Skip to main content

Title III — Obligations of Controllers and Processors

This title sets out the obligations imposed on data controllers and processors.


Chapter 1 — General Obligations

ArticleTitleDescription
Art. 15Responsibility of the ControllerThe controller shall implement appropriate technical and organisational measures to ensure that processing is performed in accordance with this Code and shall be able to demonstrate such compliance.
Art. 16Data Protection by Design and by DefaultTaking into account the state of the art, the cost of implementation, the nature, scope, context, and purposes of processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons posed by the...
Art. 17Records of Processing ActivitiesEach controller shall maintain a record of processing activities under its responsibility. That record shall contain the following information:.
Art. 18Security of ProcessingTaking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller...

Chapter 2 — Data Breach and Impact Assessment

ArticleTitleDescription
Art. 19Notification of Personal Data BreachIn the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than seventy-two hours after having become aware of it, notify the personal data breach to the supervisory authority, unless the...
Art. 20Communication of Breach to Data SubjectsWhen the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.
Art. 21Data Protection Impact AssessmentWhere a type of processing, in particular using new technologies and taking into account the nature, scope, context, and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller...

Chapter 3 — Transfers and Processors

ArticleTitleDescription
Art. 22International Data TransfersThe State of the Kaharagians, having no physical territory, recognises that all personal data processed within its legal order is inherently stored in foreign jurisdictions.
Art. 23Processor ObligationsWhere processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet...