Print

Accountability

Accountability is a common principle for organisations across many disciplines; the principle embodies that organisations live up to expectations for instance in the delivery of their products and their behaviour towards those they interact with. The General Data Protection Regulation (GDPR) integrates accountability as a principle which requires that organisations put in place appropriate technical and organisational measures and be able to demonstrate what they did and its effectiveness when requested.

Organisations, and not Data Protection Authorities, must demonstrate that they are compliant with the law.  Such measures include: adequate documentation on what personal data are processed, how, to what purpose, how long;  documented processes and procedures aiming at tackling data protection issues at an early state when building information systems or responding to a data breach; the presence of a Data Protection Officer that be integrated in the organisation planning and operations etc.

In 2015, in anticipation of the GDPR, the EDPS initiated a project to develop a framework for greater accountability in data processing to be applied to our own organisation, as an institution, a manager of financial resources and people - and a controller.

In addition, we have started to promote the accountability principle through visits to small, medium and large EU bodies to explain the new obligations resulting from the revised legal framework and the implications for EU institutions and the EDPS' work as their supervisory authority.

Filters

11
Apr
2012

European market for card, internet and mobile payments

Letter concerning Commission's Green Paper "Towards an integrated European market for card, internet and mobile payments".

See also the text of the Green Paper "Towards an integrated European market for card, internet and mobile payment".

Available languages: German, English, French
7
Mar
2012

Data protection reform package

Opinion on the data protection reform package

More information on EU Data Protection Reform Package

Available languages: German, English, French
21
Jun
2011

Energy market integrity and transparency

Opinion on the Proposal for a Regulation of the European Parliament and of the Council on energy market integrity and transparency, OJ C 279/03, 23.09.2011, p.20

Available languages: Bulgarian, Czech, Danish, German, Estonian, Greek, English, Spanish, French, Italian, Latvian, Lithuanian, Hungarian, Maltese, Dutch, Polish, Portuguese, Romanian, Slovak, Slovenian, Finnish, Swedish
5
May
2011

Consumer Protection Cooperation System ("CPCS")

Opinion on the Consumer Protection Cooperation System ("CPCS") and on Commission Recommendation 2011/136/EU on guidelines for the implementation of data protection rules in the CPCS, OJ C 217/06, 23.07.2011, p.18

Available languages: Bulgarian, Czech, Danish, German, Estonian, Greek, English, Spanish, French, Italian, Latvian, Lithuanian, Hungarian, Maltese, Dutch, Polish, Portuguese, Romanian, Slovak, Slovenian, Finnish, Swedish
14
Jan
2011

Comprehensive approach on personal data protection in the European Union

Opinion on the Communication from the Commission on "A comprehensive approach on personal data protection in the European Union", OJ C 181/01, 22.06.2011, p.1

See also the text of the Communication from the Commission to the European Parliament, the Council, the Economic and Social Committee and the Committee of the Regions - "A comprehensive approach on personal data protection in the European Union".