Onward Transfer - Ensure Protection - Generic, v1.0

Defines privacy requirements for the sensitive information controller to exercise due diligence when transferring sensitive information to ensure it will be protected in accordance with their privacy policy.

Assessment Step

1
Onward Transfer - Ensure Protection - Generic (OnwardTransfer-EnsureProtection-Generic)
Does the organization require that when sensitive information is to be transferred to another person or organization, whether domestically or internationally, the sensitive information controller should exercise due diligence and take reasonable steps to ensure that the recipient person or organization will protect the information consistently with the sensitive information controller's privacy policy?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
When personal information is to be transferred to another person or organization, whether domestically or internationally, the personal information controller should exercise due diligence and take reasonable steps to ensure that the recipient person or organization will protect the information consistently with the personal information controller's privacy policy.
Citation
APEC
Section 26, Accountability