IDEF User Notice of Changes, v1.0

Specifies requirements in accordance with Identity Ecosystem Framework (IDEF) requirement PRIVACY-9: USER NOTICE OF CHANGES.

Assessment Step

1
User Notice of Changes (UserNoticeofChanges)
Does the entity (a) notify users upon any material changes to a service or process that affects the prior or ongoing collection, generation, use, transmission, or storage of users' personal information, and (b) provide them with compensating controls designed to mitigate privacy risks that may arise from those changes, which may include seeking express affirmative consent of users in accordance with relevant law or regulation?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

User Notice of Changes
Entities MUST, upon any material changes to a service or process that affects the prior or ongoing collection, generation, use, transmission, or storage of users' personal information, notify those users, and provide them with compensating controls designed to mitigate privacy risks that may arise from those changes, which may include seeking express affirmative consent of users in accordance with relevant law or regulation.
Citation
IDEF
Page 17