Use of Sub-Processors Only with Written Authorization, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 28(2).
Assessment Step
1
Use of Sub-Processors Only with Written Authorization (UseofSub-ProcessorsOnlywithWrittenAuthorization)
Does the entity ensure that its data processors do not engage sub-processors without prior specific or general written authorization, and that the processors notify the entity of any intended changes to allow for objections?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Use of Sub-Processors Only with Written Authorization
The data controller must ensure that the data processor does not engage another processor without prior specific or general written authorization, and that the processor informs the controller of any intended changes concerning addition or replacement of sub-processors, allowing the controller to object.
Citation
GDPR
Art. 28(2), Recital 81
|