Policy Register

GDPR (Regulation (EU) 2016/679)

The register cites 22 of its 40 clauses, on 16 policy types. Rendered when the buyer ticks "GDPR".

Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. Open the standard on the compliance platform. What it expects of a policy set: the GDPR regime page.

Clauses cited

22 of 40
GDPR Art. 5 Principles relating to processing of personal data

Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.

Evidence an auditor accepts: The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it; retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs; minimisation analysis per collection point showing why each field is necessary for the stated purpose
Common gap: Purposes written so broadly, for example business purposes or service improvement, that no later use could ever be incompatible with them
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 6 Lawfulness of processing

Process personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of official authority, or legitimate interests that are not overridden by the data subject's interests, rights and freedoms. Public authorities cannot rely on legitimate interests for processing carried out in performance of their tasks. Where the basis is legal obligation or public task, that basis must be laid down in Union or Member State law and the purpose must be determined in it. Before processing for a purpose other than the one collected for, without consent or a legal mandate, assess compatibility against the link between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place.

Evidence an auditor accepts: A lawful basis recorded per processing activity, not per system or per department; legitimate interests assessments showing the interest pursued, the necessity test and the balancing against the data subject's rights; the Union or Member State provision cited where the basis is legal obligation or public task
Common gap: Consent recorded as the basis where the processing would happen regardless of the answer, which makes it neither free nor the real basis
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 7 Conditions for consent

Where processing rests on consent, be able to demonstrate that the data subject consented. Where the consent request forms part of a wider written declaration, present it in a manner clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Inform the data subject before consenting that consent may be withdrawn at any time, make withdrawal as easy as giving consent, and treat processing carried out before withdrawal as still lawful. Consent is not freely given where performance of a contract, including provision of a service, is made conditional on consent to processing that the contract does not require.

Evidence an auditor accepts: Consent records capturing who consented, when, to what wording, and through what mechanism; the consent wording and interface as presented, versioned, so an old record can be tied to what was actually shown; the withdrawal mechanism, with evidence it works and takes no more steps than giving consent did
Common gap: Consent logged as a boolean with no record of the wording shown, so the organisation cannot demonstrate what was agreed to
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 8 Conditions applicable to child's consent

Where consent is the lawful basis and information society services are offered directly to a child, processing the child's personal data on the child's own consent is lawful only from age 16, or from the lower age a Member State has set in law, which may be no lower than 13. Below that age the processing is lawful only to the extent consent is given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify that it was, taking available technology into consideration.

Evidence an auditor accepts: The assessment of whether the service is an information society service offered directly to children; the age threshold applied per Member State, with evidence the applicable national lower age was checked rather than assumed; the age assurance mechanism, and the reasoning for why it is a reasonable effort given available technology
Common gap: A self declared date of birth with no verification at all treated as reasonable effort
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 12 Transparent information, communication and modalities for rights

Provide the Article 13 and 14 information and every Article 15 to 22 and 34 communication in a concise, transparent, intelligible and easily accessible form, in clear and plain language, with particular care where the information is addressed to a child, normally in writing including by electronic means. Facilitate the exercise of data subject rights and do not refuse to act unless the controller demonstrates it cannot identify the data subject. Provide information on action taken without undue delay and in any event within one month of receipt, extendable by two further months where the complexity and number of requests requires it, with the data subject informed of the extension and its reasons within the first month. Where no action is taken, say so within one month with the reasons and inform the data subject of the right to lodge a complaint with a supervisory authority and to seek a judicial remedy. Act free of charge; a reasonable fee or refusal is available only for manifestly unfounded or excessive requests, and the controller bears the burden of demonstrating that character. Additional information may be requested only where there are reasonable doubts about the requester's identity.

Evidence an auditor accepts: The request register showing receipt date, response date, and any extension with its notification and stated reasons; readability evidence for the privacy information, such as a plain language review or a reading age assessment; the identity verification standard applied, with the reasoning that it is proportionate rather than routine
Common gap: The one month clock started when the request reached the privacy team rather than when it reached the organisation
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 13 Information to be provided where personal data are collected

Where personal data is collected from the data subject, provide at the time it is obtained the identity and contact details of the controller and any representative, the contact details of the data protection officer, the purposes and the legal basis, the legitimate interests where that is the basis, the recipients or categories of recipient, and any intention to transfer to a third country with the existence or absence of an adequacy decision and, for Article 46, 47 or 49(1) transfers, reference to the safeguards and how to obtain a copy. Provide in addition the storage period or the criteria used to determine it, the existence of the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent where consent is the basis, the right to lodge a complaint with a supervisory authority, whether providing the data is a statutory or contractual requirement and the consequences of not providing it, and the existence of automated decision-making including profiling with meaningful information about the logic involved and its significance and envisaged consequences. Before further processing for a new purpose, provide that purpose and the further information first.

