Laws · GDPR ·art-32-par-4 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
The controller and processor shall take steps to ensure that any natural person acting under the authority of the controller or the processor who has access to personal data does not process them except on instructions from the controller, unless he or she is required to do so by Union or Member State law.
How it connects
Cited by
- Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)
- S CNTAR TAROM SA (Airline): Insufficient technical and organisational measures to ensure information security
- KEPIDES: Insufficient technical and organisational measures to ensure information security
- Valoris Center S.R.L.: Insufficient technical and organisational measures to ensure information security
- Retail company (name not available at the moment): Insufficient technical and organisational measures to ensure information security
All 23
- LORIS FUEL SHOP SRL: Insufficient technical and organisational measures to ensure information security
- Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security
- SUDREZIDENȚIAL Broker S.R.L.: Insufficient technical and organisational measures to ensure information security
- Apă Canal Ilfov SA: Insufficient technical and organisational measures to ensure information security
- Med Life S.A.: Insufficient technical and organisational measures to ensure information security
- MALTA DPA: Insufficient technical and organisational measures to ensure information security
- Hotel: Insufficient legal basis for data processing
- Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security
- Compania de Apa Oltenia S.A.: Insufficient technical and organisational measures to ensure information security
- EDPB Annual Report 2024
- ANSPDCP (Romania) - 02/07/2026
- EDPB Annual Report 2023
- EDPB-EDPS Joint Opinion 02/2023 on the Proposal for a Regulation of the European Parliament and of the Council on the establishment of the digital euro
- Opinion 1/2022 on the draft decision of the Luxembourg Supervisory Authority regarding the GDPR – CARPA certification criteria
- GP v juris GmbH
- ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026
- ANSPDCP (Romania) - AMATO BESTSELLER S.R.L.
- AMATO BESTSELLER S.R.L: Non-compliance with general data processing principles
Related across sources
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
C-579/21 Proceedings brought by J.M In Case C-579/21, the Court of Justice of the European Union ruled on a preliminary reference from the Itä-Suomen hallinto-oikeus (Administrative Court of Eastern Finland)… CJEU ·First Chamber Jun 22, 2023 Right of Access Personal Data Right to Restriction
14/2021 Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor On 26 July 2021, a journalist informed the Cypriot DPA of a security vulnerability on an online platform. This online platform hosted ticket purchase sites of two Cypriot football… Administrative Court of Cyprus May 12, 2026 Controllers Processors Supervisory Authorities
C-272/19 VQ v Land Hessen In a preliminary ruling requested by the Verwaltungsgericht Wiesbaden in proceedings between VQ and Land Hessen, the CJEU addressed whether the GDPR applies to the processing of… CJEU ·Third Chamber Jul 9, 2020 Material scope (GDPR) Right of Access Personal Data
C-154/21 RW v Österreichische Post AG The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article… CJEU ·First Chamber Jan 12, 2023 Right of Access Personal Data Recipient
S 5 SF 65/24 DS SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus… Social Court Nuremberg Jun 10, 2026 Processors Controllers Integrity and Confidentiality Principle