APPI
Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
APPI: Anonymized Personal Information (Articles 43 to 46)
Where anonymized personal information is prepared, process the personal information to the Commission standards so that the person cannot be identified and the original cannot be restored, secure the deleted information and processing method, and publicly announce the categories of information contained.
- Anonymization standard and processing specification
- Re identification risk assessment
- Public announcement of the categories of information contained
- Security control measures over the deleted information and processing method
- Anonymization asserted without a risk assessment
- Categories of information not publicly announced
- Processing method retained without safeguards
Before providing anonymized personal information to a third party, publicly announce the categories of information contained and the method of provision, and expressly state to the recipient that the information is anonymized personal information.
- Public announcement covering the categories and the provision method
- Contract or transmittal wording stating the information is anonymized personal information
- Register of provisions made
- Anonymized data shared without the public announcement
- Recipient not told the data is anonymized personal information
- No register of provisions
When handling anonymized personal information, do not acquire the deleted identifiers or the processing method, and do not collate the anonymized information with other information in order to identify the person.
- Handling rules prohibiting re identification and collation
- Technical separation between anonymized data sets and identifying data
- Contractual prohibition passed to recipients
- Training and attestation records
- No prohibition communicated to analytics teams or recipients
- Anonymized data stored alongside identifying data
- Prohibition stated in policy only with no technical control
Endeavour to take the necessary and appropriate measures for the security control of anonymized personal information and to make the content of those measures publicly available.
- Security control measures applied to anonymized data sets
- Public statement of the measures taken
- Complaint handling route covering anonymized information
- Anonymized data treated as out of scope for security control
- Measures taken but not published
- No handling procedure for received anonymized data
APPI: Complaint Handling (Article 40)
Endeavour to process complaints about the handling of personal information appropriately and promptly, and to establish the system necessary to achieve that purpose.
- Complaint handling procedure with target response times
- Complaint register with outcomes
- Evidence of the resources or system established for complaint handling
- Trend analysis of complaints feeding improvement
- Complaints handled through a general customer service queue with no privacy specific route
- No complaint register
- Complaint outcomes not analysed
APPI: Pseudonymized Personal Information (Articles 41 and 42)
Where pseudonymized personal information is prepared, process the personal information to the Commission standards, secure the deleted information and processing method, limit use to the purpose, and delete the data when no longer needed.
- Pseudonymization standard and processing specification
- Security control measures over the deletion information and processing method
- Purpose of use statement for the pseudonymized data
- Deletion records
- Prohibition on identification attempts embedded in procedures
- Pseudonymization performed without a documented standard
- Deletion information stored alongside the pseudonymized data
- Use of pseudonymized data not restricted to the stated purpose
Do not provide pseudonymized personal information to a third party except in the cases based on laws and regulations, and do not contact the identifiable person or attempt identification.
- Controls preventing external transfer of pseudonymized data
- Register of any provision made and the legal basis
- Prohibition on identification and contact embedded in handling rules
- Training for teams handling pseudonymized data
- Pseudonymized data shared with analytics partners
- Identification prohibition not communicated
- No register of provisions
APPI: Purpose Specification and Acquisition (Articles 17 to 21)
Specify the purpose of use of personal information as far as possible, and do not change it beyond a scope reasonably related to the purpose before the change.
- Purpose of use statement for each processing activity
- Record of purpose changes and the relatedness assessment
- Privacy notice showing the specified purpose
- Purpose stated only in broad terms such as business use
- Purpose changed without a relatedness assessment
- No record linking each data set to its specified purpose
Do not handle personal information beyond the scope necessary to achieve the specified purpose of use without the prior consent of the identifiable person, and apply the same restriction to information acquired through a business succession.
- Consent records for handling beyond the purpose
- Processing inventory mapped to the specified purpose
- Due diligence record for personal information received through a merger or business transfer
- Assessment against the statutory exceptions relied on
- Secondary use without consent or a stated exception
- Data acquired in an acquisition used for the acquirer purposes without assessment
- Exceptions relied on but not documented
Do not use personal information by a method that may encourage or induce an unlawful or unjust act.
- Acceptable use policy for personal information
- Review of profiling, scoring and targeting use cases
- Escalation records for use cases rejected on this ground
- No review of downstream use cases
- Profiling and scoring uses never assessed for improper use
- Policy exists but no evidence of application
Do not acquire personal information by deceptive or other wrongful means, and do not acquire special care required personal information without the prior consent of the identifiable person except in the cases the Act allows.
