Law / Frameworks / NIST AI RMF

NIST AI Risk Management Framework

Below are its 72 controls in the framework's own order, and under each one the laws we track that bear on it. Each mapping is our reading that a law bears on a control, never a finding that running the control meets the law.

Where the law lands in the framework

37of 72 controls have law747laws257places

GOVERN 1.1: 30 laws in 22 placesGOVERN 1.2: 4 laws in 4 placesGOVERN 1.3: no law we trackGOVERN 1.4: 10 laws in 10 placesGOVERN 1.5: 2 laws in 2 placesGOVERN 1.6: 1 law in 1 placeGOVERN 1.7: no law we trackGOVERN 2.1: 2 laws in 2 placesGOVERN 2.2: 1 law in 1 placeGOVERN 2.3: no law we trackGOVERN 3.1: no law we trackGOVERN 3.2: 2 laws in 1 placeGOVERN 4.1: 3 laws in 3 placesGOVERN 4.2: 13 laws in 11 placesGOVERN 4.3: 3 laws in 3 placesGOVERN 5.1: no law we trackGOVERN 5.2: no law we trackGOVERN 6.1: 4 laws in 3 placesGOVERN 6.2: no law we trackMAP 1.1: 2 laws in 2 placesMAP 1.2: no law we trackMAP 1.3: no law we trackMAP 1.4: no law we trackMAP 1.5: no law we trackMAP 1.6: 29 laws in 24 placesMAP 2.1: no law we trackMAP 2.2: 5 laws in 5 placesMAP 2.3: 9 laws in 6 placesMAP 3.1: no law we trackMAP 3.2: no law we trackMAP 3.3: 202 laws in 119 placesMAP 3.3 202MAP 3.4: 1 law in 1 placeMAP 3.5: 22 laws in 21 placesMAP 4.1: 381 laws in 224 placesMAP 4.1 381MAP 4.2: no law we trackMAP 5.1: 11 laws in 9 placesMAP 5.2: no law we trackMEASURE 1.1: no law we trackMEASURE 1.2: no law we trackMEASURE 1.3: 2 laws in 2 placesMEASURE 2.1: no law we trackMEASURE 2.2: no law we trackMEASURE 2.3: 2 laws in 1 placeMEASURE 2.4: 9 laws in 5 placesMEASURE 2.5: 2 laws in 2 placesMEASURE 2.6: 18 laws in 18 placesMEASURE 2.7: 3 laws in 2 placesMEASURE 2.8: 113 laws in 68 placesMEASURE 2.8 113MEASURE 2.9: 10 laws in 9 placesMEASURE 2.10: 15 laws in 15 placesMEASURE 2.11: 13 laws in 10 placesMEASURE 2.12: no law we trackMEASURE 2.13: no law we trackMEASURE 3.1: no law we trackMEASURE 3.2: no law we trackMEASURE 3.3: 17 laws in 15 placesMEASURE 4.1: no law we trackMEASURE 4.2: no law we trackMEASURE 4.3: no law we trackMANAGE 1.1: no law we trackMANAGE 1.2: no law we trackMANAGE 1.3: 8 laws in 5 placesMANAGE 1.4: no law we trackMANAGE 2.1: no law we trackMANAGE 2.2: no law we trackMANAGE 2.3: no law we trackMANAGE 2.4: 4 laws in 2 placesMANAGE 3.1: 2 laws in 2 placesMANAGE 3.2: no law we trackMANAGE 4.1: 17 laws in 14 placesMANAGE 4.2: no law we trackMANAGE 4.3: 10 laws in 7 places1234561234512341234GOVERNMAPMEASUREMANAGE

Of these laws, 653 are in force, 63 not yet in force, 2 blocked by a court, and 29 proposed and not law.

11 of the 22 controls under Measure have no law we track under them.

  • in force
  • not yet in force
  • blocked by a court
  • proposed
  • no law we track
A bar's height is its number of laws. Select one to open the control.

Each requirement line of the AI and scraping laws we track was read on its own and mapped to the control it bears on most closely, and to a second or third only where the line has more than one limb.

