APPI
APPI: Security Control and Supervision (Articles 22 to 26)

APPI APPI-A26: Report of Leakage to the Commission and Notification to the Person

Report to the Personal Information Protection Commission and notify the identifiable person where a leakage, loss or damage of personal data or another situation prescribed by the Commission occurs.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 247 controls across 141 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

MARS-E · 4 controls

NIST SP 800-53 Rev 5 · 4 controls

API 1164 · 3 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management

BSI IT-Grundschutz · 3 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BE-CF-01 Account management and provisioning
  • BE-CF-02 Access enforcement and least privilege
  • BE-CF-06 Identity proofing and verification

C5 (Germany) · 3 controls

  • C5-IDM-07 Access to cloud customer data
  • C5-SIM-01 Policy for security incident management
  • C5-SIM-03 Documentation and reporting of security incidents

FedRAMP High · 3 controls

  • IR-4 Incident Handling
  • IR-6 Incident Reporting
  • IR-8 Incident Response Plan

FedRAMP Moderate · 3 controls

  • IR-4 Incident Handling
  • IR-6 Incident Reporting
  • IR-8 Incident Response Plan

GDPR · 3 controls

  • GDPR-Art.31 Cooperation with the supervisory authority
  • GDPR-Art.33 Notification of a personal data breach to the supervisory authority
  • GDPR-Art.34 Communication of a personal data breach to the data subject
  • GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment
  • GhCSA-Incident-Reporting-CERT-GH Cybersecurity Incident Reporting (24-Hour to CSA) and National CERT-GH Engagement
  • GhCSA-Scope-CSAGhana-Defs Scope, Cyber Security Authority (CSA Ghana) and Key Definitions

IEC 62443 · 3 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures

ISO 27001:2022 · 3 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.26 Response to information security incidents
  • 5.5 Contact with authorities

ISO 27799:2025 · 3 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-08 Information access management
  • ISO27799-17 Facility access controls

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification

ISO/SAE 21434 · 3 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification

MDS2 (Medical Device) · 3 controls

  • MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS
  • MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management
  • MDS2-Physical-Security-PLOK-Workstation-Disposal-Backup-DTBK-Disaster-Recovery MDS2 Physical Security + PLOK + Workstation + Disposal + Backup + DTBK + Disaster Recovery

NIST SP 1800-32 · 3 controls

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-66 · 3 controls

  • NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training
  • NISTSP66-5 Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls
  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication

SOC 2 · 3 controls

  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches
  • SOC2-P6.6 P6.6 Notifying breaches and incidents
  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls

CIS Controls v8 · 2 controls

  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-AccessControl-AirsideRestricted-Personnel-Background ICAO Annex 17 Chapter 4 - Access Control + Airside + Security Restricted Area + Personnel Background Checks + Vetting

ISO 27002:2022 · 2 controls

  • 5.24 Information security incident management planning and preparation
  • 5.26 Response to information security incidents

ISO 27701:2019 · 2 controls

  • 6.13.1 Management of information security incidents and improvements
  • 7.3.1 Determining and fulfilling obligations to PII principals

ISO/IEC 27010:2015 · 2 controls

  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 2 controls

  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices

MITRE ATT&CK · 2 controls

  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles

OWASP ASVS · 2 controls

  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

SLSA · 2 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule

South Korea ISMS-P · 2 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-04 Network Access Control
  • ANSSI-HYG-40 Define a Security Incident Management Procedure
  • CBPR-PR-32 Detection, prevention and response measures

APRA CPS 234 · 1 control

  • CPS234-35 APRA Notification of Material Incidents within 72 Hours

Bahrain PDPL · 1 control

CCPA/CPRA · 1 control

  • §1798.150 Private Right of Action for Data Breaches

CMMC 2.0 · 1 control

  • CA-ITSG33-SC-01 Security Control Catalogue
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour

FDA 21 CFR Part 11 · 1 control

  • Part11.AccessAndAuth Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h))

FISMA · 1 control

  • FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)

FedRAMP Rev 5 · 1 control

  • FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)

HIPAA Security Rule · 1 control

HITECH Act · 1 control

  • HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC
  • HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel
  • IACS-UR-E26-Protect-AccessControl-Authentication-IAM-Roles IACS UR E26 Protect Goal - Access Control + Identity + Authentication + Authorization + User Management
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • 62351-8 Role-based access control (RBAC)

