Consent-Based Processing of Personal Data, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 6(1)(a).
Assessment Step
1
Consent-Based Processing of Personal Data (Consent-BasedProcessingofPersonalData)
Does the entity ensure that personal data is processed lawfully where the data subject has given consent to the processing of his or her personal data for one or more specific purposes?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Consent-Based Processing of Personal Data
The data controller must ensure that personal data is processed lawfully where the data subject has given consent to the processing of his or her personal data for one or more specific purposes.
Citation
GDPR
Art. 6(1)(a), Recital 32, 42
|