Maintenance of Records of Processing Activities by the Data Processor, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 30(2).

Assessment Step

1
Maintenance of Records of Processing Activities by the Data Processor (MaintenanceofRecordsofProcessingActivitiesbytheDataProcessor)
Does the entity maintain a record of all categories of processing activities carried out on behalf of each data controller, including: the name and contact details of the data processor and the relevant data controllers; the data protection officer (if applicable); the categories of processing carried out; international transfers and safeguards (if applicable); and a general description of security measures (where possible)?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Maintenance of Records of Processing Activities by the Data Processor
The data processor must maintain a record of all categories of processing activities carried out on behalf of a data controller. This record must include: the name and contact details of the data processor and of each data controller on behalf of which the processor is acting, and, where applicable, the data protection officer; the categories of processing carried out on behalf of each data controller; where applicable, transfers of personal data to third countries or international organisations and documentation of suitable safeguards; and where possible, a general description of the technical and organisational security measures.
Citation
GDPR
Art. 30(2), Recital 82