{
  "node_id": "gu-framework",
  "title": "Guam - Federal and Territorial Privacy Rights Framework",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-04-27",
  "bluf": "Guam is an unincorporated organised territory of the United States located in the western Pacific Ocean. Guam has its own Organic Act and constitution-equivalent instrument establishing a civilian government with a Governor, legislature (Guam Legislature), and judicial branch. US federal law applies to Guam as a territory. Accordingly, the primary federal privacy statutes - including the Health Insurance Portability and Accountability Act (HIPAA), the Children's Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA), the Gramm-Leach-Bliley Act (GLBA), and the Federal Trade Commission Act - apply in Guam and govern the handling of personal data by organisations operating in the territory. The Federal Trade Commission exercises jurisdiction over unfair or deceptive acts or practices relating to personal data in Guam. The Guam Code Annotated contains provisions relevant to privacy in government records and personal information. Guam does not have a standalone comprehensive personal data protection law equivalent to the GDPR. Organisations processing personal data of individuals in Guam must comply with all applicable US federal privacy statutes, the Guam Code Annotated privacy provisions, and implement appropriate technical and organisational security measures. As a Pacific Island territory, Guam engages with Pacific regional digital governance frameworks through its participation in the region.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
    "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/gu-framework.json"
  },
  "crosswalks": {
    "_available_keys": [
      "gdpr_equivalent",
      "iso_standard",
      "nist_framework",
      "regional_framework"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "iso-27001-2022",
    "iso-27701-privacy-information-management"
  ],
  "primary_citations_count": 8
}