CHAPTER XDELEGATED ACTS AND IMPLEMENTING ACTS

Article 92Exercise of the delegation

Official text

(1)The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.

(2)The delegation of power referred to in Article 12 (8) and Article 43 (8) shall be conferred on the Commission for an indeterminate period of time from 24 May 2016.

(3)The delegation of power referred to in Article 12 (8) and Article 43 (8) may be revoked at any time by the European Parliament or by the Council. A decision of revocation shall put an end to the delegation of power specified in that decision. It shall take effect the day following that of its publication in the Official Journal of the European Unio n or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.

(4)As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council.

(5)A delegated act adopted pursuant to Article 12 (8) and Article 43 (8) shall enter into force only if no objection has been expressed by either the European Parliament or the Council within a period of three months of notification of that act to the European Parliament and the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by three months at the initiative of the European Parliament or of the Council.

Commentary

Article 92 GDPR is a procedural provision that governs the Commission's power to adopt delegated acts under the GDPR. Unlike substantive provisions regulating personal data processing, Article 92 does not create rights or obligations for controllers, processors, or data subjects. Instead, it establishes the constitutional framework through which the European Commission may supplement certain limited parts of the GDPR using delegated legislation.

The provision must be read together with:

  • Article 290 TFEU (Treaty on the Functioning of the European Union),

  • Article 12(8) GDPR (standardised privacy icons),

  • Article 43(8) GDPR (certification mechanisms),

  • Recital 166 GDPR (delegated acts).

A key point is that the GDPR grants the Commission delegated powers only in two specific areas:

  1. standardised privacy icons under Article 12(8); and

  2. certification requirements under Article 43(8).

Article 92 establishes the conditions under which those delegated powers may be exercised.

1. Purpose of Article 92

The GDPR is a legislative act adopted by the European Parliament and the Council. Under Article 290 TFEU, legislation may delegate authority to the Commission to adopt non-legislative acts that supplement or amend certain non-essential elements of the legislation.

Article 92 performs precisely this function. It defines:

  • the duration of the delegation;

  • revocation rights;

  • notification requirements;

  • parliamentary and council oversight;

  • conditions for entry into force.

The provision thus ensures democratic control over delegated legislation.


2. Relationship with Article 290 TFEU

Article 290(1) TFEU permits the legislature to delegate power to the Commission to adopt non-legislative acts of general application.

However, several strict conditions apply.

Delegation may concern only non-essential elements of legislation. Essential policy choices must remain with the legislature.

The legislature must also determine:

  • objectives;

  • content;

  • scope;

  • duration;

  • conditions of delegation.

Article 92 GDPR satisfies these requirements for the delegations contained in Articles 12(8) and 43(8).


3. Essential versus Non-Essential Elements

A fundamental constitutional principle underlying Article 92 is the distinction between:

  • essential legislative matters; and

  • non-essential technical matters.

Only non-essential matters may be delegated.

In the GDPR context, matters such as:

  • data subject rights;

  • legal bases for processing;

  • controller obligations;

  • regulatory enforcement;

  • administrative fines;

are core legislative choices and therefore cannot be delegated to the Commission.

The Commission's delegated powers are restricted to supplementary technical areas.


4. Article 92(1): Delegation Subject to Conditions of Article 92

The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.

This paragraph establishes a general rule.

The Commission's delegated powers do not exist independently. They may only be exercised under the safeguards and procedures established by Article 92.

In practical terms, this means that any delegated act adopted under:

  • Article 12(8), or

  • Article 43(8),

must comply with all procedural requirements found in Article 92.


5. Article 92(2): Duration of Delegation

The delegation of power referred to in Article 12(8) and Article 43(8) shall be conferred on the Commission for an indeterminate period of time from 24 May 2016.

This provision gives the Commission a continuing authority to legislate in the narrow areas identified by the GDPR.

At first glance, the phrase "indeterminate period of time" may appear inconsistent with Article 290 TFEU, which requires legislative acts to define the duration of delegated powers.

However, this is resolved by Article 92(3).

The delegation exists continuously but remains fully revocable.

Thus, the Commission enjoys ongoing competence while Parliament and Council retain ultimate control.


6. What Powers Are Delegated?

1. Article 12(8): Standardised Privacy Icons

The Commission may determine:

  • information represented by privacy icons;

  • procedures for using such icons.

The purpose is to support transparency by providing data subjects with easily understandable visual indicators.

Example

The Commission could theoretically adopt a standard symbol indicating:

  • international transfers;
  • profiling;
  • marketing uses;
  • retention practices. However, to date, the Commission has not established a mandatory GDPR icon regime.

7. Article 43(8): Certification Requirements

The Commission may specify technical requirements for certification mechanisms under Article 42.

Example

The Commission could define:

  • technical certification criteria;
  • certification assessment requirements;
  • accreditation standards;
  • certification documentation requirements. Such measures would supplement, rather than replace, the GDPR's certification framework.

