Reliance on Employment and Social Protection Obligations, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 9(2)(b).
Assessment Step
1
Reliance on Employment and Social Protection Obligations (RelianceonEmploymentandSocialProtectionObligations)
If and when the entity relies on employment, social security, or social protection law as the lawful basis for processing special categories of personal data, is the processing necessary for carrying out obligations and exercising specific rights, and is it authorized by Union or Member State law or a collective agreement pursuant to Member State law?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Reliance on Employment and Social Protection Obligations
If the data controller relies on employment, social security, or social protection law as the lawful basis for processing special categories of personal data, then the processing must be necessary for carrying out obligations and exercising specific rights in that domain, and it must be authorized by Union or Member State law or a collective agreement pursuant to Member State law.
Citation
GDPR
Art. 9(2)(b), Recital 52
|