GDPR
Chapter III - Rights of the Data Subject

GDPR GDPR-Art.13: Information to be provided where personal data are collected

Where personal data is collected from the data subject, provide at the time it is obtained the identity and contact details of the controller and any representative, the contact details of the data protection officer, the purposes and the legal basis, the legitimate interests where that is the basis, the recipients or categories of recipient, and any intention to transfer to a third country with the existence or absence of an adequacy decision and, for Article 46, 47 or 49(1) transfers, reference to the safeguards and how to obtain a copy. Provide in addition the storage period or the criteria used to determine it, the existence of the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent where consent is the basis, the right to lodge a complaint with a supervisory authority, whether providing the data is a statutory or contractual requirement and the consequences of not providing it, and the existence of automated decision-making including profiling with meaningful information about the logic involved and its significance and envisaged consequences. Before further processing for a new purpose, provide that purpose and the further information first.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 102 controls across 50 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CCPA/CPRA · 7 controls

  • CCR §7012 Notice at Collection Drafting Requirements
  • 1798.100(a) Inform consumers at or before collection
  • CCR 7012 Notice at collection: content, placement and third-party collection
  • CCR 7220 Give a pre-use notice before using ADMT for significant decisions
  • §1798.100 General Duties of Businesses that Collect Personal Information
  • §1798.130(a)(3) Privacy Policy Content Requirements
  • §1798.130(a)(5)(C) Notice at Collection
  • ACC-6 ACC-6 Inform the representative bodies and give each employee clear information on the access or time system
  • ACT-7 ACT-7 Inform the people concerned before the device is put in place
  • CALL-6 CALL-6 Consult the representative bodies and inform employees and callers, including the periods when employees may be recorded
  • GEO-7 GEO-7 Inform or consult the representative bodies and inform each driver before installing geolocation
  • NET-5 NET-5 Consult the representative bodies, inform staff through a charter, record the processing and involve the DPO
  • VID-8 VID-8 Post permanent visible signs with the required information and give full information by other means
  • AUCDR-PS-1 Privacy Safeguard 1 - Open and transparent management of CDR data
  • AUCDR-PS-10 Privacy Safeguard 10 - Notifying of the disclosure of CDR data
  • AUCDR-PS-3 Privacy Safeguard 3 - Seeking to collect CDR data from CDR participants
  • AUCDR-PS-5 Privacy Safeguard 5 - Notifying of the collection of CDR data
  • L1221-8 L1221-8 Tell candidates beforehand which recruitment methods and techniques are used on them
  • L1221-9 L1221-9 Collect no personal information on a candidate through an undisclosed device
  • L1222-3 L1222-3 Tell employees beforehand how they are evaluated, keep results confidential and use relevant methods
  • L1222-4 L1222-4 Collect no personal information on an employee through a device not previously disclosed
  • s32 s 32 Withhold collection-time information on further use only in the listed cases, with compensating steps
  • s4-2 s 4(2) Make video surveillance and the controller identifiable at the earliest possible point
  • s4-4 s 4(4) Inform a person when video data are attributed to them
  • s55 s 55 Publish general information about the processing

ISO 27701:2019 · 4 controls

  • 7.2.1 Identify and document purpose
  • 7.3.2 Determining information for PII principals
  • 7.3.3 Providing information to PII principals
  • 7.4.7 Retention
  • 3.1.2 3.1.2 Tell workers that monitoring exists, why, and what else fairness requires
  • 5.3(b) 5.3(b) Exclude sensitive traffic from inspection and tell employees what is monitored
  • 5.7(b) 5.7(b) Tell drivers a tracker is fitted and that movements, and possibly driving behaviour, are recorded; notice in the vehicle
  • PIPL-Art17 Notice Content Before Handling
  • PIPL-Art22 Transfer Due to Merger or Restructuring
  • PIPL-Art30 Enhanced Notice for Sensitive PI
  • 7 7 Transparency in layers: the Article 13 information for footage collected by observation
  • 7.1.2 7.1.2 Sign content: purpose, controller, rights, greatest impacts, and where to find the rest
  • 7.2 7.2 Second layer: the full Article 13 notice, easy to reach and available without entering the area
  • 41.1.1(2) para 1 41.1.1(2) para 1 State whether the employer electronically monitors employees
  • 41.1.1(2) para 1.i 41.1.1(2) para 1 i Describe how and in what circumstances employees may be monitored
  • 41.1.1(2) para 1.ii 41.1.1(2) para 1 ii State the purposes for which monitoring information may be used

