Example: GDPR Compliance Report

Summary of data and practices

Categories of Personal Data

category
1
q:Demographics
2
q:Psychographics

Categories of Data Subjects

None

Types of Personal Data

category
1
q:AdIdentifier
2
q:AdInteraction
3
q:AgeProfile
4
q:AppsUsedByUser
5
q:BusinessOccupationProfile
6
q:BuyingHistory
7
q:BuyingInterestsProfile
8
q:ContentUsage
9
q:Cookie
10
q:DataGooglePartners
11
q:DeviceIdentifier
12
q:DrivingProfile
13
q:EducationProfile
14
q:Email
15
q:EthnicityProfile
16
q:FamilyProfile
17
q:GenderProfile
18
q:GeographyProfile
19
q:HouseholdIncomeProfile
20
q:Interests
21
q:LogData
22
q:MediaHistory
23
q:MediaInterestsProfile
24
q:OccupationProfile
25
q:PoliticalAffiliationProfile
26
q:PoliticalInterestsProfile
27
q:PrivacyChoices
28
q:PrivacyNotices
29
q:ServiceUsage
30
q:ShoppingInterestsProfile
31
q:UserID
32
q:WebsiteHistory

Data Sources

data step agent agent_type
1
q:AdInteraction
q:CollectAdInteraction
2
q:AppsUsedByUser
q:visitPartnerWebsite
3
q:BuyingHistory
q:CollectDataFromThirdParties
q:DLX
gc:ThirdParty
4
q:BuyingHistory
q:CollectDataFromThirdParties
q:Experian
gc:ThirdParty
5
q:BuyingHistory
q:CollectDataFromThirdParties
q:MasterCard
gc:ThirdParty
6
q:BuyingHistory
q:CollectDataFromThirdParties
q:Netwise
gc:ThirdParty
7
q:BuyingHistory
q:CollectDataFromThirdParties
q:TiVO
gc:ThirdParty
8
q:ContentUsage
q:CollectContentUsage
9
q:Cookie
q:visitPartnerWebsite
10
q:Cookie
q:visitWebsite
11
q:Email
q:receiveEmailQuery
12
q:LogData
q:visitPartnerWebsite
13
q:LogData
q:visitWebsite
14
q:MediaHistory
q:CollectDataFromThirdParties
q:DLX
gc:ThirdParty
15
q:MediaHistory
q:CollectDataFromThirdParties
q:Experian
gc:ThirdParty
16
q:MediaHistory
q:CollectDataFromThirdParties
q:MasterCard
gc:ThirdParty
17
q:MediaHistory
q:CollectDataFromThirdParties
q:Netwise
gc:ThirdParty
18
q:MediaHistory
q:CollectDataFromThirdParties
q:TiVO
gc:ThirdParty
19
q:PrivacyChoices
q:visitPartnerWebsite
20
q:PrivacyChoices
q:visitWebsite
21
q:PrivacyNotices
q:visitPartnerWebsite
22
q:PrivacyNotices
q:visitWebsite
23
q:ServiceUsage
q:CollectServiceUsage
24
q:WebsiteHistory
q:visitPartnerWebsite

Purposes of processing

data data type Purpose
1
"Cookie"@en
"PersonalData"@en
Google
2
"Cookie"@en
"PersonalData"@en
Information, Storage, and Access
3
"Cookie"@en
"PersonalData"@en
Information, Storage, and Access with Partners
4
"Cookie"@en
"PersonalData"@en
Quantcast Advertise Services
5
"Log Data"@en
"PersonalData"@en
Monitor, Analyse, and Improve Services
6
"Log Data"@en
"PersonalData"@en
Quantcast Advertise Services
7
"email"@en
"PersonalData"@en
"Marketting"@en
8
Buying History
"PersonalData"@en
Ad selection, delivery, reporting
9
Buying History
"PersonalData"@en
Ad selection, delivery, reporting with Partners
10
Buying History
"PersonalData"@en
Quantcast Advertise Services
11
Interests
"PersonalData"@en
Ad selection, delivery, reporting
12
Interests
"PersonalData"@en
Ad selection, delivery, reporting with Partners
13
Interests
"PersonalData"@en
Content selection, delivery, reporting with Partners
14
Interests
"PersonalData"@en
Personalisation
15
Interests
"PersonalData"@en
Personalisation with Partners
16
Media History
"PersonalData"@en
Quantcast Advertise Services
17
advertising identifier
"PersonalData"@en
Information, Storage, and Access
18
advertising identifier
"PersonalData"@en
Information, Storage, and Access with Partners
19
advertising identifier
"UserIdentifier"@en
Information, Storage, and Access
20
advertising identifier
"UserIdentifier"@en
Information, Storage, and Access with Partners
21
apps used by user
"PersonalData"@en
Monitor, Analyse, and Improve Services
22
apps used by user
"PersonalData"@en
Quantcast Advertise Services
23
content usage
"PersonalData"@en
Content selection, delivery, reporting with Partners
24
content usage
"PersonalData"@en
Measurement
25
content usage
"PersonalData"@en
Measurement with Partners
26
data used by Google Partners
"PersonalData"@en
Google
27
device identifier
"PersonalData"@en
Information, Storage, and Access
28
device identifier
"PersonalData"@en
Information, Storage, and Access with Partners
29
device identifier
"UserIdentifier"@en
Information, Storage, and Access
30
device identifier
"UserIdentifier"@en
Information, Storage, and Access with Partners
31
interaction with ads
"PersonalData"@en
Ad selection, delivery, reporting
32
interaction with ads
"PersonalData"@en
Ad selection, delivery, reporting with Partners
33
service usage
"PersonalData"@en
Personalisation
34
service usage
"PersonalData"@en
Personalisation with Partners
35
website history of user
"PersonalData"@en
Monitor, Analyse, and Improve Services
36
website history of user
"PersonalData"@en
Quantcast Advertise Services

Legal Basis

process legal basis
1
"Marketting"@en
Given Consent
2
Ad selection, delivery, reporting
Given Consent
3
Ad selection, delivery, reporting with Partners
Given Consent
4
Content selection, delivery, reporting with Partners
Given Consent
5
Google
Given Consent
6
Information, Storage, and Access
Given Consent
7
Information, Storage, and Access with Partners
Given Consent
8
Measurement
Given Consent
9
Measurement with Partners
Given Consent
10
Monitor, Analyse, and Improve Services
Legitimate Interests
11
Personalisation
Given Consent
12
Personalisation with Partners
Given Consent
13
Quantcast Advertise Services
Legitimate Interests

Special categories of Personal Data

None

Legal basis for processing special categories of personal data

N/A

Retention period

data duration
1
"Cookie"@en
2
"Log Data"@en
"6"^^xsd:integer
3
"email"@en
4
Age Profile
5
Business & Occupation Profile
6
Buying History
7
Driving Profile
8
Education Profile
9
Ethnicity Profile
10
Family Profile
11
Gender Profile
12
Geography Profile
13
HouseholdIncomeProfile
14
Interests
15
Media History
16
Media Interests Profile
17
Occupation Profile
18
Political Interests Profile
19
PoliticalAffiliationProfile
20
Privacy Choices
21
Privacy Notices
22
Shopping Interests Profile
23
User ID (cookie ID)
24
advertising identifier
25
apps used by user
26
content usage
27
data used by Google Partners
28
device identifier
29
interaction with ads
30
service usage
31
website history of user

Action required to be GDPR compliant

msg
1
Consent should state data storage periods
-(Manually generated) Special categories of personal data should be declared

Validity of Consent

test focus
1
Consent Core constraints
automatic
2
Consent Activity Constraints
automatic
3
Consent Artefact Constraints
automatic
4
Third Party Sharing Constraints
automatic
5
Valid Consent Constraints
manual
6
Withdraw Consent Constraints
manual

Demonstration of Consent

quantcast-consent-screen
Given Consent Attributes

Withdraw Consent

step process
1
q:ChangeConsent
q:QChoice

Children's Personal Data

None

Age verification

N/A

Legitimate interest based data processing

Process Action Data
1
Monitor, Analyse, and Improve Services
"usesData"@en
"Log Data"@en
2
Monitor, Analyse, and Improve Services
"usesData"@en
apps used by user
3
Monitor, Analyse, and Improve Services
"usesData"@en
website history of user
4
Quantcast Advertise Services
"generatesData"@en
Age Profile
5
Quantcast Advertise Services
"generatesData"@en
Driving Profile
6
Quantcast Advertise Services
"generatesData"@en
Education Profile
7
Quantcast Advertise Services
"generatesData"@en
Ethnicity Profile
8
Quantcast Advertise Services
"generatesData"@en
Family Profile
9
Quantcast Advertise Services
"generatesData"@en
Gender Profile
10
Quantcast Advertise Services
"generatesData"@en
HouseholdIncomeProfile
11
Quantcast Advertise Services
"generatesData"@en
Media Interests Profile
12
Quantcast Advertise Services
"generatesData"@en
Political Interests Profile
13
Quantcast Advertise Services
"generatesData"@en
PoliticalAffiliationProfile
14
Quantcast Advertise Services
"generatesData"@en
Shopping Interests Profile
15
Quantcast Advertise Services
"usesData"@en
"Cookie"@en
16
Quantcast Advertise Services
"usesData"@en
"Log Data"@en
17
Quantcast Advertise Services
"usesData"@en
Buying History
18
Quantcast Advertise Services
"usesData"@en
Media History
19
Quantcast Advertise Services
"usesData"@en
apps used by user
20
Quantcast Advertise Services
"usesData"@en
website history of user
21
Quantcast Choice
"generatesData"@en
Privacy Choices
22
Quantcast Choice
"generatesData"@en
Privacy Notices

Handle SAR

https://www.quantcast.com/privacy/data-subject-rights/

Subject Access Requests (SARs) Response Time

N/A

Data Portability

subject predicate object
1
q:RightToDataPortability
rdf:type
owl:NamedIndividual
2
q:RightToDataPortability
rdf:type
gdprov:HandleRightToDataPortability
3
q:RightToDataPortability
rdfs:comment
"If you are located in the EEA and we can properly identify you, you have a number of rights with regard to your personal information. For example, you have the right to access your information and to have inaccuracies in your personal information corrected. In many cases where we process your information, you may also have a right to restrict or limit the ways in which we use your information. You also have the right to object to the processing of your personal information and to have it deleted in certain circumstances. You also have a right to obtain a copy of your personal information in an easily accessible format. For these purposes, go here. However, as outlined above, although we make predictions about consumers’ interests based on the information collected in accordance with this Privacy Policy, we don’t know who you are. Accordingly, if we receive a request from you and we cannot identify you (even if you provide us with additional information), we may not be able to assist you in exercising these rights. "^^xsd:string
4
q:RightToDataPortability
rdfs:label
"handle right to data portability"^^xsd:string
5
q:RightToDataPortability
rdfs:seeAlso
https://www.quantcast.com/privacy/data-subject-rights/

Deletion and Rectification

process
1
q:RightToErasure
2
q:RightToRectification

Right to restriction of processing

None

Right to object to processing

subject predicate object
1
q:RightToObjectProcessing
rdf:type
p-plan:Plan
2
q:RightToObjectProcessing
rdf:type
owl:NamedIndividual
3
q:RightToObjectProcessing
rdf:type
gdprov:HandleRightToObjectProcessing
4
q:RightToObjectProcessing
rdf:type
gdprov:Process
5
q:RightToObjectProcessing
rdfs:comment
"If you are located in the EEA and we can properly identify you, you have a number of rights with regard to your personal information. For example, you have the right to access your information and to have inaccuracies in your personal information corrected. In many cases where we process your information, you may also have a right to restrict or limit the ways in which we use your information. You also have the right to object to the processing of your personal information and to have it deleted in certain circumstances. You also have a right to obtain a copy of your personal information in an easily accessible format. For these purposes, go here. However, as outlined above, although we make predictions about consumers’ interests based on the information collected in accordance with this Privacy Policy, we don’t know who you are. Accordingly, if we receive a request from you and we cannot identify you (even if you provide us with additional information), we may not be able to assist you in exercising these rights. "^^xsd:string
6
q:RightToObjectProcessing
rdfs:label
"handle right to object"^^xsd:string
7
q:RightToObjectProcessing
rdfs:seeAlso
https://www.quantcast.com/privacy/data-subject-rights/

