Criterion: Privacy
Requirements for protecting personal information and privacy
Full Description
D6. Privacy
Code 7.0
Participants are to commit to protecting the reasonable privacy expectations of personal information of everyone they do business with, including suppliers, customers, consumers and employees. Participants are to comply with privacy and information security laws and regulatory requirements when personal information is collected, stored, processed, transmitted, and shared.
Elements to Demonstrate Compliance to RBA Code
1. Policy
Ensure facility ethics and/or privacy policy and procedures ensuring protection of personal information are in place, including the following elements:
- a. Safeguards are in place to prevent unauthorized disclosure of personal information.
- b. Monitoring procedures related to protection of personal information are in place.
2. Procedures & Practices
Procedures & Practices are in place such that:
- a. Personal information is visibly protected.
3. Rating
- Major: No detailed and understandable policy and procedures implemented.
- Minor: Partial policy or procedures or implementation.
Profiles using this criterion
RBA Assessment Program
- VAP Full Assessment | 7.0.0
Conformity Alignment
Priority
Pass: No
Definition: "Critical non-conformance requiring immediate action"
Remediation: 30 days
Major
Pass: No
Definition: "Significant non-conformance requiring corrective action"
Remediation: 90 days
Minor
Pass: Yes
Definition: "Non-conformance with limited impact"
Conditions: Corrective action plan required
Remediation: 180 days
Opportunity
Pass: Yes
Definition: "Opportunity for improvement identified"
Conformance
Pass: Yes
Definition: "Full conformance with criterion requirements"
Related Criterion
VAP: Intellectual Property
Relationship: Related
Protection of confidential information
VAP: Protection of Identity and Non-Retaliation
Relationship: Related
Protection of personal identity
VAP: Ethics Management System
Relationship: Parent
Management system for ethics practices
Change Log
1.0.0 (2021-01-01)
Changed
- Initial historical baseline — Privacy (RBA Code of Conduct 7.0, provision D8): Earliest imported version of the criterion (numbered D8 in VAP 7.0.0). Participants to protect the reasonable privacy expectations of personal information of everyone they do business with and to comply with privacy and information security laws when personal information is collected, stored, processed, transmitted, and shared. Rated purely on documentary policy/procedure completeness: adequate policy and procedures including safeguards to prevent unauthorized disclosure and monitoring procedures. Priority = Not Applicable; Major = no detailed and understandable policy and procedures implemented; Minor = partial policy or procedures or implementation. No individual-consent requirement.