4.2 Confidentiality

The laboratory shall ensure the confidentiality of all information obtained or created during laboratory activities, except as required by law or agreed upon with the customer.

4.2.1 Responsibility for Confidentiality

The laboratory shall be responsible, through legally enforceable commitments, for managing all information obtained or created during laboratory activities.

The laboratory shall inform the customer in advance of any information it intends to place in the public domain. Except for:

  • Information the customer makes publicly available
  • Information shared with the customer’s agreement (e.g., responding to complaints)

All other information is considered proprietary and shall be regarded as confidential.

4.2.2 Legal and Contractual Disclosure

When the laboratory is required by law or authorized by contractual agreements to release confidential information, the customer or individual concerned shall be notified of the information provided, unless prohibited by law.

4.2.3 Customer Information from External Sources

Information about the customer obtained from sources other than the customer (e.g., complainants, regulators) shall remain confidential between the laboratory and the customer.

Note:

The provider (source) of this information shall be confidential to the laboratory and shall not be shared with the customer unless agreed upon by the source.

4.2.4 Confidentiality Obligations of Personnel

Personnel, including committee members, contractors, personnel of external bodies, or individuals acting on the laboratory's behalf, shall keep confidential all information obtained or created during the performance of laboratory activities, except as required by law.