<?xml version="1.0" encoding="UTF-8"?><!--Serialized by the GTRI Trustmark Framework API, version: 1.4.74--><tf:TrustInteroperabilityProfile xmlns:tf="https://trustmarkinitiative.org/specifications/trustmark-framework/1.4/schema/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tips/nist-sp-800-53-r4-privacy-control-ip-1_-consent/4/</tf:Identifier><tf:Name>NIST SP 800-53 r4 Privacy Control IP-1: Consent</tf:Name><tf:Version>4</tf:Version><tf:Description>Profile of requirements corresponding to NIST Special Publication 800-53 r4, Privacy Control IP-1: Consent.</tf:Description><tf:PublicationDateTime>2021-04-26T00:00:00.000Z</tf:PublicationDateTime><tf:Primary>false</tf:Primary><tf:LegalNotice>This document and the information contained herein is provided on an "AS IS" basis, and the Georgia Tech Research Institute disclaims all warranties, express or implied, including but not limited to any warranty that the use of the information herein will not infringe any rights or any implied warranties or merchantability or fitness for a particular purpose. In addition, the Georgia Tech Research Institute disclaims legal liability for any loss incurred as a result of the use or reliance on the document or the information contained herein.</tf:LegalNotice><tf:Issuer><tf:Identifier>https://trustmarkinitiative.org/</tf:Identifier><tf:Name>TMI</tf:Name><tf:Contact><tf:Kind>PRIMARY</tf:Kind><tf:Responder></tf:Responder><tf:Email>help@trustmarkinitiative.org</tf:Email><tf:Telephone>555-555-5555</tf:Telephone><tf:WebsiteURL>https://trustmarkinitiative.org/</tf:WebsiteURL></tf:Contact></tf:Issuer><tf:Keywords><tf:Keyword>800-53</tf:Keyword><tf:Keyword>Consent</tf:Keyword><tf:Keyword>Individual Participation</tf:Keyword><tf:Keyword>NIST</tf:Keyword><tf:Keyword>Privacy</tf:Keyword><tf:Keyword>Redress</tf:Keyword></tf:Keywords><tf:References><tf:TrustmarkDefinitionRequirement tf:id="TD_ref1"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent-for-new-uses-of-pii-not-in-the-public-notice-at-the-time-of-collection-_where-feasible_/1.0/</tf:Identifier><tf:Number>1</tf:Number><tf:Name>Privacy - Consent for New Uses of PII Not in the Public Notice at the Time of Collection (Where Feasible)</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization ensures that, where feasible, individuals consent to all uses of PII not initially described in the public notice that was in effect at the time the organization collected the PII.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref2"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent-for-collection-_where-feasible_/1.0/</tf:Identifier><tf:Number>2</tf:Number><tf:Name>Privacy - Consent for Collection (Where Feasible)</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization provides means, where feasible and appropriate, for individuals to authorize the collection of personally identifiable information (PII) prior to its collection.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref3"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent-prior-to-new-disclosure/1.0/</tf:Identifier><tf:Number>3</tf:Number><tf:Name>Privacy - Consent Prior to New Disclosure</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization obtains consent from individuals prior to any new disclosure of previously collected PII.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref4"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent-prior-to-new-use/1.0/</tf:Identifier><tf:Number>4</tf:Number><tf:Name>Privacy - Consent Prior to New Use</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization obtains consent from individuals prior to any new uses of previously collected PII.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref5"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent-prior-to-new-disclosure-_where-feasible_/1.0/</tf:Identifier><tf:Number>5</tf:Number><tf:Name>Privacy - Consent Prior to New Disclosure (Where Feasible)</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization obtains consent, where feasible and appropriate, from individuals prior to any new disclosure of previously collected PII.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref6"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent-for-sharing/1.0/</tf:Identifier><tf:Number>6</tf:Number><tf:Name>Privacy - Consent for Sharing</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization provides means for individuals to authorize the sharing of personally identifiable information (PII) prior to its collection.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref7"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent---individuals-can-approve-or-decline-retention-of-pii/1.0/</tf:Identifier><tf:Number>7</tf:Number><tf:Name>Privacy - Consent - Individuals Can Approve or Decline Retention of PII</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization provides appropriate means for individuals to understand the consequences of decisions to approve or decline the authorization of the retention of PII.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref8"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent-for-use-_where-feasible_/1.0/</tf:Identifier><tf:Number>8</tf:Number><tf:Name>Privacy - Consent for Use (Where Feasible)</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization provides means, where feasible and appropriate, for individuals to authorize the use of personally identifiable information (PII) prior to its collection.