Laws · GDPR ·art-5-par-2 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).
How it connects
Cited by
- What Happened to the Risk-Based Approach to Data Transfers?
- Italian DPA sanctions Municipality of Policoro for CCTV signage, retention and DPO
- Guidelines 02/2024 on Article 48 GDPR
- Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679
- Guidelines 01/2022 on data subject rights - Right of access
All 219
- Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them
- Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679
- Guidelines 9/2022 on personal data breach notification under GDPR
- Guidelines 3/2019 on processing of personal data through video devices
- Guidelines 10/2020 on restrictions under Article 23 GDPR
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
- Guidelines 8/2020 on the targeting of social media users
- Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications
- IDdesign A / S: Non-compliance with general data processing principles
- PWC Business Solutions: Insufficient legal basis for data processing
- Bank of Cyprus Public Company Ltd: Insufficient technical and organisational measures to ensure information security
- Università Campus Bio-medico di Roma (Polyclinic): Non-compliance with general data processing principles
- Aleris Sjukvård AB: Insufficient technical and organisational measures to ensure information security
- Aleris Sjukvård AB: Insufficient technical and organisational measures to ensure information security
- Östergötland Region: Insufficient technical and organisational measures to ensure information security
- Västerbotten Region: Insufficient technical and organisational measures to ensure information security
- Sahlgrenska University Hospital: Insufficient technical and organisational measures to ensure information security
- Karolinska University Hospital of Solna: Insufficient technical and organisational measures to ensure information security
- Capio St. Göran AB: Insufficient technical and organisational measures to ensure information security
- VfB Stuttgart 1893 AG: Non-compliance with general data processing principles
- Regione Lazio: Insufficient data processing agreement
- S.C. Tip Top Food Industry S.R.L: Insufficient legal basis for data processing
- Irish Credit Bureau DAC: Insufficient technical and organisational measures to ensure information security
- PURPLE SEA MΟΝΟΠΡΟΣΩΠΗ ΙΚΕ: Non-compliance with general data processing principles
- Website operator: Non-compliance with general data processing principles
- NOW DOCTOR – Εταιρία Παροχής Ηλεκτρονικών Υπηρεσιών Αναζήτησης και Προβολής Ιατρών Ε.Π.Ε.: Non-compliance with general data processing principles
- Ferde AS: Non-compliance with general data processing principles
- Régie autonome des transports parisiens: Non-compliance with general data processing principles
- Telekom Romania Communications SA: Non-compliance with general data processing principles
- Warsaw University of Technology: Insufficient technical and organisational measures to ensure information security
- Enel Energia S.p.A: Insufficient legal basis for data processing
- Cosmote Mobile Telecommunications S.A.: Insufficient technical and organisational measures to ensure information security
- IAB Europe: Insufficient legal basis for data processing
- Vodafone España, S.A.U.: Non-compliance with general data processing principles
- Civil law firm 'Sabou, Burz & Cuc': Insufficient legal basis for data processing
- Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security
- Employer: Insufficient fulfilment of data subjects rights
- Klarna Bank AB: Insufficient fulfilment of information obligations
- Foreign language school: Insufficient fulfilment of data subjects rights
- Danske Bank: Non-compliance with general data processing principles
- Company: Insufficient legal basis for data processing
- MAYR MELNHOF PACKAGING ROMANIA S.R.L.: Non-compliance with general data processing principles
- Roularta Media Group: Insufficient legal basis for data processing
- Asociația de Proprietari Aviației Park: Insufficient legal basis for data processing
- Policoro municipality: Non-compliance with general data processing principles
- Wabag Water Services SRL: Insufficient legal basis for data processing
- Manx Care Ltd: Non-compliance with general data processing principles
- SLOVAKIA DPA: Non-compliance with general data processing principles
- DO VALUE GREECE LOANS & CREDITS CLAIM MANAGEMENT S.A.: Insufficient fulfilment of data subjects rights
- Company: Non-compliance with general data processing principles
- Health insurance provider: Non-compliance with general data processing principles
- Lazio Region: Non-compliance with general data processing principles
- Bank: Insufficient legal basis for data processing
- School: Non-compliance with general data processing principles
- SC Prestige Media PHG SRL: Insufficient legal basis for data processing
- Colosseo S.r.l.: Insufficient fulfilment of data subjects rights
- Mayor: Insufficient technical and organisational measures to ensure information security
- Areti spa: Non-compliance with general data processing principles
- Mister Brick S.a.s.: Insufficient legal basis for data processing
- Douglas Italia S.p.a.: Non-compliance with general data processing principles
- Company: Insufficient technical and organisational measures to ensure information security
- Centric Health Ltd.: Non-compliance with general data processing principles
