Communication of Erasure Request to Other Controllers, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 17(2).
Assessment Step
1
Communication of Erasure Request to Other Controllers (CommunicationofErasureRequesttoOtherControllers)
If the entity has made personal data public and is obliged to erase it, does the entity take reasonable steps, including technical measures, to inform other controllers processing that data of the data subject's request for erasure of links to, or copies or replications of, that data?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Communication of Erasure Request to Other Controllers
Where the data controller has made personal data public and is obliged to erase the data, the controller must take reasonable steps, including technical measures, to inform other controllers processing the data that the data subject has requested erasure of any links to, or copies or replications of, that data.
Citation
GDPR
Art. 17(2), Recital 66
|