APPI
APPI: Third Party Provision and Records (Articles 27 to 31)

APPI APPI-A27: Restriction on Provision to Third Parties

Do not provide personal data to a third party without the prior consent of the identifiable person except in the cases the Act allows, and where the opt out route is used make the prescribed matters known and notify the Commission.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 118 controls across 77 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 4 controls

  • 7.2.3 Determine when and how consent is to be obtained
  • 7.2.4 Obtain and record consent
  • 7.3.5 Providing mechanism to object to PII processing
  • 7.5.4 Records of PII disclosure to third parties
  • MYHR-CUD-1 Authorised collection, use and disclosure only
  • MYHR-CUD-2 Prohibition on unauthorised collection, use and disclosure
  • MYHR-SEC-7 Consumer access controls and consent

CCPA/CPRA · 3 controls

  • §1798.115 Right to Know Personal Information Sold or Shared and Recipients
  • §1798.120 Right to Opt Out of Sale or Sharing of Personal Information
  • §1798.135(a) Do Not Sell or Share My Personal Information Link

GDPR · 3 controls

  • APP-5 APP 5 - Notification of the collection of personal information
  • APP-6 APP 6 - Use or disclosure of personal information
  • P1 Demonstrates Commitment to Integrity and Ethical Values
  • P7 Identifies and Analyzes Risk

FedRAMP High · 2 controls

  • AC-21 Information Sharing
  • AC-4 Information Flow Enforcement

FedRAMP Moderate · 2 controls

  • AC-21 Information Sharing
  • AC-4 Information Flow Enforcement

HITECH Act · 2 controls

  • HITECH-Scope-ARRA-XIII-42USC-Ch156-Subtitles HITECH Act Statutory Scope, ARRA Title XIII Origin and 42 USC Chapter 156 Structure (Subtitles A through D)
  • HITECH-SubtitleA-ONC-HIT-Standards-EHR-MU-PI HITECH Subtitle A - ONC, HIT Standards Committee, EHR Certification, Meaningful Use / Promoting Interoperability
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making

SOC 2 · 2 controls

  • 502 Interoperability with Assistive Technology
  • 707 Real-Time Text Functionality
  • CH-FADP-09 Notification of data files to the FDPIC
  • FADP-13 Right to Data Portability (Article 28)
  • SO2.3 Open-source health data standards
  • SO3.4 Standards and interoperability governance
  • P3-S3 Cooperative Arrangements/Procedures
  • DS-2 Ensure software supply chain security

Bahrain PDPL · 1 control

  • BB-DPA-14 Section 15 - Right to Data Portability
  • DIQ-1 Data Integration and Interoperability
  • LOPDP-EC-Data-Subject-Rights-Access-Rectification-Erasure-Object-Portability-Automated-Decisions-Articles-16-27 Ecuador LOPDP Data Subject Rights + Access + Rectification + Erasure + Articles 16-27
  • UAE-PDPL-Art.8 Records of processing activities (UAE PDPL Article 8)

ISO 27001:2022 · 1 control

  • 5.14 Information transfer

ISO 27002:2022 · 1 control

  • 5.14 Information transfer
  • ISO8000-MDG-01 Master Data Quality

India DPDP Act · 1 control

  • INCDPA-ConsumerRights-Access-Correction-Deletion-Portability-OptOut-TargetedAd-Sale-Profiling-Appeal-45Day Indiana CDPA Consumer Rights - Access + Correction + Deletion + Portability + Opt-Out of Targeted Advertising/Sale/Profiling + 45-Day Response + 45-Day Extension + Authorised Agent + Appeal Process

Indonesia PDP Law · 1 control

LGPD · 1 control

  • LGPD-BR-Data-Subject-Rights-Article-18-Confirmation-Access-Correction-Anonymization-Portability-Revoke-Sharing Brazil LGPD Data Subject Rights + Article 18 + 9 Rights + Confirmation + Anonymization
  • LV-PDPL-Data-Subject-Rights-Access-Correction-Erasure-Restriction-Portability-Objection-Sec18-Sec38 Latvia PDPL Data Subject Rights + Access + Correction + Erasure + Portability + Section 18 + 38
  • DOM172-Data-Subject-ARCO-Rights-Habeas-Data-Action-Constitutional-Article-70-Access-Rectification-Cancellation-Opposition Dominican Republic Law 172-13 ARCO Rights + Habeas Data Action + Constitutional Article 70

