Skip to content

Evidence request lists

APPI

Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

APPI: Anonymized Personal Information (Articles 43 to 46)

APPI-A43
Preparation of Anonymized Personal Information

Where anonymized personal information is prepared, process the personal information to the Commission standards so that the person cannot be identified and the original cannot be restored, secure the deleted information and processing method, and publicly announce the categories of information contained.

Artefacts an auditor will ask for
  • Anonymization standard and processing specification
  • Re identification risk assessment
  • Public announcement of the categories of information contained
  • Security control measures over the deleted information and processing method
Where this commonly fails
  • Anonymization asserted without a risk assessment
  • Categories of information not publicly announced
  • Processing method retained without safeguards
APPI-A44
Disclosure When Providing Anonymized Personal Information

Before providing anonymized personal information to a third party, publicly announce the categories of information contained and the method of provision, and expressly state to the recipient that the information is anonymized personal information.

Artefacts an auditor will ask for
  • Public announcement covering the categories and the provision method
  • Contract or transmittal wording stating the information is anonymized personal information
  • Register of provisions made
Where this commonly fails
  • Anonymized data shared without the public announcement
  • Recipient not told the data is anonymized personal information
  • No register of provisions
APPI-A45
Prohibition on Re Identification

When handling anonymized personal information, do not acquire the deleted identifiers or the processing method, and do not collate the anonymized information with other information in order to identify the person.

Artefacts an auditor will ask for
  • Handling rules prohibiting re identification and collation
  • Technical separation between anonymized data sets and identifying data
  • Contractual prohibition passed to recipients
  • Training and attestation records
Where this commonly fails
  • No prohibition communicated to analytics teams or recipients
  • Anonymized data stored alongside identifying data
  • Prohibition stated in policy only with no technical control
APPI-A46
Security and Proper Handling of Anonymized Personal Information

Endeavour to take the necessary and appropriate measures for the security control of anonymized personal information and to make the content of those measures publicly available.

Artefacts an auditor will ask for
  • Security control measures applied to anonymized data sets
  • Public statement of the measures taken
  • Complaint handling route covering anonymized information
Where this commonly fails
  • Anonymized data treated as out of scope for security control
  • Measures taken but not published
  • No handling procedure for received anonymized data

APPI: Complaint Handling (Article 40)

APPI-A40
Processing of Complaints

Endeavour to process complaints about the handling of personal information appropriately and promptly, and to establish the system necessary to achieve that purpose.

Artefacts an auditor will ask for
  • Complaint handling procedure with target response times
  • Complaint register with outcomes
  • Evidence of the resources or system established for complaint handling
  • Trend analysis of complaints feeding improvement
Where this commonly fails
  • Complaints handled through a general customer service queue with no privacy specific route
  • No complaint register
  • Complaint outcomes not analysed

APPI: Pseudonymized Personal Information (Articles 41 and 42)

APPI-A41
Preparation and Handling of Pseudonymized Personal Information

Where pseudonymized personal information is prepared, process the personal information to the Commission standards, secure the deleted information and processing method, limit use to the purpose, and delete the data when no longer needed.

Artefacts an auditor will ask for
  • Pseudonymization standard and processing specification
  • Security control measures over the deletion information and processing method
  • Purpose of use statement for the pseudonymized data
  • Deletion records
  • Prohibition on identification attempts embedded in procedures
Where this commonly fails
  • Pseudonymization performed without a documented standard
  • Deletion information stored alongside the pseudonymized data
  • Use of pseudonymized data not restricted to the stated purpose
APPI-A42
Restriction on Providing Pseudonymized Personal Information

Do not provide pseudonymized personal information to a third party except in the cases based on laws and regulations, and do not contact the identifiable person or attempt identification.

Artefacts an auditor will ask for
  • Controls preventing external transfer of pseudonymized data
  • Register of any provision made and the legal basis
  • Prohibition on identification and contact embedded in handling rules
  • Training for teams handling pseudonymized data
Where this commonly fails
  • Pseudonymized data shared with analytics partners
  • Identification prohibition not communicated
  • No register of provisions

APPI: Purpose Specification and Acquisition (Articles 17 to 21)

APPI-A17
Specification of the Purpose of Use

Specify the purpose of use of personal information as far as possible, and do not change it beyond a scope reasonably related to the purpose before the change.

