GDPR Articles 92 and 93

A rigorous examination of the constitutional governance provisions that enable GDPR implementation to evolve — and their profound indirect implications for firms, banks, and advanced compliance programmes.

Article 92 – Exercise of the Delegation

Article 92 establishes the legal framework under which the European Commission may exercise delegated powers granted elsewhere in the GDPR. Delegated powers permit the Commission to supplement or amend certain non-essential elements of GDPR implementation without requiring a complete legislative revision by the European Parliament and the Council.

1

Duration of Authority

Defines the temporal scope of delegated authority granted to the Commission under GDPR provisions.

2

Revocation Rights

The European Parliament and Council retain the ability to revoke delegation at any time.

3

Objection Procedures

Formal procedures exist through which institutions may raise objections to proposed delegated acts.

4

Entry into Force

Conditions under which delegated acts formally enter into force and become binding obligations.

The article reflects the constitutional principle of accountability within EU legislative governance, creating a mechanism for regulatory evolution whilst preserving democratic oversight by EU institutions.

Practical Meaning of Article 92

Regulatory Change Management

Article 92 is fundamentally a regulatory-change-management provision. It enables future GDPR implementation details to evolve. Organisations cannot assume that GDPR obligations remain static — compliance programmes must therefore be dynamic rather than point-in-time exercises.

Organisations must continuously monitor:

  • European Commission delegated acts
  • European Data Protection Board (EDPB) guidance
  • National supervisory authority interpretations
  • Relevant CJEU decisions

Banking Sector Implications

Banks operate in heavily regulated environments where GDPR intersects with multiple frameworks simultaneously:

AML/KYC

Payment Services

Open Banking

Cloud Outsourcing

Digital Identity

Financial Crime

Any delegated act affecting certification mechanisms, data transfer requirements, security expectations, processor obligations, or consent standards could require substantial changes to banking processes.

Article 93 – Committee Procedure

Article 93 establishes the formal committee procedure through which the Commission adopts implementing acts under GDPR. It creates the administrative mechanism that supports consistent implementation of GDPR across EU Member States, aiming to prevent fragmented regulatory approaches.

1

Commission Assisted

The Commission is assisted by a formally constituted committee with defined membership and mandate.

2

Regulation 182/2011

The committee operates under Regulation (EU) No. 182/2011 governing comitology procedures.

3

Examination Procedure

The committee uses the examination procedure as its primary decision-making mechanism.

4

Emergency Procedures

Emergency procedures may be invoked where necessary to address urgent regulatory requirements.

Article 93 supports harmonisation of standard forms, certification frameworks, technical standards, and administrative procedures across all EU Member States — a critical function for multinational organisations.

Implications for Firms and the Banking Sector

Implications for All Organisations

Organisations should view Article 93 as the source of future implementing requirements. Implementing acts may introduce entirely new obligations across multiple dimensions:

New Reporting Expectations

Enhanced or standardised reporting obligations to supervisory authorities.

New Certification Mechanisms

Formalised certification schemes with defined criteria and audit requirements.

New Procedural Requirements

Standardised administrative procedures for data subject rights and breach notification.

New Supervisory Standards

Harmonised standards for supervisory authority engagement and enforcement.

Elevated Banking Sector Exposure

Banks face elevated exposure because they process high volumes of personal data, conduct international transfers, depend on complex outsourcing chains, and operate under multiple regulatory frameworks simultaneously.

As implementing acts evolve, the following may require modification:

  • Data governance programmes
  • Risk management frameworks
  • Internal control environments
  • Regulatory reporting procedures

Why Articles 92 and 93 Matter Despite Creating No Direct Obligations

Advanced practitioners frequently underestimate these provisions. Their significance lies in regulatory adaptability — they create the machinery through which GDPR evolves.

Regulatory Non-Compliance

Failure to monitor delegated and implementing act developments may result in inadvertent non-compliance with evolved obligations.

Outdated Policies

Static policy frameworks become deficient as implementing acts introduce new procedural and substantive requirements.

Deficient Technical Controls

Technical safeguards may fail to meet evolved security expectations introduced through delegated acts.

Inadequate Contractual Provisions

Processor agreements and data transfer mechanisms may become non-compliant as implementing acts evolve.

Failed Audits

Compliance audits may identify gaps where organisations have not tracked regulatory evolution under Articles 92 and 93.

Increased Enforcement Exposure

Supervisory authorities may take enforcement action where organisations demonstrate inadequate regulatory horizon-scanning.

GDPR Articles Most Closely Intersecting with Articles 92 and 93

The following GDPR provisions are most likely to be affected by future delegated or implementing acts. Advanced compliance programmes must maintain active monitoring across all of these intersections.

This breadth of intersection underscores why Articles 92 and 93 carry such significant indirect compliance weight — virtually every substantive area of GDPR may be subject to future refinement through the mechanisms they establish.

Organisational Processes Required for Compliance

Advanced organisations should implement the following governance processes to ensure continuous alignment with developments arising from Articles 92 and 93.

01

Regulatory Horizon-Scanning

Proactive monitoring of EU legislative and regulatory developments before they become binding obligations.

02

GDPR Legislative Watch Programme

Dedicated programme tracking delegated acts, implementing acts, and EDPB guidance in real time.

03

Privacy Governance Committee

Formal oversight body with quarterly review cycle and board-level reporting accountability.

04

Regulatory Change Impact Assessment

Structured methodology for assessing the operational impact of new delegated or implementing acts.

05

Policy Lifecycle Management

Systematic programme ensuring policies are reviewed, updated, and approved in response to regulatory change.

