Redress - Exceptions for Burdens, v1.0

Defines privacy requirements related to exceptions to organizations providing individuals with the ability to correct, amend, or delete sensitive information about themselves due to the burdens or expense required.

Assessment Step

1
Redress - Exceptions For Burdens (Redress-ExceptionsForBurdens)
Can the organization deny individuals' ability to correct, amend, or delete sensitive information about themselves that the organization holds where the burden or expense of providing access would be disproportionate to the risks to the individual's privacy in the case in question?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
Individuals' ability to correct, amend, or delete personal information about themselves that an organization holds may be denied where the burden or expense of providing access would be disproportionate to the risks to the individual's privacy in the case in question.
Citation
SAFE-HARBOR
Access