Frameworks / Vietnam PDPD / VIETNAMPDP-3 What else in your programme already covers this This control maps to 259 controls across 99 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CH-FADP-19 Transparency and proactive information CH-FADP-21 Data protection impact assessments CH-FADP-22 Privacy by design and default CH-FADP-23 Data processing agreements CH-FADP-24 Cross-border transfer safeguards CH-FADP-25 Compliance monitoring and auditing FADP-10 Cross-Border Disclosure (Articles 16-18) FADP-16 FDPIC Independence and Functions FADP-7 Data Protection Impact Assessment (Articles 9-10) FADP-9 Data Protection Advisor (Articles 14-15) POPIASA-4 Special Personal Information, Children, Information Quality, Documentation POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations POPIASA-6 Transborder Information Flows, Direct Marketing POPIASA-7 Information Officer, Records of Processing, Notification, Training POPIASA-8 Information Regulator Cooperation, Complaints, Enforcement BB-DPA-1 Section 1 - Short Title BB-DPA-17 Section 24 - Appropriate Safeguards BB-DPA-20 Sections 50-60 - Registration and Responsibilities BB-DPA-4 Section 4 - Principles Relating to Processing AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction AT-DSG-12 Section 62 - Administrative penalties AT-DSG-7 Section 18 - Establishment of the Data Protection Authority AZ-DPA-12 Article 13 - Cross-border transfer AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-6 Article 6 - State regulation in personal data protection BSI-13 Risk assessment procedures BSI-15 Security categorization BSI-17 Continuous monitoring strategy NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) P1-S1 Advance Electronic Information P1-S4 Targeting and Communication DIQ-2 Data Quality Management DIQ-3 Metadata Management NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use NDPA-1 Applicability, Scope, and Carve-Outs NDPA-4 Sensitive Data Processing Consent and Childrens Protections PERU-3 Data Subject Rights (ARCO), Habeas Data, Automated Decisions PERU-7 DPO, Records, Retention, Marketing, Training QATAR-6 Cross-Border Transfer and Processor Management QATAR-7 DPO, Records, Retention, Marketing, Training 2.4.4 Hazard Analysis and Risk Assessment 2.7.2 Food Fraud Plan CRM-1 AML/CFT Compliance CRM-4 Business Risk Assessment UKAI-1 Risk-Based Approach and Pro-Innovation Principles UKAI-2 Sector-Specific Regulator Engagement UNESCOAI-1 Principles 1-3: Proportionality, Safety, Fairness UNESCOAI-2 Principles 4-7: Sustainability, Privacy, Human Oversight, Transparency CPS230-11 Identification, Assessment and Management of Operational Risk ASD37-27 Outbound data loss prevention (Very Good) 4.3.1 Risk Assessment and Impact Analysis APP-8 APP 8 - Cross-border disclosure of personal information CPG-3.C Strong and Agile Encryption FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) ICP-25 Supervisory Cooperation and Coordination ISO14001-03 Legal and regulatory compliance obligations 29147-5.11 Researcher Safe Harbour and Legal Posture 3.11 Encrypt Sensitive Data at Rest PARAGUAY-5 Security of Processing, Data Integrity, Information Security RCEPEC-2 Cross-Border Transfer, Computing Facilities, Localization (12.14-15) SASB-3 Leadership and Governance (LG) SECCLIM-2 Risk Management: Identification, Assessment, Integration STUDPRV-2 Data Subject Rights for Students and Parents TCFDREC-1 Governance - Board Oversight, Management Role TISAXASS-3 Prototype Protection and Confidentiality TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator D.1 Incident Response Planning UKOPRES-3 Self-Assessment and Board Engagement UNICEFAI-4 Transparency, Explanation, Adult Capacity HE-3 FSA compliance requirements Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 259 it maps to, and the evidence behind each claim, over MCP and REST.