- Edison Energia S.p.A.: Non-compliance with general data processing principles
- Alianța pentru Unirea Românilor: Non-compliance with general data processing principles
- Szczecin-Centrum District Court: Insufficient technical and organisational measures to ensure information security
- Tehnoplus Industry SRL: Non-compliance with general data processing principles
- Company: Insufficient technical and organisational measures to ensure information security
- Political party: Insufficient technical and organisational measures to ensure information security
- Credit institution: Insufficient legal basis for data processing
- Compania Națională Poșta Română S.A.: Insufficient legal basis for data processing
- TIM S.p.A.: Insufficient legal basis for data processing
- Green Network S.p.A.: Insufficient technical and organisational measures to ensure information security
- Sorgenia S.p.a.: Insufficient technical and organisational measures to ensure information security
- BRD-Groupe Société Générale S.A.: Non-compliance with general data processing principles
- Municipality: Insufficient technical and organisational measures to ensure information security
- Municipality: Insufficient technical and organisational measures to ensure information security
- Website operator: Non-compliance with general data processing principles
- Company: Insufficient technical and organisational measures to ensure information security
- Debt collection company: Insufficient legal basis for data processing
- Axpo Italia Spa: Non-compliance with general data processing principles
- Company: Insufficient technical and organisational measures to ensure information security
- Università Telematica E-Campus: Non-compliance with general data processing principles
- Scionti Selezioni Superiori S.r.l.: Non-compliance with general data processing principles
- Compara Facile S.r.l.: Non-compliance with general data processing principles
- Tiscali Italia SpA: Non-compliance with general data processing principles
- Norwegian Labor and Welfare Administration: Insufficient technical and organisational measures to ensure information security
- Disciplinary officer: Insufficient technical and organisational measures to ensure information security
- Limit Call S.r.l.s.: Insufficient legal basis for data processing
- Owners' association: Non-compliance with general data processing principles
- Azienda Trasporto Passeggeri Emilia-Romagna S.p.A.: Non-compliance with general data processing principles
- Municipality of Modica: Non-compliance with general data processing principles
- Enel Energia SpA: Insufficient technical and organisational measures to ensure information security
- Mas s.r.l.s.: Non-compliance with general data processing principles
- Facile.Energy S.r.l.: Non-compliance with general data processing principles
- Olimpia S.r.l.: Non-compliance with general data processing principles
- Committee: Insufficient technical and organisational measures to ensure information security
- Eni Plenitude S.p.A.: Non-compliance with general data processing principles
- Vinted: Insufficient fulfilment of data subjects rights
- Company: Insufficient technical and organisational measures to ensure information security
- Profi Rom Food SRL: Insufficient legal basis for data processing
- POLAND DPA: Insufficient technical and organisational measures to ensure information security
- OpenAI OpCo LLC: Non-compliance with general data processing principles
- Illumia Spa: Insufficient technical and organisational measures to ensure information security
- Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles
- Hera Comm S.p.A.: Non-compliance with general data processing principles
- Fastweb S.p.A.: Non-compliance with general data processing principles
- ENERGYA VM GESTIÓN DE ENERGÍA, S.L.: Non-compliance with general data processing principles
- Funeral Home: Insufficient technical and organisational measures to ensure information security
- Noi Compriamo Auto.it S.r.l.: Non-compliance with general data processing principles
- L. Zamenhof University Children's Clinical Hospital in Białystok: Insufficient technical and organisational measures to ensure information security
- General Hospital of the University of Larissa: Insufficient fulfilment of data subjects rights
- One-Stop-Shop case digest on right of access
- Coordinated Enforcement Action, implementation of the right of access by controllers
- Position paper on Interplay between data protection and competition law
- Recommendations 1/2025 on the 2027 WADA World Anti-Doping Code
- Guidelines 02/2025 on processing of personal data through blockchain technologies
- EDPB Annual Report 2024
- EDPB- EDPS Joint Opinion 01/2025 on the Proposal for a Regulation on simplification measures for SMEs and SMCs, in particular the record-keeping obligation under Art. 30(5) GDPR
- EDPB contribution to the EBA public consultation on draft regulatory technical standards on AML/CFT
- Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH
- EDPB contribution to the EBA public consultation on draft regulatory technical standards on AML/CFT
- Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation
- Meta Platforms and Others v Bundeskartellamt
- VB v Natsionalna agentsia za prihodite
- UODO fines accounting firm €2,760 for email breach security failures
- UODO reprimands electricity seller for Art. 5, 24, 25, 28, 32 GDPR violations over
- WhatsApp is getting ads using personal data from Instagram and Facebook
- Permanent TSB: Insufficient technical and organisational measures to ensure information security
