Contractual Necessity as Legal Basis, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 6(1)(b).

Assessment Step

1
Contractual Necessity as Legal Basis (ContractualNecessityasLegalBasis)
Does the entity ensure that personal data is processed lawfully where the processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Contractual Necessity as Legal Basis
The data controller must ensure that personal data is processed lawfully where processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Citation
GDPR
Art. 6(1)(b), Recital 44