GDPR
Chapter IV - Controller and Processor

GDPR GDPR-Art.24: Responsibility of the controller

Implement appropriate technical and organisational measures to ensure, and to be able to demonstrate, that processing is performed in accordance with the Regulation, taking into account the nature, scope, context and purposes of processing and the risks of varying likelihood and severity for the rights and freedoms of natural persons. Review and update those measures where necessary. Where proportionate in relation to the processing activities, the measures must include implementing appropriate data protection policies. Adherence to an approved code of conduct or an approved certification mechanism may be used as one element by which to demonstrate compliance, not as a substitute for it.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 86 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 6 controls

  • 5.2.4 Information security management system
  • 5.3.2 Policy
  • 5.4.1 Actions to address risks and opportunities
  • 5.6.1 Operational planning and control
  • 6.15.1 Compliance with legal and contractual requirements
  • 6.2.1 Management direction for information security

NIST SP 800-53 Rev 5 · 5 controls

  • NIST800-PM-18 Privacy Program Plan. Develop and disseminate an organization-wide privacy program plan that provides an overview of the agency's privacy program, and: Includes a description of the structure of the privacy program and the resources
  • NIST800-PM-19 Privacy Program Leadership Role. Appoint a senior agency official for privacy with the authority, mission, accountability, and resources to coordinate, develop, and implement, applicable privacy requirements and manage privacy risks through the organization-wide privacy
  • NIST800-PM-23 Data Governance Body. Establish a Data Governance Body consisting of [organization-defined] with [organization-defined]
  • NIST800-PM-27 Privacy Reporting. Develop [organization-defined] and disseminate to: [organization-defined] to demonstrate accountability with statutory, regulatory, and policy privacy mandates; and [organization-defined] and other personnel with responsibility for monitoring privacy program compliance; and Review and update
  • NIST800-PT-1 Policy and Procedures. Develop, document, and disseminate to [organization-defined]: [organization-defined] personally identifiable information processing and transparency policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent

C5 (Germany) · 4 controls

  • C5-COM-01 Identification of applicable legal, regulatory, self-imposed or contractual requirements
  • C5-COM-03 Internal audits of the information security management system
  • C5-SP-01 Documentation, communication and provision of policies and instructions
  • C5-SP-02 Review and Approval of Policies and Instructions

FedRAMP Moderate · 4 controls

  • CA-2 Control Assessments
  • CA-5 Plan of Action and Milestones
  • PL-2 System Security and Privacy Plans
  • RA-7 Risk Response

ISO 27001:2022 · 4 controls

  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security

ISO 27002:2022 · 4 controls

  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.34 Privacy and protection of PII
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security

NIS2 Directive · 4 controls

  • Art.20.1 Management body approves the cybersecurity risk-management measures and oversees their implementation
  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure
  • Art.21.2.a Policies on risk analysis and on information system security
  • Art.21.4 Take corrective measures without undue delay on finding that the measures are not met

CCPA/CPRA · 3 controls

FedRAMP High · 3 controls

  • CA-2 Control Assessments
  • CA-5 Plan of Action and Milestones
  • PL-2 System Security and Privacy Plans
  • CA-2 Control Assessments
  • CA-5 Plan of Action and Milestones
  • PL-2 System Security and Privacy Plans
  • CA-2 Control Assessments
  • CA-5 Plan of Action and Milestones
  • PL-2 System Security and Privacy Plans
  • CA-2 Control Assessments
  • CA-5 Plan of Action and Milestones
  • PL-2 System Security and Privacy Plans

SOC 2 · 3 controls

  • SOC2-CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations
  • SOC2-CC4.2 COSO principle 17: Evaluates and communicates deficiencies in a timely manner
  • SOC2-CC5.3 COSO principle 12: Deploys control activities through policies and procedures
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • AUCDR-PS-1 Privacy Safeguard 1 - Open and transparent management of CDR data

Canadian PIPEDA · 2 controls

DORA · 2 controls

EU AI Act · 2 controls

  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed

APPI · 1 control

  • MALABO-Art20 Confidentiality and Security Obligations of the Controller
  • APP-1 APP 1 - Open and transparent management of personal information
  • AZ-DPA-10 Article 10 - Responsibilities of the operator
  • ZDPA-20 Penalty and Enforcement Readiness

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter IV - Controller and Processor

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.24 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 40 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 86 it maps to, and the evidence behind each claim, over MCP and REST.