- Acquisition channel inventory with a lawfulness assessment
- Consent records for special care required personal information
- Classification rules identifying special care required categories
- Exception assessment where consent was not obtained
- Special care required data acquired incidentally without classification
- Consent not separately obtained for sensitive categories
- Third party sourced data acquired without checking how it was collected
Promptly notify the identifiable person of the purpose of use or announce it publicly after acquisition, and notify or announce the purpose in advance where personal information is acquired directly in writing.
- Privacy notice with publication date and version history
- Point of collection notices for written and online forms
- Record of the timing of notification relative to acquisition
- Assessment where an exception to notification is relied on
- Purpose published only in a general privacy policy not linked to the collection point
- Notification given late
- Direct written acquisition without prior notice
APPI: Rights of Identifiable Persons (Articles 32 to 39)
Make accessible to identifiable persons the name and address of the business, the purpose of use of all retained personal data, the procedure for responding to requests, the contact point for complaints, and the other prescribed matters, and notify the purpose of use on request.
- Published statement of the prescribed matters
- Documented procedure for responding to requests
- Named complaint contact point
- Records of responses to requests for notification of the purpose of use
- Prescribed matters incomplete, commonly the security control measures and complaint contact
- Information published but not maintained
- Requests for notification of purpose handled informally
Disclose retained personal data and third party provision records without delay on the request of the identifiable person, in the method requested, and give notice of the reasons where disclosure is refused in whole or in part.
- Request register with receipt and response dates
- Disclosure response templates including electromagnetic record format
- Identity verification procedure
- Records of refusals with the reasons given
- Electronic format requests not supported
- Third party provision records not treated as disclosable
- Refusals issued without reasons
- Response times not tracked
Investigate without delay and correct, add to or delete retained personal data where the identifiable person requests it on the ground that the content is not factual, and notify the person of the result.
- Correction request register with investigation records
- Evidence of the correction applied in source systems
- Notification records to the person including reasons where no action was taken
- Propagation procedure to downstream recipients
- Corrections applied in one system only
- Investigation not evidenced
- Person not notified of the outcome
Cease use, erase, or cease third party provision of retained personal data on the request of the identifiable person in the circumstances the Act specifies, or take an alternative measure protecting the person rights, and notify the person of the result.
- Cessation request register
- Suppression list or equivalent control preventing further use
- Records of alternative measures where cessation was not possible
- Notification records including reasons
- Suppression applied to marketing systems only
- Alternative measures used without justification
- Grounds for the request not assessed against the statutory circumstances
Endeavour to explain the reasons to the identifiable person where notice is given that no measure will be taken in response to a request or that a different measure will be taken.
- Response templates including a reasons section
- Sample of issued responses evidencing reasons given
- Quality review of request responses
- Refusals issued as a bare statement
- No template prompting the reasons
- No review of response quality
Where a procedure is prescribed for receiving requests, keep it within reasonable bounds, obtain only the information necessary to identify the retained personal data, and have regard to the convenience of the identifiable person.
- Published request procedure
- Assessment that the identity verification burden is proportionate
- Accessibility review of the request channel
- Evidence of accommodation for persons unable to use the standard channel
- Identity verification demands excessive documentation
- Only one request channel offered
- Procedure not published
Where a fee is collected for notification of the purpose of use or for disclosure, set it within a reasonable range having regard to the actual costs.
- Published fee schedule
- Cost basis calculation supporting the fee
- Records of fees charged
- Fee charged without a published schedule
- No cost basis supporting the amount
- Fees applied to request types where they are not permitted
Recognise that an identifiable person may not file a lawsuit on a disclosure, correction or cessation request until the prescribed period after making the demand has elapsed, unless the demand was refused.
- Record of the date each demand was received
- Record of any refusal issued and its date
- Legal escalation procedure referencing the waiting period
- Date of receipt of demands not recorded
- Refusals issued without a dated record
- Legal team unaware of the statutory waiting period
APPI: Security Control and Supervision (Articles 22 to 26)
Endeavour to keep personal data accurate and up to date within the scope necessary to achieve the purpose of use, and to delete personal data without delay when it is no longer needed.
