Privacy - Redress - Non-Disclosure - Notification To Originating Agency, v1.0

Defines privacy requirements for organizations to notify third parties that are the source of information requested when information requests are denied and their determination that disclosure by the organization or referral of the requestor to the source party was neither required nor appropriate under applicable law.

Assessment Step

1
Privacy - Redress - Non-Disclosure - Notification To Originating Agency (Privacy-Redress-Non-Disclosure-NotificationToOriginatingAgency)
Does the organization notify third parties that are the source of information requested when information requests are denied and its determination that disclosure by the organization or referral of the requestor to the source party was neither required nor appropriate under applicable law?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
Does the center notify source agencies of denied information requests and its determination that disclosure by the center or referral of the requestor to the source agency was neither required nor appropriate under applicable law?
Citation
FCPP
Section K.1.2, Redress - Disclosure