DSP-12: Are processes, procedures, and technical measures defined, implemented, and
evaluated to ensure personal data is processed (per applicable laws and regulations
and for the purposes declared to the data subject)?
Implement and maintain processes, procedures, and technical measures to ensure the following: a. The data subject is made aware of the nature and purpose of information collection. b. The information is relevant and limited to processing requirements. c. Processing is performed in a reasonable manner that does not infringe upon the data subject's privacy. d. Processing is for a specific, explicitly defined, and lawful purpose related to a function or activity of the responsible party. e. Where the controller intends to further process the personal data for an alternative purpose to which the personal data were collected, the data subject should be informed of the purpose and provide consent before additional processing. f. Information is stored only as long as required.
Control implemented
Control ownership
Description
Define, implement and evaluate processes, procedures and technical
measures to ensure that personal data is processed according to any applicable
laws and regulations and for the purposes declared to the data subject.