Privacy
The documents personal data brings with it: the policy, the notice, the rights procedure, the breach procedure, the record of processing, the impact assessment, the transfer rules.
Policy types in this family
13- Consent management policy policy
When consent is the basis, how it is asked for, recorded, proven and withdrawn, and how children's consent is handled. Required by ISO 27701, GDPR; owner the data protection officer or privacy lead. - Cookie policy record
Which cookies and trackers the sites set, why, for how long, and how visitors choose. Required by GDPR; owner the data protection officer or privacy lead. - Data processing agreement record
The terms every processor signs: instructions, confidentiality, security, sub-processors, assistance, deletion and audit. Required by ISO 27701, GDPR; owner the data protection officer or privacy lead. - Data protection impact assessment procedure procedure
When an impact assessment is required, how it is carried out, what it must contain, who signs it and when the authority is consulted. Required by ISO 27701, GDPR; owner the data protection officer or privacy lead. - Data protection officer and privacy roles record
Who the data protection officer is, how they are placed and resourced, what they do, and who else holds privacy responsibilities. Required by ISO 27701, GDPR; owner the data protection officer or privacy lead. - Data protection policy policy
The organisation's internal rules for personal data: the principles, the roles, the lawful bases it relies on and how it demonstrates them. Required by ISO 27001, ISO 27701, GDPR; owner the data protection officer or privacy lead. - Data sharing agreement record
The arrangement between controllers who share personal data: who does what, who answers the data subject, and what each may do with the data. Required by ISO 27701, GDPR; owner the data protection officer or privacy lead. - Data subject rights procedure procedure
How a request from a data subject is received, verified, logged, answered within the deadline and, where refused, explained. Required by ISO 27701, GDPR; owner the data protection officer or privacy lead. - International data transfer policy policy
On what basis personal data may leave the jurisdiction, which safeguards are used, and how each transfer is assessed and recorded. Required by ISO 27701, GDPR; owner the data protection officer or privacy lead. - Legitimate interests assessment record
The recorded three-part test behind every processing activity that relies on legitimate interests. Required by ISO 27701, GDPR; owner the data protection officer or privacy lead. - Personal data breach procedure procedure
How a personal data breach is recognised, assessed against the notification thresholds, notified to the authority within 72 hours and to the people affected, and recorded. Required by ISO 27701, GDPR; owner the data protection officer or privacy lead. - Privacy notice record
What data subjects are told: who the controller is, why data is collected, on what basis, for how long, with whom it is shared and their rights. Required by ISO 27701, GDPR; owner the data protection officer or privacy lead. - Record of processing activities record
The register of every processing activity: purposes, categories, recipients, transfers, retention and security measures. Required by ISO 27701, GDPR; owner the data protection officer or privacy lead.
What reaches this family
| ISO 27001 | Expects: data protection policy. Requires, by clause: ISO 27001 5.34. |
|---|---|
| ISO 27701 | Expects: data processing agreement, data protection impact assessment procedure, data protection policy, data subject rights procedure, personal data breach procedure, privacy notice, record of processing activities. Requires, by clause: ISO 27701 A.1.2.4, ISO 27701 A.1.2.5, ISO 27701 A.1.2.7, ISO 27701 A.1.2.6, ISO 27701 5.3, ISO 27701 5.2, ISO 27701 A.1.2.8, ISO 27701 A.1.3.10, ISO 27701 A.1.3.7, ISO 27701 A.1.5.2, ISO 27701 A.1.5.4, ISO 27701 A.1.2.3, ISO 27701 A.3.12, ISO 27701 A.1.3.3, ISO 27701 A.1.3.4, ISO 27701 A.1.2.9, ISO 27701 A.1.2.2. |
| GDPR | Expects: data processing agreement, data protection impact assessment procedure, data protection policy, data subject rights procedure, international data transfer policy, personal data breach procedure, privacy notice, record of processing activities. Requires, by clause: GDPR Art. 7, GDPR Art. 8, GDPR Art. 13, GDPR Art. 28, GDPR Art. 35, GDPR Art. 36, GDPR Art. 37, GDPR Art. 39, GDPR Art. 24, GDPR Art. 26, GDPR Art. 12, GDPR Art. 15, GDPR Art. 17, GDPR Art. 44, GDPR Art. 46, GDPR Art. 6, GDPR Art. 33, GDPR Art. 34, GDPR Art. 14, GDPR Art. 30. |
Register the documents in this family
Paste the list; every document in this family is placed in its type, given its owner and cadence against the clauses, and the ones the regimes expect and the list does not carry are named. Eight documents free, no account.
Build a register