhere objections are raised, the Commission shall, without delay, enter into consultations with the relevant Member States and the conformity assessment body. In view thereof, the Commission shall decide whether the authorisation is justified. The Commission shall address its decision to the Member State concerned and to the relevant conformity assessment body.\nArticle 31 Requirements relating to notified bodies A notified body shall be established under the national law of a Member State and shall have legal personality.\nNotified bodies shall satisfy the organisational, quality management, resources and process requirements that are necessary to fulfil their tasks, as well as suitable cybersecurity requirements.\nThe organisational structure, allocation of responsibilities, reporting lines and operation of notified bodies shall ensure confidence in their performance, and in the results of the conformity assessment activities that the notified bodies conduct.\nNotified bodies shall be independent of the provider of a high-risk AI system in relation to which they perform conformity assessment activities. Notified bodies shall also be independent of any other operator having an economic interest in high-risk AI systems assessed, as well as of any competitors of the provider. This shall not preclude the use of assessed high-risk AI systems that are necessary for the operations of the conformity assessment body, or the use of such high-risk AI systems for personal purposes.\nNeither a conformity assessment body, its top-level management nor the personnel responsible for carrying out its conformity assessment tasks shall be directly involved in the design, development, marketing or use of high-risk AI systems, nor shall they represent the parties engaged in those activities. They shall not engage in any activity that might conflict with their independence of judgement or integrity in relation to conformity assessment activities for which they are notified. This shall, in particular, apply to consultancy services.\nNotified bodies shall be organised and operated so as to safeguard the independence, objectivity and impartiality of their activities. Notified bodies shall document and implement a structure and procedures to safeguard impartiality and to promote and apply the principles of impartiality throughout their organisation, personnel and assessment activities.\nNotified bodies shall have documented procedures in place ensuring that their personnel, committees, subsidiaries, subcontractors and any associated body or personnel of external bodies maintain, in accordance with Article 78, the confidentiality of the information which comes into their possession during the performance of conformity assessment activities, except when its disclosure is required by law. The staff of notified bodies shall be bound to observe professional secrecy with regard to all information obtained in carrying out their tasks under this Regulation, except in relation to the notifying authorities of the Member State in which their activities are carried out.\nNotified bodies shall have procedures for the performance of activities which take due account of the size of a provider, the sector in which it operates, its structure, and the degree of complexity of the AI system concerned.\nNotified bodies shall take out appropriate liability insurance for their conformity assessment activities, unless liability is assumed by the Member State in which they are established in accordance with national law or that Member State is itself directly responsible for the conformity assessment.\nNotified bodies shall be capable of carrying out all their tasks under this Regulation with the highest degree of professional integrity and the requisite competence in the specific field, whether those tasks are carried out by notified bodies themselves or on their behalf and under their responsibility.\nNotified bodies shall have sufficient internal competences to be able effectively to evaluate the tasks conducted by external parties on their behalf. The notified body shall have permanent availability of sufficient administrative, technical, legal and scientific personnel who possess experience and knowledge relating to the relevant types of AI systems, data and data computing, and relating to the requirements set out in Section 2.\nNotified bodies shall participate in coordination activities as referred to in Article 38. They shall also take part directly, or be represented in, European standardisation organisations, or ensure that they are aware and up to date in respect of relevant standards.\nArticle 32 Presumption of conformity with requirements relating to notified bodies Where a conformity assessment body demonstrates its conformity with the criteria laid down in the relevant harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union, it shall be presumed to comply with the requirements set out in Article 31 in so far as the applicable harmonised standards cover those requirements.\nArticle 33 Subsidiaries of notified bodies and subcontracting Where a notified body subcontracts specific tasks connected with the conformity assessment or has recourse to a subsidiary, it shall ensure that the subcontractor or the subsidiary meets the requirements laid down in Article 31, and shall inform the notifying authority accordingly.\nNotified bodies shall take full responsibility for the tasks performed by any subcontractors or subsidiaries.\nActivities may be subcontracted or carried out by a subsidiary only with the agreement of the provider. Notified bodies shall make a list of their subsidiaries publicly available.\nThe relevant documents concerning the assessment of the qualifications of the subcontractor or the subsidiary and the work carried out by them under this Regulation shall be kept at the disposal of the notifying authority for a period of five years from the termination date of the subcontracting.\nArticle 34 Operational obligations of notified bodies Notified bodies shall verify the conformity of high-risk AI systems in accordance with the conformity assessment procedures set out in Article 43.\nNotified bodies shall avoid unnecessary burdens for providers when performing their activities, and take due account of the size of the provider, the sector in which it operates, its structure and the degree of complexity of the high-risk AI system concerned, in particular in view of minimising administrative burdens and compliance costs for micro- and small enterprises within the meaning of Recommendation 2003/361/EC. The notified body shall, nevertheless, respect the degree of rigour and the level of protection required for the compliance of the high-risk AI system with the requirements of this Regulation.\nNotified bodies shall make available and submit upon request all relevant documentation, including the providers’ documentation, to the notifying authority referred to in Article 28 to allow that authority to conduct its assessment, designation, notification and monitoring activities, and to facilitate the assessment outlined in this Section.\nArticle 35 Identification numbers and lists of notified bodies The Commission shall assign a single identification number to each notified body, even where a body is notified under more than one Union act.\nThe Commission shall make publicly available the list of the bodies notified under this Regulation, including their identification numbers and the activities for which they have been notified. The Commission shall ensure that the list is kept up to date.\nArticle 36 Changes to notifications The notifying authority shall notify the Commission and the other Member States of any relevant changes to the notification of a notified body via the electronic notification tool referred to in Article 30(2).\nThe procedures laid down in Articles 29 and 30 shall apply to extensions of the scope of the notification.\nFor changes to the notification other than extensions of its scope, the procedures laid down in paragraphs (3) to (9) shall apply.\nWhere a notified body decides to cease its conformity assessment activities, it shall inform the notifying authority and the providers concerned as soon as possible and, in the case of a planned cessation, at least one year before ceasing its activities. The certificates of the notified body may remain valid for a period of nine months after cessation of the notified body’s activities, on condition that another notified body has confirmed in writing that it will assume responsibilities for the high-risk AI systems covered by those certificates. The latter notified body shall complete a full assessment of the high-risk AI systems affected by the end of that nine-month-period before issuing new certificates for those systems. Where the notified body has ceased its activity, the notifying authority shall withdraw the designation.\nWhere a notifying authority has sufficient reason to consider that a notified body no longer meets the requirements laid down in Article 31, or that it is failing to fulfil its obligations, the notifying authority shall without delay investigate the matter with the utmost diligence. In that context, it shall inform the notified body concerned about the objections raised and give it the possibility to make its views known. If the notifying authority comes to the conclusion that the notified body no longer meets the requirements laid down in Article 31 or that it is failing to fulfil its obligations, it shall restrict, suspend or withdraw the designation as appropriate, depending on the seriousness of the failure to meet those requirements or fulfil those obligations. It shall immediately inform the Commission and the other Member States accordingly.\nWhere its designation has been suspended, restricted, or fully or partially withdrawn, the notified body shall inform the providers concerned within 10 days.\nIn the event of the restriction, suspension or withdrawal of a designation, the notifying authority shall take appropriate steps to ensure that the files of the notified body concerned are kept, and to make them available to notifying authorities in other Member States and to market surveillance authorities at their request.\nIn the event of the restriction, suspension or withdrawal of a designation, the notifying authority shall:\n(a)\nassess the impact on the certificates issued by the notified body;\n(b)\nsubmit a report on its findings to the Commission and the other Member States within three months of having notified the changes to the designation;\n(c)\nrequire the notified body to suspend or withdraw, within a reasonable period of time determined by the authority, any certificates which were unduly issued, in order to ensure the continuing conformity of high-risk AI systems on the market;\n(d)\ninform the Commission and the Member States about certificates the suspension or withdrawal of which it has required;\n(e)\nprovide the national competent authorities of the Member State in which the provider has its registered place of business with all relevant information about the certificates of which it has required the suspension or withdrawal; that authority shall take the appropriate measures, where necessary, to avoid a potential risk to health, safety or fundamental rights.\nWith the exception of certificates unduly issued, and where a designation has been suspended or restricted, the certificates shall remain valid in one of the following circumstances: (a)\nthe notifying authority has confirmed, within one month of the suspension or restriction, that there is no risk to health, safety or fundamental rights in relation to certificates affected by the suspension or restriction, and the notifying authority has outlined a timeline for actions to remedy the suspension or restriction; or\n(b)\nthe notifying authority has confirmed that no certificates relevant to the suspension will be issued, amended or re-issued during the course of the suspension or restriction, and states whether the notified body has the capability of continuing to monitor and remain responsible for existing certificates issued for the period of the suspension or restriction; in the event that the notifying authority determines that the notified body does not have the capability to support existing certificates issued, the provider of the system covered by the certificate shall confirm in writing to the national competent authorities of the Member State in which it has its registered place of business, within three months of the suspension or restriction, that another qualified notified body is temporarily assuming the functions of the notified body to monitor and remain responsible for the certificates during the period of suspension or restriction.\nWith the exception of certificates unduly issued, and where a designation has been withdrawn, the certificates shall remain valid for a period of nine months under the following circumstances: (a)\nthe national competent authority of the Member State in which the provider of the high-risk AI system covered by the certificate has its registered place of business has confirmed that there is no risk to health, safety or fundamental rights associated with the high-risk AI systems concerned; and\n(b)\nanother notified body has confirmed in writing that it will assume immediate responsibility for those AI systems and completes its assessment within 12 months of the withdrawal of the designation.\nIn the circumstances referred to in the first subparagraph, the national competent authority of the Member State in which the provider of the system covered by the certificate has its place of business may extend the provisional validity of the certificates for additional periods of three months, which shall not exceed 12 months in total.\nThe national competent authority or the notified body assuming the functions of the notified body affected by the change of designation shall immediately inform the Commission, the other Member States and the other notified bodies thereof.\nArticle 37 Challenge to the competence of notified bodies The Commission shall, where necessary, investigate all cases where there are reasons to doubt the competence of a notified body or the continued fulfilment by a notified body of the requirements laid down in Article 31 and of its applicable responsibilities.\nThe notifying authority shall provide the Commission, on request, with all relevant information relating to the notification or the maintenance of the competence of the notified body concerned.\nThe Commission shall ensure that all sensitive information obtained in the course of its investigations pursuant to this Article is treated confidentially in accordance with Article 78.\nWhere the Commission ascertains that a notified body does not meet or no longer meets the requirements for its notification, it shall inform the notifying Member State accordingly and request it to take the necessary corrective measures, including the suspension or withdrawal of the notification if necessary. Where the Member State fails to take the necessary corrective measures, the Commission may, by means of an implementing act, suspend, restrict or withdraw the designation. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nArticle 38 Coordination of notified bodies The Commission shall ensure that, with regard to high-risk AI systems, appropriate coordination and cooperation between notified bodies active in the conformity assessment procedures pursuant to this Regulation are put in place and properly operated in the form of a sectoral group of notified bodies.\nEach notifying authority shall ensure that the bodies notified by it participate in the work of a group referred to in paragraph 1, directly or through designated representatives.\nThe Commission shall provide for the exchange of knowledge and best practices between notifying authorities.\nArticle 39 Conformity assessment bodies of third countries Conformity assessment bodies established under the law of a third country with which the Union has concluded an agreement may be authorised to carry out the activities of notified bodies under this Regulation, provided that they meet the requirements laid down in Article 31 or they ensure an equivalent level of compliance.\nSECTION 5\nStandards, conformity assessment, certificates, registration\nArticle 40 Harmonised standards and standardisation deliverables High-risk AI systems or general-purpose AI models which are in conformity with harmonised standards or parts thereof the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012 shall be presumed to be in conformity with the requirements set out in Section 2 of this Chapter or, as applicable, with the obligations set out in of Chapter V, Sections 2 and 3, of this Regulation, to the extent that those standards cover those requirements or obligations.\nIn accordance with Article 10 of Regulation (EU) No 1025/2012, the Commission shall issue, without undue delay, standardisation requests covering all requirements set out in Section 2 of this Chapter and, as applicable, standardisation requests covering obligations set out in Chapter V, Sections 2 and 3, of this Regulation. The standardisation request shall also ask for deliverables on reporting and documentation processes to improve AI systems’ resource performance, such as reducing the high-risk AI system’s consumption of energy and of other resources during its lifecycle, and on the energy-efficient development of general-purpose AI models. When preparing a standardisation request, the Commission shall consult the Board and relevant stakeholders, including the advisory forum.\nWhen issuing a standardisation request to European standardisation organisations, the Commission shall specify that standards have to be clear, consistent, including with the standards developed in the various sectors for products covered by the existing Union harmonisation legislation listed in Annex I, and aiming to ensure that high-risk AI systems or general-purpose AI models placed on the market or put into service in the Union meet the relevant requirements or obligations laid down in this Regulation.\nThe Commission shall request the European standardisation organisations to provide evidence of their best efforts to fulfil the objectives referred to in the first and the second subparagraph of this paragraph in accordance with Article 24 of Regulation (EU) No 1025/2012.\nThe participants in the standardisation process shall seek to promote investment and innovation in AI, including through increasing legal certainty, as well as the competitiveness and growth of the Union market, to contribute to strengthening global cooperation on standardisation and taking into account existing international standards in the field of AI that are consistent with Union values, fundamental rights and interests, and to enhance multi-stakeholder governance ensuring a balanced representation of interests and the effective participation of all relevant stakeholders in accordance with Articles 5, 6, and 7 of Regulation (EU) No 1025/2012. Article 41 Common specifications The Commission may adopt, implementing acts establishing common specifications for the requirements set out in Section 2 of this Chapter or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V where the following conditions have been fulfilled: (a)\nthe Commission has requested, pursuant to Article 10(1) of Regulation (EU) No 1025/2012, one or more European standardisation organisations to draft a harmonised standard for the requirements set out in Section 2 of this Chapter, or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V, and:\n(i)\nthe request has not been accepted by any of the European standardisation organisations; or\n(ii)\nthe harmonised standards addressing that request are not delivered within the deadline set in accordance with Article 10(1) of Regulation (EU) No 1025/2012; or\n(iii)\nthe relevant harmonised standards insufficiently address fundamental rights concerns; or\n(iv)\nthe harmonised standards do not comply with the request; and\n(b)\nno reference to harmonised standards covering the requirements referred to in Section 2 of this Chapter or, as applicable, the obligations referred to in Sections 2 and 3 of Chapter V has been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, and no such reference is expected to be published within a reasonable period.\nWhen drafting the common specifications, the Commission shall consult the advisory forum referred to in Article 67.\nThe implementing acts referred to in the first subparagraph of this paragraph shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nBefore preparing a draft implementing act, the Commission shall inform the committee referred to in Article 22 of Regulation (EU) No 1025/2012 that it considers the conditions laid down in paragraph 1 of this Article to be fulfilled.\nHigh-risk AI systems or general-purpose AI models which are in conformity with the common specifications referred to in paragraph 1, or parts of those specifications, shall be presumed to be in conformity with the requirements set out in Section 2 of this Chapter or, as applicable, to comply with the obligations referred to in Sections 2 and 3 of Chapter V, to the extent those common specifications cover those requirements or those obligations.\nWhere a harmonised standard is adopted by a European standardisation organisation and proposed to the Commission for the publication of its reference in the Official Journal of the European Union, the Commission shall assess the harmonised standard in accordance with Regulation (EU) No 1025/2012. When reference to a harmonised standard is published in the Official Journal of the European Union, the Commission shall repeal the implementing acts referred to in paragraph 1, or parts thereof which cover the same requirements set out in Section 2 of this Chapter or, as applicable, the same obligations set out in Sections 2 and 3 of Chapter V.\nWhere providers of high-risk AI systems or general-purpose AI models do not comply with the common specifications referred to in paragraph 1, they shall duly justify that they have adopted technical solutions that meet the requirements referred to in Section 2 of this Chapter or, as applicable, comply with the obligations set out in Sections 2 and 3 of Chapter V to a level at least equivalent thereto.\nWhere a Member State considers that a common specification does not entirely meet the requirements set out in Section 2 or, as applicable, comply with obligations set out in Sections 2 and 3 of Chapter V, it shall inform the Commission thereof with a detailed explanation. The Commission shall assess that information and, if appropriate, amend the implementing act establishing the common specification concerned.\nArticle 42 Presumption of conformity with certain requirements High-risk AI systems that have been trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used shall be presumed to comply with the relevant requirements laid down in Article 10(4).\nHigh-risk AI systems that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to Regulation (EU) 2019/881 and the references of which have been published in the Official Journal of the European Union shall be presumed to comply with the cybersecurity requirements set out in Article 15 of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover those requirements.\nArticle 43 Conformity assessment For high-risk AI systems listed in point 1 of Annex III, where, in demonstrating the compliance of a high-risk AI system with the requirements set out in Section 2, the provider has applied harmonised standards referred to in Article 40, or, where applicable, common specifications referred to in Article 41, the provider shall opt for one of the following conformity assessment procedures based on: (a)\nthe internal control referred to in Annex VI; or\n(b)\nthe assessment of the quality management system and the assessment of the technical documentation, with the involvement of a notified body, referred to in Annex VII.\nIn demonstrating the compliance of a high-risk AI system with the requirements set out in Section 2, the provider shall follow the conformity assessment procedure set out in Annex VII where:\n(a)\nharmonised standards referred to in Article 40 do not exist, and common specifications referred to in Article 41 are not available;\n(b)\nthe provider has not applied, or has applied only part of, the harmonised standard;\n(c)\nthe common specifications referred to in point (a) exist, but the provider has not applied them;\n(d)\none or more of the harmonised standards referred to in point (a) has been published with a restriction, and only on the part of the standard that was restricted.\nFor the purposes of the conformity assessment procedure referred to in Annex VII, the provider may choose any of the notified bodies. However, where the high-risk AI system is intended to be put into service by law enforcement, immigration or asylum authorities or by Union institutions, bodies, offices or agencies, the market surveillance authority referred to in Article 74(8) or (9), as applicable, shall act as a notified body.\nFor high-risk AI systems referred to in points 2 to 8 of Annex III, providers shall follow the conformity assessment procedure based on internal control as referred to in Annex VI, which does not provide for the involvement of a notified body.\nFor high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, the provider shall follow the relevant conformity assessment procedure as required under those legal acts. The requirements set out in Section 2 of this Chapter shall apply to those high-risk AI systems and shall be part of that assessment. Points 4.3., 4.4., 4.5. and the fifth paragraph of point 4.6 of Annex VII shall also apply.\nFor the purposes of that assessment, notified bodies which have been notified under those legal acts shall be entitled to control the conformity of the high-risk AI systems with the requirements set out in Section 2, provided that the compliance of those notified bodies with requirements laid down in Article 31(4), (5), (10) and (11) has been assessed in the context of the notification procedure under those legal acts.\nWhere a legal act listed in Section A of Annex I enables the product manufacturer to opt out from a third-party conformity assessment, provided that that manufacturer has applied all harmonised standards covering all the relevant requirements, that manufacturer may use that option only if it has also applied harmonised standards or, where applicable, common specifications referred to in Article 41, covering all requirements set out in Section 2 of this Chapter.\nHigh-risk AI systems that have already been subject to a conformity assessment procedure shall undergo a new conformity assessment procedure in the event of a substantial modification, regardless of whether the modified system is intended to be further distributed or continues to be used by the current deployer. For high-risk AI systems that continue to learn after being placed on the market or put into service, changes to the high-risk AI system and its performance that have been pre-determined by the provider at the moment of the initial conformity assessment and are part of the information contained in the technical documentation referred to in point 2(f) of Annex IV, shall not constitute a substantial modification.\nThe Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend Annexes VI and VII by updating them in light of technical progress.\nThe Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend paragraphs 1 and 2 of this Article in order to subject high-risk AI systems referred to in points 2 to 8 of Annex III to the conformity assessment procedure referred to in Annex VII or parts thereof. The Commission shall adopt such delegated acts taking into account the effectiveness of the conformity assessment procedure based on internal control referred to in Annex VI in preventing or minimising the risks to health and safety and protection of fundamental rights posed by such systems, as well as the availability of adequate capacities and resources among notified bodies.\nArticle 44 Certificates Certificates issued by notified bodies in accordance with Annex VII shall be drawn-up in a language which can be easily understood by the relevant authorities in the Member State in which the notified body is established.\nCertificates shall be valid for the period they indicate, which shall not exceed five years for AI systems covered by Annex I, and four years for AI systems covered by Annex III. At the request of the provider, the validity of a certificate may be extended for further periods, each not exceeding five years for AI systems covered by Annex I, and four years for AI systems covered by Annex III, based on a re-assessment in accordance with the applicable conformity assessment procedures. Any supplement to a certificate shall remain valid, provided that the certificate which it supplements is valid.\nWhere a notified body finds that an AI system no longer meets the requirements set out in Section 2, it shall, taking account of the principle of proportionality, suspend or withdraw the certificate issued or impose restrictions on it, unless compliance with those requirements is ensured by appropriate corrective action taken by the provider of the system within an appropriate deadline set by the notified body. The notified body shall give reasons for its decision.\nAn appeal procedure against decisions of the notified bodies, including on conformity certificates issued, shall be available.\nArticle 45 Information obligations of notified bodies Notified bodies shall inform the notifying authority of the following: (a)\nany Union technical documentation assessment certificates, any supplements to those certificates, and any quality management system approvals issued in accordance with the requirements of Annex VII;\n(b)\nany refusal, restriction, suspension or withdrawal of a Union technical documentation assessment certificate or a quality management system approval issued in accordance with the requirements of Annex VII;\n(c)\nany circumstances affecting the scope of or conditions for notification;\n(d)\nany request for information which they have received from market surveillance authorities regarding conformity assessment activities;\n(e)\non request, conformity assessment activities performed within the scope of their notification and any other activity performed, including cross-border activities and subcontracting.\nEach notified body shall inform the other notified bodies of: (a)\nquality management system approvals which it has refused, suspended or withdrawn, and, upon request, of quality system approvals which it has issued;\n(b)\nUnion technical documentation assessment certificates or any supplements thereto which it has refused, withdrawn, suspended or otherwise restricted, and, upon request, of the certificates and/or supplements thereto which it has issued.\nEach notified body shall provide the other notified bodies carrying out similar conformity assessment activities covering the same types of AI systems with relevant information on issues relating to negative and, on request, positive conformity assessment results.\nNotified bodies shall safeguard the confidentiality of the information that they obtain, in accordance with Article 78.\nArticle 46 Derogation from conformity assessment procedure By way of derogation from Article 43 and upon a duly justified request, any market surveillance authority may authorise the placing on the market or the putting into service of specific high-risk AI systems within the territory of the Member State concerned, for exceptional reasons of public security or the protection of life and health of persons, environmental protection or the protection of key industrial and infrastructural assets. That authorisation shall be for a limited period while the necessary conformity assessment procedures are being carried out, taking into account the exceptional reasons justifying the derogation. The completion of those procedures shall be undertaken without undue delay.\nIn a duly justified situation of urgency for exceptional reasons of public security or in the case of specific, substantial and imminent threat to the life or physical safety of natural persons, law-enforcement authorities or civil protection authorities may put a specific high-risk AI system into service without the authorisation referred to in paragraph 1, provided that such authorisation is requested during or after the use without undue delay. If the authorisation referred to in paragraph 1 is refused, the use of the high-risk AI system shall be stopped with immediate effect and all the results and outputs of such use shall be immediately discarded.\nThe authorisation referred to in paragraph 1 shall be issued only if the market surveillance authority concludes that the high-risk AI system complies with the requirements of Section 2. The market surveillance authority shall inform the Commission and the other Member States of any authorisation issued pursuant to paragraphs 1 and 2. This obligation shall not cover sensitive operational data in relation to the activities of law-enforcement authorities.\nWhere, within 15 calendar days of receipt of the information referred to in paragraph 3, no objection has been raised by either a Member State or the Commission in respect of an authorisation issued by a market surveillance authority of a Member State in accordance with paragraph 1, that authorisation shall be deemed justified.\nWhere, within 15 calendar days of receipt of the notification referred to in paragraph 3, objections are raised by a Member State against an authorisation issued by a market surveillance authority of another Member State, or where the Commission considers the authorisation to be contrary to Union law, or the conclusion of the Member States regarding the compliance of the system as referred to in paragraph 3 to be unfounded, the Commission shall, without delay, enter into consultations with the relevant Member State. The operators concerned shall be consulted and have the possibility to present their views. Having regard thereto, the Commission shall decide whether the authorisation is justified. The Commission shall address its decision to the Member State concerned and to the relevant operators.\nWhere the Commission considers the authorisation unjustified, it shall be withdrawn by the market surveillance authority of the Member State concerned.\nFor high-risk AI systems related to products covered by Union harmonisation legislation listed in Section A of Annex I, only the derogations from the conformity assessment established in that Union harmonisation legislation shall apply.\nArticle 47 EU declaration of conformity The provider shall draw up a written machine readable, physical or electronically signed EU declaration of conformity for each high-risk AI system, and keep it at the disposal of the national competent authorities for 10 years after the high-risk AI system has been placed on the market or put into service. The EU declaration of conformity shall identify the high-risk AI system for which it has been drawn up. A copy of the EU declaration of conformity shall be submitted to the relevant national competent authorities upon request.\nThe EU declaration of conformity shall state that the high-risk AI system concerned meets the requirements set out in Section 2. The EU declaration of conformity shall contain the information set out in Annex V, and shall be translated into a language that can be easily understood by the national competent authorities of the Member States in which the high-risk AI system is placed on the market or made available.\nWhere high-risk AI systems are subject to other Union harmonisation legislation which also requires an EU declaration of conformity, a single EU declaration of conformity shall be drawn up in respect of all Union law applicable to the high-risk AI system. The declaration shall contain all the information required to identify the Union harmonisation legislation to which the declaration relates.\nBy drawing up the EU declaration of conformity, the provider shall assume responsibility for compliance with the requirements set out in Section 2. The provider shall keep the EU declaration of conformity up-to-date as appropriate.\nThe Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend Annex V by updating the content of the EU declaration of conformity set out in that Annex, in order to introduce elements that become necessary in light of technical progress.\nArticle 48 CE marking The CE marking shall be subject to the general principles set out in Article 30 of Regulation (EC) No 765/2008.\nFor high-risk AI systems provided digitally, a digital CE marking shall be used, only if it can easily be accessed via the interface from which that system is accessed or via an easily accessible machine-readable code or other electronic means.\nThe CE marking shall be affixed visibly, legibly and indelibly for high-risk AI systems. Where that is not possible or not warranted on account of the nature of the high-risk AI system, it shall be affixed to the packaging or to the accompanying documentation, as appropriate.\nWhere applicable, the CE marking shall be followed by the identification number of the notified body responsible for the conformity assessment procedures set out in Article 43. The identification number of the notified body shall be affixed by the body itself or, under its instructions, by the provider or by the provider’s authorised representative. The identification number shall also be indicated in any promotional material which mentions that the high-risk AI system fulfils the requirements for CE marking.\nWhere high-risk AI systems are subject to other Union law which also provides for the affixing of the CE marking, the CE marking shall indicate that the high-risk AI system also fulfil the requirements of that other law.\nArticle 49 Registration Before placing on the market or putting into service a high-risk AI system listed in Annex III, with the exception of high-risk AI systems referred to in point 2 of Annex III, the provider or, where applicable, the authorised representative shall register themselves and their system in the EU database referred to in Article 71.\nBefore placing on the market or putting into service an AI system for which the provider has concluded that it is not high-risk according to Article 6(3), that provider or, where applicable, the authorised representative shall register themselves and that system in the EU database referred to in Article 71.\nBefore putting into service or using a high-risk AI system listed in Annex III, with the exception of high-risk AI systems listed in point 2 of Annex III, deployers that are public authorities, Union institutions, bodies, offices or agencies or persons acting on their behalf shall register themselves, select the system and register its use in the EU database referred to in Article 71.\nFor high-risk AI systems referred to in points 1, 6 and 7 of Annex III, in the areas of law enforcement, migration, asylum and border control management, the registration referred to in paragraphs 1, 2 and 3 of this Article shall be in a secure non-public section of the EU database referred to in Article 71 and shall include only the following information, as applicable, referred to in:\n(a)\nSection A, points 1 to 10, of Annex VIII, with the exception of points 6, 8 and 9;\n(b)\nSection B, points 1 to 5, and points 8 and 9 of Annex VIII;\n(c)\nSection C, points 1 to 3, of Annex VIII;\n(d)\npoints 1, 2, 3 and 5, of Annex IX.\nOnly the Commission and national authorities referred to in Article 74(8) shall have access to the respective restricted sections of the EU database listed in the first subparagraph of this paragraph.\nHigh-risk AI systems referred to in point 2 of Annex III shall be registered at national level. CHAPTER IV TRANSPARENCY OBLIGATIONS FOR PROVIDERS AND DEPLOYERS OF CERTAIN AI SYSTEMS\nArticle 50 Transparency obligations for providers and deployers of certain AI systems Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. This obligation shall not apply to AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, unless those systems are available for the public to report a criminal offence.\nProviders of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. Providers shall ensure their technical solutions are effective, interoperable, robust and reliable as far as this is technically feasible, taking into account the specificities and limitations of various types of content, the costs of implementation and the generally acknowledged state of the art, as may be reflected in relevant technical standards. This obligation shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof, or where authorised by law to detect, prevent, investigate or prosecute criminal offences.\nDeployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system, and shall process the personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable. This obligation shall not apply to AI systems used for biometric categorisation and emotion recognition, which are permitted by law to detect, prevent or investigate criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, and in accordance with Union law.\nDeployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offence. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations set out in this paragraph are limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.\nDeployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offences or where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content.\nThe information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The information shall conform to the applicable accessibility requirements.\nParagraphs 1 to 4 shall not affect the requirements and obligations set out in Chapter III, and shall be without prejudice to other transparency obligations laid down in Union or national law for deployers of AI systems.\nThe AI Office shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection and labelling of artificially generated or manipulated content. The Commission may adopt implementing acts to approve those codes of practice in accordance with the procedure laid down in Article 56 (6). If it deems the code is not adequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure laid down in Article 98(2).\nCHAPTER V GENERAL-PURPOSE AI MODELS\nSECTION 1\nClassification rules\nArticle 51 Classification of general-purpose AI models as general-purpose AI models with systemic risk A general-purpose AI model shall be classified as a general-purpose AI model with systemic risk if it meets any of the following conditions: (a)\nit has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks;\n(b)\nbased on a decision of the Commission, ex officio or following a qualified alert from the scientific panel, it has capabilities or an impact equivalent to those set out in point (a) having regard to the criteria set out in Annex XIII.\nA general-purpose AI model shall be presumed to have high impact capabilities pursuant to paragraph 1, point (a), when the cumulative amount of computation used for its training measured in floating point operations is greater than 1025.\nThe Commission shall adopt delegated acts in accordance with Article 97 to amend the thresholds listed in paragraphs 1 and 2 of this Article, as well as to supplement benchmarks and indicators in light of evolving technological developments, such as algorithmic improvements or increased hardware efficiency, when necessary, for these thresholds to reflect the state of the art.\nArticle 52 Procedure Where a general-purpose AI model meets the condition referred to in Article 51(1), point (a), the relevant provider shall notify the Commission without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met. That notification shall include the information necessary to demonstrate that the relevant requirement has been met. If the Commission becomes aware of a general-purpose AI model presenting systemic risks of which it has not been notified, it may decide to designate it as a model with systemic risk.\nThe provider of a general-purpose AI model that meets the condition referred to in Article 51(1), point (a), may present, with its notification, sufficiently substantiated arguments to demonstrate that, exceptionally, although it meets that requirement, the general-purpose AI model does not present, due to its specific characteristics, systemic risks and therefore should not be classified as a general-purpose AI model with systemic risk.\nWhere the Commission concludes that the arguments submitted pursuant to paragraph 2 are not sufficiently substantiated and the relevant provider was not able to demonstrate that the general-purpose AI model does not present, due to its specific characteristics, systemic risks, it shall reject those arguments, and the general-purpose AI model shall be considered to be a general-purpose AI model with systemic risk.\nThe Commission may designate a general-purpose AI model as presenting systemic risks, ex officio or following a qualified alert from the scientific panel pursuant to Article 90(1), point (a), on the basis of criteria set out in Annex XIII.\nThe Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend Annex XIII by specifying and updating the criteria set out in that Annex.\nUpon a reasoned request of a provider whose model has been designated as a general-purpose AI model with systemic risk pursuant to paragraph 4, the Commission shall take the request into account and may decide to reassess whether the general-purpose AI model can still be considered to present systemic risks on the basis of the criteria set out in Annex XIII. Such a request shall contain objective, detailed and new reasons that have arisen since the designation decision. Providers may request reassessment at the earliest six months after the designation decision. Where the Commission, following its reassessment, decides to maintain the designation as a general-purpose AI model with systemic risk, providers may request reassessment at the earliest six months after that decision.\nThe Commission shall ensure that a list of general-purpose AI models with systemic risk is published and shall keep that list up to date, without prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets in accordance with Union and national law.\nSECTION 2\nObligations for providers of general-purpose AI models\nArticle 53 Obligations for providers of general-purpose AI models Providers of general-purpose AI models shall: (a)\ndraw up and keep up-to-date the technical documentation of the model, including its training and testing process and the results of its evaluation, which shall contain, at a minimum, the information set out in Annex XI for the purpose of providing it, upon request, to the AI Office and the national competent authorities;\n(b)\ndraw up, keep up-to-date and make available information and documentation to providers of AI systems who intend to integrate the general-purpose AI model into their AI systems. Without prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets in accordance with Union and national law, the information and documentation shall:\n(i)\nenable providers of AI systems to have a good understanding of the capabilities and limitations of the general-purpose AI model and to comply with their obligations pursuant to this Regulation; and\n(ii)\ncontain, at a minimum, the elements set out in Annex XII;\n(c)\nput in place a policy to comply with Union law on copyright and related rights, and in particular to identify and comply with, including through state-of-the-art technologies, a reservation of rights expressed pursuant to Article 4(3) of Directive (EU) 2019/790;\n(d)\ndraw up and make publicly available a sufficiently detailed summary about the content used for training of the general-purpose AI model, according to a template provided by the AI Office.\nThe obligations set out in paragraph 1, points (a) and (b), shall not apply to providers of AI models that are released under a free and open-source licence that allows for the access, usage, modification, and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available. This exception shall not apply to general-purpose AI models with systemic risks.\nProviders of general-purpose AI models shall cooperate as necessary with the Commission and the national competent authorities in the exercise of their competences and powers pursuant to this Regulation.\nProviders of general-purpose AI models may rely on codes of practice within the meaning of Article 56 to demonstrate compliance with the obligations set out in paragraph 1 of this Article, until a harmonised standard is published. Compliance with European harmonised standards grants providers the presumption of conformity to the extent that those standards cover those obligations. Providers of general-purpose AI models who do not adhere to an approved code of practice or do not comply with a European harmonised standard shall demonstrate alternative adequate means of compliance for assessment by the Commission.\nFor the purpose of facilitating compliance with Annex XI, in particular points 2 (d) and (e) thereof, the Commission is empowered to adopt delegated acts in accordance with Article 97 to detail measurement and calculation methodologies with a view to allowing for comparable and verifiable documentation.\nThe Commission is empowered to adopt delegated acts in accordance with Article 97(2) to amend Annexes XI and XII in light of evolving technological developments.\nAny information or documentation obtained pursuant to this Article, including trade secrets, shall be treated in accordance with the confidentiality obligations set out in Article 78.\nArticle 54 Authorised representatives of providers of general-purpose AI models Prior to placing a general-purpose AI model on the Union market, providers established in third countries shall, by written mandate, appoint an authorised representative which is established in the Union.\nThe provider shall enable its authorised representative to perform the tasks specified in the mandate received from the provider.\nThe authorised representative shall perform the tasks specified in the mandate received from the provider. It shall provide a copy of the mandate to the AI Office upon request, in one of the official languages of the institutions of the Union. For the purposes of this Regulation, the mandate shall empower the authorised representative to carry out the following tasks:\n(a)\nverify that the technical documentation specified in Annex XI has been drawn up and all obligations referred to in Article 53 and, where applicable, Article 55 have been fulfilled by the provider;\n(b)\nkeep a copy of the technical documentation specified in Annex XI at the disposal of the AI Office and national competent authorities, for a period of 10 years after the general-purpose AI model has been placed on the market, and the contact details of the provider that appointed the authorised representative;\n(c)\nprovide the AI Office, upon a reasoned request, with all the information and documentation, including that referred to in point (b), necessary to demonstrate compliance with the obligations in this Chapter;\n(d)\ncooperate with the AI Office and competent authorities, upon a reasoned request, in any action they take in relation to the general-purpose AI model, including when the model is integrated into AI systems placed on the market or put into service in the Union.\nThe mandate shall empower the authorised representative to be addressed, in addition to or instead of the provider, by the AI Office or the competent authorities, on all issues related to ensuring compliance with this Regulation.\nThe authorised representative shall terminate the mandate if it considers or has reason to consider the provider to be acting contrary to its obligations pursuant to this Regulation. In such a case, it shall also immediately inform the AI Office about the termination of the mandate and the reasons therefor.\nThe obligation set out in this Article shall not apply to providers of general-purpose AI models that are released under a free and open-source licence that allows for the access, usage, modification, and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available, unless the general-purpose AI models present systemic risks.\nSECTION 3\nObligations of providers of general-purpose AI models with systemic risk\nArticle 55 Obligations of providers of general-purpose AI models with systemic risk In addition to the obligations listed in Articles 53 and 54, providers of general-purpose AI models with systemic risk shall: (a)\nperform model evaluation in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing of the model with a view to identifying and mitigating systemic risks;\n(b)\nassess and mitigate possible systemic risks at Union level, including their sources, that may stem from the development, the placing on the market, or the use of general-purpose AI models with systemic risk;\n(c)\nkeep track of, document, and report, without undue delay, to the AI Office and, as appropriate, to national competent authorities, relevant information about serious incidents and possible corrective measures to address them;\n(d)\nensure an adequate level of cybersecurity protection for the general-purpose AI model with systemic risk and the physical infrastructure of the model.\nProviders of general-purpose AI models with systemic risk may rely on codes of practice within the meaning of Article 56 to demonstrate compliance with the obligations set out in paragraph 1 of this Article, until a harmonised standard is published. Compliance with European harmonised standards grants providers the presumption of conformity to the extent that those standards cover those obligations. Providers of general-purpose AI models with systemic risks who do not adhere to an approved code of practice or do not comply with a European harmonised standard shall demonstrate alternative adequate means of compliance for assessment by the Commission.\nAny information or documentation obtained pursuant to this Article, including trade secrets, shall be treated in accordance with the confidentiality obligations set out in Article 78.\nSECTION 4\nCodes of practice\nArticle 56 Codes of practice The AI Office shall encourage and facilitate the drawing up of codes of practice at Union level in order to contribute to the proper application of this Regulation, taking into account international approaches.\nThe AI Office and the Board shall aim to ensure that the codes of practice cover at least the obligations provided for in Articles 53 and 55, including the following issues:\n(a)\nthe means to ensure that the information referred to in Article 53(1), points (a) and (b), is kept up to date in light of market and technological developments;\n(b)\nthe adequate level of detail for the summary about the content used for training;\n(c)\nthe identification of the type and nature of the systemic risks at Union level, including their sources, where appropriate;\n(d)\nthe measures, procedures and modalities for the assessment and management of the systemic risks at Union level, including the documentation thereof, which shall be proportionate to the risks, take into consideration their severity and probability and take into account the specific challenges of tackling those risks in light of the possible ways in which such risks may emerge and materialise along the AI value chain.\nThe AI Office may invite all providers of general-purpose AI models, as well as relevant national competent authorities, to participate in the drawing-up of codes of practice. Civil society organisations, industry, academia and other relevant stakeholders, such as downstream providers and independent experts, may support the process.\nThe AI Office and the Board shall aim to ensure that the codes of practice clearly set out their specific objectives and contain commitments or measures, including key performance indicators as appropriate, to ensure the achievement of those objectives, and that they take due account of the needs and interests of all interested parties, including affected persons, at Union level.\nThe AI Office shall aim to ensure that participants to the codes of practice report regularly to the AI Office on the implementation of the commitments and the measures taken and their outcomes, including as measured against the key performance indicators as appropriate. Key performance indicators and reporting commitments shall reflect differences in size and capacity between various participants.\nThe AI Office and the Board shall regularly monitor and evaluate the achievement of the objectives of the codes of practice by the participants and their contribution to the proper application of this Regulation. The AI Office and the Board shall assess whether the codes of practice cover the obligations provided for in Articles 53 and 55, and shall regularly monitor and evaluate the achievement of their objectives. They shall publish their assessment of the adequacy of the codes of practice.\nThe Commission may, by way of an implementing act, approve a code of practice and give it a general validity within the Union. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nThe AI Office may invite all providers of general-purpose AI models to adhere to the codes of practice. For providers of general-purpose AI models not presenting systemic risks this adherence may be limited to the obligations provided for in Article 53, unless they declare explicitly their interest to join the full code.\nThe AI Office shall, as appropriate, also encourage and facilitate the review and adaptation of the codes of practice, in particular in light of emerging standards. The AI Office shall assist in the assessment of available standards.\nCodes of practice shall be ready at the latest by 2 May 2025. The AI Office shall take the necessary steps, including inviting providers pursuant to paragraph 7.\nIf, by 2 August 2025, a code of practice cannot be finalised, or if the AI Office deems it is not adequate following its assessment under paragraph 6 of this Article, the Commission may provide, by means of implementing acts, common rules for the implementation of the obligations provided for in Articles 53 and 55, including the issues set out in paragraph 2 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nCHAPTER VI MEASURES IN SUPPORT OF INNOVATION\nArticle 57 AI regulatory sandboxes Member States shall ensure that their competent authorities establish at least one AI regulatory sandbox at national level, which shall be operational by 2 August 2026. That sandbox may also be established jointly with the competent authorities of other Member States. The Commission may provide technical support, advice and tools for the establishment and operation of AI regulatory sandboxes. The obligation under the first subparagraph may also be fulfilled by participating in an existing sandbox in so far as that participation provides an equivalent level of national coverage for the participating Member States.\nAdditional AI regulatory sandboxes at regional or local level, or established jointly with the competent authorities of other Member States may also be established.\nThe European Data Protection Supervisor may also establish an AI regulatory sandbox for Union institutions, bodies, offices and agencies, and may exercise the roles and the tasks of national competent authorities in accordance with this Chapter.\nMember States shall ensure that the competent authorities referred to in paragraphs 1 and 2 allocate sufficient resources to comply with this Article effectively and in a timely manner. Where appropriate, national competent authorities shall cooperate with other relevant authorities, and may allow for the involvement of other actors within the AI ecosystem. This Article shall not affect other regulatory sandboxes established under Union or national law. Member States shall ensure an appropriate level of cooperation between the authorities supervising those other sandboxes and the national competent authorities.\nAI regulatory sandboxes established under paragraph 1 shall provide for a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market or put into service pursuant to a specific sandbox plan agreed between the providers or prospective providers and the competent authority. Such sandboxes may include testing in real world conditions supervised therein.\nCompetent authorities shall provide, as appropriate, guidance, supervision and support within the AI regulatory sandbox with a view to identifying risks, in particular to fundamental rights, health and safety, testing, mitigation measures, and their effectiveness in relation to the obligations and requirements of this Regulation and, where relevant, other Union and national law supervised within the sandbox.\nCompetent authorities shall provide providers and prospective providers participating in the AI regulatory sandbox with guidance on regulatory expectations and how to fulfil the requirements and obligations set out in this Regulation.\nUpon request of the provider or prospective provider of the AI system, the competent authority shall provide a written proof of the activities successfully carried out in the sandbox. The competent authority shall also provide an exit report detailing the activities carried out in the sandbox and the related results and learning outcomes. Providers may use such documentation to demonstrate their compliance with this Regulation through the conformity assessment process or relevant market surveillance activities. In this regard, the exit reports and the written proof provided by the national competent authority shall be taken positively into account by market surveillance authorities and notified bodies, with a view to accelerating conformity assessment procedures to a reasonable extent.\nSubject to the confidentiality provisions in Article 78, and with the agreement of the provider or prospective provider, the Commission and the Board shall be authorised to access the exit reports and shall take them into account, as appropriate, when exercising their tasks under this Regulation. If both the provider or prospective provider and the national competent authority explicitly agree, the exit report may be made publicly available through the single information platform referred to in this Article.\nThe establishment of AI regulatory sandboxes shall aim to contribute to the following objectives:\n(a)\nimproving legal certainty to achieve regulatory compliance with this Regulation or, where relevant, other applicable Union and national law;\n(b)\nsupporting the sharing of best practices through cooperation with the authorities involved in the AI regulatory sandbox;\n(c)\nfostering innovation and competitiveness and facilitating the development of an AI ecosystem;\n(d)\ncontributing to evidence-based regulatory learning;\n(e)\nfacilitating and accelerating access to the Union market for AI systems, in particular when provided by SMEs, including start-ups.\nNational competent authorities shall ensure that, to the extent the innovative AI systems involve the processing of personal data or otherwise fall under the supervisory remit of other national authorities or competent authorities providing or supporting access to data, the national data protection authorities and those other national or competent authorities are associated with the operation of the AI regulatory sandbox and involved in the supervision of those aspects to the extent of their respective tasks and powers.\nThe AI regulatory sandboxes shall not affect the supervisory or corrective powers of the competent authorities supervising the sandboxes, including at regional or local level. Any significant risks to health and safety and fundamental rights identified during the development and testing of such AI systems shall result in an adequate mitigation. National competent authorities shall have the power to temporarily or permanently suspend the testing process, or the participation in the sandbox if no effective mitigation is possible, and shall inform the AI Office of such decision. National competent authorities shall exercise their supervisory powers within the limits of the relevant law, using their discretionary powers when implementing legal provisions in respect of a specific AI regulatory sandbox project, with the objective of supporting innovation in AI in the Union.\nProviders and prospective providers participating in the AI regulatory sandbox shall remain liable under applicable Union and national liability law for any damage inflicted on third parties as a result of the experimentation taking place in the sandbox. However, provided that the prospective providers observe the specific plan and the terms and conditions for their participation and follow in good faith the guidance given by the national competent authority, no administrative fines shall be imposed by the authorities for infringements of this Regulation. Where other competent authorities responsible for other Union and national law were actively involved in the supervision of the AI system in the sandbox and provided guidance for compliance, no administrative fines shall be imposed regarding that law.\nThe AI regulatory sandboxes shall be designed and implemented in such a way that, where relevant, they facilitate cross-border cooperation between national competent authorities.\nNational competent authorities shall coordinate their activities and cooperate within the framework of the Board.\nNational competent authorities shall inform the AI Office and the Board of the establishment of a sandbox, and may ask them for support and guidance. The AI Office shall make publicly available a list of planned and existing sandboxes and keep it up to date in order to encourage more interaction in the AI regulatory sandboxes and cross-border cooperation.\nNational competent authorities shall submit annual reports to the AI Office and to the Board, from one year after the establishment of the AI regulatory sandbox and every year thereafter until its termination, and a final report. Those reports shall provide information on the progress and results of the implementation of those sandboxes, including best practices, incidents, lessons learnt and recommendations on their setup and, where relevant, on the application and possible revision of this Regulation, including its delegated and implementing acts, and on the application of other Union law supervised by the competent authorities within the sandbox. The national competent authorities shall make those annual reports or abstracts thereof available to the public, online. The Commission shall, where appropriate, take the annual reports into account when exercising its tasks under this Regulation.\nThe Commission shall develop a single and dedicated interface containing all relevant information related to AI regulatory sandboxes to allow stakeholders to interact with AI regulatory sandboxes and to raise enquiries with competent authorities, and to seek non-binding guidance on the conformity of innovative products, services, business models embedding AI technologies, in accordance with Article 62(1), point (c). The Commission shall proactively coordinate with national competent authorities, where relevant.\nArticle 58 Detailed arrangements for, and functioning of, AI regulatory sandboxes In order to avoid fragmentation across the Union, the Commission shall adopt implementing acts specifying the detailed arrangements for the establishment, development, implementation, operation and supervision of the AI regulatory sandboxes. The implementing acts shall include common principles on the following issues: (a)\neligibility and selection criteria for participation in the AI regulatory sandbox;\n(b)\nprocedures for the application, participation, monitoring, exiting from and termination of the AI regulatory sandbox, including the sandbox plan and the exit report;\n(c)\nthe terms and conditions applicable to the participants.\nThose implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nThe implementing acts referred to in paragraph 1 shall ensure: (a)\nthat AI regulatory sandboxes are open to any applying provider or prospective provider of an AI system who fulfils eligibility and selection criteria, which shall be transparent and fair, and that national competent authorities inform applicants of their decision within three months of the application;\n(b)\nthat AI regulatory sandboxes allow broad and equal access and keep up with demand for participation; providers and prospective providers may also submit applications in partnerships with deployers and other relevant third parties;\n(c)\nthat the detailed arrangements for, and conditions concerning AI regulatory sandboxes support, to the best extent possible, flexibility for national competent authorities to establish and operate their AI regulatory sandboxes;\n(d)\nthat access to the AI regulatory sandboxes is free of charge for SMEs, including start-ups, without prejudice to exceptional costs that national competent authorities may recover in a fair and proportionate manner;\n(e)\nthat they facilitate providers and prospective providers, by means of the learning outcomes of the AI regulatory sandboxes, in complying with conformity assessment obligations under this Regulation and the voluntary application of the codes of conduct referred to in Article 95;\n(f)\nthat AI regulatory sandboxes facilitate the involvement of other relevant actors within the AI ecosystem, such as notified bodies and standardisation organisations, SMEs, including start-ups, enterprises, innovators, testing and experimentation facilities, research and experimentation labs and European Digital Innovation Hubs, centres of excellence, individual researchers, in order to allow and facilitate cooperation with the public and private sectors;\n(g)\nthat procedures, processes and administrative requirements for application, selection, participation and exiting the AI regulatory sandbox are simple, easily intelligible, and clearly communicated in order to facilitate the participation of SMEs, including start-ups, with limited legal and administrative capacities and are streamlined across the Union, in order to avoid fragmentation and that participation in an AI regulatory sandbox established by a Member State, or by the European Data Protection Supervisor is mutually and uniformly recognised and carries the same legal effects across the Union;\n(h)\nthat participation in the AI regulatory sandbox is limited to a period that is appropriate to the complexity and scale of the project and that may be extended by the national competent authority;\n(i)\nthat AI regulatory sandboxes facilitate the development of tools and infrastructure for testing, benchmarking, assessing and explaining dimensions of AI systems relevant for regulatory learning, such as accuracy, robustness and cybersecurity, as well as measures to mitigate risks to fundamental rights and society at large.\nProspective providers in the AI regulatory sandboxes, in particular SMEs and start-ups, shall be directed, where relevant, to pre-deployment services such as guidance on the implementation of this Regulation, to other value-adding services such as help with standardisation documents and certification, testing and experimentation facilities, European Digital Innovation Hubs and centres of excellence.\nWhere national competent authorities consider authorising testing in real world conditions supervised within the framework of an AI regulatory sandbox to be established under this Article, they shall specifically agree the terms and conditions of such testing and, in particular, the appropriate safeguards with the participants, with a view to protecting fundamental rights, health and safety. Where appropriate, they shall cooperate with other national competent authorities with a view to ensuring consistent practices across the Union.\nArticle 59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox\nIn the AI regulatory sandbox, personal data lawfully collected for other purposes may be processed solely for the purpose of developing, training and testing certain AI systems in the sandbox when all of the following conditions are met: (a)\nAI systems shall be developed for safeguarding substantial public interest by a public authority or another natural or legal person and in one or more of the following areas:\n(i)\npublic safety and public health, including disease detection, diagnosis prevention, control and treatment and improvement of health care systems;\n(ii)\na high level of protection and improvement of the quality of the environment, protection of biodiversity, protection against pollution, green transition measures, climate change mitigation and adaptation measures;\n(iii)\nenergy sustainability;\n(iv)\nsafety and resilience of transport systems and mobility, critical infrastructure and networks;\n(v)\nefficiency and quality of public administration and public services;\n(b)\nthe data processed are necessary for complying with one or more of the requirements referred to in Chapter III, Section 2 where those requirements cannot effectively be fulfilled by processing anonymised, synthetic or other non-personal data;\n(c)\nthere are effective monitoring mechanisms to identify if any high risks to the rights and freedoms of the data subjects, as referred to in Article 35 of Regulation (EU) 2016/679 and in Article 39 of Regulation (EU) 2018/1725, may arise during the sandbox experimentation, as well as response mechanisms to promptly mitigate those risks and, where necessary, stop the processing;\n(d)\nany personal data to be processed in the context of the sandbox are in a functionally separate, isolated and protected data processing environment under the control of the prospective provider and only authorised persons have access to those data;\n(e)\nproviders can further share the originally collected data only in accordance with Union data protection law; any personal data created in the sandbox cannot be shared outside the sandbox;\n(f)\nany processing of personal data in the context of the sandbox neither leads to measures or decisions affecting the data subjects nor does it affect the application of their rights laid down in Union law on the protection of personal data;\n(g)\nany personal data processed in the context of the sandbox are protected by means of appropriate technical and organisational measures and deleted once the participation in the sandbox has terminated or the personal data has reached the end of its retention period;\n(h)\nthe logs of the processing of personal data in the context of the sandbox are kept for the duration of the participation in the sandbox, unless provided otherwise by Union or national law;\n(i)\na complete and detailed description of the process and rationale behind the training, testing and validation of the AI system is kept together with the testing results as part of the technical documentation referred to in Annex IV;\n(j)\na short summary of the AI project developed in the sandbox, its objectives and expected results is published on the website of the competent authorities; this obligation shall not cover sensitive operational data in relation to the activities of law enforcement, border control, immigration or asylum authorities.\nFor the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security, under the control and responsibility of law enforcement authorities, the processing of personal data in AI regulatory sandboxes shall be based on a specific Union or national law and subject to the same cumulative conditions as referred to in paragraph 1.\nParagraph 1 is without prejudice to Union or national law which excludes processing of personal data for other purposes than those explicitly mentioned in that law, as well as to Union or national law laying down the basis for the processing of personal data which is necessary for the purpose of developing, testing or training of innovative AI systems or any other legal basis, in compliance with Union law on the protection of personal data.\nArticle 60 Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes may be conducted by providers or prospective providers of high-risk AI systems listed in Annex III, in accordance with this Article and the real-world testing plan referred to in this Article, without prejudice to the prohibitions under Article 5. The Commission shall, by means of implementing acts, specify the detailed elements of the real-world testing plan. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nThis paragraph shall be without prejudice to Union or national law on the testing in real world conditions of high-risk AI systems related to products covered by Union harmonisation legislation listed in Annex I.\nProviders or prospective providers may conduct testing of high-risk AI systems referred to in Annex III in real world conditions at any time before the placing on the market or the putting into service of the AI system on their own or in partnership with one or more deployers or prospective deployers.\nThe testing of high-risk AI systems in real world conditions under this Article shall be without prejudice to any ethical review that is required by Union or national law.\nProviders or prospective providers may conduct the testing in real world conditions only where all of the following conditions are met:\n(a)\nthe provider or prospective provider has drawn up a real-world testing plan and submitted it to the market surveillance authority in the Member State where the testing in real world conditions is to be conducted;\n(b)\nthe market surveillance authority in the Member State where the testing in real world conditions is to be conducted has approved the testing in real world conditions and the real-world testing plan; where the market surveillance authority has not provided an answer within 30 days, the testing in real world conditions and the real-world testing plan shall be understood to have been approved; where national law does not provide for a tacit approval, the testing in real world conditions shall remain subject to an authorisation;\n(c)\nthe provider or prospective provider, with the exception of providers or prospective providers of high-risk AI systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, and high-risk AI systems referred to in point 2 of Annex III has registered the testing in real world conditions in accordance with Article 71(4) with a Union-wide unique single identification number and with the information specified in Annex IX; the provider or prospective provider of high-risk AI systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, has registered the testing in real-world conditions in the secure non-public section of the EU database according to Article 49(4), point (d), with a Union-wide unique single identification number and with the information specified therein; the provider or prospective provider of high-risk AI systems referred to in point 2 of Annex III has registered the testing in real-world conditions in accordance with Article 49(5);\n(d)\nthe provider or prospective provider conducting the testing in real world conditions is established in the Union or has appointed a legal representative who is established in the Union;\n(e)\ndata collected and processed for the purpose of the testing in real world conditions shall be transferred to third countries only provided that appropriate and applicable safeguards under Union law are implemented;\n(f)\nthe testing in real world conditions does not last longer than necessary to achieve its objectives and in any case not longer than six months, which may be extended for an additional period of six months, subject to prior notification by the provider or prospective provider to the market surveillance authority, accompanied by an explanation of the need for such an extension;\n(g)\nthe subjects of the testing in real world conditions who are persons belonging to vulnerable groups due to their age or disability, are appropriately protected;\n(h)\nwhere a provider or prospective provider organises the testing in real world conditions in cooperation with one or more deployers or prospective deployers, the latter have been informed of all aspects of the testing that are relevant to their decision to participate, and given the relevant instructions for use of the AI system referred to in Article 13; the provider or prospective provider and the deployer or prospective deployer shall conclude an agreement specifying their roles and responsibilities with a view to ensuring compliance with the provisions for testing in real world conditions under this Regulation and under other applicable Union and national law;\n(i)\nthe subjects of the testing in real world conditions have given informed consent in accordance with Article 61, or in the case of law enforcement, where the seeking of informed consent would prevent the AI system from being tested, the testing itself and the outcome of the testing in the real world conditions shall not have any negative effect on the subjects, and their personal data shall be deleted after the test is performed;\n(j)\nthe testing in real world conditions is effectively overseen by the provider or prospective provider, as well as by deployers or prospective deployers through persons who are suitably qualified in the relevant field and have the necessary capacity, training and authority to perform their tasks;\n(k)\nthe predictions, recommendations or decisions of the AI system can be effectively reversed and disregarded.\nAny subjects of the testing in real world conditions, or their legally designated representative, as appropriate, may, without any resulting detriment and without having to provide any justification, withdraw from the testing at any time by revoking their informed consent and may request the immediate and permanent deletion of their personal data. The withdrawal of the informed consent shall not affect the activities already carried out.\nIn accordance with Article 75, Member States shall confer on their market surveillance authorities the powers of requiring providers and prospective providers to provide information, of carrying out unannounced remote or on-site inspections, and of performing checks on the conduct of the testing in real world conditions and the related high-risk AI systems. Market surveillance authorities shall use those powers to ensure the safe development of testing in real world conditions.\nAny serious incident identified in the course of the testing in real world conditions shall be reported to the national market surveillance authority in accordance with Article 73. The provider or prospective provider shall adopt immediate mitigation measures or, failing that, shall suspend the testing in real world conditions until such mitigation takes place, or otherwise terminate it. The provider or prospective provider shall establish a procedure for the prompt recall of the AI system upon such termination of the testing in real world conditions.\nProviders or prospective providers shall notify the national market surveillance authority in the Member State where the testing in real world conditions is to be conducted of the suspension or termination of the testing in real world conditions and of the final outcomes.\nThe provider or prospective provider shall be liable under applicable Union and national liability law for any damage caused in the course of their testing in real world conditions.\nArticle 61 Informed consent to participate in testing in real world conditions outside AI regulatory sandboxes\nFor the purpose of testing in real world conditions under Article 60, freely-given informed consent shall be obtained from the subjects of testing prior to their participation in such testing and after their having been duly informed with concise, clear, relevant, and understandable information regarding: (a)\nthe nature and objectives of the testing in real world conditions and the possible inconvenience that may be linked to their participation;\n(b)\nthe conditions under which the testing in real world conditions is to be conducted, including the expected duration of the subject or subjects’ participation;\n(c)\ntheir rights, and the guarantees regarding their participation, in particular their right to refuse to participate in, and the right to withdraw from, testing in real world conditions at any time without any resulting detriment and without having to provide any justification;\n(d)\nthe arrangements for requesting the reversal or the disregarding of the predictions, recommendations or decisions of the AI system;\n(e)\nthe Union-wide unique single identification number of the testing in real world conditions in accordance with Article 60(4) point (c), and the contact details of the provider or its legal representative from whom further information can be obtained.\nThe informed consent shall be dated and documented and a copy shall be given to the subjects of testing or their legal representative. Article 62 Measures for providers and deployers, in particular SMEs, including start-ups Member States shall undertake the following actions: (a)\nprovide SMEs, including start-ups, having a registered office or a branch in the Union, with priority access to the AI regulatory sandboxes, to the extent that they fulfil the eligibility conditions and selection criteria; the priority access shall not preclude other SMEs, including start-ups, other than those referred to in this paragraph from access to the AI regulatory sandbox, provided that they also fulfil the eligibility conditions and selection criteria;\n(b)\norganise specific awareness raising and training activities on the application of this Regulation tailored to the needs of SMEs including start-ups, deployers and, as appropriate, local public authorities;\n(c)\nutilise existing dedicated channels and where appropriate, establish new ones for communication with SMEs including start-ups, deployers, other innovators and, as appropriate, local public authorities to provide advice and respond to queries about the implementation of this Regulation, including as regards participation in AI regulatory sandboxes;\n(d)\nfacilitate the participation of SMEs and other relevant stakeholders in the standardisation development process.\nThe specific interests and needs of the SME providers, including start-ups, shall be taken into account when setting the fees for conformity assessment under Article 43, reducing those fees proportionately to their size, market size and other relevant indicators.\nThe AI Office shall undertake the following actions:\n(a)\nprovide standardised templates for areas covered by this Regulation, as specified by the Board in its request;\n(b)\ndevelop and maintain a single information platform providing easy to use information in relation to this Regulation for all operators across the Union;\n(c)\norganise appropriate communication campaigns to raise awareness about the obligations arising from this Regulation;\n(d)\nevaluate and promote the convergence of best practices in public procurement procedures in relation to AI systems.\nArticle 63 Derogations for specific operators Microenterprises within the meaning of Recommendation 2003/361/EC may comply with certain elements of the quality management system required by Article 17 of this Regulation in a simplified manner, provided that they do not have partner enterprises or linked enterprises within the meaning of that Recommendation. For that purpose, the Commission shall develop guidelines on the elements of the quality management system which may be complied with in a simplified manner considering the needs of microenterprises, without affecting the level of protection or the need for compliance with the requirements in respect of high-risk AI systems.\nParagraph 1 of this Article shall not be interpreted as exempting those operators from fulfilling any other requirements or obligations laid down in this Regulation, including those established in Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73.\nCHAPTER VII GOVERNANCE\nSECTION 1\nGovernance at Union level\nArticle 64 AI Office The Commission shall develop Union expertise and capabilities in the field of AI through the AI Office.\nMember States shall facilitate the tasks entrusted to the AI Office, as reflected in this Regulation.\nArticle 65 Establishment and structure of the European Artificial Intelligence Board A European Artificial Intelligence Board (the ‘Board’) is hereby established.\nThe Board shall be composed of one representative per Member State. The European Data Protection Supervisor shall participate as observer. The AI Office shall also attend the Board’s meetings, without taking part in the votes. Other national and Union authorities, bodies or experts may be invited to the meetings by the Board on a case by case basis, where the issues discussed are of relevance for them.\nEach representative shall be designated by their Member State for a period of three years, renewable once.\nMember States shall ensure that their representatives on the Board:\n(a)\nhave the relevant competences and powers in their Member State so as to contribute actively to the achievement of the Board’s tasks referred to in Article 66;\n(b)\nare designated as a single contact point vis-à-vis the Board and, where appropriate, taking into account Member States’ needs, as a single contact point for stakeholders;\n(c)\nare empowered to facilitate consistency and coordination between national competent authorities in their Member State as regards the implementation of this Regulation, including through the collection of relevant data and information for the purpose of fulfilling their tasks on the Board.\nThe designated representatives of the Member States shall adopt the Board’s rules of procedure by a two-thirds majority. The rules of procedure shall, in particular, lay down procedures for the selection process, the duration of the mandate of, and specifications of the tasks of, the Chair, detailed arrangements for voting, and the organisation of the Board’s activities and those of its sub-groups.\nThe Board shall establish two standing sub-groups to provide a platform for cooperation and exchange among market surveillance authorities and notifying authorities about issues related to market surveillance and notified bodies respectively.\nThe standing sub-group for market surveillance should act as the administrative cooperation group (ADCO) for this Regulation within the meaning of Article 30 of Regulation (EU) 2019/1020.\nThe Board may establish other standing or temporary sub-groups as appropriate for the purpose of examining specific issues. Where appropriate, representatives of the advisory forum referred to in Article 67 may be invited to such sub-groups or to specific meetings of those subgroups as observers.\nThe Board shall be organised and operated so as to safeguard the objectivity and impartiality of its activities.\nThe Board shall be chaired by one of the representatives of the Member States. The AI Office shall provide the secretariat for the Board, convene the meetings upon request of the Chair, and prepare the agenda in accordance with the tasks of the Board pursuant to this Regulation and its rules of procedure.\nArticle 66 Tasks of the Board The Board shall advise and assist the Commission and the Member States in order to facilitate the consistent and effective application of this Regulation. To that end, the Board may in particular:\n(a)\ncontribute to the coordination among national competent authorities responsible for the application of this Regulation and, in cooperation with and subject to the agreement of the market surveillance authorities concerned, support joint activities of market surveillance authorities referred to in Article 74(11);\n(b)\ncollect and share technical and regulatory expertise and best practices among Member States;\n(c)\nprovide advice on the implementation of this Regulation, in particular as regards the enforcement of rules on general-purpose AI models;\n(d)\ncontribute to the harmonisation of administrative practices in the Member States, including in relation to the derogation from the conformity assessment procedures referred to in Article 46, the functioning of AI regulatory sandboxes, and testing in real world conditions referred to in Articles 57, 59 and 60;\n(e)\nat the request of the Commission or on its own initiative, issue recommendations and written opinions on any relevant matters related to the implementation of this Regulation and to its consistent and effective application, including:\n(i)\non the development and application of codes of conduct and codes of practice pursuant to this Regulation, as well as of the Commission’s guidelines;\n(ii)\nthe evaluation and review of this Regulation pursuant to Article 112, including as regards the serious incident reports referred to in Article 73, and the functioning of the EU database referred to in Article 71, the preparation of the delegated or implementing acts, and as regards possible alignments of this Regulation with the Union harmonisation legislation listed in Annex I;\n(iii)\non technical specifications or existing standards regarding the requirements set out in Chapter III, Section 2;\n(iv)\non the use of harmonised standards or common specifications referred to in Articles 40 and 41;\n(v)\ntrends, such as European global competitiveness in AI, the uptake of AI in the Union, and the development of digital skills;\n(vi)\ntrends on the evolving typology of AI value chains, in particular on the resulting implications in terms of accountability;\n(vii)\non the potential need for amendment to Annex III in accordance with Article 7, and on the potential need for possible revision of Article 5 pursuant to Article 112, taking into account relevant available evidence and the latest developments in technology;\n(f)\nsupport the Commission in promoting AI literacy, public awareness and understanding of the benefits, risks, safeguards and rights and obligations in relation to the use of AI systems;\n(g)\nfacilitate the development of common criteria and a shared understanding among market operators and competent authorities of the relevant concepts provided for in this Regulation, including by contributing to the development of benchmarks;\n(h)\ncooperate, as appropriate, with other Union institutions, bodies, offices and agencies, as well as relevant Union expert groups and networks, in particular in the fields of product safety, cybersecurity, competition, digital and media services, financial services, consumer protection, data and fundamental rights protection;\n(i)\ncontribute to effective cooperation with the competent authorities of third countries and with international organisations;\n(j)\nassist national competent authorities and the Commission in developing the organisational and technical expertise required for the implementation of this Regulation, including by contributing to the assessment of training needs for staff of Member States involved in implementing this Regulation;\n(k)\nassist the AI Office in supporting national competent authorities in the establishment and development of AI regulatory sandboxes, and facilitate cooperation and information-sharing among AI regulatory sandboxes;\n(l)\ncontribute to, and provide relevant advice on, the development of guidance documents;\n(m)\nadvise the Commission in relation to international matters on AI;\n(n)\nprovide opinions to the Commission on the qualified alerts regarding general-purpose AI models;\n(o)\nreceive opinions by the Member States on qualified alerts regarding general-purpose AI models, and on national experiences and practices on the monitoring and enforcement of AI systems, in particular systems integrating the general-purpose AI models.\nArticle 67 Advisory forum An advisory forum shall be established to provide technical expertise and advise the Board and the Commission, and to contribute to their tasks under this Regulation.\nThe membership of the advisory forum shall represent a balanced selection of stakeholders, including industry, start-ups, SMEs, civil society and academia. The membership of the advisory forum shall be balanced with regard to commercial and non-commercial interests and, within the category of commercial interests, with regard to SMEs and other undertakings.\nThe Commission shall appoint the members of the advisory forum, in accordance with the criteria set out in paragraph 2, from amongst stakeholders with recognised expertise in the field of AI.\nThe term of office of the members of the advisory forum shall be two years, which may be extended by up to no more than four years.\nThe Fundamental Rights Agency, ENISA, the European Committee for Standardization (CEN), the European Committee for Electrotechnical Standardization (CENELEC), and the European Telecommunications Standards Institute (ETSI) shall be permanent members of the advisory forum.\nThe advisory forum shall draw up its rules of procedure. It shall elect two co-chairs from among its members, in accordance with criteria set out in paragraph 2. The term of office of the co-chairs shall be two years, renewable once.\nThe advisory forum shall hold meetings at least twice a year. The advisory forum may invite experts and other stakeholders to its meetings.\nThe advisory forum may prepare opinions, recommendations and written contributions at the request of the Board or the Commission.\nThe advisory forum may establish standing or temporary sub-groups as appropriate for the purpose of examining specific questions related to the objectives of this Regulation.\nThe advisory forum shall prepare an annual report on its activities. That report shall be made publicly available.\nArticle 68 Scientific panel of independent experts The Commission shall, by means of an implementing act, make provisions on the establishment of a scientific panel of independent experts (the ‘scientific panel’) intended to support the enforcement activities under this Regulation. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nThe scientific panel shall consist of experts selected by the Commission on the basis of up-to-date scientific or technical expertise in the field of AI necessary for the tasks set out in paragraph 3, and shall be able to demonstrate meeting all of the following conditions:\n(a)\nhaving particular expertise and competence and scientific or technical expertise in the field of AI;\n(b)\nindependence from any provider of AI systems or general-purpose AI models;\n(c)\nan ability to carry out activities diligently, accurately and objectively.\nThe Commission, in consultation with the Board, shall determine the number of experts on the panel in accordance with the required needs and shall ensure fair gender and geographical representation.\nThe scientific panel shall advise and support the AI Office, in particular with regard to the following tasks: (a)\nsupporting the implementation and enforcement of this Regulation as regards general-purpose AI models and systems, in particular by:\n(i)\nalerting the AI Office of possible systemic risks at Union level of general-purpose AI models, in accordance with Article 90;\n(ii)\ncontributing to the development of tools and methodologies for evaluating capabilities of general-purpose AI models and systems, including through benchmarks;\n(iii)\nproviding advice on the classification of general-purpose AI models with systemic risk;\n(iv)\nproviding advice on the classification of various general-purpose AI models and systems;\n(v)\ncontributing to the development of tools and templates;\n(b)\nsupporting the work of market surveillance authorities, at their request;\n(c)\nsupporting cross-border market surveillance activities as referred to in Article 74(11), without prejudice to the powers of market surveillance authorities;\n(d)\nsupporting the AI Office in carrying out its duties in the context of the Union safeguard procedure pursuant to Article 81.\nThe experts on the scientific panel shall perform their tasks with impartiality and objectivity, and shall ensure the confidentiality of information and data obtained in carrying out their tasks and activities. They shall neither seek nor take instructions from anyone when exercising their tasks under paragraph 3. Each expert shall draw up a declaration of interests, which shall be made publicly available. The AI Office shall establish systems and procedures to actively manage and prevent potential conflicts of interest.\nThe implementing act referred to in paragraph 1 shall include provisions on the conditions, procedures and detailed arrangements for the scientific panel and its members to issue alerts, and to request the assistance of the AI Office for the performance of the tasks of the scientific panel.\nArticle 69 Access to the pool of experts by the Member States Member States may call upon experts of the scientific panel to support their enforcement activities under this Regulation.\nThe Member States may be required to pay fees for the advice and support provided by the experts. The structure and the level of fees as well as the scale and structure of recoverable costs shall be set out in the implementing act referred to in Article 68(1), taking into account the objectives of the adequate implementation of this Regulation, cost-effectiveness and the necessity of ensuring effective access to experts for all Member States.\nThe Commission shall facilitate timely access to the experts by the Member States, as needed, and ensure that the combination of support activities carried out by Union AI testing support pursuant to Article 84 and experts pursuant to this Article is efficiently organised and provides the best possible added value.\nSECTION 2\nNational competent authorities\nArticle 70 Designation of national competent authorities and single points of contact Each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of this Regulation. Those national competent authorities shall exercise their powers independently, impartially and without bias so as to safeguard the objectivity of their activities and tasks, and to ensure the application and implementation of this Regulation. The members of those authorities shall refrain from any action incompatible with their duties. Provided that those principles are observed, such activities and tasks may be performed by one or more designated authorities, in accordance with the organisational needs of the Member State.\nMember States shall communicate to the Commission the identity of the notifying authorities and the market surveillance authorities and the tasks of those authorities, as well as any subsequent changes thereto. Member States shall make publicly available information on how competent authorities and single points of contact can be contacted, through electronic communication means by 2 August 2025. Member States shall designate a market surveillance authority to act as the single point of contact for this Regulation, and shall notify the Commission of the identity of the single point of contact. The Commission shall make a list of the single points of contact publicly available.\nMember States shall ensure that their national competent authorities are provided with adequate technical, financial and human resources, and with infrastructure to fulfil their tasks effectively under this Regulation. In particular, the national competent authorities shall have a sufficient number of personnel permanently available whose competences and expertise shall include an in-depth understanding of AI technologies, data and data computing, personal data protection, cybersecurity, fundamental rights, health and safety risks and knowledge of existing standards and legal requirements. Member States shall assess and, if necessary, update competence and resource requirements referred to in this paragraph on an annual basis.\nNational competent authorities shall take appropriate measures to ensure an adequate level of cybersecurity.\nWhen performing their tasks, the national competent authorities shall act in accordance with the confidentiality obligations set out in Article 78.\nBy 2 August 2025, and once every two years thereafter, Member States shall report to the Commission on the status of the financial and human resources of the national competent authorities, with an assessment of their adequacy. The Commission shall transmit that information to the Board for discussion and possible recommendations.\nThe Commission shall facilitate the exchange of experience between national competent authorities.\nNational competent authorities may provide guidance and advice on the implementation of this Regulation, in particular to SMEs including start-ups, taking into account the guidance and advice of the Board and the Commission, as appropriate. Whenever national competent authorities intend to provide guidance and advice with regard to an AI system in areas covered by other Union law, the national competent authorities under that Union law shall be consulted, as appropriate.