<?xml version="1.0" encoding="UTF-8"?><!--Serialized by the GTRI Trustmark Framework API, version: 1.4.74--><tf:TrustInteroperabilityProfile xmlns:tf="https://trustmarkinitiative.org/specifications/trustmark-framework/1.4/schema/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tips/gdpr-data-processor-compliance-profile/1.0/</tf:Identifier><tf:Name>GDPR Data Processor Compliance Profile</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Profile of requirements from the General Data Protection Regulation (GDPR) (EU) 2016/679 for the role of a Data Processor.</tf:Description><tf:PublicationDateTime>2025-05-15T00:00:00.000Z</tf:PublicationDateTime><tf:Primary>true</tf:Primary><tf:LegalNotice>This artifact is published by the Georgia Tech Research Institute (GTRI) as part of the Trustmark Initiative. This artifact and the information contained herein is provided on an "AS IS" basis, and GTRI disclaims all warranties, express or implied, including but not limited to any warranty that the use of the information herein will not infringe any rights or any implied warranties or merchantability or fitness for a particular purpose. In addition, GTRI disclaims legal liability for any loss incurred as a result of the use or reliance on the document or the information contained herein.</tf:LegalNotice><tf:Issuer><tf:Identifier>https://trustmarkinitiative.org/</tf:Identifier><tf:Name>TMI</tf:Name><tf:Contact><tf:Kind>PRIMARY</tf:Kind><tf:Responder></tf:Responder><tf:Email>help@trustmarkinitiative.org</tf:Email><tf:Telephone>555-555-5555</tf:Telephone><tf:WebsiteURL>https://trustmarkinitiative.org/</tf:WebsiteURL></tf:Contact></tf:Issuer><tf:Keywords><tf:Keyword>GDPR</tf:Keyword><tf:Keyword>Data Protection</tf:Keyword><tf:Keyword>Privacy</tf:Keyword><tf:Keyword>Data Privacy</tf:Keyword><tf:Keyword>Data Processor</tf:Keyword></tf:Keywords><tf:References><tf:TrustmarkDefinitionRequirement tf:id="TD_AppointmentofEURepresentativebyNonEUEntities"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/appointment-of-eu-representative-by-non-eu-entities/1.0/</tf:Identifier><tf:Number>1</tf:Number><tf:Name>Appointment of EU Representative by Non-EU Entities</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 27(1).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_AvailabilityoftheEURepresentativetoSupervisoryAuthoritiesandDataSubjects"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/availability-of-the-eu-representative-to-supervisory-authorities-and-data-subjects/1.0/</tf:Identifier><tf:Number>2</tf:Number><tf:Name>Availability of the EU Representative to Supervisory Authorities and Data Subjects</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 27(3).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ProcessingofPersonalDataOnlyonDocumentedInstructions"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/processing-of-personal-data-only-on-documented-instructions/1.0/</tf:Identifier><tf:Number>3</tf:Number><tf:Name>Processing of Personal Data Only on Documented Instructions</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 28(3)(a).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ConfidentialityofAuthorizedPersonnel"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/confidentiality-of-authorized-personnel/1.0/</tf:Identifier><tf:Number>4</tf:Number><tf:Name>Confidentiality of Authorized Personnel</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 28(3)(b).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_AssistancetoControllerinRespondingtoDataSubjectRequests"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/assistance-to-controller-in-responding-to-data-subject-requests/1.0/</tf:Identifier><tf:Number>5</tf:Number><tf:Name>Assistance to Controller in Responding to Data Subject Requests</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 28(3)(d).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_AssistanceinEnsuringCompliancewithArticles32to36"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/assistance-in-ensuring-compliance-with-articles-32-to-36/1.0/</tf:Identifier><tf:Number>6</tf:Number><tf:Name>Assistance in Ensuring Compliance with Articles 32 to 36</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 28(3)(e).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ReturnorDeletionofPersonalDataafterProcessing"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/return-or-deletion-of-personal-data-after-processing/1.0/</tf:Identifier><tf:Number>7</tf:Number><tf:Name>Return or Deletion of Personal Data after Processing</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 28(3)(f).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_AvailabilityforAuditsandInspections"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/availability-for-audits-and-inspections/1.0/</tf:Identifier><tf:Number>8</tf:Number><tf:Name>Availability for Audits and Inspections</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 28(3)(g).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_UseofSubProcessorsUnderEquivalentContractTerms"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/use-of-sub-processors-under-equivalent-contract-terms/1.0/</tf:Identifier><tf:Number>9</tf:Number><tf:Name>Use of Sub-Processors Under Equivalent Contract Terms</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 28(3)(h).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_RestrictionofProcessingtoDocumentedInstructions"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/restriction-of-processing-to-documented-instructions/1.0/</tf:Identifier><tf:Number>10</tf:Number><tf:Name>Restriction of Processing to Documented Instructions</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 29.