Permitted Processing During Restriction, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 18(2).

Assessment Step

1
Permitted Processing During Restriction (PermittedProcessingDuringRestriction)
When processing has been restricted at the request of the data subject, does the entity ensure that further processing occurs only with the data subject's consent, for legal claims, to protect the rights of another person, or for important public interest reasons?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Permitted Processing During Restriction
When processing has been restricted under Article 18(1), the data controller must ensure that the personal data is only processed: with the data subject's consent; for the establishment, exercise, or defense of legal claims; for the protection of the rights of another natural or legal person; or for reasons of important public interest of the Union or a Member State.
Citation
GDPR
Art. 18(2), Recital 67