Personal Data Act (personopplysningsloven)
Transfer and Processor Management

Personal Data Act (personopplysningsloven) NORWAY-6: International Transfers and Processor Agreements

Per Norwegian PDPA + GDPR Chapter V + Article 28: transfer + processor management. Requirements include (a) implement International Transfers restrictions per GDPR including adequacy + appropriate safeguards (SCCs + BCRs + certification) + derogations + (b) maintain Cross-Border Transfer Safeguards documentation + Transfer Impact Assessment (TIA) per Schrems II + (c) maintain Processor Agreements per GDPR Article 28 ensuring processors process only on documented instructions + maintain security + assist with rights + breach notification + (d) maintain inventory of cross-border flows + recipients + safeguards + (e) implement supplier + processor + sub-processor due diligence + (f) cooperate with Datatilsynet on transfer matters.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 32 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • EHDSREG-4 Digital Health Authorities, Governance, MyHealth@EU
  • EHDSREG-5 Cross-Border Health Data Flows
  • CH-FADP-24 Cross-border transfer safeguards
  • FADP-10 Cross-Border Disclosure (Articles 16-18)
  • AL-DPA-14 Direct Marketing
  • APP-8 APP 8 - Cross-border disclosure of personal information
  • AZ-DPA-12 Article 13 - Cross-border transfer

Bahrain PDPL · 1 control

  • BB-DPA-17 Section 24 - Appropriate Safeguards
  • UAE-PDPL-Art.22_23_24 Cross-border data transfers (UAE PDPL Articles 22-24)

GDPR · 1 control

  • GDPR-Art.45 Transfers on the basis of an adequacy decision
  • ICP-25 Supervisory Cooperation and Coordination
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs

PDPA Singapore · 1 control

  • PDPASG-6 Transfer Limitation, Cross-Border Safeguards, and Data Intermediary Oversight

PDPA Thailand · 1 control

  • PDPATH-6 Cross-Border Transfer and Processor Engagement
  • AUPRV-3 APP 6-9 Use/Disclosure, Direct Marketing, Cross-Border, Government Identifiers
  • RUSPD-4 Special Categories, Biometric Data
  • IM8-CLD.4 Cloud Data Sovereignty

South Korea ISMS-P · 1 control

  • ISMSP-PI-04 Cross-Border Transfer

South Korea PIPA · 1 control

  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • VIETNAMCYBER-3 Data Localization and Cross-Border

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 32 it maps to, and the evidence behind each claim, over MCP and REST.