GDPR
Chapter IV - Controller and Processor

GDPR GDPR-Art.24: Responsibility of the controller

Implement appropriate technical and organisational measures to ensure, and to be able to demonstrate, that processing is performed in accordance with the Regulation, taking into account the nature, scope, context and purposes of processing and the risks of varying likelihood and severity for the rights and freedoms of natural persons. Review and update those measures where necessary. Where proportionate in relation to the processing activities, the measures must include implementing appropriate data protection policies. Adherence to an approved code of conduct or an approved certification mechanism may be used as one element by which to demonstrate compliance, not as a substitute for it.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 83 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 6 controls

  • 5.2.4 Information security management system
  • 5.3.2 Policy
  • 5.4.1 Actions to address risks and opportunities
  • 5.6.1 Operational planning and control
  • 6.15.1 Compliance with legal and contractual requirements
  • 6.2.1 Management direction for information security

NIST SP 800-53 Rev 5 · 5 controls

C5 (Germany) · 4 controls

  • C5-COM-01 Identification of applicable legal, regulatory, self-imposed or contractual requirements
  • C5-COM-03 Internal audits of the information security management system
  • C5-SP-01 Documentation, communication and provision of policies and instructions
  • C5-SP-02 Review and Approval of Policies and Instructions

FedRAMP Moderate · 4 controls

  • CA-2 Control Assessments
  • CA-5 Plan of Action and Milestones
  • PL-2 System Security and Privacy Plans
  • RA-7 Risk Response

ISO 27001:2022 · 4 controls

  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security

ISO 27002:2022 · 4 controls

  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.34 Privacy and protection of PII
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security

NIS2 Directive · 4 controls

  • Art.20.1 Management body approves the cybersecurity risk-management measures and oversees their implementation
  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure
  • Art.21.2.a Policies on risk analysis and on information system security
  • Art.21.4 Take corrective measures without undue delay on finding that the measures are not met

CCPA/CPRA · 3 controls

FedRAMP High · 3 controls

  • CA-2 Control Assessments
  • CA-5 Plan of Action and Milestones
  • PL-2 System Security and Privacy Plans

SOC 2 · 3 controls

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
  • 5.3(c) 5.3(c) Policy on who may access suspicious log data and when, reviewed at least annually
  • 5.3(d) 5.3(d) Acceptable use and privacy policies implemented and communicated before monitoring
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • AUCDR-PS-1 Privacy Safeguard 1 - Open and transparent management of CDR data

Canadian PIPEDA · 2 controls

DORA · 2 controls

EU AI Act · 2 controls

  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed

APPI · 1 control

  • MALABO-Art20 Confidentiality and Security Obligations of the Controller
  • APP-1 APP 1 - Open and transparent management of personal information
  • AZ-DPA-10 Article 10 - Responsibilities of the operator
  • ACT-8 ACT-8 Document the compliance analysis and re-check each device before any installation or change
  • 9.3.1 9.3.1 A video surveillance policy covering responsibility, prohibited uses, access, training and requests
  • s79a s 79a Treat works council processing as part of the employer's data protection responsibility
  • RO-LAW190-020 Codes of Conduct and Certification
  • ZDPA-20 Penalty and Enforcement Readiness

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter IV - Controller and Processor

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.24 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 83 it maps to, and the evidence behind each claim, over MCP and REST.