IDEF Purpose Limitation, v1.0

Specifies requirements in accordance with Identity Ecosystem Framework (IDEF) requirement PRIVACY-2: PURPOSE LIMITATION.

Assessment Steps (2)

1
Purpose Limited to Transaction (PurposeLimitedtoTransaction)
Does the entity limit the use of personal information that is collected, used, transmitted, or stored to the specified purposes of that transaction?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
2
Persistent Records of Policies and Agreements for Personal Information (PersistentRecordsofPoliciesandAgreementsforPersonalInformation)
Has the entity established persistent records of contracts, assurances, consent, or legal authority about collecting, generating, using, transmitting, or storing personal information, so that the information, consistently is used in the same manner originally specified and permitted?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Purpose Limitation
Entities MUST limit the use of personal information that is collected, used, transmitted, or stored to the specified purposes of that transaction. Persistent records of contracts, assurances, consent, or legal authority MUST be established by entities collecting, generating, using, transmitting, or storing personal information, so that the information, consistently is used in the same manner originally specified and permitted.
Citation
IDEF
Page 10