PT-02 Authority to Process Personally Identifiable Information

Personally Identifiable Information Processing and Transparency

Privacy New in Rev 5

Description

Changes from Rev 4

New control family introduced in Rev 5

Compliance Mappings

ISO 27001:2022

A.5.34

ISO 27002:2022

5.34

COBIT 2019

APO14

CIS Controls v8

CIS 3

CSA CCM v4

DSP-08DSP-12

CSA AICM v1

DSP-08DSP-12

ISO 42001:2023

A.5.4A.7.3

BSI IT-Grundschutz

CON.2

ANSSI

SecNumCloud.19.3

FINMA Circular 2023/1

IV.D(78)IV.D(79)

OSFI B-13

B-13.1.3

EU GDPR

Art.12(1)Art.12(7)Art.13(1)Art.13(2)Art.14(1)Art.14(2)Art.5(1)(a)Art.6(1)

BIO2

5.34

RBI CSF

Annex1.15

MLPS 2.0

8.1.4.11

EU CRA

CRA.I.2g

NCA ECC

2-7

CBB TM

TM-9

CBUAE

CR-5

CBE CSF

CTO-2

SA JS2

JS2-8.2

CBN CSF

Part3.4Part5.1Part7.1

POPIA

s11s57-59s9

BoM CTRM

3.10

IOSCO Cyber Resilience

PROT-3

FFIEC IS

II.C.16

ECB CROE

CROE.2.3.3

SEBI CSCRF

DATALOCPR.DS

BOT Cyber Resilience

Ch2.3Ch9.2

CBEST

CBEST.9

Common Criteria

CC Part 2 — FPR

Solvency II

Art.49(3)EIOPA-Cloud-GL9

Lloyd's Minimum Standards

MS7.1

HITRUST CSF v11

06.a06.b13.a13.c13.e

ISO 27799

18.118.25.38.2

NHS DSPT

NDG-1.1NDG-10.2NDG-5.2

OWASP MASVS v2.1

MASVS-PRIVACY-1MASVS-PRIVACY-2

MiCA

Art.62(9)Art.98(1)

BSSC Standards

GSP-09