Laws · GDPR ·art-38-par-3 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
The controller and processor shall ensure that the data protection officer does not receive any instructions regarding the exercise of those tasks. He or she shall not be dismissed or penalised by the controller or the processor for performing his tasks. The data protection officer shall directly report to the highest management level of the controller or the processor.
How it connects
Cited by
- Data Protection Officer or Chief Privacy Officer?The rise of the Data Protection Officer
- Icelandic DPA: genetic research company violated DPO independence under Art. 38(3) GDPR
- Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)
- Company: Insufficient technical and organisational measures to ensure information security
- Company: Insufficient legal basis for data processing
All 15
- Opinion 3/2025 on the draft decision of the French Supervisory Authority (FR SA) regarding the “Lexing GDPR certification criteria”
- EDPB Annual Report 2024
- Opinion 2/2026 on the Proposal for a Directive amending Directives (EU) 2016/2341 and 2016/97 as regards the strengthening of the framework for occupational retirement provision
- Polish Postal Service: Lack of appointment of data protection officer
- EDPB-EDPS Joint opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (
- Opinion 26/2024 on the draft decision of the DE Bremen Supervisory Authority regarding the “Catalogue of Criteria for the Certification of IT-supported processing of Personal Data pursuant to art 42 GDPR (‘GDPR – information privacy standard’)” presented
- Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)
- EDPB Annual Report 2021
- X-FAB Dresden GmbH & Co. KG v FC
- Leistritz AG v LH
Related across sources
14/2021 Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor On 26 July 2021, a journalist informed the Cypriot DPA of a security vulnerability on an online platform. This online platform hosted ticket purchase sites of two Cypriot football… Administrative Court of Cyprus May 12, 2026 Controllers Processors Supervisory Authorities
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
Guidelines 8/2022 identifying a controller or processor's lead supervisory authority Guidelines for identifying a controller or processor’s lead supervisory authority Guidelines ·EDPB Apr 17, 2023 Supervision Controllers Supervisory Authorities
Opinion 19/2026 Rubrik Group — processor BCRs ·Opinion ·EDPB Jun 8, 2026 International Transfer Processors Codes of Conduct
Opinion 17/2026 Infor Group — processor BCRs ·Opinion ·EDPB May 11, 2026 International Transfer Processors Codes of Conduct
Opinion 5/2026 Arcadis Group — processor BCRs ·Opinion ·EDPB Feb 10, 2026 International Transfer Processors Codes of Conduct