Providing Basic Required Information Upon Indirect Data Collection, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 14(1).
Assessment Step
1
Providing Basic Required Information Upon Indirect Data Collection (ProvidingBasicRequiredInformationUponIndirectDataCollection)
When personal data is not obtained directly from the data subject, does the entity provide the data subject with: the identity and contact details of the controller; the contact details of the data protection officer (if applicable); the purposes of the processing; the legal basis for the processing; the categories of personal data concerned; the recipients or categories of recipients; and, where applicable, the details of international data transfers and the applicable safeguards?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Providing Basic Required Information Upon Indirect Data Collection
When personal data is not obtained directly from the data subject, the data controller must provide the data subject with the following information: the identity and contact details of the controller; the contact details of the data protection officer (if applicable); the purposes of the processing; the legal basis for the processing; the categories of personal data concerned; the recipients or categories of recipients of the personal data; and, where applicable, the details of any intention to transfer personal data to a third country or international organisation and the safeguards applied.
Citation
GDPR
Art. 14(1), Recital 60, 61
|