{
  "node_id": "as-framework",
  "title": "American Samoa - Territorial Privacy Rights and Federal Data Protection Framework",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-04-27",
  "bluf": "American Samoa is an unincorporated unorganised territory of the United States located in the South Pacific Ocean. Unlike other US territories such as Puerto Rico, Guam, and the US Virgin Islands, American Samoa is unorganised - Congress has not enacted an Organic Act for American Samoa, and the territory is governed largely by its own Constitution and laws administered by the American Samoa Government (ASG). Persons born in American Samoa are US nationals but not automatically US citizens - a unique status among US territories that has been the subject of ongoing legal proceedings. US federal statutes that are of general nationwide applicability generally extend to American Samoa unless specifically excluded. Accordingly, federal privacy statutes including HIPAA (for health data), COPPA (for children's online data), FERPA (for educational records), and the Federal Trade Commission Act (for consumer data protection) are generally understood to apply in American Samoa. The Revised Code of American Samoa provides the territorial legal framework, including provisions applicable to government records, privacy, and electronic transactions. American Samoa does not have a standalone comprehensive personal data protection law equivalent to the GDPR. The American Samoa Government's Department of Commerce and other agencies oversee regulatory compliance within the territory. Organisations processing personal data of individuals in American Samoa must comply with applicable federal privacy statutes, the Revised Code of American Samoa, and constitutional privacy protections, and implement appropriate technical and organisational security measures.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
    "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/as-framework.json"
  },
  "crosswalks": {
    "_available_keys": [
      "gdpr_equivalent",
      "iso_standard",
      "nist_framework",
      "regional_framework"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "iso-27001-2022",
    "iso-27701-privacy-information-management"
  ],
  "primary_citations_count": 8
}