Control #
C
2
.
2
Disclose AI training practices and obtain customer consent
Tell customers whether their data may be used for training, and get explicit opt-in or provide clear notice before doing so. Consent must be recorded and tied to a specific use case or context.
Evidence
Screenshots of third-party AI model provider configurations that identify data training is disabled
Policy document available to customers which discusses extent of AI training
Screenshot of mechanism by which customers consent or opt-in to AI training with their data
Recommended actions
We'll recommend specific practices and actions for complying with this control.