Generally Accepted Privacy Principles
Generally Accepted Privacy Principles is a framework intended to assist Chartered Accountants and Certified Public Accountants in creating an effective privacy program for managing and preventing privacy risks. It was developed through joint consultation with the Canadian Institute of Chartered Accountants (CICA) and the American Institute of Certified Public Accountants (AICPA) through the AICPA/CICA Privacy Task Force.[1]
The GAPP were previously known as the AICPA/CICA Privacy Framework and is founded on a single privacy principle, being that personally identifiable information must be collected, used, retained and disclosed in compliance with the commitments in the entity's privacy notice and with criteria set out in the GAPP issued by the AICPA/CICA. This privacy objective is supported by ten main principles and over seventy objectives, with associated measurable criteria.[2]
Privacy is defined in Generally Accepted Privacy Principles as "the rights and obligations of individuals and organizations with respect to the collection, use, retention, disclosure, and disposal of personal information."[3]
See also
References
External links
- Fill the GAPP, Cal CPA magazine, Oct 2007
- Review and Critique of GAPP, Society of Information Risk Analysts Feb 2014
- GAPP Targets Privacy Risks, Journal of Accountancy
- Comparison of eight Governance Risk Control (GRC) Regulatory Compliances