← All regulations

Regulation · CELEX 32016R0679

Regulation (EU) 2016/679 — data protection

View official text on EUR-Lex →

3 obligations

GDPR-028 · Regulation (EU) 2016/679 — data protection, Article 28

Processor obligations and contracts

Use only processors that provide sufficient guarantees of appropriate technical and organisational measures, governed by a binding contract covering the required terms.

Applicable now
Applies to
Controllers and processors of personal data
Severity if failed
High
Applies from
25 May 2018
Source
GDPR.txt:1675

How this is verified

  • A data processing agreement is on file for every processor and subprocessor, covering the Art 28(3) required terms, with subprocessor changes notified in advance

    DPA completeness against all of Art 28(3)(a)-(h) is a checklist a compliance expert should validate, not something inferred from the contract's existence alone.

Draft — pending expert review

Last verified against primary law 23 Jul 2026

GDPR-033 · Regulation (EU) 2016/679 — data protection, Article 33

Personal data breach notification to the supervisory authority

Notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it — unless the breach is unlikely to result in a risk to individuals' rights and freedoms.

Applicable now
Applies to
Controllers processing personal data (processors must notify controllers without undue delay, Art 33(2))
Severity if failed
Critical
Applies from
25 May 2018
Source
GDPR.txt:1835

How this is verified

  • Breach assessed and notified to the supervisory authority within 72 hours of becoming aware, or a documented reason for delay

    Requires a timestamped incident register capturing time of awareness — not yet built (§3.15 Incident Management is Phase 3 scope).

Draft — pending expert review

Last verified against primary law 23 Jul 2026

GDPR-034 · Regulation (EU) 2016/679 — data protection, Article 34

Personal data breach communication to the data subject

When a personal data breach is likely to result in a high risk to individuals' rights and freedoms, communicate the breach to the affected data subjects without undue delay.

Applicable now
Applies to
Controllers processing personal data
Severity if failed
Critical
Applies from
25 May 2018
Source
GDPR.txt:1865

How this is verified

  • Affected data subjects are notified without undue delay whenever the breach risk assessment concludes 'high risk'

    Art 34(3) lists exemptions (e.g. the data was already encrypted, or a public communication is used instead) — not modelled as separate conditions yet; the risk assessment itself is a manual judgment call pending expert input.

Draft — pending expert review

Last verified against primary law 23 Jul 2026