Laws · GDPR ·art-83-par-2-pnt-d EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32;
How it connects
Cited by
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020
- Guidelines 04/2022 on the calculation of administrative fines under the GDPR
- Permanent TSB: Insufficient technical and organisational measures to ensure information security
- VDAI fines medical company €450,000 for inadequate security measures in data breaches
- Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security
All 13
- UODO (Poland) - DKN.5131.27.2023
- UODO (Poland) - DKE.561.4.2026
- VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural
- UODO (Poland) - DKN.5131.5.2025
- Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights
- BVwG reduces DPA fine for undisclosed call recording from €25,500 to €22,000
- Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR
- UODO fines controller PLN 31,507 for failing to provide information under Art. 58(1) GDPR