A rigorous examination of the constitutional governance provisions that enable GDPR implementation to evolve — and their profound indirect implications for firms, banks, and advanced compliance programmes.
Article 92 establishes the legal framework under which the European Commission may exercise delegated powers granted elsewhere in the GDPR. Delegated powers permit the Commission to supplement or amend certain non-essential elements of GDPR implementation without requiring a complete legislative revision by the European Parliament and the Council.
Defines the temporal scope of delegated authority granted to the Commission under GDPR provisions.
The European Parliament and Council retain the ability to revoke delegation at any time.
Formal procedures exist through which institutions may raise objections to proposed delegated acts.
Conditions under which delegated acts formally enter into force and become binding obligations.
The article reflects the constitutional principle of accountability within EU legislative governance, creating a mechanism for regulatory evolution whilst preserving democratic oversight by EU institutions.
Article 92 is fundamentally a regulatory-change-management provision. It enables future GDPR implementation details to evolve. Organisations cannot assume that GDPR obligations remain static — compliance programmes must therefore be dynamic rather than point-in-time exercises.
Organisations must continuously monitor:
Banks operate in heavily regulated environments where GDPR intersects with multiple frameworks simultaneously:
Any delegated act affecting certification mechanisms, data transfer requirements, security expectations, processor obligations, or consent standards could require substantial changes to banking processes.
Article 93 establishes the formal committee procedure through which the Commission adopts implementing acts under GDPR. It creates the administrative mechanism that supports consistent implementation of GDPR across EU Member States, aiming to prevent fragmented regulatory approaches.
The Commission is assisted by a formally constituted committee with defined membership and mandate.
The committee operates under Regulation (EU) No. 182/2011 governing comitology procedures.
The committee uses the examination procedure as its primary decision-making mechanism.
Emergency procedures may be invoked where necessary to address urgent regulatory requirements.
Article 93 supports harmonisation of standard forms, certification frameworks, technical standards, and administrative procedures across all EU Member States — a critical function for multinational organisations.
Organisations should view Article 93 as the source of future implementing requirements. Implementing acts may introduce entirely new obligations across multiple dimensions:
Enhanced or standardised reporting obligations to supervisory authorities.
Formalised certification schemes with defined criteria and audit requirements.
Standardised administrative procedures for data subject rights and breach notification.
Harmonised standards for supervisory authority engagement and enforcement.
Banks face elevated exposure because they process high volumes of personal data, conduct international transfers, depend on complex outsourcing chains, and operate under multiple regulatory frameworks simultaneously.
As implementing acts evolve, the following may require modification:
Advanced practitioners frequently underestimate these provisions. Their significance lies in regulatory adaptability — they create the machinery through which GDPR evolves.
Failure to monitor delegated and implementing act developments may result in inadvertent non-compliance with evolved obligations.
Static policy frameworks become deficient as implementing acts introduce new procedural and substantive requirements.
Technical safeguards may fail to meet evolved security expectations introduced through delegated acts.
Processor agreements and data transfer mechanisms may become non-compliant as implementing acts evolve.
Compliance audits may identify gaps where organisations have not tracked regulatory evolution under Articles 92 and 93.
Supervisory authorities may take enforcement action where organisations demonstrate inadequate regulatory horizon-scanning.
The following GDPR provisions are most likely to be affected by future delegated or implementing acts. Advanced compliance programmes must maintain active monitoring across all of these intersections.

This breadth of intersection underscores why Articles 92 and 93 carry such significant indirect compliance weight — virtually every substantive area of GDPR may be subject to future refinement through the mechanisms they establish.
Advanced organisations should implement the following governance processes to ensure continuous alignment with developments arising from Articles 92 and 93.
Proactive monitoring of EU legislative and regulatory developments before they become binding obligations.
Dedicated programme tracking delegated acts, implementing acts, and EDPB guidance in real time.
Formal oversight body with quarterly review cycle and board-level reporting accountability.
Structured methodology for assessing the operational impact of new delegated or implementing acts.
