Onward Transfer - Ensure Protection - APEC, v1.0

Defines privacy requirements for due diligence when transferring sensitive information to ensure it will be protected in accordance with the APEC Privacy Principles.

Assessment Step

1
Onward Transfer - Ensure Protection - APEC (OnwardTransfer-EnsureProtection-APEC)
Does the organization require that when sensitive information is to be transferred to another person or organization, whether domestically or internationally, the sensitive information controller should exercise due diligence and take reasonable steps to ensure that the recipient person or organization will protect the information consistently with the Asia-Pacific Economic Cooperation (APEC) Privacy Principles http://publications.pec.rg/publication-detail.hp.pub_id=390?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
When personal information is to be transferred to another person or organization, whether domestically or internationally, the personal information controller should exercise due diligence and take reasonable steps to ensure that the recipient person or organization will protect the information consistently with the Asia-Pacific Economic Cooperation (APEC) Privacy Principles http://publications.apec.org/publication-detail.php?pub_id=390
Citation
APEC
Section 26, Accountability