Govern

12 of 19 controls with law
ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceBlockedProposed
GOVERN 1Policies, processes, procedures, and practices across the organization related to the mapping, measuring, and managing of AI risks are in place, transparent, and implemented effectively.
GOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented. 30 laws, 8 not yet in force, 2 proposed 30 22 8 0 2
GOVERN 1.2 The characteristics of trustworthy AI are integrated into organizational policies, processes, procedures, and practices. 4 laws, 2 proposed 4 4 0 0 2
GOVERN 1.3 Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization’s risk tolerance. no law we track no law we track
GOVERN 1.4 The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities. 10 laws, 3 not yet in force, 1 proposed 10 10 3 0 1
GOVERN 1.5 Ongoing monitoring and periodic review of the risk management process and its outcomes are planned and organizational roles and responsibilities clearly defined, including determining the frequency of periodic review. 2 laws 2 2 0 0 0
GOVERN 1.6 Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities. 1 law 1 1 0 0 0
GOVERN 1.7 Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization’s trustworthiness. no law we track no law we track
GOVERN 2Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained for mapping, measuring, and managing AI risks.
GOVERN 2.1 Roles and responsibilities and lines of communication related to mapping, measuring, and managing AI risks are documented and are clear to individuals and teams throughout the organization. 2 laws, 1 not yet in force 2 2 1 0 0
GOVERN 2.2 The organization’s personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements. 1 law 1 1 0 0 0
GOVERN 2.3 Executive leadership of the organization takes responsibility for decisions about risks associated with AI system development and deployment. no law we track no law we track
GOVERN 3Workforce diversity, equity, inclusion, and accessibility processes are prioritized in the mapping, measuring, and managing of AI risks throughout the lifecycle.
GOVERN 3.1 Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team (e.g., diversity of demographics, disciplines, experience, expertise, and backgrounds). no law we track no law we track
GOVERN 3.2 Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems. 2 laws, 2 not yet in force 2 1 2 0 0
GOVERN 4Organizational teams are committed to a culture that considers and communicates AI risk.
GOVERN 4.1 Organizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and uses of AI systems to minimize potential negative impacts. 3 laws, 2 not yet in force 3 3 2 0 0
GOVERN 4.2 Organizational teams document the risks and potential impacts of the AI technology they design, develop, deploy, evaluate, and use, and they communicate about the impacts more broadly. 13 laws, 5 not yet in force, 1 proposed 13 11 5 0 1
GOVERN 4.3 Organizational practices are in place to enable AI testing, identification of incidents, and information sharing. 3 laws, 2 not yet in force 3 3 2 0 0
GOVERN 5Processes are in place for robust engagement with relevant AI actors.
GOVERN 5.1 Organizational policies and practices are in place to collect, consider, prioritize, and integrate feedback from those external to the team that developed or deployed the AI system regarding the potential individual and societal impacts related to AI risks. no law we track no law we track
GOVERN 5.2 Mechanisms are established to enable the team that developed or deployed AI systems to regularly incorporate adjudicated feedback from relevant AI actors into system design and implementation. no law we track no law we track
GOVERN 6Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues.
GOVERN 6.1 Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party’s intellectual property or other rights. 4 laws, 3 not yet in force 4 3 3 0 0
GOVERN 6.2 Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk. no law we track no law we track

Map

9 of 18 controls with law
ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceBlockedProposed
MAP 1Context is established and understood.
MAP 1.1 Intended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented. Considerations include: the specific set or types of users along with their expectations; potential positive and negative impacts of system uses to individuals, communities, organizations, society, and the planet; assumptions and related limitations about AI system purposes, uses, and risks across the development or product AI lifecycle; and related TEVV and system metrics. 2 laws, 1 not yet in force 2 2 1 0 0
MAP 1.2 Interdisciplinary AI actors, competencies, skills, and capacities for establishing context reflect demographic diversity and broad domain and user experience expertise, and their participation is documented. Opportunities for interdisciplinary collaboration are prioritized. no law we track no law we track
MAP 1.3 The organization’s mission and relevant goals for AI technology are understood and documented. no law we track no law we track
MAP 1.4 The business value or context of business use has been clearly defined or – in the case of assessing existing AI systems – re-evaluated. no law we track no law we track
MAP 1.5 Organizational risk tolerances are determined and documented. no law we track no law we track
MAP 1.6 System requirements (e.g., “the system shall respect the privacy of its users”) are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account to address AI risks. 29 laws, 11 not yet in force, 1 proposed 29 24 11 0 1
MAP 2Categorization of the AI system is performed.
MAP 2.1 The specific tasks and methods used to implement the tasks that the AI system will support are defined (e.g., classifiers, generative models, recommenders). no law we track no law we track
MAP 2.2 Information about the AI system’s knowledge limits and how system output may be utilized and overseen by humans is documented. Documentation provides sufficient information to assist relevant AI actors when making decisions and taking subsequent actions. 5 laws, 4 not yet in force 5 5 4 0 0
MAP 2.3 Scientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection (e.g., availability, representativeness, suitability), system trustworthiness, and construct validation. 9 laws, 3 not yet in force, 1 proposed 9 6 3 0 1
MAP 3AI capabilities, targeted usage, goals, and expected benefits and costs compared with appropriate benchmarks are understood.
MAP 3.1 Potential benefits of intended AI system functionality and performance are examined and documented. no law we track no law we track
MAP 3.2 Potential costs, including non-monetary costs, which result from expected or realized AI errors or system functionality and trustworthiness – as connected to organizational risk tolerance – are examined and documented. no law we track no law we track
MAP 3.3 Targeted application scope is specified and documented based on the system’s capability, established context, and AI system categorization. 202 laws, 15 not yet in force, 2 blocked, 9 proposed 202 119 15 2 9
MAP 3.4 Processes for operator and practitioner proficiency with AI system performance and trustworthiness – and relevant technical standards and certifications – are defined, assessed, and documented. 1 law, 1 not yet in force 1 1 1 0 0
MAP 3.5 Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function. 22 laws, 8 not yet in force, 1 proposed 22 21 8 0 1
MAP 4Risks and benefits are mapped for all components of the AI system including third-party software and data.
MAP 4.1 Approaches for mapping AI technology and legal risks of its components – including the use of third-party data or software – are in place, followed, and documented, as are risks of infringement of a third party’s intellectual property or other rights. 381 laws, 10 not yet in force 381 224 10 0 0
MAP 4.2 Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. no law we track no law we track
MAP 5Impacts to individuals, groups, communities, organizations, and society are characterized.
MAP 5.1 Likelihood and magnitude of each identified impact (both potentially beneficial and harmful) based on expected use, past uses of AI systems in similar contexts, public incident reports, feedback from those external to the team that developed or deployed the AI system, or other data are identified and documented. 11 laws, 2 not yet in force, 5 proposed 11 9 2 0 5
MAP 5.2 Practices and personnel for supporting regular engagement with relevant AI actors and integrating feedback about positive, negative, and unanticipated impacts are in place and documented. no law we track no law we track

