Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook

Securely delivering a copy of data subject's personal data

Critical
High
Normal
Low

The organization must be able to provide the data subject with a copy of the personal data being processed at the data subject's request.

The organization must plan in advance a process by which a copy of the personal data can be delivered in a structured and commonly used format and securely to the data subject.

Connected other frameworks and requirements:
A.7.3.8: Providing copy of PII processed
ISO 27701

Ability to provide the data subject with personal data ready for transfer

Critical
High
Normal
Low

The data subject shall have the right to obtain the personal data provided to the controller in a structured, commonly used and machine-readable form and, if he so wishes, to transfer such data to another controller. This can mean, for example, a way to download data added to a web service at a time in a general format (eg XLS, XML, JSON).

The right applies when the following conditions are met:

  • personal data is processed automatically
  • the personal data concern the data subject and are provided by her
  • the processing of personal data is based on consent or agreement
  • when the transfer of data does not adversely affect the rights and freedoms of third parties

The right does not cover data that have been generated by the controller himself on the basis of data provided by the data subject (e.g. health assessments) or that have been compiled from the analysis of data generated from the data subject's monitoring (such as profiling).

Our organization is aware of situations where the data subject has the right to transfer their data. We have designed policies for these situations, which may include e.g.:

  • the ways in which the data subject may request the transfer of data
  • the means by which the identity of the sender of the request for information is verified
  • the forms in which the information is provided to the data subject
  • ways in which the data subject is informed
Connected other frameworks and requirements:
20. Right to data portability
GDPR
A.7.3.8: Providing copy of PII processed
ISO 27701
No items found.