{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["risk:ai-highrisk-critical-infra","risk:compliance-no-independent-audit","risk:data-breach-unauthorized-disclosure","risk:data-corruption-integrity-loss","risk:data-excessive-collection-purpose-creep","risk:data-privacy-harms-to-individuals","risk:data-privacy-program-noncompliance","risk:data-reidentification-inference","risk:data-retention-noncompliance","risk:data-surveillance-appropriation","risk:data-transparency-notice-dark-patterns","risk:hr-missing-security-terms-discipline","risk:privacy-cross-border-transfer","risk:privacy-loss-of-trust","risk:privacy-power-imbalance-self-determination","risk:tech-illegal-data-processing","risk:tprm-vendor-compliance-vicarious-liability","risk:tprm-vendor-service-nonperformance","risk:tprm-weak-supplier-oversight","uc:UC-AUDIT-23","uc:UC-DATA-02","uc:UC-DATA-05","uc:UC-DATA-06","uc:UC-DATA-07","uc:UC-DATA-08","uc:UC-DATA-13","uc:UC-TPRM-03","wf:A1","wf:C16"],"directIds":["ctrl:ccpa:CCPA-1798.100","ctrl:ccpa:CCPA-1798.105","ctrl:ccpa:CCPA-1798.106","ctrl:ccpa:CCPA-1798.110-115","ctrl:ccpa:CCPA-1798.120-121","ctrl:ccpa:CCPA-1798.125","ctrl:ccpa:CCPA-1798.130-135","ctrl:ccpa:CCPA-1798.140","ctrl:ccpa:CCPA-1798.150","ctrl:ccpa:CCPA-1798.185","std:ccpa"],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"CCPA/CPRA","next":"/assets/agent_sources-ccpa-2.eeef5bd5b6d8c24b.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"administrative","framework":"ccpa","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/ccpa/","description":"Notice at collection and consumer right to know","details":{"automation":"manual","control_category":"administrative","control_id":"CCPA-1798.100","control_type":"preventive","domains":["Data Protection & Privacy","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"ccpa","group":"CCPA/CPRA (California Consumer Privacy)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-ccpa-ccpa-1798-100-b353d024.html","id":"ctrl:ccpa:CCPA-1798.100","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Accpa%3ACCPA-1798.100","sourceIds":["ccpa"],"sourceUrl":null,"title":"CCPA-1798.100 — Notice at collection and consumer right to know","type":"control","url":"/assets/agent_record-ctrl-ccpa-ccpa-1798-100-b353d024.a53d312739a838ca.json"},{"attributes":{"category":"administrative","framework":"ccpa","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/ccpa/","description":"Right to delete personal information","details":{"automation":"manual","control_category":"administrative","control_id":"CCPA-1798.105","control_type":"corrective","domains":["Data Protection & Privacy","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"ccpa","group":"CCPA/CPRA (California Consumer Privacy)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-ccpa-ccpa-1798-105-fdc06468.html","id":"ctrl:ccpa:CCPA-1798.105","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Accpa%3ACCPA-1798.105","sourceIds":["ccpa"],"sourceUrl":null,"title":"CCPA-1798.105 — Right to delete personal information","type":"control","url":"/assets/agent_record-ctrl-ccpa-ccpa-1798-105-fdc06468.b2b4067ccac2f0d4.json"},{"attributes":{"category":"administrative","framework":"ccpa","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/ccpa/","description":"Right to correct inaccurate personal information","details":{"automation":"manual","control_category":"administrative","control_id":"CCPA-1798.106","control_type":"corrective","domains":["Data Protection & Privacy","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"ccpa","group":"CCPA/CPRA (California Consumer Privacy)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-ccpa-ccpa-1798-106-35bf5a6c.html","id":"ctrl:ccpa:CCPA-1798.106","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Accpa%3ACCPA-1798.106","sourceIds":["ccpa"],"sourceUrl":null,"title":"CCPA-1798.106 — Right to correct inaccurate personal information","type":"control","url":"/assets/agent_record-ctrl-ccpa-ccpa-1798-106-35bf5a6c.2f0c18ceefcb681c.json"},{"attributes":{"category":"administrative","framework":"ccpa","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/ccpa/","description":"Rights to access and disclosure of personal information collected, sold, or shared","details":{"automation":"manual","control_category":"administrative","control_id":"CCPA-1798.110-115","control_type":"preventive","domains":["Data Protection & Privacy","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"ccpa","group":"CCPA/CPRA (California Consumer Privacy)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-ccpa-ccpa-1798-110-115-cf470a0c.html","id":"ctrl:ccpa:CCPA-1798.110-115","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Accpa%3ACCPA-1798.110-115","sourceIds":["ccpa"],"sourceUrl":null,"title":"CCPA-1798.110-115 — Rights to access and disclosure of personal information collected, sold, or shared","type":"control","url":"/assets/agent_record-ctrl-ccpa-ccpa-1798-110-115-cf470a0c.4d55b34423fe6037.json"},{"attributes":{"category":"administrative","framework":"ccpa","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/ccpa/","description":"Right to opt out of sale/sharing and to limit use of sensitive personal information","details":{"automation":"hybrid","control_category":"administrative","control_id":"CCPA-1798.120-121","control_type":"preventive","domains":["Data Protection & Privacy","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"ccpa","group":"CCPA/CPRA (California Consumer Privacy)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-ccpa-ccpa-1798-120-121-7655ba5c.html","id":"ctrl:ccpa:CCPA-1798.120-121","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Accpa%3ACCPA-1798.120-121","sourceIds":["ccpa"],"sourceUrl":null,"title":"CCPA-1798.120-121 — Right to opt out of sale/sharing and to limit use of sensitive personal information","type":"control","url":"/assets/agent_record-ctrl-ccpa-ccpa-1798-120-121-7655ba5c.5226b0c9096d7dc8.json"},{"attributes":{"category":"administrative","framework":"ccpa","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/ccpa/","description":"Non-discrimination and financial-incentive requirements","details":{"automation":"manual","control_category":"administrative","control_id":"CCPA-1798.125","control_type":"preventive","domains":["Data Protection & Privacy","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"ccpa","group":"CCPA/CPRA (California Consumer Privacy)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-ccpa-ccpa-1798-125-f0016e3a.html","id":"ctrl:ccpa:CCPA-1798.125","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Accpa%3ACCPA-1798.125","sourceIds":["ccpa"],"sourceUrl":null,"title":"CCPA-1798.125 — Non-discrimination and financial-incentive requirements","type":"control","url":"/assets/agent_record-ctrl-ccpa-ccpa-1798-125-f0016e3a.665e4e4c930a9ebc.json"},{"attributes":{"category":"administrative","framework":"ccpa","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/ccpa/","description":"Request-handling mechanics, verification, and opt-out link requirements","details":{"automation":"manual","control_category":"administrative","control_id":"CCPA-1798.130-135","control_type":"preventive","domains":["Data Protection & Privacy","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"ccpa","group":"CCPA/CPRA (California Consumer Privacy)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-ccpa-ccpa-1798-130-135-f5dd6b5b.html","id":"ctrl:ccpa:CCPA-1798.130-135","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Accpa%3ACCPA-1798.130-135","sourceIds":["ccpa"],"sourceUrl":null,"title":"CCPA-1798.130-135 — Request-handling mechanics, verification, and opt-out link requirements","type":"control","url":"/assets/agent_record-ctrl-ccpa-ccpa-1798-130-135-f5dd6b5b.41ca30782c928770.json"},{"attributes":{"category":"administrative","framework":"ccpa","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/ccpa/","description":"Service-provider and contractor contract requirements","details":{"automation":"manual","control_category":"administrative","control_id":"CCPA-1798.140","control_type":"preventive","domains":["Data Protection & Privacy","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"ccpa","group":"CCPA/CPRA (California Consumer Privacy)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-ccpa-ccpa-1798-140-775f9cfa.html","id":"ctrl:ccpa:CCPA-1798.140","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Accpa%3ACCPA-1798.140","sourceIds":["ccpa"],"sourceUrl":null,"title":"CCPA-1798.140 — Service-provider and contractor contract requirements","type":"control","url":"/assets/agent_record-ctrl-ccpa-ccpa-1798-140-775f9cfa.b5ef741dc3aa2c1d.json"},{"attributes":{"category":"technical","framework":"ccpa","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/ccpa/","description":"Reasonable security procedures; private right of action for breaches","details":{"automation":"hybrid","control_category":"technical","control_id":"CCPA-1798.150","control_type":"preventive","domains":["Data Protection & Privacy","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"ccpa","group":"CCPA/CPRA (California Consumer Privacy)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-ccpa-ccpa-1798-150-da298199.html","id":"ctrl:ccpa:CCPA-1798.150","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Accpa%3ACCPA-1798.150","sourceIds":["ccpa"],"sourceUrl":null,"title":"CCPA-1798.150 — Reasonable security procedures; private right of action for breaches","type":"control","url":"/assets/agent_record-ctrl-ccpa-ccpa-1798-150-da298199.b7ad647e847408af.json"},{"attributes":{"category":"administrative","framework":"ccpa","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/ccpa/","description":"CPPA regulations: cybersecurity audits and risk assessments","details":{"automation":"manual","control_category":"administrative","control_id":"CCPA-1798.185","control_type":"detective","domains":["Data Protection & Privacy","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"ccpa","group":"CCPA/CPRA (California Consumer Privacy)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-ccpa-ccpa-1798-185-1b524211.html","id":"ctrl:ccpa:CCPA-1798.185","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Accpa%3ACCPA-1798.185","sourceIds":["ccpa"],"sourceUrl":null,"title":"CCPA-1798.185 — CPPA regulations: cybersecurity audits and risk assessments","type":"control","url":"/assets/agent_record-ctrl-ccpa-ccpa-1798-185-1b524211.18ee652fbb983ef5.