Frameworks / Oregon Consumer Privacy Act / OREGONCPA-7 Oregon Consumer Privacy Act
Processor and Transfers
Oregon Consumer Privacy Act OREGONCPA-7: Processor Contracts, Cross-Border Transfers, DPAs Operate processor contracts + cross-border transfers + data processing agreements per Oregon OCPA per ORS 646A.584. Processor Contracts and Obligations must (a) bind processors via written contract per ORS 646A.584, (b) include processing instructions + duration + nature + purpose + categories of data + obligations of processor including confidentiality + assistance + breach notification + deletion or return + audit cooperation, (c) flow down to subcontractors with controller approval + (d) maintain processor inventory + ongoing monitoring. Cross-border transfer safeguards must (a) implement appropriate safeguards for international transfers + (b) align with applicable federal export controls + sanctions, (c) consider data localisation requirements in target jurisdictions, (d) align with broader corporate data flow governance. Data processing agreements must (a) be in writing with processors and where applicable joint controllers, (b) document scope + responsibilities + assistance obligations, (c) integrate with broader vendor risk management.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 234 controls across 71 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
GDPR-Art.10 Processing of personal data relating to criminal convictions GDPR-Art.11 Processing which does not require identification GDPR-Art.15 Right of access by the data subject GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction GDPR-Art.45 Transfers on the basis of an adequacy decision GDPR-Art.9 Processing of special categories of personal data UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.22_23_24 Cross-border data transfers (UAE PDPL Articles 22-24) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes NORWAY-4 DPIA, Privacy by Design, Records of Processing NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control NORWAY-6 International Transfers and Processor Agreements NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement AUPRV-3 APP 6-9 Use/Disclosure, Direct Marketing, Cross-Border, Government Identifiers AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A33 Request for Disclosure of Retained Personal Data APPI-A34 Request for Correction, Addition or Deletion APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information APP-8 APP 8 - Cross-border disclosure of personal information BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-17 Section 24 - Appropriate Safeguards BB-DPA-21 Sections 61-69 - Data Privacy Officer ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management NZPRV-2 IPP 5 Storage and Security of Personal Information NZPRV-5 IPP 11-12 Disclosure, Cross-Border Disclosure (Schedule 8) NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training EHDS-HOLD-3 Dataset Descriptions and Catalogues EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29) EHDSREG-4 Digital Health Authorities, Governance, MyHealth@EU EHDSREG-5 Cross-Border Health Data Flows PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2 AL-DPA-12 International Data Transfers AL-DPA-14 Direct Marketing AL-DPA-7 Right of Access AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing AZ-DPA-12 Article 13 - Cross-border transfer AZ-DPA-14 Article 16 - Liability for violations AZ-DPA-15 Article 17 - Dispute resolution FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements ISO23894-6.3.1 AI Risk Identification ISO23894-A.1 Data Quality and Representativeness ISO23894-A.5 Privacy and Data Protection in AI ISO-25012-5.1 Establishing data quality requirements ISO-25012-5.2 Defining data quality measures ISO-25012-5.3 Planning and performing data quality evaluations 27400-5.4 Data and privacy risks 27400-6.2 Device Identity and Authentication 27400-7.3 Data minimization and purpose limitation 29100-6.10 Information security 29100-6.5 Use, retention and disclosure limitation 29100-6.9 Accountability 29134-1 Scope 29134-3 Terms and definitions 29134-9.1 PIA report structure NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) ISMSP-PI-01 Personal Information Collection ISMSP-PI-04 Cross-Border Transfer ISMSP-SYS-02 Encryption Implementation OB-CX.2 Granular Consent Management OB-SEC.2 Transport Layer Security OB-SEC.4 Certificate Management VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) VIETNAMCYBER-3 Data Localization and Cross-Border VIETNAMCYBER-4 Incident Reporting and Cooperation AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection DIQ-2 Data Quality Management DIQ-3 Metadata Management CJIS-8 Media Protection CJIS-9 System and Communications Protection FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) ISO27799-02 ePHI encryption at rest and in transit ISO27799-16 Transmission security and encryption 27557-3 Terms and definitions 27557-4.3 Individual impact consideration OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) PAKPDPB-6 Cross-Border Transfer and Data Localization PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training RUSPD-1 Scope, Definitions, Principles under 152-FZ RUSPD-4 Special Categories, Biometric Data IM8-CLD.2 Cloud Security Controls IM8-CLD.4 Cloud Data Sovereignty TURKEYKVKK-2 Information Notice and Data Subject Rights TURKEYKVKK-3 Special Categories and Sensitive Data USMCADIGITAL-1 Cross-Border Data Flows and Localisation USMCADIGITAL-2 Personal Information Protection and Consumer Protection ASD37-17 TLS encryption between email servers (Limited) DS-2 Ensure software supply chain security BSI-08 Cryptographic protection of data CA-10 Selects and Develops Control Activities FFIEC-09 Encryption and key management ICP-25 Supervisory Cooperation and Coordination 62351-9 Cyber security key management 27010-10.1 Cryptographic Protection 27011-8.3 Cryptography and key management 29115-7.4 Level of Assurance 4 (LoA4) STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management OWASPAPI-6 Security Misconfiguration and Secure API Design OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) TEFCAREC-1 Common Agreement Conformance and Onboarding VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 234 it maps to, and the evidence behind each claim, over MCP and REST.