GDPR
6 of the 40 clauses of GDPR are cited by this register, on Breach notification report pack, Customer data export and transfer, Customer statement and notification feed, Data retention purge, Regulator incident notification, Warehouse load and marts. Every one below is quoted from the copy we hold, with the hours it states where it states any.
Use only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised to process are under a duty of confidentiality, takes all Article 32 measures, respects the sub-processor conditions, assists the controller in responding to data subject rights requests, assists with Articles 32 to 36, deletes or returns all personal data at the controller's choice at the end of the service and deletes existing copies unless law requires retention, and makes available all information needed to demonstrate compliance and allows for and contributes to audits and inspections. The processor must immediately inform the controller if it considers an instruction infringes data protection law. The same obligations must be imposed on any sub-processor, and the initial processor remains fully liable for the sub-processor's performance. A processor that determines purposes and means is a controller for that processing.
What an assessor asks to see: A processor inventory reconciled against the vendor register or accounts payable, so no processor is missing from it; The Article 28(3) contract for each processor, checked clause by clause against the eight stipulations the Article names; Due diligence evidence gathered before appointment showing sufficient guarantees, distinct from the signed contract; The sub-processor authorisation position for each processor, the current sub-processor list, and evidence changes were notified. Where it usually falls short: The processor's own standard terms accepted, which commonly omit the audit right, the deletion choice and the instruction infringement notice
Maintain a written, including electronic, record of processing activities under the controller's responsibility containing the name and contact details of the controller, any joint controller, the representative and the data protection officer, the purposes of the processing, a description of the categories of data subjects and of personal data, the categories of recipients including those in third countries and international organisations, any transfers to a third country or international organisation with that destination identified and, for transfers under the second subparagraph of Article 49(1), the documentation of suitable safeguards, the envisaged time limits for erasure of each category where possible, and a general description of the Article 32(1) technical and organisational security measures where possible. A processor must maintain an equivalent record of the categories of processing carried out on behalf of each controller. Make the record available to the supervisory authority on request. The obligation does not apply to an organisation employing fewer than 250 persons unless the processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or includes special category or criminal offence data.
What an assessor asks to see: The record of processing activities in full, checked against the seven controller elements, or the four processor elements, the Article lists; Version history showing when each entry was last reviewed and by whom; Reconciliation of the record against a system inventory or data flow map, to show nothing is missing rather than that the entries read well; The transfer entries with the third country identified and the safeguard documentation referenced. Where it usually falls short: Records written once during the implementation project and never updated against reality, so they describe systems long replaced and omit those adopted since
Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Those measures include, as appropriate, the pseudonymisation and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, the ability to restore the availability of and access to personal data in a timely manner after a physical or technical incident, and a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures. Assess the appropriate level of security against the risks presented by the processing, in particular accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed. Take steps to ensure that any person acting under the controller's or processor's authority who has access to personal data processes it only on instructions.
What an assessor asks to see: The security risk assessment per processing activity, expressed as risk to the rights and freedoms of individuals rather than only as risk to the organisation; Encryption and pseudonymisation coverage at rest, in transit and in backup, with the decision recorded where either was judged not appropriate; Restoration testing results showing personal data was actually recovered inside the intended timeframe, with the date and outcome; The regular testing programme Article 32(1)(d) requires: penetration tests, vulnerability scanning and control effectiveness reviews, with findings closed out. Where it usually falls short: Risk assessed as impact to the business, so processing that is low risk to the organisation and high risk to individuals attracts weak measures
On becoming aware of a personal data breach, notify it to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; a notification made later than 72 hours must be accompanied by the reasons for the delay. A processor must notify its controller without undue delay after becoming aware of a breach. The notification must at least describe the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned, give the name and contact details of the data protection officer or other contact point, describe the likely consequences, and describe the measures taken or proposed including any measures to mitigate adverse effects. Information may be provided in phases where it cannot all be given at once. Document every personal data breach, including the facts, its effects and the remedial action taken, so the supervisory authority can verify compliance with this Article.
What an assessor asks to see: The internal breach register covering all breaches including those assessed as not notifiable, with the risk assessment recorded for each; The awareness timestamp per incident and the basis for it, since the 72 hours runs from awareness and not from confirmation or containment; Notifications as submitted, checked against the four content elements Article 33(3) requires; The methodology used to decide notifiability, and evidence it was applied rather than the decision reached first and documented after. Where it usually falls short: The awareness clock started at the end of the investigation rather than at the point of reasonable certainty that a breach had occurred
Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, communicate the breach to the affected data subjects without undue delay, describing in clear and plain language the nature of the breach and giving at least the contact point, the likely consequences and the measures taken or proposed including mitigation. Communication is not required where the controller had implemented appropriate technical and organisational protection measures and applied them to the affected data, in particular measures such as encryption rendering the data unintelligible to anyone unauthorised, where the controller has since taken measures making the high risk no longer likely to materialise, or where individual communication would involve disproportionate effort, in which case a public communication or similar equally effective measure must be made instead. The supervisory authority may require communication or decide that one of the exemptions applies.
What an assessor asks to see: The high risk assessment per breach, kept distinct from the Article 33 assessment, which uses a lower threshold; The communication as sent, assessed for clear and plain language and for the three content elements required; Where the encryption exemption is relied on, evidence the measure covered the specific affected data and that the keys were not also compromised; Where disproportionate effort is claimed, the public communication actually made and evidence of the reach it achieved. Where it usually falls short: Communication deferred until the investigation completes, when the Article requires it without undue delay once high risk is identified
Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.
What an assessor asks to see: The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it; Retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs; Minimisation analysis per collection point showing why each field is necessary for the stated purpose; Accuracy controls: how inaccurate data is detected, and records of rectification or erasure carried out without delay. Where it usually falls short: Purposes written so broadly, for example business purposes or service improvement, that no later use could ever be incompatible with them
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. The whole standard on compliance.theartofservice.com.