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Business Continuity & Disaster Recovery","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["eu-ai-act-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-highrisk-critical-infra","description":"Because AI acting as a safety component in critical digital infrastructure, road traffic, or utilities (Annex III(2)) operates without the required risk management, robustness, and human oversight, it can fail or behave unsafely, resulting in service disruption and threats to public safety and continuity.","details":{"category":"ai_governance","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"ai-highrisk-critical-infra","taxonomies":["eu-ai-act-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-highrisk-critical-infra-a7a37365.html","id":"risk:ai-highrisk-critical-infra","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-highrisk-critical-infra","sourceIds":["aiuc-1","ccpa","cobit-2019","eu-ai-act","iia-2024","iia-pos-2026-three-lines","iso-27001","iso-42001"],"sourceUrl":null,"title":"Public-safety harm from AI in critical infrastructure","type":"risk","url":"/assets/agent_record-risk-ai-highrisk-critical-infra-a7a37365.188d0210ccd8c746.json"},{"attributes":{"category":"compliance_regulatory","domain":["Compliance, Audit & Assurance","Governance, Policy & Oversight"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-no-independent-audit","description":"Because independent internal and external audit and review of information security are not performed, control deficiencies and non-conformities are neither detected nor challenged, so weaknesses persist unremediated and management and the board lose reliable assurance over control effectiveness.","details":{"category":"compliance_regulatory","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"compliance-no-independent-audit","taxonomies":["iso-27005-vulnerability","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-compliance-no-independent-audit-9e1acf0f.html","id":"risk:compliance-no-independent-audit","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-no-independent-audit","sourceIds":["ccpa","cobit-2019","iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-27001","nis2","nist-800-53"],"sourceUrl":null,"title":"Lack of independent audit and compliance review","type":"risk","url":"/assets/agent_record-risk-compliance-no-independent-audit-9e1acf0f.8a44783c74772a6f.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Incident Management & Response"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-event","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-breach-unauthorized-disclosure","description":"Unauthorized disclosure of information to parties not entitled to receive it, whether by insecure controls (insecurity), spillage, or authorized users induced to expose data — resulting in identity theft, economic loss, and loss of trust.","details":{"category":"privacy","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"data-breach-unauthorized-disclosure","taxonomies":["iso-27005-threat","nist-800-30-threat-event","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-breach-unauthorized-disclosure-3b1c296c.html","id":"risk:data-breach-unauthorized-disclosure","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-breach-unauthorized-disclosure","sourceIds":["aiuc-1","ccpa","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","soc2"],"sourceUrl":null,"title":"Unauthorized disclosure / breach of sensitive information","type":"risk","url":"/assets/agent_record-risk-data-breach-unauthorized-disclosure-3b1c296c.8431603df36984c8.json"},{"attributes":{"category":"cyber_security","domain":["Data Protection & Privacy","Secure Development (SDLC) & Application Security"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-corruption-integrity-loss","description":"Intentional or accidental alteration, deletion, defacement, or injection of false-but-believable data into systems (including web defacement and data from untrustworthy sources) renders data inaccurate and erodes confidence in it.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"data-corruption-integrity-loss","taxonomies":["iso-27005-threat","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-corruption-integrity-loss-e771738a.html","id":"risk:data-corruption-integrity-loss","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-corruption-integrity-loss","sourceIds":["aiuc-1","ccpa","cobit-2019","eu-ai-act","hipaa","iso-27001","nist-800-53","soc2"],"sourceUrl":null,"title":"Corruption or integrity loss of critical data","type":"risk","url":"/assets/agent_record-risk-data-corruption-integrity-loss-e771738a.745d8cb348a7d703.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy"],"inherent_rating":"high","taxonomy":["nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-excessive-collection-purpose-creep","description":"Collecting more personal data than necessary (data-minimization failure) and using it for purposes materially different from those disclosed without fresh notice/consent, expanding attack surface and violating purpose-limitation.","details":{"category":"privacy","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"data-excessive-collection-purpose-creep","taxonomies":["nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-excessive-collection-purpose-creep-4a691595.html","id":"risk:data-excessive-collection-purpose-creep","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-excessive-collection-purpose-creep","sourceIds":["ccpa","gdpr","hipaa","iso-27001","nist-800-53","soc2"],"sourceUrl":null,"title":"Excessive collection, purpose creep and secondary use","type":"risk","url":"/assets/agent_record-risk-data-excessive-collection-purpose-creep-4a691595.e19f1e2bcd3171d8.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","AI Governance"],"inherent_rating":"medium","taxonomy":["nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-privacy-harms-to-individuals","description":"Processing inaccurate/out-of-context data (distortion), attaching negative social labels (stigmatization), or denying services based on personal data without justification (unwarranted restriction / algorithmic gatekeeping) — causing discrimination and economic loss.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"data-privacy-harms-to-individuals","taxonomies":["nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-privacy-harms-to-individuals-510e65af.html","id":"risk:data-privacy-harms-to-individuals","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-privacy-harms-to-individuals","sourceIds":["aiuc-1","ccpa","eu-ai-act","gdpr","hipaa","iso-42001","nist-800-53","nist-ai-agent-identity","soc2"],"sourceUrl":null,"title":"Privacy harms: distortion, stigmatization, unwarranted restriction","type":"risk","url":"/assets/agent_record-risk-data-privacy-harms-to-individuals-510e65af.a2f2b4ad6db96f69.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["nist-privacy-risk","enterprise-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-privacy-program-noncompliance","description":"Failure to honour data-subject rights (access, deletion, portability, restriction) on time, missing lawful-basis/consent documentation, defective consent mechanisms, invalid cross-border transfer mechanisms, or inadequate notices — driving fines and private rights of action.","details":{"category":"privacy","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"data-privacy-program-noncompliance","taxonomies":["nist-privacy-risk","enterprise-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-privacy-program-noncompliance-ec6178fa.html","id":"risk:data-privacy-program-noncompliance","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-privacy-program-noncompliance","sourceIds":["aiuc-1","ccpa","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","soc2"],"sourceUrl":null,"title":"Privacy-program non-compliance (GDPR, CCPA, state laws)","type":"risk","url":"/assets/agent_record-risk-data-privacy-program-noncompliance-ec6178fa.f8a5498a8697316f.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy"],"inherent_rating":"medium","taxonomy":["nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-reidentification-inference","description":"Insufficient de-identification/pseudonymization, plus inference or linkage attacks and metadata leakage, re-identify individuals or reveal information they did not intend to disclose — causing embarrassment, harm, and regulatory exposure.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"data-reidentification-inference","taxonomies":["nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-reidentification-inference-d4b31f45.html","id":"risk:data-reidentification-inference","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-reidentification-inference","sourceIds":["aiuc-1","ccpa","hipaa","iso-27001","nist-800-53"],"sourceUrl":null,"title":"Re-identification and unanticipated revelation from data","type":"risk","url":"/assets/agent_record-risk-data-reidentification-inference-d4b31f45.feabe05a491c6f3f.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Compliance, Audit & Assurance"],"inherent_rating":"medium","taxonomy":["nist-privacy-risk","enterprise-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-retention-noncompliance","description":"Retaining personal data beyond necessity/mandated schedules (privacy and breach risk) or deleting records before required retention periods (litigation-hold, regulatory, tax risk); records-management policy not enforced technically.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"data-retention-noncompliance","taxonomies":["nist-privacy-risk","enterprise-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-retention-noncompliance-ec7b8dbc.html","id":"risk:data-retention-noncompliance","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-retention-noncompliance","sourceIds":["ccpa","gdpr","iso-27001","nist-800-53","soc2"],"sourceUrl":null,"title":"Unlawful retention or premature deletion of records","type":"risk","url":"/assets/agent_record-risk-data-retention-noncompliance-ec7b8dbc.36421190fb2586f6.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy"],"inherent_rating":"medium","taxonomy":["nist-privacy-risk","nist-ai-rmf-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-surveillance-appropriation","description":"Pervasive monitoring beyond stated purpose (behavioral analytics, always-on telemetry, employee monitoring), using identity/data for organizational benefit without consent, and coercing individuals to over-share — causing chilling effects and loss of autonomy.