Privacy Statement
A
privacy statement is the
security work product that is
a legally-binding document that describes the personal
information gathering, usage, and dissemination practices of a
single
application (e.g., website).
The typical objectives of a privacy statement are to
document:
- What personal information is being collected by the
application
- How this personal information will be used
- What choices, if any, are available about how the
personal information will be collected, used, and
distributed
- With whom, if anyone, the personal information will be
shared
- Safeguards to protect the personal information from loss,
misuse, or alteration
- How one can update or correct inaccuracies in one’s
personal information
The typical benefits of a privacy statement include:
The typical contents of a privacy statement include:
- Introduction
- Information Collection
- Supplimentary Information Sources
- Information Usage
- Information Sharing
- Information Security
- Information Correction
- Change Notification
- Contact Information
The typical stakeholders of a privacy statement include:
- Producers:
- Evaluators:
- Approvers:
- Maintainers:
- Users:
- The
user uses
the privacy statement to understand the privacy aspects
of the application.
Privacy statements can typically be started if the following
preconditions hold:
Privacy statements typically have the following inputs:
- Work Products:
- Stakeholders:
Privacy statements are typically constrained by the
following conventions:
Examples
-
Example Privacy Statement