Law / European Union

European Patent Organisation Adequacy Decision, Commission Implementing Decision (EU) 2025/1382

Commission Implementing Decision (EU) 2025/1382

In force since .

A cross border transfer rule binding public and private bodies.

Criminal exposure
No
Private right of action
No
Obligation class
Transfer
Audit expectation
periodic
Who audits it
Regulator

As of .

What it requires

  • A transfer of personal data from the Union to the European Patent Organisation may take place on the basis of Article 1 of the Decision, without any specific authorization (Article 45(1) of Regulation (EU) 2016/679).

Who enforces it

Enforcement body

The competent authorities of the Member States, which exercise their powers under Article 58 of Regulation (EU) 2016/679 over transfers within the scope of Article 1 and inform the Commission (Article 2), and the Commission, which monitors the application of the Organisation's legal framework and may suspend, repeal or amend the Decision (Article 3).

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Article 1 provides that, for the purpose of Article 45 of Regulation (EU) 2016/679, the European Patent Organisation ensures an adequate level of protection for personal data transferred from the Union to the European Patent Organisation. Recital 6 states that transfers from controllers and processors in the Union to the European Patent Organisation may take place without the need to obtain any further authorization.

Recital 6 adds that the Decision does not affect the direct application of Regulation (EU) 2016/679 to such entities where the conditions regarding the territorial scope laid down in Article 3 of that Regulation are fulfilled. Recital 14 identifies the Data Protection Rules adopted by the Administrative Council of the Organisation as the rules that regulate the processing of personal data by the European Patent Office.

Article 2 requires a Member State whose competent authorities exercise their powers under Article 58 of Regulation (EU) 2016/679 over data transfers within the scope of Article 1 to inform the Commission without delay. Article 3(3) requires the Commission, at least every four years, to evaluate the finding in Article 1 on the basis of all available information, including the information received as part of a review carried out together with the European Patent Organisation.

Article 3(4) provides that, where the Commission has indications that an adequate level of protection is no longer ensured, it informs the Organisation and, if necessary, may decide to suspend, amend or repeal the Decision, or limit its scope, in accordance with Article 45(5) of Regulation (EU) 2016/679. Article 4 provides that the Decision is addressed to the Member States.

When LexLint raises it

When your app profile says your app crawls the web, trains models, deploys a chatbot, sends automated outreach, processes voice recordings or processes biometric data.

Back to the example  ·  Lint your app