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"data-surveillance-appropriation","taxonomies":["nist-privacy-risk","nist-ai-rmf-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-surveillance-appropriation-18ad67e7.html","id":"risk:data-surveillance-appropriation","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-surveillance-appropriation","sourceIds":["ccpa","hipaa","nist-800-53","soc2"],"sourceUrl":null,"title":"Excessive surveillance, appropriation and induced disclosure","type":"risk","url":"/assets/agent_record-risk-data-surveillance-appropriation-18ad67e7.571fc2bbf276fe19.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Awareness & Training"],"inherent_rating":"medium","taxonomy":["nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-transparency-notice-dark-patterns","description":"Failure to give clear, timely notice of collection, use, retention, and sharing; misleading or dark-pattern consent flows; and failure to disclose automated decision-making — undermining meaningful consent and compounding power imbalance.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"data-transparency-notice-dark-patterns","taxonomies":["nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-transparency-notice-dark-patterns-9326fdf0.html","id":"risk:data-transparency-notice-dark-patterns","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-transparency-notice-dark-patterns","sourceIds":["ccpa","gdpr","hipaa","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Inadequate transparency, notice and deceptive privacy communications","type":"risk","url":"/assets/agent_record-risk-data-transparency-notice-dark-patterns-9326fdf0.86b6f27e81ff4310.json"},{"attributes":{"category":"compliance_regulatory","domain":["Human Resources / Personnel Security","Governance, Policy & Oversight","Third-Party / Supply-Chain Risk"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Ahr-missing-security-terms-discipline","description":"Employment and supplier contracts omit security/confidentiality obligations, and there is no disciplinary process for security violations — removing legal recourse and the deterrent effect against repeat offenders.","details":{"category":"compliance_regulatory","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"hr-missing-security-terms-discipline","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-hr-missing-security-terms-discipline-0a47163d.html","id":"risk:hr-missing-security-terms-discipline","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Ahr-missing-security-terms-discipline","sourceIds":["ccpa","coso-ic","gdpr","hipaa","iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Missing security terms in contracts and no disciplinary process","type":"risk","url":"/assets/agent_record-risk-hr-missing-security-terms-discipline-0a47163d.8fa26facc260e210.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Compliance, Audit & Assurance","Third-Party / Supply-Chain Risk"],"inherent_rating":"medium","taxonomy":["nist-privacy-risk","enterprise-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aprivacy-cross-border-transfer","description":"Transferring personal data to jurisdictions lacking equivalent protection without SCCs, BCRs, adequacy decisions, or other recognized mechanisms, exposing individuals and the organization to legal risk.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"privacy-cross-border-transfer","taxonomies":["nist-privacy-risk","enterprise-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-privacy-cross-border-transfer-8fb379b5.html","id":"risk:privacy-cross-border-transfer","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aprivacy-cross-border-transfer","sourceIds":["aiuc-1","ccpa","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2"],"sourceUrl":null,"title":"Cross-border personal-data transfer without safeguards","type":"risk","url":"/assets/agent_record-risk-privacy-cross-border-transfer-8fb379b5.e026bee45d4ef5d1.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Awareness & Training"],"inherent_rating":"medium","taxonomy":["nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aprivacy-loss-of-trust","description":"Systemic failure to meet reasonable privacy expectations undermines confidence in products and institutions, causing disengagement, reputational damage, and reduced adoption — an organizational as well as individual harm.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"privacy-loss-of-trust","taxonomies":["nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-privacy-loss-of-trust-a4d1142c.html","id":"risk:privacy-loss-of-trust","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aprivacy-loss-of-trust","sourceIds":["ccpa","gdpr","hipaa","nist-800-53","soc2","sox"],"sourceUrl":null,"title":"Erosion of individual trust and confidence in data practices","type":"risk","url":"/assets/agent_record-risk-privacy-loss-of-trust-a4d1142c.89dc33b8371b5f90.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","AI Governance"],"inherent_rating":"medium","taxonomy":["nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aprivacy-power-imbalance-self-determination","description":"Structural informational asymmetry (take-it-or-leave-it consent, opaque algorithmic decisions) and inability to correct, delete, or restrict processing deprive individuals of meaningful control over their own data and narrative.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"privacy-power-imbalance-self-determination","taxonomies":["nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-privacy-power-imbalance-self-determination-9112ad1d.html","id":"risk:privacy-power-imbalance-self-determination","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aprivacy-power-imbalance-self-determination","sourceIds":["aiuc-1","ccpa","eu-ai-act","gdpr","hipaa","iso-42001","nist-800-53","soc2"],"sourceUrl":null,"title":"Power imbalance and loss of self-determination over personal data","type":"risk","url":"/assets/agent_record-risk-privacy-power-imbalance-self-determination-9112ad1d.1354cb678bdbd7b3.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atech-illegal-data-processing","description":"Processing personal or sensitive data without legal authority, consent, or in violation of regulatory requirements — a data-protection breach with legal, privacy, and reputational consequences.","details":{"category":"privacy","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"tech-illegal-data-processing","taxonomies":["iso-27005-threat","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tech-illegal-data-processing-859983e3.html","id":"risk:tech-illegal-data-processing","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atech-illegal-data-processing","sourceIds":["ccpa","gdpr","hipaa","nist-800-53","soc2"],"sourceUrl":null,"title":"Illegal processing of personal or sensitive data","type":"risk","url":"/assets/agent_record-risk-tech-illegal-data-processing-859983e3.68c2387d845c9c4d.json"},{"attributes":{"category":"third_party","domain":["Third-Party / Supply-Chain Risk","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-vendor-compliance-vicarious-liability","description":"A vendor, subcontractor, or channel partner violates labor, environmental, anti-bribery (FCPA/UKBA), or data-protection rules, exposing the company to liability and reputational harm; fourth-party/N-tier dependencies are opaque.","details":{"category":"third_party","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"tprm-vendor-compliance-vicarious-liability","taxonomies":["enterprise-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tprm-vendor-compliance-vicarious-liability-0215657c.html","id":"risk:tprm-vendor-compliance-vicarious-liability","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-vendor-compliance-vicarious-liability","sourceIds":["ccpa","cobit-2019","dora","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"Third-party compliance failure creating vicarious liability","type":"risk","url":"/assets/agent_record-risk-tprm-vendor-compliance-vicarious-liability-0215657c.77578fe7de7d58ff.json"},{"attributes":{"category":"third_party","domain":["Third-Party / Supply-Chain Risk"],"inherent_rating":"medium","taxonomy":["basel-operational-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-vendor-service-nonperformance","description":"Outsourced processing, IT, payroll/HR, print/mail, or sub-custodian providers fail to meet service levels, deliver defective software, make incorrect payments, or breach contractual deliverables, causing processing errors, outages, and loss.","details":{"category":"third_party","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"tprm-vendor-service-nonperformance","taxonomies":["basel-operational-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tprm-vendor-service-nonperformance-081f2fb9.html","id":"risk:tprm-vendor-service-nonperformance","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-vendor-service-nonperformance","sourceIds":["ccpa","cobit-2019","dora","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"Vendor/outsourcing service non-performance and disputes","type":"risk","url":"/assets/agent_record-risk-tprm-vendor-service-nonperformance-081f2fb9.6aa8159a02796175.json"},{"attributes":{"category":"third_party","domain":["Third-Party / Supply-Chain Risk","Governance, Policy & Oversight"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-weak-supplier-oversight","description":"Because supplier contracts omit security requirements and SLAs and third-party service delivery is not monitored, processors and sub-processors operate without equivalent, audited obligations, so third-party weaknesses and breaches propagate into the organization undetected.","details":{"category":"third_party","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"tprm-weak-supplier-oversight","taxonomies":["iso-27005-vulnerability","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tprm-weak-supplier-oversight-1baaa012.html","id":"risk:tprm-weak-supplier-oversight","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-weak-supplier-oversight","sourceIds":["ccpa","cobit-2019","dora","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"Weak supplier security requirements and monitoring","type":"risk","url":"/assets/agent_record-risk-tprm-weak-supplier-oversight-1baaa012.91f09390d6cc203e.json"},{"attributes":{"authority":"mandatory","category":"ccpa"},"canonicalUrl":"https://controlsmap.com/frameworks/ccpa/","description":"CCPA/CPRA — California Consumer Privacy","details":{"amendmentState":"CPRA amendments; CPPA regulations","authority":"mandatory","effectiveDate":"2023-01-01 (CPRA operative)","note":null,"propositions":[],"publicationDate":"2018-06-28","reviewed_at":null,"source_url":null,"version":"CCPA (2018) as amended by CPRA (2020)"},"direct":true,"htmlUrl":"/agents/records/std-ccpa-55f3fd20.html","id":"std:ccpa","mapUrl":"https://controlsmap.com/?v=1&node=std%3Accpa","sourceIds":["ccpa"],"sourceUrl":null,"title":"CCPA/CPRA","type":"standard","url":"/assets/agent_record-std-ccpa-55f3fd20.5de3fcc2770545d3.json"},{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-23","description":"The organization plans and obtains independent reviews of its approach to managing and implementing information security - including people, processes, and technologies - at planned intervals, after significant changes, and where required by applicable law or regulation. Before relying on another provider's work, each reliance decision assesses and records the provider's independence and objectivity, competence and methodology rigor, evidence quality and reperformance capability, and recency against the covered risk's cadence, together with the resulting reliance level and rationale. Assurance activities are coordinated across internal and external providers to ensure coverage, minimize duplication, and support reliance on others' work. Material reliance limitations, assurance gaps, and duplication remain visible to management and the board. Results are reported to management and the board and drive corrective actions.","details":{"control_category":"administrative","control_type":"detective","domain":"Compliance, Audit & Assurance","guidance":[{"propositionId":"IIA-POS-TLM-03","propositionTitle":"Assurance Coordination and Reliance","source":"iia-pos-2026-three-lines","sourcePages":"Three Lines pp. 15–16, 18–19","sourceTitle":"Three Lines Model: Assurance and Advice in Support of Effective Governance"}],"members":[{"control_id":"A.5.35","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"CCPA-1798.185","coverage":"partial","delta":"risk-assessment submission obligations handled under risk management controls","framework":"ccpa","relationship":"intersects_with"},{"control_id":"MEA04","coverage":"full","framework":"cobit-2019","relationship":"superset_of"},{"control_id":"Std 9.5","coverage":"full","framework":"iia-2024","relationship":"superset_of"}],"statement":"The organization plans and obtains independent reviews of its approach to managing and implementing information security - including people, processes, and technologies - at planned intervals, after significant changes, and where required by applicable law or regulation. Before relying on another provider's work, each reliance decision assesses and records the provider's independence and objectivity, competence and methodology rigor, evidence quality and reperformance capability, and recency against the covered risk's cadence, together with the resulting reliance level and rationale. Assurance activities are coordinated across internal and external providers to ensure coverage, minimize duplication, and support reliance on others' work. Material reliance limitations, assurance gaps, and duplication remain visible to management and the board. Results are reported to management and the board and drive corrective actions.","title":"Coordinate independent assurance reviews across providers","unified_id":"UC-AUDIT-23"},"direct":false,"htmlUrl":"/agents/records/uc-uc-audit-23-124d94d5.html","id":"uc:UC-AUDIT-23","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-23","sourceIds":["ccpa","cobit-2019","iia-2024","iia-pos-2026-three-lines","iso-27001"],"sourceUrl":null,"title":"UC-AUDIT-23 — Coordinate independent assurance reviews across providers","type":"unified","url":"/assets/agent_record-uc-uc-audit-23-124d94d5.9beb44d85e6248c7.json"},{"attributes":{"category":"administrative","domain":"Data Protection & Privacy","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-02","description":"Where consent or authorization is the basis for collecting, using, retaining, disclosing, selling, or sharing personal data, present the available choices and their consequences clearly and capture freely given, specific, informed consent before the data is collected or disclosed. Maintain auditable consent records, honor withdrawal and opt-out requests (including opt-out of sale/sharing and limits on sensitive-data use) as easily as consent was given, and use compliant authorization forms where required. Document the basis for any implied consent relied upon.","details":{"control_category":"administrative","control_type":"preventive","domain":"Data Protection & Privacy","guidance":[],"members":[{"control_id":"PT-4","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"P2.1","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"P3.2","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"P6.1","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"GDPR-Art7","coverage":"full","framework":"gdpr","relationship":"superset_of"},{"control_id":"HIPAA-164.508","coverage":"partial","delta":"when authorization is mandatory (marketing, sale of PHI, psychotherapy notes) not established","framework":"hipaa","relationship":"intersects_with"},{"control_id":"CCPA-1798.120-121","coverage":"partial","delta":"under-16 opt-in consent before selling/sharing minors' data not addressed","framework":"ccpa","relationship":"intersects_with"}],"statement":"Where consent or authorization is the basis for collecting, using, retaining, disclosing, selling, or sharing personal data, present the available choices and their consequences clearly and capture freely given, specific, informed consent before the data is collected or disclosed. Maintain auditable consent records, honor withdrawal and opt-out requests (including opt-out of sale/sharing and limits on sensitive-data use) as easily as consent was given, and use compliant authorization forms where required. Document the basis for any implied consent relied upon.","title":"Obtain and honor consent for collection, use, and disclosure","unified_id":"UC-DATA-02"},"direct":false,"htmlUrl":"/agents/records/uc-uc-data-02-56e3d60a.html","id":"uc:UC-DATA-02","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-02","sourceIds":["ccpa","gdpr","hipaa","nist-800-53","soc2"],"sourceUrl":null,"title":"UC-DATA-02 — Obtain and honor consent for collection, use, and disclosure","type":"unified","url":"/assets/agent_record-uc-uc-data-02-56e3d60a.45abbc9e83da8a2e.json"},{"attributes":{"category":"administrative","domain":"Data Protection & Privacy","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-05","description":"Publish and maintain privacy notices that describe, in clear and plain language, the categories of personal data collected, purposes, lawful bases, recipients, retention periods, and data-subject rights, and deliver them at or before the point of collection. Update and re-communicate notices in a timely manner when practices change, and publish any legally required registrations such as system-of-records notices. Retain dated notice versions as evidence.","details":{"control_category":"administrative","control_type":"preventive","domain":"Data Protection & Privacy","guidance":[],"members":[{"control_id":"PT-5","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PT-6","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"P1.1","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"GDPR-Art12-14","coverage":"partial","delta":"controller/DPO identity, complaint right, transfer info, automated-decision disclosures, Art 14 source omitted","framework":"gdpr","relationship":"intersects_with"},{"control_id":"HIPAA-164.520","coverage":"partial","delta":"NPP-specific content (header, complaint process, duties, effective date) and acknowledgment mechanics omitted","framework":"hipaa","relationship":"intersects_with"},{"control_id":"CCPA-1798.100","coverage":"partial","delta":"beyond notice-at-collection: 1798.100 general duties (purpose limitation, reasonable security, contractor requirements) and verified right-to-know fulfillment satisfied by companion privacy-rights and security controls","framework":"ccpa","relationship":"intersects_with"}],"statement":"Publish and maintain privacy notices that describe, in clear and plain language, the categories of personal data collected, purposes, lawful bases, recipients, retention periods, and data-subject rights, and deliver them at or before the point of collection. Update and re-communicate notices in a timely manner when practices change, and publish any legally required registrations such as system-of-records notices. Retain dated notice versions as evidence.","title":"Provide privacy notices and transparency to data subjects","unified_id":"UC-DATA-05"},"direct":false,"htmlUrl":"/agents/records/uc-uc-data-05-3244ac25.html","id":"uc:UC-DATA-05","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-05","sourceIds":["ccpa","gdpr","hipaa","nist-800-53","soc2"],"sourceUrl":null,"title":"UC-DATA-05 — Provide privacy notices and transparency to data subjects","type":"unified","url":"/assets/agent_record-uc-uc-data-05-3244ac25.935d6452a2ea1b76.json"},{"attributes":{"category":"administrative","domain":"Data Protection & Privacy","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-06","description":"Operate a mechanism for identified and authenticated individuals to obtain confirmation of processing and a copy of their personal data, including the categories collected, sold, shared, or disclosed and the categories of recipients, within statutory deadlines. Where access is denied, inform the individual of the denial, the reason, and any recourse. Log all requests and responses as evidence.","details":{"control_category":"administrative","control_type":"preventive","domain":"Data Protection & Privacy","guidance":[],"members":[{"control_id":"P5.1","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"HIPAA-164.524","coverage":"full","framework":"hipaa","relationship":"superset_of"},{"control_id":"CCPA-1798.110-115","coverage":"partial","delta":"response must also disclose categories of sources and business/commercial purposes","framework":"ccpa","relationship":"intersects_with"}],"statement":"Operate