Privacy - CSP Limited Use of Subscriber Information, v1.0

Credential Service Providers must properly limit the use of subscriber information to protect the subscribers privacy.

Assessment Step

1
Limited Use Privacy (LimitedUsePrivacy)
Does the CSP protect information about subscribers from any use other than critical functions (authentication, fraud mitigation, legal requirements) unless it provides clear notice and obtains consent from the subscriber?
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample processes) that the CSP refrains from using subscriber information in ways other than prescribed.

Conformance Criteria (1)

C1
CSPs SHALL NOT use or disclose information about subscribers for any purpose other than conducting authentication, related fraud mitigation, or to comply with law or legal process, unless the CSP provides clear notice and obtains consent from the subscriber for additional uses. CSPs SHALL NOT make consent a condition of the service. Care SHALL be taken to ensure that use of such information is limited to its original purpose for collection. If the use of such information does not fall within uses related to authentication or to comply with law or legal process, the CSP SHALL provide notice and obtain consent from the subscriber.
Citation
NIST SP 800-63B
Section 4.4