Call us on +(33)4 28 70 91 81

Article 66 of the GDPR: Emergency procedure

Article 66 of the GDPR: Emergency procedure

Article 66 of the GDPR allows a supervisory authority to take urgent interim measures in the event of a serious risk to the rights and freedoms of individuals. This is a exceptional device, activated when waiting for European cooperation could compromise data protection.

Article 66 of the GDPR explained

A supervisory authority may, exceptionally:

  • Intervene immediately to prohibit treatment or suspend an operation;
  • Take provisional measures valid for a maximum of 3 months;
  • Inform other relevant authorities and the European Data Protection Board (EDPS) without delay;
  • At the same time, request a binding decision from the EDPS via Article 65.

This mechanism guarantees rapid response in the event of an imminent threat for fundamental rights.

Why is this article important for your GDPR compliance?

It shows that even without a complete cross-border procedure, an authority can act alone if the emergency justifies it. This requires data controllers to respond immediately to any urgent request, under penalty of sanctions.

How to comply with Article 66 of the GDPR?

  • Make one continuous monitoring of risky treatments (profiling, sensitive data, minors);
  • Integrate an internal alert and rapid response procedure;
  • Cooperate promptly with authorities in the event of emergency notification;
  • Update your documentation to warrant any prompt corrective action.

Examples of application of Article 66 of the GDPR

  • The CNIL temporarily suspends biometric processing without sufficient legal basis;
  • German authority blocks transfer of sensitive data to third country pending EDPS opinion;
  • Urgent measures are imposed on a mobile application using real-time geolocation data.

Related Resources

Accelerate your compliance in just a few clicks

With our all-in-one solution, you can accelerate and ensure compliance easily:

  • Automate your compliance with our GDPR software
  • Supported or outsourced by our DPO experts
  • Raise awareness among your teams with our GDPR training e-learning

Request a demo with an expert

Assess your situation in 15 minutes with our free, no-obligation GDPR self-diagnosis.

GDPR: Self-assess now