// Level 3 · Controls

Privacy

Personal information is collected, used, retained, disclosed, and disposed of properly.

P1.1Medium

Provides notice about its privacy practices to data subjects.

Provides notice about its privacy practices to data subjects.

P2.1Medium

Communicates choices available regarding the collection, use, retention, disclos

Communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information.

P3.1Medium

Personal information is collected consistent with objectives related to privacy.

Personal information is collected consistent with objectives related to privacy.

P3.2Medium

Explicit consent for the collection, use, retention, disclosure, and disposal of

Explicit consent for the collection, use, retention, disclosure, and disposal of sensitive personal information is obtained.

P4.1Medium

Limits the use of personal information to the purposes identified in the notice

Limits the use of personal information to the purposes identified in the notice and consistent with consent.

P4.2Medium

Retains personal information consistent with objectives related to privacy.

Retains personal information consistent with objectives related to privacy.

P4.3Medium

Securely disposes of personal information to meet objectives related to privacy.

Securely disposes of personal information to meet objectives related to privacy.

P5.1Medium

Grants identified and authenticated data subjects access to their personal infor

Grants identified and authenticated data subjects access to their personal information.

P5.2Medium

Corrects, amends, or appends personal information based on authenticated data su

Corrects, amends, or appends personal information based on authenticated data subject requests.

P6.1Medium

Discloses personal information to third parties only with explicit consent and o

Discloses personal information to third parties only with explicit consent and only for the purpose for which consent was provided.

P7.1Medium

Collects and maintains accurate, up-to-date, complete, and relevant personal inf

Collects and maintains accurate, up-to-date, complete, and relevant personal information.

P8.1Medium

Implements a process for receiving, addressing, resolving, and communicating the

Implements a process for receiving, addressing, resolving, and communicating the resolution of inquiries, complaints, and disputes from data subjects.