Reliance on Non-Profit Organizations Exception for Processing Special Categories of Personal Data, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 9(2)(d).
Assessment Step
1
Reliance on Non-Profit Organizations Exception for Processing Special Categories of Personal Data (RelianceonNon-ProfitOrganizationsExceptionforProcessingSpecialCategoriesofPersonalData)
If and when the entity relies on the non-profit body exception as the lawful basis for processing special categories of personal data, is the processing conducted with appropriate safeguards, limited to members or regular contacts, and not disclosed outside the organization without the data subject's consent?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Reliance on Non-Profit Organizations Exception for Processing Special Categories of Personal Data
If the data controller relies on the non-profit body exception as the lawful basis for processing special categories of personal data, then the processing must be carried out in the course of legitimate activities with appropriate safeguards by a not-for-profit body with a political, philosophical, religious or trade union aim, relate solely to members or regular contacts, and not be disclosed outside that body without the data subject's consent.
Citation
GDPR
Art. 9(2)(d), Recital 56
|