Availability Limitations - Authority of Law, v1.0

Defines privacy requirements related to organizations make sensitive information available for purposes other than those specified.

Assessment Step

1
Availability Limitations - Authority Of Law (AvailabilityLimitations-AuthorityOfLaw)
Does the organization permit sensitive information to be made available for purposes other than those specified without the consent of the data subject under the authority of law?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
Personal data may be made available for purposes other than those specified without the consent of the data subject under the authority of law.
Citation
OECD
Use Limitation