Skip to main content

The privacy notice names a data-protection contact and a direct way to reach them.

Intent

A data-protection contact gives the person somewhere to take a question, instead of a general enquiries address where a request can sit unread. A team is enough - the criterion asks who deals with requests, not for an individual’s name.

How to test it

An assessor scores the criterion against a single response:

Score 2
The organisation names a data-protection contact and a way to reach them that does not go through general enquiries.
Score 1
The organisation names a contact but routes the person through general enquiries, or gives an address without saying whose it is.
Score 0
The organisation names no data-protection contact.

The law it reflects

This criterion reflects Article 13(1)(b) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.

See A7 in context in the full standard.

Back to reference material

Report a problem with this page