Home > Chapter 4 - Controller and processor > Art. 24 GDPR – Responsibility of the controller

Art. 24 GDPR – Responsibility of the controller

  1. 1Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. 2Those measures shall be reviewed and updated where necessary.
  2. Where proportionate in relation to processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller.
  3. Adherence to approved codes of conduct as referred to in Article 40 or approved certification mechanisms as referred to in Article 42 may be used as an element by which to demonstrate compliance with the obligations of the controller.

Frequently Asked Questions about Article 24

+ What are the responsibilities of a data controller under the GDPR?
Article 24 requires controllers to implement appropriate technical and organisational measures to ensure and demonstrate that processing complies with the GDPR, taking account of risks to individuals.
+How does a controller demonstrate GDPR compliance?
Controllers demonstrate compliance through documented policies, data protection measures, records, and where proportionate, adherence to approved codes of conduct or certification schemes.
+ What is the accountability obligation for controllers?
Accountability means controllers must not only comply with the GDPR but also be able to prove it through appropriate measures that are reviewed and updated as needed.

Related Key Issues

Scroll to Top