Providing a Copy of Personal Data upon Request, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 15(3).

Assessment Step

1
Providing a Copy of Personal Data upon Request (ProvidingaCopyofPersonalDatauponRequest)
When requested, does the entity provide the data subject with a copy of the personal data undergoing processing, and does it only charge a reasonable administrative fee for additional copies?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Providing a Copy of Personal Data upon Request
The data controller must, upon request, provide the data subject with a copy of the personal data undergoing processing. For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs.
Citation
GDPR
Art. 15(3), Recital 63