Establishment and Demonstration of GDPR Compliance Measures, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 24(1).
Assessment Step
1
Establishment and Demonstration of GDPR Compliance Measures (EstablishmentandDemonstrationofGDPRComplianceMeasures)
Does the entity implement appropriate technical and organizational measures to ensure and to be able to demonstrate that its processing is performed in accordance with the GDPR, taking into account the nature, scope, context, and purposes of the processing and the risks of varying likelihood and severity for the rights and freedoms of natural persons?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Establishment and Demonstration of GDPR Compliance Measures
The data controller must implement appropriate technical and organizational measures to ensure and to be able to demonstrate that processing is performed in accordance with the GDPR, taking into account the nature, scope, context, and purposes of processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons.
Citation
GDPR
Art. 24(1), Recital 74
|