EU regulatory register · Dataförordningen
Article 28Contractual transparency obligations on international access and transfer
CELEX 32023R2854 · Read on 2026-08-18
Official text
Read from the EU Publications Office for this CELEX number. The wording stands as published; nothing here is rewritten or summarised.
1. Providers of data processing services shall make the following information available on their websites, and keep that information up to date:
(a)
the jurisdiction to which the ICT infrastructure deployed for data processing of their individual services is subject;
(b)
a general description of the technical, organisational and contractual measures adopted by the provider of data processing services in order to prevent international governmental access to or transfer of non-personal data held in the Union where such access or transfer would create a conflict with Union law or the national law of the relevant Member State.
2. The websites referred to in paragraph 1 shall be listed in contracts for all data processing services offered by providers of data processing services.
The text is quoted from the official source and is not legal advice. A national court reads the language version that binds in its jurisdiction.
Verifiable trust signals
- Six fixed blocks, one source per line
- No sentence written by a language model
- Engine version and read date on every answer
- No customer data, no documents, no advice
- Model card and audit published under the EU AI Act