Article 24 is one of the central accountability provisions of the GDPR. It translates the general accountability principle in Article 5(2) into a broader operational obligation imposed on the controller.
Article 5(2) establishes the principle that the controller is responsible for compliance with the GDPR and must be able to demonstrate compliance. Article 24 gives that principle practical substance by requiring the controller to establish an organisational and technical framework capable of ensuring compliance.
The provision therefore has two dimensions:
-
substantive responsibility, the controller must actually comply with the GDPR; and
-
demonstrable accountability, the controller must be able to show, with appropriate evidence, that its processing activities comply.
This makes Article 24 fundamentally different from a purely reactive obligation. The controller cannot simply wait for a complaint, investigation, data breach or regulatory inspection and then attempt to correct the problem. It must establish mechanisms before and throughout processing that are reasonably capable of preventing, identifying and correcting non-compliance.