My bookmarksSign up free

Commission Decision (EU) 2020/969 CHAPTER 3 — CONTROLLERS

Article 8 · 1 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Delegated controllers and operational controllers

Article 8

1.   Delegated controllers shall act on behalf of the Commission as controller for the purposes of the application of Regulation (EU) 2018/1725. 2.   Delegated controllers and operational controllers: (a) may consult the DPO, through the DPC, on the conformity of processing operations, in particular in the event of doubt as to conformity; (b) shall report to the DPO, through the DPC, on the handling of any request received from a data subject for the exercise of his or her rights. 3.   The delegated controller shall: (a) designate an operational controller to assist the delegated controller in ensuring compliance with Regulation (EU) 2018/1725, in particular vis-à-vis data subjects; (b) ensure that internal arrangements with other Directorates-General or Services are in place, where the delegated controller carries out processing operations jointly with those Directorates-General or Services or where those Directorates-General or Services carry out a part of the delegated controller’s processing operation. The arrangements referred to in point (b) of the first subparagraph shall determine their respective responsibilities for compliance with their data protection obligations. In particular, it shall include identification of the delegated controller determining the means and purposes of the processing operation as well as the operational controller for the processing operation, and where appropriate, which person and/or entities which shall assist the operational controller, inter alia, with information in case of data breaches or to accommodate data subjects rights. 4.   The operational controller shall: (a) receive and process all requests from data subjects; (b) notify the European Data Protection Supervisor (EDPS) in case of personal data breaches; (c) inform the DPC and the DPO in case of personal data breaches, and notify the data subject, when relevant; (d) ensure that the DPC is kept aware of all matters relating to data protection, in particular requests from data subjects; (e) carry out any other task within the scope of this Decision at the request of the delegated controller.

Back to Commission Decision (EU) 2020/969 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next