Article 92 GDPR is a procedural provision that governs the Commission's power to adopt delegated acts under the GDPR. Unlike substantive provisions regulating personal data processing, Article 92 does not create rights or obligations for controllers, processors, or data subjects. Instead, it establishes the constitutional framework through which the European Commission may supplement certain limited parts of the GDPR using delegated legislation.
The provision must be read together with:
-
Article 290 TFEU (Treaty on the Functioning of the European Union),
-
Article 12(8) GDPR (standardised privacy icons),
-
Article 43(8) GDPR (certification mechanisms),
-
Recital 166 GDPR (delegated acts).
A key point is that the GDPR grants the Commission delegated powers only in two specific areas:
-
standardised privacy icons under Article 12(8); and
-
certification requirements under Article 43(8).
Article 92 establishes the conditions under which those delegated powers may be exercised.