Skip to content

Latest commit

 

History

History
9 lines (9 loc) · 990 Bytes

p32.md

File metadata and controls

9 lines (9 loc) · 990 Bytes

SOC2 - P3.2

For information requiring explicit consent, the entity communicates the need for such consent, as well as the consequences of a failure to provide consent for the request for personal information, and obtains the consent prior to the collection of the information to meet the entity’s objectives related to privacy

Obtains Explicit Consent for Sensitive Information

Explicit consent is obtained directly from the data subject when sensitive personal information is collected, used, or disclosed, unless a law or regulation specifically requires otherwise

Documents Explicit Consent to Retain Information

Documentation of explicit consent for the collection, use, or disclosure of sensitive personal information is retained in accordance with objectives related to privacy.

Mapped SCF controls