Implementation of Data Protection by Design, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 25(1).
Assessment Step
1
Implementation of Data Protection by Design (ImplementationofDataProtectionbyDesign)
At the time of determining the means for processing and at the time of the processing itself, does the entity implement appropriate technical and organizational measures -- such as pseudonymisation -- to effectively implement data protection principles and integrate safeguards that meet GDPR requirements and protect the rights of data subjects, taking into account the state of the art, cost of implementation, nature, scope, context, and purposes of processing, and the risks to individuals' rights and freedoms?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Implementation of Data Protection by Design
The data controller must, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organizational measures -- such as pseudonymisation -- designed to implement data protection principles in an effective manner, and to integrate necessary safeguards into the processing to meet the GDPR requirements and protect the rights of data subjects. These measures must take into account the state of the art, the cost of implementation, the nature, scope, context, and purposes of processing, and the risks to the rights and freedoms of natural persons.
Citation
GDPR
Art. 25(1), Recital 78
|