GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-022 Privacy Programme and Data Protection Policy

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A documented privacy programme exists with a named privacy lead, a data protection policy approved by management, and controls covering the personal data lifecycle. The programme addresses applicable privacy regulations and is reviewed at defined intervals.

Rationale

Privacy compliance requires both a governing policy and an operationalised programme. A policy without a programme is unenforceable; a programme without a policy lacks the authoritative mandate needed for organisational compliance.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (11)

DSP-01Security and Privacy Policy and Procedurespartial
DSP-01Security and Privacy Policy and Procedurespartial
GDPR-Art.24Controller Responsibility and Demonstrable Compliancefull
GDPR-Art.5.2Accountability Principlepartial
5.34Privacy and protection of PIIfull
PM-18Privacy Program Planfull
PM-19Privacy Program Leadership Rolepartial
PM-23Data Governance Bodypartial
PM-26Complaint Managementpartial
PM-27Privacy Reportingpartial
PT-1Policy and Proceduresfull

Evidence (2)

policydocumentmanual

Data protection policy approved by management, with a named privacy lead, covering the personal data lifecycle and applicable privacy regulations.

Example: Data Protection Policy (Confluence / policy management system), approved by the named DPO or privacy lead and a senior executive, covering: lawful basis for processing, data subject rights, data retention, breach notification, and applicable regulations (GDPR, CCPA, etc.).

Test: Request the data protection policy. Verify: (1) a named privacy lead or DPO is identified, (2) lawful bases for processing are listed, (3) data subject rights procedures are referenced, (4) breach notification obligations and timelines are stated, (5) the policy has been approved and is dated within the last 12 months.

recorddocumentmanual

Privacy programme activity records confirming the privacy programme is operational, including a Records of Processing Activities (RoPA), DPIA log, or privacy review records.

Example: GDPR Records of Processing Activities document (Article 30 RoPA) and/or DPIA register (OneTrust / spreadsheet), showing at least three current processing activities with named controller, data categories, purposes, retention periods, and recipients.

Test: Request the RoPA and/or DPIA register. Verify: (1) at least the key data processing activities are documented, (2) each entry includes: data categories, purpose, legal basis, retention, and third-party recipients, (3) high-risk processing activities have an associated DPIA, (4) the RoPA is reviewed within the last 12 months.

Questions (2)

boolean

Does your organisation have a documented data protection policy approved by management?

The policy should cover lawful basis for processing, data subject rights, breach notification, and applicable regulations (e.g. GDPR, CCPA), and be approved within the last 12 months.

multi

Which of the following does your privacy programme maintain?

A named privacy lead accountable for the programmeRecords of processing activities covering the key data flowsData protection impact assessments for high-risk processingA privacy notice for data subjectsA documented procedure for handling data subject rights requestsA breach notification procedure with defined regulatory reporting timelinesNone of the above

Options run from the most commonly held to the least. A policy on its own is not a programme. The records of processing and the breach notification procedure are the two operational artefacts an assessor asks for first.