Privacy Act 2020
Disclosure and Cross-Border

Privacy Act 2020 NZPRV-5: IPP 11-12 Disclosure, Cross-Border Disclosure (Schedule 8)

Per IPPs 11-12 of Privacy Act 2020 + Schedule 8: disclosure + cross-border. Requirements include (a) IPP 11 - Limits on Disclosure of Personal Information - personal information should not be disclosed unless disclosure is one of the purposes for which it was collected + an exception applies + (b) IPP 12 - Disclosure of Personal Information Outside New Zealand - personal information may not be disclosed to a recipient outside NZ unless the recipient is subject to privacy laws comparable to Privacy Act 2020 + appropriate safeguards + individual consents + (c) maintain inventory of cross-border data flows + recipients + safeguards + (d) implement contractual + technical safeguards + (e) cooperate with Office of Privacy Commissioner (OPC) on transfer matters.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 61 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

POPIA · 4 controls

  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations
  • POPIASA-6 Transborder Information Flows, Direct Marketing
  • POPIASA-7 Information Officer, Records of Processing, Notification, Training
  • EHDS-HOLD-3 Dataset Descriptions and Catalogues
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • EHDSREG-4 Digital Health Authorities, Governance, MyHealth@EU
  • EHDSREG-5 Cross-Border Health Data Flows

Bahrain PDPL · 3 controls

  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.22_23_24 Cross-border data transfers (UAE PDPL Articles 22-24)
  • UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes
  • ISO-25012-5.1 Establishing data quality requirements
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

South Korea PIPA · 3 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2
  • AL-DPA-14 Direct Marketing
  • AL-DPA-7 Right of Access
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management

ISO/IEC 23894:2023 · 2 controls

  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-A.1 Data Quality and Representativeness
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs
  • OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring

PDPA Singapore · 2 controls

  • PDPASG-1 Accountability, Records, DPO Appointment, and Training
  • PDPASG-6 Transfer Limitation, Cross-Border Safeguards, and Data Intermediary Oversight

PDPA Thailand · 2 controls

  • PDPATH-4 DPIA, Privacy by Design, Children's Data
  • PDPATH-6 Cross-Border Transfer and Processor Engagement
  • APP-8 APP 8 - Cross-border disclosure of personal information
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • BB-DPA-17 Section 24 - Appropriate Safeguards

GDPR · 1 control

  • GDPR-Art.45 Transfers on the basis of an adequacy decision
  • ICP-25 Supervisory Cooperation and Coordination

OECD AI Principles · 1 control

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training
  • RUSPD-4 Special Categories, Biometric Data
  • AIGF-1.3 Data Management
  • IM8-CLD.4 Cloud Data Sovereignty

South Korea ISMS-P · 1 control

  • ISMSP-PI-04 Cross-Border Transfer

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • VIETNAMCYBER-3 Data Localization and Cross-Border

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 61 it maps to, and the evidence behind each claim, over MCP and REST.