GAPP: Generally Accepted Privacy Principles
The AICPA/CPA Canada GAPP contains ten privacy principles and 73 related criteria that are essential for the proper protection and management of personal information. These privacy principles and criteria are based on internationally known fair information practices included in privacy laws and regulations of various jurisdictions around the world. The criteria can be used by organizations to perform privacy strategic and business planning, privacy gap and risk analysis, and privacy policy design and implementation. While not every one of the criteria is related to outsourcing activities, many are. Here are the principles and specific criteria that can be used in designing good privacy practices for an organization's outsourcing activities. The numbers refer back to specific citations within the GAPP.