Customer statement and notification feed
None of the held texts sets a fixed period on this consumer; every row below reads no period set by the text. Paste one job that feeds this consumer, for example customer_statement_feed, weekly, and the register reads its period against the clocks below, names the gap in hours, and carries the question for its owner.
Matched on the job name or the consumer column by these words: statement, customer feed, customer portal, notification feed, customer notif, estatement, statement feed. A backup, replication, feed or return job in this class is expected to name a fallback; a blank one is a finding.
The clock each rule sets
| Regime | Clock | Clause |
|---|---|---|
| GDPR | no clock | GDPR Art. 5 Principles relating to processing of personal data |
| DORA | no clock | DORA Art. 11 Response and recovery |
| ISO 22301 | no clock | ISO 22301 8.4.4 Business continuity plans |
Questions this page answers
How often does GDPR require customer statement and notification feed?
The held text of GDPR Art. 5 (Principles relating to processing of personal data) sets no fixed period: no period set by the text. Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.
How often does DORA (Regulation (EU) 2022/2554) require customer statement and notification feed?
The held text of DORA Art. 11 (Response and recovery) sets no fixed period: no period set by the text. Financial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.
How often does ISO 22301:2019 require customer statement and notification feed?
The held text of ISO 22301 8.4.4 (Business continuity plans) sets no fixed period: no period set by the text. Document and maintain business continuity plans that guide teams through response and recovery, collectively containing the actions to continue or recover prioritized activities within predetermined time frames, the means of monitoring the disruption and the response, the pre defined thresholds and process for activating the response, procedures to deliver products and services at agreed capacity, and how the immediate consequences are managed with regard to individual welfare, prevention of further loss and environmental impact; each plan must state purpose, scope and objectives, the roles and responsibilities of the implementing team, the actions implementing the solutions, the supporting information needed to activate, operate, coordinate and communicate including activation criteria, internal and external interdependencies, resource requirements, reporting requirements and a stand down process, and must be usable and available at the time and place it is needed.
What does the register ask the owner of a customer statement and notification feed job?
What does the customer see if this feed stops for a day, and who is called?
The clauses in full
Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.
What an assessor asks to see: The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it; Retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs; Minimisation analysis per collection point showing why each field is necessary for the stated purpose; Accuracy controls: how inaccurate data is detected, and records of rectification or erasure carried out without delay. Where it usually falls short: Purposes written so broadly, for example business purposes or service improvement, that no later use could ever be incompatible with them
Financial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.
What an assessor asks to see: ICT business continuity policy + response/recovery plans; Records of plan testing. Where it usually falls short: No ICT continuity/response/recovery plans
Document and maintain business continuity plans that guide teams through response and recovery, collectively containing the actions to continue or recover prioritized activities within predetermined time frames, the means of monitoring the disruption and the response, the pre defined thresholds and process for activating the response, procedures to deliver products and services at agreed capacity, and how the immediate consequences are managed with regard to individual welfare, prevention of further loss and environmental impact; each plan must state purpose, scope and objectives, the roles and responsibilities of the implementing team, the actions implementing the solutions, the supporting information needed to activate, operate, coordinate and communicate including activation criteria, internal and external interdependencies, resource requirements, reporting requirements and a stand down process, and must be usable and available at the time and place it is needed.
What an assessor asks to see: Plan set with each plan carrying every required element; Activation criteria and thresholds stated in the plan itself; Interdependency and resource sections reconciled to the BIA; Stand down process defined. Where it usually falls short: Plans that cover activation and response but have no stand down, so the organization never formally returns to normal
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Run this job through the register