Privacy - Minimization - Retention and Destruction Policy, v1.0

Defines privacy requirements for organizations to document their retention and destruction policies.

Assessment Step

1
Privacy - Minimization - Retention And Destruction Policy (Privacy-Minimization-RetentionAndDestructionPolicy)
Does the organization have a documented retention and destruction policy? Reference laws, if applicable.
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
Does your center have a retention and destruction policy? Reference laws, if applicable.
Citation
FCPP
Section M.2, Information Retention and Destruction