Source: OJ L 265, 12.10.2022, pp. 1–66Consolidated text

Current language: SV

Artikel 15 Skyldighet att genomföra en revision


Summary What does Article 15 of the DMA regulation say?

This article establishes a transparency obligation for gatekeepers regarding their consumer profiling practices.

Building directly on the designation process in Article 3, it requires gatekeepers to formally disclose and subject to independent audit any profiling techniques they use across their core platform services.

The audited findings are then shared with the European Data Protection Board, creating a clear link between this Regulation and the EU's data protection oversight framework.

Important points:

  • Submit an independently audited description of all consumer profiling techniques used across your core platform services to the Commission within 6 months of designation.
  • The Commission shall transmit the audited description to the European Data Protection Board, connecting this obligation to the broader data protection regulatory landscape.
  • Make a public overview of the audited description available, and update both the description and the overview at least annually — though business secrets may be taken into account when doing so.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Inom sex månader efter att ha betecknats som grindvakt i enlighet med artikel 3 ska grindvakten till kommissionen lämna in en beskrivning, granskad genom en oberoende revision, av alla eventuella tekniker för profilering av konsumenter som grindvakten tillämpar på eller använder på sina centrala plattformstjänster som förtecknas i beslutet om betecknande i enlighet med artikel 3.9. Kommissionen ska översända den reviderade beskrivningen till Europeiska dataskyddsstyrelsen.

    1. Kommissionen får anta en genomförandeakt som avses i artikel 46.1 g för att utarbeta metoden och förfarandet för revisionen.

    1. Grindvakten ska offentliggöra en översikt över den reviderade beskrivning som avses i punkt 1. Grindvakten ska därvid ha rätt att beakta behovet av att skydda sina affärshemligheter. Grindvakten ska uppdatera beskrivningen och översikten åtminstone en gång om året.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod