APPI — Act on the Protection of Personal Information · vAct on the Protection of Pe…

APPI — Act on the Protection of Personal Information

APPI — Act on the Protection of Personal Information — 90% of in-scope requirements covered.

5 requirements · 5 in scope (4 enforced · 1 designed). The 90% is weighted over the in-scope base.

Source: Act on the Protection of Personal Information (APPI, Act No. 57 of 2003), as amended (2020 amendment in force 1 April 2022), supervised by the Personal Information Protection Commission (PPC). KYE™ maps the purpose-of-use, security-control, cross-border-transfer, disclosure-and-access, and breach-reporting obligations that touch an AI-supported action onto runtime evidence; the customer's organisational privacy programme stays out of scope.

By category

CategoryReqsEnforcedDesignedAdvisoryDeferredCoverage
Purpose of use & consent 1 1 0 0 0 100%
Security control measures 1 1 0 0 0 100%
Cross-border transfer 1 1 0 0 0 100%
Disclosure & access rights 1 1 0 0 0 100%
Breach reporting 1 0 1 0 0 50%

Every requirement → the KYE artefact that enforces it

IDTitleStatusKYE enforcement
appi.purpose-of-use APPI Articles 17-18 — specify the purpose of use of personal information as far as possible and do not handle personal information beyond the specified purpose without consent enforced audit_events: kye.purpose.request.v1, kye.purpose.admissibility.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
appi.security-control-measures APPI Article 23 — take necessary and appropriate measures for the security control of personal data, including access control and the prevention of leakage enforced audit_events: kye.risk.authority_register.v1, kye.evidence.tool_call.v1
engines: internal, internal
constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md, constitution/12-PURPOSE-PERMISSION.md
appi.cross-border-transfer APPI Articles 28 + 31 — provide personal data to a third party in a foreign country only with consent or an adequate-protection basis, and supply information on the recipient's data-handling regime enforced audit_events: kye.evidence.tool_call.v1, kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
appi.disclosure-access-rights APPI Articles 33-35 — respond to a data subject's request for disclosure, correction, suspension of use or erasure of their retained personal data enforced audit_events: kye.replay.proof.v1, kye.evidence.pack.v1
engines: internal, internal
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md, constitution/13-RESILIENCE-LOOP.md
appi.breach-reporting APPI Article 26 — report a leakage of personal data that is likely to harm individuals' rights and interests to the PPC and notify affected individuals designed audit_events: kye.signal.incident.opened.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md