GAISSF / D5 / D5-CTL-05

Privacy-By-Design Verification

Objective

Comply with GDPR Art. 25 + CCPA.

Control / requirement

Data minimization + purpose limitation + machine unlearning.

Business impact

Privacy-by-Design violations can trigger GDPR fines up to €20M, regulatory audits, and right-to-erasure failures with class action exposure.

Validation approach

Test ID: D5-CTL-05-VTS-001 Test Type: Manual + Automated Test Design: Audit data collection scope against stated purpose; attempt secondary use; submit erasure request Execution Steps: 1. Review data collection policy & logs 2. Attempt secondary use 3. Submit erasure request 4. Verify erasure within SLA & unlearning Pass Criteria: data_minimization_verified = True; secondary_use_blocked = True; erasure_completed_within_30_days = True; machine_unlearning_tested_annually = True Independent Verification: Auditor reviews data flows and erasure test results.

Expected evidence

Not separately specified in the available source.

Mapping and source

Not separately specified in the available source.

Implementation guidance

Translate the requirement into system-specific procedures, responsible roles, technical configurations and review conditions. Retain evidence showing both design and operating performance. Where the source provides no separate implementation instruction, do not infer that a single technical mechanism is sufficient.

Assessment considerations

  • Confirm scope and applicability.
  • Inspect control design and responsible ownership.
  • Test representative operation and adverse conditions where appropriate.
  • Evaluate evidence provenance, completeness and contradictory evidence.
  • Record limitations and notably absent outcomes.