Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: FR
- General data protection
Basic legislative acts
- GDPR regulation
Article 29 Traitement effectué sous l'autorité du responsable du traitement ou du sous-traitant
Summary What does Article 29 of the GDPR regulation say?
This is a notably brief but important article that reinforces the boundary of authority within the data processing chain.
It establishes that processors, and anyone else who acts under the direction of either the controller or the processor, are not free agents when it comes to handling personal data.
Their processing activities must stay within the boundaries set by the controller's instructions.
The only exception to this is where Union or Member State law independently requires them to act.
This article connects closely to Article 28, which sets out the formal contractual relationship between controllers and processors, and Article 29 can be seen as the operational expression of that relationship in practice.
Important points:
- Processors and anyone acting under the authority of a controller or processor must only process personal data on the instructions of the controller.
- The sole exception is where Union or Member State law requires processing beyond those instructions.
- This obligation extends beyond the processor itself to any individual person who has access to personal data within that structure.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Le sous-traitant et toute personne agissant sous l'autorité du responsable du traitement ou sous celle du sous-traitant, qui a accès à des données à caractère personnel, ne peut pas traiter ces données, excepté sur instruction du responsable du traitement, à moins d'y être obligé par le droit de l'Union ou le droit d'un État membre.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
données à caractère personnel
(En. personal data)
Definition
traitement
(En. processing)
Definition
responsable du traitement
(En. controller)
Definition
sous-traitant
(En. processor)