Skip to content

Evidence request lists

Samoa Telecommunications Act (2005) - Privacy & Data Protection

Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Customer Information Confidentiality (Sections 48 to 51)

SAM-1
Customer Information Confidentiality (Section 48)

Service providers shall not disclose customer information without written consent or regulatory/legal authorization

Artefacts an auditor will ask for
  • Customer information confidentiality policy aligned to Section 48
  • Consent capture records and templates
  • Access control records for customer information
  • Staff training records on confidentiality obligations
Where this commonly fails
  • Consent capture inconsistent
  • Access controls weak for customer records
  • Training not refreshed
  • Section 48 obligations not reflected in contracts
SAM-2
Consent Requirements

Disclosure of customer information requires the customer's written consent

Artefacts an auditor will ask for
  • Customer information confidentiality policy aligned to Section 48
  • Consent capture records and templates
  • Access control records for customer information
  • Staff training records on confidentiality obligations
Where this commonly fails
  • Consent capture inconsistent
  • Access controls weak for customer records
  • Training not refreshed
  • Section 48 obligations not reflected in contracts
SAM-5
Government Access to Information (Section 51)

Government access to confidential customer information must be in accordance with laws of Samoa

Artefacts an auditor will ask for
  • Government access request handling procedure (Section 51)
  • Legal authorisation verification log
  • Disclosure log with reviewer sign-off
  • Counsel review evidence for requests
Where this commonly fails
  • No formal procedure for Section 51 requests
  • Legal authorisation not verified
  • Disclosure log incomplete
  • Counsel not engaged
SAM-6
Legal Authorization Requirements

Disclosure is only permitted when required or authorized by the Regulator or by law

Artefacts an auditor will ask for
  • Government access request handling procedure (Section 51)
  • Legal authorisation verification log
  • Disclosure log with reviewer sign-off
  • Counsel review evidence for requests
Where this commonly fails
  • No formal procedure for Section 51 requests
  • Legal authorisation not verified
  • Disclosure log incomplete
  • Counsel not engaged

Enforcement

SAMOATEL-4
Enforcement

Per Samoa Telecommunications Act (2005) - Privacy & Data Protection: Enforcement. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for SAMOATEL-4
Where this commonly fails
  • see authoritative source for detailed gap analysis

Rights

SAMOATEL-2
Consent and Rights

Per Samoa Telecommunications Act (2005) - Privacy & Data Protection: Consent and Rights. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for SAMOATEL-2
Where this commonly fails
  • see authoritative source for detailed gap analysis

Samoa Telecommunications Act: Access Control and Security

STA-10
Security Safeguards over Networks and Systems

The licensee must implement reasonable technical and organisational measures to protect the confidentiality, integrity, and availability of customer communications and data.

Artefacts an auditor will ask for
  • information security policy
  • risk assessment for telecommunications operations
  • network and system hardening standards
  • vulnerability management evidence
Where this commonly fails
  • no documented risk assessment
  • legacy systems without hardening
  • patching deferred indefinitely
STA-13
Encryption of Sensitive Customer Data

Sensitive customer data stored or transmitted by the licensee should be protected by appropriate encryption or equivalent safeguards.

Artefacts an auditor will ask for
  • encryption standard document
  • configuration showing TLS on customer facing services
  • encryption at rest configuration for databases holding customer data
  • key management procedures
Where this commonly fails
  • legacy systems storing data in plain text
  • backups not encrypted
  • key storage on the same host as the data
STA-14
Logging of Access to Customer Data

Access to systems holding customer communications and personal data should be logged so that any inappropriate access can be detected and investigated.

Artefacts an auditor will ask for
  • log configuration for billing, CRM, and intercept systems
  • SIEM ingestion of these logs
  • monitoring rules for unusual access patterns
  • investigation records of past alerts
Where this commonly fails
  • application access not logged centrally
  • no alerting on bulk record exports
  • logs deleted after a short period
STA-4
Access Control over Subscriber Records

Access to subscriber records and traffic data must be restricted to authorised staff with a legitimate business need and must be logged and reviewed.

