Fulfillment of the Right to Restriction of Processing, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 18(1).

Assessment Step

1
Fulfillment of the Right to Restriction of Processing (FulfillmentoftheRighttoRestrictionofProcessing)
Does the entity restrict the processing of personal data upon request from the data subject if: the accuracy of the personal data is contested and verification is pending; the processing is unlawful and the data subject prefers restriction over erasure; the controller no longer needs the data but it is required for legal claims; or the data subject has objected to processing and a determination of overriding legitimate grounds is pending?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Fulfillment of the Right to Restriction of Processing
The data controller must restrict the processing of personal data upon request from the data subject if: the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy; the processing is unlawful and the data subject opposes erasure and requests restriction instead; the controller no longer needs the personal data for processing purposes but the data subject requires it for the establishment, exercise, or defense of legal claims; or the data subject has objected to processing and the controller is verifying whether legitimate grounds override the objection.
Citation
GDPR
Art. 18(1), Recital 67