\nWhere Union institutions, bodies, offices or agencies fall within the scope of this Regulation, the European Data Protection Supervisor shall act as the competent authority for their supervision.\nCHAPTER VIII EU DATABASE FOR HIGH-RISK AI SYSTEMS\nArticle 71 EU database for high-risk AI systems listed in Annex III The Commission shall, in collaboration with the Member States, set up and maintain an EU database containing information referred to in paragraphs 2 and 3 of this Article concerning high-risk AI systems referred to in Article 6(2) which are registered in accordance with Articles 49 and 60 and AI systems that are not considered as high-risk pursuant to Article 6(3) and which are registered in accordance with Article 6(4) and Article 49. When setting the functional specifications of such database, the Commission shall consult the relevant experts, and when updating the functional specifications of such database, the Commission shall consult the Board.\nThe data listed in Sections A and B of Annex VIII shall be entered into the EU database by the provider or, where applicable, by the authorised representative.\nThe data listed in Section C of Annex VIII shall be entered into the EU database by the deployer who is, or who acts on behalf of, a public authority, agency or body, in accordance with Article 49(3) and (4).\nWith the exception of the section referred to in Article 49(4) and Article 60(4), point (c), the information contained in the EU database registered in accordance with Article 49 shall be accessible and publicly available in a user-friendly manner. The information should be easily navigable and machine-readable. The information registered in accordance with Article 60 shall be accessible only to market surveillance authorities and the Commission, unless the prospective provider or provider has given consent for also making the information accessible the public.\nThe EU database shall contain personal data only in so far as necessary for collecting and processing information in accordance with this Regulation. That information shall include the names and contact details of natural persons who are responsible for registering the system and have the legal authority to represent the provider or the deployer, as applicable.\nThe Commission shall be the controller of the EU database. It shall make available to providers, prospective providers and deployers adequate technical and administrative support. The EU database shall comply with the applicable accessibility requirements.\nCHAPTER IX POST-MARKET MONITORING, INFORMATION SHARING AND MARKET SURVEILLANCE\nSECTION 1\nPost-market monitoring\nArticle 72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems\nProviders shall establish and document a post-market monitoring system in a manner that is proportionate to the nature of the AI technologies and the risks of the high-risk AI system.\nThe post-market monitoring system shall actively and systematically collect, document and analyse relevant data which may be provided by deployers or which may be collected through other sources on the performance of high-risk AI systems throughout their lifetime, and which allow the provider to evaluate the continuous compliance of AI systems with the requirements set out in Chapter III, Section 2. Where relevant, post-market monitoring shall include an analysis of the interaction with other AI systems. This obligation shall not cover sensitive operational data of deployers which are law-enforcement authorities.\nThe post-market monitoring system shall be based on a post-market monitoring plan. The post-market monitoring plan shall be part of the technical documentation referred to in Annex IV. The Commission shall adopt an implementing act laying down detailed provisions establishing a template for the post-market monitoring plan and the list of elements to be included in the plan by 2 February 2026. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nFor high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, where a post-market monitoring system and plan are already established under that legislation, in order to ensure consistency, avoid duplications and minimise additional burdens, providers shall have a choice of integrating, as appropriate, the necessary elements described in paragraphs 1, 2 and 3 using the template referred in paragraph 3 into systems and plans already existing under that legislation, provided that it achieves an equivalent level of protection.\nThe first subparagraph of this paragraph shall also apply to high-risk AI systems referred to in point 5 of Annex III placed on the market or put into service by financial institutions that are subject to requirements under Union financial services law regarding their internal governance, arrangements or processes.\nSECTION 2\nSharing of information on serious incidents\nArticle 73 Reporting of serious incidents Providers of high-risk AI systems placed on the Union market shall report any serious incident to the market surveillance authorities of the Member States where that incident occurred.\nThe report referred to in paragraph 1 shall be made immediately after the provider has established a causal link between the AI system and the serious incident or the reasonable likelihood of such a link, and, in any event, not later than 15 days after the provider or, where applicable, the deployer, becomes aware of the serious incident.\nThe period for the reporting referred to in the first subparagraph shall take account of the severity of the serious incident.\nNotwithstanding paragraph 2 of this Article, in the event of a widespread infringement or a serious incident as defined in Article 3, point (49)(b), the report referred to in paragraph 1 of this Article shall be provided immediately, and not later than two days after the provider or, where applicable, the deployer becomes aware of that incident.\nNotwithstanding paragraph 2, in the event of the death of a person, the report shall be provided immediately after the provider or the deployer has established, or as soon as it suspects, a causal relationship between the high-risk AI system and the serious incident, but not later than 10 days after the date on which the provider or, where applicable, the deployer becomes aware of the serious incident.\nWhere necessary to ensure timely reporting, the provider or, where applicable, the deployer, may submit an initial report that is incomplete, followed by a complete report.\nFollowing the reporting of a serious incident pursuant to paragraph 1, the provider shall, without delay, perform the necessary investigations in relation to the serious incident and the AI system concerned. This shall include a risk assessment of the incident, and corrective action.\nThe provider shall cooperate with the competent authorities, and where relevant with the notified body concerned, during the investigations referred to in the first subparagraph, and shall not perform any investigation which involves altering the AI system concerned in a way which may affect any subsequent evaluation of the causes of the incident, prior to informing the competent authorities of such action.\nUpon receiving a notification related to a serious incident referred to in Article 3, point (49)(c), the relevant market surveillance authority shall inform the national public authorities or bodies referred to in Article 77(1). The Commission shall develop dedicated guidance to facilitate compliance with the obligations set out in paragraph 1 of this Article. That guidance shall be issued by 2 August 2025, and shall be assessed regularly.\nThe market surveillance authority shall take appropriate measures, as provided for in Article 19 of Regulation (EU) 2019/1020, within seven days from the date it received the notification referred to in paragraph 1 of this Article, and shall follow the notification procedures as provided in that Regulation.\nFor high-risk AI systems referred to in Annex III that are placed on the market or put into service by providers that are subject to Union legislative instruments laying down reporting obligations equivalent to those set out in this Regulation, the notification of serious incidents shall be limited to those referred to in Article 3, point (49)(c).\nFor high-risk AI systems which are safety components of devices, or are themselves devices, covered by Regulations (EU) 2017/745 and (EU) 2017/746, the notification of serious incidents shall be limited to those referred to in Article 3, point (49)(c) of this Regulation, and shall be made to the national competent authority chosen for that purpose by the Member States where the incident occurred.\nNational competent authorities shall immediately notify the Commission of any serious incident, whether or not they have taken action on it, in accordance with Article 20 of Regulation (EU) 2019/1020.\nSECTION 3\nEnforcement\nArticle 74 Market surveillance and control of AI systems in the Union market Regulation (EU) 2019/1020 shall apply to AI systems covered by this Regulation. For the purposes of the effective enforcement of this Regulation: (a)\nany reference to an economic operator under Regulation (EU) 2019/1020 shall be understood as including all operators identified in Article 2(1) of this Regulation;\n(b)\nany reference to a product under Regulation (EU) 2019/1020 shall be understood as including all AI systems falling within the scope of this Regulation.\nAs part of their reporting obligations under Article 34(4) of Regulation (EU) 2019/1020, the market surveillance authorities shall report annually to the Commission and relevant national competition authorities any information identified in the course of market surveillance activities that may be of potential interest for the application of Union law on competition rules. They shall also annually report to the Commission about the use of prohibited practices that occurred during that year and about the measures taken.\nFor high-risk AI systems related to products covered by the Union harmonisation legislation listed in Section A of Annex I, the market surveillance authority for the purposes of this Regulation shall be the authority responsible for market surveillance activities designated under those legal acts.\nBy derogation from the first subparagraph, and in appropriate circumstances, Member States may designate another relevant authority to act as a market surveillance authority, provided they ensure coordination with the relevant sectoral market surveillance authorities responsible for the enforcement of the Union harmonisation legislation listed in Annex I.\nThe procedures referred to in Articles 79 to 83 of this Regulation shall not apply to AI systems related to products covered by the Union harmonisation legislation listed in section A of Annex I, where such legal acts already provide for procedures ensuring an equivalent level of protection and having the same objective. In such cases, the relevant sectoral procedures shall apply instead.\nWithout prejudice to the powers of market surveillance authorities under Article 14 of Regulation (EU) 2019/1020, for the purpose of ensuring the effective enforcement of this Regulation, market surveillance authorities may exercise the powers referred to in Article 14(4), points (d) and (j), of that Regulation remotely, as appropriate.\nFor high-risk AI systems placed on the market, put into service, or used by financial institutions regulated by Union financial services law, the market surveillance authority for the purposes of this Regulation shall be the relevant national authority responsible for the financial supervision of those institutions under that legislation in so far as the placing on the market, putting into service, or the use of the AI system is in direct connection with the provision of those financial services.\nBy way of derogation from paragraph 6, in appropriate circumstances, and provided that coordination is ensured, another relevant authority may be identified by the Member State as market surveillance authority for the purposes of this Regulation.\nNational market surveillance authorities supervising regulated credit institutions regulated under Directive 2013/36/EU, which are participating in the Single Supervisory Mechanism established by Regulation (EU) No 1024/2013, should report, without delay, to the European Central Bank any information identified in the course of their market surveillance activities that may be of potential interest for the prudential supervisory tasks of the European Central Bank specified in that Regulation.\nFor high-risk AI systems listed in point 1 of Annex III to this Regulation, in so far as the systems are used for law enforcement purposes, border management and justice and democracy, and for high-risk AI systems listed in points 6, 7 and 8 of Annex III to this Regulation, Member States shall designate as market surveillance authorities for the purposes of this Regulation either the competent data protection supervisory authorities under Regulation (EU) 2016/679 or Directive (EU) 2016/680, or any other authority designated pursuant to the same conditions laid down in Articles 41 to 44 of Directive (EU) 2016/680. Market surveillance activities shall in no way affect the independence of judicial authorities, or otherwise interfere with their activities when acting in their judicial capacity.\nWhere Union institutions, bodies, offices or agencies fall within the scope of this Regulation, the European Data Protection Supervisor shall act as their market surveillance authority, except in relation to the Court of Justice of the European Union acting in its judicial capacity.\nMember States shall facilitate coordination between market surveillance authorities designated under this Regulation and other relevant national authorities or bodies which supervise the application of Union harmonisation legislation listed in Annex I, or in other Union law, that might be relevant for the high-risk AI systems referred to in Annex III.\nMarket surveillance authorities and the Commission shall be able to propose joint activities, including joint investigations, to be conducted by either market surveillance authorities or market surveillance authorities jointly with the Commission, that have the aim of promoting compliance, identifying non-compliance, raising awareness or providing guidance in relation to this Regulation with respect to specific categories of high-risk AI systems that are found to present a serious risk across two or more Member States in accordance with Article 9 of Regulation (EU) 2019/1020. The AI Office shall provide coordination support for joint investigations.\nWithout prejudice to the powers provided for under Regulation (EU) 2019/1020, and where relevant and limited to what is necessary to fulfil their tasks, the market surveillance authorities shall be granted full access by providers to the documentation as well as the training, validation and testing data sets used for the development of high-risk AI systems, including, where appropriate and subject to security safeguards, through application programming interfaces (API) or other relevant technical means and tools enabling remote access.\nMarket surveillance authorities shall be granted access to the source code of the high-risk AI system upon a reasoned request and only when both of the following conditions are fulfilled:\n(a)\naccess to source code is necessary to assess the conformity of a high-risk AI system with the requirements set out in Chapter III, Section 2; and\n(b)\ntesting or auditing procedures and verifications based on the data and documentation provided by the provider have been exhausted or proved insufficient.\nAny information or documentation obtained by market surveillance authorities shall be treated in accordance with the confidentiality obligations set out in Article 78. Article 75 Mutual assistance, market surveillance and control of general-purpose AI systems Where an AI system is based on a general-purpose AI model, and the model and the system are developed by the same provider, the AI Office shall have powers to monitor and supervise compliance of that AI system with obligations under this Regulation. To carry out its monitoring and supervision tasks, the AI Office shall have all the powers of a market surveillance authority provided for in this Section and Regulation (EU) 2019/1020.\nWhere the relevant market surveillance authorities have sufficient reason to consider general-purpose AI systems that can be used directly by deployers for at least one purpose that is classified as high-risk pursuant to this Regulation to be non-compliant with the requirements laid down in this Regulation, they shall cooperate with the AI Office to carry out compliance evaluations, and shall inform the Board and other market surveillance authorities accordingly.\nWhere a market surveillance authority is unable to conclude its investigation of the high-risk AI system because of its inability to access certain information related to the general-purpose AI model despite having made all appropriate efforts to obtain that information, it may submit a reasoned request to the AI Office, by which access to that information shall be enforced. In that case, the AI Office shall supply to the applicant authority without delay, and in any event within 30 days, any information that the AI Office considers to be relevant in order to establish whether a high-risk AI system is non-compliant. Market surveillance authorities shall safeguard the confidentiality of the information that they obtain in accordance with Article 78 of this Regulation. The procedure provided for in Chapter VI of Regulation (EU) 2019/1020 shall apply mutatis mutandis.\nArticle 76 Supervision of testing in real world conditions by market surveillance authorities Market surveillance authorities shall have competences and powers to ensure that testing in real world conditions is in accordance with this Regulation.\nWhere testing in real world conditions is conducted for AI systems that are supervised within an AI regulatory sandbox under Article 58, the market surveillance authorities shall verify the compliance with Article 60 as part of their supervisory role for the AI regulatory sandbox. Those authorities may, as appropriate, allow the testing in real world conditions to be conducted by the provider or prospective provider, in derogation from the conditions set out in Article 60(4), points (f) and (g).\nWhere a market surveillance authority has been informed by the prospective provider, the provider or any third party of a serious incident or has other grounds for considering that the conditions set out in Articles 60 and 61 are not met, it may take either of the following decisions on its territory, as appropriate:\n(a)\nto suspend or terminate the testing in real world conditions;\n(b)\nto require the provider or prospective provider and the deployer or prospective deployer to modify any aspect of the testing in real world conditions.\nWhere a market surveillance authority has taken a decision referred to in paragraph 3 of this Article, or has issued an objection within the meaning of Article 60(4), point (b), the decision or the objection shall indicate the grounds therefor and how the provider or prospective provider can challenge the decision or objection.\nWhere applicable, where a market surveillance authority has taken a decision referred to in paragraph 3, it shall communicate the grounds therefor to the market surveillance authorities of other Member States in which the AI system has been tested in accordance with the testing plan.\nArticle 77 Powers of authorities protecting fundamental rights National public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights, including the right to non-discrimination, in relation to the use of high-risk AI systems referred to in Annex III shall have the power to request and access any documentation created or maintained under this Regulation in accessible language and format when access to that documentation is necessary for effectively fulfilling their mandates within the limits of their jurisdiction. The relevant public authority or body shall inform the market surveillance authority of the Member State concerned of any such request.\nBy 2 November 2024, each Member State shall identify the public authorities or bodies referred to in paragraph 1 and make a list of them publicly available. Member States shall notify the list to the Commission and to the other Member States, and shall keep the list up to date.\nWhere the documentation referred to in paragraph 1 is insufficient to ascertain whether an infringement of obligations under Union law protecting fundamental rights has occurred, the public authority or body referred to in paragraph 1 may make a reasoned request to the market surveillance authority, to organise testing of the high-risk AI system through technical means. The market surveillance authority shall organise the testing with the close involvement of the requesting public authority or body within a reasonable time following the request.\nAny information or documentation obtained by the national public authorities or bodies referred to in paragraph 1 of this Article pursuant to this Article shall be treated in accordance with the confidentiality obligations set out in Article 78.\nArticle 78 Confidentiality The Commission, market surveillance authorities and notified bodies and any other natural or legal person involved in the application of this Regulation shall, in accordance with Union or national law, respect the confidentiality of information and data obtained in carrying out their tasks and activities in such a manner as to protect, in particular: (a)\nthe intellectual property rights and confidential business information or trade secrets of a natural or legal person, including source code, except in the cases referred to in Article 5 of Directive (EU) 2016/943 of the European Parliament and of the Council (57);\n(b)\nthe effective implementation of this Regulation, in particular for the purposes of inspections, investigations or audits;\n(c)\npublic and national security interests;\n(d)\nthe conduct of criminal or administrative proceedings;\n(e)\ninformation classified pursuant to Union or national law.\nThe authorities involved in the application of this Regulation pursuant to paragraph 1 shall request only data that is strictly necessary for the assessment of the risk posed by AI systems and for the exercise of their powers in accordance with this Regulation and with Regulation (EU) 2019/1020. They shall put in place adequate and effective cybersecurity measures to protect the security and confidentiality of the information and data obtained, and shall delete the data collected as soon as it is no longer needed for the purpose for which it was obtained, in accordance with applicable Union or national law.\nWithout prejudice to paragraphs 1 and 2, information exchanged on a confidential basis between the national competent authorities or between national competent authorities and the Commission shall not be disclosed without prior consultation of the originating national competent authority and the deployer when high-risk AI systems referred to in point 1, 6 or 7 of Annex III are used by law enforcement, border control, immigration or asylum authorities and when such disclosure would jeopardise public and national security interests. This exchange of information shall not cover sensitive operational data in relation to the activities of law enforcement, border control, immigration or asylum authorities.\nWhen the law enforcement, immigration or asylum authorities are providers of high-risk AI systems referred to in point 1, 6 or 7 of Annex III, the technical documentation referred to in Annex IV shall remain within the premises of those authorities. Those authorities shall ensure that the market surveillance authorities referred to in Article 74(8) and (9), as applicable, can, upon request, immediately access the documentation or obtain a copy thereof. Only staff of the market surveillance authority holding the appropriate level of security clearance shall be allowed to access that documentation or any copy thereof.\nParagraphs 1, 2 and 3 shall not affect the rights or obligations of the Commission, Member States and their relevant authorities, as well as those of notified bodies, with regard to the exchange of information and the dissemination of warnings, including in the context of cross-border cooperation, nor shall they affect the obligations of the parties concerned to provide information under criminal law of the Member States.\nThe Commission and Member States may exchange, where necessary and in accordance with relevant provisions of international and trade agreements, confidential information with regulatory authorities of third countries with which they have concluded bilateral or multilateral confidentiality arrangements guaranteeing an adequate level of confidentiality.\nArticle 79 Procedure at national level for dealing with AI systems presenting a risk AI systems presenting a risk shall be understood as a ‘product presenting a risk’ as defined in Article 3, point 19 of Regulation (EU) 2019/1020, in so far as they present risks to the health or safety, or to fundamental rights, of persons.\nWhere the market surveillance authority of a Member State has sufficient reason to consider an AI system to present a risk as referred to in paragraph 1 of this Article, it shall carry out an evaluation of the AI system concerned in respect of its compliance with all the requirements and obligations laid down in this Regulation. Particular attention shall be given to AI systems presenting a risk to vulnerable groups. Where risks to fundamental rights are identified, the market surveillance authority shall also inform and fully cooperate with the relevant national public authorities or bodies referred to in Article 77(1). The relevant operators shall cooperate as necessary with the market surveillance authority and with the other national public authorities or bodies referred to in Article 77(1).\nWhere, in the course of that evaluation, the market surveillance authority or, where applicable the market surveillance authority in cooperation with the national public authority referred to in Article 77(1), finds that the AI system does not comply with the requirements and obligations laid down in this Regulation, it shall without undue delay require the relevant operator to take all appropriate corrective actions to bring the AI system into compliance, to withdraw the AI system from the market, or to recall it within a period the market surveillance authority may prescribe, and in any event within the shorter of 15 working days, or as provided for in the relevant Union harmonisation legislation.\nThe market surveillance authority shall inform the relevant notified body accordingly. Article 18 of Regulation (EU) 2019/1020 shall apply to the measures referred to in the second subparagraph of this paragraph.\nWhere the market surveillance authority considers that the non-compliance is not restricted to its national territory, it shall inform the Commission and the other Member States without undue delay of the results of the evaluation and of the actions which it has required the operator to take.\nThe operator shall ensure that all appropriate corrective action is taken in respect of all the AI systems concerned that it has made available on the Union market.\nWhere the operator of an AI system does not take adequate corrective action within the period referred to in paragraph 2, the market surveillance authority shall take all appropriate provisional measures to prohibit or restrict the AI system’s being made available on its national market or put into service, to withdraw the product or the standalone AI system from that market or to recall it. That authority shall without undue delay notify the Commission and the other Member States of those measures.\nThe notification referred to in paragraph 5 shall include all available details, in particular the information necessary for the identification of the non-compliant AI system, the origin of the AI system and the supply chain, the nature of the non-compliance alleged and the risk involved, the nature and duration of the national measures taken and the arguments put forward by the relevant operator. In particular, the market surveillance authorities shall indicate whether the non-compliance is due to one or more of the following:\n(a)\nnon-compliance with the prohibition of the AI practices referred to in Article 5;\n(b)\na failure of a high-risk AI system to meet requirements set out in Chapter III, Section 2;\n(c)\nshortcomings in the harmonised standards or common specifications referred to in Articles 40 and 41 conferring a presumption of conformity;\n(d)\nnon-compliance with Article 50.\nThe market surveillance authorities other than the market surveillance authority of the Member State initiating the procedure shall, without undue delay, inform the Commission and the other Member States of any measures adopted and of any additional information at their disposal relating to the non-compliance of the AI system concerned, and, in the event of disagreement with the notified national measure, of their objections.\nWhere, within three months of receipt of the notification referred to in paragraph 5 of this Article, no objection has been raised by either a market surveillance authority of a Member State or by the Commission in respect of a provisional measure taken by a market surveillance authority of another Member State, that measure shall be deemed justified. This shall be without prejudice to the procedural rights of the concerned operator in accordance with Article 18 of Regulation (EU) 2019/1020. The three-month period referred to in this paragraph shall be reduced to 30 days in the event of non-compliance with the prohibition of the AI practices referred to in Article 5 of this Regulation.\nThe market surveillance authorities shall ensure that appropriate restrictive measures are taken in respect of the product or the AI system concerned, such as withdrawal of the product or the AI system from their market, without undue delay.\nArticle 80 Procedure for dealing with AI systems classified by the provider as non-high-risk in application of Annex III\nWhere a market surveillance authority has sufficient reason to consider that an AI system classified by the provider as non-high-risk pursuant to Article 6(3) is indeed high-risk, the market surveillance authority shall carry out an evaluation of the AI system concerned in respect of its classification as a high-risk AI system based on the conditions set out in Article 6(3) and the Commission guidelines.\nWhere, in the course of that evaluation, the market surveillance authority finds that the AI system concerned is high-risk, it shall without undue delay require the relevant provider to take all necessary actions to bring the AI system into compliance with the requirements and obligations laid down in this Regulation, as well as take appropriate corrective action within a period the market surveillance authority may prescribe.\nWhere the market surveillance authority considers that the use of the AI system concerned is not restricted to its national territory, it shall inform the Commission and the other Member States without undue delay of the results of the evaluation and of the actions which it has required the provider to take.\nThe provider shall ensure that all necessary action is taken to bring the AI system into compliance with the requirements and obligations laid down in this Regulation. Where the provider of an AI system concerned does not bring the AI system into compliance with those requirements and obligations within the period referred to in paragraph 2 of this Article, the provider shall be subject to fines in accordance with Article 99.\nThe provider shall ensure that all appropriate corrective action is taken in respect of all the AI systems concerned that it has made available on the Union market.\nWhere the provider of the AI system concerned does not take adequate corrective action within the period referred to in paragraph 2 of this Article, Article 79(5) to (9) shall apply.\nWhere, in the course of the evaluation pursuant to paragraph 1 of this Article, the market surveillance authority establishes that the AI system was misclassified by the provider as non-high-risk in order to circumvent the application of requirements in Chapter III, Section 2, the provider shall be subject to fines in accordance with Article 99.\nIn exercising their power to monitor the application of this Article, and in accordance with Article 11 of Regulation (EU) 2019/1020, market surveillance authorities may perform appropriate checks, taking into account in particular information stored in the EU database referred to in Article 71 of this Regulation.\nArticle 81 Union safeguard procedure Where, within three months of receipt of the notification referred to in Article 79(5), or within 30 days in the case of non-compliance with the prohibition of the AI practices referred to in Article 5, objections are raised by the market surveillance authority of a Member State to a measure taken by another market surveillance authority, or where the Commission considers the measure to be contrary to Union law, the Commission shall without undue delay enter into consultation with the market surveillance authority of the relevant Member State and the operator or operators, and shall evaluate the national measure. On the basis of the results of that evaluation, the Commission shall, within six months, or within 60 days in the case of non-compliance with the prohibition of the AI practices referred to in Article 5, starting from the notification referred to in Article 79(5), decide whether the national measure is justified and shall notify its decision to the market surveillance authority of the Member State concerned. The Commission shall also inform all other market surveillance authorities of its decision.\nWhere the Commission considers the measure taken by the relevant Member State to be justified, all Member States shall ensure that they take appropriate restrictive measures in respect of the AI system concerned, such as requiring the withdrawal of the AI system from their market without undue delay, and shall inform the Commission accordingly. Where the Commission considers the national measure to be unjustified, the Member State concerned shall withdraw the measure and shall inform the Commission accordingly.\nWhere the national measure is considered justified and the non-compliance of the AI system is attributed to shortcomings in the harmonised standards or common specifications referred to in Articles 40 and 41 of this Regulation, the Commission shall apply the procedure provided for in Article 11 of Regulation (EU) No 1025/2012.\nArticle 82 Compliant AI systems which present a risk Where, having performed an evaluation under Article 79, after consulting the relevant national public authority referred to in Article 77(1), the market surveillance authority of a Member State finds that although a high-risk AI system complies with this Regulation, it nevertheless presents a risk to the health or safety of persons, to fundamental rights, or to other aspects of public interest protection, it shall require the relevant operator to take all appropriate measures to ensure that the AI system concerned, when placed on the market or put into service, no longer presents that risk without undue delay, within a period it may prescribe.\nThe provider or other relevant operator shall ensure that corrective action is taken in respect of all the AI systems concerned that it has made available on the Union market within the timeline prescribed by the market surveillance authority of the Member State referred to in paragraph 1.\nThe Member States shall immediately inform the Commission and the other Member States of a finding under paragraph 1. That information shall include all available details, in particular the data necessary for the identification of the AI system concerned, the origin and the supply chain of the AI system, the nature of the risk involved and the nature and duration of the national measures taken.\nThe Commission shall without undue delay enter into consultation with the Member States concerned and the relevant operators, and shall evaluate the national measures taken. On the basis of the results of that evaluation, the Commission shall decide whether the measure is justified and, where necessary, propose other appropriate measures.\nThe Commission shall immediately communicate its decision to the Member States concerned and to the relevant operators. It shall also inform the other Member States.\nArticle 83 Formal non-compliance Where the market surveillance authority of a Member State makes one of the following findings, it shall require the relevant provider to put an end to the non-compliance concerned, within a period it may prescribe: (a)\nthe CE marking has been affixed in violation of Article 48;\n(b)\nthe CE marking has not been affixed;\n(c)\nthe EU declaration of conformity referred to in Article 47 has not been drawn up;\n(d)\nthe EU declaration of conformity referred to in Article 47 has not been drawn up correctly;\n(e)\nthe registration in the EU database referred to in Article 71 has not been carried out;\n(f)\nwhere applicable, no authorised representative has been appointed;\n(g)\ntechnical documentation is not available.\nWhere the non-compliance referred to in paragraph 1 persists, the market surveillance authority of the Member State concerned shall take appropriate and proportionate measures to restrict or prohibit the high-risk AI system being made available on the market or to ensure that it is recalled or withdrawn from the market without delay. Article 84 Union AI testing support structures The Commission shall designate one or more Union AI testing support structures to perform the tasks listed under Article 21(6) of Regulation (EU) 2019/1020 in the area of AI.\nWithout prejudice to the tasks referred to in paragraph 1, Union AI testing support structures shall also provide independent technical or scientific advice at the request of the Board, the Commission, or of market surveillance authorities.\nSECTION 4\nRemedies\nArticle 85 Right to lodge a complaint with a market surveillance authority Without prejudice to other administrative or judicial remedies, any natural or legal person having grounds to consider that there has been an infringement of the provisions of this Regulation may submit complaints to the relevant market surveillance authority.\nIn accordance with Regulation (EU) 2019/1020, such complaints shall be taken into account for the purpose of conducting market surveillance activities, and shall be handled in line with the dedicated procedures established therefor by the market surveillance authorities.\nArticle 86 Right to explanation of individual decision-making Any affected person subject to a decision which is taken by the deployer on the basis of the output from a high-risk AI system listed in Annex III, with the exception of systems listed under point 2 thereof, and which produces legal effects or similarly significantly affects that person in a way that they consider to have an adverse impact on their health, safety or fundamental rights shall have the right to obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken.\nParagraph 1 shall not apply to the use of AI systems for which exceptions from, or restrictions to, the obligation under that paragraph follow from Union or national law in compliance with Union law.\nThis Article shall apply only to the extent that the right referred to in paragraph 1 is not otherwise provided for under Union law.\nArticle 87 Reporting of infringements and protection of reporting persons Directive (EU) 2019/1937 shall apply to the reporting of infringements of this Regulation and the protection of persons reporting such infringements.\nSECTION 5\nSupervision, investigation, enforcement and monitoring in respect of providers of general-purpose AI models\nArticle 88 Enforcement of the obligations of providers of general-purpose AI models The Commission shall have exclusive powers to supervise and enforce Chapter V, taking into account the procedural guarantees under Article 94. The Commission shall entrust the implementation of these tasks to the AI Office, without prejudice to the powers of organisation of the Commission and the division of competences between Member States and the Union based on the Treaties.\nWithout prejudice to Article 75(3), market surveillance authorities may request the Commission to exercise the powers laid down in this Section, where that is necessary and proportionate to assist with the fulfilment of their tasks under this Regulation.\nArticle 89 Monitoring actions For the purpose of carrying out the tasks assigned to it under this Section, the AI Office may take the necessary actions to monitor the effective implementation and compliance with this Regulation by providers of general-purpose AI models, including their adherence to approved codes of practice.\nDownstream providers shall have the right to lodge a complaint alleging an infringement of this Regulation. A complaint shall be duly reasoned and indicate at least:\n(a)\nthe point of contact of the provider of the general-purpose AI model concerned;\n(b)\na description of the relevant facts, the provisions of this Regulation concerned, and the reason why the downstream provider considers that the provider of the general-purpose AI model concerned infringed this Regulation;\n(c)\nany other information that the downstream provider that sent the request considers relevant, including, where appropriate, information gathered on its own initiative.\nArticle 90 Alerts of systemic risks by the scientific panel The scientific panel may provide a qualified alert to the AI Office where it has reason to suspect that: (a)\na general-purpose AI model poses concrete identifiable risk at Union level; or\n(b)\na general-purpose AI model meets the conditions referred to in Article 51.\nUpon such qualified alert, the Commission, through the AI Office and after having informed the Board, may exercise the powers laid down in this Section for the purpose of assessing the matter. The AI Office shall inform the Board of any measure according to Articles 91 to 94.\nA qualified alert shall be duly reasoned and indicate at least:\n(a)\nthe point of contact of the provider of the general-purpose AI model with systemic risk concerned;\n(b)\na description of the relevant facts and the reasons for the alert by the scientific panel;\n(c)\nany other information that the scientific panel considers to be relevant, including, where appropriate, information gathered on its own initiative.\nArticle 91 Power to request documentation and information The Commission may request the provider of the general-purpose AI model concerned to provide the documentation drawn up by the provider in accordance with Articles 53 and 55, or any additional information that is necessary for the purpose of assessing compliance of the provider with this Regulation.\nBefore sending the request for information, the AI Office may initiate a structured dialogue with the provider of the general-purpose AI model.\nUpon a duly substantiated request from the scientific panel, the Commission may issue a request for information to a provider of a general-purpose AI model, where the access to information is necessary and proportionate for the fulfilment of the tasks of the scientific panel under Article 68(2).\nThe request for information shall state the legal basis and the purpose of the request, specify what information is required, set a period within which the information is to be provided, and indicate the fines provided for in Article 101 for supplying incorrect, incomplete or misleading information.\nThe provider of the general-purpose AI model concerned, or its representative shall supply the information requested. In the case of legal persons, companies or firms, or where the provider has no legal personality, the persons authorised to represent them by law or by their statutes, shall supply the information requested on behalf of the provider of the general-purpose AI model concerned. Lawyers duly authorised to act may supply information on behalf of their clients. The clients shall nevertheless remain fully responsible if the information supplied is incomplete, incorrect or misleading.\nArticle 92 Power to conduct evaluations The AI Office, after consulting the Board, may conduct evaluations of the general-purpose AI model concerned: (a)\nto assess compliance of the provider with obligations under this Regulation, where the information gathered pursuant to Article 91 is insufficient; or\n(b)\nto investigate systemic risks at Union level of general-purpose AI models with systemic risk, in particular following a qualified alert from the scientific panel in accordance with Article 90(1), point (a).\nThe Commission may decide to appoint independent experts to carry out evaluations on its behalf, including from the scientific panel established pursuant to Article 68. Independent experts appointed for this task shall meet the criteria outlined in Article 68(2).\nFor the purposes of paragraph 1, the Commission may request access to the general-purpose AI model concerned through APIs or further appropriate technical means and tools, including source code.\nThe request for access shall state the legal basis, the purpose and reasons of the request and set the period within which the access is to be provided, and the fines provided for in Article 101 for failure to provide access.\nThe providers of the general-purpose AI model concerned or its representative shall supply the information requested. In the case of legal persons, companies or firms, or where the provider has no legal personality, the persons authorised to represent them by law or by their statutes, shall provide the access requested on behalf of the provider of the general-purpose AI model concerned.\nThe Commission shall adopt implementing acts setting out the detailed arrangements and the conditions for the evaluations, including the detailed arrangements for involving independent experts, and the procedure for the selection thereof. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nPrior to requesting access to the general-purpose AI model concerned, the AI Office may initiate a structured dialogue with the provider of the general-purpose AI model to gather more information on the internal testing of the model, internal safeguards for preventing systemic risks, and other internal procedures and measures the provider has taken to mitigate such risks.\nArticle 93 Power to request measures Where necessary and appropriate, the Commission may request providers to: (a)\ntake appropriate measures to comply with the obligations set out in Articles 53 and 54;\n(b)\nimplement mitigation measures, where the evaluation carried out in accordance with Article 92 has given rise to serious and substantiated concern of a systemic risk at Union level;\n(c)\nrestrict the making available on the market, withdraw or recall the model.\nBefore a measure is requested, the AI Office may initiate a structured dialogue with the provider of the general-purpose AI model.\nIf, during the structured dialogue referred to in paragraph 2, the provider of the general-purpose AI model with systemic risk offers commitments to implement mitigation measures to address a systemic risk at Union level, the Commission may, by decision, make those commitments binding and declare that there are no further grounds for action.\nArticle 94 Procedural rights of economic operators of the general-purpose AI model Article 18 of Regulation (EU) 2019/1020 shall apply mutatis mutandis to the providers of the general-purpose AI model, without prejudice to more specific procedural rights provided for in this Regulation.\nCHAPTER X CODES OF CONDUCT AND GUIDELINES\nArticle 95 Codes of conduct for voluntary application of specific requirements The AI Office and the Member States shall encourage and facilitate the drawing up of codes of conduct, including related governance mechanisms, intended to foster the voluntary application to AI systems, other than high-risk AI systems, of some or all of the requirements set out in Chapter III, Section 2 taking into account the available technical solutions and industry best practices allowing for the application of such requirements.\nThe AI Office and the Member States shall facilitate the drawing up of codes of conduct concerning the voluntary application, including by deployers, of specific requirements to all AI systems, on the basis of clear objectives and key performance indicators to measure the achievement of those objectives, including elements such as, but not limited to:\n(a)\napplicable elements provided for in Union ethical guidelines for trustworthy AI;\n(b)\nassessing and minimising the impact of AI systems on environmental sustainability, including as regards energy-efficient programming and techniques for the efficient design, training and use of AI;\n(c)\npromoting AI literacy, in particular that of persons dealing with the development, operation and use of AI;\n(d)\nfacilitating an inclusive and diverse design of AI systems, including through the establishment of inclusive and diverse development teams and the promotion of stakeholders’ participation in that process;\n(e)\nassessing and preventing the negative impact of AI systems on vulnerable persons or groups of vulnerable persons, including as regards accessibility for persons with a disability, as well as on gender equality.\nCodes of conduct may be drawn up by individual providers or deployers of AI systems or by organisations representing them or by both, including with the involvement of any interested stakeholders and their representative organisations, including civil society organisations and academia. Codes of conduct may cover one or more AI systems taking into account the similarity of the intended purpose of the relevant systems.\nThe AI Office and the Member States shall take into account the specific interests and needs of SMEs, including start-ups, when encouraging and facilitating the drawing up of codes of conduct.\nArticle 96 Guidelines from the Commission on the implementation of this Regulation The Commission shall develop guidelines on the practical implementation of this Regulation, and in particular on: (a)\nthe application of the requirements and obligations referred to in Articles 8 to 15 and in Article 25;\n(b)\nthe prohibited practices referred to in Article 5;\n(c)\nthe practical implementation of the provisions related to substantial modification;\n(d)\nthe practical implementation of transparency obligations laid down in Article 50;\n(e)\ndetailed information on the relationship of this Regulation with the Union harmonisation legislation listed in Annex I, as well as with other relevant Union law, including as regards consistency in their enforcement;\n(f)\nthe application of the definition of an AI system as set out in Article 3, point (1).\nWhen issuing such guidelines, the Commission shall pay particular attention to the needs of SMEs including start-ups, of local public authorities and of the sectors most likely to be affected by this Regulation.\nThe guidelines referred to in the first subparagraph of this paragraph shall take due account of the generally acknowledged state of the art on AI, as well as of relevant harmonised standards and common specifications that are referred to in Articles 40 and 41, or of those harmonised standards or technical specifications that are set out pursuant to Union harmonisation law.\nAt the request of the Member States or the AI Office, or on its own initiative, the Commission shall update guidelines previously adopted when deemed necessary. CHAPTER XI DELEGATION OF POWER AND COMMITTEE PROCEDURE\nArticle 97 Exercise of the delegation The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.\nThe power to adopt delegated acts referred to in Article 6(6) and (7), Article 7(1) and (3), Article 11(3), Article 43(5) and (6), Article 47(5), Article 51(3), Article 52(4) and Article 53(5) and (6) shall be conferred on the Commission for a period of five years from 1 August 2024. The Commission shall draw up a report in respect of the delegation of power not later than nine months before the end of the five-year period. The delegation of power shall be tacitly extended for periods of an identical duration, unless the European Parliament or the Council opposes such extension not later than three months before the end of each period.\nThe delegation of power referred to in Article 6(6) and (7), Article 7(1) and (3), Article 11(3), Article 43(5) and (6), Article 47(5), Article 51(3), Article 52(4) and Article 53(5) and (6) may be revoked at any time by the European Parliament or by the Council. A decision of revocation shall put an end to the delegation of power specified in that decision. It shall take effect the day following that of its publication in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.\nBefore adopting a delegated act, the Commission shall consult experts designated by each Member State in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making.\nAs soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council.\nAny delegated act adopted pursuant to Article 6(6) or (7), Article 7(1) or (3), Article 11(3), Article 43(5) or (6), Article 47(5), Article 51(3), Article 52(4) or Article 53(5) or (6) shall enter into force only if no objection has been expressed by either the European Parliament or the Council within a period of three months of notification of that act to the European Parliament and the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by three months at the initiative of the European Parliament or of the Council.\nArticle 98 Committee procedure The Commission shall be assisted by a committee. That committee shall be a committee within the meaning of Regulation (EU) No 182/2011.\nWhere reference is made to this paragraph, Article 5 of Regulation (EU) No 182/2011 shall apply.\nCHAPTER XII PENALTIES\nArticle 99 Penalties In accordance with the terms and conditions laid down in this Regulation, Member States shall lay down the rules on penalties and other enforcement measures, which may also include warnings and non-monetary measures, applicable to infringements of this Regulation by operators, and shall take all measures necessary to ensure that they are properly and effectively implemented, thereby taking into account the guidelines issued by the Commission pursuant to Article 96. The penalties provided for shall be effective, proportionate and dissuasive. They shall take into account the interests of SMEs, including start-ups, and their economic viability.\nThe Member States shall, without delay and at the latest by the date of entry into application, notify the Commission of the rules on penalties and of other enforcement measures referred to in paragraph 1, and shall notify it, without delay, of any subsequent amendment to them.\nNon-compliance with the prohibition of the AI practices referred to in Article 5 shall be subject to administrative fines of up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.\nNon-compliance with any of the following provisions related to operators or notified bodies, other than those laid down in Articles 5, shall be subject to administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher:\n(a)\nobligations of providers pursuant to Article 16;\n(b)\nobligations of authorised representatives pursuant to Article 22;\n(c)\nobligations of importers pursuant to Article 23;\n(d)\nobligations of distributors pursuant to Article 24;\n(e)\nobligations of deployers pursuant to Article 26;\n(f)\nrequirements and obligations of notified bodies pursuant to Article 31, Article 33(1), (3) and (4) or Article 34;\n(g)\ntransparency obligations for providers and deployers pursuant to Article 50.\nThe supply of incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request shall be subject to administrative fines of up to EUR 7 500 000 or, if the offender is an undertaking, up to 1 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.\nIn the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.\nWhen deciding whether to impose an administrative fine and when deciding on the amount of the administrative fine in each individual case, all relevant circumstances of the specific situation shall be taken into account and, as appropriate, regard shall be given to the following:\n(a)\nthe nature, gravity and duration of the infringement and of its consequences, taking into account the purpose of the AI system, as well as, where appropriate, the number of affected persons and the level of damage suffered by them;\n(b)\nwhether administrative fines have already been applied by other market surveillance authorities to the same operator for the same infringement;\n(c)\nwhether administrative fines have already been applied by other authorities to the same operator for infringements of other Union or national law, when such infringements result from the same activity or omission constituting a relevant infringement of this Regulation;\n(d)\nthe size, the annual turnover and market share of the operator committing the infringement;\n(e)\nany other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement;\n(f)\nthe degree of cooperation with the national competent authorities, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;\n(g)\nthe degree of responsibility of the operator taking into account the technical and organisational measures implemented by it;\n(h)\nthe manner in which the infringement became known to the national competent authorities, in particular whether, and if so to what extent, the operator notified the infringement;\n(i)\nthe intentional or negligent character of the infringement;\n(j)\nany action taken by the operator to mitigate the harm suffered by the affected persons.\nEach Member State shall lay down rules on to what extent administrative fines may be imposed on public authorities and bodies established in that Member State.\nDepending on the legal system of the Member States, the rules on administrative fines may be applied in such a manner that the fines are imposed by competent national courts or by other bodies, as applicable in those Member States. The application of such rules in those Member States shall have an equivalent effect.\nThe exercise of powers under this Article shall be subject to appropriate procedural safeguards in accordance with Union and national law, including effective judicial remedies and due process.\nMember States shall, on an annual basis, report to the Commission about the administrative fines they have issued during that year, in accordance with this Article, and about any related litigation or judicial proceedings.\nArticle 100 Administrative fines on Union institutions, bodies, offices and agencies The European Data Protection Supervisor may impose administrative fines on Union institutions, bodies, offices and agencies falling within the scope of this Regulation. When deciding whether to impose an administrative fine and when deciding on the amount of the administrative fine in each individual case, all relevant circumstances of the specific situation shall be taken into account and due regard shall be given to the following: (a)\nthe nature, gravity and duration of the infringement and of its consequences, taking into account the purpose of the AI system concerned, as well as, where appropriate, the number of affected persons and the level of damage suffered by them;\n(b)\nthe degree of responsibility of the Union institution, body, office or agency, taking into account technical and organisational measures implemented by them;\n(c)\nany action taken by the Union institution, body, office or agency to mitigate the damage suffered by affected persons;\n(d)\nthe degree of cooperation with the European Data Protection Supervisor in order to remedy the infringement and mitigate the possible adverse effects of the infringement, including compliance with any of the measures previously ordered by the European Data Protection Supervisor against the Union institution, body, office or agency concerned with regard to the same subject matter;\n(e)\nany similar previous infringements by the Union institution, body, office or agency;\n(f)\nthe manner in which the infringement became known to the European Data Protection Supervisor, in particular whether, and if so to what extent, the Union institution, body, office or agency notified the infringement;\n(g)\nthe annual budget of the Union institution, body, office or agency.\nNon-compliance with the prohibition of the AI practices referred to in Article 5 shall be subject to administrative fines of up to EUR 1 500 000.\nThe non-compliance of the AI system with any requirements or obligations under this Regulation, other than those laid down in Article 5, shall be subject to administrative fines of up to EUR 750 000.\nBefore taking decisions pursuant to this Article, the European Data Protection Supervisor shall give the Union institution, body, office or agency which is the subject of the proceedings conducted by the European Data Protection Supervisor the opportunity of being heard on the matter regarding the possible infringement. The European Data Protection Supervisor shall base his or her decisions only on elements and circumstances on which the parties concerned have been able to comment. Complainants, if any, shall be associated closely with the proceedings.\nThe rights of defence of the parties concerned shall be fully respected in the proceedings. They shall be entitled to have access to the European Data Protection Supervisor’s file, subject to the legitimate interest of individuals or undertakings in the protection of their personal data or business secrets.\nFunds collected by imposition of fines in this Article shall contribute to the general budget of the Union. The fines shall not affect the effective operation of the Union institution, body, office or agency fined.\nThe European Data Protection Supervisor shall, on an annual basis, notify the Commission of the administrative fines it has imposed pursuant to this Article and of any litigation or judicial proceedings it has initiated.\nArticle 101 Fines for providers of general-purpose AI models The Commission may impose on providers of general-purpose AI models fines not exceeding 3 % of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher., when the Commission finds that the provider intentionally or negligently: (a)\ninfringed the relevant provisions of this Regulation;\n(b)\nfailed to comply with a request for a document or for information pursuant to Article 91, or supplied incorrect, incomplete or misleading information;\n(c)\nfailed to comply with a measure requested under Article 93;\n(d)\nfailed to make available to the Commission access to the general-purpose AI model or general-purpose AI model with systemic risk with a view to conducting an evaluation pursuant to Article 92.\nIn fixing the amount of the fine or periodic penalty payment, regard shall be had to the nature, gravity and duration of the infringement, taking due account of the principles of proportionality and appropriateness. The Commission shall also into account commitments made in accordance with Article 93(3) or made in relevant codes of practice in accordance with Article 56.\nBefore adopting the decision pursuant to paragraph 1, the Commission shall communicate its preliminary findings to the provider of the general-purpose AI model and give it an opportunity to be heard.\nFines imposed in accordance with this Article shall be effective, proportionate and dissuasive.\nInformation on fines imposed under this Article shall also be communicated to the Board as appropriate.\nThe Court of Justice of the European Union shall have unlimited jurisdiction to review decisions of the Commission fixing a fine under this Article. It may cancel, reduce or increase the fine imposed.\nThe Commission shall adopt implementing acts containing detailed arrangements and procedural safeguards for proceedings in view of the possible adoption of decisions pursuant to paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nCHAPTER XIII FINAL PROVISIONS\nArticle 102 Amendment to Regulation (EC) No 300/2008 In Article 4(3) of Regulation (EC) No 300/2008, the following subparagraph is added:\n‘When adopting detailed measures related to technical specifications and procedures for approval and use of security equipment concerning Artificial Intelligence systems within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.\nArticle 103 Amendment to Regulation (EU) No 167/2013 In Article 17(5) of Regulation (EU) No 167/2013, the following subparagraph is added:\n‘When adopting delegated acts pursuant to the first subparagraph concerning artificial intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.\nArticle 104 Amendment to Regulation (EU) No 168/2013 In Article 22(5) of Regulation (EU) No 168/2013, the following subparagraph is added:\n‘When adopting delegated acts pursuant to the first subparagraph concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.\nArticle 105 Amendment to Directive 2014/90/EU In Article 8 of Directive 2014/90/EU, the following paragraph is added:\n‘5. For Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), when carrying out its activities pursuant to paragraph 1 and when adopting technical specifications and testing standards in accordance with paragraphs 2 and 3, the Commission shall take into account the requirements set out in Chapter III, Section 2, of that Regulation.\nArticle 106 Amendment to Directive (EU) 2016/797 In Article 5 of Directive (EU) 2016/797, the following paragraph is added:\n‘12. When adopting delegated acts pursuant to paragraph 1 and implementing acts pursuant to paragraph 11 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.\nArticle 107 Amendment to Regulation (EU) 2018/858 In Article 5 of Regulation (EU) 2018/858 the following paragraph is added:\n‘4. When adopting delegated acts pursuant to paragraph 3 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.\nArticle 108 Amendments to Regulation (EU) 2018/1139 Regulation (EU) 2018/1139 is amended as follows:\n(1)\nin Article 17, the following paragraph is added:\n‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.\n(*) Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (OJ L, 2024/1689, 12.7.2024, ELI: http://data.europa.eu/eli/reg/2024/1689/oj ).’;\u0026quot;\n(2)\nin Article 19, the following paragraph is added:\n‘4. When adopting delegated acts pursuant to paragraphs 1 and 2 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’\n;\n(3)\nin Article 43, the following paragraph is added:\n‘4. When adopting implementing acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’\n;\n(4)\nin Article 47, the following paragraph is added:\n‘3. When adopting delegated acts pursuant to paragraphs 1 and 2 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’\n;\n(5)\nin Article 57, the following subparagraph is added:\n‘When adopting those implementing acts concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’\n;\n(6)\nin Article 58, the following paragraph is added:\n‘3. When adopting delegated acts pursuant to paragraphs 1 and 2 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’.\nArticle 109 Amendment to Regulation (EU) 2019/2144 In Article 11 of Regulation (EU) 2019/2144, the following paragraph is added:\n‘3. When adopting the implementing acts pursuant to paragraph 2, concerning artificial intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.\nArticle 110 Amendment to Directive (EU) 2020/1828 In Annex I to Directive (EU) 2020/1828 of the European Parliament and of the Council (58), the following point is added:\n‘(68)\nRegulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (OJ L, 2024/1689, 12.7.2024, ELI: http://data.europa.eu/eli/reg/2024/1689/oj ).’.\nArticle 111 AI systems already placed on the market or put into service and general-purpose AI models already placed on the marked\nWithout prejudice to the application of Article 5 as referred to in Article 113(3), point (a), AI systems which are components of the large-scale IT systems established by the legal acts listed in Annex X that have been placed on the market or put into service before 2 August 2027 shall be brought into compliance with this Regulation by 31 December 2030. The requirements laid down in this Regulation shall be taken into account in the evaluation of each large-scale IT system established by the legal acts listed in Annex X to be undertaken as provided for in those legal acts and where those legal acts are replaced or amended.\nWithout prejudice to the application of Article 5 as referred to in Article 113(3), point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before 2 August 2026, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations of this Regulation by 2 August 2030.\nProviders of general-purpose AI models that have been placed on the market before 2 August 2025 shall take the necessary steps in order to comply with the obligations laid down in this Regulation by 2 August 2027.\nArticle 112 Evaluation and review The Commission shall assess the need for amendment of the list set out in Annex III and of the list of prohibited AI practices laid down in Article 5, once a year following the entry into force of this Regulation, and until the end of the period of the delegation of power laid down in Article 97. The Commission shall submit the findings of that assessment to the European Parliament and the Council.\nBy 2 August 2028 and every four years thereafter, the Commission shall evaluate and report to the European Parliament and to the Council on the following:\n(a)\nthe need for amendments extending existing area headings or adding new area headings in Annex III;\n(b)\namendments to the list of AI systems requiring additional transparency measures in Article 50;\n(c)\namendments enhancing the effectiveness of the supervision and governance system.\nBy 2 August 2029 and every four years thereafter, the Commission shall submit a report on the evaluation and review of this Regulation to the European Parliament and to the Council. The report shall include an assessment with regard to the structure of enforcement and the possible need for a Union agency to resolve any identified shortcomings. On the basis of the findings, that report shall, where appropriate, be accompanied by a proposal for amendment of this Regulation. The reports shall be made public.\nThe reports referred to in paragraph 2 shall pay specific attention to the following:\n(a)\nthe status of the financial, technical and human resources of the national competent authorities in order to effectively perform the tasks assigned to them under this Regulation;\n(b)\nthe state of penalties, in particular administrative fines as referred to in Article 99(1), applied by Member States for infringements of this Regulation;\n(c)\nadopted harmonised standards and common specifications developed to support this Regulation;\n(d)\nthe number of undertakings that enter the market after the entry into application of this Regulation, and how many of them are SMEs.\nBy 2 August 2028, the Commission shall evaluate the functioning of the AI Office, whether the AI Office has been given sufficient powers and competences to fulfil its tasks, and whether it would be relevant and needed for the proper implementation and enforcement of this Regulation to upgrade the AI Office and its enforcement competences and to increase its resources. The Commission shall submit a report on its evaluation to the European Parliament and to the Council.\nBy 2 August 2028 and every four years thereafter, the Commission shall submit a report on the review of the progress on the development of standardisation deliverables on the energy-efficient development of general-purpose AI models, and asses the need for further measures or actions, including binding measures or actions. The report shall be submitted to the European Parliament and to the Council, and it shall be made public.\nBy 2 August 2028 and every three years thereafter, the Commission shall evaluate the impact and effectiveness of voluntary codes of conduct to foster the application of the requirements set out in Chapter III, Section 2 for AI systems other than high-risk AI systems and possibly other additional requirements for AI systems other than high-risk AI systems, including as regards environmental sustainability.\nFor the purposes of paragraphs 1 to 7, the Board, the Member States and national competent authorities shall provide the Commission with information upon its request and without undue delay.\nIn carrying out the evaluations and reviews referred to in paragraphs 1 to 7, the Commission shall take into account the positions and findings of the Board, of the European Parliament, of the Council, and of other relevant bodies or sources.\nThe Commission shall, if necessary, submit appropriate proposals to amend this Regulation, in particular taking into account developments in technology, the effect of AI systems on health and safety, and on fundamental rights, and in light of the state of progress in the information society.\nTo guide the evaluations and reviews referred to in paragraphs 1 to 7 of this Article, the AI Office shall undertake to develop an objective and participative methodology for the evaluation of risk levels based on the criteria outlined in the relevant Articles and the inclusion of new systems in:\n(a)\nthe list set out in Annex III, including the extension of existing area headings or the addition of new area headings in that Annex;\n(b)\nthe list of prohibited practices set out in Article 5; and\n(c)\nthe list of AI systems requiring additional transparency measures pursuant to Article 50.\nAny amendment to this Regulation pursuant to paragraph 10, or relevant delegated or implementing acts, which concerns sectoral Union harmonisation legislation listed in Section B of Annex I shall take into account the regulatory specificities of each sector, and the existing governance, conformity assessment and enforcement mechanisms and authorities established therein.\nBy 2 August 2031, the Commission shall carry out an assessment of the enforcement of this Regulation and shall report on it to the European Parliament, the Council and the European Economic and Social Committee, taking into account the first years of application of this Regulation. On the basis of the findings, that report shall, where appropriate, be accompanied by a proposal for amendment of this Regulation with regard to the structure of enforcement and the need for a Union agency to resolve any identified shortcomings.\nArticle 113 Entry into force and application This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.\nIt shall apply from 2 August 2026.\nHowever:\n(a)\nChapters I and II shall apply from 2 February 2025;\n(b)\nChapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101;\n(c)\nArticle 6(1) and the corresponding obligations in this Regulation shall apply from 2 August 2027.\nThis Regulation shall be binding in its entirety and directly applicable in all Member States.\nDone at Brussels, 13 June 2024.\nFor the European Parliament\nThe President\nR. METSOLA\nFor the Council\nThe President\nM. MICHEL\n(1) OJ C 517, 22.12.2021, p. 56.\n(2) OJ C 115, 11.3.2022, p. 5.\n(3) OJ C 97, 28.2.2022, p. 60.\n(4) Position of the European Parliament of 13 March 2024 (not yet published in the Official Journal) and decision of the Council of 21 May 2024.\n(5) European Council, Special meeting of the European Council (1 and 2 October 2020) — Conclusions, EUCO 13/20, 2020, p. 6.\n(6) European Parliament resolution of 20 October 2020 with recommendations to the Commission on a framework of ethical aspects of artificial intelligence, robotics and related technologies, 2020/2012(INL).\n(7) Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July 2008 setting out the requirements for accreditation and repealing Regulation (EEC) No 339/93 (OJ L 218, 13.8.2008, p. 30).\n(8) Decision No 768/2008/EC of the European Parliament and of the Council of 9 July 2008 on a common framework for the marketing of products, and repealing Council Decision 93/465/EEC (OJ L 218, 13.8.2008, p. 82).\n(9) Regulation (EU) 2019/1020 of the European Parliament and of the Council of 20 June 2019 on market surveillance and compliance of products and amending Directive 2004/42/EC and Regulations (EC) No 765/2008 and (EU) No 305/2011 (OJ L 169, 25.6.2019, p. 1).\n(10) Council Directive 85/374/EEC of 25 July 1985 on the approximation of the laws, regulations and administrative provisions of the Member States concerning liability for defective products (OJ L 210, 7.8.1985, p. 29).\n(11) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1).\n(12) Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39).\n(13) Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, p. 89).\n(14) Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) (OJ L 201, 31.7.2002, p. 37).\n(15) Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) (OJ L 277, 27.10.2022, p. 1).\n(16) Directive (EU) 2019/882 of the European Parliament and of the Council of 17 April 2019 on the accessibility requirements for products and services (OJ L 151, 7.6.2019, p. 70).\n(17) Directive 2005/29/EC of the European Parliament and of the Council of 11 May 2005 concerning unfair business-to-consumer commercial practices in the internal market and amending Council Directive 84/450/EEC, Directives 97/7/EC, 98/27/EC and 2002/65/EC of the European Parliament and of the Council and Regulation (EC) No 2006/2004 of the European Parliament and of the Council (‘Unfair Commercial Practices Directive’) (OJ L 149, 11.6.2005, p. 22).\n(18) Council Framework Decision 2002/584/JHA of 13 June 2002 on the European arrest warrant and the surrender procedures between Member States (OJ L 190, 18.7.2002, p. 1).\n(19) Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC (OJ L 333, 27.12.2022, p. 164).\n(20) OJ C 247, 29.6.2022, p. 1.\n(21) Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices, amending Directive 2001/83/EC, Regulation (EC) No 178/2002 and Regulation (EC) No 1223/2009 and repealing Council Directives 90/385/EEC and 93/42/EEC (OJ L 117, 5.5.2017, p. 1).\n(22) Regulation (EU) 2017/746 of the European Parliament and of the Council of 5 April 2017 on in vitro diagnostic medical devices and repealing Directive 98/79/EC and Commission Decision 2010/227/EU (OJ L 117, 5.5.2017, p. 176).\n(23) Directive 2006/42/EC of the European Parliament and of the Council of 17 May 2006 on machinery, and amending Directive 95/16/EC (OJ L 157, 9.6.2006, p. 24).\n(24) Regulation (EC) No 300/2008 of the European Parliament and of the Council of 11 March 2008 on common rules in the field of civil aviation security and repealing Regulation (EC) No 2320/2002 (OJ L 97, 9.4.2008, p. 72).\n(25) Regulation (EU) No 167/2013 of the European Parliament and of the Council of 5 February 2013 on the approval and market surveillance of agricultural and forestry vehicles (OJ L 60, 2.3.2013, p. 1).\n(26) Regulation (EU) No 168/2013 of the European Parliament and of the Council of 15 January 2013 on the approval and market surveillance of two- or three-wheel vehicles and quadricycles (OJ L 60, 2.3.2013, p. 52).\n(27) Directive 2014/90/EU of the European Parliament and of the Council of 23 July 2014 on marine equipment and repealing Council Directive 96/98/EC (OJ L 257, 28.8.2014, p. 146).\n(28) Directive (EU) 2016/797 of the European Parliament and of the Council of 11 May 2016 on the interoperability of the rail system within the European Union (OJ L 138, 26.5.2016, p. 44).\n(29) Regulation (EU) 2018/858 of the European Parliament and of the Council of 30 May 2018 on the approval and market surveillance of motor vehicles and their trailers, and of systems, components and separate technical units intended for such vehicles, amending Regulations (EC) No 715/2007 and (EC) No 595/2009 and repealing Directive 2007/46/EC (OJ L 151, 14.6.2018, p. 1).\n(30) Regulation (EU) 2018/1139 of the European Parliament and of the Council of 4 July 2018 on common rules in the field of civil aviation and establishing a European Union Aviation Safety Agency, and amending Regulations (EC) No 2111/2005, (EC) No 1008/2008, (EU) No 996/2010, (EU) No 376/2014 and Directives 2014/30/EU and 2014/53/EU of the European Parliament and of the Council, and repealing Regulations (EC) No 552/2004 and (EC) No 216/2008 of the European Parliament and of the Council and Council Regulation (EEC) No 3922/91 (OJ L 212, 22.8.2018, p. 1).\n(31) Regulation (EU) 2019/2144 of the European Parliament and of the Council of 27 November 2019 on type-approval requirements for motor vehicles and their trailers, and systems, components and separate technical units intended for such vehicles, as regards their general safety and the protection of vehicle occupants and vulnerable road users, amending Regulation (EU) 2018/858 of the European Parliament and of the Council and repealing Regulations (EC) No 78/2009, (EC) No 79/2009 and (EC) No 661/2009 of the European Parliament and of the Council and Commission Regulations (EC) No 631/2009, (EU) No 406/2010, (EU) No 672/2010, (EU) No 1003/2010, (EU) No 1005/2010, (EU) No 1008/2010, (EU) No 1009/2010, (EU) No 19/2011, (EU) No 109/2011, (EU) No 458/2011, (EU) No 65/2012, (EU) No 130/2012, (EU) No 347/2012, (EU) No 351/2012, (EU) No 1230/2012 and (EU) 2015/166 (OJ L 325, 16.12.2019, p. 1).\n(32) Regulation (EC) No 810/2009 of the European Parliament and of the Council of 13 July 2009 establishing a Community Code on Visas (Visa Code) (OJ L 243, 15.9.2009, p. 1).\n(33) Directive 2013/32/EU of the European Parliament and of the Council of 26 June 2013 on common procedures for granting and withdrawing international protection (OJ L 180, 29.6.2013, p. 60).\n(34) Regulation (EU) 2024/900 of the European parliament and of the Council of 13 March 2024 on the transparency and targeting of political advertising (OJ L, 2024/900, 20.3.2024, ELI: http://data.europa.eu/eli/reg/2024/900/oj ).\n(35) Directive 2014/31/EU of the European Parliament and of the Council of 26 February 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of non-automatic weighing instruments (OJ L 96, 29.3.2014, p. 107).\n(36) Directive 2014/32/EU of the European Parliament and of the Council of 26 February 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of measuring instruments (OJ L 96, 29.3.2014, p. 149).\n(37) Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act) (OJ L 151, 7.6.2019, p. 15).\n(38) Directive (EU) 2016/2102 of the European Parliament and of the Council of 26 October 2016 on the accessibility of the websites and mobile applications of public sector bodies (OJ L 327, 2.12.2016, p. 1).\n(39) Directive 2002/14/EC of the European Parliament and of the Council of 11 March 2002 establishing a general framework for informing and consulting employees in the European Community (OJ L 80, 23.3.2002, p. 29).\n(40) Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019 on copyright and related rights in the Digital Single Market and amending Directives 96/9/EC and 2001/29/EC (OJ L 130, 17.5.2019, p. 92).\n(41) Regulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012 on European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC, 2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing Council Decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of the Council (OJ L 316, 14.11.2012, p. 12).\n(42) Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance and amending Regulation (EU) 2018/1724 (Data Governance Act) (OJ L 152, 3.6.2022, p. 1).\n(43) Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act) (OJ L, 2023/2854, 22.12.2023, ELI: http://data.europa.eu/eli/reg/2023/2854/oj ).\n(44) Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises (OJ L 124, 20.5.2003, p. 36).\n(45) Commission Decision of 24.1.2024 establishing the European Artificial Intelligence Office C(2024) 390.\n(46) Regulation (EU) No 575/2013 of the European Parliament and of the Council of 26 June 2013 on prudential requirements for credit institutions and investment firms and amending Regulation (EU) No 648/2012 (OJ L 176, 27.6.2013, p. 1).\n(47) Directive 2008/48/EC of the European Parliament and of the Council of 23 April 2008 on credit agreements for consumers and repealing Council Directive 87/102/EEC (OJ L 133, 22.5.2008, p. 66).\n(48) Directive 2009/138/EC of the European Parliament and of the Council of 25 November 2009 on the taking-up and pursuit of the business of Insurance and Reinsurance (Solvency II) (OJ L 335, 17.12.2009, p. 1).\n(49) Directive 2013/36/EU of the European Parliament and of the Council of 26 June 2013 on access to the activity of credit institutions and the prudential supervision of credit institutions and investment firms, amending Directive 2002/87/EC and repealing Directives 2006/48/EC and 2006/49/EC (OJ L 176, 27.6.2013, p. 338).\n(50) Directive 2014/17/EU of the European Parliament and of the Council of 4 February 2014 on credit agreements for consumers relating to residential immovable property and amending Directives 2008/48/EC and 2013/36/EU and Regulation (EU) No 1093/2010 (OJ L 60, 28.2.2014, p. 34).\n(51) Directive (EU) 2016/97 of the European Parliament and of the Council of 20 January 2016 on insurance distribution (OJ L 26, 2.2.2016, p. 19).\n(52) Council Regulation (EU) No 1024/2013 of 15 October 2013 conferring specific tasks on the European Central Bank concerning policies relating to the prudential supervision of credit institutions (OJ L 287, 29.10.2013, p. 63).\n(53) Regulation (EU) 2023/988 of the European Parliament and of the Council of 10 May 2023 on general product safety, amending Regulation (EU) No 1025/2012 of the European Parliament and of the Council and Directive (EU) 2020/1828 of the European Parliament and the Council, and repealing Directive 2001/95/EC of the European Parliament and of the Council and Council Directive 87/357/EEC (OJ L 135, 23.5.2023, p. 1).\n(54) Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 on the protection of persons who report breaches of Union law (OJ L 305, 26.11.2019, p. 17).\n(55) OJ L 123, 12.5.2016, p. 1.\n(56) Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general principles concerning mechanisms for control by Member States of the Commission’s exercise of implementing powers (OJ L 55, 28.2.2011, p. 13).\n(57) Directive (EU) 2016/943 of the European Parliament and of the Council of 8 June 2016 on the protection of undisclosed know-how and business information (trade secrets) against their unlawful acquisition, use and disclosure (OJ L 157, 15.6.2016, p. 1).\n(58) Directive (EU) 2020/1828 of the European Parliament and of the Council of 25 November 2020 on representative actions for the protection of the collective interests of consumers and repealing Directive 2009/22/EC (OJ L 409, 4.12.2020, p. 1).\nANNEX I List of Union harmonisation legislation\nSection A. List of Union harmonisation legislation based on the New Legislative Framework\nDirective 2006/42/EC of the European Parliament and of the Council of 17 May 2006 on machinery, and amending Directive 95/16/EC (OJ L 157, 9.6.2006, p. 24);\nDirective 2009/48/EC of the European Parliament and of the Council of 18 June 2009 on the safety of toys (OJ L 170, 30.6.2009, p. 1);\nDirective 2013/53/EU of the European Parliament and of the Council of 20 November 2013 on recreational craft and personal watercraft and repealing Directive 94/25/EC (OJ L 354, 28.12.2013, p. 90);\nDirective 2014/33/EU of the European Parliament and of the Council of 26 February 2014 on the harmonisation of the laws of the Member States relating to lifts and safety components for lifts (OJ L 96, 29.3.2014, p. 251);\nDirective 2014/34/EU of the European Parliament and of the Council of 26 February 2014 on the harmonisation of the laws of the Member States relating to equipment and protective systems intended for use in potentially explosive atmospheres (OJ L 96, 29.3.2014, p. 309);\nDirective 2014/53/EU of the European Parliament and of the Council of 16 April 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of radio equipment and repealing Directive 1999/5/EC (OJ L 153, 22.5.2014, p. 62);\nDirective 2014/68/EU of the European Parliament and of the Council of 15 May 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of pressure equipment (OJ L 189, 27.6.2014, p. 164);\nRegulation (EU) 2016/424 of the European Parliament and of the Council of 9 March 2016 on cableway installations and repealing Directive 2000/9/EC (OJ L 81, 31.3.2016, p. 1);\nRegulation (EU) 2016/425 of the European Parliament and of the Council of 9 March 2016 on personal protective equipment and repealing Council Directive 89/686/EEC (OJ L 81, 31.3.2016, p. 51);\nRegulation (EU) 2016/426 of the European Parliament and of the Council of 9 March 2016 on appliances burning gaseous fuels and repealing Directive 2009/142/EC (OJ L 81, 31.3.2016, p. 99);\nRegulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices, amending Directive 2001/83/EC, Regulation (EC) No 178/2002 and Regulation (EC) No 1223/2009 and repealing Council Directives 90/385/EEC and 93/42/EEC (OJ L 117, 5.5.2017, p. 1);\nRegulation (EU) 2017/746 of the European Parliament and of the Council of 5 April 2017 on in vitro diagnostic medical devices and repealing Directive 98/79/EC and Commission Decision 2010/227/EU (OJ L 117, 5.5.2017, p. 176).\nSection B. List of other Union harmonisation legislation\nRegulation (EC) No 300/2008 of the European Parliament and of the Council of 11 March 2008 on common rules in the field of civil aviation security and repealing Regulation (EC) No 2320/2002 (OJ L 97, 9.4.2008, p. 72);\nRegulation (EU) No 168/2013 of the European Parliament and of the Council of 15 January 2013 on the approval and market surveillance of two- or three-wheel vehicles and quadricycles (OJ L 60, 2.3.2013, p. 52);\nRegulation (EU) No 167/2013 of the European Parliament and of the Council of 5 February 2013 on the approval and market surveillance of agricultural and forestry vehicles (OJ L 60, 2.3.2013, p. 1);\nDirective 2014/90/EU of the European Parliament and of the Council of 23 July 2014 on marine equipment and repealing Council Directive 96/98/EC (OJ L 257, 28.8.2014, p. 146);\nDirective (EU) 2016/797 of the European Parliament and of the Council of 11 May 2016 on the interoperability of the rail system within the European Union (OJ L 138, 26.5.2016, p. 44);\nRegulation (EU) 2018/858 of the European Parliament and of the Council of 30 May 2018 on the approval and market surveillance of motor vehicles and their trailers, and of systems, components and separate technical units intended for such vehicles, amending Regulations (EC) No 715/2007 and (EC) No 595/2009 and repealing Directive 2007/46/EC (OJ L 151, 14.6.2018, p. 1);\nRegulation (EU) 2019/2144 of the European Parliament and of the Council of 27 November 2019 on type-approval requirements for motor vehicles and their trailers, and systems, components and separate technical units intended for such vehicles, as regards their general safety and the protection of vehicle occupants and vulnerable road users, amending Regulation (EU) 2018/858 of the European Parliament and of the Council and repealing Regulations (EC) No 78/2009, (EC) No 79/2009 and (EC) No 661/2009 of the European Parliament and of the Council and Commission Regulations (EC) No 631/2009, (EU) No 406/2010, (EU) No 672/2010, (EU) No 1003/2010, (EU) No 1005/2010, (EU) No 1008/2010, (EU) No 1009/2010, (EU) No 19/2011, (EU) No 109/2011, (EU) No 458/2011, (EU) No 65/2012, (EU) No 130/2012, (EU) No 347/2012, (EU) No 351/2012, (EU) No 1230/2012 and (EU) 2015/166 (OJ L 325, 16.12.2019, p. 1);\nRegulation (EU) 2018/1139 of the European Parliament and of the Council of 4 July 2018 on common rules in the field of civil aviation and establishing a European Union Aviation Safety Agency, and amending Regulations (EC) No 2111/2005, (EC) No 1008/2008, (EU) No 996/2010, (EU) No 376/2014 and Directives 2014/30/EU and 2014/53/EU of the European Parliament and of the Council, and repealing Regulations (EC) No 552/2004 and (EC) No 216/2008 of the European Parliament and of the Council and Council Regulation (EEC) No 3922/91 (OJ L 212, 22.8.2018, p. 1), in so far as the design, production and placing on the market of aircrafts referred to in Article 2(1), points (a) and (b) thereof, where it concerns unmanned aircraft and their engines, propellers, parts and equipment to control them remotely, are concerned.\nANNEX II List of criminal offences referred to in Article 5(1), first subparagraph, point (h)(iii)\nCriminal offences referred to in Article 5(1), first subparagraph, point (h)(iii):\n—\nterrorism,\n—\ntrafficking in human beings,\n—\nsexual exploitation of children, and child pornography,\n—\nillicit trafficking in narcotic drugs or psychotropic substances,\n—\nillicit trafficking in weapons, munitions or explosives,\n—\nmurder, grievous bodily injury,\n—\nillicit trade in human organs or tissue,\n—\nillicit trafficking in nuclear or radioactive materials,\n—\nkidnapping, illegal restraint or hostage-taking,\n—\ncrimes within the jurisdiction of the International Criminal Court,\n—\nunlawful seizure of aircraft or ships,\n—\nrape,\n—\nenvironmental crime,\n—\norganised or armed robbery,\n—\nsabotage,\n—\nparticipation in a criminal organisation involved in one or more of the offences listed above.\nANNEX III High-risk AI systems referred to in Article 6(2)\nHigh-risk AI systems pursuant to Article 6(2) are the AI systems listed in any of the following areas:\nBiometrics, in so far as their use is permitted under relevant Union or national law: (a)\nremote biometric identification systems.\nThis shall not include AI systems intended to be used for biometric verification the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be;\n(b)\nAI systems intended to be used for biometric categorisation, according to sensitive or protected attributes or characteristics based on the inference of those attributes or characteristics;\n(c)\nAI systems intended to be used for emotion recognition.\nCritical infrastructure: AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.\nEducation and vocational training:\n(a)\nAI systems intended to be used to determine access or admission or to assign natural persons to educational and vocational training institutions at all levels;\n(b)\nAI systems intended to be used to evaluate learning outcomes, including when those outcomes are used to steer the learning process of natural persons in educational and vocational training institutions at all levels;\n(c)\nAI systems intended to be used for the purpose of assessing the appropriate level of education that an individual will receive or will be able to access, in the context of or within educational and vocational training institutions at all levels;\n(d)\nAI systems intended to be used for monitoring and detecting prohibited behaviour of students during tests in the context of or within educational and vocational training institutions at all levels.\nEmployment, workers’ management and access to self-employment: (a)\nAI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates;\n(b)\nAI systems intended to be used to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships.\nAccess to and enjoyment of essential private services and essential public services and benefits: (a)\nAI systems intended to be used by public authorities or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services, as well as to grant, reduce, revoke, or reclaim such benefits and services;\n(b)\nAI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud;\n(c)\nAI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance;\n(d)\nAI systems intended to evaluate and classify emergency calls by natural persons or to be used to dispatch, or to establish priority in the dispatching of, emergency first response services, including by police, firefighters and medical aid, as well as of emergency healthcare patient triage systems.\nLaw enforcement, in so far as their use is permitted under relevant Union or national law: (a)\nAI systems intended to be used by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices or agencies in support of law enforcement authorities or on their behalf to assess the risk of a natural person becoming the victim of criminal offences;\n(b)\nAI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices or agencies in support of law enforcement authorities as polygraphs or similar tools;\n(c)\nAI systems intended to be used by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices or agencies, in support of law enforcement authorities to evaluate the reliability of evidence in the course of the investigation or prosecution of criminal offences;\n(d)\nAI systems intended to be used by law enforcement authorities or on their behalf or by Union institutions, bodies, offices or agencies in support of law enforcement authorities for assessing the risk of a natural person offending or re-offending not solely on the basis of the profiling of natural persons as referred to in Article 3(4) of Directive (EU) 2016/680, or to assess personality traits and characteristics or past criminal behaviour of natural persons or groups;\n(e)\nAI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices or agencies in support of law enforcement authorities for the profiling of natural persons as referred to in Article 3(4) of Directive (EU) 2016/680 in the course of the detection, investigation or prosecution of criminal offences.\nMigration, asylum and border control management, in so far as their use is permitted under relevant Union or national law: (a)\nAI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies as polygraphs or similar tools;\n(b)\nAI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies to assess a risk, including a security risk, a risk of irregular migration, or a health risk, posed by a natural person who intends to enter or who has entered into the territory of a Member State;\n(c)\nAI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies to assist competent public authorities for the examination of applications for asylum, visa or residence permits and for associated complaints with regard to the eligibility of the natural persons applying for a status, including related assessments of the reliability of evidence;\n(d)\nAI systems intended to be used by or on behalf of competent public authorities, or by Union institutions, bodies, offices or agencies, in the context of migration, asylum or border control management, for the purpose of detecting, recognising or identifying natural persons, with the exception of the verification of travel documents.\nAdministration of justice and democratic processes: (a)\nAI systems intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution;\n(b)\nAI systems intended to be used for influencing the outcome of an election or referendum or the voting behaviour of natural persons in the exercise of their vote in elections or referenda. This does not include AI systems to the output of which natural persons are not directly exposed, such as tools used to organise, optimise or structure political campaigns from an administrative or logistical point of view.\nANNEX IV Technical documentation referred to in Article 11(1)\nThe technical documentation referred to in Article 11(1) shall contain at least the following information, as applicable to the relevant AI system:\nA general description of the AI system including: (a)\nits intended purpose, the name of the provider and the version of the system reflecting its relation to previous versions;\n(b)\nhow the AI system interacts with, or can be used to interact with, hardware or software, including with other AI systems, that are not part of the AI system itself, where applicable;\n(c)\nthe versions of relevant software or firmware, and any requirements related to version updates;\n(d)\nthe description of all the forms in which the AI system is placed on the market or put into service, such as software packages embedded into hardware, downloads, or APIs;\n(e)\nthe description of the hardware on which the AI system is intended to run;\n(f)\nwhere the AI system is a component of products, photographs or illustrations showing external features, the marking and internal layout of those products;\n(g)\na basic description of the user-interface provided to the deployer;\n(h)\ninstructions for use for the deployer, and a basic description of the user-interface provided to the deployer, where applicable;\nA detailed description of the elements of the AI system and of the process for its development, including: (a)\nthe methods and steps performed for the development of the AI system, including, where relevant, recourse to pre-trained systems or tools provided by third parties and how those were used, integrated or modified by the provider;\n(b)\nthe design specifications of the system, namely the general logic of the AI system and of the algorithms; the key design choices including the rationale and assumptions made, including with regard to persons or groups of persons in respect of who, the system is intended to be used; the main classification choices; what the system is designed to optimise for, and the relevance of the different parameters; the description of the expected output and output quality of the system; the decisions about any possible trade-off made regarding the technical solutions adopted to comply with the requirements set out in Chapter III, Section 2;\n(c)\nthe description of the system architecture explaining how software components build on or feed into each other and integrate into the overall processing; the computational resources used to develop, train, test and validate the AI system;\n(d)\nwhere relevant, the data requirements in terms of datasheets describing the training methodologies and techniques and the training data sets used, including a general description of these data sets, information about their provenance, scope and main characteristics; how the data was obtained and selected; labelling procedures (e.g. for supervised learning), data cleaning methodologies (e.g. outliers detection);\n(e)\nassessment of the human oversight measures needed in accordance with Article 14, including an assessment of the technical measures needed to facilitate the interpretation of the outputs of AI systems by the deployers, in accordance with Article 13(3), point (d);\n(f)\nwhere applicable, a detailed description of pre-determined changes to the AI system and its performance, together with all the relevant information related to the technical solutions adopted to ensure continuous compliance of the AI system with the relevant requirements set out in Chapter III, Section 2;\n(g)\nthe validation and testing procedures used, including information about the validation and testing data used and their main characteristics; metrics used to measure accuracy, robustness and compliance with other relevant requirements set out in Chapter III, Section 2, as well as potentially discriminatory impacts; test logs and all test reports dated and signed by the responsible persons, including with regard to pre-determined changes as referred to under point (f);\n(h)\ncybersecurity measures put in place;\nDetailed information about the monitoring, functioning and control of the AI system, in particular with regard to: its capabilities and limitations in performance, including the degrees of accuracy for specific persons or groups of persons on which the system is intended to be used and the overall expected level of accuracy in relation to its intended purpose; the foreseeable unintended outcomes and sources of risks to health and safety, fundamental rights and discrimination in view of the intended purpose of the AI system; the human oversight measures needed in accordance with Article 14, including the technical measures put in place to facilitate the interpretation of the outputs of AI systems by the deployers; specifications on input data, as appropriate;\nA description of the appropriateness of the performance metrics for the specific AI system;\nA detailed description of the risk management system in accordance with Article 9;\nA description of relevant changes made by the provider to the system through its lifecycle;\nA list of the harmonised standards applied in full or in part the references of which have been published in the Official Journal of the European Union; where no such harmonised standards have been applied, a detailed description of the solutions adopted to meet the requirements set out in Chapter III, Section 2, including a list of other relevant standards and technical specifications applied;\nA copy of the EU declaration of conformity referred to in Article 47;\nA detailed description of the system in place to evaluate the AI system performance in the post-market phase in accordance with Article 72, including the post-market monitoring plan referred to in Article 72(3).