GDPR
Chapter III - Rights of the Data Subject

GDPR GDPR-Art.14: Information where personal data have not been obtained from the data subject

Where personal data has not been obtained from the data subject, provide the same identity, contact, purpose, legal basis, recipient and transfer information as Article 13, plus the categories of personal data concerned and the source the data came from including whether it was a publicly accessible source. Provide it within a reasonable period and at the latest within one month of obtaining the data, or at the latest at the first communication with the data subject if the data is used to communicate with them, or at the latest when the data is first disclosed to another recipient. The obligation does not apply where the data subject already has the information, where provision proves impossible or would involve disproportionate effort in which case appropriate protective measures including making the information publicly available must be taken, where obtaining or disclosure is expressly laid down by Union or Member State law with appropriate safeguards, or where the data must remain confidential under an obligation of professional secrecy.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 29 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CCPA/CPRA · 3 controls

  • CCR §7012 Notice at Collection Drafting Requirements
  • §1798.110 Right to Know Categories and Specific Pieces of Personal Information Collected
  • §1798.130(a)(3) Privacy Policy Content Requirements
  • s29 s 29 Apply the secrecy exceptions to information, access and breach notice narrowly
  • s33 s 33 Withhold information on data obtained from others only in the listed cases, with compensating steps
  • s56 s 56 Where a law requires notification, include the minimum content, and defer only on listed grounds

APPI · 2 controls

  • APPI-A21 Notice or Public Announcement of the Purpose of Use
  • APPI-A30 Confirmation and Records When Receiving Personal Data from a Third Party
  • AUCDR-PS-4 Privacy Safeguard 4 - Dealing with unsolicited CDR data
  • AUCDR-PS-5 Privacy Safeguard 5 - Notifying of the collection of CDR data

SOC 2 · 2 controls

  • SOC2-P1.1 P1.1 Privacy notice to data subjects
  • SOC2-P3.1 P3.1 Collecting personal information consistent with objectives
  • AL-DPA-6 Data Subject Rights - Information
  • AM-DPA-08 Information to Data Subjects at Collection
  • 5.1(a) 5.1(a) Recruitment: social media and public data only with a legal ground, when relevant to the job, and with prior notice
  • APP-5 APP 5 - Notification of the collection of personal information
  • PIPL-Art17 Notice Content Before Handling
  • 6.2 6.2 Third-party collection only with notice and explicit consent

ISO 27701:2019 · 1 control

  • 7.3.2 Determining information for PII principals
  • 30a Art. 30a Inform patients when care providers transfer medical records for retention, and do so free of charge

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter III - Rights of the Data Subject

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.14 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 29 it maps to, and the evidence behind each claim, over MCP and REST.