Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook

Records of personal data disclosures to third parties

Critical
High
Normal
Low

The organization should save information concerning personal data disclosures to third parties. The information should include what personal data has been disclosed, to whom and when.

Connected other frameworks and requirements:
A.7.5.4: Records of PII disclosure to third parties
ISO 27701

Documentation of data disclosures for data stores

Critical
High
Normal
Low

The data in a data store are, in principle, only available to that controller and under the same responsibility. If you pass data on to another organization for other use, you must clearly inform about it and state e.g. the recipient of the transfer and the legal basis.

Connected other frameworks and requirements:
30. Records of processing activities
GDPR
28. Processor
GDPR
12. Transparent information, communication and modalities for the exercise of the rights of the data subject
GDPR
A.6.2: Recording of PII disclosures
ISO 27018
A.7.3.7: PII controllers' obligations to inform third parties
ISO 27701
No items found.