Measure

11 of 22 controls with law
ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceBlockedProposed
MEASURE 1Appropriate methods and metrics are identified and applied.
MEASURE 1.1 Approaches and metrics for measurement of AI risks enumerated during the MAP function are selected for implementation starting with the most significant AI risks. The risks or trustworthiness characteristics that will not – or cannot – be measured are properly documented. no law we track no law we track
MEASURE 1.2 Appropriateness of AI metrics and effectiveness of existing controls are regularly assessed and updated, including reports of errors and potential impacts on affected communities. no law we track no law we track
MEASURE 1.3 Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates. Domain experts, users, AI actors external to the team that developed or deployed the AI system, and affected communities are consulted in support of assessments as necessary per organizational risk tolerance. 2 laws, 1 not yet in force 2 2 1 0 0
MEASURE 2AI systems are evaluated for trustworthy characteristics.
MEASURE 2.1 Test sets, metrics, and details about the tools used during TEVV are documented. no law we track no law we track
MEASURE 2.2 Evaluations involving human subjects meet applicable requirements (including human subject protection) and are representative of the relevant population. no law we track no law we track
MEASURE 2.3 AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s). Measures are documented. 2 laws, 2 not yet in force 2 1 2 0 0
MEASURE 2.4 The functionality and behavior of the AI system and its components – as identified in the MAP function – are monitored when in production. 9 laws, 5 not yet in force, 1 proposed 9 5 5 0 1
MEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of the generalizability beyond the conditions under which the technology was developed are documented. 2 laws, 2 not yet in force 2 2 2 0 0
MEASURE 2.6 The AI system is evaluated regularly for safety risks – as identified in the MAP function. The AI system to be deployed is demonstrated to be safe, its residual negative risk does not exceed the risk tolerance, and it can fail safely, particularly if made to operate beyond its knowledge limits. Safety metrics reflect system reliability and robustness, real-time monitoring, and response times for AI system failures. 18 laws, 10 not yet in force, 1 proposed 18 18 10 0 1
MEASURE 2.7 AI system security and resilience – as identified in the MAP function – are evaluated and documented. 3 laws, 2 not yet in force 3 2 2 0 0
MEASURE 2.8 Risks associated with transparency and accountability – as identified in the MAP function – are examined and documented. 113 laws, 24 not yet in force, 1 blocked, 18 proposed 113 68 24 1 18
MEASURE 2.9 The AI model is explained, validated, and documented, and AI system output is interpreted within its context – as identified in the MAP function – to inform responsible use and governance. 10 laws, 1 not yet in force 10 9 1 0 0
MEASURE 2.10 Privacy risk of the AI system – as identified in the MAP function – is examined and documented. 15 laws, 2 not yet in force 15 15 2 0 0
MEASURE 2.11 Fairness and bias – as identified in the MAP function – are evaluated and results are documented. 13 laws, 3 not yet in force, 1 proposed 13 10 3 0 1
MEASURE 2.12 Environmental impact and sustainability of AI model training and management activities – as identified in the MAP function – are assessed and documented. no law we track no law we track
MEASURE 2.13 Effectiveness of the employed TEVV metrics and processes in the MEASURE function are evaluated and documented. no law we track no law we track
MEASURE 3Mechanisms for tracking identified AI risks over time are in place.
MEASURE 3.1 Approaches, personnel, and documentation are in place to regularly identify and track existing, unanticipated, and emergent AI risks based on factors such as intended and actual performance in deployed contexts. no law we track no law we track
MEASURE 3.2 Risk tracking approaches are considered for settings where AI risks are difficult to assess using currently available measurement techniques or where metrics are not yet available. no law we track no law we track
MEASURE 3.3 Feedback processes for end users and impacted communities to report problems and appeal system outcomes are established and integrated into AI system evaluation metrics. 17 laws, 2 not yet in force, 5 proposed 17 15 2 0 5
MEASURE 4Feedback about efficacy of measurement is gathered and assessed.
MEASURE 4.1 Measurement approaches for identifying AI risks are connected to deployment context(s) and informed through consultation with domain experts and other end users. Approaches are documented. no law we track no law we track
MEASURE 4.2 Measurement results regarding AI system trustworthiness in deployment context(s) and across the AI lifecycle are informed by input from domain experts and relevant AI actors to validate whether the system is performing consistently as intended. Results are documented. no law we track no law we track
MEASURE 4.3 Measurable performance improvements or declines based on consultations with relevant AI actors, including affected communities, and field data about context-relevant risks and trustworthiness characteristics are identified and documented. no law we track no law we track

Manage

5 of 13 controls with law
ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceBlockedProposed
MANAGE 1AI risks based on assessments and other analytical output from the MAP and MEASURE functions are prioritized, responded to, and managed.
MANAGE 1.1 A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed. no law we track no law we track
MANAGE 1.2 Treatment of documented AI risks is prioritized based on impact, likelihood, and available resources or methods. no law we track no law we track
MANAGE 1.3 Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and documented. Risk response options can include mitigating, transferring, avoiding, or accepting. 8 laws, 1 not yet in force, 3 proposed 8 5 1 0 3
MANAGE 1.4 Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented. no law we track no law we track
MANAGE 2Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by input from relevant AI actors.
MANAGE 2.1 Resources required to manage AI risks are taken into account – along with viable non-AI alternative systems, approaches, or methods – to reduce the magnitude or likelihood of potential impacts. no law we track no law we track
MANAGE 2.2 Mechanisms are in place and applied to sustain the value of deployed AI systems. no law we track no law we track
MANAGE 2.3 Procedures are followed to respond to and recover from a previously unknown risk when it is identified. no law we track no law we track
MANAGE 2.4 Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use. 4 laws, 3 not yet in force 4 2 3 0 0
MANAGE 3AI risks and benefits from third-party entities are managed.
MANAGE 3.1 AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. 2 laws, 1 not yet in force 2 2 1 0 0
MANAGE 3.2 Pre-trained models which are used for development are monitored as part of AI system regular monitoring and maintenance. no law we track no law we track
MANAGE 4Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored regularly.
MANAGE 4.1 Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management. 17 laws, 3 not yet in force, 1 proposed 17 14 3 0 1
MANAGE 4.2 Measurable activities for continual improvements are integrated into AI system updates and include regular engagement with interested parties, including relevant AI actors. no law we track no law we track
MANAGE 4.3 Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. 10 laws, 2 not yet in force 10 7 2 0 0

AI duties with no home in the NIST AI RMF

24 lines in 12 laws

Each line below was read against the AI RMF and recorded as having no control to sit under.

AI governance 6

PlaceLawThe duty, as read
California AI Auditor Registry Act (AB 1405) from , in 2.3 years

If you offer, sell, or conduct a covered AI audit, an audit assessing internal controls, processes, or systems implemented for an AI system or model that are necessary for compliance with California law, register with the Government Operations Agency before doing so, starting .

If you register as an AI auditor, give the agency your business name, contact information, the California laws or regulations you audit under, relevant certifications, a description of your services, and a standard operating procedure describing the standards you apply and the basis for your accuracy and reliability claims.

+5 more
California Independent Verification Organizations Act (SB 813) from , in 3 months

If you want to be designated as an IVO, apply once the Government Operations Agency publishes its application requirements and designation criteria, due by .

If you are a designated IVO, submit an annual report on your standards, methodologies, governance changes, and conflicts of interest to the agency and the Legislature, starting no sooner than 12 months after your designation.

European Union AI Act, Article 19 (automatically generated logs) from , in 14 months

Retain the logs for a period appropriate to the system's intended purpose, at least six months, longer where other Union or national law, such as data-protection law, requires it.

If you are a financial institution, keep the logs as part of the documentation your sector's internal-governance rules already require.

European Union AI Act, Article 26(6) (deployer log-keeping) from , in 14 months

Retain the logs for a period appropriate to the system's intended purpose, at least six months, longer where other Union or national law, such as data-protection law, requires it.

If you are a financial institution, keep the logs as part of the documentation your sector's internal-governance rules already require.

Indonesia Electronic Information and Transactions Law, electronic agent liability

A qualifying Electronic Agent operator must let a user correct information they submitted while a transaction is still in process.

Ireland Regulation of Artificial Intelligence Act 2026

Do not knowingly give false or misleading information to an adjudicator, or disclose confidential material relevant to an adjudicator's finding without authorisation (ss. 95, 104).

AI transparency 3

PlaceLawThe duty, as read
China Provisions on the Administration of Deep Synthesis Internet Information Services, Articles 16 and 17

Retain the log information the Provisions require

Connecticut Subscription-Based AI Provider Disclosure Duty from , in 2 days

Before entering into or renewing a consumer subscription for an AI technology, or collecting a fee for one, give the consumer written notice of the key terms and conditions and obtain the consumer's written acceptance.

In the initial-subscription notice, disclose any quantitative or qualitative limitations you may impose, including limitations you may impose in response to the consumer's own conduct.

+2 more
Louisiana Act 250 (HB 178), attorney duty to verify and disclose AI-generated evidence

As an attorney appearing in a Louisiana court, exercise reasonable diligence to verify the authenticity of evidence, including evidence that may be artificially generated or altered, before offering it to the court.

AI prohibited practices 1

PlaceLawThe duty, as read
Utah Identity Protection Modifications, AI Defamation and Identity Replication (SB 256, 2026 General Session)

Give a person written notice before filing a defamation action over digitally created content; if you are the publisher and remove the content within 10 days of that notice, the plaintiff's recovery is limited to actual damages

AI risk obligations 1

PlaceLawThe duty, as read
South Korea AI Framework Act, Article 34 (business-operator duties for high-impact AI)

Keep that documentation, and the basis for it, for five years, including in electronic form.

AI sector rules 1

PlaceLawThe duty, as read
Utah Health Insurance Preauthorization AI Disclosure (SB 319, 2026 General Session) from , in 3 months

Set an authorization validity period of at least 12 months for a drug, device, or covered service treating a chronic or long-term care condition, and at least six months for an outpatient covered service

Scraping duties no NIST framework has a home for

141 lines in 106 laws

The AI RMF's third-party data controls, MAP 4.1 and GOVERN 6.1, are the only NIST home for a duty not to collect without authorisation. Each line below fits neither, and was recorded as having no control.

Computer misuse 89

PlaceLawThe duty, as read
Afghanistan Penal Code, Part Twelve, Chapter One (Cyber Crimes and Punishment)

Do not alter, damage, destroy, disrupt, or otherwise interfere with a computer system, program, or data without authorization, including by installing a virus, hijacking a network connection, or forging or deceptively accessing a computer system.

Do not disclose a password, access code, or other means of access to a program, computer system, or data without authorization.

+1 more
Alaska Criminal use of a computer

Do not introduce false information into, or tamper with, disrupt, or disable, a computer, computer system, program, or network you access without a right to do so.

Albania Criminal Code, Interference in the Computer Transmissions

Do not interfere, in any way, with computer transmissions or programs; the offence is a penal contravention whether or not the interference causes serious consequences.

Algeria Code pénal, atteintes aux systèmes de traitement automatisé de données

Do not introduce, delete, or modify data held in a system without authorization.

