Regolamento · CELEX 32016R0679
Regulation (EU) 2016/679 — data protection
Leggi il testo ufficiale su EUR-Lex →5 obblighi
GDPR-028 · Regulation (EU) 2016/679 — data protection, Article 28
Processor obligations and contracts
Use only processors that provide sufficient guarantees of appropriate technical and organisational measures, governed by a binding contract covering the required terms.
Applicable now
GDPR-028 · Regulation (EU) 2016/679 — data protection, Article 28
Processor obligations and contracts
Use only processors that provide sufficient guarantees of appropriate technical and organisational measures, governed by a binding contract covering the required terms.
- Applies to
- Controllers and processors of personal data
- Severity if failed
- High
- Applies from
- 25 May 2018
- Source
- GDPR.txt:1675
How this is verified
A data processing agreement is on file for every processor and subprocessor, covering the Art 28(3) required terms, with subprocessor changes notified in advance
DPA completeness against all of Art 28(3)(a)-(h) is a checklist a compliance expert should validate, not something inferred from the contract's existence alone.
Last verified against primary law 23 Jul 2026
GDPR-030 · Regulation (EU) 2016/679 — data protection, Article 30
Records of processing activities
Maintain a written record of the processing you carry out, covering who you are, why you process, whose data and what kinds, who receives it, any transfers out of the EU, erasure periods where possible, and a general description of your security measures.
Applicable now
GDPR-030 · Regulation (EU) 2016/679 — data protection, Article 30
Records of processing activities
Maintain a written record of the processing you carry out, covering who you are, why you process, whose data and what kinds, who receives it, any transfers out of the EU, erasure periods where possible, and a general description of your security measures.
- Applies to
- Controllers and processors of personal data (Art 30(5) exempts organisations under 250 staff only where processing is occasional, low-risk and not of special-category data)
- Severity if failed
- Medium
- Applies from
- 25 May 2018
- Source
- GDPR.txt:1739
How this is verified
A written record of processing activities exists covering all of Art 30(1)(a)-(g), is kept current, and can be made available to the supervisory authority on request
Whether the Art 30(5) small-organisation exemption applies is a legal judgement about the entity, not something the platform infers — in practice it rarely holds, because employee data is processed regularly.
Last verified against primary law 23 Jul 2026
GDPR-033 · Regulation (EU) 2016/679 — data protection, Article 33
Personal data breach notification to the supervisory authority
Notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it — unless the breach is unlikely to result in a risk to individuals' rights and freedoms.
Applicable now
GDPR-033 · Regulation (EU) 2016/679 — data protection, Article 33
Personal data breach notification to the supervisory authority
Notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it — unless the breach is unlikely to result in a risk to individuals' rights and freedoms.
- Applies to
- Controllers processing personal data (processors must notify controllers without undue delay, Art 33(2))
- Severity if failed
- Critical
- Applies from
- 25 May 2018
- Source
- GDPR.txt:1835
How this is verified
Breach assessed and notified to the supervisory authority within 72 hours of becoming aware, or a documented reason for delay
Requires a timestamped incident register capturing time of awareness — not yet built (§3.15 Incident Management is Phase 3 scope).
Last verified against primary law 23 Jul 2026
GDPR-034 · Regulation (EU) 2016/679 — data protection, Article 34
Personal data breach communication to the data subject
When a personal data breach is likely to result in a high risk to individuals' rights and freedoms, communicate the breach to the affected data subjects without undue delay.
Applicable now
GDPR-034 · Regulation (EU) 2016/679 — data protection, Article 34
Personal data breach communication to the data subject
When a personal data breach is likely to result in a high risk to individuals' rights and freedoms, communicate the breach to the affected data subjects without undue delay.
- Applies to
- Controllers processing personal data
- Severity if failed
- Critical
- Applies from
- 25 May 2018
- Source
- GDPR.txt:1865
How this is verified
Affected data subjects are notified without undue delay whenever the breach risk assessment concludes 'high risk'
Art 34(3) lists exemptions (e.g. the data was already encrypted, or a public communication is used instead) — not modelled as separate conditions yet; the risk assessment itself is a manual judgment call pending expert input.
Last verified against primary law 23 Jul 2026
GDPR-046 · Regulation (EU) 2016/679 — data protection, Article 46
Transfers subject to appropriate safeguards
Where you send personal data outside the EEA to a country with no adequacy decision, you may do so only on an appropriate safeguard — in practice the Commission's standard contractual clauses — with enforceable rights and effective remedies for the people whose data it is, and a documented assessment that the destination's law does not stop the importer honouring those clauses.
Applicable now
GDPR-046 · Regulation (EU) 2016/679 — data protection, Article 46
Transfers subject to appropriate safeguards
Where you send personal data outside the EEA to a country with no adequacy decision, you may do so only on an appropriate safeguard — in practice the Commission's standard contractual clauses — with enforceable rights and effective remedies for the people whose data it is, and a documented assessment that the destination's law does not stop the importer honouring those clauses.
- Applies to
- Controllers and processors transferring personal data to a third country or international organisation without an adequacy decision
- Severity if failed
- High
- Applies from
- 25 May 2018
- Source
- GDPR.txt:2285
How this is verified
For each transfer with no adequacy decision, the unmodified standard contractual clauses are signed with the correct module, Annexes I to III are completed with real detail, and a Clause 14 transfer impact assessment is documented and kept current
Whether the safeguard is actually effective in the destination country is a legal judgement about that country's law and practice — the platform can check the assessment exists and covers what Clause 14(b) requires, not whether its conclusion is right.
Last verified against primary law 23 Jul 2026