Skip to main content

Provide processing confirmation

Requirement#

The system must provide confirmation to its users of whether or not it is storing and/or processing their personal data.

Description#

Systems usually request information from their users, obtain it from third parties or collect it based on their interactions with the application. They should have a mechanism that allows users to request confirmation of whether or not the system is managing their personal information, even if it was not obtained from the users but from a third party.

Exceptions#

  1. If the system is able to demonstrate that it is not possible to individually identify the users based on the information collected from them, this requirement is not applicable.

  2. The processing of the personal information might have scientific or historical research purposes or statistical purposes. If the system properly safeguards this information and if complying with this requirement seriously impairs those purposes, this requirement is not applicable.

  3. The processing of the personal information might have archiving purposes in the public interest. If the system properly safeguards this information and if complying with this requirement seriously impairs those purposes, this requirement is not applicable.

References#