Lawful basis, consent and privacy notice: the clause the question tests
On what legal ground personal data is processed and what the people concerned were told.
How the customer usually asks it
example"What is your lawful basis for processing personal data?"
Anchor clauses
3 frameworks| Framework | Anchor clause |
|---|---|
| ISO/IEC 27001:2022 | 5.34 Privacy and protection of personal identifiable information (PII) |
| SIG (Shared Assessments) | domain O Privacy |
| GDPR, Regulation (EU) 2016/679 | Art. 6 Lawfulness of processing |
Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.
Evidence expected
For a processor, the processing instructions in the contract; the lawful basis and the notice to the people concerned are the controller's own records.
The clauses, with what an assessor asks for
ISO 27001 5.34 Privacy and protection of personal identifiable information (PII)Identify and meet privacy and PII-protection requirements from law, regulation and contract.
Where answers usually fall short: Missing documented consent for all data subjects; Incomplete inventory of PII across legacy systems
Source: ISO/IEC 27001:2022
SIG domain O PrivacyWhat it asks for, in one line (the standard's own text is not quoted here):
Manage personal data in accordance with applicable privacy laws and contractual obligations, including data subject rights, lawful basis, cross border transfers, and breach notification.
Where answers usually fall short: No transfer impact assessment for non adequacy jurisdictions; DSR metrics not tracked against statutory deadlines
Source: SIG (Shared Assessments)
GDPR Art. 6 Lawfulness of processingProcess personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of official authority, or legitimate interests that are not overridden by the data subject's interests, rights and freedoms. Public authorities cannot rely on legitimate interests for processing carried out in performance of their tasks. Where the basis is legal obligation or public task, that basis must be laid down in Union or Member State law and the purpose must be determined in it. Before processing for a purpose other than the one collected for, without consent or a legal mandate, assess compatibility against the link between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place.
Where answers usually fall short: Consent recorded as the basis where the processing would happen regardless of the answer, which makes it neither free nor the real basis; Legitimate interests asserted with no balancing test on file, or a balancing test that never reaches an adverse conclusion for any activity
Source: GDPR, Regulation (EU) 2016/679