Frameworks / APPI / APPI-A23 APPI
APPI: Security Control and Supervision (Articles 22 to 26)
APPI APPI-A23: Security Control Measures Take necessary and appropriate measures for the security control of personal data, including measures to prevent leakage, loss or damage.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 366 controls across 130 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
GDPR-Art.10 Processing of personal data relating to criminal convictions GDPR-Art.11 Processing which does not require identification GDPR-Art.15 Right of access by the data subject GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction GDPR-Art.32 Security of processing GDPR-Art.5 Principles relating to processing of personal data GDPR-Art.9 Processing of special categories of personal data SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software SOC2-P3.1 P3.1 Collecting personal information consistent with objectives SOC2-P4.3 P4.3 Securely disposing of personal information SOC2-P6.1 P6.1 Disclosure to third parties with consent ASBv3-PA-7 Follow just enough administration (least privilege) principle BR-1 Ensure regular automated backups DP-4 Enable data at rest encryption by default DS-2 Ensure software supply chain security LT-3 Enable logging for security investigation NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-4 Sensitive Data Processing Consent and Childrens Protections NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NDPA-7 Data Protection Assessments and Processor Contracts NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles NG-NDPA-4 Data Subject Rights and Automated Decision-Making NG-NDPA-5 Security of Processing, Breach Notification, and DPIA NG-NDPA-7 Cross-Border Data Transfers and International Cooperation ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources ANSSI-HYG-18 Encrypt Sensitive Data Transmitted Over the Internet ANSSI-HYG-31 Encrypt Sensitive Data, in Particular on Equipment That May Be Lost ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components APP-1 APP 1 - Open and transparent management of personal information APP-11 APP 11 - Security of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information C5-CRY-03 Encryption of sensitive data for storage C5-IDM-09 Authentication mechanisms C5-OPS-09 Data Backup and Recovery - Storage C5-PS-01 Physical Security and Environmental Control Requirements CIS-3.10 Encrypt Sensitive Data in Transit CIS-3.11 Encrypt Sensitive Data at Rest CIS-3.13 Deploy a Data Loss Prevention Solution CIS-3.3 Configure Data Access Control Lists AC-3 Access Enforcement CP-9 System Backup SC-28 Protection of Information at Rest SC-8 Transmission Confidentiality and Integrity AC-3 Access Enforcement CP-9 System Backup SC-28 Protection of Information at Rest SC-8 Transmission Confidentiality and Integrity UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) 5.34 Privacy and protection of personal identifiable information (PII) 8.13 Information backup 8.24 Use of cryptography 8.3 Information access restriction 10.2.1 10.2.1 Audit logging enabled on all system components 12.1.1 12.1.1 Overall information security policy established and disseminated 3.5.1 3.5.1 Stored PAN rendered unreadable 7.3.1 7.3.1 Need-to-know access control system covers all components TANZANIA-1 Scope, Registration, Lawful Basis TANZANIA-3 Data Subject Rights TANZANIA-4 Security and Cross-Border TANZANIA-5 DPO, Governance, Breach TRINIDAD-1 Scope, Definitions, Commission TRINIDAD-3 Data Subject Rights TRINIDAD-4 Security, Accuracy TRINIDAD-5 Enforcement and Sanctions Standard 13 Nudge Techniques Standard 14 Connected Toys and Devices Standard 5 Detrimental Use of Data Standard 8 Data Minimisation AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing AZ-DPA-12 Article 13 - Cross-border transfer AZ-DPA-14 Article 16 - Liability for violations AZ-DPA-15 Article 17 - Dispute resolution BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-21 Sections 61-69 - Data Privacy Officer BE-DPA-11 Transposition of the Law Enforcement Directive BE-DPA-13 Corrective powers and administrative fines BE-DPA-5 Processing of special categories for substantial public interest FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) 29100-6.10 Information security 29100-6.5 Use, retention and disclosure limitation 29100-6.9 Accountability 29134-1 Scope 29134-3 Terms and definitions 29134-9.1 PIA report structure IsraelPPL-CrossBorder-Transfer-Sec36-EU-Adequacy-Israel-Adequacy-SCCs-Reciprocity-Foreign-Recipient Israel POPL Cross-Border Transfer + Section 36 + Privacy Protection (Transfer of Data to Databases Abroad) Regulations 5761-2001 + EU Adequacy Decision (2011) + SCCs + Foreign Recipient Obligations + Reciprocity IsraelPPL-DataSubjectRights-Access-Correction-Information-Delivery-Sec13-14-23A-23C-Subject-Notification Israel POPL Data Subject Rights - Section 13 Right of Access + Section 14 Right of Correction + Section 23A-C Prohibition on Information Delivery + Notice Obligation + Right to Object + Amendment 13 Enhancements IsraelPPL-Database-Registration-Definition-Document-Security-Level-Classification-Sec7-8-PPA-Registry Israel POPL Database Registration + Section 7 Database Definitions + Section 8 Registration Requirement + Database Definition Document + Security Level Classification + PPA Public Registry + Amendment 13 Threshold Changes MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing MY-PDPA-Data-Subject-Rights-Access-Correction-Portability-Withdraw-Consent-Prevent-Marketing-Sections-30-43 Malaysia PDPA Subject Rights + Access + Correction + Portability + Withdraw Consent + Prevent Marketing + Sections 30 to 43 MY-PDPA-Seven-Personal-Data-Protection-Principles-General-Notice-Choice-Disclosure-Security-Retention-Data-Integrity-Access Malaysia PDPA Seven Principles + General + Notice and Choice + Disclosure + Security + Retention + Data Integrity + Access NISTSP122-4 PII Minimisation, Purpose Limitation, and Pseudonymisation NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP122-6 PII Breach Response and Incident Handling NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NHPA-6 Reasonable Data Security and Breach Response NHPA-7 Data Protection Assessments and Processor Contracts NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP NGOB-2 Customer Consent Management and Lifecycle NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs SASB-4 Social Capital (SC) SASB-SC-1 Customer Privacy and Data Security SASB-SOC-2 Customer Privacy SA-PDPL-13 Encryption of personal data SA-PDPL-15 Access control for personal data SA-PDPL-22 Privacy by design and default ISMSP-PI-01 Personal Information Collection ISMSP-PI-04 Cross-Border Transfer ISMSP-SYS-02 Encryption Implementation SWE-1 Scope and Purpose SWE-11 Integritetsskyddsmyndigheten (IMY) SWE-2 Relationship to GDPR UK-DPA18-GEN-04 UK-Specific Exemptions UK-DPA18-LE-02 Data Subject Rights (Law Enforcement) UK-DPA18-LE-03 International Transfers (Law Enforcement) 27400-5.4 Data and privacy risks 27400-7.3 Data minimization and purpose limitation 27557-3 Terms and definitions 27557-4.3 Individual impact consideration ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination ItalyCodice-SpecialCategories-Health-Workplace-Education-ScientificResearch-HistoricalResearch-Art75-92-96-99-101 Italy Codice Special Categories + Article 75 Administrative Fines + Article 92 Medical Records + Article 96 Education + Article 99 Scientific Research + Article 101 Historical Research + Workplace Privacy + Worker Monitoring Article 4 Workers Statute MU-DPA-Data-Subject-Rights-Sections-26-33-Access-Rectification-Erasure-Restriction-Portability-Objection Mauritius DPA Subject Rights + Sections 26 to 33 + Access + Rectification + Erasure + Restriction + Portability + Objection MU-DPA-Seven-Principles-Section-21-Lawfulness-Purpose-Minimisation-Accuracy-Storage-Integrity-Accountability Mauritius DPA Seven Principles + Section 21 + Lawfulness + Purpose + Minimisation + Accuracy + Storage + Integrity + Accountability MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014 MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent MN-CDPA-Enforcement-AG-Ellison-Section-325O-10-USD-7500-Per-Violation-Data-Broker-Registration-325O-13-Sunset-25-Jan-2026 Minnesota CDPA Enforcement + AG Ellison + Section 325O.10 + USD 7,500 Per Violation + Data Broker Registration + Sunset 25 January 2026 MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification MT-CDPA-Privacy-Notice-MCA-30-14-2806-Categories-Purposes-Rights-Email-Online-Mechanism-Appeal Montana CDPA Privacy Notice + MCA 30-14-2806 + Categories + Purposes + Rights + Online Mechanism + Appeal MT-CDPA-Scope-SB-384-Gianforte-19-May-2023-Effective-1-October-2024-MCA-30-14-2801-AG-Knudsen-50K-Threshold Montana CDPA Scope + SB 384 + Gianforte 19 May 2023 + Effective 1 October 2024 + MCA 30-14-2801 + AG Knudsen + 50K Threshold NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions POPIASA-4 Special Personal Information, Children, Information Quality, Documentation NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement PERU-2 Consent, Privacy Notice, Sensitive Data PERU-5 Security of Personal Data and Processor Agreements NZPRV-2 IPP 5 Storage and Security of Personal Information NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design QATAR-3 Data Subject Rights QATAR-7 DPO, Records, Retention, Marketing, Training RIDTPPA-11 Data Minimisation and Purpose Limitation RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) SSAE18-P1.1 P1.1 - Privacy Notice SSAE18-P1.2 P1.2 - Choice and Consent PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2 TAIWAN-2 Consent, Notice, Sensitive Data TAIWAN-3 Data Subject Rights UKGDPRREG-2 Data Subject Rights (Articles 12-22) UKGDPRREG-3 Controller and Processor (Articles 24-43) USMCADIGITAL-1 Cross-Border Data Flows and Localisation USMCADIGITAL-2 Personal Information Protection and Consumer Protection UGA-13 Unlawful Obtaining or Disclosure UGA-15 Unauthorized Sale of Data URUGUAY-1 Scope, Lawful Basis, Consent URUGUAY-5 Database Registration with AGESIC URCDP VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) VIETNAMCYBER-4 Incident Reporting and Cooperation CPS234-21 Implementation of Information Security Controls AL-DPA-12 International Data Transfers §1798.150 Private Right of Action for Data Breaches CA-10 Selects and Develops Control Activities LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) FedRAMP-PII-Privacy FedRAMP PII processing + privacy controls (NIST 800-53 Rev 5 PT family + Privacy Act) CBPR-9-APEC-Privacy-Principles Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm) IEEE7000-Values-Elicitation-Prioritisation-IEEE7000Family-Bias-Privacy-Transparency IEEE 7000 Clauses 6 + 6.1 - Ethical Values Elicitation + Prioritisation + IEEE 7000 Family Integration (Bias + Privacy + Transparency + Wellbeing) 5.34 Privacy and protection of PII 7.4.9 PII transmission controls ISO23894-A.5 Privacy and Data Protection in AI A.4.5 System and computing resources INCDPA-Controller-PrivacyNotice-PurposeLimitation-DataMinimisation-Transparency-LawfulBasis Indiana CDPA Controller Obligations - Privacy Notice + Purpose Limitation + Data Minimisation + Transparency + Lawful Basis + Reasonable + Adequate + Relevant + Limited to What is Necessary JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response DOM172-Lawful-Basis-Consent-Notice-Information-Duty-Articles-4-12-Quality-Principle-Purpose-Limitation-Minimisation Dominican Republic Law 172-13 Lawful Basis + Consent + Notice + Information Duty + Articles 4-12 NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7 NISTAI600-7 Confabulation, Bias, Information Integrity, Privacy, IP (Risks 2, 4, 5, 6, 7, 8, 10, 11) NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management NGNDPR-2 Governing Principles, Lawful Basis, and Consent under NDPR Section 2.1-2.3 AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OMANCS-4 Data Protection, Cryptography, and Privacy Alignment PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training RCEPEC-1 Online Personal Information Protection (12.13) SOC-CY-DC2 Nature of Sensitive Information SAPAIA-4 Information Regulator Cooperation and Appeals STUDPRV-2 Data Subject Rights for Students and Parents TEFCAREC-1 Common Agreement Conformance and Onboarding TISAXASS-3 Prototype Protection and Confidentiality TEXASTDPSA-3 Sensitive Data, Children, Sale Notice TURKEYKVKK-2 Information Notice and Data Subject Rights UKAI-2 Sector-Specific Regulator Engagement OB-CX.2 Granular Consent Management UNICEFAI-4 Transparency, Explanation, Adult Capacity VIETNAMPDP-1 Scope, Categorisation, Lawful Basis VIRGINIAVCDPA-1 Scope, Applicability, Definitions SO3.2 Regulatory frameworks for digital health Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in APPI: Security Control and Supervision (Articles 22 to 26) You are reading one control. How much of APPI have you already done? APPI APPI-A23 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of APPI your existing evidence covers. Hold APEC Cross-Border Privacy Rules (CBPR) System and 16 of 30 APPI controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APEC Cross-Border Privacy Rules (CBPR) System pair alone.
Query this from an agent The graph holds this control, the 366 it maps to, and the evidence behind each claim, over MCP and REST.