I was completing a survey of the various regulations and standards that require Privacy or Security Awareness training, and have compiled the following list from various sources:
FEDERAL LAWS AND REGULATIONS
- HIPAA
- GLBA
- FISMA
- FTC Red Flags Rule
INDUSTRY CODES
- PCI DSS
STANDARDS
- NIST 800-53
- ISO/IEC 27002
REGIONAL LAWS
- US-EU Safe Harbor Arrangement
- Canada’s PIPEDA
- Texas Health Privacy Law
- Massachusetts Data Security Law
But I am not seeing anything specific for the UK or EU. Are there regulations that apply?