APPI
APPI: Third Party Provision and Records (Articles 27 to 31)

APPI APPI-A27: Restriction on Provision to Third Parties

Do not provide personal data to a third party without the prior consent of the identifiable person except in the cases the Act allows, and where the opt out route is used make the prescribed matters known and notify the Commission.

What else in your programme already covers this

This control maps to 123 controls across 80 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 4 controls

  • 7.2.3 Determine when and how consent is to be obtained
  • 7.2.4 Obtain and record consent
  • 7.3.5 Providing mechanism to object to PII processing
  • 7.5.4 Records of PII disclosure to third parties
  • MYHR-CUD-1 Authorised collection, use and disclosure only
  • MYHR-CUD-2 Prohibition on unauthorised collection, use and disclosure
  • MYHR-SEC-7 Consumer access controls and consent

CCPA/CPRA · 3 controls

  • §1798.115 Right to Know Personal Information Sold or Shared and Recipients
  • §1798.120 Right to Opt Out of Sale or Sharing of Personal Information
  • §1798.135(a) Do Not Sell or Share My Personal Information Link

GDPR · 3 controls

  • APP-5 APP 5 - Notification of the collection of personal information
  • APP-6 APP 6 - Use or disclosure of personal information
  • P1 Demonstrates Commitment to Integrity and Ethical Values
  • P7 Identifies and Analyzes Risk

FedRAMP High · 2 controls

  • AC-21 Information Sharing
  • AC-4 Information Flow Enforcement

FedRAMP Moderate · 2 controls

  • AC-21 Information Sharing
  • AC-4 Information Flow Enforcement

HITECH Act · 2 controls

  • AC-21 Information Sharing
  • AC-4 Information Flow Enforcement
  • AC-21 Information Sharing
  • AC-4 Information Flow Enforcement
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making

SOC 2 · 2 controls

  • SOC2-P2.1 Consent is obtained for the collection, use, and disclosure of personal information
  • SOC2-P6.1 Personal information is disclosed to third parties only as committed
  • 502 Interoperability with Assistive Technology
  • 707 Real-Time Text Functionality
  • CH-FADP-09 Notification of data files to the FDPIC
  • FADP-13 Right to Data Portability (Article 28)
  • SO2.3 Open-source health data standards
  • SO3.4 Standards and interoperability governance
  • P3-S3 Cooperative Arrangements/Procedures
  • DS-2 Ensure software supply chain security

Bahrain PDPL · 1 control

  • BB-DPA-14 Section 15 - Right to Data Portability
  • DIQ-1 Data Integration and Interoperability

ISO 27001:2022 · 1 control

  • 5.14 Information transfer

ISO 27002:2022 · 1 control

  • 5.14 Information transfer

India DPDP Act · 1 control

Indonesia PDP Law · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment

NIST SP 800-122 · 1 control

  • NISTSP122-3 PII Data Subject Rights and Automated Decision-Making
  • NIST800-PT-4 Consent. Implement [organization-defined] for individuals to consent to the processing of their personally identifiable information prior to its collection that facilitate individuals' informed decision-making
  • NRFCS-4 Consumer Privacy Rights, Consent, Marketing, and Loyalty Data
  • NHPA-4 Sensitive Data, Children, and Minors 13-16 Opt-In Consent
  • NJDPA-4 Sensitive Data, Children, and Adolescents 13-17 Opt-In
  • NGNDPR-4 Data Subject Rights and Automated Decision-Making
  • OREGONCPA-2 Consumer Rights: Access, Correction, Deletion, Portability, Opt-Out

PDPA Singapore · 1 control

  • PDPASG-3 Access, Correction, Data Portability, and Individual Rights

PDPA Thailand · 1 control

  • PDPATH-3 Data Subject Rights, Automated Decisions, Accuracy

POPIA · 1 control

  • POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions
  • NORWAY-2 Data Subject Rights and Automated Decision-Making

Peru DPL · 1 control

  • PERU-5 Security of Personal Data and Processor Agreements

Privacy Act 2020 · 1 control

  • NZPRV-3 IPP 6-8 Access, Correction, Accuracy

Qatar DPL · 1 control

  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)

Saudi Arabia PDPL · 1 control

South Korea PIPA · 1 control

Taiwan PDPA · 1 control

  • TAIWAN-2 Consent, Notice, Sensitive Data

Turkey KVKK · 1 control

Uruguay DPL · 1 control

  • URUGUAY-2 Data Subject Rights (ARCO + Habeas Data)

Vietnam PDPD · 1 control

Virginia CDPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in APPI: Third Party Provision and Records (Articles 27 to 31)

You are reading one control. How much of APPI have you already done?

APPI APPI-A27 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of APPI your existing evidence covers. Hold APEC Cross-Border Privacy Rules (CBPR) System and 16 of 30 APPI controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APEC Cross-Border Privacy Rules (CBPR) System pair alone.

Query this from an agent

The graph holds this control, the 123 it maps to, and the evidence behind each claim, over MCP and REST.