Restriction of Processing to Documented Instructions, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 29.

Assessment Step

1
Restriction of Processing to Documented Instructions (RestrictionofProcessingtoDocumentedInstructions)
Does the entity ensure that any natural person acting under its authority, and who has access to personal data, processes that data only on documented instructions from a data controller, unless processing is required by Union or Member State law?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Restriction of Processing to Documented Instructions
The data controller and the data processor must ensure that any natural person acting under their authority, who has access to personal data, does not process that data except on documented instructions from the data controller, unless required to do so by Union or Member State law.
Citation
GDPR
Art. 29, Recital 81