Privacy Act 1988 (Australia)
Use and Disclosure

Privacy Act 1988 (Australia) AUPRV-3: APP 6-9 Use/Disclosure, Direct Marketing, Cross-Border, Government Identifiers

Per APPs 6-9: use + disclosure + marketing + cross-border + government identifiers. Requirements include (a) implement APP 6 - Use or Disclosure of Personal Information only for primary purpose collected unless data subject would reasonably expect or has consented + (b) implement APP 7 - Direct Marketing only where conditions met + opt-out mechanism + (c) implement APP 8 - Cross-Border Disclosure of Personal Information including reasonable steps that recipient does not breach APPs + (d) implement APP 9 - Adoption, Use, or Disclosure of Government Related Identifiers prohibited except in limited circumstances + (e) maintain records of use + disclosure + cross-border flows + (f) implement contractual + technical safeguards.

What else in your programme already covers this

This control maps to 41 controls across 37 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation

India DPDP Act · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

MTCS (Singapore) · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

NIST SP 800-122 · 1 control

  • NISTSP122-7 PII Sharing, Cross-Border Transfers, and Third-Party Agreements
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NGNDPR-7 Cross-Border Transfer of Personal Data under NDPR Section 2.7-CBT
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs

PDPA Singapore · 1 control

  • PDPASG-6 Transfer Limitation, Cross-Border Safeguards, and Data Intermediary Oversight

PDPA Thailand · 1 control

  • PDPATH-6 Cross-Border Transfer and Processor Engagement

POPIA · 1 control

  • POPIASA-6 Transborder Information Flows, Direct Marketing
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • NORWAY-6 International Transfers and Processor Agreements
  • RUSPD-4 Special Categories, Biometric Data

South Korea PIPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 41 it maps to, and the evidence behind each claim, over MCP and REST.