The texts, article by article
The detail of each provision, with its exact quotation and the link to the official text.
The quotations on this page are reproduced in their official version as published in the Official Journal of the European Union. They have not been translated by us. Some quotations are not yet available in this language. We do not translate them ourselves: they will be added as soon as the official version has been verified.
The texts, one by one
Reglement general sur la protection des donnees
Reglement (UE) 2016/679, JO L 119 du 4.5.2016. In force since 2018-05-25.
Reglement general sur la protection des donnees, article 28, paragraphe 3, point h)
makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
- Who must prove
- le sous-traitant
- To whom
- le responsable du traitement, c'est-a-dire le client donneur d'ordre, un autre auditeur mandate par lui
- Frequency
- aucune frequence dans le texte ; le droit d'audit est ouvert pendant toute la duree du contrat
- Reference
- Reglement (UE) 2016/679, JO L 119 du 4.5.2016
Read the official text
Reglement general sur la protection des donnees, article 28, paragraphe 1
Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.
- Who must prove
- le sous-traitant, indirectement
- To whom
- le responsable du traitement
- Frequency
- no frequency stated in the text
- Reference
- Reglement (UE) 2016/679, JO L 119 du 4.5.2016
Read the official text
Reglement general sur la protection des donnees, article 32, paragraphe 1, point d)
a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
- Who must prove
- le responsable du traitement ET le sous-traitant
- To whom
- non nomme
- Frequency
- regulierement, AUCUNE frequence chiffree dans le texte
- Reference
- Reglement (UE) 2016/679, JO L 119 du 4.5.2016
Read the official text
Reglement general sur la protection des donnees, article 5, paragraphe 2
2. The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).
- Who must prove
- le responsable du traitement
- To whom
- aucun destinataire nomme
- Frequency
- no frequency stated in the text
- Reference
- Reglement (UE) 2016/679, JO L 119 du 4.5.2016
Read the official text
Reglement general sur la protection des donnees, article 24, paragraphe 1
1. Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. Those measures shall be reviewed and updated where necessary.
- Who must prove
- le responsable du traitement
- To whom
- aucun destinataire nomme
- Frequency
- si necessaire
- Reference
- Reglement (UE) 2016/679, JO L 119 du 4.5.2016
Read the official text
Reglement delegue completant DORA sur la politique relative aux services TIC
Reglement delegue (UE) 2024/1773 de la Commission du 13 mars 2024. In force since a_verifier : la date exacte d'entree en vigueur de l'acte n'a pas ete lue a l'ecran. DORA lui-meme est applicable depuis le 17/01/2025..
Reglement delegue completant DORA sur la politique relative aux services TIC, article 6, paragraphe 1
1. The policy shall set out an appropriate and proportionate process for selecting and assessing the prospective ICT third-party service providers taking into account whether or not the ICT third party service provider is an intragroup ICT service provider, and shall require that the financial entity assesses, before entering into a contractual arrangement, whether the ICT third-party service provider:
- Who must prove
- le prestataire tiers de services TIC, c'est-a-dire NOTRE PROSPECT
- To whom
- l'entite financiere, des tiers designes a cet effet, les autorites competentes
- Frequency
- obligation prealable au contrat
- Reference
- Reglement delegue (UE) 2024/1773 de la Commission du 13 mars 2024
Read the official text
Reglement delegue completant DORA sur la politique relative aux services TIC, article 6, paragraphe 3
the use of independent audit reports made on request by the ICT third-party service provider;
- Who must prove
- le prestataire tiers de services TIC
- To whom
- l'entite financiere
- Frequency
- no frequency stated in the text
- Reference
- Reglement delegue (UE) 2024/1773 de la Commission du 13 mars 2024
Read the official text
Reglement delegue completant DORA sur la politique relative aux services TIC, article 8, paragraphe 2
2. The policy shall specify that the relevant contractual arrangements are to include the right for the financial entity to access information, to carry out inspections and audits, and to perform tests on ICT. For that purpose, the policy shall require that the financial entity uses the following methods, without prejudice to the ultimate responsibility of the financial entity:
- Who must prove
- le prestataire
- To whom
- l'entite financiere
- Frequency
- no frequency stated in the text
- Reference
- Reglement delegue (UE) 2024/1773 de la Commission du 13 mars 2024
Read the official text
Directive NIS2
Directive (UE) 2022/2555, JO L 333 du 27.12.2022, p. 80. In force since echeance de transposition 17/10/2024.
Directive NIS2, article 32, paragraphe 2, troisieme alinea
The results of any targeted security audit shall be made available to the competent authority. The costs of such targeted security audit carried out by an independent body shall be paid by the audited entity, except in duly substantiated cases when the competent authority decides otherwise.
- Who must prove
- l'entite controlee
- To whom
- l'autorite competente
- Frequency
- no frequency stated in the text
- Reference
- Directive (UE) 2022/2555, JO L 333 du 27.12.2022, p. 80
Read the official text
Directive NIS2, article 32, paragraphe 2, point g)
(g) requests for evidence of implementation of cybersecurity policies, such as the results of security audits carried out by a qualified auditor and the respective underlying evidence.
- Who must prove
- l'entite
- To whom
- l'autorite competente
- Frequency
- no frequency stated in the text
- Reference
- Directive (UE) 2022/2555, JO L 333 du 27.12.2022, p. 80
Read the official text
This page quotes official texts. Every quotation is reproduced word for word and links back to its source. It does not constitute legal advice and is no substitute for reading the text that applies to your own situation. European Union texts quoted on this page are reused under Decision 2011/833/EU, licensed under the Creative Commons Attribution 4.0 International licence. © European Union, 1998-2026. Quotations are reproduced without modification; only their formatting differs from the original. Source: EUR-Lex (eur-lex.europa.eu). Only European Union legislation printed in the paper edition of the Official Journal of the European Union is deemed authentic.
Constater cette réponse du questionnaire plutôt que la déclarer
Votre domaine est-il protégé contre l'usurpation d'expéditeur ? Saisissez-le : le test lit vos enregistrements DNS publics (SPF, DKIM, DMARC) et affiche l'état constaté, sans compte ni inscription. Il porte uniquement sur ce qui est visible de l'extérieur, pas sur l'intérieur de votre messagerie.
Voir l'état de mon domaine
SYAGA Audit · audit du tenant
Microsoft 365 en zéro-knowledge. Vos données réelles ne sortent jamais de chez vous.