Laws · GDPR ·art-38-par-1 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
The controller and the processor shall ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal data.
How it connects
Cited by
- Icelandic DPA: genetic research company violated DPO independence under Art. 38(3) GDPR
- LUXEMBOURG DPA: Insufficient involvement of data protection officer
- LUXEMBOURG DPA: Insufficient involvement of data protection officer
- LUXEMBOURG DPA: Insufficient involvement of data protection officer
- LUXEMBOURG DPA: Insufficient involvement of data protection officer
All 18
- LUXEMBOURG DPA: Insufficient involvement of data protection officer
- Company: Insufficient involvement of data protection officer
- MALTA DPA: Insufficient fulfilment of data subjects rights
- Hospital: Insufficient technical and organisational measures to ensure information security
- McDonald’s Polska Sp. z o.o.: Non-compliance with general data processing principles
- 24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security
- SAMARITAINE SAS: Non-compliance with general data processing principles
- Recommendations 1/2025 on the 2027 WADA World Anti-Doping Code
- EDPB Annual Report 2024
- Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive (‘‘LED’’) under Article 62 LED
- Guidelines 01/2023 on Article 37 Law Enforcement Directive
- EDPB Annual Report 2021
- Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive (LED) under Article 62
Related across sources
14/2021 Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor On 26 July 2021, a journalist informed the Cypriot DPA of a security vulnerability on an online platform. This online platform hosted ticket purchase sites of two Cypriot football… Administrative Court of Cyprus May 12, 2026 Controllers Processors Supervisory Authorities
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
Guidelines 8/2022 identifying a controller or processor's lead supervisory authority Guidelines for identifying a controller or processor’s lead supervisory authority Guidelines ·EDPB Apr 17, 2023 Supervision Controllers Supervisory Authorities
Opinion 19/2026 Rubrik Group — processor BCRs ·Opinion ·EDPB Jun 8, 2026 International Transfer Processors Codes of Conduct
Opinion 17/2026 Infor Group — processor BCRs ·Opinion ·EDPB May 11, 2026 International Transfer Processors Codes of Conduct
Opinion 5/2026 Arcadis Group — processor BCRs ·Opinion ·EDPB Feb 10, 2026 International Transfer Processors Codes of Conduct