Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: EN
- General data protection
Basic legislative acts
- GDPR regulation
Article 24 Responsibility of the controller
Summary What does Article 24 of the GDPR regulation say?
This article establishes the overarching accountability obligation for controllers under the GDPR.
It requires controllers to not only comply with the regulation but to be able to actively demonstrate that compliance through appropriate technical and organisational measures.
The article is a cornerstone of the accountability principle introduced by the GDPR, and it connects directly to other articles in the regulation, such as Article 40 on codes of conduct and Article 42 on certification mechanisms, which can serve as tools to evidence compliance.
Important points:
- Implement appropriate technical and organisational measures to ensure processing complies with the regulation, and review and update those measures where necessary.
- Where proportionate, those measures must include the implementation of data protection policies.
- Adherence to approved codes of conduct (Article 40) or approved certification mechanisms (Article 42) can be used as a means of demonstrating compliance.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. Those measures shall be reviewed and updated where necessary.
Where proportionate in relation to processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller.
Adherence to approved codes of conduct as referred to in Article 40 or approved certification mechanisms as referred to in Article 42 may be used as an element by which to demonstrate compliance with the obligations of the controller.
Relevant recitals
Recital 74 Controller's responsibility and liability
The responsibility and liability of the controller for any processing of personal data carried out by the controller or on the controller's behalf should be established. In particular, the controller should be obliged to implement appropriate and effective measures and be able to demonstrate the compliance of processing activities with this Regulation, including the effectiveness of the measures. Those measures should take into account the nature, scope, context and purposes of the processing and the risk to the rights and freedoms of natural persons.
Recital 77 Guidance on demonstrating compliance
Guidance on the implementation of appropriate measures and on the demonstration of compliance by the controller or the processor, especially as regards the identification of the risk related to the processing, their assessment in terms of origin, nature, likelihood and severity, and the identification of best practices to mitigate the risk, could be provided in particular by means of approved codes of conduct, approved certifications, guidelines provided by the Board or indications provided by a data protection officer. The Board may also issue guidelines on processing operations that are considered to be unlikely to result in a high risk to the rights and freedoms of natural persons and indicate what measures may be sufficient in such cases to address such risk.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
processing
Definition
controller
Definition
processor
Definition
personal data