Reliance on Public Interest in Public Health Exception for Processing Special Categories of Personal Data, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 9(2)(i).

Assessment Step

1
Reliance on Public Interest in Public Health Exception for Processing Special Categories of Personal Data (RelianceonPublicInterestinPublicHealthExceptionforProcessingSpecialCategoriesofPersonalData)
If and when the entity relies on the public health exception as the lawful basis for processing special categories of personal data, is the processing necessary for reasons of public interest in public health and based on Union or Member State law that includes suitable and specific safeguards for the rights and freedoms of the data subject?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Reliance on Public Interest in Public Health Exception for Processing Special Categories of Personal Data
If the data controller relies on the public health exception as the lawful basis for processing special categories of personal data, then the processing must be necessary for reasons of public interest in the area of public health and based on Union or Member State law which provides for suitable and specific measures to safeguard the rights and freedoms of the data subject.
Citation
GDPR
Art. 9(2)(i), Recital 54