Under active development Content is continuously updated and improved

TPM-11Personal Information Processing and Transfer Agreement

>Control Description

Appropriate data processing and transfer agreements are established for the collection, processing, transfer, or storage of personal information by, or on behalf of, Organization.

Theme

Process

Type

Preventive

Policy/Standard

Vendor Information Security Policy

>Implementation Guidance

1. Ensure that a process is defined and documented for establishing data processing and transfer agreements for the collection, processing, transfer, or storage of personal information by, or on behalf of, the Organization. 2. Ensure these agreements are signed and retained appropriately as per organization's policy.

>Testing Procedure

1. Inspect and validate that a process is defined and documented for establishing data processing and transfer agreements for the collection, processing, transfer, or storage of personal information by, or on behalf of, the Organization. 2. Validate for a sample agreement that it is signed and retained appropriately as per organization's policy.

>Audit Artifacts

E-TPM-17

>Framework Mappings

Cross-framework mappings provided by Adobe CCF Open Source under Creative Commons License.

Ask AI

Configure your API key to use AI features.