8. Article 92(3): Revocation of Delegated Powers

The delegation of power may be revoked at any time by the European Parliament or by the Council.

This provision is one of the most important safeguards.

Although delegation is granted indefinitely, Parliament and Council can withdraw it whenever they consider such action necessary.


9. Purpose of Revocation Power

The revocation mechanism ensures that the Commission remains politically accountable.

If the Commission:

  • exceeds its intended role,

  • adopts controversial delegated acts,

  • legislates beyond the GDPR's objectives,

the legislature can intervene and terminate the delegation.


10. Effect of Revocation

Revocation does not automatically invalidate previous delegated acts.

The GDPR explicitly protects existing delegated acts that have already entered into force.

Therefore:

Before Revocation

Commission adopts delegated act. Delegated act enters into force. Parliament later revokes delegation.

Result

The delegated act remains valid unless separately amended or repealed.


11. Timing of Revocation

The revocation decision takes effect:

  • on the day after publication in the Official Journal; or

  • on a later date specified in the decision.

This ensures legal certainty.


12. Article 92(4): Notification Requirement

As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council.

This creates a procedural checkpoint before the delegated act can become legally effective.

The Commission cannot adopt a delegated act quietly.

Instead, it must immediately notify both:

  • the European Parliament;

  • the Council of the European Union.


13. Purpose

The notification serves two functions:

Democratic Oversight

It allows the legislators to review the delegated act.

Triggering the Objection Period

The notification starts the three-month scrutiny period under Article 92(5).

Without notification, the delegated act cannot proceed through the control mechanism established by the GDPR.


14. Article 92(5): Entry into Force

A delegated act enters into force only if:

  • neither Parliament nor Council objects within three months; or

  • both institutions notify the Commission that they will not object.

The period may be extended by three additional months.


15. Significance

Unlike ordinary Commission administrative measures, delegated acts operate under a system of legislative supervision.

The Commission may adopt the act, but it does not become effective automatically.

The legislators retain a veto power.


16. Normal Procedure

Step 1

Commission adopts delegated act.

Step 2

Commission notifies Parliament and Council.

Step 3

Three-month review period starts.

Step 4

Parliament and Council decide whether to object.

Step 5

If neither objects, the delegated act enters into force.


17. Extension of Review Period

Either Parliament or Council may request an additional three months.

Thus:

  • standard review period = 3 months;

  • extended review period = up to 6 months.

This allows additional scrutiny for complex or politically sensitive delegated measures.


18. Possible Outcomes

Scenario

A: No Objections Neither Parliament nor Council objects. Result: ✅ Delegated act enters into force.


19. Scenario B: Early Approval

Both institutions notify the Commission that they will not object.

Result:

✅ Delegated act may enter into force before expiry of the three-month period.


20. Scenario C: Parliament Objects

Parliament objects during review period.

Result:

❌ Delegated act cannot enter into force.


21. Scenario D: Council Objects

Council objects during review period.

Result:

❌ Delegated act cannot enter into force.


22. Scenario E: Both Object

Both institutions object.

Result:

❌ Delegated act fails entirely.

The Commission would need to revise its proposal.


23. Recital 166

Recital 166 explains why delegated powers are necessary.

The recital emphasises two principles:

  1. the Commission should be able to supplement technical aspects of the GDPR;

  2. Parliament and Council must retain supervision over such delegated powers.

The recital specifically highlights consultation, expertise, and careful preparation before adoption of delegated acts.

This is particularly relevant to the development of:

  • standardised privacy icons;

  • certification requirements.


24. Practical Importance

Article 92 has relatively limited practical significance because the GDPR grants delegated powers in only two areas.

As of today, the provision has had considerably less practical impact than major substantive GDPR provisions such as:

  • Article 5 (principles),

  • Article 6 (legal bases),

  • Article 13 (transparency),

  • Article 15 (access),

  • Article 17 (erasure),

  • Article 32 (security),

  • Article 83 (fines).

Nevertheless, Article 92 remains important because it preserves the constitutional balance between:

  • the EU legislature (Parliament and Council), and

  • the European Commission.

It ensures that the Commission may supplement certain technical aspects of the GDPR while preventing it from altering the GDPR's essential policy choices without democratic oversight.

Key Takeaways

Article 92 establishes the procedural framework for GDPR delegated acts.

The Commission may receive delegated authority only under:

  • Article 12(8) (privacy icons); and

  • Article 43(8) (certification requirements).

The delegation:

  • exists for an indefinite period;

  • can be revoked at any time by Parliament or Council;

  • requires immediate notification after adoption;

  • is subject to a three-month objection period (extendable to six months);

  • enters into force only if no objection is raised.

Ultimately, Article 92 is a constitutional safeguard provision designed to ensure that any GDPR delegated legislation remains subject to parliamentary and council oversight while allowing limited technical supplementation of the Regulation.