Nebraska Data Privacy Act
Risk and Vendor Management

Nebraska Data Privacy Act NDPA-7: Data Protection Assessments and Processor Contracts

Conduct and document Data Protection Assessments (DPAs) for high-risk processing including: (a) sale of personal data, (b) targeted advertising, (c) profiling presenting reasonably foreseeable risk of unfair or deceptive treatment + financial or physical injury + intrusion upon solitude + other substantial injury, (d) processing of sensitive data, (e) any processing presenting heightened risk of harm. Document risk vs benefit analysis. Make assessments available to AG upon request. Maintain processor contracts with required NDPA clauses (instructions + duration + nature + purpose + types of data + obligations + return/delete on termination + audit rights + subprocessor consent + confidentiality).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 359 controls across 98 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 9 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.25 Data protection by design and by default
  • GDPR-Art.35 Data protection impact assessment
  • GDPR-Art.38 Position of the data protection officer
  • GDPR-Art.45 Transfers on the basis of an adequacy decision
  • GDPR-Art.9 Processing of special categories of personal data

Bahrain PDPL · 7 controls

  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-17 Section 24 - Appropriate Safeguards
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-3 Sensitive Personal Data, Children, and Special Categories
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements
  • NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

ISO 27799:2025 · 6 controls

  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-03 Minimum necessary standard enforcement
  • ISO27799-04 Patient data de-identification procedures
  • ISO27799-05 Audit trail for ePHI access
  • ISO27799-06 Security management process and risk analysis
  • ISO27799-16 Transmission security and encryption
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-3 APP 6-9 Use/Disclosure, Direct Marketing, Cross-Border, Government Identifiers
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.22_23_24 Cross-border data transfers (UAE PDPL Articles 22-24)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes

ISO/IEC 23894:2023 · 5 controls

  • ISO23894-6.3 AI Risk Assessment
  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-6.3.3 AI Risk Evaluation
  • ISO23894-A.1 Data Quality and Representativeness
  • ISO23894-A.5 Privacy and Data Protection in AI

ISO/IEC 27400:2022 · 5 controls

  • 27400-5.4 Data and privacy risks
  • 27400-6.2 Device Identity and Authentication
  • 27400-7.1 Network Security for IoT
  • 27400-7.3 Data minimization and purpose limitation
  • 27400-7.4 Data retention and deletion
  • IM8-CLD.2 Cloud Security Controls
  • IM8-CLD.4 Cloud Data Sovereignty
  • IM8-DAT.2 Data Protection
  • IM8-DAT.4 Data Retention and Disposal
  • IM8-SEC.4 Vulnerability Management

South Korea ISMS-P · 5 controls

  • ISMSP-MS-02 Risk Management
  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-SYS-02 Encryption Implementation
  • ISMSP-SYS-04 Vulnerability Management

APPI · 4 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APPI-A34 Request for Correction, Addition or Deletion
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • APP-8 APP 8 - Cross-border disclosure of personal information
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection

BSI IT-Grundschutz · 4 controls

  • BSI-08 Cryptographic protection of data
  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy

ISO/IEC 27011:2024 · 4 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.3 Cryptography and key management
  • 27011-8.6 Data protection and backup

ISO/IEC 27043:2015 · 4 controls

  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management

ISO/SAE 21434 · 4 controls

  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-19 Certificate management
  • PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism
  • PQC-5 Cryptographic Inventory and PQC Migration Roadmap
  • PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation
  • PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response
  • NGCB-1 Regulation 5.260 Scope, Applicability, and Licensee Categories
  • NGCB-5 Technical Security Controls - Access + Network + Encryption + Vulnerability + Logging
  • NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management
  • NGCB-8 Annual Independent Cybersecurity Assessment + Reporting + Board Oversight
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGNDPR-6 Data Protection Officer, DPCOs, and Processor Obligations
  • NGNDPR-7 Cross-Border Transfer of Personal Data under NDPR Section 2.7-CBT
  • NGNDPR-8 Annual Data Protection Audit, Penalties, and NDPA Transition
  • EHDS-HOLD-3 Dataset Descriptions and Catalogues
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • EHDSREG-4 Digital Health Authorities, Governance, MyHealth@EU
  • EHDSREG-5 Cross-Border Health Data Flows

South Korea PIPA · 4 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2
  • AWWA-1.2 Risk Assessment
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection
  • AL-DPA-12 International Data Transfers
  • AL-DPA-14 Direct Marketing
  • AL-DPA-7 Right of Access
  • CJIS-17 Risk Assessment
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements
  • ISO-25012-5.1 Establishing data quality requirements
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • 27557-6.3 Privacy risk assessment

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure
  • NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NHPA-6 Reasonable Data Security and Breach Response
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-3 Data Localization and Cross-Border
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

API 1164 · 2 controls

  • API1164-07 Remote Access
  • API1164-24 Vulnerability assessment for critical systems
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-27 Outbound data loss prevention (Very Good)
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management
  • IS.D.OR.205 Information Security Risk Assessment
  • IS.I.OR.205 Information Security Risk Assessment
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • Sapin2-Pillar3-Risk-Mapping Pillar 3 - Corruption Risk Mapping (Cartographie des Risques)
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain

IEC 62443 · 2 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-24 Vulnerability assessment for critical systems

ISO/IEC 27003:2017 · 2 controls

  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.2 Information security risk assessment

ISO/IEC 27019:2024 · 2 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-24 Vulnerability assessment for critical systems

OWASP ASVS · 2 controls

OWASP MASVS · 2 controls

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan

Turkey KVKK · 2 controls

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • D.1 Incident Response Planning
  • UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP)
  • CPSC-CS.3 Data Protection for Safety Systems
  • CPSC-RA.3 Lifecycle Risk Assessment
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • AMLCTF-PartA-RiskAssess ML/TF Risk Assessment
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • 4.3.1 Risk Assessment and Impact Analysis
  • DS-2 Ensure software supply chain security
  • CA-10 Selects and Develops Control Activities
  • CTDPA-1 Definitions
  • FFIEC-09 Encryption and key management

FIDO2 / WebAuthn · 1 control

  • ICP-25 Supervisory Cooperation and Coordination
  • 62351-9 Cyber security key management
  • ISO-22313-8.2 Business impact analysis and risk assessment

ISO 26000:2010 · 1 control

  • ISO-26000-6.7 Consumer issues
  • ISO-26262-3-7 Hazard analysis and risk assessment (HARA)

ISO/IEC 27010:2015 · 1 control

  • 27010-10.1 Cryptographic Protection

ISO/IEC 27031:2011 · 1 control

  • 27031-7.2 Resource Requirements
  • 29115-7.4 Level of Assurance 4 (LoA4)

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • AIGF-1.3 Data Management
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 359 it maps to, and the evidence behind each claim, over MCP and REST.