Samoa Telecommunications Act (2005) - Privacy & Data Protection
Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Customer Information Confidentiality (Sections 48 to 51)
Service providers shall not disclose customer information without written consent or regulatory/legal authorization
- Customer information confidentiality policy aligned to Section 48
- Consent capture records and templates
- Access control records for customer information
- Staff training records on confidentiality obligations
- Consent capture inconsistent
- Access controls weak for customer records
- Training not refreshed
- Section 48 obligations not reflected in contracts
Disclosure of customer information requires the customer's written consent
- Customer information confidentiality policy aligned to Section 48
- Consent capture records and templates
- Access control records for customer information
- Staff training records on confidentiality obligations
- Consent capture inconsistent
- Access controls weak for customer records
- Training not refreshed
- Section 48 obligations not reflected in contracts
Government access to confidential customer information must be in accordance with laws of Samoa
- Government access request handling procedure (Section 51)
- Legal authorisation verification log
- Disclosure log with reviewer sign-off
- Counsel review evidence for requests
- No formal procedure for Section 51 requests
- Legal authorisation not verified
- Disclosure log incomplete
- Counsel not engaged
Disclosure is only permitted when required or authorized by the Regulator or by law
- Government access request handling procedure (Section 51)
- Legal authorisation verification log
- Disclosure log with reviewer sign-off
- Counsel review evidence for requests
- No formal procedure for Section 51 requests
- Legal authorisation not verified
- Disclosure log incomplete
- Counsel not engaged
Enforcement
Per Samoa Telecommunications Act (2005) - Privacy & Data Protection: Enforcement. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for SAMOATEL-4
- see authoritative source for detailed gap analysis
Rights
Per Samoa Telecommunications Act (2005) - Privacy & Data Protection: Consent and Rights. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for SAMOATEL-2
- see authoritative source for detailed gap analysis
Samoa Telecommunications Act: Access Control and Security
The licensee must implement reasonable technical and organisational measures to protect the confidentiality, integrity, and availability of customer communications and data.
- information security policy
- risk assessment for telecommunications operations
- network and system hardening standards
- vulnerability management evidence
- no documented risk assessment
- legacy systems without hardening
- patching deferred indefinitely
Sensitive customer data stored or transmitted by the licensee should be protected by appropriate encryption or equivalent safeguards.
- encryption standard document
- configuration showing TLS on customer facing services
- encryption at rest configuration for databases holding customer data
- key management procedures
- legacy systems storing data in plain text
- backups not encrypted
- key storage on the same host as the data
Access to systems holding customer communications and personal data should be logged so that any inappropriate access can be detected and investigated.
- log configuration for billing, CRM, and intercept systems
- SIEM ingestion of these logs
- monitoring rules for unusual access patterns
- investigation records of past alerts
- application access not logged centrally
- no alerting on bulk record exports
- logs deleted after a short period
Access to subscriber records and traffic data must be restricted to authorised staff with a legitimate business need and must be logged and reviewed.
- role based access matrix for billing and CRM systems
- access request and approval records
- access logs from subscriber systems
- periodic access review records
- shared logins to billing systems
- blanket access for entire teams without role differentiation
- no review of who accessed which subscriber record
Employees and contractors with access to customer communications or records must give a documented confidentiality undertaking and be trained on their obligations.
- employment contracts with confidentiality clauses
- signed undertakings from contractors
- training completion records on confidentiality
- disciplinary policy for breach of confidentiality
- contractors without written confidentiality terms
- training never refreshed
- no consequences applied after past breaches
Samoa Telecommunications Act: Confidentiality and Lawful Disclosure
A telecommunications service provider in Samoa must protect the confidentiality of customer communications carried over its network and must not disclose the content to third parties except as authorised by law.
- confidentiality policy referencing the Samoa Telecommunications Act 2005
- staff acknowledgment records of the confidentiality policy
- register of lawful disclosure requests with legal basis
- training materials covering confidentiality obligations
- call centre agents discussing customer content informally
- no register of lawful intercept or disclosure requests
- third party support staff not bound by confidentiality terms
Where the licensee records calls or other communications for quality, training, or compliance, customers should be informed and the recordings should be protected.
- customer notice or recorded message about call recording
- policy on access to and retention of recordings
- access controls and encryption on recording stores
- deletion schedule for recordings
- recordings retained indefinitely
- wide access to recording archives
- no notification of recording on inbound or outbound calls
Disclosure of customer communications or related data may occur only under a lawful order or recognised exception, with the request properly authenticated, recorded, and limited to what is required.
- procedure for handling lawful interception requests
- register of received requests with date, requesting authority, scope, and outcome
- approval workflow involving legal counsel
- evidence of refusing or narrowing overbroad requests
- disclosures handled by operations without legal review
- no record of what was disclosed and to whom
- broad standing arrangements without per request authorisation
Customer identifiers such as phone numbers, account numbers, and IMSI should be protected from unauthorised disclosure and from abuse such as number harvesting.
