Chapter 4 · Controller and Processor

Article 24Responsibility of the controller

All 99 Articles Chapter 4: Controller and Processor

The controller must implement appropriate technical and organisational measures to ensure — and be able to demonstrate — that processing complies with the GDPR. This is accountability in practice.

Official text & source

Article 24 of the General Data Protection Regulation (Regulation (EU) 2016/679). Read the full, authoritative text on EUR-Lex.

Official text on EUR-Lex

Official text

Verbatim text of Article 24 of the General Data Protection Regulation — Regulation (EU) 2016/679.

1 Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. 2 Those measures shall be reviewed and updated where necessary.

Where proportionate in relation to processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller.

Adherence to approved codes of conduct as referred to in Article 40 or approved certification mechanisms as referred to in Article 42 may be used as an element by which to demonstrate compliance with the obligations of the controller.

Source: Regulation (EU) 2016/679 (OJ L 119, 4.5.2016, p. 1). Official text reproduced from EUR-Lex — © European Union. Only European Union legislation published in the Official Journal is deemed authentic.

Related articles

Learn the context

These summaries are a plain-English orientation only and are not a substitute for the official text of the Regulation or for legal advice.

Need to apply Article 24?

Our data-protection lawyers turn the text into a plan.

Talk to a lawyer