a mechanism for identified and authenticated individuals to obtain confirmation of processing and a copy of their personal data, including the categories collected, sold, shared, or disclosed and the categories of recipients, within statutory deadlines. Where access is denied, inform the individual of the denial, the reason, and any recourse. Log all requests and responses as evidence.","title":"Provide data subjects access to their personal data","unified_id":"UC-DATA-06"},"direct":false,"htmlUrl":"/agents/records/uc-uc-data-06-14975c65.html","id":"uc:UC-DATA-06","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-06","sourceIds":["ccpa","hipaa","soc2"],"sourceUrl":null,"title":"UC-DATA-06 — Provide data subjects access to their personal data","type":"unified","url":"/assets/agent_record-uc-uc-data-06-14975c65.e1ea4e9d7a7890a9.json"},{"attributes":{"category":"administrative","domain":"Data Protection & Privacy","type":"corrective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-07","description":"Maintain personal data that is accurate, complete, up to date, and relevant for its intended use, with periodic data-quality checks. Provide a process for individuals to request correction or amendment, execute or formally deny each request within statutory deadlines with stated reasons, and communicate corrections to third parties to whom the data was disclosed.","details":{"control_category":"administrative","control_type":"corrective","domain":"Data Protection & Privacy","guidance":[],"members":[{"control_id":"P7.1","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"P5.2","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"HIPAA-164.526","coverage":"partial","delta":"statement-of-disagreement appending and inclusion in future disclosures omitted","framework":"hipaa","relationship":"intersects_with"},{"control_id":"CCPA-1798.106","coverage":"full","framework":"ccpa","relationship":"superset_of"},{"control_id":"SI-18","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Maintain personal data that is accurate, complete, up to date, and relevant for its intended use, with periodic data-quality checks. Provide a process for individuals to request correction or amendment, execute or formally deny each request within statutory deadlines with stated reasons, and communicate corrections to third parties to whom the data was disclosed.","title":"Keep personal data accurate and honor correction requests","unified_id":"UC-DATA-07"},"direct":false,"htmlUrl":"/agents/records/uc-uc-data-07-a6976e38.html","id":"uc:UC-DATA-07","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-07","sourceIds":["ccpa","hipaa","nist-800-53","soc2"],"sourceUrl":null,"title":"UC-DATA-07 — Keep personal data accurate and honor correction requests","type":"unified","url":"/assets/agent_record-uc-uc-data-07-a6976e38.ec335b443cf3e7ed.json"},{"attributes":{"category":"administrative","domain":"Data Protection & Privacy","type":"corrective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-08","description":"Operate a verified rights-request process with designated intake channels, identity verification, and statutory response clocks that executes data-subject rights including erasure/deletion, portability, restriction, objection, and rights related to automated decision-making, and directs service providers to do the same. Do not discriminate or retaliate against individuals for exercising rights, and disclose the material terms of any financial-incentive program with opt-in consent. Track every request end-to-end as evidence.","details":{"control_category":"administrative","control_type":"corrective","domain":"Data Protection & Privacy","guidance":[],"members":[{"control_id":"GDPR-Art15-22","coverage":"partial","delta":"Art 22 standing automated-decision prohibition and Art 19 recipient notification exceed request handling","framework":"gdpr","relationship":"intersects_with"},{"control_id":"CCPA-1798.105","coverage":"partial","delta":"notifying third parties (beyond service providers) to delete sold/shared data omitted","framework":"ccpa","relationship":"intersects_with"},{"control_id":"CCPA-1798.130-135","coverage":"partial","delta":"homepage 'Do Not Sell/Share' links and opt-out preference-signal (GPC) handling omitted","framework":"ccpa","relationship":"intersects_with"},{"control_id":"CCPA-1798.125","coverage":"full","framework":"ccpa","relationship":"superset_of"}],"statement":"Operate a verified rights-request process with designated intake channels, identity verification, and statutory response clocks that executes data-subject rights including erasure/deletion, portability, restriction, objection, and rights related to automated decision-making, and directs service providers to do the same. Do not discriminate or retaliate against individuals for exercising rights, and disclose the material terms of any financial-incentive program with opt-in consent. Track every request end-to-end as evidence.","title":"Execute deletion and other rights requests within deadlines","unified_id":"UC-DATA-08"},"direct":false,"htmlUrl":"/agents/records/uc-uc-data-08-794007b4.html","id":"uc:UC-DATA-08","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-08","sourceIds":["ccpa","gdpr"],"sourceUrl":null,"title":"UC-DATA-08 — Execute deletion and other rights requests within deadlines","type":"unified","url":"/assets/agent_record-uc-uc-data-08-794007b4.ebc8985d46550cb8.json"},{"attributes":{"category":"administrative","domain":"Data Protection & Privacy","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-13","description":"Identify the statutory, regulatory, and contractual requirements that apply to the personal information the organization holds, and implement reasonable administrative, technical, and physical safeguards appropriate to its volume and sensitivity. Assign responsibility for PII protection, verify the safeguards periodically, and remediate identified gaps.","details":{"control_category":"administrative","control_type":"preventive","domain":"Data Protection & Privacy","guidance":[],"members":[{"control_id":"A.5.34","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"CCPA-1798.150","coverage":"full","framework":"ccpa","relationship":"superset_of"},{"control_id":"HIPAA-164.312(c)","coverage":"partial","delta":"the electronic mechanism to authenticate that ePHI has not been altered or destroyed is the specific integrity-verification arm","framework":"hipaa","relationship":"intersects_with"}],"statement":"Identify the statutory, regulatory, and contractual requirements that apply to the personal information the organization holds, and implement reasonable administrative, technical, and physical safeguards appropriate to its volume and sensitivity. Assign responsibility for PII protection, verify the safeguards periodically, and remediate identified gaps.","title":"Safeguard personal information with reasonable security","unified_id":"UC-DATA-13"},"direct":false,"htmlUrl":"/agents/records/uc-uc-data-13-c09befaf.html","id":"uc:UC-DATA-13","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-13","sourceIds":["ccpa","hipaa","iso-27001"],"sourceUrl":null,"title":"UC-DATA-13 — Safeguard personal information with reasonable security","type":"unified","url":"/assets/agent_record-uc-uc-data-13-c09befaf.14b53d834bc3d5bc.json"},{"attributes":{"category":"administrative","domain":"Third-Party / Supply-Chain Risk","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-03","description":"Include binding security and privacy requirements in contracts and agreements with vendors, service providers, and processors before access, service delivery, or data exchange begins: required security controls, confidentiality, breach notification, audit rights, subcontractor terms, and data handling, return, and deletion obligations. Document and authorize each information exchange or system interconnection under an appropriate agreement, and review agreements periodically. Ensure agreements satisfy the contractual clause requirements mandated by applicable privacy and security regulations for the data and services involved.","details":{"control_category":"administrative","control_type":"preventive","domain":"Third-Party / Supply-Chain Risk","guidance":[],"members":[{"control_id":"CA-3","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SA-4","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"GV.SC-05","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GDPR-Art28","coverage":"full","framework":"gdpr","relationship":"superset_of"},{"control_id":"HIPAA-164.314","coverage":"partial","delta":"group health plan document requirements (164.314(b)) fall outside vendor/BA contracting","framework":"hipaa","relationship":"intersects_with"},{"control_id":"CCPA-1798.140","coverage":"full","framework":"ccpa","relationship":"superset_of"}],"statement":"Include binding security and privacy requirements in contracts and agreements with vendors, service providers, and processors before access, service delivery, or data exchange begins: required security controls, confidentiality, breach notification, audit rights, subcontractor terms, and data handling, return, and deletion obligations. Document and authorize each information exchange or system interconnection under an appropriate agreement, and review agreements periodically. Ensure agreements satisfy the contractual clause requirements mandated by applicable privacy and security regulations for the data and services involved.","title":"Bind vendors to security and privacy terms by contract","unified_id":"UC-TPRM-03"},"direct":false,"htmlUrl":"/agents/records/uc-uc-tprm-03-c9edcf93.html","id":"uc:UC-TPRM-03","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-03","sourceIds":["ccpa","gdpr","hipaa","nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"UC-TPRM-03 — Bind vendors to security and privacy terms by contract","type":"unified","url":"/assets/agent_record-uc-uc-tprm-03-c9edcf93.ac47f6d6fa922fb9.