Article 23*

Article 23 – Documentation

Commission Proposal

1. Member States shall provide that each controller and processor maintains documentation of all processing systems and procedures under their responsibility.

2. The documentation shall contain at least the following information:

(a) the name and contact details of the controller, or any joint controller or processor;

(b) the purposes of the processing;

(c) the recipients or categories of recipients of the personal data;

(d) transfers of data to a third country or an international organisation, including the identification of that third country or international organisation.

3. The controller and the processor shall make the documentation available, on request, to the supervisory authority.

EDRi’s proposed amendment

1. Member States shall provide that each controller and processor maintains documentation of all processing systems and procedures under their responsibility.

2. The documentation shall contain at least the following information:

(a) the name and contact details of the controller, or any joint controller or processor;

(aa) the name and contact details of the data protection officer;

(b) the purposes of the processing;

(ba) a description of the categories of data subjects and of the categories of personal data relating to them;

(c) the recipients or categories of recipients of the personal data;

(d) transfers of data to a third country or an international organisation, including the identification of that third country or international organisation and the legal basis for these transfers, including a substantive explanation in the cases referred to in Article 35 or 36 of this Directive;

(da) a general indication of the time limits for erasure of the different categories of personal data;

(db) the description of the measures referred to in Article 18(3).

3. The controller and the processor shall make the documentation available, on request, to the supervisory authority.

Justification

This amendment serves to bring this Article in line with its counterpart in the General Data Protection Regulation, Article 28, and EDRi’s proposed amendments to it. The addition in point (d) of paragraph 2 is also based on the EDPS opinion, pt. 395.

  • eu logo The launch and upkeep (until December 31, 2012) of this website received financial support from the EU's Fundamental Rights and Citizenship Programme.
Follow

Get every new post delivered to your Inbox.

%d bloggers like this: