Adequate Notice - Personal Information Controller Contact, v1.0

Defines privacy requirements that the means to contact the information controller about their practices and handling of sensitive information are included in statements with respect to it.

Assessment Step

1
Adequate Notice - Personal Information Controller Contact (AdequateNotice-PersonalInformationControllerContact)
Does the organization require that sensitive information controller statements with respect to sensitive information include information on how to contact the information controller about their practices and handling of sensitive information?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
Personal information controller statements with respect to personal information include information on how to contact the information controller about their practices and handling of personal information.
Citation
APEC
Section 15, Notice