User Notification About Third-Party Requests for User Information

Criteria: The company tells me if the government or other third parties ask for my information.

See the test in action:

Indicators

  1. The company notifies users when government entities (including courts or other judicial bodies) request their user information.
  2. The company notifies users when private parties request their user information.
  3. The company clearly discloses situations when it might not notify users, including a description of the types of government requests it is prohibited by law from disclosing to users.

Methodology for Assessing Each Indicator

1) The company notifies users when government entities (including courts or other judicial bodies) request their user information.

  • Obtain and review the company’s legal documents, particularly their privacy policy, usually available on the company’s website.
  • Look for a commitment within the legal documents to inform users when a government entity requests their personal information or information associated with their user account.
  • If the legal documents are not clear about whether they apply to the “smart device” being evaluated, or only to the websites and other services of the service provider, limit grade to PARTIAL PASS.
  • If the legal documents commit to notifying the user when government entities request their personal information or information associated with their user account, mark PASS.
  • If the legal documents carry no commitment to notifying the user when governmental entities request their personal information or information associated with their user account, mark FAIL.

2) The company notifies users when private parties request their user information.

  • Obtain and review the company’s legal documents, particularly their privacy policy, usually available on the company’s website.
  • Look for a commitment within the legal documents to inform users when a private party requests their personal information or information associated with their user account.
  • If the legal documents are not clear about whether they apply to the “smart device” being evaluated, or only to the websites and other services of the service provider, limit grade to PARTIAL PASS.
  • If the legal documents commit to notifying the user when private parties request their personal information or information associated with their user account, mark PASS.
  • If the legal documents carry no commitment to notifying the user when private parties request their personal information of information associated with their user account, mark FAIL.

3) The company clearly discloses situations when it might not notify users, including a description of the types of government requests it is prohibited by law from disclosing to users.

  • Obtain and review the company’s legal documents, particularly their privacy policy, usually available on the company’s website.
  • Look for information about when the company may not notify users of requests to access their information.
  • If the legal documents are not clear about whether they apply to the “smart device” being evaluated, or only to the websites and other services of the service provider, limit grade to PARTIAL PASS.
  • If the legal documents include a list of situations in which the company will not notify users of requests to access their information, including the types of government requests from which it is prohibited from notifying users, mark PASS.
  • If the legal documents include a list of situations in which the company will not notify users of requests to access their information, but does not include further details, mark PARTIAL PASS.
  • If the legal documents do not mention that the company may be prohibited from notifying users of requests to access their information, mark FAIL.
User Notification About Third-Party Requests for User Information

Table of Contents

Close