Onward Transfer - Agents, v1.0

Defines privacy requirements related to organizations ensuring third parties subscribe to the Safe Harbor Privacy Principles.

Assessment Step

1
Onward Transfer - Agents (OnwardTransfer-Agents)
When disclosing sensitive information to a third party, does the organization make sure that the third party subscribes to the Safe Harbor Privacy Principles or is subject to the Directive or another adequacy finding?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
To disclose personal information to a third party, organizations must make sure that the third party subscribes to the Safe Harbor Privacy Principles or is subject to the Directive or another adequacy finding.
Citation
SAFE-HARBOR
Onward Transfer (Transfers to Third Parties)