The processor and any person acting under the authority of the controller or of the processor, who has access to personal data, shall not process those data except on instructions from the controller, unless required to do so by Union or Member State law.
Home› Data Protection & Digital› EU Institutions Data Protection Regulation
Chapter IV · CONTROLLER AND PROCESSOR › Section 1 · General obligations › Article 30
Processing under the authority of the controller or processor
←→ also move between articles