- Elektronikus Egészségügyi Szolgáltatási Tér: Insufficient technical and organisational measures to ensure information security
- Coordinated Enforcement Action,
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- Smokescreens of digital markets—choice manipulation and the illusion of consent
- AKI (Estonia) - No. 2.1-1/24/397-890-38
- VDAI fines medical company €450,000 for inadequate security measures in data breaches
- UODO (Poland) - DKN.5131.27.2023
- Persónuvernd (Island) - 2025010358
- Generative AI and data protection
- UODO (Poland) - DKE.561.4.2026
- Garante per la protezione dei dati personali (Italy) - 487/2026
- AEPD fines DIGI Telecom for issuing duplicate SIM to impersonator without consent
- Belgian DPA: Roularta Media Group violated cookie consent rules
- LG Rostock: Pre-ticked cookie consent boxes invalid under Art 6(1)(a) GDPR
- Belgian DPA finds MediaHuis violated GDPR fairness over cookie banner design
- Garante per la protezione dei dati personali (Italy) - 419/2026
- Greek HDPA: Classroom video surveillance at school unlawful; oral notice insufficient
- Austrian FAC: DPA rightly found loyalty program consent for profiling invalid under GDPR
- Guidelines on processing of personal data through blockchain technologies
- EDPB Annual Report 2025
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
- Opinion 27/2024 on the Brand Compliance criteria of certification regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 (GDPR)
- Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)
- Opinion 18/2024 on the draft decision of the Austrian Supervisory Authority regarding DSGVO-zt GmbH certification criteria
- Report of the work undertaken by the ChatGPT Taskforce
- EDPB Annual Report 2023
- Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms
- EDPB-EDPS Joint Opinion 02/2023 on the Proposal for a Regulation of the European Parliament and of the Council on the establishment of the digital euro
- Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)
- Report of the work undertaken by the supervisory authorities within the 101 Taskforce
- EDPB Annual Report 2022
- Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR
- EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space
- EDPB Annual Report 2021
- EDPB-EDPS Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act)
- EDPB-EDPS Joint Opinion 1/2022 on the extension of the Covid-19 certificate Regulation
- Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data
- EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)
- Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects
- Court upholds €50,000 fine on Sociálna poisťovňa for sending sensitive data by ordinary
- X v Russmedia Digital SRL and Inform Media Press SRL
- Amt der Tiroler Landesregierung v Datenschutzbehörde
- Maximilian Schrems v Meta Platforms Ireland Limited
- Agentsia po vpisvaniyata v OL
- TR v Land Hessen
- Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V
- Budapest Főváros IV. Kerület Újpest Önkormányzat Polgármesteri Hivatala v Nemzeti Adatvédelmi és Információszabadság Hatóság
- BL v MediaMarktSaturn Hagen-Iserlohn GmbH
- État belge v Autorité de protection des données
- OQ v Land Hessen
- RK v Ministerstvo zdravotnictví
- UZ v Bundesrepublik Deutschland
- RW v Österreichische Post AG
- Proximus NV v Gegevensbeschermingsautoriteit
- Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság
- Robert Roos and Others v European Parliament
- SIA 'SS' v Valsts ieņēmumu dienests
- KPN BV v Autoriteit Consument en Markt (ACM)
- UODO reprimands hospital for inadequate processor oversight and email security failures
- DSB (Austria) - 2026-0.043.390
- HDPA (Greece) - 33/2020
- DSB (Austria) - 2025-0.950.759
- AEPD fines El Español for publishing video of minor assailant without anonymization
- VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural
- UODO (Poland) - DKN.5131.5.2025
- NAIH (Hungary) - NAIH-450-7-2026
- AEPD fines MÁS SOL ENERGÍA for marketing call to Robinson List subscriber
- NAIH (Hungary) - NAIH-4462-5-2026
- Garante per la protezione dei dati personali (Italy) - 556/2026
- VG Berlin - 42 K 73/25
- DSB: Retailer must grant full access and delete data after third-party fraud order
- UODO reprimands mayor for disclosing data subject's data to company without legal basis
- VG Munich: university may be GDPR controller for professors' editorial work emails
- Persónuvernd (Iceland) - 2025010364
- AEPD: Data subject entitled to identity of professionals who accessed medical records
- Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste
- Hôpital privé de la Loire: Insufficient technical and organisational measures to ensure information security
- Character Technologies Inc.: Non-compliance with general data processing principles
- HDPA investigates Greek Infrastructure Ministry for SMS sent without consent or
- Italian DPA: employer breached Art. 15 GDPR by ignoring access request over disciplinary
- AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight
- Slovenian DPA: Controller breached Art. 32, 15 and 34 GDPR over data breach and access
- Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR
- Icelandic DPA: City of Reykjavik cannot request bank statements from NPA disabled service
- District Governor of Lubartów: Insufficient technical and organisational measures to ensure information security
- Operator of an online shop for alcoholic beverages: Insufficient fulfilment of information obligations