Control #

C

2

.

2

Disclose AI training practices and obtain customer consent

Tell customers whether their data may be used for training, and get explicit opt-in or provide clear notice before doing so. Consent must be recorded and tied to a specific use case or context.

Evidence

Screenshots of third-party AI model provider configurations that identify data training is disabled

Policy document available to customers which discusses extent of AI training

Screenshot of mechanism by which customers consent or opt-in to AI training with their data

Recommended actions

We'll recommend specific practices and actions for complying with this control.

Provide feedback on this control