Finally, your organization needs to stand behind its privacy policies and the practices of third parties by taking remedial action (7.2.4) in response to misuse of personal information by third parties. Specifically, your organization should consider these four practices:
1.Monitor complaints to identify indications of any misuse of personal information by third parties.
2.Respond to any knowledge of a third party using or disclosing personal information in variance with the entity's privacy policies and procedures, or contractual arrangements.
3.To the extent practicable, mitigate any harm caused by the use or disclosure of personal information by the third party in violation of the entity's privacy policies and procedures.
4.Take remedial action in the event that a third party misuses personal information (contractual clauses address the ramification of misuse of personal information, for example).