Andorra Penal Code, Attacks on Information Systems

Do not obstruct or interrupt a network or information system, or delete, damage, alter, or make inaccessible data within one, without authorization.

Arizona Computer tampering (Arizona's computer-misuse statute)

Do not design a crawler or bot to prevent a user from exiting a site or a connected location in order to compel the user's device to keep communicating with or displaying your service.

Arizona Unauthorized release of proprietary or confidential computer security information

Do not communicate, release, or publish proprietary or confidential security information, security-related measures, algorithms, or encryption devices specific to a particular computer, system, or network without that system's owner's or operator's authorization.

Arizona Unlawful possession of an access device

Do not knowingly possess, traffic in, publish, or control another person's access device, a credential or similar means of reaching an account or system, without the consent of its issuer, owner, or authorized user and with intent to use or distribute it; this can reach obtaining or trading in login credentials used to collect data from behind a login wall.

Arkansas Unlawful interference with access to computers; unlawful use or access of computers

Do not knowingly and without authorization interfere with, deny, or cause the denial of access to a computer, system, or network to a person who has the duty and right to use it.

Austria StGB Sections 118a and 126a to 126c, Computer-Misuse Offenses

Do not alter, delete, suppress, or render unusable data over which you lack sole authority, in a way that damages another, per StGB Section 126a.

Do not seriously disrupt a computer system's functioning by entering or transmitting data, per StGB Section 126b.

+1 more
Show the other 79 laws
Azerbaijan Criminal Code, unauthorised access, illegal interception, and system interference

Do not intentionally damage, delete, corrupt, modify, or block computer data, or seriously obstruct a computer system's operation, in a way that causes significant damage.

Belarus Criminal Code, Crimes Against Computer Security

Do not develop, use, distribute, or sell a program or device known to be intended for defeating a protection system or for unauthorized access to, or destruction, blocking, or modification of, computer information.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre VI (cybercriminalité), atteintes aux réseaux et systèmes d'information

Do not cause an interruption of a computer system's normal operation, or damage, delete, deteriorate, alter, or suppress computer data, without right.

Do not produce, sell, obtain, import, or distribute a device, program, password, or access code designed to commit any of the above offenses.

+1 more
Bermuda Computer Misuse Act 1996, unauthorised access and modification offences

Do not modify computer material, or cause a computer to cease to function, without authorisation.

Bhutan Information, Communications and Media Act of Bhutan 2018, unauthorized access and tampering with computer systems

Do not cause a stoppage or denial of service, delete or alter data, diminish a system's value or utility, or introduce a computer contaminant, with intent to cause or knowing it is likely to cause wrongful loss, gain, or damage; this is punishable as tampering with computer material under the Penal Code of Bhutan.

Bolivia Código Penal, Manipulación Informática

Do not manipulate a computer data-processing or data-transfer operation to produce an incorrect result, or to avoid a process that would otherwise have produced a correct one, in order to obtain an undue benefit at a third party's expense.

Botswana Cybercrime and Computer Related Crimes Act, 2018 (Act No. 18 of 2018)

Do not damage, delete, alter, or interfere with computer data, or hinder or interfere with the functioning of a computer or computer system, without lawful excuse.

Do not manufacture, sell, distribute, or possess a device, password, or access code designed or adapted to commit an offence under the Act.

+1 more
Burkina Faso Loi n°025-2018/AN du 31 mai 2018 portant Code pénal, computer and data systems offenses (Livre VII, Titre I, Chapitre 1)

Do not hinder or falsify the operation of a computer system, or introduce, damage, delete, alter, or suppress computer data without right.

Do not produce, sell, obtain, import, or distribute a device, program, password, or access code intended to commit any of the above offenses, unless it is for authorized testing or protecting a computer system.

+1 more
Canada Criminal Code, unauthorized use of a computer

Do not use, possess, traffic in, or permit another person to have access to a computer password to commit either of the above.

China Criminal Law, Arts. 285-286 (unauthorized computer intrusion and system destruction)

Do not damage or destroy a computer information system's function, data, or programs (Art. 286).

Croatia Kazneni zakon, Computer Crime Chapter (Arts. 266-273)

Do not make, acquire, sell, possess, distribute or make available a device, computer program or computer data created or adapted to commit any of these offences; doing so is itself a criminal offence carrying up to three years' imprisonment, or up to two years for passwords, access codes or similar data.

Cyprus Attacks against Information Systems Law, Articles 3, 4, 7, 11-12 (Illegal Access, System Interference, Tools, Corporate Liability)

Do not intentionally and without right seriously hinder or interrupt an information system's operation, including by inputting, transmitting, damaging, deleting, deteriorating, altering or suppressing its data or by blocking access to it.

Do not, intentionally and without right, produce, sell, procure for use, import, distribute or otherwise make available a computer program designed or adapted primarily to commit an offence under articles 3 to 6, or a password, access code or similar data giving access to an information system, intending it to be used to commit such an offence.

Djibouti Digital Code, Book VI: Fraudulent Access to Information Systems

Do not introduce, or attempt to introduce, data into an information system without authorization.

Dominican Republic Ley No. 53-07 sobre Crímenes y Delitos de Alta Tecnología, Acceso Ilícito

Do not divulge, generate, copy, capture, use, alter, traffic in, or decode an access code or similar mechanism used to achieve illicit access to such a system, and do not falsify an access device.

Ecuador COIP, ataque a la integridad de sistemas informáticos

Do not destroy, damage, delete, deteriorate, alter, suspend, obstruct, or suppress computer data or an information system's logical components, and do not design, acquire, or distribute malicious software meant to do so.

Egypt Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes

Do not disrupt, slow, damage, or alter the design of a website, email account, or information system without authorization.

