Redress - Challenge Denial, v1.0

Defines privacy requirements related to providing reasons why a challenge of information held by the sensitive information controller was denied.

Assessment Step

1
Redress - Challenge Denial (Redress-ChallengeDenial)
If a challenge of information held by the sensitive information controller is denied, does the organization provide the individual with reasons why and are they able to challenge such denial?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
If a challenge of information held by the personal information controller is denied, individual should be provided with reasons why and be able to challenge such denial.
Citation
APEC
Section 25, Access and Correction