Privacy - Types of Information Prohibited, v1.0

Defines privacy requirements for organizations to document what information it may NOT seek, retain, share, disclose, or disseminate.

Assessment Step

1
Privacy - Types Of Information Prohibited (Privacy-TypesOfInformationProhibited)
Has the organization documented what information may NOT be sought, retained, shared, or disclosed by the organization? This may include federal or state constitutional prohibitions or prohibitions in federal, state, local, or tribal laws.
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
Identify what information may not be sought, retained, shared, or disclosed by the center. This may include federal or state constitutional prohibitions or prohibitions in federal, state, local, or tribal laws.
Citation
FCPP
Section E.2, Information