Frameworks / Oregon Consumer Privacy Act / OREGONCPA-5 Oregon Consumer Privacy Act
Assessments, PbD, Security
Oregon Consumer Privacy Act OREGONCPA-5: Data Protection Assessments, Privacy by Design, Security Practices Conduct data protection assessments + apply privacy by design + maintain security practices per Oregon OCPA per ORS 646A.580. Data Protection Assessments (DPAs) per ORS 646A.580 are required for processing activities that present a heightened risk of harm including (a) sale of personal data, (b) targeted advertising, (c) profiling producing legal or similarly significant effects, (d) processing sensitive data, (e) processing for purposes other than the purpose for which the data was collected (further processing). DPAs must (a) identify + weigh benefits flowing to controller + consumer + other interested parties + the public + (b) consider risks to the rights of consumers + (c) document mitigations + (d) be available to Attorney General on request. Privacy by design and default per general OCPA obligations must (a) embed privacy considerations in system design + procurement + change management + (b) maintain privacy-preserving defaults + (c) maintain data minimisation by design. Reasonable Data Security Practices per ORS 646A.578 must (a) establish + implement + maintain reasonable administrative + technical + physical data security practices appropriate to volume + nature + complexity of activities, (b) align with applicable security frameworks (NIST CSF + ISO 27001 + state breach notification preceded security standards).
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 341 controls across 98 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
GDPR-Art.10 Processing of personal data relating to criminal convictions GDPR-Art.11 Processing which does not require identification GDPR-Art.15 Right of access by the data subject GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction GDPR-Art.25 Data protection by design and by default GDPR-Art.35 Data protection impact assessment GDPR-Art.38 Position of the data protection officer GDPR-Art.9 Processing of special categories of personal data ISO27799-01 ePHI access controls and authorization ISO27799-03 Minimum necessary standard enforcement ISO27799-04 Patient data de-identification procedures ISO27799-05 Audit trail for ePHI access ISO27799-06 Security management process and risk analysis ISO27799-08 Information access management ISO27799-17 Facility access controls ISMSP-AC-01 Access Control Policy ISMSP-AC-04 Network Access Control ISMSP-MS-02 Risk Management ISMSP-PI-01 Personal Information Collection ISMSP-PI-04 Cross-Border Transfer ISMSP-SYS-02 Encryption Implementation ISMSP-SYS-04 Vulnerability Management AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-12 Section 62 - Administrative penalties AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing AT-DSG-7 Section 18 - Establishment of the Data Protection Authority BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions BSI-13 Risk assessment procedures BSI-15 Security categorization BSI-17 Continuous monitoring strategy BB-DPA-1 Section 1 - Short Title BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-20 Sections 50-60 - Registration and Responsibilities BB-DPA-21 Sections 61-69 - Data Privacy Officer BB-DPA-4 Section 4 - Principles Relating to Processing 27011-5.2 Information Security Roles in Telecoms 27011-5.3 Segregation of duties 27011-6.3 Awareness and Training 27011-8.1 User Endpoint Devices 27011-8.6 Data protection and backup NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management API1164-24 Vulnerability assessment for critical systems APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A26 Report of Leakage to the Commission and Notification to the Person APPI-A33 Request for Disclosure of Retained Personal Data AWWA-1.2 Risk Assessment AWWA-2.1 User Access Management AWWA-2.4 Physical Access Controls AWWA-3.4 Encryption and Data Protection AZ-DPA-12 Article 13 - Cross-border transfer AZ-DPA-14 Article 16 - Liability for violations AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-6 Article 6 - State regulation in personal data protection UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures IEC62443-24 Vulnerability assessment for critical systems ISO23894-6.3 AI Risk Assessment ISO23894-6.3.1 AI Risk Identification ISO23894-6.3.3 AI Risk Evaluation ISO23894-A.5 Privacy and Data Protection in AI ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures ISO27019-24 Vulnerability assessment for critical systems 27400-5.4 Data and privacy risks 27400-7.1 Network Security for IoT 27400-7.3 Data minimization and purpose limitation 27400-7.4 Data retention and deletion NORWAY-4 DPIA, Privacy by Design, Records of Processing NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response IM8-DAT.2 Data Protection IM8-DAT.4 Data Retention and Disposal IM8-SEC.2 Access Control IM8-SEC.4 Vulnerability Management APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information ISO27043-11 Access control policy and enforcement ISO27043-14 Privileged access management ISO27043-15 Access review and recertification 27557-3 Terms and definitions 27557-4.3 Individual impact consideration 27557-6.3 Privacy risk assessment 29100-6.10 Information security 29100-6.5 Use, retention and disclosure limitation 29100-6.9 Accountability 29134-1 Scope 29134-3 Terms and definitions 29134-9.1 PIA report structure ISO21434-12 User access management and provisioning ISO21434-14 Privileged access management ISO21434-15 Access review and recertification PAKPDPB-6 Cross-Border Transfer and Data Localization PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training NZPRV-2 IPP 5 Storage and Security of Personal Information NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 CPSC-CS.2 Authentication and Access Controls CPSC-CS.3 Data Protection for Safety Systems CPSC-RA.3 Lifecycle Risk Assessment AL-DPA-12 International Data Transfers AL-DPA-14 Direct Marketing DSO-2 Data Security DSO-3 Data Access Management IS.D.OR.205 Information Security Risk Assessment IS.I.OR.205 Information Security Risk Assessment CAT-D3-1 Preventative controls CAT-D4-3 Third-party access controls FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) Sapin2-Pillar3-Risk-Mapping Pillar 3 - Corruption Risk Mapping (Cartographie des Risques) Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A) ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain ISO27003-6.1 Actions to address risks and opportunities ISO27003-8.2 Information security risk assessment 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use NDPA-1 Applicability, Scope, and Carve-Outs NDPA-4 Sensitive Data Processing Consent and Childrens Protections ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security RUSPD-1 Scope, Definitions, Principles under 152-FZ RUSPD-4 Special Categories, Biometric Data 2.4.4 Hazard Analysis and Risk Assessment 2.7.2 Food Fraud Plan TURKEYKVKK-2 Information Notice and Data Subject Rights TURKEYKVKK-3 Special Categories and Sensitive Data CRM-1 AML/CFT Compliance CRM-4 Business Risk Assessment D.1 Incident Response Planning UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP) USMCADIGITAL-1 Cross-Border Data Flows and Localisation USMCADIGITAL-2 Personal Information Protection and Consumer Protection VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VERMONTAICDA-4 Vermont AG Enforcement and Cure VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) VIETNAMCYBER-4 Incident Reporting and Cooperation AMLCTF-PartA-RiskAssess ML/TF Risk Assessment CPS230-11 Identification, Assessment and Management of Operational Risk ASD37-27 Outbound data loss prevention (Very Good) 4.3.1 Risk Assessment and Impact Analysis DS-2 Ensure software supply chain security CA-10 Selects and Develops Control Activities CA-ITSG33-SC-01 Security Control Catalogue IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment 62351-8 Role-based access control (RBAC) ISO-22313-8.2 Business impact analysis and risk assessment ISO-26000-6.7 Consumer issues ISO-26262-3-7 Hazard analysis and risk assessment (HARA) ISO28001-PS-01 Facility Security ISO20000-15 Access management for services 27031-7.2 Resource Requirements 29147-5.11 Researcher Safe Harbour and Legal Posture ITIL4-15 Access management for services NFPA1600-5.1 Risk Assessment ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) TEFCAREC-1 Common Agreement Conformance and Onboarding OB-CX.2 Granular Consent Management USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 341 it maps to, and the evidence behind each claim, over MCP and REST.