Skip to main content

Repository → 💼 SOC 2

💼 P6.0 Privacy Criteria Related to Disclosure and Notification

  • ID: /frameworks/soc-2/p6

Description

Empty...

Similar

  • Internal
    • ID: dec-b-74bdced7

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 P6.1 The entity discloses personal information to third parties with the explicit consent of data subjects and such consent is obtained prior to disclosure to meet the entity's objectives related to privacy.4no data
 💼 P6.1-1 Communicates Privacy Policies to Third Partiesno data
 💼 P6.1-2 Discloses Personal Information Only When Appropriateno data
 💼 P6.1-3 Discloses Personal Information Only to Appropriate Third Partiesno data
 💼 P6.1-4 Discloses Information to Third Parties for New Purposes and Usesno data
💼 P6.2 The entity creates and retains a complete, accurate, and timely record of authorized disclosures of personal information to meet the entity's objectives related to privacy.1no data
 💼 P6.2-1 Creates and Retains Record of Authorized Disclosuresno data
💼 P6.3 The entity creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures (including breaches) of personal information to meet the entity's objectives related to privacy.1no data
 💼 P6.3-1 Creates and Retains Record of Detected or Reported Unauthorized Disclosuresno data
💼 P6.4 The entity obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity's objectives related to privacy.3no data
 💼 P6.4-1 Evaluates Third-Party Compliance With Privacy Commitmentsno data
 💼 P6.4-2 Remediates Misuse of Personal Information by a Third Partyno data
 💼 P6.4-3 Obtains Commitments to Report Unauthorized Disclosuresno data
💼 P6.5 The entity obtains commitments from vendors and other third parties with access to personal information to notify the entity in the event of actual or suspected unauthorized disclosures of personal information.2no data
 💼 P6.5-1 Remediates Misuse of Personal Information by a Third Partyno data
 💼 P6.5-2 Reports Actual or Suspected Unauthorized Disclosuresno data
💼 P6.6 The entity provides notification of breaches and incidents to affected data subjects, regulators, and others to meet the entity's objectives related to privacy.2no data
 💼 P6.6-1 Identifies Reporting Requirementsno data
 💼 P6.6-2 Provides Notice of Breaches and Incidentsno data
💼 P6.7 The entity provides data subjects with an accounting of the personal information held and disclosure of the data subjects' personal information, upon the data subjects' request, to meet the entity's objectives related to privacy.3no data
 💼 P6.7-1 Responds to Data Controller Requestsno data
 💼 P6.7-2 Identifies Types of Personal Information and Handling Processno data
 💼 P6.7-3 Captures, Identifies, and Communicates Requests for Informationno data