Timely Response to Data Subject Requests, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 12(3).
Assessment Step
1
Timely Response to Data Subject Requests (TimelyResponsetoDataSubjectRequests)
Does the entity provide information on action taken on a request under Articles 15 to 22 without undue delay and within one month of receipt, and if an extension is necessary, notify the data subject within one month with the reason and expected duration?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Timely Response to Data Subject Requests
The data controller must provide information on action taken on a request under Articles 15 to 22 without undue delay and in any event within one month of receipt, with extensions up to two additional months where necessary, notifying the data subject of delay and reasons.
Citation
GDPR
Art. 12(3), Recital 59
|