Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: SV

Artikel 29 Behandling under den personuppgiftsansvariges eller personuppgiftsbiträdets överinseende


Summary What does Article 29 of the GDPR regulation say?

This is a notably brief but important article that reinforces the boundary of authority within the data processing chain.

It establishes that processors, and anyone else who acts under the direction of either the controller or the processor, are not free agents when it comes to handling personal data.

Their processing activities must stay within the boundaries set by the controller's instructions.

The only exception to this is where Union or Member State law independently requires them to act.

This article connects closely to Article 28, which sets out the formal contractual relationship between controllers and processors, and Article 29 can be seen as the operational expression of that relationship in practice.

Important points:

  • Processors and anyone acting under the authority of a controller or processor must only process personal data on the instructions of the controller.
  • The sole exception is where Union or Member State law requires processing beyond those instructions.
  • This obligation extends beyond the processor itself to any individual person who has access to personal data within that structure.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

Personuppgiftsbiträdet och personer som utför arbete under den personuppgiftsansvariges eller personuppgiftsbiträdets överinseende, och som får tillgång till personuppgifter, får endast behandla dessa på instruktion från den personuppgiftsansvarige, såvida han eller hon inte är skyldig att göra det enligt unionsrätten eller medlemsstaternas nationella rätt.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod