GDPR GDPR-Art.5: Principles relating to processing of personal data
Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 234 controls across 76 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ACC-1 ACC-1 Do not use biometric or photo-taking time clocks to control working hours
ACC-2 ACC-2 Do not reuse access-control logs for another purpose such as checking hours
ACC-3 ACC-3 Do not track movements inside the premises or check staff representatives' movements and delegation hours
ACC-5 ACC-5 Keep identification data for the authorisation period, access logs three months and time-tracking data up to five years
ACT-1 ACT-1 Define the objective and scope of each control device and identify the risks to employees' rights before installing it
ACT-2 ACT-2 Show the device is necessary: no less intrusive means, only the data, retention and access strictly required
ACT-3 ACT-3 Do not place staff under constant or permanent surveillance
ACT-4 ACT-4 Do not use a device for a hidden purpose other than the one declared
ACT-5 ACT-5 Keystroke loggers are disproportionate for monitoring staff
CALL-1 CALL-1 Listen to or record calls only occasionally, for training, evaluation, service quality or legally provided proof, collecting only what is needed
CALL-2 CALL-2 Do not record calls permanently or systematically unless a law requires it
CALL-5 CALL-5 Keep recordings up to six months and analysis documents up to one year
GEO-1 GEO-1 Use vehicle geolocation only for the purposes the CNIL recognises
GEO-2 GEO-2 Do not use geolocation to check speed, to monitor continuously, for free-roaming staff, staff representatives or outside working time
GEO-6 GEO-6 Keep location data two months, one year for route optimisation or proof, five years for working time
NET-2 NET-2 Do not receive automatic copies of all staff email, and keep connection logs no more than six months
PHN-1 PHN-1 Mask the last four digits on call records, keep telephony data a year at most and never monitor representatives' calls
SCR-1 SCR-1 Do not couple screen captures with call recording
SCR-2 SCR-2 Couple screen video with call recording only for training, with every listed safeguard
TLW-1 TLW-1 Do not monitor teleworkers constantly by webcam, audio, screen sharing, keyloggers or forced presence checks
VID-1 VID-1 Install cameras only for a defined, lawful and legitimate purpose
VID-2 VID-2 Point cameras at entrances, exits, emergency exits, circulation routes and storage areas, not at workstations
VID-3 VID-3 Do not film break or rest areas, toilets, or union and staff representative premises
VID-5 VID-5 Record sound only in particular situations, triggered by an employee
VID-7 VID-7 Set a retention period tied to the purpose, in principle not over one month, and log extractions
NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
You are reading one control. How much of GDPR have you already done?
GDPR GDPR-Art.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.