\nANNEX V EU declaration of conformity\nThe EU declaration of conformity referred to in Article 47, shall contain all of the following information:\nAI system name and type and any additional unambiguous reference allowing the identification and traceability of the AI system;\nThe name and address of the provider or, where applicable, of their authorised representative;\nA statement that the EU declaration of conformity referred to in Article 47 is issued under the sole responsibility of the provider;\nA statement that the AI system is in conformity with this Regulation and, if applicable, with any other relevant Union law that provides for the issuing of the EU declaration of conformity referred to in Article 47;\nWhere an AI system involves the processing of personal data, a statement that that AI system complies with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680;\nReferences to any relevant harmonised standards used or any other common specification in relation to which conformity is declared;\nWhere applicable, the name and identification number of the notified body, a description of the conformity assessment procedure performed, and identification of the certificate issued;\nThe place and date of issue of the declaration, the name and function of the person who signed it, as well as an indication for, or on behalf of whom, that person signed, a signature.\nANNEX VI Conformity assessment procedure based on internal control\nThe conformity assessment procedure based on internal control is the conformity assessment procedure based on points 2, 3 and 4.\nThe provider verifies that the established quality management system is in compliance with the requirements of Article 17.\nThe provider examines the information contained in the technical documentation in order to assess the compliance of the AI system with the relevant essential requirements set out in Chapter III, Section 2.\nThe provider also verifies that the design and development process of the AI system and its post-market monitoring as referred to in Article 72 is consistent with the technical documentation.\nANNEX VII Conformity based on an assessment of the quality management system and an assessment of the technical documentation\nIntroduction Conformity based on an assessment of the quality management system and an assessment of the technical documentation is the conformity assessment procedure based on points 2 to 5.\nOverview The approved quality management system for the design, development and testing of AI systems pursuant to Article 17 shall be examined in accordance with point 3 and shall be subject to surveillance as specified in point 5. The technical documentation of the AI system shall be examined in accordance with point 4.\nQuality management system 3.1.\nThe application of the provider shall include: (a)\nthe name and address of the provider and, if the application is lodged by an authorised representative, also their name and address;\n(b)\nthe list of AI systems covered under the same quality management system;\n(c)\nthe technical documentation for each AI system covered under the same quality management system;\n(d)\nthe documentation concerning the quality management system which shall cover all the aspects listed under Article 17;\n(e)\na description of the procedures in place to ensure that the quality management system remains adequate and effective;\n(f)\na written declaration that the same application has not been lodged with any other notified body.\n3.2.\nThe quality management system shall be assessed by the notified body, which shall determine whether it satisfies the requirements referred to in Article 17. The decision shall be notified to the provider or its authorised representative.\nThe notification shall contain the conclusions of the assessment of the quality management system and the reasoned assessment decision.\n3.3.\nThe quality management system as approved shall continue to be implemented and maintained by the provider so that it remains adequate and efficient. 3.4.\nAny intended change to the approved quality management system or the list of AI systems covered by the latter shall be brought to the attention of the notified body by the provider. The proposed changes shall be examined by the notified body, which shall decide whether the modified quality management system continues to satisfy the requirements referred to in point 3.2 or whether a reassessment is necessary.\nThe notified body shall notify the provider of its decision. The notification shall contain the conclusions of the examination of the changes and the reasoned assessment decision.\nControl of the technical documentation. 4.1.\nIn addition to the application referred to in point 3, an application with a notified body of their choice shall be lodged by the provider for the assessment of the technical documentation relating to the AI system which the provider intends to place on the market or put into service and which is covered by the quality management system referred to under point 3. 4.2.\nThe application shall include: (a)\nthe name and address of the provider;\n(b)\na written declaration that the same application has not been lodged with any other notified body;\n(c)\nthe technical documentation referred to in Annex IV.\n4.3.\nThe technical documentation shall be examined by the notified body. Where relevant, and limited to what is necessary to fulfil its tasks, the notified body shall be granted full access to the training, validation, and testing data sets used, including, where appropriate and subject to security safeguards, through API or other relevant technical means and tools enabling remote access. 4.4.\nIn examining the technical documentation, the notified body may require that the provider supply further evidence or carry out further tests so as to enable a proper assessment of the conformity of the AI system with the requirements set out in Chapter III, Section 2. Where the notified body is not satisfied with the tests carried out by the provider, the notified body shall itself directly carry out adequate tests, as appropriate. 4.5.\nWhere necessary to assess the conformity of the high-risk AI system with the requirements set out in Chapter III, Section 2, after all other reasonable means to verify conformity have been exhausted and have proven to be insufficient, and upon a reasoned request, the notified body shall also be granted access to the training and trained models of the AI system, including its relevant parameters. Such access shall be subject to existing Union law on the protection of intellectual property and trade secrets. 4.6.\nThe decision of the notified body shall be notified to the provider or its authorised representative. The notification shall contain the conclusions of the assessment of the technical documentation and the reasoned assessment decision. Where the AI system is in conformity with the requirements set out in Chapter III, Section 2, the notified body shall issue a Union technical documentation assessment certificate. The certificate shall indicate the name and address of the provider, the conclusions of the examination, the conditions (if any) for its validity and the data necessary for the identification of the AI system.\nThe certificate and its annexes shall contain all relevant information to allow the conformity of the AI system to be evaluated, and to allow for control of the AI system while in use, where applicable.\nWhere the AI system is not in conformity with the requirements set out in Chapter III, Section 2, the notified body shall refuse to issue a Union technical documentation assessment certificate and shall inform the applicant accordingly, giving detailed reasons for its refusal.\nWhere the AI system does not meet the requirement relating to the data used to train it, re-training of the AI system will be needed prior to the application for a new conformity assessment. In this case, the reasoned assessment decision of the notified body refusing to issue the Union technical documentation assessment certificate shall contain specific considerations on the quality data used to train the AI system, in particular on the reasons for non-compliance.\n4.7.\nAny change to the AI system that could affect the compliance of the AI system with the requirements or its intended purpose shall be assessed by the notified body which issued the Union technical documentation assessment certificate. The provider shall inform such notified body of its intention to introduce any of the abovementioned changes, or if it otherwise becomes aware of the occurrence of such changes. The intended changes shall be assessed by the notified body, which shall decide whether those changes require a new conformity assessment in accordance with Article 43(4) or whether they could be addressed by means of a supplement to the Union technical documentation assessment certificate. In the latter case, the notified body shall assess the changes, notify the provider of its decision and, where the changes are approved, issue to the provider a supplement to the Union technical documentation assessment certificate. Surveillance of the approved quality management system. 5.1.\nThe purpose of the surveillance carried out by the notified body referred to in Point 3 is to make sure that the provider duly complies with the terms and conditions of the approved quality management system. 5.2.\nFor assessment purposes, the provider shall allow the notified body to access the premises where the design, development, testing of the AI systems is taking place. The provider shall further share with the notified body all necessary information. 5.3.\nThe notified body shall carry out periodic audits to make sure that the provider maintains and applies the quality management system and shall provide the provider with an audit report. In the context of those audits, the notified body may carry out additional tests of the AI systems for which a Union technical documentation assessment certificate was issued. ANNEX VIII Information to be submitted upon the registration of high-risk AI systems in accordance with Article 49\nSection A — Information to be submitted by providers of high-risk AI systems in accordance with Article 49(1)\nThe following information shall be provided and thereafter kept up to date with regard to high-risk AI systems to be registered in accordance with Article 49(1):\nThe name, address and contact details of the provider;\nWhere submission of information is carried out by another person on behalf of the provider, the name, address and contact details of that person;\nThe name, address and contact details of the authorised representative, where applicable;\nThe AI system trade name and any additional unambiguous reference allowing the identification and traceability of the AI system;\nA description of the intended purpose of the AI system and of the components and functions supported through this AI system;\nA basic and concise description of the information used by the system (data, inputs) and its operating logic;\nThe status of the AI system (on the market, or in service; no longer placed on the market/in service, recalled);\nThe type, number and expiry date of the certificate issued by the notified body and the name or identification number of that notified body, where applicable;\nA scanned copy of the certificate referred to in point 8, where applicable;\nAny Member States in which the AI system has been placed on the market, put into service or made available in the Union;\nA copy of the EU declaration of conformity referred to in Article 47;\nElectronic instructions for use; this information shall not be provided for high-risk AI systems in the areas of law enforcement or migration, asylum and border control management referred to in Annex III, points 1, 6 and 7;\nA URL for additional information (optional).\nSection B — Information to be submitted by providers of high-risk AI systems in accordance with Article 49(2)\nThe following information shall be provided and thereafter kept up to date with regard to AI systems to be registered in accordance with Article 49(2):\nThe name, address and contact details of the provider;\nWhere submission of information is carried out by another person on behalf of the provider, the name, address and contact details of that person;\nThe name, address and contact details of the authorised representative, where applicable;\nThe AI system trade name and any additional unambiguous reference allowing the identification and traceability of the AI system;\nA description of the intended purpose of the AI system;\nThe condition or conditions under Article 6(3)based on which the AI system is considered to be not-high-risk;\nA short summary of the grounds on which the AI system is considered to be not-high-risk in application of the procedure under Article 6(3);\nThe status of the AI system (on the market, or in service; no longer placed on the market/in service, recalled);\nAny Member States in which the AI system has been placed on the market, put into service or made available in the Union.\nSection C — Information to be submitted by deployers of high-risk AI systems in accordance with Article 49(3)\nThe following information shall be provided and thereafter kept up to date with regard to high-risk AI systems to be registered in accordance with Article 49(3):\nThe name, address and contact details of the deployer;\nThe name, address and contact details of the person submitting information on behalf of the deployer;\nThe URL of the entry of the AI system in the EU database by its provider;\nA summary of the findings of the fundamental rights impact assessment conducted in accordance with Article 27;\nA summary of the data protection impact assessment carried out in accordance with Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680 as specified in Article 26(8) of this Regulation, where applicable.\nANNEX IX Information to be submitted upon the registration of high-risk AI systems listed in Annex III in relation to testing in real world conditions in accordance with Article 60\nThe following information shall be provided and thereafter kept up to date with regard to testing in real world conditions to be registered in accordance with Article 60:\nA Union-wide unique single identification number of the testing in real world conditions;\nThe name and contact details of the provider or prospective provider and of the deployers involved in the testing in real world conditions;\nA brief description of the AI system, its intended purpose, and other information necessary for the identification of the system;\nA summary of the main characteristics of the plan for testing in real world conditions;\nInformation on the suspension or termination of the testing in real world conditions.\nANNEX X Union legislative acts on large-scale IT systems in the area of Freedom, Security and Justice\nSchengen Information System (a)\nRegulation (EU) 2018/1860 of the European Parliament and of the Council of 28 November 2018 on the use of the Schengen Information System for the return of illegally staying third-country nationals (OJ L 312, 7.12.2018, p. 1).\n(b)\nRegulation (EU) 2018/1861 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System (SIS) in the field of border checks, and amending the Convention implementing the Schengen Agreement, and amending and repealing Regulation (EC) No 1987/2006 (OJ L 312, 7.12.2018, p. 14).\n(c)\nRegulation (EU) 2018/1862 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System (SIS) in the field of police cooperation and judicial cooperation in criminal matters, amending and repealing Council Decision 2007/533/JHA, and repealing Regulation (EC) No 1986/2006 of the European Parliament and of the Council and Commission Decision 2010/261/EU (OJ L 312, 7.12.2018, p. 56).\nVisa Information System (a)\nRegulation (EU) 2021/1133 of the European Parliament and of the Council of 7 July 2021 amending Regulations (EU) No 603/2013, (EU) 2016/794, (EU) 2018/1862, (EU) 2019/816 and (EU) 2019/818 as regards the establishment of the conditions for accessing other EU information systems for the purposes of the Visa Information System (OJ L 248, 13.7.2021, p. 1).\n(b)\nRegulation (EU) 2021/1134 of the European Parliament and of the Council of 7 July 2021 amending Regulations (EC) No 767/2008, (EC) No 810/2009, (EU) 2016/399, (EU) 2017/2226, (EU) 2018/1240, (EU) 2018/1860, (EU) 2018/1861, (EU) 2019/817 and (EU) 2019/1896 of the European Parliament and of the Council and repealing Council Decisions 2004/512/EC and 2008/633/JHA, for the purpose of reforming the Visa Information System (OJ L 248, 13.7.2021, p. 11).\nEurodac Regulation (EU) 2024/1358 of the European Parliament and of the Council of 14 May 2024 on the establishment of ‘Eurodac’ for the comparison of biometric data in order to effectively apply Regulations (EU) 2024/1315 and (EU) 2024/1350 of the European Parliament and of the Council and Council Directive 2001/55/EC and to identify illegally staying third-country nationals and stateless persons and on requests for the comparison with Eurodac data by Member States’ law enforcement authorities and Europol for law enforcement purposes, amending Regulations (EU) 2018/1240 and (EU) 2019/818 of the European Parliament and of the Council and repealing Regulation (EU) No 603/2013 of the European Parliament and of the Council (OJ L, 2024/1358, 22.5.2024, ELI: http://data.europa.eu/eli/reg/2024/1358/oj ).\nEntry/Exit System Regulation (EU) 2017/2226 of the European Parliament and of the Council of 30 November 2017 establishing an Entry/Exit System (EES) to register entry and exit data and refusal of entry data of third-country nationals crossing the external borders of the Member States and determining the conditions for access to the EES for law enforcement purposes, and amending the Convention implementing the Schengen Agreement and Regulations (EC) No 767/2008 and (EU) No 1077/2011 (OJ L 327, 9.12.2017, p. 20).\nEuropean Travel Information and Authorisation System (a)\nRegulation (EU) 2018/1240 of the European Parliament and of the Council of 12 September 2018 establishing a European Travel Information and Authorisation System (ETIAS) and amending Regulations (EU) No 1077/2011, (EU) No 515/2014, (EU) 2016/399, (EU) 2016/1624 and (EU) 2017/2226 (OJ L 236, 19.9.2018, p. 1).\n(b)\nRegulation (EU) 2018/1241 of the European Parliament and of the Council of 12 September 2018 amending Regulation (EU) 2016/794 for the purpose of establishing a European Travel Information and Authorisation System (ETIAS) (OJ L 236, 19.9.2018, p. 72).\nEuropean Criminal Records Information System on third-country nationals and stateless persons Regulation (EU) 2019/816 of the European Parliament and of the Council of 17 April 2019 establishing a centralised system for the identification of Member States holding conviction information on third-country nationals and stateless persons (ECRIS-TCN) to supplement the European Criminal Records Information System and amending Regulation (EU) 2018/1726 (OJ L 135, 22.5.2019, p. 1).\nInteroperability (a)\nRegulation (EU) 2019/817 of the European Parliament and of the Council of 20 May 2019 on establishing a framework for interoperability between EU information systems in the field of borders and visa and amending Regulations (EC) No 767/2008, (EU) 2016/399, (EU) 2017/2226, (EU) 2018/1240, (EU) 2018/1726 and (EU) 2018/1861 of the European Parliament and of the Council and Council Decisions 2004/512/EC and 2008/633/JHA (OJ L 135, 22.5.2019, p. 27).\n(b)\nRegulation (EU) 2019/818 of the European Parliament and of the Council of 20 May 2019 on establishing a framework for interoperability between EU information systems in the field of police and judicial cooperation, asylum and migration and amending Regulations (EU) 2018/1726, (EU) 2018/1862 and (EU) 2019/816 (OJ L 135, 22.5.2019, p. 85).\nANNEX XI Technical documentation referred to in Article 53(1), point (a) — technical documentation for providers of general-purpose AI models\nSection 1\nInformation to be provided by all providers of general-purpose AI models\nThe technical documentation referred to in Article 53(1), point (a) shall contain at least the following information as appropriate to the size and risk profile of the model:\nA general description of the general-purpose AI model including: (a)\nthe tasks that the model is intended to perform and the type and nature of AI systems in which it can be integrated;\n(b)\nthe acceptable use policies applicable;\n(c)\nthe date of release and methods of distribution;\n(d)\nthe architecture and number of parameters;\n(e)\nthe modality (e.g. text, image) and format of inputs and outputs;\n(f)\nthe licence.\nA detailed description of the elements of the model referred to in point 1, and relevant information of the process for the development, including the following elements: (a)\nthe technical means (e.g. instructions of use, infrastructure, tools) required for the general-purpose AI model to be integrated in AI systems;\n(b)\nthe design specifications of the model and training process, including training methodologies and techniques, the key design choices including the rationale and assumptions made; what the model is designed to optimise for and the relevance of the different parameters, as applicable;\n(c)\ninformation on the data used for training, testing and validation, where applicable, including the type and provenance of data and curation methodologies (e.g. cleaning, filtering, etc.), the number of data points, their scope and main characteristics; how the data was obtained and selected as well as all other measures to detect the unsuitability of data sources and methods to detect identifiable biases, where applicable;\n(d)\nthe computational resources used to train the model (e.g. number of floating point operations), training time, and other relevant details related to the training;\n(e)\nknown or estimated energy consumption of the model.\nWith regard to point (e), where the energy consumption of the model is unknown, the energy consumption may be based on information about computational resources used.\nSection 2\nAdditional information to be provided by providers of general-purpose AI models with systemic risk\nA detailed description of the evaluation strategies, including evaluation results, on the basis of available public evaluation protocols and tools or otherwise of other evaluation methodologies. Evaluation strategies shall include evaluation criteria, metrics and the methodology on the identification of limitations.\nWhere applicable, a detailed description of the measures put in place for the purpose of conducting internal and/or external adversarial testing (e.g. red teaming), model adaptations, including alignment and fine-tuning.\nWhere applicable, a detailed description of the system architecture explaining how software components build or feed into each other and integrate into the overall processing.\nANNEX XII Transparency information referred to in Article 53(1), point (b) — technical documentation for providers of general-purpose AI models to downstream providers that integrate the model into their AI system\nThe information referred to in Article 53(1), point (b) shall contain at least the following:\nA general description of the general-purpose AI model including: (a)\nthe tasks that the model is intended to perform and the type and nature of AI systems into which it can be integrated;\n(b)\nthe acceptable use policies applicable;\n(c)\nthe date of release and methods of distribution;\n(d)\nhow the model interacts, or can be used to interact, with hardware or software that is not part of the model itself, where applicable;\n(e)\nthe versions of relevant software related to the use of the general-purpose AI model, where applicable;\n(f)\nthe architecture and number of parameters;\n(g)\nthe modality (e.g. text, image) and format of inputs and outputs;\n(h)\nthe licence for the model.\nA description of the elements of the model and of the process for its development, including: (a)\nthe technical means (e.g. instructions for use, infrastructure, tools) required for the general-purpose AI model to be integrated into AI systems;\n(b)\nthe modality (e.g. text, image, etc.) and format of the inputs and outputs and their maximum size (e.g. context window length, etc.);\n(c)\ninformation on the data used for training, testing and validation, where applicable, including the type and provenance of data and curation methodologies.\nANNEX XIII Criteria for the designation of general-purpose AI models with systemic risk referred to in Article 51\nFor the purpose of determining that a general-purpose AI model has capabilities or an impact equivalent to those set out in Article 51(1), point (a), the Commission shall take into account the following criteria:\n(a)\nthe number of parameters of the model;\n(b)\nthe quality or size of the data set, for example measured through tokens;\n(c)\nthe amount of computation used for training the model, measured in floating point operations or indicated by a combination of other variables such as estimated cost of training, estimated time required for the training, or estimated energy consumption for the training;\n(d)\nthe input and output modalities of the model, such as text to text (large language models), text to image, multi-modality, and the state of the art thresholds for determining high-impact capabilities for each modality, and the specific type of inputs and outputs (e.g. biological sequences);\n(e)\nthe benchmarks and evaluations of capabilities of the model, including considering the number of tasks without additional training, adaptability to learn new, distinct tasks, its level of autonomy and scalability, the tools it has access to;\n(f)\nwhether it has a high impact on the internal market due to its reach, which shall be presumed when it has been made available to at least 10 000 registered business users established in the Union;\n(g)\nthe number of registered end-users.\n","permalink":"https://ai.intlaws.com/en/compliance/eu/eu-ai-act-full-text/","summary":"Official Englishof Regulation (EU) 2024/1689 (Artificial Intelligence Act) as published in the Official Journal of the European Union (OJ L, 12.7.2024): 13 chapters, 113 articles and 13 annexes, reproduced verbatim from EUR-Lex. Unofficial Chinese translation pending.","title":"Regulation (EU) 2024/1689 — Artificial Intelligence Act"},{"content":" Version and sources (verifiable)\nItem Content Instrument Senate Bill 53 (2025–2026 Regular Session), \u0026ldquo;Artificial intelligence models: large developers\u0026rdquo; Status approved by the Governor and filed with the Secretary of State on 29 September 2025 (chaptered) Chapter Chapter 138, Statutes of 2025 Short title Transparency in Frontier Artificial Intelligence Act (TFAIA) — per the Legislative Counsel\u0026rsquo;s Digest and the chapter heading of B\u0026amp;P Code Chapter 25.1 Effect adds Business and Professions Code Chapter 25.1 (commencing with Section 22757.10); amends Government Code Section 11546.8; adds Labor Code Chapter 5.1 (commencing with Section 1107) Official text https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53 Verification 2026-09-23 re-verified against the official Chapter 138 chaptered PDF (leginfo version 20250SB5390CHP, 16 pp.): SECTION/SEC 6/6; code sections 11/11; item markers (a)–(p) counts identical per letter; numeric markers identical per SEC — no omissions against the official text Legislative status page bill status ｜ Governor\u0026rsquo;s signing release (29 Sep 2025) Chinese version No official Chinese text. A Chinese translation by our editorial team, marked non-official, is available → 中文全文 Retrieval \u0026amp; verification Retrieved 2026-09-22 from the official California Legislative Information bill-text page; SECTION numbering and code references checked against the published text. Scope note This page reproduces the bill text as published; it is the enacted instrument, not the codified code sections as later integrated into the codes. SECTION 1. The Legislature finds and declares all of the following:\n(a) California is leading the world in artificial intelligence innovation and research through companies large and small and through the state’s remarkable public and private universities.\n(b) Artificial intelligence, including new advances in foundation models, has the potential to catalyze innovation and the rapid development of a wide range of benefits for Californians and the California economy, including advances in medicine, wildfire forecasting and prevention, and climate science, and to push the bounds of human creativity and capacity.\n(c) The Joint California Policy Working Group on AI Frontier Models has recommended sound principles for policy in artificial intelligence.\n(d) Targeted interventions to support effective artificial intelligence governance should balance the technology’s benefits and the potential for material risks.\n(e) In building a robust and transparent evidence environment, policymakers can align incentives to simultaneously protect consumers, leverage industry expertise, and recognize leading safety practices.\n(f) As industry actors conduct internal research on their technologies’ impacts, public trust in these technologies would significantly benefit from access to information regarding, and increased awareness of, frontier AI capabilities.\n(g) Greater transparency can also advance accountability, competition, and public trust.\n(h) Whistleblower protections and public-facing information sharing are key instruments to increase transparency.\n(i) Incident reporting systems enable monitoring of the post-deployment impacts of artificial intelligence.\n(j) Unless they are developed with careful diligence and reasonable precaution, there is concern that advanced artificial intelligence systems could have capabilities that pose catastrophic risks from both malicious uses and malfunctions, including artificial intelligence-enabled hacking, biological attacks, and loss of control.\n(k) With the frontier of artificial intelligence rapidly evolving, there is a need for legislation to track the frontier of artificial intelligence research and alert policymakers and the public to serious risks and harms from the very most advanced artificial intelligence systems, while avoiding burdening smaller companies behind the frontier.\n(l) While the major artificial intelligence developers have already voluntarily established the creation, use, and publication of frontier AI frameworks as an industry best practice, not all developers are providing reporting that is consistent and sufficient to ensure necessary transparency and protection of the public. Mandatory, standardized, and objective reporting by frontier developers is required to provide the government and the public with timely and accurate information.\n(m) Timely reporting of critical safety incidents to the government is essential to ensure that public authorities are promptly informed of ongoing and emerging risks to public safety. This reporting enables the government to monitor, assess, and respond effectively in the event that advanced capabilities emerge in frontier artificial intelligence models that may pose a threat to the public.\n(n) In the future, foundation models developed by smaller companies or that are behind the frontier may pose significant catastrophic risk, and additional legislation may be needed at that time.\n(o) The recent release of the Governor’s California Report on Frontier AI Policy and testimony from legislative hearings on artificial intelligence before the Legislature reflect the advances in AI model capabilities that could pose potential catastrophic risk in frontier artificial intelligence, which this act aims to address.\n(p) It is the intent of the Legislature to create more transparency, but collective safety will depend in part on frontier developers taking due care in their development and deployment of frontier models proportional to the scale of the foreseeable risks.\nSEC. 2. Chapter 25.1 (commencing with Section 22757.10) is added to Division 8 of the Business and Professions Code, to read:\nCHAPTER 25.1. Transparency in Frontier Artificial Intelligence Act 22757.10. This chapter shall be known as the Transparency in Frontier Artificial Intelligence Act.\n22757.11. For purposes of this chapter:\n(a) “Affiliate” means a person controlling, controlled by, or under common control with a specified person, directly or indirectly, through one or more intermediaries.\n(b) “Artificial intelligence model” means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.\n(c) (1) “Catastrophic risk” means a foreseeable and material risk that a frontier developer’s development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than one billion dollars ($1,000,000,000) in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following:\n(A) Providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon.\n(B) Engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense.\n(C) Evading the control of its frontier developer or user.\n(2) “Catastrophic risk” does not include a foreseeable and material risk from any of the following:\n(A) Information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model.\n(B) Lawful activity of the federal government.\n(C) Harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.\n(d) “Critical safety incident” means any of the following:\n(1) Unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury.\n(2) Harm resulting from the materialization of a catastrophic risk.\n(3) Loss of control of a frontier model causing death or bodily injury.\n(4) A frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.\n(e) (1) “Deploy” means to make a frontier model available to a third party for use, modification, copying, or combination with other software.\n(2) “Deploy” does not include making a frontier model available to a third party for the primary purpose of developing or evaluating the frontier model.\n(f) “Foundation model” means an artificial intelligence model that is all of the following:\n(1) Trained on a broad data set.\n(2) Designed for generality of output.\n(3) Adaptable to a wide range of distinctive tasks.\n(g) “Frontier AI framework” means documented technical and organizational protocols to manage, assess, and mitigate catastrophic risks.\n(h) “Frontier developer” means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in subdivision (i).\n(i) (1) “Frontier model” means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations.\n(2) The quantity of computing power described in paragraph (1) shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.\n(j) “Large frontier developer” means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of five hundred million dollars ($500,000,000) in the preceding calendar year.\n(k) “Model weight” means a numerical parameter in a frontier model that is adjusted through training and that helps determine how inputs are transformed into outputs.\n(l) “Property” means tangible or intangible property.\n22757.12. (a) A large frontier developer shall write, implement, comply with, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer’s frontier models and describes how the large frontier developer approaches all of the following:\n(1) Incorporating national standards, international standards, and industry-consensus best practices into its frontier AI framework.\n(2) Defining and assessing thresholds used by the large frontier developer to identify and assess whether a frontier model has capabilities that could pose a catastrophic risk, which may include multiple-tiered thresholds.\n(3) Applying mitigations to address the potential for catastrophic risks based on the results of assessments undertaken pursuant to paragraph (2).\n(4) Reviewing assessments and adequacy of mitigations as part of the decision to deploy a frontier model or use it extensively internally.\n(5) Using third parties to assess the potential for catastrophic risks and the effectiveness of mitigations of catastrophic risks.\n(6) Revisiting and updating the frontier AI framework, including any criteria that trigger updates and how the large frontier developer determines when its frontier models are substantially modified enough to require disclosures pursuant to subdivision (c).\n(7) Cybersecurity practices to secure unreleased model weights from unauthorized modification or transfer by internal or external parties.\n(8) Identifying and responding to critical safety incidents.\n(9) Instituting internal governance practices to ensure implementation of these processes.\n(10) Assessing and managing catastrophic risk resulting from the internal use of its frontier models, including risks resulting from a frontier model circumventing oversight mechanisms.\n(b) (1) A large frontier developer shall review and, as appropriate, update its frontier AI framework at least once per year.\n(2) If a large frontier developer makes a material modification to its frontier AI framework, the large frontier developer shall clearly and conspicuously publish the modified frontier AI framework and a justification for that modification within 30 days.\n(c) (1) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a frontier developer shall clearly and conspicuously publish on its internet website a transparency report containing all of the following:\n(A) The internet website of the frontier developer.\n(B) A mechanism that enables a natural person to communicate with the frontier developer.\n(C) The release date of the frontier model.\n(D) The languages supported by the frontier model.\n(E) The modalities of output supported by the frontier model.\n(F) The intended uses of the frontier model.\n(G) Any generally applicable restrictions or conditions on uses of the frontier model.\n(2) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a large frontier developer shall include in the transparency report required by paragraph (1) summaries of all of the following:\n(A) Assessments of catastrophic risks from the frontier model conducted pursuant to the large frontier developer’s frontier AI framework.\n(B) The results of those assessments.\n(C) The extent to which third-party evaluators were involved.\n(D) Other steps taken to fulfill the requirements of the frontier AI framework with respect to the frontier model.\n(3) A frontier developer that publishes the information described in paragraph (1) or (2) as part of a larger document, including a system card or model card, shall be deemed in compliance with the applicable paragraph.\n(4) A frontier developer is encouraged, but not required, to make disclosures described in this subdivision that are consistent with, or superior to, industry best practices.\n(d) A large frontier developer shall transmit to the Office of Emergency Services a summary of any assessment of catastrophic risk resulting from internal use of its frontier models every three months or pursuant to another reasonable schedule specified by the large frontier developer and communicated in writing to the Office of Emergency Services with written updates, as appropriate.\n(e) (1) (A) A frontier developer shall not make a materially false or misleading statement about catastrophic risk from its frontier models or its management of catastrophic risk.\n(B) A large frontier developer shall not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework.\n(2) This subdivision does not apply to a statement that was made in good faith and was reasonable under the circumstances.\n(f) (1) When a frontier developer publishes documents to comply with this section, the frontier developer may make redactions to those documents that are necessary to protect the frontier developer’s trade secrets, the frontier developer’s cybersecurity, public safety, or the national security of the United States or to comply with any federal or state law.\n(2) If a frontier developer redacts information in a document pursuant to this subdivision, the frontier developer shall describe the character and justification of the redaction in any published version of the document to the extent permitted by the concerns that justify redaction and shall retain the unredacted information for five years.\n22757.13. (a) The Office of Emergency Services shall establish a mechanism to be used by a frontier developer or a member of the public to report a critical safety incident that includes all of the following:\n(1) The date of the critical safety incident.\n(2) The reasons the incident qualifies as a critical safety incident.\n(3) A short and plain statement describing the critical safety incident.\n(4) Whether the incident was associated with internal use of a frontier model.\n(b) (1) The Office of Emergency Services shall establish a mechanism to be used by a large frontier developer to confidentially submit summaries of any assessments of the potential for catastrophic risk resulting from internal use of its frontier models.\n(2) The Office of Emergency Services shall take all necessary precautions to limit access to any reports related to internal use of frontier models to only personnel with a specific need to know the information and to protect the reports from unauthorized access.\n(c) (1) Subject to paragraph (2), a frontier developer shall report any critical safety incident pertaining to one or more of its frontier models to the Office of Emergency Services within 15 days of discovering the critical safety incident.\n(2) If a frontier developer discovers that a critical safety incident poses an imminent risk of death or serious physical injury, the frontier developer shall disclose that incident within 24 hours to an authority, including any law enforcement agency or public safety agency with jurisdiction, that is appropriate based on the nature of that incident and as required by law.\n(3) A frontier developer that discovers information about a critical safety incident after filing the initial report required by this subdivision may file an amended report.\n(4) A frontier developer is encouraged, but not required, to report critical safety incidents pertaining to foundation models that are not frontier models.\n(d) The Office of Emergency Services shall review critical safety incident reports submitted by frontier developers and may review reports submitted by members of the public.\n(e) (1) The Attorney General or the Office of Emergency Services may transmit reports of critical safety incidents and reports from covered employees made pursuant to Chapter 5.1 (commencing with Section 1107) of Part 3 of Division 2 of the Labor Code to the Legislature, the Governor, the federal government, or appropriate state agencies.\n(2) The Attorney General or the Office of Emergency Services shall strongly consider any risks related to trade secrets, public safety, cybersecurity of a frontier developer, or national security when transmitting reports.\n(f) A report of a critical safety incident submitted to the Office of Emergency Services pursuant to this section, a report of assessments of catastrophic risk from internal use pursuant to Section 22757.12, and a covered employee report made pursuant to Chapter 5.1 (commencing with Section 1107) of Part 3 of Division 2 of the Labor Code are exempt from the California Public Records Act (Division 10 (commencing with Section 7920.000) of Title 1 of the Government Code).\n(g) (1) Beginning January 1, 2027, and annually thereafter, the Office of Emergency Services shall produce a report with anonymized and aggregated information about critical safety incidents that have been reviewed by the Office of Emergency Services since the preceding report.\n(2) The Office of Emergency Services shall not include information in a report pursuant to this subdivision that would compromise the trade secrets or cybersecurity of a frontier developer, public safety, or the national security of the United States or that would be prohibited by any federal or state law.\n(3) The Office of Emergency Services shall transmit a report pursuant to this subdivision to the Legislature, pursuant to Section 9795, and to the Governor.\n(h) The Office of Emergency Services may adopt regulations designating one or more federal laws, regulations, or guidance documents that meet all of the following conditions for the purposes of subdivision (i):\n(1) (A) The law, regulation, or guidance document imposes or states standards or requirements for critical safety incident reporting that are substantially equivalent to, or stricter than, those required by this section.\n(B) The law, regulation, or guidance document described in subparagraph (A) does not need to require critical safety incident reporting to the State of California.\n(2) The law, regulation, or guidance document is intended to assess, detect, or mitigate the catastrophic risk.\n(i) (1) A frontier developer that intends to comply with this section by complying with the requirements of, or meeting the standards stated by, a federal law, regulation, or guidance document designated pursuant to subdivision\n(h) shall declare its intent to do so to the Office of Emergency Services.\n(2) After a frontier developer has declared its intent pursuant to paragraph (1), both of the following apply:\n(A) The frontier developer shall be deemed in compliance with this section to the extent that the frontier developer meets the standards of, or complies with the requirements imposed or stated by, the designated federal law, regulation, or guidance document until the frontier developer declares the revocation of that intent to the Office of Emergency Services or the Office of Emergency Services revokes a relevant regulation pursuant to subdivision (j).\n(B) The failure by a frontier developer to meet the standards of, or comply with the requirements stated by, the federal law, regulation, or guidance document designated pursuant to subdivision\n(h) shall constitute a violation of this chapter.\n(j) The Office of Emergency Services shall revoke a regulation adopted under subdivision\n(h) if the requirements of subdivision\n(h) are no longer met.\n22757.14. (a) On or before January 1, 2027, and annually thereafter, the Department of Technology shall assess recent evidence and developments relevant to the purposes of this chapter and shall make recommendations about whether and how to update any of the following definitions for the purposes of this chapter to ensure that they accurately reflect technological developments, scientific literature, and widely accepted national and international standards:\n(1) “Frontier model” so that it applies to foundation models at the frontier of artificial intelligence development.\n(2) “Frontier developer” so that it applies to developers of frontier models who are themselves at the frontier of artificial intelligence development.\n(3) “Large frontier developer” so that it applies to well-resourced frontier developers.\n(b) In making recommendations pursuant to this section, the Department of Technology shall take into account all of the following:\n(1) Similar thresholds used in international standards or federal law, guidance, or regulations for the management of catastrophic risk and shall align with a definition adopted in a federal law or regulation to the extent that it is consistent with the purposes of this chapter.\n(2) Input from stakeholders, including academics, industry, the open-source community, and governmental entities.\n(3) The extent to which a person will be able to determine, before beginning to train or deploy a foundation model, whether that person will be subject to the definition as a frontier developer or as a large frontier developer with an aim toward allowing earlier determinations if possible.\n(4) The complexity of determining whether a person or foundation model is covered, with an aim toward allowing simpler determinations if possible.\n(5) The external verifiability of determining whether a person or foundation model is covered, with an aim toward definitions that are verifiable by parties other than the frontier developer.\n(c) Upon developing recommendations pursuant to this section, the Department of Technology shall submit a report to the Legislature, pursuant to Section 9795 of the Government Code, with those recommendations.\n(d) (1) Beginning January 1, 2027, and annually thereafter, the Attorney General shall produce a report with anonymized and aggregated information about reports from covered employees made pursuant to Chapter 5.1 (commencing with Section 1107) of Part 3 of Division 2 of the Labor Code that have been reviewed by the Attorney General since the preceding report.\n(2) The Attorney General shall not include information in a report pursuant to this subdivision that would compromise the trade secrets or cybersecurity of a frontier developer, confidentiality of a covered employee, public safety, or the national security of the United States or that would be prohibited by any federal or state law.\n(3) The Attorney General shall transmit a report pursuant to this subdivision to the Legislature, pursuant to Section 9795 of the Government Code, and to the Governor.\n22757.15. (a) A large frontier developer that fails to publish or transmit a compliant document required to be published or transmitted under this chapter, makes a statement in violation of subdivision\n(e) of Section 22757.12, fails to report an incident as required by Section 22757.13, or fails to comply with its own frontier AI framework shall be subject to a civil penalty in an amount dependent upon the severity of the violation that does not exceed one million dollars ($1,000,000) per violation.\n(b) A civil penalty described in this section shall be recovered in a civil action brought only by the Attorney General.\n22757.16. The loss of value of equity does not count as damage to or loss of property for the purposes of this chapter.\nSEC. 3. Section 11546.8 is added to the Government Code, to read:\n11546.8. (a) There is hereby established within the Government Operations Agency a consortium that shall develop, pursuant to this section, a framework for the creation of a public cloud computing cluster to be known as “CalCompute.”\n(b) The consortium shall develop a framework for the creation of CalCompute that advances the development and deployment of artificial intelligence that is safe, ethical, equitable, and sustainable by doing, at a minimum, both of the following:\n(1) Fostering research and innovation that benefits the public.\n(2) Enabling equitable innovation by expanding access to computational resources.\n(c) The consortium shall make reasonable efforts to ensure that CalCompute is established within the University of California to the extent possible.\n(d) CalCompute shall include, but not be limited to, all of the following:\n(1) A fully owned and hosted cloud platform.\n(2) Necessary human expertise to operate and maintain the platform.\n(3) Necessary human expertise to support, train, and facilitate the use of CalCompute.\n(e) The consortium shall operate in accordance with all relevant labor and workforce laws and standards.\n(f) (1) On or before January 1, 2027, the Government Operations Agency shall submit, pursuant to Section 9795, a report from the consortium to the Legislature with the framework developed pursuant to subdivision\n(b) for the creation and operation of CalCompute.\n(2) The report required by this subdivision shall include all of the following elements:\n(A) A landscape analysis of California’s current public, private, and nonprofit cloud computing platform infrastructure.\n(B) An analysis of the cost to the state to build and maintain CalCompute and recommendations for potential funding sources.\n(C) Recommendations for the governance structure and ongoing operation of CalCompute.\n(D) Recommendations for the parameters for use of CalCompute, including, but not limited to, a process for determining which users and projects will be supported by CalCompute.\n(E) An analysis of the state’s technology workforce and recommendations for equitable pathways to strengthen the workforce, including the role of CalCompute.\n(F) A detailed description of any proposed partnerships, contracts, or licensing agreements with nongovernmental entities, including, but not limited to, technology-based companies, that demonstrates compliance with the requirements of subdivisions\n(c) and (d).\n(G) Recommendations regarding how the creation and ongoing management of CalCompute can prioritize the use of the current public sector workforce.\n(g) The consortium shall, consistent with state constitutional law, consist of 14 members as follows:\n(1) Four representatives of the University of California and other public and private academic research institutions and national laboratories appointed by the Secretary of Government Operations.\n(2) Three representatives of impacted workforce labor organizations appointed by the Speaker of the Assembly.\n(3) Three representatives of stakeholder groups with relevant expertise and experience, including, but not limited to, ethicists, consumer rights advocates, and other public interest advocates appointed by the Senate Rules Committee.\n(4) Four experts in technology and artificial intelligence to provide technical assistance appointed by the Secretary of Government Operations.\n(h) The members of the consortium shall serve without compensation, but shall be reimbursed for all necessary expenses actually incurred in the performance of their duties.\n(i) The consortium shall be dissolved upon submission of the report required by paragraph (1) of subdivision\n(f) to the Legislature.\n(j) If CalCompute is established within the University of California, the University of California may receive private donations for the purposes of implementing CalCompute.\n(k) This section shall become operative only upon an appropriation in a budget act, or other measure, for the purposes of this section.\nSEC. 4. Chapter 5.1 (commencing with Section 1107) is added to Part 3 of Division 2 of the Labor Code, to read:\nCHAPTER 5.1. Whistleblower Protections: Catastrophic Risks in AI Foundation Models 1107. For purposes of this chapter:\n(a) (1) “Catastrophic risk” means a foreseeable and material risk that a frontier developer’s development, storage, use, or deployment of a foundation model will materially contribute to the death of, or serious injury to, more than 50 people or more than one billion dollars ($1,000,000,000) in damage to, or loss of, property arising from a single incident involving a foundation model doing any of the following:\n(A) Providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon.\n(B) Engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense.\n(C) Evading the control of its frontier developer or user.\n(2) “Catastrophic risk” does not include a foreseeable and material risk from any of the following:\n(A) Information that a foundation model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model.\n(B) Lawful activity of the federal government.\n(C) Harm caused by a foundation model in combination with other software where the foundation model did not materially contribute to the harm.\n(b) “Covered employee” means an employee responsible for assessing, managing, or addressing risk of critical safety incidents.\n(c) “Critical safety incident” means any of the following:\n(1) Unauthorized access to, modification of, or exfiltration of the model weights of a foundation model that results in death, bodily injury, or damage to, or loss of, property.\n(2) Harm resulting from the materialization of a catastrophic risk.\n(3) Loss of control of a foundation model causing death or bodily injury.\n(4) A foundation model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.\n(d) “Foundation model” has the meaning defined in Section 22757.11 of the Business and Professions Code.\n(e) “Frontier developer” has the meaning defined in Section 22757.11 of the Business and Professions Code.\n(f) “Large frontier developer” has the meaning defined in Section 22757.11 of the Business and Professions Code.\n1107.1. (a) A frontier developer shall not make, adopt, enforce, or enter into a rule, regulation, policy, or contract that prevents a covered employee from disclosing, or retaliates against a covered employee for disclosing, information to the Attorney General, a federal authority, a person with authority over the covered employee, or another covered employee who has authority to investigate, discover, or correct the reported issue, if the covered employee has reasonable cause to believe that the information discloses either of the following:\n(1) The frontier developer’s activities pose a specific and substantial danger to the public health or safety resulting from a catastrophic risk.\n(2) The frontier developer has violated Chapter 25.1 (commencing with Section 22757.10) of Division 8 of the Business and Professions Code.\n(b) A frontier developer shall not enter into a contract that prevents a covered employee from making a disclosure protected under Section 1102.5.\n(c) A covered employee may use the hotline described in Section 1102.7 to make reports described in subdivision (a).\n(d) A frontier developer shall provide a clear notice to all covered employees of their rights and responsibilities under this section, including by doing either of the following:\n(1) At all times posting and displaying within any workplace maintained by the frontier developer a notice to all covered employees of their rights under this section, ensuring that any new covered employee receives equivalent notice, and ensuring that any covered employee who works remotely periodically receives an equivalent notice.\n(2) At least once each year, providing written notice to each covered employee of the covered employee’s rights under this section and ensuring that the notice is received and acknowledged by all of those covered employees.\n(e) (1) A large frontier developer shall provide a reasonable internal process through which a covered employee may anonymously disclose information to the large frontier developer if the covered employee believes in good faith that the information indicates that the large frontier developer’s activities present a specific and substantial danger to the public health or safety resulting from a catastrophic risk or that the large frontier developer violated Chapter 25.1 (commencing with Section 22757.10) of Division 8 of the Business and Professions Code, including a monthly update to the person who made the disclosure regarding the status of the large frontier developer’s investigation of the disclosure and the actions taken by the large frontier developer in response to the disclosure.\n(2) (A) Except as provided in subparagraph (B), the disclosures and responses of the process required by this subdivision shall be shared with officers and directors of the large frontier developer at least once each quarter.\n(B) If a covered employee has alleged wrongdoing by an officer or director of the large frontier developer in a disclosure or response, subparagraph (A) shall not apply with respect to that officer or director.\n(f) The court is authorized to award reasonable attorney’s fees to a plaintiff who brings a successful action for a violation of this section.\n(g) In a civil action brought pursuant to this section, once it has been demonstrated by a preponderance of the evidence that an activity proscribed by this section was a contributing factor in the alleged prohibited action against the covered employee, the frontier developer shall have the burden of proof to demonstrate by clear and convincing evidence that the alleged action would have occurred for legitimate, independent reasons even if the covered employee had not engaged in activities protected by this section.\n(h) (1) In a civil action or administrative proceeding brought pursuant to this section, a covered employee may petition the superior court in any county wherein the violation in question is alleged to have occurred, or wherein the person resides or transacts business, for appropriate temporary or preliminary injunctive relief.\n(2) Upon the filing of the petition for injunctive relief, the petitioner shall cause notice thereof to be served upon the person, and thereupon the court shall have jurisdiction to grant temporary injunctive relief as the court deems just and proper.\n(3) In addition to any harm resulting directly from a violation of this section, the court shall consider the chilling effect on other covered employees asserting their rights under this section in determining whether temporary injunctive relief is just and proper.\n(4) Appropriate injunctive relief shall be issued on a showing that reasonable cause exists to believe a violation has occurred.\n(5) An order authorizing temporary injunctive relief shall remain in effect until an administrative or judicial determination or citation has been issued, or until the completion of a review pursuant to subdivision\n(b) of Section 98.74, whichever is longer, or at a certain time set by the court. Thereafter, a preliminary or permanent injunction may be issued if it is shown to be just and proper. Any temporary injunctive relief shall not prohibit a frontier developer from disciplining or terminating a covered employee for conduct that is unrelated to the claim of the retaliation.\n(i) Notwithstanding Section 916 of the Code of Civil Procedure, injunctive relief granted pursuant to this section shall not be stayed pending appeal.\n(j) (1) This section does not impair or limit the applicability of Section 1102.5, including with respect to the rights of employees who are not covered employees to report violations of this chapter or Chapter 25.1 (commencing with Section 22757.10) of Division 8 of the Business and Professions Code.\n(2) The remedies provided by this section are cumulative to each other and the remedies or penalties available under all other laws of this state.\n1107.2. The loss of value of equity does not count as damage to or loss of property for the purposes of this chapter.\nSEC. 5. (a) The provisions of this act are severable. If any provision of this act or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.\n(b) This act shall be liberally construed to effectuate its purposes.\n(c) The duties and obligations imposed by this act are cumulative with any other duties or obligations imposed under other law and shall not be construed to relieve any party from any duties or obligations imposed under other law and do not limit any rights or remedies under existing law.\n(d) This act shall not apply to the extent that it strictly conflicts with the terms of a contract between a federal government entity and a frontier developer.\n(e) This act shall not apply to the extent that it is preempted by federal law.\n(f) This act preempts any rule, regulation, code, ordinance, or other law adopted by a city, county, city and county, municipality, or local agency on or after January 1, 2025, specifically related to the regulation of frontier developers with respect to their management of catastrophic risk.\nSEC. 6. The Legislature finds and declares that Section 2 of this act, which adds Chapter 25.1 (commencing with Section 22757.10) to Division 8 of the Business and Professions Code, imposes a limitation on the public’s right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:\nInformation in critical safety incident reports, assessments of risks from internal use, and reports from covered employees may contain information that could threaten public safety or compromise the response to an incident if disclosed to the public.\n","permalink":"https://ai.intlaws.com/en/compliance/us/california-sb-53/","summary":"Official text of California Senate Bill 53 (2025–2026 session), which adds transparency and incident-reporting duties for developers of large frontier artificial intelligence models — amending the Business and Professions Code (new Chapter 25.1, commencing with Section 22757.10), the Government Code (Section 11546.8) and the Labor Code (new Chapter 5.1, commencing with Section 1107). Registered with the Secretary of State on 29 September 2025.","title":"California Transparency in Frontier Artificial Intelligence Act (TFAIA)"},{"content":"Version and sources (verifiable)\nItem Content Instrument Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data Reference ETS No. 108 (European Treaty Series No. 108) Opened for signature Strasbourg, 28 January 1981 Structure 7 chapters, 20 articles Status This page reproduces the original 1981 text. The Convention has since been modernised by Protocol CETS No. 223 (\u0026ldquo;Convention 108+\u0026rdquo;) — see the separate entry in this library. The amending Protocol has NOT yet entered into force: as of 2026-09-22, 34 of the required 38 ratifications have been deposited (or ratification by all ETS 108 Parties is required) — Council of Europe announcement Official text (English) https://rm.coe.int/1680078b37 (Council of Europe document repository) Treaty Office record https://www.coe.int/en/web/conventions/full-list?module=treaty-detail\u0026amp;treatynum=108 Official name Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108, 1981) Chinese version No official Chinese text (official languages: English and French). A Chinese translation by our editorial team is in preparation and will be marked non-official. Retrieval \u0026amp; verification 2026-09-22, retrieved through a rendering proxy (r.jina.ai) because the Council of Europe blocks automated direct access from this network. Text de-hyphenated; the two-column PDF layout merges chapter and article headings on one line, so those lines were split before parsing; article numbers accepted only in strict ascending order (1–20) to exclude cross-references. | 中文译本 | 无官方中文译本（欧洲理事会官方文本为英文、法文两种同等作准文本）。本页中文译文由本网据官方英文文本逐条译校，为非官方译本、仅供参考 → 中文全文 |\nConvention for the Protection of Individuals with regard to Automatic Processing of Personal Data Preamble — The member States of the Council of Europe, signatory hereto, considering that the aim of the Council of Europe is to achieve greater unity between its members, based in particular on respect for the rule of law, as well as human rights and fundamental freedoms; considering that it is desirable to extend the safeguards for everyone\u0026rsquo;s rights and fundamental freedoms, and in particular the right to the respect for privacy, taking account of the increasing flow across frontiers of personal data undergoing automatic processing; reaffirming at the same time their commitment to freedom of information regardless of frontiers; recognising that it is necessary to reconcile the fundamental values of the respect for privacy and the free flow of information between peoples, have agreed as follows:\nPreamble — # Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data The member States of the Council of Europe, signatory hereto, Considering that the aim of the Council of Europe is to achieve greater unity between its members, based in particular on respect for the rule of law, as well as human rights and fundamental freedoms; Considering that it is desirable to extend the safeguards for everyone\u0026rsquo;s rights and fundamental freedoms, and in particular the right to the respect for privacy, taking account of the increasing flow across frontiers of personal data undergoing automatic processing; Reaffirming at the same time their commitment to freedom of information regardless of frontiers; Recognising that it is necessary to reconcile the fundamental values of the respect for privacy and the free flow of information between peoples, Have agreed as follows:\nChapter I – General provisions Article 1 – Object and purpose\nThe purpose of this Convention is to secure in the territory of each Party for every individual, whatever his nationality or residence, respect for his rights and fundamental freedoms, and in particular his right to privacy, with regard to automatic processing of personal data relating to him (\u0026ldquo;data protection\u0026rdquo;).\nArticle 2 – Definitions\nFor the purposes of this Convention:\n(a) \u0026ldquo;personal data\u0026rdquo; means any information relating to an identified or identifiable individual (\u0026ldquo;data subject\u0026rdquo;);\n(b) \u0026ldquo;automated data file\u0026rdquo; means any set of data undergoing automatic processing;\n(c) \u0026ldquo;automatic processing\u0026rdquo; includes the following operations if carried out in whole or in part by automated means: storage of data, carrying out of logical and/or arithmetical operations on those data, their alteration, erasure, retrieval or dissemination;\n(d) \u0026ldquo;controller of the file\u0026rdquo; means the natural or legal person, public authority, agency or any other body who is competent according to the national law to decide what should be the purpose of the automated data file, which categories of personal data should be stored and which operations should be applied to them.\nArticle 3 – Scope\n(1) The Parties undertake to apply this Convention to automated personal data files and automatic processing of personal data in the public and private sectors.\n(2) Any State may, at the time of signature or when depositing its instrument of ratification, acceptance, approval or accession, or at any later time, give notice by a declaration addressed to the Secretary General of the Council of Europe:\n(a) that it will not apply this Convention to certain categories of automated personal data files, a list of which will be deposited. In this list it shall not include, however, categories of automated data files subject under its domestic law to data protection provisions. Consequently, it shall amend this list by a new declaration whenever additional categories of automated personal data files are subjected to data protection provisions under its domestic law;\n(b) that it will also apply this Convention to information relating to groups of persons, associations, foundations, companies, corporations and any other bodies consisting directly or indirectly of individuals, whether or not such bodies possess legal personality;\n(c) that it will also apply this Convention to personal data files which are not processed automatically.\n(3) Any State which has extended the scope of this Convention by any of the declarations provided for in sub-paragraph 2.b or c above may give notice in the said declaration that such extensions shall apply only to certain categories of personal data files, a list of which will be deposited.\n(4) Any Party which has excluded certain categories of automated personal data files by a declaration provided for in sub-paragraph 2.a above may not claim the application of this Convention to such categories by a Party which has not excluded them.\n(5) Likewise, a Party which has not made one or other of the extensions provided for in sub-paragraphs 2.b and c above may not claim the application of this Convention on these points with respect to a Party which has made such extensions.\n(6) The declarations provided for in paragraph 2 above shall take effect from the moment of the entry into force of the Convention with regard to the State which has made them if they have been made at the time of signature or deposit of its instrument of ratification, acceptance, approval or accession, or three months after their receipt by the Secretary General of the Council of Europe if they have been made at any later time. These declarations may be withdrawn, in whole or in part, by a notification addressed to the Secretary General of the Council of Europe. Such withdrawals shall take effect three months after the date of receipt of such notification.\nChapter II – Basic principles for data protection Article 4 – Duties of the Parties\n(1) Each Party shall take the necessary measures in its domestic law to give effect to the basic principles for data protection set out in this chapter.\n(2) These measures shall be taken at the latest at the time of entry into force of this Convention in respect of that Party.\nArticle 5 – Quality of data\nPersonal data undergoing automatic processing shall be:\n(a) obtained and processed fairly and lawfully;\n(b) stored for specified and legitimate purposes and not used in a way incompatible with those purposes;\n(c) adequate, relevant and not excessive in relation to the purposes for which they are stored;\n(d) accurate and, where necessary, kept up to date;\n(e) preserved in a form which permits identification of the data subjects for no longer than is required for the purpose for which those data are stored.\nArticle 6 – Special categories of data\nPersonal data revealing racial origin, political opinions or religious or other beliefs, as well as personal data concerning health or sexual life, may not be processed automatically unless domestic law provides appropriate safeguards. The same shall apply to personal data relating to criminal convictions.\nArticle 7 – Data security\nAppropriate security measures shall be taken for the protection of personal data stored in automated data files against accidental or unauthorised destruction or accidental loss as well as against unauthorised access, alteration or dissemination.\nArticle 8 – Additional safeguards for the data subject\nAny person shall be enabled:\n(a) to establish the existence of an automated personal data file, its main purposes, as well as the identity and habitual residence or principal place of business of the controller of the file;\n(b) to obtain at reasonable intervals and without excessive delay or expense confirmation of whether personal data relating to him are stored in the automated data file as well as communication to him of such data in an intelligible form;\n(c) to obtain, as the case may be, rectification or erasure of such data if these have been processed contrary to the provisions of domestic law giving effect to the basic principles set out in Articles 5 and 6 of this Convention;\n(d) to have a remedy if a request for confirmation or, as the case may be, communication, rectification or erasure as referred to in paragraphs b and c of this article is not complied with.\nArticle 9 – Exceptions and restrictions\n(1) No exception to the provisions of Articles 5, 6 and 8 of this Convention shall be allowed except within the limits defined in this article.\n(2) Derogation from the provisions of Articles 5, 6 and 8 of this Convention shall be allowed when such derogation is provided for by the law of the Party and constitutes a necessary measure in a democratic society in the interests of:\n(a) protecting State security, public safety, the monetary interests of the State or the suppression of criminal offences;\n(b) protecting the data subject or the rights and freedoms of others.\n(3) Restrictions on the exercise of the rights specified in Article 8, paragraphs b, c and d, may be provided by law with respect to automated personal data files used for statistics or for scientific research purposes when there is obviously no risk of an infringement of the privacy of the data subjects.\nArticle 10 – Sanctions and remedies\nEach Party undertakes to establish appropriate sanctions and remedies for violations of provisions of domestic law giving effect to the basic principles for data protection set out in this chapter.\nArticle 11 – Extended protection\nNone of the provisions of this chapter shall be interpreted as limiting or otherwise affecting the possibility for a Party to grant data subjects a wider measure of protection than that stipulated in this Convention.\nChapter III – Transborder data flows Article 12 – Transborder flows of personal data and domestic law\n(1) The following provisions shall apply to the transfer across national borders, by whatever medium, of personal data undergoing automatic processing or collected with a view to their being automatically processed.\n(2) A Party shall not, for the sole purpose of the protection of privacy, prohibit or subject to special authorisation transborder flows of personal data going to the territory of another Party.\n(3) Nevertheless, each Party shall be entitled to derogate from the provisions of paragraph 2:\n(a) insofar as its legislation includes specific regulations for certain categories of personal data or of automated personal data files, because of the nature of those data or those files, except where the regulations of the other Party provide an equivalent protection;\n(b) when the transfer is made from its territory to the territory of a non-Contracting State through the intermediary of the territory of another Party, in order to avoid such transfers resulting in circumvention of the legislation of the Party referred to at the beginning of this paragraph.\nChapter IV – Mutual assistance Article 13 – Co-operation between Parties\n(1) The Parties agree to render each other mutual assistance in order to implement this Convention.\n(2) For that purpose:\n(a) each Party shall designate one or more authorities, the name and address of each of which it shall communicate to the Secretary General of the Council of Europe;\n(b) each Party which has designated more than one authority shall specify in its communication referred to in the previous sub-paragraph the competence of each authority.\n(3) An authority designated by a Party shall at the request of an authority designated by another Party:\n(a) furnish information on its law and administrative practice in the field of data protection;\n(b) take, in conformity with its domestic law and for the sole purpose of protection of privacy, all appropriate measures for furnishing factual information relating to specific automatic processing carried out in its territory, with the exception however of the personal data being processed.\nArticle 14 – Assistance to data subjects resident abroad\n(1) Each Party shall assist any person resident abroad to exercise the rights conferred by its domestic law giving effect to the principles set out in Article 8 of this Convention.\n(2) When such a person resides in the territory of another Party he shall be given the option of submitting his request through the intermediary of the authority designated by that Party.\n(3) The request for assistance shall contain all the necessary particulars, relating inter alia to:\n(a) the name, address and any other relevant particulars identifying the person making the request;\n(b) the automated personal data file to which the request pertains, or its controller; c the purpose of the request.\nArticle 15 – Safeguards concerning assistance rendered by designated authorities\n(1) An authority designated by a Party which has received information from an authority designated by another Party either accompanying a request for assistance or in reply to its own request for assistance shall not use that information for purposes other than those specified in the request for assistance.\n(2) Each Party shall see to it that the persons belonging to or acting on behalf of the designated authority shall be bound by appropriate obligations of secrecy or confidentiality with regard to that information.\n(3) In no case may a designated authority be allowed to make under Article 14, paragraph 2, a request for assistance on behalf of a data subject resident abroad, of its own accord and without the express consent of the person concerned.\nArticle 16 – Refusal of requests for assistance\nA designated authority to which a request for assistance is addressed under Articles 13 or 14 of this Convention may not refuse to comply with it unless:\n(a) the request is not compatible with the powers in the field of data protection of the authorities responsible for replying;\n(b) the request does not comply with the provisions of this Convention;\n(c) compliance with the request would be incompatible with the sovereignty, security or public policy ( ordre public ) of the Party by which it was designated, or with the rights and fundamental freedoms of persons under the jurisdiction of that Party.\nArticle 17 – Costs and procedures of assistance\n(1) Mutual assistance which the Parties render each other under Article 13 and assistance they render to data subjects abroad under Article 14 shall not give rise to the payment of any costs or fees other than those incurred for experts and interpreters. The latter costs or fees shall be borne by the Party which has designated the authority making the request for assistance.\n(2) The data subject may not be charged costs or fees in connection with the steps taken on his behalf in the territory of another Party other than those lawfully payable by residents of that Party.\n(3) Other details concerning the assistance relating in particular to the forms and procedures and the languages to be used, shall be established directly between the Parties concerned.\nChapter V – Consultative Committee Article 18 – Composition of the committee\n(1) A Consultative Committee shall be set up after the entry into force of this Convention.\n(2) Each Party shall appoint a representative to the committee and a deputy representative. Any member State of the Council of Europe which is not a Party to the Convention shall have the right to be represented on the committee by an observer.\n(3) The Consultative Committee may, by unanimous decision, invite any non-member State of the Council of Europe which is not a Party to the Convention to be represented by an observer at a given meeting.\nArticle 19 – Functions of the committee\nThe Consultative Committee:\n(a) may make proposals with a view to facilitating or improving the application of the Convention;\n(b) may make proposals for amendment of this Convention in accordance with Article 21;\n(c) shall formulate its opinion on any proposal for amendment of this Convention which is referred to it in accordance with Article 21, paragraph 3;\n(d) may, at the request of a Party, express an opinion on any question concerning the application of this Convention.\nArticle 20 – Procedure\n(1) The Consultative Committee shall be convened by the Secretary General of the Council of Europe. Its first meeting shall be held within twelve months of the entry into force of this Convention. It shall subsequently meet at least once every two years and in any case when one-third of the representatives of the Parties request its convocation.\n(2) A majority of representatives of the Parties shall constitute a quorum for a meeting of the Consultative Committee.\n(3) After each of its meetings, the Consultative Committee shall submit to the Committee of Ministers of the Council of Europe a report on its work and on the functioning of the Convention.\n(4) Subject to the provisions of this convention, the Consultative Committee shall draw up its own Rules of Procedure.\nChapter VI – Amendments Article 21 – Amendments\n(1) Amendments to this Convention may be proposed by a Party, the Committee of Ministers of the Council of Europe or the Consultative Committee.\n(2) Any proposal for amendment shall be communicated by the Secretary General of the Council of Europe to the member States of the Council of Europe and to every non-member State which has acceded to or has been invited to accede to this Convention in accordance with the provisions of Article 23.\n(3) Moreover, any amendment proposed by a Party or the Committee of Ministers shall be communicated to the Consultative Committee, which shall submit to the Committee of Ministers its opinion on that proposed amendment.\n(4) The Committee of Ministers shall consider the proposed amendment and any opinion submitted by the Consultative Committee and may approve the amendment.\n(5) The text of any amendment approved by the Committee of Ministers in accordance with paragraph 4 of this article shall be forwarded to the Parties for acceptance.\n(6) Any amendment approved in accordance with paragraph 4 of this article shall come into force on the thirtieth day after all Parties have informed the Secretary General of their acceptance thereof.\nChapter VII – Final clauses Article 22 – Entry into force\n(1) This Convention shall be open for signature by the member States of the Council of Europe. It is subject to ratification, acceptance or approval. Instruments of ratification, acceptance or approval shall be deposited with the Secretary General of the Council of Europe.\n(2) This Convention shall enter into force on the first day of the month following the expiration of a period of three months after the date on which five member States of the Council of Europe have expressed their consent to be bound by the Convention in accordance with the provisions of the preceding paragraph.\n(3) In respect of any member State which subsequently expresses its consent to be bound by it, the Convention shall enter into force on the first day of the month following the expiration of a period of three months after the date of deposit of the instrument of ratification, acceptance or approval.\nArticle 23 – Accession by non-member States\n(1) After the entry into force of this Convention, the Committee of Ministers of the Council of Europe may invite any State not a member of the Council of Europe to accede to this Convention by a decision taken by the majority provided for in Article 20.d of the Statute of the Council of Europe and by the unanimous vote of the representatives of the Contracting States entitled to sit on the committee.\n(2) In respect of any acceding State, the Convention shall enter into force on the first day of the month following the expiration of a period of three months after the date of deposit of the instrument of accession with the Secretary General of the Council of Europe.\nArticle 24 – Territorial clause\n(1) Any State may at the time of signature or when depositing its instrument of ratification, acceptance, approval or accession, specify the territory or territories to which this Convention shall apply.\n(2) Any State may at any later date, by a declaration addressed to the Secretary General of the Council of Europe, extend the application of this Convention to any other territory specified in the declaration. In respect of such territory the Convention shall enter into force on the first day of the month following the expiration of a period of three months after the date of receipt of such declaration by the Secretary General.\n(3) Any declaration made under the two preceding paragraphs may, in respect of any territory specified in such declaration, be withdrawn by a notification addressed to the Secretary General. The withdrawal shall become effective on the first day of the month following the expiration of a period of six months after the date of receipt of such notification by the Secretary General.\nArticle 25 – Reservations\nNo reservation may be made in respect of the provisions of this Convention.\nArticle 26 – Denunciation\n(1) Any Party may at any time denounce this Convention by means of a notification addressed to the Secretary General of the Council of Europe.\n(2) Such denunciation shall become effective on the first day of the month following the expiration of a period of six months after the date of receipt of the notification by the Secretary General.\nArticle 27 – Notifications\nThe Secretary General of the Council of Europe shall notify the member States of the Council and any State which has acceded to this Convention of:\n(a) any signature;\n(b) the deposit of any instrument of ratification, acceptance, approval or accession;\n(c) any date of entry into force of this Convention in accordance with Articles 22, 23 and 24;\n(d) any other act, notification or communication relating to this Convention. In witness whereof the undersigned, being duly authorised thereto, have signed this Convention. Done at Strasbourg, the 28th day of January 1981, in English and in French, both texts being equally authoritative, in a single copy which shall remain deposited in the archives of the Council of Europe. The Secretary General of the Council of Europe shall transmit certified copies to each member State of the Council of Europe and to any State invited to accede to this Convention.\n","permalink":"https://ai.intlaws.com/en/compliance/intl/coe-convention-108/","summary":"Official English text of the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108), opened for signature in Strasbourg on 28 January 1981 — the first binding international instrument on data protection, comprising 20 articles. The Convention as modernised by Protocol CETS No. 223 (\u0026ldquo;Convention 108+\u0026rdquo;) is published separately in this library.","title":"Convention 108"},{"content":" Version and sources (verifiable)\nItem Content Original law adopted 7 November 2016, effective 1 June 2017 Amendment Decision on Amending the Cybersecurity Law of the People\u0026rsquo;s Republic of China adopted 28 October 2025 Version this page contains the consolidated amended text, effective 1 January 2026 Structure 7 chapters, 81 articles Key amendments new Article 3 (CPC leadership; holistic approach to national security); new Article 20 (artificial intelligence); new Article 63 (penalties for uncertified critical network equipment); penalty caps raised to RMB 10 million in the most serious cases; article numbering re-ordered throughout — always cite the version Chinese original CAC — amended text ; amendment decision English version No official English translation of the 2025 amendment has been published. This English text is a translation by our editorial team cross-checked article by article against the official Chinese text; it is not an official translation and is for reference only. Verification Retrieved 2026-09-22; 81 articles, no gaps; chapter and section structure verified against the official text Chapter I General provisions Article 1 This Law is enacted for the purposes of safeguarding cybersecurity, maintaining cyberspace sovereignty and national security and public interests, protecting the lawful rights and interests of citizens, legal persons and other organisations, and promoting the sound development of the information economy and society.\nArticle 2 This Law applies to the construction, operation, maintenance and use of networks within the territory of the People\u0026rsquo;s Republic of China, and to the supervision and administration of cybersecurity.\nArticle 3 Cybersecurity work upholds the leadership of the Communist Party of China, implements the holistic approach to national security, coordinates development and security, and advances the building of a strong cyber power.\nArticle 4 The State attaches equal importance to cybersecurity and the development of informatisation, follows the principles of active use, scientific development, administration in accordance with law and ensuring security, promotes the construction of cyber infrastructure and interconnection, encourages innovation in and application of cyber technology, supports the training of cybersecurity professionals, and establishes and improves a cybersecurity assurance system so as to enhance cybersecurity protection capacity.\nArticle 5 The State formulates and continuously improves the national cybersecurity strategy, defines the basic requirements and main objectives for safeguarding cybersecurity, and sets out cybersecurity policies, tasks and measures for key areas.\nArticle 6 The State takes measures to monitor, defend against and handle cybersecurity risks and threats originating within and outside the territory of the People\u0026rsquo;s Republic of China, protects critical information infrastructure against attacks, intrusions, interference and destruction, and punishes cybercrime and unlawful activities in accordance with law so as to maintain security and order in cyberspace.\nArticle 7 The State advocates honesty, credibility, healthy and civilised online conduct, promotes the dissemination of the core socialist values, and takes measures to raise the cybersecurity awareness and standards of society as a whole, so as to create a favourable environment in which all of society participates in promoting cybersecurity.\nArticle 8 The State actively carries out international exchanges and cooperation in cyberspace governance, research and development of cyber technology and formulation of standards, and combating cybercrime and unlawful activities, promotes the building of a peaceful, secure, open and cooperative cyberspace, and works to establish a multilateral, democratic and transparent system of cyberspace governance.\nArticle 9 The national cyberspace administration department is responsible for coordinating cybersecurity work and the related supervision and administration. The telecommunications department of the State Council, the public security department and other relevant authorities are responsible, within the scope of their respective duties, for cybersecurity protection and supervision and administration in accordance with this Law and the provisions of relevant laws and administrative regulations.\nThe cybersecurity protection and supervision and administration duties of the relevant departments of local people\u0026rsquo;s governments at or above the county level shall be determined in accordance with the relevant provisions of the State.\nArticle 10 In conducting business and service activities, network operators shall comply with laws and administrative regulations, respect public order and good morals, observe business ethics, act in good faith, perform their cybersecurity protection obligations, accept supervision by the government and society, and bear social responsibility.\nArticle 11 In constructing or operating networks or providing services through networks, technical measures and other necessary measures shall be taken in accordance with laws, administrative regulations and the mandatory requirements of national standards to safeguard cybersecurity and stable operation, effectively respond to cybersecurity incidents, prevent and combat cybercrime and unlawful activities, and maintain the integrity, confidentiality and availability of network data.\nArticle 12 Network-related industry organisations shall, in accordance with their articles of association, strengthen industry self-regulation, formulate norms of cybersecurity conduct, guide their members in strengthening cybersecurity protection, raise the level of cybersecurity protection and promote the sound development of the industry.\nArticle 13 The State protects the right of citizens, legal persons and other organisations to use networks in accordance with law, promotes the spread of network access, improves network service standards, provides society with secure and convenient network services, and safeguards the lawful, orderly and free flow of network information.\nAny individual or organisation using a network shall comply with the Constitution and laws, observe public order, respect public morality, and must not endanger cybersecurity or use networks to engage in activities that endanger national security, honour and interests; incite subversion of State power or overthrow of the socialist system; incite secession or undermine national unity; propagate terrorism or extremism; propagate ethnic hatred or ethnic discrimination; disseminate violent or obscene and pornographic information; fabricate or disseminate false information disrupting economic and social order; or infringe the reputation, privacy, intellectual property rights or other lawful rights and interests of others.\nArticle 14 The State supports the research, development and provision of network products and services conducive to the healthy growth of minors, punishes in accordance with law the use of networks for activities harmful to the physical and mental health of minors, and provides minors with a secure and healthy network environment.\nArticle 15 Any individual or organisation has the right to report conduct endangering cybersecurity to the cyberspace administration, telecommunications and public security departments. Departments receiving such reports shall handle them promptly in accordance with law; where a report falls outside their duties, they shall promptly transfer it to the competent department.\nThe relevant departments shall keep confidential the information of the reporting person and protect the reporting person\u0026rsquo;s lawful rights and interests.\nChapter II Support for and promotion of cybersecurity Article 16 The State establishes and improves the cybersecurity standards system. The administrative department for standardisation of the State Council and other relevant departments of the State Council shall, in accordance with their respective duties, organise the formulation and timely revision of national and industry standards relating to cybersecurity administration and the security of network products, services and operation.\nThe State supports enterprises, research institutions, institutions of higher education and network-related industry organisations in participating in the formulation of national and industry cybersecurity standards.\nArticle 17 The State Council and the people\u0026rsquo;s governments of provinces, autonomous regions and municipalities directly under the Central Government shall, through overall planning, increase investment, support key cybersecurity technology industries and projects, support the research, development and application of cybersecurity technology, promote secure and trustworthy network products and services, protect intellectual property rights in network technology, and support enterprises, research institutions and institutions of higher education in participating in national cybersecurity technology innovation projects.\nArticle 18 The State promotes the building of a socialised cybersecurity service system and encourages relevant enterprises and institutions to carry out security services such as cybersecurity certification, testing and risk assessment.\nArticle 19 The State encourages the development of technologies for the protection and exploitation of network data security, promotes the opening of public data resources, and drives technological innovation and economic and social development.\nArticle 20 The State supports basic theoretical research on artificial intelligence and the research and development of key technologies such as algorithms, advances the construction of infrastructure including training data resources and computing power, improves ethical norms for artificial intelligence, strengthens risk monitoring, assessment and security regulation, and promotes the application and healthy development of artificial intelligence.\nThe State supports innovation in cybersecurity management methods and the use of new technologies such as artificial intelligence to raise the level of cybersecurity protection.\nArticle 21 People\u0026rsquo;s governments at all levels and their relevant departments shall organise and carry out regular cybersecurity publicity and education, and guide and urge relevant entities to perform cybersecurity publicity and education work well.\nThe mass media shall carry out targeted cybersecurity publicity and education for the public.\nArticle 22 The State supports enterprises and institutions of higher education, vocational schools and other education and training institutions in carrying out cybersecurity-related education and training, cultivates cybersecurity professionals in various ways, and promotes the exchange of cybersecurity professionals.\nChapter III Network operation security Section 1 General provisions Article 23 The State applies a system of classified protection for cybersecurity. Network operators shall, in accordance with the requirements of the classified protection system for cybersecurity, perform the following security protection obligations to protect networks against interference, destruction or unauthorised access and to prevent network data from being leaked, stolen or tampered with:\n(1) formulate internal security management systems and operating procedures, designate a person responsible for cybersecurity, and implement cybersecurity protection responsibilities;\n(2) adopt technical measures to prevent computer viruses, cyber attacks, network intrusions and other conduct endangering cybersecurity;\n(3) adopt technical measures to monitor and record network operation status and cybersecurity incidents, and retain the relevant network logs for not less than six months as required;\n(4) adopt measures such as data classification, backup of important data and encryption;\n(5) other obligations provided for by laws and administrative regulations.\nArticle 24 Network products and services shall comply with the mandatory requirements of relevant national standards. Providers of network products and services must not install malicious programs; where they discover risks such as security defects or vulnerabilities in their network products or services, they shall immediately take remedial measures, promptly inform users and report to the competent departments as required.\nProviders of network products and services shall continuously provide security maintenance for their products and services; within the period prescribed or agreed by the parties, they must not terminate the provision of security maintenance.\nWhere network products or services have the function of collecting user information, their providers shall expressly inform users and obtain their consent; where personal information of users is involved, the provisions of this Law and relevant laws and administrative regulations on the protection of personal information shall also be complied with.\nArticle 25 Critical network equipment and specialised cybersecurity products shall be sold or provided only after passing security certification by a qualified institution or meeting the requirements of security testing in accordance with the mandatory requirements of relevant national standards. The national cyberspace administration department, together with the relevant departments of the State Council, formulates and publishes the catalogue of critical network equipment and specialised cybersecurity products, and promotes mutual recognition of security certification and security testing results so as to avoid duplicated certification and testing.\nArticle 26 Where a network operator handles network access or domain name registration services for a user, handles network access formalities such as fixed-line and mobile telephony, or provides a user with services such as information publication or instant messaging, it shall require the user to provide true identity information when concluding an agreement with the user or confirming the provision of services. Where a user does not provide true identity information, the network operator must not provide the relevant services to that user.\nThe State implements a trusted identity strategy for networks, supports the research, development and provision of secure and convenient electronic identity authentication technologies, and promotes mutual recognition among different electronic identity authentication systems.\nArticle 27 Network operators shall formulate emergency response plans for cybersecurity incidents and promptly handle security risks such as system vulnerabilities, computer viruses, cyber attacks and network intrusions; when an incident endangering cybersecurity occurs, they shall immediately activate the emergency response plan, take corresponding remedial measures and report to the competent departments as required.\nArticle 28 Conducting activities such as cybersecurity certification, testing and risk assessment, and releasing to the public cybersecurity information such as system vulnerabilities, computer viruses, cyber attacks and network intrusions, shall comply with the relevant provisions of the State.\nArticle 29 No individual or organisation may engage in activities endangering cybersecurity such as unlawfully intruding into another\u0026rsquo;s network, interfering with the normal functions of another\u0026rsquo;s network, or stealing network data; nor provide programs or tools specifically used for such activities as intruding into networks, interfering with the normal functions of networks and protective measures, or stealing network data; where a person knows that another is engaged in activities endangering cybersecurity, the person must not provide technical support, advertising promotion, payment and settlement or other assistance to that other person.\nArticle 30 Network operators shall provide technical support and assistance to public security organs and State security organs in their activities to safeguard national security and investigate crimes in accordance with law.