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref9"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent-for-use/1.0/</tf:Identifier><tf:Number>9</tf:Number><tf:Name>Privacy - Consent for Use</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization provides means for individuals to authorize the use of personally identifiable information (PII) prior to its collection.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref10"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent-for-maintenance/1.0/</tf:Identifier><tf:Number>10</tf:Number><tf:Name>Privacy - Consent for Maintenance</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization provides means for individuals to authorize the maintaining of personally identifiable information (PII) prior to its collection.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref11"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent-for-maintenance-_where-feasible_/1.0/</tf:Identifier><tf:Number>11</tf:Number><tf:Name>Privacy - Consent for Maintenance (Where Feasible)</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization provides means, where feasible and appropriate, for individuals to authorize the maintaining of personally identifiable information (PII) prior to its collection.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref12"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent-for-new-uses-of-pii-not-in-the-public-notice-at-the-time-of-collection/1.0/</tf:Identifier><tf:Number>12</tf:Number><tf:Name>Privacy - Consent for New Uses of PII Not in the Public Notice at the Time of Collection</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization ensures that individuals consent to all uses of PII not initially described in the public notice that was in effect at the time the organization collected the PII.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref13"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent-prior-to-new-use-_where-feasible_/1.0/</tf:Identifier><tf:Number>13</tf:Number><tf:Name>Privacy - Consent Prior to New Use (Where Feasible)</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization obtains consent, where feasible and appropriate, from individuals prior to any new uses of previously collected PII.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref14"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent---individuals-can-approve-or-decline-collection-of-pii/1.0/</tf:Identifier><tf:Number>14</tf:Number><tf:Name>Privacy - Consent - Individuals Can Approve or Decline Collection of PII</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization provides appropriate means for individuals to understand the consequences of decisions to approve or decline the authorization of the collection of PII.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref15"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---notice-of-new-uses-of-pii-not-in-the-public-notice-at-the-time-of-collection/1.0/</tf:Identifier><tf:Number>15</tf:Number><tf:Name>Privacy - Notice of New Uses of PII Not in the Public Notice at the Time of Collection</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization ensures that individuals are aware of all uses of PII not initially described in the public notice that was in effect at the time the organization collected the PII.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref16"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent---individuals-can-approve-or-decline-use-of-pii/1.0/</tf:Identifier><tf:Number>16</tf:Number><tf:Name>Privacy - Consent - Individuals Can Approve or Decline Use of PII</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization provides appropriate means for individuals to understand the consequences of decisions to approve or decline the authorization of the use of PII.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref17"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent-for-collection/1.0/</tf:Identifier><tf:Number>17</tf:Number><tf:Name>Privacy - Consent for Collection</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization provides means for individuals to authorize the collection of personally identifiable information (PII) prior to its collection.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref18"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/privacy---consent---individuals-can-approve-or-decline-dissemination-of-pii/1.0/</tf:Identifier><tf:Number>18</tf:Number><tf:Name>Privacy - Consent - Individuals Can Approve or Decline Dissemination of PII</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for verifying that an organization provides appropriate means for individuals to understand the consequences of decisions to approve or decline the authorization of the dissemination of PII.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement></tf:References><tf:TrustExpression><![CDATA[TD_ref1 and TD_ref2 and TD_ref3 and TD_ref4 and TD_ref5 and TD_ref6 and TD_ref7 and TD_ref8 and TD_ref9 and TD_ref10 and TD_ref11 and TD_ref12 and TD_ref13 and TD_ref14 and TD_ref15 and TD_ref16 and TD_ref17 and TD_ref18]]></tf:TrustExpression><tf:Sources><tf:Source tf:id="Source-2112165102"><tf:Identifier>SP800-53R4</tf:Identifier><tf:Reference>NIST Special Publication 800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, National Institute of Standards and Technology, April 2013 (Includes updates as of 01-15-2014). Available at &lt;a href="http://dx.doi.org/10.6028/NIST.SP.800-53r4"&gt;http://dx.doi.org/10.6028/NIST.SP.800-53r4&lt;/a&gt;.</tf:Reference></tf:Source></tf:Sources></tf:TrustInteroperabilityProfile>