Artefacts an auditor will ask for
  • Purpose of use statement for each processing activity
  • Record of purpose changes and the relatedness assessment
  • Privacy notice showing the specified purpose
Where this commonly fails
  • Purpose stated only in broad terms such as business use
  • Purpose changed without a relatedness assessment
  • No record linking each data set to its specified purpose
APPI-A18
Restriction on Handling Beyond the Purpose of Use

Do not handle personal information beyond the scope necessary to achieve the specified purpose of use without the prior consent of the identifiable person, and apply the same restriction to information acquired through a business succession.

Artefacts an auditor will ask for
  • Consent records for handling beyond the purpose
  • Processing inventory mapped to the specified purpose
  • Due diligence record for personal information received through a merger or business transfer
  • Assessment against the statutory exceptions relied on
Where this commonly fails
  • Secondary use without consent or a stated exception
  • Data acquired in an acquisition used for the acquirer purposes without assessment
  • Exceptions relied on but not documented
APPI-A19
Prohibition of Improper Use

Do not use personal information by a method that may encourage or induce an unlawful or unjust act.

Artefacts an auditor will ask for
  • Acceptable use policy for personal information
  • Review of profiling, scoring and targeting use cases
  • Escalation records for use cases rejected on this ground
Where this commonly fails
  • No review of downstream use cases
  • Profiling and scoring uses never assessed for improper use
  • Policy exists but no evidence of application
APPI-A20
Proper Acquisition and Special Care Required Personal Information

Do not acquire personal information by deceptive or other wrongful means, and do not acquire special care required personal information without the prior consent of the identifiable person except in the cases the Act allows.

Artefacts an auditor will ask for
  • Acquisition channel inventory with a lawfulness assessment
  • Consent records for special care required personal information
  • Classification rules identifying special care required categories
  • Exception assessment where consent was not obtained
Where this commonly fails
  • Special care required data acquired incidentally without classification
  • Consent not separately obtained for sensitive categories
  • Third party sourced data acquired without checking how it was collected
APPI-A21
Notice or Public Announcement of the Purpose of Use

Promptly notify the identifiable person of the purpose of use or announce it publicly after acquisition, and notify or announce the purpose in advance where personal information is acquired directly in writing.

Artefacts an auditor will ask for
  • Privacy notice with publication date and version history
  • Point of collection notices for written and online forms
  • Record of the timing of notification relative to acquisition
  • Assessment where an exception to notification is relied on
Where this commonly fails
  • Purpose published only in a general privacy policy not linked to the collection point
  • Notification given late
  • Direct written acquisition without prior notice

APPI: Rights of Identifiable Persons (Articles 32 to 39)

APPI-A32
Matters Concerning Retained Personal Data to Be Made Accessible

Make accessible to identifiable persons the name and address of the business, the purpose of use of all retained personal data, the procedure for responding to requests, the contact point for complaints, and the other prescribed matters, and notify the purpose of use on request.

Artefacts an auditor will ask for
  • Published statement of the prescribed matters
  • Documented procedure for responding to requests
  • Named complaint contact point
  • Records of responses to requests for notification of the purpose of use
Where this commonly fails
  • Prescribed matters incomplete, commonly the security control measures and complaint contact
  • Information published but not maintained
  • Requests for notification of purpose handled informally
APPI-A33
Request for Disclosure of Retained Personal Data

Disclose retained personal data and third party provision records without delay on the request of the identifiable person, in the method requested, and give notice of the reasons where disclosure is refused in whole or in part.

Artefacts an auditor will ask for
  • Request register with receipt and response dates
  • Disclosure response templates including electromagnetic record format
  • Identity verification procedure
  • Records of refusals with the reasons given
Where this commonly fails
  • Electronic format requests not supported
  • Third party provision records not treated as disclosable
  • Refusals issued without reasons
  • Response times not tracked
APPI-A34
Request for Correction, Addition or Deletion

Investigate without delay and correct, add to or delete retained personal data where the identifiable person requests it on the ground that the content is not factual, and notify the person of the result.

Artefacts an auditor will ask for
  • Correction request register with investigation records
  • Evidence of the correction applied in source systems
  • Notification records to the person including reasons where no action was taken
  • Propagation procedure to downstream recipients
Where this commonly fails
  • Corrections applied in one system only
  • Investigation not evidenced
  • Person not notified of the outcome
APPI-A35
Request for Cessation of Use, Erasure or Cessation of Third Party Provision

Cease use, erase, or cease third party provision of retained personal data on the request of the identifiable person in the circumstances the Act specifies, or take an alternative measure protecting the person rights, and notify the person of the result.