\nArticle 31 The State supports cooperation among network operators in the collection, analysis, notification and emergency handling of cybersecurity information so as to enhance network operators\u0026rsquo; security assurance capability.\nRelevant industry organisations shall establish and improve cybersecurity protection norms and cooperation mechanisms for their industries, strengthen analysis and assessment of cybersecurity risks, periodically issue risk warnings to their members, and support and assist their members in responding to cybersecurity risks.\nArticle 32 Information obtained by the cyberspace administration departments and relevant departments in the performance of cybersecurity protection duties may only be used for the needs of maintaining cybersecurity and must not be used for other purposes.\nSection 2 Security of the operation of critical information infrastructure Article 33 On the basis of the classified protection system for cybersecurity, the State applies key protection to critical information infrastructure in important industries and fields such as public communications and information services, energy, transport, water conservancy, finance, public services and e-government, and other critical information infrastructure which, once destroyed, losing its function or suffering data leakage, may seriously endanger national security, the national economy and people\u0026rsquo;s livelihood, or the public interest. The specific scope of critical information infrastructure and the measures for its security protection shall be formulated by the State Council.\nThe State encourages network operators other than those of critical information infrastructure to participate voluntarily in the critical information infrastructure protection system.\nArticle 34 In accordance with the division of duties prescribed by the State Council, the departments responsible for the security protection of critical information infrastructure shall respectively prepare and organise the implementation of security plans for critical information infrastructure in their respective industries and fields, and guide and supervise the security protection of the operation of critical information infrastructure.\nArticle 35 The construction of critical information infrastructure shall ensure that it has the performance to support stable and continuous business operation, and shall ensure that security technical measures are planned, built and put into use simultaneously.\nArticle 36 In addition to the provisions of Article 23 of this Law, operators of critical information infrastructure shall also perform the following security protection obligations:\n(1) establish a dedicated security management body and a security management officer, and conduct security background checks on that officer and personnel in key positions;\n(2) periodically conduct cybersecurity education, technical training and skills assessment for employees;\n(3) carry out disaster recovery backup for important systems and databases;\n(4) formulate emergency response plans for cybersecurity incidents and conduct regular drills;\n(5) other obligations provided for by laws and administrative regulations.\nArticle 37 Where the procurement of network products and services by an operator of critical information infrastructure may affect national security, it shall undergo a national security review organised by the national cyberspace administration department together with the relevant departments of the State Council.\nArticle 38 Operators of critical information infrastructure shall, as required, conclude security and confidentiality agreements with providers when procuring network products and services, clarifying security and confidentiality obligations and responsibilities.\nArticle 39 Personal information and important data collected and generated by operators of critical information infrastructure in the course of their operations within the territory of the People\u0026rsquo;s Republic of China shall be stored within the territory. Where it is truly necessary to provide them abroad for business needs, a security assessment shall be conducted in accordance with the measures formulated by the national cyberspace administration department together with the relevant departments of the State Council; where laws and administrative regulations provide otherwise, those provisions shall prevail.\nArticle 40 Operators of critical information infrastructure shall, by themselves or by engaging a cybersecurity service institution, conduct at least one testing and assessment each year of the security of their networks and of possible risks, and submit the testing and assessment results and improvement measures to the department responsible for the security protection of critical information infrastructure.\nArticle 41 The national cyberspace administration department shall coordinate the relevant departments in taking the following measures for the security protection of critical information infrastructure:\n(1) conduct spot checks and testing of the security risks of critical information infrastructure, propose improvement measures, and, where necessary, engage cybersecurity service institutions to test and assess security risks existing in the networks;\n(2) periodically organise operators of critical information infrastructure to conduct cybersecurity emergency drills to improve their capacity to respond to cybersecurity incidents and their coordination capabilities;\n(3) promote the sharing of cybersecurity information among relevant departments, operators of critical information infrastructure, relevant research institutions and cybersecurity service institutions;\n(4) provide technical support and assistance for the emergency handling of cybersecurity incidents and the restoration of network functions.\nChapter IV Network information security Article 42 Network operators shall keep strictly confidential the user information they collect and shall establish and improve user information protection systems.\nIn processing personal information, network operators shall comply with the provisions of this Law, the Civil Code of the People\u0026rsquo;s Republic of China, the Personal Information Protection Law of the People\u0026rsquo;s Republic of China and other laws and administrative regulations.\nArticle 43 Network operators shall, in collecting and using personal information, follow the principles of lawfulness, legitimacy and necessity, publicly disclose their rules for collection and use, expressly state the purpose, method and scope of collecting and using the information, and obtain the consent of the person whose information is collected.\nNetwork operators must not collect personal information unrelated to the services they provide, must not collect or use personal information in violation of laws and administrative regulations or contrary to the agreement between the parties, and shall handle the personal information they retain in accordance with laws and administrative regulations and their agreement with users.\nArticle 44 Network operators must not divulge, tamper with or destroy the personal information they collect; they must not provide personal information to others without the consent of the person whose information is collected, except where the information cannot identify a specific person and cannot be restored after processing.\nNetwork operators shall adopt technical measures and other necessary measures to ensure the security of the personal information they collect and to prevent leakage, destruction or loss of information. Where personal information is or may be leaked, destroyed or lost, they shall immediately take remedial measures, promptly inform users as required and report to the competent departments.\nArticle 45 Where an individual discovers that a network operator collects or uses his or her personal information in violation of laws and administrative regulations or of the agreement between the parties, the individual has the right to require the network operator to delete the personal information; where the personal information collected or stored by the network operator is erroneous, the individual has the right to require the network operator to correct it. Network operators shall take measures to delete or correct it.\nArticle 46 No individual or organisation may steal or obtain personal information by other unlawful means, or unlawfully sell or unlawfully provide personal information to others.\nArticle 47 Departments with cybersecurity supervision and administration duties in accordance with law and their staff must keep strictly confidential the personal information, privacy and trade secrets learned in the performance of their duties, and must not divulge, sell or unlawfully provide them to others.\nArticle 48 Every individual and organisation shall be responsible for its conduct in using networks, and must not set up websites or communication groups for committing fraud, teaching criminal methods, or producing or selling prohibited or controlled items or other illegal or criminal activities, and must not use networks to publish information involving the commission of fraud, the production or sale of prohibited or controlled items, or other illegal or criminal activities.\nArticle 49 Network operators shall strengthen the administration of information published by their users, and where they discover information whose publication or transmission is prohibited by laws and administrative regulations, they shall immediately stop transmitting that information, take measures such as elimination, prevent the spread of the information, preserve the relevant records and report to the competent departments.\nArticle 50 Electronic information sent and application software provided by any individual or organisation must not contain malicious programs or information whose publication or transmission is prohibited by laws and administrative regulations.\nProviders of electronic information sending services and providers of application software download services shall perform their security management obligations, and where they know that their users have committed the acts specified in the preceding paragraph, they shall stop providing services, take measures such as elimination, preserve the relevant records and report to the competent departments.\nArticle 51 Network operators shall establish complaint and reporting systems for network information security, publish information on how to make complaints and reports, and promptly accept and handle complaints and reports concerning network information security.\nNetwork operators shall cooperate with the supervision and inspection carried out by cyberspace administration departments and relevant departments in accordance with law.\nArticle 52 Where the national cyberspace administration department and relevant departments, in performing their network information security supervision and administration duties in accordance with law, discover information whose publication or transmission is prohibited by laws and administrative regulations, they shall require network operators to stop transmitting it, take measures such as elimination and preserve relevant records; for such information originating outside the territory of the People\u0026rsquo;s Republic of China, they shall notify the relevant institutions to take technical measures and other necessary measures to block its dissemination.\nChapter V Monitoring, early warning and emergency handling Article 53 The State establishes systems for cybersecurity monitoring, early warning and information notification. The national cyberspace administration department shall coordinate the relevant departments in strengthening the collection, analysis and notification of cybersecurity information and shall uniformly release cybersecurity monitoring and early warning information as required.\nArticle 54 Departments responsible for the security protection of critical information infrastructure shall establish and improve cybersecurity monitoring, early warning and information notification systems for their respective industries and fields, and submit cybersecurity monitoring and early warning information as required.\nArticle 55 The national cyberspace administration department shall coordinate the relevant departments in establishing and improving cybersecurity risk assessment and emergency response mechanisms, formulating emergency response plans for cybersecurity incidents, and organising regular drills.\nDepartments responsible for the security protection of critical information infrastructure shall formulate emergency response plans for cybersecurity incidents in their respective industries and fields and organise regular drills.\nEmergency response plans for cybersecurity incidents shall classify cybersecurity incidents according to factors such as the degree of harm and scope of impact after occurrence and shall provide for corresponding emergency handling measures.\nArticle 56 Where the risk of a cybersecurity incident increases, the relevant departments of people\u0026rsquo;s governments at or above the provincial level shall, in accordance with the prescribed powers and procedures, and in light of the characteristics of the cybersecurity risk and the harm it may cause, take the following measures:\n(1) require the relevant departments, institutions and personnel to promptly collect and report information and strengthen monitoring of cybersecurity risks;\n(2) organise relevant departments, institutions and professionals to analyse and assess cybersecurity risk information and predict the likelihood, scope of impact and degree of harm of an incident;\n(3) release cybersecurity risk warnings to the public and publish measures to avoid and mitigate harm.\nArticle 57 Where a cybersecurity incident occurs, the emergency response plan for cybersecurity incidents shall be immediately activated, the incident shall be investigated and assessed, network operators shall be required to take technical measures and other necessary measures to eliminate hidden security dangers and prevent the expansion of harm, and warning information relevant to the public shall be released to the public in a timely manner.\nArticle 58 Where the relevant departments of people\u0026rsquo;s governments at or above the provincial level, in performing their cybersecurity supervision and administration duties, discover that a relatively serious security risk exists in a network or that a security incident has occurred, they may, in accordance with the prescribed powers and procedures, conduct a regulatory interview with the legal representative or principal person in charge of the network operator. The network operator shall take measures as required, carry out rectification and eliminate the hidden danger.\nArticle 59 Where a cybersecurity incident gives rise to an emergency or a work safety accident, it shall be handled in accordance with the provisions of the Emergency Response Law of the People\u0026rsquo;s Republic of China, the Work Safety Law of the People\u0026rsquo;s Republic of China and other relevant laws and administrative regulations.\nArticle 60 Where necessary for safeguarding national security and public order or handling a major sudden social security incident, temporary measures such as restricting network communications in specified areas may be taken upon decision or approval by the State Council.\nChapter VI Legal liability Article 61 Where a network operator fails to perform the cybersecurity protection obligations provided for in Articles 23 and 27 of this Law, the competent departments shall order it to correct, give it a warning and may impose a fine of not less than RMB 10,000 and not more than RMB 50,000; where it refuses to correct or causes consequences such as endangering cybersecurity, a fine of not less than RMB 50,000 and not more than RMB 500,000 shall be imposed, and a fine of not less than RMB 10,000 and not more than RMB 100,000 shall be imposed on the directly responsible persons in charge and other directly responsible persons.\nWhere an operator of critical information infrastructure fails to perform the cybersecurity protection obligations provided for in Articles 35, 36, 38 and 40 of this Law, the competent departments shall order it to correct, give it a warning and may impose a fine of not less than RMB 50,000 and not more than RMB 100,000; where it refuses to correct or causes consequences such as endangering cybersecurity, a fine of not less than RMB 100,000 and not more than RMB 1,000,000 shall be imposed, and a fine of not less than RMB 10,000 and not more than RMB 100,000 shall be imposed on the directly responsible persons in charge and other directly responsible persons.\nWhere the acts in the preceding two paragraphs cause serious consequences endangering cybersecurity, such as the leakage of a large volume of data or the loss of partial functions of critical information infrastructure, the competent departments shall impose a fine of not less than RMB 500,000 and not more than RMB 2,000,000, and a fine of not less than RMB 50,000 and not more than RMB 200,000 on the directly responsible persons in charge and other directly responsible persons; where the acts cause especially serious consequences endangering cybersecurity, such as the loss of the main functions of critical information infrastructure, a fine of not less than RMB 2,000,000 and not more than RMB 10,000,000 shall be imposed, and a fine of not less than RMB 200,000 and not more than RMB 1,000,000 shall be imposed on the directly responsible persons in charge and other directly responsible persons.\nArticle 62 Where the provisions of the first and second paragraphs of Article 24 and the first paragraph of Article 50 of this Law are violated and any of the following acts is committed, the competent departments shall order correction and give a warning; where the offender refuses to correct or causes consequences such as endangering cybersecurity, a fine of not less than RMB 50,000 and not more than RMB 500,000 shall be imposed, and a fine of not less than RMB 10,000 and not more than RMB 100,000 shall be imposed on the directly responsible person in charge:\n(1) installing malicious programs;\n(2) failing to immediately take remedial measures for risks such as security defects or vulnerabilities in its products or services, or failing to promptly inform users and report to the competent departments as required;\n(3) terminating without authorisation the provision of security maintenance for its products or services.\nWhere the acts in items (1) and (2) of the preceding paragraph cause the consequences specified in the third paragraph of Article 61 of this Law, the penalty shall be imposed in accordance with that paragraph.\nArticle 63 Where the provisions of Article 25 of this Law are violated by selling or providing critical network equipment or specialised cybersecurity products that have not passed security certification or security testing, or that fail to pass security certification or do not meet the requirements of security testing, the competent departments shall order the cessation of the sale or provision, give a warning and confiscate the unlawful gains; where there are no unlawful gains or the unlawful gains are less than RMB 100,000, a concurrent fine of not less than RMB 20,000 and not more than RMB 100,000 shall be imposed; where the unlawful gains are RMB 100,000 or more, a concurrent fine of not less than one time and not more than five times the unlawful gains shall be imposed; where the circumstances are serious, the competent departments may concurrently order the suspension of the relevant business, suspension of business for rectification, revocation of the relevant business licence or revocation of the business licence. Where laws and administrative regulations provide otherwise, those provisions shall prevail.\nArticle 64 Where a network operator violates the first paragraph of Article 26 of this Law by failing to require a user to provide true identity information, or by providing the relevant services to a user who does not provide true identity information, the competent departments shall order correction; where the operator refuses to correct or the circumstances are serious, a fine of not less than RMB 50,000 and not more than RMB 500,000 shall be imposed, and the competent departments may concurrently order the suspension of the relevant business, suspension of business for rectification, closure of the website or application, revocation of the relevant business licence or revocation of the business licence, and shall impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons.\nArticle 65 Where the provisions of Article 28 of this Law are violated by conducting activities such as cybersecurity certification, testing or risk assessment, or by releasing to the public cybersecurity information such as system vulnerabilities, computer viruses, cyber attacks or network intrusions, the competent departments shall order correction, give a warning and may impose a fine of not less than RMB 10,000 and not more than RMB 100,000; where the offender refuses to correct or the circumstances are serious, a fine of not less than RMB 100,000 and not more than RMB 1,000,000 shall be imposed, and the competent departments may concurrently order the suspension of the relevant business, suspension of business for rectification, closure of the website or application, revocation of the relevant business licence or revocation of the business licence, and shall impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons.\nWhere the acts in the preceding paragraph cause the consequences specified in the third paragraph of Article 61 of this Law, the penalty shall be imposed in accordance with that paragraph.\nArticle 66 Where the provisions of Article 29 of this Law are violated by engaging in activities endangering cybersecurity, or providing programs or tools specifically used for such activities, or providing technical support, advertising promotion, payment and settlement or other assistance to another person\u0026rsquo;s activities endangering cybersecurity, and the act does not yet constitute a crime, the public security organ shall confiscate the unlawful gains and impose detention of not more than five days, and may concurrently impose a fine of not less than RMB 50,000 and not more than RMB 500,000; where the circumstances are relatively serious, detention of not less than five days and not more than fifteen days shall be imposed, and a fine of not less than RMB 100,000 and not more than RMB 1,000,000 may concurrently be imposed.\nWhere a unit commits the act in the preceding paragraph, the public security organ shall confiscate its unlawful gains, impose a fine of not less than RMB 100,000 and not more than RMB 1,000,000, and punish the directly responsible persons in charge and other directly responsible persons in accordance with the provisions of the preceding paragraph.\nA person who violates Article 29 of this Law and receives a public security administration penalty must not engage in cybersecurity management or key positions in network operations for five years; a person who receives a criminal penalty must not engage in cybersecurity management or key positions in network operations for life.\nArticle 67 Where an operator of critical information infrastructure violates Article 37 of this Law by using network products or services that have not undergone security review or have failed security review, the competent departments shall order correction within a time limit, order the cessation of use and the elimination of the impact on national security, impose a fine of not less than one time and not more than ten times the procurement amount, and impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons.\nArticle 68 Where the provisions of Article 48 of this Law are violated by setting up websites or communication groups for committing illegal or criminal activities, or by using networks to publish information involving the commission of illegal or criminal activities, and the act does not yet constitute a crime, the public security organ shall impose detention of not more than five days, and may concurrently impose a fine of not less than RMB 10,000 and not more than RMB 100,000; where the circumstances are relatively serious, detention of not less than five days and not more than fifteen days shall be imposed, and a fine of not less than RMB 50,000 and not more than RMB 500,000 may concurrently be imposed. The websites or communication groups used for committing the illegal or criminal activities shall be closed.\nWhere a unit commits the act in the preceding paragraph, the public security organ shall impose a fine of not less than RMB 100,000 and not more than RMB 500,000 and shall punish the directly responsible persons in charge and other directly responsible persons in accordance with the provisions of the preceding paragraph.\nArticle 69 Where a network operator violates Article 49 of this Law by failing to stop transmitting information whose publication or transmission is prohibited by laws and administrative regulations, failing to take measures such as elimination, failing to preserve the relevant records or failing to report to the competent departments, or violates Article 52 of this Law by failing to stop transmitting such information, take measures such as elimination and preserve the relevant records at the request of the relevant departments, the competent departments shall order correction, give a warning and circulate a notice of criticism, and may impose a fine of not less than RMB 50,000 and not more than RMB 500,000; where the offender refuses to correct or the circumstances are serious, a fine of not less than RMB 500,000 and not more than RMB 2,000,000 shall be imposed, and the competent departments may concurrently order the suspension of the relevant business, suspension of business for rectification, closure of the website or application, revocation of the relevant business licence or revocation of the business licence, and shall impose a fine of not less than RMB 50,000 and not more than RMB 200,000 on the directly responsible persons in charge and other directly responsible persons.\nWhere the acts in the preceding paragraph cause an especially serious impact or especially serious consequences, the competent departments shall impose a fine of not less than RMB 2,000,000 and not more than RMB 10,000,000, order the suspension of the relevant business, suspension of business for rectification, closure of the website or application, revocation of the relevant business licence or revocation of the business licence, and impose a fine of not less than RMB 200,000 and not more than RMB 1,000,000 on the directly responsible persons in charge and other directly responsible persons.\nWhere a provider of electronic information sending services or a provider of application software download services fails to perform the security management obligations provided for in the second paragraph of Article 50 of this Law, it shall be punished in accordance with the preceding two paragraphs.\nArticle 70 Where a network operator violates the provisions of this Law and commits any of the following acts, the competent departments shall order correction; where the operator refuses to correct or the circumstances are serious, a fine of not less than RMB 50,000 and not more than RMB 500,000 shall be imposed, and a fine of not less than RMB 10,000 and not more than RMB 100,000 shall be imposed on the directly responsible persons in charge and other directly responsible persons:\n(1) refusing or obstructing supervision and inspection carried out by the relevant departments in accordance with law;\n(2) refusing to provide technical support and assistance to public security organs and State security organs.\nArticle 71 Any of the following acts shall be handled and punished in accordance with the provisions of relevant laws and administrative regulations:\n(1) publishing or transmitting information whose publication or transmission is prohibited by the second paragraph of Article 13 of this Law or by other laws and administrative regulations;\n(2) infringing upon the rights and interests of personal information in violation of the third paragraph of Article 24 and Articles 43 to 45 of this Law;\n(3) in violation of Article 39 of this Law, storing personal information and important data outside the territory or providing personal information and important data abroad by an operator of critical information infrastructure.\nA person who violates Article 46 of this Law by stealing or otherwise unlawfully obtaining, unlawfully selling or unlawfully providing personal information to others, where the act does not yet constitute a crime, shall be punished by the public security organ in accordance with the provisions of relevant laws and administrative regulations.\nArticle 72 Where an unlawful act is provided for in this Law, it shall be recorded in credit files and made public in accordance with the provisions of relevant laws and administrative regulations.\nArticle 73 Where this Law is violated but circumstances provided for in the Administrative Penalty Law of the People\u0026rsquo;s Republic of China for a mitigated, reduced or no penalty exist, a mitigated or reduced penalty shall be imposed or no penalty shall be imposed in accordance with those provisions.\nArticle 74 Where an operator of a government network of a State organ fails to perform the cybersecurity protection obligations provided for in this Law, its superior authority or the relevant authority shall order it to correct; the directly responsible persons in charge and other directly responsible persons shall be given sanctions in accordance with law.\nArticle 75 Where the cyberspace administration departments and relevant departments violate Article 32 of this Law by using information obtained in the performance of cybersecurity protection duties for other purposes, the directly responsible persons in charge and other directly responsible persons shall be given sanctions in accordance with law.\nWhere staff of the cyberspace administration departments and relevant departments derelict their duties, abuse their powers or engage in malpractices for personal gain, and the act does not yet constitute a crime, they shall be given sanctions in accordance with law.\nArticle 76 Where a violation of this Law causes damage to another person, civil liability shall be borne in accordance with law.\nWhere a violation of this Law constitutes an act violating public security administration, a public security administration penalty shall be imposed in accordance with law; where a crime is constituted, criminal liability shall be pursued in accordance with law.\nArticle 77 Where an institution, organisation or individual outside the territory engages in activities endangering the cybersecurity of the People\u0026rsquo;s Republic of China, legal liability shall be pursued in accordance with law; where serious consequences are caused, the public security department of the State Council and the relevant departments may decide to take measures such as freezing property or other necessary sanctions against that institution, organisation or individual.\nChapter VII Supplementary provisions Article 78 For the purposes of this Law, the following terms have the meanings set out below:\n(1) \u0026ldquo;network\u0026rdquo; means a system composed of computers or other information terminals and related equipment that collects, stores, transmits, exchanges and processes information in accordance with certain rules and procedures;\n(2) \u0026ldquo;cybersecurity\u0026rdquo; means, through the adoption of necessary measures, preventing attacks, intrusions, interference, destruction and unlawful use of, and accidents affecting, networks, keeping networks in a stable and reliable state of operation, and the capacity to safeguard the integrity, confidentiality and availability of network data;\n(3) \u0026ldquo;network operator\u0026rdquo; means the owner or administrator of a network and the provider of network services;\n(4) \u0026ldquo;network data\u0026rdquo; means various electronic data collected, stored, transmitted, processed and generated through networks;\n(5) \u0026ldquo;personal information\u0026rdquo; means various information recorded electronically or otherwise that can, alone or in combination with other information, identify a natural person\u0026rsquo;s personal identity, including but not limited to a natural person\u0026rsquo;s name, date of birth, identity document number, personal biometric information, address and telephone number.\nArticle 79 In addition to complying with this Law, the security protection of the operation of networks that store or process information involving State secrets shall also comply with the provisions of laws and administrative regulations on the protection of secrets.\nArticle 80 The security protection of military networks shall be separately prescribed by the Central Military Commission.\nArticle 81 This Law shall come into force on 1 June 2017.\n","permalink":"https://ai.intlaws.com/en/compliance/china/csl/","summary":"Full text of the Cybersecurity Law of the People\u0026rsquo;s Republic of China as amended on 28 October 2025 (effective 1 January 2026), 81 articles in seven chapters: the new Article 3 (CPC leadership and the holistic approach to national security), the new Article 20 on artificial intelligence, the new Article 63 on penalties for uncertified critical network equipment, and the substantially raised penalty caps (up to RMB 10 million). English translation by our editorial team (non-official).","title":"Cybersecurity Law of the People's Republic of China (2025 Amendment)"},{"content":" Version and sources (verifiable)\nItem Content Adopted 29th Meeting of the Standing Committee of the 13th NPC, June 10, 2021 In force September 1, 2021 Chinese original source Cyberspace Administration of China: https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm English translation source NPC official English site (Translation for Reference Only): http://en.npc.gov.cn.cdurl.cn/2021-06/10/c_689311.htm Verification Retrieved 2026-09-22; 7 chapters / 55 articles; 1:1 correspondence, no gaps Chapter I General Provisions Article 1 This Law is enacted for the purpose of regulating data processing, ensuring data security, promoting development and utilization of data, protecting the lawful rights and interests of individuals and organizations, and safeguarding the sovereignty, security, and development interests of the state.\nArticle 2 This Law shall apply to data processing activities and security supervision and regulation of such activities within the territory of the People\u0026rsquo;s Republic of China. Where data processing outside the territory of People\u0026rsquo;s Republic of China harms the national security, public interests, or the lawful rights and interests of individuals or organizations of the People\u0026rsquo;s Republic of China, legal liability shall be investigated in accordance with the law.\nArticle 3 For the purpose of this Law, the term \u0026ldquo;data\u0026rdquo; refers to any record of information in electronic or any other form. \u0026ldquo;Data processing\u0026rdquo; includes the collection, storage, use, processing, transmission, provision, and disclosure of data, among others.\n\u0026ldquo;Data security\u0026rdquo; refers to ensuring that data is effectively protected and lawfully used through adopting necessary measures, and to possessing the capacity to guarantee the continuous security of data.\nArticle 4 In preserving data security, the holistic approach to national security shall be adopted, sound data security governance systems shall be established, and data security and protection capabilities shall be improved.\nArticle 5 The central leading authority for national security shall be responsible for the decision-making, deliberation and coordination of the national data security work; researching, formulating, and guiding the implementation of the national data security strategy and related major guidelines and policies; coordinating major matters and important work in respect of national data security; and establishing a coordination mechanism for national data security.\nArticle 6 All localities and departments shall bear responsibility for the management of the data collected or generated in their work as well as for the data security thereof. The competent departments of industry, telecommunications, transport, finance, natural resources, health, education, technology and other relevant competent departments shall assume the responsibilities of supervising and regulating data security in their respective trades and sectors.\nPublic security organs and national security organs, etc. shall assume the responsibilities of supervising and regulating data security within the scopes of their respective duties in accordance with the provisions of this Law and other relevant laws and administrative regulations.\nThe national cyberspace affairs department shall be in charge of the overall planning and coordination of network data security and the related supervision and regulation in accordance with the provisions of this Law and other relevant laws and administrative regulations.\nArticle 7 The state shall protect the data-related rights and interests of individuals and organizations, encourage the lawful, reasonable, and effective use of data, ensure free flow of data in an orderly manner and in accordance with the law, and promote the development of a digital economy with data as the key factor.\nArticle 8 Whoever processes data shall observe laws and regulations, respect social morality and ethics, observe business and professional ethics, uphold honesty and trustworthiness, fulfill data security protection obligations, and undertake social responsibilities; and shall not endanger national security and public interests, nor harm the lawful rights and interests of individuals and organizations.\nArticle 9 The state supports the dissemination and popularization of knowledge of data security to raise public awareness in this regard and ability to protect data security, and promotes the joint participation by relevant departments, industry organizations, research institutions, enterprises, and individuals in data security protection, so as to create a good environment for members of the whole society to jointly protect data, ensure data security and promote development of relevant industries.\nArticle 10 Relevant industry associations shall, in accordance with their articles of association, formulate the code of conduct and standards to ensure data security according to the law, strengthen self-regulation in their respective industries, guide members to strengthen data security protection, improve their protection level and promote the healthy development of the industries.\nArticle 11 The state shall actively carry out international exchanges and cooperation in fields such as data security governance and data development and utilization, participate in the formulation of relevant international rules and standards for data security, and promote the safe and free flow of data across borders.\nArticle 12 Any individual or organization shall have the right to file complaints about or report violations of this Law to the competent departments. The departments receiving such complaints or reports shall deal with them in a timely manner in accordance with the law. The competent departments shall keep confidential the relevant information of those making such complaints or reports, and protect their lawful rights and interests.\nData Security and Development\nChapter II Data Security and Development Article 13 The state shall make an overall plan to coordinate development and security, to promote data security through data development and utilization and through industrial development on one hand, and on the other hand, to ensure that data security facilitates data development and utilization as well as industrial development.\nArticle 14 The state shall implement the big data strategy, advance the construction of data infrastructure, and encourage and support the innovative application of data in all industries and fields. People\u0026rsquo;s governments at or above the provincial level shall incorporate the development of digital economy into their national economic and social development plans, and formulate development plans for the digital economy as needed.\nArticle 15 The state supports development and utilization of data to render public services smarter. In providing smarter public services, the needs of the elderly and the disabled shall be taken into full account to avoid posing obstacles to their daily lives.\nArticle 16 The state supports research on development and utilization of data and on data security related technologies, encourages popularization and commercial innovation of technologies in the foregoing fields, and fosters and develops products and industrial systems for development and utilization of data and for data security.\nArticle 17 The state shall advance the forming of the standards for data development and the standards for data utilization technologies and data security. The department in charge of standardization under the State Council and other relevant departments under the State Council shall, within the scopes of their respective duties and functions, organize the establishment of, and make revisions in due time to the standards for technologies and products for data development and data utilization and the standards for data security. The state shall support enterprises, social groups, and education or research institutions, etc. in their participation in the establishment of such standards.\nArticle 18 The state encourages the development of services such as data security testing, evaluation, and accreditation, and supports agencies specialized in data security testing, evaluation, accreditation, etc. to provide services according to the law. The state supports collaboration among relevant departments, industry associations, enterprises, education and research institutions, relevant specialized agencies, etc. in the fields such as data security related risk assessment, prevention, and disposal .\nArticle 19 The state shall establish sound systems for data trading management, standardize data trading activities, and foster a data trading market.\nArticle 20 The state supports education and research institutions, enterprises, and other entities in carrying out education and training on technologies for data development and utilization and on data security, cultivates professionals in data development and utilization technologies and in data security by a variety of means, and promotes talent exchanges. Data Security Systems\nChapter III Data Security Systems Article 21 The state shall establish a categorized and classified system and carry out data protection based on the importance of the data in economic and social development, as well as the extent of harm to national security, public interests, or the lawful rights and interests of individuals or organizations that will be caused once the data are altered, destroyed, leaked, or illegally obtained or used. The coordination mechanism for national data security shall coordinate the relevant departments to formulate a catalog of important data and strengthen protection of important data. Data concerning national security, lifelines of the national economy, important aspects of people\u0026rsquo;s lives, major public interests, ect., are core data of the state, for which a stricter management system shall be implemented.\nAll localities and departments shall, in accordance with the categorized and classified data protection system, prepare specific catalogs of important data for their respective regions, departments, and relevant industries and sectors, and give priority to the data listed in the catalogs in terms of data protection.\nArticle 22 The state shall establish a centralized, unified, highly effective, and authoritative mechanism for assessing, reporting, information sharing, monitoring, and early alert of data security risks. The coordinating mechanism for national data security shall make an overall plan on and coordinate relevant departments in strengthening the work about acquiring, analyzing, researching and evaluating information of data security risks and the work about early alert of such risks.\nArticle 23 The state shall establish a data security emergency response mechanism. Where a data security incident occurs, the relevant competent departments shall initiate emergency response in accordance with the plan and the law, take corresponding measures to prevent further harm and eliminate security hazards, and send out warnings to the public by publishing information relevant thereto in a timely manner.\nArticle 24 The state shall establish a review system for data security, conducting national security reviews of data processing that affects or may affect national security. Security review decisions made in accordance with the law are final decisions.\nArticle 25 The state shall apply export control in accordance with the law on data that are controlled items and concern national security and interests and the performance of international obligations.\nArticle 26 Where any country or region adopts discriminatory prohibitions, restrictions, or other similar measures against the People\u0026rsquo;s Republic of China in respect of investment, trade or any other field related to data and data development and utilization technologies, the People\u0026rsquo;s Republic of China may take countermeasures against that country or region in light of the actual circumstances. 1 2 \u0026gt;\nChapter IV Data Security Protection Obligations Article 27 In data processing, the laws and regulations shall be complied with, a sound data security management system throughout the whole process shall be established, data security education and training shall be organized and conducted, and corresponding technical measures and other necessary measures shall be adopted to ensure data security. In data processing by making use of the internet or any other information networks, the abovementioned data security obligations shall be fulfilled on the basis of the classified protection system for cyber security. Processors of important data shall be clear about their persons responsible for data security and the data security management bodies, and fulfill the responsibilities for data security.\nArticle 28 Data processing as well as research and development of new data technologies shall be conducive to furthering economic and social development, and improving the well-being of people, and shall conform to social morals and ethics.\nArticle 29 Closer risk monitoring shall be applied in data processing. Where data security defects, bugs, or other risks are discovered, remedial measures shall be taken immediately. Where a data security incident occurs, measures shall be taken immediately to address it, and users shall be notified and reports made to relevant competent departments in a timely manner in accordance with relevant provisions.\nArticle 30 Processors of important data shall, in accordance with the relevant provisions, conduct risk assessments of their data processing on a regular basis and submit risk assessment reports to relevant competent departments. Risk assessment reports shall include the types and amounts of important data processed, information on data processing, data security risks and the response measures for them.\nArticle 31 The provisions of the Cyber Security Law of the People\u0026rsquo;s Republic of China shall apply to the outbound security management of the important data collected or produced by critical information infrastructure operators during their operation within the territory of the People\u0026rsquo;s Republic of China, and the measures for the outbound security management of the important data collected or produced by others data processors during their operation within the territory of the People\u0026rsquo;s Republic of China shall be formulated by the national cyberspace authority in conjunction with the relevant departments under the State Council.\nArticle 32 An organization or individual shall collect data by lawful and proper means, and shall not acquire data by theft or in other illegal manners. Where laws or administrative regulations have provisions on the purposes or scopes of data collection and use, data shall be collected and used for the purposes and within the scopes provided for by those laws and administrative regulations.\nArticle 33 When providing services, data transaction intermediaries shall require data providers to specify the sources of the data, verify the identities of both parties to the transactions, and retain the verification and transaction records.\nArticle 34 Where laws or administrative regulations require that administrative permissions be acquired for providing services related to data processing, service providers shall obtain such administrative permissions in accordance with these provisions.\nArticle 35 Where a public security organ or national security organ needs to obtain data for the sake of national security or for investigating crimes in accordance with the law, strict approval formalities shall be completed in accordance with the relevant provisions of the state and data be obtained in accordance with the law, and the relevant organizations and individuals shall cooperate.\nArticle 36 The competent authorities of the People\u0026rsquo;s Republic of China shall handle requests for data made by foreign judicial or law enforcement authorities, in accordance with the relevant laws and international treaties or agreements concluded or acceded to by the People\u0026rsquo;s Republic of China, or in accordance with the principles of equality and reciprocity. Without the approval of the competent authorities of the People\u0026rsquo;s Republic of China, organizations or individuals in the People\u0026rsquo;s Republic of China shall not provide data stored within the territory of the People\u0026rsquo;s Republic of China to any overseas judicial or law enforcement body. Security and Openness of Government Data\nChapter V Security and Openness of Government Data Article 37 The state shall make great efforts to promote the development of e-government, make government database more scientific, accurate, and time-efficient, and improve the ability of using data to serve economic and social development.\nArticle 38 Where state organs need to collect or use data to perform their statutory duties, they shall collect or use data within the scope as needed for performance of their statutory duties and under the conditions and procedures provided by laws and administrative regulations. They shall, in accordance with the law, preserve the confidentiality of the data accessed in the course of performing their duties, such as personal privacy, personal information, trade secrets, and confidential business information, and shall not divulge such data or illegally provide them to others.\nArticle 39 State organs shall, in accordance with the provisions of laws and administrative regulations, establish sound data security management systems, fulfill data security protection responsibilities, and ensure the security of government data.\nArticle 40 Where a state organ entrusts others to construct or maintain e-government systems, or to store or process government data, the state organ shall go through strict approval procedures, and shall supervise the entrusted party in the performance of data security protection obligations. The entrusted party shall perform its data security protection obligations in accordance with the provisions of laws, regulations, and contracts signed, and shall not retain, use, divulge, or provide others with government data without authorization.\nArticle 41 State organs shall, under the principles of fairness, equality and convenience for the people, disclose government data in a timely and accurate manner in accordance with the provisions, except those which shall not be disclosed in accordance with the law.\nArticle 42 The state shall formulate the catalog of open government data, build an open, uniform, standardized, interconnected, safe and controllable government data platform, and promote the release and utilization of government data.\nArticle 43 The provisions of this Chapter shall apply to the data processing carried out by the organizations with the functions of administering public affairs as authorized by laws and regulations for the purpose of performing their statutory duties. Legal Liability\nChapter VI Legal Liability Article 44 Where competent departments discover the existence of major security risks in data processing when they perform their regulatory duties as regards data security, they may, in accordance with the prescribed limits of authority and procedures, conduct regulatory talks with the relevant organizations and/or individuals, and require the relevant organizations and/or individuals to adopt measures to make rectifications and eliminate potential hazards.\nArticle 45 Where an organization or individual that processes data fails to perform the data security protection obligations provided in Articles 27, 29 and 30 of this Law, the organization or individual shall be ordered to make rectifications and be given a warning, and may be concurrently fined not less than RMB 50,000 yuan but not more than RMB 500,000 yuan by the competent department, and the directly liable persons in charge and other directly liable persons may be fined not less than RMB 10,000 yuan but not more than RMB 100,000 yuan. Where the organization or individual refuses to make rectifications or has caused serious consequences such as a massive data breach, the organization or individual shall be fined not less than RMB 500,000 yuan but not more than RMB 2 million yuan, and may be ordered to suspend the relevant business or suspend operations for rectification, or have relevant business permits or the business license revoked, and the directly liable persons in charge and other directly liable persons shall be fined not less than RMB 50,000 yuan but not more than RMB 200,000 yuan. Where the organization or individual violates the national core data management rules and endangers national sovereignty, security, or development interests of the state, the competent department shall impose upon the organization or individual a fine of not less than RMB 2 million yuan but not more than RMB 10 million yuan, and may, based on the circumstances, order a suspension of relevant business or a suspension of operations for rectification, or revoke relevant business permits or the business license. Where a crime is constituted, criminal responsibilities shall be investigated in accordance with the law.\nArticle 46 Whoever, in violation of the provisions of Article 31 of this Law, provides important data abroad, shall be ordered to make rectifications and be given a warning by the competent department, and may be concurrently fined not less than RMB 100,000 yuan but not more than RMB 1 million yuan, and the directly liable persons in charge and other directly liable persons may be fined not less than RMB 10,000 yuan but not more than RMB 100,000 yuan. Where the circumstances are serious, the violator shall be fined not less than RMB 1 million but not more than RMB 10 million yuan, and may also be ordered to suspend the relevant business or suspend operations for rectification, or have relevant business permits or the business license revoked, and the directly liable persons in charge and other directly liable persons shall be fined not less than RMB 100,000 yuan but not more than RMB 1 million yuan.\nArticle 47 Where a data transaction intermediary fails to perform the obligations prescribed in Article 33 of this Law, it shall be ordered by the competent department to make rectifications, its illegal gains, if any, shall be confiscated, and it shall also be fined not less than the amount of but not more than ten times the amount of the illegal gains; if there are no illegal gains or the illegal gains are less than RMB 100,000 yuan, it shall be fined not less than RMB 100,000 yuan but not more than RMB 1 million yuan. It may be concurrently ordered to suspend the relevant business or suspend operations for rectification, or have relevant business permits or the business license revoked. The directly liable persons in charge and other directly liable persons shall be fined not less than RMB 10,000 yuan but not more than RMB 100,000 yuan.\nArticle 48 Whoever in violation of Article 35 of this Law, refuses to cooperate when a public organ or national security organ needs to access the data, shall be ordered by the competent department to make rectifications and be given a warning, and shall be concurrently fined not less than RMB 50,000 yuan but nor more than RMB 500,000 yuan, and the directly liable persons in charge and other directly liable persons may be fined not less than RMB 10,000 yuan but not more than RMB 100,000 yuan. Whoever, in violation of Article 36 of this Law, provides data to an overseas judicial or law enforcement body without the approval of the competent authorities, shall be given a warning by the competent department, and may be concurrently fined not less than RMB 100,000 yuan but not more than RMB 1 million yuan, and the directly liable persons in charge and other directly liable persons may be fined not less than RMB 10,000 yuan but not more than RMB 100,000 yuan. If serious consequences are caused, the violator shall be fined not less than RMB 1 million yuan but not more than RMB 5 million yuan, and may be ordered to suspend the relevant business or suspend operations for rectification, or have relevant business permits or the business license revoked. The directly liable persons in charge and other directly liable persons shall be fined not less than RMB 50,000 yuan but not more than RMB 500,000 yuan.\nArticle 49 Where a state organ fails to perform data security obligations as provided for in this Law, the directly liable persons in charge and other directly liable persons shall be given a sanction in accordance with the law.\nArticle 50 Any state functionary performing data security related regulation regulation neglects his duty, abuses power, or engages in malpractice for personal gain, shall be given a sanction in accordance with the law.\nArticle 51 Whoever obtains data through theft or by any other illegal means, or eliminates or restricts competition in data processing, or harms the lawful rights and interests of individuals or organizations, shall be punished in accordance with the provisions of relevant laws and administrative regulations.\nArticle 52 Whoever, in violation of this Law, causes damages to others shall bear civil liability in accordance with the law. Where a violation of the provisions of this Law constitutes a violation of public security administration, a public security administrative penalty shall be given in accordance with the law. Where a crime is constituted, criminal responsibility shall be investigated in accordance with the law.\nSupplementary Provisions\nChapter VII Supplementary Provisions Article 53 The provisions of the Law of the People\u0026rsquo;s Republic of China on Guarding State Secrets and other relevant laws and administrative regulations shall apply to data processing that involves state secrets. The provisions of relevant laws and administrative regulations shall also be observed when data are processed in statistical or archival work and in data processing involving personal information.\nArticle 54 Measures for the military data security and protection shall be separately formulated by the Central Military Commission in accordance with this Law.\nArticle 55 This Law shall come into force as of September 1, 2021. 1 2\n","permalink":"https://ai.intlaws.com/en/compliance/china/dsl/","summary":"Officialof the Data Security Law of the PRC: 7 chapters, 55 articles, adopted 2021-06-10, in force 2021-09-01. English text from the NPC official English site (marked \u0026ldquo;Translation for Reference Only\u0026rdquo;); Chinese original from the Cyberspace Administration of China.","title":"Data Security Law of the PRC"},{"content":" Version and sources (verifiable)\nItem Content Instrument Executive Order 14365 of 11 December 2025 Official publication 90 FR 58499, published 16 December 2025 (Federal Register document no. 2025-23092) Structure 9 sections (Purpose; Policy; AI Litigation Task Force; Evaluation of State AI Laws; Restrictions on State Funding; Federal Reporting and Disclosure Standard; Preemption of State Laws Mandating Deceptive Conduct in AI Models; Legislation; General Provisions) Official text https://www.federalregister.gov/documents/2025/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-intelligence Chinese version No official Chinese text. A Chinese translation by our editorial team, marked non-official, is available → 中文全文 Status note This is an executive order, not a statute. The legislative recommendation contemplated by section 8 is a proposal; do not treat it as enacted law. Retrieval \u0026amp; verification Retrieved 2026-09-22 from the Federal Register full-text publication; section numbering and citations (47 U.S.C. 902(b), 47 U.S.C. 1702(e)-(f), 15 U.S.C. 45) checked against the published text. Executive Order 14365 of December 11, 2025\nEnsuring a National Policy Framework for Artificial Intelligence By the authority vested in me as President by the Constitution and the laws of the United States of America, it is hereby ordered:\nSection 1. Purpose. United States leadership in Artificial Intelligence (AI) will promote United States national and economic security and dominance across many domains. Pursuant to Executive Order 14179 of January 23, 2025 (Removing Barriers to American Leadership in Artificial Intelligence), I revoked my predecessor\u0026rsquo;s attempt to paralyze this industry and directed my Administration to remove barriers to United States AI leadership. My Administration has already done tremendous work to advance that objective, including by updating existing Federal regulatory frameworks to remove barriers to and encourage adoption of AI applications across sectors. These efforts have already delivered tremendous benefits to the American people and led to trillions of dollars of investments across the country. But we remain in the earliest days of this technological revolution and are in a race with adversaries for supremacy within it.\nTo win, United States AI companies must be free to innovate without cumbersome regulation. But excessive State regulation thwarts this imperative. First, State-by-State regulation by definition creates a patchwork of 50 different regulatory regimes that makes compliance more challenging, particularly for start-ups. Second, State laws are increasingly responsible for requiring entities to embed ideological bias within models. For example, a new Colorado law banning \u0026ldquo;algorithmic discrimination\u0026rdquo; may even force AI models to produce false results in order to avoid a \u0026ldquo;differential treatment or impact\u0026rdquo; on protected groups. Third, State laws sometimes impermissibly regulate beyond State borders, impinging on interstate commerce.\nMy Administration must act with the Congress to ensure that there is a minimally burdensome national standard—not 50 discordant State ones. The resulting framework must forbid State laws that conflict with the policy set forth in this order. That framework should also ensure that children are protected, censorship is prevented, copyrights are respected, and communities are safeguarded. A carefully crafted national framework can ensure that the United States wins the AI race, as we must. Until such a national standard exists, however, it is imperative that my Administration takes action to check the most onerous and excessive laws emerging from the States that threaten to stymie innovation.\nSec. 2. Policy. It is the policy of the United States to sustain and enhance the United States\u0026rsquo; global AI dominance through a minimally burdensome national policy framework for AI.\nSec. 3. AI Litigation Task Force. Within 30 days of the date of this order, the Attorney General shall establish an AI Litigation Task Force (Task Force) whose sole responsibility shall be to challenge State AI laws inconsistent with the policy set forth in section 2 of this order, including on grounds that such laws unconstitutionally regulate interstate commerce, are preempted by existing Federal regulations, or are otherwise unlawful in the Attorney General\u0026rsquo;s judgment, including, if appropriate, those laws identified pursuant to section 4 of this order. The Task Force shall consult from time to time with the Special Advisor for AI and Crypto, the Assistant to the President for Science and Technology, the Assistant to the President for Economic Policy, and the Assistant to the President and Counsel to the President regarding the emergence of specific State AI laws that warrant challenge.\nSec. 4. Evaluation of State AI Laws. Within 90 days of the date of this order, the Secretary of Commerce, consistent with the Secretary\u0026rsquo;s authorities under 47 U.S.C. 902(b), shall, in consultation with the Special Advisor for AI and Crypto, the Assistant to the President for Economic Policy, the Assistant to the President for Science and Technology, and the Assistant to the President and Counsel to the President, publish an evaluation of existing State AI laws that identifies onerous laws that conflict with the policy set forth in section 2 of this order, as well as laws that should be referred to the Task Force established pursuant to section 3 of this order. That evaluation of State AI laws shall, at a minimum, identify laws that require AI models to alter their truthful outputs, or that may compel AI developers or deployers to disclose or report information in a manner that would violate the First Amendment or any other provision of the Constitution. The evaluation may additionally identify State laws that promote AI innovation consistent with the policy set forth in section 2 of this order.\nSec. 5. Restrictions on State Funding. (a) Within 90 days of the date of this order, the Secretary of Commerce, through the Assistant Secretary of Commerce for Communications and Information, shall issue a Policy Notice specifying the conditions under which States may be eligible for remaining funding under the Broadband Equity Access and Deployment (BEAD) Program that was saved through my Administration\u0026rsquo;s \u0026ldquo;Benefit of the Bargain\u0026rdquo; reforms, consistent with 47 U.S.C. 1702(e)-(f). That Policy Notice must provide that States with onerous AI laws identified pursuant to section 4 of this order are ineligible for non-deployment funds, to the maximum extent allowed by Federal law. The Policy Notice must also describe how a fragmented State regulatory landscape for AI threatens to undermine BEAD-funded deployments, the growth of AI applications reliant on high-speed networks, and BEAD\u0026rsquo;s mission of delivering universal, high-speed connectivity.\n(b) Executive departments and agencies (agencies) shall assess their discretionary grant programs in consultation with the Special Advisor for AI and Crypto and determine whether agencies may condition such grants on States either not enacting an AI law that conflicts with the policy of this order, including any AI law identified pursuant to section 4 or challenged pursuant to section 3 of this order, or, for those States that have enacted such laws, on those States entering into a binding agreement with the relevant agency not to enforce any such laws during the performance period in which it receives the discretionary funding.\nSec. 6. Federal Reporting and Disclosure Standard. Within 90 days of the publication of the identification specified in section 4 of this order, the Chairman of the Federal Communications Commission shall, in consultation with the Special Advisor for AI and Crypto, initiate a proceeding to determine whether to adopt a Federal reporting and disclosure standard for AI models that preempts conflicting State laws.\nSec. 7. Preemption of State Laws Mandating Deceptive Conduct in AI Models. Within 90 days of the date of this order, the Chairman of the Federal Trade Commission shall, in consultation with the Special Advisor for AI and Crypto, issue a policy statement on the application of the Federal Trade Commission Act\u0026rsquo;s prohibition on unfair and deceptive acts or practices under 15 U.S.C. 45 to AI models. That policy statement must explain the circumstances under which State laws that require alterations to the truthful outputs of AI models are preempted by the Federal Trade Commission Act\u0026rsquo;s prohibition on engaging in deceptive acts or practices affecting commerce.\nSec. 8. Legislation. (a) The Special Advisor for AI and Crypto and the Assistant to the President for Science and Technology shall jointly prepare a legislative recommendation establishing a uniform Federal policy framework for AI that preempts State AI laws that conflict with the policy set forth in this order.\n(b) The legislative recommendation called for in subsection (a) of this section shall not propose preempting otherwise lawful State AI laws relating to: (i) child safety protections; (ii) AI compute and data center infrastructure, other than generally applicable permitting reforms; (iii) State government procurement and use of AI; and (iv) other topics as shall be determined.\nSec. 9. General Provisions. (a) Nothing in this order shall be construed to impair or otherwise affect: (i) the authority granted by law to an executive department or agency, or the head thereof; or (ii) the functions of the Director of the Office of Management and Budget relating to budgetary, administrative, or legislative proposals.\n(b) This order shall be implemented consistent with applicable law and subject to the availability of appropriations.\n(c) This order is not intended to, and does not, create any right or benefit, substantive or procedural, enforceable at law or in equity by any party against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person.\n(d) The costs for publication of this order shall be borne by the Department of Commerce.\nTHE WHITE HOUSE, December 11, 2025.\n","permalink":"https://ai.intlaws.com/en/compliance/us/executive-order-14365/","summary":"Official text of Executive Order 14365 of 11 December 2025, \u0026ldquo;Ensuring a National Policy Framework for Artificial Intelligence\u0026rdquo;, published at 90 FR 58499 (16 December 2025), nine sections: policy of a minimally burdensome national AI framework, an AI Litigation Task Force, a Commerce Department evaluation of State AI laws, restrictions on State funding (BEAD, discretionary grants), an FCC proceeding on a Federal reporting and disclosure standard, an FTC policy statement on preemption, and a legislative recommendation that does not preempt State laws on child safety, AI compute/data-centre infrastructure, State procurement, and other topics as determined.","title":"Executive Order 14365"},{"content":" Version and sources (verifiable)\nItem Content Adopted deliberated and adopted at the 12th executive meeting of the Cyberspace Administration of China in 2023 (23 May 2023), and agreed by the National Development and Reform Commission, the Ministry of Education, the Ministry of Science and Technology, the Ministry of Industry and Information Technology, the Ministry of Public Security and the National Radio and Television Administration Promulgated 10 July 2023 (Order No. 15 of seven departments) Effective 15 August 2023 Structure 5 chapters, 24 articles Currently effective Yes (as of 2026-09-22) Chinese original https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm English version No official English translation published. This English text is a translation by our editorial team, cross-checked article by article against the official Chinese text; it is not an official translation and is for reference only. Verification Retrieved 2026-09-22; 24 articles, correspondence with the Chinese text verified one-for-one, no gaps Chapter I General provisions Article 1 These Measures are formulated in accordance with the Cybersecurity Law of the People\u0026rsquo;s Republic of China, the Data Security Law of the People\u0026rsquo;s Republic of China, the Personal Information Protection Law of the People\u0026rsquo;s Republic of China, the Law of the People\u0026rsquo;s Republic of China on Scientific and Technological Progress and other laws and administrative regulations, for the purposes of promoting the sound development and regulated application of generative artificial intelligence, safeguarding national security and the public interest, and protecting the lawful rights and interests of citizens, legal persons and other organisations.\nArticle 2 These Measures apply to services that use generative artificial intelligence technology to provide the public within the territory of the People\u0026rsquo;s Republic of China with content such as text, images, audio and video (hereinafter \u0026ldquo;generative AI services\u0026rdquo;).\nWhere the State has other provisions on the use of generative AI services for activities such as news and publishing, film and television production, and literary and artistic creation, those provisions shall prevail.\nThese Measures do not apply to industry organisations, enterprises, educational and research institutions, public cultural institutions and relevant professional institutions that develop and apply generative AI technology without providing generative AI services to the public within the territory.\nArticle 3 The State adheres to the principle of attaching equal importance to development and security and combining the promotion of innovation with governance according to law, takes effective measures to encourage innovative development of generative artificial intelligence, and exercises inclusive, prudent and classification-based, tiered regulation over generative AI services.\nArticle 4 The provision and use of generative AI services shall comply with laws and administrative regulations, respect public order and good morals and ethics, and comply with the following provisions:\n(1) uphold the core socialist values; not generate content prohibited by laws and administrative regulations, such as content that incites subversion of State power or overthrow of the socialist system, endangers national security and interests or damages the national image, incites secession and undermines national unity and social stability, propagates terrorism or extremism, propagates ethnic hatred or ethnic discrimination, or is violent or obscene, or false and harmful information;\n(2) take effective measures in the course of algorithm design, selection of training data, model generation and optimisation, and service provision to prevent discrimination on grounds such as ethnicity, belief, country, region, gender, age, occupation and health;\n(3) respect intellectual property rights and business ethics, keep trade secrets, and refrain from using advantages in algorithms, data or platforms to engage in monopolistic or unfair competitive practices;\n(4) respect the lawful rights and interests of others; not endanger the physical or mental health of others; not infringe others\u0026rsquo; rights to portrait, reputation, honour, privacy or personal information;\n(5) take effective measures, in light of the characteristics of the type of service, to enhance the transparency of generative AI services and improve the accuracy and reliability of generated content.\nArticle 5 Innovative application of generative artificial intelligence technology in all industries and fields is encouraged, so as to generate positive, healthy and uplifting high-quality content, explore and optimise application scenarios, and build an application ecosystem.\nIndustry organisations, enterprises, educational and research institutions, public cultural institutions and relevant professional institutions are supported in collaborating on technological innovation, construction of data resources, transformation and application, and risk prevention in generative artificial intelligence.\nArticle 6 Independent innovation in basic technologies such as generative artificial intelligence algorithms, frameworks, chips and supporting software platforms is encouraged, as are international exchanges and cooperation on the basis of equality and mutual benefit and participation in the formulation of international rules relating to generative artificial intelligence.\nThe construction of generative artificial intelligence infrastructure and public training-data resource platforms shall be promoted. Collaborative sharing of computing power resources shall be facilitated and the efficiency of their use improved. The classified and tiered, orderly opening of public data shall be promoted to expand high-quality public training-data resources. The use of secure and trustworthy chips, software, tools, computing power and data resources is encouraged.\nChapter II Development and governance of generative AI technology Article 7 Providers of generative AI services (hereinafter \u0026ldquo;providers\u0026rdquo;) shall, in accordance with law, carry out training data processing activities such as pre-training and optimisation training, and shall comply with the following provisions:\n(1) use data and foundation models with lawful sources;\n(2) where intellectual property is involved, not infringe intellectual property rights lawfully enjoyed by others;\n(3) where personal information is involved, obtain the consent of the individual or satisfy other circumstances provided for by laws and administrative regulations;\n(4) take effective measures to improve the quality of training data and enhance its authenticity, accuracy, objectivity and diversity;\n(5) comply with other relevant provisions of the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law and other laws and administrative regulations, and with the relevant regulatory requirements of the competent departments.\nArticle 8 Where data annotation is carried out in the course of research and development of generative artificial intelligence technology, the provider shall formulate clear, specific and operable annotation rules that meet the requirements of these Measures; carry out quality assessment of data annotation and verify by sampling the accuracy of annotated content; and provide necessary training to annotators to raise their awareness of law-abiding conduct and supervise and guide them to carry out annotation work in a standardised manner.\nArticle 9 A provider shall, in accordance with law, bear the responsibility of an online information content producer and perform its online information security obligations. Where personal information is involved, it shall, in accordance with law, bear the responsibility of a personal information processor and perform its personal information protection obligations.\nA provider shall conclude a service agreement with the users of the generative AI service registered with it (hereinafter \u0026ldquo;users\u0026rdquo;) to clarify the rights and obligations of both parties.\nArticle 10 A provider shall clearly define and publicly disclose the applicable groups of people, occasions and purposes of its service, guide users to understand and use generative artificial intelligence technology in a scientific and rational manner and in accordance with law, and take effective measures to prevent minor users from becoming overly dependent on or addicted to generative AI services.\nArticle 11 A provider shall, in accordance with law, perform protection obligations in respect of users\u0026rsquo; input information and usage records, shall not collect unnecessary personal information, shall not unlawfully retain input information and usage records that can identify users, and shall not unlawfully provide users\u0026rsquo; input information and usage records to others.\nA provider shall, in accordance with law and in a timely manner, accept and handle individuals\u0026rsquo; requests to access, copy, correct, supplement and delete their personal information.\nArticle 12 A provider shall label generated content such as images and videos in accordance with the Provisions on the Administration of Deep Synthesis of Internet Information Services.\nArticle 13 A provider shall, in the course of its service, provide safe, stable and continuous service and ensure normal use by users.\nArticle 14 Where a provider discovers illegal content, it shall promptly take measures such as stopping generation, stopping transmission and elimination, take measures such as model optimisation training for rectification, and report to the competent departments.\nWhere a provider discovers that a user is using the generative AI service to engage in illegal activities, it shall, in accordance with law and the agreement, take measures such as warning, restricting functions, suspending or terminating the provision of services to that user, preserve the relevant records, and report to the competent departments.\nArticle 15 A provider shall establish and improve complaint and reporting mechanisms, set up convenient complaint and reporting channels, publish the handling process and the time limit for feedback, and promptly accept and handle public complaints and reports and give feedback on the outcome.\nChapter III Obligations of providers Article 16 The departments for cyberspace administration, development and reform, education, science and technology, industry and information technology, public security, radio and television and news and publishing shall, in accordance with their respective duties and in accordance with law, strengthen the administration of generative AI services.\nThe competent State departments shall, in light of the characteristics of generative artificial intelligence technology and its service applications in the relevant industries and fields, improve scientific regulatory approaches compatible with innovative development, and formulate corresponding classification-based and tiered regulatory rules or guidelines.\nArticle 17 A provider that provides generative AI services with attributes of public opinion or capacity for social mobilisation shall carry out a security assessment in accordance with the relevant State provisions and, in accordance with the Provisions on the Administration of Algorithmic Recommendations in Internet Information Services, complete the procedures for algorithm filing and for modification and cancellation of filing.\nArticle 18 Where a user discovers that a generative AI service does not comply with laws, administrative regulations and these Measures, the user has the right to complain to or report the matter to the competent departments.\nArticle 19 The competent departments shall, in accordance with their duties, carry out supervision and inspection of generative AI services, and providers shall cooperate in accordance with law, explain as required the sources, scale and types of training data, annotation rules, and the mechanisms of the algorithms, and provide the necessary technical and data support and assistance.\nRelevant institutions and personnel participating in the security assessment and supervision and inspection of generative AI services shall, in accordance with law, keep confidential the State secrets, trade secrets, personal privacy and personal information learned in the performance of their duties, and shall not disclose them or unlawfully provide them to others.\nArticle 20 Where a generative AI service provided to the public within the territory from outside the territory of the People\u0026rsquo;s Republic of China does not comply with laws, administrative regulations and these Measures, the national cyberspace administration department shall notify the relevant institutions to take technical measures and other necessary measures to deal with it.\nArticle 21 Where a provider violates these Measures, the competent departments shall impose penalties in accordance with the provisions of the Cybersecurity Law of the People\u0026rsquo;s Republic of China, the Data Security Law of the People\u0026rsquo;s Republic of China, the Personal Information Protection Law of the People\u0026rsquo;s Republic of China, the Law of the People\u0026rsquo;s Republic of China on Scientific and Technological Progress and other laws and administrative regulations; where laws and administrative regulations do not so provide, the competent departments shall, in accordance with their duties, issue a warning or a notice of criticism and order correction within a time limit; where the provider refuses to correct or the circumstances are serious, order it to suspend the provision of the relevant service.\nWhere the act constitutes a violation of public security administration, public security administrative penalties shall be imposed in accordance with law; where a crime is constituted, criminal liability shall be pursued in accordance with law.\nChapter IV Definitions Article 22 For the purposes of these Measures:\n(1) \u0026ldquo;generative artificial intelligence technology\u0026rdquo; means models and related technology with the capacity to generate content such as text, images, audio and video;\n(2) \u0026ldquo;provider of generative AI services\u0026rdquo; means an organisation or individual that uses generative artificial intelligence technology to provide generative AI services (including providing such services through, for example, programmable interfaces);\n(3) \u0026ldquo;user of generative AI services\u0026rdquo; means an organisation or individual that uses generative AI services to generate content.\nChapter V Supplementary provisions Article 23 Where laws and administrative regulations require that a relevant administrative licence be obtained to provide generative AI services, the provider shall obtain the licence in accordance with law.\nForeign-invested generative AI services shall comply with the provisions of laws and administrative regulations on foreign investment.\nArticle 24 These Measures shall come into force on 15 August 2023.\n","permalink":"https://ai.intlaws.com/en/compliance/china/generative-ai-interim-measures/","summary":"Full text of the Interim Measures for the Administration of Generative Artificial Intelligence Services (promulgated 10 July 2023, effective 15 August 2023), 24 articles in five chapters: scope, training-data obligations, provider duties, obligations to users, security assessment and algorithm filing for services with public-opinion or social-mobilisation attributes, and penalties. English translation by our editorial team (non-official, cross-checked article by article against the official Chinese text).","title":"Interim Measures for the Administration of Generative Artificial Intelligence Services"},{"content":" Version and sources (verifiable)\nItem Content Official title 人工知能関連技術の研究開発及び活用の推進に関する法律 Common name AI Promotion Act (AI 推進法) Act number Act No. 53 of Reiwa 7 (令和七年法律第五十三号) Promulgation 4 June 2025 Structure 28 articles + 2 supplementary provisions; four chapters (Ch. I General Provisions, Ch. II Basic Measures, Ch. III AI Basic Plan, Ch. IV AI Strategy Headquarters) Official text (Japanese) e-Gov Law Search ｜ e-Gov API (machine readable) English translation No official English translation has been issued by the Government of Japan. This English text is translated by this journal from the official Japanese text; it is unofficial and for reference only Chinese translation 中文译本(非官方) Scope note The Japanese text is the authoritative version; in case of any discrepancy, the Japanese text prevails. Verification record 2026-09-22, three hard checks against the official Japanese text: ① article headings 30/30 (Articles 1–28 + 2 supplementary provisions); ② paragraph markers 15/15 and items 5/5 in exact sequence; ③ all 7 statutory instrument numbers mapped and verified (7/7), numerical set complete. Translation notes: 7 terms carry [to verify], incl. 知的基盤 (\u0026ldquo;knowledge base\u0026rdquo;) and 主任の大臣 (\u0026ldquo;competent minister\u0026rdquo;) Full text (official Japanese text) 令和七年法律第五十三号\n人工知能関連技術の研究開発及び活用の推進に関する法律\n目次\n第一章　総則\n（第一条―第十条）\n第二章　基本的施策\n（第十一条―第十七条）\n第三章　人工知能基本計画\n（第十八条）\n第四章　人工知能戦略本部\n（第十九条―第二十八条）\n附則\n第一章　総則\n第一条　（目的）\nこの法律は、人工知能関連技術が我が国の経済社会の発展の基盤となる技術であることに鑑み、人工知能関連技術の研究開発及び活用の推進に関する施策について、基本理念並びに人工知能関連技術の研究開発及び活用の推進に関する基本的な計画の策定その他の施策の基本となる事項を定めるとともに、人工知能戦略本部を設置することにより、科学技術・イノベーション基本法（平成七年法律第百三十号）及びデジタル社会形成基本法（令和三年法律第三十五号）その他の関係法律による施策と相まって、人工知能関連技術の研究開発及び活用の推進に関する施策の総合的かつ計画的な推進を図り、もって国民生活の向上及び国民経済の健全な発展に寄与することを目的とする。\n第二条　（定義）\nこの法律において、「人工知能関連技術」とは、人工的な方法により人間の認知、推論及び判断に係る知的な能力を代替する機能を実現するために必要な技術並びに入力された情報を当該技術を利用して処理し、その結果を出力する機能を実現するための情報処理システムに関する技術をいう。\n第三条　（基本理念）\n人工知能関連技術の研究開発及び活用の推進は、科学技術・イノベーション基本法第三条に定める科学技術・イノベーション創出の振興に関する方針及びデジタル社会形成基本法第二章に定める基本理念のほか、この条に定める基本理念に基づいて行うものとする。\n２　人工知能関連技術の研究開発及び活用の推進は、人工知能関連技術が、その適正かつ効果的な活用によって行政事務及び民間の事業活動の著しい効率化及び高度化並びに新産業の創出をもたらすものとして経済社会の発展の基盤となる技術であるとともに、安全保障の観点からも重要な技術であることに鑑み、我が国において人工知能関連技術の研究開発を行う能力を保持するとともに、人工知能関連技術に関する産業の国際競争力を向上させることを旨として、行うものとする。\n３　人工知能関連技術の研究開発及び活用の推進は、人工知能関連技術の基礎研究から国民生活及び経済活動における活用に至るまでの各段階の関係者による取組が相互に密接な関連を有することに鑑み、これらの取組を総合的かつ計画的に推進することを旨として、行うものとする。\n４　人工知能関連技術の研究開発及び活用は、不正な目的又は不適切な方法で行われた場合には、犯罪への利用、個人情報の漏えい、著作権の侵害その他の国民生活の平穏及び国民の権利利益が害される事態を助長するおそれがあることに鑑み、その適正な実施を図るため、人工知能関連技術の研究開発及び活用の過程の透明性の確保その他の必要な施策が講じられなければならない。\n５　人工知能関連技術の研究開発及び活用は、我が国及び国際社会の平和と発展に寄与するものとなるよう、国際的協調の下に推進することを旨とし、我が国が人工知能関連技術の研究開発及び活用に関する国際協力において主導的な役割を果たすよう努めるものとする。\n第四条　（国の責務）\n国は、前条に定める基本理念（以下「基本理念」という。）にのっとり、人工知能関連技術の研究開発及び活用の推進に関する施策を総合的かつ計画的に策定し、及び実施する責務を有する。\n２　国は、行政事務の効率化及び高度化を図るため、国の行政機関における人工知能関連技術の積極的な活用を進めるものとする。\n第五条　（地方公共団体の責務）\n地方公共団体は、基本理念にのっとり、人工知能関連技術の研究開発及び活用の推進に関し、国との適切な役割分担の下、地方公共団体が実施すべき施策として、その地方公共団体の区域の特性を生かした自主的な施策を策定し、及び実施する責務を有する。\n第六条　（研究開発機関の責務等）\n大学、科学技術・イノベーション創出の活性化に関する法律（平成二十年法律第六十三号）第二条第九項に規定する研究開発法人その他の人工知能関連技術の研究開発を行う機関（以下「研究開発機関」という。）は、基本理念にのっとり、人工知能関連技術の研究開発及びその成果の普及並びに専門的かつ幅広い知識を有する人材の育成に積極的に努めるとともに、第四条の規定に基づき国が実施する施策及び前条の規定に基づき地方公共団体が実施する施策に協力するよう努めるものとする。\n２　国及び地方公共団体は、人工知能関連技術の研究開発及び活用の推進に関する施策で大学に係るものを策定し、及び実施するに当たっては、大学における研究活動の活性化を図るよう努めるとともに、研究者の自主性の尊重その他の大学における研究の特性に配慮しなければならない。\n３　研究開発機関は、人工知能関連技術の研究開発を効果的に進めるに当たっては、人文科学及び自然科学に関する多様な分野の知見を総合的に活用することが必要であることに鑑み、学際的又は総合的な研究開発に努めるものとする。\n第七条　（活用事業者の責務）\n人工知能関連技術を活用した製品又はサービスの開発又は提供をしようとする者その他の人工知能関連技術を事業活動において活用しようとする者（以下「活用事業者」という。）は、基本理念にのっとり、自ら積極的な人工知能関連技術の活用により事業活動の効率化及び高度化並びに新産業の創出に努めるとともに、第四条の規定に基づき国が実施する施策及び第五条の規定に基づき地方公共団体が実施する施策に協力しなければならない。\n第八条　（国民の責務）\n国民は、基本理念にのっとり、人工知能関連技術に対する理解と関心を深めるとともに、第四条の規定に基づき国が実施する施策及び第五条の規定に基づき地方公共団体が実施する施策に協力するよう努めるものとする。\n第九条　（連携の強化）\n国は、国、地方公共団体、研究開発機関及び活用事業者が相互に連携を図りながら協力することにより人工知能関連技術の研究開発及び活用の推進が図られることに鑑み、これらの者の間の連携の強化に必要な施策を講ずるものとする。\n第十条　（法制上の措置等）\n国は、人工知能関連技術の研究開発及び活用の推進に関する施策を実施するため必要な法制上又は財政上の措置その他の措置を講ずるものとする。\n第二章　基本的施策\n第十一条　（研究開発の推進等）\n国は、人工知能関連技術の基礎研究から実用化のための研究開発に至るまでの一貫した研究開発の推進、研究開発機関における研究開発の成果の移転のための体制の整備、研究開発の成果に係る情報の提供その他の施策を講ずるものとする。\n第十二条　（施設及び設備等の整備及び共用の促進）\n国は、人工知能関連技術の研究開発及び活用に当たって必要となる大規模な情報処理、情報通信、電磁的記録（電子的方式、磁気的方式その他人の知覚によっては認識することができない方式で作られる記録であって、電子計算機による情報処理の用に供されるものをいう。）の保管等に係る施設及び設備並びにデータセット（特定の目的をもって収集した情報の集合物をいう。）その他の知的基盤（科学技術・イノベーション創出の活性化に関する法律第二十四条の四に規定する知的基盤をいう。以下この条において同じ。）を研究開発機関及び活用事業者が広く利用できるようにするため、これらの施設及び設備並びに知的基盤の整備及び共用の促進のために必要な施策を講ずるものとする。\n第十三条　（適正性の確保）\n国は、人工知能関連技術の研究開発及び活用の適正な実施を図るため、国際的な規範の趣旨に即した指針の整備その他の必要な施策を講ずるものとする。\n第十四条　（人材の確保等）\n国は、地方公共団体、研究開発機関及び活用事業者と緊密な連携協力を図りながら、人工知能関連技術の基礎研究から国民生活及び経済活動における活用に至るまでの各段階において必要となる専門的かつ幅広い知識を有する多様な分野の人材の確保、養成及び資質の向上に必要な施策を講ずるものとする。\n第十五条　（教育の振興等）\n国は、国民が広く人工知能関連技術に対する理解と関心を深めるよう、人工知能関連技術に関する教育及び学習の振興、広報活動の充実その他の必要な施策を講ずるものとする。\n第十六条　（調査研究等）\n国は、国内外の人工知能関連技術の研究開発及び活用の動向に関する情報の収集、不正な目的又は不適切な方法による人工知能関連技術の研究開発又は活用に伴って国民の権利利益の侵害が生じた事案の分析及びそれに基づく対策の検討その他の人工知能関連技術の研究開発及び活用の推進に資する調査及び研究を行い、その結果に基づいて、研究開発機関、活用事業者その他の者に対する指導、助言、情報の提供その他の必要な措置を講ずるものとする。\n第十七条　（国際協力）\n国は、人工知能関連技術の研究開発及び活用に関する国際協力を推進するとともに、国際的な規範の策定に積極的に参画するものとする。\n第三章　人工知能基本計画\n第十八条\n政府は、基本理念にのっとり、前章に定める基本的施策を踏まえ、人工知能関連技術の研究開発及び活用の推進に関する基本的な計画（以下「人工知能基本計画」という。）を定めるものとする。\n２　人工知能基本計画は、次に掲げる事項について定めるものとする。\n一　人工知能関連技術の研究開発及び活用の推進に関する施策についての基本的な方針\n二　人工知能関連技術の研究開発及び活用の推進に関し、政府が総合的かつ計画的に講ずべき施策\n三　前二号に掲げるもののほか、人工知能関連技術の研究開発及び活用の推進に関する施策を政府が総合的かつ計画的に推進するために必要な事項\n３　内閣総理大臣は、人工知能戦略本部の作成した人工知能基本計画の案について閣議の決定を求めるものとする。\n４　内閣総理大臣は、前項の閣議の決定があったときは、遅滞なく、人工知能基本計画を公表するものとする。\n５　前二項の規定は、人工知能基本計画の変更について準用する。\n第四章　人工知能戦略本部\n第十九条　（設置）\n人工知能関連技術の研究開発及び活用の推進に関する施策を総合的かつ計画的に推進するため、内閣に、人工知能戦略本部（以下「本部」という。）を置く。\n第二十条　（所掌事務）\n本部は、次に掲げる事務をつかさどる。\n一　人工知能基本計画の案の作成及び実施の推進に関すること。\n二　前号に掲げるもののほか、人工知能関連技術の研究開発及び活用の推進に関する施策で重要なものの企画及び立案並びに総合調整に関すること。\n第二十一条　（組織）\n本部は、人工知能戦略本部長、人工知能戦略副本部長及び人工知能戦略本部員をもって組織する。\n第二十二条　（人工知能戦略本部長）\n本部の長は、人工知能戦略本部長（以下「本部長」という。）とし、内閣総理大臣をもって充てる。\n２　本部長は、本部の事務を総括し、所部の職員を指揮監督する。\n第二十三条　（人工知能戦略副本部長）\n本部に、人工知能戦略副本部長（次項及び次条第二項において「副本部長」という。）を置き、内閣官房長官及び人工知能戦略担当大臣（内閣総理大臣の命を受けて、人工知能関連技術の研究開発及び活用の総合的かつ計画的な推進に関し内閣総理大臣を助けることをその職務とする国務大臣をいう。）をもって充てる。\n２　副本部長は、本部長の職務を助ける。\n第二十四条　（人工知能戦略本部員）\n本部に、人工知能戦略本部員（次項において「本部員」という。）を置く。\n２　本部員は、本部長及び副本部長以外の全ての国務大臣をもって充てる。\n第二十五条　（資料の提出その他の協力）\n本部は、その所掌事務を遂行するため必要があると認めるときは、関係行政機関、地方公共団体、独立行政法人（独立行政法人通則法（平成十一年法律第百三号）第二条第一項に規定する独立行政法人をいう。）及び地方独立行政法人（地方独立行政法人法（平成十五年法律第百十八号）第二条第一項に規定する地方独立行政法人をいう。）の長並びに特殊法人（法律により直接に設立された法人又は特別の法律により特別の設立行為をもって設立された法人であって、総務省設置法（平成十一年法律第九十一号）第四条第一項第八号の規定の適用を受けるものをいう。）の代表者に対して、資料の提出、意見の表明、説明その他必要な協力を求めることができる。\n２　本部は、その所掌事務を遂行するために特に必要があると認めるときは、前項に規定する者以外の者に対しても、必要な協力を依頼することができる。\n第二十六条　（事務）\n本部に関する事務は、内閣府において処理する。\n第二十七条　（主任の大臣）\n本部に係る事項については、内閣法（昭和二十二年法律第五号）にいう主任の大臣は、内閣総理大臣とする。\n第二十八条　（政令への委任）\nこの法律に定めるもののほか、本部に関し必要な事項は、政令で定める。\n附　則\n第一条　（施行期日）\nこの法律は、公布の日から施行する。ただし、第三章及び第四章並びに附則第三条及び第四条の規定は、公布の日から起算して三月を超えない範囲内において政令で定める日から施行する。\n第二条　（検討）\n政府は、人工知能関連技術の研究開発及び活用の推進に関する諸施策についての国際的動向その他の社会経済情勢の変化を勘案しつつ、この法律の施行の状況について検討を加え、必要があると認めるときは、その結果に基づいて所要の措置を講ずるものとする。\nEnglish translation (unofficial) Reiwa 7 (2025) Act No. 53\nAct on the Promotion of Research and Development and Utilization of Artificial Intelligence-Related Technology\nTable of Contents\nChapter I General Provisions\n(Articles 1 through 10)\nChapter II Basic Measures\n(Articles 11 through 17)\nChapter III AI Basic Plan\n(Article 18)\nChapter IV AI Strategy Headquarters\n(Articles 19 through 28)\nSupplementary Provisions\nChapter I General Provisions\nArticle 1 (Purpose)\nThis Act, in view of the fact that AI-related technology is a technology that forms the foundation for the development of Japan\u0026rsquo;s economy and society, provides for the basic principles concerning measures for the promotion of the research and development and utilization of AI-related technology, and provides for the formulation of a basic plan concerning the promotion of the research and development and utilization of AI-related technology and other matters that form the basis of measures, and establishes the AI Strategy Headquarters, and thereby, in conjunction with the measures under the Science, Technology and Innovation Basic Act (Act No. 130 of 1995) and the Digital Society Formation Basic Act (Act No. 35 of 2021) and other relevant laws, seeks to achieve the comprehensive and systematic promotion of measures concerning the research and development and utilization of AI-related technology, and thereby to contribute to the improvement of the lives of the people and the sound development of the national economy.\nArticle 2 (Definitions)\nIn this Act, \u0026ldquo;AI-related technology\u0026rdquo; means technology necessary for realizing, by artificial methods, functions that substitute for the intellectual capabilities involved in human cognition, reasoning and judgment, as well as technology concerning information processing systems for realizing functions that process input information by using said technology and output the results thereof.\nArticle 3 (Basic Principles)\nThe promotion of the research and development and utilization of AI-related technology is to be carried out based on the basic principles provided for in this Article, in addition to the policy concerning the promotion of the creation of science, technology and innovation provided for in Article 3 of the Science, Technology and Innovation Basic Act and the basic principles provided for in Chapter II of the Digital Society Formation Basic Act.\n2 The promotion of the research and development and utilization of AI-related technology is to be carried out, in view of the fact that AI-related technology is a technology that forms the foundation for the development of the economy and society by bringing about significant efficiency gains and sophistication in administrative affairs and private business activities and the creation of new industries through its appropriate and effective utilization, and is also an important technology from the perspective of national security, with the aim of maintaining Japan\u0026rsquo;s capacity to conduct the research and development of AI-related technology and enhancing the international competitiveness of industries related to AI-related technology.\n3 The promotion of the research and development and utilization of AI-related technology is to be carried out with the aim of comprehensively and systematically promoting the efforts of the parties concerned at each stage from basic research on AI-related technology to its utilization in the lives of the people and economic activities, in view of the fact that those efforts are closely interrelated with one another.\n4 In view of the fact that, if the research and development and utilization of AI-related technology is carried out for wrongful purposes or by inappropriate methods, there is a risk of encouraging situations in which the tranquility of the lives of the people and the rights and interests of the people are harmed through use in crimes, leakage of personal information, infringement of copyright and other means, necessary measures such as ensuring the transparency of the process of the research and development and utilization of AI-related technology must be taken in order to ensure that such research and development and utilization is carried out properly.\n5 The research and development and utilization of AI-related technology is to be promoted under international coordination so as to contribute to the peace and development of Japan and the international community, and efforts are to be made so that Japan plays a leading role in international cooperation concerning the research and development and utilization of AI-related technology.\nArticle 4 (Responsibilities of the State)\nThe State has the responsibility to comprehensively and systematically formulate and implement measures concerning the promotion of the research and development and utilization of AI-related technology, in accordance with the basic principles provided for in the preceding Article (hereinafter referred to as the \u0026ldquo;basic principles\u0026rdquo;).\n2 The State is to promote the active utilization of AI-related technology in the State\u0026rsquo;s administrative organs in order to achieve efficiency gains and sophistication in administrative affairs.\nArticle 5 (Responsibilities of Local Governments)\nLocal governments have the responsibility to formulate and implement, in accordance with the basic principles, under an appropriate division of roles with the State, and as measures that the local governments should implement concerning the promotion of the research and development and utilization of AI-related technology, independent measures that make use of the characteristics of the areas of the relevant local governments.\nArticle 6 (Responsibilities, etc. of Research and Development Institutions)\nUniversities, research and development corporations provided for in Article 2, paragraph (9) of the Act on the Activation of Science, Technology and Innovation Creation [to verify] (Act No. 63 of 2008) and other institutions that conduct the research and development of AI-related technology (hereinafter referred to as \u0026ldquo;research and development institutions\u0026rdquo;) are to, in accordance with the basic principles, actively endeavor to conduct the research and development of AI-related technology, to disseminate the results thereof, and to foster human resources with specialized and wide-ranging knowledge, and are to endeavor to cooperate with the measures implemented by the State pursuant to the provisions of Article 4 and the measures implemented by local governments pursuant to the provisions of the preceding Article.\n2 When the State and local governments formulate and implement measures concerning the promotion of the research and development and utilization of AI-related technology that relate to universities, they are to endeavor to activate research activities at universities and must give consideration to respect for the autonomy of researchers and other characteristics of research at universities.\n3 Research and development institutions are to endeavor to conduct interdisciplinary or comprehensive research and development, in view of the fact that it is necessary to comprehensively utilize knowledge from diverse fields in the humanities and the natural sciences in order to effectively advance the research and development of AI-related technology.\nArticle 7 (Responsibilities of Utilizing Business Operators)\nPersons who intend to develop or provide products or services utilizing AI-related technology, and other persons who intend to utilize AI-related technology in their business activities (hereinafter referred to as \u0026ldquo;utilizing business operators\u0026rdquo; [to verify]), must, in accordance with the basic principles, endeavor to achieve efficiency gains and sophistication in their business activities and the creation of new industries through their own active utilization of AI-related technology, and must cooperate with the measures implemented by the State pursuant to the provisions of Article 4 and the measures implemented by local governments pursuant to the provisions of Article 5.\nArticle 8 (Responsibilities of the People)\nThe people are to, in accordance with the basic principles, deepen their understanding of and interest in AI-related technology and endeavor to cooperate with the measures implemented by the State pursuant to the provisions of Article 4 and the measures implemented by local governments pursuant to the provisions of Article 5.\nArticle 9 (Strengthening of Coordination)\nThe State is to take the necessary measures for strengthening coordination among the State, local governments, research and development institutions and utilizing business operators, in view of the fact that the promotion of the research and development and utilization of AI-related technology is achieved through cooperation among those parties while they coordinate with one another.\nArticle 10 (Legislative Measures, etc.)\nThe State is to take legislative or financial measures and other measures necessary for implementing measures concerning the promotion of the research and development and utilization of AI-related technology.\nChapter II Basic Measures\nArticle 11 (Promotion of Research and Development, etc.)\nThe State is to take measures for the promotion of consistent research and development from basic research on AI-related technology through research and development for practical application, for the development of systems for transferring the results of research and development at research and development institutions, for the provision of information concerning the results of research and development, and other measures.\nArticle 12 (Development of Facilities and Equipment, etc. and Promotion of Their Shared Use)\nThe State is to take the necessary measures for the development and promotion of the shared use of facilities and equipment and of the knowledge base [to verify], in order to enable research and development institutions and utilizing business operators to make wide use of the facilities and equipment pertaining to large-scale information processing, information and communications, and the storage of electromagnetic records [to verify] (meaning records made in an electronic form, a magnetic form or any other form not perceivable by human senses and used for information processing by computers) that are necessary for the research and development and utilization of AI-related technology, as well as of datasets (meaning collections of information gathered for a specific purpose) and other knowledge bases (meaning the knowledge base provided for in Article 24-4 of the Act on the Activation of Science, Technology and Innovation Creation; hereinafter the same applies in this Article).