Providing Basic Required Information Upon Data Collection, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 13(1).

Assessment Step

1
Providing Basic Required Information Upon Data Collection (ProvidingBasicRequiredInformationUponDataCollection)
Does the entity, at the time of collecting personal data directly from the data subject, provide the data subject with: the identity and contact details of the controller; contact details of the data protection officer (if applicable); the purposes of processing; the legal basis for processing; the legitimate interests pursued (if applicable); the recipients or categories of recipients of the personal data; details of any international transfers and applicable safeguards; the storage period or the criteria used to determine it; the data subject's rights; the right to withdraw consent at any time; the right to lodge a complaint with a supervisory authority; whether the provision of data is a statutory or contractual requirement and the consequences of failing to provide it; and the existence of automated decision-making, including profiling?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Providing Basic Required Information Upon Data Collection
When collecting personal data directly from the data subject, the data controller must provide the data subject with: (a) identity and contact details of the controller; (b) contact details of the DPO (if applicable); (c) purposes and legal basis for processing; (d) legitimate interests (if applicable); (e) recipients or categories of recipients; (f) details of international transfers and safeguards (if applicable); (g) retention period or criteria; (h) data subject rights; (i) right to withdraw consent; (j) right to lodge a complaint; (k) whether provision of data is required and consequences of failure to provide; (l) existence of automated decision-making, including profiling.
Citation
GDPR
Art. 13(1), Recital 60, 61