Artefacts an auditor will ask for
  • Cessation request register
  • Suppression list or equivalent control preventing further use
  • Records of alternative measures where cessation was not possible
  • Notification records including reasons
Where this commonly fails
  • Suppression applied to marketing systems only
  • Alternative measures used without justification
  • Grounds for the request not assessed against the statutory circumstances
APPI-A36
Explanation of Reasons for a Response to a Request

Endeavour to explain the reasons to the identifiable person where notice is given that no measure will be taken in response to a request or that a different measure will be taken.

Artefacts an auditor will ask for
  • Response templates including a reasons section
  • Sample of issued responses evidencing reasons given
  • Quality review of request responses
Where this commonly fails
  • Refusals issued as a bare statement
  • No template prompting the reasons
  • No review of response quality
APPI-A37
Procedure for Receiving Requests

Where a procedure is prescribed for receiving requests, keep it within reasonable bounds, obtain only the information necessary to identify the retained personal data, and have regard to the convenience of the identifiable person.

Artefacts an auditor will ask for
  • Published request procedure
  • Assessment that the identity verification burden is proportionate
  • Accessibility review of the request channel
  • Evidence of accommodation for persons unable to use the standard channel
Where this commonly fails
  • Identity verification demands excessive documentation
  • Only one request channel offered
  • Procedure not published
APPI-A38
Fees for Disclosure and Notification of Purpose

Where a fee is collected for notification of the purpose of use or for disclosure, set it within a reasonable range having regard to the actual costs.

Artefacts an auditor will ask for
  • Published fee schedule
  • Cost basis calculation supporting the fee
  • Records of fees charged
Where this commonly fails
  • Fee charged without a published schedule
  • No cost basis supporting the amount
  • Fees applied to request types where they are not permitted
APPI-A39
Prior Demand Before Litigation on a Request

Recognise that an identifiable person may not file a lawsuit on a disclosure, correction or cessation request until the prescribed period after making the demand has elapsed, unless the demand was refused.

Artefacts an auditor will ask for
  • Record of the date each demand was received
  • Record of any refusal issued and its date
  • Legal escalation procedure referencing the waiting period
Where this commonly fails
  • Date of receipt of demands not recorded
  • Refusals issued without a dated record
  • Legal team unaware of the statutory waiting period

APPI: Security Control and Supervision (Articles 22 to 26)

APPI-A22
Accuracy and Deletion of Personal Data

Endeavour to keep personal data accurate and up to date within the scope necessary to achieve the purpose of use, and to delete personal data without delay when it is no longer needed.

Artefacts an auditor will ask for
  • Data retention schedule with deletion triggers
  • Deletion and disposal logs
  • Data quality and correction procedure
  • Evidence of periodic review of retained data
Where this commonly fails
  • No retention schedule
  • Data retained indefinitely after the purpose has ended
  • Deletion performed but not evidenced
APPI-A23
Security Control Measures

Take necessary and appropriate measures for the security control of personal data, including measures to prevent leakage, loss or damage.

Artefacts an auditor will ask for
  • Information security policy covering personal data
  • Organisational, human, physical and technical safeguard documentation
  • Access control records and encryption standards
  • Risk assessment covering personal data
  • Internal audit or assessment reports on the safeguards
Where this commonly fails
  • Generic information security policy with no personal data specific measures
  • Safeguards implemented but never assessed
  • No mapping of safeguards to the categories the Commission guidance expects
APPI-A24
Supervision of Employees

Exercise necessary and appropriate supervision over employees who handle personal data so that its security is ensured.

Artefacts an auditor will ask for
  • Personal data handling rules for staff
  • Training records with completion tracking
  • Confidentiality undertakings
  • Monitoring or access review evidence
  • Disciplinary procedure covering data misuse
Where this commonly fails
  • Training delivered once at induction only
  • No monitoring of employee access to personal data
  • Confidentiality terms absent for contractors treated as employees
APPI-A25
Supervision of Trustees

Where the handling of personal data is entrusted to another party, exercise necessary and appropriate supervision over that party so that the security of the entrusted data is ensured.

