Looking for an external Data Protection Officer?DATUREX GmbH Dresden
DATUREXData Protection Laws
GDPR — Table of Contents

AI-generated summary

This provision requires controllers to implement appropriate technical and organisational measures to ensure and demonstrate that processing complies with the Regulation, taking into account the nature, scope, context, and purposes of processing as well as associated risks. Adherence to approved codes of conduct or certification mechanisms may serve as evidence of compliance.

Art. 24 GDPR

Responsibility of the controller

(1.)Taking into account the nature, scope, context and purposes of as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that is performed in accordance with this Regulation. Those measures shall be reviewed and updated where necessary.
(2.)Where proportionate in relation to activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the .
(3.)Adherence to approved codes of conduct as referred to in Article 40 or approved certification mechanisms as referred to in Article 42 may be used as an element by which to demonstrate compliance with the obligations of the .
Source:
EUR-Lex CELEX 02016R0679-20160504
Citation:
OJ L 119, 04.05.2016, p. 1; corrected by OJ L 127, 23.05.2018, p. 2
As of:
2016-05-04
Retrieved:
2026-02-25