<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=Privacy_Req_9</id>
	<title>Privacy Req 9 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=Privacy_Req_9"/>
	<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=Privacy_Req_9&amp;action=history"/>
	<updated>2026-05-06T10:00:04Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.38.4</generator>
	<entry>
		<id>https://wiki.idesg.org/index.php?title=Privacy_Req_9&amp;diff=5915&amp;oldid=prev</id>
		<title>Omaerz: 9 revisions imported: Initial Upload of old pages from IDESG Wiki</title>
		<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=Privacy_Req_9&amp;diff=5915&amp;oldid=prev"/>
		<updated>2018-06-28T04:03:05Z</updated>

		<summary type="html">&lt;p&gt;9 revisions imported: Initial Upload of old pages from IDESG Wiki&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 04:03, 28 June 2018&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-notice&quot; lang=&quot;en&quot;&gt;&lt;div class=&quot;mw-diff-empty&quot;&gt;(No difference)&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>Omaerz</name></author>
	</entry>
	<entry>
		<id>https://wiki.idesg.org/index.php?title=Privacy_Req_9&amp;diff=5914&amp;oldid=prev</id>
		<title>Mary Hodder: updated SG for phase II</title>
		<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=Privacy_Req_9&amp;diff=5914&amp;oldid=prev"/>
		<updated>2018-06-13T20:44:57Z</updated>

		<summary type="html">&lt;p&gt;updated SG for phase II&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;lt;&amp;lt; Back to [[Baseline_Functional_Requirements_v1.0|Baseline Functional Requirements Index]]&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
== PRIVACY-9.    USER NOTICE OF CHANGES ==&lt;br /&gt;
Entities MUST, upon any material changes to a service or process that affects the prior or ongoing collection, generation, use, transmission, or storage of [[IDEF Glossary USERS|USERS]]’ &lt;br /&gt;
[[IDEF Glossary PERSONAL INFORMATION|personal information]], notify those USERS, and provide them with compensating controls designed to mitigate privacy risks that may arise from those changes, which may include seeking express affirmative consent of USERS in accordance with relevant law or regulation.&lt;br /&gt;
&lt;br /&gt;
=== SUPPLEMENTAL GUIDANCE ===&lt;br /&gt;
Once USERS have been notified of the planned uses and processing of their personal information&lt;br /&gt;
(see [[Privacy Req 6|PRIVACY 6 (USAGE NOTICE)]]), and exercised whatever consent, limitation or withdrawal rights they&lt;br /&gt;
have (see [[Privacy Req 7|PRIVACY-7 (USER DATA CONTROL)]]), material changes to those uses or processing may render&lt;br /&gt;
their choices obsolete, so entities should refresh the USER&amp;#039;s opportunity to exercise those controls in&lt;br /&gt;
light of the new information. (See [[Usable Req 4|USABLE-4 (NAVIGATION)]], [[Usable Req 5|USABLE-5 (ACCESSIBILITY)]] and [[Usable Req 6|USABLE-6&lt;br /&gt;
(USABILITY FEEDBACK)]].)&lt;br /&gt;
&lt;br /&gt;
Regarding &amp;quot;personal information&amp;quot;, see [[APPENDIX_A-Defined_Terms|Appendix A]], and [[Privacy Req 1|PRIVACY-1 (DATA MINIMIZATION)]].&lt;br /&gt;
&lt;br /&gt;
“Express affirmative consent” should not be used to mitigate privacy risks created by technical&lt;br /&gt;
architecture or design, or to mitigate risks that individuals could not be reasonably expected to be able&lt;br /&gt;
to assess; see [[Privacy Req 5|PRIVACY-5 (DATA AGGREGATION RISK)]].&lt;br /&gt;
&lt;br /&gt;
“Compensating controls” are controls or mechanisms, which may operate either by policy or&lt;br /&gt;
(preferably) technology, designed to mitigate privacy risks that may arise when a material change is&lt;br /&gt;
made to the system. Examples might include an opportunity to assent or withdraw, or risk-shifting&lt;br /&gt;
rules occurring upon a change. Those controls can be under user administration, but only if the user&lt;br /&gt;
can be reasonably expected to understand how to use those mechanisms to effectively mitigate their&lt;br /&gt;
risk.&lt;br /&gt;
&lt;br /&gt;
The Kantara Consent Receipt is now available (January 2018) in draft form at https://groups.google.com/forum/#!topic/wg-infosharing/553qIdgaq0o&lt;br /&gt;
&lt;br /&gt;
=== REFERENCES ===&lt;br /&gt;
Further reference materials to aid organizations interested in conforming to these Requirements can be found at the wiki page [[Supplemental Privacy Guidance]]; this has been archived at https://workspace.idesg.org/kws/public/download.php/56/Supplemental-Privacy-Guidance.docx&lt;br /&gt;
&lt;br /&gt;
=== APPLIES TO ACTIVITIES ===&lt;br /&gt;
[[IDEF Functional Model REGISTRATION|REGISTRATION]], [[IDEF Functional Model CREDENTIALING|CREDENTIALING]], [[IDEF Functional Model AUTHENTICATION|AUTHENTICATION]], [[IDEF Functional Model AUTHORIZATION|AUTHORIZATION]], [[IDEF Functional Model INTERMEDIATION|INTERMEDIATION]]&lt;br /&gt;
&lt;br /&gt;
=== KEYWORDS ===&lt;br /&gt;
[[IDEF Keywords CHANGES|CHANGES]], [[IDEF Keywords CONSENT|CONSENT]], [[IDEF Keywords NOTICE|NOTICE]], [[IDEF Keywords PRIVACY|PRIVACY]], [[IDEF Keywords PURPOSE|PURPOSE]]&lt;br /&gt;
&lt;br /&gt;
=== APPLIES TO ROLES ===&lt;br /&gt;
1 - [[IDEF Glossary RELYING PARTIES|RELYING PARTIES]] &amp;lt;br&amp;gt;&lt;br /&gt;
2 - [[IDEF Glossary IDENTITY PROVIDERS|IDENTITY PROVIDERS]] &amp;lt;br&amp;gt;&lt;br /&gt;
3 - Attribute Providers &amp;lt;br&amp;gt;&lt;br /&gt;
4 – Intermediaries &amp;lt;br&amp;gt;&lt;br /&gt;
5 - Credential Service Providers (where there is user interaction) &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
----&lt;br /&gt;
Quick Links:   [[SALS]]  |  [[Baseline Functional Requirements v1.0]]  |  [[Glossary]]  |&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Mary Hodder</name></author>
	</entry>
</feed>