Privacy - Information Collection - Prohibited Sources, v1.0

Defines privacy requirements for organizations to document the types of information sources from which the organization will NOT receive, seek, accept, or retain information.

Assessment Step

1
Privacy - Information Collection - Prohibited Sources (Privacy-InformationCollection-ProhibitedSources)
Has the organization documented the types of information sources (nongovernmental, commercial, or private entities or institutions or classes of individuals) from which the organization will NOT receive, seek, accept, or retain information?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
What are the types of information sources (nongovernmental, commercial, or private entities or institutions or classes of individuals) from which the center will not receive, seek, accept, or retain information?
Citation
FCPP
Section F.7, Acquiring and Receiving Information