← GDPR · Controller obligations

Art.24 — Responsibility of the controller

high policy-governance

Requirement

Taking into account the nature, scope, context, purposes and risks of processing, the controller shall implement appropriate technical and organisational measures — including, where proportionate, data protection policies — to ensure and be able to demonstrate compliance, and review and update them where necessary.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
data protection policyprivacy policyprivacy programmeprivacy programdata protection programmedata protection programtechnical and organisational measurestechnical and organizational measures
Required element 2 — any one of
reviewedreviewupdatedapproveddemonstrateownermaintained
Supporting terms — specificity signals
article 24annuallyrisk-basedproportionateaccountab…board

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
SOC 2 CC5.1 Selection and development of control activities policy-governance
SOC 2 CC5.3 Deployment through policies and procedures policy-governance
ISO 27001 A.5.1 Policies for information security policy-governance
ISO 27001 A.6.4 Disciplinary process policy-governance
PCI DSS 4.0.1 12.1 Information security policy policy-governance
HIPAA 164.308(a)(1)(ii)(C) Sanction policy (R) policy-governance
NIST CSF 2.0 GV.PO-01 Cybersecurity policy is established and communicated policy-governance
SOC 2 CC1.1 Commitment to integrity and ethical values policy-governance