CHAPTER XIFINAL PROVISIONS

Article 97Commission reports

Official text

(1)By 25 May 2020 and every four years thereafter, the Commission shall submit a report on the evaluation and review of this Regulation to the European Parliament and to the Council. The reports shall be made public.

(2)In the context of the evaluations and reviews referred to in paragraph 1, the Commission shall examine, in particular, the application and functioning of:

(a)Chapter V on the transfer of personal data to third countries or international organisations with particular regard to decisions adopted pursuant to Article 45 (3) of this Regulation and decisions adopted on the basis of Article 25(6) of Directive 95/46/EC;

(b)Chapter VII on cooperation and consistency.

(3)For the purpose of paragraph 1, the Commission may request information from Member States and supervisory authorities.

(4)In carrying out the evaluations and reviews referred to in paragraphs 1 and 2, the Commission shall take into account the positions and findings of the European Parliament, of the Council, and of other relevant bodies or sources.

(5)The Commission shall, if necessary, submit appropriate proposals to amend this Regulation, in particular taking into account of developments in information technology and in the light of the state of progress in the information society.

Commentary

Article 97 creates a formal system for the periodic evaluation of the GDPR by the European Commission. It recognises that data protection law operates in a rapidly changing technological, commercial and regulatory environment. The GDPR cannot be treated as legislation whose effectiveness is assessed only when a serious problem arises. The Commission must examine its operation at regular intervals, publish its conclusions, and consider whether amendments are necessary.

Unlike many GDPR provisions, Article 97 does not directly regulate controllers, processors or data subjects. It imposes obligations primarily on the European Commission. Nevertheless, its operation can affect all participants in the GDPR system because Commission reports may identify enforcement difficulties, inconsistencies between Member States, shortcomings in international transfer mechanisms, or areas requiring legislative reform.

Article 97 contains no specifically assigned recital. Its purpose must therefore be understood from its wording, the GDPR’s wider objectives, and the provisions that it expressly requires the Commission to examine. It is particularly connected with:

  • Chapter V, concerning transfers to third countries and international organisations;

  • Article 45, concerning adequacy decisions;

  • Chapter VII, concerning cooperation and consistency;

  • Articles 60 to 67, which establish cooperation between supervisory authorities and the consistency mechanism;

  • Article 70, concerning the functions of the European Data Protection Board;

  • the Commission’s power to propose EU legislation under the Treaties.

1. Overall function of Article 97

Article 97 establishes a review cycle through which the Commission must answer three broad questions:

  1. Is the GDPR operating effectively in practice?

  2. Are its international transfer and supervisory cooperation mechanisms working as intended?

  3. Does the GDPR require amendment in light of technological and social developments?

The provision is therefore not simply a reporting formality. It is a mechanism of institutional accountability and legislative maintenance.

The reporting obligation also reflects the difference between the text of a law and its practical implementation. A provision may appear clear in legislation but produce inconsistent outcomes when applied by supervisory authorities, courts, businesses and public bodies across different Member States. Periodic review allows such difficulties to be formally identified.

Illustration

Suppose supervisory authorities in several Member States interpret the one-stop-shop mechanism differently, causing uncertainty about which authority should lead a cross-border investigation. An Article 97 review may examine that difficulty, consider evidence from the authorities and the EDPB, and recommend procedural or legislative changes.


2. Article 97(1): Timing, recipients and publication of reports

Article 97(1) required the Commission to submit its first evaluation and review report by 25 May 2020, two years after the GDPR became applicable. It must submit further reports every four years thereafter.

The reports must be sent to:

  • the European Parliament; and

  • the Council of the European Union.

They must also be made public.


3. 2.1 Mandatory nature of the review

The wording “shall submit” makes the reporting obligation mandatory. The Commission does not have discretion to decide whether a review is politically convenient or administratively necessary.

The four-year cycle creates continuing oversight rather than a one-time evaluation. It enables comparison over time. A problem that appears temporary in one review may prove structural in a later review. Conversely, a difficulty identified in an earlier report may be resolved through guidance, case law, enforcement cooperation or technical improvement.


4. 2.2 Meaning of “evaluation and review”

The two expressions indicate a broad examination.

An evaluation considers how the GDPR has operated in practice, including whether it has achieved its objectives, whether enforcement has been effective, and whether the legal mechanisms are proportionate and workable.

A review considers whether the legal framework itself remains appropriate or requires adjustment.

