The cascade of compliance obligations

An obligation placed on a company does not stop with that company. It passes down to its suppliers by contract, not by law. Here are the articles that set this out.

The quotations on this page are reproduced in their official version as published in the Official Journal of the European Union. They have not been translated by us. Some quotations are not yet available in this language. We do not translate them ourselves: they will be added as soon as the official version has been verified.

Who must prove what, and to whom

TextArticleWho must proveTo whomSize threshold
Reglement general sur la protection des donnees28, paragraphe 3, point h)le sous-traitantle responsable du traitement, c'est-a-dire le client donneur d'ordre, un autre auditeur mandate par luinone
Reglement general sur la protection des donnees28, paragraphe 1le sous-traitant, indirectementle responsable du traitementnone
Reglement general sur la protection des donnees32, paragraphe 1, point d)le responsable du traitement ET le sous-traitantnon nommenone
Reglement general sur la protection des donnees5, paragraphe 2le responsable du traitementaucun destinataire nommenone
Reglement general sur la protection des donnees24, paragraphe 1le responsable du traitementaucun destinataire nommenone
Reglement delegue completant DORA sur la politique relative aux services TIC6, paragraphe 1le prestataire tiers de services TIC, c'est-a-dire NOTRE PROSPECTl'entite financiere, des tiers designes a cet effet, les autorites competentesaucun seuil de taille cote prestataire ; champ sectoriel cot
Reglement delegue completant DORA sur la politique relative aux services TIC6, paragraphe 3le prestataire tiers de services TICl'entite financiereaucun seuil de taille cote prestataire ; champ sectoriel cot
Reglement delegue completant DORA sur la politique relative aux services TIC8, paragraphe 2le prestatairel'entite financiereaucun seuil de taille cote prestataire ; champ sectoriel cot
Directive NIS232, paragraphe 2, troisieme alineal'entite controleel'autorite competenteEntite Essentielle : 250 salaries OU CA > 50 M EUR et bilan
Directive NIS232, paragraphe 2, point g)l'entitel'autorite competenteEntite Essentielle : 250 salaries OU CA > 50 M EUR et bilan

What each text says

Reglement general sur la protection des donnees, article 28, paragraphe 3, point h)

makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
Who must prove
le sous-traitant
To whom
le responsable du traitement, c'est-a-dire le client donneur d'ordre, un autre auditeur mandate par lui
Frequency
aucune frequence dans le texte ; le droit d'audit est ouvert pendant toute la duree du contrat
Reference
Reglement (UE) 2016/679, JO L 119 du 4.5.2016

Read the official text

Reglement general sur la protection des donnees, article 28, paragraphe 1

Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.
Who must prove
le sous-traitant, indirectement
To whom
le responsable du traitement
Frequency
no frequency stated in the text
Reference
Reglement (UE) 2016/679, JO L 119 du 4.5.2016

Read the official text

Reglement general sur la protection des donnees, article 32, paragraphe 1, point d)

a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
Who must prove
le responsable du traitement ET le sous-traitant
To whom
non nomme
Frequency
regulierement, AUCUNE frequence chiffree dans le texte
Reference
Reglement (UE) 2016/679, JO L 119 du 4.5.2016

Read the official text

Reglement general sur la protection des donnees, article 5, paragraphe 2

2. The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).
Who must prove
le responsable du traitement
To whom
aucun destinataire nomme
Frequency
no frequency stated in the text
Reference
Reglement (UE) 2016/679, JO L 119 du 4.5.2016

Read the official text

Reglement general sur la protection des donnees, article 24, paragraphe 1

1. Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. Those measures shall be reviewed and updated where necessary.
Who must prove
le responsable du traitement
To whom
aucun destinataire nomme
Frequency
si necessaire
Reference
Reglement (UE) 2016/679, JO L 119 du 4.5.2016

Read the official text

Reglement delegue completant DORA sur la politique relative aux services TIC, article 6, paragraphe 1

1. The policy shall set out an appropriate and proportionate process for selecting and assessing the prospective ICT third-party service providers taking into account whether or not the ICT third party service provider is an intragroup ICT service provider, and shall require that the financial entity assesses, before entering into a contractual arrangement, whether the ICT third-party service provider:
Who must prove
le prestataire tiers de services TIC, c'est-a-dire NOTRE PROSPECT
To whom
l'entite financiere, des tiers designes a cet effet, les autorites competentes
Frequency
obligation prealable au contrat
Reference
Reglement delegue (UE) 2024/1773 de la Commission du 13 mars 2024

Read the official text

Reglement delegue completant DORA sur la politique relative aux services TIC, article 6, paragraphe 3

the use of independent audit reports made on request by the ICT third-party service provider;
Who must prove
le prestataire tiers de services TIC
To whom
l'entite financiere
Frequency
no frequency stated in the text
Reference
Reglement delegue (UE) 2024/1773 de la Commission du 13 mars 2024

Read the official text

Reglement delegue completant DORA sur la politique relative aux services TIC, article 8, paragraphe 2

2. The policy shall specify that the relevant contractual arrangements are to include the right for the financial entity to access information, to carry out inspections and audits, and to perform tests on ICT. For that purpose, the policy shall require that the financial entity uses the following methods, without prejudice to the ultimate responsibility of the financial entity:
Who must prove
le prestataire
To whom
l'entite financiere
Frequency
no frequency stated in the text
Reference
Reglement delegue (UE) 2024/1773 de la Commission du 13 mars 2024

Read the official text

Directive NIS2, article 32, paragraphe 2, troisieme alinea

The results of any targeted security audit shall be made available to the competent authority. The costs of such targeted security audit carried out by an independent body shall be paid by the audited entity, except in duly substantiated cases when the competent authority decides otherwise.
Who must prove
l'entite controlee
To whom
l'autorite competente
Frequency
no frequency stated in the text
Reference
Directive (UE) 2022/2555, JO L 333 du 27.12.2022, p. 80

Read the official text

Directive NIS2, article 32, paragraphe 2, point g)

(g) requests for evidence of implementation of cybersecurity policies, such as the results of security audits carried out by a qualified auditor and the respective underlying evidence.
Who must prove
l'entite
To whom
l'autorite competente
Frequency
no frequency stated in the text
Reference
Directive (UE) 2022/2555, JO L 333 du 27.12.2022, p. 80

Read the official text

This page quotes official texts. Every quotation is reproduced word for word and links back to its source. It does not constitute legal advice and is no substitute for reading the text that applies to your own situation. European Union texts quoted on this page are reused under Decision 2011/833/EU, licensed under the Creative Commons Attribution 4.0 International licence. © European Union, 1998-2026. Quotations are reproduced without modification; only their formatting differs from the original. Source: EUR-Lex (eur-lex.europa.eu). Only European Union legislation printed in the paper edition of the Official Journal of the European Union is deemed authentic.

Constater cette réponse du questionnaire plutôt que la déclarer

Votre domaine est-il protégé contre l'usurpation d'expéditeur ? Saisissez-le : le test lit vos enregistrements DNS publics (SPF, DKIM, DMARC) et affiche l'état constaté, sans compte ni inscription. Il porte uniquement sur ce qui est visible de l'extérieur, pas sur l'intérieur de votre messagerie.

Voir l'état de mon domaine

SYAGA Audit · audit du tenant Microsoft 365 en zéro-knowledge. Vos données réelles ne sortent jamais de chez vous.

de chaque page. -->