Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Back to the act

EU regulatory register · EUDPR

Article 91Security of processing of operational personal data

CELEX 32018R1725 · Read on 2026-08-18

Official text

Read from the EU Publications Office for this CELEX number. The wording stands as published; nothing here is rewritten or summarised.

1. The controller and the processor shall, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks, in particular as regards the processing of special categories of operational personal data.

2. In respect of automated processing, the controller and the processor shall, following an evaluation of the risks, implement measures designed to:

(a)

deny unauthorised persons access to data processing equipment used for processing (‘equipment access control’);

(b)

prevent the unauthorised reading, copying, modification or removal of data media (‘data media control’);

(c)

prevent the unauthorised input of operational personal data and the unauthorised inspection, modification or deletion of stored operational personal data (‘storage control’);

(d)

prevent the use of automated processing systems by unauthorised persons using data communication equipment (‘user control’);

(e)

ensure that persons authorised to use an automated processing system have access only to the operational personal data covered by their access authorisation (‘data access control’);

(f)

ensure that it is possible to verify and establish the bodies to which operational personal data have been or may be transmitted or made available using data communication (‘communication control’);

The article continues in the official text.

Open the article on EUR-Lex

The text is quoted from the official source and is not legal advice. A national court reads the language version that binds in its jurisdiction.

Verifiable trust signals

  • Six fixed blocks, one source per line
  • No sentence written by a language model
  • Engine version and read date on every answer
  • No customer data, no documents, no advice
  • Model card and audit published under the EU AI Act

Model cardAudit