Profiling and automated processing

None

Right to obtain human intervention

N/A

Purpose Limitation

msg
1
Consent should cover all purposes http://example.com/Quantcast#InformationStorageAccessWithPartners for same processing activities http://example.com/Quantcast#StoreIdentifiers
2
Consent should cover all purposes http://example.com/Quantcast#InformationStorageAccessWithPartners for same processing activities http://example.com/Quantcast#UseIdentifiers

Data minimisation

Data used
1
"Cookie"@en
"true"^^xsd:boolean
2
"Log Data"@en
"true"^^xsd:boolean
3
"email"@en
"true"^^xsd:boolean
4
Privacy Choices
"false"^^xsd:boolean
5
Privacy Notices
"false"^^xsd:boolean
6
apps used by user
"true"^^xsd:boolean
7
content usage
"true"^^xsd:boolean
8
interaction with ads
"true"^^xsd:boolean
9
service usage
"true"^^xsd:boolean
10
website history of user
"true"^^xsd:boolean

Destroy data securely

None

Provide Information listed in Article 13

consent_dialogue medium location
1
q:CATQAds
dialog box on website
https://quantcast.com/
2
q:CATQInfoStorageAccess
dialog box on website
https://quantcast.com/
3
q:CATQMeasure
dialog box on website
https://quantcast.com/
4
q:CATQPersonalise
dialog box on website
https://quantcast.com/
5
q:CATTPAds
dialog box on website
https://quantcast.com/
6
q:CATTPContentSelection
dialog box on website
https://quantcast.com/
7
q:CATTPGoogle
dialog box on website
https://quantcast.com/
8
q:CATTPInfoStorageAccess
dialog box on website
https://quantcast.com/
9
q:CATTPMeasure
dialog box on website
https://quantcast.com/
10
q:CATTPPersonalise
dialog box on website
https://quantcast.com/

Provide Information listed in Article 14

ThirdParty Data
1
DLX
Buying History
2
Experian
Buying History
3
MasterCard
Buying History
4
Netwise
Buying History
5
TiVO
Buying History
6
DLX
Media History
7
Experian
Media History
8
MasterCard
Media History
9
Netwise
Media History
10
TiVO
Media History

Data Protection Impact Assessments (DPIAs)

None

Compliance Validation Report

name test gdpr result node msg
1
Consent != Inactivity
Manual
gdpr:recital32
PASS
2
Consent != Pre-ticked Boxes
Manual
gdpr:recital32
PASS
3
Consent != Silence
Manual
gdpr:recital32
PASS
4
Consent --> Data Subject
Automatic
gdpr:article4-11
PASS
5
Consent --> Given To
Automatic
PASS
6
Consent --> Location
Automatic
PASS
7
Consent --> Medium
Automatic
gdpr:article7-2
PASS
8
Consent --> Medium
Automatic
gdpr:recital32
PASS
9
Consent --> Personal Data
Automatic
gdpr:article4-11
PASS
10
Consent --> Personal Data
Automatic
gdpr:recital32
PASS
11
Consent --> Processing
Automatic
gdpr:article4-11
PASS
12
Consent --> Processing
Automatic
gdpr:recital32
PASS
13
Consent --> Provided By
Automatic
gdpr:article7-2
PASS
14
Consent --> Purpose
Automatic
gdpr:recital32
PASS
15
Consent --> Purpose
Automatic
gdpr:recital42
PASS
16
Consent --> Status
Automatic
PASS
17
Consent --> Timestamp
Automatic
FAIL
q:Consent20190415120753
Consent should have a timestamp
18
Consent --> Timestamp
Automatic
FAIL
q:Consent20190415140000
Consent should have a timestamp
19
Consent == Choice
Manual
PASS
20
Consent == Freely Given
Manual
gdpr:article4-11
PASS
21
Consent == Specific
Manual
gdpr:article4-11
PASS
22
Consent == Statement of Clear Action
Manual
gdpr:article4-11
PASS
23
Consent == Unambigious
Manual
gdpr:article4-11
PASS
24
Consent Generating Activity
Automatic
PASS
25
Consent Request == Clear
Manual
gdpr:recital32
PASS
26
Consent Request == Concise
Manual
gdpr:recital32
PASS
27
Consent Request == Not Disruptive
Manual
gdpr:recital32
PASS
28
Consent Template
Automatic
PASS
29
Ease of Withdraw Consent
Manual
gdpr:article7-3
PASS
30
Many Processing x One Purpose
Automatic
gdpr:recital32
PASS
31
One Processing x Many Purposes
Automatic
gdpr:recital32
FAIL
q:Consent20190415120753
Consent should cover all purposes http://example.com/Quantcast#InformationStorageAccessWithPartners for same processing activities http://example.com/Quantcast#StoreIdentifiers
32
One Processing x Many Purposes
Automatic
gdpr:recital32
FAIL
q:Consent20190415140000
Consent should cover all purposes http://example.com/Quantcast#InformationStorageAccessWithPartners for same processing activities http://example.com/Quantcast#StoreIdentifiers
33
One Processing x Many Purposes
Automatic
gdpr:recital32
FAIL
q:Consent20190415120753
Consent should cover all purposes http://example.com/Quantcast#InformationStorageAccessWithPartners for same processing activities http://example.com/Quantcast#UseIdentifiers
34
One Processing x Many Purposes
Automatic
gdpr:recital32
FAIL
q:Consent20190415140000
Consent should cover all purposes http://example.com/Quantcast#InformationStorageAccessWithPartners for same processing activities http://example.com/Quantcast#UseIdentifiers
35
Personal Data --> Storage Period
Automatic
gdpr:article13-2-a
FAIL
q:CATQInfoStorageAccess
Consent should state data storage periods
36
Personal Data --> Storage Period
Automatic
gdpr:article13-2-a
FAIL
q:CATTPInfoStorageAccess
Consent should state data storage periods
37
Personal Data --> Storage Period
Automatic
gdpr:article13-2-a
FAIL
q:Consent20190415120753
Consent should state data storage periods
38
Personal Data --> Storage Period
Automatic
gdpr:article13-2-a
FAIL
q:Consent20190415140000
Consent should state data storage periods
39
Personal Data --> Storage Period
Automatic
gdpr:article14-2-a
FAIL
q:CATQInfoStorageAccess
Consent should state data storage periods
40
Personal Data --> Storage Period
Automatic
gdpr:article14-2-a
FAIL
q:CATTPInfoStorageAccess
Consent should state data storage periods
41
Personal Data --> Storage Period
Automatic
gdpr:article14-2-a
FAIL
q:Consent20190415120753
Consent should state data storage periods
42
Personal Data --> Storage Period
Automatic
gdpr:article14-2-a
FAIL
q:Consent20190415140000
Consent should state data storage periods
43
Personal Data --> Storage Period
Automatic
gdpr:article5-1-e
FAIL
q:CATQInfoStorageAccess
Consent should state data storage periods
44
Personal Data --> Storage Period
Automatic
gdpr:article5-1-e
FAIL
q:CATTPInfoStorageAccess
Consent should state data storage periods
45
Personal Data --> Storage Period
Automatic
gdpr:article5-1-e
FAIL
q:Consent20190415120753
Consent should state data storage periods
46
Personal Data --> Storage Period
Automatic
gdpr:article5-1-e
FAIL
q:Consent20190415140000
Consent should state data storage periods
47
Personal Data --> Storage Period
Automatic
gdpr:recital39
FAIL
q:CATQInfoStorageAccess
Consent should state data storage periods
48
Personal Data --> Storage Period
Automatic
gdpr:recital39
FAIL
q:CATTPInfoStorageAccess
Consent should state data storage periods
49
Personal Data --> Storage Period
Automatic
gdpr:recital39
FAIL
q:Consent20190415120753
Consent should state data storage periods
50
Personal Data --> Storage Period
Automatic
gdpr:recital39
FAIL
q:Consent20190415140000
Consent should state data storage periods
51
Right to Withdraw
Automatic
gdpr:article7-3
PASS
52
Separation of Processing
Manual
gdpr:recital43
PASS
53
Third Party Categories
Automatic
gdpr:article44
PASS
54
Third Party Identities
Automatic
gdpr:article13-1-e
PASS
55
Third Party Identities
Automatic
gdpr:article14-1-e
PASS
56
Third Party Identities
Automatic
gdpr:article30-1-d
PASS
57
Third Party Identities
Automatic
gdpr:article44
PASS
58
Third Party Safeguards
Automatic
PASS
59
Withdraw Consent Information
Manual
gdpr:article7-3
PASS