Frameworks / Nigeria Data Protection Act 2023 (NDPA) / NG-NDPA-7 Nigeria Data Protection Act 2023 (NDPA)
Cross-Border Transfers
Nigeria Data Protection Act 2023 (NDPA) NG-NDPA-7: Cross-Border Data Transfers and International Cooperation Conduct cross-border data transfers per NDPA Section 41(CBT) using adequate level of protection mechanisms including: countries on NDPC Whitelist (adequacy) + Binding Corporate Rules (BCR) approved by NDPC + Standard Contractual Clauses approved by NDPC + explicit consent + necessary for performance of contract + public interest + legal claims + vital interests. Conduct Transfer Impact Assessments for transfers to high-risk jurisdictions. Coordinate with Mauritius + Ghana + Kenya + Senegal + AU Convention 2014 on cyber security and personal data protection.
What else in your programme already covers this This control maps to 399 controls across 115 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
GDPR-Art.10 Processing of personal data relating to criminal convictions GDPR-Art.11 Processing which does not require identification GDPR-Art.15 Right of access by the data subject GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction GDPR-Art.25 Data protection by design and by default GDPR-Art.35 Data protection impact assessment GDPR-Art.38 Position of the data protection officer GDPR-Art.45 Transfers on the basis of an adequacy decision GDPR-Art.9 Processing of special categories of personal data BB-DPA-1 Section 1 - Short Title BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-17 Section 24 - Appropriate Safeguards BB-DPA-20 Sections 50-60 - Registration and Responsibilities BB-DPA-21 Sections 61-69 - Data Privacy Officer BB-DPA-4 Section 4 - Principles Relating to Processing NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-3 Opt-Out Rights for Targeted Advertising, Sale, and Profiling NDPA-4 Sensitive Data Processing Consent and Childrens Protections NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NDPA-6 Reasonable Security Practices and Incident Response NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-12 Section 62 - Administrative penalties AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing AT-DSG-7 Section 18 - Establishment of the Data Protection Authority AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework AUPRV-3 APP 6-9 Use/Disclosure, Direct Marketing, Cross-Border, Government Identifiers AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A33 Request for Disclosure of Retained Personal Data APPI-A34 Request for Correction, Addition or Deletion APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information APP-8 APP 8 - Cross-border disclosure of personal information AZ-DPA-12 Article 13 - Cross-border transfer AZ-DPA-14 Article 16 - Liability for violations AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-6 Article 6 - State regulation in personal data protection BSI-08 Cryptographic protection of data BSI-13 Risk assessment procedures BSI-15 Security categorization BSI-17 Continuous monitoring strategy PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism PQC-5 Cryptographic Inventory and PQC Migration Roadmap PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response NGCB-1 Regulation 5.260 Scope, Applicability, and Licensee Categories NGCB-5 Technical Security Controls - Access + Network + Encryption + Vulnerability + Logging NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management NGCB-8 Annual Independent Cybersecurity Assessment + Reporting + Board Oversight NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security NGNDPR-6 Data Protection Officer, DPCOs, and Processor Obligations NGNDPR-7 Cross-Border Transfer of Personal Data under NDPR Section 2.7-CBT NGNDPR-8 Annual Data Protection Audit, Penalties, and NDPA Transition EHDS-HOLD-3 Dataset Descriptions and Catalogues EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29) EHDSREG-4 Digital Health Authorities, Governance, MyHealth@EU EHDSREG-5 Cross-Border Health Data Flows NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NHPA-6 Reasonable Data Security and Breach Response NHPA-7 Data Protection Assessments and Processor Contracts NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-7 Data Protection Assessments and Processor Contracts NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs PAKPDPB-6 Cross-Border Transfer and Data Localization PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training ASD37-17 TLS encryption between email servers (Limited) ASD37-27 Outbound data loss prevention (Very Good) DIQ-2 Data Quality Management DIQ-3 Metadata Management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) 6.6 Confidentiality or non-disclosure agreements 6.7 Conducting Audit Follow-up 6.6 Confidentiality or non-disclosure agreements 6.7 Conducting Audit Follow-up 6.6 Confidentiality or non-disclosure agreements 6.7 Conducting Audit Follow-up OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process RUSPD-1 Scope, Definitions, Principles under 152-FZ RUSPD-4 Special Categories, Biometric Data 2.4.4 Hazard Analysis and Risk Assessment 2.7.2 Food Fraud Plan CRM-1 AML/CFT Compliance CRM-4 Business Risk Assessment D.1 Incident Response Planning UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP) CPS230-11 Identification, Assessment and Management of Operational Risk 9.1 Risk communication and consultation 4.3.1 Risk Assessment and Impact Analysis DS-2 Ensure software supply chain security CA-10 Selects and Develops Control Activities ICP-25 Supervisory Cooperation and Coordination 62351-9 Cyber security key management 9.1 Risk communication and consultation 29147-5.11 Researcher Safe Harbour and Legal Posture STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment NZISM-3 Personnel Security, Physical Security, and Cryptography AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold OWASPAPI-6 Security Misconfiguration and Secure API Design OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) TEFCAREC-1 Common Agreement Conformance and Onboarding USCOPPA-3 Data Minimisation, Retention, Erasure (Eraser Button) Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 399 it maps to, and the evidence behind each claim, over MCP and REST.