Privacy Act 1988 (Australia)
Individual Rights

Privacy Act 1988 (Australia) AUPRV-5: APP 12-13 Access and Correction of Personal Information

Per APPs 12-13: access + correction. Requirements include (a) implement APP 12 - Access to Personal Information - upon request give access to personal information unless an exception applies + (b) implement APP 13 - Correction of Personal Information - upon request correct personal information that is inaccurate + out-of-date + incomplete + irrelevant + misleading + (c) maintain mechanism for receiving + verifying + responding to access + correction requests within statutory timelines + (d) handle refusals consistent with the Act + provide written notice of reasons + (e) maintain records of requests + responses + (f) integrate with complaint handling.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 45 controls across 40 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

HITECH Act · 2 controls

  • HITECH-Scope-ARRA-XIII-42USC-Ch156-Subtitles HITECH Act Statutory Scope, ARRA Title XIII Origin and 42 USC Chapter 156 Structure (Subtitles A through D)
  • HITECH-SubtitleA-ONC-HIT-Standards-EHR-MU-PI HITECH Subtitle A - ONC, HIT Standards Committee, EHR Certification, Meaningful Use / Promoting Interoperability
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • 502 Interoperability with Assistive Technology
  • 707 Real-Time Text Functionality
  • LOPDP-EC-Data-Subject-Rights-Access-Rectification-Erasure-Object-Portability-Automated-Decisions-Articles-16-27 Ecuador LOPDP Data Subject Rights + Access + Rectification + Erasure + Articles 16-27
  • UAE-PDPL-Art.8 Records of processing activities (UAE PDPL Article 8)

India DPDP Act · 1 control

  • INCDPA-ConsumerRights-Access-Correction-Deletion-Portability-OptOut-TargetedAd-Sale-Profiling-Appeal-45Day Indiana CDPA Consumer Rights - Access + Correction + Deletion + Portability + Opt-Out of Targeted Advertising/Sale/Profiling + 45-Day Response + 45-Day Extension + Authorised Agent + Appeal Process

Indonesia PDP Law · 1 control

LGPD · 1 control

  • LGPD-BR-Data-Subject-Rights-Article-18-Confirmation-Access-Correction-Anonymization-Portability-Revoke-Sharing Brazil LGPD Data Subject Rights + Article 18 + 9 Rights + Confirmation + Anonymization
  • LV-PDPL-Data-Subject-Rights-Access-Correction-Erasure-Restriction-Portability-Objection-Sec18-Sec38 Latvia PDPL Data Subject Rights + Access + Correction + Erasure + Portability + Section 18 + 38
  • DOM172-Data-Subject-ARCO-Rights-Habeas-Data-Action-Constitutional-Article-70-Access-Rectification-Cancellation-Opposition Dominican Republic Law 172-13 ARCO Rights + Habeas Data Action + Constitutional Article 70

Liechtenstein DPA · 1 control

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-Security-Principle-Retention-Data-Integrity-Breach-Notification-72-Hour-Section-12B-2024-Amendment Malaysia PDPA Security + Retention + Data Integrity + Breach Notification 72 Hour + Section 12B + 2024 Amendment

Mauritius DPA · 1 control

  • MU-DPA-Data-Subject-Rights-Sections-26-33-Access-Rectification-Erasure-Restriction-Portability-Objection Mauritius DPA Subject Rights + Sections 26 to 33 + Access + Rectification + Erasure + Restriction + Portability + Objection

Mexico LFPDPPP · 1 control

  • MX-LFPDPPP-ARCO-Rights-Articles-22-25-Acceso-Rectificacion-Cancelacion-Oposicion-Reglamento-89-103 Mexico LFPDPPP ARCO Rights + Articles 22-25 + Acceso + Rectificacion + Cancelacion + Oposicion + Reglamento 89-103
  • MN-CDPA-Consumer-Rights-Section-325O-04-Access-Correct-Delete-Portability-List-Third-Parties-Opt-Out-Appeal-AIQUEST-Profile Minnesota CDPA Consumer Rights + Section 325O.04 + Access + Correct + Delete + Portability + List of Third Parties + Opt-Out + Appeal + AI Question Profile
  • MT-CDPA-Consumer-Rights-MCA-30-14-2807-Access-Correct-Delete-Portability-Opt-Out-Appeal-AG-Referral Montana CDPA Consumer Rights + MCA 30-14-2807 + Access + Correct + Delete + Portability + Opt-Out + Appeal + AG Referral
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment

NIST SP 800-122 · 1 control

  • NISTSP122-3 PII Data Subject Rights and Automated Decision-Making
  • NRFCS-4 Consumer Privacy Rights, Consent, Marketing, and Loyalty Data
  • NHPA-4 Sensitive Data, Children, and Minors 13-16 Opt-In Consent
  • NJDPA-4 Sensitive Data, Children, and Adolescents 13-17 Opt-In
  • NGNDPR-4 Data Subject Rights and Automated Decision-Making
  • OREGONCPA-2 Consumer Rights: Access, Correction, Deletion, Portability, Opt-Out

PDPA Singapore · 1 control

  • PDPASG-3 Access, Correction, Data Portability, and Individual Rights

PDPA Thailand · 1 control

  • PDPATH-3 Data Subject Rights, Automated Decisions, Accuracy

POPIA · 1 control

  • POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions
  • NORWAY-2 Data Subject Rights and Automated Decision-Making

Peru DPL · 1 control

  • PERU-5 Security of Personal Data and Processor Agreements

South Korea PIPA · 1 control

  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • VERMONTAICDA-1 AI System Inventory and Risk Assessment

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 45 it maps to, and the evidence behind each claim, over MCP and REST.