APPI: Third Party Provision and Records (Articles 27 to 31)
APPI APPI-A27: Restriction on Provision to Third Parties
Do not provide personal data to a third party without the prior consent of the identifiable person except in the cases the Act allows, and where the opt out route is used make the prescribed matters known and notify the Commission.
What else in your programme already covers this
This control maps to 123 controls across 80 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
NIST800-PT-4 Consent. Implement [organization-defined] for individuals to consent to the processing of their personally identifiable information prior to its collection that facilitate individuals' informed decision-making
You are reading one control. How much of APPI have you already done?
APPI APPI-A27 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of APPI your existing evidence covers. Hold APEC Cross-Border Privacy Rules (CBPR) System and 16 of 30 APPI controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APEC Cross-Border Privacy Rules (CBPR) System pair alone.