Chapter IVController and processor
Section 1 – General obligations
- Article 24Responsibility of the controller
1. Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of…
- Article 25Data protection by design and by default
1. Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of…
- Article 26Joint controllers
1. Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers. They shall in a transparent manner determine their respective…
- Article 27Representatives of controllers or processors not established in the United Kingdom
1. Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the United Kingdom. 2. The obligation laid down in paragraph 1…
- Article 28Processor
1. Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational…
- Article 29Processing under the authority of the controller or processor
The processor and any person acting under the authority of the controller or of the processor, who has access to personal data, shall not process those data except…
- Article 30Records of processing activities
1. Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility. That record shall contain all of the following information:…
- Article 31Cooperation with the Commission
The controller and the processor and, where applicable, their representatives, shall cooperate, on request, with the Commission in the performance of the Commission's tasks.
Section 2 – Security of personal data
- Article 32Security of processing
1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of…
- Article 33Notification of a personal data breach to the Commission
1. In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of…
- Article 34Communication of a personal data breach to the data subject
1. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal…
Section 3 – Data protection impact assessment and prior consultation
- Article 35Data protection impact assessment
1. Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result…
- Article 36Prior consultation
1. The controller shall consult the Commission prior to processing where a data protection impact assessment under Article 35 indicates that the processing would result in a high…
Section 4 – Data protection officer
- Article 37Designation of the data protection officer
1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body,…
- Article 38Position of the data protection officer
1. The controller and the processor shall ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the…
- Article 39Tasks of the data protection officer
1. The data protection officer shall have at least the following tasks: (a) to inform and advise the controller or the processor and the employees who carry out…
Section 5 – Codes of conduct and certification
- Article 40Codes of conduct
1. The Commission shall encourage the drawing up of codes of conduct intended to contribute to the proper application of this Regulation, taking account of the specific features…
- Article 41Monitoring of approved codes of conduct
1. Without prejudice to the tasks and powers of the Commission under Articles 57 and 58 , the monitoring of compliance with a code of conduct pursuant to…
- Article 42Certification
1. The Commission shall encourage ... the establishment of data protection certification mechanisms and of data protection seals and marks, for the purpose of demonstrating compliance with this…
- Article 43Certification bodies
1. Without prejudice to the tasks and powers of the Commission under Articles 57 and 58 , certification bodies which have an appropriate level of expertise in relation…
https://uk-gdpr.digiphile.law/chapter/chapter-IV.html
Text as at 17 September 2026.
This is an unofficial convenience version of the UK GDPR (Regulation (EU) 2016/679 as retained in UK law). It is presented “as is” without guarantee of accuracy, completeness or reliability. See the source text for the official version. This site was last updated in September 2026.