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_MaintenanceofRecordsofProcessingActivitiesbytheDataProcessor"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/maintenance-of-records-of-processing-activities-by-the-data-processor/1.0/</tf:Identifier><tf:Number>11</tf:Number><tf:Name>Maintenance of Records of Processing Activities by the Data Processor</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 30(2).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_CooperationwiththeSupervisoryAuthority"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/cooperation-with-the-supervisory-authority/1.0/</tf:Identifier><tf:Number>12</tf:Number><tf:Name>Cooperation with the Supervisory Authority</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 31.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ImplementationofAppropriateSecurityMeasures"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/implementation-of-appropriate-security-measures/1.0/</tf:Identifier><tf:Number>13</tf:Number><tf:Name>Implementation of Appropriate Security Measures</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 32(1).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_NotificationofPersonalDataBreachtotheDataController"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/notification-of-personal-data-breach-to-the-data-controller/1.0/</tf:Identifier><tf:Number>14</tf:Number><tf:Name>Notification of Personal Data Breach to the Data Controller</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 33(2).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_DesignationofaDataProtectionOfficerUnderSpecifiedConditions"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/designation-of-a-data-protection-officer-under-specified-conditions/1.0/</tf:Identifier><tf:Number>15</tf:Number><tf:Name>Designation of a Data Protection Officer Under Specified Conditions</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 37(1).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_DesignationoftheDataProtectionOfficerBasedonExpertiseandProfessionalQualities"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/designation-of-the-data-protection-officer-based-on-expertise-and-professional-qualities/1.0/</tf:Identifier><tf:Number>16</tf:Number><tf:Name>Designation of the Data Protection Officer Based on Expertise and Professional Qualities</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 37(5).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_PublicCommunicationandSupervisoryAuthorityNotificationoftheDataProtectionOfficer"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/public-communication-and-supervisory-authority-notification-of-the-data-protection-officer/1.0/</tf:Identifier><tf:Number>17</tf:Number><tf:Name>Public Communication and Supervisory Authority Notification of the Data Protection Officer</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 37(7).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_InvolvementoftheDataProtectionOfficerinAllDataProtectionMatters"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/involvement-of-the-data-protection-officer-in-all-data-protection-matters/1.0/</tf:Identifier><tf:Number>18</tf:Number><tf:Name>Involvement of the Data Protection Officer in All Data Protection Matters</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 38(1).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_SupportfortheDataProtectionOfficersTasks"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/support-for-the-data-protection-officer_s-tasks/1.0/</tf:Identifier><tf:Number>19</tf:Number><tf:Name>Support for the Data Protection Officer's Tasks</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 38(2).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_SafeguardsfortheIndependenceandNonPenalizationoftheDataProtectionOfficer"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/safeguards-for-the-independence-and-non-penalization-of-the-data-protection-officer/1.0/</tf:Identifier><tf:Number>20</tf:Number><tf:Name>Safeguards for the Independence and Non-Penalization of the Data Protection Officer</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 38(3).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_DefinitionandSupportofDataProtectionOfficerResponsibilities"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/definition-and-support-of-data-protection-officer-responsibilities/1.0/</tf:Identifier><tf:Number>21</tf:Number><tf:Name>Definition and Support of Data Protection Officer Responsibilities</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 39(1).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_AdherencetoApprovedCodesofConductwithMonitoring"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/adherence-to-approved-codes-of-conduct-with-monitoring/1.0/</tf:Identifier><tf:Number>22</tf:Number><tf:Name>Adherence to Approved Codes of Conduct with Monitoring</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 40(4).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_CompliancewithAccreditedMonitoringBodyforCodesofConduct"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/compliance-with-accredited-monitoring-body-for-codes-of-conduct/1.0/</tf:Identifier><tf:Number>23</tf:Number><tf:Name>Compliance with Accredited Monitoring Body for Codes of Conduct</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 41(4).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_CooperationwithCertificationBodies"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/cooperation-with-certification-bodies/1.0/</tf:Identifier><tf:Number>24</tf:Number><tf:Name>Cooperation with Certification Bodies</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 42(3).