> For the complete documentation index, see [llms.txt](https://www.mica.wtf/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43.md).

# Chapter IV — Controller and processor (Art. 24–43)

- [Art. 24 — Responsibility of the controller](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/24.md): GDPR Article 24 — Responsibility of the controller. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 25 — Data protection by design and by default](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/25.md): GDPR Article 25 — Data protection by design and by default. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 26 — Joint controllers](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/26.md): GDPR Article 26 — Joint controllers. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 27 — Representatives of controllers or processors not established in the Union](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/27.md): GDPR Article 27 — Representatives of controllers or processors not established in the Union. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 28 — Processor](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/28.md): GDPR Article 28 — Processor. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 29 — Processing under the authority of the controller or processor](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/29.md): GDPR Article 29 — Processing under the authority of the controller or processor. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 30 — Records of processing activities](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/30.md): GDPR Article 30 — Records of processing activities. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 31 — Cooperation with the supervisory authority](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/31.md): GDPR Article 31 — Cooperation with the supervisory authority. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 32 — Security of processing](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/32.md): GDPR Article 32 — Security of processing. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 33 — Notification of a personal data breach to the supervisory authority](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/33.md): GDPR Article 33 — Notification of a personal data breach to the supervisory authority. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 34 — Communication of a personal data breach to the data subject](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/34.md): GDPR Article 34 — Communication of a personal data breach to the data subject. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 35 — Data protection impact assessment](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/35.md): GDPR Article 35 — Data protection impact assessment. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 36 — Prior consultation](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/36.md): GDPR Article 36 — Prior consultation. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 37 — Designation of the data protection officer](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/37.md): GDPR Article 37 — Designation of the data protection officer. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 38 — Position of the data protection officer](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/38.md): GDPR Article 38 — Position of the data protection officer. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 39 — Tasks of the data protection officer](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/39.md): GDPR Article 39 — Tasks of the data protection officer. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 40 — Codes of conduct](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/40.md): GDPR Article 40 — Codes of conduct. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 41 — Monitoring of approved codes of conduct](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/41.md): GDPR Article 41 — Monitoring of approved codes of conduct. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 42 — Certification](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/42.md): GDPR Article 42 — Certification. Regulation (EU) 2016/679, Chapter IV — Controller and processor.
- [Art. 43 — Certification bodies](https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43/43.md): GDPR Article 43 — Certification bodies. Regulation (EU) 2016/679, Chapter IV — Controller and processor.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://www.mica.wtf/gdpr/chapter-iv-controller-and-processor-art.-24-43.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
