Frameworks / APPI / APPI-A26 APPI
APPI: Security Control and Supervision (Articles 22 to 26)
APPI APPI-A26: Report of Leakage to the Commission and Notification to the Person Report to the Personal Information Protection Commission and notify the identifiable person where a leakage, loss or damage of personal data or another situation prescribed by the Commission occurs.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 247 controls across 141 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions BE-CF-01 Account management and provisioning BE-CF-02 Access enforcement and least privilege BE-CF-06 Identity proofing and verification C5-IDM-07 Access to cloud customer data C5-SIM-01 Policy for security incident management C5-SIM-03 Documentation and reporting of security incidents IR-4 Incident Handling IR-6 Incident Reporting IR-8 Incident Response Plan IR-4 Incident Handling IR-6 Incident Reporting IR-8 Incident Response Plan GDPR-Art.31 Cooperation with the supervisory authority GDPR-Art.33 Notification of a personal data breach to the supervisory authority GDPR-Art.34 Communication of a personal data breach to the data subject GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment GhCSA-Incident-Reporting-CERT-GH Cybersecurity Incident Reporting (24-Hour to CSA) and National CERT-GH Engagement GhCSA-Scope-CSAGhana-Defs Scope, Cyber Security Authority (CSA Ghana) and Key Definitions IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures 5.24 Information security incident management planning and preparation 5.26 Response to information security incidents 5.5 Contact with authorities ISO27799-01 ePHI access controls and authorization ISO27799-08 Information access management ISO27799-17 Facility access controls ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures ISO27043-11 Access control policy and enforcement ISO27043-14 Privileged access management ISO27043-15 Access review and recertification ISO21434-12 User access management and provisioning ISO21434-14 Privileged access management ISO21434-15 Access review and recertification MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management MDS2-Physical-Security-PLOK-Workstation-Disposal-Backup-DTBK-Disaster-Recovery MDS2 Physical Security + PLOK + Workstation + Disposal + Backup + DTBK + Disaster Recovery NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training NISTSP66-5 Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches SOC2-P6.6 P6.6 Notifying breaches and incidents AWWA-2.1 User Access Management AWWA-2.4 Physical Access Controls CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents CIS-17.4 Establish and Maintain an Incident Response Process DSO-2 Data Security DSO-3 Data Access Management CAT-D3-1 Preventative controls CAT-D4-3 Third-party access controls ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) ICAO-ANX17-Chap4-AccessControl-AirsideRestricted-Personnel-Background ICAO Annex 17 Chapter 4 - Access Control + Airside + Security Restricted Area + Personnel Background Checks + Vetting 5.24 Information security incident management planning and preparation 5.26 Response to information security incidents 6.13.1 Management of information security incidents and improvements 7.3.1 Determining and fulfilling obligations to PII principals 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources 27011-5.3 Segregation of duties 27011-8.1 User Endpoint Devices NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security SUPCHAIN-1 Build Integrity - Source, Build, Provenance SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule ISMSP-AC-01 Access Control Policy ISMSP-AC-04 Network Access Control ANSSI-HYG-40 Define a Security Incident Management Procedure CBPR-PR-32 Detection, prevention and response measures CPS234-35 APRA Notification of Material Incidents within 72 Hours §1798.150 Private Right of Action for Data Breaches CA-ITSG33-SC-01 Security Control Catalogue LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour Part11.AccessAndAuth Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h)) FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance) FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel IACS-UR-E26-Protect-AccessControl-Authentication-IAM-Roles IACS UR E26 Protect Goal - Access Control + Identity + Authentication + Authorization + User Management IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment 62351-8 Role-based access control (RBAC) IEEE1686-Section5.1-AccessControl-Accounts-Roles-Password-Session-Remote IEEE 1686 Section 5.1 - Electronic Access Account Management + Roles + Password + Failed Login + Session + Remote Access + Personnel IMO-MSC-FAL-Protect-AccessControl-NetworkSegmentation-MalwareDefence-Patch-Awareness-DataSecurity IMO MSC-FAL Protect Function - Access Control + Network Segmentation + Malware Defence + Patch Management + Awareness Training + Data Security + Crew BYOD + Removable Media ISO28001-PS-01 Facility Security ISO20000-15 Access management for services A.8.4 Communication of incidents ITIL4-15 Access management for services INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing MU-DPA-Governance-DPO-Designation-Section-25-DPO-ROPA-DPIA-Codes-Section-38-Commissioner-Registration Mauritius DPA Governance + DPO + ROPA + DPIA + Codes Section 38 + Commissioner Registration MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014 MN-CDPA-Chief-Privacy-Officer-Section-325O-06-MN-UNIQUE-Designation-Privacy-Programme-Training Minnesota CDPA Chief Privacy Officer + Section 325O.06 + MINNESOTA-UNIQUE Designation + Privacy Programme + Training MT-CDPA-Sensitive-Data-MCA-30-14-2802-Opt-In-Children-13-Parental-Consent-Minors-13-16-Opt-In Montana CDPA Sensitive Data + MCA 30-14-2802 + Affirmative Opt-In + Children Under 13 Parental + Minors 13-16 Opt-In NAIC-2 Information Security Program (ISP) - Section 4 NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP123-3 Authentication, Access Control, and Account Management NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NHPA-7 Data Protection Assessments and Processor Contracts NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-3 Identity and Access Management, Authentication, Privileged Access OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working 12.10.1 12.10.1 Incident response plan ready for activation PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations PTESPHASE-2 Intelligence Gathering (OSINT) NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control PERU-7 DPO, Records, Retention, Marketing, Training NZPRV-2 IPP 5 Storage and Security of Personal Information QATAR-5 Security of Processing SHAREASSESS-2 Access Control, Identity, Authentication SOC-CY-S1 Logical and Physical Access Controls SA-PDPL-15 Access control for personal data SIGSTORE-2 Transparency Log (Rekor) and Verification PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 TSAPIPE-2 OT/IT Network Segmentation and Access Control TAIWAN-3 Data Subject Rights TEXASTDPSA-2 Consumer Rights TURKEYKVKK-2 Information Notice and Data Subject Rights UKGAMBLE-4 Resilience and Incident Response SEMD-PS-2 Site Security Measures UK-TSA-NET-02 Access Control and Authentication CPSC-CS.2 Authentication and Access Controls USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) US-ITAR-EAR-DS-03 Access Controls URUGUAY-3 Sensitive Data, Health Data, Children VIETNAMPDP-2 Consent and Notice VIRGINIAVCDPA-3 Sensitive Data Consent and Children Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in APPI: Security Control and Supervision (Articles 22 to 26) You are reading one control. How much of APPI have you already done? APPI APPI-A26 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of APPI your existing evidence covers. Hold APEC Cross-Border Privacy Rules (CBPR) System and 16 of 30 APPI controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APEC Cross-Border Privacy Rules (CBPR) System pair alone.
Query this from an agent The graph holds this control, the 247 it maps to, and the evidence behind each claim, over MCP and REST.