Artefacts an auditor will ask for
  • role based access matrix for billing and CRM systems
  • access request and approval records
  • access logs from subscriber systems
  • periodic access review records
Where this commonly fails
  • shared logins to billing systems
  • blanket access for entire teams without role differentiation
  • no review of who accessed which subscriber record
STA-6
Employee Confidentiality Undertakings

Employees and contractors with access to customer communications or records must give a documented confidentiality undertaking and be trained on their obligations.

Artefacts an auditor will ask for
  • employment contracts with confidentiality clauses
  • signed undertakings from contractors
  • training completion records on confidentiality
  • disciplinary policy for breach of confidentiality
Where this commonly fails
  • contractors without written confidentiality terms
  • training never refreshed
  • no consequences applied after past breaches

Samoa Telecommunications Act: Confidentiality and Lawful Disclosure

STA-1
Confidentiality of Communications

A telecommunications service provider in Samoa must protect the confidentiality of customer communications carried over its network and must not disclose the content to third parties except as authorised by law.

Artefacts an auditor will ask for
  • confidentiality policy referencing the Samoa Telecommunications Act 2005
  • staff acknowledgment records of the confidentiality policy
  • register of lawful disclosure requests with legal basis
  • training materials covering confidentiality obligations
Where this commonly fails
  • call centre agents discussing customer content informally
  • no register of lawful intercept or disclosure requests
  • third party support staff not bound by confidentiality terms
STA-19
Recording of Calls and Communications

Where the licensee records calls or other communications for quality, training, or compliance, customers should be informed and the recordings should be protected.

Artefacts an auditor will ask for
  • customer notice or recorded message about call recording
  • policy on access to and retention of recordings
  • access controls and encryption on recording stores
  • deletion schedule for recordings
Where this commonly fails
  • recordings retained indefinitely
  • wide access to recording archives
  • no notification of recording on inbound or outbound calls
STA-2
Lawful Interception and Disclosure Controls

Disclosure of customer communications or related data may occur only under a lawful order or recognised exception, with the request properly authenticated, recorded, and limited to what is required.

Artefacts an auditor will ask for
  • procedure for handling lawful interception requests
  • register of received requests with date, requesting authority, scope, and outcome
  • approval workflow involving legal counsel
  • evidence of refusing or narrowing overbroad requests
Where this commonly fails
  • disclosures handled by operations without legal review
  • no record of what was disclosed and to whom
  • broad standing arrangements without per request authorisation
STA-20
Number and Identifier Protection

Customer identifiers such as phone numbers, account numbers, and IMSI should be protected from unauthorised disclosure and from abuse such as number harvesting.

Artefacts an auditor will ask for
  • access controls on subscriber identifier databases
  • monitoring for bulk export of identifiers
  • anti fraud controls on number portability and SIM swap
  • training on identifier sensitivity
Where this commonly fails
  • SIM swap performed with weak identity verification
  • subscriber lists shared in spreadsheets
  • no monitoring of bulk queries against the HLR or equivalent
STA-5
Traffic and Metadata Protection

Traffic data and metadata that identify or describe customer communications must be protected with the same care as the content of communications.

Artefacts an auditor will ask for
  • data classification that includes traffic data
  • retention policy for call detail records and similar metadata
  • access controls on metadata stores
  • encryption of metadata at rest and in transit
Where this commonly fails
  • metadata treated as low sensitivity
  • CDR exports shared with marketing without controls
  • no retention limits on metadata stores

Samoa Telecommunications Act: Customer Data Handling

STA-16
Privacy by Design in New Services

When designing new telecommunications services or features, the licensee should consider privacy and confidentiality requirements from the outset.

Artefacts an auditor will ask for
  • service design review checklist including privacy
  • privacy impact assessments for new services
  • sign off records from privacy or legal function
Where this commonly fails
  • new services launched without privacy review
  • PIA exists but recommendations not actioned
  • marketing led launches bypassing review
STA-3
Customer Personal Data Handling

Personal data collected from telecommunications customers must be handled in line with the purposes for which it was provided and protected against unauthorised use or disclosure.

Artefacts an auditor will ask for
  • customer privacy notice
  • record of processing activities for customer data
  • data classification scheme covering customer records
  • training on personal data handling for customer facing staff
Where this commonly fails
  • customer data used for marketing without separate consent
  • no record of processing activities
  • customer service tools storing data beyond what is needed
STA-8
Data Retention Limits

Customer data should be retained only as long as is necessary for the purposes of the service, billing, or legal obligation, and then securely disposed of.

