{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Data Protection & Privacy","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-06","description":"Operate a mechanism for identified and authenticated individuals to obtain confirmation of processing and a copy of their personal data, including the categories collected, sold, shared, or disclosed and the categories of recipients, within statutory deadlines. Where access is denied, inform the individual of the denial, the reason, and any recourse. Log all requests and responses as evidence.","details":{"control_category":"administrative","control_type":"preventive","domain":"Data Protection & Privacy","guidance":[],"members":[{"control_id":"P5.1","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"HIPAA-164.524","coverage":"full","framework":"hipaa","relationship":"superset_of"},{"control_id":"CCPA-1798.110-115","coverage":"partial","delta":"response must also disclose categories of sources and business/commercial purposes","framework":"ccpa","relationship":"intersects_with"}],"statement":"Operate a mechanism for identified and authenticated individuals to obtain confirmation of processing and a copy of their personal data, including the categories collected, sold, shared, or disclosed and the categories of recipients, within statutory deadlines. Where access is denied, inform the individual of the denial, the reason, and any recourse. Log all requests and responses as evidence.","title":"Provide data subjects access to their personal data","unified_id":"UC-DATA-06"},"id":"uc:UC-DATA-06","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-06","sourceIds":["ccpa","hipaa","soc2"],"sourceUrl":null,"title":"UC-DATA-06 — Provide data subjects access to their personal data","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0397d83c942955bc563ce4621fb8047bb032df2964e3023994df0f935d05b448","properties":{},"sourceDetailPath":"/data/v1/records/wf-r7-2fc6568b.json","sourceId":"wf:R7","targetDetailPath":"/data/v1/records/uc-uc-data-06-14975c65.json","targetId":"uc:UC-DATA-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:224ce45cdbe3079825638c0f37c6c30bf72ac8fa4e76a5e2dc798a5602c78ef0","properties":{"control_id":"CCPA-1798.110-115","coverage":"partial","delta":"response must also disclose categories of sources and business/commercial purposes","framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-06-14975c65.json","sourceId":"uc:UC-DATA-06","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-110-115-cf470a0c.json","targetId":"ctrl:ccpa:CCPA-1798.110-115","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3ac880a93694bbcb186eee38fd1f88554de0deac884da9fba61bd51898c47d5e","properties":{},"sourceDetailPath":"/data/v1/records/wf-d22-f1c724b8.json","sourceId":"wf:D22","targetDetailPath":"/data/v1/records/uc-uc-data-06-14975c65.json","targetId":"uc:UC-DATA-06","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:507c1d4b76c3c9354c1015bed108c4c0f7deaa70306e648dcb43bee10e0277b5","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-06-14975c65.json","sourceId":"uc:UC-DATA-06","targetDetailPath":"/data/v1/records/risk-data-surveillance-appropriation-18ad67e7.json","targetId":"risk:data-surveillance-appropriation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7e1c334a192711150cbfa5ea1a528b86583491532ea229eea14b994be9d4f400","properties":{"control_id":"P5.1","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-data-06-14975c65.json","sourceId":"uc:UC-DATA-06","targetDetailPath":"/data/v1/records/ctrl-soc2-p5-1-c99cbcc8.json","targetId":"ctrl:soc2:P5.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b2a214b13d62b4e14783c3eae4ada122863c80907dd25fab0198d7be368231ee","properties":{"rationale":"Fulfilling access requests within statutory deadlines addresses the failure-to-honor-DSR driver of non-compliance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-06-14975c65.json","sourceId":"uc:UC-DATA-06","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b4a52314083c62606dd5b45a89f201bf62653f36f71bc0445b6daf6f53606c3b","properties":{"control_id":"HIPAA-164.524","coverage":"full","delta":null,"framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-06-14975c65.json","sourceId":"uc:UC-DATA-06","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-524-2cfa4f29.json","targetId":"ctrl:hipaa:HIPAA-164.524","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dd92f9edd53f28da2d66217336321ef8869c946307508aac76da9307959a9a64","properties":{"rationale":"Giving individuals confirmation and a copy of their data plus recipient/category detail directly restores knowledge and control over their own data.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-06-14975c65.json","sourceId":"uc:UC-DATA-06","targetDetailPath":"/data/v1/records/risk-privacy-power-imbalance-self-determination-9112ad1d.json","targetId":"risk:privacy-power-imbalance-self-determination","type":"mitigates"}],"schemaVersion":1}
