Laws · GDPR ·art-24-par-1 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. Those measures shall be reviewed and updated where necessary.
How it connects
Cited by
- Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation
- Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
- Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR
- BELGIUM DPA: Insufficient fulfilment of data subjects rights
All 86
- BELGIUM DPA: Insufficient fulfilment of data subjects rights
- Ålesund Municipality: Insufficient technical and organisational measures to ensure information security
- Cyfrowy Polsat S.A.: Insufficient technical and organisational measures to ensure information security
- Irish Credit Bureau DAC: Insufficient technical and organisational measures to ensure information security
- Magazine publisher: Insufficient legal basis for data processing
- Warsaw University of Technology: Insufficient technical and organisational measures to ensure information security
- IAB Europe: Insufficient legal basis for data processing
- Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security
- Fortum Marketing and Sales Polska S.A.: Insufficient technical and organisational measures to ensure information security
- Budapest Bank Zrt.: Insufficient legal basis for data processing
- Universal Life Insurance Public Co Ltd.: Insufficient data processing agreement
- Bank of Cyprus Public Company Ltd.: Insufficient technical and organisational measures to ensure information security
- Cyprus Electricity Authority: Insufficient technical and organisational measures to ensure information security
- Company: Insufficient technical and organisational measures to ensure information security
- Edison Energia S.p.A.: Non-compliance with general data processing principles
- Szczecin-Centrum District Court: Insufficient technical and organisational measures to ensure information security
- Company: Insufficient technical and organisational measures to ensure information security
- Epic Ltd.: Insufficient legal basis for data processing
- Municipality: Insufficient technical and organisational measures to ensure information security
- TikTok Limited: Non-compliance with general data processing principles
- Company: Insufficient technical and organisational measures to ensure information security
- Scionti Selezioni Superiori S.r.l.: Non-compliance with general data processing principles
- Compara Facile S.r.l.: Non-compliance with general data processing principles
- Norwegian Labor and Welfare Administration: Insufficient technical and organisational measures to ensure information security
- Reykjanesbær municipality: Non-compliance with general data processing principles
- City of Reykjavik: Non-compliance with general data processing principles
- Garðabær municipality: Non-compliance with general data processing principles
- City of Hafnarfjörður: Non-compliance with general data processing principles
- City of Kópavogur: Non-compliance with general data processing principles
- Enel Energia SpA: Insufficient technical and organisational measures to ensure information security
- Res-Gastro M. Gaweł Sp. k.: Insufficient technical and organisational measures to ensure information security
- Facile.Energy S.r.l.: Non-compliance with general data processing principles
- Olimpia S.r.l.: Non-compliance with general data processing principles
- Healthcare facility: Insufficient technical and organisational measures to ensure information security
- Fastweb S.p.A.: Non-compliance with general data processing principles
- Telenor ASA.: Non-compliance with general data processing principles
- Polskie Radio Szczecin: Insufficient technical and organisational measures to ensure information security
- Employment Service under the Ministry of Social Security and Labor of the Republic of Lithuania: Insufficient technical and organisational measures to ensure information security
- Company: Non-compliance with general data processing principles
- Sligo County Council: Non-compliance with general data processing principles
- Housing Finance Corporation: Insufficient legal basis for data processing
- EDPB Annual Report 2024
- Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation
- Opinion 2/2026 on the Proposal for a Directive amending Directives (EU) 2016/2341 and 2016/97 as regards the strengthening of the framework for occupational retirement provision
- VB v Natsionalna agentsia za prihodite
- UODO fines accounting firm €2,760 for email breach security failures
- UODO reprimands electricity seller for Art. 5, 24, 25, 28, 32 GDPR violations over
- EDPB-EDPS Joint opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- BGH - VI ZR 375/2
- VDAI fines medical company €450,000 for inadequate security measures in data breaches
- UODO (Poland) - DKN.5131.27.2023
- Garante per la protezione dei dati personali (Italy) - 487/2026
- LG Rostock: Pre-ticked cookie consent boxes invalid under Art 6(1)(a) GDPR
- DPC (Ireland) - 06/SIU/2018
- Statement 4/2024 on the recent legislative developments on the Draft Regulation laying down additional procedural rules for the enforcement of the GDPR
- Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)
- Guidelines 01/2023 on Article 37 Law Enforcement Directive
- Report of the work undertaken by the ChatGPT Taskforce
- EDPB Annual Report 2023
- EDPB-EDPS Joint Opinion 01/2023 on the Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679
- Report of the work undertaken by the supervisory authorities within the 101 Taskforce
- EDPB Annual Report 2021
- Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data
- Court upholds €50,000 fine on Sociálna poisťovňa for sending sensitive data by ordinary
- TR v Land Hessen
- IAB Europe v Gegevensbeschermingsautoriteit
- Proceedings brought by J.M
- Meta Platforms Ireland Ltd, formerly Facebook Ireland Ltd v European Commission
- Meta Platforms Ireland Ltd, formerly Facebook Ireland Ltd v European Commission
- Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband eV
- Deutsche Post AG v Hauptzollamt Köln
- UODO reprimands hospital for inadequate processor oversight and email security failures
- AEPD (Spain) - PS-00140-2025
- UODO (Poland) - DKN.5131.5.2025
- HDPA orders TEIRESIAS S.A. to ensure data accuracy under Art. 5(1)(d) GDPR
- InMedica UAB: Insufficient technical and organisational measures to ensure information security
- Persónuvernd (Iceland) - 2025010364
- Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor
- Character Technologies Inc.: Non-compliance with general data processing principles
- Austrian Federal Administrative Court: address publisher's data transfer and Article 15