Artefacts an auditor will ask for
  • Register of entrusted processing arrangements
  • Contracts containing security control obligations
  • Vendor due diligence and periodic review records
  • Audit or assurance reports obtained from trustees
  • Sub entrustment approval records
Where this commonly fails
  • No register of entrusted processing
  • Contracts silent on security control measures
  • Supervision limited to contract signature with no ongoing review
  • Sub entrustment not controlled
APPI-A26
Report of Leakage to the Commission and Notification to the Person

Report to the Personal Information Protection Commission and notify the identifiable person where a leakage, loss or damage of personal data or another situation prescribed by the Commission occurs.

Artefacts an auditor will ask for
  • Incident response procedure with the statutory reporting trigger and timeline
  • Preliminary and final report records submitted to the Commission
  • Notification records to identifiable persons or the substitute measure used
  • Incident register with the assessment of each event against the reporting threshold
Where this commonly fails
  • Incident procedure lacks the statutory reporting trigger
  • Individuals not notified where no substitute measure applies
  • No record of the threshold assessment for incidents judged not reportable
  • Reports made outside the required timing

APPI: Third Party Provision and Records (Articles 27 to 31)

APPI-A27
Restriction on Provision to Third Parties

Do not provide personal data to a third party without the prior consent of the identifiable person except in the cases the Act allows, and where the opt out route is used make the prescribed matters known and notify the Commission.

Artefacts an auditor will ask for
  • Consent records for third party provision
  • Opt out notification filed with the Commission and the matters made accessible
  • Register of third party disclosures with the legal basis for each
  • Assessment of joint use and outsourcing arrangements that are not third party provision
Where this commonly fails
  • Provision made under an exception without recording which exception
  • Opt out used without notifying the Commission
  • Joint use arrangements not documented with the prescribed matters
APPI-A28
Provision to Third Parties in Foreign Countries

Obtain the prior consent of the identifiable person before providing personal data to a third party in a foreign country, provide the person with information about that country and the recipient safeguards, and take ongoing measures where an equivalent standard system is relied on.

Artefacts an auditor will ask for
  • Cross border transfer register naming each country and recipient
  • Consent records including the information provided about the foreign regime
  • Documentation of the recipient conforming system where relied on
  • Records of ongoing checks on the recipient equivalent measures and information provided to the person on request
Where this commonly fails
  • Transfers to overseas group companies treated as internal
  • Consent obtained without informing the person about the destination country
  • Reliance on a recipient conforming system without ongoing verification
  • No register of cross border transfers
APPI-A29
Records When Providing Personal Data to a Third Party

Where personal data is provided to a third party, create and retain a record of the date of provision, the identity of the recipient and the prescribed matters.

Artefacts an auditor will ask for
  • Provision records containing the prescribed matters
  • Retention schedule meeting the statutory retention period
  • System generated logs supporting the records
Where this commonly fails
  • Records not created for provisions made under consent
  • Recipient identity captured only informally
  • Records not retained for the required period
APPI-A30
Confirmation and Records When Receiving Personal Data from a Third Party

Where personal data is received from a third party, confirm the identity of the provider and the circumstances of its acquisition, and create and retain a record of the prescribed matters.

Artefacts an auditor will ask for
  • Receipt records containing the prescribed matters
  • Evidence of the confirmation of the provider identity and acquisition circumstances
  • Retention schedule meeting the statutory retention period
  • Procedure for acquiring data from data brokers and list vendors
Where this commonly fails
  • Data purchased from vendors without confirming how it was acquired
  • No receipt records created
  • Confirmation performed but not documented
APPI-A31
Provision of Personally Referable Information

Where personally referable information is provided to a third party that is expected to acquire it as personal data, confirm that the consent of the identifiable person has been obtained and that the prescribed information was provided where the recipient is in a foreign country.

Artefacts an auditor will ask for
  • Inventory of personally referable information shared, including online identifiers and cookie based data
  • Confirmation records that recipient side consent was obtained
  • Records of the confirmation and the prescribed matters
  • Contractual terms with advertising and analytics recipients
Where this commonly fails
  • Cookie and identifier sharing with advertising partners not assessed under this article
  • Recipient side consent assumed rather than confirmed
  • No records of the confirmation
  • Foreign recipients not given the additional information treatment
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the APPI framework page.