Openness and Transparency - Explicit on Type of Use, v1.0

Defines privacy requirements for organizations to explicitly state the default usage of sensitive information.

Assessment Step

1
Openness And Transparency - Explicit On Type Of Use (OpennessAndTransparency-ExplicitOnTypeOfUse)
Is the organization explicit about the default usage of sensitive information: whether it will only be used by explicit request (opt-in), or if it will be used until a request is made to discontinue that use (opt-out)?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
Be explicit about the default usage of personal information: whether it will only be used by explicit request (opt-in), or if it will be used until a request is made to discontinue that use (opt-out)
Citation
ACM
Openness