European Commission proposes GDPR amendments extending SME relief measures to small mid-caps
Original title: Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL amending Regulations (EU) 2016/679, (EU) 2016/1036, (EU) 2016/1037, (EU) 2017/1129, (EU) 2023/1542 and (EU) 2024/573 as regards
The European Commission proposes amendments to GDPR and five other EU regulations to expand eligibility for existing SME relief measures to small mid-cap enterprises. The proposal aims to reduce the compliance burden for smaller organizations while maintaining data protection standards. This expansion recognizes that small mid-cap companies face similar resource constraints as SMEs in implementing comprehensive data protection frameworks.
What changed
- Extension of existing SME exemptions and mitigating measures under GDPR to small mid-cap enterprises, broadening the scope of organizations eligible for relief provisions
- Further simplification measures integrated across amended regulations to reduce administrative and compliance requirements for affected entities
- Amendments to Regulations (EU) 2016/1036, 2016/1037, 2017/1129, 2023/1542 and 2024/573 to align relief measures across EU regulatory framework
Who is affected
Small and medium-sized enterprises (SMEs) and newly covered small mid-cap enterprises operating in the EU. Affects organizations across all sectors subject to GDPR and related EU regulations.
Summary generated by a language model; the official text prevails. Not legal advice.