# Policy Data Protection | Document information | Value | |-----------------------|------| | Document type | Policy | | Scope | {{ISMS_SCOPE}} | | Organisation | {{ORG_NAME}} | | Responsible | {{ROLE_DPO}} | | Approved by | {{ROLE_MANAGEMENT}} | | Version | {{DOC_VERSION}} | | Date | {{DOC_DATE}} | | Status | {{DOC_STATUS}} | ## 1. Purpose This policy governs the protection of personal data (assessment objective data protection, VDA ISA chapter 9). It elaborates the information security policy ({{LINK:L00}}) and complements the policy Compliance and Data Protection ({{LINK:R14}}). ## 2. Scope This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}), insofar as personal data is processed. ## 3. Requirements and implementation > Structure per section: **Requirement** (1:1 from VDA ISA, chapter 9) and **Implementation at {{ORG_NAME}}**. {{#if FLAG_PERSONAL_DATA}} ### 3.1 Data protection organisation (ISA 9.1.1) **Requirement** - **[MUST]** Responsibilities for data protection are appointed and the data protection organisation is documented. **Implementation at {{ORG_NAME}}** The role {{ROLE_DPO}} is appointed and integrated into the ISMS organisation. Tasks, reporting paths and escalation are documented. ### 3.2 Lawfulness and record of processing activities (ISA 9.2.1) **Requirement** - **[MUST]** Processing of personal data is lawful, purpose-bound and recorded in a record of processing activities. **Implementation at {{ORG_NAME}}** A record of processing activities is maintained and updated regularly. For each processing activity, the legal basis, purpose and deletion periods are documented. {{/if}}