Home / Fast Track / Privacy: lawful basis & data-subject rights
Shared control area · counts toward 2 standards
Privacy: lawful basis & data-subject rights
This control area ensures that personal data is processed legally and that individuals can exercise their rights over their information. Most frameworks require this because privacy protection is a legal mandate in most jurisdictions and a core component of overall information security risk management.
Implement it once
- Establish a Record of Processing Activities (RoPA) to document what data is collected, why, and the specific lawful basis for each activity.
- Deploy a mechanism for capturing, recording, and managing user consent where required.
- Create a standardized internal procedure for receiving, verifying, and responding to Data Subject Access Requests (DSARs).
- Implement a Data Protection Impact Assessment (DPIA) process to evaluate privacy risks before launching new high-risk processing activities.
- Publish a clear, up-to-date Privacy Notice that informs users of their rights and how their data is handled.
Evidence it produces
- A completed Data Inventory or RoPA spreadsheet/database.
- Time-stamped consent logs demonstrating when and how user agreement was obtained.
- An audit trail of DSAR tickets showing the request date, verification steps, and response delivery within legal timeframes.
- Signed DPIA reports for major systems or product changes.
- The public-facing Privacy Policy version history.
Where it counts
Implementing these controls satisfies both regulatory privacy laws and security certifications simultaneously. By centralizing these artifacts, an organization avoids duplicating effort when moving from a security-focused audit to a privacy-specific certification.