Chapter 4 · Controller and Processor

Article 29Processing under the authority of controller or processor

All 99 Articles Chapter 4: Controller and Processor

Anyone acting under a controller or processor may only process personal data on documented instructions — not on their own initiative.

Official text & source

Article 29 of the General Data Protection Regulation (Regulation (EU) 2016/679). Read the full, authoritative text on EUR-Lex.

Official text on EUR-Lex

Official text

Verbatim text of Article 29 of the General Data Protection Regulation — Regulation (EU) 2016/679.

The processor and any person acting under the authority of the controller or of the processor, who has access to personal data, shall not process those data except on instructions from the controller, unless required to do so by Union or Member State law.

GDPR

Table of contents

Report error

Logo

We are a consulting company specialised in the fields of data protection, IT security and IT forensics. CTA

Learn more

Follow us:

XING |

LinkedIn

Rate us:

Please wait...

Source: Regulation (EU) 2016/679 (OJ L 119, 4.5.2016, p. 1). Official text reproduced from EUR-Lex — © European Union. Only European Union legislation published in the Official Journal is deemed authentic.

Related articles

These summaries are a plain-English orientation only and are not a substitute for the official text of the Regulation or for legal advice.

Need to apply Article 29?

Our data-protection lawyers turn the text into a plan.

Talk to a lawyer