Fulfillment of Data Subject Right of Access, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 15(1).

Assessment Step

1
Fulfillment of Data Subject Right of Access (FulfillmentofDataSubjectRightofAccess)
When the data subject requests access, does the entity confirm whether personal data concerning the data subject is being processed and, if so, provide the data subject with: access to the personal data; the purposes of processing; the categories of personal data concerned; the recipients or categories of recipients, including those in third countries or international organisations; the retention period or criteria used to determine it; the rights to request rectification, erasure, restriction of processing, or to object; the right to lodge a complaint with a supervisory authority; the source of the data (if not collected from the data subject); and the existence of automated decision-making, including profiling, along with meaningful information about the logic involved and its significance and consequences?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Fulfillment of Data Subject Right of Access
The data controller must, upon request from the data subject, confirm whether personal data concerning that data subject is being processed, and if so, provide access to the personal data along with the following information: the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipients to whom the personal data have been or will be disclosed, particularly recipients in third countries or international organisations; the envisaged retention period or the criteria used to determine it; the existence of the rights to request rectification, erasure, restriction of processing, or to object to such processing; the right to lodge a complaint with a supervisory authority; where the personal data was not collected from the data subject, any available information as to its source; and the existence of automated decision-making, including profiling, with meaningful information about the logic involved and the significance and consequences of such processing.
Citation
GDPR
Art. 15(1), Recital 63