Charging Fees for Requests, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 12(5).
Assessment Step
1
Charging Fees for Requests (ChargingFeesforRequests)
Does the entity refrain from charging a fee for actions under Articles 15 to 22 unless the request is manifestly unfounded or excessive, and if a fee is charged or the request refused, does the entity document justification?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Charging Fees for Requests
The data controller must not charge a fee for actions under Articles 15 to 22, unless the request is manifestly unfounded or excessive; in such cases, the controller may charge a reasonable fee or refuse to act, provided justification is documented.
Citation
GDPR
Art. 12(5), Recital 59
|