Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook

Data processing partner listing and owner assignment

Critical
High
Normal
Low

The organization must maintain a list of partners who have access to confidential information. System vendors and processors of personal data are listed separately from other stakeholders because they play an active role in the processing of data.

Connected other frameworks and requirements:
28. Processor
GDPR
44. General principle for transfers
GDPR
26. Joint controllers
GDPR
15.1.1: Information security policy for supplier relationships
ISO 27001
8.1.1: Inventory of assets
ISO 27001

Informing third parties about relevant changes to personal data

Critical
High
Normal
Low

The organization should have pre-planned procedures for situations where third parties need to be notified of changes, deletions and prohibitions regarding shared personal data.

These parties can be, for example, partners who process data or organizations to which personal data has been disclosed forward.</p>

Connected other frameworks and requirements:
A.7.3.7: PII controllers' obligations to inform third parties
ISO 27701

Documentation of data disclosures for data stores

Critical
High
Normal
Low

The data in a data store are, in principle, only available to that controller and under the same responsibility. If you pass data on to another organization for other use, you must clearly inform about it and state e.g. the recipient of the transfer and the legal basis.

Connected other frameworks and requirements:
12. Transparent information, communication and modalities for the exercise of the rights of the data subject
GDPR
28. Processor
GDPR
30. Records of processing activities
GDPR
A.6.2: Recording of PII disclosures
ISO 27018
A.7.3.7: PII controllers' obligations to inform third parties
ISO 27701
No items found.