[Prev]

2.2.1 Legal and Contractual Compliance Requirements

CR21-Lawful

All legal requirements MUST be satisfied. Members MUST operate within the law.

CR22-Arch

All normative requirements of [TAS3ARCH] MUST be satisfied.

CR23-Proto

All normative requirements of [TAS3PROTO] MUST be satisfied.

CR24-File

Each member MUST be registered on the file at the Trust Guarantor. The filing MUST include details appropriate for the jurisdiction to identify the entity to the extent needed to raise a law suit and/or coordinate investigation with the tax authorities. Typically this means at least

  1. Entity name

  2. Address

  3. Company registration or VAT number

  4. Version of Governance Agreement signed and date signed (Req. D1.2-6.13-Contract)

Whenever this information changes, the member MUST prompty inform the Trust Guarantor.

CR25-Policy

Each member MUST conspiciously publish a Privacy Policy and Terms of Use for their services on the internet. Member must make available a registry description and offer consultation, rectification, and/or removal of PII.

The Policy and the Terms MUST address at least

  1. Entity name and contact for inquiries

  2. Data retention policy

  3. How is User identified (database keys, properties, such as pseudonymity, of identifier, etc.)

  4. With whom data is exchanged and why

  5. Whether the policy may change and how existing customers are handled upon the change.

A member MUST adhere to its own Policy and Terms.


[Prev | Next]