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_CompliancewithGDPRRequirementsforInternationalDataTransfers"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/compliance-with-gdpr-requirements-for-international-data-transfers/1.0/</tf:Identifier><tf:Number>25</tf:Number><tf:Name>Compliance with GDPR Requirements for International Data Transfers</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 44.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_RelianceonAdequacyDecisionsforDataTransfers"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/reliance-on-adequacy-decisions-for-data-transfers/1.0/</tf:Identifier><tf:Number>26</tf:Number><tf:Name>Reliance on Adequacy Decisions for Data Transfers</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 45(1).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ImplementationofAppropriateSafeguardsforInternationalTransfers"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/implementation-of-appropriate-safeguards-for-international-transfers/1.0/</tf:Identifier><tf:Number>27</tf:Number><tf:Name>Implementation of Appropriate Safeguards for International Transfers</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 46(1).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_UseofApprovedBindingCorporateRulesforGroupTransfers"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/use-of-approved-binding-corporate-rules-for-group-transfers/1.0/</tf:Identifier><tf:Number>28</tf:Number><tf:Name>Use of Approved Binding Corporate Rules for Group Transfers</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 47(1).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_RestrictiononThirdCountryAccessWithoutEULegalAuthorization"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/restriction-on-third-country-access-without-eu-legal-authorization/1.0/</tf:Identifier><tf:Number>29</tf:Number><tf:Name>Restriction on Third-Country Access Without EU Legal Authorization</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 48.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_UseofDerogationsforInternationalDataTransfersWithoutSafeguards"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/use-of-derogations-for-international-data-transfers-without-safeguards/1.0/</tf:Identifier><tf:Number>30</tf:Number><tf:Name>Use of Derogations for International Data Transfers Without Safeguards</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 49(1).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_LiabilityforGDPRViolationsCausingDamage"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/liability-for-gdpr-violations-causing-damage/1.0/</tf:Identifier><tf:Number>31</tf:Number><tf:Name>Liability for GDPR Violations Causing Damage</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 82(2)-(3).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_AccountabilityforCompliancewiththeGDPRSubjecttoFines"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/accountability-for-compliance-with-the-gdpr-subject-to-fines/1.0/</tf:Identifier><tf:Number>32</tf:Number><tf:Name>Accountability for Compliance with the GDPR, Subject to Fines</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 83(2)-(6).</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement></tf:References><tf:TrustExpression><![CDATA[TD_AppointmentofEURepresentativebyNonEUEntities and TD_AvailabilityoftheEURepresentativetoSupervisoryAuthoritiesandDataSubjects and TD_ProcessingofPersonalDataOnlyonDocumentedInstructions and TD_ConfidentialityofAuthorizedPersonnel and TD_AssistancetoControllerinRespondingtoDataSubjectRequests and TD_AssistanceinEnsuringCompliancewithArticles32to36 and TD_ReturnorDeletionofPersonalDataafterProcessing and TD_AvailabilityforAuditsandInspections and TD_UseofSubProcessorsUnderEquivalentContractTerms and TD_RestrictionofProcessingtoDocumentedInstructions and TD_MaintenanceofRecordsofProcessingActivitiesbytheDataProcessor and TD_CooperationwiththeSupervisoryAuthority and TD_ImplementationofAppropriateSecurityMeasures and TD_NotificationofPersonalDataBreachtotheDataController and TD_DesignationofaDataProtectionOfficerUnderSpecifiedConditions and TD_DesignationoftheDataProtectionOfficerBasedonExpertiseandProfessionalQualities and TD_PublicCommunicationandSupervisoryAuthorityNotificationoftheDataProtectionOfficer and TD_InvolvementoftheDataProtectionOfficerinAllDataProtectionMatters and TD_SupportfortheDataProtectionOfficersTasks and TD_SafeguardsfortheIndependenceandNonPenalizationoftheDataProtectionOfficer and TD_DefinitionandSupportofDataProtectionOfficerResponsibilities and TD_AdherencetoApprovedCodesofConductwithMonitoring and TD_CompliancewithAccreditedMonitoringBodyforCodesofConduct and TD_CooperationwithCertificationBodies and TD_CompliancewithGDPRRequirementsforInternationalDataTransfers and TD_RelianceonAdequacyDecisionsforDataTransfers and TD_ImplementationofAppropriateSafeguardsforInternationalTransfers and TD_UseofApprovedBindingCorporateRulesforGroupTransfers and TD_RestrictiononThirdCountryAccessWithoutEULegalAuthorization and TD_UseofDerogationsforInternationalDataTransfersWithoutSafeguards and TD_LiabilityforGDPRViolationsCausingDamage and TD_AccountabilityforCompliancewiththeGDPRSubjecttoFines]]></tf:TrustExpression><tf:Sources><tf:Source tf:id="Source2183071"><tf:Identifier>GDPR</tf:Identifier><tf:Reference>General Data Protection Regulation (GDPR) (EU) 2016/679, as published in the Official Journal of the European Union (OJ L 119, 4.5.2016, p. 1-88).</tf:Reference></tf:Source></tf:Sources></tf:TrustInteroperabilityProfile>