Enterprise Privacy Certification Standards
TRUSTe Enterprise Privacy Certification Standards are aligned with the Standards set forth in the TrustArc Privacy & Data Governance Framework which enable organizations to design and/or engineer effective privacy and data governance controls into organizational processes, products and technologies – and maintain or enhance those controls throughout the lifecycle for the product, process or technology. The TrustArc Framework Standards are based upon recognized laws and regulatory standards, such as the OECD Privacy Guidelines, the APEC Privacy Framework, the EU General Data Protection Regulation (“GDPR”), the U.S. Health Insurance Portability and Accountability Act (“HIPAA”), ISO 27001 International Standard for Information Security Management Systems and other global privacy laws and regulations.
TRUSTe Certifications are conducted in three phases:
Privacy Assessments provide the information required to understand and remediate compliance risks. An experienced member of our Global Privacy Solutions team guides you through the process, utilizing our proven methodology and powerful technology.
The first step is to define the assessment scope by business units, product/service lines, and digital properties (websites, apps, cloud platforms). A member of the Global Privacy Solutions team works with your team to efficiently guide discovery of necessary information, including relevant data flows and evaluation of your privacy policies and practices against relevant standards.
A findings report is delivered which includes a gap analysis, risk summary and remediation recommendations. The report outlines actionable steps required to achieve compliance.
Remediation and Certification Phase
Based on the information gleaned from the assessment, a member of the Global Privacy Solutions team guides you through the remediation process, helping to ensure required changes are completed.
Remediation / Validation
A member of the Global Privacy Solutions team assists with any necessary remediation steps, including providing relevant templates and process change advice. We then validate that your privacy statements accurately reflect your updated privacy practices and are consistent with applicable standards.
Letter of Attestation
As proof of TRUSTe Certification, an official Letter of Attestation can be shared with your business partners, providing your organization with competitive differentiation.
TRUSTe Privacy Certification Seal
After completing the required changes, we authorize your use of the TRUSTe Certified Privacy Seal for display on approved privacy notices and digital properties linking to that notice. The seal is hosted and linked to a TRUSTe Validation Page to provide real-time verification along with an easy-to-understand consumer notice that you meet globally recognized privacy requirements.
Ongoing Monitoring and Guidance Phase
Searchable Audit Trail
All assessment work and supporting documentation is available in a searchable, central repository – providing a way to respond to inquiries and demonstrate compliance for internal / external audits.
Ongoing Monitoring and Guidance
Ongoing compliance monitoring is provided throughout the term of the agreement. Access is provided to privacy experts for ongoing policy guidance along with educational webinars, events, whitepapers, client advisories, privacy tips and research.
Access to our third-party dispute resolution service, which helps efficiently manage privacy inquiries from customers and addresses dispute handling compliance requirements.
TRUSTe Privacy Feedback Button