Transmission of Personal Data to Another Controller, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 20(2).
Assessment Step
1
Transmission of Personal Data to Another Controller (TransmissionofPersonalDatatoAnotherController)
If and when. the entity processes personal data based on the data subject's consent or a contract, and the processing is carried out by automated means, does the entity, upon request and where technically feasible, transmit the personal data directly to another controller?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Transmission of Personal Data to Another Controller
If the data controller processes personal data based on the data subject's consent or a contract, and the processing is carried out by automated means, then the controller must, upon request and where technically feasible, transmit the personal data directly to another controller.
Citation
GDPR
Art. 20(2), Recital 68
|