Implementation of Data Protection by Default, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 25(2).
Assessment Step
1
Implementation of Data Protection by Default (ImplementationofDataProtectionbyDefault)
Does the entity implement appropriate technical and organizational measures to ensure that, by default, only personal data necessary for each specific purpose is processed, including in terms of the amount of data collected, the extent of processing, the period of storage, and the accessibility of the data?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Implementation of Data Protection by Default
The data controller must implement appropriate technical and organizational measures to ensure that, by default, only personal data which is necessary for each specific purpose of the processing is processed. This applies to the amount of personal data collected, the extent of processing, the period of storage, and the accessibility of the data.
Citation
GDPR
Art. 25(2), Recital 78
|