Frameworks / APPI / APPI-A33 APPI
APPI: Rights of Identifiable Persons (Articles 32 to 39)
APPI APPI-A33: Request for Disclosure of Retained Personal Data Disclose retained personal data and third party provision records without delay on the request of the identifiable person, in the method requested, and give notice of the reasons where disclosure is refused in whole or in part.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 304 controls across 115 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
GDPR-Art.10 Processing of personal data relating to criminal convictions GDPR-Art.11 Processing which does not require identification GDPR-Art.12 Transparent information, communication and modalities for rights GDPR-Art.15 Right of access by the data subject GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction GDPR-Art.20 Right to data portability GDPR-Art.9 Processing of special categories of personal data NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-4 Sensitive Data Processing Consent and Childrens Protections NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NDPA-7 Data Protection Assessments and Processor Contracts NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles NG-NDPA-4 Data Subject Rights and Automated Decision-Making NG-NDPA-5 Security of Processing, Breach Notification, and DPIA NG-NDPA-7 Cross-Border Data Transfers and International Cooperation SOC2-P3.1 P3.1 Collecting personal information consistent with objectives SOC2-P4.3 P4.3 Securely disposing of personal information SOC2-P5.1 P5.1 Data subject access SOC2-P6.1 P6.1 Disclosure to third parties with consent SOC2-P6.7 P6.7 Accounting of personal information held and disclosed APP-1 APP 1 - Open and transparent management of personal information APP-12 APP 12 - Access to personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) TANZANIA-1 Scope, Registration, Lawful Basis TANZANIA-3 Data Subject Rights TANZANIA-4 Security and Cross-Border TANZANIA-5 DPO, Governance, Breach TRINIDAD-1 Scope, Definitions, Commission TRINIDAD-3 Data Subject Rights TRINIDAD-4 Security, Accuracy TRINIDAD-5 Enforcement and Sanctions Standard 13 Nudge Techniques Standard 14 Connected Toys and Devices Standard 5 Detrimental Use of Data Standard 8 Data Minimisation AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing AZ-DPA-12 Article 13 - Cross-border transfer AZ-DPA-14 Article 16 - Liability for violations AZ-DPA-15 Article 17 - Dispute resolution BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-21 Sections 61-69 - Data Privacy Officer BE-DPA-11 Transposition of the Law Enforcement Directive BE-DPA-13 Corrective powers and administrative fines BE-DPA-5 Processing of special categories for substantial public interest §1798.110 Right to Know Categories and Specific Pieces of Personal Information Collected §1798.115 Right to Know Personal Information Sold or Shared and Recipients §1798.130(a)(2) 45-Day Response Window and Identity Verification FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) 7.3.6 Access, correction and/or erasure 7.3.8 Providing copy of PII processed 7.3.9 Handling requests 29100-6.10 Information security 29100-6.5 Use, retention and disclosure limitation 29100-6.9 Accountability 29134-1 Scope 29134-3 Terms and definitions 29134-9.1 PIA report structure IsraelPPL-CrossBorder-Transfer-Sec36-EU-Adequacy-Israel-Adequacy-SCCs-Reciprocity-Foreign-Recipient Israel POPL Cross-Border Transfer + Section 36 + Privacy Protection (Transfer of Data to Databases Abroad) Regulations 5761-2001 + EU Adequacy Decision (2011) + SCCs + Foreign Recipient Obligations + Reciprocity IsraelPPL-DataSubjectRights-Access-Correction-Information-Delivery-Sec13-14-23A-23C-Subject-Notification Israel POPL Data Subject Rights - Section 13 Right of Access + Section 14 Right of Correction + Section 23A-C Prohibition on Information Delivery + Notice Obligation + Right to Object + Amendment 13 Enhancements IsraelPPL-Database-Registration-Definition-Document-Security-Level-Classification-Sec7-8-PPA-Registry Israel POPL