[Prev]

2.3 Compliance Requirements for Governing Agreements

CR30-GA

Governing Agreement should at least address

  1. Governance structure, such as advisory and audit boards

  2. Criteria to join and stay on the network, including certification and audits (Req. D1.2-6.14-Compat)

  3. Process for removal from the network

  4. Process for complaints, arbitration, and disciplinary action (Req. D1.2-6.9-Complaint)

  5. Commercial liability and its fair appropriation

  6. Liability due to negligence in criminal cases and its fair appropriation

  7. Privacy protection

  8. Redress for users that have suffered unwarranted disclosure (Req. D1.2-6.10-Redress)

  9. Minimal mandatory security practises and policies (Reqs. D1.2-6.11-Confid and D1.2-6.15-MinPolicy)

  10. Acceptable use for Service Providers

  11. Acceptable use for Users

  12. Requirement to be legally bound (Reqs. D1.2-6.16-Bound and D1.2-6.17-TechBind)

CR31-CheckList

Any prospective Trust Network member should document the answer to the following questions:

  1. Are you collecting or using PII as part of the service?

  2. Do you have a Privacy Policy that you are bound to follow?

  3. Do you use PII for any purpose other than providing the service?

  4. Do you get User's consent or let him opt out before his information is used for other purposes than providing the specific service?

  5. Do you share PII beyond your company or family of companies?

  6. Do you get user's consent or let him opt out before your share his information with any other company not needed to provide the specific service?

  7. Do you allow user to manage these preferences over time and change my options?


[Prev | Next]