Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook

Documentation of personal data processing purposes for data stores

Critical
High
Normal
Low

Processing of personal data is only lawful if one of the legal bases set out in the General Data Protection Regulation is met. The organization must be able to communicate the purpose of the processing and the legal basis to the data subject and, where appropriate, to the supervisory authority.

The documentation shall include at least:

  • the legal basis for the processing and the necessary additional information
  • the parties to whom the processing has been outsourced
  • related data sets
Connected other frameworks and requirements:
6. Lawfulness of processing
GDPR
30. Records of processing activities
GDPR
18.1.4: Privacy and protection of personally identifiable information
A.7.2.2: Identify lawful basis
ISO 27701
A.7.2.8: Records related to processing PII
ISO 27701

Records of processing activities -report publishing and maintenance

Critical
High
Normal
Low

Records of processing activities is a written description of the processing of personal data by the organization.

This report is mandatory if any of the following occurs:

  • the organization has more than 250 employees
  • the processing of personal data is not incidental
  • the processing of personal data is likely to pose a risk to the data subject's rights and freedoms
  • the personal data processed contain special categories of data or personal data relating to criminal convictions and offenses

Records must be kept up to date. They also serve as a first-level way of assessing the lawfulness of processing, so it must be provided to the supervisory authority on request.

In Cyberday, records of processing activities is an own report, which is automatically gathered from the data on documentation sections.

Connected other frameworks and requirements:
30. Records of processing activities
GDPR
A.7.2.8: Records related to processing PII
ISO 27701

Documentation of data disclosures for data stores

Critical
High
Normal
Low

The data in a data store are, in principle, only available to that controller and under the same responsibility. If you pass data on to another organization for other use, you must clearly inform about it and state e.g. the recipient of the transfer and the legal basis.

Connected other frameworks and requirements:
12. Transparent information, communication and modalities for the exercise of the rights of the data subject
GDPR
28. Processor
GDPR
30. Records of processing activities
GDPR
A.6.2: Recording of PII disclosures
ISO 27018
A.7.3.7: PII controllers' obligations to inform third parties
ISO 27701
No items found.