\nArticle 13 (Ensuring Appropriateness)\nThe State is to take measures for the development of guidelines conforming to the purport of international norms and other necessary measures in order to ensure that the research and development and utilization of AI-related technology is carried out properly.\nArticle 14 (Securing Human Resources, etc.)\nThe State is to take the necessary measures for securing, training and improving the qualities of human resources in diverse fields who have specialized and wide-ranging knowledge required at each stage from basic research on AI-related technology to its utilization in the lives of the people and economic activities, while achieving close coordination and cooperation with local governments, research and development institutions and utilizing business operators.\nArticle 15 (Promotion of Education, etc.)\nThe State is to take measures for the promotion of education and learning concerning AI-related technology, for the enhancement of public relations activities and other necessary measures so that the people may widely deepen their understanding of and interest in AI-related technology.\nArticle 16 (Research and Study, etc.)\nThe State is to conduct research and study contributing to the promotion of the research and development and utilization of AI-related technology, such as the collection of information concerning trends in the research and development and utilization of AI-related technology in Japan and abroad, the analysis of cases in which the rights and interests of the people have been harmed in connection with the research and development or utilization of AI-related technology for wrongful purposes or by inappropriate methods, and the examination of countermeasures based on that analysis, and is to take necessary measures such as guidance, advice and provision of information to research and development institutions, utilizing business operators and other persons based on the results thereof.\nArticle 17 (International Cooperation)\nThe State is to promote international cooperation concerning the research and development and utilization of AI-related technology, and is to actively participate in the formulation of international norms.\nChapter III AI Basic Plan\nArticle 18\nThe Government is to formulate a basic plan concerning the promotion of the research and development and utilization of AI-related technology (hereinafter referred to as the \u0026ldquo;AI Basic Plan\u0026rdquo;), in accordance with the basic principles and based on the basic measures provided for in the preceding Chapter.\n2 The AI Basic Plan is to provide for the following matters:\n(i) the basic policy concerning measures for the promotion of the research and development and utilization of AI-related technology;\n(ii) the measures that the Government should take comprehensively and systematically concerning the promotion of the research and development and utilization of AI-related technology;\n(iii) in addition to the matters set forth in the preceding two items, the matters necessary for the Government to comprehensively and systematically promote measures concerning the promotion of the research and development and utilization of AI-related technology.\n3 The Prime Minister is to seek a Cabinet decision on the draft AI Basic Plan prepared by the AI Strategy Headquarters.\n4 When the Cabinet decision under the preceding paragraph has been made, the Prime Minister is to publish the AI Basic Plan without delay.\n5 The provisions of the preceding two paragraphs apply mutatis mutandis to amendments to the AI Basic Plan.\nChapter IV AI Strategy Headquarters\nArticle 19 (Establishment)\nThe AI Strategy Headquarters (hereinafter referred to as the \u0026ldquo;Headquarters\u0026rdquo;) is established in the Cabinet in order to comprehensively and systematically promote measures concerning the promotion of the research and development and utilization of AI-related technology.\nArticle 20 (Affairs under Its Jurisdiction)\nThe Headquarters is to administer the following affairs:\n(i) matters concerning the preparation of the draft AI Basic Plan and the promotion of its implementation;\n(ii) in addition to the matter set forth in the preceding item, matters concerning the planning and drafting, and the comprehensive coordination, of important measures concerning the promotion of the research and development and utilization of AI-related technology.\nArticle 21 (Organization)\nThe Headquarters is organized with the Director-General of the AI Strategy Headquarters, the Vice-Directors-General of the AI Strategy Headquarters and the Members of the AI Strategy Headquarters.\nArticle 22 (Director-General of the AI Strategy Headquarters)\nThe head of the Headquarters is the Director-General of the AI Strategy Headquarters (hereinafter referred to as the \u0026ldquo;Director-General\u0026rdquo;), and the Prime Minister is appointed to that position.\n2 The Director-General is to supervise the affairs of the Headquarters and direct and supervise the staff of the Headquarters.\nArticle 23 (Vice-Directors-General of the AI Strategy Headquarters)\nVice-Directors-General of the AI Strategy Headquarters (referred to as the \u0026ldquo;Vice-Directors-General\u0026rdquo; in the following paragraph and in paragraph (2) of the following Article) are established in the Headquarters, and the Chief Cabinet Secretary and the Minister in Charge of AI Strategy [to verify] (meaning the Minister of State whose duties are to assist the Prime Minister, under the orders of the Prime Minister, with respect to the comprehensive and systematic promotion of the research and development and utilization of AI-related technology) are appointed to those positions.\n2 The Vice-Directors-General are to assist the Director-General in the performance of the Director-General\u0026rsquo;s duties.\nArticle 24 (Members of the AI Strategy Headquarters)\nMembers of the AI Strategy Headquarters (referred to as the \u0026ldquo;Members\u0026rdquo; in the following paragraph) are established in the Headquarters.\n2 All Ministers of State other than the Director-General and the Vice-Directors-General are appointed as the Members.\nArticle 25 (Submission of Materials and Other Cooperation)\nThe Headquarters may, when it finds it necessary for performing the affairs under its jurisdiction, request the submission of materials, the expression of opinions, explanations and other necessary cooperation from the heads of relevant administrative organs, local governments, incorporated administrative agencies (meaning incorporated administrative agencies provided for in Article 2, paragraph (1) of the Act on General Incorporated Administrative Agencies (Act No. 103 of 1999)) and local incorporated administrative agencies (meaning local incorporated administrative agencies provided for in Article 2, paragraph (1) of the Local Incorporated Administrative Agencies Act (Act No. 118 of 2003)), and from the representatives of special corporations [to verify] (meaning corporations directly established by law, or corporations established by a special act of establishment under a special law, to which the provisions of Article 4, paragraph (1), item (viii) of the Act for Establishment of the Ministry of Internal Affairs and Communications (Act No. 91 of 1999) apply).\n2 The Headquarters may, when it finds it particularly necessary for performing the affairs under its jurisdiction, request necessary cooperation also from persons other than those provided for in the preceding paragraph.\nArticle 26 (Affairs)\nAffairs relating to the Headquarters are handled in the Cabinet Office.\nArticle 27 (Competent Minister)\nWith respect to matters relating to the Headquarters, the competent minister [to verify] referred to in the Cabinet Act (Act No. 5 of 1947) is the Prime Minister.\nArticle 28 (Delegation to Cabinet Orders)\nBeyond what is provided for in this Act, necessary matters relating to the Headquarters are prescribed by Cabinet Order.\nSupplementary Provisions\nArticle 1 (Effective Date)\nThis Act comes into effect as from the day of its promulgation; provided, however, that the provisions of Chapter III and Chapter IV and of Articles 3 and 4 of the Supplementary Provisions come into effect as from the day specified by Cabinet Order within a period not exceeding three months from the day of promulgation.\nArticle 2 (Review)\nThe Government is to review the state of enforcement of this Act while taking into consideration changes in the socioeconomic situation, such as international trends concerning the various measures for the promotion of the research and development and utilization of AI-related technology, and is to take any necessary measures based on the results thereof when it finds it necessary.\n| Scope of the Supplementary Provisions | This page reproduces supplementary provisions Articles 1–2 (effective date; review). The official e-Gov data marks the supplementary provisions as an excerpt (抜粋), and the articles cross-referenced in the proviso to Supplementary Provision Article 1 (\u0026ldquo;Articles 3 and 4 of the Supplementary Provisions\u0026rdquo;) are not included in that data. The text is reproduced faithfully as published, with nothing added. |\n","permalink":"https://ai.intlaws.com/en/compliance/other/japan-ai-promotion-act/","summary":"Official Japanese text of the Act on Promotion of Research, Development and Utilization of AI-Related Technologies (Act No. 53 of 2025, promulgated 4 June 2025), 28 articles in four chapters plus 2 supplementary provisions. The Japanese text below is the authoritative version taken from the official e-Gov database; the English translation is prepared by this journal and is unofficial and for reference only.","title":"Japan's Act on Promotion of Research, Development and Utilization of AI-Related Technologies (Act No. 53 of 2025)"},{"content":" Version and sources (verifiable)\nItem Content Official title 인공지능 발전과 신뢰 기반 조성 등에 관한 기본법 Common name AI Framework Act (AI 기본법) Enactment Act No. 20676, promulgated 21 January 2025 Entry into force 22 January 2026 (one year after promulgation; the part on digital medical devices in Article 2 subparagraph 4(d) from 24 January 2026) Amendments ①Act No. 21065 (1 October 2025, Government Organization Act): in Article 38(1), \u0026ldquo;the Commissioner of the Statistics Korea\u0026rdquo; became \u0026ldquo;the Commissioner of the National Data Administration\u0026rdquo;; ②Act No. 21311 (20 January 2026): certain provisions enter into force 6 months after promulgation Current version In force as of 21 July 2026 (date on which the amending provisions of Act No. 21311 took effect) Structure 6 chapters, 2 sections, 43 articles (plus Article 17-2, 22-2 and 22-3 — 46 article units in total); three sets of addenda Official Korean text National Law Information Center (current version) ｜ Enactment version (Act No. 20676) Official English translation Korea Legislation Research Institute (KLRI) — the English text reproduced on this page is that official KLRI translation Chinese translation 中文译本(本网译校,非官方) Related instrument The Enforcement Decree (Presidential Decree) of this Act is a separate instrument, in force 20 August 2026; not reproduced here Scope Articles 1–43 and the addenda (Act No. 20676; the part of Act No. 21065 affecting this Act; Act No. 21311). Passages that the official page itself marks as omitted (provisions amending other statutes) are reproduced as-is, not completed Verification record 2026-09-22: article sequence 1–43 contiguous (46 article units); chapters and sections match the official text (6 chapters, 2 sections); addenda blocks 3, matching the official source Full text (official Korean text) 제1장 총칙\n제1조(목적) 이 법은 인공지능의 건전한 발전과 신뢰 기반 조성에 필요한 기본적인 사항을 규정함으로써 국민의 권익과 존엄성을 보호하고 국민의 삶의 질 향상과 국가경쟁력을 강화하는 데 이바지함을 목적으로 한다.\n제2조(정의) 이 법에서 사용하는 용어의 뜻은 다음과 같다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n“인공지능”이란 학습, 추론, 지각, 판단, 언어의 이해 등 인간이 가진 지적 능력을 전자적 방법으로 구현한 것을 말한다.\n“인공지능시스템”이란 다양한 수준의 자율성과 적응성을 가지고 주어진 목표를 위하여 실제 및 가상환경에 영향을 미치는 예측, 추천, 결정 등의 결과물을 추론하는 인공지능 기반 시스템을 말한다.\n“인공지능기술”이란 인공지능을 구현하기 위하여 필요한 하드웨어ㆍ소프트웨어 기술 또는 그 활용 기술을 말한다.\n“고영향 인공지능”이란 사람의 생명, 신체의 안전 및 기본권에 중대한 영향을 미치거나 위험을 초래할 우려가 있는 인공지능시스템으로서 다음 각 목의 어느 하나의 영역에서 활용되는 것을 말한다.\n가. 「에너지법」 제2조제1호에 따른 에너지의 공급\n나. 「먹는물관리법」 제3조제1호에 따른 먹는물의 생산 공정\n다. 「보건의료기본법」 제3조제1호에 따른 보건의료의 제공 및 이용체계의 구축ㆍ운영\n라. 「의료기기법」 제2조제1항에 따른 의료기기 및 「디지털의료제품법」 제2조제2호에 따른 디지털의료기기의 개발 및 이용\n마. 「원자력시설 등의 방호 및 방사능 방재 대책법」 제2조제1항제1호에 따른 핵물질과 같은 항 제2호에 따른 원자력시설의 안전한 관리 및 운영\n바. 범죄 수사나 체포 업무를 위한 생체인식정보(얼굴ㆍ지문ㆍ홍채 및 손바닥 정맥 등 개인을 식별할 수 있는 신체적ㆍ생리적ㆍ행동적 특징에 관한 개인정보를 말한다)의 분석ㆍ활용\n사. 채용, 대출 심사 등 개인의 권리ㆍ의무 관계에 중대한 영향을 미치는 판단 또는 평가\n아. 「교통안전법」 제2조제1호부터 제3호까지에 따른 교통수단, 교통시설, 교통체계의 주요한 작동 및 운영\n자. 공공서비스 제공에 필요한 자격 확인 및 결정 또는 비용징수 등 국민에게 영향을 미치는 국가, 지방자치단체, 「공공기관의 운영에 관한 법률」 제4조에 따른 공공기관 등(이하 “국가기관등”이라 한다)의 의사결정\n차. 「교육기본법」 제9조제1항에 따른 유아교육ㆍ초등교육 및 중등교육에서의 학생 평가\n카. 그 밖에 사람의 생명ㆍ신체의 안전 및 기본권 보호에 중대한 영향을 미치는 영역으로서 대통령령으로 정하는 영역\n“생성형 인공지능”이란 입력한 데이터(「데이터 산업진흥 및 이용촉진에 관한 기본법」 제2조제1호에 따른 데이터를 말한다. 이하 같다)의 구조와 특성을 모방하여 글, 소리, 그림, 영상, 그 밖의 다양한 결과물을 생성하는 인공지능시스템을 말한다.\n“인공지능산업”이란 인공지능 또는 인공지능기술을 활용한 제품(이하 “인공지능제품”이라 한다)을 개발ㆍ제조ㆍ생산 또는 유통하거나 이와 관련한 서비스(이하 “인공지능서비스”라 한다)를 제공하는 산업을 말한다.\n“인공지능사업자”란 인공지능산업과 관련된 사업을 하는 자로서 다음 각 목의 어느 하나에 해당하는 법인, 단체, 개인 및 국가기관등을 말한다.\n가. 인공지능개발사업자: 인공지능을 개발하여 제공하는 자\n나. 인공지능이용사업자: 가목의 사업자가 제공한 인공지능을 이용하여 인공지능제품 또는 인공지능서비스를 제공하는 자\n“이용자”란 인공지능제품 또는 인공지능서비스를 제공받는 자를 말한다.\n“영향받는 자”란 인공지능제품 또는 인공지능서비스에 의하여 자신의 생명, 신체의 안전 및 기본권에 중대한 영향을 받는 자를 말한다.\n“인공지능사회”란 인공지능을 통하여 산업ㆍ경제, 사회ㆍ문화, 행정 등 모든 분야에서 가치를 창출하고 발전을 이끌어가는 사회를 말한다.\n“인공지능윤리”란 인간의 존엄성에 대한 존중을 기초로 하여, 국민의 권익과 생명ㆍ재산을 보호할 수 있는 안전하고 신뢰할 수 있는 인공지능사회를 구현하기 위하여 인공지능의 개발, 제공 및 이용 등 모든 영역에서 사회구성원이 지켜야 할 윤리적 기준을 말한다.\n“학습용데이터”란 인공지능의 개발ㆍ활용 등에 사용되는 데이터를 말한다.\n제3조(기본원칙 및 국가 등의 책무) ① 인공지능기술과 인공지능산업은 안전성과 신뢰성을 제고하여 국민의 삶의 질을 향상시키는 방향으로 발전되어야 한다.\n② 영향받는 자는 인공지능의 최종결과 도출에 활용된 주요 기준 및 원리 등에 대하여 기술적ㆍ합리적으로 가능한 범위에서 명확하고 의미 있는 설명을 제공받을 수 있어야 한다.\n③ 국가 및 지방자치단체는 인공지능사업자의 창의정신을 존중하고, 안전한 인공지능 이용환경의 조성을 위하여 노력하여야 한다.\n④ 국가 및 지방자치단체는 인공지능이 가져오는 사회ㆍ경제ㆍ문화와 국민의 일상생활 등 모든 영역에서의 변화에 대응하여 모든 국민이 안정적으로 적응할 수 있도록 시책을 강구하여야 한다.\n⑤ 국가 및 지방자치단체는 인공지능 관련 정책의 개발과 수립 과정에 인공지능제품 또는 인공지능서비스의 이용에 어려움을 겪는 장애인ㆍ고령자 등 대통령령으로 정하는 취약계층(이하 “인공지능취약계층”이라 한다)의 참여를 보장하고 의견이 반영될 수 있도록 노력하여야 한다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n제4조(적용범위) ① 이 법은 국외에서 이루어진 행위라도 국내 시장 또는 이용자에게 영향을 미치는 경우에는 적용한다.\n② 이 법은 국방 또는 국가안보 목적으로만 개발ㆍ이용되는 인공지능으로서 대통령령으로 정하는 인공지능에 대하여는 적용하지 아니한다.\n제5조(다른 법률과의 관계) ① 인공지능, 인공지능기술, 인공지능산업 및 인공지능사회(이하 “인공지능등”이라 한다)에 관하여 다른 법률에 특별한 규정이 있는 경우를 제외하고는 이 법에서 정하는 바에 따른다.\n② 인공지능등에 관하여 다른 법률을 제정하거나 개정하는 경우에는 이 법의 목적에 부합하도록 하여야 한다.\n제2장 인공지능의 건전한 발전과 신뢰 기반 조성을 위한 추진체계\n제6조(인공지능 기본계획의 수립) ① 과학기술정보통신부장관은 관계 중앙행정기관의 장 및 지방자치단체의 장의 의견을 들어 3년마다 인공지능기술 및 인공지능산업의 진흥과 국가경쟁력 강화를 위하여 인공지능 기본계획(이하 “기본계획”이라 한다)을 제7조에 따른 국가인공지능전략위원회의 심의ㆍ의결을 거쳐 수립ㆍ변경 및 시행하여야 한다. 다만, 기본계획 중 대통령령으로 정하는 경미한 사항을 변경하는 경우에는 그러하지 아니하다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n② 기본계획에는 다음 각 호의 사항이 포함되어야 한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n인공지능등에 관한 정책의 기본 방향과 전략에 관한 사항\n인공지능산업의 체계적 육성을 위한 전문인력의 양성 및 인공지능 개발ㆍ활용 촉진 기반 조성 등에 관한 사항\n인공지능윤리의 확산 등 건전한 인공지능사회 구현을 위한 법ㆍ제도 및 문화에 관한 사항\n인공지능기술 개발 및 인공지능산업 진흥을 위한 재원의 확보와 투자의 방향 등에 관한 사항\n4의2. 「공공데이터의 제공 및 이용 활성화에 관한 법률」에 따른 공공데이터를 이용한 학습용데이터 생성, 공공데이터 제공 등의 범위와 기준 및 그 활성화에 관한 사항\n인공지능의 공정성ㆍ투명성ㆍ책임성ㆍ안전성ㆍ접근성 확보 등 신뢰 기반 조성에 관한 사항\n인공지능기술의 발전 방향 및 그에 따른 교육ㆍ노동ㆍ경제ㆍ문화 등 사회 각 영역의 변화와 대응에 관한 사항\n6의2. 인공지능기술의 이해 및 활용을 위한 교육의 지원 및 홍보에 관한 사항\n인공지능제품 또는 인공지능서비스에 대한 인공지능취약계층의 접근ㆍ이용을 보장하기 위한 사항\n그 밖에 인공지능기술 및 인공지능산업의 진흥과 국제협력 등 국가경쟁력 강화를 위하여 과학기술정보통신부장관이 필요하다고 인정하는 사항\n③ 과학기술정보통신부장관은 기본계획을 수립할 때에는 「지능정보화 기본법」 제6조제1항에 따른 종합계획 및 같은 법 제7조제1항에 따른 실행계획을 고려하여야 하며, 제2항제4호의2에 따른 학습용데이터 중 「공공데이터의 제공 및 이용 활성화에 관한 법률」에 따라 공공데이터를 학습용데이터로 제공하기 위한 사항에 대해서는 행정안전부장관과 협의하여 정한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n④ 과학기술정보통신부장관은 관계 중앙행정기관, 지방자치단체 및 공공기관(「지능정보화 기본법」 제2조제16호에 따른 공공기관을 말한다. 이하 같다)의 장에게 기본계획의 수립에 필요한 자료의 제출을 요청할 수 있다. 이 경우 자료의 제출을 요청받은 기관의 장은 특별한 사정이 없으면 이에 따라야 한다.\n⑤ 기본계획은 「지능정보화 기본법」 제13조제1항에 따른 인공지능 및 인공지능산업 분야의 부문별 추진계획으로 본다.\n⑥ 중앙행정기관의 장 및 지방자치단체의 장은 소관 주요 정책을 수립하고 집행할 때 기본계획을 고려하여야 한다.\n⑦ 기본계획의 수립ㆍ변경 및 시행에 필요한 사항은 대통령령으로 정한다.\n제7조(국가인공지능전략위원회) ① 인공지능 발전과 신뢰 기반 조성 등을 위한 주요 정책 등에 관한 사항을 심의ㆍ의결하기 위하여 대통령 소속으로 국가인공지능전략위원회(이하 “위원회”라 한다)를 둔다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n② 위원회는 위원장 1명과 3명 이내의 부위원장을 포함한 60명 이내의 위원으로 구성한다. 이 경우 제4항제4호에 따른 위원이 전체 위원의 과반수가 되어야 하고, 특정 성(性)으로만 위원회를 구성할 수 없다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n③ 위원회의 위원장은 대통령이 되고, 부위원장은 제4항제1호 또는 제4호에 해당하는 사람 중 대통령이 지명하는 사람이 된다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n④ 위원회의 위원은 다음 각 호의 사람이 된다.\n대통령령으로 정하는 관계 중앙행정기관의 장\n국가안보실의 인공지능에 관한 업무를 담당하는 차장\n대통령비서실의 인공지능에 관한 업무를 보좌하는 수석비서관\n인공지능 관련 전문지식과 경험이 풍부한 사람 중 대통령이 위촉하는 사람\n⑤ 위원회의 위원장은 위원회를 대표하고 위원회의 사무를 총괄한다.\n⑥ 위원회의 위원장은 필요한 경우 부위원장으로 하여금 그 직무를 대행하게 할 수 있다.\n⑦ 제4항제4호에 따른 위원의 임기는 2년으로 하되 한 차례에 한정하여 연임할 수 있다.\n⑧ 위원회에 간사위원 1명을 두며, 간사위원은 제4항제3호의 위원이 된다.\n⑨ 위원회의 위원은 그 직무상 알게 된 비밀을 타인에게 누설하거나 직무상 목적 외의 용도로 사용하여서는 아니 된다. 다만, 다른 법률에 특별한 규정이 있는 경우에는 그러하지 아니하다.\n⑩ 위원회의 위원장은 위원회의 회의를 소집하고 그 의장이 된다.\n⑪ 위원회의 회의는 위원 과반수의 출석으로 개의하고, 출석위원 과반수의 찬성으로 의결한다.\n⑫ 위원회의 업무 및 운영을 지원하기 위하여 위원회에 지원단을 둔다.\n⑬ 위원회는 이 법 시행일부터 5년간 존속한다.\n⑭ 그 밖에 위원회와 제12항에 따른 지원단의 구성 및 운영 등에 필요한 사항은 대통령령으로 정한다.\n[제목개정 2026. 1. 20.]\n제8조(위원회의 기능) ① 위원회는 다음 각 호의 사항을 심의ㆍ의결한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n기본계획의 수립ㆍ변경 및 시행의 점검ㆍ분석에 관한 사항\n인공지능등 관련 국가 비전 및 중장기 전략 수립에 관한 사항\n2의2. 인공지능 관련 정책 및 사업 등의 수립ㆍ조정 및 부처 간 조율에 관한 사항\n2의3. 인공지능 관련 정책 및 사업 등에 대한 이행점검 및 성과관리에 관한 사항\n인공지능등에 관한 연구개발 전략 수립에 관한 사항\n인공지능등에 관한 투자 방향 설정 및 투자 전략 수립에 관한 사항\n인공지능산업 발전과 경쟁력을 저해하는 규제의 발굴 및 개선에 관한 사항\n5의2. 인공지능등 관련 기술ㆍ인력ㆍ입지 등 제도 개선에 관한 사항\n5의3. 인공지능 및 인공지능기술 관련 전문인력의 양성 및 지원에 관한 사항\n인공지능 데이터센터(「지능정보화 기본법」 제40조제1항에 따른 데이터센터를 말한다. 이하 같다) 등 인프라 확충 방안에 관한 사항 6의2. 인공지능 발전을 위한 데이터(학습용데이터를 포함한다) 수집ㆍ관리 및 활용 촉진에 관한 사항\n제조업ㆍ서비스업 등 산업부문 및 공공부문에서의 인공지능 활용 촉진에 관한 사항\n인공지능 국제규범 마련 등 인공지능 관련 국제협력에 관한 사항\n제2항에 따른 권고 또는 의견의 표명에 관한 사항\n고영향 인공지능 규율에 관한 사항\n고영향 인공지능과 관련된 사회적 변화 양상과 정책적 대응에 관한 사항\n이 법 또는 다른 법률에서 위원회의 심의사항으로 정한 사항\n그 밖에 위원회의 위원장이 필요하다고 인정하여 위원회의 회의에 부치는 사항\n② 위원회는 국가기관등의 장 및 인공지능사업자 등에 대하여 인공지능의 올바른 사용과 인공지능윤리의 실천, 인공지능기술의 안전성ㆍ신뢰성에 관한 권고 또는 의견의 표명을 할 수 있다.\n③ 위원회가 국가기관등의 장에게 법령ㆍ제도의 개선 또는 실천방안의 수립 등에 대하여 제2항에 따른 권고 또는 의견의 표명을 한 때에는 해당 국가기관등의 장은 법령ㆍ제도 등의 개선방안과 실천방안 등을 수립하여야 한다.\n제9조(위원의 제척ㆍ기피 및 회피) ① 위원회의 위원은 업무의 공정성 확보를 위하여 다음 각 호의 어느 하나에 해당하는 경우에는 해당 안건의 심의ㆍ의결에서 제척(除斥)된다.\n위원 또는 위원이 속한 법인ㆍ단체 등과 직접적인 이해관계가 있는 경우\n위원의 가족(「민법」 제779조에 따른 가족을 말한다)이 이해관계인인 경우\n② 심의 대상 안건의 당사자(당사자가 법인ㆍ단체 등인 경우에는 그 임원 및 직원을 포함한다)는 위원에게 공정한 직무집행을 기대하기 어려운 사정이 있으면 위원회에 기피 신청을 할 수 있으며, 위원회는 기피 신청이 타당하다고 인정하면 의결로 기피를 결정하여야 한다.\n③ 위원은 제1항 또는 제2항의 사유에 해당하면 스스로 해당 안건의 심의를 회피하여야 한다.\n제10조(분과위원회 등) ① 위원회는 위원회의 업무를 전문 분야별로 수행하기 위하여 필요한 경우 분과위원회를 둘 수 있다.\n② 위원회는 인공지능등 관련 특정 현안을 논의하기 위하여 필요한 경우 특별위원회를 둘 수 있다.\n③ 위원회는 인공지능등 관련 사항을 전문적으로 검토하기 위하여 관계 전문가 등으로 구성된 자문단을 둘 수 있다.\n④ 위원회는 정부 내 인공지능 주요 시책의 수립과 사업의 효율적인 추진을 위하여 대통령령으로 정하는 인공지능책임관으로 구성되는 인공지능책임관협의회를 운영할 수 있다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n⑤ 그 밖에 분과위원회, 특별위원회, 자문단 및 인공지능책임관협의회의 구성ㆍ운영 등에 필요한 사항은 대통령령으로 정한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n제11조(인공지능정책센터) ① 과학기술정보통신부장관은 인공지능 관련 정책의 개발과 국제규범 정립ㆍ확산에 필요한 업무를 종합적으로 수행하기 위하여 인공지능정책센터(이하 “센터”라 한다)를 지정할 수 있다.\n② 센터는 다음 각 호의 사업을 수행한다.\n기본계획의 수립ㆍ시행에 필요한 전문기술의 지원\n인공지능과 관련한 시책의 개발 및 관련 사업의 기획ㆍ시행에 관한 전문기술의 지원\n인공지능의 활용 확산에 따른 사회, 경제, 문화 및 국민의 일상생활 등에 미치는 영향의 조사ㆍ분석\n인공지능 및 인공지능기술 관련 정책 개발을 지원하기 위한 동향 분석，사회ㆍ문화 변화와 미래예측 및 법ㆍ제도의 조사ㆍ연구\n다른 법령에서 센터의 업무로 정하거나 센터에 위탁한 사업\n그 밖에 국가기관등의 장이 위탁하는 사업\n③ 그 밖에 센터의 지정 등에 필요한 사항은 대통령령으로 정한다.\n제12조(인공지능안전연구소) ① 과학기술정보통신부장관은 인공지능과 관련하여 발생할 수 있는 위험으로부터 국민의 생명ㆍ신체ㆍ재산 등을 보호하고 인공지능사회의 신뢰 기반을 유지하기 위한 상태(이하 “인공지능안전”이라 한다)를 확보하기 위한 업무를 전문적이고 효율적으로 수행하기 위하여 인공지능안전연구소(이하 “안전연구소”라 한다)를 운영할 수 있다.\n② 안전연구소는 다음 각 호의 사업을 수행한다.\n인공지능안전 관련 위험 정의 및 분석\n인공지능안전 정책 연구\n인공지능안전 평가 기준ㆍ방법 연구\n인공지능안전 기술 및 표준화 연구\n인공지능안전 관련 국제교류ㆍ국제협력\n제32조에 따른 인공지능시스템의 안전성 확보에 관한 지원\n그 밖에 인공지능안전에 관한 사업으로서 대통령령으로 정하는 사업\n③ 정부는 안전연구소의 운영과 사업 추진 등에 필요한 경비를 예산의 범위에서 출연하거나 지원할 수 있다.\n④ 그 밖에 안전연구소의 운영 등에 필요한 사항은 대통령령으로 정한다.\n제3장 인공지능기술 개발 및 산업 육성\n제1절 인공지능산업 기반 조성\n제13조(인공지능기술 개발 및 안전한 이용 지원) ① 정부는 인공지능기술 개발 활성화를 위하여 다음 각 호의 사업을 지원할 수 있다.\n국내외 인공지능기술 동향ㆍ수준 및 관련 제도의 조사\n인공지능기술의 연구ㆍ개발, 시험 및 평가 또는 개발된 기술의 활용\n인공지능기술 확산, 인공지능기술 협력ㆍ이전 등 기술의 실용화 및 사업화 지원\n인공지능기술의 구현을 위한 정보의 원활한 유통 및 산학협력\n그 밖에 인공지능기술의 개발 및 연구ㆍ조사와 관련하여 대통령령으로 정하는 사업\n② 정부는 인공지능기술의 안전하고 편리한 이용을 위하여 다음 각 호의 사업을 지원할 수 있다.\n「지능정보화 기본법」 제60조제1항 각 호의 사항을 인공지능기술로 구현하는 연구개발 사업\n「지능정보화 기본법」 제60조제3항에 따른 비상정지 기능을 인공지능제품 또는 인공지능서비스에서 구현하기 위한 기술 연구 지원 및 해당 기술의 확산을 위한 사업\n인공지능기술의 개발에 있어서 「지능정보화 기본법」 제61조제2항에 따른 사생활등의 보호에 적합한 설계 기준 및 기술의 연구개발 및 보급 사업\n인공지능기술의 「지능정보화 기본법」 제56조제1항에 따른 사회적 영향평가의 실시와 적용을 위한 연구개발 사업\n인공지능이 인간의 존엄성 및 기본권을 존중하는 방향으로 개발ㆍ이용될 수 있도록 하는 기술 또는 기준 등의 연구개발 및 보급 사업\n인공지능의 안전한 개발과 이용을 위한 인식개선, 올바른 이용방법과 안전 환경 조성을 위한 교육 및 홍보 사업\n그 밖에 인공지능의 개발과 이용에 있어서 국민의 기본권, 신체와 재산을 보호하기 위하여 필요한 사업\n③ 정부는 제2항에 따른 사업의 결과를 누구든지 손쉽게 이용할 수 있도록 공개하고 보급하여야 한다. 이 경우 기술을 개발한 자를 보호하기 위하여 필요한 경우에는 보호기간을 정하여 기술사용료를 받을 수 있게 하거나 그 밖의 방법으로 보호할 수 있다.\n제14조(인공지능기술의 표준화) ① 정부는 인공지능기술, 학습용데이터, 인공지능의 안전성ㆍ신뢰성 등과 관련된 표준화를 위하여 다음 각 호의 사업을 추진할 수 있다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n인공지능기술 관련 표준의 제정ㆍ개정 및 폐지와 그 보급\n인공지능기술 관련 국내외 표준의 조사ㆍ연구개발\n그 밖에 인공지능기술 관련 표준화 사업\n② 정부는 제1항제1호에 따라 제정된 표준을 고시하여 관련 사업자에게 그 준수를 권고할 수 있다.\n③ 정부는 민간 부문에서 추진하는 인공지능기술 관련 표준화 사업에 필요한 지원을 할 수 있다.\n④ 정부는 인공지능기술 표준과 관련된 국제표준기구 또는 국제표준기관과 협력체계를 유지ㆍ강화하여야 한다.\n⑤ 그 밖에 제1항 및 제3항에 따른 표준화 사업의 추진 및 지원 등과 관련하여 필요한 사항은 대통령령으로 정한다.\n제15조(인공지능 학습용데이터 관련 시책의 수립 등) ① 과학기술정보통신부장관은 관계 중앙행정기관의 장과 협의하여 학습용데이터의 생산ㆍ수집ㆍ관리ㆍ유통ㆍ활용 촉진 및 품질수준 확보 등을 위하여 필요한 시책을 추진하여야 한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n② 정부는 학습용데이터의 생산ㆍ수집ㆍ관리ㆍ유통 및 활용 등에 관한 시책을 효율적으로 추진하기 위하여 지원대상사업을 선정하고 예산의 범위에서 지원할 수 있다.\n③ 정부는 학습용데이터의 생산ㆍ수집ㆍ관리ㆍ유통 및 활용의 활성화 등을 위하여 다양한 학습용데이터를 제작ㆍ생산하여 제공하는 사업(이하 “학습용데이터 구축사업”이라 한다)을 시행할 수 있다.\n④ 과학기술정보통신부장관은 학습용데이터 구축사업의 효율적 수행을 위하여 학습용데이터를 통합적으로 제공ㆍ관리할 수 있는 시스템(이하 “통합제공시스템”이라 한다)을 구축ㆍ관리하고 민간이 자유롭게 이용할 수 있도록 제공하여야 한다.\n⑤ 과학기술정보통신부장관은 통합제공시스템을 이용하는 자에 대하여 비용을 징수할 수 있다.\n⑥ 그 밖에 제2항에 따른 지원대상사업의 선정 및 지원, 학습용데이터 구축사업의 시행, 통합제공시스템의 구축ㆍ관리 및 제5항에 따른 비용의 징수 등에 필요한 사항은 대통령령으로 정한다.\n제2절 인공지능기술 개발 및 인공지능산업 활성화\n제16조(인공지능기술 도입ㆍ활용 시책 등) ① 국가 및 지방자치단체는 기업 및 공공기관의 인공지능기술 도입 촉진 및 활용 확산을 위한 시책을 수립ㆍ시행하여야 한다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n② 국가 및 지방자치단체는 기업 및 공공기관의 인공지능기술 도입 촉진 및 활용 확산을 위하여 필요한 경우에는 다음 각 호의 지원을 할 수 있다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n인공지능기술, 인공지능제품 또는 인공지능서비스의 개발 지원 및 연구ㆍ개발 성과의 확산\n인공지능기술을 도입ㆍ활용하고자 하는 기업 및 공공기관에 대한 컨설팅 지원\n2의2. 공공기관이 보유ㆍ관리하고 있는 데이터를 학습용데이터로 생성ㆍ제공하고 적절한 품질수준을 확보하기 위하여 필요한 지원\n「중소기업기본법」 제2조제1항에 따른 중소기업, 「벤처기업육성에 관한 특별법」 제2조제1항에 따른 벤처기업 및 「소상공인기본법」 제2조제1항에 따른 소상공인(이하 “중소기업등”이라 한다)의 임직원에 대한 인공지능기술 도입 및 활용 관련 교육 지원\n중소기업등의 인공지능기술 도입 및 활용에 사용되는 자금의 지원\n그 밖에 기업 및 공공기관의 인공지능기술 도입 및 활용을 촉진하기 위하여 대통령령으로 정하는 사항\n③ 국가기관등은 업무 수행에 필요한 제품 또는 서비스를 구매하거나 용역을 발주하려는 경우 대통령령으로 정하는 인공지능제품 또는 인공지능서비스를 우선적으로 고려하여야 한다. 다만, 업무 특성상 인공지능기술의 활용이 적합하지 아니한 경우에는 그러하지 아니하다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n④ 제3항에 따른 인공지능제품 또는 인공지능서비스의 구매 또는 사용으로 국가기관등에 손해가 발생한 경우에도 그 구매 또는 사용 업무를 담당한 자는 해당 기관의 손해에 대하여 배상할 책임이 없다. 다만, 해당 업무 담당자의 고의 또는 중대한 과실로 손해가 발생한 경우에는 그러하지 아니하다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n⑤ 제2항에 따른 지원에 필요한 사항은 대통령령으로 정한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n[제목개정 2026. 1. 20.]\n제17조(중소기업등을 위한 특별지원) ① 이 법에 따라 인공지능기술 및 인공지능산업과 관련한 각종 지원시책을 시행할 때에는 중소기업등을 우선 고려하여야 한다.\n② 정부는 인공지능산업에 대한 중소기업등의 참여 활성화를 위하여 노력하여야 하며, 이와 관련한 사항을 기본계획에 반영하여야 한다.\n③ 과학기술정보통신부장관은 인공지능의 안전성 및 신뢰성 확보를 위하여 중소기업등의 제34조에 따른 조치 이행 및 제35조에 따른 영향평가를 지원할 수 있다.\n제17조의2(인공지능제품 및 인공지능서비스 이용비용의 지원) ① 국가와 지방자치단체는 경제적 여건으로 인하여 인공지능제품 및 인공지능서비스를 이용하기 어려운 사람에 대하여 예산의 범위에서 그 비용의 전부 또는 일부를 지원할 수 있다.\n② 제1항에 따른 비용 지원의 요건과 대상 등에 필요한 사항은 대통령령으로 정한다.\n[본조신설 2026. 1. 20.]\n제18조(창업의 활성화 등) ① 정부는 인공지능산업 분야의 창업을 활성화하기 위하여 다음 각 호의 사업을 추진할 수 있다.\n인공지능산업 분야의 창업자 발굴 및 육성ㆍ지원 등에 관한 사업\n인공지능산업 분야의 창업 활성화를 위한 교육ㆍ훈련에 관한 사업\n제21조에 따른 전문인력의 우수 인공지능기술에 대한 사업화 지원\n인공지능기술의 가치평가 및 창업자금의 금융지원\n인공지능 관련 연구 및 기술개발 성과의 제공\n인공지능산업 분야의 창업을 지원하는 기관ㆍ단체의 육성\n그 밖에 인공지능산업 분야의 창업 활성화를 위하여 필요한 사업\n② 지방자치단체는 인공지능산업 분야의 창업을 지원하는 공공기관 등 공공단체에 출연하거나 출자할 수 있다.\n③ 중앙행정기관의 장은 인공지능산업 분야의 창업을 활성화하기 위하여 중소벤처기업부장관과 협의하여 「벤처투자 촉진에 관한 법률」 제70조에 따른 벤처투자모태조합을 활용한 지원을 할 수 있다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n④ 제3항에 따른 지원을 위한 자금은 다음 각 호의 재원으로 조성한다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n국가, 지방자치단체 또는 공공기관의 출자금\n국가, 지방자치단체 또는 공공기관 외의 자로서 인공지능산업과 관련하여 벤처투자모태조합에 출자를 희망하는 자의 출자금\n그 밖의 부대수입\n⑤ 제3항에 따른 벤처투자모태조합에의 출자에 필요한 사항은 대통령령으로 정한다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n[제목개정 2026. 1. 20.]\n제19조(인공지능 융합의 촉진) ① 정부는 인공지능산업과 그 밖의 산업 간 융합을 촉진하고 전 분야에서 인공지능 활용을 활성화하기 위하여 필요한 시책을 수립하여 추진하여야 한다.\n② 정부는 인공지능 융합 제품 및 서비스의 개발을 지원하기 위하여 필요한 경우에는 「국가연구개발혁신법」에 따른 국가연구개발사업에 인공지능 융합 제품 및 서비스에 관한 연구개발과제를 우선적으로 반영하여 추진할 수 있다.\n③ 정부는 제2항에 따라 개발된 인공지능 융합 제품 및 서비스에 대하여는 「정보통신 진흥 및 융합 활성화 등에 관한 특별법」 제37조에 따른 임시허가 및 같은 법 제38조의2에 따른 실증을 위한 규제특례가 원활히 시행될 수 있도록 적극 지원하여야 한다.\n제20조(제도개선 등) ① 정부는 인공지능산업의 발전과 신뢰 기반 조성을 위하여 법령의 정비 등 관련 제도를 개선할 수 있도록 노력하여야 한다.\n② 정부는 제1항에 따른 제도개선을 촉진하기 위하여 관련 법ㆍ제도의 연구 및 사회 각계의 의견수렴 등에 필요한 행정적ㆍ재정적 지원을 할 수 있다.\n제21조(전문인력의 확보) ① 과학기술정보통신부장관은 인공지능기술의 개발 및 인공지능산업의 발전을 위하여 「지능정보화 기본법」 제23조제1항에 따른 시책에 따라 인공지능 및 인공지능기술 관련 전문인력을 양성하고 지원할 수 있도록 다음 각 호의 사업을 추진할 수 있다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n전문인력의 직무역량 강화 및 경력개발을 위한 교육훈련 프로그램 개발ㆍ활용\n전문인력의 취업 지원 및 신규 인력유입 활성화 등 고용 촉진\n전문인력의 공직 진출 기회 확대 등 진출 다변화 촉진\n전문인력의 국내외 연수 지원 및 국제교류 활성화\n전문인력의 근로환경 개선과 처우 증진 등 복지 향상\n그 밖에 인공지능 및 인공지능기술 관련 전문인력의 양성ㆍ지원을 위한 사업\n② 정부는 인공지능 및 인공지능기술 관련 해외 전문인력의 확보를 위하여 다음 각 호의 시책을 추진할 수 있다.\n인공지능 및 인공지능기술 관련 해외 대학ㆍ연구기관ㆍ기업 등의 전문인력에 관한 조사ㆍ분석\n해외 전문인력의 유치를 위한 국제네트워크 구축\n해외 전문인력의 국내 취업 지원\n국내 인공지능 연구기관의 해외진출 및 해외 인공지능 연구기관의 국내 유치 지원\n인공지능 및 인공지능기술 관련 국제기구 및 국제행사의 국내 유치 지원\n그 밖에 해외 전문인력의 확보를 위하여 필요한 사항\n제22조(국제협력 및 해외시장 진출의 지원) ① 정부는 인공지능과 관련한 국제적 동향을 파악하고 국제협력을 추진하여야 한다.\n② 정부는 인공지능산업의 경쟁력 강화와 해외시장 진출을 촉진하기 위하여 인공지능산업에 종사하는 개인ㆍ기업 또는 단체 등에 대하여 다음 각 호의 지원을 할 수 있다.\n인공지능산업 관련 정보ㆍ기술ㆍ인력의 국제교류\n인공지능산업 관련 해외진출에 관한 정보의 수집ㆍ분석 및 제공\n국가 간 인공지능기술, 인공지능제품 또는 인공지능서비스의 공동 연구ㆍ개발 및 국제표준화\n인공지능산업 관련 외국자본의 투자유치\n인공지능등 관련 해외 전문 학회 및 전시회 참가 등 홍보 및 해외 마케팅\n인공지능제품 또는 인공지능서비스의 수출에 필요한 판매체계ㆍ유통체계 및 협력체계 등의 구축\n인공지능윤리에 관한 국제적 동향 파악 및 국제협력\n그 밖에 인공지능산업의 경쟁력 강화와 해외시장 진출 촉진을 위하여 필요한 사항\n③ 정부는 제2항 각 호에 따른 지원을 효율적으로 수행하기 위하여 대통령령으로 정하는 바에 따라 공공기관 또는 그 밖의 단체에 이를 위탁하거나 대행하게 할 수 있으며, 이에 필요한 비용을 보조할 수 있다.\n제22조의2(인공지능연구소의 설립 및 지원 등) ① 대학, 기업 등 대통령령으로 정하는 자는 단독으로 또는 공동으로 인공지능의 개발ㆍ활용에 관한 연구소(이하 “인공지능연구소”라 한다)를 설립ㆍ운영할 수 있다.\n② 제1항에 따라 대학, 기업 등 대통령령으로 정하는 자가 인공지능연구소를 설립하려는 경우에는 다음 각 호의 요건을 갖추고 과학기술정보통신부장관의 허가를 받아야 한다.\n3명 이상의 발기인(發起人)이 있을 것\n제5항의 사업을 수행할 수 있는 인력ㆍ시설 등의 능력을 보유하고 있을 것\n그 밖에 인공지능연구소의 설립ㆍ운영을 위하여 필요한 것으로서 대통령령으로 정하는 요건을 갖출 것\n③ 인공지능연구소에 소장을 둔다. 인공지능연구소의 소장은 인공지능연구소를 대표하고 인공지능연구소의 업무를 총괄한다.\n④ 인공지능연구소의 정관에는 다음 각 호의 사항이 포함되어야 한다.\n목적\n명칭\n사무소의 소재지\n자산에 관한 규정\n소장의 자격과 임면에 관한 규정\n소장의 책임과 권한에 관한 규정\n⑤ 인공지능연구소는 업종별ㆍ기능별로 다음 각 호의 사업을 수행한다.\n인공지능기술 연구개발\n인공지능기술과 다른 기술 및 학제 간 융합에 관한 연구개발\n인공지능기술 연구개발 성과 관리ㆍ이전ㆍ활용 및 사업화\n인공지능기술 연구개발 전문인력 양성\n인공지능기술 연구개발 관련 국제교류ㆍ국제협력\n그 밖에 인공지능기술 연구개발에 필요한 사항\n⑥ 정부와 지방자치단체는 예산의 범위에서 인공지능연구소의 운영과 사업 추진 등에 필요한 경비를 지원할 수 있다.\n⑦ 인공지능연구소는 운영에 필요한 재원을 조성하기 위하여 정부ㆍ지방자치단체 외의 자로부터 보조금 또는 기부금 등을 받거나, 정관으로 정하는 바에 따라 수익사업을 할 수 있다.\n⑧ 인공지능연구소의 소장은 인공지능기술의 연구개발 등을 위하여 필요한 경우 제1항에 따른 대학, 기업 등 대통령령으로 정하는 자와 협의하여 임직원을 파견받거나 겸임근무하게 하여 인공지능연구소의 연구 등을 담당하게 할 수 있으며, 파견받은 임직원의 소속 기관에 필요한 지원을 할 수 있다. 이 경우 필요하면 과학기술정보통신부장관에게 협의를 위한 지원을 요청할 수 있다.\n⑨ 인공지능연구소에 관하여 이 법에서 정한 것을 제외하고는 「민법」 중 재단법인에 관한 규정을 준용한다.\n⑩ 과학기술정보통신부장관은 인공지능연구소가 다음 각 호의 어느 하나에 해당하는 경우 시정을 명하거나 그 설립허가를 취소할 수 있다. 다만, 제1호 또는 제2호에 해당하는 경우 그 허가를 취소하여야 한다.\n거짓이나 그 밖의 부정한 방법으로 설립허가를 받은 경우\n목적 달성이 불가능하게 된 경우\n제2항에 따른 허가 요건을 충족하지 못하게 된 경우\n목적사업 외의 사업을 한 경우\n법령, 정관 또는 이 법에 따른 명령을 위반한 경우\n공익을 해치는 행위를 한 경우\n정당한 사유 없이 설립허가를 받은 날부터 6개월 이내에 목적사업을 시작하지 아니하거나 1년 이상 사업실적이 없는 경우\n⑪ 과학기술정보통신부장관은 제10항에 따라 인공지능연구소의 설립허가를 취소하려는 경우에는 청문을 하여야 한다.\n⑫ 그 밖에 인공지능연구소의 설립 절차, 운영, 지원 등에 필요한 사항은 대통령령으로 정한다.\n[본조신설 2026. 1. 20.]\n제22조의3(인공지능기술 확보를 위한 연구기관의 설립ㆍ운영) 과학기술정보통신부장관은 혁신적인 인공지능기술의 확보를 위하여 필요한 경우 대통령령으로 정하는 바에 따라 인공지능의 개발ㆍ활용 등에 관한 연구를 수행하는 기관을 설립ㆍ운영할 수 있다.\n[본조신설 2026. 1. 20.]\n제23조(인공지능집적단지 지정 등) ① 국가 및 지방자치단체는 인공지능산업의 진흥과 인공지능 개발ㆍ활용의 경쟁력 강화를 위하여 인공지능 및 인공지능기술의 연구ㆍ개발을 수행하는 기업, 기관이나 단체의 기능적ㆍ물리적ㆍ지역적 집적화를 추진할 수 있다.\n② 국가 및 지방자치단체는 제1항에 따른 집적화를 위하여 필요한 경우에는 대통령령으로 정하는 바에 따라 인공지능집적단지(이하 “인공지능집적단지”라 한다)를 지정하여 행정적ㆍ재정적ㆍ기술적 지원을 할 수 있다.\n③ 국가 및 지방자치단체는 다음 각 호의 어느 하나에 해당하는 경우 인공지능집적단지의 지정을 취소할 수 있다. 다만, 제1호에 해당하는 경우에는 그 지정을 취소하여야 한다.\n거짓이나 그 밖의 부정한 방법으로 지정을 받은 경우\n인공지능집적단지 지정의 목적을 달성하기 어렵다고 인공지능집적단지를 지정한 국가 또는 지방자치단체의 장이 인정하는 경우\n④ 정부는 제1항에 따른 집적화를 지역에 효과적으로 정착시키기 위하여 관련 업무를 종합적으로 지원하는 전담기관을 설치하거나 지정할 수 있다.\n⑤ 정부는 제4항에 따른 전담기관의 운영 및 사업 수행에 필요한 비용의 전부 또는 일부를 출연하거나 보조할 수 있다.\n⑥ 그 밖에 인공지능집적단지의 지정 및 지정취소와 제4항에 따른 전담기관의 설치 또는 지정 등에 필요한 사항은 대통령령으로 정한다.\n제24조(인공지능 실증기반 조성 등) ① 국가 및 지방자치단체는 인공지능사업자가 개발하거나 이전받은 기술의 실증, 성능시험, 제30조에 따른 검ㆍ인증등(이하 “실증시험등”이라 한다)을 지원하기 위하여 시험, 평가 등에 필요한 시설ㆍ장비ㆍ설비 등(이하 “실증기반등”이라 한다)을 구축ㆍ운영할 수 있다.\n② 국가 및 지방자치단체는 실증시험등을 촉진하기 위하여 대통령령으로 정하는 기관이 보유하고 있는 실증기반등을 인공지능사업자에게 개방할 수 있다.\n③ 그 밖에 실증기반등의 구축ㆍ운영 및 개방 등에 필요한 사항은 대통령령으로 정한다.\n제25조(인공지능 데이터센터 관련 시책의 추진 등) ① 정부는 인공지능의 개발ㆍ활용 등에 이용되는 데이터센터(이하 “인공지능 데이터센터”라 한다)의 구축 및 운영을 활성화하기 위하여 필요한 시책을 추진하여야 한다.\n② 정부는 제1항에 따른 시책을 추진하기 위하여 다음 각 호의 업무를 수행할 수 있다.\n인공지능 데이터센터의 구축 및 운영에 필요한 행정적ㆍ재정적 지원\n중소기업, 연구기관 등의 인공지능 데이터센터 이용 지원\n인공지능 데이터센터 등 인공지능 관련 인프라 시설의 지역별 균형 발전을 위한 지원\n제26조(한국인공지능진흥협회의 설립) ① 인공지능등과 관련한 연구 및 업무에 종사하는 자는 인공지능의 개발ㆍ이용 촉진, 인공지능산업 및 인공지능기술의 진흥, 인공지능등에 대한 교육ㆍ홍보 등을 위하여 대통령령으로 정하는 바에 따라 과학기술정보통신부장관의 인가를 받아 한국인공지능진흥협회(이하 “협회”라 한다)를 설립하거나 협회로 지정받을 수 있다.\n② 협회는 법인으로 한다.\n③ 협회는 다음 각 호의 업무를 수행한다.\n인공지능기술, 인공지능제품 또는 인공지능서비스의 이용 촉진 및 확산\n인공지능등에 대한 현황 및 관련 통계 조사\n인공지능사업자를 위한 공동이용시설의 설치ㆍ운영 및 전문인력 양성을 위한 교육 등\n인공지능사업자 및 인공지능 관련 전문인력의 해외진출 지원\n안전하고 신뢰할 수 있는 인공지능의 개발ㆍ활용을 위한 교육 및 홍보\n이 법 또는 다른 법률에 따라 협회가 위탁받은 사업\n그 밖에 협회의 설립목적을 달성하는 데 필요한 사업으로서 정관으로 정하는 사업\n④ 국가 및 지방자치단체는 인공지능산업의 발전과 신뢰 기반 조성을 위하여 필요한 경우 예산의 범위에서 협회의 사업수행에 필요한 자금을 지원하거나 운영에 필요한 경비를 보조할 수 있다.\n⑤ 협회 회원의 자격과 임원에 관한 사항, 협회의 업무 등은 정관으로 정하며, 그 밖에 정관에 포함하여야 할 사항은 대통령령으로 정한다.\n⑥ 과학기술정보통신부장관은 제1항에 따른 인가를 한 때에는 그 사실을 공고하여야 한다.\n⑦ 협회에 관하여 이 법에 규정된 것을 제외하고는 「민법」 중 사단법인에 관한 규정을 준용한다.\n제4장 인공지능윤리 및 신뢰성 확보\n제27조(인공지능 윤리원칙 등) ① 정부는 인공지능윤리의 확산을 위하여 다음 각 호의 사항을 포함하는 인공지능 윤리원칙(이하 “윤리원칙”이라 한다)을 대통령령으로 정하는 바에 따라 제정ㆍ공표할 수 있다.\n인공지능의 개발ㆍ활용 등의 과정에서 사람의 생명과 신체, 정신적 건강 등에 해가 되지 아니하도록 하는 안전성과 신뢰성에 관한 사항\n인공지능기술이 적용된 제품ㆍ서비스 등을 모든 사람이 자유롭고 편리하게 이용할 수 있는 접근성에 관한 사항\n사람의 삶과 번영에의 공헌을 위한 인공지능의 개발ㆍ활용 등에 관한 사항\n② 과학기술정보통신부장관은 사회 각계의 의견을 수렴하여 윤리원칙이 인공지능의 개발ㆍ활용 등에 관여하는 모든 사람에 의하여 실현될 수 있도록 실천방안을 수립하고 이를 공개 및 홍보ㆍ교육하여야 한다.\n③ 중앙행정기관 또는 지방자치단체의 장이 인공지능윤리기준(그 명칭 및 형태를 불문하고 인공지능윤리에 관한 법령, 기준, 지침, 가이드라인 등을 말한다)을 제정하거나 개정하는 경우 과학기술정보통신부장관은 윤리원칙 및 제2항에 따른 실천방안과의 연계성ㆍ정합성 등에 관한 권고 또는 의견의 표명을 할 수 있다.\n제28조(민간자율인공지능윤리위원회의 설치 등) ① 다음 각 호의 기관 또는 단체는 윤리원칙을 준수하기 위하여 민간자율인공지능윤리위원회(이하 “민간자율위원회”라 한다)를 둘 수 있다.\n인공지능기술 연구 및 개발을 수행하는 사람이 소속된 교육기관ㆍ연구기관\n인공지능사업자\n그 밖에 대통령령으로 정하는 인공지능기술 관련 기관\n② 민간자율위원회는 다음 각 호의 업무를 자율적으로 수행한다.\n인공지능기술 연구ㆍ개발ㆍ활용에 있어서 윤리원칙의 준수 여부 확인\n인공지능기술 연구ㆍ개발ㆍ활용의 안전 및 인권침해 등에 관한 조사ㆍ연구\n인공지능기술 연구ㆍ개발ㆍ활용의 절차 및 결과에 관한 조사ㆍ감독\n해당 기관 또는 단체의 연구자 및 종사자에 대한 윤리원칙 교육\n인공지능기술 연구ㆍ개발ㆍ활용에 적합한 분야별 인공지능윤리 지침 마련\n그 밖에 윤리원칙 구현에 필요한 업무\n③ 민간자율위원회의 구성ㆍ운영 등에 필요한 사항은 해당 기관 또는 단체 등에서 자율적으로 정한다. 다만, 그 구성을 특정한 성(性)으로만 할 수 없으며, 사회적ㆍ윤리적 타당성을 평가할 수 있는 경험과 지식을 갖춘 사람 및 그 기관 또는 단체에 종사하지 아니하는 사람을 각각 포함하여야 한다.\n④ 과학기술정보통신부장관은 민간자율위원회의 공정하고 중립적인 구성ㆍ운영을 위하여 표준 지침 등을 마련하여 보급할 수 있다.\n제29조(인공지능 신뢰 기반 조성을 위한 시책의 마련) 정부는 인공지능이 국민의 생활에 미치는 잠재적 위험을 최소화하고 안전한 인공지능의 이용을 위한 신뢰 기반을 조성하기 위하여 다음 각 호의 시책을 마련하여야 한다.\n안전하고 신뢰할 수 있는 인공지능 이용환경 조성\n인공지능의 이용이 국민의 일상생활에 미치는 영향 등에 관한 전망과 예측 및 관련 법령ㆍ제도의 정비\n인공지능의 안전성ㆍ신뢰성 확보를 위한 안전기술 및 인증기술의 개발 및 확산 지원\n안전하고 신뢰할 수 있는 인공지능사회 구현 및 인공지능윤리 실천을 위한 교육ㆍ홍보\n인공지능사업자의 안전성ㆍ신뢰성 관련 자율적인 규약의 제정ㆍ시행 지원\n인공지능사업자, 이용자 등으로 구성된 인공지능 관련 단체(이하 “단체등”이라 한다)의 인공지능의 안전성ㆍ신뢰성 증진을 위한 자율적인 협력, 윤리지침 제정 등 민간 활동의 지원 및 확산\n그 밖에 인공지능의 안전성ㆍ신뢰성 확보를 위하여 대통령령으로 정하는 사항\n제30조(인공지능 안전성ㆍ신뢰성 검ㆍ인증등 지원) ① 과학기술정보통신부장관은 단체등이 인공지능의 안전성ㆍ신뢰성 확보를 위하여 자율적으로 추진하는 검증ㆍ인증 활동(이하 “검ㆍ인증등”이라 한다)을 지원하기 위하여 다음 각 호의 사업을 추진할 수 있다.\n인공지능의 개발에 관한 가이드라인 보급\n검ㆍ인증등에 관한 연구의 지원\n검ㆍ인증등에 이용되는 장비 및 시스템의 구축ㆍ운영 지원\n검ㆍ인증등에 필요한 전문인력의 양성 지원\n그 밖에 검ㆍ인증등을 지원하기 위하여 대통령령으로 정하는 사항\n② 과학기술정보통신부장관은 검ㆍ인증등을 받고자 하는 중소기업등에 대하여 대통령령으로 정하는 바에 따라 관련 정보를 제공하거나 행정적ㆍ재정적 지원을 할 수 있다.\n③ 인공지능사업자가 고영향 인공지능을 제공하는 경우 사전에 검ㆍ인증등을 받도록 노력하여야 한다.\n④ 국가기관등이 고영향 인공지능을 이용하려는 경우에는 검ㆍ인증등을 받은 인공지능에 기반한 제품 또는 서비스를 우선적으로 고려하여야 한다.\n제31조(인공지능 투명성 확보 의무) ① 인공지능사업자는 고영향 인공지능이나 생성형 인공지능을 이용한 제품 또는 서비스를 제공하려는 경우 제품 또는 서비스가 해당 인공지능에 기반하여 운용된다는 사실을 이용자에게 사전에 고지하여야 한다.\n② 인공지능사업자는 생성형 인공지능 또는 이를 이용한 제품 또는 서비스를 제공하는 경우 그 결과물이 생성형 인공지능에 의하여 생성되었다는 사실을 표시하여야 한다.\n③ 인공지능사업자는 인공지능시스템을 이용하여 실제와 구분하기 어려운 가상의 음향, 이미지 또는 영상 등의 결과물을 제공하는 경우 해당 결과물이 인공지능시스템에 의하여 생성되었다는 사실을 이용자가 명확하게 인식할 수 있는 방식으로 고지 또는 표시하여야 한다. 이 경우 해당 결과물이 예술적ㆍ창의적 표현물에 해당하거나 그 일부를 구성하는 경우에는 전시 또는 향유 등을 저해하지 아니하는 방식으로 고지 또는 표시할 수 있다.\n④ 그 밖에 제1항에 따른 사전고지, 제2항에 따른 표시, 제3항에 따른 고지 또는 표시의 방법 및 그 예외 등에 관하여 필요한 사항은 대통령령으로 정한다.\n제32조(인공지능 안전성 확보 의무) ① 인공지능사업자는 학습에 사용된 누적 연산량이 대통령령으로 정하는 기준 이상인 인공지능시스템의 안전성을 확보하기 위하여 다음 각 호의 사항을 이행하여야 한다.\n인공지능 수명주기 전반에 걸친 위험의 식별ㆍ평가 및 완화\n인공지능 관련 안전사고를 모니터링하고 대응하는 위험관리체계 구축\n② 인공지능사업자는 제1항 각 호에 따른 사항의 이행 결과를 과학기술정보통신부장관에게 제출하여야 한다.\n③ 과학기술정보통신부장관은 제1항 각 호에 따른 사항의 구체적인 이행 방식 및 제2항에 따른 결과 제출 등에 필요한 사항을 정하여 고시하여야 한다.\n제33조(고영향 인공지능의 확인) ① 인공지능사업자는 인공지능 또는 이를 이용한 제품ㆍ서비스를 제공하는 경우 그 인공지능이 고영향 인공지능에 해당하는지에 대하여 사전에 검토하여야 하며, 필요한 경우 과학기술정보통신부장관에게 고영향 인공지능에 해당하는지 여부의 확인을 요청할 수 있다.\n② 과학기술정보통신부장관은 제1항에 따른 요청이 있는 경우 고영향 인공지능 해당 여부를 확인하여야 하며, 필요한 경우 전문위원회를 설치하여 관련 자문을 받을 수 있다.\n③ 과학기술정보통신부장관은 고영향 인공지능의 기준과 예시 등에 관한 가이드라인을 수립하여 보급할 수 있다.\n④ 그 밖에 제1항에 따른 확인 절차 등에 관하여 필요한 사항은 대통령령으로 정한다.\n제34조(고영향 인공지능과 관련한 사업자의 책무) ① 인공지능사업자는 고영향 인공지능 또는 이를 이용한 제품ㆍ서비스를 제공하는 경우 고영향 인공지능의 안전성ㆍ신뢰성을 확보하기 위하여 다음 각 호의 내용을 포함하는 조치를 대통령령으로 정하는 바에 따라 이행하여야 한다.\n위험관리방안의 수립ㆍ운영\n기술적으로 가능한 범위에서의 인공지능이 도출한 최종결과, 인공지능의 최종결과 도출에 활용된 주요 기준, 인공지능의 개발ㆍ활용에 사용된 학습용데이터의 개요 등에 대한 설명 방안의 수립ㆍ시행\n이용자 보호 방안의 수립ㆍ운영\n고영향 인공지능에 대한 사람의 관리ㆍ감독\n안전성ㆍ신뢰성 확보를 위한 조치의 내용을 확인할 수 있는 문서의 작성과 보관\n그 밖에 고영향 인공지능의 안전성ㆍ신뢰성 확보를 위하여 위원회에서 심의ㆍ의결된 사항\n② 과학기술정보통신부장관은 제1항 각 호에 따른 조치의 구체적인 사항을 정하여 고시하고, 인공지능사업자에게 이를 준수하도록 권고할 수 있다.\n③ 인공지능사업자가 다른 법령에 따라 제1항 각 호에 준하는 조치를 대통령령으로 정하는 바에 따라 이행한 경우에는 제1항에 따른 조치를 이행한 것으로 본다.\n제35조(고영향 인공지능 영향평가) ① 인공지능사업자가 고영향 인공지능을 이용한 제품 또는 서비스를 제공하는 경우 사전에 사람의 기본권에 미치는 영향을 평가(이하 “영향평가”라 한다)하기 위하여 노력하여야 한다. 이 경우 영향평가에는 고영향 인공지능을 이용한 제품 또는 서비스의 성격을 고려하여 인공지능취약계층의 특성이 반영될 수 있도록 하여야 한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n② 국가기관등이 고영향 인공지능을 이용한 제품 또는 서비스를 이용하려는 경우에는 영향평가를 실시한 제품 또는 서비스를 우선적으로 고려하여야 한다.\n③ 그 밖에 영향평가의 구체적인 내용ㆍ방법 등에 관하여 필요한 사항은 대통령령으로 정한다.\n제36조(국내대리인 지정) ① 국내에 주소 또는 영업소가 없는 인공지능사업자로서 이용자 수, 매출액 등이 대통령령으로 정하는 기준에 해당하는 자는 다음 각 호의 사항을 대리하는 자(이하 “국내대리인”이라 한다)를 서면으로 지정하고, 이를 과학기술정보통신부장관에게 신고하여야 한다.\n제32조제2항에 따른 이행 결과의 제출\n제33조제1항에 따른 고영향 인공지능 해당 여부 확인의 요청\n제34조제1항 각 호에 따른 안전성ㆍ신뢰성 확보 조치의 이행에 필요한 지원(같은 항 제5호에 따른 문서의 최신성ㆍ정확성에 대한 점검을 포함한다)\n② 국내대리인은 국내에 주소 또는 영업소가 있는 자로 한다.\n③ 국내대리인이 제1항 각 호와 관련하여 이 법을 위반한 경우에는 해당 국내대리인을 지정한 인공지능사업자가 그 행위를 한 것으로 본다.\n제5장 보칙\n제37조(인공지능산업의 진흥을 위한 재원의 확충 등) ① 국가는 기본계획 및 이 법에 따른 시책 등을 효과적으로 추진하기 위하여 필요한 재원을 지속적이고 안정적으로 확충할 수 있는 방안을 마련하여야 한다.\n② 과학기술정보통신부장관은 인공지능산업의 진흥을 위하여 필요한 경우에는 공공기관으로 하여금 인공지능산업의 진흥에 관한 사업 등에 필요한 지원을 하도록 권고할 수 있다.\n③ 국가 및 지방자치단체는 기업 등 민간이 적극적으로 인공지능산업의 진흥과 관련된 사업에 투자할 수 있도록 필요한 조치를 마련하여야 한다.\n④ 국가 및 지방자치단체는 인공지능산업의 발전단계 등을 종합적으로 고려하여 투자재원을 효율적으로 집행하도록 노력하여야 한다.\n제38조(실태조사, 통계 및 지표의 작성) ① 과학기술정보통신부장관은 국가데이터처장과 협의하여 기본계획 및 인공지능등 관련 시책과 사업의 기획ㆍ수립ㆍ추진을 위하여 국내외 인공지능등에 관한 실태조사, 통계 및 지표를 「과학기술기본법」 제26조의2에 따른 통계와 연계하여 작성ㆍ관리하고 공표하여야 한다. \u0026lt;개정 2025. 10. 1.\u0026gt;\n② 과학기술정보통신부장관은 제1항에 따른 통계 및 지표의 작성을 위하여 관계 중앙행정기관의 장, 지방자치단체의 장 및 공공기관의 장에게 자료의 제출 등 협조를 요청할 수 있다. 이 경우 협조를 요청받은 기관의 장은 특별한 사정이 없으면 이에 따라야 한다.\n③ 그 밖에 제1항에 따른 실태조사, 통계 및 지표의 작성ㆍ관리 및 공표 등에 필요한 사항은 대통령령으로 정한다.\n제39조(권한의 위임 및 업무의 위탁) ① 과학기술정보통신부장관 또는 관계 중앙행정기관의 장은 이 법에 따른 권한의 일부를 대통령령으로 정하는 바에 따라 소속 기관의 장 또는 특별시장ㆍ광역시장ㆍ특별자치시장ㆍ도지사ㆍ특별자치도지사(이하 이 조에서 “시ㆍ도지사”라 한다)에게 위임할 수 있다. 이 경우 시ㆍ도지사는 위임받은 권한의 일부를 시장(「제주특별자치도 설치 및 국제자유도시 조성을 위한 특별법」 제11조제2항에 따른 행정시장을 포함한다)ㆍ군수ㆍ구청장(자치구의 구청장을 말한다)에게 재위임할 수 있다.\n② 정부는 다음 각 호의 업무를 대통령령으로 정하는 바에 따라 관련 기관 또는 단체에 위탁할 수 있다.\n제13조에 따른 인공지능기술 개발 및 이용 관련 사업에 대한 지원\n제15조제2항 및 제3항에 따른 학습용데이터의 생산ㆍ수집ㆍ관리ㆍ유통 및 활용 등에 관한 지원대상사업의 선정ㆍ지원과 학습용데이터 구축사업의 추진\n통합제공시스템의 구축ㆍ운영 및 관리\n제18조에 따른 창업 활성화를 위하여 과학기술정보통신부장관이 필요하다고 인정하는 사항\n제30조제2항에 따른 검ㆍ인증등 관련 지원\n제38조에 따른 실태조사, 통계 및 지표의 작성\n그 밖에 인공지능산업의 육성 및 인공지능윤리의 확산을 위하여 대통령령으로 정하는 사무\n제40조(사실조사 등) ① 과학기술정보통신부장관은 다음 각 호의 어느 하나에 해당하는 경우에는 인공지능사업자에 대하여 관련 자료를 제출하게 하거나, 소속 공무원으로 하여금 필요한 조사를 하게 할 수 있다.\n제31조제2항ㆍ제3항, 제32조제1항ㆍ제2항 또는 제34조제1항에 위반되는 사항을 발견하거나 혐의가 있음을 알게 된 경우\n제31조제2항ㆍ제3항, 제32조제1항ㆍ제2항 또는 제34조제1항의 위반에 대한 신고를 받거나 민원이 접수된 경우\n② 과학기술정보통신부장관은 제1항에 따른 조사를 위하여 필요한 경우 소속 공무원으로 하여금 인공지능사업자의 사무소ㆍ사업장에 출입하여 장부ㆍ서류, 그 밖의 자료나 물건을 조사하게 할 수 있다. 이 경우 조사의 내용ㆍ방법 및 절차 등에 관하여 이 법에서 정하는 사항을 제외하고는 「행정조사기본법」에서 정하는 바에 따른다.\n③ 과학기술정보통신부장관은 제1항 및 제2항에 따른 조사 결과 인공지능사업자가 이 법을 위반한 사실이 있다고 인정되면 인공지능사업자에게 해당 위반행위의 중지나 시정을 위하여 필요한 조치를 명할 수 있다.\n제41조(벌칙 적용에서 공무원 의제) ① 위원회의 위원 중 공무원이 아닌 위원은 「형법」 제129조부터 제132조까지에 따른 벌칙을 적용할 때에는 공무원으로 본다.\n② 제39조제2항에 따라 위탁받은 업무에 종사하는 기관 또는 단체의 임직원은 「형법」 제127조 및 제129조부터 제132조까지에 따른 벌칙을 적용할 때에는 공무원으로 본다.\n제6장 벌칙\n제42조(벌칙) 제7조제9항을 위반하여 직무상 알게 된 비밀을 타인에게 누설하거나 직무상 목적 외의 용도로 사용한 자는 3년 이하의 징역 또는 3천만원 이하의 벌금에 처한다.\n제43조(과태료) ① 다음 각 호의 어느 하나에 해당하는 자에게는 3천만원 이하의 과태료를 부과한다.\n제31조제1항을 위반하여 고지를 이행하지 아니한 자\n제36조제1항을 위반하여 국내대리인을 지정하지 아니한 자\n제40조제3항에 따른 중지명령이나 시정명령을 이행하지 아니한 자\n② 제1항에 따른 과태료는 대통령령으로 정하는 바에 따라 과학기술정보통신부장관이 부과ㆍ징수한다.\n부 칙 \u0026lt;법률 제20676호, 2025. 1. 21.\u0026gt;\n제1조(시행일) 이 법은 공포 후 1년이 경과한 날부터 시행한다. 다만, 제2조제4호라목 중 디지털의료기기에 관한 부분은 2026년 1월 24일부터 시행한다.\n제2조(이 법 시행을 위한 준비행위) 이 법을 시행하기 위하여 필요한 위원회 위원의 위촉, 분과위원회, 특별위원회, 자문단 및 지원단의 구성 등은 이 법 시행 전에 할 수 있다.\n제3조(전담기관에 관한 특례) 이 법 시행 당시 제23조제1항에 따른 집적화를 지역에 효과적으로 정착시키기 위하여 정부로부터 관련 예산을 지원받아 운영 중인 기관 중 조직, 인력 등 대통령령으로 정하는 요건을 충족한 기관은 제23조제4항에도 불구하고 이 법에 따라 전담기관으로 지정된 것으로 본다.\n부 칙 \u0026lt;법률 제21065호, 2025. 10. 1.\u0026gt; (정부조직법)\n제1조(시행일) 이 법은 공포한 날부터 시행한다. 다만, 부칙 제7조에 따라 개정되는 법률 중 이 법 시행 전에 공포되었으나 시행일이 도래하지 아니한 법률을 개정한 부분은 각각 해당 법률의 시행일부터ㆍㆍㆍ\u0026lt;생략\u0026gt;ㆍㆍㆍ 시행한다.\n및 2. 생략 제2조부터 제6조까지 생략\n제7조(다른 법률의 개정) ①부터 \u0026lt;95\u0026gt;까지 생략\n\u0026lt;96\u0026gt; 인공지능 발전과 신뢰 기반 조성 등에 관한 기본법 일부를 다음과 같이 개정한다.\n제38조제1항 중 “통계청장”을 “국가데이터처장”으로 한다.\n\u0026lt;97\u0026gt;부터 \u0026lt;626\u0026gt;까지 생략\n제8조 생략\n부 칙 \u0026lt;법률 제21311호, 2026. 1. 20.\u0026gt;\n이 법은 2026년 1월 22일부터 시행한다. 다만, 제3조제5항, 제6조제2항제7호ㆍ제8호, 제16조제3항부터 제5항까지(제2항제2호의2의 개정규정에 관한 부분에 한정한다), 제17조의2, 제18조, 제22조의3 및 제35조제1항 후단의 개정규정은 공포 후 6개월이 경과한 날부터 시행한다.\nOfficial English translation (Korea Legislation Research Institute) Source: KLRI elaw, Statutes of the Republic of Korea — official translation by the Korea Legislation Research Institute (KLRI), reproduced as published, with attribution. © Korea Legislation Research Institute; rights in the translation belong to KLRI.\nFRAMEWORK ACT ON THE DEVELOPMENT OF ARTIFICIAL INTELLIGENCE AND THE CREATION OF A FOUNDATION FOR TRUST\nAct No. 20676, Jan. 21, 2025\nAmended by Act No. 21311, Jan. 20, 2026\nChapter I: General Provisions Article 1 (Purpose)\nThe purpose of this Act is to prescribe the basic matters necessary for the sound development of artificial intelligence and the creation of a foundation for trust in artificial intelligence, thereby contributing to the protection of citizens’ rights, interests, and dignity, the improvement of their quality of life, and the strengthening of national competitiveness.\nArticle 2 (Definitions)\nThe terms used in this Act are defined as follows: \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n\u0026ldquo;Artificial intelligence\u0026rdquo; (AI) means the electronic implementation of human intellectual abilities, including learning, reasoning, perception, judgment, and language comprehension; \u0026ldquo;AI system\u0026rdquo; means an AI-based system that infers outputs such as predictions, recommendations, and decisions that affect real and virtual environments for a given goal with various levels of autonomy and adaptability; \u0026ldquo;AI technology\u0026rdquo; means hardware and software technologies, or their application technologies, necessary to implement AI; \u0026ldquo;High-impact AI\u0026rdquo; means an AI system that is likely to have a significant impact on or pose a risk to human life, physical safety, and fundamental rights, and that is utilized in any of the following areas:\na.\tSupply of energy under subparagraph 1 of Article 2 of the Energy Act;\nb.\tProduction process of drinking water under subparagraph 1 of Article 3 of the Drinking Water Management Act;\nc.\tEstablishment and operation of a system for providing and using health and medical services under subparagraph 1 of Article 3 of the Framework Act on Health and Medical Care;\nd.\tDevelopment and use of medical devices under Article 2(1) of the Medical Devices Act and digital medical devices under subparagraph 2 of Article 2 of the Digital Medical Products Act;\ne.\tSafe management and operation of nuclear materials under Article 2(1)1 of the Act on Physical Protection and Radiological Emergency and nuclear facilities under subparagraph 2 of that paragraph;\nf.\tAnalysis and utilization of biometric information (referring to personal information on physical, physiological, and behavioral characteristics by which an individual can be identified, such as facial, fingerprint, iris, and palm vein patterns) for criminal investigation or arrests;\ng.\tJudgments or evaluations that have a significant impact on the rights and obligations of individuals, such as hiring and loan screening;\nh.\tMajor operation and management of means of transportation, traffic facilities, and traffic systems under subparagraphs 1 through 3 of Article 2 of the Traffic Safety Act;\ni.\tDecision-making by the State, a local government, a public institution under Article 4 of the Act on the Management of Public Institutions, or other such entity (hereinafter referred to as \u0026ldquo;State agency or other public entity\u0026rdquo;) that affects citizens, such as through the verification and determination of qualifications required for the provision of public services or the collection of expenses;\nj.\tEvaluation of students in early childhood education, elementary education, and secondary education under Article 9(1) of the Framework Act on Education;\nk.\tOther areas prescribed by Presidential Decree, which have a significant impact on the protection of human life, physical safety, and fundamental rights; \u0026ldquo;Generative AI\u0026rdquo; means an AI system that generates text, sound, images, videos, and other various outputs by imitating the structure and characteristics of input data (referring to data defined in subparagraph 1 of Article 2 of the Framework Act on Promotion of Data Industry and Data Utilization; hereinafter the same shall apply); \u0026ldquo;AI industry\u0026rdquo; means an industry that develops, manufactures, produces, or distributes products utilizing AI or AI technology (hereinafter referred to as \u0026ldquo;AI products\u0026rdquo;) or provides services related thereto (hereinafter referred to as \u0026ldquo;AI services\u0026rdquo;); \u0026ldquo;AI business operator\u0026rdquo; means any of the following corporations, organizations, individuals, State agencies and other public entities that is engaged in business related to the AI industry:\na.\tAI development business operator: A person that develops and provides AI;\nb.\tAI use business operator: A person that provides AI products or AI services using AI provided by a business operator under item a; \u0026ldquo;User\u0026rdquo; means a person that is provided with an AI product or AI service; \u0026ldquo;Impacted person\u0026rdquo; means a person whose life, physical safety, and fundamental rights are significantly impacted by AI products or AI services; \u0026ldquo;AI society\u0026rdquo; means a society that creates value and drives development in all fields, including industry, the economy, society, culture, and public administration, through AI; \u0026ldquo;AI ethics\u0026rdquo; means the ethical standards that all members of society should observe in all areas, including the development, provision, and use of AI, in order to realize a safe and trustworthy AI society capable of protecting citizens’ rights, interests, lives, and property based on respect for human dignity; \u0026ldquo;Training data\u0026rdquo; means data used for AI development, utilization, and other related purposes.\nArticle 3 (Basic principles and the State\u0026rsquo;s responsibilities)\n(1)\tAI technology and the AI industry shall be developed in a manner that enhances safety and trustworthiness, thereby improving the quality of life of the people.\n(2)\tAn impacted person shall be entitled to be provided with a clear and meaningful explanation of the main criteria, principles, etc. utilized in deriving the final results of AI, to the extent technically and reasonably possible.\n(3)\tThe State and local governments shall respect the creative spirit of AI business operators and endeavor to create a safe environment for the use of AI.\n(4)\tThe State and local governments shall devise policy measures to ensure that all citizens can stably adapt to the changes brought about by AI in all areas, including society, the economy, and culture, as well as in the daily lives of the people.\n(5)\tThe State and local governments shall endeavor to ensure the participation of, and to reflect the opinions of, vulnerable groups prescribed by Presidential Decree who experience difficulties in using AI products or AI services, including persons with disabilities and the senior citizens (hereinafter referred to as \u0026ldquo;AI-vulnerable groups\u0026rdquo;), in the process of developing and establishing AI-related policies. \u0026lt;Add on Jan. 20, 2026\u0026gt;\nArticle 4 (Scope of application)\n(1)\tThis Act shall apply to any conduct outside the Republic of Korea if the conduct impacts the domestic market or users.\n(2)\tThis Act shall not apply to AI prescribed by Presidential Decree that is developed and used solely for the purpose of national defense or national security.\nArticle 5 (Relationship to other statutes)\n(1)\tExcept as otherwise expressly provided in other statutes, this Act shall apply to AI, AI technology, the AI industry, and AI society (hereinafter referred to as \u0026ldquo;AI and related matters\u0026rdquo;).\n(2)\tThe enactment or amendment of other statutes regarding AI and related matters shall be made in conformity with the purpose of this Act. Chapter II: System For Promoting Sound Development Of Ai And Creation Of Foundation For Trust Article 6 (Formulation of AI master plans)\n(1)\tThe Minister of Science and ICT shall formulate, modify, and implement an AI master plan (hereinafter referred to as \u0026ldquo;master plan\u0026rdquo;), subject to deliberation and resolution by the Presidential Council on National Artificial Intelligence Strategy under Article 7, for the promotion of AI technology and the AI industry and the enhancement of national competitiveness every 3 years after hearing the opinions of the heads of relevant central administrative agencies and the heads of local governments; provided, the foregoing shall not apply to modifications concern minor matters prescribed by Presidential Decree in the master plan. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n(2)\tThe master plan shall include the following: \u0026lt;Amended on Jan. 20, 2026\u0026gt;\nMatters regarding the basic direction and strategies for policies on AI and related matters; Matters regarding the training of professionals for the systematic fostering of the AI industry, the establishment of a foundation for promoting the development and utilization of AI, and other related matters; Matters regarding statutes, systems, and culture for the realization of a sound AI society, such as the dissemination of AI ethics; Matters regarding the securing of financial resources, the direction of investment, etc. for the development of AI technology and the promotion of the AI industry;\n4-2.\tMatters regarding the scope and standards for the generation of training data using public data, the provision of public data, and other related activities, and the promotion thereof, under the Act on Promotion of the Provision and Use of Public Data; Matters regarding the creation of a foundation for trust, including ensuring fairness, transparency, accountability, safety, and accessibility of AI; Matters regarding the direction of development of AI technology, and changes and responses in various areas of society, such as education, labor, economy, and culture;\n6-2.\tMatters regarding support for education and public awareness campaigns for understanding and utilizing AI technology; Matters to ensure access to and use of AI products or AI services by AI-vulnerable groups; Other matters deemed necessary by the Minister of Science and ICT to strengthen national competitiveness, including promotion of AI technology and the AI industry and international cooperation.\n(3)\tWhen the Minister of Science and ICT formulates a master plan, the Minister shall consider the comprehensive plan under Article 6(1) of the Framework Act on Intelligent Informatization and the action plan under Article 7(1) of that Act, and shall determine, in consultation with the Minister of the Interior and Safety, matters regarding the provision of public data as training data under the Act on Promotion of the Provision and Use of Public Data among training data referred to in paragraph (2)4-2. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n(4)\tThe Minister of Science and ICT may request the heads of relevant central administrative agencies, heads of local governments, and heads of public institutions (referring to public institutions under subparagraph 16 of Article 2 of the Framework Act on Intelligent Informatization (hereinafter referred to as \u0026ldquo;public institutions\u0026rdquo;; hereinafter the same shall apply) to submit data necessary for the formulation of a master plan. In this case, the head of the agency, local government, or public institution requested to submit data shall comply with the request unless there is a compelling reason not to do so.\n(5)\tThe master plan shall be deemed a sectoral implementation plan for the fields of AI and the AI industry under Article 13(1) of the Framework Act on Intelligent Informatization.\n(6)\tThe heads of central administrative agencies and the heads of local governments shall take the master plan into consideration when establishing and executing policies under their jurisdictions.\n(7)\tOther matters necessary for the formulation, modification, and implementation of master plans shall be prescribed by Presidential Decree.\nArticle 7 (Presidential Council on National Artificial Intelligence Strategy)\n(1)\tA Presidential Council on National Artificial Intelligence Strategy (hereinafter referred to as the \u0026ldquo;Council\u0026rdquo;) shall be established under the President to deliberate and resolve on matters related to major policies, etc. for the development of AI and the creation of a foundation for trust. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n(2)\tThe Council shall consist of up to 60 members, including 1 chair and up to 3 vice chairs. In this case, the members under paragraph (4)4 shall constitute a majority of all the members, and the Council shall not be composed exclusively of members of a single gender. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n(3)\tThe President shall be the chair of the Council, and the vice chairs shall be persons designated by the President from among those under paragraph (4)1 or 4. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n(4)\tMembers of the Council shall be the following persons: Heads of relevant central administrative agencies prescribed by Presidential Decree; Deputy director of the National Security Office who is responsible for AI affairs; Senior secretary of the Office of President responsible for AI affairs; Persons with extensive expertise and experience in AI who are commissioned by the President.\n(5)\tThe chair of the Council shall represent the Council and have general supervision and control of the affairs of the Council.\n(6)\tThe chair of the Council may have the vice chairs of the Council perform the duties on behalf of the chair, if necessary.\n(7)\tThe term of office for members under paragraph (4)4 shall be 2 years, and members may be appointed consecutively for only 1 further term.\n(8)\tThe Council shall have 1 executive secretary, who shall be a member under paragraph (4)3.\n(9)\tA member of the Council shall not disclose secrets obtained in the course of performing the duties to others or use them for purposes other than those of the duties; provided, this shall not apply if there are special provisions in other statutes.\n(10)\tThe chair of the Council shall convene and preside over meetings of the Council.\n(11)\tA majority of the members of the Council shall constitute a quorum, and any decision thereof shall require the concurring vote of a majority of those present.\n(12)\tA secretariat shall be established within the Council to support the work and operations of the Council.\n(13)\tThe Commission shall remain in existence for 5 years from the date this Act enters into force.\n(14)\tOther matters necessary for the composition and operation of the Council and the secretariat under paragraph (12) shall be prescribed by Presidential Decree.\n[Title Amended on Jan. 20, 2026]\nArticle 8 (Functions of the Council)\n(1)\tThe Council shall deliberate and decide on the following: \u0026lt;Amended on Jan. 20, 2026\u0026gt; Matters regarding inspection and analysis of the formulation, modification, and implementation of the master plan; Matters regarding the establishment of national vision and mid- to long-term strategies for AI and related matters;\n2-2.\tMatters regarding the establishment, coordination, and inter-ministerial coordination of policies, programs, and other matters related to AI; Matters regarding implementation monitoring and performance management for policies and programs related to AI; Matters regarding the establishment of research and development strategies for AI and related matters; Matters regarding the establishment of investment directions and the formulation of strategies for AI and related matters; Matters regarding the identification and improvement of regulations that hinder the development and competitiveness of the AI industry;\n5-2.\tMatters regarding institutional improvements related to technologies, human resources, and locations for AI and related matters;\n5-3.\tOther matters regarding the training and support of professionals in AI and AI technology. Matters regarding plans for expansion of infrastructure such as AI data centers (referring to data centers under Article 40(1) of the Framework Act on Intelligent Informatization; hereinafter the same shall apply);\n6-2.\tMatters regarding the promotion of data (including training data) collection, management, and utilization for the advancement of AI; Matters regarding the promotion of AI utilization in industrial sectors, such as manufacturing and service industries, as well as in the public sector; Matters regarding international cooperation related to AI, including the establishment of international AI norms; Matters regarding the expression of recommendations or opinions under paragraph (2); Matters regarding the regulation of high-impact AI; Matters regarding the patterns of social change associated with high-impact AI and policy responses; Matters specified by this Act or any other statute requiring deliberation by the Council; Other matters deemed necessary by the chair of the Council to be submitted to a meeting of the Council.\n(2)\tThe Council may make recommendations or express opinions to the heads of State agencies and public entities, AI business operators, and other such entities regarding the proper use of AI, the practice of AI ethics, the safety and trustworthiness of AI technology.\n(3)\tWhen the Council makes recommendations or expresses opinions under paragraph (2) to the head of a State agency or other public entity regarding the improvement of statutes, regulations, or systems, or the formulation of action plans, the head of the State agency or entity shall formulate improvement plans for statutes, regulations, or systems, as well as action plans.\nArticle 9 (Exclusion of, challenge to, and recusal by member)\n(1)\tWhere any of the following applies to a member of the Council, the member shall be excluded from deliberation and resolution on the relevant agenda item to ensure the impartial performance of the duties: Where a member or a corporation or organization to which the member belongs has a direct interest in the relevant agenda item; Where a family member of a member (referring to any of the family members as defined in Article 779 of the Civil Act) is an interested party.\n(2)\tA party to an agenda item subject to deliberation (including its executive officers and employees if the party is a corporation or organization) may file a request for challenge to a member with the Council if the circumstances indicate that it would be impractical to expect the member to perform their duties impartially, and the Council shall make a decision to challenge by resolution if it recognizes that the request for challenge is valid.\n(3)\tIf the ground under paragraph (1) or (2) applies to a member, the member shall recuse himself or herself from the deliberation on the relevant agenda item.\nArticle 10 (Expert standing committees)\n(1)\tThe Council may establish expert standing committees, where necessary, in order to perform its affairs in specialized areas.\n(2)\tThe Council may establish special committees, where necessary, in order to discuss specific issues related to AI and related matters.\n(3)\tThe Council may establish an advisory committee consisting of relevant experts and others to professionally review matters regarding AI and related matters.\n(4)\tThe Council may operate a council of chief AI officers, composed of chief AI officers as prescribed by Presidential Decree, for the purpose of establishing major government-wide AI policy measures and promoting the efficient implementation of related programs. \u0026lt;Added on Jan. 20, 2026\u0026gt;\n(5)\tOther matters necessary for the composition, operation, etc. of expert standing committees, special committees, advisory committees, and the council of chief AI officers shall be prescribed by Presidential Decree. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\nArticle 11 (AI Policy Center)\n(1)\tThe Minister of Science and ICT may designate an AI Policy Center (hereinafter referred to as the \u0026ldquo;Center\u0026rdquo;) to comprehensively perform the affairs necessary for the development of AI-related policies and the establishment and dissemination of international norms.\n(2)\tThe Center shall perform the following functions: Provision of specialized technical support required for the formulation and implementation of master plans; Provision of specialized technical support for the development of AI-related policy measures and the planning and implementation of related programs; Investigation and analysis of the impact of the expanded utilization of AI on society, the economy, culture, and the daily lives of the people; Trend analyses, social and cultural changes and future forecasting, and investigation and research on laws and systems to support the development of policies related to AI and AI technology; Functions assigned to the Center as its duties or entrusted to the Center under other statutes and regulations; Other tasks entrusted by the head of a State agency or other public entity.\n(3)\tOther matters necessary for the designation, etc. of the Center shall be prescribed by Presidential Decree.\nArticle 12 (AI Safety Institute)\n(1)\tThe Minister of Science and ICT may operate an AI Safety Institute (hereinafter referred to as \u0026ldquo;AISI\u0026rdquo;) to professionally and efficiently perform its duties to secure the state of protecting citizens\u0026rsquo; lives, physical well-being, and property from risks arising in relation to AI and maintaining of a foundation for trust in an AI society (hereinafter referred to as \u0026ldquo;AI safety\u0026rdquo;).\n(2)\tAISI shall perform the following projects: Definition and analysis of risks related to AI safety; Research on AI safety policies; Research on criteria and methods for AI safety evaluation; Research on AI safety technologies and standardization; Promoting international exchange and cooperation related to AI safety; Support for ensuring the safety of AI systems under Article 32; Other projects prescribed by Presidential Decree that are related to AI safety.\n(3)\tThe Government may contribute to or support the expenses necessary for the operation and project implementation of AISI within the budget.\n(4)\tOther matters necessary for the operation, etc. of AISI shall be prescribed by Presidential Decree. Chapter III: Development Of Ai Technology And Fostering Of Ai Industry SECTION 1 Establishment of Foundation for AI Industry\nArticle 13 (Support for development and safe use of AI technology)\n(1)\tThe Government may support the following programs to promote the development of AI technology:\nInvestigation of domestic and international trends and levels of AI technology and related systems; Research and development, testing, and evaluation of AI technology, or utilization of the developed technology; Support for the practical application and commercialization of AI technology, including the dissemination, cooperation, and transfer of AI technology; Efficient dissemination of information and promotion of industry-academia cooperation for the implementation of AI technology; Other programs prescribed by Presidential Decree related to the development, research, and investigation of AI technology.\n(2)\tThe Government may support the following programs for the safe and convenient use of AI technology: Research and development programs that implement the matters under the subparagraphs of Article 60(1) of the Framework Act on Intelligent Informatization with AI technology; Programs to support research on technologies for implementing emergency stop functions under Article 60(3) of the Framework Act on Intelligent Informatization in AI products or AI services and to promote the dissemination of such technologies; Programs for research and development and dissemination of design criteria and technologies suitable for the protection of privacy and personal information under Article 61 (2) of the Framework Act on Intelligent Informatization in the development of AI technology; Research and development programs for the implementation and application of social impact assessments of AI technology in accordance with Article 56(1) of the Framework Act on Intelligent Informatization; Programs for research and development and dissemination of technologies, criteria, etc. that enable AI to be developed and used in a manner that respects human dignity and fundamental rights; Programs for awareness improvement of the safe development and use of AI, and for providing education and public campaigns to promote proper usage methods and safe environment creation; Other programs necessary for the protection of citizens’ fundamental rights, physical safety, and property in the development and use of AI.\n(3)\tThe Government shall disclose and disseminate the results of the programs referred in paragraph (2) so that anyone can readily access and use them. In such cases, where necessary to protect those who have developed technologies under such programs, a protection period may be established to allow those persons to receive royalties or to be protected through other means.\nArticle 14 (Standardization of AI technology)\n(1)\tThe Government may implement the following programs for standardization related to the AI technology, training data, and the safety and trustworthiness of AI: \u0026lt;Amended on Jan. 20, 2026\u0026gt; Establishment, revision, and abolition of standards related to AI technology, and their dissemination; Investigation and research and development of domestic and international standards related to AI technology; Other standardization programs related to AI technology.\n(2)\tThe Government may publicly notify the standards established under paragraph (1)1 and recommend that relevant business operators comply with them.\n(3)\tThe Government may provide support necessary for standardization programs related to AI technology undertaken by the private sector.\n(4)\tThe Government shall maintain and strengthen the cooperation system with international standards organizations or international standards bodies related to AI technology standards.\n(5)\tOther matters necessary for the promotion and support of standardization programs under paragraphs (1) and (3) shall be prescribed by Presidential Decree.\nArticle 15 (Establishment of policies measures related to AI training data)\n(1)\tThe Minister of Science and ICT shall, in consultation with the heads of relevant central administrative agencies, implement necessary policy measures to facilitate the production, collection, management, distribution, and utilization of training data, and to ensure the quality level thereof. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n(2)\tThe Government may select projects eligible for support and provide assistance within the budget to efficiently promote policy measures related to the production, collection, management, distribution, and utilization of training data.\n(3)\tThe Government may implement a project that produces and provides various training data (hereinafter referred to as \u0026ldquo;training data development project\u0026rdquo;) to promote the production, collection, management, distribution, and utilization of training data.\n(4)\tThe Minister of Science and ICT shall establish and manage a system that can integrally provide and manage training data (hereinafter referred to as the \u0026ldquo;integrated provision system\u0026rdquo;) for the efficient implementation of the training data development project and make it freely available to the private sector.\n(5)\tThe Minister of Science and ICT may collect fees from persons using the integrated provision system.\n(6)\tMatters necessary for selecting and supporting target projects under paragraph (2), the implementation of the training data development project, the establishment and management of the integrated provision system, and the collection of fees under paragraph (5) shall be prescribed by Presidential Decree.\nSECTION 2 Development of AI technology and Promotion of the AI industry\nArticle 16 (Policy measures for adoption and utilization of AI technology)\n(1)\tThe State and local governments shall establish and implement policy measures to promote the adoption and widespread utilization of AI technology by enterprises and public institutions: \u0026lt;Added on Jan. 20, 2026\u0026gt;\n(2)\tThe State and local governments may, if necessary, provide the following support to promote the adoption and utilization of AI technology by enterprises and public institutions: \u0026lt;Amended on Jan. 20, 2026\u0026gt; Support for the development of AI technology, AI products, or AI services, and the dissemination of research and development outcomes; Consulting support for enterprises and public institutions seeking to adopt and utilize AI technology;\n2-2.\tSupport necessary for public institutions to generate and provide data they hold and manage as training data, and to ensure an appropriate level of quality; Support for education related to the adoption and utilization of AI technology for executive officers and employees of small and medium enterprises under Article 2(1) of the Framework Act on Small and Medium Enterprises, venture businesses under Article 2(1) of the Special Act on the Promotion of Venture Businesses, and micro enterprises under Article 2(1) of Framework Act on Micro Enterprises (hereinafter referred to as \u0026ldquo;small and medium enterprises, etc.\u0026rdquo;); Funding for the adoption and utilization of AI technology by small and medium enterprises, etc.; Other matters prescribed by Presidential Decree to promote the adoption and utilization of AI technology by enterprises and public institutions.\n(3)\tA State agency or other public entity shall give priority consideration to AI products or AI services prescribed by Presidential Decree where intending to procure products or services or award service contracts necessary for the performance of its duties; provided, this shall not apply where the use of AI technology is not appropriate due to the nature of the duties. \u0026lt;Added on Jan. 20, 2026\u0026gt;\n(4)\tEven where damage occurs to a State agency or other public entity as a result of the purchase or use of AI products or AI services under paragraph (3), the person in charge of the purchase or use shall not be liable for compensation for damages to the agency or entity; provided, this shall not apply if the damages resulted from the intentional conduct or gross negligence of that person. \u0026lt;Added on Jan. 20, 2026\u0026gt;\n(5)\tMatters necessary for support under paragraph (2) shall be prescribed by Presidential Decree. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n[Title Amended on Jan. 20, 2026]\nArticle 17 (Special support for small and medium enterprises, etc.)\n(1)\tWhen implementing various support policy measures related to AI technology and the AI industry under this Act, priority shall be given to small and medium enterprises, etc.\n(2)\tThe Government shall endeavor to promote participation of small and medium enterprises, etc. in the AI industry and shall reflect matters related thereto in the master plan.\n(3)\tThe Minister of Science and ICT may provide support to small and medium enterprises, etc., in implementing the measures under Article 34 and in conducting impact assessments under Article 35 to ensure the safety and trustworthiness of AI.\nArticle 17-2 (Support for expenses of using AI products and AI services)\n(1)\tThe State and local governments may, within the budget, provide financial support to cover all or part of the expenses of using AI products and AI services for individuals who have difficulty accessing the products and services due to economic circumstances.\n(2)\tThe requirements, eligible recipients, and other necessary matters for cost support under paragraph (1) shall be prescribed by Presidential Decree.\n[This Article Added on Jan. 20, 2026]\nArticle 18 (Promotion of business start-up)\n(1)\tThe Government may implement the following programs to promote business start-up in the AI industry: Programs related to the identification, fostering, and support of entrepreneurs in the AI industry sectors; Programs related to education and training for the promotion of business start-up in the AI industry sectors; Support for the commercialization of advanced AI technology developed by professionals under Article 21; Valuation of AI technology and financial support for startup funding; Provision of AI-related research and technology development outcomes; Fostering institutions and organizations that support business start-up in the AI industry sectors; Other programs necessary to promote business start-up in the AI industry sectors.\n(2)\tLocal governments may contribute to or invest in public organizations such as public institutions that support business start-up in the AI industry sectors.\n(3)\tThe head of a central administrative agency may, in consultation with the Minister of SMEs and Startups, provide support through the fund of funds for venture investment established under Article 70 of the Venture Investment Promotion Act in order to encourage business start-up in the AI industry. \u0026lt;Added on Jan. 20, 2026\u0026gt;\n(4)\tThe funds for the support under paragraph (3) shall be created with the following financial resources: \u0026lt;Added on Jan. 20, 2026\u0026gt; Capital contributions made by the State, local governments, or public institutions; Capital contributions made by a person, other than the State, a local government, or a public institution, that wishes to invest in the fund of funds for venture investment in connection with the AI industry; Other incidental income.\n(5)\tMatters necessary for making capital contributions to the fund of funds for venture investment under paragraph (3) shall be prescribed by Presidential Decree. \u0026lt;Added on Jan. 20, 2026\u0026gt;\n[Title Amended on Jan. 20, 2026]\nArticle 19 (Promotion of AI convergence)\n(1)\tThe Government shall establish and implement necessary policy measures to facilitate convergence between the AI industry and other industries and to promote the utilization of AI across all sectors.\n(2)\tThe Government may, if necessary, prioritize and promote research and development programs on AI convergence products and services in national research and development programs under the National Research and Development Innovation Act to support the development of AI convergence products and services.\n(3)\tThe Government shall actively support the smooth implementation of temporary permission under Article 37 of the Special Act on Information and Communications Promotion and Convergence Activation and regulatory exceptions for demonstration under Article 38-2 of that Act for AI convergence products and services developed under paragraph (2).\nArticle 20 (System improvement)\n(1)\tThe Government shall endeavor to improve relevant systems, including the revision of statutes and regulations, to promote the development of the AI industry and the creation of a foundation for trust.\n(2)\tThe Government may provide administrative and financial support necessary for research on related laws and systems and for gathering opinions from various sectors of society in order to facilitate the improvement of systems under paragraph (1).\nArticle 21 (Securing AI professionals)\n(1)\tThe Minister of Science and ICT shall implement the following programs to develop and support professionals in AI and AI technology in accordance with the policy measures under Article 23(1) of the Framework Act on Intelligent Informatization for the development of AI technology and the advancement of the AI industry. \u0026lt;Amended on Jan. 20, 2026\u0026gt; Development and implementation of education and training programs to enhance the job competencies and career development of professionals; Promotion of employment, including by supporting the employment of professionals and facilitating the influx of new talent; Promotion of diversified career paths, including the expansion of opportunities for professionals to enter public service; Support for domestic and international training programs for professionals and promotion of international exchange; Improvement of the welfare of professionals, including the improvement of working conditions and enhancement of benefits; Other programs for the development and support of professionals in AI and AI technology.\n(2)\tThe Government may implement the following policy measures to secure overseas professionals in AI and AI technology: Investigation and analysis on professionals at overseas universities, research institutes, enterprises related to AI and AI technology; Establishment of an international network to attract overseas professionals; Support for overseas professionals seeking employment in the Republic of Korea; Support for overseas expansion of domestic AI research institutes and attraction of overseas AI research institutes to the Republic of Korea; Support for attracting international organizations and international events related to AI and AI technology to the Republic of Korea; Other matters necessary to secure overseas professionals.\nArticle 22 (Support for international cooperation and overseas expansion)\n(1)\tThe Government shall identify international trends related to AI and promote international cooperation.\n(2)\tThe Government may provide the following support to individuals, enterprises, or organizations engaged in the AI industry in order to strengthen the competitiveness of the AI industry and promote expansion into overseas markets: International exchange of information, technology, and personnel related to the AI industry; Collection, analysis, and provision of information on overseas expansion related to the AI industry; Joint research and development and international standardization of AI technology, AI products, or AI services between countries; Attraction of foreign capital investment related to the AI industry; Public awareness activities and overseas marketing, including participation in international professional conferences and exhibitions on AI and related matters; Establishment of sales systems, distribution systems, and cooperative systems necessary for the export of AI products or AI services; Identification of international trends in AI ethics, and international cooperation; Other matters necessary to strengthen the competitiveness of the AI industry and promote entry into overseas markets.\n(3)\tIn order to efficiently perform the support under each subparagraph of paragraph (2), the Government may entrust the support to, or have it carried out by, public institutions or other organizations, and may subsidize the costs necessary for the purpose.\nArticle 22-2 (Establishment and support of AI research institutes)\n(1)\tEntities prescribed by the Presidential Decree, such as universities or enterprises, may establish and operate research institutes for the development and utilization of AI (each hereinafter referred to as \u0026ldquo;AI research institute\u0026rdquo;), independently or jointly.\n(2)\tWhere an entity prescribed by the Presidential Decree, such as a university or an enterprise, intends to establish an AI research institute under paragraph (1), it shall obtain permission from the Minister of Science and ICT after meeting the following requirements: It shall have at least 3 promoters; It shall have the capability, including personnel and facilities, to conduct projects under paragraph (5); It shall meet other requirements prescribed by Presidential Decree necessary for the establishment and operation of the AI research institute.\n(3)\tAn AI research institute shall have a director. The director of the AI research institute shall represent the institute and exercise overall control over its affairs.\n(4)\tThe articles of incorporation of an AI research institute shall include the following matters: Purposes; Name; Location of the principal office; Regulations on assets; Regulations on the qualifications and appointment and dismissal of the director of the Institute; Regulations on the responsibilities and authorities of the director of the Institute.\n(5)\tAn AI research institute shall perform the following projects by industry and by function: AI technology research and development; Research and development on the convergence of AI technology with other technologies and interdisciplinary fields; Management, transfer, utilization, and commercialization of research and development outcomes in AI technology; Training of professionals engaged in AI technology research and development; International exchange and cooperation related to AI technology research and development; Other matters necessary for AI technology research and development.\n(6)\tThe Government and local governments may provide financial support within the budget for the expenses necessary for the operation and project implementation of AI research institutes.\n(7)\tAI research institutes may receive subsidies, donations, or other contributions from persons other than the Government or local governments or may engage in revenue-generating activities as stipulated in their articles of incorporation, in order to generate funds necessary for their operation.\n(8)\tThe director of an AI research institute may, where necessary for the research and development of AI technology and related activities, consult with entities prescribed by Presidential Decree, such as universities and enterprises, under paragraph (1), arrange for executive officers or employees to be seconded to, or to serve concurrently at, the AI research institute to conduct research or related activities, and may provide necessary support to the entities to which the executive officers or employees belong. In such cases, the director of the institute may request support for consultation from the Minister of Science and ICT if necessary.\n(9)\tExcept as provided in this Act, the provisions of the Civil Act governing incorporated foundations shall apply mutatis mutandis to AI research institutes.\n(10)\tThe Minister of Science and ICT may issue a corrective order or revoke the permission for the establishment of an AI research institute if it falls under any of the following cases; provided, if the institute falls under subparagraph 1 or 2, the permission shall be revoked: Where the institute has obtained permission for its establishment by fraud or other improper means; Where the institute becomes impossible to achieve its purposes; Where the institute fails to meet the requirements for permission under paragraph (2); Where the institute conducts any business outside the scope of its intended business; Where the Institute violates any statute or regulation, articles of incorporation, or order issued under this Act; Where the institute commits an act harmful to the public interest; Where the institute fails to commence its intended business within 6 months from the date of permission for its establishment without good cause, or it has no business performance for 1 year or more.\n(11)\tThe Minister of Science and ICT shall hold a hearing if the Minister intends to revoke the permission for the establishment of an AI research institute under paragraph (10).\n(12)\tOther matters necessary for the procedures for establishment of AI research institutes, and the operation and support thereof shall be prescribed by Presidential Decree.\n[This Article Added on Jan. 20, 2026]\nArticle 22-3 (Establishment and operation of research institutions for securing AI technology)\nThe Minister of Science and ICT may establish and operate institutions that conduct research on the development and utilization of AI, as prescribed by Presidential Decree, where necessary to secure innovative AI technology.\n[This Article Added on Jan. 20, 2026]\nArticle 23 (Designation of AI clusters)\n(1)\tThe State and local governments may implement the functional, physical, and regional clustering of enterprises, institutions, or organizations engaged in the research and development of AI and AI technology in order to foster the AI industry and strengthen competitiveness in AI development and utilization.\n(2)\tThe State and local governments may, if necessary for the clustering under paragraph (1), designate an AI cluster (hereinafter referred to as the \u0026ldquo;AI cluster\u0026rdquo;) and provide administrative, financial, and technical support as prescribed by Presidential Decree.\n(3)\tThe Minister of Science and ICT may revoke the designation of an AI cluster in any of the following cases; provided, in the case of subparagraph 1, the designation shall be revoked: Where the designation is obtained by fraud or other improper means; Where the head of the State or head of the local government that designated the AI cluster determines that it is difficult for the AI cluster to achieve the purpose of its designation.\n(4)\tThe Government may establish or designate a dedicated institution to comprehensively support related tasks in order to effectively anchor the clustering implemented under paragraph (1) within a region.\n(5)\tThe Government may contribute or subsidize all or part of the expenses necessary for the operation and project execution of the dedicated institution under paragraph (4).\n(6)\tOther matters necessary for the designation and revocation of designation of an AI cluster and the establishment or designation of a dedicated institution under paragraph (4) shall be prescribed by Presidential Decree.\nArticle 24 (Establishment of AI demonstration infrastructure)\n(1)\tThe State and local governments may establish and operate facilities, equipment, installations, etc. necessary for testing and evaluation (hereinafter referred to as \u0026ldquo;demonstration infrastructure\u0026rdquo;) to support demonstration, performance testing, and verification and certification under Article 30 of technologies developed by or transferred to AI business operators (hereinafter referred to as \u0026ldquo;demonstration testing and related activities\u0026rdquo;).\n(2)\tThe State and local governments may make available to AI business operators any demonstration infrastructure held by institutions designated by Presidential Decree in order to promote demonstration testing and related activities.\n(3)\tOther matters necessary for the establishment, operation, availability, etc. of demonstration infrastructure shall be prescribed by Presidential Decree.\nArticle 25 (Implementation of policy measures related to AI data centers)\n(1)\tThe Government shall implement necessary policy measures to encourage the establishment and operation of data centers used for the development and utilization of AI (hereinafter referred to as \u0026ldquo;AI data centers\u0026rdquo;).\n(2)\tThe Government may perform the following tasks to implement the policy measures under paragraph (1). Administrative and financial support necessary for the establishment and operation of AI data centers Support for the use of AI data centers by small and medium enterprises, research institutes, etc.; Support for balanced regional development of AI-related infrastructure facilities, including AI data centers.\nArticle 26 (Establishment of Korean AI promotion association)\n(1)\tPersons engaged in research and practice in AI and related matters may establish or be designated as a Korean AI promotion association (hereinafter referred to as \u0026ldquo;Association\u0026rdquo;) with the authorization of the Minister of Science and ICT, as prescribed by Presidential Decree, to promote the development and use of AI, to advance the AI industry and AI technology, and to provide education and publicity on AI and related matters.\n(2)\tThe Association shall be a corporation.\n(3)\tThe Association shall perform the following duties: Promotion and dissemination of the use of AI technology, AI products, or AI services; Survey on the current state of AI and related matters and on relevant statistics; Establishment and operation of shared facilities for AI business operators, and provision of education for the development of professionals; Support for the overseas expansion of AI business operators and AI-related professionals; Education and publicity for the development and utilization of safe and trustworthy AI; Projects entrusted to the Association under this Act or other statutes; Other projects necessary for achieving the purposes of the establishment of the Association, as prescribed by its articles of incorporation.\n(4)\tThe State and the local government may support funds necessary for the Association\u0026rsquo;s implementation of its projects or subsidize expenses necessary for its operation within the budget where necessary for the development of the AI industry and the creation of a foundation for trust.\n(5)\tThe qualifications for members of the Association, its executive officers, its duties, etc. shall be prescribed by the articles of incorporation; and other matters to be included in the articles of incorporation shall be prescribed by Presidential Decree.\n(6)\tWhere the Minister of Science and ICT grants authorization under paragraph (1), the Minister shall publicly announce the fact.\n(7)\tExcept as provided in this Act, the provisions of the Civil Act governing incorporated associations shall apply mutatis mutandis to the Association. Chapter IV: Ensuring Ai Ethics And Trustworthiness Article 27 (AI Ethics Principles)\n(1)\tThe Government may establish and promulgate AI ethics principles (hereinafter referred to as the \u0026ldquo;Ethics Principles\u0026rdquo;) that include the following matters, as prescribed by Presidential Decree, to promote the dissemination of AI ethics:\nMatters related to AI safety and trustworthiness to ensure that human life, physical health, or mental well-being are not harmed during the process of developing and utilizing AI; Matters related to accessibility that allow all people to freely and conveniently use products, services, etc. incorporating AI technology; Matters related to the development and utilization of AI that contribute to human well-being and prosperity.\n(2)\tThe Minister of Science and ICT shall establish action plans to ensure that the Ethics Principles can be realized by all persons involved in the development and utilization of AI after gathering opinions from various sectors of society and shall disclose, publicize, and educate them.\n(3)\tWhere the head of a central administrative agency or the head of a local government establishes or revises AI ethics standards (referring to statutes or regulations, standards, guidelines, or other instruments related to AI ethics, regardless of their name or form), the Minister of Science and ICT may make recommendations or express opinions on the connectivity and consistency with the Ethics Principles and the action plans under paragraph (2).\nArticle 28 (Establishment of private-sector self-regulatory AI ethics committees)\n(1)\tThe following institutions or organizations may establish a private-sector self-regulatory AI ethics committee (hereinafter referred to as \u0026ldquo;private-sector self-regulatory committee\u0026rdquo;) in order to comply with the Ethics Principles: Educational institutions and research institutes to which persons who conduct AI technology research and development belong; AI business operators; Other AI technology-related institutions prescribed by Presidential Decree.\n(2)\tPrivate-sector self-regulatory committees shall independently perform the following duties: Checking compliance with the Ethics Principles in AI technology research, development, and utilization; Investigation and research on safety, human rights violations, etc. in AI technology research, development, and utilization; Investigation and supervision of the procedures and results of AI technology research, development, and utilization; Provision of education on the Ethics Principles to researchers and employees of the relevant institution or organization; Preparation of sector-specific AI ethics guidelines suitable for AI technology research, development, and utilization; Other duties necessary for the implementation of the Ethics Principles.\n(3)\tThe matters necessary for the composition and operation of the private-sector self-regulatory committee shall be determined autonomously of the relevant institution or organization; provided, the committee shall not be composed of members of a single gender, and shall include persons who have experience and knowledge to evaluate social and ethical validity and persons who are not employed by the relevant institution or organization, respectively.\n(4)\tThe Minister of Science and ICT may prepare and disseminate standard guidelines, etc. for the fair and neutral composition and operation of private-sector self-regulatory committees.\nArticle 29 (Preparation of policy measures to create foundation for trust in AI)\nThe Government shall prepare the following policy measures to minimize the potential risks that AI poses to the daily lives of the people and to create a foundation of trust for the safe use of AI: Creation of a safe and trustworthy environment for the use of AI; Prospects and forecasts regarding the impact of the use of AI on the daily lives of the people and the reorganization of related statutes and regulations and systems; Support for the development and dissemination of safety technologies and certification technologies to ensure the safety and trustworthiness of AI; Provision of education and publicity for the realization of a safe and trustworthy AI society and the practice of AI ethics; Support for AI business operators in the autonomous establishment and implementation of rules related to safety and trustworthiness; Support and dissemination of private activities, such as autonomous cooperation to enhance the safety and trustworthiness of AI and the establishment of ethical guidelines by AI-related organizations composed of AI business operators, users, etc. (hereinafter referred to as \u0026ldquo;organizations, etc.\u0026rdquo;); Other matters prescribed by Presidential Decree to ensure the safety and trustworthiness of AI.\nArticle 30 (Support for verification and certification of AI safety and trustworthiness)\n(1)\tThe Minister of Science and ICT may implement the following projects to support verification and certification activities (hereinafter referred to as \u0026ldquo;verification and certification\u0026rdquo;) voluntarily performed by organizations, etc. to ensure the safety and trustworthiness of AI: Dissemination of guidelines on AI development; Support for research on verification and certification; Support for the construction and operation of equipment and systems used for verification and certification; Support for the training of professionals needed for verification and certification; Other matters prescribed by Presidential Decree to support verification and certification.\n(2)\tThe Minister of Science and ICT may, as prescribed by Presidential Decree, provide related information or administrative and financial support to small and medium enterprises, etc. that intends to obtain verification and certification.\n(3)\tAn AI business operator shall endeavor to obtain verification and certification in advance where the operator provides high-impact AI.\n(4)\tWhere the State agency or other public entity intends to use high-impact AI, it shall give preferential consideration to products or services based on AI that has obtained verification and certification.\nArticle 31 (Obligation to ensure AI transparency)\n(1)\tAn AI business operator that intends to provide a product or service using high-impact AI or generative AI shall notify the user in advance that the product or service is operated based on that AI.\n(2)\tAn AI business operator that provides generative AI or a product or service using it shall indicate that the output was generated by generative AI.\n(3)\tWhere an AI business operator provides outputs, such as synthetic sound, images, or video, that are difficult to distinguish from the real ones, by using an AI system, the operator shall notify or indicate in a manner that users can readily recognize the fact that such outputs have been generated by the AI system. In this case, if the outputs correspond to an artistic or creative work or constitute a part thereof, the fact may be notified or indicated in a manner that does not hinder the exhibition or enjoyment.\n(4)\tOther matters necessary for the prior notification under paragraph (1), the indication under paragraph (2), the method of notification or indication and its exceptions under paragraph (3) shall be prescribed by Presidential Decree.\nArticle 32 (Obligation to ensure AI safety)\n(1)\tAn AI business operator shall implement the following to ensure the safety of an AI system in which the cumulative amount of compute used for training meets or exceeds the threshold prescribed by Presidential Decree: Identification, assessment, and mitigation of risks throughout the entire AI lifecycle; Establishment of a risk management system capable of monitoring and responding to AI safety incidents.\n(2)\tAn AI business operator shall submit the results of the implementation of the matters in the subparagraphs of paragraph (1) to the Minister of Science and ICT.\n(3)\tThe Minister of Science and ICT shall determine and publicly notify the specific implementation methods for the matters in the subparagraphs of paragraph (1) and the matters necessary for submitting the results under paragraph (2).\nArticle 33 (Confirmation of high-impact AI)\n(1)\tWhere an AI business operator provides AI or products and services using the AI, the operator shall review in advance whether the AI falls under the high-impact AI, and if necessary, may request the Minister of Science and ICT to confirm whether it falls under the high-impact AI.\n(2)\tThe Minister of Science and ICT shall, upon receipt of the request under paragraph (1), confirm whether the AI falls under the high-impact AI, and may establish a specialized committee to obtain related advice if necessary.\n(3)\tThe Minister of Science and ICT may establish and disseminate guidelines on criteria, examples, etc. of high-impact AI.\n(4)\tOther matters necessary for the confirmation procedures under paragraph (1) shall be prescribed by Presidential Decree.\nArticle 34 (Responsibilities of business operators regarding high-impact AI)\n(1)\tWhere an AI business operator provides high-impact AI or a product or service using it, the operator shall implement measures, as prescribed by Presidential Decree, that include the following to ensure the safety and trustworthiness of high-impact AI: Establishing and operating risk management measures; Establishing and implementing explanation measures regarding, to the extent technically feasible, the final results derived by the AI, the main criteria utilized to derive the final results of the AI, and the overview of training data used in the development and utilization of the AI; Establishing and operating user protection measures; Ensuring human management and oversight of high-impact AI; Preparing and retaining documents that can verify the contents of the measures taken to ensure the safety and trustworthiness; Other matters deliberated and resolved by the Council to ensure the safety and trustworthiness of high-impact AI.\n(2)\tThe Minister of Science and ICT may determine and publicly notify the details of the measures in the subparagraphs of paragraph (1) and may recommend that AI business operators comply with them.\n(3)\tWhere an AI business operator has implemented measures equivalent to those in the subparagraphs of paragraph (1) as prescribed by Presidential Decree, they shall be deemed to have implemented the measures under paragraph (1).\nArticle 35 (Impact assessment of high-impact AI)\n(1)\tWhere an AI business operator provides products or services using high-impact AI, the operator shall endeavor to assess the impact on the fundamental rights of people in advance (hereinafter referred to as \u0026ldquo;impact assessment\u0026rdquo;). In such cases, the impact assessment shall be conducted in a manner that reflects the characteristics of AI-vulnerable groups, considering the nature of the products or services using high-impact AI. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n(2)\tWhere the State agency or other public entity intends to use products or services using high-impact AI, it shall give preferential consideration to products or services that have undergone impact assessments.\n(3)\tOther matters necessary for the specific content and methods of impact assessments shall be prescribed by Presidential Decree.\nArticle 36 (Designation of domestic representative)\n(1)\tAn AI business operator that has no domicile or place of business in the country and meets the criteria for the number of users, sales revenue, etc. as prescribed by Presidential Decree shall designate a person who acts on behalf of the operator in the following matters (hereinafter referred to as a \u0026ldquo;domestic representative\u0026rdquo;) in writing and shall report it to the Minister of Science and ICT: Submission of implementation results under Article 32(2); Request for confirmation of whether it falls under the high-impact AI under Article 33 (1); Support necessary for implementing the measures to ensure safety and trustworthiness under the subparagraphs of Article 34(1) (including the inspection of the up-to-dateness and accuracy of the documents under subparagraph 5 of that paragraph).\n(2)\tThe domestic representative shall be a person that has a domicile or place of business within the Republic of Korea.\n(3)\tWhere a domestic representative has violated this Act in connection with the subparagraphs of paragraph (1), the AI business operator that designated the domestic representative shall be deemed to have committed the violation. Chapter V: Supplementary Provisions Article 37 (Expansion of financial resources for promotion of the AI industry)\n(1)\tThe State shall prepare a plan to continuously and stably expand the necessary financial resources to effectively promote the master plan and the policy measures, etc. under this Act.\n(2)\tThe Minister of Science and ICT may, if necessary for the promotion of the AI industry, recommend that a public institution provide necessary support for programs, etc. related to the promotion of the AI industry.\n(3)\tThe State and local governments shall take necessary measures to enable the private sector, including enterprises, to actively invest in programs related to the promotion of the AI industry.\n(4)\tThe State and local governments shall endeavor to efficiently execute investment resources, comprehensively considering the development stage, etc. of the AI industry.\nArticle 38 (Compilation of fact-finding surveys, statistics, and indicators)\n(1)\tThe Minister of Science and ICT shall, in consultation with the Minister of Data and Statistics, prepare, manage, and publish fact-finding surveys, statistics, and indicators regarding domestic and international AI and related matters, in conjunction with the statistics under Article 26-2 of the Framework Act on Science and Technology in order to plan, establish, and implement master plans and other policy measures and programs regarding AI and related matters. \u0026lt;Amended on Oct. 1, 2025\u0026gt;\n(2)\tThe Minister of Science and ICT may request cooperation, such as data submission, from the heads of relevant central administrative agencies, heads of local governments, and heads of public institutions for the compilation of the statistics and indicators under paragraph (1). In this case, the head of the agency, local government, or public institution requested to cooperate shall comply therewith unless there is a compelling reasons not to do so.\n(3)\tOther matters necessary for compiling, managing, and publishing fact-finding surveys, statistics, and indicators under paragraph (1) shall be prescribed by Presidential Decree.\nArticle 39 (Delegation of authority and entrustment of tasks)\n(1)\tThe Minister of Science and ICT or the head of a relevant central administrative agency may delegate part of the authority under this Act to the head of a subordinate agency or the Special Metropolitan City Mayor, a Metropolitan City Mayor, a Special Self-Governing City Mayor, a Do Governor, or a Special Self-Governing Province Governor (hereinafter referred to as the \u0026ldquo;Mayor/Do Governor\u0026rdquo; in this Article) as prescribed by Presidential Decree. In this case, the Mayor/Do Governor may redelegate a part of the delegated authority to the head of a Si (including the head of an administrative Si under Article 11(2) of the Special Act on the Establishment of Jeju Special Self-Governing Province and the Development of Free International Free City)/Gun/Gu (the head of a Gu refers to the head of an autonomous Gu).\n(2)\tThe Government may entrust the following tasks to a relevant institution or organization as prescribed by Presidential Decree:\nSupport for programs related to the development and utilization of AI technology under Article 13; Selection and support of projects eligible for support regarding the production, collection, management, distribution, and utilization of training data and the implementation of training data development projects under Article 15(2) and (3); Establishment, operation, and management of the integrated provision system; Matters deemed necessary by the Minister of Science and ICT for the promotion of business start-up under Article 18; Support related to verification and certification under Article 30(2); Compilation of fact-finding surveys, statistics, and indicators under Article 38; Other tasks prescribed by Presidential Decree for the fostering of the AI industry and the dissemination of AI ethics.\nArticle 40 (Fact-finding investigations)\n(1)\tThe Minister of Science and ICT may require an AI business operator to submit relevant data or have public officials under his or her control conduct necessary investigations in any of the following cases: Where any violation of Article 31(2) or (3), Article 32(1) or (2), or Article 34(1) is discovered or suspected; Where a report is received or a complaint is filed regarding a violation of Article 31(2) or (3), Article 32(1) or (2), or Article 34(1).