Providing Basic Required Information Upon Data Collection, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 13(1).
Assessment Step
1
Providing Basic Required Information Upon Data Collection (ProvidingBasicRequiredInformationUponDataCollection)
Does the entity, at the time of collecting personal data directly from the data subject, provide the data subject with: the identity and contact details of the controller; contact details of the data protection officer (if applicable); the purposes of processing; the legal basis for processing; the legitimate interests pursued (if applicable); the recipients or categories of recipients of the personal data; details of any international transfers and applicable safeguards; the storage period or the criteria used to determine it; the data subject's rights; the right to withdraw consent at any time; the right to lodge a complaint with a supervisory authority; whether the provision of data is a statutory or contractual requirement and the consequences of failing to provide it; and the existence of automated decision-making, including profiling?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Providing Basic Required Information Upon Data Collection
When collecting personal data directly from the data subject, the data controller must provide the data subject with: (a) identity and contact details of the controller; (b) contact details of the DPO (if applicable); (c) purposes and legal basis for processing; (d) legitimate interests (if applicable); (e) recipients or categories of recipients; (f) details of international transfers and safeguards (if applicable); (g) retention period or criteria; (h) data subject rights; (i) right to withdraw consent; (j) right to lodge a complaint; (k) whether provision of data is required and consequences of failure to provide; (l) existence of automated decision-making, including profiling.
Citation
GDPR
Art. 13(1), Recital 60, 61
|