Evidence an auditor accepts: The privacy notice mapped item by item against every information element Article 13 lists; evidence of the point and timing at which the notice is presented for each collection channel, including forms, telephone and in person; the storage periods or criteria as published, reconciled against the actual retention schedule
Common gap: Recipients described only as third parties or trusted partners, which names neither a recipient nor a category
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 14 Information where personal data have not been obtained from the data subject

Where personal data has not been obtained from the data subject, provide the same identity, contact, purpose, legal basis, recipient and transfer information as Article 13, plus the categories of personal data concerned and the source the data came from including whether it was a publicly accessible source. Provide it within a reasonable period and at the latest within one month of obtaining the data, or at the latest at the first communication with the data subject if the data is used to communicate with them, or at the latest when the data is first disclosed to another recipient. The obligation does not apply where the data subject already has the information, where provision proves impossible or would involve disproportionate effort in which case appropriate protective measures including making the information publicly available must be taken, where obtaining or disclosure is expressly laid down by Union or Member State law with appropriate safeguards, or where the data must remain confidential under an obligation of professional secrecy.

Evidence an auditor accepts: A source register showing, per dataset, where the data came from and whether the source was publicly accessible; evidence of the notification sent with its date, tested against the one month, first communication and first disclosure triggers; the disproportionate effort assessment where the exemption is relied on, showing what was weighed rather than only that a conclusion was reached
Common gap: Purchased or enriched marketing data used with no Article 14 notification at all, which is the most common finding in this area
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 15 Right of access by the data subject

On request, confirm whether personal data concerning the data subject is being processed and, where it is, provide access to that data together with the purposes, the categories of personal data, the recipients or categories of recipient including any in third countries or international organisations, the envisaged storage period or the criteria setting it, the existence of the rights to rectification, erasure, restriction and objection, the right to lodge a complaint with a supervisory authority, any available information on the source where the data was not collected from the data subject, and the existence of automated decision-making including profiling with meaningful information about the logic involved and its significance and envisaged consequences. Where data has been transferred to a third country, inform the data subject of the Article 46 safeguards relating to the transfer. Provide a copy of the personal data undergoing processing, in a commonly used electronic form where the request was made electronically, free for the first copy and at a reasonable fee based on administrative costs for further copies. The right to obtain a copy must not adversely affect the rights and freedoms of others.

Evidence an auditor accepts: The search methodology showing every system, archive and unstructured store searched, and how completeness was assured; a worked response covering all the supplementary information items, not only the copy of the data; the redaction position and the applied redaction log where third party data was withheld, with a reason recorded per redaction
Common gap: Structured database records returned while email, chat, ticketing and free text notes naming the person are never searched
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 17 Right to erasure (right to be forgotten)

Erase personal data without undue delay where the data is no longer necessary for the purposes it was collected or processed for, where consent is withdrawn and no other legal ground applies, where the data subject objects under Article 21(1) and there are no overriding legitimate grounds or objects to direct marketing under Article 21(2), where the data has been unlawfully processed, where erasure is required by Union or Member State law, or where the data was collected in relation to information society services offered to a child. Where the data has been made public, take reasonable steps including technical measures, allowing for available technology and the cost of implementation, to inform other controllers processing it that erasure of any links to, or copies or replications of, the data has been requested. The obligation does not apply to the extent processing is necessary for freedom of expression and information, for compliance with a legal obligation or a public interest task, for public health reasons, for archiving, research or statistics under Article 89(1) where erasure would seriously impair those objectives, or for the establishment, exercise or defence of legal claims.

