TEFCA - Trusted Exchange Framework and Common Agreement
Trusted Exchange Framework Principles

TEFCA - Trusted Exchange Framework and Common Agreement TEF-2: Openness and Transparency

Exchange practices must be open and transparent regarding policies, procedures, and data handling practices.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 119 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

GDPR · 3 controls

ISO 27799:2025 · 3 controls

  • ISO27799-03 Minimum necessary standard enforcement
  • ISO27799-04 Patient data de-identification procedures
  • ISO27799-05 Audit trail for ePHI access

ISO/IEC 27011:2024 · 3 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.6 Data protection and backup

NIST SP 800-190 · 3 controls

  • UGA-3 Accountability Principle
  • UGA-6 Personal Data Protection Office
  • UGA-7 Data Protection Officer
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection

Bahrain PDPL · 2 controls

  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)

ISO/IEC 27400:2022 · 2 controls

  • 27400-7.1 Network Security for IoT
  • 27400-7.4 Data retention and deletion
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections

Saudi Arabia PDPL · 2 controls

  • SA-PDPL-19 Data protection officer designation
  • SA-PDPL-21 Data protection impact assessments
  • IM8-DAT.2 Data Protection
  • IM8-DAT.4 Data Retention and Disposal
  • SWE-1 Scope and Purpose
  • SWE-2 Relationship to GDPR
  • Standard 15 Online Tools
  • Standard 2 Data Protection Impact Assessments
  • UKGDPRREG-2 Data Subject Rights (Articles 12-22)
  • UKGDPRREG-3 Controller and Processor (Articles 24-43)

Uruguay DPL · 2 controls

  • URUGUAY-4 Security and Cross-Border
  • URUGUAY-5 Database Registration with AGESIC URCDP
  • ASD37-27 Outbound data loss prevention (Very Good)
  • AL-DPA-14 Direct Marketing

ISO 26000:2010 · 1 control

  • ISO-26000-6.7 Consumer issues

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.5 Privacy and Data Protection in AI
  • SOC-CY-C2 Encryption and Data Protection
  • TISAXASS-3 Prototype Protection and Confidentiality

Taiwan PDPA · 1 control

  • TAIWAN-3 Data Subject Rights
  • TSSR-INFO-1 Network Data Protection
  • TEXASTDPSA-3 Sensitive Data, Children, Sale Notice
  • UKAI-2 Sector-Specific Regulator Engagement
  • UNESCOAI-2 Principles 4-7: Sustainability, Privacy, Human Oversight, Transparency
  • CPSC-CS.3 Data Protection for Safety Systems
  • US-ITAR-EAR-DS-01 Technical Data Protection

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-3 Sensitive Data Consent and Children

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Trusted Exchange Framework Principles

Query this from an agent

The graph holds this control, the 119 it maps to, and the evidence behind each claim, over MCP and REST.