7.3.5 Providing mechanism to object to PII processing
The organization must provide a mechanism for individuals to object to the processing of their data, documenting the legal and regulatory requirements relating to objection such as objection to direct marketing, informin
4
artefacts
0
held by a system
1
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Objection records and evidence processing actually stopped · Document repository
governing documentDocuments that govern the control
- Objection mechanism appropriate to each service channel · Document repository
- Register of the objection rights that apply, by jurisdiction and processing type · Policy repository / GRC workspace
- Information given to individuals about when they may object · Document repository
First move
This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.
Common gaps auditors find
- Objection conflated with consent withdrawal, so objections against non consent based processing have no route
- Marketing suppression applied in one system while other systems continue to select the individual
- Objection right described in the notice with no mechanism behind it
- Objections recorded as complaints and closed rather than actioned as a standing instruction
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet7.3.4 Providing mechanism to modify or withdraw consent · 7.3.6 Access, correction and/or erasure