Nebraska Data Privacy Act
Privacy Notice and Data Hygiene

Nebraska Data Privacy Act NDPA-5: Privacy Notice, Data Minimisation, and Purpose Limitation

Provide a reasonably accessible + clear + meaningful privacy notice that includes: (1) categories of personal data processed, (2) purposes of processing, (3) how consumers may exercise their rights including the appeal process, (4) categories of personal data shared with third parties, (5) categories of third parties with whom data is shared, (6) opt-out method for sale + targeted advertising + profiling. Apply data minimisation - process only personal data adequate + relevant + reasonably necessary in relation to the disclosed purposes. Apply purpose limitation - do not process personal data for purposes incompatible with the disclosed purposes without consent.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 423 controls across 164 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-3 Sensitive Personal Data, Children, and Special Categories
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance

ISO 22320:2018 · 6 controls

  • ISO-22320-5.1 General process requirements
  • ISO-22320-5.2 Incident management process
  • ISO-22320-5.3 Incident management structure (command)
  • ISO-22320-5.4 Roles and responsibilities
  • ISO-22320-B Annex B: Incident management plan structure
  • ISO-22320-C Annex C: Incident management task examples

ISO/IEC 29100:2024 · 6 controls

  • 29100-1 Scope
  • 29100-3 Terms and definitions
  • 29100-4.1 Actors and roles
  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

APPI · 5 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA

Bahrain PDPL · 5 controls

  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-2 Section 2 - Interpretation
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer

GDPR · 5 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.9 Processing of special categories of personal data
  • NRC7354-2 Critical Digital Asset (CDA) Identification, Scope, and Boundary
  • NRC7354-4 Security Controls Implementation per NRC RG 5.71 Appendix B/C
  • RG5.71-C.3 Cyber Security Training
  • RG5.71-C.5 Recovery and Restoration
  • RG5.71-C.6 Configuration Management

South Korea ISMS-P · 5 controls

  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-SYS-02 Encryption Implementation
  • ISMSP-SYS-04 Vulnerability Management
  • ISMSP-SYS-05 Incident Response
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-2 Article 2 - Basic Concepts
  • FFIEC-05 Roles and responsibilities definition
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement

ISO/IEC 23894:2023 · 4 controls

  • ISO23894-1 Scope of AI Risk Management
  • ISO23894-3 AI-Specific Terminology
  • ISO23894-6.2 Scope, Context and Criteria
  • ISO23894-A.5 Privacy and Data Protection in AI

ISO/IEC 27400:2022 · 4 controls

  • 27400-3 Terms and definitions
  • 27400-5.4 Data and privacy risks
  • 27400-6.5 Security monitoring and incident response
  • 27400-7.3 Data minimization and purpose limitation
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • 27557-6.2 Scope, context, and criteria for privacy

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • AL-DPA-1 Scope and Definitions
  • AL-DPA-12 International Data Transfers
  • AL-DPA-3 Lawful Basis for Processing
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information

BSI IT-Grundschutz · 3 controls

  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management
  • RMD-1 Reference Data Management
  • IS.AR.215 Information Security Incident Response
  • IS.D.OR.225 External Reporting of Information Security Events
  • IS.I.OR.225 External Reporting
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • FDBR-702 Definitions (§501.702)
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • IEC62304-5.2 Software Requirements Analysis
  • IEC62304-5.3 Software Architectural Design
  • IEC62304-7.2 Risk Control Measures

IEC 62443 · 3 controls

  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents
  • ISO-15189-5.1 Legal entity
  • ISO-15189-5.4 Structure and authority
  • ISO-15189-6.7 Service agreements
  • ISO-19650-1-4 Information management concepts
  • ISO-19650-1-7 Common Data Environment (CDE) concept
  • ISO-19650-3-5.3 Trigger events for information exchange

