// Level 3 · Controls

Chapter 4: Controller and processor obligations

Controller and processor obligations

Art. 24Medium

Responsibility of the controller

Implement appropriate technical and organisational measures to ensure and demonstrate compliance.

Art. 25Medium

Data protection by design and by default

Bake in privacy from design stage; default settings should minimise data.

Art. 26Medium

Joint controllers

Joint controllers must transparently determine and document respective responsibilities.

Art. 27Medium

Representatives of controllers or processors not established in the Union

Non-EU controllers/processors offering services to EU subjects must designate an EU representative.

Art. 28Medium

Processor

Processors must offer sufficient guarantees; controller-processor relationship governed by binding contract (DPA).

Art. 29Medium

Processing under the authority of the controller or processor

Personnel may only process personal data on documented instructions from the controller.

Art. 30Medium

Records of processing activities

Maintain detailed records of processing activities (RoPA); required for orgs ≥250 staff or higher-risk processing.

Art. 31Medium

Cooperation with the supervisory authority

Controllers/processors must cooperate with supervisory authorities upon request.

Art. 32High

Security of processing

Implement appropriate security measures: pseudonymisation, encryption, confidentiality, integrity, availability, resilience, testing.

Art. 33High

Notification of a personal data breach to the supervisory authority

Notify supervisory authority within 72 hours of becoming aware of a breach (unless unlikely to result in risk).

Art. 34High

Communication of a personal data breach to the data subject

Notify affected data subjects without undue delay when breach likely to result in high risk.

Art. 35High

Data protection impact assessment

DPIA required for high-risk processing (large-scale, sensitive data, systematic monitoring, new technologies).

Art. 36Medium

Prior consultation

Consult supervisory authority before processing where DPIA indicates high residual risk.

Art. 37Medium

Designation of the data protection officer

Mandatory DPO for public authorities, large-scale systematic monitoring, or large-scale special category processing.

Art. 38Medium

Position of the data protection officer

DPO must be involved early, given resources, independent, and report to highest management.

Art. 39Medium

Tasks of the data protection officer

Inform/advise, monitor compliance, advise on DPIAs, cooperate with supervisory authority.

Art. 40Medium

Codes of conduct

Industry associations may draw up codes of conduct, subject to supervisory authority approval.

Art. 41Medium

Monitoring of approved codes of conduct

Accredited bodies monitor compliance with approved codes of conduct.

Art. 42Medium

Certification

Voluntary data protection certification mechanisms to demonstrate compliance.

Art. 43Medium

Certification bodies

Requirements for accreditation of certification bodies issuing GDPR certifications.