R316. Allow rectification requests

Requirement

The system must allow its users to request rectification of the collected data belonging to them.

Description

Systems usually request information from their users, obtain it from third parties or collect it based on their interactions with the application. They should have a mechanism that allows users to find out about this information and request rectification if they consider it necessary.

Exceptions

  1. If the system is able to demonstrate that it is not possible to individually identify users based on the information collected from them, this requirement is not applicable.

  2. The processing of the personal information might have scientific, historical research or statistical purposes. If the system properly safeguards this information and if complying with this requirement seriously impairs these purposes, this requirement is not applicable.

  3. The processing of the personal information might have archiving purposes in the public interest. If the system properly safeguards this information and if complying with this requirement seriously impairs these purposes, this requirement is not applicable.

References

  1. GDPR. Art. 11: Processing which does not require identification.(2). Where the controller is able to demonstrate that it is not in a position to identify the data subject, articles 15 to 20 shall not apply.

  2. GDPR. Art. 16: Right to rectification.(1). The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her.

  3. GDPR. Art. 89: Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes.(2). Where personal data are processed for scientific or historical research purposes or statistical purposes, Union or Member State law may provide for derogations from the rights referred to in Articles 15, 16, 18 and 21.

  4. GDPR. Art. 89: Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes.(3). Where personal data are processed for archiving purposes in the public interest, Union or Member State law may provide for derogations from the rights referred to in Articles 15, 16, 18, 19, 20 and 21.

  5. ISO 27001:2013. Annex A - 18.1.4 When applicable, guarantee the privacy and security of personal information, as required by the relevant legislation and regulations.

Copyright © 2020 Fluid Attacks, We hack your software. All rights reserved.

Service status - Terms of Use - Privacy Policy - Cookie Policy