[Print Page] | [Close]
Chartered Accountants of Canada

Generally Accepted Privacy Principles

Generally Accepted Privacy Principles (GAPP) is a comprehensive privacy framework that is designed to assist management in creating an effective privacy program that addresses privacy risks and business opportunities. It was developed under a joint effort of the CICA and the American Institute of Certified Public Accountants (AICPA) through the AICPA/CICA Privacy Task Force.

Formerly known as the AICPA/CICA Privacy Framework, it is founded on a single privacy principle that is supported by 10 principles and over 70 objective and measurable criteria. Click here for a description of GAPP’s overall privacy objective and its 10 principles.

GAPP can be used by organizations to perform a thorough review of their privacy practices, such as:

  • Privacy policy design and implementation
  • Performance Measurement
  • Benchmarking
  • Monitoring and auditing privacy programs

 

Generally Accepted Privacy Principles was updated in August 2009

Summary of changes

 

Privacy – An Introduction to Generally Accepted Privacy Principles

An overview and introduction to GAPP [PDF]

 

Generally Accepted Privacy Principles - A Global Privacy Framework

Business Version [PDF] - for members in industry or businesses in general
Practitioner Version [PDF] - for members in public practice

 

Appendices of Generally Accepted Privacy Principles – A Global Privacy Framework

Appendix A: Glossary – Commonly used privacy terms
Appendix B: CA Practitioner Services Using GAPP (included in Practitioner Version only)
Appendix C: Illustrative Privacy Audit Reports (included in Practitioner Version only)