DAT-02Data and Privacy

Lawful, minimised processing

Personal data is processed on a stated basis, limited to what is needed and kept only as long as needed.

Why it exists

Minimisation is the cheapest control there is.

What usually proves it

Processing records, retention schedule, deletion evidence.

Smaller organizations

A retention line per data type, applied on a calendar.

Mapped to

  • Partially addressedSOC 2 Trust Services Criteria · P4.0 — Only when privacy criteria are in scope.
  • Partially addressedISO/IEC 27001 Annex A · A.5.34 — Privacy of PII is required; lawful basis is not.
  • Partially addressedNIST Cybersecurity Framework · GV.OC-03 — Through legal requirements.
  • Fully addressedPCI DSS · 3.2.1
  • Fully addressedHIPAA Security Rule · 164.502(b)
  • Fully addressedGDPR · Art. 5, 6
  • Partially addressedEU AI Act · Art. 10(5) — Special category processing for bias detection.
  • Partially addressedNIST AI Risk Management Framework · MAP 4.1 — Privacy risk mapping.