Frameworks / Nebraska Data Privacy Act / NDPA-8 Nebraska Data Privacy Act
Enforcement and Compliance
Nebraska Data Privacy Act NDPA-8: Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties Acknowledge exclusive enforcement by the Nebraska Attorney General Mike Hilgers (in office since January 2023). No private right of action. Civil penalties up to USD 7,500 per violation under the Nebraska Consumer Protection Act. Receive 30-day cure period (which is PERMANENT - unlike Connecticut + Indiana + Tennessee + Texas which have cure period sunsets) before AG may bring action. Effective date: 1 January 2025. Maintain compliance documentation including AG notification readiness + cure response procedures + executive accountability.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 109 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles NG-NDPA-3 Sensitive Personal Data, Children, and Special Categories NG-NDPA-4 Data Subject Rights and Automated Decision-Making NG-NDPA-5 Security of Processing, Breach Notification, and DPIA NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements NG-NDPA-7 Cross-Border Data Transfers and International Cooperation CH-FADP-19 Transparency and proactive information CH-FADP-21 Data protection impact assessments CH-FADP-25 Compliance monitoring and auditing FADP-16 FDPIC Independence and Functions FADP-7 Data Protection Impact Assessment (Articles 9-10) FADP-9 Data Protection Advisor (Articles 14-15) AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction AT-DSG-12 Section 62 - Administrative penalties AT-DSG-7 Section 18 - Establishment of the Data Protection Authority UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Status UAE PDPL status, executive regulations, UAE Data Office guidance evolution ISO27799-03 Minimum necessary standard enforcement ISO27799-04 Patient data de-identification procedures ISO27799-05 Audit trail for ePHI access 27011-5.2 Information Security Roles in Telecoms 27011-6.3 Awareness and Training 27011-8.6 Data protection and backup NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security NGNDPR-6 Data Protection Officer, DPCOs, and Processor Obligations NGNDPR-8 Annual Data Protection Audit, Penalties, and NDPA Transition AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-6 Article 6 - State regulation in personal data protection BB-DPA-1 Section 1 - Short Title BB-DPA-4 Section 4 - Principles Relating to Processing 27400-7.1 Network Security for IoT 27400-7.4 Data retention and deletion PAKPDPB-6 Cross-Border Transfer and Data Localization PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO IM8-DAT.2 Data Protection IM8-DAT.4 Data Retention and Disposal PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2 VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VERMONTAICDA-4 Vermont AG Enforcement and Cure ASD37-27 Outbound data loss prevention (Very Good) AWWA-3.4 Encryption and Data Protection AL-DPA-14 Direct Marketing CPG-3.C Strong and Agile Encryption FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) ISO-26000-6.7 Consumer issues ISO23894-A.5 Privacy and Data Protection in AI NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination DSOMM-6 Metrics, Maturity Measurement, and Continuous Improvement EHDSREG-5 Cross-Border Health Data Flows RUSPD-4 Special Categories, Biometric Data TURKEYKVKK-3 Special Categories and Sensitive Data D.1 Incident Response Planning CPSC-CS.3 Data Protection for Safety Systems HE-3 FSA compliance requirements VIETNAMCYBER-4 Incident Reporting and Cooperation Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 109 it maps to, and the evidence behind each claim, over MCP and REST.