SkarpSkarp

Chapter 11 of 16

Operational Accountability: Records, Security, DPIAs, and DPOs

Articles 29–39 supply the operational machinery for controlled processing, auditability, secure systems, breach response, high-risk review, and independent compliance advice. The module follows a processing operation from authorised access through incident management and prior regulatory consultation.

25 min readen

Article 29: Start with authorised instructions

Who Article 29 covers

Article 29 covers a processor and any person acting under the authority of a controller or processor who has access to personal data.

The mandatory boundary

They "shall not process those data except on instructions from the controller". Technical access is not a free-standing right to use data.

The stated exception

The restriction has one stated exception: processing may occur where Union or Member State law requires it.

Operational meaning

Use instructions that staff can follow: defined roles, approved workflows, access controls, training, and an escalation path for unusual requests.

Articles 30-31: Make processing auditable

Controller record: Article 30(1)

A controller "shall maintain a record of processing activities under its responsibility." It maps parties, purposes, data, recipients, transfers, erasure limits, and security.

Processor record: Article 30(2)

A processor records categories of processing performed for each controller, relevant parties, applicable transfers and safeguards, and, where possible, a general security description.

Format and availability

Records must be in writing, including electronic form. They must be made available to the supervisory authority on request.

The fewer-than-250 rule

The Article 30(5) limitation applies to "an enterprise or an organisation employing fewer than 250 persons" only unless one of its listed risk, regularity, or data-category conditions applies.

Article 31

Controllers, processors, and applicable representatives "shall cooperate, on request, with the supervisory authority in the performance of its tasks."

Article 32: Build security around risk

A risk-based security standard

Article 32 requires "appropriate technical and organisational measures to ensure a level of security appropriate to the risk" after considering context, purposes, costs, state of the art, and risk.

Examples, not a universal checklist

Measures include, as appropriate, pseudonymisation, encryption, resilient systems, timely restoration after incidents, and regular testing and evaluation.

Risks Article 32 highlights

Consider destruction, loss, alteration, unauthorised disclosure, and unauthorised access affecting personal data transmitted, stored, or otherwise processed.

Codes and certification

An approved Article 40 code or Article 42 certification mechanism may be an element used to demonstrate compliance with Article 32(1).

People are part of security

Article 32(4) requires steps ensuring that people under controller or processor authority process accessed data only on controller instructions, subject to the legal exception.

Checkpoint: Records and security

Choose the answer that preserves Article 30(5)'s conditions exactly.

Which statement best reflects Article 30(5) as currently applicable on July 25, 2026?

  1. Every organisation employing fewer than 250 persons is exempt from Article 30 records.
  2. The Article 30 record obligations do not apply to an organisation employing fewer than 250 persons unless its processing is likely to create risk, is not occasional, or includes the listed Article 9(1) or Article 10 data.
  3. Only processors employing 250 or more persons must keep records.
  4. An approved code of conduct removes the need for Article 30 records.
Show Answer

Answer: B) The Article 30 record obligations do not apply to an organisation employing fewer than 250 persons unless its processing is likely to create risk, is not occasional, or includes the listed Article 9(1) or Article 10 data.

Article 30(5) is conditional. The fewer-than-250 limitation does not apply where processing is likely to result in risk to rights and freedoms, is not occasional, or includes Article 9(1) special-category data or Article 10 criminal-conviction-and-offence data. The proposed COM(2025) 501 change is not in force.

Articles 33-34: Respond to a personal data breach

Processor first

Once aware of a breach, "The processor shall notify the controller without undue delay after becoming aware of a personal data breach."

Controller-to-authority threshold

The controller notifies unless the breach is unlikely to result in a risk. The deadline is "without undue delay and, where feasible, not later than 72 hours after having become aware of it".

What the authority notification contains

Describe the breach, affected categories and approximate numbers where possible, contact point, likely consequences, and measures taken or proposed. Phased information is allowed where necessary.

When individuals must hear

Where a breach is likely to result in high risk, "the controller shall communicate the personal data breach to the data subject without undue delay."

Three Article 34(3) conditions

No individual communication is required if listed protection made data unintelligible, subsequent measures remove likely high risk, or disproportionate effort is replaced with equally effective public communication.

Article 35: Decide whether a DPIA is needed

The Article 35 trigger

Where processing "is likely to result in a high risk to the rights and freedoms of natural persons", "the controller shall, prior to the processing, carry out an assessment".

Three cases specifically named

A DPIA is in particular required for significant automated evaluation or profiling, large-scale Article 9 or Article 10 processing, and "a systematic monitoring of a publicly accessible area on a large scale."

Minimum DPIA contents

Describe operations and purposes; assess necessity and proportionality; assess risks; and identify safeguards, security measures, and mechanisms that address risks and demonstrate compliance.

Lists, consultation, and review

Authorities publish required-DPIA lists and may publish no-DPIA lists. Seek DPO advice where designated; seek data-subject views where appropriate; review where necessary, at least when risk changes.

Do not overread the examples

Article 35(3)'s listed cases are cases where a DPIA is in particular required. The broader Article 35(1) high-risk trigger remains the starting point.

Article 36: Escalate unresolved high risk

The consultation trigger

"The controller shall consult the supervisory authority prior to processing" where the Article 35 DPIA indicates high risk without controller measures to mitigate that risk.

What the controller supplies

Provide relevant roles, purposes and means, safeguards, DPO contact details where applicable, the DPIA, and any other information requested by the authority.

