GDPR
Chapter III - Rights of the Data Subject

GDPR GDPR-Art.12: Transparent information, communication and modalities for rights

Provide the Article 13 and 14 information and every Article 15 to 22 and 34 communication in a concise, transparent, intelligible and easily accessible form, in clear and plain language, with particular care where the information is addressed to a child, normally in writing including by electronic means. Facilitate the exercise of data subject rights and do not refuse to act unless the controller demonstrates it cannot identify the data subject. Provide information on action taken without undue delay and in any event within one month of receipt, extendable by two further months where the complexity and number of requests requires it, with the data subject informed of the extension and its reasons within the first month. Where no action is taken, say so within one month with the reasons and inform the data subject of the right to lodge a complaint with a supervisory authority and to seek a judicial remedy. Act free of charge; a reasonable fee or refusal is available only for manifestly unfounded or excessive requests, and the controller bears the burden of demonstrating that character. Additional information may be requested only where there are reasonable doubts about the requester's identity.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 57 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

APPI · 5 controls

  • APPI-A32 Matters Concerning Retained Personal Data to Be Made Accessible
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APPI-A36 Explanation of Reasons for a Response to a Request
  • APPI-A37 Procedure for Receiving Requests
  • APPI-A38 Fees for Disclosure and Notification of Purpose

CCPA/CPRA · 4 controls

ISO 27701:2019 · 4 controls

  • 7.3.1 Determining and fulfilling obligations to PII principals
  • 7.3.3 Providing information to PII principals
  • 7.3.9 Handling requests
  • 8.3.1 Obligations to PII principals
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-12 APP 12 - Access to personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • PIPL-Art48 Right to Explanation of Handling Rules
  • PIPL-Art50 Request-Handling Mechanism and Remedy
  • PIPL-Art7 Openness and Transparency

NIST SP 800-53 Rev 5 · 3 controls

SOC 2 · 3 controls

  • SOC2-P1.1 P1.1 Privacy notice to data subjects
  • SOC2-P5.1 P5.1 Data subject access
  • SOC2-P8.1 P8.1 Inquiries, complaints, disputes and compliance monitoring
  • AUCDR-PS-1 Privacy Safeguard 1 - Open and transparent management of CDR data
  • AUCDR-PS-5 Privacy Safeguard 5 - Notifying of the collection of CDR data
  • MYHR-GOV-4 Review of decisions
  • MYHR-REG-2 Healthcare recipient registration and identity verification

Canadian PIPEDA · 2 controls

  • Art. 2-quinquies(2) Art. 2-quinquies(2) Write information for children in clear, simple language they can understand
  • Art. 2-undecies Art. 2-undecies Restrict data subject rights only in the listed cases, with reasoned notice and the Garante route
  • 34 Art. 34 Decide on data subject requests in writing within the GDPR periods
  • 5(4) Art. 5(4) Let the right person exercise data subject rights for minors and wards
  • CAYDPA-P6 Sixth Principle - Rights of Data Subjects
  • CCM-DSP-11 Personal Data Access, Reversal, Rectification and Deletion
  • AUCDR-OB-4 CDR policy publication
  • 7.1.1 7.1.1 Warning signs at about eye level before the monitored area, making clear what is covered

EU AI Act · 1 control

  • EUAI-Art.13 Transparency and provision of information to deployers
  • EGY-PDPL-Art.37 Penalty for denying rights and unlawful collection
  • s59 s 59 Communicate clearly, free of charge, in the form of the request
  • RO-LAW190-010 Data Subject Rights Handling
  • ZDPA-05 Data Subject Rights Handling

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter III - Rights of the Data Subject

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.12 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 57 it maps to, and the evidence behind each claim, over MCP and REST.