AICPA Privacy Management Framework (PMF)
Data Integrity and Quality

AICPA Privacy Management Framework (PMF) PMF-DI.1: Data Accuracy

Organisation maintains accurate, complete, and relevant personal information to suit the purposes it is used for.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 172 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 6 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.5 Principles relating to processing of personal data
  • GDPR-Art.9 Processing of special categories of personal data
  • TANZANIA-1 Scope, Registration, Lawful Basis
  • TANZANIA-3 Data Subject Rights
  • TANZANIA-4 Security and Cross-Border
  • TANZANIA-5 DPO, Governance, Breach
  • TRINIDAD-1 Scope, Definitions, Commission
  • TRINIDAD-3 Data Subject Rights
  • TRINIDAD-4 Security, Accuracy
  • TRINIDAD-5 Enforcement and Sanctions
  • Standard 13 Nudge Techniques
  • Standard 14 Connected Toys and Devices
  • Standard 5 Detrimental Use of Data
  • Standard 8 Data Minimisation

APPI · 3 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution

Bahrain PDPL · 3 controls

  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

SASB Standards · 3 controls

  • SASB-4 Social Capital (SC)
  • SASB-SC-1 Customer Privacy and Data Security
  • SASB-SOC-2 Customer Privacy

SOC 2 · 3 controls

  • SOC2-P3.1 P3.1 Collecting personal information consistent with objectives
  • SOC2-P4.3 P4.3 Securely disposing of personal information
  • SOC2-P6.1 P6.1 Disclosure to third parties with consent

Saudi Arabia PDPL · 3 controls

  • SA-PDPL-13 Encryption of personal data
  • SA-PDPL-15 Access control for personal data
  • SA-PDPL-22 Privacy by design and default

South Korea ISMS-P · 3 controls

  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-SYS-02 Encryption Implementation
  • SWE-1 Scope and Purpose
  • SWE-11 Integritetsskyddsmyndigheten (IMY)
  • SWE-2 Relationship to GDPR
  • UK-DPA18-GEN-04 UK-Specific Exemptions
  • UK-DPA18-LE-02 Data Subject Rights (Law Enforcement)
  • UK-DPA18-LE-03 International Transfers (Law Enforcement)
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

ISO/IEC 27400:2022 · 2 controls

  • 27400-5.4 Data and privacy risks
  • 27400-7.3 Data minimization and purpose limitation
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration

POPIA · 2 controls

  • POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions
  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation

Qatar DPL · 2 controls

  • QATAR-3 Data Subject Rights
  • QATAR-7 DPO, Records, Retention, Marketing, Training
  • SSAE18-P1.1 P1.1 - Privacy Notice
  • SSAE18-P1.2 P1.2 - Choice and Consent

Taiwan PDPA · 2 controls

  • TAIWAN-2 Consent, Notice, Sensitive Data
  • TAIWAN-3 Data Subject Rights
  • UKGDPRREG-2 Data Subject Rights (Articles 12-22)
  • UKGDPRREG-3 Controller and Processor (Articles 24-43)
  • UGA-13 Unlawful Obtaining or Disclosure
  • UGA-15 Unauthorized Sale of Data

Uruguay DPL · 2 controls

  • URUGUAY-1 Scope, Lawful Basis, Consent
  • URUGUAY-5 Database Registration with AGESIC URCDP
  • AL-DPA-12 International Data Transfers
  • DS-2 Ensure software supply chain security
  • CA-10 Selects and Develops Control Activities
  • CTDPA-1 Definitions
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.5 Privacy and Data Protection in AI
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • RCEPEC-1 Online Personal Information Protection (12.13)
  • RIDTPPA-11 Data Minimisation and Purpose Limitation
  • SOC-CY-DC2 Nature of Sensitive Information
  • STUDPRV-2 Data Subject Rights for Students and Parents
  • TISAXASS-3 Prototype Protection and Confidentiality
  • TEXASTDPSA-3 Sensitive Data, Children, Sale Notice
  • UKAI-2 Sector-Specific Regulator Engagement
  • OB-CX.2 Granular Consent Management
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-1 Scope, Applicability, Definitions
  • SO3.2 Regulatory frameworks for digital health

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Data Integrity and Quality

Query this from an agent

The graph holds this control, the 172 it maps to, and the evidence behind each claim, over MCP and REST.