Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
DSP - Data Security & Privacy Lifecycle Management

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-DSP-11: Personal Data Access, Reversal, Rectification and Deletion

Give data subjects a working route to request access to, correction of or deletion of their personal data, and fulfil those requests as applicable law requires.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 39 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SOC 2 · 7 controls

  • SOC2-P2.1 P2.1 Choice and consent
  • SOC2-P3.2 P3.2 Explicit consent before collecting information that requires it
  • SOC2-P5.1 P5.1 Data subject access
  • SOC2-P5.2 P5.2 Correction of personal information
  • SOC2-P6.7 P6.7 Accounting of personal information held and disclosed
  • SOC2-P7.1 P7.1 Quality of personal information
  • SOC2-P8.1 P8.1 Inquiries, complaints, disputes and compliance monitoring

ISO 27701:2019 · 5 controls

  • 7.3.1 Determining and fulfilling obligations to PII principals
  • 7.3.6 Access, correction and/or erasure
  • 7.3.8 Providing copy of PII processed
  • 7.3.9 Handling requests
  • 8.3.1 Obligations to PII principals

APPI · 4 controls

  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APPI-A34 Request for Correction, Addition or Deletion
  • APPI-A35 Request for Cessation of Use, Erasure or Cessation of Third Party Provision
  • APPI-A37 Procedure for Receiving Requests

GDPR · 4 controls

  • MYHR-GOV-5 Retention, destruction and correction obligations of the System Operator
  • MYHR-REG-2 Healthcare recipient registration and identity verification
  • MYHR-SEC-7 Consumer access controls and consent
  • APP-12 APP 12 - Access to personal information
  • APP-13 APP 13 - Correction of personal information

EU AI Act · 2 controls

  • EUAI-Art.61 Informed consent to participate in testing in real world conditions outside AI regulatory sandboxes
  • EUAI-Art.86 Right to explanation of individual decision-making

NIST SP 800-53 Rev 5 · 2 controls

  • AUCDR-PS-13 Privacy Safeguard 13 - Correction of CDR data

C5 (Germany) · 1 control

DORA · 1 control

ISO 27001:2022 · 1 control

  • 5.34 Privacy and protection of personal identifiable information (PII)

ISO 27002:2022 · 1 control

  • 5.34 Privacy and protection of PII

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DSP - Data Security & Privacy Lifecycle Management

You are reading one control. How much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 have you already done?

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-DSP-11 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 140 of 197 Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 12 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 39 it maps to, and the evidence behind each claim, over MCP and REST.