Skip to main content
← All controls
A.7.2.2 / NIST Privacy Framework PR.PO-P2 / GDPR Article 13-14 ISO/IEC 27701:2019

Privacy notice up to date

Demonstrate that privacy notices accurately reflect current data processing practices, are reviewed and updated on a defined schedule, and remain compliant with applicable privacy laws and regulations.

Description

What this control does

This control requires that privacy notices provided to data subjects are kept current with actual data processing activities, legal requirements, and organizational practices. It ensures that individuals receive accurate, complete information about how their personal data is collected, used, stored, shared, and protected before or at the point of collection. Regular reviews and update mechanisms are necessary to maintain alignment between published notices and operational reality, particularly when new processing activities are introduced, third-party relationships change, or privacy regulations evolve.

Control objective

What auditing this proves

Demonstrate that privacy notices accurately reflect current data processing practices, are reviewed and updated on a defined schedule, and remain compliant with applicable privacy laws and regulations.

Associated risks

Risks this control addresses

  • Individuals consent to data processing based on outdated or inaccurate information, invalidating legal basis for processing under GDPR, CCPA, or similar regulations
  • Regulatory fines and enforcement actions resulting from failure to provide accurate, up-to-date privacy disclosures as required by law
  • Reputational damage and loss of customer trust when actual data practices diverge from published privacy commitments
  • Legal liability from processing data beyond the scope disclosed in outdated privacy notices, creating unauthorized data use scenarios
  • Inability to demonstrate accountability and transparency in privacy governance during regulatory audits or investigations
  • Failure to inform data subjects of material changes in data sharing arrangements with third parties, processors, or cross-border transfers
  • Non-compliance with breach notification or privacy rights fulfillment due to outdated contact information or procedures in privacy notices

Testing procedure

How an auditor verifies this control

  1. Obtain all current privacy notices published across organizational channels including website, mobile applications, point-of-sale systems, and customer-facing forms
  2. Retrieve the privacy notice review and update policy, including defined triggers for updates and approval workflows
  3. Interview the privacy officer or designated data protection lead to understand the process for identifying when privacy notice updates are required
  4. Compare the published privacy notice content against documented data processing activities, data flow diagrams, and Records of Processing Activities (ROPA) to verify alignment
  5. Review change logs, version control records, or document management system metadata to verify the date of last privacy notice review and update
  6. Select a sample of recent changes to data processing activities (new vendor engagements, new data collection points, new product launches) and verify corresponding privacy notice updates were completed
  7. Verify that privacy notice update approval involved legal counsel, privacy/compliance team, and appropriate business stakeholders as defined in policy
  8. Test public-facing privacy notice accessibility by attempting to locate and access notices from multiple user entry points and verify they display the current version with effective date
Evidence required Collect current privacy notices from all publication channels with version numbers and effective dates. Obtain privacy notice review logs, change management tickets, and approval records showing update cycles. Capture Records of Processing Activities, data flow documentation, and vendor agreements used for privacy notice validation. Retrieve policy documentation defining review frequency and update triggers, along with interview notes from privacy officers describing the update process.
Pass criteria Privacy notices accurately reflect current data processing activities as documented in Records of Processing Activities, have been reviewed within the policy-defined timeframe, include current effective dates, and demonstrate documented updates when material changes to processing occurred.

Where this control is tested

Audit programs including this control