Apply Section 7 PII sharing controls including: information sharing agreements (ISA) + memoranda of understanding (MOU) + computer matching agreements per Computer Matching and Privacy Protection Act of 1988; cross-border transfer safeguards per FTC Section 5 + APEC CBPR + EU-US Data Privacy Framework + Standard Contractual Clauses + Binding Corporate Rules where applicable; data processing agreements (DPA) with vendors + processors + third parties + cloud providers per FedRAMP + StateRAMP + DoD Impact Levels. Conduct Privacy Impact Assessment (PIA) prior to sharing per E-Government Act 2002.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 62 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021