\n(2)\tWhere the Minister of Science and ICT deems it necessary for the investigation under paragraph (1), he or she may authorize public officials of the Ministry to enter the office or place of business of an AI business operator to investigate ledgers, documents, and other data or things. In this case, except for matters prescribed in this Act regarding the content, method, and procedures of the investigation, the provisions of the Framework Act on Administrative Investigations shall apply.\n(3)\tWhere the Minister of Science and ICT recognizes, based on the results of investigations under paragraphs (1) and (2), that an AI business operator has violated this Act, the Minister may order the AI business operator to take necessary measures to cease or correct the violation.\nArticle 41 (Legal fiction as public officials for purposes of applying penalty provisions)\nA member of the Council who is not a public official shall be deemed a public official for purposes of applying penalty provisions under Articles 129 through 132 of the Criminal Act.\n(2)\tThe executive officers and employees of an institution or organization engaged in the tasks entrusted under Article 39(2) shall be deemed public officials for purposes of applying penalty provisions under Articles 127 and 129 through 132 of the Criminal Act. Chapter VI: Penalty Provisions Article 42 (Penalty provisions)\nA person who, in violation of Article 7(9), discloses any secret that he or she has learned in the course of his or her duties to another person or uses such secret for purposes other than those related to his or her duties shall be punished by imprisonment with labor for not more than 3 years or by a fine not exceeding 30 million won.\nArticle 43 (Administrative fines)\n(1)\tAny of the following persons shall be subject to an administrative fine not exceeding 30 million won:\nA person who fails to provide the notification, in violation of Article 31(1); A person who fails to designate a domestic representative, in violation of Article 36(1); A person who fails to comply with an order to cease or correct a violation issued under Article 40(3);\n(2)\tAdministrative fines under paragraph (1) shall be imposed and collected by the Minister of Science and ICT as prescribed by Presidential Decree.\nADDENDA \u0026lt;Act No. 20676, Jan. 21, 2025\u0026gt;\nArticle 1 (Enforcement date)\nThis Act shall enter into force 1 year after the date of its promulgation; provided, the portion regarding digital medical devices under subparagraph 4d of Article 2 under shall enter into force on January 24, 2026.\nArticle 2 (Preparatory actions for enforcing this Act)\nThe commissioning of members of the Council and the establishment of expert standing committees, special committees, advisory committees, and a secretariat necessary for enforcing this Act may be conducted before this Act enters into force.\nArticle 3 (Special cases concerning dedicated institutions)\nAn institution that, at the time this Act enters into force, is operating with budgetary support from the Government to effectively anchor the clustering in relevant regions in accordance with Article 23(1), and that meets the requirements prescribed by Presidential Decree, including organization and personnel, shall be deemed designated as a dedicated institution in accordance with this Act, notwithstanding Article 23(4).\nADDENDA \u0026lt;Act No. 21065, Oct. 1, 2025\u0026gt;\nArticle 1 (Enforcement date)\nThis Act shall enter into force on the date of its promulgation; provided, among the statutes to be amended under Article 7 of the Addenda, any amendment made by this Act to the statutes that were promulgated before this Act enters into force but whose enforcement dates have yet to arrive shall enter into force \u0026hellip; \u0026hellip; on the enforcement date of the respective statute: and 2. Omitted.\nArticles 2 through 6 Omitted.\nArticle 7 Omitted.\nArticle 8 Omitted.\nADDENDUM \u0026lt;Act No. 21311, Jan. 20, 2026\u0026gt;\nThis Act shall enter into force on January 22, 2026; provided, the amended provisions of Article 3(5), Article 6(2)7 and 8, Article 16(3) through (5) (limited to the portion regarding the amended provisions of paragraph (2)2-2), Article 17-2, Article 18, Article 22-3, and the latter part of Article 35(1) shall enter into force 6 months after the date of their promulgation. ","permalink":"https://ai.intlaws.com/en/compliance/other/korea-ai-framework-act/","summary":"Official Korean text of the Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (Act No. 20676, promulgated 21 January 2025; in force 22 January 2026; amended by Act No. 21311 of 20 January 2026), six chapters and two sections, 43 articles plus three sub-numbered articles, with three sets of addenda. The English text on this page is the official translation by the Korea Legislation Research Institute (KLRI). The Korean text is authoritative.","title":"Korea's Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (AI Framework Act)"},{"content":" Version and sources (verifiable)\nItem Content Promulgated 14 March 2025 by the Cyberspace Administration of China, the Ministry of Industry and Information Technology, the Ministry of Public Security and the National Radio and Television Administration Effective 1 September 2025 Structure 14 articles Currently effective Yes (as of 2026-09-22) Chinese original https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm English version No official English translation published. This English text is a translation by our editorial team, cross-checked article by article against the official Chinese text; it is not an official translation and is for reference only. Verification Retrieved 2026-09-22; 14 articles, correspondence with the Chinese text verified one-for-one, no gaps Article 1 These Measures are formulated in accordance with the Cybersecurity Law of the People\u0026rsquo;s Republic of China, the Provisions on the Administration of Algorithmic Recommendations in Internet Information Services, the Provisions on the Administration of Deep Synthesis of Internet Information Services, the Interim Measures for the Administration of Generative Artificial Intelligence Services and other laws, administrative regulations and departmental rules, for the purposes of promoting the sound development of artificial intelligence, regulating the labelling of AI-generated synthetic content, protecting the lawful rights and interests of citizens, legal persons and other organisations, and safeguarding the public interest.\nArticle 2 These Measures apply to labelling activities for AI-generated synthetic content carried out by providers of internet information services (hereinafter \u0026ldquo;service providers\u0026rdquo;) that fall within the circumstances provided for in the Provisions on the Administration of Algorithmic Recommendations in Internet Information Services, the Provisions on the Administration of Deep Synthesis of Internet Information Services, and the Interim Measures for the Administration of Generative Artificial Intelligence Services.\nArticle 3 AI-generated synthetic content means information such as text, images, audio, video and virtual scenes generated or synthesised by means of artificial intelligence technology.\nLabelling of AI-generated synthetic content includes explicit labels and implicit labels.\nAn explicit label means a label added to the generated synthetic content or to the interface of an interactive scenario, presented in the form of text, sound, graphics or otherwise, and clearly perceivable by users.\nAn implicit label means a label added to the file data of the generated synthetic content by technical measures, and not readily perceivable by users.\nArticle 4 Where the generative synthetic services provided by a service provider fall within the circumstances provided for in Article 17, paragraph 1 of the Provisions on the Administration of Deep Synthesis of Internet Information Services, the service provider shall add explicit labels to the generated synthetic content in accordance with the following requirements:\n(1) add a text prompt, a generic symbol prompt or a similar label at the beginning, the end or an appropriate position in the middle of the text, or add a conspicuous prompt label in the interactive scenario interface or around the text;\n(2) add a voice prompt, an audio rhythm prompt or a similar label at the beginning, the end or an appropriate position in the middle of the audio, or add a conspicuous prompt label in the interactive scenario interface;\n(3) add a conspicuous prompt label at an appropriate position on the image;\n(4) add a conspicuous prompt label at an appropriate position on the opening frame of the video and around the video playback area, and may add a conspicuous prompt label at appropriate positions at the end and in the middle of the video;\n(5) when presenting a virtual scene, add a conspicuous prompt label at an appropriate position on the opening frame, and may add a conspicuous prompt label at an appropriate position during the continued provision of the virtual scene service;\n(6) in other generative synthetic service scenarios, add a conspicuous prompt label according to the characteristics of the application concerned.\nWhere a service provider provides functions such as downloading, copying and exporting generated synthetic content, it shall ensure that the file contains explicit labels meeting the requirements.\nArticle 5 A service provider shall, in accordance with Article 16 of the Provisions on the Administration of Deep Synthesis of Internet Information Services, add implicit labels in the file metadata of the generated synthetic content; implicit labels shall include the attribute information of the generated synthetic content, the name or code of the service provider, the content number and other information on the elements of production.\nService providers are encouraged to add implicit labels in the form of digital watermarks and the like to generated synthetic content.\nFile metadata means descriptive information embedded in the file header in a specific encoding format, used to record information such as the source, attributes and purpose of the file.\nArticle 6 Service providers that provide online information content dissemination services shall take the following measures to regulate the dissemination of generated synthetic content:\n(1) verify whether the file metadata contains an implicit label; where the file metadata clearly indicates that the content is generated synthetic content, add, in an appropriate manner, a conspicuous prompt label around the published content to clearly remind the public that the content is generated synthetic content;\n(2) where no implicit label is verified in the file metadata but the user declares the content to be generated synthetic content, add, in an appropriate manner, a conspicuous prompt label around the published content to remind the public that the content may be generated synthetic content;\n(3) where no implicit label is verified in the file metadata and the user has not declared the content to be generated synthetic content, but the service provider providing online information content dissemination services detects an explicit label or other traces of generation or synthesis, identify the content as suspected generated synthetic content and add, in an appropriate manner, a conspicuous prompt label around the published content to remind the public that the content is suspected to be generated synthetic content;\n(4) provide the necessary labelling functions and remind users to voluntarily declare whether the content they publish contains generated synthetic content.\nWhere any of the circumstances in items (1) to (3) of the preceding paragraph applies, the attribute information of the generated synthetic content, the name or code of the dissemination platform, the content number and other information on dissemination elements shall be added to the file metadata.\nArticle 7 When reviewing an internet application for listing or going online, an internet application distribution platform shall require the provider of the internet application service to state whether it provides AI-generated synthetic services. Where the provider of the internet application service provides AI-generated synthetic services, the internet application distribution platform shall verify the materials relating to the labelling of its generated synthetic content.\nArticle 8 A service provider shall clearly explain in its user service agreement the normative content of the labelling of generated synthetic content, such as the method and style of labelling, and shall prompt users to carefully read and understand the relevant labelling management requirements.\nArticle 9 Where a user applies to a service provider for generated synthetic content that does not carry explicit labels, the service provider may, after making clear the user\u0026rsquo;s labelling obligations and responsibilities for use through the user agreement, provide generated synthetic content without explicit labels, and shall retain the relevant logs, including information on the recipient of the provision, for not less than six months in accordance with law.\nArticle 10 Where a user publishes generated synthetic content using an online information content dissemination service, the user shall voluntarily declare it and use the labelling functions provided by the service provider to label it.\nNo organisation or individual may maliciously delete, tamper with, forge or conceal the labels of generated synthetic content provided for in these Measures, may provide tools or services for others to carry out the aforesaid malicious acts, or may harm the lawful rights and interests of others through improper labelling means.\nArticle 11 Where a service provider carries out labelling activities, it shall also comply with the requirements of relevant laws, administrative regulations, departmental rules and mandatory national standards.\nArticle 12 When completing formalities such as algorithm filing and security assessment, a service provider shall, in accordance with these Measures, provide materials relating to the labelling of generated synthetic content, strengthen the sharing of labelling information, and provide support and assistance for the prevention and combating of relevant illegal and criminal activities.\nArticle 13 Where these Measures are violated, the relevant competent departments for cyberspace administration, telecommunications, public security and radio and television shall, in accordance with their duties, deal with the matter in accordance with the provisions of relevant laws, administrative regulations and departmental rules.\nArticle 14 These Measures shall come into force on 1 September 2025.\n","permalink":"https://ai.intlaws.com/en/compliance/china/ai-generated-content-labelling-measures/","summary":"Full text of the Measures for the Labelling of AI-Generated Synthetic Content (promulgated 14 March 2025, effective 1 September 2025), 14 articles: definitions of explicit and implicit labels, labelling duties across six content scenarios, verification duties of dissemination platforms, and the prohibition on providing tools that remove labels. English translation by our editorial team (non-official, cross-checked article by article against the official Chinese text).","title":"Measures for the Labelling of AI-Generated Synthetic Content"},{"content":" Version and sources (verifiable)\nItem Content Promulgated 7 July 2022 by the Cyberspace Administration of China (Order No. 11); deliberated and adopted at the 10th executive meeting of the CAC in 2022 on 19 May 2022; signed by Zhuang Rongwen, Director of the CAC Effective 1 September 2022 Structure 20 articles Currently effective Yes, as amended in operation by the Provisions on Promoting and Regulating Cross-Border Data Flows (2024) — see Article 13 of those Provisions, which prevails in case of inconsistency Chinese original https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm English version No official English translation published. This English text is a translation by our editorial team, cross-checked article by article against the official Chinese text; it is not an official translation and is for reference only. Verification Retrieved 2026-09-22; 20 articles, correspondence with the Chinese text verified one-for-one, no gaps Article 1 These Measures are formulated in accordance with the Cybersecurity Law of the People\u0026rsquo;s Republic of China, the Data Security Law of the People\u0026rsquo;s Republic of China, the Personal Information Protection Law of the People\u0026rsquo;s Republic of China and other laws and regulations, for the purposes of regulating data export activities, protecting the rights and interests of personal information, safeguarding national security and the public interest, and promoting the secure and free flow of data across borders.\nArticle 2 These Measures apply to the security assessment of data processors providing overseas important data and personal information collected and generated in the course of operations within the territory of the People\u0026rsquo;s Republic of China. Where laws and administrative regulations provide otherwise, those provisions shall prevail.\nArticle 3 The security assessment of data export adheres to combining prior assessment with continuous supervision, and combining self-assessment of risks with security assessment, so as to prevent data export security risks and ensure the lawful, orderly and free flow of data.\nArticle 4 Where a data processor provides data overseas and any of the following circumstances applies, it shall, through the cyberspace administration department of the province where it is located, report to the national cyberspace administration department for the security assessment of data export:\n(1) the data processor provides important data overseas;\n(2) a critical information infrastructure operator, or a data processor that processes the personal information of more than 1,000,000 individuals, provides personal information overseas;\n(3) a data processor that has cumulatively provided overseas the personal information of 100,000 individuals, or the sensitive personal information of 10,000 individuals, since 1 January of the previous year, provides personal information overseas;\n(4) other circumstances requiring a report for the security assessment of data export as provided by the national cyberspace administration department.\nArticle 5 Before reporting for the security assessment of data export, a data processor shall carry out a self-assessment of the risks of data export, focusing on the following matters:\n(1) the lawfulness, legitimacy and necessity of the purposes, scope and methods of the data export and of the overseas recipient\u0026rsquo;s processing of the data;\n(2) the scale, scope, categories and sensitivity of the exported data, and the risks that the data export may pose to national security, the public interest, and the lawful rights and interests of individuals or organisations;\n(3) the responsibilities and obligations undertaken by the overseas recipient and whether its management and technical measures and capabilities for performing those responsibilities and obligations can guarantee the security of the exported data;\n(4) the risks of the exported data being tampered with, destroyed, leaked, lost, transferred, or illegally obtained or illegally used during and after export, and whether the channels for safeguarding personal information rights and interests are unobstructed;\n(5) whether the contract relating to data export or other documents with legal effect (hereinafter collectively \u0026ldquo;legal documents\u0026rdquo;) to be concluded with the overseas recipient fully stipulate the responsibilities and obligations for data security protection;\n(6) other matters that may affect the security of the data export.\nArticle 6 The following materials shall be submitted when reporting for the security assessment of data export:\n(1) the application form;\n(2) the report on the self-assessment of the risks of data export;\n(3) the legal documents to be concluded between the data processor and the overseas recipient;\n(4) other materials required for the security assessment work.\nArticle 7 The provincial cyberspace administration department shall complete a completeness check within 5 working days from the date of receipt of the application materials. Where the application materials are complete, it shall submit them to the national cyberspace administration department; where the application materials are incomplete, it shall return them to the data processor and inform it, in a single notification, of the materials to be supplemented.\nThe national cyberspace administration department shall, within 7 working days from the date of receipt of the application materials, decide whether to accept the application and notify the data processor in writing.\nArticle 8 The security assessment of data export focuses on assessing the risks that data export activities may pose to national security, the public interest, and the lawful rights and interests of individuals or organisations, mainly including the following matters:\n(1) the lawfulness, legitimacy and necessity of the purposes, scope and methods of the data export;\n(2) the impact of the data security protection policies, laws and regulations and the cybersecurity environment of the country or region where the overseas recipient is located on the security of the exported data, and whether the overseas recipient\u0026rsquo;s level of data protection meets the requirements of the laws, administrative regulations and mandatory national standards of the People\u0026rsquo;s Republic of China;\n(3) the scale, scope, categories and sensitivity of the exported data, and the risks of the data being tampered with, destroyed, leaked, lost, transferred, or illegally obtained or illegally used during and after export;\n(4) whether data security and personal information rights and interests can be fully and effectively safeguarded;\n(5) whether the legal documents to be concluded between the data processor and the overseas recipient fully stipulate the responsibilities and obligations for data security protection;\n(6) compliance with Chinese laws, administrative regulations and departmental rules;\n(7) other matters that the national cyberspace administration department considers necessary to assess.\nArticle 9 A data processor shall clearly stipulate in the legal documents concluded with the overseas recipient the responsibilities and obligations for data security protection, including at least the following:\n(1) the purposes and methods of the data export and the scope of the data, and the purposes and methods of the overseas recipient\u0026rsquo;s processing of the data;\n(2) the place and period of storage of the data overseas, and the measures for handling the exported data upon expiry of the storage period, completion of the agreed purposes, or termination of the legal documents;\n(3) binding requirements on the overseas recipient for the onward transfer of the exported data to other organisations or individuals;\n(4) the security measures to be taken where the overseas recipient undergoes a substantive change in actual control or business scope, or where changes in the data security protection policies, laws and regulations and the cybersecurity environment of the country or region where it is located, or other force majeure circumstances, make it difficult to guarantee data security;\n(5) the remedial measures, liability for breach and methods of dispute resolution for breach of the data security protection obligations agreed in the legal documents;\n(6) the requirements for properly carrying out emergency response where the exported data is at risk of being tampered with, destroyed, leaked, lost, transferred, or illegally obtained or illegally used, and the ways and means of safeguarding individuals\u0026rsquo; ability to protect their personal information rights and interests.\nArticle 10 After accepting a report, the national cyberspace administration department shall organise the relevant departments of the State Council, provincial cyberspace administration departments and specialised agencies to conduct the security assessment according to the circumstances of the report.\nArticle 11 In the course of the security assessment, where it is found that the application materials submitted by the data processor do not meet the requirements, the national cyberspace administration department may require it to supplement or correct them. Where the data processor fails to supplement or correct them without justified reasons, the national cyberspace administration department may terminate the security assessment.\nThe data processor is responsible for the authenticity of the materials it submits; where it deliberately submits false materials, the assessment shall be treated as failed and corresponding legal liability shall be pursued in accordance with law.\nArticle 12 The national cyberspace administration department shall complete the security assessment of data export within 45 working days from the date of issuing the written notice of acceptance to the data processor; where the circumstances are complex or materials need to be supplemented or corrected, the period may be appropriately extended and the data processor shall be informed of the estimated extension.\nThe assessment result shall be notified to the data processor in writing.\nArticle 13 Where a data processor objects to the assessment result, it may, within 15 working days of receipt of the assessment result, apply to the national cyberspace administration department for a re-assessment; the re-assessment result is final.\nArticle 14 The result of a passed security assessment of data export is valid for 2 years, counted from the date on which the assessment result is issued. Where any of the following circumstances occurs within the validity period, the data processor shall re-report for assessment:\n(1) changes in the purposes, methods, scope and categories of the data provided overseas or in the purposes and methods of the overseas recipient\u0026rsquo;s processing of the data affect the security of the exported data, or the period of storage of personal information and important data overseas is extended;\n(2) changes in the data security protection policies, laws and regulations and the cybersecurity environment of the country or region where the overseas recipient is located, other force majeure circumstances, changes in the actual control of the data processor or the overseas recipient, or changes to the legal documents between the data processor and the overseas recipient, affect the security of the exported data;\n(3) other circumstances affecting the security of the exported data occur.\nWhere the validity period expires and the data processor needs to continue the data export activities, it shall re-report for assessment 60 working days before the expiry of the validity period.\nArticle 15 Relevant institutions and personnel participating in the security assessment work shall, in accordance with law, keep confidential the state secrets, personal privacy, personal information, trade secrets, confidential commercial information and other data learned in the performance of their duties, and shall not disclose them or illegally provide them to or illegally use them for others.\nArticle 16 Where any organisation or individual discovers that a data processor provides data overseas in violation of these Measures, it may report the matter to the cyberspace administration department at or above the provincial level.\nArticle 17 Where the national cyberspace administration department discovers that data export activities that have passed the assessment no longer meet the data export security management requirements in actual processing, it shall notify the data processor in writing to terminate the data export activities. Where the data processor needs to continue the data export activities, it shall rectify in accordance with the requirements and re-report for assessment after completion of the rectification.\nArticle 18 Where these Measures are violated, the matter shall be dealt with in accordance with the Cybersecurity Law of the People\u0026rsquo;s Republic of China, the Data Security Law of the People\u0026rsquo;s Republic of China, the Personal Information Protection Law of the People\u0026rsquo;s Republic of China and other laws and regulations; where a crime is constituted, criminal liability shall be pursued in accordance with law.\nArticle 19 For the purposes of these Measures, \u0026ldquo;important data\u0026rdquo; means data that, once tampered with, destroyed, leaked, or illegally obtained or illegally used, may endanger national security, economic operation, social stability, public health and safety, and the like.\nArticle 20 These Measures shall come into force on 1 September 2022. Where data export activities already carried out before these Measures come into force do not comply with these Measures, rectification shall be completed within 6 months from the date these Measures come into force.\nRelationship between provisions (editorial note, not part of the legal text)\nArticle 19 of the Measures provides the identification standard for \u0026ldquo;important data\u0026rdquo;; Article 2 of the 2024 Provisions and Article 37 of the Regulations make the reporting obligation conditional on notification or public designation by the regulator. The two operate as definition and procedure and do not conflict: it is the regulator, not the processor, that designates important data.\n","permalink":"https://ai.intlaws.com/en/compliance/china/data-export-security-assessment-measures/","summary":"Full text of the Measures for the Security Assessment of Data Export (Cyberspace Administration of China Order No. 11, promulgated 7 July 2022, effective 1 September 2022), 20 articles: the triggers for filing, the self-assessment of risks, materials required, the assessment factors, mandatory clauses in legal documents, the 45-working-day time limit, and the two-year validity of assessment results. English translation by our editorial team (non-official, cross-checked article by article against the official Chinese text).","title":"Measures for the Security Assessment of Data Export"},{"content":" Version and sources (verifiable)\nItem Content Adopted 30th Meeting of the Standing Committee of the 13th NPC, August 20, 2021 In force November 1, 2021 Currently effective Yes (no amendment as of 2026-09-22) Chinese original source Cyberspace Administration of China: https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm English translation source NPC official English site, \u0026ldquo;Laws (Translation for Reference Only)\u0026rdquo;: http://en.npc.gov.cn.cdurl.cn/2021-12/29/c_694559.htm (3 pages) Nature of translation Published on the official NPC English site and marked \u0026ldquo;Translation for Reference Only\u0026rdquo; Verification Retrieved 2026-09-22; 8 chapters / 74 articles; article numbers match the Chinese original one-for-one, with no gaps Chapter I General Provisions Article 1 This Law is enacted in accordance with the Constitution for the purposes of protecting the rights and interests on personal information, regulating personal information processing activities, and promoting reasonable use of personal information.\nArticle 2 The personal information of natural persons shall be protected by law. No organization or individual may infringe upon natural persons\u0026rsquo; rights and interests on their personal information.\nArticle 3 This Law shall apply to the processing of personal information of natural persons within the territory of the People\u0026rsquo;s Republic of China. This Law shall also apply to the processing outside the territory of the People\u0026rsquo;s Republic of China of the personal information of natural persons within the territory of the People\u0026rsquo;s Republic of China, under any of the following circumstances:\n(1) for the purpose of providing products or services for natural persons inside the People\u0026rsquo;s Republic of China;\n(2) analyzing or evaluating the behaviors of natural persons within the territory of the People\u0026rsquo;s Republic of China; and\n(3) any other circumstance as provided by any law or administrative regulation.\nArticle 4 \u0026ldquo;Personal information\u0026rdquo; refers to various information related to an identified or identifiable natural person recorded electronically or by other means, but does not include anonymized information. Personal information processing includes personal information collection, storage, use, processing, transmission, provision, disclosure and deletion, among others.\nArticle 5 Personal information shall be processed according to law when it is necessary, with justified reason, and in good faith, and the processing may not involve misguidance, fraud, coercion, and the like.\nArticle 6 Personal information processing shall be based on explicit and reasonable purposes and directly related to those purposes, and shall exert the minimum impacts on the rights and interests of individuals. The collection of personal information shall be limited to the minimum scope required by the purpose of processing, and personal information may not be collected excessively.\nArticle 7 The principles of openness and transparency shall be observed in the processing of personal information, the rules for processing personal information shall be disclosed, and the purposes, means, and scope of processing shall be explicitly indicated.\nArticle 8 The quality of personal information shall be guaranteed in personal information processing, to avoid adverse impacts on the rights and interests of individuals caused by inaccurate and incomplete personal information.\nArticle 9 Personal information processors shall be responsible for their personal information processing activities and take necessary measures to ensure the security of the personal information they process.\nArticle 10 No organization or individual shall illegally collect, use, process, or transmit the personal information of other persons, or illegally trade, provide or disclose the personal information of other persons, or engage in personal information processing activities that endanger national security or harm public interests.\nArticle 11 The state shall establish and improve the personal information protection system to prevent and punish infringements upon the rights and interests on personal information, strengthen publicity and education on personal information protection, and promote a favorable environment for the government, enterprises, relevant industry organizations, and the public to jointly participate in personal information protection.\nArticle 12 The state will actively engage in the development of international rules on personal information protection, promote the international exchanges and cooperation in personal information protection, and encourage the mutual recognition of personal information protection rules and standards, among others, with other countries, regions, and international organizations.\nChapter II Personal Information Processing Rules Section 1 General Rules Article 13 A personal information processor can process personal information of an individual only if one of the following circumstances exists: (1) the individual\u0026rsquo;s consent has been obtained;\n(2) the processing is necessary for the conclusion or performance of a contract in which the individual is a party, or necessary for human resources management in accordance with the labor rules and regulations established in accordance with the law and the collective contracts signed in accordance with the law;\n(3) the processing is necessary for the performance of statutory duties or obligations;\n(4) the processing is necessary for the response to public health emergencies, or for the protection of life, health, and property safety of natural persons in emergencies;\n(5) the personal information is reasonably processed for news reporting, media supervision, and other activities conducted in the public interest;\n(6) the personal information disclosed by the individual himself or other legally disclosed personal information of the individual is reasonably processed in accordance with this Law; and\n(7) other circumstances as provided by laws or administrative regulations.\nIndividual consent shall be obtained for processing personal information if any other relevant provisions of this Law so provide, except under the circumstances specified in Subparagraphs (2) to (7) of the preceding paragraph.\nArticle 14 Where personal information processing is based on individual consent, the individual consent shall be voluntary, explicit, and fully informed. Where any other law or administrative regulation provides that an individual\u0026rsquo;s separate consent or written consent must be obtained for processing personal information, such provisions shall apply. In the case of any change of the purposes or means of personal information processing, or the category of processed personal information, a new consent shall be obtained from the individual.\nArticle 15 Where personal information processing is based on individual consent, an individual shall have the right to withdraw his consent. Personal information processors shall provide convenient ways for individuals to withdraw their consents. The withdrawal of consent shall not affect the validity of the processing activities conducted based on consent before it is withdrawn.\nArticle 16 A personal information processor shall not refuse to provide products or services for an individual on the grounds that the individual withholds his consent for the processing of his personal information or has withdrawn his consent for the processing of personal information, except where the processing of personal information is necessary for the provision of products or services.\nArticle 17 A personal information processor shall, before processing personal information, truthfully, accurately and fully inform an individual of the following matters in a easy-to-notice manner and in clear and easy-to-understand language: (1) the name and contact information of the personal information processor;\n(2) the purposes and means of personal information processing, and the categories and storage periods of the personal information to be processed;\n(3) the methods and procedures for the individual to exercise his rights as provided in this Law; and\n(4) other matters that the individual should be notified of as provided by laws and administrative regulations.\nWhere any matter as set forth in the preceding paragraph changes, the individual shall be informed of the change.\nWhere the personal information processor informs an individual of the matters specified in the first paragraph by formulating personal information processing rules, the processing rules shall be made public and be easy to consult and save.\nArticle 18 When processing personal information, personal information processors are permitted not to inform individuals of the matters specified in the first paragraph of the preceding article where laws or administrative regulations require confidentiality or provide no requirement for such notification. Where it is impossible to notify individuals in a timely manner in a bid to protect natural persons\u0026rsquo; life, health and property safety in case of emergency, the personal information processors shall notify them without delay after the emergency is removed.\nArticle 19 Except as otherwise provided by laws and administrative regulations, the storage period of personal information shall be the minimum time necessary to achieve the purpose of processing.\nArticle 20 Where two or more personal information processors jointly determine the purposes and means of processing certain personal information, they shall reach an agreement on their respective rights and obligations in processing the personal information. However, this agreement shall not affect an individual\u0026rsquo;s request to any one of them to exercise his rights as provided in this Law. Where, in jointly processing certain personal information, a processor infringes the rights and interests on personal information and causes damages, other personal information processors shall bear joint and several liability in accordance with law.\nArticle 21 A personal information processor entrusting the processing of certain personal information to a party shall reach an agreement with the entrusted party on the purposes, period and means of processing, the categories of personal information to be processed and the protection measures, as well as the rights and obligations of both parties, among others, and shall supervise the personal information processing activities of the entrusted party. The entrusted party shall process personal information in accordance with the agreement and may not process personal information beyond the purposes, means and other conditions as agreed upon. Where the entrustment contract has not taken effect, or is invalid, or is revoked or terminated, the entrusted party shall return the personal information in question to the personal information processor or delete it and shall not retain the personal information.\nWithout the consent of the personal information processor, the entrusted party may not sub-contract the processing of personal information to any other party.\nArticle 22 Where a personal information processor needs to transfer personal information due to a merger, division, dissolution, or bankruptcy or for other reasons, the processor shall inform the individuals of the name and contact information of the recipient of the transferred personal information. The recipient shall continue to perform the obligations of the said personal information processor. Any change of the original purposes or means of processing by the recipient shall be subject to individual consent in accordance with this Law.\nArticle 23 To provide personal information for any other processor, a personal information processor shall inform the individuals of the recipient\u0026rsquo;s name and contact information, the purposes and means of processing and the categories of personal information to be processed, and shall obtain the individuals\u0026rsquo; separate consent. The recipient shall process personal information within the scope of the purposes, means, and categories of personal information mentioned above. Any change of the purposes or means of processing by the recipient shall be subject to individual consent in accordance with this Law.\nArticle 24 Personal information processors using personal information for automated decision making shall ensure the transparency of the decision making and the fairness and impartiality of the results, and may not apply unreasonable differential treatment to individuals in terms of transaction prices and other transaction conditions. Information push and commercial marketing to individuals based on automated decision making shall be simultaneously accompanied by options not specific to their personal characteristics or with convenient means for individuals to refuse.\nWhere a decision that may have a significant impact on an individual\u0026rsquo;s rights and interests is made through automated decision making, the individual shall have the right to request clarification from the personal information processor and the right to refuse the processor for making the decision only through automated decision making.\nArticle 25 Personal information processors shall not disclose the personal information they process, except where separate consents has been obtained from the individuals. 1 2 3 \u0026gt;\nArticle 26 Image collection and personal identification equipment in public places shall be installed only when it is necessary for the purpose of maintaining public security, and shall be installed in compliance with the relevant provisions of the state and with prominent reminders. The personal images and identification information collected can only be used for the purpose of maintaining public security and, unless the individuals\u0026rsquo; separate consents are obtained, shall not be used for any other purpose.\nArticle 27 A personal information processor may reasonably process the personal information disclosed by an individual himself or other legally disclosed personal information, except where the individual expressly refuses. Where the processing of disclosed personal information may have a significant impact on an individual\u0026rsquo;s rights and interests, the personal information processors shall first obtain the individual\u0026rsquo;s consent in accordance with the provisions of this Law.\nSection 2 Rules on Processing Sensitive Personal Information Article 28 \u0026ldquo;Sensitive personal information\u0026rdquo; is personal information that once leaked or illegally used, may easily lead to the infringement of the personal dignity of a natural person or may endanger his personal safety or property, including information such as biometrics, religious belief, specific identity, medical health status, financial accounts, and the person\u0026rsquo;s whereabouts, as well as the personal information of a minor under the age of 14 years. Personal information processors can process sensitive personal information only when there is a specific purpose and when it is of necessity, under the circumstance where strict protective measures are taken.\nArticle 29 For the processing of sensitive personal information, individual\u0026rsquo;s separate consent shall be obtained. Where other laws or administrative regulations provide that written consent shall be obtained for the processing of sensitive personal information, such provisions shall prevail.\nArticle 30 In addition to the matters specified in the first paragraph of Article 17 of this Law, a processor processing sensitive personal information shall notify an individual of the necessity of processing his sensitive personal information and the impact it has on his rights and interests, except where such notification is not required in accordance with the provisions of this Law.\nArticle 31 To process the personal information of minors under the age of 14, personal information processors shall obtain the consent of the parents or other guardians of the minors. Personal information processors processing the personal information of minors under the age of 14 shall develop special rules for processing such personal information.\nArticle 32 Where other laws or administrative regulations provide that relevant administrative permit shall be obtained for the processing of sensitive personal information or impose other restrictions, such provisions shall prevail.\nSection 3 Special Provisions on the Processing of Personal Information by State Organs Article 33 This Law shall apply to the processing of personal information by state organs; where there are special provisions in this Section, the provisions of this Section shall prevail.\nArticle 34 When state organs process personal information in order to perform their statutory duties, they shall act in accordance with the authority and procedures prescribed by laws and administrative regulations, and shall not exceed the scope and limits necessary to perform their statutory duties.\nArticle 35 When state organs process personal information in order to perform their statutory duties, they shall fulfill the obligation of notification in accordance with the provisions of this Law, except under the circumstances specified in the first paragraph of Article 18 of this Law or where notification will hinder the state organs from performing their statutory duties.\nArticle 36 Personal information processed by state organs shall be stored within the territory of the People\u0026rsquo;s Republic of China. A security assessment shall be conducted where it is truly necessary to provide such information for any party outside of the territory of the People\u0026rsquo;s Republic of China. In the security assessment the relevant departments shall provide support and assistance if so requested.\nArticle 37 Where organizations authorized by laws or regulations with the function of administering public affairs process personal information in order to fulfill their statutory duties, the provisions herein on the processing of personal information by state organs shall apply.\nChapter III Rules on Provision of Personal Information Across Border Article 38 A personal information processor that truly needs to provide personal information for a party outside the territory of the People\u0026rsquo;s Republic of China for business sake or other reasons, shall meet one of the following requirements: (1) passing the security assessment organized by the national cyberspace department in accordance with Article 40 of this Law;\n(2) obtaining personal information protection certification from the relevant specialized institution according to the provisions issued by the national cyberspace department;\n(3) concluding a contract stipulating both parties\u0026rsquo; rights and obligations with the overseas recipient in accordance with the standard contract formulated by the national cyberspace department; and\n(4) meeting other conditions set forth by laws and administrative regulations and by the national cyberspace department.\nWhere an international treaty or agreement that the People\u0026rsquo;s Republic of China has concluded or acceded to stipulates conditions for providing personal information for a party outside the territory of the People\u0026rsquo;s Republic of China, such stipulations may be followed.\nThe personal information processor shall take necessary measures to ensure that the personal information processing activities of the overseas recipient meet the personal information protection standards set forth in this Law.\nArticle 39 Where a personal information processor provides personal information for any party outside the territory of the People\u0026rsquo;s Republic of China, the processor shall inform the individuals of the overseas recipient\u0026rsquo;s name and contact information, the purposes and means of processing, the categories of personal information to be processed, as well as the methods and procedures for the individuals to exercise their rights as provided in this Law over the overseas recipient, etc., and shall obtain individual\u0026rsquo;s separate consent.\nArticle 40 Critical information infrastructure operators and the personal information processors that process personal information up to the amount prescribed by the national cyberspace department shall store domestically the personal information collected and generated within the territory of the People\u0026rsquo;s Republic of China. Where it is truly necessary to provide the information for a party outside the territory of the People\u0026rsquo;s Republic of China, the matter shall be subjected to security assessment organized by the national cyberspace department. Where laws, administrative regulations, or the provisions issued by the national cyberspace department provide that security assessment is not necessary, such provisions shall prevail.\nArticle 41 The competent authorities of the People\u0026rsquo;s Republic of China shall handle foreign judicial or law enforcement authorities\u0026rsquo; requests for personal information stored within China in accordance with relevant laws and the international treaties and agreements concluded or acceded to by the People\u0026rsquo;s Republic of China, or under the principle of equality and reciprocity. Without the approval of the competent authorities of the People\u0026rsquo;s Republic of China, no organization or individual shall provide data stored in the territory of the People\u0026rsquo;s Republic of China for any foreign judicial or law enforcement authority.\nArticle 42 Where overseas organizations or individuals engage in personal information processing activities, which infringe upon the rights and interests of citizens of the People\u0026rsquo;s Republic of China on personal information or endanger the national security or public interests of the People\u0026rsquo;s Republic of China, the national cyberspace department may include them in a list of restricted or prohibited recipients of personal information, publicize the list, and take measures such as restricting or prohibiting the provision of personal information for such organizations and individuals.\nArticle 43 Where any country or region adopts any prohibitive, restrictive or other similar discriminatory measures against the People\u0026rsquo;s Republic of China in terms of personal information protection, the People\u0026rsquo;s Republic of China may take countermeasures against the aforesaid country or region based on actual situations.\nChapter IV Individuals\u0026rsquo; Rights in Personal Information Processing Activities Article 44 Individuals shall have the right to be informed, the right to make decisions on the processing of their personal information, and the right to restrict or refuse the processing of their personal information by others, except as otherwise provided by laws or administrative regulations.\nArticle 45 Individuals shall have the right to consult and duplicate their personal information from personal information processors, except under circumstances as set out in the first paragraph of Article 18 and Article 35 of this Law. Where an individual requests the consultation or duplication of his personal information, the requested personal information processor shall provide such information in a timely manner.\nWhere an individual requests the transfer of his personal information to a designated personal information processor, which meets the requirements of national cyberspace department for transferring personal information , the requested personal information processor shall provide means for the transfer.\nArticle 46 Where an individual discovers that his personal information is incorrect or incomplete, he shall have the right to request the personal information processors to rectify or supplement relevant information. Where an individual requests the rectification or supplementation of his personal information, the personal information processors shall verify the information in question, and make rectification or supplementation in a timely manner.\nArticle 47 In any of the following circumstances, a personal information processor shall take the initiative to erase personal information, and an individual has the right to request the deletion of his personal information if the personal information processor fails to erase the information: (1) the purposes of processing have been achieved or cannot be achieved, or such information is no longer necessary for achieving the purposes of processing;\n(2) the personal information processor ceases to provide products or services, or the storage period has expired;\n(3) the individual withdraws his consent;\n(4) the personal information processor processes personal information in violation of laws, administrative regulations, or agreements; or\n(5) other circumstances as provided by laws and administrative regulations.\nWhere the storage period provided by any law or administrative regulation has not expired, or it is difficult to erase personal information technically, the personal information processor shall cease the processing of personal information other than storing and taking necessary security protection measures for such information.\nArticle 48 An individuals has the right to request a personal information processor to interpret the personal information processing rules developed by the latter.\nArticle 49 The close relatives of a deceased natural person may, for their own legal and legitimate interests, exercise the rights to handle the personal information of the deceased, such as consultation, duplication, rectification, and deletion, as provided in this Chapter, except as otherwise arranged by the deceased before death.\nArticle 50 A personal information processor shall establish the mechanism for receiving and handling individuals\u0026rsquo; requests for exercising their rights. Where an individual\u0026rsquo;s request is rejected, the reasons therefor shall be given. Where an individual\u0026rsquo;s request to exercise his rights is rejected by a personal information processor, the individual may file a lawsuit with the people\u0026rsquo;s court in accordance with the law.\nChapter V Obligations of Personal Information Processors Article 51 Personal information processors shall take the following measures to ensure that their personal information processing activities are in compliance with laws and administrative regulations based on the purpose and means of processing, the categories of personal information to be processed, the impact on personal rights and interests, and the potential security risks, among others, and shall prevent unauthorized access to, as well as breach, tampering or loss of any personal information: (1) formulating internal management system and operational procedures;\n(2) implementing classified management of personal information;\n(3) adopting corresponding security technical measures such as encryption and de-identification;\n(4) reasonably determining the operational authority of personal information processing, and regularly conducting safety education and training for practitioners;\n(5) formulating contingent plans for personal information security emergencies and organizing the implementation of such plans; and\n(6) other measures as provided by laws and administrative regulations.\n1 2 3 \u0026gt;\nArticle 52 A personal information processor that processes personal information up to the amount prescribed by the national cyberspace department shall designate a person in charge of personal information protection, who shall supervise the personal information processing activities of the processor as well as the protective measures taken thereby, among others. The personal information processor shall disclose the contact information of the person in charge of personal information protection, and submit the said person\u0026rsquo;s name, contact information, and other information to the departments with personal information protection duties.\nArticle 53 Personal information processors outside the territory of the People\u0026rsquo;s Republic of China as specified in the second paragraph of Article 3 of this Law shall set up specialized agencies or designate representatives within the territory of the People\u0026rsquo;s Republic of China to be responsible for handling personal information protection related matters, and shall submit the names, contact information, and other information of the agencies and representatives to the departments with personal information protection duties.\nArticle 54 Personal information processors shall regularly conduct compliance audits of their personal information processing activities with laws and administrative regulations.\nArticle 55 In any of the following circumstances, a personal information processor shall assess in advance the impact on personal information protection and keep a record of the course of the processing: (1) processing sensitive personal information;\n(2) using personal information to conduct automated decision making;\n(3) entrusting personal information processing to another party, providing personal information for another party, or publicizing personal information;\n(4) providing personal information for any party outside the territory of the People\u0026rsquo;s Republic of China; or\n(5) conducting other personal information processing activities which may have significant impacts on individuals.\nArticle 56 The assessment of impact on personal information protection shall include the following contents: (1) whether the purposes and means of personal information processing, are legitimate, justified and necessary;\n(2) the impact on individuals\u0026rsquo; rights and interests, and security risks; and\n(3) whether the protection measures taken are legitimate, effective, and compatible with the degree of risks.\nThe report of the impact assessment on personal information protection and the processing record shall be retained for at least three years.\nArticle 57 Where the breach, tampering, or loss of personal information occurs or may occur, a personal information processor shall immediately take remedial measures and notify the departments with personal information protection duties and the relevant individuals. The notice shall include the following items: (1) the categories of personal information that has been or may be breached, tampered with or lost, and the reasons and possible harm of the breach, tampering and loss;\n(2) the remedial measures adopted by the personal information processor and the measures the individuals may take to mitigate the harm; and\n(3) the contact information of the personal information processor.\nWhere the measures taken by the personal information processor can effectively avoid the harm caused by breach, tampering, or loss of personal information, the personal information processor is not required to notify individuals; where the departments with personal information protection duties consider that harm may be caused, they have the authority to request the personal information processor to notify individuals.\nArticle 58 A personal information processor that provides important internet platform services involving a huge number of users and complicated business types shall perform the following obligations: (1) establishing and improving the personal information protection compliance system in accordance with the provisions of the state and establishing an independent organization mainly composed of external members to supervise the protection of personal information;\n(2) following the principles of openness, fairness, and justice, formulating platform rules, and clarifying the norms and obligations that product or service providers within the platform should meet when processing personal information;\n(3) stopping providing services for product or service providers within the platforms that process personal information in serious violation of laws and administrative regulations; and\n(4) regularly publishing social responsibility reports on personal information protection for public supervision.\nArticle 59 The party entrusted with the processing of personal information shall, in accordance with this Law and relevant laws and administrative regulations, take the necessary measures to ensure the security of the personal information entrusted for processing, and assist the entrusting personal information processor in fulfilling the obligations provided by this Law.\nChapter VI Departments with Personal Information Protection Duties Article 60 The national cyberspace department shall be responsible for the overall planning and coordination of personal information protection and related supervision and administration. The relevant departments of the State Council shall, in accordance with this Law and other relevant laws and administrative regulations, be responsible for personal information protection and related supervision and administration within the scope of their respective duties. The duties of personal information protection and related supervision and administration of the relevant departments of the local people\u0026rsquo;s governments at or above the county level shall be determined in accordance with the relevant provisions of the state.\nThe departments provided in the preceding two paragraphs are collectively referred to as the departments with personal information protection duties.\nArticle 61 Departments with personal information protection duties shall perform the following personal information protection duties: (1) conducting publicity and education on personal information protection, and guiding and supervising personal information processors in their protection of personal information;\n(2) receiving and handling complaints and reports related to personal information protection;\n(3) organizing evaluations on applications, etc. in terms of personal information protection and publish the results of such evaluations;\n(4) investigating and handling illegal personal information processing activities; and\n(5) other duties as provided by laws and administrative regulations.\nArticle 62 The national cyberspace department shall coordinate relevant departments to promote personal information protection through the following efforts in accordance with this Law: (1) formulating specific rules and standards for personal information protection;\n(2) developing special personal information protection rules and standards for small personal information processors, the processing of sensitive personal information, and new technologies and applications such as face recognition and artificial intelligence;\n(3) supporting the research and development, and promoting the application of secure and convenient electronic identity authentication technology, and advancing the public services for network identity authentication;\n(4) promoting the development of a personal information protection service system with the participation of various social sectors, and supporting relevant institutions in providing personal information protection assessment and certification services; and\n(5) improving the complaint and reporting mechanism related to personal information protection .\nArticle 63 A department with personal information protection duties when fulfilling related duties may take the following measures: (1) questioning relevant parties, and investigating circumstances related to personal information processing activities;\n(2) consulting and duplicating the parties\u0026rsquo; contracts, records, account books and other relevant materials related to personal information processing activities;\n(3) conducting on-site inspections, and investigating suspected illegal personal information processing activities; and\n(4) inspecting equipment and articles related to personal information processing activities; and sealing up or seizing equipment and articles related to illegal personal information processing activities as proved by evidence after submitting written reports to and obtaining approval from the principal person in charge of the departments with personal information protection duties.\nWhen departments with personal information protection duties carry out their duties in accordance with the law, the parties concerned shall cooperate and provide assistance, and shall not reject or obstruct them.\nArticle 64 Where a department with personal information protection duties finds, when performing its duties, relatively high risks in personal information processing activities or the occurrence of personal information security incidents, the department may hold an interview with the legal representative or the principal person in charge of the personal information processor according to the provided authority and procedures, or request the processor to entrust a professional institution to conduct compliance audits of the personal information processing activities. The personal information processor shall adopt measures to make rectification and eliminate potential risks as required. Where a department with personal information protection duties, in performing its duties, finds an illegal personal information processing activity that may involve a crime, the department shall transfer the case to the public security organ in a timely manner in accordance with the law.\nArticle 65 Any organization or individual has the right to complain and report to a department with personal information protection duties about illegal personal information processing. The department that receives such a complaint or report shall handle it in a timely manner in accordance with the law, and notify the complainant or informant of the results. Departments with personal information protection duties shall publish their contact information for receiving complaints and reports.\nChapter VII Legal Liability Article 66 Where personal information is processed in violation of the provisions of this Law or without fulfilling the personal information protection obligations provided in this Law, the departments with personal information protection duties shall order the violator to make corrections, give a warning, confiscate the illegal gains, and order the suspension or termination of provision of services by the applications that illegally process personal information; where the violator refuses to make corrections, a fine of not more than RMB one million yuan shall be imposed thereupon; and the directly liable persons in charge and other directly liable persons shall each be fined not less than RMB 10,000 yuan nor more than RMB 100,000 yuan. In case of an illegal act as prescribed in the preceding paragraph and the circumstances are serious, the departments with personal information protection duties at or above the provincial level shall order the violator to make corrections, confiscate the illegal gains, impose a fine of not more than RMB 50 million yuan or not more than five percent of the previous year\u0026rsquo;s turnover; may also order the suspension of relevant businesses, or order the suspension of all the business operations for an overhaul, and notify the competent authorities to revoke relevant business permits or license; shall impose a fine of not less than RMB 100,000 yuan but not more than RMB 1 million yuan upon each of the directly liable persons in charge and other directly liable persons, and may decide to prohibit the abovementioned persons from serving as directors, supervisors, senior managers, or the persons in charge of relevant companies within a specific period of time.\nArticle 67 Any violation of the provisions of this Law shall be entered in the relevant credit record and be published in accordance with the provisions of the relevant laws and administrative regulations.\nArticle 68 Where any state organ fails to fulfill the personal information protection obligations as provided in this Law, the organ at the higher level or the departments with personal information protection duties shall order it to make corrections, and discipline the directly liable person in charge and other directly liable persons in accordance with the law. Where a staff member of a department with personal information protection duties neglects duties, abuses power, or practices favoritism, which does not constitute a crime, the staff member shall be subject to sanction in accordance with the law.\nArticle 69 Where a personal information processor infringes the rights or interests on personal information due to any personal information processing activity and cannot prove that the processor is not at fault, the processor shall assume the liability for damages and other tort liability. The liability for damages prescribed in the preceding paragraph shall be determined based on the losses of individuals incurred thereby and the benefits acquired by the infringing personal information processor; and where it is difficult to determine the aforementioned losses or the benefits, the amount of damages shall be determined based on the actual circumstances.\nArticle 70 Where a personal information processor processes personal information in violation of the provisions of this Law and infringes the rights and interests of many individuals, the people\u0026rsquo;s procuratorate, the consumer organizations specified by law, and the organization designated by the national cyberspace department may file a lawsuit with the people\u0026rsquo;s court in accordance with the law.\nArticle 71 Any violation of this Law which constitutes a violation of public security administration shall be subject to public security administration penalty in accordance with the law. If the violation constitutes a crime, the violator shall be held criminally liable in accordance with the law.\nChapter VIII Supplementary Provisions Article 72 This Law is not applicable where a natural person processes personal information for personal or household affairs. Where other laws provide personal information processing in statistical or archives management activities organized and conducted by the people\u0026rsquo;s governments at all levels and their relevant departments, the provisions of such laws shall prevail.\nArticle 73 For purposes of this Law, the following terms shall have the following meanings: (1) \u0026ldquo;A personal information processor\u0026rdquo; refers to an organization or individual that autonomously determines the purposes and means of personal information processing.\n(2) \u0026ldquo;automated decision making\u0026rdquo; refers to the activities of automatically analyzing and evaluating personal behaviors, hobbies, or economic, health, and credit status, among others, through computer programs, and making decisions.\n(3) \u0026ldquo;de-identification\u0026rdquo; refers to processing personal information to make it impossible to identify specific natural persons in the absence of the support of additional information.\n(4) \u0026ldquo;anonymization\u0026rdquo; refers to the process of processing personal information to make it impossible to identify specific natural persons and impossible to restore.\nArticle 74 This Law shall come into force as of November 1st , 2021. 1 2 3\n","permalink":"https://ai.intlaws.com/en/compliance/china/pipl/","summary":"Officialof the Personal Information Protection Law of the PRC: 8 chapters, 74 articles, adopted 2021-08-20, in force 2021-11-01. English text as published on the NPC official English site (marked \u0026ldquo;Translation for Reference Only\u0026rdquo;).","title":"Personal Information Protection Law of the PRC"},{"content":" Version and sources (verifiable)\nItem Content Instrument Protocol amending the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data — the \u0026ldquo;Convention 108+\u0026rdquo; Reference CETS No. 223 (Council of Europe Treaty Series No. 223) Opened for signature Strasbourg, 10 October 2018, open for signature by the Contracting States to Treaty ETS 108 Entry into force Two independent paths (Article 37): ① ratification by all Parties to treaty ETS 108; or ② five years after the opening for signature (10 October 2018), i.e. as from 11 October 2023, once 38 Parties to the Convention have ratified the Protocol. Status NOT YET IN FORCE. As of 2026-09-22, 34 Parties have ratified (the 34th being the Republic of Moldova, 15 May 2026 — Council of Europe announcement ); four further ratifications are still needed. Entry into force must not be described as imminent. Structure 40 articles: Articles 1–35 amend Convention 108 article by article; Articles 36–40 are final clauses Official text (English) https://rm.coe.int/16808ac918 (Council of Europe repository, 18 pages) Treaty Office record (signatures / ratifications / status) https://www.coe.int/en/web/conventions/full-list?module=treaty-detail\u0026amp;treatynum=223 Explanatory Report https://rm.coe.int/cets-223-explanatory-report-to-the-protocol-amending-the-convention-fo/16808ac91a Chinese version No official Chinese text (official languages: English and French). A Chinese translation by our editorial team, cross-checked article by article, marked non-official, for reference only → 中文全文 Retrieval \u0026amp; verification 2026-09-22. The Council of Europe blocks automated direct access from this network (Cloudflare), so the official PDF was retrieved through a rendering proxy. Text de-hyphenated; article numbers accepted only in strict ascending order (1–40) to exclude cross-references; article count and headings checked against the Treaty Office record. Preamble — # Protocol amending the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data The member States of the Council of Europe and the other Parties to the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108), opened for signature in Strasbourg on 28 January 1981 (hereinafter referred to as “the Convention”), Having regard to Resolution No. 3 on data protection and privacy in the third millennium adopted at the 30th Council of Europe Conference of Ministers of Justice (Istanbul, Turkey, 24-26 November 2010); Having regard to the Parliamentary Assembly of the Council of Europe’s Resolution 1843 (2011) on the protection of privacy and personal data on the Internet and online media and Resolution 1986 (2014) on improving user protection and security in cyberspace; Having regard to Opinion 296 (2017) on the draft protocol amending the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108) and its explanatory memorandum, adopted by the Standing Committee on behalf of the Parliamentary Assembly of the Council of Europe on 24 November 2017; Considering that new challenges to the protection of individuals with regard to the processing of personal data have emerged since the Convention was adopted; Considering the need to ensure that the Convention continues to play its pre-eminent role in protecting individuals with regard to the pr\nArticle 1\n(1) The first recital of the preamble of the Convention shall be replaced by the following:\n“The member States of the Council of Europe, and the other signatories hereto,”\n(2) The third recital of the preamble of the Convention shall be replaced by the following:\n“Considering that it is necessary to secure the human dignity and protection of the human rights and fundamental freedoms of every individual and, given the diversification, intensification and globalisation of data processing and personal data flows, personal autonomy based on a person’s right to control his or her personal data and the processing of such data;”\n(3) The fourth recital of the preamble of the Convention shall be replaced by the following:\n“Recalling that the right to protection of personal data is to be considered in respect of its role in society and that it has to be reconciled with other human rights and fundamental freedoms, including freedom of expression;”\n(4) The following recital shall be added after the fourth recital of the preamble of the Convention:\n“Considering that this Convention permits account to be taken, in the implementation of the rules laid down therein, of the principle of the right of access to official documents;”\n(5) The fifth recital of the preamble of the Convention shall be deleted. New fifth and sixth recitals shall be added, which read as follows:\n“Recognising that it is necessary to promote at the global level the fundamental values of respect for privacy and protection of personal data, thereby contributing to the free flow of information between people;”\n“Recognising the interest of a reinforcement of international co-operation between the Parties to the Convention,”\nArticle 2\nThe text of Article 1 of the Convention shall be replaced by the following:\n“The purpose of this Convention is to protect every individual, whatever his or her nationality or residence, with regard to the processing of their personal data, thereby contributing to respect for his or her human rights and fundamental freedoms, and in particular the right to privacy.”\nArticle 3\n(1) Littera b of Article 2 of the Convention shall be replaced by the following:\n“b ‘data processing’ means any operation or set of operations performed on personal data, such as the collection, storage, preservation, alteration, retrieval, disclosure, making available, erasure, or destruction of, or the carrying out of logical and/or arithmetical operations on such data;”\n(2) Littera c of Article 2 of the Convention shall be replaced by the following:\n“c where automated processing is not used, ‘data processing’ means an operation or set of operations performed upon personal data within a structured set of such data which are accessible or retrievable according to specific criteria;”\n(3) Littera d of Article 2 of the Convention shall be replaced by the following:\n“d ‘controller’ means the natural or legal person, public authority, service, agency or any other body which, alone or jointly with others, has decision-making power with respect to data processing;”\n(4) The following new litterae shall be added after littera d of Article 2 of the Convention:\n“e ‘recipient’ means a natural or legal person, public authority, service, agency or any other body to whom data are disclosed or made available;\n(f) ‘processor’ means a natural or legal person, public authority, service, agency or any other body which processes personal data on behalf of the controller.”\nArticle 4\n(1) Paragraph 1 of Article 3 of the Convention shall be replaced by the following:\n“1 Each Party undertakes to apply this Convention to data processing subject to its\njurisdiction in the public and private sectors, thereby securing every individual’s right to protection of his or her personal data .”\n(2) Paragraph 2 of Article 3 of the Convention shall be replaced by the following:\n“2 This Convention shall not apply to data processing carried out by an individual in the course of purely personal or household activities .”\n(3) Paragraphs 3 to 6 of Article 3 of the Convention shall be deleted.\nArticle 5\nThe title of Chapter II of the Convention shall be replaced by the following:\n“Chapter II – Basic principles for the protection of personal data”.\nArticle 6\n(1) Paragraph 1 of Article 4 of the Convention shall be replaced by the following:\n“1 Each Party shall take the necessary measures in its law to give effect to the provisions of this Convention and secure their effective application .”\n(2) Paragraph 2 of Article 4 of the Convention shall be replaced by the following:\n“2 These measures shall be taken by each Party and shall have come into force by the time of ratification or of accession to this Convention .”\n(3) A new paragraph shall be added after paragraph 2 of Article 4 of the Convention:\n“3 Each Party undertakes:\n(a) to allow the Convention Committee provided for in Chapter VI to evaluate the effectiveness of the measures it has taken in its law to give effect to the provisions of this Convention; and\n(b) to contribute actively to this evaluation process.”\nArticle 7\n(1) The title of Article 5 shall be replaced by the following:\n“Article 5 – Legitimacy of data processing and quality of data”.\n(2) The text of Article 5 of the Convention shall be replaced by the following:\n“1 Data processing shall be proportionate in relation to the legitimate purpose pursued and reflect at all stages of the processing a fair balance between all interests concerned, whether public or private, and the rights and freedoms at stake .\n(2) Each Par ty shall provide that data processing can be carried out on the basis of the free, specific, informed and unambiguous consent of the data subject or of some other legitimate basis laid down by law .\n(3) Personal data undergoing processing shall be processed lawfully.\n(4) Personal data undergoing processing shall be:\n(a) processed fairly and in a transparent manner;\n(b) collected for explicit, specified and legitimate purposes and not processed in a way incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is, subject to appropriate safeguards, compatible with those purposes;\n(c) adequate, relevant and not excessive in relation to the purposes for which they are processed;\n(d) accurate and, where necessary, kept up to date;\n(e) preserved in a form which permits identification of the data subjects for no longer than is necessary for the purposes for which those data are processed.”\nArticle 8\nThe text of Article 6 of the Convention shall be replaced by the following:\n“1 The processing of:\n– genetic data;\n– personal data relating to offences, criminal proceedings and convictions, and related security measures;\n– biometric data uniquely identifying a person;\n– personal data for the information they reveal relating to racial or ethnic origin, political opinions, trade-union membership, religious or other beliefs, health or sexual life, shall only be allowed where appropriate safeguards are enshrined in law, complementing\nthose of this Convention.\n(2) Such safeguards shall guard against the risks that the processing of sensitive data may present for the interests, rights and fundamental freedoms of the data subject, notably a risk of discrimination .”\nArticle 9\nThe text of Article 7 of the Convention shall be replaced by the following:\n“1 Each Party shall provide that the controller, and where applicable the processor, takes appropriate security measures against risks such as accidental or unauthorised access to, destruction, loss, use, modification or disclosure of personal data .\n(2) Each Party shall provide that the controller notifies, without delay, at least the competent supervisory authority within the meaning of Article 1 5 of this Convention, of those data breaches which may seriously interfere with the rights and fundamental freedoms of data subjects .”\nArticle 10\nA new Article 8 shall be added after Article 7 of the Convention as follows:\n“Article 8 – Transparency of processing\n(1) Each Party shall provide that the controller informs the data subjects of:\n(a) his or her identity and habitual residence or establishment;\n(b) the legal basis and the purposes of the intended processing;\n(c) the categories of personal data processed;\n(d) the recipients or categories of recipients of the personal data, if any; and\n(e) the means of exercising the rights set out in Article 9,\nas well as any necessary additional information in order to ensure fair and transparent processing of the personal data.\n(2) Paragraph 1 shall not apply where the data subject already has the relevant information.\n(3) Where the personal data are not collected from the data subjects, the controller shall not be required to provide such information where the processing is expressly prescribed by law or this proves to be impossible or involves disproportionate efforts.”\nArticle 11\n(1) The former Article 8 of the Convention shall be renumbered Article 9 and the title shall be replaced by the following:\n“Article 9 – Rights of the data subject”.\n(2) The text of Article 8 of the Convention (new Article 9) shall be replaced by the following:\n“1 Every individual shall have a right:\n(a) not to be subject to a decision significantly affecting him or her based solely on an automated processing of data without having his or her views taken into consideration;\n(b) to obtain, on request, at reasonable intervals and without excessive delay or expense, confirmation of the processing of personal data relating to him or her, the communication in an intelligible form of the data processed, all available information on their origin, on the preservation period as well as any other information that the controller is required to provide in order to ensure the transparency of processing in accordance with Article 8, paragraph 1;\n(c) to obtain, on request, knowledge of the reasoning underlying data processing where the results of such processing are applied to him or her;\n(d) to object at any time, on grounds relating to his or her situation, to the processing of personal data concerning him or her unless the controller demonstrates legitimate grounds for the processing which override his or her interests or rights and fundamental freedoms;\n(e) to obtain, on request, free of charge and without excessive delay, rectification or erasure, as the case may be, of such data if these are being, or have been, processed contrary to the provisions of this Convention;\n(f) to have a remedy under Article 12 where his or her rights under this Convention have been violated;\n(g) to benefit, whatever his or her nationality or residence, from the assistance of a supervisory authority within the meaning of Article 15, in exercising his or her rights under this Convention.\n(2) Paragraph 1.a shall not apply if the decision is authorised by a law to which the controller is subject and which also lays down suitable measures to safeguard the data subject\u0026rsquo;s rights, freedoms and legitimate interests.”\nArticle 12\nA new Article 10 shall be added after the new Article 9 of the Convention as follows:\n“Article 10 – Additional obligations\n(1) Each Party shall provide that controllers and, where applicable, processors, take all appropriate measures to comply with the obligations of this Convention and be able to demonstrate, subject to the domestic legislation adopted in accordance with Article 11, paragraph 3, in particular to the competent supervisory authority provided for in Article 15, that the data processing under their control is in compliance with the provisions of this Convention.\n(2) Each Party shall provide that controllers and, where applicable, processors, examine the likely impact of intended data processing on the rights and fundamental freedoms of data subjects prior to the commencement of such processing, and shall design the data processing in such a manner as to prevent or minimise the risk of interference with those rights and fundamental freedoms.\n(3) Each Party shall provide that controllers, and, where applicable, processors, implement technical and organisational measures which take into account the implications of the right to the protection of personal data at all stages of the data processing.\n(4) Each Party may, having regard to the risks arising for the interests, rights and fundamental freedoms of the data subjects, adapt the application of the provisions of paragraphs 1, 2 and 3 in the law giving effect to the provisions of this Convention, according to the nature and volume of the data, the nature, scope and purpose of the processing and, where appropriate, the size of the controller or processor.”\nArticle 13\nThe former Articles 9 to 12 of the Convention shall become Articles 11 to 14 of the Convention.\nArticle 14\nThe text of Article 9 of the Convention (new Article 11) shall be replaced by the following:\n“1 No exception to the provisions set out in this chapter shall be allowed except to the provisions of Article 5, paragraph 4, Article 7, paragraph 2, Article 8, paragraph 1, and Article 9, when such an exception is provided for by law, respects the essence of the fundamental rights and freedoms and constitutes a necessary and proportionate measure in a democratic society for:\n(a) the protection of national security, defence, public safety, important economic and financial interests of the State, the impartiality and independence of the judiciary or the prevention, investigation and prosecution of criminal offences and the execution of criminal penalties, and other essential objectives of general public interest;\n(b) the protection of the data subject or the rights and fundamental freedoms of others, notably freedom of expression.\n(2) Restrictions on the exercise of the provisions specified in Articles 8 and 9 may be provided for by law with respect to data processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes when there is no recognisable risk of infringement of the rights and fundamental freedoms of data subjects.\n(3) In addition to the exceptions allowed for in paragraph 1 of this article, with reference to processing activities for national security and defence purposes, each Party may provide, by law and only to the extent that it constitutes a necessary and proportionate measure in a democratic society to fulfil such an aim, exceptions to Article 4, paragraph 3, Article 14, paragraphs 5 and 6, and Article 15, paragraph 2, litterae a, b, c and d.\nThis is without prejudice to the requirement that processing activities for national security and defence purposes are subject to independent and effective review and supervision under the domestic legislation of the respective Party.”\nArticle 15\nThe text of Article 10 of the Convention (new Article 12) shall be replaced by the following:\n“Each Party undertakes to establish appropriate judicial and non-judicial sanctions and remedies for violations of the provisions of this Convention.”\nArticle 16\nThe title of Chapter III shall be replaced by the following:\n“Chapter III – Transborder flows of personal data”.\nArticle 17\n(1) The title of Article 12 of the Convention (new Article 14) shall be replaced by the following:\n“Article 14 – Transborder flows of personal data”.\n(2) The text of Article 12 of the Convention (new Article 14) shall be replaced by the following:\n“1 A Party shall not, for the sole purpose of the protection of personal data, prohibit or subject to special authorisation the transfer of such data to a recipient who is subject to the jurisdiction of another Party to the Convention. Such a Party may, however, do so if there is a real and serious risk that the transfer to another Party, or from that other Party to a non-Party, would lead to circumventing the provisions of the Convention. A Party may also do so if bound by harmonised rules of protection shared by States belonging to a regional international organisation.\n(2) When the recipient is subject to the jurisdiction of a State or international organisation which is not Party to this Convention, the transfer of personal data may only take place where an appropriate level of protection based on the provisions of this Convention is secured.\n(3) An appropriate level of protection can be secured by:\n(a) the law of that State or international organisation, including the applicable international treaties or agreements; or\n(b) ad hoc or approved standardised safeguards provided by legally-binding and enforceable instruments adopted and implemented by the persons involved in the transfer and further processing.\n(4) Notwithstanding the provisions of the previous paragraphs, each Party may provide that the transfer of personal data may take place if:\n(a) the data subject has given explicit, specific and free consent, after being informed of risks arising in the absence of appropriate safeguards; or\n(b) the specific interests of the data subject require it in the particular case; or\n(c) prevailing legitimate interests, in particular important public interests, are provided for by law and such transfer constitutes a necessary and proportionate measure in a democratic society; or\n(d) it constitutes a necessary and proportionate measure in a democratic society for freedom of expression.\n(5) Each Party shall provide that the competent supervisory authority, within the meaning of Article 15 of this Convention, is provided with all relevant information concerning the transfers of data referred to in paragraph 3, littera b and, upon request, paragraph 4,\nlitterae b and c.\n(6) Each Party shall also provide that the supervisory authority is entitled to request that the person who transfers data demonstrates the effectiveness of the safeguards or the existence of prevailing legitimate interests and that the supervisory authority may, in order to protect the rights and fundamental freedoms of data subjects, prohibit such transfers, suspend them or subject them to conditions.”\n(3) The text of Article 12 of the Convention (new Article 14) includes the provisions of Article 2 of the Additional Protocol of 2001 regarding supervisory authorities and transborder data flows (ETS No. 181) on transborder flows of personal data to a recipient which is not subject to the jurisdiction of a Party to the Convention.\nArticle 18\nA new Chapter IV shall be added after Chapter III of the Convention, as follows:\n“Chapter IV – Supervisory authorities”.\nArticle 19\nA new Article 15 includes the provisions of Article 1 of the Additional Protocol of 2001 (ETS No.181) and reads as follows:\n“Article 15 – Supervisory authorities\n(1) Each Party shall provide for one or more authorities to be responsible for ensuring compliance with the provisions of this Convention.\n(2) To this end, such authorities:\n(a) shall have powers of investigation and intervention;\n(b) shall perform the functions relating to transfers of data provided for under Article 14, notably the approval of standardised safeguards;\n(c) shall have powers to issue decisions with respect to violations of the provisions of this Convention and may, in particular, impose administrative sanctions;\n(d) shall have the power to engage in legal proceedings or to bring to the attention of the competent judicial authorities violations of the provisions of this Convention;\n(e) shall promote:\n(i) public awareness of their functions and powers, as well as their activities; \u0026gt; ii public awareness of the rights of data subjects and the exercise of such rights; \u0026gt; iii awareness of controllers and processors of their responsibilities under this Convention;\nspecific attention shall be given to the data protection rights of children and other vulnerable individuals.\n(3) The competent supervisory authorities shall be consulted on proposals for any legislative or administrative measures which provide for the processing of personal data.\n(4) Each competent supervisory authority shall deal with requests and complaints lodged by data subjects concerning their data protection rights and shall keep data subjects informed of progress.\n(5) The supervisory authorities shall act with complete independence and impartiality in performing their duties and exercising their powers and in doing so shall neither seek nor accept instructions.\n(6) Each Party shall ensure that the supervisory authorities are provided with the resources necessary for the effective performance of their functions and exercise of their powers.\n(7) Each supervisory authority shall prepare and publish a periodical report outlining its activities.\n(8) Members and staff of the supervisory authorities shall be bound by obligations of confidentiality with regard to confidential information to which they have access, or have had access to, in the performance of their duties and exercise of their powers.\n(9) Decisions of the supervisory authorities may be subject to appeal through the courts.\n(10) The supervisory authorities shall not be competent with respect to processing carried out by bodies when acting in their judicial capacity.”\nArticle 20\n(1) Chapters IV to VII of the Convention shall be renumbered to Chapters V to VIII of the Convention.\n(2) The title of Chapter V shall be replaced by “Chapter V – Co-operation and mutual assistance”.\n(3) A new Article 17 shall be added, and former Articles 13 to 27 of the Convention shall become Articles 16 to 31 of the Convention.\nArticle 21\n(1) The title of Article 13 of the Convention (new Article 16) shall be replaced by the following:\n“Article 16 – Designation of supervisory authorities”.\n(2) Paragraph 1 of Article 13 of the Convention (new Article 16) shall be replaced by the following:\n“1 The Parties agree to co -operate and render each other mutual assistance in order to implement this Convention .”\n(3) Paragraph 2 of Article 13 of the Convention (new Article 16) shall be replaced by the following:\n“2 For that purpose:\n(a) each Party shall designate one or more supervisory authorities within the meaning of Article 15 of this Convention, the name and address of each of which it shall communicate to the Secretary General of the Council of Europe;\n(b) each Party which has designated more than one supervisory authority shall specify the competence of each authority in its communication referred to in the previous littera .”\n(4) Paragraph 3 of Article 13 of the Convention (new Article 16) shall be deleted.\nArticle 22\nA new Article 17 shall be added after the new Article 16 of the Convention as follows:\n“Article 17 – Forms of co-operation\n(1) The supervisory authorities shall co-operate with one another to the extent necessary for the performance of their duties and exercise of their powers, in particular by:\n(a) providing mutual assistance by exchanging relevant and useful information and co-operating with each other under the condition that, as regards the protection of personal data, all the rules and safeguards of this Convention are complied with;\n(b) co-ordinating their investigations or interventions, or conducting joint actions;\n(c) providing information and documentation on their law and administrative practice relating to data protection.\n(2) The information referred to in paragraph 1 shall not include personal data undergoing processing unless such data are essential for co-operation, or where the data subject concerned has given explicit, specific, free and informed consent to its provision.\n(3) In order to organise their co-operation and to perform the duties set out in the preceding paragraphs, the supervisory authorities of the Parties shall form a network.”\nArticle 23\n(1) The title of Article 14 of the Convention (new Article 18) shall be replaced by the following:\n“Article 18 – Assistance to data subjects”.\n(2) The text of Article 14 of the Convention (new Article 18) shall be replaced by the following:\n“1 Each Party shall assist any data subject, whatever his or her nationality or residence, to exercise his or her rights under Article 9 of this Convention.\n(2) Where a data subject resides on the territory of another Party, he or she shall be given the option of submitting the request through the intermediary of the supervisory authority designated by that Party.\n(3) The request for assistance shall contain all the necessary particulars, relating inter alia to:\n(a) the name, address and any other relevant particulars identifying the data subject making the request;\n(b) the processing to which the request pertains, or its controller;\n(c) the purpose of the request.”\nArticle 24\n(1) The title of Article 15 of the Convention (new Article 19) shall be replaced by the following:\n“Article 19 – Safeguards”.\n(2) The text of Article 15 of the Convention (new Article 19) shall be replaced by the following:\n“1 A supervisory authority which has received information from another supervisory authority, either accompanying a request or in reply to its own request, shall not use that information for purposes other than those specified in the request.\n(2) In no case may a supervisory authority be allowed to make a request on behalf of a data subject of its own accord and without the express approval of the data subject concerned.”\nArticle 25\n(1) The title of Article 16 of the Convention (new Article 20) shall be replaced by the following:\n“Article 20 – Refusal of requests”.\n(2) The recital of Article 16 of the Convention (new Article 20) shall be replaced by the following:\n“A supervisory authority to which a request is addressed under Article 17 of this Convention may not refuse to comply with it unless:”\n(3) Littera a of Article 16 of the Convention (new Article 20) shall be replaced by the following:\n“a the request is not compatible with its powers.”\n(4) Littera c of Article 16 of the Convention (new Article 20) shall be replaced by the following:\n“c compliance with the request would be incompatible with the sovereignty, national security or public order of the Party by which it was designated, or with the rights and fundamental freedoms of individuals under the jurisdiction of that Party.”\nArticle 26\n(1) The title of Article 17 of the Convention (new Article 21) shall be replaced by the following:\n“Article 21 – Costs and procedures”.\n(2) Paragraph 1 of Article 17 of the Convention (new Article 21) shall be replaced by the following:\n“1 Co-operation and mutual assistance which the Parties render each other under Article 17 and assistance they render to data subjects under Articles 9 and 18 shall not give rise to the payment of any costs or fees other than those incurred for experts and interpreters. The latter costs or fees shall be borne by the Party making the request.”\n(3) The terms “his or her” shall replace “his” in paragraph 2 of Article 17 of the Convention (new Article 21).\nArticle 27\nThe title of Chapter V of the Convention (new Chapter VI) shall be replaced by the following:\n“Chapter VI – Convention Committee”.\nArticle 28\n(1) The terms “Consultative Committee” in paragraph 1 of Article 18 of the Convention (new Article 22) shall be replaced by “Convention Committee”.\n(2) Paragraph 3 of Article 18 of the Convention (new Article 22) shall be replaced by the following:\n“3 The Convention Committee may, by a decision taken by a majority of two-thirds of the representatives of the Parties, invite an observer to be represented at its meetings.”\n(3) A new paragraph 4 shall be added after paragraph 3 of Article 18 of the Convention (new Article 22):\n“4 Any Party which is not a member of the Council of Europe shall contribute to the funding of the activities of the Convention Committee according to the modalities established by the Committee of Ministers in agreement with that Party.”\nArticle 29\n(1) The terms “Consultative Committee” in the recital of Article 19 of the Convention (new Article 23) shall be replaced by “Convention Committee”.\n(2) The term “proposals” in littera a of Article 19 of the Convention (new Article 23) shall be replaced with the term “recommendations”.