graphgrc

SCF - PRI-04 - Restrict Collection To Identified Purpose

Mechanisms exist to collect Personal Data (PD) only for the purposes identified in the data privacy notice and includes protections against collecting PD from minors without appropriate parental, or legal guardian, consent.

Mapped framework controls

GDPR

ISO 27002

SOC 2

Control questions

Does the organization collect Personal Data (PD) only for the purposes identified in the data privacy notice and includes protections against collecting PD from minors without appropriate parental, or legal guardian, consent?