P6.6 Provides notification of breaches and incidents to affected data subjects, regulators, and others to meet the entity's objectives related to privacy
Provides notification of breaches and incidents to affected data subjects, regulators, and others to meet the entity's objectives related to privacy.
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Notification records for the period, showing what was sent, to whom and when · Data governance / DLP tooling
- Assessment records determining whether notification was required for each incident, including where it was assessed as not required · Data governance / DLP tooling
- Evidence of the legal or regulatory analysis underpinning the notification decision · Data governance / DLP tooling
governing documentDocuments that govern the control
- Documented breach notification procedure identifying the recipients, being affected data subjects, regulators and others, and the trigger and timeframe for each · Policy repository / GRC workspace
- Templates or sample notifications showing the content provided to data subjects · Policy repository / GRC workspace
First move
Common gaps auditors find
- Procedure covers regulator notification while notification to affected data subjects is undefined
- Decisions not to notify recorded as a conclusion with no supporting assessment, leaving the judgement unauditable
- Contact information for affected individuals unavailable or stale, so notification cannot be executed within the timeframe
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetP6.5 Obtains commitments from vendors and other third parties with access to personal information to notify the entity in the event of actual or suspected unauthorized disclosures of personal information. Such notifications are reported to · P6.7 Provides data subjects with an accounting of the personal information held and disclosure of the data subjects' personal information, upon the data subjects' request, to meet the entity's objectives related to privacy