Other tasks from the same security theme

Task name
Priority
Policy
Other requirements
Privacy notices -report publishing and maintenance
Critical
High
Normal
Low
Informing and data subject requests
18
requirements

Examples of other requirements this task affects

14. Information to be provided where personal data have not been obtained from the data subject
GDPR
12. Transparent information, communication and modalities for the exercise of the rights of the data subject
GDPR
13. Information to be provided where personal data are collected from the data subject
GDPR
18.1.4: Privacy and protection of personally identifiable information
ISO 27001
A.12.1: Geographical location of PII
ISO 27018
See all related requirements and other information from tasks own page.
Go to >
Privacy notices -report publishing and maintenance
Process for receiving and handling data subject requests
Critical
High
Normal
Low
Informing and data subject requests
24
requirements

Examples of other requirements this task affects

15. Right of access by the data subject
GDPR
16. Right to rectification
GDPR
18. Right to restriction of processing
GDPR
19. Notification obligation regarding rectification or erasure of personal data or restriction of processing
GDPR
21. Right to object
GDPR
See all related requirements and other information from tasks own page.
Go to >
Process for receiving and handling data subject requests
Data erasure processes and the "right to be forgotten"
Critical
High
Normal
Low
Informing and data subject requests
7
requirements

Examples of other requirements this task affects

17. Right to erasure (‘right to be forgotten’)
GDPR
A.7.3.6: Access, correction and/or erasure
ISO 27701
A.8.2.3: Marketing and advertising use
ISO 27701
TSU-19.4: Rekisteröidyn oikeudet - Tietojen oikaiseminen, poistaminen, siirtäminen, käsittelyn rajoittaminen ja vastustaminen
Julkri
P4.3: Secure disposal of personal information
SOC 2
See all related requirements and other information from tasks own page.
Go to >
Data erasure processes and the "right to be forgotten"
Documentation of personal data sources for data systems
Critical
High
Normal
Low
Informing and data subject requests
5
requirements

Examples of other requirements this task affects

14. Information to be provided where personal data have not been obtained from the data subject
GDPR
A.7.3.3: Providing information to PII principals
ISO 27701
TSU-19.2: Rekisteröidyn oikeudet - Läpinäkyvä informointi
Julkri
P3.1: Collection of personal information is consistent with objects related to privacy
SOC 2
See all related requirements and other information from tasks own page.
Go to >
Documentation of personal data sources for data systems
Informing the controller of the processors of personal data
Critical
High
Normal
Low
Informing and data subject requests
6
requirements

Examples of other requirements this task affects

A.8: Openness, transparency and notice
ISO 27018
A.8.1: Disclosure of sub-contracted PII processing
ISO 27018
A.8.5.6: Disclosure of subcontractors used to process PII
ISO 27701
A.8.5.7: Engagement of subcontractor to process PII
ISO 27701
A.8.5.8: Change of subcontractor to process PII
ISO 27701
See all related requirements and other information from tasks own page.
Go to >
Informing the controller of the processors of personal data
Listing of non-recurring data disclosures and contractual commitment to informing them to customers
Critical
High
Normal
Low
Informing and data subject requests
7
requirements

Examples of other requirements this task affects

A.6.1: PII disclosure notification
ISO 27018
A.6.2: Recording of PII disclosures
ISO 27018
A.6: Use, retention and disclosure limitation
ISO 27018
A.8.5.1: Basis for PII transfer between jurisdictions
ISO 27701
A.8.5.4: Notification of PII disclosure requests
ISO 27701
See all related requirements and other information from tasks own page.
Go to >
Listing of non-recurring data disclosures and contractual commitment to informing them to customers
Process for data subjects to edit or cancel a consent
Critical
High
Normal
Low
Informing and data subject requests
2
requirements

Examples of other requirements this task affects

A.7.3.4: Providing mechanism to modify or withdraw consent
ISO 27701
P2.1: Communication of choices about personal information to data subjects
SOC 2
See all related requirements and other information from tasks own page.
Go to >
Process for data subjects to edit or cancel a consent
Process for data subjects to object processing
Critical
High
Normal
Low
Informing and data subject requests
2
requirements

Examples of other requirements this task affects

A.7.3.5: Providing mechanism to object to PII processing
ISO 27701
TSU-19.4: Rekisteröidyn oikeudet - Tietojen oikaiseminen, poistaminen, siirtäminen, käsittelyn rajoittaminen ja vastustaminen
Julkri
See all related requirements and other information from tasks own page.
Go to >
Process for data subjects to object processing
Process for data subjects to rectify inaccurate personal data
Critical
High
Normal
Low
Informing and data subject requests
3
requirements

Examples of other requirements this task affects

A.7.3.6: Access, correction and/or erasure
ISO 27701
TSU-19.4: Rekisteröidyn oikeudet - Tietojen oikaiseminen, poistaminen, siirtäminen, käsittelyn rajoittaminen ja vastustaminen
Julkri
P5.2: Correction of personal information
SOC 2
See all related requirements and other information from tasks own page.
Go to >
Process for data subjects to rectify inaccurate personal data
Informing third parties about relevant changes to personal data
Critical
High
Normal
Low
Informing and data subject requests
1
requirements

