SCF - PRI-03 - Choice & Consent
Mechanisms exist to authorize the processing of their Personal Data (PD) prior to its collection that:
- Uses plain language and provide examples to illustrate the potential data privacy risks of the authorization; and
- Provides a means for users to decline the authorization.
Mapped framework controls
GDPR
ISO 27002
SOC 2
Control questions
Does the organization authorize the processing of their Personal Data (PD) prior to its collection that:
- Uses plain language and provide examples to illustrate the potential data privacy risks of the authorization; and
- Provides a means for users to decline the authorization?