ISO/IEC 27004:2016 · 3 controls

  • 27004-3 Terms and definitions
  • 27004-A.2 Patching and Vulnerability Measures
  • 27004-B.1 Example measurement definitions

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

ISO/IEC 30111:2019 · 3 controls

  • 30111-3 Terms and definitions
  • 30111-5.1 Organizational policy
  • 30111-5.2 Vulnerability handling team
  • NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NHPA-6 Reasonable Data Security and Breach Response
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-6 Reasonable Data Security and Incident Response
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management
  • ORANWG11-6 Security Test Specifications, Certification, and Conformance
  • PICSGMP-2 Chapter 2: Personnel - Qualified Personnel, Key Responsibilities, Training
  • PICSGMP-5 Chapter 5: Production Operations and Material Management
  • PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management

South Korea PIPA · 3 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • PIPA-Sensitive-Information-Unique-ID-Resident-Registration-Numbers-CCTV-Articles-23-24-25 Korea PIPA Sensitive Information + Unique ID + RRN + CCTV + Articles 23-25
  • TRINIDAD-1 Scope, Definitions, Commission
  • TRINIDAD-2 Lawful Processing and Consent
  • TRINIDAD-3 Data Subject Rights

UK Bribery Act 2010 · 3 controls

  • Section 6(5) Definition of Foreign Public Official
  • Section 8 Definition of Associated Person
  • UKBRIBE-3 Due Diligence on Third Parties
  • 58.1 Scope
  • 58.3 Definitions

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.7 Emergency and Incident Response
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training
  • CA-10 Selects and Develops Control Activities
  • CA-12 Deploys Through Policies and Procedures
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-6 Configuration Settings
  • FEDRAMP-CP-9 System Backup
  • 60601-1.3 Terminology and definitions
  • 60601-1.4.1 General requirements
  • ISO-20400-4.2 Principles of sustainable procurement
  • ISO-20400-7.2 Integrating sustainability into specifications
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • ISO28001-PI-01 Personnel Security Screening
  • ISO-41001-4.1 Understanding the organization and its context
  • ISO-41001-4.3 Determining the scope of the FM management system

ISO 56002 · 2 controls

  • ISO-56002-4.3 Determining the scope of the innovation management system
  • ISO-56002-8.3.4 Develop solutions
  • ISO8000-DQM-02 Data Quality Dimensions
  • ISO8000-MDG-03 Continuous Improvement
  • ISO-17025-5.1 Legal entity
  • ISO-17025-5.4 Personnel for the management system
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 27011:2024 · 2 controls

  • 27011-1 Scope
  • 27011-3 Terms and definitions

ISO/IEC 27014:2020 · 2 controls

  • 27014-1 Scope
  • 27014-3 Terms and definitions

ISO/IEC 29147:2018 · 2 controls

  • 29147-3 Terms and definitions
  • 29147-9.2 Contact mechanisms and scope
  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management
  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • RIDTPPA-1 Scope, Applicability, Definitions
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • PICERL-P2 Risk Assessment
  • PICERL-P3 CSIRT Formation

SOC 2 · 2 controls

  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SSAE18-CC7.4 CC7.4 - Incident Response
  • SSAE18-PI1.1 PI1.1 - Processing Integrity Definition
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • SCA-S2 Interpretation and Definitions
  • SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.3 Incident Response
  • TANZANIA-1 Scope, Registration, Lawful Basis
  • TANZANIA-4 Security and Cross-Border
  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • UKGAMBLE-1 Scope and Applicability to Licensees
  • UKGAMBLE-4 Resilience and Incident Response
  • CYB-5 Cyber Incident Response Plan
  • USMTSA-2 Cybersecurity Assessment and CSO Designation
  • US-SEC-DA-SC-01 Howey Test Application
  • US-SEC-DA-SC-02 Registration Requirements
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-4 Incident Reporting and Cooperation
  • CFR211-A-3 Section 211.3 - Definitions
  • CPS230-13 Board Accountability for Operational Risk Management
  • DS-2 Ensure software supply chain security
  • CPG-6.B Supply Chain Incident Reporting