Evidence an auditor accepts: Erasure records showing the ground relied on, the decision, and the date the data actually left each system; a deletion capability map covering production, replicas, warehouses, logs, search indexes, backups and processors, with method and lag for each; where an exemption is applied, the specific Article 17(3) ground and the necessity reasoning for the data actually retained
Common gap: Records flagged as deleted in the application while remaining fully readable in the database, the warehouse and the search index
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 22 Automated individual decision-making, including profiling

Do not subject a data subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless the decision is necessary for entering into or performing a contract between the data subject and the controller, is authorised by Union or Member State law that lays down suitable safeguards, or is based on the data subject's explicit consent. Where the contract or explicit consent route is used, implement suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express a point of view and to contest the decision. Such decisions must not be based on special categories of personal data unless explicit consent or substantial public interest applies and suitable safeguards are in place.

Evidence an auditor accepts: An inventory of automated decisions with the assessment of whether each produces legal or similarly significant effects; the exception relied on for each in scope decision, and for contract based ones the necessity reasoning rather than a convenience argument; the human intervention process, showing the reviewer has the authority and the information to change the outcome
Common gap: A rubber stamp reviewer treated as human involvement, which leaves the decision solely automated in substance
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 24 Responsibility of the controller

Implement appropriate technical and organisational measures to ensure, and to be able to demonstrate, that processing is performed in accordance with the Regulation, taking into account the nature, scope, context and purposes of processing and the risks of varying likelihood and severity for the rights and freedoms of natural persons. Review and update those measures where necessary. Where proportionate in relation to the processing activities, the measures must include implementing appropriate data protection policies. Adherence to an approved code of conduct or an approved certification mechanism may be used as one element by which to demonstrate compliance, not as a substitute for it.

Evidence an auditor accepts: The data protection policy set, each with an approval authority, an effective date and a review cycle; the risk assessment that drove the choice of measures, referencing nature, scope, context, purposes and risk to individuals; review records showing the measures were reassessed and updated after material changes to the processing
Common gap: A policy suite adopted once and never reviewed, so it describes processing the organisation no longer carries out
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 26 Joint controllers

Where two or more controllers jointly determine the purposes and means of processing, determine their respective responsibilities for compliance in a transparent manner by an arrangement between them, unless those responsibilities are already determined by Union or Member State law, covering in particular the exercise of the data subject's rights and each party's duty to provide the Article 13 and 14 information. The arrangement may designate a contact point for data subjects. It must duly reflect the parties' respective roles and relationships towards data subjects, and its essence must be made available to the data subject. Irrespective of the terms of the arrangement, a data subject may exercise their rights in respect of and against each of the controllers.

Evidence an auditor accepts: The joint controllership assessment identifying every relationship where purposes and means are jointly determined; the Article 26 arrangement for each, allocating responsibility for rights handling, transparency, security and breach response; the essence of the arrangement as published or otherwise made available to data subjects
Common gap: A controller to processor agreement used where the relationship is in substance joint controllership
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 28 Processor

Use only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised to process are under a duty of confidentiality, takes all Article 32 measures, respects the sub-processor conditions, assists the controller in responding to data subject rights requests, assists with Articles 32 to 36, deletes or returns all personal data at the controller's choice at the end of the service and deletes existing copies unless law requires retention, and makes available all information needed to demonstrate compliance and allows for and contributes to audits and inspections. The processor must immediately inform the controller if it considers an instruction infringes data protection law. The same obligations must be imposed on any sub-processor, and the initial processor remains fully liable for the sub-processor's performance. A processor that determines purposes and means is a controller for that processing.

Evidence an auditor accepts: A processor inventory reconciled against the vendor register or accounts payable, so no processor is missing from it; the Article 28(3) contract for each processor, checked clause by clause against the eight stipulations the Article names; due diligence evidence gathered before appointment showing sufficient guarantees, distinct from the signed contract
Common gap: The processor's own standard terms accepted, which commonly omit the audit right, the deletion choice and the instruction infringement notice
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 30 Records of processing activities

Maintain a written, including electronic, record of processing activities under the controller's responsibility containing the name and contact details of the controller, any joint controller, the representative and the data protection officer, the purposes of the processing, a description of the categories of data subjects and of personal data, the categories of recipients including those in third countries and international organisations, any transfers to a third country or international organisation with that destination identified and, for transfers under the second subparagraph of Article 49(1), the documentation of suitable safeguards, the envisaged time limits for erasure of each category where possible, and a general description of the Article 32(1) technical and organisational security measures where possible. A processor must maintain an equivalent record of the categories of processing carried out on behalf of each controller. Make the record available to the supervisory authority on request. The obligation does not apply to an organisation employing fewer than 250 persons unless the processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or includes special category or criminal offence data.

