Source: OJ L, 2023/2854, 22.12.2023Consolidated text

Current language: DE

Artikel 28 Vertragliche Transparenzpflichten in Bezug auf den Zugang und die Übermittlung im internationalen Umfeld


Summary What does Article 28 of the Data act regulation say?

This article establishes a transparency obligation on providers of data processing services, requiring them to publicly disclose specific information about their infrastructure and data protection practices.

It sits alongside Article 32, which deals more substantively with the actual measures to prevent unlawful third-country governmental access to non-personal data — Article 28 is essentially the public-facing disclosure counterpart to those obligations.

Important points:

  • Providers of data processing services must publish on their websites the jurisdiction governing their ICT infrastructure and a description of measures taken to prevent unlawful international governmental access to non-personal data held in the Union.
  • This published information must be kept up to date.
  • Providers of data processing services must reference these websites in all contracts they conclude for their data processing services.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Anbieter von Datenverarbeitungsdiensten stellen auf ihren Websites folgende Informationen bereit und halten diese Informationen auf dem neuesten Stand:

      1. die Gerichtsbarkeit, der die IKT-Infrastruktur unterliegt, die für die Datenverarbeitung der einzelnen Dienste der Anbieter errichtet wurde;

      2. eine allgemeine Beschreibung der technischen, organisatorischen und vertraglichen Maßnahmen, die der Anbieter von Datenverarbeitungsdiensten getroffen hat, um einen internationalen staatlichen Zugang zu oder eine internationale staatliche Übermittlung von in der Union gespeicherten nicht-personenbezogenen Daten zu verhindern, wenn ein entsprechender Zugang oder eine entsprechende Übermittlung im Widerspruch zum Unionsrecht oder zum nationalen Recht des betreffenden Mitgliedstaats stünde.

    1. Die in Absatz 1 genannten Websites werden in dem Vertrag für alle Datenverarbeitungsdienste, die von Anbietern von Datenverarbeitungsdiensten angeboten werden, aufgeführt.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod