GDPREU 2016/679
Digiphile
Chapters

Chapter IVController and processor

Section 1 – General obligations

Section 2 – Security of personal data

Section 3 – Data protection impact assessment and prior consultation

  • Article 35Data protection impact assessment

    1. Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result…

  • Article 36Prior consultation

    1. The controller shall consult the supervisory authority prior to processing where a data protection impact assessment under Article 35 indicates that the processing would result in a…

Section 4 – Data protection officer

Section 5 – Codes of conduct and certification

  • Article 40Codes of conduct

    1. The Member States, the supervisory authorities, the Board and the Commission shall encourage the drawing up of codes of conduct intended to contribute to the proper application…

  • Article 41Monitoring of approved codes of conduct

    1. Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58 , the monitoring of compliance with a code of conduct…

  • Article 42Certification

    1. The Member States, the supervisory authorities, the Board and the Commission shall encourage, in particular at Union level, the establishment of data protection certification mechanisms and of…

  • Article 43Certification bodies

    1. Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58 , certification bodies which have an appropriate level of expertise…