Which of the following are the mandatory pieces of information to be included in the documentation of records of processing activities for an organization that processes personal data on behalf of another organization?
A.
Copies of the consent forms from each data subject.
B.
Time limits for erasure of different categories of data.
C.
Contact details of the processor and Data Protection Offer (DPO).
D.
Descriptions of the processing activities and relevant data subjects.
D. Descriptions of the processing activities and relevant data subjects.
The records of processing activities must include descriptions of the processing activities and relevant data subjects.
Records of processing activities must include significant information about data processing, including data categories, the group of data subjects, the purpose of the processing and the data recipients. This must be completely made available to authorities upon request.
https://gdpr-info.eu/issues/records-of-processing-activities/#:~:text=GDPR%20Records%20of%20Processing%20Activities&text=Records%20of%20processing%20activities%20must,available%20to%20authorities%20upon%20request.
As per Art. 30 GDPR Records of processing activities, it's mandatory to provide name/contact details of the controller/DPO. Providing time limits is only "where possible". https://gdpr-info.eu/art-30-gdpr/
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Ssourav
3 months, 2 weeks agoz80r
1 year, 10 months agoSara_sw
2 years agopipzz
2 years, 4 months agopipzz
2 years, 4 months ago187san
2 years, 11 months ago