What is it about?
Due to the close connection between buildings and their users, digitalization processes often go hand in hand with the processing of personal data. The General Data Protection Regulation (GDPR) sets strict requirements for the processing of personal data, which those responsible for processing must comply with. These include, in particular, transparency and accountability obligations, as well as the fundamental requirement of a legal basis.
How does it work?
The following criteria catalog includes all obligations from the GDPR in the form of “criteria” and “requirements”, which are specified for each purpose category. The catalog divides the GDPR requirements into 14 “topics” and can be specifically searched using a dropdown system and a search field.
-
On the one hand, it serves to make data protection law and the underlying goals and values understandable to the readers.
-
On the other hand, the “requirements” can be understood as a checklist that those responsible should follow before processing personal data.
-
The requirements from this criteria catalog will be transferred into a certification program by the end of the project. In the future, those responsible should be able to obtain an EU data protection seal in accordance with Article 42 of the GDPR.
Note
The criteria catalog is currently being continuously updated and revised. All recommendations are typified examples that must be considered and implemented in light of the specific use case.