Article 24: Responsibility of the controller
Praxikon tracks Article 24 (Responsibility of the controller) under the GDPR, alongside the EU AI Act, citing the source for every statement.
What does Article 24 govern?
Article 24 places the core of accountability with the controller: you must implement appropriate technical and organisational measures to comply with the GDPR and to be able to demonstrate that you do (paragraph 1). Which measures are appropriate depends on the nature, scope, context and purposes of the processing and on the risk to people's rights and freedoms (paragraph 1, recital 76). Those measures are not a one-off: you review them and update them where necessary (paragraph 1). Where proportionate to the processing, this includes a data protection policy (paragraph 2). The article exists because the GDPR asks not only that you follow the rules, but also that you can show you follow them and that your measures are effective (recital 74).
Key term: Accountability: you must not only comply with the rules but also be able to demonstrate, through measures and documentation, that you do
Directly affects:controller
Praxikon’s reading of the text and the recitals; the official text below prevails.
Official text
Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.
What does this mean for you?
Controller
For each processing operation, record the risks to the people concerned and the technical and organisational measures you have taken to address them (paragraph 1). Schedule a fixed moment to review and update those measures (paragraph 1). Adopt a data protection policy where the scale of your processing justifies it (paragraph 2); adherence to an approved code of conduct (Article 40) or an approved certification mechanism (Article 42) can be one of the elements by which you demonstrate compliance (paragraph 3).
Data Protection Officer
The article does not mention you, but recital 77 treats your indications as one of the sources the controller can use to determine appropriate measures and demonstrate compliance. You can therefore actively guide the risk assessment and the periodic review of measures (paragraph 1).
Compliance checklist
Related recitals
The responsibility and liability of the controller for any processing of personal data carried out by the controller or on the controller's behalf should be established. In particular, the controller ...
(75)The risk to the rights and freedoms of natural persons, of varying likelihood and severity, may result from personal data processing which could lead to physical, material or non-material damage, in p...
(76)The likelihood and severity of the risk to the rights and freedoms of the data subject should be determined by reference to the nature, scope, context and purposes of the processing. Risk should be ev...
(77)Guidance on the implementation of appropriate measures and on the demonstration of compliance by the controller or the processor, especially as regards the identification of the risk related to the pr...
Cross-references
Frequently asked questions
Connections
What connects to Article 24 GDPR
Themes where this returns
The counterpart in the other law
Case law
- Russmedia: an online marketplace operator is controller for personal data in adverts and must check before publication
2025-12-02 · final, Hof van Justitie van de EU (Grote kamer), X tegen Russmedia Digital SRL en Inform Media Press SRL
Guidelines
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default
2020-10-20 · final, European Data Protection Board (EDPB)