Frameworks / Nebraska Data Privacy Act / NDPA-4 Nebraska Data Privacy Act
Sensitive Data and Minors
Nebraska Data Privacy Act NDPA-4: Sensitive Data Processing Consent and Childrens Protections Obtain affirmative consent before processing sensitive data including racial or ethnic origin + religious beliefs + mental or physical health diagnosis + sexual orientation + citizenship or immigration status + genetic or biometric data processed for unique identification + precise geolocation + data of known children under 13. For known children under 13 process pursuant to COPPA. For minors aged 13 to under 17 obtain opt-in consent for sale of personal data + targeted advertising (one of the stronger US state law protections for teens).
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 304 controls across 95 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CH-FADP-02 Principles of lawful processing CH-FADP-04 Data subject access right CH-FADP-05 Data accuracy and rectification CH-FADP-09 Notification of data files to the FDPIC CH-FADP-19 Transparency and proactive information CH-FADP-21 Data protection impact assessments FADP-11 Duty to Inform (Article 19) FADP-12 Right of Access (Article 25) FADP-13 Right to Data Portability (Article 28) FADP-15 Data Breach Notification FADP-16 FDPIC Independence and Functions FADP-7 Data Protection Impact Assessment (Articles 9-10) FADP-9 Data Protection Advisor (Articles 14-15) GDPR-Art.10 Processing of personal data relating to criminal convictions GDPR-Art.11 Processing which does not require identification GDPR-Art.15 Right of access by the data subject GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction GDPR-Art.20 Right to data portability GDPR-Art.25 Data protection by design and by default GDPR-Art.35 Data protection impact assessment GDPR-Art.38 Position of the data protection officer GDPR-Art.9 Processing of special categories of personal data NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles NG-NDPA-3 Sensitive Personal Data, Children, and Special Categories NG-NDPA-5 Security of Processing, Breach Notification, and DPIA NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements NG-NDPA-7 Cross-Border Data Transfers and International Cooperation NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-12 Section 62 - Administrative penalties AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing AT-DSG-7 Section 18 - Establishment of the Data Protection Authority BB-DPA-1 Section 1 - Short Title BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-21 Sections 61-69 - Data Privacy Officer BB-DPA-4 Section 4 - Principles Relating to Processing APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A27 Restriction on Provision to Third Parties APPI-A33 Request for Disclosure of Retained Personal Data AZ-DPA-12 Article 13 - Cross-border transfer AZ-DPA-14 Article 16 - Liability for violations AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-6 Article 6 - State regulation in personal data protection UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-Art.8 Records of processing activities (UAE PDPL Article 8) 27400-5.4 Data and privacy risks 27400-7.1 Network Security for IoT 27400-7.3 Data minimization and purpose limitation 27400-7.4 Data retention and deletion NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NHPA-6 Reasonable Data Security and Breach Response NHPA-7 Data Protection Assessments and Processor Contracts NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information ISO27799-03 Minimum necessary standard enforcement ISO27799-04 Patient data de-identification procedures ISO27799-05 Audit trail for ePHI access 27011-5.2 Information Security Roles in Telecoms 27011-6.3 Awareness and Training 27011-8.6 Data protection and backup 29100-6.10 Information security 29100-6.5 Use, retention and disclosure limitation 29100-6.9 Accountability 29134-1 Scope 29134-3 Terms and definitions 29134-9.1 PIA report structure NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-7 Data Protection Assessments and Processor Contracts NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs NGNDPR-4 Data Subject Rights and Automated Decision-Making NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security NGNDPR-6 Data Protection Officer, DPCOs, and Processor Obligations AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-5 APP 12-13 Access and Correction of Personal