Access - Information Is Held, v1.0

Defines privacy requirements related to individuals obtaining confirmation of whether or not sensitive information is held about them.

Assessment Step

1
Access - Information Is Held (Access-InformationIsHeld)
Does the organization require that individuals are able to obtain from the sensitive information controller confirmation of whether or not the sensitive information controller holds sensitive information about them?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
Individuals should be able to obtain from the personal information controller confirmation of whether or not the personal information controller holds personal information about them.
Citation
APEC
Section 23, Access and Correction