\n(3) References to “Article 21” in littera b and “Article 21 paragraph 3” in littera c of Article 19 of the Convention (new Article 23) shall be replaced respectively by references to “Article 25” and “Article 25, paragraph 3”.\n(4) Littera d of Article 19 of the Convention (new Article 23) shall be replaced by the following:\n“d may express an opinion on any question concerning the interpretation or application of this Convention;”.\n(5) The following additional litterae shall be added following littera d of Article 19 of the Convention (new Article 23):\n“e shall prepare, before any new accession to the Convention, an opinion for the Committee of Ministers relating to the level of personal data protection of the candidate for accession and, where necessary, recommend measures to take to reach compliance with the provisions of this Convention;\n(f) may, at the request of a State or an international organisation, evaluate whether the level of personal data protection the former provides is in compliance with the provisions of this Convention and, where necessary, recommend measures to be taken in order to reach such compliance;\n(g) may develop or approve models of standardised safeguards referred to in Article 14;\n(h) shall review the implementation of this Convention by the Parties and recommend measures to be taken in the case where a Party is not in compliance with this Convention;\n(i) shall facilitate, where necessary, the friendly settlement of all difficulties related to the application of this Convention.”\nArticle 30\nThe text of Article 20 of the Convention (new Article 24) shall be replaced by the following:\n“1 The Convention Committee shall be convened by the Secretary General of the Council of Europe. Its first meeting shall be held within twelve months of the entry into force of this Convention. It shall subsequently meet at least once a year, and in any case when one-third of the representatives of the Parties request its convocation.\n(2) After each of its meetings, the Convention Committee shall submit to the Committee of Ministers of the Council of Europe a report on its work and on the functioning of this Convention.\n(3) The voting arrangements in the Convention Committee are laid down in the elements for the rules of procedure appended to Protocol CETS No. 223.\n(4) The Convention Committee shall draw up the other elements of its rules of procedure and establish, in particular, the procedures for evaluation and review referred to in Article 4, paragraph 3, and Article 23, litterae e, f and h on the basis of objective criteria.”\nArticle 31\n(1) Paragraphs 1 to 4 of Article 21 of the Convention (new Article 25) shall be replaced by the following:\n“1 Amendments to this Convention may be proposed by a Party, the Committee of Ministers of the Council of Europe or the Convention Committee.\n(2) Any proposal for amendment shall be communicated by the Secretary General of the Council of Europe to the Parties to this Convention, to the other member States of the Council of Europe, to the European Union and to every non-member State or international organisation which has been invited to accede to this Convention in accordance with the provisions of Article 27.\n(3) Moreover, any amendment proposed by a Party or the Committee of Ministers shall be communicated to the Convention Committee, which shall submit to the Committee of Ministers its opinion on that proposed amendment.\n(4) The Committee of Ministers shall consider the proposed amendment and any opinion submitted by the Convention Committee, and may approve the amendment.”\n(2) An additional paragraph 7 shall be added after paragraph 6 of Article 21 of the Convention (new Article 25) as follows:\n“7 Moreover, the Committee of Ministers may, after consulting the Convention Committee, unanimously decide that a particular amendment shall enter into force at the expiration of a period of three years from the date on which it has been opened to acceptance, unless a Party notifies the Secretary General of the Council of Europe of an objection to its entry into force. If such an objection is notified, the amendment shall enter into force on the first day of the month following the date on which the Party to this Convention which has notified the objection has deposited its instrument of acceptance with the Secretary General of the Council of Europe.”\nArticle 32\n(1) Paragraph 1 of Article 22 of the Convention (new Article 26) shall be replaced by the following:\n“1 This Convention shall be open for signature by the member States of the Council of Europe and by the European Union. It is subject to ratification, acceptance or approval. Instruments of ratification, acceptance or approval shall be deposited with the Secretary General of the Council of Europe.”\n(2) The terms “member State” in paragraph 3 of Article 22 of the Convention (new Article 26) shall be replaced by “Party”.\nArticle 33\nThe title and the text of Article 23 of the Convention (new Article 27) shall be replaced as follows:\n“Article 27 – Accession by non-member States or international organisations\n(1) After the entry into force of this Convention, the Committee of Ministers of the Council of Europe may, after consulting the Parties to this Convention and obtaining their unanimous agreement, and in light of the opinion prepared by the Convention Committee in accordance with Article 23.e, invite any State not a member of the Council of Europe or an international organisation to accede to this Convention by a decision taken by the majority provided for in Article 20.d of the Statute of the Council of Europe and by the unanimous vote of the representatives of the Contracting States entitled to sit on the Committee of Ministers.\n(2) In respect of any State or international organisation acceding to this Convention according to paragraph 1 above, the Convention shall enter into force on the first day of the month following the expiration of a period of three months after the date of deposit of the instrument of accession with the Secretary General of the Council of Europe.”\nArticle 34\nParagraphs 1 and 2 of Article 24 of the Convention (new Article 28) shall be replaced by the following:\n“1 Any State, the European Union or other international organisation may, at the time of signature or when depositing its instrument of ratification, acceptance, approval or accession, specify the territory or territories to which this Convention shall apply.\n(2) Any State, the European Union or other international organisation may, at any later date, by a declaration addressed to the Secretary General of the Council of Europe, extend the application of this Convention to any other territory specified in the declaration. In respect of such territory the Convention shall enter into force on the first day of the month following the expiration of a period of three months after the date of receipt of such declaration by the Secretary General.”\nArticle 35\n(1) The term “State” in the recital of Article 27 of the Convention (new Article 31) shall be replaced by “Party”.\n(2) References to “Articles 22, 23 and 24” in littera c shall be replaced by references to “Articles 26, 27 and 28”.\nArticle 36\n– Signature, ratification and accession\n(1) This Protocol shall be open for signature by Contracting States to the Convention. It shall be subject to ratification, acceptance or approval. Instruments of ratification, acceptance or approval shall be deposited with the Secretary General of the Council of Europe.\n(2) After the opening for signature of this Protocol and before its entry into force, any other State shall express its consent to be bound by this Protocol by accession. It may not become a Party to the Convention without acceding simultaneously to this Protocol.\nArticle 37\n– Entry into force\n(1) This Protocol shall enter into force on the first day of the month following the expiration of a period of three months after the date on which all Parties to the Convention have expressed their consent to be bound by the Protocol, in accordance with the provisions of paragraph 1 of Article 36.\n(2) In the event this Protocol has not entered into force in accordance with paragraph 1, following the expiry of a period of five years after the date on which it has been opened for signature, the Protocol shall enter into force in respect of those States which have expressed their consent to be bound by it in accordance with paragraph 1, provided that the Protocol has at least thirty-eight Parties. As between the Parties to the Protocol, all provisions of the amended Convention shall have effect immediately upon entry into force.\n(3) Pending the entry into force of this Protocol and without prejudice to the provisions regarding the entry into force and the accession by non-member States or international organisations, a Party to the Convention may, at the time of signature of this Protocol or at any later moment, declare that it will apply the provisions of this Protocol on a provisional basis. In such cases, the provisions of this Protocol shall apply only with respect to the other Parties to the Convention which have made a declaration to the same effect. Such a declaration shall take effect on the first day of the third month following the date of its receipt by the Secretary General of the Council of Europe.\n(4) From the date of entry into force of this Protocol, the Additional Protocol to the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, regarding supervisory authorities and transborder data flows (ETS No. 181) shall be repealed.\n(5) From the date of the entry into force of this Protocol, the amendments to the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, approved by the Committee of Ministers, in Strasbourg, on 15 June 1999, have lost their purpose.\nArticle 38\n– Declarations related to the Convention From the date of entry into force of this Protocol, with respect to a Party having entered one or more declarations in pursuance of Article 3 of the Convention, such declaration(s) will lapse.\nArticle 39\n– Reservations No reservation may be made to the provisions of this Protocol.\nArticle 40\n– Notifications The Secretary General of the Council of Europe shall notify the member States of the Council of Europe and any other Party to the Convention of:\n(a) any signature;\n(b) the deposit of any instrument of ratification, acceptance, approval or accession;\n(c) the date of entry into force of this Protocol in accordance with Article 37;\n(d) any other act, notification or communication relating to this Protocol.\nIn witness whereof the undersigned, being duly authorised thereto, have signed this Protocol.\nDone at Strasbourg, this 10th day of October 2018, in English and in French, both texts being equally authentic, in a single copy which shall be deposited in the archives of the Council of Europe. The Secretary General of the Council of Europe shall transmit certified copies to each member State of the Council of Europe, to other Parties to the Convention and any State invited to accede to the Convention. Appendix to the Protocol: Elements for the rules of procedure of the Convention Committee\n(1) Each Party has a right to vote and shall have one vote.\n(2) A two-thirds majority of representatives of the Parties shall constitute a quorum for the meetings of the Convention Committee. In case the amending Protocol to the Convention enters into force in accordance with its Article 37 (2) before its entry into force in respect of all Contracting States to the Convention, the quorum for the meetings of the Convention Committee shall be no less than 34 Parties to the Protocol.\n(3) The decisions under Article 23 shall be taken by a four-fifths majority. The decisions pursuant to Article 23, littera h, shall be taken by a four-fifths majority, including a majority of the votes of States Parties not members of a regional integration organisation that is a Party to the Convention.\n(4) Where the Convention Committee takes decisions pursuant to Article 23, littera h, the Party concerned by the review shall not vote. Whenever such a decision concerns a matter falling within the competence of a regional integration organisation, neither the organisation nor its member States shall vote.\n(5) Decisions concerning procedural issues shall be taken by a simple majority.\n(6) Regional integration organisations, in matters within their competence, may exercise their right to vote in the Convention Committee, with a number of votes equal to the number of their member States that are Parties to the Convention. Such an organisation shall not exercise its right to vote if any of its member States exercises its right.\n(7) In case of vote, all Parties must be informed of the subject and time for the vote, as well as whether the vote will be exercised by the Parties individually or by a regional integration organisation on behalf of its member States.\n(8) The Convention Committee may further amend its rules of procedure by a two-thirds majority, except for the voting arrangements which may only be amended by unanimous vote of the Parties and to which Article 25 of the Convention applies.\n","permalink":"https://ai.intlaws.com/en/compliance/intl/coe-convention-108-plus/","summary":"Official English text of Protocol CETS No. 223, which modernises Convention 108 (the \u0026ldquo;Convention 108+\u0026rdquo;) — opened for signature in Strasbourg on 10 October 2018, comprising 40 articles: amendments to Convention 108 article by article (Articles 1–35) and final clauses (Articles 36–40). Per the Council of Europe Treaty Office, it enters into force upon ratification by all Parties to Treaty ETS 108, or, as from 11 October 2023, once 38 Parties to the Convention have ratified it.","title":"Protocol amending Convention 108"},{"content":" Version and sources (verifiable)\nItem Content Promulgated 22 March 2024 by the Cyberspace Administration of China (Order No. 16); effective on the date of promulgation Structure 14 articles Currently effective Yes (as of 2026-09-22) Chinese original https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm English version No official English translation published. This English text is a translation by our editorial team, cross-checked article by article against the official Chinese text; it is not an official translation and is for reference only. Where a term has an established rendering in official translations of the Cybersecurity Law, the Data Security Law and the Personal Information Protection Law, that rendering is used. Verification Retrieved 2026-09-22; 14 articles, correspondence with the Chinese text verified one-for-one, no gaps Article 1 These Provisions are formulated in accordance with the Cybersecurity Law of the People\u0026rsquo;s Republic of China, the Data Security Law of the People\u0026rsquo;s Republic of China, the Personal Information Protection Law of the People\u0026rsquo;s Republic of China and other laws and regulations, for the purposes of safeguarding data security, protecting the rights and interests of personal information, and promoting the lawful, orderly and free flow of data, and in order to govern the implementation of the data export regimes — security assessment of data export, standard contracts for the export of personal information, and personal information protection certification.\nArticle 2 Data processors shall identify and report important data in accordance with relevant provisions. Where no department or region has notified or publicly released data as important data, the data processor is not required to report it as important data for the security assessment of data export.\nArticle 3 Where data collected and generated in activities such as international trade, cross-border transportation, academic cooperation, cross-border manufacturing and marketing are provided overseas and do not contain personal information or important data, the data processor is exempted from reporting for the security assessment of data export, from concluding standard contracts for the export of personal information, and from obtaining personal information protection certification.\nArticle 4 Where personal information collected and generated overseas by a data processor is transmitted into China for processing and is thereafter provided overseas again, and no personal information or important data within China was introduced in the course of processing, the data processor is exempted from reporting for the security assessment of data export, from concluding standard contracts for the export of personal information, and from obtaining personal information protection certification.\nArticle 5 Where a data processor provides personal information overseas and meets any of the following conditions, it is exempted from reporting for the security assessment of data export, from concluding standard contracts for the export of personal information, and from obtaining personal information protection certification:\n(1) where it is genuinely necessary to provide personal information overseas for the conclusion or performance of a contract to which the individual is a party, such as cross-border shopping, cross-border delivery, cross-border remittance, cross-border payment, cross-border account opening, air ticket and hotel booking, visa application, and examination services;\n(2) where it is genuinely necessary to provide employees\u0026rsquo; personal information overseas for the implementation of cross-border human resources management in accordance with labour rules and regulations formulated according to law and collective contracts concluded according to law;\n(3) where it is genuinely necessary to provide personal information overseas in an emergency to protect the life, health and property safety of natural persons;\n(4) where a data processor other than a critical information infrastructure operator has cumulatively provided overseas the personal information of fewer than 100,000 individuals (excluding sensitive personal information) since 1 January of the current year.\nThe personal information provided overseas referred to in the preceding paragraph does not include important data.\nArticle 6 Within the framework of the national data classification and grading protection system, a pilot free trade zone may itself formulate a list of data within the zone that is to be included in the scope of the security assessment of data export, the standard contracts for the export of personal information, and personal information protection certification (hereinafter the \u0026ldquo;negative list\u0026rdquo;), and after approval by the provincial cyberspace and informatisation commission, shall file it with the national cyberspace administration department and the national data administration department. Where a data processor within a pilot free trade zone provides overseas data that is outside the negative list, it is exempted from reporting for the security assessment of data export, from concluding standard contracts for the export of personal information, and from obtaining personal information protection certification.\nArticle 7 Where a data processor provides data overseas and meets any of the following conditions, it shall, through the cyberspace administration department of the province where it is located, report to the national cyberspace administration department for the security assessment of data export:\n(1) a critical information infrastructure operator provides personal information or important data overseas;\n(2) a data processor other than a critical information infrastructure operator provides important data overseas, or has cumulatively provided overseas the personal information of more than 1,000,000 individuals (excluding sensitive personal information), or the sensitive personal information of more than 10,000 individuals, since 1 January of the current year.\nWhere any of the circumstances provided for in Articles 3, 4, 5 and 6 of these Provisions applies, those provisions shall prevail.\nArticle 8 Where a data processor other than a critical information infrastructure operator has cumulatively provided overseas the personal information of 100,000 or more but fewer than 1,000,000 individuals (excluding sensitive personal information), or the sensitive personal information of fewer than 10,000 individuals, since 1 January of the current year, it shall, in accordance with law, conclude with the overseas recipient a standard contract for the export of personal information, or obtain personal information protection certification. Where any of the circumstances provided for in Articles 3, 4, 5 and 6 of these Provisions applies, those provisions shall prevail.\nArticle 9 The result of a security assessment of data export is valid for three years, counted from the date on which the assessment result is issued. Where the validity period expires and the data processor needs to continue the data export activities and no circumstance requiring a fresh report for the security assessment of data export has occurred, the data processor may, within 60 working days before the expiry of the validity period, apply through the cyberspace administration department of the province where it is located to the national cyberspace administration department for an extension of the validity period of the assessment result. Upon approval by the national cyberspace administration department, the validity period of the assessment result may be extended by three years.\nArticle 10 Where a data processor provides personal information overseas, it shall, in accordance with laws and administrative regulations, perform obligations including informing the individual, obtaining the individual\u0026rsquo;s separate consent, and conducting a personal information protection impact assessment.\nArticle 11 Where a data processor provides data overseas, it shall comply with laws and regulations, perform its data security protection obligations, and adopt technical measures and other necessary measures to ensure the security of data export. Where a data security incident occurs or is likely to occur, it shall adopt remedial measures and promptly report to the cyberspace administration department at or above the provincial level and other competent departments.\nArticle 12 Cyberspace administration departments in all localities shall strengthen guidance and supervision over the data export activities of data processors, improve the security assessment system for data export, and optimise the assessment process; strengthen whole-chain, whole-process and all-round supervision before, during and after the event, and where data export activities present relatively high risks or a data security incident occurs, require the data processor to rectify and eliminate the hidden danger; and where the data processor refuses to rectify or causes serious consequences, pursue legal liability in accordance with law.\nArticle 13 Where relevant provisions such as the Measures for the Security Assessment of Data Export (Cyberspace Administration of China Order No. 11), promulgated on 7 July 2022, and the Measures for Standard Contracts for the Export of Personal Information (Cyberspace Administration of China Order No. 13), promulgated on 22 February 2023, are inconsistent with these Provisions, these Provisions shall prevail.\nArticle 14 These Provisions shall come into force on the date of promulgation.\nRelationship between provisions (editorial note, not part of the legal text)\nArticle 19 of the Measures provides the identification standard for \u0026ldquo;important data\u0026rdquo;; Article 2 of the 2024 Provisions and Article 37 of the Regulations make the reporting obligation conditional on notification or public designation by the regulator. The two operate as definition and procedure and do not conflict: it is the regulator, not the processor, that designates important data.\n","permalink":"https://ai.intlaws.com/en/compliance/china/data-cross-border-flow-provisions/","summary":"Full text of the Provisions on Promoting and Regulating Cross-Border Data Flows (CAC Order No. 16, promulgated and effective 22 March 2024), 14 articles: exemption scenarios, the negative-list mechanism in pilot free trade zones, the thresholds for the security assessment and the standard contract, and the three-year validity of assessment results. English translation by our editorial team (non-official, cross-checked article by article against the official Chinese text).","title":"Provisions on Promoting and Regulating Cross-Border Data Flows"},{"content":" Version and sources (verifiable)\nItem Content Adopted 30 August 2024, at the 40th executive meeting of the State Council Promulgated 24 September 2024 (State Council Order No. 790, signed by Premier Li Qiang) Effective 1 January 2025 Structure 9 chapters, 64 articles Currently effective Yes (as of 2026-09-22) Chinese original State Council Order No. 790 — (the original gov.cn link is no longer reachable; this is theof the Order as republished on a government website) English version No official English translation published. This English text is a translation by our editorial team cross-checked article by article against the official Chinese text; it is not an official translation and is for reference only. Verification Retrieved 2026-09-22; 64 articles, no gaps; chapter structure verified against the official text Chapter I General provisions Article 1 These Regulations are formulated in accordance with the Cybersecurity Law of the People\u0026rsquo;s Republic of China, the Data Security Law of the People\u0026rsquo;s Republic of China, the Personal Information Protection Law of the People\u0026rsquo;s Republic of China and other laws, for the purposes of regulating network data processing activities, safeguarding network data security, promoting the lawful, reasonable and effective use of network data, protecting the lawful rights and interests of individuals and organisations, and maintaining national security and the public interest.\nArticle 2 These Regulations apply to network data processing activities carried out within the territory of the People\u0026rsquo;s Republic of China and to the supervision and administration of their security.\nThese Regulations also apply to activities processing, outside the territory of the People\u0026rsquo;s Republic of China, the personal information of natural persons within the territory of the People\u0026rsquo;s Republic of China, where the circumstances provided for in the second paragraph of Article 3 of the Personal Information Protection Law of the People\u0026rsquo;s Republic of China are met.\nWhere network data processing activities carried out outside the territory of the People\u0026rsquo;s Republic of China harm the national security or public interests of the People\u0026rsquo;s Republic of China or the lawful rights and interests of its citizens and organisations, legal liability shall be pursued in accordance with law.\nArticle 3 Network data security management work upholds the leadership of the Communist Party of China, implements the holistic approach to national security, and coordinates the promotion of the development and utilisation of network data with the safeguarding of network data security.\nArticle 4 The State encourages innovative applications of network data in all industries and fields, strengthens capacity-building for network data security protection, supports innovation in technologies, products and services relating to network data, carries out publicity, education and personnel training on network data security, and promotes the development and utilisation of network data and the growth of the industry.\nArticle 5 The State applies classified and graded protection to network data according to its importance in economic and social development and the degree of harm that tampering, destruction, leakage, unlawful acquisition or unlawful use would cause to national security, the public interest or the lawful rights and interests of individuals and organisations.\nArticle 6 The State actively participates in the formulation of international rules and standards relating to network data security and promotes international exchange and cooperation.\nArticle 7 The State supports relevant industry organisations in formulating, in accordance with their articles of association, norms of conduct for network data security, strengthening industry self-regulation, guiding their members in strengthening network data security protection, raising the level of network data security protection and promoting the sound development of the industry.\nChapter II General provisions Article 8 No individual or organisation may use network data to engage in illegal activities, or engage in illegal network data processing activities such as stealing or otherwise unlawfully obtaining network data, or unlawfully selling or unlawfully providing network data to others.\nNo individual or organisation may provide programs or tools specifically used for the illegal activities in the preceding paragraph; where a person knows that another is engaged in the illegal activities in the preceding paragraph, the person must not provide that other person with technical support such as internet access, server hosting, network storage or communication transmission, or assistance such as advertising promotion or payment and settlement.\nArticle 9 Network data processors shall, in accordance with laws and administrative regulations and the mandatory requirements of national standards, and on the basis of the classified protection of cybersecurity, strengthen network data security protection, establish and improve network data security management systems, adopt technical measures such as encryption, backup, access control and security authentication and other necessary measures, protect network data against tampering, destruction, leakage, unlawful acquisition or unlawful use, handle network data security incidents, prevent and combat illegal and criminal activities directed at and using network data, and bear primary responsibility for the security of the network data they process.\nArticle 10 Network products and services provided by network data processors shall comply with the mandatory requirements of relevant national standards; where risks such as security defects or vulnerabilities in network products or services are discovered, remedial measures shall be taken immediately, users shall be promptly informed as required and a report shall be made to the competent departments; where national security or the public interest is endangered, the network data processor shall also report to the competent departments within 24 hours.\nArticle 11 Network data processors shall establish and improve emergency response plans for network data security incidents; when a network data security incident occurs, they shall immediately activate the plan, take measures to prevent the expansion of harm and eliminate hidden security dangers, and report to the competent departments as required.\nWhere a network data security incident harms the lawful rights and interests of individuals or organisations, the network data processor shall promptly notify the interested parties, by telephone, short message, instant messaging tool, email or public announcement, of the incident and the risk situation, the consequences of the harm and the remedial measures already taken; where laws and administrative regulations provide that notification may be dispensed with, those provisions shall prevail. Where a network data processor discovers in the course of handling a network data security incident any leads suggesting illegality or crime, it shall report the case to the public security organ and the State security organ as required and cooperate in investigation, inquiry and handling.\nArticle 12 Where a network data processor provides or entrusts the processing of personal information and important data to another network data processor, it shall, by contract or otherwise, agree with the network data recipient on the processing purpose, method, scope and security protection obligations, and supervise the recipient\u0026rsquo;s performance of those obligations. Records of the provision or entrusted processing of personal information and important data to another network data processor shall be kept for at least three years.\nThe network data recipient shall perform network data security protection obligations and process the personal information and important data in accordance with the agreed purpose, method and scope.\nWhere two or more network data processors jointly determine the processing purpose and method of personal information and important data, they shall agree on their respective rights and obligations.\nArticle 13 Where network data processing activities carried out by a network data processor affect or may affect national security, a national security review shall be conducted in accordance with the relevant provisions of the State.\nArticle 14 Where network data needs to be transferred due to merger, division, dissolution, bankruptcy or other reasons, the network data recipient shall continue to perform the network data security protection obligations.\nArticle 15 Where a State organ entrusts another person with the construction, operation or maintenance of an e-government system or with the storage or processing of government data, it shall, in accordance with the relevant provisions of the State, go through strict approval procedures, clarify the entrusted party\u0026rsquo;s network data processing authority and protection responsibilities, and supervise the entrusted party\u0026rsquo;s performance of network data security protection obligations.\nArticle 16 Where a network data processor provides services to a State organ or an operator of critical information infrastructure, or participates in the construction, operation or maintenance of other public infrastructure or public service systems, it shall perform network data security protection obligations in accordance with laws, regulations and the contract, and provide secure, stable and continuous services.\nA network data processor referred to in the preceding paragraph must not, without the consent of the commissioning party, access, obtain, retain, use or divulge network data or provide it to others, or conduct correlation analysis of network data.\nArticle 17 Information systems providing services for State organs shall strengthen network data security management by reference to the management requirements for e-government systems, so as to safeguard network data security.\nArticle 18 Where a network data processor uses automated tools to access or collect network data, it shall assess the impact on network services, and must not unlawfully intrude into another\u0026rsquo;s network or interfere with the normal operation of network services.\nArticle 19 A network data processor providing generative artificial intelligence services shall strengthen the security management of training data and training data processing activities and take effective measures to prevent and handle network data security risks.\nArticle 20 Network data processors providing products or services to the public shall accept public supervision, establish convenient channels for complaints and reports about network data security, publish information such as the methods for making complaints and reports, and promptly accept and handle complaints and reports about network data security.\nChapter III Personal information protection Article 21 Where a network data processor informs individuals in accordance with law by formulating personal information processing rules before processing their personal information, the personal information processing rules shall be publicly displayed in a centralised manner, easy to access and placed in a prominent position, and shall be clear, specific and easy to understand, including but not limited to the following:\n(1) the name of the network data processor and its contact information;\n(2) the purpose, method and categories of the processing of personal information, the necessity of processing sensitive personal information and the impact on individual rights and interests;\n(3) the retention period of personal information and the method of handling it upon expiry; where the retention period is difficult to determine, the method for determining the retention period shall be specified;\n(4) the methods and channels for individuals to access, copy, transfer, correct, supplement or delete personal information, restrict its processing, cancel accounts and withdraw consent.\nWhere a network data processor informs individuals, in accordance with the preceding paragraph, of the purpose, method and categories of collecting personal information and providing it to other network data processors, and of the information of the network data recipient, it shall set them out in a list or other form. Where a network data processor processes the personal information of minors under the age of fourteen, it shall also formulate dedicated personal information processing rules.\nArticle 22 Where a network data processor processes personal information on the basis of individual consent, it shall comply with the following provisions:\n(1) the collection of personal information shall be necessary for providing products or services; it must not collect personal information beyond the necessary scope, and must not obtain consent by misleading, deceiving or coercing individuals;\n(2) where sensitive personal information such as biometric data, religious belief, specific identity, medical and health information, financial accounts or whereabouts is processed, the individual\u0026rsquo;s separate consent shall be obtained;\n(3) where the personal information of minors under the age of fourteen is processed, the consent of the minors\u0026rsquo; parents or other guardians shall be obtained;\n(4) personal information must not be processed beyond the purpose, method, categories and retention period consented to by the individual;\n(5) where an individual has clearly expressed that he or she does not consent to the processing of his or her personal information, consent must not be sought frequently;\n(6) where the purpose, method or categories of processing of personal information change, the individual\u0026rsquo;s consent shall be obtained anew.\nWhere laws and administrative regulations provide that written consent shall be obtained for the processing of sensitive personal information, those provisions shall prevail.\nArticle 23 Where an individual requests access to, a copy of, correction, supplementation or deletion of, or restriction on the processing of his or her personal information, or cancels an account or withdraws consent, the network data processor shall promptly accept the request and provide convenient methods and channels to support the individual\u0026rsquo;s exercise of rights, and must not impose unreasonable conditions to restrict the individual\u0026rsquo;s reasonable requests.\nArticle 24 Where non-essential personal information or personal information for which individual consent has not been lawfully obtained is inevitably collected through the use of automated collection technology, or where an individual cancels an account, the network data processor shall delete the personal information or anonymise it. Where the retention period provided for by laws and administrative regulations has not expired, or where deletion or anonymisation of personal information is technically difficult to achieve, the network data processor shall stop processing other than storage and the taking of necessary security protection measures.\nArticle 25 For a request to transfer personal information that meets the following conditions, the network data processor shall provide a channel for other network data processors designated by the individual to access and obtain the relevant personal information:\n(1) the true identity of the requesting person can be verified;\n(2) what is requested to be transferred is personal information provided with the individual\u0026rsquo;s consent or collected on the basis of a contract;\n(3) the transfer of the personal information is technically feasible;\n(4) the transfer of the personal information does not harm the lawful rights and interests of others.\nWhere the number of requests to transfer personal information clearly exceeds a reasonable range, the network data processor may charge a necessary fee based on the cost of transferring the personal information.\nArticle 26 Where a network data processor outside the territory of the People\u0026rsquo;s Republic of China processes the personal information of natural persons within the territory and, in accordance with Article 53 of the Personal Information Protection Law of the People\u0026rsquo;s Republic of China, establishes a dedicated institution or designates a representative within the territory, it shall report the name of the institution or the name and contact information of the representative to the cyberspace administration department of the city with districts where it is located; the cyberspace administration department shall promptly notify the relevant competent departments at the same level.\nArticle 27 Network data processors shall, periodically and by themselves or by engaging a professional institution, conduct compliance audits of their processing of personal information for compliance with laws and administrative regulations.\nArticle 28 A network data processor that processes the personal information of 10 million or more individuals shall also comply with the provisions of Articles 30 and 32 of these Regulations applicable to network data processors processing important data (hereinafter \u0026ldquo;processors of important data\u0026rdquo;).\nChapter IV Important data security Article 29 The national data security work coordinating mechanism shall coordinate the relevant departments in formulating a catalogue of important data and shall strengthen the protection of important data. All regions and departments shall, in accordance with the classified and graded protection system for data, determine the specific catalogues of important data for their region, department and relevant industries and fields, and apply key protection to the network data included in the catalogues.\nNetwork data processors shall identify and report important data in accordance with the relevant provisions of the State. Where data is confirmed to be important data, the relevant region or department shall promptly inform the network data processor or make it public. The network data processor shall perform its network data security protection responsibilities.\nThe State encourages network data processors to use technologies and products such as data labelling to improve the level of important data security management.\nArticle 30 A processor of important data shall designate a person responsible for network data security and a network data security management body. The network data security management body shall perform the following network data security protection responsibilities:\n(1) formulate and implement network data security management systems, operating procedures and emergency response plans for network data security incidents;\n(2) periodically organise network data security risk monitoring, risk assessment, emergency drills and publicity, education and training activities, and promptly handle network data security risks and incidents;\n(3) accept and handle complaints and reports about network data security.\nThe person responsible for network data security shall have professional knowledge of network data security and relevant management experience, shall be a member of the management of the network data processor, and shall have the authority to report network data security situations directly to the competent departments.\nA network data processor that controls important data of the specific categories and scale prescribed by the competent departments shall conduct security background checks on the person responsible for network data security and personnel in key positions and strengthen the training of the relevant personnel. In conducting the checks, it may apply to the public security organ and the State security organ for assistance.\nArticle 31 A processor of important data shall, before providing, entrusting the processing of, or jointly processing important data, conduct a risk assessment, except where this is for the performance of statutory duties or legal obligations.\nThe risk assessment shall focus on the following:\n(1) whether providing, entrusting the processing of or jointly processing network data, and the purpose, method and scope of the network data recipient\u0026rsquo;s processing of network data, are lawful, legitimate and necessary;\n(2) the risk of the network data provided, entrusted for processing or jointly processed being tampered with, destroyed, leaked or unlawfully acquired or used, and the risks to national security, the public interest or the lawful rights and interests of individuals and organisations;\n(3) the integrity and law-abiding conduct of the network data recipient;\n(4) whether the network data security requirements in the relevant contracts concluded or to be concluded with the network data recipient can effectively bind the recipient to perform its network data security protection obligations;\n(5) whether the technical and management measures taken or to be taken can effectively prevent risks such as the network data being tampered with, destroyed, leaked or unlawfully acquired or used;\n(6) other assessment contents prescribed by the competent departments.\nArticle 32 Where a processor of important data may affect the security of important data due to merger, division, dissolution, bankruptcy or other reasons, it shall take measures to safeguard network data security and report to the relevant competent departments at or above the provincial level the disposal plan for the important data and the name and contact information of the recipient; where the competent department is unclear, it shall report to the data security work coordinating mechanism at or above the provincial level.\nArticle 33 A processor of important data shall conduct a risk assessment of its network data processing activities each year and submit a risk assessment report to the relevant competent departments at or above the provincial level, and the relevant competent departments shall promptly notify the cyberspace administration departments and public security organs at the same level.\nThe risk assessment report shall include the following:\n(1) basic information on the network data processor, information on the network data security management body, and the name and contact information of the person responsible for network data security;\n(2) the purpose, categories, quantity, method, scope, storage period and storage location of the processing of important data, and the situation of network data processing activities, excluding the content of the network data itself;\n(3) the network data security management system and its implementation, and technical measures such as encryption, backup, labelling, access control and security authentication, other necessary measures and their effectiveness;\n(4) network data security risks discovered, and network data security incidents that occurred and their handling;\n(5) the risk assessment of providing, entrusting the processing of, or jointly processing important data;\n(6) the situation of network data cross-border transfer;\n(7) other report contents prescribed by the competent departments.\nA large online platform service provider processing important data shall, in addition to the contents in the preceding paragraph, fully explain the network data security situation of its key business and supply chain in its risk assessment report.\nWhere the processing activities of important data by a processor of important data may endanger national security, the relevant competent departments at or above the provincial level shall order it to take measures such as rectification or to stop processing important data. The processor of important data shall immediately take measures in accordance with the relevant requirements.\nChapter V Security administration of cross-border network data transfer Article 34 The national cyberspace administration department shall coordinate the relevant departments in establishing a special working mechanism for national data export security administration, studying and formulating national policies for the security administration of network data export, and coordinating the handling of major matters concerning network data export security.\nArticle 35 A network data processor may provide personal information abroad where one of the following conditions is met:\n(1) it has passed a data export security assessment organised by the national cyberspace administration department;\n(2) it has obtained personal information protection certification from a professional institution in accordance with the provisions of the national cyberspace administration department;\n(3) it complies with the provisions on standard contracts for the export of personal information formulated by the national cyberspace administration department;\n(4) it is truly necessary to provide personal information abroad for the conclusion or performance of a contract to which the individual is a party;\n(5) it is truly necessary to provide employees\u0026rsquo; personal information abroad for cross-border human resources management implemented in accordance with lawfully formulated labour rules and lawfully concluded collective contracts;\n(6) it is truly necessary to provide personal information abroad for the performance of statutory duties or legal obligations;\n(7) it is truly necessary to provide personal information abroad in an emergency to protect the life, health and property safety of natural persons;\n(8) other conditions provided for by laws, administrative regulations or the national cyberspace administration department.\nArticle 36 Where international treaties or agreements concluded or acceded to by the People\u0026rsquo;s Republic of China provide for the conditions for providing personal information outside the territory of the People\u0026rsquo;s Republic of China, those provisions may be followed.\nArticle 37 Where important data collected and generated by a network data processor in the course of its operations within the territory of the People\u0026rsquo;s Republic of China is truly necessary to be provided abroad, it shall pass a data export security assessment organised by the national cyberspace administration department. Where a network data processor has identified and reported important data in accordance with the relevant provisions of the State but has not been informed or publicly notified by the relevant region or department that the data is important data, it need not report it as important data for the data export security assessment.\nArticle 38 After passing a data export security assessment, a network data processor providing personal information and important data abroad must not exceed the purpose, method, scope, categories and scale of data export specified in the assessment.\nArticle 39 The State takes measures to prevent and handle network data cross-border security risks and threats. No individual or organisation may provide programs or tools specifically used to destroy or circumvent technical measures; where a person knows that another is engaged in activities such as destroying or circumventing technical measures, the person must not provide technical support or assistance to that other person.\nChapter VI Obligations of online platform service providers Article 40 Online platform service providers shall, through platform rules or contracts, clarify the network data security protection obligations of third-party product and service providers accessing their platforms, and urge third-party product and service providers to strengthen network data security management.\nThe preceding paragraph applies to producers of devices such as smart terminals with pre-installed applications.\nWhere a third-party product or service provider carries out network data processing activities in violation of laws and administrative regulations, platform rules or contractual agreements and causes harm to users, the online platform service provider, the third-party product or service provider and the producer of devices such as smart terminals with pre-installed applications shall bear corresponding liability in accordance with law.\nThe State encourages insurance companies to develop insurance products covering liability for damage caused by network data and encourages online platform service providers and producers of devices such as smart terminals with pre-installed applications to take out such insurance.\nArticle 41 An online platform service provider providing application distribution services shall establish verification rules for applications and carry out verification relating to network data security. Where it discovers that an application to be distributed or already distributed does not comply with laws and administrative regulations or the mandatory requirements of national standards, it shall take measures such as issuing a warning, refusing distribution, suspending distribution or terminating distribution.\nArticle 42 Where an online platform service provider pushes information to individuals through automated decision-making, it shall provide an easy-to-understand, easy-to-access and easy-to-operate option to turn off personalised recommendations, and provide users with functions such as refusing to receive pushed information and deleting user tags targeting their personal characteristics.\nArticle 43 The State promotes the building of a national public service for online identity authentication, which is promoted and applied on the principle of government guidance and user voluntariness.\nOnline platform service providers are encouraged to support users in using the national public service for online identity authentication to register and verify their true identity information.\nArticle 44 Large online platform service providers shall publish an annual social responsibility report on personal information protection, covering, among other things, personal information protection measures and their results, the handling of applications for individuals to exercise their rights, and the performance of duties by the personal information protection supervision body composed mainly of external members.\nArticle 45 Where a large online platform service provider provides network data across borders, it shall comply with the State\u0026rsquo;s requirements for the security administration of cross-border data, improve the relevant technical and management measures, and prevent network data cross-border security risks.\nArticle 46 A large online platform service provider must not use network data, algorithms or platform rules to engage in the following activities:\n(1) processing the network data generated by users on the platform by misleading, deceiving or coercing users;\n(2) restricting users\u0026rsquo; access to or use of the network data generated by them on the platform without justified reasons;\n(3) applying unreasonable differential treatment to users, harming users\u0026rsquo; lawful rights and interests;\n(4) other activities prohibited by laws and administrative regulations.\nChapter VII Supervision and administration Article 47 The national cyberspace administration department is responsible for coordinating network data security and the related supervision and administration.\nPublic security organs and State security organs shall, in accordance with the provisions of relevant laws and administrative regulations and these Regulations, assume network data security supervision and administration duties within the scope of their respective duties, and prevent and combat illegal and criminal activities endangering network data security in accordance with law.\nThe national data management department shall perform the corresponding network data security duties in the specific work of data management.\nAll regions and departments are responsible for the network data collected and generated in the work of their region or department and for the security of that network data.\nArticle 48 The relevant competent departments shall assume network data security supervision and administration duties for their respective industries and fields, designate the bodies responsible for network data security protection in their respective industries and fields, coordinate the formulation and organisation of the implementation of emergency response plans for network data security incidents in their respective industries and fields, periodically organise network data security risk assessments in their respective industries and fields, supervise and inspect the performance by network data processors of their network data security protection obligations, and guide and urge network data processors to promptly rectify existing risks and hidden dangers.\nArticle 49 The national cyberspace administration department shall coordinate the relevant competent departments in promptly compiling, assessing, sharing and publishing information related to network data security risks, and in strengthening the sharing of network data security information, the monitoring and early warning of network data security risks and threats, and the emergency handling of network data security incidents.\nArticle 50 The relevant competent departments may take the following measures to supervise and inspect network data security:\n(1) require network data processors and the relevant personnel to explain matters relating to the supervision and inspection;\n(2) consult and copy documents and records relating to network data security;\n(3) inspect the operation of network data security measures;\n(4) inspect equipment and articles relating to network data processing activities;\n(5) other necessary measures provided for by laws and administrative regulations.\nNetwork data processors shall cooperate with the network data security supervision and inspection carried out by the relevant competent departments in accordance with law.\nArticle 51 In carrying out network data security supervision and inspection, the relevant competent departments shall be objective and impartial and must not charge fees to the entities inspected.\nIn network data security supervision and inspection, the relevant competent departments must not access or collect business information unrelated to network data security, and the information obtained may only be used for the needs of maintaining network data security and must not be used for other purposes.\nWhere the relevant competent departments discover that a network data processor\u0026rsquo;s network data processing activities involve relatively serious security risks, they may, in accordance with the prescribed powers and procedures, require the network data processor to suspend the relevant services, revise platform rules, improve technical measures, etc. so as to eliminate hidden dangers to network data security.\nArticle 52 In carrying out network data security supervision and inspection, the relevant competent departments shall strengthen coordination and information communication, reasonably determine the frequency and methods of inspection, and avoid unnecessary inspections and duplicative overlapping inspections.\nPersonal information protection compliance audits, important data risk assessments, important data export security assessments and the like shall be better connected so as to avoid duplicative assessment and auditing. Where the contents of an important data risk assessment and a cybersecurity classified protection evaluation overlap, the relevant results may be mutually accepted.\nArticle 53 The relevant competent departments and their staff shall, in accordance with law, keep confidential the personal privacy, personal information, trade secrets and confidential business information and other network data learned in the performance of their duties, and must not divulge them or unlawfully provide them to others.\nArticle 54 Where an organisation or individual outside the territory engages in network data processing activities that endanger the national security or public interest of the People\u0026rsquo;s Republic of China, or infringe the personal information rights and interests of citizens of the People\u0026rsquo;s Republic of China, the national cyberspace administration department, together with the relevant competent departments, may take corresponding necessary measures in accordance with law.\nChapter VIII Legal liability Article 55 Where the provisions of Articles 12, 16 to 20, 22, the first and second paragraphs of Article 40, Article 41 and Article 42 of these Regulations are violated, the competent departments for cyberspace administration, telecommunications and public security shall, in accordance with their respective duties, order correction, give a warning and confiscate the unlawful gains; where the offender refuses to correct or the circumstances are serious, a fine of not more than RMB 1,000,000 shall be imposed, and the competent departments may order the suspension of the relevant business, suspension of business for rectification, revocation of the relevant business licence or revocation of the business licence, and may impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons.\nArticle 56 Where Article 13 of these Regulations is violated, the competent departments for cyberspace administration, telecommunications, public security and State security shall, in accordance with their respective duties, order correction, give a warning and may concurrently impose a fine of not less than RMB 100,000 and not more than RMB 1,000,000, and may impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons; where the offender refuses to correct or the circumstances are serious, a fine of not less than RMB 1,000,000 and not more than RMB 10,000,000 shall be imposed, and the competent departments may order the suspension of the relevant business, suspension of business for rectification, revocation of the relevant business licence or revocation of the business licence, and shall impose a fine of not less than RMB 100,000 and not more than RMB 1,000,000 on the directly responsible persons in charge and other directly responsible persons.\nArticle 57 Where the second paragraph of Article 29, the second and third paragraphs of Article 30, Article 31 or Article 32 of these Regulations are violated, the competent departments for cyberspace administration, telecommunications and public security shall, in accordance with their respective duties, order correction, give a warning and may concurrently impose a fine of not less than RMB 50,000 and not more than RMB 500,000, and may impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons; where the offender refuses to correct or causes serious consequences such as the leakage of a large volume of data, a fine of not less than RMB 500,000 and not more than RMB 2,000,000 shall be imposed, and the competent departments may order the suspension of the relevant business, suspension of business for rectification, revocation of the relevant business licence or revocation of the business licence, and shall impose a fine of not less than RMB 50,000 and not more than RMB 200,000 on the directly responsible persons in charge and other directly responsible persons.\nArticle 58 Where other relevant provisions of these Regulations are violated, the relevant competent departments shall pursue legal liability in accordance with the relevant provisions of the Cybersecurity Law of the People\u0026rsquo;s Republic of China, the Data Security Law of the People\u0026rsquo;s Republic of China, the Personal Information Protection Law of the People\u0026rsquo;s Republic of China and other laws.\nArticle 59 Where a network data processor voluntarily eliminates or mitigates the harmful consequences of an unlawful act, or the unlawful act is minor and promptly corrected without causing harmful consequences, or it is a first violation with minor harmful consequences that is promptly corrected, a mitigated or reduced administrative penalty shall be imposed or no administrative penalty shall be imposed in accordance with the provisions of the Administrative Penalty Law of the People\u0026rsquo;s Republic of China.\nArticle 60 Where a State organ fails to perform the network data security protection obligations provided for in these Regulations, its superior authority or the relevant competent department shall order it to correct; the directly responsible persons in charge and other directly responsible persons shall be given sanctions in accordance with law.\nArticle 61 Where a violation of these Regulations causes damage to another person, civil liability shall be borne in accordance with law; where the act constitutes a violation of public security administration, a public security administration penalty shall be imposed in accordance with law; where a crime is constituted, criminal liability shall be pursued in accordance with law.\nChapter IX Supplementary provisions Article 62 For the purposes of these Regulations, the following terms have the meanings set out below:\n(1) \u0026ldquo;network data\u0026rdquo; means various electronic data processed and generated through networks;\n(2) \u0026ldquo;network data processing activities\u0026rdquo; means activities such as the collection, storage, use, processing, transmission, provision, disclosure and deletion of network data;\n(3) \u0026ldquo;network data processor\u0026rdquo; means an individual or organisation that independently determines the processing purpose and processing method in network data processing activities;\n(4) \u0026ldquo;important data\u0026rdquo; means data in a specific field, for a specific group or in a specific region, or of a certain precision and scale, which, once tampered with, destroyed, leaked, or unlawfully acquired or used, may directly endanger national security, economic operation, social stability, or public health and safety;\n(5) \u0026ldquo;entrusted processing\u0026rdquo; means network data processing activities carried out by an individual or organisation entrusted by a network data processor in accordance with the agreed purpose and method;\n(6) \u0026ldquo;joint processing\u0026rdquo; means network data processing activities in which two or more network data processors jointly determine the processing purpose and processing method of network data;\n(7) \u0026ldquo;separate consent\u0026rdquo; means a specific and explicit consent specially given by an individual for specific processing of his or her personal information;\n(8) \u0026ldquo;large online platform\u0026rdquo; means an online platform with more than 50 million registered users or more than 10 million monthly active users, with complex business types, whose network data processing activities have an important impact on national security, economic operation, the national economy and people\u0026rsquo;s livelihood.\nArticle 63 Network data processing activities involving core data shall be carried out in accordance with the relevant provisions of the State.\nThese Regulations do not apply to natural persons processing personal information for personal or family affairs.\nNetwork data processing activities involving State secrets or work secrets shall be governed by the provisions of laws and administrative regulations such as the Law of the People\u0026rsquo;s Republic of China on Guarding State Secrets.\nArticle 64 These Regulations shall come into force on 1 January 2025.\n","permalink":"https://ai.intlaws.com/en/compliance/china/network-data-security-regulations/","summary":"Full text of the Regulations on the Administration of Network Data Security (State Council Order No. 790, promulgated 24 September 2024, effective 1 January 2025), 64 articles in nine chapters: classified and graded protection, personal information processing rules, important data (security officer, annual risk assessment), cross-border transfer (assessment, certification, standard contract), obligations of large online platforms, supervision, and penalties of up to RMB 10 million. English translation by our editorial team (non-official).","title":"Regulations on the Administration of Network Data Security"},{"content":" Version and sources (verifiable)\nItem Content Instrument HB 149 (89th Texas Legislature) — the Texas Responsible Artificial Intelligence Governance Act (\u0026quot;TRAIGA\u0026quot;) Enacted text creates Business \u0026amp; Commerce Code Chapters 551–554; this page reproduces Chapter 552 (Artificial Intelligence Protection) in full Effective 1 January 2026 (per the enrolled act\u0026rsquo;s effective-date provision) Structure Chapter 552: 16 sections (552.001–552.003 general; 552.051–552.057 protections; 552.101–552.106 enforcement) Official text Enrolled bill text (HB 149) ｜ codified chapter Scope note This page covers Chapter 552 only. The same act also creates Chapter 551 (general provisions), Chapter 553 (AI regulatory sandbox programme) and Chapter 554 (Texas Artificial Intelligence Council) — those chapters are not reproduced here. Chinese version No official Chinese text. A Chinese translation by our editorial team, marked non-official, is available → 中文全文 Retrieval \u0026amp; verification Retrieved 2026-09-22 from the enrolled bill text published by the Texas Legislature; section numbering (552.001–552.106) and subsection markers checked against the published text. CHAPTER 552. ARTIFICIAL INTELLIGENCE PROTECTION SUBCHAPTER A. GENERAL PROVISIONS\nSec. 552.001. DEFINITIONS. In this chapter:\n(1) \u0026ldquo;Deployer\u0026rdquo; means a person who deploys an\nartificial intelligence system for use in this state.\n(2) \u0026ldquo;Developer\u0026rdquo; means a person who develops an\nartificial intelligence system that is offered, sold, leased,\ngiven, or otherwise provided in this state.\n(3) \u0026ldquo;Governmental entity\u0026rdquo; means any department,\ncommission, board, office, authority, or other administrative unit\nof this state or of any political subdivision of this state, that\nexercises governmental functions under the authority of the laws of\nthis state. The term does not include:\n(A) a hospital district created under the Health\nand Safety Code or Article IX, Texas Constitution; or\n(B) an institution of higher education, as\ndefined by Section 61.003, Education Code, including any university\nsystem or any component institution of the system.\nSec. 552.002. CONSTRUCTION OF CHAPTER. This chapter may\nnot be construed to:\n(1) impose a requirement on a person that adversely\naffects the rights or freedoms of any person, including the right of\nfree speech; or\n(2) authorize any department or agency other than the\nDepartment of Insurance to regulate or oversee the business of\ninsurance.\nSec. 552.003. LOCAL PREEMPTION. This chapter supersedes\nand preempts any ordinance, resolution, rule, or other regulation\nadopted by a political subdivision regarding the use of artificial\nintelligence systems.\nSUBCHAPTER B. DUTIES AND PROHIBITIONS ON USE OF ARTIFICIAL\nINTELLIGENCE\nSec. 552.051. DISCLOSURE TO CONSUMERS.\n(a) In this\nsection, \u0026ldquo;health care services\u0026rdquo; means services related to human\nhealth or to the diagnosis, prevention, or treatment of a human\ndisease or impairment provided by an individual licensed,\nregistered, or certified under applicable state or federal law to\nprovide those services.\n(b) A governmental agency that makes available an\nartificial intelligence system intended to interact with consumers\nshall disclose to each consumer, before or at the time of\ninteraction, that the consumer is interacting with an artificial\nintelligence system.\n(c) A person is required to make the disclosure under\nSubsection\n(b) regardless of whether it would be obvious to a\nreasonable consumer that the consumer is interacting with an\nartificial intelligence system.\n(d) A disclosure under Subsection (b):\n(1) must be clear and conspicuous;\n(2) must be written in plain language; and\n(3) may not use a dark pattern, as that term is defined\nby Section 541.001.\n(e) A disclosure under Subsection\n(b) may be provided by\nusing a hyperlink to direct a consumer to a separate Internet web\npage.\n(f) If an artificial intelligence system is used in relation\nto health care service or treatment, the provider of the service or\ntreatment shall provide the disclosure under Subsection\n(b) to the\nrecipient of the service or treatment or the recipient\u0026rsquo;s personal\nrepresentative not later than the date the service or treatment is\nfirst provided, except in the case of emergency, in which case the\nprovider shall provide the required disclosure as soon as\nreasonably possible.\nSec. 552.052. MANIPULATION OF HUMAN BEHAVIOR. A person may\nnot develop or deploy an artificial intelligence system in a manner\nthat intentionally aims to incite or encourage a person to:\n(1) commit physical self-harm, including suicide;\n(2) harm another person; or\n(3) engage in criminal activity.\nSec. 552.053. SOCIAL SCORING. A governmental entity may\nnot use or deploy an artificial intelligence system that evaluates\nor classifies a natural person or group of natural persons based on\nsocial behavior or personal characteristics, whether known,\ninferred, or predicted, with the intent to calculate or assign a\nsocial score or similar categorical estimation or valuation of the\nperson or group of persons that results or may result in:\n(1) detrimental or unfavorable treatment of a person\nor group of persons in a social context unrelated to the context in\nwhich the behavior or characteristics were observed or noted;\n(2) detrimental or unfavorable treatment of a person\nor group of persons that is unjustified or disproportionate to the\nnature or gravity of the observed or noted behavior or\ncharacteristics; or\n(3) the infringement of any right guaranteed under the\nUnited States Constitution, the Texas Constitution, or state or\nfederal law.\nSec. 552.054. CAPTURE OF BIOMETRIC DATA.\n(a) In this\nsection, \u0026ldquo;biometric data\u0026rdquo; means data generated by automatic\nmeasurements of an individual\u0026rsquo;s biological characteristics. The\nterm includes a fingerprint, voiceprint, eye retina or iris, or\nother unique biological pattern or characteristic that is used to\nidentify a specific individual. The term does not include a\nphysical or digital photograph or data generated from a physical or\ndigital photograph, a video or audio recording or data generated\nfrom a video or audio recording, or information collected, used, or\nstored for health care treatment, payment, or operations under the\nHealth Insurance Portability and Accountability Act of 1996 (42\nU.S.C. Section 1320d et seq.).\n(b) A governmental entity may not develop or deploy an\nartificial intelligence system for the purpose of uniquely\nidentifying a specific individual using biometric data or the\ntargeted or untargeted gathering of images or other media from the\nInternet or any other publicly available source without the\nindividual\u0026rsquo;s consent, if the gathering would infringe on any right\nof the individual under the United States Constitution, the Texas\nConstitution, or state or federal law.\n(c) A violation of Section 503.001 is a violation of this\nsection.\nSec. 552.055. CONSTITUTIONAL PROTECTION.\n(a) A person may\nnot develop or deploy an artificial intelligence system with the\nsole intent for the artificial intelligence system to infringe,\nrestrict, or otherwise impair an individual\u0026rsquo;s rights guaranteed\nunder the United States Constitution.\n(b) This section is remedial in purpose and may not be\nconstrued to create or expand any right guaranteed by the United\nStates Constitution.\nSec. 552.056. UNLAWFUL DISCRIMINATION.\n(a) In this\nsection:\n(1) \u0026ldquo;Financial institution\u0026rdquo; has the meaning assigned\nby Section 201.101, Finance Code.\n(2) \u0026ldquo;Insurance entity\u0026rdquo; means:\n(A) an entity described by Section 82.002(a),\nInsurance Code;\n(B) a fraternal benefit society regulated under\nChapter 885, Insurance Code; or\n(C) the developer of an artificial intelligence\nsystem used by an entity described by Paragraph (A) or (B).\n(3) \u0026ldquo;Protected class\u0026rdquo; means a group or class of\npersons with a characteristic, quality, belief, or status protected\nfrom discrimination by state or federal civil rights laws, and\nincludes race, color, national origin, sex, age, religion, or\ndisability.\n(b) A person may not develop or deploy an artificial\nintelligence system with the intent to unlawfully discriminate\nagainst a protected class in violation of state or federal law.\n(c) For purposes of this section, a disparate impact is not\nsufficient by itself to demonstrate an intent to discriminate.\n(d) This section does not apply to an insurance entity for\npurposes of providing insurance services if the entity is subject\nto applicable statutes regulating unfair discrimination, unfair\nmethods of competition, or unfair or deceptive acts or practices\nrelated to the business of insurance.\n(e) A federally insured financial institution is considered\nto be in compliance with this section if the institution complies\nwith all federal and state banking laws and regulations.\nSec. 552.057. CERTAIN SEXUALLY EXPLICIT CONTENT AND CHILD\nPORNOGRAPHY. A person may not:\n(1) develop or distribute an artificial intelligence\nsystem with the sole intent of producing, assisting or aiding in\nproducing, or distributing:\n(A) visual material in violation of Section\n43.26, Penal Code; or\n(B) deep fake videos or images in violation of\nSection 21.165, Penal Code; or\n(2) intentionally develop or distribute an artificial\nintelligence system that engages in text-based conversations that\nsimulate or describe sexual conduct, as that term is defined by\nSection 43.25, Penal Code, while impersonating or imitating a child\nyounger than 18 years of age.\nSUBCHAPTER C. ENFORCEMENT\nSec. 552.101. ENFORCEMENT AUTHORITY.\n(a) The attorney\ngeneral has exclusive authority to enforce this chapter, except to\nthe extent provided by Section 552.106.\n(b) This chapter does not provide a basis for, and is not\nsubject to, a private right of action for a violation of this\nchapter or any other law.\nSec. 552.102. INFORMATION AND COMPLAINTS. The attorney\ngeneral shall create and maintain an online mechanism on the\nattorney general\u0026rsquo;s Internet website through which a consumer may\nsubmit a complaint under this chapter to the attorney general.\nSec. 552.103. INVESTIGATIVE AUTHORITY.\n(a) If the\nattorney general receives a complaint through the online mechanism\nunder Section 552.102 alleging a violation of this chapter, the\nattorney general may issue a civil investigative demand to\ndetermine if a violation has occurred. The attorney general shall\nissue demands in accordance with and under the procedures\nestablished under Section 15.10.\n(b) The attorney general may request from the person\nreported through the online mechanism, pursuant to a civil\ninvestigative demand issued under Subsection (a):\n(1) a high-level description of the purpose, intended\nuse, deployment context, and associated benefits of the artificial\nintelligence system with which the person is affiliated;\n(2) a description of the type of data used to program\nor train the artificial intelligence system;\n(3) a high-level description of the categories of data\nprocessed as inputs for the artificial intelligence system;\n(4) a high-level description of the outputs produced\nby the artificial intelligence system;\n(5) any metrics the person uses to evaluate the\nperformance of the artificial intelligence system;\n(6) any known limitations of the artificial\nintelligence system;\n(7) a high-level description of the post-deployment\nmonitoring and user safeguards the person uses for the artificial\nintelligence system, including, if the person is a deployer, the\noversight, use, and learning process established by the person to\naddress issues arising from the system\u0026rsquo;s deployment; or\n(8) any other relevant documentation reasonably\nnecessary for the attorney general to conduct an investigation\nunder this section.\nSec. 552.104. NOTICE OF VIOLATION; OPPORTUNITY TO CURE\n(a) If the attorney general determines that a person has violated\nor is violating this chapter, the attorney general shall notify the\nperson in writing of the determination, identifying the specific\nprovisions of this chapter the attorney general alleges have been\nor are being violated.\n(b) The attorney general may not bring an action against the\nperson:\n(1) before the 60th day after the date the attorney\ngeneral provides the notice under Subsection (a); or\n(2) if, before the 60th day after the date the attorney\ngeneral provides the notice under Subsection (a), the person:\n(A) cures the identified violation; and\n(B) provides the attorney general with a written\nstatement that the person has:\n(i) cured the alleged violation;\n(ii) provided supporting documentation to\nshow the manner in which the person cured the violation; and\n(iii) made any necessary changes to\ninternal policies to reasonably prevent further violation of this\nchapter.\nSec. 552.105. CIVIL PENALTY; INJUNCTION.\n(a) A person who\nviolates this chapter and does not cure the violation under Section\n552.104 is liable to this state for a civil penalty in an amount of:\n(1) for each violation the court determines to be\ncurable or a breach of a statement submitted to the attorney general\nunder Section 552.104(b)(2), not less than $10,000 and not more\nthan $12,000;\n(2) for each violation the court determines to be\nuncurable, not less than $80,000 and not more than $200,000; and\n(3) for a continued violation, not less than $2,000\nand not more than $40,000 for each day the violation continues.\n(b) The attorney general may bring an action in the name of\nthis state to:\n(1) collect a civil penalty under this section;\n(2) seek injunctive relief against further violation\nof this chapter; and\n(3) recover attorney\u0026rsquo;s fees and reasonable court costs\nor other investigative expenses.\n(c) There is a rebuttable presumption that a person used\nreasonable care as required under this chapter.\n(d) A defendant in an action under this section may seek an\nexpedited hearing or other process, including a request for\ndeclaratory judgment, if the person believes in good faith that the\nperson has not violated this chapter.\n(e) A defendant in an action under this section may not be\nfound liable if:\n(1) another person uses the artificial intelligence\nsystem affiliated with the defendant in a manner prohibited by this\nchapter; or\n(2) the defendant discovers a violation of this\nchapter through:\n(A) feedback from a developer, deployer, or other\nperson who believes a violation has occurred;\n(B) testing, including adversarial testing or\nred-team testing;\n(C) following guidelines set by applicable state\nagencies; or\n(D) if the defendant substantially complies with\nthe most recent version of the \u0026ldquo;Artificial Intelligence Risk\nManagement Framework: Generative Artificial Intelligence Profile\u0026rdquo;\npublished by the National Institute of Standards and Technology or\nanother nationally or internationally recognized risk management\nframework for artificial intelligence systems, an internal review\nprocess.\n(f) The attorney general may not bring an action to collect\na civil penalty under this section against a person for an\nartificial intelligence system that has not been deployed.\nSec. 552.106. ENFORCEMENT ACTIONS BY STATE AGENCIES.\n(a) A\nstate agency may impose sanctions against a person licensed,\nregistered, or certified by that agency for a violation of\nSubchapter B if:\n(1) the person has been found in violation of this\nchapter under Section 552.105; and\n(2) the attorney general has recommended additional\nenforcement by the applicable agency.\n(b) Sanctions under this section may include:\n(1) suspension, probation, or revocation of a license,\nregistration, certificate, or other authorization to engage in an\nactivity; and\n(2) a monetary penalty not to exceed $100,000.\n","permalink":"https://ai.intlaws.com/en/compliance/us/texas-traiga-chapter-552/","summary":"Official text of Chapter 552 (Artificial Intelligence Protection) of the Texas Business \u0026amp; Commerce Code, enacted by HB 149 — the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), effective 1 January 2026. Sixteen sections: definitions, construction, local preemption, disclosure to consumers, prohibition of manipulation of human behaviour, social scoring (governmental entities only), capture of biometric data, constitutional protection, unlawful discrimination, sexually explicit content and child protection, and enforcement by the attorney general (investigations, notice and cure, civil penalties, injunctions).","title":"Texas Artificial Intelligence Protection Act"},{"content":" Version and sources (verifiable)\nItem Content Adopted 24 December 2024 by UNGA resolution 79/243; contained in the annex Structure Preamble + 9 chapters, 68 articles Entry into force Article 65: ninetieth day after deposit of the fortieth instrument of ratification, acceptance, approval or accession (verified from the official text) Status Not yet in force (as of 2026-09-22; see UN Treaty Collection https://treaties.un.org ) English source UNODC: https://www.unodc.org/unodc/en/cybercrime/convention/text/convention-full-text.html ; official document A/RES/79/243 (English): https://documents.un.org/api/symbol/access?s=A%2FRES%2F79%2F243\u0026amp;l=en\u0026amp;t=pdf Verification Retrieved 2026-09-22; 68 articles correspond one-for-one with the Chinese official text; the Article 47 heading (missing from the UN PDF text layer) was restored from the official UNODC HTML text and cross-checked against the Chinese official text Chapter I: General provisions Article 1 Statement of purpose\nThe purposes of this Convention are to:\n(a) Promote and strengthen measures to prevent and combat cybercrime more efficiently and effectively;\n(b) Promote, facilitate and strengthen international cooperation in preventing and combating cybercrime; and\n(c) Promote, facilitate and support technical assistance and capacity-building to prevent and combat cybercrime, in particular for the benefit of developing countries.\nArticle 2 Use of terms\nFor the purposes of this Convention:\n(a) “Information and communications technology system” shall mean any device or group of interconnected or related devices, one or more of which, pursuant to a program, gathers, stores and performs automatic processing of electronic data;\n(b) “Electronic data” shall mean any representation of facts, information or concepts in a form suitable for processing in an information and communications technology system, including a program suitable to cause an information and communications technology system to perform a function;\n(c) “Traffic data” shall mean any electronic data relating to a communication by means of an information and communications technology system, generated by an information and communications technology system that formed a part in the chain of communication, indicating the communication’s origin, destination, route, time, date, size, duration or type of underlying service;\n(d) “Content data” shall mean any electronic data, other than subscriber information or traffic data, relating to the substance of the data transferred by an information and communications technology system, including, but not limited to, images, text messages, voice messages, audio recordings and video recordings;\n(e) “Service provider” shall mean any public or private entity that:\n(f) “Subscriber information” shall mean any information that is held by a service provider, relating to subscribers of its services other than traffic or content data and by which can be established:\n(g) “Personal data” shall mean any information relating to an identified or identifiable natural person;\n(h) “Serious crime” shall mean conduct constituting an offence punishable by a maximum deprivation of liberty of at least four years or a more serious penalty;\n(i) “Property” shall mean assets of every kind, whether corporeal or incorporeal, movable or immovable, tangible or intangible, including virtual assets, and legal documents or instruments evidencing title to, or interest in, such assets;\n(j) “Proceeds of crime” shall mean any property derived from or obtained, directly or indirectly, through the commission of an offence;\n(k) “Freezing” or “seizure” shall mean temporarily prohibiting the transfer, conversion, disposition or movement of property or temporarily assuming custody or control of property on the basis of an order issued by a court or other competent authority;\n(l) “Confiscation”, which includes forfeiture where applicable, shall mean the permanent deprivation of property by order of a court or other competent authority;\n(m) “Predicate offence” shall mean any offence as a result of which proceeds have been generated that may become the subject of an offence as defined in article 17 of this Convention;\n(n) “Regional economic integration organization” shall mean an organization constituted by sovereign States of a given region to which its member States have transferred competence in respect of matters governed by this Convention and which has been duly authorized, in accordance with its internal procedures, to sign, ratify, accept, approve or accede to it; references to “States Parties” under this Convention shall apply to such organizations within the limits of their competence;\n(o) “Emergency” shall mean a situation in which there is a significant and imminent risk to the life or safety of any natural person.\nArticle 3 Scope of application\nThis Convention shall apply, except as otherwise stated herein, to:\n(a) The prevention, investigation and prosecution of the criminal offences established in accordance with this Convention, including the freezing, seizure, confiscation and return of the proceeds from such offences;\n(b) The collecting, obtaining, preserving and sharing of evidence in electronic form for the purpose of criminal investigations or proceedings, as provided for in articles 23 and 35 of this Convention.\nArticle 4 Offences established in accordance with other United Nations conventions and protocols\nIn giving effect to other applicable United Nations conventions and protocols to which they are Parties, States Parties shall ensure that criminal offences established in accordance with such conventions and protocols are also considered criminal offences under domestic law when committed through the use of information and communications technology systems. Nothing in this article shall be interpreted as establishing criminal offences in accordance with this Convention. Article 5 Protection of sovereignty\nStates Parties shall carry out their obligations under this Convention in a manner consistent with the principles of sovereign equality and territorial integrity of States and that of non-intervention in the domestic affairs of other States. Nothing in this Convention shall entitle a State Party to undertake in the territory of another State the exercise of jurisdiction and performance of functions that are reserved exclusively for the authorities of that other State by its domestic law. Article 6 Respect for human rights\nStates Parties shall ensure that the implementation of their obligations under this Convention is consistent with their obligations under international human rights law. Nothing in this Convention shall be interpreted as permitting suppression of human rights or fundamental freedoms, including the rights related to the freedoms of expression, conscience, opinion, religion or belief, peaceful assembly and association, in accordance and in a manner consistent with applicable international human rights law. Chapter II: Criminalization Article 7 Illegal access\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as a criminal offence under its domestic law, when committed intentionally, the access to the whole or any part of an information and communications technology system without right. A State Party may require that the offence be committed by infringing security measures, with the intent of obtaining electronic data or other dishonest or criminal intent or in relation to an information and communications technology system that is connected to another information and communications technology system. Article 8 Illegal interception\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the interception, made by technical means, of non‑public transmissions of electronic data to, from or within an information and communications technology system, including electromagnetic emissions from an information and communications technology system carrying such electronic data. A State Party may require that the offence be committed with dishonest or criminal intent, or in relation to an information and communications technology system that is connected to another information and communications technology system. Article 9 Interference with electronic data\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the damaging, deletion, deterioration, alteration or suppression of electronic data. A State Party may require that the conduct described in paragraph 1 of this article result in serious harm. Article 10 Interference with an information and communications technology system\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the serious hindering of the functioning of an information and communications technology system by inputting, transmitting, damaging, deleting, deteriorating, altering or suppressing electronic data.\nArticle 11 Misuse of devices\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right:\n(a) The obtaining, production, sale, procurement for use, import, distribution or otherwise making available of:\nwith the intent that the device, including a program, or the password, access credentials, electronic signature or similar data be used for the purpose of committing any of the offences established in accordance with articles 7 to 10 of this Convention; and\n(b) The possession of an item referred to in paragraph 1 (a) (i) or (ii) of this article, with intent that it be used for the purpose of committing any of the offences established in accordance with articles 7 to 10 of this Convention. This article shall not be interpreted as imposing criminal liability where the obtaining, production, sale, procurement for use, import, distribution or otherwise making available, or the possession referred to in paragraph 1 of this article is not for the purpose of committing an offence established in accordance with articles 7 to 10 of this Convention, such as for the authorized testing or protection of an information and communications technology system. Each State Party may reserve the right not to apply paragraph 1 of this article, provided that the reservation does not concern the sale, distribution or otherwise making available of the items referred to in paragraph 1 (a) (ii) of this article. Article 12 Information and communications technology system-related forgery\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the input, alteration, deletion or suppression of electronic data resulting in inauthentic data with the intent that they be considered or acted upon for legal purposes as if they were authentic, regardless of whether or not the data are directly readable and intelligible. A State Party may require an intent to defraud, or a similar dishonest or criminal intent, before criminal liability attaches. Article 13 Information and communications technology system-related theft or fraud\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as a criminal offence under its domestic law, when committed intentionally and without right, the causing of a loss of property to another person by means of:\n(a) Any input, alteration, deletion or suppression of electronic data;\n(b) Any interference with the functioning of an information and communications technology system;\n(c) Any deception as to factual circumstances made through an information and communications technology system that causes a person to do or omit to do anything which that person would not otherwise do or omit to do;\nwith the fraudulent or dishonest intent of procuring for oneself or for another person, without right, a gain in money or other property.\nArticle 14 Offences related to online child sexual abuse or child sexual exploitation material\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the following conduct:\n(a) Producing, offering, selling, distributing, transmitting, broadcasting, displaying, publishing or otherwise making available child sexual abuse or child sexual exploitation material through an information and communications technology system;\n(b) Soliciting, procuring or accessing child sexual abuse or child sexual exploitation material through an information and communications technology system;\n(c) Possessing or controlling child sexual abuse or child sexual exploitation material stored in an information and communications technology system or another storage medium;\n(d) Financing the offences established in accordance with subparagraphs (a) to (c) of this paragraph, which States Parties may establish as a separate offence. For the purposes of this article, the term “child sexual abuse or child sexual exploitation material” shall include visual material, and may include written or audio content, that depicts, describes or represents any person under 18 years of age:\n(a) Engaging in real or simulated sexual activity;\n(b) In the presence of a person engaging in any sexual activity;\n(c) Whose sexual parts are displayed for primarily sexual purposes; or\n(d) Subjected to torture or cruel, inhumane or degrading treatment or punishment and such material is sexual in nature. A State Party may require that the material identified in paragraph 2 of this article be limited to material that:\n(a) Depicts, describes or represents an existing person; or\n(b) Visually depicts child sexual abuse or child sexual exploitation. In accordance with their domestic law and consistent with applicable international obligations, States Parties may take steps to exclude the criminalization of:\n(a) Conduct by children for self-generated material depicting them; or\n(b) The consensual production, transmission, or possession of material described in paragraph 2 (a) to (c) of this article, where the underlying conduct depicted is legal as determined by domestic law, and where such material is maintained exclusively for the private and consensual use of the persons involved. Nothing in this Convention shall affect any international obligations which are more conducive to the realization of the rights of the child. Article 15 Solicitation or grooming for the purpose of committing a sexual offence against a child\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law the act of intentionally communicating, soliciting, grooming, or making any arrangement through an information and communications technology system for the purpose of committing a sexual offence against a child, as defined in domestic law, including for the commission of any of the offences established in accordance with article 14 of this Convention. A State Party may require an act in furtherance of the conduct described in paragraph 1 of this article. A State Party may consider extending criminalization in accordance with paragraph 1 of this article in relation to a person believed to be a child. States Parties may take steps to exclude the criminalization of conduct as described in paragraph 1 of this article when committed by children. Article 16 Non-consensual dissemination of intimate images\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the selling, distributing, transmitting, publishing or otherwise making available of an intimate image of a person by means of an information and communications technology system, without the consent of the person depicted in the image. For the purpose of paragraph 1 of this article, “intimate image” shall mean a visual recording of a person over the age of 18 years made by any means, including a photograph or video recording, that is sexual in nature, in which the person’s sexual parts are exposed or the person is engaged in sexual activity, which was private at the time of the recording, and in respect of which the person or persons depicted maintained a reasonable expectation of privacy at the time of the offence. A State Party may extend the definition of intimate images, as appropriate, to depictions of persons who are under the age of 18 years if they are of legal age to engage in sexual activity under domestic law and the image does not depict child abuse or exploitation. For the purposes of this article, a person who is under the age of 18 years and depicted in an intimate image cannot consent to the dissemination of an intimate image that constitutes child sexual abuse or child sexual exploitation material under article 14 of this Convention. A State Party may require the intent to cause harm before criminal liability attaches. States Parties may take other measures concerning matters related to this article, in accordance with their domestic law and consistent with applicable international obligations. Article 17 Laundering of proceeds of crime\nEach State Party shall adopt, in accordance with fundamental principles of its domestic law, such legislative and other measures as may be necessary to establish as criminal offences, when committed intentionally:\n(a)\n(i) The conversion or transfer of property, knowing that such property is the proceeds of crime, for the purpose of concealing or disguising the illicit origin of the property or of helping any person who is involved in the commission of the predicate offence to evade the legal consequences of that person’s actions;\n(ii) The concealment or disguise of the true nature, source, location, disposition, movement or ownership of or rights with respect to property, knowing that such property is the proceeds of crime;\n(b) Subject to the basic concepts of its legal system:\n(i) The acquisition, possession or use of property, knowing, at the time of receipt, that such property is the proceeds of crime;\n(ii) Participation in, association with or conspiracy to commit, attempts to commit and aiding, abetting, facilitating and counselling the commission of any of the offences established in accordance with this article. For purposes of implementing or applying paragraph 1 of this article:\n(a) Each State Party shall establish as predicate offences relevant offences established in accordance with articles 7 to 16 of this Convention;\n(b) In the case of States Parties whose legislation sets out a list of specific predicate offences, they shall, at a minimum, include in that list a comprehensive range of offences established in accordance with articles 7 to 16 of this Convention;\n(c) For the purposes of subparagraph (b) of this paragraph, predicate offences shall include offences committed both within and outside the jurisdiction of the State Party in question. However, offences committed outside the jurisdiction of a State Party shall constitute predicate offences only when the relevant conduct is a criminal offence under the domestic law of the State where it is committed and would be a criminal offence under the domestic law of the State Party implementing or applying this article, had it been committed there;\n(d) Each State Party shall furnish copies of its laws that give effect to this article and of any subsequent changes to such laws or a description thereof to the Secretary-General of the United Nations;\n(e) If required by fundamental principles of the domestic law of a State Party, it may be provided that the offences set forth in paragraph 1 of this article do not apply to the persons who committed the predicate offence;\n(f) Knowledge, intent or purpose required as an element of an offence set forth in paragraph 1 of this article may be inferred from objective factual circumstances. Article 18 Liability of legal persons\nEach State Party shall adopt such measures as may be necessary, consistent with its legal principles, to establish the liability of legal persons for participation in the offences established in accordance with this Convention. Subject to the legal principles of the State Party, the liability of legal persons may be criminal, civil or administrative. Such liability shall be without prejudice to the criminal liability of the natural persons who have committed the offences. Each State Party shall, in particular, ensure that legal persons held liable in accordance with this article are subject to effective, proportionate and dissuasive criminal or non-criminal sanctions, including monetary sanctions. Article 19 Participation and attempt\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as a criminal offence, in accordance with its domestic law, when committed intentionally, the participation in any capacity, such as that of an accomplice, assistant or instigator, in an offence established in accordance with this Convention. Each State Party may adopt the necessary legislative and other measures to establish as a criminal offence, in accordance with its domestic law, when committed intentionally, any attempt to commit an offence established in accordance with this Convention. Each State Party may adopt the necessary legislative and other measures to establish as a criminal offence, in accordance with its domestic law, when committed intentionally, the preparation for an offence established in accordance with this Convention. Article 20 Statute of limitations\nEach State Party shall, where appropriate, considering the gravity of the crime, establish under its domestic law a long statute of limitations period in which to commence proceedings for any offence established in accordance with this Convention and establish a longer statute of limitations period or provide for the suspension of the statute of limitations where the alleged offender has evaded the administration of justice.