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-cybersecurity-assurance-review","description":"Cybersecurity Assurance Review — a CAE-owned assurance engagement that runs on the EXISTING Audit item opened from the audit plan (audit_type=it_audit, status PLANNED, lead_auditor and scope already set): the workflow instance attaches to that item and enriches it end to end, never creating a duplicate engagement record. It covers the three IIA Cybersecurity Topical Requirement domains (governance, risk management, and control activities) over the cyber estate bounded in the engagement memo (in scope: named legal entities, networks, cloud tenants, and OT/ICS where included; out of scope: areas whose assurance is documented as delivered by other engagements), testing against the NIST 800-53 Rev 5 catalog with CSF 2.0 / ISO 27001 as the aggregation frame. It originates from the audit plan (no upstream workflow) and produces the findings register (one four-Cs Issue per finding), the cyber posture summary carrying the per-domain and overall Standard 14.5 conclusions, and the approved engagement package — which it hands to the downstream Audit Report Drafting workflow.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-cybersecurity-assurance-review","capabilities":[],"controls":["UC-AUDIT-12","UC-AUDIT-13","UC-AUDIT-16","UC-AUDIT-23","UC-GOV-15","UC-VULN-01","UC-LOG-04","UC-IR-01","UC-BCDR-13","UC-LOG-01","UC-LOG-03","UC-LOG-05","UC-LOG-08","UC-VULN-05","UC-AUDIT-14"],"domains":["audit"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:b1b1849f755b1bd298e35c5fe4919ba4e021cf217f67943330cb40b47b726828","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[{"code":"reliance-basis-incomplete","message":"Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.","missing":["independence","competence","evidence","recency","reliance rationale"],"nodeIds":[],"title":"Reliance basis is incomplete"}]},"sourceTemplateId":"workflow-library:audit-cybersecurity-assurance-review","standards":["iia-2024","nist-800-53"],"teams":["internal-audit","it"]},"direct":false,"htmlUrl":"/agents/records/wf-a1-f09c8201.html","id":"wf:A1","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AA1","slug":"audit-cybersecurity-assurance-review","sourceIds":["ccpa","cobit-2019","hipaa","iia-2024","iia-pos-2026-three-lines","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Cybersecurity Assurance Review","type":"workflow","url":"/assets/agent_record-wf-a1-f09c8201.bcf6d3e5957c24c1.json"},{"attributes":{"department":"internal-audit","domain":"controls","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-isms-internal-audit-management-review","description":"Runs one ISO 27001 clause 9.2 internal audit and clause 9.3 management review cycle — including clause 10.1 corrective actions — against the existing Audit item for this cycle (audit_type=internal), whose scope, lead_auditor, and period dates already carry the ISMS audit-programme entry: the workflow enriches that Audit item and its findings, never creates a duplicate audit. Upstream it consumes the Annex A control population (Control items, framework iso-27001) and the applicability decisions in the Statement of Applicability, the risk register (Risk items) and treatment plan, the prior-cycle Audit and open Issue records, and the org's ISMS policies and procedures (Policy items) as audit criteria. Named deliverables: the internal audit findings report, the clause 10.1 corrective-action records (recorded on the finding Issue items), the management review pack, and the approved clause 9.3 minutes and action register. Out of scope: the certification-body external audit and day-to-day control operation. No upstream workflow feeds this cycle and no single downstream workflow consumes its output; at close the cycle is archived on the Audit item as retained ISMS documented information, and carry-forward items re-enter the audit programme (the next PLANNED Audit item), the risk register, or the next review's inputs.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-isms-internal-audit-management-review","capabilities":[],"controls":["UC-AUDIT-23","UC-AUDIT-22","UC-GOV-15","UC-AUDIT-17"],"domains":["controls"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:742d77471fcfb9e129cd8c2c7bf4a77d76efc0dc9e0982900aaa8c182a577076","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[{"code":"reliance-basis-incomplete","message":"Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.","missing":["independence","competence","evidence","recency","reliance rationale"],"nodeIds":[],"title":"Reliance basis is incomplete"}]},"sourceTemplateId":"workflow-library:controls-isms-internal-audit-management-review","standards":["iso-27001"],"teams":["internal-audit","it","executive"]},"direct":false,"htmlUrl":"/agents/records/wf-c16-5cfe940e.html","id":"wf:C16","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC16","slug":"controls-isms-internal-audit-management-review","sourceIds":["ccpa","cobit-2019","iia-2024","iia-pos-2026-three-lines","iso-27001","nist-800-53","nist-csf-2","nydfs-500"],"sourceUrl":null,"title":"ISMS Internal Audit & Management Review","type":"workflow","url":"/assets/agent_record-wf-c16-5cfe940e.b4554998fd4e48e4.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:02b6742c91fa0718e15194147640b7f574337534b53d4840d943c3f17c360c59","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-106-35bf5a6c.json","sourceId":"ctrl:ccpa:CCPA-1798.106","targetDetailPath":"/data/v1/records/std-ccpa-55f3fd20.json","targetId":"std:ccpa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0397d83c942955bc563ce4621fb8047bb032df2964e3023994df0f935d05b448","properties":{},"sourceDetailPath":"/data/v1/records/wf-r7-2fc6568b.json","sourceId":"wf:R7","targetDetailPath":"/data/v1/records/uc-uc-data-06-14975c65.json","targetId":"uc:UC-DATA-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:083eb07ca149e8112ed6cf7541a60e05026915716647852270d94d91d25914e5","properties":{"rationale":"Planning and obtaining independent reviews of information security at intervals and after change (ISO A.5.35) is the independent-review control this risk lacks.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","sourceId":"uc:UC-AUDIT-23","targetDetailPath":"/data/v1/records/risk-compliance-no-independent-audit-9e1acf0f.json","targetId":"risk:compliance-no-independent-audit","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0d04968156b772bf7a410f5f378671c49da4e7a97a6afdf67647fdce31650c41","properties":{"rationale":"Ensuring agreements satisfy the contractual clauses mandated by privacy regulations (e.g., GDPR transfer clauses/SCCs) directly enables safeguarded cross-border transfer.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/risk-privacy-cross-border-transfer-8fb379b5.json","targetId":"risk:privacy-cross-border-transfer","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:10ab744fc2f05812744d0be837bb31e3211af44a5d3e5027b8455f310249bb3a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c16-5cfe940e.json","sourceId":"wf:C16","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:11ba931f331b0ba94293ab12e87aa5f837c7ee771592b41dc6e5ade63b027943","properties":{"rationale":"Contractually defining deliverables and obligations before service begins creates enforceable recourse against non-performance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/risk-tprm-vendor-service-nonperformance-081f2fb9.json","targetId":"risk:tprm-vendor-service-nonperformance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:153916c8d4adaef1fddde7e44d7535399a5efac931c724be644ae20200e1f51d","properties":{"control_id":"CCPA-1798.106","coverage":"full","delta":null,"framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","sourceId":"uc:UC-DATA-07","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-106-35bf5a6c.json","targetId":"ctrl:ccpa:CCPA-1798.106","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1827f1bc36ce33f1a9780dee59e37237270664e144f751ebc063fb8b40220d05","properties":{},"sourceDetailPath":"/data/v1/records/wf-r11-a48dfcd0.json","sourceId":"wf:R11","targetDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","targetId":"uc:UC-DATA-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1e2bd6679be011acc04c51bd48e6fb98b29fe6f75a52aeecd0e358286263f14d","properties":{"control_id":"CCPA-1798.150","coverage":"full","delta":null,"framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","sourceId":"uc:UC-DATA-13","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-150-da298199.json","targetId":"ctrl:ccpa:CCPA-1798.150","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:20e3e3a432cb5de49175d693d788e2349042169d81f6a28f7c64fa543f0e823d","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-110-115-cf470a0c.json","sourceId":"ctrl:ccpa:CCPA-1798.110-115","targetDetailPath":"/data/v1/records/std-ccpa-55f3fd20.json","targetId":"std:ccpa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:224ce45cdbe3079825638c0f37c6c30bf72ac8fa4e76a5e2dc798a5602c78ef0","properties":{"control_id":"CCPA-1798.110-115","coverage":"partial","delta":"response must also disclose categories of sources and business/commercial purposes","framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-06-14975c65.json","sourceId":"uc:UC-DATA-06","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-110-115-cf470a0c.json","targetId":"ctrl:ccpa:CCPA-1798.110-115","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:24223814b0af26a6a7bffe54a7395610ea8a9465ebc55bba9c3ada3d2a550911","properties":{},"sourceDetailPath":"/data/v1/records/wf-r10-bc8bf886.json","sourceId":"wf:R10","targetDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","targetId":"uc:UC-DATA-07","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:25b361efed9a48364dfbe8d920629d2fd37c139d5d1072a20087ec08a980df24","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-130-135-f5dd6b5b.json","sourceId":"ctrl:ccpa:CCPA-1798.130-135","targetDetailPath":"/data/v1/records/std-ccpa-55f3fd20.json","targetId":"std:ccpa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2865d6ac583d94f616703bc2f0c20a1747ead3d85b199ce0bc173599f4f10455","properties":{},"sourceDetailPath":"/data/v1/records/wf-r11-a48dfcd0.json","sourceId":"wf:R11","targetDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","targetId":"uc:UC-DATA-13","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2ce39baacf4e08681a6e141f99447226f227084a6d955c5b9f97cc90a6558291","properties":{"rationale":"Maintaining legally-required notices and registrations addresses the inadequate-notice driver of regulatory non-compliance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2e1a500f18d0e2b83e81106ed2f4fbf92860977b1a8e6661d8bc8b375f5e1366","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-140-775f9cfa.json","sourceId":"ctrl:ccpa:CCPA-1798.140","targetDetailPath":"/data/v1/records/std-ccpa-55f3fd20.json","targetId":"std:ccpa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:311f1c9e910cf8d774d86a7bd67c2a5b53ae07067c13a3b348efe6d898619609","properties":{"rationale":"Publishing clear, timely, plain-language notices at/before collection directly counters inadequate/late transparency and non-disclosure of practices.