Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook

Records of personal data transfers to third parties

Critical
High
Normal
Low

The organization should record transfers of personal data to and from third parties. The organization should also ensure the cooperation of the relevant parties in order to enable the implementation of requests regarding obligations related to data subjects in the future as well.

The principle of data minimization must be taken into account in recordings concerning transfers and only the information that is actually needed must be kept.

Connected other frameworks and requirements:
A.7.5.3: Records of transfer of PII
ISO 27701
A.8.5.3: Records of PII disclosure to third parties
ISO 27701
No items found.