Redress - Request Denial, v1.0

Defines privacy requirements related to organizations providing individuals with reasons why requests for information from the information controller are denied, and the ability to challenge the denial.

Assessment Step

1
Redress - Request Denial (Redress-RequestDenial)
If a request for information from the sensitive information controller is denied, does the organization provide the individual with reasons why and are they able to challenge such denial?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
If a request for information from the personal information controller is denied, individual should be provided with reasons why and be able to challenge such denial.
Citation
APEC
Section 25, Access and Correction