Skip to main content

The Categories of Data

The response states the categories of the person's personal data that the organisation processes.

Criterion
E2
Level
Level 1
Domain
Supplementary Information
Reflects
Article 15(1)(b)

Intent

Categories tell the person what kinds of data the organisation processes, which is how they spot something they did not expect it to have.

How to test it

An assessor scores the criterion against a single response:

Score 2
The response names the categories closely enough for the person to tell what kinds of data the organisation processes.
Score 1
The response gives categories so broad they say little about what the organisation processes.
Score 0
The response states no categories at all.

The law it reflects

This criterion reflects Article 15(1)(b) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.

See E2 in context in the full standard.