Evidence an auditor accepts: The record of processing activities in full, checked against the seven controller elements, or the four processor elements, the Article lists; version history showing when each entry was last reviewed and by whom; reconciliation of the record against a system inventory or data flow map, to show nothing is missing rather than that the entries read well
Common gap: Records written once during the implementation project and never updated against reality, so they describe systems long replaced and omit those adopted since
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 33 Notification of a personal data breach to the supervisory authority

On becoming aware of a personal data breach, notify it to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; a notification made later than 72 hours must be accompanied by the reasons for the delay. A processor must notify its controller without undue delay after becoming aware of a breach. The notification must at least describe the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned, give the name and contact details of the data protection officer or other contact point, describe the likely consequences, and describe the measures taken or proposed including any measures to mitigate adverse effects. Information may be provided in phases where it cannot all be given at once. Document every personal data breach, including the facts, its effects and the remedial action taken, so the supervisory authority can verify compliance with this Article.

Evidence an auditor accepts: The internal breach register covering all breaches including those assessed as not notifiable, with the risk assessment recorded for each; the awareness timestamp per incident and the basis for it, since the 72 hours runs from awareness and not from confirmation or containment; notifications as submitted, checked against the four content elements Article 33(3) requires
Common gap: The awareness clock started at the end of the investigation rather than at the point of reasonable certainty that a breach had occurred
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 34 Communication of a personal data breach to the data subject

Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, communicate the breach to the affected data subjects without undue delay, describing in clear and plain language the nature of the breach and giving at least the contact point, the likely consequences and the measures taken or proposed including mitigation. Communication is not required where the controller had implemented appropriate technical and organisational protection measures and applied them to the affected data, in particular measures such as encryption rendering the data unintelligible to anyone unauthorised, where the controller has since taken measures making the high risk no longer likely to materialise, or where individual communication would involve disproportionate effort, in which case a public communication or similar equally effective measure must be made instead. The supervisory authority may require communication or decide that one of the exemptions applies.

Evidence an auditor accepts: The high risk assessment per breach, kept distinct from the Article 33 assessment, which uses a lower threshold; the communication as sent, assessed for clear and plain language and for the three content elements required; where the encryption exemption is relied on, evidence the measure covered the specific affected data and that the keys were not also compromised
Common gap: Communication deferred until the investigation completes, when the Article requires it without undue delay once high risk is identified
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 35 Data protection impact assessment

Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data before the processing begins; a single assessment may address a set of similar operations presenting similar risks. An assessment is required in particular for systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions producing legal or similarly significant effects are based, for large scale processing of special category or criminal offence data, and for systematic monitoring of a publicly accessible area on a large scale. Seek the advice of the data protection officer where one is designated, and where appropriate seek the views of data subjects or their representatives. The assessment must contain at least a systematic description of the envisaged operations and purposes including any legitimate interest pursued, an assessment of the necessity and proportionality of the operations in relation to the purposes, an assessment of the risks to the rights and freedoms of data subjects, and the measures envisaged to address those risks including safeguards, security measures and mechanisms to protect personal data and demonstrate compliance. Carry out a review where necessary and at least when the risk represented by the processing operations changes.

Evidence an auditor accepts: The screening or threshold process applied to new and changed processing, with its outcomes recorded including the negative ones; completed assessments checked against the four minimum content elements Article 35(7) requires; the data protection officer's advice sought and given on each assessment, recorded as advice rather than as approval
Common gap: An assessment opened at project start and never revisited, so its residual risk conclusion is never tested against how the processing actually turned out
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 36 Prior consultation

Consult the supervisory authority prior to processing where a data protection impact assessment under Article 35 indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate that risk. When consulting, provide the respective responsibilities of the controller, any joint controllers and the processors involved, the purposes and means of the intended processing, the measures and safeguards provided to protect the rights and freedoms of data subjects, the contact details of the data protection officer where applicable, the impact assessment itself, and any other information the authority requests. The authority has up to eight weeks to provide written advice where it considers the intended processing would infringe the Regulation, extendable by six weeks with notification of the extension and its reasons, and may use its Article 58 powers. Member State law may additionally require consultation and prior authorisation for processing carried out for a public interest task.

