GDPR Article 24 – Responsibility of the Controller

An Advanced Practitioner Analysis of the Operational Core of GDPR Accountability

Foundation

Introduction: Article 24 as the Operational Core of GDPR Accountability

Governance Obligation

Article 24 GDPR transforms data protection from a purely legal obligation into a governance obligation, requiring controllers to comply and demonstrate compliance through evidence, governance structures, and technical controls.

The Meta-Obligation

Article 24 is often described as the "meta-obligation" of GDPR because virtually every other controller obligation ultimately feeds into the controller's duty to ensure and demonstrate compliance.

Operationalising Accountability

Whereas Article 5(2) establishes the principle of accountability, Article 24 operationalises accountability through evidence, governance structures, technical controls, organisational controls, and continuous review.

Regulatory Priority

Supervisory authorities frequently assess Article 24 compliance first, because deficiencies in governance, documentation, risk assessment, or oversight often indicate broader GDPR failures.

Practitioner Perspective

Advanced practitioners should view Article 24 as a compliance management system requirement rather than a standalone legal provision.

Legal Text

Textual Structure of Article 24

Article 24(1) – Technical & Organisational Measures

Controllers must implement appropriate TOMs that both ensure and demonstrate GDPR compliance. Measures must be:

  • Risk-based and proportionate
  • Reviewed periodically
  • Updated when necessary

Assessment factors include the nature, scope, context, and purposes of processing, plus the likelihood and severity of risks to data subjects.

Article 24(2) – Formal Data Protection Policies

Where proportionate, controllers must establish formal data protection policies. These policies become evidence of governance maturity and accountability.


Article 24(3) – Compliance Demonstration Tools

Two mechanisms may be used as evidence supporting compliance demonstrations:

  • Approved Codes of Conduct (Article 40)
  • Approved Certification Mechanisms (Article 42)
Theory

Theoretical Foundation: Accountability

Accountability is the foundational governance principle underlying modern privacy law. GDPR moved beyond prescriptive compliance and adopted a risk-based accountability model.

Know What You Process

Understand every processing activity across the organisation.

Know Why You Process It

Establish and document a lawful basis for each activity.

Know the Risks

Assess likelihood and severity of risks to data subjects.

Implement Controls

Deploy proportionate technical and organisational measures.

Document Decisions

Maintain records of every governance decision made.

Prove All of the Above

Be able to demonstrate compliance to supervisory authorities at any time.

Key Legal Elements

Risk-Based Decision Making Under Article 24

Article 24 does not impose identical obligations on every organisation. Measures must be tailored to risk. The required governance maturity varies dramatically depending on the nature and scale of processing.

Small Veterinary Practice

  • Limited data subjects
  • Local processing only
  • Low-volume data

Proportionate, lighter-touch governance measures are appropriate and sufficient.

Global Health Technology Company

  • Millions of records
  • Special category data
  • AI-driven profiling

Demands a mature, enterprise-grade governance framework with robust controls.

Demonstrability & Continuous Review Requirements

Demonstrability Requirement

Compliance alone is insufficient. Controllers must maintain evidence. Rather than merely stating "employees receive privacy training," the controller must maintain:

  • Training materials
  • Attendance records
  • Assessment results
  • Refresher schedules
  • Metrics

Continuous Review Requirement

Article 24 explicitly requires measures to be reviewed and updated where necessary. An annual review should be triggered by:

  • New processing activities
  • Cloud migration
  • AI deployment
  • Mergers and acquisitions
  • Regulatory developments
Legal Intersections

GDPR Articles Intersecting with Article 24

Art. 5(2) – Accountability Principle

Article 24 operationalises Article 5(2). Without Article 24, accountability remains merely conceptual.

Art. 25 – Privacy by Design

Article 24 requires accountability; Article 25 requires embedding it into systems — e.g. privacy settings enabled by default, data minimisation built into application architecture.

Art. 30 – ROPA

Records of Processing Activities are one of the strongest demonstrations of Article 24 compliance, achieved through a centralised processing inventory.

Art. 32 – Security of Processing

Security measures — encryption, access control, resilience testing — are specific technical manifestations of Article 24 obligations.

Art. 35 – DPIAs

Data Protection Impact Assessments demonstrate risk-based decision making, e.g. for facial recognition deployment or AI-based employee monitoring.

Legal Intersections Continued

Further GDPR Articles Intersecting with Article 24

Art. 37–39 – DPO

DPO governance contributes significantly to Article 24 accountability.

Art. 28 – Processors

Controllers remain accountable even when processing is outsourced. Cloud provider oversight and processor audits are required.

Art. 33 – Breach Notification

Incident management procedures demonstrate accountability.

Art. 34 – Data Subject Communication

Accountability includes transparent breach communication to data subjects.

Arts. 12–22 – Rights Management

Data subject rights management processes constitute accountability evidence.

Art. 40 & 42 – CoC & Certification

Codes of Conduct and Certification are explicitly referenced in Article 24(3) as compliance demonstration tools.

Arts. 44–49 – Transfers

International transfer governance forms part of controller accountability obligations.

Art. 26 – Joint Controllers

Allocation of responsibilities between joint controllers must be documented.

Art. 6 – Lawful Basis

Accountability requires documented lawful basis selection for every processing activity.

Art. 9 – Special Category Data

Higher risk demands stronger Article 24 controls when processing sensitive data.

