Privacy - Onward Transfer - Ordinarily Not Provided Per Legal Authority, v1.0

Defines privacy requirements for organizations to document the categories of records that will ordinarily NOT be provided to the public pursuant to applicable legal authority.

Assessment Step

1
Privacy - Onward Transfer - Ordinarily Not Provided Per Legal Authority (Privacy-OnwardTransfer-OrdinarilyNotProvidedPerLegalAuthority)
Has the organization documented the categories of records that will ordinarily NOT be provided to the public pursuant to applicable legal authority? Examples: Records required to be kept confidential by law are exempted from disclosure requirements under [cite public records act and applicable section]. Information that meets the definition of "classified information" as that term is defined in the National Security Act, Public Law 235, Section 606. Investigatory records of law enforcement agencies that are exempted from disclosure requirements under [cite public records act and applicable section]. However, certain law enforcement records must be made available for inspection and copying under [cite public records act and applicable section]. A record or part of a record the public disclosure of which would have a reasonable likelihood of threatening public safety by exposing a vulnerability to terrorist attack is exempted from disclosure requirements under [cite public records act and applicable section]. This includes a record assembled, prepared, or maintained to prevent, mitigate, or respond to an act of terrorism under [cite public records act and applicable section] or an act of agricultural terrorism under [cite public records act and applicable section], vulnerability assessments, risk planning documents, needs assessments, and threat assessments. Protected federal, state, local, or tribal records, which may include records originated and controlled by another party that cannot, under [cite applicable law], be shared without permission. A violation of an authorized nondisclosure agreement under [cite applicable law]
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
What are the categories of records that will ordinarily not be provided to the public pursuant to applicable legal authority? Examples: Records required to be kept confidential by law are exempted from disclosure requirements under [cite public records act and applicable section]. Information that meets the definition of "classified information" as that term is defined in the National Security Act, Public Law 235, Section 606. Investigatory records of law enforcement agencies that are exempted from disclosure requirements under [cite public records act and applicable section]. However, certain law enforcement records must be made available for inspection and copying under [cite public records act and applicable section]. A record or part of a record the public disclosure of which would have a reasonable likelihood of threatening public safety by exposing a vulnerability to terrorist attack is exempted from disclosure requirements under [cite public records act and applicable section]. This includes a record assembled, prepared, or maintained to prevent, mitigate, or respond to an act of terrorism under [cite public records act and applicable section] or an act of agricultural terrorism under [cite public records act and applicable section], vulnerability assessments, risk planning documents, needs assessments, and threat assessments. Protected federal, state, local, or tribal records, which may include records originated and controlled by another agency that cannot, under [cite applicable law], be shared without permission. A violation of an authorized nondisclosure agreement under [cite applicable law].
Citation
FCPP
Section J.9, Sharing and Disclosure