Examples of other requirements this task affects

A.7.3.7: PII controllers' obligations to inform third parties
ISO 27701
See all related requirements and other information from tasks own page.
Go to >
Informing third parties about relevant changes to personal data
Securely delivering a copy of data subject's personal data
Critical
High
Normal
Low
Informing and data subject requests
2
requirements

Examples of other requirements this task affects

A.7.3.8: Providing copy of PII processed
ISO 27701
TSU-19.3: Rekisteröidyn oikeudet - Oikeus saada pääsy tietoihin
Julkri
See all related requirements and other information from tasks own page.
Go to >
Securely delivering a copy of data subject's personal data
Yhteisrekisterinpitäjänä toimiminen
Critical
High
Normal
Low
Informing and data subject requests
2
requirements

Examples of other requirements this task affects

TSU-03: Yhteisrekisterinpitäjät
Julkri
58: Yhteisrekisterinpitäjyystilanteiden tunnistaminen
Digiturvan kokonaiskuvapalvelu
See all related requirements and other information from tasks own page.
Go to >
Yhteisrekisterinpitäjänä toimiminen
Identification of the rights available to the data subject
Critical
High
Normal
Low
Informing and data subject requests
2
requirements

Examples of other requirements this task affects

TSU-19.1: Rekisteröidyn oikeudet - Rekisteröidyn käytettävissä olevien oikeuksien tunnistaminen
Julkri
P5.1: Granting access to stored personal data
SOC 2
See all related requirements and other information from tasks own page.
Go to >
Identification of the rights available to the data subject
Notification channel for the registered for reporting privacy problems
Critical
High
Normal
Low
Informing and data subject requests
1
requirements

Examples of other requirements this task affects

P8.1: Periodic monitoring of privacy compliance
SOC 2
See all related requirements and other information from tasks own page.
Go to >
Notification channel for the registered for reporting privacy problems
Ensuring the timeliness of privacy communication
Critical
High
Normal
Low
Informing and data subject requests
8
requirements

Examples of other requirements this task affects

12. Transparent information, communication and modalities for the exercise of the rights of the data subject
GDPR
18.2.2: Compliance with security policies and standards
ISO 27001
18.1.4: Privacy and protection of personally identifiable information
ISO 27001
A.7.3.2: Determining information for PII principals
ISO 27701
TSU-19.2: Rekisteröidyn oikeudet - Läpinäkyvä informointi
Julkri
See all related requirements and other information from tasks own page.
Go to >
Ensuring the timeliness of privacy communication
Testing the clarity of privacy communications
Critical
High
Normal
Low
Informing and data subject requests
4
requirements

Examples of other requirements this task affects

12. Transparent information, communication and modalities for the exercise of the rights of the data subject
GDPR
TSU-19.2: Rekisteröidyn oikeudet - Läpinäkyvä informointi
Julkri
64: Informointikäytäntöjen määrittäminen
Digiturvan kokonaiskuvapalvelu
P1.1: Providing notice to data subjects about privacy practices
SOC 2
See all related requirements and other information from tasks own page.
Go to >
Testing the clarity of privacy communications
Ability to provide the data subject with personal data ready for transfer
Critical
High
Normal
Low
Informing and data subject requests
5
requirements

Examples of other requirements this task affects

20. Right to data portability
GDPR
A.7.3.8: Providing copy of PII processed
ISO 27701
TSU-19.4: Rekisteröidyn oikeudet - Tietojen oikaiseminen, poistaminen, siirtäminen, käsittelyn rajoittaminen ja vastustaminen
Julkri
9.6.1: Management of data subject requests
TISAX
See all related requirements and other information from tasks own page.
Go to >
Ability to provide the data subject with personal data ready for transfer
Clear communication about the effects of consent
Critical
High
Normal
Low
Informing and data subject requests
1
requirements

Examples of other requirements this task affects

P2.1: Communication of choices about personal information to data subjects
SOC 2
See all related requirements and other information from tasks own page.
Go to >
Clear communication about the effects of consent
Communication methods for refusing to implement data protection requests
Critical
High
Normal
Low
Informing and data subject requests
2
requirements

Examples of other requirements this task affects

P5.1: Granting access to stored personal data
SOC 2
P5.2: Correction of personal information
SOC 2
See all related requirements and other information from tasks own page.
Go to >
Communication methods for refusing to implement data protection requests

Never duplicate effort. Do it once - improve compliance across frameworks.

Reach multi-framework compliance in the simplest possible way
Security frameworks tend to share the same core requirements - like risk management, backup, malware, personnel awareness or access management.
Cyberday maps all frameworks’ requirements into shared tasks - one single plan that improves all frameworks’ compliance.
Do it once - we automatically apply it to all current and future frameworks.
Get to know Cyberday
Start your free trial
Cyberday is your all-in-one solution for building a secure and compliant organization. Whether you're setting up a cyber security plan, evaluating policies, implementing tasks, or generating automated reports, Cyberday simplifies the entire process.
With AI-driven insights and a user-friendly interface, it's easier than ever to stay ahead of compliance requirements and focus on continuous improvement.
Clear framework compliance plans
Activate relevant frameworks and turn them into actionable policies tailored to your needs.
Credible reports to proof your compliance
Use guided tasks to ensure secure implementations and create professional reports with just a few clicks.
AI-powered improvement suggestions
Focus on the most impactful improvements in your compliance with help from Cyberday AI.