Source: OJ L, 2023/2854, 22.12.2023

Current language: SV

Artikel 28 Avtalsenliga insynsskyldigheter i fråga om internationell åtkomst och överföring


Summary What does Article 28 of the Data act regulation say?

This article establishes a transparency obligation on providers of data processing services, requiring them to publicly disclose specific information about their infrastructure and data protection practices.

It sits alongside Article 32, which deals more substantively with the actual measures to prevent unlawful third-country governmental access to non-personal data — Article 28 is essentially the public-facing disclosure counterpart to those obligations.

Important points:

  • Providers of data processing services must publish on their websites the jurisdiction governing their ICT infrastructure and a description of measures taken to prevent unlawful international governmental access to non-personal data held in the Union.
  • This published information must be kept up to date.
  • Providers of data processing services must reference these websites in all contracts they conclude for their data processing services.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Leverantörer av databehandlingstjänster ska göra följande information tillgänglig på sina webbplatser och hålla den informationen uppdaterad:

      1. Vilken jurisdiktion som den IKT-infrastruktur som används för databehandling av deras enskilda tjänster tillhör.

      2. En allmän beskrivning av de tekniska, organisatoriska och avtalsmässiga åtgärder som leverantören av databehandlingstjänster vidtagit för att förhindra internationell statlig åtkomst till eller överföring av icke-personuppgifter som innehas i unionen, om en sådan åtkomst eller överföring skulle strida mot unionsrätten eller den berörda medlemsstatens nationella rätt.

    1. De webbplatser som avses i punkt 1 ska förtecknas i avtal för alla databehandlingstjänster som erbjuds av leverantörer av databehandlingstjänster.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod