ID Proofing - Attribute Collection - Limitations on Use of Collected Attributes, v1.0

Credential Service Providers that process attributes for purposes other than the primary functions of an identity service (identity proofing, authentication, attribute assertions, fraud mitigation, or legal processes) shall implement additional measures appropriate for the additional risk these attributes present.

Assessment Step

1
CSP Attribute Collection Limitations (CSPAttributeCollectionLimitations)
If the CSP processes additional attributes not related to the core identity service functions, do they implement appropriate measures to mitigate any additional risk created from these attributes? (such as requesting consent or enabling selective disclosure)
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample consent statements, or sample disclosure control capabilities) that make it clear what compensating controls are employed by the CSP.

Conformance Criteria (1)

C1
If CSPs process attributes for purposes other than identity proofing, authentication, or attribute assertions (collectively "identity service"), related fraud mitigation, or to comply with law or legal process, CSPs SHALL implement measures to maintain predictability and manageability commensurate with the privacy risk arising from the additional processing. Measures MAY include providing clear notice, obtaining subscriber consent, or enabling selective use or disclosure of attributes. When CSPs use consent measures, CSPs SHALL NOT make consent for the additional processing a condition of the identity service.
Citation
NIST SP 800-63A
Section 4.2. (4)