You are performing an ISMS audit at a European-based residential nursing home called ABC that provides healthcare services.
During the audit, you discovered evidence suggesting that ABC may be leaking personal data of residents’ family members to a third party for marketing purposes, despite signed agreements prohibiting this. Complaints were treated as nonconformities, and corrective actions were documented under procedure ISMS L2 10.1.
You decide to write a non-conformity. Select the best sentence for the nonconformity:
Submit