APPI — Act on the Protection of Personal Information · vAct on the Protection of Pe…
APPI — Act on the Protection of Personal Information
APPI — Act on the Protection of Personal Information — 90% of in-scope requirements covered.
5 requirements · 5 in scope (4 enforced · 1 designed). The 90% is weighted over the in-scope base.
Source: Act on the Protection of Personal Information (APPI, Act No. 57 of 2003), as amended (2020 amendment in force 1 April 2022), supervised by the Personal Information Protection Commission (PPC). KYE™ maps the purpose-of-use, security-control, cross-border-transfer, disclosure-and-access, and breach-reporting obligations that touch an AI-supported action onto runtime evidence; the customer's organisational privacy programme stays out of scope.
By category
| Category | Reqs | Enforced | Designed | Advisory | Deferred | Coverage |
|---|---|---|---|---|---|---|
| Purpose of use & consent | 1 | 1 | 0 | 0 | 0 | 100% |
| Security control measures | 1 | 1 | 0 | 0 | 0 | 100% |
| Cross-border transfer | 1 | 1 | 0 | 0 | 0 | 100% |
| Disclosure & access rights | 1 | 1 | 0 | 0 | 0 | 100% |
| Breach reporting | 1 | 0 | 1 | 0 | 0 | 50% |
Every requirement → the KYE™ artefact that enforces it
| ID | Title | Status | KYE™ enforcement |
|---|---|---|---|
appi.purpose-of-use |
APPI Articles 17-18 — specify the purpose of use of personal information as far as possible and do not handle personal information beyond the specified purpose without consent | enforced | audit_events: kye.purpose.request.v1, kye.purpose.admissibility.v1engines: internal, internalconstitution_refs: constitution/12-PURPOSE-PERMISSION.md |
appi.security-control-measures |
APPI Article 23 — take necessary and appropriate measures for the security control of personal data, including access control and the prevention of leakage | enforced | audit_events: kye.risk.authority_register.v1, kye.evidence.tool_call.v1engines: internal, internalconstitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md, constitution/12-PURPOSE-PERMISSION.md |
appi.cross-border-transfer |
APPI Articles 28 + 31 — provide personal data to a third party in a foreign country only with consent or an adequate-protection basis, and supply information on the recipient's data-handling regime | enforced | audit_events: kye.evidence.tool_call.v1, kye.evidence.decision_map.v1engines: internal, internalconstitution_refs: constitution/21-DELEGATED-AUDITABILITY.md |
appi.disclosure-access-rights |
APPI Articles 33-35 — respond to a data subject's request for disclosure, correction, suspension of use or erasure of their retained personal data | enforced | audit_events: kye.replay.proof.v1, kye.evidence.pack.v1engines: internal, internalconstitution_refs: constitution/21-DELEGATED-AUDITABILITY.md, constitution/13-RESILIENCE-LOOP.md |
appi.breach-reporting |
APPI Article 26 — report a leakage of personal data that is likely to harm individuals' rights and interests to the PPC and notify affected individuals | designed | audit_events: kye.signal.incident.opened.v1, kye.compliance.attestation.v1engines: internal, internalconstitution_refs: constitution/13-RESILIENCE-LOOP.md |