GDPR Article 11 deals with data minimisation principles, which largely limit how data is processed linked to only that which is deemed necessary.
Controllers should delete or obscure any references to the data subject the moment the data is no longer required. When this occurs, controllers also need to obtain further info about the data subject to remain compliant.
If subjects would like to be re-identified, controllers should take this on board and formulate steps to address the request.
It’s important to note that, if the subject is not identified, Article 11 applies in part, but if they data subject requests re-identification, the controller needs to attempt this (unless, by burden of proof, this proves to be impossible).
Processing which does not require identification
Processing which does not require identification
We can’t think of any company whose service can hold a candle to ISMS.online.
When PII no longer fulfils a stated purpose, organisations either need to completely destroy the data, or modify it in a way that prevents any form of identification in any way, either internally or externally.
As soon as the organisation established that the PII doesn’t need to be processed at any time in the future, the information should be deleted or amended in a way that makes it impossible for the data subject to be identified
Organisations should document the information that PII principals receive, that outlines how PII is processed.
There needs to be set of requirements that govern when information is to be provided, and precisely what that information is, such as:
ISMS.online will save you time and money
Get your quoteOrganisations need to outline who the PII controller is, and how data is processed, through ‘clear and accessible’ means that do not inhibit the dissemination of crucial information.
Information should be easy to follow, and set out in layman’s terms so that anyone who reads it is able to understand the nature of what’s being conveyed, along with any technical or operational specifics (see ISO 27701 Clause 7.3.2).
GDPR Article | ISO 27701 Clause | ISO 27701 Supporting Clauses |
---|---|---|
EU GDPR Article 11 (1) | ISO 27701 7.4.5 | None |
EU GDPR Article 11 (2) | ISO 27701 7.3.2 | None |
EU GDPR Article 11 (2) | ISO 27701 7.3.3 | ISO 27701 7.3.2 |
Our pre-built environment allows you to describe and demonstrate your approach to protecting your European and UK customer data in a way that seamlessly integrates into your management system.
The ISMS.online platform contains built-in guidance at each step, as well as our ‘Adopt, Adapt, Add’ implementation approach, which reduces the amount of effort required to comply with GDPR. You will also receive a range of time-saving benefits.
Whether you are having trouble getting to GDPR because of a lack of confidence, ability, or motivation to take action, we can help you by providing our in-house experts or by recommending one of our trusted partners.
Find out more by booking a demo.
Book a tailored hands-on session
based on your needs and goals
Book your demo
Request a quote