Access - Ease of Obtaining Information, v1.0

Defines privacy requirements related to individuals obtaining sensitive information that is held about them.

Assessment Step

1
Access - Ease Of Obtaining Information (Access-EaseOfObtainingInformation)
Does the organization require that individuals are able to obtain from the sensitive information controller the sensitive information that is held about them: i. within a reasonable time; ii. at a charge, if any, that is not excessive; iii. in a reasonable manner; iv. in a form that is generally understandable?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
Individuals should be able to obtain from the personal information controller the personal information that is held about them: i. within a reasonable time; ii. at a charge, if any, that is not excessive; iii. in a reasonable manner; iv. in a form that is generally understandable
Citation
APEC
Section 23, Access and Correction