unified
UC-DATA-16 — Bind third parties handling personal data to privacy commitments
Before granting vendors or other third parties access to personal information, obtain written privacy commitments covering permitted use, safeguards, and notification of actual or suspected unauthorized disclosures. Assess their compliance periodically and as needed, route their breach notifications into the incident-response process, and take corrective action or terminate access when commitments are not met.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Data Protection & Privacy
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-DATA-16
- title
- Bind third parties handling personal data to privacy commitments
- statement
- Before granting vendors or other third parties access to personal information, obtain written privacy commitments covering permitted use, safeguards, and notification of actual or suspected unauthorized disclosures. Assess their compliance periodically and as needed, route their breach notifications into the incident-response process, and take corrective action or terminate access when commitments are not met.
- domain
- Data Protection & Privacy
- control_type
- preventive
- control_category
- administrative
- members
- framework
- soc2
- control_id
- P6.4
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- P6.5
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-DATA-16 — Bind third parties handling personal data to privacy commitments mitigates Unauthorized disclosure / breach of sensitive information
- strength
- primary
- rationale
- Binding third parties to permitted-use, safeguard, and breach-notification commitments with periodic assessment directly reduces unauthorized disclosure via vendors.
- Vendor Due Diligence & Contracting Gate operates UC-DATA-16 — Bind third parties handling personal data to privacy commitments
- UC-DATA-16 — Bind third parties handling personal data to privacy commitments mitigates Privacy-program non-compliance (GDPR, CCPA, state laws)
- strength
- related
- rationale
- Written processor commitments and their enforcement support the organization's data-protection compliance obligations.
- Privacy Breach Assessment & Notification operates UC-DATA-16 — Bind third parties handling personal data to privacy commitments
- Third-Party Vendor Risk Lifecycle oversees UC-DATA-16 — Bind third parties handling personal data to privacy commitments
- UC-DATA-16 — Bind third parties handling personal data to privacy commitments maps_to P6.4 — The entity obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity's objectives related to privacy. The entity assesses those parties' compliance on a periodic and as-needed basis and takes corrective action, if necessary.
- framework
- soc2
- control_id
- P6.4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Privacy Criteria Assessment tests UC-DATA-16 — Bind third parties handling personal data to privacy commitments
- UC-DATA-16 — Bind third parties handling personal data to privacy commitments maps_to P6.5 — The entity obtains commitments from vendors and other third parties with access to personal information to notify the entity in the event of actual or suspected unauthorized disclosures of personal information. Such notifications are reported to appropriate personnel and acted on in accordance with established incident response procedures to meet the entity's objectives related to privacy.
- framework
- soc2
- control_id
- P6.5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-DATA-16 — Bind third parties handling personal data to privacy commitments mitigates Failure to detect, assess, and notify breaches on time
- strength
- related
- rationale
- Routing vendors' breach notifications into incident response ensures timely detection/notification of third-party breaches.