APPI
APPI: Security Control and Supervision (Articles 22 to 26)

APPI APPI-A22: Accuracy and Deletion of Personal Data

Endeavour to keep personal data accurate and up to date within the scope necessary to achieve the purpose of use, and to delete personal data without delay when it is no longer needed.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 42 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • APP-10 APP 10 - Quality of personal information
  • APP-11 APP 11 - Security of personal information
  • APP-13 APP 13 - Correction of personal information
  • APP-4 APP 4 - Dealing with unsolicited personal information

ISO 27701:2019 · 3 controls

  • 7.4.3 Accuracy and quality
  • 7.4.5 PII de-identification and deletion at the end of processing
  • 7.4.7 Retention

NIST SP 800-53 Rev 5 · 3 controls

  • NIST800-PM-22 PM-22 Personally Identifiable Information Quality Management
  • NIST800-SI-12 SI-12 Information Management and Retention
  • NIST800-SI-18 SI-18 Personally Identifiable Information Quality Operations

C5 (Germany) · 2 controls

  • C5-OPS-11 Logging and Monitoring - Metadata Management Concept
  • C5-PI-03 Secure deletion of data

CCPA/CPRA · 2 controls

  • §1798.100 General Duties of Businesses that Collect Personal Information
  • §1798.106 Right to Correct Inaccurate Personal Information

CIS Controls v8 · 2 controls

FedRAMP High · 2 controls

  • MP-6 Media Sanitization
  • SI-12 Information Management and Retention

FedRAMP Moderate · 2 controls

  • MP-6 Media Sanitization
  • SI-12 Information Management and Retention

HIPAA Security Rule · 2 controls

  • NIST-CSF-ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles

NIST SP 800-161 Rev 1 · 2 controls

  • 161R1-PM-22 Personally Identifiable Information Quality Management
  • 161R1-SI-12 Information Management and Retention

NIST SP 800-66 Rev 2 · 2 controls

SOC 2 · 2 controls

  • SOC2-P4.2 P4.2 Retaining personal information
  • SOC2-P7.1 P7.1 Quality of personal information
  • MYHR-GOV-5 Retention, destruction and correction obligations of the System Operator

CMMC 2.0 · 1 control

GDPR · 1 control

  • GDPR-Art.5 Principles relating to processing of personal data

ISO 27001:2022 · 1 control

  • 8.10 Information deletion

ISO 27002:2022 · 1 control

  • 8.10 Information deletion

ISO/IEC 42001:2023 · 1 control

  • A.7.4 Quality of data for AI systems

PCI DSS 4.0 · 1 control

  • 3.2.1 3.2.1 Data retention and disposal minimise stored account data

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in APPI: Security Control and Supervision (Articles 22 to 26)

You are reading one control. How much of APPI have you already done?

APPI APPI-A22 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of APPI your existing evidence covers. Hold APEC Cross-Border Privacy Rules (CBPR) System and 16 of 30 APPI controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APEC Cross-Border Privacy Rules (CBPR) System pair alone.

Query this from an agent

The graph holds this control, the 42 it maps to, and the evidence behind each claim, over MCP and REST.