Liability for GDPR Violations Causing Damage, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 82(2)-(3).
Assessment Step
1
Liability for GDPR Violations Causing Damage (LiabilityforGDPRViolationsCausingDamage)
If personal data processing results in damage due to a violation of the GDPR, is the entity prepared to assume liability where it acted as a data controller or, in the case of a data processor, where it failed to meet processor-specific obligations or acted outside the data controller’s instructions?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Liability for GDPR Violations Causing Damage
The data controller is liable for damage caused by processing that infringes the GDPR. The data processor is liable for damage caused by its failure to comply with processor-specific obligations under the GDPR, or by acting outside or contrary to lawful instructions from the data controller.
Citation
GDPR
Art. 82(2)–(3), Recital 146
|