Providing Additional Required Information Upon Indirect Data Collection, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 14(2).
Assessment Step
1
Providing Additional Required Information Upon Indirect Data Collection (ProvidingAdditionalRequiredInformationUponIndirectDataCollection)
When personal data is not obtained directly from the data subject, does the entity provide the data subject with: the retention period or criteria used to determine it; the rights to access, rectify, erase, restrict, or object to processing, and to data portability; the right to withdraw consent (if applicable); the right to lodge a complaint with a supervisory authority; the source of the personal data and whether it came from a publicly accessible source; and the existence of automated decision-making, including profiling, with meaningful information about the logic involved and the significance and consequences?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Providing Additional Required Information Upon Indirect Data Collection
When personal data is not obtained directly from the data subject, the data controller must provide the data subject with the following information: the period for which the personal data will be stored or, if that is not possible, the criteria used to determine that period; the existence of the rights to request access to, rectification or erasure of personal data or restriction of processing concerning the data subject and to object to processing as well as the right to data portability; where the processing is based on consent, the existence of the right to withdraw consent at any time; the right to lodge a complaint with a supervisory authority; the source from which the personal data originate and, if applicable, whether it came from publicly accessible sources; and the existence of automated decision-making, including profiling, and meaningful information about the logic involved as well as the significance and consequences of such processing.
Citation
GDPR
Art. 14(2), Recital 60, 61
|