Agent · institutions-2018-1725-91
EUDPR artikel 91: Security of processing of operational personal data
Structural tree: the article's own paragraphs, verbatim.
CELEX 32018R1725 · 2026-08-18 · Weight 62 · minimal-risk
OpenOpen reading. No metering is planned for this class.
- What this page is
- Agent, EUDPR artikel 91
- Checked against the official source
- 2026-08-18Current
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does EUDPR Article 91 require, and what outcome does the rule tree give?
EUDPR Article 91 is tested here by a deterministic rule tree of 14 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Paragraph 1 applies, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32018R1725. The outcome is a machine classification, not a compliance decision.
EUDPR Article 91Checked against the publisher 2026-08-18Official text
- Paragraph 1 applies. 1. The controller and the processor shall, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks, in particular as regards…
- Paragraph 2 applies. 2. In respect of automated processing, the controller and the processor shall, following an evaluation of the risks, implement measures designed to:
- Paragraph 3 applies. (a)
A source reference, not legal advice.
Jurisdiction
The same agent, read through one country's lens.
Inputs
- in_scopeThe article applies to the situationboolean
- punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)
Rule tree
If: alla(in_scope = true, punkt = 1)
Paragraph 1 applies
1. The controller and the processor shall, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks, in particular as regards…
Paragraph 1
If: alla(in_scope = true, punkt = 2)
Paragraph 2 applies
2. In respect of automated processing, the controller and the processor shall, following an evaluation of the risks, implement measures designed to:
Paragraph 2
If: alla(in_scope = true, punkt = 3)
Paragraph 3 applies
(a)
Paragraph 3
If: alla(in_scope = true, punkt = 4)
Paragraph 4 applies
deny unauthorised persons access to data processing equipment used for processing (‘equipment access control’);
Paragraph 4
If: alla(in_scope = true, punkt = 5)
Paragraph 5 applies
(b)
Paragraph 5
If: alla(in_scope = true, punkt = 6)
Paragraph 6 applies
prevent the unauthorised reading, copying, modification or removal of data media (‘data media control’);
Paragraph 6
If: alla(in_scope = true, punkt = 7)
Paragraph 7 applies
(c)
Paragraph 7
If: alla(in_scope = true, punkt = 8)
Paragraph 8 applies
prevent the unauthorised input of operational personal data and the unauthorised inspection, modification or deletion of stored operational personal data (‘storage control’);
Paragraph 8
If: alla(in_scope = true, punkt = 9)
Paragraph 9 applies
(d)
Paragraph 9
If: alla(in_scope = true, punkt = 10)
Paragraph 10 applies
prevent the use of automated processing systems by unauthorised persons using data communication equipment (‘user control’);
Paragraph 10
If: alla(in_scope = true, punkt = 11)
Paragraph 11 applies
(e)
Paragraph 11
If: alla(in_scope = true, punkt = 12)
Paragraph 12 applies
ensure that persons authorised to use an automated processing system have access only to the operational personal data covered by their access authorisation (‘data access control’);
Paragraph 12
If: alla(in_scope = true, punkt = 13)
Paragraph 13 applies
(f)
Paragraph 13
If: alla(in_scope = true, punkt = 14)
Paragraph 14 applies
ensure that it is possible to verify and establish the bodies to which operational personal data have been or may be transmitted or made available using data communication (‘communication control’);
Paragraph 14
If no rule matches: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.
The article text as read
- 11. The controller and the processor shall, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks, in particular as regards the processing of special categories of operational personal data.
- 22. In respect of automated processing, the controller and the processor shall, following an evaluation of the risks, implement measures designed to:
- 3(a)
- 4deny unauthorised persons access to data processing equipment used for processing (‘equipment access control’);
- 5(b)
- 6prevent the unauthorised reading, copying, modification or removal of data media (‘data media control’);
- 7(c)
- 8prevent the unauthorised input of operational personal data and the unauthorised inspection, modification or deletion of stored operational personal data (‘storage control’);
- 9(d)
- 10prevent the use of automated processing systems by unauthorised persons using data communication equipment (‘user control’);
- 11(e)
- 12ensure that persons authorised to use an automated processing system have access only to the operational personal data covered by their access authorisation (‘data access control’);
- 13(f)
- 14ensure that it is possible to verify and establish the bodies to which operational personal data have been or may be transmitted or made available using data communication (‘communication control’);
Lineage
Interface
Hashes
Artefacts
No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Citation: 32018R1725 art. 91, Security of processing of operational personal data. ExploreWorld Legal, https://legal.exploreworldai.com/agent/institutions-2018-1725/artikel-91 (hämtad 2026-08-18, bevis sha256:ee1ecf69f79ded40, bygge legal-2026-08-25).