Article 97 creates a formal system for the periodic evaluation of the GDPR by the European Commission. It recognises that data protection law operates in a rapidly changing technological, commercial and regulatory environment. The GDPR cannot be treated as legislation whose effectiveness is assessed only when a serious problem arises. The Commission must examine its operation at regular intervals, publish its conclusions, and consider whether amendments are necessary.
Unlike many GDPR provisions, Article 97 does not directly regulate controllers, processors or data subjects. It imposes obligations primarily on the European Commission. Nevertheless, its operation can affect all participants in the GDPR system because Commission reports may identify enforcement difficulties, inconsistencies between Member States, shortcomings in international transfer mechanisms, or areas requiring legislative reform.
Article 97 contains no specifically assigned recital. Its purpose must therefore be understood from its wording, the GDPR’s wider objectives, and the provisions that it expressly requires the Commission to examine. It is particularly connected with:
-
Chapter V, concerning transfers to third countries and international organisations;
-
Article 45, concerning adequacy decisions;
-
Chapter VII, concerning cooperation and consistency;
-
Articles 60 to 67, which establish cooperation between supervisory authorities and the consistency mechanism;
-
Article 70, concerning the functions of the European Data Protection Board;
-
the Commission’s power to propose EU legislation under the Treaties.