Duty to Inform When Refusing Requests, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 12(4).
Assessment Step
1
Duty to Inform When Refusing Requests (DutytoInformWhenRefusingRequests)
If the entity does not intend to act on a request, does it inform the data subject without delay and at the latest within one month of receipt, stating the reasons and the right to complain or seek judicial remedy?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Duty to Inform When Refusing Requests
The data controller must inform the data subject without delay and at the latest within one month of receipt of the request when it does not intend to take action, including the reasons and the possibility to lodge a complaint with a supervisory authority and seek judicial remedy.
Citation
GDPR
Art. 12(4), Recital 59
|