Notification of Recipients and Disclosure of Recipient Information Upon Request, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 19.

Assessment Step

1
Notification of Recipients and Disclosure of Recipient Information Upon Request (NotificationofRecipientsandDisclosureofRecipientInformationUponRequest)
When personal data has been rectified, erased, or restricted under Articles 16, 17(1), or 18, does the entity notify each recipient to whom the personal data was disclosed, unless this proves impossible or involves disproportionate effort, and does it inform the data subject of those recipients if requested?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Notification of Recipients and Disclosure of Recipient Information Upon Request
The data controller must notify each recipient to whom personal data has been disclosed of any rectification, erasure, or restriction of processing carried out under Articles 16, 17(1), and 18, unless this proves impossible or involves disproportionate effort. The data controller must also inform the data subject, upon request, about those recipients.
Citation
GDPR
Art. 19, Recital 66