Article 24 of the GDPR: Controller's Responsibility
Article 24 of the GDPR Explained
The data controller must implement appropriate technical and organisational measures, as defined by the GDPR, in order to ensure and be able to demonstrate that the processing is performed in accordance with the regulation. These measures must be adjusted according to:
- The nature, scope, context, and purposes of the processing;
- The risks to the rights and freedoms of natural persons.
These measures notably include internal policies and the implementation of effective safeguards.
Why This Article is Important for Your GDPR Compliance
This principle is at the heart of GDPR: the data controller must be proactive, document their actions, and be able to justify their compliance at any time. This implies a rigorous approach to personal data management and risk anticipation.
Article 24 GDPR Application Examples
- A company drafts an internal GDPR charter and has every employee sign it.
- A GDPR manager maintains a documented register of all data processing operations.
- An association conducts an impact assessment before launching a donation campaign involving the collection of sensitive information.
Related Resources
Accelerate Your Compliance in a Few Clicks
With our all-in-one solution, you can easily accelerate and ensure your compliance:
- Automate your compliance with our GDPR software
- Supported or outsourced by our DPO experts
- Raise awareness among your teams with our GDPR e-learning training
Evaluate your situation in 15 minutes with our GDPR self-assessment, free and without obligation.
How to Comply with Article 24 of the GDPR?