Chapter 4 of 16
Accountability in Practice: Risk, Security, Breaches, and Governance
Compliance is not merely a claim; the controller must select, implement, document, and be able to demonstrate appropriate measures. These recitals build the GDPR's risk-based governance model and follow it through security incidents, impact assessments, data protection officers, codes, and certification.
1. Accountability Starts with Demonstrable Responsibility
Accountability is demonstrable
Recital (74) says responsibility and liability of the controller should be established for processing done by the controller or on its behalf.
"the controller should be obliged to implement appropriate and effective measures and be able to demonstrate the compliance of processing activities with this Regulation"
Appropriate depends on context
Measures should reflect the processing's nature, scope, context, purposes, and risks to rights and freedoms.
What can make risk serious?
Recital (75) lists harms such as discrimination, identity theft, financial loss, reputational damage, loss of confidentiality, profiling, vulnerable persons' data, and large-scale processing.
Risk versus high risk
"Risk should be evaluated on the basis of an objective assessment, by which it is established whether data processing operations involve a risk or a high risk."
2. Turning Risk Assessment into Accountability Decisions
Scenario
A university wellbeing platform stores stress and health-related information, appointment notes, and engagement data. It flags students who may need support.
Risk indicators from Recital (75)
Relevant indicators include health data, evaluation or prediction of personal aspects, potentially vulnerable data subjects, and processing affecting many students.
Use an objective assessment
Do not label risk only from the beneficial purpose or only from one data category. Assess nature, scope, context, purposes, likelihood, and severity.
Show the measures
Accountability means being able to demonstrate decisions and measures: restricted access, correction routes, retention choices, and limits on secondary use.
3. Governance by Design, Clear Roles, and Trusted Processors
Sources of practical guidance
Recital (77) says approved codes, certifications, Board guidelines, and a data protection officer's indications could help identify, assess, and mitigate risk.
Design and default
"the controller should adopt internal policies and implement measures which meet in particular the principles of data protection by design and data protection by default."
Recital (78) examples include minimisation, pseudonymisation as soon as possible, functional transparency, user monitoring, and improved security features.
Clear allocation
Recital (79) calls for clear responsibilities, including joint controllers and processing carried out on behalf of a controller.
Processor governance and records
Recitals (81)-(82) address sufficient processor guarantees, a binding processing arrangement, return or deletion after processing where applicable, records, and cooperation with supervisory authorities.
4. Security: Match Safeguards to Processing Risk
The Recital (83) sequence
Evaluate risks inherent in processing, then implement measures to mitigate them. Encryption is an example of a possible measure.
Appropriate security is contextual
Security should include confidentiality and should account for the state of the art, implementation costs, risks, and the nature of the personal data.
The threat list
Consider accidental or unlawful destruction, loss, alteration, unauthorised disclosure, and unauthorised access to transmitted, stored, or otherwise processed data.
Security is broader than encryption
Encryption can help with confidentiality. It does not alone solve every problem, including accidental deletion, improper changes, or overly broad access.
5. DPIAs and Prior Consultation: Act Before High-Risk Processing
When a DPIA is in view
Recital (84) addresses processing likely to result in a high risk to rights and freedoms.
"the controller should be responsible for the carrying-out of a data protection impact assessment to evaluate, in particular, the origin, nature, particularity and severity of that risk."
What the DPIA informs
Its outcome should be taken into account when selecting measures to demonstrate compliant processing.
Residual high risk
If high risk cannot be mitigated by appropriate measures in light of available technology and implementation costs, supervisory-authority consultation should occur before processing.
Before, not after
Recital (90) says the DPIA should be carried out prior to processing and should include proposed safeguards and mechanisms for mitigation, protection, and demonstration of compliance.
External currency note
The Digital Omnibus proposal, COM(2025) 837 final of November 19, 2025, is not in force as of July 25, 2026. Existing GDPR requirements remain applicable.
6. DPIA Triggers in Practice: Large-Scale Monitoring and Profiling
City-camera scenario
A transport authority uses networked optic-electronic cameras across stations and generates travel-pattern alerts for review.
"A data protection impact assessment is equally required for monitoring publicly accessible areas on a large scale"
Other Recital (91) signals
Systematic and extensive profiling for decisions about individuals, certain sensitive-data processing, large-scale operations, and operations impairing rights or services are all identified.
Keep the exception precise
Patients or clients of an individual physician, other healthcare professional, or lawyer should not be considered large-scale processing; in such cases a DPIA should not be mandatory.
Residual risk means consultation
Under Recital (94), inability to mitigate high risk by reasonable means, considering available technologies and costs, points to consultation before processing starts.
7. Personal Data Breaches: Notify, Communicate, and Document the Reasoning
Start with awareness
Recital (85) concerns what happens as soon as a controller becomes aware that a personal data breach has occurred.
Notify without undue delay and, "where feasible, not later than 72 hours after having become aware of it".
Do not omit the exception
No notification is needed where the controller can demonstrate, under accountability, that the breach is unlikely to result in a risk to rights and freedoms.
A different threshold for communication
"The controller should communicate to the data subject a personal data breach, without undue delay, where that personal data breach is likely to result in a high risk to the rights and freedoms of the natural person"
Communicate useful information
The communication should describe the breach's nature and give recommendations for mitigating potential adverse effects.
External currency note
COM(2025) 837 final proposes a 96-hour, high-risk notification model, but remains proposed as of July 25, 2026. The existing 72-hour GDPR rule remains applicable.
8. DPOs, Codes of Conduct, and Certification
When expert assistance is identified
Recital (97) covers public authorities with stated exceptions, large-scale regular and systematic monitoring as a core activity, and large-scale sensitive or criminal-data processing as a core activity.
