SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Privacy Policy

  Quote
Guest
Guest user Created:   Nov 03, 2020 Last commented:   Nov 06, 2020

Privacy Policy

Dear Sir/Madam

I need your advice regarding the below

1. As a data processor , is it required to create a privacy policy
2. what is data processor obligation regarding data subject right

0 0

Assign topic to the user

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Alessandra Nisticò Nov 06, 2020

"Dear Sir/MadamI need your advice regarding the belowAs a data processor , is it required to create a privacy policy

From your question, I understand that you are asking me if the processor has to inform data subjects about data processing through the privacy notice under Article 13 GDPR. 

The purpose of a Privacy notice is to provide to data subject all the information about data processing. In fact, Article 13 GDPR requires that the controller inform the data subjects about what kind of data is processed, the purposes of the processing, if there are any data transfer, and all the information that needs to be provided by the controller to the data subjects. Privacy notice is mandatory.

The privacy policy, instead, is an internal document from the management that shows how the organization processes personal data and sets rules on processing, access data, data retention period, and so on. The privacy policy is considered one of the organizational measures to be taken by both processors and controllers. It is mandatory under Article 24 (2) GDPR when proportionate in relation to processing activities.

What is data processor obligation regarding data subject right"

As a processor, you need to establish processes that allow the controller to fulfill its obligation towards data subjects. This means that if the controller receives a request to exercise the right of erasure (right to be forgotten) and request you to erase the data of the data subject, you need to comply with such request.

Here you can find more information:

You can also consider enrolling in this free online training EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 03, 2020

Nov 06, 2020

Suggested Topics