Safe Harbor
What is Safe Harbor?
Legal provisions that protect organizations from liability or penalties when they have acted in good faith compliance with specified requirements.
Terms that appear alongside safe harbor
Each of these is named in at least one of the same controls as safe harbor. The number is how many controls name both.
- hipaa 9 shared controls
- consent 7 shared controls
- compliance 7 shared controls
- nist 6 shared controls
- audit 6 shared controls
- encryption 6 shared controls
- cybersecurity 5 shared controls
- authentication 5 shared controls
Frameworks that govern safe harbor
What the standards actually require on safe harbor
Requirements naming safe harbor across 6 standards, quoted from the control text.
Membership in ESRB Privacy Certified requires an operator that is, or that processes personal information on behalf of an operator that is, a COPPA-covered entity, and selection of the applicable seal: the ESRB Privacy Certified Seal (general audience) or the...
ESRB-PC-01 · COPPA Safe Harbor program eligibility and Seal selection →Industry self-regulatory guidelines may be submitted to the FTC for approval as safe harbor programs. Approved programs must provide substantially the same or greater protections than the Rule, include an effective mandatory mechanism for independent assessmen...
COPPA-312.11 · FTC-Approved Safe Harbor Programs →Civil Code 1798.91.04(b): If a connected device is equipped with a means for authentication outside a local area network, the security feature is deemed reasonable if either (1) the preprogrammed password is unique to each device manufactured, or (2) the devic...
CA-SB327-1798.91.04b · Authentication Outside a Local Area Network (Password Safe Harbor) →Untimely filing of Item 1.05 8-K does not result in loss of Form S-3 short-form registration eligibility, and Section 10(b)/Rule 10b-5 liability attaches only for materially misleading statements, not for omissions during the 4-day window;
SEC-SAFE-HARBOR · Limited Safe Harbor for Item 1.05 Late Filings →HITECH crosswalk to verified subordinate substantive rules + adjacent frameworks. HIPAA PRIVACY RULE (45 CFR Parts 160 + 164 Subpart E) - primary substantive privacy controls;
HITECH-Crosswalk-HIPAA-NIST-CSF-405d-Sectoral · HITECH Crosswalk to HIPAA Privacy + Security + Breach Notification Rules + NIST CSF + HHS 405d + State Laws →GLBA Sections 6802 and 6803 - disclosure + notice + opt-out obligations. SECTION 6802 OBLIGATIONS WITH RESPECT TO DISCLOSURES: a financial institution may not disclose NPI to a NONAFFILIATED THIRD PARTY unless (a) the financial institution has provided the con...
GLBA-Sec6802-6803-Disclosure-Notice-OptOut · GLBA Section 6802-6803 - Disclosure Limits, Privacy Notice and Opt-Out →Questions people ask about safe harbor
What is Safe Harbor?
Why is Safe Harbor important for compliance?
Which compliance frameworks address Safe Harbor?
Where can I learn more about Safe Harbor?
See how Safe Harbor applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.