FintastIQTrust Center
LoginBook a Consultation
Framework

EU General Data Protection Regulation (GDPR)

Version: Regulation (EU) 2016/679

The EU regulation governing the processing of personal data, applicable to controllers and processors established in the EU and to those outside it that offer goods or services to, or monitor the behavior of, people in the EU. This catalog covers the operative obligations in Chapters II to V (Articles 5 to 49).

Official source

Summary

Where we stand

Controls
81%
Evidence
18%
Policies
27%

11 of 45 clauses mapped to adopted controls

As of (just now)

Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.

Clauses

Clause-by-clause readiness

ClauseTitleControlsEvidencePoliciesLast tested
Ch. II Principles
Art. 5Principles relating to processing of personal data
Controls: DATA-04, LEGAL-01
PassingNot currentNot approvedNot yet
Art. 6Lawfulness of processingUnmappedUnmappedUnmappedNot yet
Art. 7Conditions for consentUnmappedUnmappedUnmappedNot yet
Art. 8Conditions applicable to child's consent in relation to information society servicesUnmappedUnmappedUnmappedNot yet
Art. 9Processing of special categories of personal dataUnmappedUnmappedUnmappedNot yet
Art. 10Processing of personal data relating to criminal convictions and offenses
Controls: PEOPLE-01
Not passingCurrentNot approved(4 mo ago)
Art. 11Processing which does not require identificationUnmappedUnmappedUnmappedNot yet
Ch. III Rights of the data subject
Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subject
Controls: LEGAL-01
PassingNot currentApprovedNot yet
Art. 13Information to be provided where personal data are collected from the data subject
Controls: LEGAL-01
PassingNot currentApprovedNot yet
Art. 14Information to be provided where personal data have not been obtained from the data subject
Controls: LEGAL-01
PassingNot currentApprovedNot yet
Art. 15Right of access by the data subjectUnmappedUnmappedUnmappedNot yet
Art. 16Right to rectificationUnmappedUnmappedUnmappedNot yet
Art. 17Right to erasure ('right to be forgotten')
Controls: DATA-05
PassingNot currentNot approvedNot yet
Art. 18Right to restriction of processingUnmappedUnmappedUnmappedNot yet
Art. 19Notification obligation regarding rectification or erasure of personal data or restriction of processingUnmappedUnmappedUnmappedNot yet
Art. 20Right to data portabilityUnmappedUnmappedUnmappedNot yet
Art. 21Right to objectUnmappedUnmappedUnmappedNot yet
Art. 22Automated individual decision-making, including profilingUnmappedUnmappedUnmappedNot yet
Art. 23RestrictionsUnmappedUnmappedUnmappedNot yet
Ch. IV Controller and processor
Art. 24Responsibility of the controller
Controls: BIZ-04, BIZ-14
PassingNot currentNot approvedNot yet
Art. 25Data protection by design and by defaultUnmappedUnmappedUnmappedNot yet
Art. 26Joint controllersUnmappedUnmappedUnmappedNot yet
Art. 27Representatives of controllers or processors not established in the UnionUnmappedUnmappedUnmappedNot yet
Art. 28Processor
Controls: VEND-03
PassingNot currentNot approvedNot yet
Art. 29Processing under the authority of the controller or processor
Controls: PEOPLE-02
PassingNot currentNot approvedNot yet
Art. 30Records of processing activitiesUnmappedUnmappedUnmappedNot yet
Art. 31Cooperation with the supervisory authorityUnmappedUnmappedUnmappedNot yet
Art. 32Security of processing
Controls: BIZ-01, DATA-02, DATA-03, DATA-12, IAM-04, MON-04
Not passingNot currentNot approved(8 h ago)
Art. 33Notification of a personal data breach to the supervisory authority
Controls: BIZ-03
PassingCurrentNot approved(8 h ago)
Art. 34Communication of a personal data breach to the data subjectUnmappedUnmappedUnmappedNot yet
Art. 35Data protection impact assessmentUnmappedUnmappedUnmappedNot yet
Art. 36Prior consultationUnmappedUnmappedUnmappedNot yet
Art. 37Designation of the data protection officerUnmappedUnmappedUnmappedNot yet
Art. 38Position of the data protection officerUnmappedUnmappedUnmappedNot yet
Art. 39Tasks of the data protection officerUnmappedUnmappedUnmappedNot yet
Art. 40Codes of conductUnmappedUnmappedUnmappedNot yet
Art. 41Monitoring of approved codes of conductUnmappedUnmappedUnmappedNot yet
Art. 42CertificationUnmappedUnmappedUnmappedNot yet
Art. 43Certification bodiesUnmappedUnmappedUnmappedNot yet
Ch. V Transfers of personal data to third countries or international organisations
Art. 44General principle for transfersUnmappedUnmappedUnmappedNot yet
Art. 45Transfers on the basis of an adequacy decisionUnmappedUnmappedUnmappedNot yet
Art. 46Transfers subject to appropriate safeguardsUnmappedUnmappedUnmappedNot yet
Art. 47Binding corporate rulesUnmappedUnmappedUnmappedNot yet
Art. 48Transfers or disclosures not authorized by Union lawUnmappedUnmappedUnmappedNot yet
Art. 49Derogations for specific situationsUnmappedUnmappedUnmappedNot yet