Evidence an auditor accepts: The decision record for each impact assessment that concluded on residual high risk, showing whether consultation was triggered and on what reasoning; the consultation submission carrying all six information items Article 36(3) requires; the authority's written advice and the changes made to the processing in response, tracked to closure
Common gap: Residual risk written down to medium in the assessment precisely to avoid the consultation trigger, with no measure actually added to justify the reduction
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 37 Designation of the data protection officer

Designate a data protection officer where the processing is carried out by a public authority or body, except for courts acting in their judicial capacity, where the core activities consist of processing operations which by their nature, scope or purposes require regular and systematic monitoring of data subjects on a large scale, or where the core activities consist of processing on a large scale of special category data or of personal data relating to criminal convictions and offences. A group of undertakings may appoint a single data protection officer provided that officer is easily accessible from each establishment. Designate on the basis of professional qualities, in particular expert knowledge of data protection law and practice and the ability to fulfil the Article 39 tasks. The officer may be a staff member or fulfil the tasks under a service contract. Publish the officer's contact details and communicate them to the supervisory authority.

Evidence an auditor accepts: The Article 37(1) assessment, made whether or not an officer was appointed, showing how core activities, large scale and regular and systematic monitoring were judged; the designation record, with evidence the contact details were both published and communicated to the supervisory authority; the officer's qualifications and experience measured against the data protection risk the organisation's processing presents
Common gap: No appointment made and no assessment on file, so the absence of an officer cannot be justified when it is challenged
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 39 Tasks of the data protection officer

The data protection officer must at least inform and advise the controller or processor and the employees who carry out processing of their obligations under the Regulation and other Union or Member State data protection provisions; monitor compliance with those provisions and with the controller's or processor's own data protection policies, including the assignment of responsibilities, awareness raising, the training of staff involved in processing operations, and the related audits; provide advice where requested on the data protection impact assessment and monitor its performance under Article 35; cooperate with the supervisory authority; and act as the contact point for the supervisory authority on processing issues including the Article 36 prior consultation, consulting on any other matter where appropriate. In performing these tasks the officer must have due regard to the risk associated with the processing operations, taking account of their nature, scope, context and purposes.

Evidence an auditor accepts: The officer's monitoring plan and its output, such as a review or audit programme with findings and their closure; advice given, recorded with its date and outcome including where it was not followed and by whose decision; training and awareness activity delivered or overseen, with coverage figures for the staff involved in processing operations
Common gap: The officer acting as the compliance delivery function, writing and running the very controls they are meant to independently monitor
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 44 General principle for transfers

Transfer personal data undergoing processing, or intended for processing after transfer, to a third country or an international organisation only where the conditions laid down in Chapter V are complied with by the controller and the processor, including for onward transfers from that third country or international organisation to another third country or international organisation. Apply all the provisions of Chapter V so that the level of protection of natural persons guaranteed by the Regulation is not undermined.

Evidence an auditor accepts: A transfer register listing every transfer with the destination country, the recipient, the data categories and the Chapter V mechanism relied on; the onward transfer position for each recipient, showing what the recipient may do with the data and under which mechanism; evidence that remote access from a third country was assessed as a transfer alongside physical movement of data
Common gap: Remote support access, cloud administration and follow the sun operations from third countries never recognised as transfers at all
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 46 Transfers subject to appropriate safeguards

In the absence of an adequacy decision, transfer personal data to a third country or an international organisation only where the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. Safeguards requiring no specific authorisation are a legally binding and enforceable instrument between public authorities or bodies, binding corporate rules under Article 47, standard data protection clauses adopted by the Commission, standard clauses adopted by a supervisory authority and approved by the Commission, an approved code of conduct together with binding and enforceable commitments from the recipient to apply the safeguards including as to data subject rights, or an approved certification mechanism with the same commitments. Subject to authorisation from the competent supervisory authority, safeguards may also be provided by contractual clauses between the parties or by provisions inserted into administrative arrangements between public authorities that include enforceable and effective data subject rights.

Evidence an auditor accepts: The executed instrument for each transfer, with the modules, annexes and schedules of technical and organisational measures actually completed rather than left blank; the transfer risk assessment examining the destination's law and practice, in particular public authority access, and the conclusion on whether the safeguards are effective there; the supplementary measures adopted where that assessment found the instrument alone insufficient, and evidence they are in place
Common gap: Standard clauses signed with the annexes unfilled, so the data, the purposes and the security measures the clauses are meant to bind are left undefined
Source: GDPR (Regulation (EU) 2016/679)

See which clauses your list answers

Paste the list and every document names the clauses behind it, filtered to the regimes that apply to you. Eight documents free, no account.

Build a register