Core does not mean ancillary
For private-sector controllers, core activities are primary activities and do not include merely ancillary personal-data processing.
"Such data protection officers, whether or not they are an employee of the controller, should be in a position to perform their duties and tasks in an independent manner."
Codes of conduct
Associations and representative bodies should be encouraged to create codes that facilitate effective application and can calibrate obligations to likely risk.
Certification
"the establishment of certification mechanisms and data protection seals and marks should be encouraged" so people can quickly assess protection levels.
9. Quiz: Breach Thresholds and Timing
Choose the best answer
A controller discovers a breach on Monday. Its documented, objective assessment supports the conclusion that the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Which answer most accurately reflects Recital (85)?
Which answer is correct?
- The controller should always notify the supervisory authority within exactly 72 hours, regardless of risk.
- The controller should notify without undue delay and, where feasible, no later than 72 hours after awareness, unless it can demonstrate under accountability that the breach is unlikely to result in a risk to rights and freedoms.
- The controller may wait until all technical investigation is complete, because phased notification is never permitted.
- The controller must communicate with every data subject whenever any breach occurs.
Show Answer
Answer: B) The controller should notify without undue delay and, where feasible, no later than 72 hours after awareness, unless it can demonstrate under accountability that the breach is unlikely to result in a risk to rights and freedoms.
Recital (85) preserves both the risk-based exception and the phrase "where feasible, not later than 72 hours after having become aware of it." If notification is delayed beyond 72 hours, reasons should accompany it, and information may be provided in phases without undue further delay. Recital (86) uses a separate high-risk threshold for communication to data subjects.
10. Flashcards: Governance Vocabulary
Flip each card and recall the Recital-based rule.
- Accountability in Recital (74)
- The controller should implement appropriate and effective measures and be able to demonstrate compliance, considering nature, scope, context, purposes, and risk.
- Objective risk evaluation
- Recital (76): assess whether processing involves a risk or a high risk by reference to its nature, scope, context, and purposes.
- Data protection by design and by default
- Recital (78): the controller should adopt internal policies and implement measures meeting these principles; examples include minimisation and pseudonymisation as soon as possible.
- DPIA
- Recital (84): for processing likely to result in high risk, the controller should carry out a DPIA evaluating the origin, nature, particularity, and severity of risk.
- Large-scale public monitoring
- Recital (91): a DPIA is equally required for monitoring publicly accessible areas on a large scale, especially with optic-electronic devices.
- Breach notification
- Recital (85): notify without undue delay and, where feasible, no later than 72 hours after awareness, unless the breach is unlikely to result in a risk.
- Breach communication to data subjects
- Recital (86): communicate without undue delay where the breach is likely to result in a high risk to the rights and freedoms of the natural person.
- DPO independence
- Recital (97): DPOs, whether or not employees, should be able to perform duties and tasks independently.
- Certification
- Recital (100): certification mechanisms and data protection seals and marks should be encouraged to improve transparency and compliance.
11. Quiz: Identify the Best DPIA Analysis
Apply Recital (91) carefully
A single lawyer keeps client files for a limited personal practice. Separately, a transport authority plans a city-wide system of optic-electronic monitoring in publicly accessible stations. Which answer best preserves the wording and qualifications of Recital (91)?
Which analysis is most accurate?
- Both activities are automatically large-scale because both concern personal data.
- The lawyer's client files should not be considered large-scale in the stated individual-practice situation, and a DPIA should not be mandatory in such cases; monitoring publicly accessible areas on a large scale equally requires a DPIA.
- Only processing special categories of personal data can require a DPIA.
- A DPIA is required only after an actual breach occurs.
Show Answer
Answer: B) The lawyer's client files should not be considered large-scale in the stated individual-practice situation, and a DPIA should not be mandatory in such cases; monitoring publicly accessible areas on a large scale equally requires a DPIA.
Recital (91) expressly states that processing patients' or clients' data by an individual physician, other healthcare professional, or lawyer should not be considered large scale and that a DPIA should not be mandatory in such cases. The same recital states that a DPIA is equally required for monitoring publicly accessible areas on a large scale, especially when optic-electronic devices are used.
Key Terms
- risk
- A possible effect on rights and freedoms whose likelihood and severity should be assessed objectively by reference to processing's nature, scope, context, and purposes.
- high risk
- The higher-risk category relevant to DPIAs, prior consultation, and communication of a breach to data subjects under the recitals covered in this module.
- processor
- An actor that may carry out processing on behalf of a controller; Recital (81) addresses sufficient guarantees and a binding contract or other legal act.
- controller
- The actor whose responsibility and liability Recital (74) addresses for processing carried out by the controller or on the controller's behalf.
- accountability
- In Recital (74), the controller should implement appropriate and effective measures and be able to demonstrate compliance of processing activities with the GDPR.
- code of conduct
- A sectoral instrument that associations or representative bodies should be encouraged to draw up within GDPR limits to facilitate effective application.
- pseudonymisation
- A measure Recital (78) identifies as an example of a measure that could support data protection by design and by default; Recitals (75) and (85) identify unauthorised reversal as a possible harm.
- prior consultation
- Consultation with the supervisory authority before processing where a DPIA identifies high risk that the controller cannot mitigate by appropriate measures under the conditions described in Recitals (84) and (94).
- personal data breach
- An event addressed in Recitals (85)-(88), for which notification and, where high risk exists, communication to affected data subjects are discussed.
- certification mechanism
- A mechanism, seal, or mark that Recital (100) says should be encouraged to improve transparency and compliance.
- data protection officer
- A person with expert knowledge of data protection law and practices who should assist with monitoring internal compliance in the Recital (97) situations and should be able to act independently.
- data protection impact assessment
- An assessment for processing likely to result in high risk that evaluates, in particular, the origin, nature, particularity, and severity of risk.