Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: EN

Article 24 Responsibility of the controller


Summary What does Article 24 of the GDPR regulation say?

This article establishes the overarching accountability obligation for controllers under the GDPR.

It requires controllers to not only comply with the regulation but to be able to actively demonstrate that compliance through appropriate technical and organisational measures.

The article is a cornerstone of the accountability principle introduced by the GDPR, and it connects directly to other articles in the regulation, such as Article 40 on codes of conduct and Article 42 on certification mechanisms, which can serve as tools to evidence compliance.

Important points:

  • Implement appropriate technical and organisational measures to ensure processing complies with the regulation, and review and update those measures where necessary.
  • Where proportionate, those measures must include the implementation of data protection policies.
  • Adherence to approved codes of conduct (Article 40) or approved certification mechanisms (Article 42) can be used as a means of demonstrating compliance.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. Those measures shall be reviewed and updated where necessary.

    1. Where proportionate in relation to processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller.

    1. Adherence to approved codes of conduct as referred to in Article 40 or approved certification mechanisms as referred to in Article 42 may be used as an element by which to demonstrate compliance with the obligations of the controller.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod