SkarpSkarp

Chapter 10 of 16

Individual Control and the Controller's Organisational Duties

The GDPR gives individuals tools to correct, remove, contain, move, or contest data processing, then places corresponding organisational responsibilities on those deciding how processing occurs. This module links rights under Articles 16–23 with design, joint control, representation, and processor contracting under Articles 24–28.

26 min readen

1. The architecture: individual control meets organisational responsibility

A linked system

Articles 16-22 give the data subject tools to influence processing. Articles 24-28 require controllers to build organisational arrangements that make lawful processing and rights responses possible.

The practical chain

A request is not merely a customer-service event. It can trigger a controller duty to correct, erase, restrict, notify recipients, provide data, stop processing, or provide safeguards.

Read conditions precisely

The GDPR attaches triggers and limits to rights. Study each Article's exact ground, exception, timing language, and party responsible rather than treating rights as unconditional.

2. Articles 16-17: correct data, then assess erasure

Rectification

Article 16 gives a right to obtain without undue delay the rectification of inaccurate personal data concerning him or her. Incomplete data may be completed, including with a supplementary statement.

Six Article 17(1) grounds

Erasure is triggered by no-longer-needed data, withdrawn consent with no other ground, qualifying objection, unlawful processing, a legal obligation to erase, or Article 8(1) information-society-service collection.

Public disclosure is different

A controller that made data public and is obliged to erase must take reasonable steps, including technical measures, to inform other controllers of requested erasure of links, copies, or replications.

Erasure has stated exceptions

Article 17(3) limits paragraphs 1 and 2 only to the extent processing is necessary for listed interests, including expression, legal duties, public health, research, and legal claims.

3. Articles 18-20: contain processing, notify recipients, and move data

Restriction: four triggers

Article 18 applies to contested accuracy, unlawful processing where erasure is opposed, data needed for legal claims after the controller no longer needs them, and a pending Article 21(1) objection.

What restriction permits

After restriction, storage remains possible. Other processing is limited to consent, legal claims, another person's rights, or important Union or Member State public interest.

Recipient notification

Article 19 requires communication to each recipient of rectification, Article 17(1) erasure, or restriction unless impossible or disproportionate. Requested recipient information must be provided to the data subject.

Portability conditions

Article 20 requires data provided by the person, a consent-or-contract legal basis, and automated processing. Direct controller-to-controller transmission applies where technically feasible.

4. Article 21: objection is context-specific, and marketing has a decisive rule

General objection

Article 21(1) concerns Article 6(1)(e) or (f) processing, including associated profiling. The objection must be on grounds relating to the person's particular situation.

Controller response

Following an Article 21(1) objection, processing stops unless the controller demonstrates compelling overriding legitimate grounds or a need for legal claims.

Marketing objection

For direct marketing, objection may occur at any time and includes related profiling. Once the person objects, personal data shall no longer be processed for those marketing purposes.

Visibility and research

The controller must clearly and separately highlight objection rights by the first communication. Research and statistics objections have a stated public-interest-task exception.

5. Article 22: solely automated decisions and required safeguards

When Article 22 applies

The baseline right concerns a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects the individual.

Three stated exceptions

Article 22(2) lists contractual necessity, authorisation by applicable Union or Member State law with safeguards, and the data subject's explicit consent.

Minimum safeguards

For contractual necessity and explicit consent, safeguards must include at least human intervention, the opportunity to express a point of view, and the ability to contest the decision.

Currency check

A November 19, 2025 Digital Omnibus proposal would affect Article 22, but it remains proposed as of July 25, 2026. The GDPR wording in this lesson remains current law.

6. Article 23: rights may be legislatively restricted only within a structured test

Who may restrict rights?

Article 23 permits restrictions only through a Union or Member State legislative measure to which the controller or processor is subject. A controller's internal policy is not such a measure.

The legal test

A restriction must respect the essence of fundamental rights and freedoms and be necessary and proportionate in a democratic society for one of Article 23(1)'s listed objectives.

Listed protected interests

The list includes national security, defence, public security, criminal-law purposes, important public interests, judicial proceedings, regulatory functions, others' rights, and civil claims.

Specific safeguards

Article 23(2) requires relevant specific provisions, including the safeguards to prevent abuse or unlawful access or transfer, storage rules, risks, and information rights.

7. Articles 24-25: accountability, design, and default settings

Article 24 accountability

The controller must implement appropriate technical and organisational measures both to ensure compliance and to demonstrate it, with measures reviewed and updated where necessary.

Proportionate policies

Where proportionate, Article 24 requires appropriate data-protection policies. Approved codes of conduct and certification may be elements used to demonstrate compliance.

Design stage and operation

Article 25 applies when deciding processing means and while processing occurs. Pseudonymisation is an example of a measure designed to implement principles such as data minimisation.

Default settings

By default, only data necessary for each specific purpose may be processed. The duty reaches collection, use, storage, accessibility, and indefinite public accessibility.

8. Articles 26-27: shared decisions and representation in the Union

Joint determination

Joint controller status follows where two or more controllers jointly determine purposes and means. Article 26 requires a transparent allocation arrangement, subject to applicable Union or Member State law.

Rights remain usable

The arrangement's essence must be available to data subjects. Regardless of its terms, a data subject may exercise GDPR rights in respect of and against each joint controller.

Written Union representative

Where Article 3(2) applies, a non-Union controller or processor shall designate a representative in writing in the Union, subject to Article 27(2)'s detailed exceptions.

The representative's role

The representative may be addressed by supervisory authorities and data subjects on processing issues, but designation does not shield the controller or processor from legal action.

