Chapter IV · Art. 24–43
The core of the obligations for businesses. Accountability, processor contracts, records, security, incidents, the DPIA and the DPO.
Art. 24 The responsibility of the controller: to put in place appropriate technical and organisational measures according to the nature and risks of the processing, and to be able to demonstrate them. The risk-based approach that then returns in Art. 25, 32 and 35.
Art. 25 Data protection by design and by default. Data protection is built into the design of systems, and the default settings process only the necessary minimum. The sister principle to the design requirements in the AI Act.
Art. 26 Joint controllers allocate their duties by an arrangement and make the essence of it available to data subjects. The data subject may exercise their rights against any of them, and the arrangement does not bind anyone externally. A website operator who embeds a social-network button that collects visitors' data is also a joint controller (C-40/17 Fashion ID).
Art. 27 Controllers and processors outside the EU that the Regulation reaches through Art. 3 designate a representative in the Union in writing.
Art. 28 A processor acts only under a contract with the mandatory content of paragraph 3: the controller's instructions, confidentiality, security, the conditions for engaging sub-processors, cooperation, erasure or return at the end, and audit rights. The most frequently reviewed contract type in the whole Regulation.
Art. 29 Anyone with access to the data processes it only on the controller's instructions.
Art. 30 Records of processing activities for both controllers and processors. The exemption for organisations under 250 employees is full of holes (it does not apply to non-occasional processing, to risk, or to special categories), so in practice almost everyone keeps records.
Art. 31 Mandatory cooperation with the supervisory authority on request.
Art. 32 Security appropriate to the risk, with pseudonymisation and encryption expressly named, the ability to ensure confidentiality, integrity, availability and resilience, recovery after an incident, and regular testing of the effectiveness of the measures. A successful hacker attack does not in itself mean the measures were inappropriate; appropriateness is judged against the risk (C-340/21).
Art. 33 A personal data breach is notified to the supervisory authority without undue delay, where feasible within 72 hours, unless the risk to people's rights is unlikely. A processor notifies the controller without undue delay. Internal records of all breaches are mandatory in every case, including those not notified.
Art. 34 Where the risk to people is high, the breach is communicated to them too, in clear terms and with recommendations. Exceptions apply where there was effective protection (encryption), where subsequent measures were taken, or where it would take disproportionate effort (then a public communication).
Art. 35 A data protection impact assessment (DPIA) before processing that is likely to be high-risk, typically a systematic and extensive evaluation of people including profiling, large-scale processing of special categories, or systematic monitoring of public areas. The ÚOOÚ maintains a list of operations that always require a DPIA. The methodological forerunner of the FRIA in Art. 27 of the AI Act.
Art. 36 Where a DPIA shows a high residual risk that the controller cannot mitigate, it goes to the supervisory authority for prior consultation before processing.
Art. 37 A data protection officer is mandatory for public authorities, for large-scale regular and systematic monitoring, and for large-scale processing of special categories. There may be one for a group, and the DPO may be internal or external.
Art. 38 The position of the DPO: involvement in all data protection matters, resources, independence (no instructions on how to perform the role, no dismissal for performing it) and direct access to top management.
Art. 39 The tasks of the DPO: to inform and advise, monitor compliance, advise on the DPIA, and act as the contact point for the authority and for data subjects.
Art. 40 Associations may draw up codes of conduct that specify the Regulation for their sector, approved by the supervisory authority.
Art. 41 Compliance with a code may be monitored by an accredited body, without prejudice to the powers of the supervisory authority.
Art. 42 Voluntary certifications, seals and marks as evidence of compliance, valid for at most three years; certification does not reduce liability.
Art. 43 Certification bodies are accredited by the supervisory authority or the national accreditation body.