Frameworks / US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule / HE-3 US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
Applicability to Title IV Institutions
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule HE-3: FSA compliance requirements Federal Student Aid requires institutions to comply with the amended Safeguards Rule as programme participation condition.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 69 controls across 56 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-Responsibilities MTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles MTCS-Scope-SS-584-Singapore-Standards-Council-IMDA-SAC-3-Tier-2013-2015-2020-2024-Certification MTCS Scope + SS 584 + Singapore Standards Council + IMDA + SAC + 3-Tier Framework + Certification NDPA-1 Applicability, Scope, and Carve-Outs NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance SASB-3 Leadership and Governance (LG) SASB-LG-1 Business Ethics UAE-PDPL-Status UAE PDPL status, executive regulations, UAE Data Office guidance evolution IEEE7000-Scope-VBE-EAD-IEEE7000Family-EUAIAct-NIST-ISO42001-Coord IEEE 7000-2021 - Scope + Value-Based Engineering (VBE) + Ethically Aligned Design + IEEE 7000 Family + Coordination EU AI Act + NIST AI RMF + ISO/IEC 42001 ISSB-IFRS-S1-Sources-SASB-Industry-Disclosures-Connected-Information-Reporting-Boundary ISSB IFRS S1 Sources of Guidance + SASB Standards Industry-Specific Disclosures + Connected Information + Reporting Boundary + Time of Reporting + Comparative Information + 11 SASB Sectors INCDPA-Enforcement-30DayCure-AttorneyGeneralOnly-NoPrivateRight-CivilPenalties-7500-PerViolation Indiana CDPA Enforcement - Attorney General Exclusive + 30-Day Cure Period + No Private Right of Action + Civil Penalties Up to USD 7500 Per Violation + Investigation + Compliance JP-AIG-Accountability-Governance-AI-Inventory-Stakeholder-Engagement-Board-Reporting-Tone-at-Top Japan AI Guidelines Accountability + Governance + AI Inventory + Stakeholder Engagement + Board Reporting + Tone at Top + AI Ethics Committee + DPO + AI Officer + Regulatory Compliance + Multi-Stakeholder LGPD-BR-Enforcement-Sanctions-ANPD-Article-52-55-Administrative-Sanctions-2-Percent-Turnover-50M-BRL Brazil LGPD Enforcement + Sanctions + Article 52 + 2% Turnover + 50M BRL + ANPD MY-PDPA-Enforcement-PDPC-Investigation-RM1M-Fine-3-Year-Prison-Class-Action-Section-104-2024-Amendment Malaysia PDPA Enforcement + PDPC Investigation + RM1M Fine + 3 Year Prison + Class Action + 2024 Amendment MU-DPA-Enforcement-Commissioner-Section-41-43-MUR-200K-5-Year-Prison-ICT-Appeal-Tribunal-Supreme-Court Mauritius DPA Enforcement + Commissioner + Section 41 + Section 43 + MUR 200K + 5 Year Prison + ICT Appeal Tribunal + Supreme Court MX-LFPDPPP-Enforcement-INAI-Articles-63-64-67-320K-Days-Minimum-Wage-3-Year-Prison-TFJA-Recurso-Revision-SCJN Mexico LFPDPPP Enforcement + INAI + Articles 63-64-67 + 320K Days Minimum Wage + 3 Year Prison + TFJA + Recurso de Revision + SCJN MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification MT-CDPA-Processor-Contract-Security-MCA-30-14-2809-30-14-2811-Pseudonymisation-De-Identification Montana CDPA Processor + MCA 30-14-2809 + Security + Pseudonymisation + MCA 30-14-2811 + De-Identification NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-1 On-Demand Self-Service and Broad Network Access Characteristics NIST190-04 Regulatory compliance for cloud services NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs NZISM-2 Certification and Accreditation (C&A) for Government Systems NGNDPR-8 Annual Data Protection Audit, Penalties, and NDPA Transition OECDAI-8 AI Incident Reporting, Regulatory Compliance, Public Reporting, and International Cooperation OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring PDPASG-7 Retention Limitation, Do Not Call, Compliance, Complaints PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training POPIASA-8 Information Regulator Cooperation, Complaints, Enforcement NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training QATAR-7 DPO, Records, Retention, Marketing, Training SA-PDPL-25 Compliance monitoring and auditing PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2 TCFDREC-1 Governance - Board Oversight, Management Role TAIWAN-4 DPIA, Privacy by Design TEXASTDPSA-3 Sensitive Data, Children, Sale Notice TURKEYKVKK-3 Special Categories and Sensitive Data UKAI-2 Sector-Specific Regulator Engagement URUGUAY-5 Database Registration with AGESIC URCDP VIETNAMPDP-3 Data Subject Rights VIRGINIAVCDPA-4 Privacy Notice and DPIA Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Applicability to Title IV Institutions Query this from an agent The graph holds this control, the 69 it maps to, and the evidence behind each claim, over MCP and REST.