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/risk-data-transparency-notice-dark-patterns-9326fdf0.json","targetId":"risk:data-transparency-notice-dark-patterns","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3779d37740ab4093d5350e29113e0cfd004724773daa5ea2c106899f2f5fa851","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-120-121-7655ba5c.json","sourceId":"ctrl:ccpa:CCPA-1798.120-121","targetDetailPath":"/data/v1/records/std-ccpa-55f3fd20.json","targetId":"std:ccpa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3ac880a93694bbcb186eee38fd1f88554de0deac884da9fba61bd51898c47d5e","properties":{},"sourceDetailPath":"/data/v1/records/wf-d22-f1c724b8.json","sourceId":"wf:D22","targetDetailPath":"/data/v1/records/uc-uc-data-06-14975c65.json","targetId":"uc:UC-DATA-06","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:41280e986145674087f4497ff33260f1d466fb931a9cec5de5003fdfc2bdbd8c","properties":{"rationale":"Disclosing purposes, recipients, retention, and rights reduces the informational asymmetry between organization and individual.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/risk-privacy-power-imbalance-self-determination-9112ad1d.json","targetId":"risk:privacy-power-imbalance-self-determination","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:41b7f73e4fe60fabed772b3cde61b49549111b3158d867c81ed21dbe4177d453","properties":{"rationale":"Obtaining valid consent supplies the lawful basis where consent is required, reducing unlawful processing.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-02-56e3d60a.json","sourceId":"uc:UC-DATA-02","targetDetailPath":"/data/v1/records/risk-tech-illegal-data-processing-859983e3.json","targetId":"risk:tech-illegal-data-processing","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4355f5ef22b06957363d841765100f11a24c6f18d9dbd1b88932c3df041640ef","properties":{},"sourceDetailPath":"/data/v1/records/wf-d22-f1c724b8.json","sourceId":"wf:D22","targetDetailPath":"/data/v1/records/uc-uc-data-02-56e3d60a.json","targetId":"uc:UC-DATA-02","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:48303bab97616f0e5f1342e26f5dd1bca6d01ba43e99eaa60d8ee32cec2458af","properties":{},"sourceDetailPath":"/data/v1/records/wf-g33-6008159c.json","sourceId":"wf:G33","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4c459c2b31ac58cc45c8c8679b0a7d85672da865c3c704c220047944889cd27b","properties":{"rationale":"A correction/amendment right directly addresses the named 'inability to correct' facet of lost self-determination.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","sourceId":"uc:UC-DATA-07","targetDetailPath":"/data/v1/records/risk-privacy-power-imbalance-self-determination-9112ad1d.json","targetId":"risk:privacy-power-imbalance-self-determination","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:507c1d4b76c3c9354c1015bed108c4c0f7deaa70306e648dcb43bee10e0277b5","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-06-14975c65.json","sourceId":"uc:UC-DATA-06","targetDetailPath":"/data/v1/records/risk-data-surveillance-appropriation-18ad67e7.json","targetId":"risk:data-surveillance-appropriation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:507ea1e75ef25e36b5f7364972159265d7e73ab3b750ce7299bd00a585ba5332","properties":{},"sourceDetailPath":"/data/v1/records/wf-r9-636a9e6e.json","sourceId":"wf:R9","targetDetailPath":"/data/v1/records/uc-uc-data-02-56e3d60a.json","targetId":"uc:UC-DATA-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:53a7e11a50d323541c74ab8bc9a41e57728e810b20b91dc44c0eaa12f458c5f1","properties":{"rationale":"Binding required security controls, audit rights, and breach-notification terms into supplier contracts directly supplies the security requirements the risk says are missing.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5d3158fc5a1ac7d68c5708e840c3784b02a21c451532d965567e134722484087","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-150-da298199.json","sourceId":"ctrl:ccpa:CCPA-1798.150","targetDetailPath":"/data/v1/records/std-ccpa-55f3fd20.json","targetId":"std:ccpa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5e7aa8d8a260e84476d64b57fc54ac18bea178c7a41e76f6b8e84aaccadaf9b3","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-105-fdc06468.json","sourceId":"ctrl:ccpa:CCPA-1798.105","targetDetailPath":"/data/v1/records/std-ccpa-55f3fd20.json","targetId":"std:ccpa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5ed1c248bc7ad0fa6172f058cb28b870525e43a8d7677363c3fb0fab266e1f7c","properties":{"control_id":"CCPA-1798.105","coverage":"partial","delta":"notifying third parties (beyond service providers) to delete sold/shared data omitted","framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-08-794007b4.json","sourceId":"uc:UC-DATA-08","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-105-fdc06468.json","targetId":"ctrl:ccpa:CCPA-1798.105","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6a3558ec7e9a10fd979fb2146dad124e9e35ecb0607b2fe082cd69dd44934bc9","properties":{},"sourceDetailPath":"/data/v1/records/wf-c17-334c380f.json","sourceId":"wf:C17","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6da7bf5a3b8a345fe74a341399c60cd7c389912a2449916aea20ee15fa98f734","properties":{},"sourceDetailPath":"/data/v1/records/wf-d22-f1c724b8.json","sourceId":"wf:D22","targetDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","targetId":"uc:UC-DATA-05","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6db868c65485ee877f1cfd1368a44f6b2f96275089bf0a76de3f35673acc94be","properties":{},"sourceDetailPath":"/data/v1/records/wf-d56-387bb72b.json","sourceId":"wf:D56","targetDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","targetId":"uc:UC-TPRM-03","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6e8ccc435a5fcf927ce307de1a1e12e8921071d5f9e7484da8836b088cd51f71","properties":{},"sourceDetailPath":"/data/v1/records/wf-d05-2302db1f.json","sourceId":"wf:D05","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6fd598b196e61c1753b0491a313d783c4e6647f9346bee365fd94eca69bf0ba5","properties":{"rationale":"Including required security and confidentiality obligations in supplier agreements directly fixes the missing-security-terms facet in supplier contracts.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/risk-hr-missing-security-terms-discipline-0a47163d.json","targetId":"risk:hr-missing-security-terms-discipline","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:797932c738f5104f8f4a01aeb7695575ad4d9d28a420458b926f15caabec88ef","properties":{"rationale":"Transparent, current notices meet reasonable privacy expectations, sustaining confidence in data practices.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/risk-privacy-loss-of-trust-a4d1142c.json","targetId":"risk:privacy-loss-of-trust","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:79eff9273f79143b6398cfbda69f47579dc0ad6193385ab69e0a9ac037a7c5fe","properties":{"control_id":"CCPA-1798.120-121","coverage":"partial","delta":"under-16 opt-in consent before selling/sharing minors' data not addressed","framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-02-56e3d60a.json","sourceId":"uc:UC-DATA-02","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-120-121-7655ba5c.json","targetId":"ctrl:ccpa:CCPA-1798.120-121","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7a4fcf47042ea9982abc5f27817a6fafef13967f6bdb8024af9b65241982ffb6","properties":{"rationale":"Contractual flow-down of compliance obligations, subcontractor terms, and audit rights creates recourse and deterrence that reduce vicarious-liability exposure.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/risk-tprm-vendor-compliance-vicarious-liability-0215657c.json","targetId":"risk:tprm-vendor-compliance-vicarious-liability","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7aa69c83502aa3c57c2105fbc3bdea5adaba879e297214818886752faa90e9d2","properties":{"rationale":"Freely-given consent with withdrawal/opt-out as easy as opt-in partly counters take-it-or-leave-it asymmetry.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-02-56e3d60a.json","sourceId":"uc:UC-DATA-02","targetDetailPath":"/data/v1/records/risk-privacy-power-imbalance-self-determination-9112ad1d.json","targetId":"risk:privacy-power-imbalance-self-determination","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:85201cd31f0ee0e6db246c32a2fc40ce83139071e77d05dea752549461bcd912","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","sourceId":"uc:UC-AUDIT-23","targetDetailPath":"/data/v1/records/risk-ai-highrisk-critical-infra-a7a37365.json","targetId":"risk:ai-highrisk-critical-infra","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:900f2470ca4c4df7af12d284683862a42ee705902d2e28bfa5295b4ffbc5620f","properties":{"rationale":"Presenting choices/consequences clearly and capturing freely-given, specific, informed consent directly counters misleading dark-pattern consent flows.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-02-56e3d60a.json","sourceId":"uc:UC-DATA-02","targetDetailPath":"/data/v1/records/risk-data-transparency-notice-dark-patterns-9326fdf0.json","targetId":"risk:data-transparency-notice-dark-patterns","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:91009775ad3f068d3dc9c55e3e41cb9b4a1800e0aff8127b232b2f778cb7108b","properties":{"rationale":"Valid consent capture, records, and honored withdrawals/opt-outs remove the defective-consent-mechanism driver of fines and private actions.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-02-56e3d60a.json","sourceId":"uc:UC-DATA-02","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9675e11635b80d5c85fe22d26aa4c26e65d945d72c3bf7c0a25dd9f24d02e0cb","properties":{"rationale":"No-discrimination/retaliation rules and automated-decision-making rights curb algorithmic gatekeeping and unwarranted restriction.