Providing Additional Required Information Upon Data Collection, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 13(2).

Assessment Step

1
Providing Additional Required Information Upon Data Collection (ProvidingAdditionalRequiredInformationUponDataCollection)
Does the entity, at the time of collecting personal data directly from the data subject, inform the data subject of: the right to withdraw consent at any time; the right to lodge a complaint with a supervisory authority; whether the provision of personal data is a statutory or contractual requirement and the possible consequences of failing to provide such data; and the existence of automated decision-making, including profiling, along with meaningful information about the logic involved and the significance and consequences of such processing?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Providing Additional Required Information Upon Data Collection
When collecting personal data directly from the data subject, the data controller must provide the data subject with: (a) information about the right to withdraw consent at any time; (b) right to lodge a complaint; (c) whether provision of data is statutory/contractual, and consequences of not providing it; (d) existence of automated decision-making, including profiling, and meaningful information about the logic involved, significance, and consequences.
Citation
GDPR
Art. 13(2), Recital 60, 61