A supplementary statement is an explanatory note attached to disputed personal data when the person and the organisation do not agree on its accuracy. It does not replace the original record. Instead, it records the disagreement so anyone relying on the data can see that the information is contested.
What the term means in practice
A supplementary statement is not a correction in the record itself. It is a formal note that preserves the disputed version of the data while making clear that the subject has challenged its accuracy.
This matters because the original entry remains visible to systems and users that rely on it, so the supplementary statement functions as an attached context layer rather than a replacement. In privacy and records workflows, that distinction helps preserve traceability, accountability, and the integrity of the underlying record.
How it changes data handling
Once attached, the statement affects how the record should be read, interpreted, and relied on. A downstream user should be able to see that the information is contested before making a decision that depends on it.
That makes the term especially important in systems where accuracy, dispute handling, and data subject rights overlap. A supplementary statement does not settle the disagreement on its own, but it ensures the organisation cannot treat the challenged data as uncontested fact.
Relationship to correction and record integrity
The key distinction is that a supplementary statement preserves history. If the organisation believes the record is correct, the disputed entry can still remain, but the note records that there is a live disagreement about it.
This is useful in audit trails, customer records, compliance workflows, and any process where later reviewers need to understand both the original assertion and the objection to it. It prevents the common mistake of assuming that a dispute must either erase the original entry or leave the record unchanged.
Why it matters for reliance and decision-making
Because the note travels with the record, it can change how confidently the data should be used. Decision-makers may need to factor in the dispute, especially where the data affects risk scoring, eligibility, eligibility checks, or other outcomes that depend on accuracy.
If the statement is not surfaced properly, the organisation can continue operating as though the record were uncontested, which weakens transparency and can propagate incorrect assumptions into other systems.
Risk and Threat Considerations
A supplementary statement reduces the risk of silent reliance on disputed personal data, but it only helps if it is consistently displayed and carried forward. If downstream systems ignore the note, the same inaccurate record can still drive decisions, create privacy harm, or amplify a records dispute.
Failure mechanism: The organisation stores the dispute note separately, suppresses it in user interfaces, or fails to propagate it into dependent systems, so consumers of the data never see that the record is contested.
Impact: Incorrect or disputed personal data may continue to be used as if it were settled, increasing the chance of unfair decisions, compliance gaps, and avoidable customer or subject harm.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | A.5.1 — Principles | Supplementary statements support fair, transparent processing of disputed personal data. |
| A.16 — Security of processing | Contested records need integrity and visibility controls so disputes are not lost downstream. | |
| Recommendation — Ensure disputed data carries an attached explanatory note wherever the record is used. Preserve dispute notices across systems, exports, and user-facing views. | ||
| NIST SP 800-53 Rev 5 | AU-3 — Content of Audit Records | The term depends on preserving contextual record information about disagreement. |
| AC-6 — Least Privilege | Only authorised users should alter or remove dispute annotations tied to personal records. | |
| Recommendation — Log dispute annotations so reviewers can see when data accuracy is contested. Restrict who can edit or clear supplementary statements on sensitive records. | ||
| ISO/IEC 27001:2022 | A.5.34 — Privacy and protection of PII | PII governance requires preserving dispute context for contested personal data. |
| Recommendation — Maintain supplementary statements as part of PII handling and record governance. | ||
Practitioner Guidance
Common misunderstanding: A supplementary statement is not a correction and should not overwrite the original record. Practitioners should treat it as an attached explanation that changes how the data is interpreted, not as a data-edit operation.
Governance implication: The note needs clear ownership, durable retention, and visibility wherever the underlying record is used. If a record can be exported, replicated, or surfaced in a portal, the supplementary statement should remain attached so the dispute does not disappear in transit.
Related resources from NHI Mgmt Group
- What do teams get wrong about the statement of applicability?
- How do you know if quantum preparedness is more than a policy statement?
- What is the difference between relying on a transfer framework and relying on updated standard contractual clauses with supplementary measures?
- How should security teams write an ISO 27001 Statement of Applicability so it stands up in audit and internal review?