SBS - The best value in QMS software

Confidentiality of Customer Information in ISO 9001?

Sidney Vianna

Post Responsibly
Staff member
Admin
#11
This is analagous to stating that ISO 9001 requires back-up of electronic records. And I have seen a number of auditors who firmly believe that to be the case.

Sometimes people read too much into a requirement.

Jan summed up the best. Certain customer data (not all) needs to be kept confidential, and that should be specifically dealt with via some type of contractual arrangement.
 
Elsmar Forum Sponsor
P

Phil Fields

#13
Interesting replies! So is there a final opinion or ruling as to the ISO 9001 requirement on confidentiality?

Phil
 

Stijloor

Staff member
Super Moderator
#14
Interesting replies! So is there a final opinion or ruling as to the ISO 9001 requirement on confidentiality?

Phil
Phil,

You've been here long enough to know that some threads never end. :D The dialogue continues or may end inconclusive. Every Cover has to make up their own mind...:yes:

Stijloor.
 

Colin

Quite Involved in Discussions
#15
This is analagous to stating that ISO 9001 requires back-up of electronic records. And I have seen a number of auditors who firmly believe that to be the case.

Sometimes people read too much into a requirement.

Jan summed up the best. Certain customer data (not all) needs to be kept confidential, and that should be specifically dealt with via some type of contractual arrangement.
Hmmm, interesting point Sidney. So if an organisation keeps records in an electronic form and does not do back-ups, how do they ensure records are protected?
 

Sidney Vianna

Post Responsibly
Staff member
Admin
#16
Hmmm, interesting point Sidney. So if an organisation keeps records in an electronic form and does not do back-ups, how do they ensure records are protected?
Well, depending on the media the electronic records are stored, protection could be as simple as ensuring that the devices used to store the data are physically protected from the elements, fire, water damage, etc...

If you understand that ISO 9001 mandates back-up of electronic records (as means of protection), why don't you enforce the same policy for hard copy records? Why would an auditor have a double standard between electronic and paper records?

It should be unnecessary to state, but....obviously electronic data back-up is a wise thing to do and business continuity concerns reminds us of that. However, in my opinion, ISO 9001 does not mandate such practice. That's all.
 

Colin

Quite Involved in Discussions
#17
I see your point Sidney and agree that there is a need to protect records no matter what the media. I guess that paper records are more likely to remain safe unless there is a fire/flood situation whereas electronic records are more prone to loss via additional means such as accidental deletion, corruption, mechanical failure, etc and therefore need more protection.

I even wonder about the method of backing up too. It is obviously good practice but I fear that some organisations are putting too much faith in memory sticks (USB flash drives). They are very convenient but not overly reliable and easy to lose.
 
