EU AI Act Info
← Tutte le normative

Regolamento · CELEX 32016R0679

Regulation (EU) 2016/679 — data protection

Leggi il testo ufficiale su EUR-Lex →

5 obblighi

GDPR-028 · Regulation (EU) 2016/679 — data protection, Article 28

Processor obligations and contracts

Use only processors that provide sufficient guarantees of appropriate technical and organisational measures, governed by a binding contract covering the required terms.

Applicable now
Applies to
Controllers and processors of personal data
Severity if failed
High
Applies from
25 May 2018
Source
GDPR.txt:1675

How this is verified

  • A data processing agreement is on file for every processor and subprocessor, covering the Art 28(3) required terms, with subprocessor changes notified in advance

    DPA completeness against all of Art 28(3)(a)-(h) is a checklist a compliance expert should validate, not something inferred from the contract's existence alone.

Draft — pending expert review

Last verified against primary law 23 Jul 2026

GDPR-030 · Regulation (EU) 2016/679 — data protection, Article 30

Records of processing activities

Maintain a written record of the processing you carry out, covering who you are, why you process, whose data and what kinds, who receives it, any transfers out of the EU, erasure periods where possible, and a general description of your security measures.

Applicable now
Applies to
Controllers and processors of personal data (Art 30(5) exempts organisations under 250 staff only where processing is occasional, low-risk and not of special-category data)
Severity if failed
Medium
Applies from
25 May 2018
Source
GDPR.txt:1739

How this is verified

  • A written record of processing activities exists covering all of Art 30(1)(a)-(g), is kept current, and can be made available to the supervisory authority on request

    Whether the Art 30(5) small-organisation exemption applies is a legal judgement about the entity, not something the platform infers — in practice it rarely holds, because employee data is processed regularly.

Draft — pending expert review

Last verified against primary law 23 Jul 2026

GDPR-033 · Regulation (EU) 2016/679 — data protection, Article 33

Personal data breach notification to the supervisory authority

Notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it — unless the breach is unlikely to result in a risk to individuals' rights and freedoms.

Applicable now
Applies to
Controllers processing personal data (processors must notify controllers without undue delay, Art 33(2))
Severity if failed
Critical
Applies from
25 May 2018
Source
GDPR.txt:1835

How this is verified

  • Breach assessed and notified to the supervisory authority within 72 hours of becoming aware, or a documented reason for delay

    Requires a timestamped incident register capturing time of awareness — not yet built (§3.15 Incident Management is Phase 3 scope).

Draft — pending expert review

Last verified against primary law 23 Jul 2026

GDPR-034 · Regulation (EU) 2016/679 — data protection, Article 34

Personal data breach communication to the data subject

When a personal data breach is likely to result in a high risk to individuals' rights and freedoms, communicate the breach to the affected data subjects without undue delay.

Applicable now
Applies to
Controllers processing personal data
Severity if failed
Critical
Applies from
25 May 2018
Source
GDPR.txt:1865

How this is verified

  • Affected data subjects are notified without undue delay whenever the breach risk assessment concludes 'high risk'

    Art 34(3) lists exemptions (e.g. the data was already encrypted, or a public communication is used instead) — not modelled as separate conditions yet; the risk assessment itself is a manual judgment call pending expert input.

Draft — pending expert review

Last verified against primary law 23 Jul 2026

GDPR-046 · Regulation (EU) 2016/679 — data protection, Article 46

Transfers subject to appropriate safeguards

Where you send personal data outside the EEA to a country with no adequacy decision, you may do so only on an appropriate safeguard — in practice the Commission's standard contractual clauses — with enforceable rights and effective remedies for the people whose data it is, and a documented assessment that the destination's law does not stop the importer honouring those clauses.

Applicable now
Applies to
Controllers and processors transferring personal data to a third country or international organisation without an adequacy decision
Severity if failed
High
Applies from
25 May 2018
Source
GDPR.txt:2285

How this is verified

  • For each transfer with no adequacy decision, the unmodified standard contractual clauses are signed with the correct module, Annexes I to III are completed with real detail, and a Clause 14 transfer impact assessment is documented and kept current

    Whether the safeguard is actually effective in the destination country is a legal judgement about that country's law and practice — the platform can check the assessment exists and covers what Clause 14(b) requires, not whether its conclusion is right.

Draft — pending expert review

Last verified against primary law 23 Jul 2026