NIST SP 800-122
Sharing and Transfers

NIST SP 800-122 NISTSP122-7: PII Sharing, Cross-Border Transfers, and Third-Party Agreements

Apply Section 7 PII sharing controls including: information sharing agreements (ISA) + memoranda of understanding (MOU) + computer matching agreements per Computer Matching and Privacy Protection Act of 1988; cross-border transfer safeguards per FTC Section 5 + APEC CBPR + EU-US Data Privacy Framework + Standard Contractual Clauses + Binding Corporate Rules where applicable; data processing agreements (DPA) with vendors + processors + third parties + cloud providers per FedRAMP + StateRAMP + DoD Impact Levels. Conduct Privacy Impact Assessment (PIA) prior to sharing per E-Government Act 2002.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 62 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • EHDS-HOLD-3 Dataset Descriptions and Catalogues
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • EHDSREG-4 Digital Health Authorities, Governance, MyHealth@EU
  • EHDSREG-5 Cross-Border Health Data Flows

Bahrain PDPL · 3 controls

  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.22_23_24 Cross-border data transfers (UAE PDPL Articles 22-24)
  • UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes
  • ISO-25012-5.1 Establishing data quality requirements
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations
  • AUPRV-3 APP 6-9 Use/Disclosure, Direct Marketing, Cross-Border, Government Identifiers
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

South Korea PIPA · 3 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2
  • AL-DPA-14 Direct Marketing
  • AL-DPA-7 Right of Access
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management

ISO/IEC 23894:2023 · 2 controls

  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-A.1 Data Quality and Representativeness
  • APP-8 APP 8 - Cross-border disclosure of personal information
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • BB-DPA-17 Section 24 - Appropriate Safeguards

GDPR · 1 control

  • GDPR-Art.45 Transfers on the basis of an adequacy decision
  • ICP-25 Supervisory Cooperation and Coordination
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • RUSPD-4 Special Categories, Biometric Data
  • AIGF-1.3 Data Management
  • IM8-CLD.4 Cloud Data Sovereignty

South Korea ISMS-P · 1 control

  • ISMSP-PI-04 Cross-Border Transfer

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • VIETNAMCYBER-3 Data Localization and Cross-Border

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 62 it maps to, and the evidence behind each claim, over MCP and REST.