Personal Data Act (personopplysningsloven)
Security

Personal Data Act (personopplysningsloven) NORWAY-5: Security of Processing, Encryption, Pseudonymization, Access Control

Per Norwegian PDPA + GDPR Article 32: security of processing. Requirements include (a) implement appropriate technical + organisational security measures appropriate to risk per GDPR Article 32 + (b) implement Encryption of personal data at rest + in transit + appropriate to classification + (c) implement Pseudonymization Techniques where appropriate + (d) implement Access Control for personal data including authentication + authorisation + audit + (e) conduct Regular Security Testing and Assessment + (f) integrate with broader information security programme + (g) align with NSM (Norwegian National Security Authority) guidance + Datatilsynet expectations.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 275 controls across 87 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27043:2015 · 7 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification
  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management

ISO/SAE 21434 · 7 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification
  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-19 Certificate management

APPI · 6 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A31 Provision of Personally Referable Information
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APPI-A34 Request for Correction, Addition or Deletion

Bahrain PDPL · 6 controls

NIST SP 800-53 Rev 5 · 6 controls

  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)

GDPR · 5 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.9 Processing of special categories of personal data

ISO 27799:2025 · 5 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-08 Information access management
  • ISO27799-16 Transmission security and encryption
  • ISO27799-17 Facility access controls

South Korea ISMS-P · 5 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-04 Network Access Control
  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-SYS-02 Encryption Implementation
  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection

BSI IT-Grundschutz · 4 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-08 Cryptographic protection of data

ISO/IEC 27400:2022 · 4 controls

  • 27400-5.4 Data and privacy risks
  • 27400-6.2 Device Identity and Authentication
  • 27400-6.3 Secure Update Mechanism
  • 27400-7.3 Data minimization and purpose limitation
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP
  • NGOB-2 Customer Consent Management and Lifecycle
  • NGOB-3 API Security Standards, mTLS, and Encryption
  • NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN
  • OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections
  • OREGONCPA-4 Universal Opt-Out, Targeted Advertising, Profiling
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs

API 1164 · 3 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

IEC 62443 · 3 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

ISO/IEC 27010:2015 · 3 controls

  • 27010-10.1 Cryptographic Protection
  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 3 controls

  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices
  • 27011-8.3 Cryptography and key management

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

NIST SP 1800-32 · 3 controls

  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management
  • ORANWG11-8 Supply Chain, Secure Development Lifecycle, Privacy, Multi-Vendor Trust
  • IM8-CLD.2 Cloud Security Controls
  • IM8-DSS.3 Secure Development Practices
  • IM8-SEC.2 Access Control

South Korea PIPA · 3 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls
  • FFIEC-08 Application security controls
  • FFIEC-09 Encryption and key management
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • 62351-8 Role-based access control (RBAC)
  • 62351-9 Cyber security key management
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment

OpenSSF Scorecard · 2 controls

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts

PDPA Singapore · 2 controls

  • PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis
  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 2 controls

  • PDPATH-5 Security Measures and Data Protection
  • PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-4 Incident Reporting and Cooperation
  • ASD37-17 TLS encryption between email servers (Limited)
  • AL-DPA-12 International Data Transfers
  • DS-2 Ensure software supply chain security
  • CA-10 Selects and Develops Control Activities
  • CA-ITSG33-SC-01 Security Control Catalogue
  • CTDPA-1 Definitions

FIDO2 / WebAuthn · 1 control

  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ISO28001-PS-01 Facility Security
  • ISO20000-15 Access management for services

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.5 Privacy and Data Protection in AI
  • 29115-7.4 Level of Assurance 4 (LoA4)

ITIL 4 · 1 control

  • ITIL4-15 Access management for services
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

NIST SP 800-190 · 1 control

  • NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection
  • NZISM-3 Personnel Security, Physical Security, and Cryptography

OECD AI Principles · 1 control

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 275 it maps to, and the evidence behind each claim, over MCP and REST.