Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: DE

Artikel 24 Verantwortung des für die Verarbeitung Verantwortlichen


Summary What does Article 24 of the GDPR regulation say?

This article establishes the overarching accountability obligation for controllers under the GDPR.

It requires controllers to not only comply with the regulation but to be able to actively demonstrate that compliance through appropriate technical and organisational measures.

The article is a cornerstone of the accountability principle introduced by the GDPR, and it connects directly to other articles in the regulation, such as Article 40 on codes of conduct and Article 42 on certification mechanisms, which can serve as tools to evidence compliance.

Important points:

  • Implement appropriate technical and organisational measures to ensure processing complies with the regulation, and review and update those measures where necessary.
  • Where proportionate, those measures must include the implementation of data protection policies.
  • Adherence to approved codes of conduct (Article 40) or approved certification mechanisms (Article 42) can be used as a means of demonstrating compliance.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Der Verantwortliche setzt unter Berücksichtigung der Art, des Umfangs, der Umstände und der Zwecke der Verarbeitung sowie der unterschiedlichen Eintrittswahrscheinlichkeit und Schwere der Risiken für die Rechte und Freiheiten natürlicher Personen geeignete technische und organisatorische Maßnahmen um, um sicherzustellen und den Nachweis dafür erbringen zu können, dass die Verarbeitung gemäß dieser Verordnung erfolgt. Diese Maßnahmen werden erforderlichenfalls überprüft und aktualisiert.

    1. Sofern dies in einem angemessenen Verhältnis zu den Verarbeitungstätigkeiten steht, müssen die Maßnahmen gemäß Absatz 1 die Anwendung geeigneter Datenschutzvorkehrungen durch den Verantwortlichen umfassen.

    1. Die Einhaltung der genehmigten Verhaltensregeln gemäß Artikel 40 oder eines genehmigten Zertifizierungsverfahrens gemäß Artikel 42 kann als Gesichtspunkt herangezogen werden, um die Erfüllung der Pflichten des Verantwortlichen nachzuweisen.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod