Privacy Act 2020
Security

Privacy Act 2020 NZPRV-2: IPP 5 Storage and Security of Personal Information

Per IPP 5 of Privacy Act 2020: storage and security. Requirements include (a) IPP 5 - Storage and Security of Personal Information - agency holding personal information must ensure it is protected by reasonable security safeguards against loss + unauthorised access + use + modification + disclosure + (b) if agency provides personal information to another person for storing + processing - ensure preventive measures + (c) implement encryption + access control + activity logging where appropriate + (d) conduct regular security testing + assessment + (e) integrate with broader information security baseline + (f) maintain documented security measures aligned to OPC guidance.

What else in your programme already covers this

This control maps to 297 controls across 97 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27043 · 7 controls

ISO/SAE 21434 · 7 controls

APPI · 6 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A31 Provision of Personally Referable Information
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APPI-A34 Request for Correction, Addition or Deletion

Bahrain PDPL · 6 controls

NIST SP 800-53 Rev 5 · 6 controls

GDPR · 5 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.9 Processing of special categories of personal data

ISO 13485 · 5 controls

ISO 27799 · 5 controls

South Korea ISMS-P · 5 controls

BSI IT-Grundschutz · 4 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-08 Cryptographic protection of data

ISO/IEC 27400:2022 · 4 controls

  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections
  • OREGONCPA-4 Universal Opt-Out, Targeted Advertising, Profiling
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs

Peru DPL · 4 controls

  • PERU-2 Consent, Privacy Notice, Sensitive Data
  • PERU-4 Children's Data, Privacy Impact, Sensitive Categories
  • PERU-5 Security of Personal Data and Processor Agreements
  • PERU-7 DPO, Records, Retention, Marketing, Training

API 1164 · 3 controls

  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer

IEC 62443 · 3 controls

ISO 27019 · 3 controls

ISO/IEC 27010:2015 · 3 controls

ISO/IEC 27011:2024 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

NIST SP 1800-32 · 3 controls

  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management
  • ORANWG11-8 Supply Chain, Secure Development Lifecycle, Privacy, Multi-Vendor Trust

POPIA · 3 controls

  • POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions
  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

South Korea PIPA · 3 controls

  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • 62351-8 Role-based access control (RBAC)
  • 62351-9 Cyber security key management
  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO 19011 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO 20000-1 · 2 controls

  • 9.1 Risk communication and consultation
  • ISO20000-15 Access management for services

ISO 31000:2018 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO/IEC 27014:2020 · 2 controls

  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment

OpenSSF Scorecard · 2 controls

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts

PDPA Singapore · 2 controls

  • PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis
  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 2 controls

  • PDPATH-5 Security Measures and Data Protection
  • PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • ASD37-17 TLS encryption between email servers (Limited)
  • DS-2 Ensure software supply chain security
  • CA-10 Selects and Develops Control Activities

FIDO2 / WebAuthn · 1 control

ISO 27005 · 1 control

  • 9.1 Risk communication and consultation

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO/IEC 23894:2023 · 1 control

ITIL 4 · 1 control

  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

NIST SP 800-190 · 1 control

OECD AI Principles · 1 control

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • USCOPPA-3 Data Minimisation, Retention, Erasure (Eraser Button)
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 297 it maps to, and the evidence behind each claim, over MCP and REST.