Information AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response IM8-DAT.2 Data Protection IM8-DAT.3 Data Sharing and Transfer IM8-DAT.4 Data Retention and Disposal ISMSP-PI-01 Personal Information Collection ISMSP-PI-04 Cross-Border Transfer ISMSP-SYS-02 Encryption Implementation TRINIDAD-1 Scope, Definitions, Commission TRINIDAD-4 Security, Accuracy TRINIDAD-5 Enforcement and Sanctions UGA-3 Accountability Principle UGA-6 Personal Data Protection Office UGA-7 Data Protection Officer AL-DPA-12 International Data Transfers AL-DPA-14 Direct Marketing FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) 27557-3 Terms and definitions 27557-4.3 Individual impact consideration NISTSP144-3 Data Classification, Handling, and Sovereignty NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP146-6 Cloud Security and Privacy Recommendations NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring PDPASG-1 Accountability, Records, DPO Appointment, and Training PDPASG-4 Children's Data, DPIA, and Privacy by Design PDPATH-4 DPIA, Privacy by Design, Children's Data PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training POPIASA-4 Special Personal Information, Children, Information Quality, Documentation POPIASA-7 Information Officer, Records of Processing, Notification, Training PAKPDPB-3 Data Subject Rights PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training NORWAY-4 DPIA, Privacy by Design, Records of Processing NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training RUSPD-1 Scope, Definitions, Principles under 152-FZ RUSPD-4 Special Categories, Biometric Data SA-PDPL-19 Data protection officer designation SA-PDPL-21 Data protection impact assessments 502 Interoperability with Assistive Technology 707 Real-Time Text Functionality PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 SWE-1 Scope and Purpose SWE-2 Relationship to GDPR TEF-2 Openness and Transparency TEFCAREC-1 Common Agreement Conformance and Onboarding TURKEYKVKK-1 VERBIS Registration and Lawful Basis TURKEYKVKK-2 Information Notice and Data Subject Rights Standard 15 Online Tools Standard 2 Data Protection Impact Assessments UKGDPRREG-2 Data Subject Rights (Articles 12-22) UKGDPRREG-3 Controller and Processor (Articles 24-43) CPSC-CS.3 Data Protection for Safety Systems CPSC-STD.4 Interoperability Safety USMCADIGITAL-1 Cross-Border Data Flows and Localisation USMCADIGITAL-2 Personal Information Protection and Consumer Protection URUGUAY-4 Security and Cross-Border URUGUAY-5 Database Registration with AGESIC URCDP VERMONTAICDA-1 AI System Inventory and Risk Assessment VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) VIETNAMCYBER-4 Incident Reporting and Cooperation ASD37-27 Outbound data loss prevention (Very Good) AWWA-3.4 Encryption and Data Protection DS-2 Ensure software supply chain security CPG-3.C Strong and Agile Encryption CA-10 Selects and Develops Control Activities DIQ-1 Data Integration and Interoperability ISO-26000-6.7 Consumer issues ISO8000-MDG-01 Master Data Quality ISO23894-A.5 Privacy and Data Protection in AI LV-PDPL-Data-Subject-Rights-Access-Correction-Erasure-Restriction-Portability-Objection-Sec18-Sec38 Latvia PDPL Data Subject Rights + Access + Correction + Erasure + Portability + Section 18 + 38 NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OMANCS-4 Data Protection, Cryptography, and Privacy Alignment PARAGUAY-5 Security of Processing, Data Integrity, Information Security PERU-3 Data Subject Rights (ARCO), Habeas Data, Automated Decisions QATAR-7 DPO, Records, Retention, Marketing, Training RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) SOC-CY-C2 Encryption and Data Protection STUDPRV-2 Data Subject Rights for Students and Parents TISAXASS-3 Prototype Protection and Confidentiality TAIWAN-3 Data Subject Rights TANZANIA-1 Scope, Registration, Lawful Basis TSSR-INFO-1 Network Data Protection TEXASTDPSA-3 Sensitive Data, Children, Sale Notice UKAI-2 Sector-Specific Regulator Engagement D.1 Incident Response Planning UNESCOAI-2 Principles 4-7: Sustainability, Privacy, Human Oversight, Transparency UNICEFAI-4 Transparency, Explanation, Adult Capacity US-ITAR-EAR-DS-01 Technical Data Protection VIETNAMPDP-3 Data Subject Rights VIRGINIAVCDPA-3 Sensitive Data Consent and Children Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 304 it maps to, and the evidence behind each claim, over MCP and REST.