Fulfillment of the Right to Restriction of Processing, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 18(1).
Assessment Step
1
Fulfillment of the Right to Restriction of Processing (FulfillmentoftheRighttoRestrictionofProcessing)
Does the entity restrict the processing of personal data upon request from the data subject if: the accuracy of the personal data is contested and verification is pending; the processing is unlawful and the data subject prefers restriction over erasure; the controller no longer needs the data but it is required for legal claims; or the data subject has objected to processing and a determination of overriding legitimate grounds is pending?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Fulfillment of the Right to Restriction of Processing
The data controller must restrict the processing of personal data upon request from the data subject if: the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy; the processing is unlawful and the data subject opposes erasure and requests restriction instead; the controller no longer needs the personal data for processing purposes but the data subject requires it for the establishment, exercise, or defense of legal claims; or the data subject has objected to processing and the controller is verifying whether legitimate grounds override the objection.
Citation
GDPR
Art. 18(1), Recital 67
|