ISO 27701:2019
Additional ISO/IEC 27002 guidance for PII controllers, ISO 27701:2019

ISO 27701:2019 7.4.3: Accuracy and quality

The organization must make sure, and record, that personal data is kept as complete, accurate and current as its processing purposes need, throughout the data lifecycle, implementing policies, procedures or mechanisms that minimise inaccuracy and that respond to instances of inaccurate data, and including those in its documented information, for example through technical system configurations.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 43 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SOC 2 · 7 controls

  • SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13)
  • SOC2-P5.2 P5.2 Correction of personal information
  • SOC2-P7.1 P7.1 Quality of personal information
  • SOC2-PI1.2 PI1.2 Controls over system inputs
  • SOC2-PI1.3 PI1.3 Controls over system processing
  • SOC2-PI1.4 PI1.4 Controls over output delivery
  • SOC2-PI1.5 PI1.5 Controls over stored inputs, work in process and outputs

ISO 27001:2022 · 4 controls

  • 5.12 Classification of information
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 8.13 Information backup
  • 8.15 Logging

PCI DSS 4.0 · 4 controls

  • 10.2.1 10.2.1 Audit logging enabled on all system components
  • 10.5.1 10.5.1 Keep logs 12 months, latest three months online
  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 3.2.1 3.2.1 Data retention and disposal minimise stored account data

APPI · 2 controls

  • APPI-A22 Accuracy and Deletion of Personal Data
  • APPI-A34 Request for Correction, Addition or Deletion
  • AUCDR-PS-11 Privacy Safeguard 11 - Quality of CDR data
  • AUCDR-PS-13 Privacy Safeguard 13 - Correction of CDR data
  • APP-10 APP 10 - Quality of personal information
  • APP-13 APP 13 - Correction of personal information

GDPR · 2 controls

  • 25012-Accuracy Accuracy
  • ISO-25012-4.1 Accuracy

ISO/IEC 29100:2024 · 2 controls

  • 29100-6.6 Accuracy and quality
  • ISO29100-5.10.6 Accuracy and Quality

NIST SP 800-53 Rev 5 · 2 controls

  • NIST800-PM-22 PM-22 Personally Identifiable Information Quality Management
  • NIST800-SI-18 SI-18 Personally Identifiable Information Quality Operations

CCPA/CPRA · 1 control

  • §1798.106 Right to Correct Inaccurate Personal Information
  • SD134-7 Accuracy and Quality

FedRAMP High · 1 control

  • SI-10 Information Input Validation

FedRAMP Moderate · 1 control

  • SI-10 Information Input Validation

ISO 14001:2015 · 1 control

  • 7.4.3 External communication

ISO 22000:2018 · 1 control

  • 7.4.3 Internal communication

ISO 27002:2022 · 1 control

  • 5.34 Privacy and protection of PII

ISO 45001:2018 · 1 control

  • 7.4.3 External communication
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • 161R1-PM-22 Personally Identifiable Information Quality Management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Additional ISO/IEC 27002 guidance for PII controllers, ISO 27701:2019

You are reading one control. How much of ISO 27701:2019 have you already done?

ISO 27701:2019 7.4.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27701:2019 your existing evidence covers. Hold SOC 2 and 58 of 108 ISO 27701:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 289 were rejected on the SOC 2 pair alone.

Query this from an agent

The graph holds this control, the 43 it maps to, and the evidence behind each claim, over MCP and REST.