On top of the exceptions in ss 27, 28 and 29, the GDPR Art. 15 right of access is excluded where information is withheld under s 33(1) no. 1 or 2(b) or s 33(3), or where the data are kept only because retention law prevents erasure or only for data protection monitoring or backup, access would take disproportionate effort, and technical and organisational measures rule out other use. Refusals are documented, and the data subject is told the reasons unless that would defeat the purpose. Data held to answer access requests may be used only for that and data protection monitoring. Where a federal public body refuses access, it provides the information to the Federal Commissioner at the data subject's request unless the supreme federal authority finds that this would endanger security. Access to unstructured non-automated records of public bodies requires information allowing them to be found and proportionate effort.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.