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-08-794007b4.json","sourceId":"uc:UC-DATA-08","targetDetailPath":"/data/v1/records/risk-data-privacy-harms-to-individuals-510e65af.json","targetId":"risk:data-privacy-harms-to-individuals","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9ae7358f763b8260c0f6fe9fa493cc2557b41b004c96ffa66e0f0b76d399a7dd","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9e37e898082c14bfbe659c24feed0d0d1b518d918031c210a3466e77f28c45bc","properties":{"control_id":"CCPA-1798.125","coverage":"full","delta":null,"framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-08-794007b4.json","sourceId":"uc:UC-DATA-08","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-125-f0016e3a.json","targetId":"ctrl:ccpa:CCPA-1798.125","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9faf8a94071e8116b366bb45920bf621cc6c6119423787e39bfe5790e13c6009","properties":{},"sourceDetailPath":"/data/v1/records/wf-a1-f09c8201.json","sourceId":"wf:A1","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a092db43ec68d7cc5bf48c7b8adcbc0c9aeff13ff38233c27c9ff01bc82eaab7","properties":{"control_id":"CCPA-1798.185","coverage":"partial","delta":"risk-assessment submission obligations handled under risk management controls","framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","sourceId":"uc:UC-AUDIT-23","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-185-1b524211.json","targetId":"ctrl:ccpa:CCPA-1798.185","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ad33ac7214bf5abb5e5dd0089a9c14fc9612faa45a4d37273341850d8bc9bbee","properties":{"rationale":"Honoring consent choices and opt-outs meets privacy expectations, sustaining individual trust.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-02-56e3d60a.json","sourceId":"uc:UC-DATA-02","targetDetailPath":"/data/v1/records/risk-privacy-loss-of-trust-a4d1142c.json","targetId":"risk:privacy-loss-of-trust","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b288b6a36eea554ba24fb212fc87faa0c94acca7b8db8977cad9f6d1305a8550","properties":{"rationale":"Keeping data accurate/current and executing corrections directly counters distortion harm from processing inaccurate/out-of-context data.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","sourceId":"uc:UC-DATA-07","targetDetailPath":"/data/v1/records/risk-data-privacy-harms-to-individuals-510e65af.json","targetId":"risk:data-privacy-harms-to-individuals","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b2a214b13d62b4e14783c3eae4ada122863c80907dd25fab0198d7be368231ee","properties":{"rationale":"Fulfilling access requests within statutory deadlines addresses the failure-to-honor-DSR driver of non-compliance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-06-14975c65.json","sourceId":"uc:UC-DATA-06","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b4afee5e0589649b274ce743fe2fe4681eafa401c0640c827db767ab9cff898e","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","targetId":"uc:UC-DATA-13","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b56d83736730185faefb32d434fec9af7c80c5b08446a9620c03e3f2e47a05cd","properties":{"rationale":"Periodic data-quality checks detect and correct inaccurate or altered data, limiting integrity loss.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","sourceId":"uc:UC-DATA-07","targetDetailPath":"/data/v1/records/risk-data-corruption-integrity-loss-e771738a.json","targetId":"risk:data-corruption-integrity-loss","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b9f010e652a86ba096c55275dae7215b6d336e955a7220132db8747e27fd35c9","properties":{"rationale":"Implementing reasonable admin/technical/physical safeguards sized to data volume/sensitivity directly reduces unauthorized disclosure/breach.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","sourceId":"uc:UC-DATA-13","targetDetailPath":"/data/v1/records/risk-data-breach-unauthorized-disclosure-3b1c296c.json","targetId":"risk:data-breach-unauthorized-disclosure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:babc2f679c479b5e1c64ef64adffeec5727c9bab34ed9fee8461e2e6be6d107d","properties":{"rationale":"Executing/denying correction requests within statutory deadlines addresses the DSR-timeliness driver of non-compliance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","sourceId":"uc:UC-DATA-07","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bb610d04c71da3f279147ee116490166020dfc381a936ab40d1bddb6767a0c60","properties":{"rationale":"PII-protection requirements include data-minimization and purpose-limitation, directly addressing over-collection and purpose creep.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","sourceId":"uc:UC-DATA-13","targetDetailPath":"/data/v1/records/risk-data-excessive-collection-purpose-creep-4a691595.json","targetId":"risk:data-excessive-collection-purpose-creep","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bd3d4679a51e4456a526dc8287d9adfe70592a44844d9d0b698e73121dd3757e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-185-1b524211.json","sourceId":"ctrl:ccpa:CCPA-1798.185","targetDetailPath":"/data/v1/records/std-ccpa-55f3fd20.json","targetId":"std:ccpa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bd9fc26d2c6769c24d75fd5160ee8ea0890c901e9bd59e1c6b52910e8bd5a696","properties":{"control_id":"CCPA-1798.130-135","coverage":"partial","delta":"homepage 'Do Not Sell/Share' links and opt-out preference-signal (GPC) handling omitted","framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-08-794007b4.json","sourceId":"uc:UC-DATA-08","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-130-135-f5dd6b5b.json","targetId":"ctrl:ccpa:CCPA-1798.130-135","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c155012acf013e8a1e3c96c8c7765103fb5c190959a137a8a6cc41a1a4350970","properties":{"control_id":"CCPA-1798.140","coverage":"full","delta":null,"framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-140-775f9cfa.json","targetId":"ctrl:ccpa:CCPA-1798.140","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c8ca93910cdaab4b8e5eb6137031ced2d72703c1b8870a0749d54ba253b04841","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","sourceId":"uc:UC-DATA-13","targetDetailPath":"/data/v1/records/risk-data-reidentification-inference-d4b31f45.json","targetId":"risk:data-reidentification-inference","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ccd42bc2159369288be380b381f6b7245fb043acff866634af74660097fb589d","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-100-b353d024.json","sourceId":"ctrl:ccpa:CCPA-1798.100","targetDetailPath":"/data/v1/records/std-ccpa-55f3fd20.json","targetId":"std:ccpa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d7087093aa2ac0f2a9cc70fa5acdfb27e33c2c3e142af2d8bfd87f509a2a1c2c","properties":{},"sourceDetailPath":"/data/v1/records/wf-g28-6078329f.json","sourceId":"wf:G28","targetDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","targetId":"uc:UC-TPRM-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d87f115fdbef50bd52106f58ee1b2e0ebacdc5a152c961fe436b0015ec9d2659","properties":{"rationale":"Executing erasure requests deletes specific subjects' data, reducing unlawful over-retention.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-08-794007b4.json","sourceId":"uc:UC-DATA-08","targetDetailPath":"/data/v1/records/risk-data-retention-noncompliance-ec7b8dbc.json","targetId":"risk:data-retention-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d8b3d2ad2dc1cf91d15037c94c19180526aed4dba44780ac8c5dc7ec24dcffc0","properties":{},"sourceDetailPath":"/data/v1/records/wf-d22-f1c724b8.json","sourceId":"wf:D22","targetDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","targetId":"uc:UC-DATA-07","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d8fe8176e92760aee02eb486cd4dd3d1188788b093d5b3607fbb9b89c0cd8b99","properties":{"control_id":"CCPA-1798.100","coverage":"partial","delta":"beyond notice-at-collection: 1798.100 general duties (purpose limitation, reasonable security, contractor requirements) and verified right-to-know fulfillment satisfied by companion privacy-rights and security controls","framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-100-b353d024.json","targetId":"ctrl:ccpa:CCPA-1798.100","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dd92f9edd53f28da2d66217336321ef8869c946307508aac76da9307959a9a64","properties":{"rationale":"Giving individuals confirmation and a copy of their data plus recipient/category detail directly restores knowledge and control over their own data.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-06-14975c65.json","sourceId":"uc:UC-DATA-06","targetDetailPath":"/data/v1/records/risk-privacy-power-imbalance-self-determination-9112ad1d.json","targetId":"risk:privacy-power-imbalance-self-determination","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ea7b0f02af40eff5e0f538783b7ce78a185f3b1ca45a83e4c65e6f9d8510efdc","properties":{},"sourceDetailPath":"/data/v1/records/wf-r7-2fc6568b.json","sourceId":"wf:R7","targetDetailPath":"/data/v1/records/uc-uc-data-08-794007b4.json","targetId":"uc:UC-DATA-08","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb3246a4e1cba415c2efa0d2ed40ce4947a226ac4a39637acc1c127df8cf7d1b","properties":{"rationale":"Operating deletion, restriction, and objection rights directly restores individuals' ability to delete and restrict processing of their data.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-08-794007b4.json","sourceId":"uc:UC-DATA-08","targetDetailPath":"/data/v1/records/risk-privacy-power-imbalance-self-determination-9112ad1d.json","targetId":"risk:privacy-power-imbalance-self-determination","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f904d64067d0121654ee8d018acdf44e96484364813f8f3778bfcbc227893874","properties":{"rationale":"A verified process executing erasure/portability/restriction/objection within statutory clocks is the core defense against failing to honor DSRs on time.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-08-794007b4.json","sourceId":"uc:UC-DATA-08","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f9caea0220c0f389ba0f63c3e49c48ade41cc55cfbf31a8af1df6c617bbedd4e","properties":{},"sourceDetailPath":"/data/v1/records/wf-g2-bd9bee15.json","sourceId":"wf:G2","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fe06f755edbc3ac0dc9a18f6201ea633e15a5b502d65b18727d884bce33ddc46","properties":{},"sourceDetailPath":"/data/v1/records/wf-g13-0f34ff59.json","sourceId":"wf:G13","targetDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","targetId":"uc:UC-TPRM-03","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ff73172d05c2d771fce0581080cf38bdd1e6275a5a7aed5291070b5869f7d62a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-125-f0016e3a.json","sourceId":"ctrl:ccpa:CCPA-1798.125","targetDetailPath":"/data/v1/records/std-ccpa-55f3fd20.json","targetId":"std:ccpa","type":"belongs_to"}],"schemaVersion":1,"scope":"sources","total":53}
