Privacy - Redress - Non-Disclosure Conditions Documented in Privacy Policy, v1.0

Defines privacy requirements for organizations to document the conditions under which it will NOT disclose information to an individual about whom information has been gathered.

Assessment Step

1
Privacy - Redress - Non-Disclosure Conditions Documented In Privacy Policy (Privacy-Redress-Non-DisclosureConditionsDocumentedInPrivacyPolicy)
Has the organization documented the conditions under which it will NOT disclose information to an individual about whom information has been gathered? Examples: Disclosure would interfere with, compromise, or delay an ongoing investigation or prosecution. Disclosure would endanger the health or safety of an individual, organization, or community. The information is in a criminal intelligence information system subject to 28 CFR Part 23 [see 28 CFR § 23.0(e)]. The information relates to [title, regulation, or code, etc. The information source does not reside with the organization. The organization did not originate and does not have a right to disclose the information. Other authorized basis for denial.
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
What are the conditions under which the center will not disclose information to an individual about whom information has been gathered? Examples: Disclosure would interfere with, compromise, or delay an ongoing investigation or prosecution. Disclosure would endanger the health or safety of an individual, organization, or community. The information is in a criminal intelligence information system subject to 28 CFR Part 23 [see 28 CFR § 23.20(e)]. The information relates to [title, regulation, or code, etc.]. The information source does not reside with the center. The center did not originate and does not have a right to disclose the information. Other authorized basis for denial.
Citation
FCPP
Section K.1.2, Redress - Disclosure