Skip to main content

Delivered Securely

The organisation delivers the response by a means that protects it from being read by anyone other than the person.

Criterion
G3
Level
Level 1
Domain
Format and Delivery
Reflects
Article 5(1)(f)

Intent

A subject access response is a concentrated set of one person's data. Sent carelessly, exercising the right creates the exposure it was meant to reveal.

How to test it

An assessor scores the criterion against a single response:

Score 2
The organisation delivered the response so that only the person could open it.
Score 1
The organisation sent the response protected, but sent the password or link by the same channel.
Score 0
The organisation sent the data unprotected, or to an address the person had not given.

The law it reflects

This criterion reflects Article 5(1)(f) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.

See G3 in context in the full standard.