
the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident.the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.the pseudonymisation and encryption of personal data.Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:.99 GDPR – Entry into force and applicationġ4 11 Art. 98 GDPR – Review of other Union legal acts on data protection 96 GDPR – Relationship with previously concluded Agreements 95 GDPR – Relationship with Directive 2002/58/EC 91 GDPR – Existing data protection rules of churches and religious associations 89 GDPR – Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes 88 GDPR – Processing in the context of employment 87 GDPR – Processing of the national identification number 86 GDPR – Processing and public access to official documents 85 GDPR – Processing and freedom of expression and information Provisions relating to specific processing situations 83 GDPR – General conditions for imposing administrative fines 82 GDPR – Right to compensation and liability 80 GDPR – Representation of data subjects 79 GDPR – Right to an effective judicial remedy against a controller or processor 78 GDPR – Right to an effective judicial remedy against a supervisory authority 77 GDPR – Right to lodge a complaint with a supervisory authority 60 GDPR – Cooperation between the lead supervisory authority and the other supervisory authorities concerned 62 GDPR – Joint operations of supervisory authorities 56 GDPR – Competence of the lead supervisory authority 54 GDPR – Rules on the establishment of the supervisory authority

53 GDPR – General conditions for the members of the supervisory authority 50 GDPR – International cooperation for the protection of personal data 49 GDPR – Derogations for specific situations 48 GDPR – Transfers or disclosures not authorised by Union law 46 GDPR – Transfers subject to appropriate safeguards 45 GDPR – Transfers on the basis of an adequacy decision 44 GDPR – General principle for transfers Transfers of personal data to third countries or international organisations 41 GDPR – Monitoring of approved codes of conduct 39 GDPR – Tasks of the data protection officer 38 GDPR – Position of the data protection officer 37 GDPR – Designation of the data protection officer 35 GDPR – Data protection impact assessment 34 GDPR – Communication of a personal data breach to the data subject 33 GDPR – Notification of a personal data breach to the supervisory authority 31 GDPR – Cooperation with the supervisory authority 30 GDPR – Records of processing activities 29 GDPR – Processing under the authority of the controller or processor 27 GDPR – Representatives of controllers or processors not established in the Union 25 GDPR – Data protection by design and by default 24 GDPR – Responsibility of the controller

22 GDPR – Automated individual decision-making, including profiling 19 GDPR – Notification obligation regarding rectification or erasure of personal data or restriction of processing 18 GDPR – Right to restriction of processing

17 GDPR – Right to erasure (‘right to be forgotten’) 15 GDPR – Right of access by the data subject 14 GDPR – Information to be provided where personal data have not been obtained from the data subject 13 GDPR – Information to be provided where personal data are collected from the data subject 12 GDPR – Transparent information, communication and modalities for the exercise of the rights of the data subject 11 GDPR – Processing which does not require identification 10 GDPR – Processing of personal data relating to criminal convictions and offences 9 GDPR – Processing of special categories of personal data 8 GDPR – Conditions applicable to child’s consent in relation to information society services 5 GDPR – Principles relating to processing of personal data
