Article 28 › 1
GDPR
Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.
← 28 · All articles · 2 →
Source: EUR-Lex CELLAR · retrieved 2026-08-26