APRA’s draft Prudential Standard, CPS 230 Operational Risk Management, has implications for data management service providers
Legal update, APRA's draft CPS 230 Operational Risk Management: Implications for data protection obligations. This update provides an overview of the Australian Prudential Regulation Authority's (APRA's) draft Prudential Standard, CPS 230 Operational Risk Management, and its potential implications for data protection obligations for APRA-regulated entities, especially in regard to the use of third or fourth party data storage or data processing service providers. The update also provides information regarding the projected timeline for the finalisation and implementation of CPS 230.