Brunei Darussalam

Brunei Personal Data Protection Order 2022 (PDPO)

31 controls. 2 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

31 controls 2 frameworks share controls with it Brunei Darussalam verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

Brunei Personal Data Protection Order 2022 Evidence & Implementation Kit

31 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
BN-PDPO-s10Valid consent0
BN-PDPO-s11Deemed consent0
BN-PDPO-s13Withdrawal of consent0
BN-PDPO-s14Collection, use and disclosure without consent0
BN-PDPO-s15Limitation of purpose and extent0
BN-PDPO-s17Notification of purpose0
BN-PDPO-s18Access to personal data0
BN-PDPO-s19Correction of personal data0
BN-PDPO-s2Interpretation0
BN-PDPO-s20Exercise of rights on behalf of an individual0
BN-PDPO-s21Accuracy of personal data0
BN-PDPO-s22Protection of personal data1
BN-PDPO-s23Retention of personal data0
BN-PDPO-s24Transfer of personal data outside Brunei Darussalam1
BN-PDPO-s26Notifiable data breaches2
BN-PDPO-s27Duty to conduct assessment of a data breach0
BN-PDPO-s28Duty to notify a notifiable data breach1
BN-PDPO-s29Obligations of a data processor of a public agency1
BN-PDPO-s3Application of Order0
BN-PDPO-s31Unauthorised disclosure of personal data0
BN-PDPO-s32Improper use of personal data0
BN-PDPO-s33Unauthorised re-identification of anonymised information0
BN-PDPO-s36Directions for non-compliance0
BN-PDPO-s37Financial penalties0
BN-PDPO-s4Administration of the Order (the Authority)0
BN-PDPO-s42Appeal from direction or decision of the Authority0
BN-PDPO-s5Functions and duties of the Authority0
BN-PDPO-s59Right of private action0
BN-PDPO-s7Responsibilities of organisation (accountability)1
BN-PDPO-s8Consent required1
BN-PDPO-s9Consent for direct marketing messages1

Tell me when Brunei Personal Data Protection Order 2022 (PDPO) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Consent UX
  • Granular preference centre
  • Audit trail of consents
  • Withdrawal mechanism as easy as giving
  • Lawful basis register per processing
  • Consent records (granular and withdrawable)
  • Records retention schedule
  • Retention schedule
  • Retention schedule and disposal records
  • Records inventory

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for Brunei Personal Data Protection Order 2022 (PDPO), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition