CBPR-01 | Notice | 9 |
CBPR-02 | Collection Limitation | 8 |
CBPR-03 | Uses of Personal Information | 10 |
CBPR-04 | Choice | 8 |
CBPR-05 | Integrity of Personal Information | 9 |
CBPR-06 | Security Safeguards | 18 |
CBPR-07 | Access and Correction | 9 |
CBPR-08 | Accountability | 16 |
CBPR-09 | Preventing Harm | 17 |
CBPR-PR-01 | Privacy statement published | 9 |
CBPR-PR-02 | Notice at the time of collection | 9 |
CBPR-PR-03 | Purposes stated at collection | 8 |
CBPR-PR-04 | Notice of sharing with third parties | 9 |
CBPR-PR-05 | Collection methods identified | 9 |
CBPR-PR-06 | Collection limited to relevant information | 7 |
CBPR-PR-07 | Lawful and fair collection | 8 |
CBPR-PR-08 | Use limited to stated purposes | 10 |
CBPR-PR-09 | Grounds for unrelated use | 9 |
CBPR-PR-10 | Disclosure to other controllers identified | 11 |
CBPR-PR-11 | Transfers to processors identified | 13 |
CBPR-PR-12 | Disclosure consistent with original purpose | 10 |
CBPR-PR-13 | Grounds for other disclosure | 8 |
CBPR-PR-14 | Choice over collection | 8 |
CBPR-PR-15 | Choice over use | 6 |
CBPR-PR-16 | Choice over disclosure | 7 |
CBPR-PR-17 | Choices clear and conspicuous | 5 |
CBPR-PR-18 | Choices clearly worded | 4 |
CBPR-PR-19 | Choices accessible and affordable | 5 |
CBPR-PR-20 | Mechanisms to honour choices | 7 |
CBPR-PR-21 | Accuracy verification | 14 |
CBPR-PR-22 | Correction mechanism | 9 |
CBPR-PR-23 | Corrections communicated after transfer | 6 |
CBPR-PR-24 | Corrections communicated after disclosure | 8 |
CBPR-PR-25 | Processor obligation to report data quality issues | 4 |
CBPR-PR-26 | Information security policy | 16 |
CBPR-PR-27 | Physical, technical and administrative safeguards | 17 |
CBPR-PR-28 | Safeguards proportional to risk | 18 |
CBPR-PR-29 | Employee security awareness | 16 |
CBPR-PR-30 | Specific proportional safeguards in place | 10 |
CBPR-PR-31 | Secure disposal policy | 18 |
CBPR-PR-32 | Detection, prevention and response measures | 15 |
CBPR-PR-33 | Testing the effectiveness of safeguards | 14 |
CBPR-PR-34 | Risk assessments and third party certifications | 16 |
CBPR-PR-35 | Processor protection obligations | 16 |
CBPR-PR-36 | Confirmation of holding | 7 |
CBPR-PR-37 | Access to personal information | 8 |
CBPR-PR-38 | Challenge and rectification | 8 |
CBPR-PR-39 | Measures to ensure compliance | 18 |
CBPR-PR-40 | Responsible individual appointed | 10 |
CBPR-PR-41 | Complaint handling procedures | 7 |
CBPR-PR-42 | Timely complaint response | 6 |
CBPR-PR-43 | Remedial action explained | 6 |
CBPR-PR-44 | Employee privacy training | 16 |
CBPR-PR-45 | Response to legal demands | 6 |
CBPR-PR-46 | Mechanisms with processors to meet obligations | 19 |
CBPR-PR-47 | Processor agreement content | 17 |
CBPR-PR-48 | Processor self-assessments | 12 |
CBPR-PR-49 | Spot checking and monitoring of processors | 14 |
CBPR-PR-50 | Disclosure where due diligence is impractical | 4 |