Database Registration + Section 7 Database Definitions + Section 8 Registration Requirement + Database Definition Document + Security Level Classification + PPA Public Registry + Amendment 13 Threshold Changes MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing MY-PDPA-Data-Subject-Rights-Access-Correction-Portability-Withdraw-Consent-Prevent-Marketing-Sections-30-43 Malaysia PDPA Subject Rights + Access + Correction + Portability + Withdraw Consent + Prevent Marketing + Sections 30 to 43 MY-PDPA-Seven-Personal-Data-Protection-Principles-General-Notice-Choice-Disclosure-Security-Retention-Data-Integrity-Access Malaysia PDPA Seven Principles + General + Notice and Choice + Disclosure + Security + Retention + Data Integrity + Access NISTSP122-4 PII Minimisation, Purpose Limitation, and Pseudonymisation NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP122-6 PII Breach Response and Incident Handling NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NHPA-6 Reasonable Data Security and Breach Response NHPA-7 Data Protection Assessments and Processor Contracts NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP NGOB-2 Customer Consent Management and Lifecycle NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs SASB-4 Social Capital (SC) SASB-SC-1 Customer Privacy and Data Security SASB-SOC-2 Customer Privacy SA-PDPL-13 Encryption of personal data SA-PDPL-15 Access control for personal data SA-PDPL-22 Privacy by design and default ISMSP-PI-01 Personal Information Collection ISMSP-PI-04 Cross-Border Transfer ISMSP-SYS-02 Encryption Implementation SWE-1 Scope and Purpose SWE-11 Integritetsskyddsmyndigheten (IMY) SWE-2 Relationship to GDPR UK-DPA18-GEN-04 UK-Specific Exemptions UK-DPA18-LE-02 Data Subject Rights (Law Enforcement) UK-DPA18-LE-03 International Transfers (Law Enforcement) 27400-5.4 Data and privacy risks 27400-7.3 Data minimization and purpose limitation 27557-3 Terms and definitions 27557-4.3 Individual impact consideration ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination ItalyCodice-SpecialCategories-Health-Workplace-Education-ScientificResearch-HistoricalResearch-Art75-92-96-99-101 Italy Codice Special Categories + Article 75 Administrative Fines + Article 92 Medical Records + Article 96 Education + Article 99 Scientific Research + Article 101 Historical Research + Workplace Privacy + Worker Monitoring Article 4 Workers Statute MU-DPA-Data-Subject-Rights-Sections-26-33-Access-Rectification-Erasure-Restriction-Portability-Objection Mauritius DPA Subject Rights + Sections 26 to 33 + Access + Rectification + Erasure + Restriction + Portability + Objection MU-DPA-Seven-Principles-Section-21-Lawfulness-Purpose-Minimisation-Accuracy-Storage-Integrity-Accountability Mauritius DPA Seven Principles + Section 21 + Lawfulness + Purpose + Minimisation + Accuracy + Storage + Integrity + Accountability MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014 MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent MN-CDPA-Enforcement-AG-Ellison-Section-325O-10-USD-7500-Per-Violation-Data-Broker-Registration-325O-13-Sunset-25-Jan-2026 Minnesota CDPA Enforcement + AG Ellison + Section 325O.10 + USD 7,500 Per Violation + Data Broker Registration + Sunset 25 January 2026 MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification MT-CDPA-Privacy-Notice-MCA-30-14-2806-Categories-Purposes-Rights-Email-Online-Mechanism-Appeal Montana CDPA Privacy Notice + MCA 30-14-2806 + Categories + Purposes + Rights + Online Mechanism + Appeal MT-CDPA-Scope-SB-384-Gianforte-19-May-2023-Effective-1-October-2024-MCA-30-14-2801-AG-Knudsen-50K-Threshold Montana CDPA Scope + SB 384 + Gianforte 19 May 2023 + Effective 1 October 2024 + MCA 30-14-2801 + AG Knudsen + 50K Threshold NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions POPIASA-4 Special Personal Information, Children, Information Quality, Documentation NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement PERU-2 Consent, Privacy Notice, Sensitive Data PERU-5 Security of Personal Data and Processor Agreements NZPRV-2 