Providing Additional Required Information Upon Data Collection, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 13(2).
Assessment Step
1
Providing Additional Required Information Upon Data Collection (ProvidingAdditionalRequiredInformationUponDataCollection)
Does the entity, at the time of collecting personal data directly from the data subject, inform the data subject of: the right to withdraw consent at any time; the right to lodge a complaint with a supervisory authority; whether the provision of personal data is a statutory or contractual requirement and the possible consequences of failing to provide such data; and the existence of automated decision-making, including profiling, along with meaningful information about the logic involved and the significance and consequences of such processing?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Providing Additional Required Information Upon Data Collection
When collecting personal data directly from the data subject, the data controller must provide the data subject with: (a) information about the right to withdraw consent at any time; (b) right to lodge a complaint; (c) whether provision of data is statutory/contractual, and consequences of not providing it; (d) existence of automated decision-making, including profiling, and meaningful information about the logic involved, significance, and consequences.
Citation
GDPR
Art. 13(2), Recital 60, 61
|