Minimization - Required vs Desired Information, v1.0

Defines privacy requirements for documentation to distinguish between information needed to conduct authentication and any other information requested by a relying party.

Assessment Step

1
Minimization - Required Vs Desired Information (Minimization-RequiredVsDesiredInformation)
Does the organization require that written documentation distinguishes between information that a relying party needs to conduct the authentication transaction and any other information that the relying party would like to collect (e.g. increase efficiency or convenience in providing the service requested by the user)?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.

Conformance Criteria (1)

C-1
Written documentation distinguishes between information that a relying party needs to conduct the authentication transaction and any other information that the relying party would like to collect (e.g. to increase efficiency or convenience in providing the service requested by the user).
Citation
FICAM-TFPAP
Section 3.2.3