Redress - Information Challenge Exceptions, v1.0

Defines privacy requirements related to ensuring access and opportunity for the correction of sensitive information held by the sensitive information controller with identified exceptions.

Assessment Step

1
Redress - Information Challenge Exceptions (Redress-InformationChallengeExceptions)
Does the organization ensure that access and opportunity for the correction of sensitive information held by the sensitive information controller is provided except where: (i) the burden or expense of doing so would be unreasonable or disproportionate to the risks to the individual's privacy in the case in question; (ii) the information should not be disclosed due to legal or security reasons or to protect confidential commercial information; or (iii) the information privacy of persons other than the individual would be violated?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
Access and opportunity for the correction of personal information held by the personal information controller should be provided except where: (i) the burden or expense of doing so would be unreasonable or disproportionate to the risks to the individual's privacy in the case in question; (ii) the information should not be disclosed due to legal or security reasons or to protect confidential commercial information; or (iii) the information privacy of persons other than the individual would be violated.
Citation
APEC
Section 24, Access and Correction