Source | Azure Portal | ||||||||||||||||||||||||||||||||||||||||||||
Display name | Implement methods for consumer requests | ||||||||||||||||||||||||||||||||||||||||||||
Id | b8ec9ebb-5b7f-8426-17c1-2bc3fcd54c6e | ||||||||||||||||||||||||||||||||||||||||||||
Version | 1.1.0 Details on versioning |
||||||||||||||||||||||||||||||||||||||||||||
Versioning |
Versions supported for Versioning: 1 1.1.0 Built-in Versioning [Preview] |
||||||||||||||||||||||||||||||||||||||||||||
Category | Regulatory Compliance Microsoft Learn |
||||||||||||||||||||||||||||||||||||||||||||
Description | CMA_0319 - Implement methods for consumer requests | ||||||||||||||||||||||||||||||||||||||||||||
Additional metadata |
Name/Id: CMA_0319 / CMA_0319 Category: Operational Title: Implement methods for consumer requests Ownership: Customer Description: Microsoft recommends that your organization make available two or more designated methods for consumers to exercise the right to request access, disclosure, use of (including selling), correction and/or deletion of personal information collected by your organization. At a minimum, it is recommended that this include a toll-free telephone number, and if the business maintains a website, a discoverable link that is accessible by consumers. We recommend that at least one method be in a format in which a person with disabilities can submit requests and interpret the response. It is also recommended that your organization make feasible arrangements and provide a copy of personal data records if the data subject or authorized delegate is under special circumstances that prevent them from exercising their rights to inspect and review their data. Microsoft recommends that your organization determine any fees associated with providing information to data subjects. Various data protection regulations allow data subjects to obtain information free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, your organization may either charge a reasonable fee considering the administrative costs of providing the information or communication or taking the action requested or refuse to act on the request. The New Zealand Health Information Privacy Code prohibits private sector health agencies from requiring the payment of any charges for information privacy requests concerning health information. Non-private sector agencies may require a reasonable charge when that agency has already made health information available to that individual in response to a request, and the individual requests the same or substantially the same health information within a period of 12 months, or for providing a copy of an x-ray, a video recording, an MRI scan photograph, a PET scan photograph, or a CAT scan photograph. If the charge is likely to exceed $30, the agency must provide the individual with an estimate of the charge before dealing with the request. Requirements: The customer is responsible for implementing this recommendation. |
||||||||||||||||||||||||||||||||||||||||||||
Mode | All | ||||||||||||||||||||||||||||||||||||||||||||
Type | BuiltIn | ||||||||||||||||||||||||||||||||||||||||||||
Preview | False | ||||||||||||||||||||||||||||||||||||||||||||
Deprecated | False | ||||||||||||||||||||||||||||||||||||||||||||
Effect | Default Manual Allowed Manual, Disabled |
||||||||||||||||||||||||||||||||||||||||||||
RBAC role(s) | none | ||||||||||||||||||||||||||||||||||||||||||||
Rule aliases | none | ||||||||||||||||||||||||||||||||||||||||||||
Rule resource types | IF (1) Microsoft.Resources/subscriptions |
||||||||||||||||||||||||||||||||||||||||||||
Compliance |
The following 3 compliance controls are associated with this Policy definition 'Implement methods for consumer requests' (b8ec9ebb-5b7f-8426-17c1-2bc3fcd54c6e)
| ||||||||||||||||||||||||||||||||||||||||||||
Initiatives usage |
|
||||||||||||||||||||||||||||||||||||||||||||
History |
|
||||||||||||||||||||||||||||||||||||||||||||
JSON compare |
compare mode:
version left:
version right:
|
||||||||||||||||||||||||||||||||||||||||||||
JSON |
|