Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: FR

Article 80 Représentation des personnes concernées


Summary What does Article 80 of the GDPR regulation say?

This article addresses the ability of data subjects to be represented by qualifying third-party organisations when exercising their rights under the GDPR.

It allows data subjects to mandate not-for-profit bodies — provided they meet certain criteria — to act on their behalf in complaints, judicial proceedings, and compensation claims.

The article also opens the door for Member States to go further, permitting such bodies to act without any individual mandate if they consider that data subject rights have been infringed.

Important points:

  • Data subjects can mandate a qualifying not-for-profit body to lodge complaints, pursue judicial remedies under Articles 77, 78 and 79, and seek compensation under Article 82 on their behalf.
  • The representing body must be properly constituted under Member State law, have statutory objectives in the public interest, and be active in the field of personal data protection.
  • Member States may allow qualifying bodies to act independently of any individual mandate, bringing complaints and exercising rights under Articles 78 and 79 on their own initiative.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. La personne concernée a le droit de mandater un organisme, une organisation ou une association à but non lucratif, qui a été valablement constitué conformément au droit d'un État membre, dont les objectifs statutaires sont d'intérêt public et est actif dans le domaine de la protection des droits et libertés des personnes concernées dans le cadre de la protection des données à caractère personnel les concernant, pour qu'il introduise une réclamation en son nom, exerce en son nom les droits visés aux articles 77, 78 et 79 et exerce en son nom le droit d'obtenir réparation visé à l'article 82 lorsque le droit d'un État membre le prévoit.

    1. Les États membres peuvent prévoir que tout organisme, organisation ou association visé au paragraphe 1 du présent article, indépendamment de tout mandat confié par une personne concernée, a, dans l'État membre en question, le droit d'introduire une réclamation auprès de l'autorité de contrôle qui est compétente en vertu de l'article 77, et d'exercer les droits visés aux articles 78 et 79 s'il considère que les droits d'une personne concernée prévus dans le présent règlement ont été violés du fait du traitement.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod