Facilitation of Data Subject Rights, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 12(2).

Assessment Step

1
Facilitation of Data Subject Rights (FacilitationofDataSubjectRights)
Does the entity facilitate the exercise of rights under Articles 15 to 22 and refrain from refusing to act on a request unless it can demonstrate it is not in a position to identify the data subject?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Facilitation of Data Subject Rights
The data controller must facilitate the exercise of data subject rights under Articles 15 to 22 and must not refuse to act on a request unless the controller demonstrates it is not in a position to identify the data subject.
Citation
GDPR
Art. 12(2), Recital 59