The Commission should therefore examine both:

  • the effectiveness of implementation; and

  • the continuing adequacy of the legislative design.

Illustration

If cross-border complaints take several years to resolve, the Commission should not merely record the number of complaints. It should examine why the delay occurs, whether the difficulty arises from inadequate resources, procedural rules, inconsistent national systems, or shortcomings in the GDPR itself.


5. 2.3 Reports to Parliament and Council

The European Parliament and Council are the principal EU legislative institutions that adopted the GDPR. Submission to both institutions ensures that the findings are placed before the bodies capable of considering legislative reform.

The reports may support:

  • parliamentary scrutiny;

  • Council discussions;

  • proposals for amendments;

  • institutional recommendations;

  • further studies;

  • requests for action by the Commission or Member States.

The Commission’s report does not itself amend the GDPR. Any legislative change must follow the applicable EU legislative procedure.


6. 2.4 Public availability

Article 97 expressly requires the reports to be public. Publication promotes transparency and permits scrutiny by:

  • data subjects;

  • supervisory authorities;

  • researchers;

  • civil society organisations;

  • controllers and processors;

  • industry associations;

  • legal practitioners;

  • national legislatures.

Public reporting also makes it possible to compare the Commission’s conclusions with the practical experience of other stakeholders.

Illustration

If the Commission concludes that international transfer mechanisms operate adequately, privacy organisations, businesses or supervisory authorities may examine the published evidence and challenge, support or qualify that conclusion.


7. Article 97(2): Mandatory subjects of examination

Article 97(2) identifies two areas that the Commission must examine in particular:

  1. international transfers under Chapter V; and

  2. cooperation and consistency under Chapter VII.

The words “in particular” indicate that these are mandatory priority areas, but they do not necessarily prevent the Commission from examining other parts of the GDPR.


8. 3.1 Article 97(2)(a): International transfers under Chapter V

Chapter V governs transfers of personal data to third countries and international organisations. It seeks to prevent the protection guaranteed within the EEA from being undermined when personal data is transferred abroad.

The Commission’s review must pay particular attention to:

  • adequacy decisions adopted under Article 45(3) GDPR; and

  • older adequacy decisions adopted under Article 25(6) of Directive 95/46/EC.

An adequacy decision permits personal data to flow to a third country, territory, specified sector or international organisation without the exporter having to obtain a separate authorisation or rely on another Chapter V safeguard.

Because adequacy decisions can facilitate very large volumes of transfers, their continuing reliability is important. Changes in a third country’s laws, surveillance powers, access-to-remedy framework or enforcement practices may affect whether the country continues to provide an essentially equivalent level of protection.

Illustration

A third country may have had strong privacy safeguards when an adequacy decision was adopted. If it later expands governmental access to communications data without independent oversight or effective remedies, the Commission must consider whether the original adequacy assessment remains sustainable. Article 97 complements the review structure under Article 45. It reflects lessons from disputes concerning international transfer arrangements, including judicial scrutiny of whether third-country safeguards adequately protect rights under Articles 7, 8 and 47 of the EU Charter. The review should not be limited to the existence of written laws. It should consider how the system operates in practice, including:

  • effective enforcement;
  • judicial independence;
  • access by public authorities;
  • redress mechanisms;
  • developments in surveillance law;
  • obligations imposed on data importers.

9. 3.2 Article 97(2)(b): Cooperation and consistency under Chapter VII

Chapter VII establishes mechanisms intended to ensure consistent GDPR enforcement across the Union. Its provisions include:

  • mutual assistance between supervisory authorities;

  • joint operations;

  • cooperation in cross-border cases;

  • the one-stop-shop system;

  • the consistency mechanism;

  • dispute resolution by the EDPB.

This area is important because many organisations process personal data across several Member States. Without effective coordination, the same processing activity could be subject to inconsistent decisions or fragmented enforcement.

The Commission’s review should therefore consider whether the cooperation system produces:

  • timely investigations;

  • effective participation by concerned authorities;

  • consistent legal interpretation;

  • appropriate lead-authority allocation;

  • effective EDPB dispute resolution;

  • accessible remedies for data subjects.

Illustration

A platform has its main EU establishment in one Member State but millions of users across the Union. A complaint concerning the platform may involve one lead supervisory authority and several concerned authorities. Article 97 review should consider whether this system resolves the complaint efficiently and gives affected individuals meaningful protection. The review may also distinguish legal problems from resource problems. Delays may arise because a provision is unclear, but they may also result from inadequate staffing, differences in national administrative procedure, translation demands or highly complex investigations.