Artefacts an auditor will ask for
  • retention schedule per data type
  • evidence of scheduled deletion or archival
  • secure disposal procedures for paper and media
  • review of legacy data stores
Where this commonly fails
  • indefinite retention of CDRs
  • old billing systems retained without purpose
  • no destruction certificates for retired media
STA-9
Marketing Use of Customer Data

Use of customer contact details and usage data for marketing must respect the customer's choices, with a documented opt out or consent mechanism.

Artefacts an auditor will ask for
  • consent or opt out records per customer
  • marketing communication policy
  • process for honouring opt out requests
  • audit of marketing lists against opt out registers
Where this commonly fails
  • marketing campaigns using all customer numbers without filtering
  • opt outs collected but not applied across channels
  • no auditing of consent state

Samoa Telecommunications Act: Incidents, Customer Rights and Regulator

STA-11
Incident Notification

Incidents that compromise the confidentiality or integrity of customer data should be investigated, documented, and reported to the regulator or affected customers where required.

Artefacts an auditor will ask for
  • incident response plan with privacy specific scenarios
  • register of incidents affecting customer data
  • notification templates for regulator and customers
  • post incident review evidence
Where this commonly fails
  • incidents resolved without documentation
  • no defined notification thresholds
  • regulator contact details out of date
STA-12
Customer Access to Their Own Information

Customers should be able to obtain information held about them by the licensee on reasonable request, subject to verification of identity.

Artefacts an auditor will ask for
  • procedure for handling customer information requests
  • identity verification steps
  • register of requests received and responses
  • training for customer service on handling requests
Where this commonly fails
  • informal handling of requests via call centre
  • no time targets for response
  • weak identity verification before disclosing data
STA-15
Regulator Cooperation

The licensee must cooperate with the regulator in matters concerning privacy, confidentiality, and security of customer data, providing information and access as required.

Artefacts an auditor will ask for
  • regulator engagement log
  • reports submitted to the regulator
  • policy on regulator information requests
  • evidence of inspection responses
Where this commonly fails
  • regulator queries handled ad hoc
  • no central register of regulator interactions
  • out of date contact details
STA-18
Complaint Handling

The licensee must provide a mechanism for customers to complain about privacy or confidentiality concerns and handle complaints fairly and promptly.

Artefacts an auditor will ask for
  • complaint handling procedure
  • register of privacy complaints with outcomes
  • service level targets for complaint resolution
  • escalation path to the regulator
Where this commonly fails
  • privacy complaints not separately tracked
  • long resolution times
  • no escalation procedure for unresolved cases

Samoa Telecommunications Act: Third Parties and Cross-Border Transfer

STA-17
Cross Border Transfer Controls

Where customer data is transferred outside Samoa for processing or storage, equivalent protections must be in place and the arrangements must be documented.

Artefacts an auditor will ask for
  • inventory of offshore processing arrangements
  • contracts with offshore providers including privacy clauses
  • due diligence on destination country protections
  • customer notice covering offshore processing where relevant
Where this commonly fails
  • cloud services used without documenting offshore processing
  • no clauses on lawful access by foreign authorities
  • customer notice silent on overseas processing
STA-7
Third Party Provider Obligations

Third parties processing customer data on behalf of the licensee must be bound by contract to protect confidentiality and to comply with the Act.

Artefacts an auditor will ask for
  • list of third parties handling customer data
  • contractual confidentiality and privacy clauses
  • due diligence assessments
  • monitoring evidence of third party compliance
Where this commonly fails
  • legacy vendors without updated clauses
  • offshore support centres without local law obligations
  • no ongoing monitoring after onboarding

Scope

SAMOATEL-1
Scope and Lawful Processing

Per Samoa Telecommunications Act (2005) - Privacy & Data Protection: Scope and Lawful Processing. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for SAMOATEL-1
Where this commonly fails
  • see authoritative source for detailed gap analysis

Security

SAMOATEL-3
Security and Cross-Border

Per Samoa Telecommunications Act (2005) - Privacy & Data Protection: Security and Cross-Border. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for SAMOATEL-3
Where this commonly fails
  • see authoritative source for detailed gap analysis
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Samoa Telecommunications Act (2005) - Privacy & Data Protection framework page.