Confidentiality of Authorized Personnel, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 28(3)(b).
Assessment Step
1
Confidentiality of Authorized Personnel (ConfidentialityofAuthorizedPersonnel)
Does the entity ensure that all persons authorised to process personal data are bound by confidentiality obligations, either through commitment or statutory obligation?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Confidentiality of Authorized Personnel
The data processor must ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Citation
GDPR
Art. 28(3)(b), Recital 81
|