IPP 5 Storage and Security of Personal Information NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design QATAR-3 Data Subject Rights QATAR-7 DPO, Records, Retention, Marketing, Training RIDTPPA-11 Data Minimisation and Purpose Limitation RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) SSAE18-P1.1 P1.1 - Privacy Notice SSAE18-P1.2 P1.2 - Choice and Consent PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2 TAIWAN-2 Consent, Notice, Sensitive Data TAIWAN-3 Data Subject Rights UKGDPRREG-2 Data Subject Rights (Articles 12-22) UKGDPRREG-3 Controller and Processor (Articles 24-43) USMCADIGITAL-1 Cross-Border Data Flows and Localisation USMCADIGITAL-2 Personal Information Protection and Consumer Protection UGA-13 Unlawful Obtaining or Disclosure UGA-15 Unauthorized Sale of Data URUGUAY-1 Scope, Lawful Basis, Consent URUGUAY-5 Database Registration with AGESIC URCDP VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) VIETNAMCYBER-4 Incident Reporting and Cooperation AL-DPA-12 International Data Transfers DS-2 Ensure software supply chain security CA-10 Selects and Develops Control Activities CCM-DSP-11 Personal Data Access, Reversal, Rectification and Deletion LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) FedRAMP-PII-Privacy FedRAMP PII processing + privacy controls (NIST 800-53 Rev 5 PT family + Privacy Act) CBPR-9-APEC-Privacy-Principles Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm) IEEE7000-Values-Elicitation-Prioritisation-IEEE7000Family-Bias-Privacy-Transparency IEEE 7000 Clauses 6 + 6.1 - Ethical Values Elicitation + Prioritisation + IEEE 7000 Family Integration (Bias + Privacy + Transparency + Wellbeing) ISO23894-A.5 Privacy and Data Protection in AI INCDPA-Controller-PrivacyNotice-PurposeLimitation-DataMinimisation-Transparency-LawfulBasis Indiana CDPA Controller Obligations - Privacy Notice + Purpose Limitation + Data Minimisation + Transparency + Lawful Basis + Reasonable + Adequate + Relevant + Limited to What is Necessary JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response DOM172-Lawful-Basis-Consent-Notice-Information-Duty-Articles-4-12-Quality-Principle-Purpose-Limitation-Minimisation Dominican Republic Law 172-13 Lawful Basis + Consent + Notice + Information Duty + Articles 4-12 NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7 NISTAI600-7 Confabulation, Bias, Information Integrity, Privacy, IP (Risks 2, 4, 5, 6, 7, 8, 10, 11) NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management NGNDPR-2 Governing Principles, Lawful Basis, and Consent under NDPR Section 2.1-2.3 AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OMANCS-4 Data Protection, Cryptography, and Privacy Alignment PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training RCEPEC-1 Online Personal Information Protection (12.13) SOC-CY-DC2 Nature of Sensitive Information SAPAIA-4 Information Regulator Cooperation and Appeals STUDPRV-2 Data Subject Rights for Students and Parents TEFCAREC-1 Common Agreement Conformance and Onboarding TISAXASS-3 Prototype Protection and Confidentiality TEXASTDPSA-3 Sensitive Data, Children, Sale Notice TURKEYKVKK-2 Information Notice and Data Subject Rights UKAI-2 Sector-Specific Regulator Engagement OB-CX.2 Granular Consent Management UNICEFAI-4 Transparency, Explanation, Adult Capacity VIETNAMPDP-1 Scope, Categorisation, Lawful Basis VIRGINIAVCDPA-1 Scope, Applicability, Definitions SO3.2 Regulatory frameworks for digital health Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in APPI: Rights of Identifiable Persons (Articles 32 to 39) You are reading one control. How much of APPI have you already done? APPI APPI-A33 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of APPI your existing evidence covers. Hold APEC Cross-Border Privacy Rules (CBPR) System and 16 of 30 APPI controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APEC Cross-Border Privacy Rules (CBPR) System pair alone.
Query this from an agent The graph holds this control, the 304 it maps to, and the evidence behind each claim, over MCP and REST.