graphgrc

SCF - PRI-04.1 - Authority To Collect, Use, Maintain & Share Personal Data

Mechanisms exist to determine and document the legal authority that permits the collection, use, maintenance and sharing of Personal Data (PD), either generally or in support of a specific program or system need.

Mapped framework controls

GDPR

SOC 2

Control questions

Does the organization determine and document the legal authority that permits the collection, use, maintenance and sharing of Personal Data (PD), either generally or in support of a specific program or system need?