Estonia Karistusseadustik (Penal Code) Sections 206 and 207, Interference with Computer Data and Hindering of Functioning of Computer Systems

Do not alter, delete, damage or block data in a computer system, and do not interfere with or hinder the functioning of a computer system, including by an automated crawler's request volume or behavior.

France Code pénal STAD Offenses, Unauthorized Access to and Interference with Automated Data Processing Systems

Do not impair, falsify, corrupt, or delete data on a French computer system in the course of an automated crawl, which Articles 323-2 and 323-3 punish separately from unauthorized access itself, with a higher penalty where the system is a State personal-data system.

Gambia Information and Communications Act, 2009, Computer Misuse and Cyber Crime part

Do not modify data held in a computer system, or degrade, interrupt, or deny access to a computer system, without lawful authority or excuse.

Do not manufacture, sell, import, distribute, or possess a device or data designed or adapted primarily to commit an offence under this Part.

+1 more
Germany Ausspaehen, Abfangen und Manipulation von Daten (Computer Misuse and Data Interference)

Do not produce, obtain, sell, or distribute passwords, security codes, or software designed to commit these offences.

Do not unlawfully delete, suppress, render unusable, or alter data.

+1 more
Ghana Electronic Transactions Act, Cyber Offences

Do not disclose a password or access code, or modify a programme or electronic record, without authority.

Guatemala Código Penal, Decreto 17-73, Arts. 274 'A' a 274 'G' (Delitos Informáticos)

Do not destroy, erase, or render useless another's computer records or the programs a computer uses, and do not distribute destructive programs capable of damaging computerized records, programs, or equipment.

Hawaii Hawaii Computer Crime Law, Part IX (unauthorized computer access, computer fraud, computer damage)

Knowingly accessing a computer with intent to commit theft is computer fraud, graded by the degree of theft intended, up to a class A felony.

Knowingly or intentionally causing unauthorized damage to a computer, computer system, or computer network is computer damage, graded up to a class A felony where the computer manages or controls critical infrastructure.

Honduras Código Penal, seguridad de las redes y de los sistemas informáticos

Do not introduce, delete, alter or suppress computer data, or disable a computer system's operation, without authorization.

Hungary Büntető Törvénykönyv (Criminal Code), Sections 423-424, Violation of Information Systems or Data

Do not hinder an information system's operation, or modify, delete, or render inaccessible data stored in it, without authorization; Btk. Section 423(2) makes this a felony independent of Section 423(1)'s access offense.

Ireland Criminal Justice (Offences Relating to Information Systems) Act 2017

Do not intentionally hinder or interrupt an information system, or delete, damage, alter, suppress or intercept data on it, without lawful authority (ss. 3-5).

Do not produce, distribute or make available a computer programme, password, code or similar data designed for committing any of the section 2 to 5 offences (s. 6).

Italy Codice Penale Art. 615-quater, Illicit Possession or Distribution of Access Devices

Do not obtain, hold, produce, reproduce, distribute, or supply codes, passwords, devices, or other means suited to accessing a computer or telematic system protected by security measures, or instructions enabling that access, without authorization.

Kansas Unlawful acts concerning computers (Kansas's computer-crime statute)

Do not knowingly and without authorization disclose a password, code, or other means of access to a computer, computer network, social networking website, or another person's personal electronic content.

Kazakhstan Penal Code, disruption of an informatization object

Do not carry out intentional acts or omissions directed at disrupting the operation of an informatization object, such as a server or online service.

Latvia Krimināllikums Sections 241, 243, 244, Automated Data Processing System Offences

Do not modify, damage, destroy, impair, or conceal information in an automated data processing system without authorization, or knowingly enter false information into it, per Section 243.

Do not manufacture, adapt, distribute, acquire, transport, or store a tool, device, software, password, or access code intended to influence such a system's resources, or to gain unauthorized access to it for committing a crime, per Section 244.

Lebanon Law No. 81/2018 on Electronic Transactions and Personal Data, Illegal Access to an Information System and Related IT-System Offences

Do not fraudulently damage or hinder the operation of an information system, or fraudulently enter, delete, or modify digital data hosted by one.

Do not intentionally hinder, disturb, or disrupt access to a service, hardware, software, or data source through the information network.

Lesotho Penal Code Act, 2010, Misuse of Property of Another

Do not interfere with a computer or electronic storage device owned by another, or the data or programmes on it, without the owner's consent, if you intend to secure an advantage for yourself or cause damage.

Liechtenstein Strafgesetzbuch Arts. 126a to 126c, Data Damage, System Interference and Misuse of Devices

Do not change, delete, or otherwise make unusable or suppress data processed, transmitted, or supplied by automation that is not at your sole disposal, in a way that causes damage to another person.

Do not seriously interfere with the functioning of a computer system that you may not use, or may not use alone, by entering or transmitting data.

+1 more
Maine Aggravated criminal invasion of computer privacy

Do not intentionally or knowingly damage a computer resource, or introduce or allow the introduction of a computer virus into one, without a reasonable ground to believe you have the right to do so.

Malta Criminal Code Article 337D, Misuse of Hardware

Do not modify, damage, destroy, or impair the operation of computer equipment, a computer, a computer system, or a computer network without authorisation while crawling or otherwise interacting with it in Malta, under Article 337D of the Criminal Code.

Massachusetts Obtaining computer services by fraud or misrepresentation; penalties

Do not obtain, or attempt to obtain, a subscription-based or otherwise paid commercial computer service by false representation, false statement, unauthorized account charging, equipment tampering, or any other fraudulent means.

