Article 10 — Data and data governance
Official title, Regulation (EU) 2024/1689 · cited here as Art.10, Annex IV §3
Data and data governance
- Who it binds
- provider
- Evidence that discharges it
- a data protection impact assessment
- Usually owned by
- DPO
- Severity
- Critical — a gap here is the kind regulators act on first, and in the prohibitions it is not curable by documentation.
Does it apply to you?
Applicability under the Act is risk tier × operator role, not tier alone. This grid is computed by running the same function the assessment uses, so it cannot drift from what the product would tell you.
- high riskprovider
Read against Regulation (EU) 2024/1689 as amended, consolidated text 02024R1689-20260727 (consolidation 001.001, incorporating Regulation (EU) 2026/1744). What we work from