COBIT 2019 · 1 control

  • COBIT-BAI02 Managed requirements definition
  • CA-ITSG33-SC-01 Security Control Catalogue
  • CTDPA-1 Definitions
  • CAT-D5-1 Incident planning and strategy

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections
  • Sapin2-Pillar1-Code-of-Conduct Pillar 1 - Anti-Corruption Code of Conduct
  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor
  • IATA-IOSA-Section1-ORG-Organization-ManagementSystem-SMS IATA IOSA Section 1 - ORG Organization and Management System + Safety Management System (SMS) + Safety Policy + Hazard ID + Quality
  • 62351-2 Glossary of terms
  • ISO-14064-1-5.1 Organizational boundaries
  • ISO-26262-3-5 Item definition
  • ISO20000-11 Incident management

ISO/IEC 23837:2023 · 1 control

  • 23837-1.1 Scope

ISO/IEC 27003:2017 · 1 control

  • ISO27003-4.3 Determining the scope of the information security management system

ISO/IEC 27007:2020 · 1 control

  • 27007-5.2 Audit Programme Objectives

ISO/IEC 27010:2015 · 1 control

  • 27010-16.1 Continuity of Sharing

ISO/IEC 27031:2011 · 1 control

  • 27031-5.1 IRBC Policy

ISO/IEC 27043:2015 · 1 control

  • ISO27043-04 Roles and responsibilities definition
  • 27050-1.4 Terms and definitions
  • 29115-3 Terms and definitions

ISO/SAE 21434 · 1 control

  • ISO21434-04 Roles and responsibilities definition

ITIL 4 · 1 control

  • ITIL4-11 Incident management
  • BIPA-SEC5-1 Biometric Identifier Definition

NERC CIP · 1 control

  • NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009)
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment

NIST SP 800-123 · 1 control

NIST SP 800-137 · 1 control

  • NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-145 · 1 control

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition

NIST SP 800-146 · 1 control

  • NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework

NIST SP 800-190 · 1 control

  • NISTSP61-2 Computer Security Incident Response Team (CSIRT) Structure and Staffing

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-1 Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-1 Log Management Programme, Policy, Roles, and Operational Runbooks
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold

OSFI B-13 · 1 control

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense
  • DSOMM-1 Culture, Organization, Education, and Governance

OWASP SAMM · 1 control

  • OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures
  • OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX

OpenSSF Scorecard · 1 control

  • OSSFSC-1 Branch Protection, Code Review, and Repository Governance

PCI DSS 4.0 · 1 control

  • 2.2.2 2.2.2 Vendor default accounts managed

PCI P2PE · 1 control

  • PCI-P2PE-05 Roles and responsibilities definition

PCI PIN Security · 1 control

  • PCI-PIN-05 Roles and responsibilities definition

PCI SSF · 1 control

  • PCI-SSF-05 Roles and responsibilities definition

PSD2 SCA · 1 control

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements

PTES · 1 control

  • PTESPHASE-1 Pre-Engagement Interactions and Scoping
  • PHILCC-1 Computer Crime Offences (Illegal Access, Interference, Misuse of Devices)
  • PSPF24-1 Security Culture, Governance, Risk Management
  • RCEPEC-1 Online Personal Information Protection (12.13)
  • SHAREASSESS-1 Information Governance and Risk

SLSA · 1 control

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SWE-2 Relationship to GDPR
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11)
  • OB-OPS.2 Performance Standards
  • UK-TSA-NET-01 Security Architecture
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VPSHR-3 Implementation Guidance and Reporting

WCAG 2.2 · 1 control

  • WCAGREC-3 Principle 3: Understandable
  • SO2.2 Digital health architecture blueprint

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 423 it maps to, and the evidence behind each claim, over MCP and REST.