L 119/16
EN
Official Journal of the European Union
4.5.2016
nature, context, scope and purposes of the processing or if the controller is a public authority or body. The rep
resentative should act on behalf of the controller or the processor and may be addressed by any supervisory
authority. The representative should be explicitly designated by a written mandate of the controller or of the
processor to act on its behalf with regard to its obligations under this Regulation. The designation of such a rep
resentative does not affect the responsibility or liability of the controller or of the processor under this
Regulation. Such a representative should perform its tasks according to the mandate received from the controller
or processor, including cooperating with the competent supervisory authorities with regard to any action taken
to ensure compliance with this Regulation. The designated representative should be subject to enforcement
proceedings in the event of non-compliance by the controller or processor.
(81)
To ensure compliance with the requirements of this Regulation in respect of the processing to be carried out by
the processor on behalf of the controller, when entrusting a processor with processing activities, the controller
should use only processors providing sufficient guarantees, in particular in terms of expert knowledge, reliability
and resources, to implement technical and organisational measures which will meet the requirements of this
Regulation, including for the security of processing. The adherence of the processor to an approved code of
conduct or an approved certification mechanism may be used as an element to demonstrate compliance with the
obligations of the controller. The carrying-out of processing by a processor should be governed by a contract or
other legal act under Union or Member State law, binding the processor to the controller, setting out the subjectmatter and duration of the processing, the nature and purposes of the processing, the type of personal data and
categories of data subjects, taking into account the specific tasks and responsibilities of the processor in the
context of the processing to be carried out and the risk to the rights and freedoms of the data subject. The
controller and processor may choose to use an individual contract or standard contractual clauses which are
adopted either directly by the Commission or by a supervisory authority in accordance with the consistency
mechanism and then adopted by the Commission. After the completion of the processing on behalf of the
controller, the processor should, at the choice of the controller, return or delete the personal data, unless there is
a requirement to store the personal data under Union or Member State law to which the processor is subject.
(82)
In order to demonstrate compliance with this Regulation, the controller or processor should maintain records of
processing activities under its responsibility. Each controller and processor should be obliged to cooperate with
the supervisory authority and make those records, on request, available to it, so that it might serve for
monitoring those processing operations.
(83)
In order to maintain security and to prevent processing in infringement of this Regulation, the controller or
processor should evaluate the risks inherent in the processing and implement measures to mitigate those risks,
such as encryption. Those measures should ensure an appropriate level of security, including confidentiality,
taking into account the state of the art and the costs of implementation in relation to the risks and the nature of
the personal data to be protected. In assessing data security risk, consideration should be given to the risks that
are presented by personal data processing, such as accidental or unlawful destruction, loss, alteration,
unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed which may in
particular lead to physical, material or non-material damage.
(84)
In order to enhance compliance with this Regulation where processing operations are likely to result in a high
risk to the rights and freedoms of natural persons, the controller should be responsible for the carrying-out of a
data protection impact assessment to evaluate, in particular, the origin, nature, particularity and severity of that
risk. The outcome of the assessment should be taken into account when determining the appropriate measures to
be taken in order to demonstrate that the processing of personal data complies with this Regulation. Where a
data-protection impact assessment indicates that processing operations involve a high risk which the controller
cannot mitigate by appropriate measures in terms of available technology and costs of implementation, a
consultation of the supervisory authority should take place prior to the processing.
(85)
A personal data breach may, if not addressed in an appropriate and timely manner, result in physical, material or
non-material damage to natural persons such as loss of control over their personal data or limitation of their
rights, discrimination, identity theft or fraud, financial loss, unauthorised reversal of pseudonymisation, damage
to reputation, loss of confidentiality of personal data protected by professional secrecy or any other significant
economic or social disadvantage to the natural person concerned. Therefore, as soon as the controller becomes