Strong Compliance

Examples of Strong Article 24 Compliance

Mature Financial Institution

  • Enterprise privacy governance framework
  • Comprehensive data inventory
  • Annual privacy risk assessments
  • Automated access management
  • DPIA programme
  • Vendor oversight programme
  • Board-level reporting

Result: Demonstrates Article 24 maturity across all dimensions.

Healthcare Organisation

  • Clinical data classification
  • Encryption at rest
  • DPO oversight
  • Security monitoring
  • Periodic privacy audits
  • Data retention enforcement

Result: Strong evidence of accountability for high-risk special category data.

SaaS Provider

  • Privacy-by-design lifecycle
  • Security architecture reviews
  • Vendor risk management
  • Data subject rights automation
  • Audit logging

Result: Supports demonstrability requirements throughout the product lifecycle.

Compliance Failures

Examples of Article 24 Failures

Understanding failure modes is as important as understanding best practice. The following scenarios illustrate common Article 24 deficiencies identified by supervisory authorities.

Failure 1 – No Governance Infrastructure

No processing inventory, no DPIAs, no privacy policies.

Failure 2 – Unverified Processor Reliance

Reliance on processor assurances without conducting audits or independent verification.

Failure 3 – Undocumented Controls

Security controls implemented in practice but not documented anywhere.

Controls Framework

Twenty Cross-Cutting Controls: Part 1

The following technical and organisational controls collectively support Article 24 compliance. Each addresses a distinct dimension of the accountability framework.

Enterprise Privacy Governance Framework

Establish accountability structure, define ownership, and define reporting lines across the organisation.

Data Processing Inventory (ROPA)

Comprehensive processing register with data flow mapping covering all processing activities.

Risk Assessment Methodology

Formal privacy risk assessment process with consistent risk scoring applied across all activities.

Data Protection Impact Assessment Programme

Defined trigger criteria, approval workflow, and periodic review cycle for all high-risk processing.

Data Classification Framework

Personal data categorisation with sensitivity labels applied consistently across all data assets.

Controls Framework

Twenty Cross-Cutting Controls: Part 2

6. Access Control Governance

Role-based access control with least privilege principles enforced across all systems.

7. Identity & Access Management

Centralised provisioning with automated deprovisioning upon role change or departure.

8. Multi-Factor Authentication

Protection for administrative access and all remote access entry points.

9. Encryption Programme

Data at rest, data in transit, and robust key management procedures.

10. Pseudonymisation Capability

Risk reduction technique supporting research processing and data minimisation.

11. Audit Logging & Monitoring

Accountability evidence generation and investigation support for all critical systems.

12. SIEM

Security Information and Event Management for centralised monitoring and incident detection.

Controls Framework

Twenty Cross-Cutting Controls: Part 3

1

Data Retention & Deletion Controls

Automated retention enforcement and secure disposal procedures for all personal data.

2

Vendor Risk Management Programme

Processor assessments, contract reviews, and ongoing monitoring of all third-party processors.

3

Article 28 Processor Compliance Reviews

Processor audits and security assurance validation to maintain controller accountability.

4

Data Subject Rights Management Platform

End-to-end intake, verification, fulfilment, and tracking of all data subject requests.

5

Incident Response & Breach Management

Detection, investigation, and notification workflows meeting Article 33 and 34 requirements.

6

Privacy Training & Awareness Programme

Role-specific, executive, and technical training with documented attendance and assessment records.

7

Privacy by Design Review Process

SDLC integration, architecture reviews, and change assessments embedded in development lifecycle.

8

Continuous Compliance Monitoring & Internal Audit

KPI monitoring, control testing, and corrective action tracking on an ongoing basis.

Advanced Interpretation

Advanced Practitioner Interpretation

Article 24 should not be viewed as a compliance checklist. It is a governance architecture requirement.

The most mature organisations treat Article 24 as an integrated management system that combines multiple disciplines into a unified accountability framework:

Legal Compliance

Meeting all GDPR obligations across the organisation.

Information Security

Technical controls protecting personal data at every layer.

Risk Management

Continuous identification and mitigation of privacy risks.

Internal Audit

Independent assurance over the effectiveness of controls.

Corporate Governance

Board-level accountability and oversight of data protection.

Operational Resilience

Ensuring continuity of compliance through disruption and change.

Conclusion

Advanced Practitioner Teaching Conclusion

Article 24 establishes the controller as the accountable actor within the GDPR ecosystem. Its purpose is not merely compliance, but demonstrable, evidence-based compliance.

Risk-Based Governance

Tailor measures to the nature, scope, and risk profile of each processing activity.

Documented Decision Making

Record every governance decision, lawful basis selection, and risk assessment outcome.

Technical & Organisational Controls

Deploy proportionate TOMs across all processing activities and review them regularly.

Continuous Monitoring

Maintain ongoing oversight through KPI tracking, control testing, and audit programmes.

Ongoing Improvement

Treat compliance as a living programme, not a one-time exercise.

Organisations That Can Prove Compliance

Organisations that can produce evidence of their governance, controls, and decision making generally satisfy Article 24's accountability standard.

Organisations That Cannot Produce Evidence

Organisations that cannot produce evidence, regardless of their actual practices, generally fail Article 24's accountability standard. Evidence is not optional — it is the standard.

Datari Home