Fulfillment of the Right to Object to Direct Marketing, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 21(2).
Assessment Step
1
Fulfillment of the Right to Object to Direct Marketing (FulfillmentoftheRighttoObjecttoDirectMarketing)
If and when the entity processes personal data for direct marketing purposes, and the data subject objects, does the entity refrain from processing the data for such purposes?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Fulfillment of the Right to Object to Direct Marketing
If the data controller processes personal data for direct marketing purposes, then the controller must, upon objection by the data subject, no longer process the data for such purposes.
Citation
GDPR
Art. 21(2), Recital 70
|