1 The responsibility and liability of the controller for any processing of personal data carried out by the controller or on the controller’s behalf should be established. 2 In particular, the controller should be obliged to implement appropriate and effective measures and be able to demonstrate the compliance of processing activities with this Regulation, including the effectiveness of the measures. 3 Those measures should take into account the nature, scope, context and purposes of the processing and the risk to the rights and freedoms of natural persons.
This recital of the General Data Protection Regulation clarifies article 24 GDPR (Responsibility of the controller).*