- Data retention schedule with deletion triggers
- Deletion and disposal logs
- Data quality and correction procedure
- Evidence of periodic review of retained data
- No retention schedule
- Data retained indefinitely after the purpose has ended
- Deletion performed but not evidenced
Take necessary and appropriate measures for the security control of personal data, including measures to prevent leakage, loss or damage.
- Information security policy covering personal data
- Organisational, human, physical and technical safeguard documentation
- Access control records and encryption standards
- Risk assessment covering personal data
- Internal audit or assessment reports on the safeguards
- Generic information security policy with no personal data specific measures
- Safeguards implemented but never assessed
- No mapping of safeguards to the categories the Commission guidance expects
Exercise necessary and appropriate supervision over employees who handle personal data so that its security is ensured.
- Personal data handling rules for staff
- Training records with completion tracking
- Confidentiality undertakings
- Monitoring or access review evidence
- Disciplinary procedure covering data misuse
- Training delivered once at induction only
- No monitoring of employee access to personal data
- Confidentiality terms absent for contractors treated as employees
Where the handling of personal data is entrusted to another party, exercise necessary and appropriate supervision over that party so that the security of the entrusted data is ensured.
- Register of entrusted processing arrangements
- Contracts containing security control obligations
- Vendor due diligence and periodic review records
- Audit or assurance reports obtained from trustees
- Sub entrustment approval records
- No register of entrusted processing
- Contracts silent on security control measures
- Supervision limited to contract signature with no ongoing review
- Sub entrustment not controlled
Report to the Personal Information Protection Commission and notify the identifiable person where a leakage, loss or damage of personal data or another situation prescribed by the Commission occurs.
- Incident response procedure with the statutory reporting trigger and timeline
- Preliminary and final report records submitted to the Commission
- Notification records to identifiable persons or the substitute measure used
- Incident register with the assessment of each event against the reporting threshold
- Incident procedure lacks the statutory reporting trigger
- Individuals not notified where no substitute measure applies
- No record of the threshold assessment for incidents judged not reportable
- Reports made outside the required timing
APPI: Third Party Provision and Records (Articles 27 to 31)
Do not provide personal data to a third party without the prior consent of the identifiable person except in the cases the Act allows, and where the opt out route is used make the prescribed matters known and notify the Commission.
- Consent records for third party provision
- Opt out notification filed with the Commission and the matters made accessible
- Register of third party disclosures with the legal basis for each
- Assessment of joint use and outsourcing arrangements that are not third party provision
- Provision made under an exception without recording which exception
- Opt out used without notifying the Commission
- Joint use arrangements not documented with the prescribed matters
Obtain the prior consent of the identifiable person before providing personal data to a third party in a foreign country, provide the person with information about that country and the recipient safeguards, and take ongoing measures where an equivalent standard system is relied on.
- Cross border transfer register naming each country and recipient
- Consent records including the information provided about the foreign regime
- Documentation of the recipient conforming system where relied on
- Records of ongoing checks on the recipient equivalent measures and information provided to the person on request
- Transfers to overseas group companies treated as internal
- Consent obtained without informing the person about the destination country
- Reliance on a recipient conforming system without ongoing verification
- No register of cross border transfers
Where personal data is provided to a third party, create and retain a record of the date of provision, the identity of the recipient and the prescribed matters.
- Provision records containing the prescribed matters
- Retention schedule meeting the statutory retention period
- System generated logs supporting the records
- Records not created for provisions made under consent
- Recipient identity captured only informally
- Records not retained for the required period
Where personal data is received from a third party, confirm the identity of the provider and the circumstances of its acquisition, and create and retain a record of the prescribed matters.
- Receipt records containing the prescribed matters
- Evidence of the confirmation of the provider identity and acquisition circumstances
- Retention schedule meeting the statutory retention period
- Procedure for acquiring data from data brokers and list vendors
- Data purchased from vendors without confirming how it was acquired
- No receipt records created
- Confirmation performed but not documented
Where personally referable information is provided to a third party that is expected to acquire it as personal data, confirm that the consent of the identifiable person has been obtained and that the prescribed information was provided where the recipient is in a foreign country.
- Inventory of personally referable information shared, including online identifiers and cookie based data
- Confirmation records that recipient side consent was obtained
- Records of the confirmation and the prescribed matters
- Contractual terms with advertising and analytics recipients
- Cookie and identifier sharing with advertising partners not assessed under this article
- Recipient side consent assumed rather than confirmed
- No records of the confirmation
- Foreign recipients not given the additional information treatment
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the APPI framework page.