\nArticle 21 Prosecution, adjudication and sanctions\nEach State Party shall make the commission of an offence established in accordance with this Convention liable to effective, proportionate and dissuasive sanctions that take into account the gravity of the offence. Each State Party may adopt, in accordance with its domestic law, such legislative and other measures as may be necessary to establish aggravating circumstances in relation to the offences established in accordance with this Convention, including circumstances that affect critical information infrastructures. Each State Party shall endeavour to ensure that any discretionary legal powers under its domestic law relating to the prosecution of persons for offences established in accordance with this Convention are exercised in order to maximize the effectiveness of law enforcement measures in respect of those offences and with due regard to the need to deter the commission of such offences. Each State Party shall ensure that any person prosecuted for offences established in accordance with this Convention enjoys all rights and guarantees in conformity with domestic law and consistent with the applicable international obligations of the State Party, including the right to a fair trial and the rights of the defence. In the case of offences established in accordance with this Convention, each State Party shall take appropriate measures, in accordance with its domestic law and with due regard to the rights of the defence, to seek to ensure that conditions imposed in connection with decisions on release pending trial or appeal take into consideration the need to ensure the presence of the defendant at subsequent criminal proceedings. Each State Party shall take into account the gravity of the offences concerned when considering the eventuality of early release or parole of persons convicted of such offences. States Parties shall ensure that appropriate measures are in place under domestic law to protect children who are accused of offences established in accordance with this Convention, consistent with the obligations under the Convention on the Rights of the Child and the applicable Protocols thereto, as well as other applicable international or regional instruments. Nothing contained in this Convention shall affect the principle that the description of the offences established in accordance with this Convention and of the applicable legal defences or other legal principles controlling the lawfulness of conduct is reserved to the domestic law of a State Party and that such offences shall be prosecuted and punished in accordance with that law. Chapter III: Jurisdiction Article 22 Jurisdiction\nEach State Party shall adopt such measures as may be necessary to establish its jurisdiction over the offences established in accordance with this Convention when:\n(a) The offence is committed in the territory of that State Party; or\n(b) The offence is committed on board a vessel that is flying the flag of that State Party or an aircraft that is registered under the laws of that State Party at the time when the offence is committed. Subject to article 5of this Convention, a State Party may also establish its jurisdiction over any such offence when:\n(a) The offence is committed against a national of that State Party; or\n(b) The offence is committed by a national of that State Party or a stateless person with habitual residence in its territory; or\n(c) The offence is one of those established in accordance with article 17, paragraph 1 (b) (ii), of this Convention and is committed outside its territory with a view to the commission of an offence established in accordance with article 17, paragraph 1 (a) (i) or (ii) or (b) (i), of this Convention within its territory; or\n(d) The offence is committed against the State Party. For the purposes of article 37, paragraph 11,of this Convention, each State Party shall take such measures as may be necessary to establish its jurisdiction over the offences established in accordance with this Convention when the alleged offender is present in its territory and it does not extradite such person solely on the ground that the person is one of its nationals. Each State Party may also adopt such measures as may be necessary to establish its jurisdiction over the offences established in accordance with this Convention when the alleged offender is present in its territory and it does not extradite the person. If a State Party exercising its jurisdiction under paragraph 1 or 2 of this article has been notified, or has otherwise learned, that any other States Parties are conducting an investigation, prosecution or judicial proceeding in respect of the same conduct, the competent authorities of those States Parties shall, as appropriate, consult one another with a view to coordinating their actions. Without prejudice to norms of general international law, this Convention shall not exclude the exercise of any criminal jurisdiction established by a State Party in accordance with its domestic law. Chapter IV: Procedural measures and law enforcement Article 23 Scope of procedural measures\nEach State Party shall adopt such legislative and other measures as may be necessary to establish the powers and procedures provided for in this chapter for the purpose of specific criminal investigations or proceedings. Except as provided otherwise in this Convention, each State Party shall apply the powers and procedures referred to in paragraph 1 of this article to:\n(a) The criminal offences established in accordance with this Convention;\n(b) Other criminal offences committed by means of an information and communications technology system; and\n(c) The collection of evidence in electronic form of any criminal offence. (a) Each State Party may reserve the right to apply the measures referred to in article 29 of this Convention only to offences or categories of offences specified in the reservation, provided that the range of such offences or categories of offences is not more restricted than the range of offences to which it applies the measures referred to in article 30 of this Convention. Each State Party shall consider restricting such a reservation to enable the broadest application of the measures referred to in article 29;\n(b) Where a State Party, owing to limitations in its legislation in force at the time of the adoption of this Convention, is not able to apply the measures referred to in articles 29 and 30 of this Convention to communications being transmitted within an information and communications technology system of a service provider which:\nthat State Party may reserve the right not to apply these measures to such communications. Each State Party shall consider restricting such a reservation to enable the broadest application of the measures referred to in articles 29 and 30 of this Convention. Article 24 Conditions and safeguards\nEach State Party shall ensure that the establishment, implementation and application of the powers and procedures provided for in this chapter are subject to conditions and safeguards provided for under its domestic law, which shall provide for the protection of human rights, in accordance with its obligations under international human rights law, and which shall incorporate the principle of proportionality. In accordance with and pursuant to the domestic law of each State Party, such conditions and safeguards shall, as appropriate in view of the nature of the procedure or power concerned, include, inter alia, judicial or other independent review, the right to an effective remedy, grounds justifying application, and limitation of the scope and the duration of such power or procedure. To the extent that it is consistent with the public interest, in particular the proper administration of justice, each State Party shall consider the impact of the powers and procedures in this chapter upon the rights, responsibilities and legitimate interests of third parties. The conditions and safeguards established in accordance with this article shall apply at the domestic level to the powers and procedures set forth in this chapter, both for the purpose of domestic criminal investigations and proceedings and for the purpose of rendering international cooperation by the requested State Party. References to judicial or other independent review in paragraph 2 of this article are references to such review at the domestic level. Article 25 Expedited preservation of stored electronic data\nEach State Party shall adopt such legislative and other measures as may be necessary to enable its competent authorities to order or similarly obtain the expeditious preservation of specified electronic data, including traffic data, content data and subscriber information, that have been stored by means of an information and communications technology system, in particular where there are grounds to believe that the electronic data are particularly vulnerable to loss or modification. Where a State Party gives effect to paragraph 1 of this article by means of an order to a person to preserve specified stored electronic data in the person’s possession or control, the State Party shall adopt such legislative and other measures as may be necessary to oblige that person to preserve and maintain the integrity of those electronic data for a period of time as long as necessary, up to a maximum of 90 days, to enable the competent authorities to seek their disclosure. A State Party may provide for such an order to be subsequently renewed. Each State Party shall adopt such legislative and other measures as may be necessary to oblige the custodian or other person who is to preserve the electronic data to keep confidential the undertaking of such procedures for the period of time provided for in its domestic legislation. Article 26 Expedited preservation and partial disclosure of traffic data\nEach State Party shall adopt, in respect of traffic data that are to be preserved under the provisions of article 25 of this Convention, such legislative and other measures as may be necessary to:\n(a) Ensure that such expeditious preservation of traffic data is available regardless of whether one or more service providers were involved in the transmission of a communication; and\n(b) Ensure the expeditious disclosure to the State Party’s competent authority, or a person designated by that authority, of a sufficient amount of traffic data to enable the State Party to identify the service providers and the path through which the communication or indicated information was transmitted.\nArticle 27 Production order\nEach State Party shall adopt such legislative and other measures as may be necessary to empower its competent authorities to order:\n(a) A person in its territory to submit specified electronic data in that person’s possession or control that are stored in an information and communications technology system or an electronic data storage medium; and\n(b) A service provider offering its services in the territory of the State Party to submit subscriber information relating to such services in that service provider’s possession or control.\nArticle 28 Search and seizure of stored electronic data\nEach State Party shall adopt such legislative and other measures as may be necessary to empower its competent authorities to search or similarly access:\n(a) An information and communications technology system, part of it, and electronic data stored therein; and\n(b) An electronic data storage medium in which the electronic data sought may be stored;\nin the territory of that State Party. Each State Party shall adopt such legislative and other measures as may be necessary to ensure that, where its authorities search or similarly access a specific information and communications technology system or part of it, pursuant to paragraph 1 (a) of this article, and have grounds to believe that the electronic data sought are stored in another information and communications technology system or part of it in its territory, and such data are lawfully accessible from or available to the initial system, such authorities shall be able to expeditiously conduct the search to obtain access to that other information and communications technology system. Each State Party shall adopt such legislative and other measures as may be necessary to empower its competent authorities to seize or similarly secure electronic data in its territory accessed in accordance with paragraph 1 or 2 of this article. These measures shall include the power to:\n(a) Seize or similarly secure an information and communications technology system or part of it, or an electronic data storage medium;\n(b) Make and retain copies of those electronic data in electronic form;\n(c) Maintain the integrity of the relevant stored electronic data;\n(d) Render inaccessible or remove those electronic data in the accessed information and communications technology system. Each State Party shall adopt such legislative and other measures as may be necessary to empower its competent authorities to order any person who has knowledge about the functioning of the information and communications technology system in question, the information and telecommunications network, or their component parts, or measures applied to protect the electronic data therein, to provide, as is reasonable, the necessary information to enable the undertaking of the measures referred to in paragraphs 1 to 3 of this article. Article 29 Real-time collection of traffic data\nEach State Party shall adopt such legislative and other measures as may be necessary to empower its competent authorities to:\n(a) Collect or record, through the application of technical means in the territory of that State Party; and\n(b) Compel a service provider, within its existing technical capability: Where a State Party, owing to the principles of its domestic legal system, cannot adopt the measures referred to in paragraph 1 (a) of this article, it may instead adopt such legislative and other measures as may be necessary to ensure the real-time collection or recording of traffic data associated with specified communications transmitted in its territory, through the application of technical means in that territory. Each State Party shall adopt such legislative and other measures as may be necessary to oblige a service provider to keep confidential the fact of the execution of any power provided for in this article and any information relating to it. Article 30 Interception of content data\nEach State Party shall adopt such legislative and other measures as may be necessary, in relation to a range of serious criminal offences to be determined by domestic law, to empower its competent authorities to:\n(a) Collect or record, through the application of technical means in the territory of that State Party; and\n(b) Compel a service provider, within its existing technical capability: Where a State Party, owing to the principles of its domestic legal system, cannot adopt the measures referred to in paragraph 1 (a) of this article, it may instead adopt such legislative and other measures as may be necessary to ensure the real-time collection or recording of content data on specified communications in its territory, through the application of technical means in that territory. Each State Party shall adopt such legislative and other measures as may be necessary to oblige a service provider to keep confidential the fact of the execution of any power provided for in this article and any information relating to it. Article 31 Freezing, seizure and confiscation of the proceeds of crime\nEach State Party shall adopt, to the greatest extent possible within its domestic legal system, such measures as may be necessary to enable the confiscation of:\n(a) Proceeds of crime derived from offences established in accordance with this Convention or property the value of which corresponds to that of such proceeds;\n(b) Property, equipment or other instrumentalities used in or destined for use in offences established in accordance withthis Convention. Each State Party shall adopt such measures as may be necessary to enable the identification, tracing, freezing or seizure of any item referred to in paragraph 1 of this article for the purpose of eventual confiscation. Each State Party shall adopt, in accordance with its domestic law, such legislative and other measures as may be necessary to regulate the administration by the competent authorities of frozen, seized or confiscated property covered in paragraphs 1 and 2 of this article. If proceeds of crime have been transformed or converted, in part or in full, into other property, such property shall be liable to the measures referred to in this article instead of the proceeds. If proceeds of crime have been intermingled with property acquired from legitimate sources, such property shall, without prejudice to any powers relating to freezing or seizure, be liable to confiscation up to the assessed value of the intermingled proceeds. Income or other benefits derived from proceeds of crime, from property into which proceeds of crime have been transformed or converted or from property with which proceeds of crime have been intermingled, shall also be liable to the measures referred to in this article, in the same manner and to the same extent as proceeds of crime. For the purposes of this article and article 50 of this Convention, each State Party shall empower its courts or other competent authorities to order that bank, financial or commercial records be made available or be seized. A State Party shall not decline to act under the provisions of this paragraph on the ground of bank secrecy. Each State Party may consider the possibility of requiring that an offender demonstrate the lawful origin of alleged proceeds of crime or other property liable to confiscation, to the extent that such a requirement is consistent with the principles of their domestic law and with the nature of the judicial and other proceedings. The provisions of this article shall not be construed as prejudicing the rights of bona fide third parties. Nothing contained in this article shall affect the principle that the measures to which it refers shall be defined and implemented in accordance with the provisions of the domestic law of a State Party. Article 32 Establishment of criminal record\nEach State Party may adopt such legislative or other measures as may be necessary to take into consideration, under such terms as, and for the purpose that, it deems appropriate, any previous conviction in another State of an alleged offender for the purpose of using such information in criminal proceedings relating to an offence established in accordance with this Convention.\nArticle 33 Protection of witnesses\nEach State Party shall take appropriate measures, in accordance with its domestic law and within its means, to provide effective protection from potential retaliation or intimidation for witnesses who give testimony or, in good faith and on reasonable grounds, provide information concerning offences established in accordance with this Convention or otherwise cooperate with investigative or judicial authorities and, as appropriate, for their relatives and other persons close to them. The measures envisaged in paragraph 1 of this article may include, inter alia, without prejudice to the rights of the defendant, including the right to due process:\n(a) Establishing procedures for the physical protection of such persons, such as, to the extent necessary and feasible, relocating them and permitting, where appropriate, non-disclosure or limitations on the disclosure of information concerning the identity and whereabouts of such persons;\n(b) Providing evidentiary rules to permit witness testimony to be given in a manner that ensures the safety of the witness, such as permitting testimony to be given through the use of communications technology such as video links or other adequate means. States Parties shall consider entering into agreements or arrangements with other States for the relocation of persons referred to in paragraph 1 of this article. The provisions of this article shall also apply to victims insofar as they are witnesses. Article 34 Assistance to and protection of victims\nEach State Party shall take appropriate measures within its means to provide assistance and protection to victims of offences established in accordance with this Convention, in particular in cases of threat of retaliation or intimidation. Each State Party shall, subject to its domestic law, establish appropriate procedures to provide access to compensation and restitution for victims of offences established in accordance with this Convention. Each State Party shall, subject to its domestic law, enable views and concerns of victims to be presented and considered at appropriate stages of criminal proceedings against offenders in a manner not prejudicial to the rights of the defence. With respect to the offences established in accordance with articles 14 to 16 of this Convention, each State Party shall, subject to its domestic law, take measures to provide assistance to victims of such offences, including for their physical and psychological recovery, in cooperation with relevant international organizations, non‑governmental organizations, and other elements of civil society. In applying the provisions of paragraphs 2 to 4 of this article, each State Party shall take into account the age, gender and the particular circumstances and needs of victims, including the particular circumstances and needs of children. Each State Party shall, to the extent consistent with its domestic legal framework, take effective steps to ensure compliance with requests to remove or render inaccessible the content described in articles 14 and 16 of this Convention. Chapter V: International cooperation Article 35 General principles of international cooperation\nStates Parties shall cooperate with each other in accordance with the provisions of this Convention, as well as other applicable international instruments on international cooperation in criminal matters, and domestic laws, for the purpose of:\n(a) The investigation and prosecution of, and judicial proceedings in relation to, the criminal offences established in accordance with this Convention, including the freezing, seizure, confiscation and return of the proceeds from such offences;\n(b) The collecting, obtaining, preserving and sharing of evidence in electronic form of criminal offences established in accordance with this Convention;\n(c) The collecting, obtaining, preserving and sharing of evidence in electronic form of any serious crime, including serious crimes established in accordance with other applicable United Nations conventions and protocols in force at the time of the adoption of this Convention. For the purpose of the collecting, obtaining, preserving and sharing of evidence in electronic form of offences as provided for in paragraph 1 (b) and (c) of this article, the relevant paragraphs of article 40, and articles 41 to 46 of this Convention shall apply. In matters of international cooperation, whenever dual criminality is considered a requirement, it shall be deemed fulfilled irrespective of whether the laws of the requested State Party place the offence within the same category of offence or denominate the offence by the same terminology as the requesting State Party, if the conduct underlying the offence for which assistance is sought is a criminal offence under the laws of both States Parties. Article 36 Protection of personal data\n(a) A State Party transferring personal data pursuant to this Convention shall do so in accordance with its domestic law and any obligations the transferring Party may have under applicable international law. States Parties shall not be required to transfer personal data in accordance with this Convention if the data cannot be provided in compliance with their applicable laws concerning the protection of personal data;\n(b) Where the transfer of personal data would not be compliant with paragraph 1 (a) of this article, States Parties may seek to impose appropriate conditions, in accordance with such applicable laws, to achieve compliance in order to respond to a request for personal data;\n(c) States Parties are encouraged to establish bilateral or multilateral arrangements to facilitate the transfer of personal data. For personal data transferred in accordance with this Convention, States Parties shall ensure that the personal data received are subject to effective and appropriate safeguards in the respective legal frameworks of the States Parties. In order to transfer personal data obtained in accordance with this Convention to a third country or an international organization, a State Party shall notify the original transferring State Party of its intention and request its authorization. The State Party shall transfer such personal data only with the authorization of the original transferring State Party, which may require that the authorization be provided in written form. Article 37 Extradition\nThis article shall apply to the criminal offences established in accordance with this Convention where the person who is the subject of the request for extradition is present in the territory of the requested State Party, provided that the offence for which extradition is sought is punishable under the domestic law of both the requesting State Party and the requested State Party. When the extradition is sought for the purpose of serving a final sentence of imprisonment or another form of detention imposed in respect of an extraditable offence, the requested State Party may grant the extradition in accordance with domestic law. Notwithstanding paragraph 1 of this article, a State Party whose law so permits may grant the extradition of a person for any of the criminal offences established in accordance with this Convention that are not punishable under its own domestic law. If the request for extradition includes several separate criminal offences, at least one of which is extraditable under this article and some of which are not extraditable by reason of their period of imprisonment but are related to offences established in accordance with this Convention, the requested State Party may apply this article also in respect of those offences. Each of the offences to which this article applies shall be deemed to be included as an extraditable offence in any extradition treaty existing between States Parties. States Parties undertake to include such offences as extraditable offences in every extradition treaty to be concluded between them. If a State Party that makes extradition conditional on the existence of a treaty receives a request for extradition from another State Party with which it has no extradition treaty, it may consider this Convention the legal basis for extradition in respect of any offence to which this article applies. States Parties that make extradition conditional on the existence of a treaty shall:\n(a) At the time of deposit of their instruments of ratification, acceptance or approval of or accession to this Convention, inform the Secretary-General of the United Nations whether they will take this Convention as the legal basis for cooperation in extradition with other States Parties to this Convention; and\n(b) If they do not take this Convention as the legal basis for cooperation in extradition, seek, where appropriate, to conclude treaties on extradition with other States Parties to this Convention in order to implement this article. States Parties that do not make extradition conditional on the existence of a treaty shall recognize offences to which this article applies as extraditable offences between themselves. Extradition shall be subject to the conditions provided for by the domestic law of the requested State Party or by applicable extradition treaties, including, inter alia, conditions in relation to the minimum penalty requirement for extradition and the grounds upon which the requested State Party may refuse extradition. States Parties shall, subject to their domestic law, endeavour to expedite extradition procedures and to simplify evidentiary requirements relating thereto in respect of any offence to which this article applies. Subject to the provisions of its domestic law and its extradition treaties, the requested State Party may, upon being satisfied that the circumstances so warrant and are urgent, and at the request of the requesting State Party, including when the request is transmitted through existing channels of the International Criminal Police Organization, take a person whose extradition is sought and who is present in its territory into custody or take other appropriate measures to ensure the person’s presence at extradition proceedings. A State Party in whose territory an alleged offender is found, if it does not extradite such person in respect of an offence to which this article applies solely on the ground that the person is one of its nationals, shall, at the request of the State Party seeking extradition, be obliged to submit the case without undue delay to its competent authorities for the purpose of prosecution. Those authorities shall take their decisions and conduct their proceedings in the same manner as in the case of any other offence of a comparable nature under the domestic law of that State Party. The States Parties concerned shall cooperate with each other, in particular on procedural and evidentiary aspects, to ensure the efficiency of such prosecution. Whenever a State Party is permitted under its domestic law to extradite or otherwise surrender one of its nationals only upon the condition that the person will be returned to that State Party to serve the sentence imposed as a result of the trial or proceedings for which the extradition or surrender of the person was sought and that State Party and the State Party seeking the extradition of the person agree with this option and other terms that they may deem appropriate, such conditional extradition or surrender shall be sufficient to discharge the obligation set forth in paragraph 11 of this article. If extradition, sought for purposes of enforcing a sentence, is refused because the person sought is a national of the requested State Party, the requested State Party shall, if its domestic law so permits and in conformity with the requirements of such law, upon application of the requesting State Party, consider the enforcement of the sentence imposed under the domestic law of the requesting State Party or the remainder thereof. Any person regarding whom proceedings are being carried out in connection with any of the offences to which this article applies shall be guaranteed fair treatment at all stages of the proceedings, including enjoyment of all the rights and guarantees provided by the domestic law of the State Party in the territory of which that person is present. Nothing in this Convention shall be interpreted as imposing an obligation to extradite if the requested State Party has substantial grounds for believing that the request has been made for the purpose of prosecuting or punishing a person on account of that person’s sex, race, language, religion, nationality, ethnic origin or political opinions, or that compliance with the request would cause prejudice to that person’s position for any one of these reasons. States Parties may not refuse a request for extradition on the sole ground that the offence is also considered to involve fiscal matters. Before refusing extradition, the requested State Party shall, where appropriate, consult with the requesting State Party to provide it with ample opportunity to present its opinions and to provide information relevant to its allegation. The requested State Party shall inform the requesting State Party of its decision with regard to the extradition. The requested State Party shall inform the requesting State Party of any reason for refusal of extradition unless the requested State Party is prevented from doing so by its domestic law or its international legal obligations. Each State Party shall, at the time of signature or when depositing its instrument of ratification, acceptance, approval or accession, communicate to the Secretary-General of the United Nations the name and address of an authority responsible for making or receiving requests for extradition or provisional arrest. The Secretary-General shall set up and keep updated a register of authorities so designated by the States Parties. Each State Party shall ensure that the details held in the register are correct at all times. States Parties shall seek to conclude bilateral and multilateral agreements or arrangements to carry out or to enhance the effectiveness of extradition. Article 38 Transfer of sentenced persons\nStates Parties may, taking into consideration the rights of sentenced persons, consider entering into bilateral or multilateral agreements or arrangements on the transfer to their territory of persons sentenced to imprisonment or other forms of deprivation of liberty for offences established in accordance with this Convention, in order that they may complete their sentences there. States Parties may also take into account issues relating to consent, rehabilitation and reintegration.\nArticle 39 Transfer of criminal proceedings\nStates Parties shall consider the possibility of transferring to one another proceedings for the criminal prosecution of an offence established in accordance with this Convention where such a transfer is deemed to be in the interests of the proper administration of justice, particularly in cases where several jurisdictions are involved, with a view to concentrating the prosecution. If a State Party that makes the transfer of criminal proceedings conditional on the existence of a treaty receives a request for transfer from another State Party with which it has no treaty in this matter, it may consider this Convention as the legal basis for the transfer of criminal proceedings in respect of any offence to which this article applies. Article 40 General principles and procedures relating to mutual legal assistance\nStates Parties shall afford one another the widest measure of mutual legal assistance in investigations, prosecutions and judicial proceedings in relation to the offences established in accordance with this Convention, and for the purposes of the collection of evidence in electronic form of offences established in accordance with this Convention, as well as of serious crimes. Mutual legal assistance shall be afforded to the fullest extent possible under relevant laws, treaties, agreements and arrangements of the requested State Party with respect to investigations, prosecutions and judicial proceedings in relation to the offences for which a legal person may be held liable in accordance with article 18 of this Convention in the requesting State Party. Mutual legal assistance to be afforded in accordance with this article may be requested for any of the following purposes:\n(a) Taking evidence or statements from persons;\n(b) Effecting service of judicial documents;\n(c) Executing searches and seizures, and freezing;\n(d) Searching or similarly accessing, seizing or similarly securing, and disclosing electronic data stored by means of an information and communications technology system pursuant to article 44 of this Convention;\n(e) Collecting traffic data in real time pursuant to article 45 of this Convention;\n(f) Intercepting content data pursuant to article 46 of this Convention;\n(g) Examining objects and sites;\n(h) Providing information, evidence and expert evaluations;\n(i) Providing originals or certified copies of relevant documents and records, including government, bank, financial, corporate or business records;\n(j) Identifying or tracing proceeds of crime, property, instrumentalities or other things for evidentiary purposes;\n(k) Facilitating the voluntary appearance of persons in the requesting State Party\n(l) Recovering proceeds of crime;\n(m) Any other type of assistance that is not contrary to the domestic law of the requested State Party. Without prejudice to domestic law, the competent authorities of a State Party may, without prior request, transmit information relating to criminal matters to a competent authority in another State Party where they believe that such information could assist the authority in undertaking or successfully concluding inquiries and criminal proceedings or could result in a request formulated by the latter State Party pursuant to this Convention. The transmission of information pursuant to paragraph 4 of this article shall be without prejudice to inquiries and criminal proceedings in the State of the competent authorities providing the information. The competent authorities receiving the information shall comply with a request that said information remain confidential, even temporarily, or with restrictions on its use. However, this shall not prevent the receiving State Party from disclosing in its proceedings information that is exculpatory to an accused person. In such a case, the receiving State Party shall notify the transmitting State Party prior to the disclosure and, if so requested, consult with the transmitting State Party. If, in an exceptional case, advance notice is not possible, the receiving State Party shall inform the transmitting State Party of the disclosure without delay. The provisions of this article shall not affect obligations under any other treaty, bilateral or multilateral, that governs or will govern, in whole or in part, mutual legal assistance. Paragraphs 8 to 31 of this article shall apply to requests made pursuant to this article if the States Parties in question are not bound by a treaty on mutual legal assistance. If those States Parties are bound by such a treaty, the corresponding provisions of that treaty shall apply unless the States Parties agree to apply paragraphs 8 to 31 of this article in lieu thereof. States Parties are strongly encouraged to apply the provisions of those paragraphs if they facilitate cooperation. States Parties may decline to render assistance pursuant to this article on the ground of absence of dual criminality. However, the requested State Party may, when it deems appropriate, provide assistance, to the extent it decides at its discretion, irrespective of whether the conduct would constitute an offence under the domestic law of the requested State Party. Assistance may be refused when requests involve matters of a de minimis nature or matters for which the cooperation or assistance sought is available under other provisions of this Convention. A person who is being detained or is serving a sentence in the territory of one State Party and whose presence in another State Party is requested for purposes of identification, testimony or otherwise providing assistance in obtaining evidence for investigations, prosecutions or judicial proceedings in relation to offences established in accordance with this Convention may be transferred if the following conditions are met:\n(a) The person freely gives informed consent;\n(b) The competent authorities of both States Parties agree, subject to such conditions as those States Parties may deem appropriate. For the purposes of paragraph 9 of this article:\n(a) The State Party to which the person is transferred shall have the authority and obligation to keep the person transferred in custody, unless otherwise requested or authorized by the State Party from which the person was transferred;\n(b) The State Party to which the person is transferred shall, without delay, implement its obligation to return the person to the custody of the State Party from which the person was transferred as agreed beforehand, or as otherwise agreed, by the competent authorities of both States Parties;\n(c) The State Party to which the person is transferred shall not require the State Party from which the person was transferred to initiate extradition proceedings for the return of the person;\n(d) The person transferred shall receive credit for service of the sentence being served in the State from which the person was transferred for time spent in the custody of the State Party to which the person was transferred. Unless the State Party from which a person is to be transferred in accordance with paragraphs 9 and 10 of this article so agrees, that person, regardless of the person’s nationality, shall not be prosecuted, detained, punished or subjected to any other restriction of liberty in the territory of the State to which that person is transferred in respect of acts, omissions or convictions prior to the person’s departure from the territory of the State from which the person was transferred. (a) Each State Party shall designate a central authority or authorities that shall have the responsibility and power to receive requests for mutual legal assistance and either to execute them or to transmit them to the competent authorities for execution. Where a State Party has a special region or territory with a separate system of mutual legal assistance, it may designate a distinct central authority that shall have the same function for that region or territory;\n(b) Central authorities shall ensure the speedy and proper execution or transmission of the requests received. Where the central authority transmits the request to a competent authority for execution, it shall encourage the speedy and proper execution of the request by the competent authority;\n(c) The Secretary-General of the United Nations shall be notified of the central authority designated for this purpose at the time each State Party deposits its instrument of ratification, acceptance or approval of or accession to this Convention, and shall set up and keep updated a register of central authorities designated by the States Parties. Each State Party shall ensure that the details held in the register are correct at all times;\n(d) Requests for mutual legal assistance and any communication related thereto shall be transmitted to the central authorities designated by the States Parties. This requirement shall be without prejudice to the right of a State Party to require that such requests and communications be addressed to it through diplomatic channels and, in urgent circumstances, where the States Parties agree, through the International Criminal Police Organization, if possible. Requests shall be made in writing or, where possible, by any means capable of producing a written record, in a language acceptable to the requested State Party, under conditions allowing that State Party to establish authenticity. The Secretary-General of the United Nations shall be notified of the language or languages acceptable to each State Party at the time it deposits its instrument of ratification, acceptance or approval of or accession to this Convention. In urgent circumstances and where agreed by the States Parties, requests may be made orally, but shall be confirmed in writing forthwith. Where not prohibited by their respective laws, central authorities of States Parties are encouraged to transmit and receive requests for mutual legal assistance, and communications related thereto, as well as evidence, in electronic form under conditions allowing the requested State Party to establish authenticity and ensuring the security of communications. A request for mutual legal assistance shall contain:\n(a) The identity of the authority making the request;\n(b) The subject matter and nature of the investigation, prosecution or judicial proceeding to which the request relates and the name and functions of the authority conducting the investigation, prosecution or judicial proceeding;\n(c) A summary of the relevant facts, except in relation to requests for the purpose of service of judicial documents;\n(d) A description of the assistance sought and details of any particular procedure that the requesting State Party wishes to be followed;\n(e) Where possible and appropriate, the identity, location and nationality of any person concerned, as well as the country of origin, description and location of any item or accounts concerned;\n(f) Where applicable, the time period for which the evidence, information or other assistance is sought; and\n(g) The purpose for which the evidence, information or other assistance is sought. The requested State Party may request additional information when it appears necessary for the execution of the request in accordance with its domestic law or when it can facilitate such execution. A request shall be executed in accordance with the domestic law of the requested State Party and, to the extent not contrary to the domestic law of the requested State Party and where possible, in accordance with the procedures specified in the request. Wherever possible and consistent with fundamental principles of domestic law, when an individual is in the territory of a State Party and has to be heard as a witness, victim or expert by the judicial authorities of another State Party, the first State Party may, at the request of the other, permit the hearing to take place by videoconference if it is not possible or desirable for the individual in question to appear in person in the territory of the requesting State Party. States Parties may agree that the hearing shall be conducted by a judicial authority of the requesting State Party and attended by a judicial authority of the requested State Party. If the requested State Party does not have access to the technical means necessary for holding a videoconference, such means may be provided by the requesting State Party, upon mutual agreement. The requesting State Party shall not transmit or use information or evidence furnished by the requested State Party for investigations, prosecutions or judicial proceedings other than those stated in the request without the prior consent of the requested State Party. Nothing in this paragraph shall prevent the requesting State Party from disclosing in its proceedings information or evidence that is exculpatory to an accused person. In the latter case, the requesting State Party shall notify the requested State Party prior to the disclosure and, if so requested, consult with the requested State Party. If, in an exceptional case, advance notice is not possible, the requesting State Party shall inform the requested State Party of the disclosure without delay. The requesting State Party may require that the requested State Party keep confidential the fact and substance of the request, except to the extent necessary to execute the request. If the requested State Party cannot comply with the requirement of confidentiality, it shall promptly inform the requesting State Party. Mutual legal assistance may be refused:\n(a) If the request is not made in conformity with the provisions of this article;\n(b) If the requested State Party considers that execution of the request is likely to prejudice its sovereignty, security, ordre public or other essential interests;\n(c) If the authorities of the requested State Party would be prohibited by its domestic law from carrying out the action requested with regard to any similar offence, had it been subject to investigation, prosecution or judicial proceedings under their own jurisdiction;\n(d) If it would be contrary to the legal system of the requested State Party relating to mutual legal assistance for the request to be granted. Nothing in this Convention shall be interpreted as imposing an obligation to afford mutual legal assistance if the requested State Party has substantial grounds for believing that the request has been made for the purpose of prosecuting or punishing a person on account of that person’s sex, race, language, religion, nationality, ethnic origin or political opinions, or that compliance with the request would cause prejudice to that person’s position for any one of these reasons. States Parties may not refuse a request for mutual legal assistance on the sole ground that the offence is also considered to involve fiscal matters. States Parties shall not decline to render mutual legal assistance pursuant to this article on the ground of bank secrecy. Reasons shall be given for any refusal of mutual legal assistance. The requested State Party shall execute the request for mutual legal assistance as soon as possible and shall take as full account as possible of any deadlines suggested by the requesting State Party and for which reasons are given, preferably in the request. The requested State Party shall respond to reasonable requests by the requesting State Party on the status, and progress in its handling, of the request. The requesting State Party shall promptly inform the requested State Party when the assistance sought is no longer required. Mutual legal assistance may be postponed by the requested State Party on the ground that it interferes with an ongoing investigation, prosecution or judicial proceeding. Before refusing a request pursuant to paragraph 21 of this article or postponing its execution pursuant to paragraph 27 of this article, the requested State Party shall consult with the requesting State Party to consider whether assistance may be granted subject to such terms and conditions as it deems necessary. If the requesting State Party accepts assistance subject to those conditions, it shall comply with the conditions. Without prejudice to the application of paragraph 11 of this article, a witness, expert or other person who, at the request of the requesting State Party, consents to give evidence in a proceeding or to assist in an investigation, prosecution or judicial proceeding in the territory of the requesting State Party shall not be prosecuted, detained, punished or subjected to any other restriction of the person’s liberty in that territory in respect of acts, omissions or convictions prior to the person’s departure from the territory of the requested State Party. Such safe conduct shall cease when the witness, expert or other person having had, for a period of 15 consecutive days or for any period agreed upon by the States Parties from the date on which the person has been officially informed that the presence of the person is no longer required by the judicial authorities, an opportunity of leaving, has nevertheless remained voluntarily in the territory of the requesting State Party or, having left it, has returned of the person’s own free will. The ordinary costs of executing a request shall be borne by the requested State Party, unless otherwise agreed by the States Parties concerned. If expenses of a substantial or extraordinary nature are or will be required to fulfil the request, the States Parties shall consult to determine the terms and conditions under which the request will be executed, as well as the manner in which the costs shall be borne. The requested State Party:\n(a) Shall provide to the requesting State Party copies of government records, documents or information in its possession that under its domestic law are available to the general public;\n(b) May, at its discretion, provide to the requesting State Party, in whole, in part or subject to such conditions as it deems appropriate, copies of any government records, documents or information in its possession that under its domestic law are not available to the general public. States Parties shall consider, as may be necessary, the possibility of concluding bilateral or multilateral agreements or arrangements that would serve the purposes of, give practical effect to or enhance the provisions of this article. Article 41 24/7 network\nEach State Party shall designate a point of contact available 24 hours a day, 7 days a week, in order to ensure the provision of immediate assistance for the purpose of specific criminal investigations, prosecutions or judicial proceedings concerning offences established in accordance with this Convention, or for the collection, obtaining and preservation of evidence in electronic form for the purposes of paragraph 3 of this article and in relation to the offences established in accordance with this Convention, as well as to serious crime. The Secretary-General of the United Nations shall be notified of such point of contact and keep an updated register of points of contact designated for the purposes of this article and shall annually circulate to the States Parties the updated list of contact points. Such assistance shall include facilitating or, if permitted by the domestic law and practice of the requested State Party, directly carrying out the following measures:\n(a) The provision of technical advice;\n(b) The preservation of stored electronic data pursuant to articles 42 and 43 of this Convention, including, as appropriate, information about the location of the service provider, if known to the requested State Party, to assist the requesting State Party in making a request;\n(c) The collection of evidence and the provision of legal information;\n(d) The locating of suspects; or\n(e) The provision of electronic data to avert an emergency. A State Party’s point of contact shall have the capacity to carry out communications with the point of contact of another State Party on an expedited basis. If the point of contact designated by a State Party is not part of that State Party’s authority or authorities responsible for mutual legal assistance or extradition, the point of contact shall ensure that it is able to coordinate with that authority or those authorities on an expedited basis. Each State Party shall ensure that trained and equipped personnel are available to ensure the operation of the 24/7 network. States Parties may also use and strengthen existing authorized networks of points of contact, where applicable, and within the limits of their domestic laws, including the 24/7 networks for computer-related crime of the International Criminal Police Organization for prompt police-to-police cooperation and other methods of information exchange cooperation. Article 42 International cooperation for the purpose of expedited preservation of stored electronic data\nA State Party may request another State Party to order or otherwise obtain, in accordance with article 25 of this Convention, the expeditious preservation of electronic data stored by means of an information and communications technology system located within the territory of that other State Party, and in respect of which the requesting State Party intends to submit a request for mutual legal assistance in the search or similar access, seizure or similar securing, or disclosure of the electronic data. The requesting State Party may use the 24/7 network provided for in article 41 of this Convention to seek information concerning the location of the electronic data stored by means of an information and communications technology system and, as appropriate, information about the location of the service provider. A request for preservation made under paragraph 1 of this article shall specify:\n(a) The authority seeking the preservation;\n(b) The offence that is the subject of a criminal investigation, prosecution or judicial proceeding and a brief summary of the related facts;\n(c) The stored electronic data to be preserved and their relationship to the offence;\n(d) Any available information identifying the custodian of the stored electronic data or the location of the information and communications technology system;\n(e) The necessity of the preservation;\n(f) That the requesting State Party intends to submit a request for mutual legal assistance in the search or similar access, seizure or similar securing, or disclosure of the stored electronic data;\n(g) As appropriate, the need to keep the request for preservation confidential and not to notify the user. Upon receiving the request from another State Party, the requested State Party shall take all appropriate measures to preserve expeditiously the specified electronic data in accordance with its domestic law. For the purposes of responding to a request, dual criminality shall not be required as a condition for providing such preservation. A State Party that requires dual criminality as a condition for responding to a request for mutual legal assistance in the search or similar access, seizure or similar securing, or disclosure of stored electronic data may, in respect of offences other than those established in accordance with this Convention, reserve the right to refuse the request for preservation under this article in cases where it has reasons to believe that, at the time of disclosure, the condition of dual criminality could not be fulfilled. In addition, a request for preservation may be refused only on the basis of the grounds contained in article 40, paragraph 21 (b) and (c) and paragraph 22, of this Convention. Where the requested State Party believes that preservation will not ensure the future availability of the data or will threaten the confidentiality of or otherwise prejudice the requesting State Party’s investigation, it shall promptly so inform the requesting State Party, which shall then determine whether the request should nevertheless be executed. Any preservation effected in response to a request made pursuant to paragraph 1 of this article shall be for a period of not less than 60 days, in order to enable the requesting State Party to submit a request for the search or similar access, seizure or similar securing, or disclosure of the data. Following the receipt of such a request, the data shall continue to be preserved pending a decision on that request. Before the expiry of the preservation period in paragraph 8 of this article, the requesting State Party may request an extension of the period of preservation. Article 43 International cooperation for the purpose of expedited disclosure of preserved traffic data\nWhere, in the course of the execution of a request made pursuant to article 42 of this Convention to preserve traffic data concerning a specific communication, the requested State Party discovers that a service provider in another State Party was involved in the transmission of the communication, the requested State Party shall expeditiously disclose to the requesting State Party a sufficient amount of traffic data to identify that service provider and the path through which the communication was transmitted. Disclosure of traffic data under paragraph 1 of this article may be refused only on the basis of the grounds contained in article 40, paragraph 21 (b) and (c) and paragraph 22, of this Convention. Article 44 Mutual legal assistance in accessing stored electronic data\nA State Party may request another State Party to search or similarly access, seize or similarly secure, and disclose electronic data stored by means of an information and communications technology system located within the territory of the requested State Party, including electronic data that have been preserved pursuant to article 42 of this Convention. The requested State Party shall respond to the request through the application of relevant international instruments and laws referred to in article 35 of this Convention, and in accordance with other relevant provisions of this chapter. The request shall be responded to on an expedited basis where:\n(a) There are grounds to believe that the relevant data are particularly vulnerable to loss or modification; or\n(b) The instruments and laws referred to in paragraph 2 of this article otherwise provide for expedited cooperation. Article 45 Mutual legal assistance in the real-time collection of traffic data\nStates Parties shall endeavour to provide mutual legal assistance to each other in the real-time collection of traffic data associated with specified communications in their territory transmitted by means of an information and communications technology system. Subject to the provisions of paragraph 2 of this article, such assistance shall be governed by the conditions and procedures provided for under domestic law. Each State Party shall endeavour to provide such assistance at least with respect to criminal offences for which the real-time collection of traffic data would be available in a similar domestic case. A request made in accordance with paragraph 1 of this article shall specify:\n(a) The name of the requesting authority;\n(b) A summary of the main facts and the nature of the investigation, prosecution or judicial proceeding to which the request relates;\n(c) The electronic data in relation to which the collection of the traffic data is required and their relationship to the offence;\n(d) Any available data that identify the owner or user of the data or the location of the information and communications technology system;\n(e) Justification for the need to collect the traffic data;\n(f) The period for which traffic data are to be collected and a corresponding justification of its duration. Article 46 Mutual legal assistance in the interception of content data\nStates Parties shall endeavour to provide mutual legal assistance to each other in the real-time collection or recording of content data of specified communications transmitted by means of an information and communications technology system, to the extent permitted under treaties applicable to them or under their domestic laws.\nArticle 47 Law enforcement cooperation\nStates Parties shall cooperate closely with one another, consistent with their respective domestic legal and administrative systems, to enhance the effectiveness of law enforcement action to combat the offences established in accordance with this Convention. States Parties shall, in particular, take effective measures:\n(a) To enhance and, where necessary, to establish channels of communication between their competent authorities, agencies and services, taking into account existing channels, including those of the International Criminal Police Organization, in order to facilitate the secure and rapid exchange of information concerning all aspects of the offences established in accordance with this Convention, including, if the States Parties concerned deem it appropriate, links with other criminal activities;\n(b) To cooperate with other States Parties in conducting inquiries with respect to offences established in accordance with this Convention concerning:\n(c) To provide, where appropriate, necessary items or data for analytical or investigative purposes;\n(d) To exchange, where appropriate, information with other States Parties concerning specific means and methods used to commit the offences established in accordance with this Convention, including the use of false identities, forged, altered or false documents and other means of concealing activities, as well as cybercrime tactics, techniques and procedures;\n(e) To facilitate effective coordination between their competent authorities, agencies and services and to promote the exchange of personnel and other experts, including, subject to bilateral agreements or arrangements between the States Parties concerned, the posting of liaison officers;\n(f) To exchange information and coordinate administrative and other measures taken, as appropriate, for the purpose of early identification of the offences established in accordance with this Convention. With a view to giving effect to this Convention, States Parties shall consider entering into bilateral or multilateral agreements or arrangements on direct cooperation between their law enforcement agencies and, where such agreements or arrangements already exist, amending them. In the absence of such agreements or arrangements between the States Parties concerned, the States Parties may consider this Convention to be the basis for mutual law enforcement cooperation in respect of the offences established in accordance with this Convention. Whenever appropriate, States Parties shall make full use of agreements or arrangements, including international or regional organizations, to enhance the cooperation between their law enforcement agencies. Article 48 Joint investigations\nStates Parties shall consider concluding bilateral or multilateral agreements or arrangements whereby, in relation to offences established in accordance with this Convention that are the subject of criminal investigations, prosecutions or judicial proceedings in one or more States, the competent authorities concerned may establish joint investigative bodies. In the absence of such agreements or arrangements, joint investigations may be undertaken by agreement on a case-by-case basis. The States Parties involved shall ensure that the sovereignty of the State Party in whose territory such investigations are to take place is fully respected.\nArticle 49 Mechanisms for the recovery of property through international cooperation in confiscation\nEach State Party, in order to provide mutual legal assistance pursuant to article 50 of this Convention with respect to property acquired through or involved in the commission of an offence established in accordance with this Convention, shall, in accordance with its domestic law:\n(a) Take such measures as may be necessary to permit its competent authorities to give effect to an order of confiscation issued by a court of another State Party;\n(b) Take such measures as may be necessary to permit its competent authorities, where they have jurisdiction, to order the confiscation of such property of foreign origin by adjudication of an offence of money-laundering or such other offence as may be within its jurisdiction or by other procedures authorized under its domestic law; and\n(c) Consider taking such measures as may be necessary to allow confiscation of such property without a criminal conviction in cases in which the offender cannot be prosecuted by reason of death, flight or absence or in other appropriate cases. Each State Party, in order to provide mutual legal assistance upon a request made pursuant to article 50, paragraph 2, of this Convention, shall, in accordance with its domestic law:\n(a) Take such measures as may be necessary to permit its competent authorities to freeze or seize property upon a freezing or seizure order issued by a court or competent authority of a requesting State Party that provides a reasonable basis for the requested State Party to believe that there are sufficient grounds for taking such actions and that the property would eventually be subject to an order of confiscation for the purposes of paragraph 1 (a) of this article;\n(b) Take such measures as may be necessary to permit its competent authorities to freeze or seize property upon a request that provides a reasonable basis for the requested State Party to believe that there are sufficient grounds for taking such actions and that the property would eventually be subject to an order of confiscation for the purposes of paragraph 1 (a) of this article; and\n(c) Consider taking additional measures to permit its competent authorities to preserve property for confiscation, such as on the basis of a foreign arrest or criminal charge related to the acquisition of such property. Article 50 International cooperation for the purposes of confiscation\nA State Party that has received a request from another State Party having jurisdiction over an offence established in accordance with this Convention for the confiscation of proceeds of crime, property, equipment or other instrumentalities referred to in article 31, paragraph 1, of this Convention situated in its territory shall, to the greatest extent possible within its domestic legal system:\n(a) Submit the request to its competent authorities for the purpose of obtaining an order of confiscation and, if such an order is granted, give effect to it; or\n(b) Submit to its competent authorities, with a view to giving effect to it to the extent requested, an order of confiscation issued by a court in the territory of the requesting State Party in accordance with article 31, paragraph 1, of this Convention insofar as it relates to proceeds of crime, property, equipment or other instrumentalities situated in the territory of the requested State Party. Following a request made by another State Party having jurisdiction over an offence established in accordance with this Convention, the requested State Party shall take measures to identify, trace and freeze or seize proceeds of crime, property, equipment or other instrumentalities referred to in article 31, paragraph 1, of this Convention for the purpose of eventual confiscation to be ordered either by the requesting State Party or, pursuant to a request under paragraph 1 of this article, by the requested State Party. The provisions of article 40 of this Convention are applicable, mutatis mutandis, to this article. In addition to the information specified in article 40, paragraph 15, of this Convention, requests made pursuant to this article shall contain:\n(a) In the case of a request pertaining to paragraph 1 (a) of this article, a description of the property to be confiscated, including, to the extent possible, the location, and where relevant, the estimated value of the property and a statement of the facts relied upon by the requesting State Party sufficient to enable the requested State Party to seek the order under its domestic law;\n(b) In the case of a request pertaining to paragraph 1 (b) of this article, a legally admissible copy of an order of confiscation upon which the request is based issued by the requesting State Party, a statement of the facts and information as to the extent to which execution of the order is requested, a statement specifying the measures taken by the requesting State Party to provide adequate notification to bona fide third parties and to ensure due process, and a statement that the confiscation order is final;\n(c) In the case of a request pertaining to paragraph 2 of this article, a statement of the facts relied upon by the requesting State Party and a description of the actions requested and, where available, a legally admissible copy of an order on which the request is based. The decisions or actions provided for in paragraphs 1 and 2 of this article shall be taken by the requested State Party in accordance with and subject to the provisions of its domestic law and its procedural rules or any bilateral or multilateral treaty, agreement or arrangement to which it may be bound in relation to the requesting State Party. Each State Party shall furnish copies of its laws and regulations that give effect to this article and of any subsequent changes to such laws and regulations or a description thereof to the Secretary-General of the United Nations. If a State Party elects to make the taking of the measures referred to in paragraphs 1 and 2 of this article conditional on the existence of a relevant treaty, that State Party shall consider this Convention the necessary and sufficient treaty basis. Cooperation under this article may also be refused or provisional measures may be lifted if the requested State Party does not receive sufficient and timely evidence or if the property is of a de minimis value. Before lifting any provisional measure taken pursuant to this article, the requested State Party shall, wherever possible, give the requesting State Party an opportunity to present its reasons in favour of continuing the measure. The provisions of this article shall not be construed as prejudicing the rights of bona fide third parties. States Parties shall consider concluding bilateral or multilateral treaties, agreements or arrangements to enhance the effectiveness of international cooperation undertaken pursuant to this article. Article 51 Special cooperation\nWithout prejudice to its domestic law, each State Party shall endeavour to take measures to permit it to forward, without prejudice to its own criminal investigations, prosecutions or judicial proceedings, information on proceeds of offences established in accordance with this Convention to another State Party without prior request, when it considers that the disclosure of such information might assist the receiving State Party in initiating or carrying out criminal investigations, prosecutions or judicial proceedings or might lead to a request by that State Party under article 50 of this Convention.\nArticle 52 Return and disposal of confiscated proceeds of crime or property\nProceeds of crime or property confiscated by a State Party pursuant to article 31 or 50 of this Convention shall be disposed of by that State Party in accordance with its domestic law and administrative procedures. When acting on a request made by another State Party in accordance with article 50 of this Convention, States Parties shall, to the extent permitted by domestic law and if so requested, give priority consideration to returning the confiscated proceeds of crime or property to the requesting State Party so that it can give compensation to the victims of the crime or return such proceeds of crime or property to their prior legitimate owners. When acting on a request made by another State Party in accordance with articles 31 and 50 of this Convention, a State Party may, after due consideration has been given to compensation of victims, give special consideration to concluding agreements or arrangements on:\n(a) Contributing the value of such proceeds of crime or property or funds derived from the sale of such proceeds of crime or property or a part thereof to the account designated in accordance with article 56, paragraph 2 (c), of this Convention, and to intergovernmental bodies specializing in the fight against cybercrime;\n(b) Sharing with other States Parties, on a regular or case-by-case basis, such proceeds of crime or property, or funds derived from the sale of such proceeds of crime or property, in accordance with its domestic law or administrative procedures. Where appropriate, unless States Parties decide otherwise, the requested State Party may deduct reasonable expenses incurred in investigations, prosecutions or judicial proceedings leading to the return or disposition of confiscated property pursuant to this article. Chapter VI: Preventive measures Article 53 Preventive measures\nEach State Party shall endeavour, in accordance with fundamental principles of its legal system, to develop and implement or maintain effective and coordinated policies and best practices to reduce existing or future opportunities for cybercrime through appropriate legislative, administrative or other measures. Each State Party shall take appropriate measures, within its means and in accordance with fundamental principles of its domestic law, to promote the active participation of relevant individuals and entities outside the public sector, such as non-governmental organizations, civil society organizations, academic institutions and private sector entities, as well as the general public, in the relevant aspects of prevention of the offences established in accordance with this Convention. Preventive measures may include:\n(a) Strengthening cooperation between law enforcement agencies or prosecutors and relevant individuals and entities outside the public sector, such as non-governmental organizations, civil society organizations, academic institutions and private sector entities for the purpose of addressing relevant aspects of preventing and combating the offences established in accordance with this Convention;\n(b) Promoting public awareness regarding the existence, causes and gravity of the threat posed by the offences established in accordance with this Convention through public information activities, public education, media and information literacy programmes and curricula that promote public participation in preventing and combating such offences;\n(c) Building and making efforts to increase the capacity of domestic criminal justice systems, including training and developing expertise among criminal justice practitioners, as part of national prevention strategies against the offences established in accordance with this Convention;\n(d) Encouraging service providers to take effective measures, where feasible in the light of national circumstances and to the extent permitted by domestic law, to strengthen the security of the service providers’ products, services and customers;\n(e) Recognizing the contributions of the legitimate activities of security researchers when intended solely, and to the extent permitted and subject to the conditions prescribed by domestic law, to strengthen and improve the security of service providers’ products, services and customers located within the territory of the State Party;\n(f) Developing, facilitating and promoting programmes and activities in order to discourage those at risk of engaging in cybercrime from becoming offenders and to develop their skills in a lawful manner;\n(g) Endeavouring to promote the reintegration into society of persons convicted of offences established in accordance with this Convention;\n(h) Developing strategies and policies, in accordance with domestic law, to prevent and eradicate gender-based violence that occurs through the use of an information and communications technology system, as well as taking into consideration the special circumstances and needs of persons in vulnerable situations in developing preventive measures;\n(i) Undertaking specific and tailored efforts to keep children safe online, including through education and training on and raising public awareness of child sexual abuse or child sexual exploitation online and through revising domestic legal frameworks and enhancing international cooperation aimed at its prevention, as well as making efforts to ensure the swift removal of child sexual abuse and child sexual exploitation material;\n(j) Enhancing the transparency of and promoting the contribution of the public to decision-making processes and ensuring that the public has adequate access to information;\n(k) Respecting, promoting and protecting the freedom to seek, receive and impart public information concerning cybercrime;\n(l) Developing or strengthening support programmes for victims of the offences established in accordance with this Convention;\n(m) Preventing and detecting transfers of proceeds of crime and property related to the offences established in accordance with this Convention. Each State Party shall take appropriate measures to ensure that the relevant competent authority or authorities responsible for preventing and combating cybercrime are known and accessible to the public, where appropriate, for the reporting, including anonymously, of any incident that may be considered a criminal offence established in accordance with this Convention. States Parties shall endeavour to periodically evaluate existing relevant national legal frameworks and administrative practices with a view to identifying gaps and vulnerabilities and ensuring their relevance in the face of changing threats posed by the offences established in accordance with this Convention. States Parties may collaborate with each other and with relevant international and regional organizations in promoting and developing the measures referred to in this article. This includes participation in international projects aimed at the prevention of cybercrime. Each State Party shall inform the Secretary-General of the United Nations of the name and address of the authority or authorities that may assist other States Parties in developing and implementing specific measures to prevent cybercrime. Chapter VII: Technical assistance and information exchange Article 54 Technical assistance and capacity-building\nStates Parties shall, according to their capacity, consider affording one another the widest measure of technical assistance and capacity-building, including training and other forms of assistance, the mutual exchange of relevant experience and specialized knowledge and the transfer of technology on mutually agreed terms, taking into particular consideration the interests and needs of developing States Parties, with a view to facilitating the prevention, detection, investigation and prosecution of the offences covered by this Convention. States Parties shall, to the extent necessary, initiate, develop, implement or improve specific training programmes for their personnel responsible for the prevention, detection, investigation and prosecution of the offences covered by this Convention. Activities referred to in paragraphs 1 and 2 of this article may deal, to the extent permitted by domestic law, with the following:\n(a) Methods and techniques used in the prevention, detection, investigation and prosecution of the offences covered by this Convention;\n(b) Building capacity in the development and planning of strategic policies and legislation to prevent and combat cybercrime;\n(c) Building capacity in the collection, preservation and sharing of evidence, in particular in electronic form, including the maintenance of the chain of custody and forensic analysis;\n(d) Modern law enforcement equipment and the use thereof;\n(e) Training of competent authorities in the preparation of requests for mutual legal assistance and other means of cooperation that meet the requirements of this Convention, especially for the collection, preservation and sharing of evidence in electronic form;\n(f) Prevention, detection and monitoring of the movements of proceeds deriving from the commission of the offences covered by this Convention, property, equipment or other instrumentalities and methods used for the transfer, concealment or disguise of such proceeds, property, equipment or other instrumentalities;\n(g) Appropriate and efficient legal and administrative mechanisms and methods for facilitating the seizure, confiscation and return of proceeds of offences covered by this Convention;\n(h) Methods used in the protection of victims and witnesses who cooperate with judicial authorities;\n(i) Training in relevant substantive and procedural law, and law enforcement investigation powers, as well as in national and international regulations and in languages. States Parties shall, subject to their domestic law, endeavour to leverage the expertise of and cooperate closely with other States Parties and relevant international and regional organizations, non-governmental organizations, civil society organizations, academic institutions and private sector entities, with a view to enhancing the effective implementation of this Convention. States Parties shall assist one another in planning and implementing research and training programmes designed to share expertise in the areas referred to in paragraph 3 of this article, and to that end shall also, when appropriate, use regional and international conferences and seminars to promote cooperation and to stimulate discussion on problems of mutual concern. States Parties shall consider assisting one another, upon request, in conducting evaluations, studies and research relating to the types, causes and effects of offences covered by this Convention committed in their respective territories, with a view to developing, with the participation of the competent authorities and relevant non‑governmental organizations, civil society organizations, academic institutions and private sector entities, strategies and action plans to prevent and combat cybercrime. States Parties shall promote training and technical assistance that facilitates timely extradition and mutual legal assistance. Such training and technical assistance may include language training, assistance with the drafting and handling of mutual legal assistance requests, and secondments and exchanges between personnel in central authorities or agencies with relevant responsibilities. States Parties shall strengthen, to the extent necessary, efforts to maximize the effectiveness of technical assistance and capacity-building in international and regional organizations and in the framework of relevant bilateral and multilateral agreements or arrangements. States Parties shall consider establishing voluntary mechanisms with a view to contributing financially to the efforts of developing countries to implement this Convention through technical assistance programmes and capacity-building projects. Each State Party shall endeavour to make voluntary contributions to the United Nations Office on Drugs and Crime for the purpose of fostering, through the Office, programmes and projects with a view to implementing this Convention through technical assistance and capacity-building. Article 55 Exchange of information\nEach State Party shall consider analysing, as appropriate, in consultation with relevant experts, including from non-governmental organizations, civil society organizations, academic institutions and private sector entities, trends in its territory with respect to offences covered by this Convention, as well as the circumstances in which such offences are committed. States Parties shall consider developing and sharing with each other and through international and regional organizations statistics, analytical expertise and information concerning cybercrime, with a view to developing, insofar as possible, common definitions, standards and methodologies, as well as best practices, to prevent and combat such crime. Each State Party shall consider monitoring its policies and practical measures to prevent and combat offences covered by this Convention and making assessments of their effectiveness and efficiency. States Parties shall consider exchanging information on legal, policy and technological developments related to cybercrime and the collection of evidence in electronic form. Article 56 Implementation of the Convention through economic development and technical assistance\nStates Parties shall take measures conducive to the optimal implementation of this Convention to the extent possible, through international cooperation, taking into account the negative effects of the offences covered by this Convention on society in general and, in particular, on sustainable development. States Parties are strongly encouraged to make concrete efforts, to the extent possible and in coordination with each other, as well as with international and regional organizations:\n(a) To enhance their cooperation at various levels with other States Parties, in particular developing countries, with a view to strengthening their capacity to prevent and combat the offences covered by this Convention;\n(b) To enhance financial and material assistance to support the efforts of other States Parties, in particular developing countries, in effectively preventing and combating the offences covered by this Convention and to help them to implement this Convention;\n(c) To provide technical assistance to other States Parties, in particular developing countries, in support of meeting their needs regarding the implementation of this Convention. To that end, States Parties shall endeavour to make adequate and regular voluntary contributions to an account specifically designated for that purpose in a United Nations funding mechanism;\n(d) To encourage, as appropriate, non-governmental organizations, civil society organizations, academic institutions and private sector entities, as well as financial institutions, to contribute to the efforts of States Parties, including in accordance with this article, in particular by providing more training programmes and modern equipment to developing countries in order to assist them in achieving the objectives of this Convention;\n(e) To exchange best practices and information with regard to activities undertaken, with a view to improving transparency, avoiding duplication of effort and making best use of any lessons learned. States Parties shall also consider using existing subregional, regional and international programmes, including conferences and seminars, to promote cooperation and technical assistance and to stimulate discussion on problems of mutual concern, including the special problems and needs of developing countries. To the extent possible, States Parties shall ensure that resources and efforts are distributed and directed to support the harmonization of standards, skills, capacity, expertise and technical capabilities with the aim of establishing common minimum standards among States Parties to eradicate safe havens for the offences covered by this Convention and strengthen the fight against cybercrime. To the extent possible, the measures taken under this article shall be without prejudice to existing foreign assistance commitments or to other financial cooperation arrangements at the bilateral, regional or international levels. States Parties may conclude bilateral, regional or multilateral agreements or arrangements on material and logistical assistance, taking into consideration the financial arrangements necessary for the means of international cooperation provided for by this Convention to be effective and for the prevention, detection, investigation and prosecution of the offences covered by this Convention. Chapter VIII: Mechanism of implementation Article 57 Conference of the States Parties to the Convention\nA Conference of the States Parties to the Convention is hereby established to improve the capacity of and cooperation between States Parties to achieve the objectives set forth in this Convention and to promote and review its implementation. The Secretary-General of the United Nations shall convene the Conference of the States Parties not later than one year following the entry into force of this Convention. Thereafter, regular meetings of the Conference shall be held in accordance with the rules of procedure adopted by the Conference. The Conference of the States Parties shall adopt rules of procedure and rules governing the activities set forth in this article, including rules concerning the admission and participation of observers, and the payment of expenses incurred in carrying out those activities. Such rules and related activities shall take into account principles such as effectiveness, inclusivity, transparency, efficiency and national ownership. In establishing its regular meetings, the Conference of the States Parties shall take into account the time and location of the meetings of other relevant international and regional organizations and mechanisms in similar matters, including their subsidiary treaty bodies, consistent with the principles identified in paragraph 3 of this article. The Conference of the States Parties shall agree upon activities, procedures and methods of work to achieve the objectives set forth in paragraph 1 of this article, including:\n(a) Facilitating the effective use and implementation of this Convention, the identification of any problems thereof, as well as the activities carried out by States Parties under this Convention, including encouraging the mobilization of voluntary contributions;\n(b) Facilitating the exchange of information on legal, policy and technological developments pertaining to the offences established in accordance with this Convention and the collection of evidence in electronic form among States Parties and relevant international and regional organizations, as well as non-governmental organizations, civil society organizations, academic institutions and private sector entities, in accordance with domestic law, as well as on patterns and trends in cybercrime and on successful practices for preventing and combating such offences;\n(c) Cooperating with relevant international and regional organizations, as well as non-governmental organizations, civil society organizations, academic institutions and private sector entities;\n(d) Making appropriate use of relevant information produced by other international and regional organizations and mechanisms for preventing and combating the offences established in accordance with this Convention, in order to avoid unnecessary duplication of work;\n(e) Reviewing periodically the implementation of this Convention by its States Parties;\n(f) Making recommendations to improve this Convention and its implementation as well as considering possible supplementation or amendment of the Convention;\n(g) Elaborating and adopting supplementary protocols to this Convention on the basis of articles 61 and 62 of this Convention;\n(h) Taking note of the technical assistance and capacity-building requirements of States Parties regarding the implementation of this Convention and recommending any action it may deem necessary in that respect. Each State Party shall provide the Conference of the States Parties with information on legislative, administrative and other measures, as well as on its programmes, plans and practices, to implement this Convention, as required by the Conference. The Conference shall examine the most effective way of receiving and acting upon information, including, inter alia, information received from States Parties and from competent international and regional organizations. Inputs received from representatives of relevant non-governmental organizations, civil society organizations, academic institutions and private sector entities, duly accredited in accordance with procedures to be decided upon by the Conference, may also be considered. For the purpose of paragraph 5 of this article, the Conference of the States Parties may establish and administer such review mechanisms as it considers necessary. Pursuant to paragraphs 5 to 7 of this article, the Conference of the States Parties shall establish, if it deems necessary, any appropriate mechanisms or subsidiary bodies to assist in the effective implementation of the Convention. Article 58 Secretariat\nThe Secretary-General of the United Nations shall provide the necessary secretariat services to the Conference of the States Parties to the Convention. The secretariat shall:\n(a) Assist the Conference of the States Parties in carrying out the activities set forth in this Convention and make arrangements and provide the necessary services for the sessions of the Conference as they pertain to this Convention;\n(b) Upon request, assist States Parties in providing information to the Conference of the States Parties, as envisaged in this Convention; and\n(c) Ensure the necessary coordination with the secretariats of relevant international and regional organizations. Chapter IX: Final provisions Article 59 Implementation of the Convention\nEach State Party shall take the necessary measures, including legislative and administrative measures, in accordance with fundamental principles of its domestic law, to ensure the implementation of its obligations under this Convention. Each State Party may adopt more strict or severe measures than those provided for by this Convention for preventing and combating the offences established in accordance with this Convention. Article 60 Effects of the Convention\nIf two or more States Parties have already concluded an agreement or treaty on the matters dealt with in this Convention or have otherwise established their relations on such matters, or should they in future do so, they shall also be entitled to apply that agreement or treaty or to regulate those relations accordingly. Nothing in this Convention shall affect other rights, restrictions, obligations and responsibilities of a State Party under international law. Article 61 Relation with protocols\nThis Convention may be supplemented by one or more protocols. In order to become a Party to a protocol, a State or a regional economic integration organization must also be a Party to this Convention. A State Party to this Convention is not bound by a protocol unless it becomes a Party to the protocol in accordance with the provisions thereof. Any protocol to this Convention shall be interpreted together with this Convention, taking into account the purpose of that protocol. Article 62 Adoption of supplementary protocols\nAt least 60 States Parties shall be required before any supplementary protocol is considered for adoption by the Conference of the States Parties. The Conference shall make every effort to achieve consensus on any supplementary protocol. If all efforts at consensus have been exhausted and no agreement has been reached, the supplementary protocol shall, as a last resort, require for its adoption at least a two‑thirds majority vote of the States Parties present and voting at the meeting of the Conference. Regional economic integration organizations, in matters within their competence, shall exercise their right to vote under this article with a number of votes equal to the number of their member States that are Parties to this Convention. Such organizations shall not exercise their right to vote if their member States exercise theirs and vice versa. Article 63 Settlement of disputes\nStates Parties shall endeavour to settle disputes concerning the interpretation or application of this Convention through negotiation or any other peaceful means of their own choice. Any dispute between two or more States Parties concerning the interpretation or application of this Convention that cannot be settled through negotiation or other peaceful means within a reasonable time shall, at the request of one of those States Parties, be submitted to arbitration. If, six months after the date of the request for arbitration, those States Parties are unable to agree on the organization of the arbitration, any one of those States Parties may refer the dispute to the International Court of Justice by request in accordance with the Statute of the Court. Each State Party may, at the time of signature, ratification, acceptance or approval of or accession to this Convention, declare that it does not consider itself bound by paragraph 2 of this article. The other States Parties shall not be bound by paragraph 2 of this article with respect to any State Party that has made such a reservation. Any State Party that has made a reservation in accordance with paragraph 3 of this article may at any time withdraw that reservation by notification to the Secretary-General of the United Nations. Article 64 Signature, ratification, acceptance, approval and accession\nThis Convention shall be open to all States for signature in Hanoi in 2025 and thereafter at United Nations Headquarters in New York until 31 December 2026. This Convention shall also be open for signature by regional economic integration organizations, provided that at least one member State of such an organization has signed this Convention in accordance with paragraph 1 of this article. This Convention is subject to ratification, acceptance or approval. Instruments of ratification, acceptance or approval shall be deposited with the Secretary-General of the United Nations. A regional economic integration organization may deposit its instrument of ratification, acceptance or approval if at least one of its member States has done likewise. In that instrument of ratification, acceptance or approval, such organization shall declare the extent of its competence with respect to the matters governed by this Convention. Such organization shall also inform the depositary of any relevant modification in the extent of its competence. This Convention is open for accession by any State or any regional economic integration organization of which at least one member State is a Party to this Convention. Instruments of accession shall be deposited with the Secretary-General of the United Nations. At the time of its accession, a regional economic integration organization shall declare the extent of its competence with respect to matters governed by this Convention. Such organization shall also inform the depositary of any relevant modification in the extent of its competence. Article 65 Entry into force\nThis Convention shall enter into force on the ninetieth day after the date of deposit of the fortieth instrument of ratification, acceptance, approval or accession. For the purpose of this paragraph, any instrument deposited by a regional economic integration organization shall not be counted as additional to those deposited by member States of that organization. For each State or regional economic integration organization ratifying, accepting, approving or acceding to this Convention after the deposit of the fortieth instrument of such action, this Convention shall enter into force on the thirtieth day after the date of deposit by such State or organization of the relevant instrument or on the date on which this Convention enters into force pursuant to paragraph 1 of this article, whichever is later. Article 66 Amendment\nAfter the expiry of five years from the entry into force of this Convention, a State Party may propose an amendment and transmit it to the Secretary-General of the United Nations, who shall thereupon communicate the proposed amendment to the States Parties and to the Conference of the States Parties to the Convention for the purpose of considering and deciding on the proposal. The Conference shall make every effort to achieve consensus on each amendment. If all efforts at consensus have been exhausted and no agreement has been reached, the amendment shall, as a last resort, require for its adoption a two-thirds majority vote of the States Parties present and voting at the meeting of the Conference. Regional economic integration organizations, in matters within their competence, shall exercise their right to vote under this article with a number of votes equal to the number of their member States that are Parties to this Convention. Such organizations shall not exercise their right to vote if their member States exercise theirs and vice versa. An amendment adopted in accordance with paragraph 1 of this article is subject to ratification, acceptance or approval by States Parties. An amendment adopted in accordance with paragraph 1 of this article shall enter into force in respect of a State Party 90 days after the date of the deposit with the Secretary-General of the United Nations of an instrument of ratification, acceptance or approval of such amendment. When an amendment enters into force, it shall be binding on those States Parties that have expressed their consent to be bound by it. Other States Parties shall still be bound by the provisions of this Convention and any earlier amendments that they have ratified, accepted or approved. Article 67 Denunciation\nA State Party may denounce this Convention by written notification to the Secretary-General of the United Nations. Such denunciation shall become effective one year after the date of receipt of the notification by the Secretary-General. A regional economic integration organization shall cease to be a Party to this Convention when all of its member States have denounced it. Denunciation of this Convention in accordance with paragraph 1 of this article shall entail the denunciation of any protocols thereto. Article 68 Depositary and languages\nThe Secretary-General of the United Nations is designated depositary of this Convention. The original of this Convention, of which the Arabic, Chinese, English, French, Russian and Spanish texts are equally authentic, shall be deposited with the Secretary-General of the United Nations.\nIN WITNESS WHEREOF, the undersigned plenipotentiaries, being duly authorized thereto by their respective Governments, have signed this Convention. ","permalink":"https://ai.intlaws.com/en/compliance/intl/un-cybercrime-convention/","summary":"Officialof the UN Convention against Cybercrime (UNGA resolution 79/243, 24 December 2024, annex; 9 chapters, 68 articles). Enters into force on the ninetieth day after deposit of the fortieth instrument of ratification; not yet in force. Text taken from official UN sources.","title":"United Nations Convention against Cybercrime"}]