{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Data Protection & Privacy","type":"corrective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-07","description":"Maintain personal data that is accurate, complete, up to date, and relevant for its intended use, with periodic data-quality checks. Provide a process for individuals to request correction or amendment, execute or formally deny each request within statutory deadlines with stated reasons, and communicate corrections to third parties to whom the data was disclosed.","details":{"control_category":"administrative","control_type":"corrective","domain":"Data Protection & Privacy","guidance":[],"members":[{"control_id":"P7.1","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"P5.2","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"HIPAA-164.526","coverage":"partial","delta":"statement-of-disagreement appending and inclusion in future disclosures omitted","framework":"hipaa","relationship":"intersects_with"},{"control_id":"CCPA-1798.106","coverage":"full","framework":"ccpa","relationship":"superset_of"},{"control_id":"SI-18","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Maintain personal data that is accurate, complete, up to date, and relevant for its intended use, with periodic data-quality checks. Provide a process for individuals to request correction or amendment, execute or formally deny each request within statutory deadlines with stated reasons, and communicate corrections to third parties to whom the data was disclosed.","title":"Keep personal data accurate and honor correction requests","unified_id":"UC-DATA-07"},"id":"uc:UC-DATA-07","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-07","sourceIds":["ccpa","hipaa","nist-800-53","soc2"],"sourceUrl":null,"title":"UC-DATA-07 — Keep personal data accurate and honor correction requests","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:153916c8d4adaef1fddde7e44d7535399a5efac931c724be644ae20200e1f51d","properties":{"control_id":"CCPA-1798.106","coverage":"full","delta":null,"framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","sourceId":"uc:UC-DATA-07","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-106-35bf5a6c.json","targetId":"ctrl:ccpa:CCPA-1798.106","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:24223814b0af26a6a7bffe54a7395610ea8a9465ebc55bba9c3ada3d2a550911","properties":{},"sourceDetailPath":"/data/v1/records/wf-r10-bc8bf886.json","sourceId":"wf:R10","targetDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","targetId":"uc:UC-DATA-07","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2d7ed6c4666048e562c101adeffad6f1534f427ad6016f2c9001e2665e0e34f0","properties":{"control_id":"P5.2","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","sourceId":"uc:UC-DATA-07","targetDetailPath":"/data/v1/records/ctrl-soc2-p5-2-cd39b81f.json","targetId":"ctrl:soc2:P5.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4c459c2b31ac58cc45c8c8679b0a7d85672da865c3c704c220047944889cd27b","properties":{"rationale":"A correction/amendment right directly addresses the named 'inability to correct' facet of lost self-determination.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","sourceId":"uc:UC-DATA-07","targetDetailPath":"/data/v1/records/risk-privacy-power-imbalance-self-determination-9112ad1d.json","targetId":"risk:privacy-power-imbalance-self-determination","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7920eed39ccb3c5cfedad315cb15840acae3519e27154fb527f507adebe1b108","properties":{"control_id":"P7.1","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","sourceId":"uc:UC-DATA-07","targetDetailPath":"/data/v1/records/ctrl-soc2-p7-1-678a8b81.json","targetId":"ctrl:soc2:P7.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a616eefd957ef1efb73a33a028e698a53d3947c58b58cc7e7c1f94a0bd4672a8","properties":{"control_id":"SI-18","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","sourceId":"uc:UC-DATA-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-18-f72ef0dc.json","targetId":"ctrl:nist-800-53:SI-18","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b288b6a36eea554ba24fb212fc87faa0c94acca7b8db8977cad9f6d1305a8550","properties":{"rationale":"Keeping data accurate/current and executing corrections directly counters distortion harm from processing inaccurate/out-of-context data.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","sourceId":"uc:UC-DATA-07","targetDetailPath":"/data/v1/records/risk-data-privacy-harms-to-individuals-510e65af.json","targetId":"risk:data-privacy-harms-to-individuals","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b56d83736730185faefb32d434fec9af7c80c5b08446a9620c03e3f2e47a05cd","properties":{"rationale":"Periodic data-quality checks detect and correct inaccurate or altered data, limiting integrity loss.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","sourceId":"uc:UC-DATA-07","targetDetailPath":"/data/v1/records/risk-data-corruption-integrity-loss-e771738a.json","targetId":"risk:data-corruption-integrity-loss","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:babc2f679c479b5e1c64ef64adffeec5727c9bab34ed9fee8461e2e6be6d107d","properties":{"rationale":"Executing/denying correction requests within statutory deadlines addresses the DSR-timeliness driver of non-compliance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","sourceId":"uc:UC-DATA-07","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d41f0bc69ad3c8a5089dc58f95d944447d4b94539bbfdf3975aa97dedee63698","properties":{"control_id":"HIPAA-164.526","coverage":"partial","delta":"statement-of-disagreement appending and inclusion in future disclosures omitted","framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","sourceId":"uc:UC-DATA-07","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-526-a1e5b051.json","targetId":"ctrl:hipaa:HIPAA-164.526","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d8b3d2ad2dc1cf91d15037c94c19180526aed4dba44780ac8c5dc7ec24dcffc0","properties":{},"sourceDetailPath":"/data/v1/records/wf-d22-f1c724b8.json","sourceId":"wf:D22","targetDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","targetId":"uc:UC-DATA-07","type":"tests"}],"schemaVersion":1}
