Processing of Personal Data Only on Documented Instructions, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 28(3)(a).

Assessment Step

1
Processing of Personal Data Only on Documented Instructions (ProcessingofPersonalDataOnlyonDocumentedInstructions)
Does the entity process personal data only on documented instructions from a data controller, including instructions on transfers to third countries or international organisations, and, if required by law to process without such instructions, does the entity inform the dta controller in advance unless prohibited by law for important public interest reasons?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Processing of Personal Data Only on Documented Instructions
The data processor must process personal data only on documented instructions from a data controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law; in such a case, the processor must inform the controller of that legal requirement before processing, unless prohibited by law for important public interest reasons.
Citation
GDPR
Art. 28(3)(a), Recital 81