Systematic programme ensuring policies are reviewed, updated, and approved in response to regulatory change.
Comprehensive annual review of the entire GDPR compliance framework against current regulatory requirements.
Ongoing review of international transfer mechanisms, SCCs, and transfer impact assessments.
Active management of GDPR certifications and assurance attestations as certification frameworks evolve.
Structured process for engaging with national supervisory authorities and monitoring their interpretations.
Centralised programme ensuring audit evidence is retained and accessible to demonstrate ongoing compliance.
Systematic review and interpretation of EDPB guidance documents and their operational implications.
Formal process for interpreting regulatory developments and translating them into actionable compliance requirements.
Monitoring of regulatory developments affecting processors, sub-processors, and outsourcing partners.
Regular testing programme validating that technical and organisational controls remain effective and current.
Structured methodology for assessing privacy risks arising from regulatory change and operational developments.
Regular reporting to board and senior management on GDPR compliance status and regulatory developments.
Formal process for identifying, escalating, and remediating compliance exceptions and control gaps.
Maintained inventory of all applicable GDPR obligations, mapped to controls and evidence.
Comprehensive governance programme covering all data processing activities and their legal bases.
Structured oversight of all processors and sub-processors, including regular due diligence reviews.
The following controls provide strong assurance that an organisation remains compliant not only with Articles 92 and 93 but also with the broader GDPR framework they influence.
Automated monitoring of EU legislative developments, tracking of delegated acts and implementing acts.
Formal oversight body with quarterly review cycle and defined escalation pathways.
Identification → Assessment → Approval → Implementation → Validation.
Mapping GDPR obligations to controls with full traceability maintenance.
Dynamic Article 30 record maintenance with automated update triggers.
Automated DPIA triggering and risk scoring aligned to evolving regulatory expectations.
Sensitivity-based classification with special-category identification and automated tagging.
Mandatory design reviews and architectural privacy checkpoints embedded in development lifecycles.
Technical safeguards aligned to Article 32 and evolving implementing act security expectations.
Encryption at rest, in transit, and comprehensive key management oversight.
Role-based access control with segregation of duties enforced across all systems.
Enhanced monitoring of administrative accounts with real-time alerting capabilities.
Automated control validation and compliance dashboards providing real-time assurance.
Vendor privacy assessments and processor due diligence aligned to Article 28 requirements.
Centralised audit evidence storage with version control and access management.
Monitoring of transfer mechanisms, SCC management, and transfer impact assessments.
Integrated breach detection with defined escalation procedures and regulatory notification workflows.
Management of GDPR certifications and control attestations as certification frameworks evolve.
Policy-driven deletion with automated enforcement ensuring data is not retained beyond lawful periods.
Internal audit, external audit, and continuous assurance reviews providing independent validation of the entire control environment — the ultimate demonstration of governance maturity under Articles 92 and 93.
Banks should additionally implement the following controls beyond the standard organisational baseline:
Privacy integration into operational risk frameworks and enterprise risk management.
Comprehensive data lineage mapping across all banking systems and data flows.
Dedicated privacy controls for AML and fraud-monitoring systems addressing the GDPR/financial crime tension.
Privacy governance framework specifically designed for open banking APIs and PSD2 obligations.
Cloud privacy assurance reviews and data sovereignty monitoring for cloud-hosted banking systems.
Privacy reviews embedded within AI and model-governance frameworks for algorithmic decision-making.
Formal procedures for resolving conflicts between financial crime obligations and GDPR requirements.
Elevated governance for cross-border transfers given the international nature of banking operations.
Articles 92 and 93 are not operational privacy requirements in themselves. They are constitutional governance provisions within the GDPR framework. Their practical importance arises because they enable GDPR implementation to evolve over time.
Mature organisations therefore focus less on the text of Articles 92 and 93 and more on the governance capability required to:
The material within this site is provided for general guidance only and does not constitute legal, regulatory, or professional advice. Datari accepts no liability for any actions taken or not taken based on this content. Organisations should seek their own independent advice before making decisions.
GDPR Articles 92 and 93