9. Article 28: choosing and controlling processors

Select for sufficient guarantees

Article 28 starts with controller selection: only processors providing sufficient guarantees of appropriate technical and organisational measures may be used for processing on the controller's behalf.

Sub-processors need authorisation

Another processor needs prior specific or general written authorisation. General authorisation still requires notice of intended additions or replacements and an opportunity for the controller to object.

The Article 28(3) contract

A binding contract or legal act must define the processing and require instruction-only processing, confidentiality, security measures, rights assistance, compliance assistance, deletion or return, and audit cooperation.

Liability and role change

Sub-processors must bear the same obligations, while the initial processor remains fully liable to the controller. A processor determining purposes and means becomes a controller for that processing.

10. Flashcards: exact triggers and consequences

Flip each card, state the rule aloud, then identify the Article that supplies it.

Article 16: What can the data subject obtain?
Without undue delay, **the rectification of inaccurate personal data concerning him or her.** Incomplete data may also be completed, including by a supplementary statement, taking account of processing purposes.
Article 17: When does the controller's erasure duty arise?
Where one Article 17(1) ground applies: no longer necessary, qualifying consent withdrawal, qualifying objection, unlawful processing, legal obligation, or specified Article 8(1) collection.
Article 18: Does restriction mean no processing whatsoever?
No. Storage is excepted. Other processing is limited to consent, legal claims, protection of another person's rights, or important Union or Member State public interest.
Article 20: What two conditions are required for portability?
Processing must be based on the specified consent or contract grounds, and it must be carried out by automated means. The data also concern the person and were provided by that person.
Article 21: What follows from an objection to direct marketing?
**Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.**
Article 22: Name the minimum safeguards in contract and explicit-consent cases.
At least human intervention by the controller, an opportunity to express a point of view, and an opportunity to contest the decision.
Article 25: What does data protection by default require?
By default, only personal data necessary for each specific purpose are processed, covering amount, extent, storage period, and accessibility.
Article 28: What happens if a processor determines purposes and means?
If it does so in infringement of the GDPR, the processor shall be considered a controller in respect of that processing.

11. Quiz: restriction, erasure, and portability

Choose the most accurate answer under Articles 17, 18, and 20.

A data subject contests the accuracy of an account record. Which statement most closely reflects Article 18(1)(a)?

  1. The controller must erase the record immediately in every case.
  2. The data subject may obtain restriction for a period enabling the controller to verify the accuracy of the personal data.
  3. The data subject automatically obtains portability, whether or not processing is automated.
  4. The controller may continue every form of processing without limitation while it investigates.
Show Answer

Answer: B) The data subject may obtain restriction for a period enabling the controller to verify the accuracy of the personal data.

Article 18(1)(a) provides restriction where accuracy is contested, for the period enabling the controller to verify accuracy. It does not make erasure automatic. Article 20 portability has separate conditions, including automated processing and a specified legal basis.

12. Quiz: controllers, processors, and automated decisions

Choose the answer that preserves the GDPR's exact allocation of responsibility.

Which statement is correct under Articles 22, 26, and 28?

  1. A joint-controller arrangement prevents a data subject from bringing rights requests against one of the joint controllers.
  2. A processor may appoint any sub-processor without telling the controller if the processor believes it is secure.
  3. In Article 22(2)(a) and (c) cases, the controller shall implement suitable safeguards including at least human intervention, expression of view, and contesting the decision.
  4. A processor that determines processing purposes and means always remains only a processor.
Show Answer

Answer: C) In Article 22(2)(a) and (c) cases, the controller shall implement suitable safeguards including at least human intervention, expression of view, and contesting the decision.

Article 22(3) expressly requires those minimum safeguards in the contractual-necessity and explicit-consent cases. Article 26(3) preserves rights against each joint controller. Article 28(2) requires prior written authorisation for another processor, and Article 28(10) treats a processor that determines purposes and means in infringement as a controller for that processing.

Key Terms

erasure
Deletion of personal data where an Article 17(1) ground applies, subject to Article 17(3)'s necessity-based exceptions.
processor
A party carrying out processing on behalf of a controller, subject to Article 28's selection, instruction, contract, confidentiality, assistance, audit, and sub-processor rules.
profiling
A form of processing expressly included in Article 21 objections when based on Article 6(1)(e) or (f), and in Article 22's rule on decisions based solely on automated processing.
controller
The party to whom the GDPR assigns central responsibility for responding to many data-subject rights and for the accountability, design, and processor duties in Articles 24 to 28.
data subject
The natural person whose personal data are being processed and who holds the rights described in Articles 16 to 22.
rectification
Correction of inaccurate personal data and, taking account of processing purposes, completion of incomplete personal data.
sub-processor
Another processor engaged by a processor for specific processing activities on the controller's behalf, subject to Article 28(2) and (4).
data portability
The Article 20 right to receive personal data provided by the data subject in a structured, commonly used and machine-readable format and to transmit them to another controller, where stated conditions apply.
joint controllers
Two or more controllers that jointly determine the purposes and means of processing.
Union representative
A representative designated in writing in the Union where Article 3(2) applies, subject to the Article 27(2) exceptions.
data protection by design
Article 25(1)'s requirement to implement appropriate technical and organisational measures at the determination-of-means stage and during processing to implement principles and safeguards effectively.
restriction of processing
A containment measure under Article 18. Following restriction, storage remains possible, but other processing is allowed only in the specified circumstances.
data protection by default
Article 25(2)'s requirement that only personal data necessary for each specific purpose are processed by default.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself