AICPA Privacy Management Framework (PMF)
Data Integrity and Quality

AICPA Privacy Management Framework (PMF) PMF-DI.2: Data Quality Processes

Organisation has processes to verify and correct inaccurate or incomplete personal information.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 221 controls across 57 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 7 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.16 Right to rectification
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.5 Principles relating to processing of personal data
  • GDPR-Art.9 Processing of special categories of personal data

Bahrain PDPL · 5 controls

Saudi Arabia PDPL · 5 controls

  • SA-PDPL-13 Encryption of personal data
  • SA-PDPL-15 Access control for personal data
  • SA-PDPL-20 Records of processing activities
  • SA-PDPL-22 Privacy by design and default
  • SA-PDPL-23 Data processing agreements
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes

POPIA · 4 controls

  • POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions
  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations
  • POPIASA-7 Information Officer, Records of Processing, Notification, Training
  • TANZANIA-1 Scope, Registration, Lawful Basis
  • TANZANIA-3 Data Subject Rights
  • TANZANIA-4 Security and Cross-Border
  • TANZANIA-5 DPO, Governance, Breach
  • TRINIDAD-1 Scope, Definitions, Commission
  • TRINIDAD-3 Data Subject Rights
  • TRINIDAD-4 Security, Accuracy
  • TRINIDAD-5 Enforcement and Sanctions
  • Standard 13 Nudge Techniques
  • Standard 14 Connected Toys and Devices
  • Standard 5 Detrimental Use of Data
  • Standard 8 Data Minimisation

APPI · 3 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management
  • RMD-2 Master Data Management

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-A.1 Data Quality and Representativeness
  • ISO23894-A.5 Privacy and Data Protection in AI
  • ISO-25012-5.1 Establishing data quality requirements
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

SASB Standards · 3 controls

  • SASB-4 Social Capital (SC)
  • SASB-SC-1 Customer Privacy and Data Security
  • SASB-SOC-2 Customer Privacy

SOC 2 · 3 controls

  • SOC2-P3.1 P3.1 Collecting personal information consistent with objectives
  • SOC2-P4.3 P4.3 Securely disposing of personal information
  • SOC2-P6.1 P6.1 Disclosure to third parties with consent

South Korea ISMS-P · 3 controls

  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-SYS-02 Encryption Implementation
  • SWE-1 Scope and Purpose
  • SWE-11 Integritetsskyddsmyndigheten (IMY)
  • SWE-2 Relationship to GDPR

Taiwan PDPA · 3 controls

  • TAIWAN-2 Consent, Notice, Sensitive Data
  • TAIWAN-3 Data Subject Rights
  • TAIWAN-4 DPIA, Privacy by Design
  • UK-DPA18-GEN-04 UK-Specific Exemptions
  • UK-DPA18-LE-02 Data Subject Rights (Law Enforcement)
  • UK-DPA18-LE-03 International Transfers (Law Enforcement)

Virginia CDPA · 3 controls

  • VIRGINIAVCDPA-1 Scope, Applicability, Definitions
  • VIRGINIAVCDPA-3 Sensitive Data Consent and Children
  • VIRGINIAVCDPA-4 Privacy Notice and DPIA
  • AL-DPA-12 International Data Transfers
  • AL-DPA-7 Right of Access
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

ISO/IEC 27400:2022 · 2 controls

  • 27400-5.4 Data and privacy risks
  • 27400-7.3 Data minimization and purpose limitation
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration

Qatar DPL · 2 controls

  • QATAR-3 Data Subject Rights
  • QATAR-7 DPO, Records, Retention, Marketing, Training
  • SSAE18-P1.1 P1.1 - Privacy Notice
  • SSAE18-P1.2 P1.2 - Choice and Consent
  • UKGDPRREG-2 Data Subject Rights (Articles 12-22)
  • UKGDPRREG-3 Controller and Processor (Articles 24-43)
  • UNESCO-AI-PA3 Data Policy
  • UNESCOAI-2 Principles 4-7: Sustainability, Privacy, Human Oversight, Transparency
  • UGA-13 Unlawful Obtaining or Disclosure
  • UGA-15 Unauthorized Sale of Data

Uruguay DPL · 2 controls

  • URUGUAY-1 Scope, Lawful Basis, Consent
  • URUGUAY-5 Database Registration with AGESIC URCDP
  • SO3.2 Regulatory frameworks for digital health
  • SO3.3 Data governance and protection
  • DS-2 Ensure software supply chain security
  • CA-10 Selects and Develops Control Activities
  • CTDPA-1 Definitions
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • RICS-DT-3.2 Data Quality Assurance
  • RCEPEC-1 Online Personal Information Protection (12.13)
  • EHDS-HOLD-3 Dataset Descriptions and Catalogues
  • RIDTPPA-11 Data Minimisation and Purpose Limitation
  • SOC-CY-DC2 Nature of Sensitive Information
  • AIGF-1.3 Data Management
  • STUDPRV-2 Data Subject Rights for Students and Parents
  • TISAXASS-3 Prototype Protection and Confidentiality
  • TEXASTDPSA-3 Sensitive Data, Children, Sale Notice
  • UKAI-2 Sector-Specific Regulator Engagement
  • OB-CX.2 Granular Consent Management
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Data Integrity and Quality

Query this from an agent

The graph holds this control, the 221 it maps to, and the evidence behind each claim, over MCP and REST.