Providing Timely Information Upon Indirect Collection, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 14(3).
Assessment Step
1
Providing Timely Information Upon Indirect Collection (ProvidingTimelyInformationUponIndirectCollection)
When personal data is not obtained directly from the data subject, does the entity provide all required information as described in Article 14(1) and 14(2) within one month of obtaining the data; or, if the data is used to communicate with the data subject, at the time of the first communication; or, if the data is disclosed to another recipient, before or at the time of disclosure?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Providing Timely Information Upon Indirect Collection
When personal data is not obtained directly from the data subject, the data controller must provide the information described in Article 14(1) and 14(2) within one month of obtaining the personal data; or, if the data is to be used for communication with the data subject, at the time of the first communication; or, if the data is to be disclosed to another recipient, at the latest when the data is first disclosed.
Citation
GDPR
Art. 14(3), Recital 61
|