Privacy - Onward Transfer - Prohibited Disclosure, v1.0

Defines privacy requirements for organizations to document the circumstances under which it will NOT disclose records and information.

Assessment Step

1
Privacy - Onward Transfer - Prohibited Disclosure (Privacy-OnwardTransfer-ProhibitedDisclosure)
Has the organization documented the circumstances under which it will NOT disclose records and information? Examples: Sold, published, exchanged, or disclosed for commercial purposes. Disclosed or published without prior notice to the originating party that such information is subject to disclosure or publication, unless disclosure is agreed to as part of the normal operations of the party. Disseminated to persons not authorized to access or use the information.
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
Under what circumstances and to whom will the center not disclose records and information? Examples: Sold, published, exchanged, or disclosed for commercial purposes. Disclosed or published without prior notice to the originating agency that such information is subject to disclosure or publication, unless disclosure is agreed to as part of the normal operations of the agency. Disseminated to persons not authorized to access or use the information.
Citation
FCPP
Section J.8, Sharing and Disclosure