Maintenance of Records of Processing Activities by the Data Processor, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 30(2).
Assessment Step
1
Maintenance of Records of Processing Activities by the Data Processor (MaintenanceofRecordsofProcessingActivitiesbytheDataProcessor)
Does the entity maintain a record of all categories of processing activities carried out on behalf of each data controller, including: the name and contact details of the data processor and the relevant data controllers; the data protection officer (if applicable); the categories of processing carried out; international transfers and safeguards (if applicable); and a general description of security measures (where possible)?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Maintenance of Records of Processing Activities by the Data Processor
The data processor must maintain a record of all categories of processing activities carried out on behalf of a data controller. This record must include: the name and contact details of the data processor and of each data controller on behalf of which the processor is acting, and, where applicable, the data protection officer; the categories of processing carried out on behalf of each data controller; where applicable, transfers of personal data to third countries or international organisations and documentation of suitable safeguards; and where possible, a general description of the technical and organisational security measures.
Citation
GDPR
Art. 30(2), Recital 82
|