Thread starter Similar threads Forum Replies Date
J Ensure customer confidentiality - TS 16949 Cl. 7.1.3 Confidentiality Various Other Specifications, Standards, and related Requirements 7
D Cybersecurity and Risk Management: Loss of confidentiality IEC 62304 - Medical Device Software Life Cycle Processes 4
O Medical Device Technical File Confidentiality - On site reviews EU Medical Device Regulations 14
P Procedure for maintaining Confidentiality And Impartiality in a Laboratory Quality Management System (QMS) Manuals 2
S AS9100 and Confidentiality requirement AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 3
C Internal Audit Confidentiality - Exempt from review by the FDA under 820.180(c)? 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 4
K Competence, Training and Awareness - Documenting Training and Confidentiality Aspects ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 12
J Auditor Confidentiality vs. Liability General Auditing Discussions 34
F CVs/Resumes & Competence, Training, and Awareness - Employee Confidentiality ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 4
Marc Confidentiality (Non-Disclosure) Agreement - Financial Statements Document Control Systems, Procedures, Forms and Templates 11
S Sample of Confidentiality Statement/Policy of Inspection Body Other ISO and International Standards and European Regulations 4
B External Auditor Confidentiality Agreement General Auditing Discussions 8
M Confidentiality Issues Relating to Registration - Documentation, Processes, Etc. Registrars and Notified Bodies 22
S Audit finding - "Cost of Poor Quality" reporting - Confidentiality Issues IATF 16949 - Automotive Quality Systems Standard 13
I Confidentiality Audit - Confidential Infomation and related Documents Audit General Auditing Discussions 9
D TS 16949 Clause 7.1.3 - Confidentiality IATF 16949 - Automotive Quality Systems Standard 3
C Confidentiality - Minimum / Generic Information on Control Plan FMEA and Control Plans 1
Marc QS-9000, Appendix I, #6, Confidentiality - DaimlerChyrsler - Hank Gryn? QS-9000 - American Automotive Manufacturers Standard 7
D Suggestions for Ishikawa for hyperdetailed customer - plastic molding automotive parts Nonconformance and Corrective Action 9
J WAIVED ON Q1 - We Don't have to comply with FORDS customer specific requirements IATF 16949 - Automotive Quality Systems Standard 2
A Customer Approval (Medical Devices) Document Control Systems, Procedures, Forms and Templates 4
M Reduce occurrence rating based on the PMS data and customer complaint data ISO 14971 - Medical Device Risk Management 2
M IATF16949 Clause 9.1.2.1e - Customer notification related IATF 16949 - Automotive Quality Systems Standard 4
G Too many customer complaints Customer Complaints 16
lanley liao Does the customer`s trademark belong to customer-supplied property? Oil and Gas Industry Standards and Regulations 2
J Customer Complaint & SCAR, false data Nonconformance and Corrective Action 14
S Annual Inspection Layout - Based on Customer print ? IATF 16949 - Automotive Quality Systems Standard 8
G Risk of stopping your customer's line IATF 16949 - Automotive Quality Systems Standard 4
S Calibration/Verification of customer fixtures IATF 16949 - Automotive Quality Systems Standard 6
D CB and customer audits considered as internal audits? General Auditing Discussions 9
O Informational Ford Motor Company Customer Specific Requirements for IATF 16949:2016 - 08 Jan 2021 Customer and Company Specific Requirements 0
G Bad Parts cause Customer line stop IATF 16949 - Automotive Quality Systems Standard 13
O IATF 16949 News Ford Motors Customer Specific Requirements Update - Nov 2020 IATF 16949 - Automotive Quality Systems Standard 5
D Question regarding customer feedback process ISO 13485:2016 - Medical Device Quality Management Systems 3
D Change Approval Requirements - Does every change need formal customer approval? Design and Development of Products and Processes 17
B Retention Samples when Customer Leaves Pharmaceuticals (21 CFR Part 210, 21 CFR Part 211 and related Regulations) 1
M Email Template that go to a customer and then get returned to us for RMA/Warranty Document Control Systems, Procedures, Forms and Templates 1
B FCA US Customer Specific IATF 16949- Critical Characteristics 8.6.2 Customer and Company Specific Requirements 0
D ISO 13485 8.2.1 and 8.2.2 - Customer Feedback and Customer Complaints ISO 13485:2016 - Medical Device Quality Management Systems 5
J Customer Complaint Response 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 3
V Quality review Meeting with Customer for complaints we received Customer Complaints 6
D IATF16949 - Interpretation of Customer Requirements clauses IATF 16949 - Automotive Quality Systems Standard 3
S Obligation to accept customer audits? IATF 16949 - Automotive Quality Systems Standard 23
D IATF16949 7.5.3.2.1 Record Retention - Our Product or Customer Product? Elsmar Cove Forum Suggestions, Complaints, Problems and Bug Reports 1
S Customer Specific Requirements (CSR) not signed/approved IATF 16949 - Automotive Quality Systems Standard 17
B FCA US IATF 16949 Customer Requirements updates Customer and Company Specific Requirements 3
G Same parts but new customer - What will the auditor ask me? IATF 16949 - Automotive Quality Systems Standard 2
R Customer Satisfaction importance in companies with Government/Public Administration as main customer? ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 11
G Self Assessment Audit from a new potential customer General Auditing Discussions 3
P Customer Corrective Action Requests in OASIS? AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 4

Similar threads

Top Bottom