Security Questionnaire Mapper

Data subject requests: the clause the question tests

How requests from the people whose data it is are handled, and who answers them.

How the customer usually asks it

example

"How do you handle data subject access and erasure requests?"

Read this question

Anchor clauses

4 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20225.34 Privacy and protection of personal identifiable information (PII)
SIG (Shared Assessments)domain O Privacy
CSA Cloud Controls Matrix v4.0.1DSP-11 Personal Data Access, Reversal, Rectification and Deletion
GDPR, Regulation (EU) 2016/679Art. 15 Right of access by the data subject · Art. 28 Processor

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The procedure for passing a data subject request to the customer and assisting with it, with the time the supplier commits to.

The clauses, with what an assessor asks for

ISO 27001 5.34 Privacy and protection of personal identifiable information (PII)

Identify and meet privacy and PII-protection requirements from law, regulation and contract.

Evidence an assessor expects: Privacy policy; Data inventory; Processing agreements; Breach records
Where answers usually fall short: Missing documented consent for all data subjects; Incomplete inventory of PII across legacy systems
Source: ISO/IEC 27001:2022
SIG domain O Privacy

What it asks for, in one line (the standard's own text is not quoted here):

Manage personal data in accordance with applicable privacy laws and contractual obligations, including data subject rights, lawful basis, cross border transfers, and breach notification.

Evidence an assessor expects: Privacy program policy; Data subject request handling procedure and metrics; Records of processing activities; Transfer impact assessments and standard contractual clauses
Where answers usually fall short: No transfer impact assessment for non adequacy jurisdictions; DSR metrics not tracked against statutory deadlines
Source: SIG (Shared Assessments)
CSA CCM DSP-11 Personal Data Access, Reversal, Rectification and Deletion

What it asks for, in one line (the standard's own text is not quoted here):

Give data subjects a working route to request access to, correction of or deletion of their personal data, and fulfil those requests as applicable law requires.

Evidence an assessor expects: The published request route and the procedure behind it; A log of requests received with dates and outcomes; Evidence requests were fulfilled inside the legal timeframe; The technical means by which data is located, changed or deleted across systems
Where answers usually fall short: Request route published with no process behind it; Deletion performed in the primary system while backups and exports retain the data
Source: CSA Cloud Controls Matrix v4.0.1
GDPR Art. 15 Right of access by the data subject

On request, confirm whether personal data concerning the data subject is being processed and, where it is, provide access to that data together with the purposes, the categories of personal data, the recipients or categories of recipient including any in third countries or international organisations, the envisaged storage period or the criteria setting it, the existence of the rights to rectification, erasure, restriction and objection, the right to lodge a complaint with a supervisory authority, any available information on the source where the data was not collected from the data subject, and the existence of automated decision-making including profiling with meaningful information about the logic involved and its significance and envisaged consequences. Where data has been transferred to a third country, inform the data subject of the Article 46 safeguards relating to the transfer. Provide a copy of the personal data undergoing processing, in a commonly used electronic form where the request was made electronically, free for the first copy and at a reasonable fee based on administrative costs for further copies. The right to obtain a copy must not adversely affect the rights and freedoms of others.

Evidence an assessor expects: The search methodology showing every system, archive and unstructured store searched, and how completeness was assured; A worked response covering all the supplementary information items, not only the copy of the data; The redaction position and the applied redaction log where third party data was withheld, with a reason recorded per redaction; Timeliness records for the last twelve months of requests measured against the one month limit; The source information provided where the data was not collected from the data subject
Where answers usually fall short: Structured database records returned while email, chat, ticketing and free text notes naming the person are never searched; The copy of the data provided with none of the supplementary information the Article requires alongside it
Source: GDPR, Regulation (EU) 2016/679
GDPR Art. 28 Processor

Use only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised to process are under a duty of confidentiality, takes all Article 32 measures, respects the sub-processor conditions, assists the controller in responding to data subject rights requests, assists with Articles 32 to 36, deletes or returns all personal data at the controller's choice at the end of the service and deletes existing copies unless law requires retention, and makes available all information needed to demonstrate compliance and allows for and contributes to audits and inspections. The processor must immediately inform the controller if it considers an instruction infringes data protection law. The same obligations must be imposed on any sub-processor, and the initial processor remains fully liable for the sub-processor's performance. A processor that determines purposes and means is a controller for that processing.

Evidence an assessor expects: A processor inventory reconciled against the vendor register or accounts payable, so no processor is missing from it; The Article 28(3) contract for each processor, checked clause by clause against the eight stipulations the Article names; Due diligence evidence gathered before appointment showing sufficient guarantees, distinct from the signed contract; The sub-processor authorisation position for each processor, the current sub-processor list, and evidence changes were notified; Audit or assurance rights exercised in practice, such as a report reviewed with findings tracked, and end of service deletion certificates
Where answers usually fall short: The processor's own standard terms accepted, which commonly omit the audit right, the deletion choice and the instruction infringement notice; A processor inventory that misses tools adopted directly by individual teams, which is where undocumented processing usually sits
Source: GDPR, Regulation (EU) 2016/679
Put to a supplier that processes personal data on the customer's behalf, this is the customer's own duty as controller; the register marks it "privacy question to a processor" and names GDPR Article 28, under which the processor assists.

Other families in privacy and data subject rights