Regulation (EU) 2016/679 as retained in UK law (UK GDPR) – Article 24 – Responsibility of the controller
Articles
Article 24Responsibility of the controller
1. Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. Those measures shall be reviewed and updated where necessary.
2. Where proportionate in relation to processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller.
3. Adherence to approved codes of conduct as referred to in Article 40 or approved certification mechanisms as referred to in Article 42 may be used as [F1a means of demonstrating] compliance with the obligations of the controller.
Amended text
This Article is shown as amended by the Data (Use and Access) Act 2025 (c. 18), among other instruments (see the annotations below) (commenced provisions as at 30 September 2026, ELI), as incorporated in the text in force on 30 September 2026 as published on legislation.gov.uk.
Annotations and footnotes
Textual Amendments
- F1 Words in Art. 24(3) substituted (20.8.2025) by Data (Use and Access) Act 2025 (c. 18), s. 142(1), Sch. 11 para. 7; S.I. 2025/904, reg. 2(y)
https://uk-gdpr.digiphile.law/article/article-24.html
Text as at 17 September 2026.
This is an unofficial convenience version of the UK GDPR (Regulation (EU) 2016/679 as retained in UK law). It is presented “as is” without guarantee of accuracy, completeness or reliability. See the source text for the official version. This site was last updated in September 2026.