7.3.8 Providing copy of PII processed
The organization must be able to provide a copy of the personal data it processes when the individual asks, in a structured and commonly used format accessible to that individual, portable and machine readable where the
5
artefacts
2
held by a system
1
at each review
moderate
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Documented export capability with the formats supported · Document repository
- Evidence exports are scoped to the requesting individual only · Document repository
periodic reviewEvidence produced at each review
- Direct transfer capability where technically feasible, or the assessment that it is not · Document repository
governing documentDocuments that govern the control
- Procedure for informing an individual that data has already been deleted · Policy repository / GRC workspace
- Position on re-identification, recording that it is not attempted merely to answer a request · Document repository
First move
Start with the 2 of 5 artefacts that already live in a system (Document repository); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Export produced as a screen capture or report rather than a structured format
- Export including other individuals' data present in shared records or free text
- Re-identification attempted on de-identified holdings in order to answer a request, creating the exposure the de-identification removed
- No response where data has been deleted, leaving the individual to assume it is withheld
- Portability treated as identical to access, ignoring the format requirement
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet7.3.7 PII controllers' obligations to inform third parties · 7.3.9 Handling requests