Missouri Tampering with computer data, computer equipment, and computer users

Do not deny computer system services to an authorized user.

Monaco Code Pénal Arts. 389-1 to 389-9, Unauthorized Access, System Interference and Data Damage

Do not produce, hold, or supply a tool, device, password or access code principally designed to commit these offences, other than for authorized testing, research, or protecting an information system.

Mozambique Electronic Transactions Law, Computer Misuse Contraventions

Do not damage, delete, deteriorate, alter, or suppress data belonging to a computer system without authorisation.

Do not intentionally affect the functioning of a computer system or network by introducing, transmitting, damaging, deleting, deteriorating, altering, or suppressing data.

New Mexico Computer Crimes Act, unauthorized computer use

Do not alter, damage, disrupt or destroy computer property or a computer service, or introduce data known to be false with intent to harm another's property or financial interests.

New Zealand Copyright Act 1994, Technological Protection Measures

Do not make, import, sell, distribute, or advertise a device, or provide a service or publish information, intended to circumvent a technological protection measure if you know or have reason to believe it will be used to infringe copyright in the protected work.

Nicaragua Ley No. 1042, interference with and damage to computer systems, as reformed by Ley No. 1219

Do not interfere with, alter, damage, or disable a computer system or the data it holds.

Niger Loi n° 2019-33, accès illégal et maintien frauduleux

Do not cause the suppression, modification or alteration of data, or a malfunction of the system, when accessing or remaining present in it without right.

North Korea Criminal Code, Computer and Information Offences

Do not destroy important information stored on a computer or other information-processing device, or input or spread false information through a computer network in a way that causes confusion in information processing.

North Macedonia Criminal Code, Damage and Unauthorized Entry into a Computer System

Do not delete, alter, damage or conceal computer data, a program, or a computer system without authorization, or otherwise disable or hinder the use of a computer system, data, program or computer communication.

Pakistan Prevention of Electronic Crimes Act 2016, unauthorized access and interference offences

Do not interfere with, damage, or disrupt an information system or data in Pakistan without authorization, which section 5 of the Act separately punishes.

Paraguay Código Penal, arts. 146 b y 174 b, introducidos por la Ley N° 4439/2011, acceso indebido a datos y a sistemas informáticos

Do not obstruct a data-processing operation by destroying, disabling, removing or altering the infrastructure that carries it out.

Peru Ley 30096, unauthorized access and data/system integrity offenses

Do not damage, introduce, delete, deteriorate, alter, suppress, or make inaccessible another party's computer data.

Do not disable a computer system, impede access to it, or hinder or prevent its operation or the provision of its services.

+1 more
Poland Kodeks karny, Unauthorized Access to Information and Computer-Misuse Offenses

Do not produce, obtain, sell, or supply a device, computer program, password, or access code adapted to commit an Art. 267, 268a, 269, or 269a offense; doing so is a separate offense under Art. 269b carrying imprisonment up to 5 years, unless you act solely to secure a system or to develop a securing method.

Republic of the Congo Law on Combating Cybercrime, Unauthorised Access, Interference and Fraudulent Copying of Data

Do not hinder or attempt to hinder the functioning of an information system.

Rhode Island Rhode Island Computer Crime chapter, unauthorized access and computer trespass

Do not use a computer or network without authority and with intent to disable, alter, or erase data or programs, or to cause a malfunction, even where no fraudulent purpose is involved.

Romania Cod penal, Art. 360-366, Infracțiuni contra siguranței și integrității sistemelor și datelor informatice (Offences Against the Security and Integrity of Computer Systems and Data)

Do not produce, distribute, or possess a device, program, password, or access code intended to commit one of these offences, per Cod penal art. 365.

Russia Criminal Code Article 273, Creation, Use and Distribution of Malicious Computer Programs

Do not create, use, or distribute computer programs, or other computer information, known to be intended for unauthorized destruction, blocking, modification, or copying of computer information, or for defeating computer-information security tools, under Criminal Code Article 273; this reaches tools built to circumvent a site's technical access controls.

Saint Kitts and Nevis Electronic Crimes Act, illegal access and related computer-misuse offences

Do not interfere with data on, or the operation of, a computer system without lawful excuse or justification.

Saint Lucia Computer Misuse Act, unauthorized access, interception and modification

Do not modify data held in a computer system without authorization, including to impair the system's operation or the reliability of the data it holds.

Samoa Crimes Act 2013, computer-access and interference offences

Do not produce, sell, procure, import, distribute, or make available a device, access code, or password designed or intended for use in accessing an electronic system without authorisation.

San Marino Computer Crimes Law, Unlawful Access to Computer or Telematics Systems

Do not hold or access tools suited to enter a security-measure-protected system, or equipment or programmes designed to alter such a system or its data, without justified reason.

Serbia Criminal Code, Offences Against the Security of Computer Data

Do not delete, alter, damage, or conceal computer data or a program without authorisation.

Slovakia Trestný zákon, Unauthorized Access to a Computer System and Related Offences

Do not interfere with a computer system's operation or with computer data within it without authorization, including by unauthorized insertion, transmission, damage, deletion, degradation, alteration, suppression, or blocking of computer data.

Do not produce, import, procure, sell, exchange, distribute, or otherwise make available a device, computer program, password, access code, or similar data created to enable unauthorized access to a computer system.

South Dakota South Dakota Unlawful Use of a Computer System, Software, or Data

Do not disrupt, deny, or inhibit access to software, data, or a computer system, or modify, change, alter, destroy, or disable software, data, or a computer system, without the owner's consent; these acts carry felony exposure up to a Class 2 felony (up to twenty-five years and a $50,000 fine) where the access is also part of a deceptive scheme to obtain money, property, or services.

