Australian Privacy Principles (APPs)
Part 5 - Access to, and Correction of, Personal Information

Australian Privacy Principles (APPs) APP-12: APP 12 - Access to personal information

Give individuals access to their personal information on request, subject to exceptions.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 22 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

APPI · 4 controls

  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APPI-A36 Explanation of Reasons for a Response to a Request
  • APPI-A37 Procedure for Receiving Requests
  • APPI-A38 Fees for Disclosure and Notification of Purpose

ISO 27701:2019 · 4 controls

  • 7.3.1 Determining and fulfilling obligations to PII principals
  • 7.3.6 Access, correction and/or erasure
  • 7.3.8 Providing copy of PII processed
  • 7.3.9 Handling requests

CCPA/CPRA · 3 controls

  • MYHR-REG-2 Healthcare recipient registration and identity verification
  • MYHR-SEC-7 Consumer access controls and consent

GDPR · 2 controls

  • GDPR-Art.12 Transparent information, communication and modalities for rights
  • GDPR-Art.15 Right of access by the data subject
  • 23 s 23 Worker access to surveillance records on written request
  • core-12.2 Information management: participants told about storage, access, correction and withdrawal
  • CCM-DSP-11 Personal Data Access, Reversal, Rectification and Deletion
  • s459A-C s 459A and s 459C Correct inaccurate or out-of-date listings within 7 days and give copies within 14 days

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Part 5 - Access to, and Correction of, Personal Information

You are reading one control. How much of Australian Privacy Principles (APPs) have you already done?

Australian Privacy Principles (APPs) APP-12 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Australian Privacy Principles (APPs) your existing evidence covers. Hold GDPR and 11 of 13 Australian Privacy Principles (APPs) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the GDPR pair alone.

Query this from an agent

The graph holds this control, the 22 it maps to, and the evidence behind each claim, over MCP and REST.