Frameworks / Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) / CH-FADP-13 Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
Data Subject Rights
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) CH-FADP-13: Right to object and request blocking Data subjects may object to processing carried out by private persons or federal bodies, and may request blocking, rectification, or deletion of data where the legal basis for processing no longer applies.
What else in your programme already covers this This control maps to 218 controls across 138 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism PQC-5 Cryptographic Inventory and PQC Migration Roadmap PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response CJIS-8 Media Protection CJIS-9 System and Communications Protection 6.6 Confidentiality or non-disclosure agreements 6.7 Conducting Audit Follow-up 6.6 Confidentiality or non-disclosure agreements 6.7 Conducting Audit Follow-up 6.6 Confidentiality or non-disclosure agreements 6.7 Conducting Audit Follow-up NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions NAIC-2 Information Security Program (ISP) - Section 4 NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NDPA-1 Applicability, Scope, and Carve-Outs NDPA-7 Data Protection Assessments and Processor Contracts NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-7 Cross-Border Data Transfers and International Cooperation CISABD-1 Take Ownership of Customer Security Outcomes SBD-DEV-04 Phishing-Resistant Authentication APPI-A34 Request for Correction, Addition or Deletion 9.1 Risk communication and consultation ASD37-17 TLS encryption between email servers (Limited) BSI-08 Cryptographic protection of data Part11.30 Controls for open systems (21 CFR §11.30) FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance) FedRAMP-Baselines FedRAMP Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) 62351-9 Cyber security key management 9.1 Risk communication and consultation 9.1 Risk communication and consultation STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NIS2I-5 Cyber Hygiene, Training, Cryptography, and Human Resources Security NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP123-4 Server Cryptography - Encryption, Key Management, Certificates NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment NHPA-6 Reasonable Data Security and Breach Response NJDPA-7 Data Protection Assessments and Processor Contracts NZISM-3 Personnel Security, Physical Security, and Cryptography NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security NGOB-3 API Security Standards, mTLS, and Encryption ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-4 Data Protection, Cryptography, and Privacy Alignment OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations PSDTWO-2 SCA Exemptions and Risk-Based Authentication NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control PERU-7 DPO, Records, Retention, Marketing, Training NZPRV-2 IPP 5 Storage and Security of Personal Information SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule TAIWAN-2 Consent, Notice, Sensitive Data URUGUAY-3 Sensitive Data, Health Data, Children Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Data Subject Rights Query this from an agent The graph holds this control, the 218 it maps to, and the evidence behind each claim, over MCP and REST.