Fulfillment of the Right to Object to Legitimate Interest or Public Task Processing, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 21(1).
Assessment Step
1
Fulfillment of the Right to Object to Legitimate Interest or Public Task Processing (FulfillmentoftheRighttoObjecttoLegitimateInterestorPublicTaskProcessing)
If and when the entity processes personal data based on legitimate interests or the performance of a task carried out in the public interest or in the exercise of official authority, and the data subject objects, does the entity refrain from processing unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or the processing is necessary for the establishment, exercise, or defense of legal claims?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Fulfillment of the Right to Object to Legitimate Interest or Public Task Processing
If the data controller processes personal data based on legitimate interests or the performance of a task carried out in the public interest or in the exercise of official authority, then the controller must, upon objection by the data subject, no longer process the data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or the processing is necessary for the establishment, exercise, or defense of legal claims.
Citation
GDPR
Art. 21(1), Recital 69
|