Source: OJ L 265, 12.10.2022, pp. 1–66Consolidated text

Current language: FR

Article 15 Obligation d’audit


Summary What does Article 15 of the DMA regulation say?

This article establishes a transparency obligation for gatekeepers regarding their consumer profiling practices.

Building directly on the designation process in Article 3, it requires gatekeepers to formally disclose and subject to independent audit any profiling techniques they use across their core platform services.

The audited findings are then shared with the European Data Protection Board, creating a clear link between this Regulation and the EU's data protection oversight framework.

Important points:

  • Submit an independently audited description of all consumer profiling techniques used across your core platform services to the Commission within 6 months of designation.
  • The Commission shall transmit the audited description to the European Data Protection Board, connecting this obligation to the broader data protection regulatory landscape.
  • Make a public overview of the audited description available, and update both the description and the overview at least annually — though business secrets may be taken into account when doing so.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Dans les six mois suivant sa désignation conformément à l’article 3, le contrôleur d’accès soumet à la Commission une description ayant fait l’objet d’un audit indépendant de toutes les techniques de profilage des consommateurs qu’il applique dans le cadre de ses services de plateforme essentiels énumérés dans la décision de désignation conformément à l’article 3, paragraphe 9. La Commission transmet cette description ayant fait l’objet d’un audit au comité européen de la protection des données.

    1. La Commission peut adopter un acte d’exécution visé à l’article 46, paragraphe 1, point g), afin de mettre au point la méthodologie et la procédure de l’audit.

    1. Le contrôleur d’accès met à la disposition du public un aperçu de la description ayant fait l’objet d’un audit visée au paragraphe 1. Ce faisant, le contrôleur d’accès est autorisé à tenir compte de la nécessité que ses secrets d’affaires ne soient pas divulgués. Le contrôleur d’accès met à jour au moins annuellement cette description et cet aperçu.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod