Controller — EU recitals
What the recitals mean for the role of controller: the obligations, the articles carrying them, the workflows that get you there and what most often fails. Every row carries article, reading date and hash.
Obligations
- GDPR — 24: Responsibility of the controller — Implement and demonstrate measures that make processing compliant.
- GDPR — 25: Data protection by design and by default — Apply data protection by design and by default.
- GDPR — 30: Records of processing activities — Keep records of processing activities.
- GDPR — 32: Security of processing — Ensure a level of security appropriate to the risk.
- GDPR — 33: Notification of a personal data breach to the supervisory authority — Notify a personal data breach to the supervisory authority.
- GDPR — 35: Data protection impact assessment — Carry out a data protection impact assessment for high-risk processing.
Risk points
- The legal basis is chosen once and never retested when the purpose changes.
What forces a redo
- The node hash changes — the text behind the row is no longer the same.
- The reading date moves forward — the row has been re-read against the source.
- A timeline passes — the requirement starts to apply or tightens.
As data
- The same node as data: add ?format=json to the address, or ?format=agent for receipt and dependencies.
Workflows
Articles
Relations
Metadata
- Acts
- GDPR
- Articles
- 6
- Reading date
- 2026-08-31
- Freshness
- 74/100
- Hash
- 3857a85829a0d5c5
- Corpus version
- legal-2026-08-25
- Next check
- —
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.