IEEE 1686 · 1 control

  • IEEE1686-Section5.1-AccessControl-Accounts-Roles-Password-Session-Remote IEEE 1686 Section 5.1 - Electronic Access Account Management + Roles + Password + Failed Login + Session + Remote Access + Personnel
  • IMO-MSC-FAL-Protect-AccessControl-NetworkSegmentation-MalwareDefence-Patch-Awareness-DataSecurity IMO MSC-FAL Protect Function - Access Control + Network Segmentation + Malware Defence + Patch Management + Awareness Training + Data Security + Crew BYOD + Removable Media
  • ISO28001-PS-01 Facility Security
  • ISO20000-15 Access management for services

ISO/IEC 42001:2023 · 1 control

  • A.8.4 Communication of incidents

ITIL 4 · 1 control

  • ITIL4-15 Access management for services

India DPDP Act · 1 control

  • INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification

Indonesia PDP Law · 1 control

LGPD · 1 control

  • LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response
  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification

Liechtenstein DPA · 1 control

MITRE D3FEND · 1 control

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing

Mauritius DPA · 1 control

  • MU-DPA-Governance-DPO-Designation-Section-25-DPO-ROPA-DPIA-Codes-Section-38-Commissioner-Registration Mauritius DPA Governance + DPO + ROPA + DPIA + Codes Section 38 + Commissioner Registration

Mexico LFPDPPP · 1 control

  • MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014
  • MN-CDPA-Chief-Privacy-Officer-Section-325O-06-MN-UNIQUE-Designation-Privacy-Programme-Training Minnesota CDPA Chief Privacy Officer + Section 325O.06 + MINNESOTA-UNIQUE Designation + Privacy Programme + Training
  • MT-CDPA-Sensitive-Data-MCA-30-14-2802-Opt-In-Children-13-Parental-Consent-Minors-13-16-Opt-In Montana CDPA Sensitive Data + MCA 30-14-2802 + Affirmative Opt-In + Children Under 13 Parental + Minors 13-16 Opt-In
  • NAIC-2 Information Security Program (ISP) - Section 4
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-122 · 1 control

  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit

NIST SP 800-123 · 1 control

  • NISTSP123-3 Authentication, Access Control, and Account Management

NIST SP 800-137 · 1 control

  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring
  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP MASVS · 1 control

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture

OWASP Top 10:2025 · 1 control

  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access

OpenSSF Scorecard · 1 control

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PCI DSS 4.0 · 1 control

  • 12.10.1 12.10.1 Incident response plan ready for activation

PDPA Singapore · 1 control

  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 1 control

  • PDPATH-5 Security Measures and Data Protection

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

PTES · 1 control

  • PTESPHASE-2 Intelligence Gathering (OSINT)
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information

Qatar DPL · 1 control

  • QATAR-5 Security of Processing
  • SHAREASSESS-2 Access Control, Identity, Authentication
  • SOC-CY-S1 Logical and Physical Access Controls

Saudi Arabia PDPL · 1 control

  • SA-PDPL-15 Access control for personal data
  • SIGSTORE-2 Transparency Log (Rekor) and Verification

South Korea PIPA · 1 control

  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Taiwan PDPA · 1 control

  • TAIWAN-3 Data Subject Rights
  • TEXASTDPSA-2 Consumer Rights

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • UKGAMBLE-4 Resilience and Incident Response
  • UK-TSA-NET-02 Access Control and Authentication
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • US-ITAR-EAR-DS-03 Access Controls

Uruguay DPL · 1 control

  • URUGUAY-3 Sensitive Data, Health Data, Children

Vietnam PDPD · 1 control

  • VIETNAMPDP-2 Consent and Notice

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-3 Sensitive Data Consent and Children

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in APPI: Security Control and Supervision (Articles 22 to 26)

You are reading one control. How much of APPI have you already done?

APPI APPI-A26 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of APPI your existing evidence covers. Hold APEC Cross-Border Privacy Rules (CBPR) System and 16 of 30 APPI controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APEC Cross-Border Privacy Rules (CBPR) System pair alone.

Query this from an agent

The graph holds this control, the 247 it maps to, and the evidence behind each claim, over MCP and REST.