Duties and Responsibilities of Controller and Processor
摘要
The chapter focuses on the obligations and tasks designated to data controllers and data processors. According to the WP29, the main purpose of defining the concept of a data controller is to determine who is responsible for complying with data protection Regulations and how data subjects can exercise their rights effectively. Essentially, it is about assigning responsibility. To comprehend the expectations, we will examine rulings from the CJEU and determinations made by the data protection authorities. Additionally, guidance from the EDPB and the ICO is consulted to grasp the standard expectations. The GDPR establishes that the primary responsibility consistently lies with the data controller.