Liechtenstein DPA · 1 control

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-Security-Principle-Retention-Data-Integrity-Breach-Notification-72-Hour-Section-12B-2024-Amendment Malaysia PDPA Security + Retention + Data Integrity + Breach Notification 72 Hour + Section 12B + 2024 Amendment

Mauritius DPA · 1 control

  • MU-DPA-Data-Subject-Rights-Sections-26-33-Access-Rectification-Erasure-Restriction-Portability-Objection Mauritius DPA Subject Rights + Sections 26 to 33 + Access + Rectification + Erasure + Restriction + Portability + Objection

Mexico LFPDPPP · 1 control

  • MX-LFPDPPP-ARCO-Rights-Articles-22-25-Acceso-Rectificacion-Cancelacion-Oposicion-Reglamento-89-103 Mexico LFPDPPP ARCO Rights + Articles 22-25 + Acceso + Rectificacion + Cancelacion + Oposicion + Reglamento 89-103
  • MN-CDPA-Consumer-Rights-Section-325O-04-Access-Correct-Delete-Portability-List-Third-Parties-Opt-Out-Appeal-AIQUEST-Profile Minnesota CDPA Consumer Rights + Section 325O.04 + Access + Correct + Delete + Portability + List of Third Parties + Opt-Out + Appeal + AI Question Profile
  • MT-CDPA-Consumer-Rights-MCA-30-14-2807-Access-Correct-Delete-Portability-Opt-Out-Appeal-AG-Referral Montana CDPA Consumer Rights + MCA 30-14-2807 + Access + Correct + Delete + Portability + Opt-Out + Appeal + AG Referral
  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment

NIST SP 800-122 · 1 control

  • NISTSP122-3 PII Data Subject Rights and Automated Decision-Making
  • NRFCS-4 Consumer Privacy Rights, Consent, Marketing, and Loyalty Data
  • NHPA-4 Sensitive Data, Children, and Minors 13-16 Opt-In Consent
  • NJDPA-4 Sensitive Data, Children, and Adolescents 13-17 Opt-In
  • NGNDPR-4 Data Subject Rights and Automated Decision-Making
  • OREGONCPA-2 Consumer Rights: Access, Correction, Deletion, Portability, Opt-Out

PDPA Singapore · 1 control

  • PDPASG-3 Access, Correction, Data Portability, and Individual Rights

PDPA Thailand · 1 control

  • PDPATH-3 Data Subject Rights, Automated Decisions, Accuracy

POPIA · 1 control

  • POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions
  • NORWAY-2 Data Subject Rights and Automated Decision-Making

Peru DPL · 1 control

  • PERU-5 Security of Personal Data and Processor Agreements

Privacy Act 2020 · 1 control

  • NZPRV-3 IPP 6-8 Access, Correction, Accuracy

Qatar DPL · 1 control

  • QATAR-3 Data Subject Rights
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)

Saudi Arabia PDPL · 1 control

  • SA-PDPL-09 Right to data portability
  • IM8-DAT.3 Data Sharing and Transfer

South Korea PIPA · 1 control

  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37

Taiwan PDPA · 1 control

  • TAIWAN-2 Consent, Notice, Sensitive Data
  • TEXASTDPSA-1 Scope, Applicability, Exemptions

Turkey KVKK · 1 control

  • TURKEYKVKK-1 VERBIS Registration and Lawful Basis
  • Standard 9 Data Sharing
  • UKGDPRREG-2 Data Subject Rights (Articles 12-22)
  • OB-API.2 Open Data API Specification
  • CPSC-STD.4 Interoperability Safety

Uruguay DPL · 1 control

  • URUGUAY-2 Data Subject Rights (ARCO + Habeas Data)

Vietnam PDPD · 1 control

  • VIETNAMPDP-1 Scope, Categorisation, Lawful Basis

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-2 Consumer Rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in APPI: Third Party Provision and Records (Articles 27 to 31)

You are reading one control. How much of APPI have you already done?

APPI APPI-A27 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of APPI your existing evidence covers. Hold APEC Cross-Border Privacy Rules (CBPR) System and 16 of 30 APPI controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APEC Cross-Border Privacy Rules (CBPR) System pair alone.

Query this from an agent

The graph holds this control, the 118 it maps to, and the evidence behind each claim, over MCP and REST.