Content library
Digital security overview
64: Informointikäytäntöjen määrittäminen

How to fill the requirement

Digital security overview

64: Informointikäytäntöjen määrittäminen

Task name
Priority
Status
Theme
Policy
Other requirements
Privacy notices -report publishing and maintenance
Critical
High
Normal
Low
Fully done
Mostly done
Partly done
Not done
Privacy
Informing and data subject requests
requirements

Task is fulfilling also these other security requirements

14. Information to be provided where personal data have not been obtained from the data subject
GDPR
12. Transparent information, communication and modalities for the exercise of the rights of the data subject
GDPR
13. Information to be provided where personal data are collected from the data subject
GDPR
18.1.4: Privacy and protection of personally identifiable information
ISO27 Full
A.12.1: Geographical location of PII
ISO 27018
1. Task description

With regard to the processing of personal data, the data subject must be provided with the information specified in the GDPR in a concise, comprehensible and easily accessible form. This is often done in the form of privacy statements, which are published, for example, on the organisation's website.

Where personal data have not been collected from the data subject himself, the descriptions shall state, in addition to the basic content:

  • where the data were obtained
  • which categories of personal data are covered
Testing the clarity of privacy communications
Critical
High
Normal
Low
Fully done
Mostly done
Partly done
Not done
Privacy
Informing and data subject requests
requirements

Task is fulfilling also these other security requirements

12. Transparent information, communication and modalities for the exercise of the rights of the data subject
GDPR
TSU-19.2: Rekisteröidyn oikeudet - Läpinäkyvä informointi
Julkri
64: Informointikäytäntöjen määrittäminen
Sec overview
P1.1: Providing notice to data subjects about privacy practices
SOC 2
1. Task description

Privacy communications should be concise, easy to understand and easily accessible. To develop privacy communications, we test our communications for different uses by providing a snapshot of the privacy communications to a test group selected from among data subjects, and modifying the communications based on their feedback.

Ensuring the timeliness of privacy communication
Critical
High
Normal
Low
Fully done
Mostly done
Partly done
Not done
Privacy
Informing and data subject requests
requirements

Task is fulfilling also these other security requirements

12. Transparent information, communication and modalities for the exercise of the rights of the data subject
GDPR
18.2.2: Compliance with security policies and standards
ISO27 Full
18.1.4: Privacy and protection of personally identifiable information
ISO27 Full
A.7.3.2: Determining information for PII principals
ISO 27701
TSU-19.2: Rekisteröidyn oikeudet - Läpinäkyvä informointi
Julkri
1. Task description

The purposes of the processing of personal data will change as the business develops. Privacy communications should stay up-to-date and reflect the actual state of processing.

We regularly make sure that all processing purposes are mentioned in communications (e.g. privacy statements), that the processing is accurately described, and that communications are provided to data subjects within the required time limits.

No items found.