Article 6 (SENSITIVE PERSONAL DATA) - processing of sensitive personal data is PROHIBITED unless one of specific conditions applies: (a) EXPLICIT consent (heightened beyond ordinary consent); (b) processing necessary to protect VITAL interests where data subject is physically / legally incapable; (c) processing carried out by a non-profit body + the data relates to its members + is necessary for the body's activities; (d) processing necessary for substantial PUBLIC INTEREST or LEGAL CLAIMS; (e) processing for occupational MEDICINE / public health / clinical research. Sensitive personal data includes racial / ethnic origin + political opinions + religious / philosophical beliefs + trade union membership + genetic / biometric data for unique identification + health data + sex life / sexual orientation. Article 7 (CHILDREN'S DATA) - processing of personal data of children under 16 years old requires the consent of the holder of parental responsibility; the controller must make reasonable efforts to verify that consent is given by the parent (or legal guardian); the consent verification mechanism must be proportionate to the available technology + risk; specific protections + special-care for children's data + the requirement that children's data is processed only where there is a clear + legitimate reason in the child's best interest.
This control maps to 248 controls across 137 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 248 it maps to, and the evidence behind each claim, over MCP and REST.