71% of Australia Consumer Data Right you already have
Australian Privacy Principles (APPs) already covers about 71% of Australia Consumer Data Right, leaving
8 of 28 controls as genuinely new work.
Already covered 18
Likely covered 2
New work 8
What is genuinely new work
Nothing in Australian Privacy Principles (APPs) reaches these. This is the list to scope.
AUCDR-IS-1Limit risk of unauthorised access to the CDR data environment
AUCDR-IS-2Secure the network and systems within the data environment
AUCDR-IS-3Securely manage information assets over their lifecycle
AUCDR-IS-4Formal vulnerability management program
AUCDR-IS-5Limit, prevent, detect and remove malware
AUCDR-IS-6Information security training and awareness program
AUCDR-OB-1Accreditation as an accredited data recipient
AUCDR-OB-7Reporting to ACCC and OAIC
Show the 20 you already have
AUCDR-OB-2Consent requirements
AUCDR-OB-3Data minimisation
AUCDR-OB-4CDR policy publication
AUCDR-OB-5Deletion or de-identification of redundant data
AUCDR-OB-8Complaints handling
AUCDR-PS-1Privacy Safeguard 1 - Open and transparent management of CDR data
AUCDR-PS-10Privacy Safeguard 10 - Notifying of the disclosure of CDR data
AUCDR-PS-11Privacy Safeguard 11 - Quality of CDR data
AUCDR-PS-12Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data
AUCDR-PS-13Privacy Safeguard 13 - Correction of CDR data
AUCDR-PS-2Privacy Safeguard 2 - Anonymity and pseudonymity
AUCDR-PS-3Privacy Safeguard 3 - Seeking to collect CDR data from CDR participants
AUCDR-PS-4Privacy Safeguard 4 - Dealing with unsolicited CDR data
AUCDR-PS-5Privacy Safeguard 5 - Notifying of the collection of CDR data
AUCDR-PS-6Privacy Safeguard 6 - Use or disclosure of CDR data
AUCDR-PS-7Privacy Safeguard 7 - Use or disclosure of CDR data for direct marketing
AUCDR-PS-8Privacy Safeguard 8 - Overseas disclosure of CDR data
AUCDR-PS-9Privacy Safeguard 9 - Adoption or disclosure of government related identifiers
AUCDR-OB-6Records of CDR data
AUCDR-OB-9Outsourced service provider and representative arrangements
How this is calculated
Already covered means a mapping runs from a control in Australian Privacy Principles (APPs) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition