Delivered Securely
The organisation delivers the response by a means that protects it from being read by anyone other than the person.
Intent
A response gathers one person's data into a single place. Sent carelessly, it hands that data to whoever else can read it.
How to test it
An assessor scores the criterion against a single response:
- Score 2
- The organisation delivered the response so that only the person could open it.
- Score 1
- The organisation sent the response protected, but sent the password or link by the same channel.
- Score 0
- The organisation sent the data unprotected, or to an address the person had not given.
The law it reflects
This criterion reflects Article 5(1)(f) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.
See G3 in context in the full standard.