Through commitments that can be enforced in law, the laboratory is responsible for managing all information it obtains or produces while carrying out its activities. It tells the customer beforehand what information it plans to make public, and treats all other information as proprietary and confidential, except what the customer itself makes public or where laboratory and customer have agreed otherwise. Where law or contractual arrangements require the laboratory to release confidential information, it tells the customer or person concerned what is being released, unless the law forbids this. Information about the customer that comes from someone other than the customer (for example a complainant or a regulator) is kept confidential, shared only by customer and laboratory, and the laboratory does not reveal who provided it unless that source agrees. Staff, committee members, contractors, staff of external bodies and anyone else acting for the laboratory keep information confidential except where the law requires otherwise.
This control maps to 14 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 14 it maps to, and the evidence behind each claim, over MCP and REST.