Authority response time

Where it considers the intended processing would infringe the Regulation, the authority provides written advice "within period of up to eight weeks of receipt of the request for consultation".

Extensions and suspension

The period may be extended by six weeks for complexity. The authority must notify an extension within one month, and time may be suspended while requested information is outstanding.

Articles 37-38: Designate and protect the DPO

When designation is mandatory

"The controller and the processor shall designate a data protection officer" for listed public bodies, large-scale regular and systematic monitoring, and listed large-scale sensitive or criminal-data core activities.

Flexible organisational arrangements

One DPO may serve a group if easily accessible from each establishment. One may also serve several public bodies, considering their structure and size.

Professional basis

The DPO is chosen for professional qualities, especially "expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39."

Independence and protection

The DPO receives no instructions on those tasks, cannot be dismissed or penalised for performing them, and directly reports to the organisation's highest management level.

Resources and conflicts

Controllers and processors must provide resources, access, and support for expertise. Additional DPO duties are allowed only where they do not result in a conflict of interests.

Article 39: Turn the DPO into a compliance function

Inform, advise, and monitor

The DPO informs and advises the organisation and processing employees, then monitors compliance, policies, responsibility assignments, awareness, training, and related audits.

DPIAs

The DPO provides advice where requested on Article 35 DPIAs and monitors their performance. Article 35(2) separately requires the controller to seek DPO advice where designated.

Authority-facing tasks

The DPO cooperates with the supervisory authority and acts as its contact point, including for Article 36 prior consultation and, where appropriate, other matters.

Risk-aware performance

In performing tasks, the DPO shall have due regard to processing risk, taking account of nature, scope, context, and purposes.

Checkpoint: DPIA, consultation, and DPOs

Apply the triggers and roles in Articles 35-39.

A controller's Article 35 DPIA indicates that intended processing would result in high risk if the controller's planned measures do not mitigate that risk. What does Article 36(1) require?

  1. The controller may begin processing and notify the authority within 72 hours.
  2. The controller shall consult the supervisory authority prior to processing.
  3. The processor alone must seek approval from the DPO.
  4. The controller must communicate the DPIA to every data subject.
Show Answer

Answer: B) The controller shall consult the supervisory authority prior to processing.

Article 36(1) says that the controller shall consult the supervisory authority prior to processing where an Article 35 DPIA indicates high risk in the absence of controller measures to mitigate the risk. The 72-hour rule belongs to Article 33 breach notification, not Article 36.

Flashcards: Operational accountability essentials

Flip each card, then explain the condition or qualifier aloud before moving on.

Article 29 instruction rule
A processor and a person acting under controller or processor authority with access to personal data **"shall not process those data except on instructions from the controller"**, unless Union or Member State law requires it.
Article 30 controller record
Each controller and, where applicable, its representative **"shall maintain a record of processing activities under its responsibility."**
Article 30 small-organisation condition
The limitation concerns **"an enterprise or an organisation employing fewer than 250 persons"**, but does not apply where listed risk, non-occasional-processing, or sensitive/criminal-data conditions are present.
Article 32 security standard
Controllers and processors shall implement **"appropriate technical and organisational measures to ensure a level of security appropriate to the risk."**
Article 33 deadline
A controller notifies the authority **"without undue delay and, where feasible, not later than 72 hours after having become aware of it"**, unless the breach is unlikely to result in a risk.
Article 34 individual communication trigger
Where a breach is likely to result in high risk, **"the controller shall communicate the personal data breach to the data subject without undue delay."**
Article 35 DPIA trigger and timing
Where processing **"is likely to result in a high risk to the rights and freedoms of natural persons"**, **"the controller shall, prior to the processing, carry out an assessment"**.
Article 36 consultation
**"The controller shall consult the supervisory authority prior to processing"** where the DPIA indicates high risk in the absence of controller mitigation measures.
Article 38 DPO independence
The controller and processor shall ensure **"the data protection officer does not receive any instructions regarding the exercise of those tasks."** The DPO directly reports to the highest management level.

Key Terms

DPIA
A data protection impact assessment under Article 35: an assessment carried out before processing where the Article 35(1) high-risk trigger applies.
high risk
The threshold used in Articles 34, 35, and 36. It is distinct from the Article 33(1) supervisory-authority notification exception, which turns on whether a breach is unlikely to result in a risk.
processor
The party that carries out processing on behalf of a controller and has its own Article 30 record duty, Article 32 security duty, Article 33(2) breach-notification duty to the controller, and possible DPO-designation duty.
controller
The party referred to throughout Articles 29-39 as responsible for key decisions and duties, including maintaining its Article 30 record, implementing Article 32 measures, notifying breaches under Article 33, and carrying out DPIAs under Article 35.
prior consultation
The Article 36 process in which the controller consults the supervisory authority before processing where a DPIA indicates high risk in the absence of controller mitigation measures.
personal data breach
The event addressed by Articles 33 and 34. Article 33 requires documentation of facts, effects, and remedial action for every such breach.
supervisory authority
The authority with which controllers and processors must cooperate on request under Article 31, which receives relevant breach notifications, publishes DPIA lists, and is consulted under Article 36 where its conditions are met.
data protection officer
The DPO designated in the Article 37 cases, supported and protected under Article 38, and assigned at least the tasks listed in Article 39.
special categories of data
The categories referred to in Article 9(1), relevant in Articles 30(5), 35(3)(b), and 37(1)(c).

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself