Article 98 GDPR requires the European Commission to consider whether other European Union legal instruments dealing with personal data should be amended so that individuals receive uniform and consistent protection across the EU legal order. The provision addresses a structural problem: the GDPR is the general EU framework for personal data protection, but it is not the only EU instrument governing the processing of personal data.
Numerous EU legislative acts contain sector-specific data protection rules. These may concern EU institutions, financial regulation, criminal justice, law enforcement, border control, migration, telecommunications, healthcare, transport, anti-money laundering, or cooperation through EU agencies. If those rules use different concepts, provide weaker safeguards, or conflict with the GDPR’s principles, the overall EU data protection framework can become fragmented.
Article 98 therefore gives the Commission a legislative-review function. Where appropriate, the Commission must propose amendments to other EU acts so that they operate consistently with the GDPR.
The provision is particularly connected with:
-
Article 2(3) GDPR, concerning processing by EU institutions, bodies, offices and agencies;
-
Recital 17 GDPR, concerning the adaptation of Regulation (EC) No 45/2001;
-
Article 95 and Recital 173 GDPR, concerning the relationship with the ePrivacy Directive;
-
Article 97 GDPR, concerning periodic review of the GDPR itself;
-
the principles in Article 5 GDPR;
-
the fundamental rights guaranteed by Articles 7, 8 and 47 of the Charter of Fundamental Rights of the European Union.