Laws · GDPR ·art-28-par-2 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes.
How it connects
Cited by
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
- Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)
- Roma Capitale (Rome Municipality): Non-compliance with general data processing principles
- Healthcare provider: Insufficient fulfilment of information obligations
- Scanshare S.r.l.: Insufficient technical and organisational measures to ensure information security
All 29
- Wens Experience SRL: Insufficient data processing agreement
- NTT Data Italia S.P.A: Insufficient fulfilment of data breach notification obligations
- ADMINISTRACIONES BENIPON, S.L.: Insufficient fulfilment of data breach notification obligations
- SENDING TRANSPORTE Y COMUNICACIÓN, S.A.: Insufficient data processing agreement
- Study on the secondary use of personal data in the context of scientific research
- Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH
- Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive (‘‘LED’’) under Article 62 LED
- AKI (Estonia) - No. 2.1-1/24/397-890-38
- Statement 4/2024 on the recent legislative developments on the Draft Regulation laying down additional procedural rules for the enforcement of the GDPR
- Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)
- Opinion 18/2024 on the draft decision of the Austrian Supervisory Authority regarding DSGVO-zt GmbH certification criteria
- Opinion 19/2024 on the EuroPrise criteria of certification regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 (GDPR)
- Report of the work undertaken by the ChatGPT Taskforce
- Opinion 7/2024 on the draft decision of the German North Rhine Westphalia Supervisory Authority regarding the EU Cloud Service Data Protection (Auditor) certification criteria
- EDPB-EDPS Joint Opinion 01/2023 on the Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679
- Opinion 15/2023 on the draft decision of the Dutch Supervisory Authority regarding the Brand Compliance certification criteria
- Statement 1/2023 on the first review of the functioning of the adequacy decision for Japan
- Opinion 25/2022 regarding the European Privacy Seal (EuroPriSe ) certification criteria for the certification of processing operations by processors
- Opinion 20/2021 on Tobacco Traceability System
- EDPB-EDPS Joint Opinion 2/2021 on standard contractual clauses for the transfer of personal data to third countries
- Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR)
- Meta Platforms Ireland Ltd, formerly Facebook Ireland Ltd v European Commission
- Meta Platforms Ireland Ltd, formerly Facebook Ireland Ltd v European Commission
- Köln-Aktienfonds Deka v Staatssecretaris van Financiën
Related across sources
C-46/23 Budapest Főváros IV. Kerület Újpest Önkormányzat Polgármesteri Hivatala v Nemzeti Adatvédelmi és Információszabadság Hatóság In a preliminary ruling requested by the Budapest High Court, the Court of Justice interpreted whether Article 58(2)(d) and (g) of the GDPR permits a national supervisory… CJEU ·Fifth Chamber Mar 14, 2024 Right to be Forgotten Personal Data Right to Restriction
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
S 5 SF 65/24 DS SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus… Social Court Nuremberg Jun 10, 2026 Processors Controllers Integrity and Confidentiality Principle
C-311/18 Data Protection Commissioner v Facebook Ireland and Maximillian Schrems C-311/18 (Schrems II) CJEU Jul 16, 2020 Privacy Shield Processing Agreement International Transfer
C-306/21 Komisia za zashtita na lichnite danni and Tsentralna izbiratelna komisia v Koalitsia „Demokratichna Bulgaria - Obedinenie“ In this preliminary ruling, the Court of Justice of the European Union addressed whether the GDPR applies to the processing of personal data during national and European elections… CJEU ·Eighth Chamber Oct 20, 2022 Material scope (GDPR) Supervision Personal Data
C-362/14 Maximillian Schrems v Data Protection Commissioner C-362/14 (Schrems I) CJEU Oct 6, 2015 Privacy Shield Supervision IP Address