APPI · 2 controls

  • APPI-A21 Notice or Public Announcement of the Purpose of Use
  • APPI-A32 Matters Concerning Retained Personal Data to Be Made Accessible
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-5 APP 5 - Notification of the collection of personal information

COPPA · 2 controls

  • COPPA-312.4c Direct Notice to the Parent
  • COPPA-312.4d Online Notice of Information Practices (Privacy Policy)

Canadian PIPEDA · 2 controls

  • CDR-PS-10 Privacy Safeguard 10: Notifying of the Disclosure of CDR Data
  • CDR-PS-5 Privacy Safeguard 5: Notifying of the Collection of CDR Data
  • 31-48d(b)(1) notice 31-48d(b)(1) Give prior written notice of the types and specific locations of monitoring
  • 31-48d(b)(1) posting 31-48d(b)(1) Post the notice conspicuously, including where monitoring occurs
  • 705(b)(1) 705(b)(1) Daily electronic notice on each day of access
  • 705(b)(2) 705(b)(2) One-time notice acknowledged by the employee
  • 5.8 5.8 Keep workers and representatives informed
  • 6.14(1) 6.14(1) Tell workers in advance about monitoring and minimize intrusion
  • Art. 111-bis Art. 111-bis Give the privacy notice to spontaneous job applicants at the first useful contact
  • Art. 131 Art. 131 Tell subscribers and the other party when communications can be overheard or listened to

NIST SP 800-53 Rev 5 · 2 controls

  • 52-c(2)(a) notice 52-c(2)(a) Give written notice on hiring, acknowledged by the employee
  • 52-c(2)(b) 52-c(2)(b) Content: all communications and internet use may be monitored at any time by lawful means

SOC 2 · 2 controls

  • SOC2-P1.1 P1.1 Privacy notice to data subjects
  • SOC2-P6.1 P6.1 Disclosure to third parties with consent
  • 13 s 13 Written notice of surveillance, 14 days ahead, with the required content
  • AL-DPA-6 Data Subject Rights - Information
  • AM-DPA-08 Information to Data Subjects at Collection
  • MYHR-SBD-4 Notice where information is not being shared
  • CL21719-A14ter Lawfulness Documentation and Transparency (Art. 14 ter)
  • CO-L1581-A12 Duty to Inform the Data Subject (Privacy Notice)
  • CZ-110-§8 Informacni povinnost (information duty adaptations)
  • RDCOC-RIG-01 Data Subject Rights and Information in Research
  • ESRB-PC-06 Online Privacy Notice (privacy policy)

EU AI Act · 1 control

  • EUAI-Art.50 Transparency obligations for providers and deployers of certain AI systems
  • DGA-Art.20_21 Transparency and safeguarding requirements (Articles 20-21)
  • ePD-Art.5 Confidentiality of communications including the Article 5(3) cookie consent rule
  • EGY-PDPL-Art.2 Data subject rights and consent requirement
  • UAE-PDPL-Art.11_12_13_14_15_16 Data subject rights (UAE PDPL Articles 11-16)
  • Art. 4(3) Art. 4(3) Give workers adequate information before using monitoring data, and comply with the data protection code
  • s10 s 10 Written notice of surveillance at least 14 days before it starts
  • CIA-PRV-POL-15 Public disclosure of credit information processing policy

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter III - Rights of the Data Subject

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.13 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 102 it maps to, and the evidence behind each claim, over MCP and REST.