Personal Data Act (personopplysningsloven)
Governance and Lifecycle

Personal Data Act (personopplysningsloven) NORWAY-7: DPO, Cooperation with Datatilsynet, Retention, Marketing, Training

Per Norwegian PDPA: governance + lifecycle. Requirements include (a) appoint Data Protection Officer where required per GDPR Article 37 with defined responsibilities + reporting to highest management + (b) maintain Cooperation With Datatilsynet (Norwegian Data Protection Authority) including responding to inquiries + facilitating audits + (c) implement Retention and Erasure including retention schedules + secure deletion + anonymisation + (d) implement Direct Marketing and ePrivacy safeguards per Norwegian + EU ePrivacy including consent + opt-out + suppression lists + (e) deliver Training and Awareness programmes including role-based content + GDPR + Norwegian specifics + (f) maintain documented governance + accountability framework.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 133 controls across 47 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • CH-FADP-22 Privacy by design and default
  • CH-FADP-23 Data processing agreements
  • CH-FADP-24 Cross-border transfer safeguards
  • CH-FADP-25 Compliance monitoring and auditing
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)

Bahrain PDPL · 5 controls

  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes
  • UAE-PDPL-Status UAE PDPL status, executive regulations, UAE Data Office guidance evolution

NIST SP 800-190 · 4 controls

PDPA Singapore · 4 controls

  • PDPASG-1 Accountability, Records, DPO Appointment, and Training
  • PDPASG-4 Children's Data, DPIA, and Privacy by Design
  • PDPASG-6 Transfer Limitation, Cross-Border Safeguards, and Data Intermediary Oversight
  • PDPASG-7 Retention Limitation, Do Not Call, Compliance, Complaints
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

GDPR · 3 controls

ISO 27799:2025 · 3 controls

  • ISO27799-03 Minimum necessary standard enforcement
  • ISO27799-04 Patient data de-identification procedures
  • ISO27799-05 Audit trail for ePHI access

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-A.1 Data Quality and Representativeness
  • ISO23894-A.5 Privacy and Data Protection in AI
  • ISO-25012-5.1 Establishing data quality requirements
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 27011:2024 · 3 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.6 Data protection and backup
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs
  • OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring

PDPA Thailand · 3 controls

  • PDPATH-4 DPIA, Privacy by Design, Children's Data
  • PDPATH-6 Cross-Border Transfer and Processor Engagement
  • PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

South Korea PIPA · 3 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2
  • AL-DPA-14 Direct Marketing
  • AL-DPA-7 Right of Access
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management

ISO/IEC 27400:2022 · 2 controls

  • 27400-7.1 Network Security for IoT
  • 27400-7.4 Data retention and deletion
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections

OECD AI Principles · 2 controls

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation
  • OECDAI-8 AI Incident Reporting, Regulatory Compliance, Public Reporting, and International Cooperation
  • EHDS-HOLD-3 Dataset Descriptions and Catalogues
  • EHDSREG-5 Cross-Border Health Data Flows
  • IM8-DAT.2 Data Protection
  • IM8-DAT.4 Data Retention and Disposal
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • ASD37-27 Outbound data loss prevention (Very Good)
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

FedRAMP High · 1 control

  • AC-2 Account Management

FedRAMP Moderate · 1 control

  • AC-2 Account Management
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)

ISO 26000:2010 · 1 control

  • ISO-26000-6.7 Consumer issues
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NZISM-2 Certification and Accreditation (C&A) for Government Systems
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • PARAGUAY-5 Security of Processing, Data Integrity, Information Security
  • RUSPD-4 Special Categories, Biometric Data
  • AIGF-1.3 Data Management

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • CPSC-CS.3 Data Protection for Safety Systems
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 133 it maps to, and the evidence behind each claim, over MCP and REST.