Privacy - Handling of Tips and Leads, or Suspicious Activity Reports, v1.0

Defines privacy requirements for organizations that receive or collect tips and leads and/or suspicious activity report (SAR) information to maintain and adhere to policies and procedures for information collection and handling.

Assessment Step

1
Privacy - Handling Of Tips And Leads, Or Suspicious Activity Reports (Privacy-HandlingOfTipsAndLeadsOrSuspiciousActivityReports)
If the organization receives or collects tips and leads and/or suspicious activity report (SAR) information (information received or collected based on a level of suspicion that may be less than "reasonable suspicion"), Does the organization maintain and adhere to policies and procedures for: Receipt and collection (information acquisition)-How the information is originally gathered, collected, observed, or submitted. Assessment of credibility and value (organizational processing)-The series of manual and automated steps and decision points followed by the organization to evaluate the SAR information. Storage (integration and consolidation)- The point at which SAR information is placed into a SAR database, using a standard submission format, for purposes of permitting access by authorized personnel and agencies. Access and dissemination (data retrieval and dissemination)-The process of making the information available to other agencies and obtaining feedback on investigative outcomes. Retention and security of the information? Note: Some organizations, based on state law or policy, use the "reasonable suspicion" standard as the threshold for sharing any information and intelligence containing sensitive information. If that is the case, the policy should so indicate.
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameters
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
If your center receives or collects tips and leads and/or suspicious activity report (SAR) information (information received or collected based on a level of suspicion that may be less than "reasonable suspicion"), does your center maintain and adhere to policies and procedures for: Receipt and collection (information acquisition)-How the information is originally gathered, collected, observed, or submitted? Assessment of credibility and value (organizational processing)-The series of manual and automated steps and decision points followed by the center to evaluate the SAR information? Storage (integration and consolidation)- The point at which SAR information is placed into a SAR database, using a standard submission format, for purposes of permitting access by authorized personnel and agencies? Access and dissemination (data retrieval and dissemination)-The process of making the information available to other agencies and obtaining feedback on investigative outcomes? Retention and security of the information? Note: Some centers, based on state law or policy, use the "reasonable suspicion" standard as the threshold for sharing any information and intelligence containing personal information. If that is the case, the policy should so indicate.
Citation
FCPP
Section E.7, Information