- access controls on subscriber identifier databases
- monitoring for bulk export of identifiers
- anti fraud controls on number portability and SIM swap
- training on identifier sensitivity
- SIM swap performed with weak identity verification
- subscriber lists shared in spreadsheets
- no monitoring of bulk queries against the HLR or equivalent
Traffic data and metadata that identify or describe customer communications must be protected with the same care as the content of communications.
- data classification that includes traffic data
- retention policy for call detail records and similar metadata
- access controls on metadata stores
- encryption of metadata at rest and in transit
- metadata treated as low sensitivity
- CDR exports shared with marketing without controls
- no retention limits on metadata stores
Samoa Telecommunications Act: Customer Data Handling
When designing new telecommunications services or features, the licensee should consider privacy and confidentiality requirements from the outset.
- service design review checklist including privacy
- privacy impact assessments for new services
- sign off records from privacy or legal function
- new services launched without privacy review
- PIA exists but recommendations not actioned
- marketing led launches bypassing review
Personal data collected from telecommunications customers must be handled in line with the purposes for which it was provided and protected against unauthorised use or disclosure.
- customer privacy notice
- record of processing activities for customer data
- data classification scheme covering customer records
- training on personal data handling for customer facing staff
- customer data used for marketing without separate consent
- no record of processing activities
- customer service tools storing data beyond what is needed
Customer data should be retained only as long as is necessary for the purposes of the service, billing, or legal obligation, and then securely disposed of.
- retention schedule per data type
- evidence of scheduled deletion or archival
- secure disposal procedures for paper and media
- review of legacy data stores
- indefinite retention of CDRs
- old billing systems retained without purpose
- no destruction certificates for retired media
Use of customer contact details and usage data for marketing must respect the customer's choices, with a documented opt out or consent mechanism.
- consent or opt out records per customer
- marketing communication policy
- process for honouring opt out requests
- audit of marketing lists against opt out registers
- marketing campaigns using all customer numbers without filtering
- opt outs collected but not applied across channels
- no auditing of consent state
Samoa Telecommunications Act: Incidents, Customer Rights and Regulator
Incidents that compromise the confidentiality or integrity of customer data should be investigated, documented, and reported to the regulator or affected customers where required.
- incident response plan with privacy specific scenarios
- register of incidents affecting customer data
- notification templates for regulator and customers
- post incident review evidence
- incidents resolved without documentation
- no defined notification thresholds
- regulator contact details out of date
Customers should be able to obtain information held about them by the licensee on reasonable request, subject to verification of identity.
- procedure for handling customer information requests
- identity verification steps
- register of requests received and responses
- training for customer service on handling requests
- informal handling of requests via call centre
- no time targets for response
- weak identity verification before disclosing data
The licensee must cooperate with the regulator in matters concerning privacy, confidentiality, and security of customer data, providing information and access as required.
- regulator engagement log
- reports submitted to the regulator
- policy on regulator information requests
- evidence of inspection responses
- regulator queries handled ad hoc
- no central register of regulator interactions
- out of date contact details
The licensee must provide a mechanism for customers to complain about privacy or confidentiality concerns and handle complaints fairly and promptly.
- complaint handling procedure
- register of privacy complaints with outcomes
- service level targets for complaint resolution
- escalation path to the regulator
- privacy complaints not separately tracked
- long resolution times
- no escalation procedure for unresolved cases
Samoa Telecommunications Act: Third Parties and Cross-Border Transfer
Where customer data is transferred outside Samoa for processing or storage, equivalent protections must be in place and the arrangements must be documented.
- inventory of offshore processing arrangements
- contracts with offshore providers including privacy clauses
- due diligence on destination country protections
- customer notice covering offshore processing where relevant
- cloud services used without documenting offshore processing
- no clauses on lawful access by foreign authorities
- customer notice silent on overseas processing
Third parties processing customer data on behalf of the licensee must be bound by contract to protect confidentiality and to comply with the Act.
- list of third parties handling customer data
- contractual confidentiality and privacy clauses
- due diligence assessments
- monitoring evidence of third party compliance
- legacy vendors without updated clauses
- offshore support centres without local law obligations
- no ongoing monitoring after onboarding
Scope
Per Samoa Telecommunications Act (2005) - Privacy & Data Protection: Scope and Lawful Processing. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for SAMOATEL-1
- see authoritative source for detailed gap analysis
Security
Per Samoa Telecommunications Act (2005) - Privacy & Data Protection: Security and Cross-Border. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for SAMOATEL-3
- see authoritative source for detailed gap analysis
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Samoa Telecommunications Act (2005) - Privacy & Data Protection framework page.