Regulation · CELEX 32016R0679
Regulation (EU) 2016/679 — data protection
View official text on EUR-Lex →3 obligations
GDPR-028 · Regulation (EU) 2016/679 — data protection, Article 28
Processor obligations and contracts
Use only processors that provide sufficient guarantees of appropriate technical and organisational measures, governed by a binding contract covering the required terms.
Applicable now
GDPR-028 · Regulation (EU) 2016/679 — data protection, Article 28
Processor obligations and contracts
Use only processors that provide sufficient guarantees of appropriate technical and organisational measures, governed by a binding contract covering the required terms.
- Applies to
- Controllers and processors of personal data
- Severity if failed
- High
- Applies from
- 25 May 2018
- Source
- GDPR.txt:1675
How this is verified
A data processing agreement is on file for every processor and subprocessor, covering the Art 28(3) required terms, with subprocessor changes notified in advance
DPA completeness against all of Art 28(3)(a)-(h) is a checklist a compliance expert should validate, not something inferred from the contract's existence alone.
Last verified against primary law 23 Jul 2026
GDPR-033 · Regulation (EU) 2016/679 — data protection, Article 33
Personal data breach notification to the supervisory authority
Notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it — unless the breach is unlikely to result in a risk to individuals' rights and freedoms.
Applicable now
GDPR-033 · Regulation (EU) 2016/679 — data protection, Article 33
Personal data breach notification to the supervisory authority
Notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it — unless the breach is unlikely to result in a risk to individuals' rights and freedoms.
- Applies to
- Controllers processing personal data (processors must notify controllers without undue delay, Art 33(2))
- Severity if failed
- Critical
- Applies from
- 25 May 2018
- Source
- GDPR.txt:1835
How this is verified
Breach assessed and notified to the supervisory authority within 72 hours of becoming aware, or a documented reason for delay
Requires a timestamped incident register capturing time of awareness — not yet built (§3.15 Incident Management is Phase 3 scope).
Last verified against primary law 23 Jul 2026
GDPR-034 · Regulation (EU) 2016/679 — data protection, Article 34
Personal data breach communication to the data subject
When a personal data breach is likely to result in a high risk to individuals' rights and freedoms, communicate the breach to the affected data subjects without undue delay.
Applicable now
GDPR-034 · Regulation (EU) 2016/679 — data protection, Article 34
Personal data breach communication to the data subject
When a personal data breach is likely to result in a high risk to individuals' rights and freedoms, communicate the breach to the affected data subjects without undue delay.
- Applies to
- Controllers processing personal data
- Severity if failed
- Critical
- Applies from
- 25 May 2018
- Source
- GDPR.txt:1865
How this is verified
Affected data subjects are notified without undue delay whenever the breach risk assessment concludes 'high risk'
Art 34(3) lists exemptions (e.g. the data was already encrypted, or a public communication is used instead) — not modelled as separate conditions yet; the risk assessment itself is a manual judgment call pending expert input.
Last verified against primary law 23 Jul 2026