{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Data Protection & Privacy","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-16","description":"Before granting vendors or other third parties access to personal information, obtain written privacy commitments covering permitted use, safeguards, and notification of actual or suspected unauthorized disclosures. Assess their compliance periodically and as needed, route their breach notifications into the incident-response process, and take corrective action or terminate access when commitments are not met.","details":{"control_category":"administrative","control_type":"preventive","domain":"Data Protection & Privacy","guidance":[],"members":[{"control_id":"P6.4","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"P6.5","coverage":"full","framework":"soc2","relationship":"superset_of"}],"statement":"Before granting vendors or other third parties access to personal information, obtain written privacy commitments covering permitted use, safeguards, and notification of actual or suspected unauthorized disclosures. Assess their compliance periodically and as needed, route their breach notifications into the incident-response process, and take corrective action or terminate access when commitments are not met.","title":"Bind third parties handling personal data to privacy commitments","unified_id":"UC-DATA-16"},"id":"uc:UC-DATA-16","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-16","sourceIds":["soc2"],"sourceUrl":null,"title":"UC-DATA-16 — Bind third parties handling personal data to privacy commitments","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7f3b3fe0a6bcff3e2828618adf67b373a4593c4a10293f4283637df72166e785","properties":{"rationale":"Binding third parties to permitted-use, safeguard, and breach-notification commitments with periodic assessment directly reduces unauthorized disclosure via vendors.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-16-57ae2c9a.json","sourceId":"uc:UC-DATA-16","targetDetailPath":"/data/v1/records/risk-data-breach-unauthorized-disclosure-3b1c296c.json","targetId":"risk:data-breach-unauthorized-disclosure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8e8c348ca31b2ccafcf8709db7835700d8d507d56d423998db579955168a3b9f","properties":{},"sourceDetailPath":"/data/v1/records/wf-g28-6078329f.json","sourceId":"wf:G28","targetDetailPath":"/data/v1/records/uc-uc-data-16-57ae2c9a.json","targetId":"uc:UC-DATA-16","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8ee06b48f8255c98016fe00d9a68a99481f46dc60bb8934f6c8725f29fd01a01","properties":{"rationale":"Written processor commitments and their enforcement support the organization's data-protection compliance obligations.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-16-57ae2c9a.json","sourceId":"uc:UC-DATA-16","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:94b21ae83f86a03a5515a9e49098b83b15a5662084be5ea8d7c71f45f6d20454","properties":{},"sourceDetailPath":"/data/v1/records/wf-r16-5b93e206.json","sourceId":"wf:R16","targetDetailPath":"/data/v1/records/uc-uc-data-16-57ae2c9a.json","targetId":"uc:UC-DATA-16","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ab4bbde73775636a60c5f2578ef0ac2e49a68b995ef39ca3742c5683f48f3575","properties":{},"sourceDetailPath":"/data/v1/records/wf-g13-0f34ff59.json","sourceId":"wf:G13","targetDetailPath":"/data/v1/records/uc-uc-data-16-57ae2c9a.json","targetId":"uc:UC-DATA-16","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b27876d9f9016c29b76da8f9fc0ae27cc115c82c27a5cdbfc2bb24618f99e620","properties":{"control_id":"P6.4","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-data-16-57ae2c9a.json","sourceId":"uc:UC-DATA-16","targetDetailPath":"/data/v1/records/ctrl-soc2-p6-4-0d001058.json","targetId":"ctrl:soc2:P6.4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bc7442d184ab748d54fd0af2949c45f12e55c5a3cf124fca17ed029e1e6a08bd","properties":{},"sourceDetailPath":"/data/v1/records/wf-d22-f1c724b8.json","sourceId":"wf:D22","targetDetailPath":"/data/v1/records/uc-uc-data-16-57ae2c9a.json","targetId":"uc:UC-DATA-16","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e1d8633b1bcf0308a3f784ae42c287e90600903a8a7be775690c77f2afd87f9f","properties":{"control_id":"P6.5","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-data-16-57ae2c9a.json","sourceId":"uc:UC-DATA-16","targetDetailPath":"/data/v1/records/ctrl-soc2-p6-5-eba23c68.json","targetId":"ctrl:soc2:P6.5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:edf4d97d894de8125bfdae26b6463316b7b9f6bfee002bc741291f2fe9d15c0b","properties":{"rationale":"Routing vendors' breach notifications into incident response ensures timely detection/notification of third-party breaches.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-16-57ae2c9a.json","sourceId":"uc:UC-DATA-16","targetDetailPath":"/data/v1/records/risk-ir-breach-notification-failure-1f01c218.json","targetId":"risk:ir-breach-notification-failure","type":"mitigates"}],"schemaVersion":1}
