My bookmarksSign up free

Commission Implementing Regulation (EU) 2025/486 CHAPTER V — Data protection

Article 28 · 1 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Personal data protection

Article 28

1.   The personal data specified in this Regulation and registered in the CBAM registry, established in accordance with Article 14(6) of Regulation (EU) 2023/956, shall be processed for the purposes of measures related to the granting and revocation of the status of authorised CBAM declarant. 2.   In relation to the processing of personal data referred to in paragraph 1 of this Article, the competent authority granting or revoking the status of authorised CBAM declarant shall be regarded as controller within the meaning of Article 4(7) of Regulation (EU) 2016/679. 3.   No special categories of data, as defined in Article 9 of Regulation (EU) 2016/679 and Article 10 of Regulation (EU) 2018/1725, shall be recorded for the purpose of applying for and granting of the status of authorised CBAM declarant.

Back to Commission Implementing Regulation (EU) 2025/486 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next