{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Data Protection & Privacy","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-05","description":"Publish and maintain privacy notices that describe, in clear and plain language, the categories of personal data collected, purposes, lawful bases, recipients, retention periods, and data-subject rights, and deliver them at or before the point of collection. Update and re-communicate notices in a timely manner when practices change, and publish any legally required registrations such as system-of-records notices. Retain dated notice versions as evidence.","details":{"control_category":"administrative","control_type":"preventive","domain":"Data Protection & Privacy","guidance":[],"members":[{"control_id":"PT-5","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PT-6","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"P1.1","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"GDPR-Art12-14","coverage":"partial","delta":"controller/DPO identity, complaint right, transfer info, automated-decision disclosures, Art 14 source omitted","framework":"gdpr","relationship":"intersects_with"},{"control_id":"HIPAA-164.520","coverage":"partial","delta":"NPP-specific content (header, complaint process, duties, effective date) and acknowledgment mechanics omitted","framework":"hipaa","relationship":"intersects_with"},{"control_id":"CCPA-1798.100","coverage":"partial","delta":"beyond notice-at-collection: 1798.100 general duties (purpose limitation, reasonable security, contractor requirements) and verified right-to-know fulfillment satisfied by companion privacy-rights and security controls","framework":"ccpa","relationship":"intersects_with"}],"statement":"Publish and maintain privacy notices that describe, in clear and plain language, the categories of personal data collected, purposes, lawful bases, recipients, retention periods, and data-subject rights, and deliver them at or before the point of collection. Update and re-communicate notices in a timely manner when practices change, and publish any legally required registrations such as system-of-records notices. Retain dated notice versions as evidence.","title":"Provide privacy notices and transparency to data subjects","unified_id":"UC-DATA-05"},"id":"uc:UC-DATA-05","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-05","sourceIds":["ccpa","gdpr","hipaa","nist-800-53","soc2"],"sourceUrl":null,"title":"UC-DATA-05 — Provide privacy notices and transparency to data subjects","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1827f1bc36ce33f1a9780dee59e37237270664e144f751ebc063fb8b40220d05","properties":{},"sourceDetailPath":"/data/v1/records/wf-r11-a48dfcd0.json","sourceId":"wf:R11","targetDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","targetId":"uc:UC-DATA-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:21baa02f63b58872be3376d300780e39d7371ce87049afde2bd305be4d9a7f65","properties":{"control_id":"PT-5","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pt-5-87626c3c.json","targetId":"ctrl:nist-800-53:PT-5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2ce39baacf4e08681a6e141f99447226f227084a6d955c5b9f97cc90a6558291","properties":{"rationale":"Maintaining legally-required notices and registrations addresses the inadequate-notice driver of regulatory non-compliance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:311f1c9e910cf8d774d86a7bd67c2a5b53ae07067c13a3b348efe6d898619609","properties":{"rationale":"Publishing clear, timely, plain-language notices at/before collection directly counters inadequate/late transparency and non-disclosure of practices.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/risk-data-transparency-notice-dark-patterns-9326fdf0.json","targetId":"risk:data-transparency-notice-dark-patterns","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:41280e986145674087f4497ff33260f1d466fb931a9cec5de5003fdfc2bdbd8c","properties":{"rationale":"Disclosing purposes, recipients, retention, and rights reduces the informational asymmetry between organization and individual.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/risk-privacy-power-imbalance-self-determination-9112ad1d.json","targetId":"risk:privacy-power-imbalance-self-determination","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6da7bf5a3b8a345fe74a341399c60cd7c389912a2449916aea20ee15fa98f734","properties":{},"sourceDetailPath":"/data/v1/records/wf-d22-f1c724b8.json","sourceId":"wf:D22","targetDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","targetId":"uc:UC-DATA-05","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:797932c738f5104f8f4a01aeb7695575ad4d9d28a420458b926f15caabec88ef","properties":{"rationale":"Transparent, current notices meet reasonable privacy expectations, sustaining confidence in data practices.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/risk-privacy-loss-of-trust-a4d1142c.json","targetId":"risk:privacy-loss-of-trust","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:838acb68e5edfaa0371e73a93223c2f4b3eb67d38a4f0e5cc32f8e51aee7b4c3","properties":{"control_id":"GDPR-Art12-14","coverage":"partial","delta":"controller/DPO identity, complaint right, transfer info, automated-decision disclosures, Art 14 source omitted","framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art12-14-51a7eca7.json","targetId":"ctrl:gdpr:GDPR-Art12-14","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c1fbcea3921a16b9e7385d64cfdea26afb335b35891013fa7b3be8e731582774","properties":{"control_id":"P1.1","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/ctrl-soc2-p1-1-c08fea86.json","targetId":"ctrl:soc2:P1.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c9304276963b8cebed4157199a87c0fea07b8f6ec3f954c32a61412b3c03ec8b","properties":{"control_id":"PT-6","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pt-6-97abd359.json","targetId":"ctrl:nist-800-53:PT-6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d8fe8176e92760aee02eb486cd4dd3d1188788b093d5b3607fbb9b89c0cd8b99","properties":{"control_id":"CCPA-1798.100","coverage":"partial","delta":"beyond notice-at-collection: 1798.100 general duties (purpose limitation, reasonable security, contractor requirements) and verified right-to-know fulfillment satisfied by companion privacy-rights and security controls","framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-100-b353d024.json","targetId":"ctrl:ccpa:CCPA-1798.100","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fbbd0dcfdd8c9aa3e68221ba809794838d36c34b66b5794d6d87cb634894f6ad","properties":{"control_id":"HIPAA-164.520","coverage":"partial","delta":"NPP-specific content (header, complaint process, duties, effective date) and acknowledgment mechanics omitted","framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-520-e2735a22.json","targetId":"ctrl:hipaa:HIPAA-164.520","type":"maps_to"}],"schemaVersion":1}