10. Article 97(3): Information from Member States and supervisory authorities

Article 97(3) permits the Commission to request information from:

  • Member States; and

  • supervisory authorities.

This provision enables evidence-based evaluation. The Commission is not expected to assess the GDPR only from public reports or its own institutional perspective.

Relevant information may include:

  • enforcement statistics;

  • complaint numbers;

  • investigation durations;

  • cross-border case experience;

  • administrative fine practices;

  • resource constraints;

  • international transfer developments;

  • difficulties applying particular provisions;

  • interaction between GDPR and national law.

The paragraph uses “may request”, giving the Commission discretion as to the nature and extent of the information sought. That discretion should be exercised consistently with the need for a comprehensive and reliable review.

Illustration

To assess Chapter VII, the Commission may ask supervisory authorities how many cross-border cases they handled, how long procedures took, what cooperation difficulties arose, and how often disagreements required EDPB resolution. Importantly, Article 97(3) concerns the Commission’s ability to gather information. The obligation to consider broader institutional positions appears separately in Article 97(4).


11. Article 97(4): Positions and findings to be considered

When carrying out its review, the Commission must consider the positions and findings of:

  • the European Parliament;

  • the Council;

  • other relevant bodies or sources.

“Other relevant bodies or sources” is deliberately broad. Depending on the issue, it may include:

  • the EDPB;

  • the EDPS;

  • the CJEU;

  • national courts;

  • supervisory authorities;

  • EU agencies;

  • academic research;

  • civil society findings;

  • industry evidence;

  • technical studies.

The Commission is not required to agree with every position. It must, however, consider relevant evidence rather than conduct the review in isolation.

Illustration

If the EDPB identifies recurring problems in applying the one-stop-shop mechanism, the Commission should take those findings into account even if Member States or industry participants present different views. This broad evidentiary base is particularly important because GDPR effectiveness cannot be measured solely through the number or size of fines. Relevant considerations also include preventive compliance, practical enjoyment of rights, consistency of interpretation, procedural speed, and the real protection provided to individuals.


12. Article 97(5): Proposals to amend the GDPR

Article 97(5) provides that the Commission shall submit appropriate proposals to amend the GDPR if necessary. Particular attention must be paid to:

  • developments in information technology; and

  • progress in the information society.

This paragraph does not require amendment after every review. It requires the Commission to consider whether amendment is necessary and, where it is, to make appropriate proposals.

Technological developments relevant to review may include:

  • artificial intelligence;

  • automated decision-making;

  • biometric identification;

  • large-scale behavioural profiling;

  • connected devices;

  • cloud infrastructure;

  • data brokerage;

  • privacy-enhancing technologies;

  • new forms of online tracking.

Illustration

If new technology permits detailed conclusions about individuals to be drawn from data previously regarded as low-risk or anonymous, the Commission may need to examine whether existing GDPR definitions, safeguards or enforcement mechanisms remain sufficient. Any amendment must still respect the GDPR’s fundamental objectives, including protection of natural persons, free movement of personal data, and the rights guaranteed by the EU Charter. Article 97(5) is therefore not merely a mechanism for reducing regulatory burdens. It can support stronger protection where new technologies create new risks.


13. Practical significance

Article 97 establishes an ongoing cycle:

  1. the GDPR is applied in practice;

  2. institutions and authorities collect experience;

  3. the Commission evaluates that experience;

  4. findings are reported publicly;

  5. Parliament, Council and stakeholders scrutinise the report;

  6. legislative proposals may follow where necessary.

The Article therefore helps prevent the GDPR from becoming disconnected from technological and institutional reality. At the same time, it preserves legislative stability by requiring periodic, evidence-based review rather than continuous informal alteration.

Key takeaways

  • Article 97 imposes a mandatory four-year reporting cycle on the Commission.

  • Reports must be submitted to Parliament and Council and made public.

  • Chapter V international transfers and Chapter VII cooperation are mandatory areas of review.

  • Both GDPR-era and certain pre-GDPR adequacy decisions must be examined.

  • The Commission may request evidence from Member States and supervisory authorities.

  • It must consider findings from Parliament, Council and other relevant sources.

  • Where review shows that reform is necessary, the Commission must submit appropriate proposals.

  • Technological and information-society developments are expressly relevant to possible amendment.

Article 97 is consequently the GDPR’s built-in mechanism for periodic institutional review, public accountability and evidence-based legislative adaptation.