06

Annual GDPR Framework Review

Comprehensive annual review of the entire GDPR compliance framework against current regulatory requirements.

07

Cross-Border Transfer Review

Ongoing review of international transfer mechanisms, SCCs, and transfer impact assessments.

08

Certification Management Process

Active management of GDPR certifications and assurance attestations as certification frameworks evolve.

09

Supervisory Authority Engagement

Structured process for engaging with national supervisory authorities and monitoring their interpretations.

10

Compliance Evidence Retention

Centralised programme ensuring audit evidence is retained and accessible to demonstrate ongoing compliance.

01

EDPB Guidance Review Process

Systematic review and interpretation of EDPB guidance documents and their operational implications.

02

Regulatory Interpretation Management

Formal process for interpreting regulatory developments and translating them into actionable compliance requirements.

03

Third-Party Regulatory Monitoring

Monitoring of regulatory developments affecting processors, sub-processors, and outsourcing partners.

04

Data Protection Control Testing

Regular testing programme validating that technical and organisational controls remain effective and current.

05

Privacy Risk Assessment Methodology

Structured methodology for assessing privacy risks arising from regulatory change and operational developments.

06

Board-Level Privacy Reporting

Regular reporting to board and senior management on GDPR compliance status and regulatory developments.

07

Compliance Exception Management

Formal process for identifying, escalating, and remediating compliance exceptions and control gaps.

08

Regulatory Inventory Maintenance

Maintained inventory of all applicable GDPR obligations, mapped to controls and evidence.

09

Data Processing Governance Programme

Comprehensive governance programme covering all data processing activities and their legal bases.

10

Processor Oversight Programme

Structured oversight of all processors and sub-processors, including regular due diligence reviews.

Twenty Cross-Cutting Technical and Organisational Controls

The following controls provide strong assurance that an organisation remains compliant not only with Articles 92 and 93 but also with the broader GDPR framework they influence.

1

Regulatory Intelligence Platform

Automated monitoring of EU legislative developments, tracking of delegated acts and implementing acts.

2

Privacy Governance Committee

Formal oversight body with quarterly review cycle and defined escalation pathways.

3

Regulatory Change Management Workflow

Identification → Assessment → Approval → Implementation → Validation.

4

Legal Obligation Inventory

Mapping GDPR obligations to controls with full traceability maintenance.

5

Data Processing Register Automation

Dynamic Article 30 record maintenance with automated update triggers.

6

DPIA Framework

Automated DPIA triggering and risk scoring aligned to evolving regulatory expectations.

1

Data Classification Programme

Sensitivity-based classification with special-category identification and automated tagging.

2

Privacy-by-Design Control Framework

Mandatory design reviews and architectural privacy checkpoints embedded in development lifecycles.

3

Security Control Baseline

Technical safeguards aligned to Article 32 and evolving implementing act security expectations.

4

Encryption Governance

Encryption at rest, in transit, and comprehensive key management oversight.

5

Identity and Access Management

Role-based access control with segregation of duties enforced across all systems.

6

Privileged Access Monitoring

Enhanced monitoring of administrative accounts with real-time alerting capabilities.

1

Continuous Compliance Monitoring

Automated control validation and compliance dashboards providing real-time assurance.

2

Third-Party Risk Management

Vendor privacy assessments and processor due diligence aligned to Article 28 requirements.

3

Regulatory Evidence Repository

Centralised audit evidence storage with version control and access management.

4

Data Transfer Governance

Monitoring of transfer mechanisms, SCC management, and transfer impact assessments.

5

Privacy Incident Management

Integrated breach detection with defined escalation procedures and regulatory notification workflows.

6

Certification and Assurance Management

Management of GDPR certifications and control attestations as certification frameworks evolve.

Data Retention and Disposal Control

Policy-driven deletion with automated enforcement ensuring data is not retained beyond lawful periods.

Independent Privacy Assurance Programme

Internal audit, external audit, and continuous assurance reviews providing independent validation of the entire control environment — the ultimate demonstration of governance maturity under Articles 92 and 93.

Banking-Specific Control Enhancements & Key Teaching Point

Banking-Specific Control Enhancements

Banks should additionally implement the following controls beyond the standard organisational baseline:

Operational Risk Integration

Privacy integration into operational risk frameworks and enterprise risk management.

Data Lineage Mapping

Comprehensive data lineage mapping across all banking systems and data flows.

AML and Fraud-Monitoring Privacy Controls

Dedicated privacy controls for AML and fraud-monitoring systems addressing the GDPR/financial crime tension.

Open Banking API Governance

Privacy governance framework specifically designed for open banking APIs and PSD2 obligations.

Cloud Privacy Assurance

Cloud privacy assurance reviews and data sovereignty monitoring for cloud-hosted banking systems.

AI and Model Governance

Privacy reviews embedded within AI and model-governance frameworks for algorithmic decision-making.

Financial Crime Conflict Resolution

Formal procedures for resolving conflicts between financial crime obligations and GDPR requirements.

Enhanced Cross-Border Transfer Governance

Elevated governance for cross-border transfers given the international nature of banking operations.

Key Teaching Point for Advanced Practitioners

Articles 92 and 93 are not operational privacy requirements in themselves. They are constitutional governance provisions within the GDPR framework. Their practical importance arises because they enable GDPR implementation to evolve over time.

Mature organisations therefore focus less on the text of Articles 92 and 93 and more on the governance capability required to:

Detect

Interpret

Assess

Implement

Evidence

Monitor

Datari Home

The material within this site is provided for general guidance only and does not constitute legal, regulatory, or professional advice. Datari accepts no liability for any actions taken or not taken based on this content. Organisations should seek their own independent advice before making decisions.