South Korea Information and Communications Network Act, Article 48 (network intrusion and anti-circumvention)

Do not build, install, or distribute a tool whose purpose is to bypass a network's normal access-control or authentication procedures.

South Sudan Penal Code Act, 2008, computer and electronic related offences

Do not deliberately introduce a computer virus into a computer or computer network without authority from its owner.

Sri Lanka Computer Crime Act, unauthorised access, modification and dealing with unlawfully obtained data from a date not yet set

Do not intentionally cause unauthorised modification or damage to a computer, computer system, or computer programme in the course of an automated collection process.

State of Palestine Law by Decree No. 10 of 2018 on Cybercrime, Unauthorised Access and Computer Interference

Do not obstruct or disrupt access to a service, device, programme, or data source on the network (art. 5).

Do not introduce anything that suspends or disrupts a system's operation, or damages, deletes, or modifies a programme, on the network (art. 6).

Suriname Wetboek van Strafrecht, Hacking and Denial of Access (arts. 187b-187c)

Do not hinder another person's access to or use of a computer system by flooding it with data.

Taiwan Criminal Code, Offenses Against Computer Security

Do not build or use a program whose purpose is committing one of the offenses in this chapter (Article 362).

Turkey Turkish Penal Code, Information System Crimes

Do not obstruct or disrupt a computer system's operation, or corrupt, destroy, alter, or render inaccessible the data it holds, or insert or transmit its data without authorisation, regardless of whether the data taken is personal.

Ukraine Criminal Code, Creation and Distribution of Malicious Software

Do not create, distribute or sell software or technical means designed for unauthorized interference in the operation of an information, electronic communications or information-and-communications system or network.

Ukraine Criminal Code, Unauthorized Interference with Information Systems

Do not interfere, without authorization, in the operation of an information, electronic communications or information-and-communications system or network.

United States Virgin Islands Virgin Islands Computer Crimes Act, unauthorized access and computer trespass

Do not access or cause to be accessed a computer, computer system, or computer network to devise or execute a scheme to defraud, or to obtain money, property, or services by false or fraudulent pretenses, representations, or promises.

Do not access, without authorization and for a fraudulent or other illegal purpose, a computer, computer system, computer network, computer software, computer program, or the data it contains, to alter, damage, or destroy it.

Uruguay Código Penal arts. 297 bis, 297 ter, 297 quater, 358 quater, and 358 quinquies, computer-offence provisions inserted by Ley N° 20.327

Do not destroy, alter, or render unusable data or computer systems belonging to another without authorization.

Vanuatu Cybercrime Act 2021, computer-access and interference offences

Do not do any act that causes unauthorised interference to a computer system, program or data; the fine and prison term rise sharply where the interference causes a financial loss over VT1,000,000, threatens national security or public health or safety, or causes physical injury or death.

Do not produce, sell, import, export, distribute or make available software, a device, a password or an access code for the purpose of unauthorised interception or interference with a computer system, except for authorised training, testing or protection of a computer system.

Vatican City Unauthorised access to a protected computer or telematic system (Legge N. DXXXI, arts. 158 ter-158 quater)

Do not cause the destruction or damage of a system, or of the data, information, or programs it holds, or interrupt its operation, when you access it; the penalty is higher where the system belongs to the Holy See, Vatican City State, or another public authority.

Do not obtain, reproduce, disseminate, or supply passwords or other means of accessing a protected system, or instructions for doing so, for profit or to cause harm.

Venezuela Ley Especial contra los Delitos Informáticos, unauthorized access and sabotage of systems (Arts. 6-11)

Do not import, distribute, sell, or use equipment or programs meant to defeat a system's security measures.

Vietnam Law on Cybersecurity, unauthorized access prohibition

Do not distribute software, or use a tool, that obstructs, disrupts, or harms the operation of a telecom network, computer network, information system, or database.

Virginia Virginia Computer Trespass, malicious intent or deceptive means requirement

Intentionally deceptive circumvention of a technical barrier to disable or alter data or programs squarely fits this statute's elements.

West Virginia West Virginia Computer Crime and Abuse Act

Do not knowingly and willfully access a computer, computer service, or computer network to execute a scheme to defraud or to obtain money, property, or services by fraudulent pretenses; this is a felony punishable by up to $10,000 and ten years, or both.

Do not introduce ransomware into a computer, computer system, or computer network with intent to extort money or other consideration; this is a separate felony punishable by up to $100,000 and ten years, or both.

Wisconsin Wisconsin computer crimes statute

Intentionally flooding a computer, program, system, or network with messages that exceed its processing capacity, causing an interruption in service, is a separate offense under this statute regardless of whether any data is altered.

Zimbabwe Cyber and Data Protection Act, Insertion of Computer-Misuse Offences into the Criminal Law Code

Do not damage, delete, alter, or block access to computer data, or interfere with the functioning of a computer or information system, without lawful authority.

Do not communicate, disclose, or use an access code, password, or programme designed to gain unauthorised access to data or a computer system.

Copyright and text and data mining (TDM) 8

PlaceLawThe duty, as read
Cook Islands Copyright Act 2013, economic rights, computer program copying, and technological protection measures

Do not manufacture, import for sale or rental, or supply a device or means designed to circumvent a technological measure applied to a work, sound recording, or communication to the public to prevent or restrict its copying.

Germany Text und Data Mining (General Text and Data Mining Exception)

May reproduce lawfully accessible works for text and data mining, but must delete the reproduction once it is no longer needed for that purpose.

Hungary Szjt. Section 35/A, Text and Data Mining Exception

Keep any copies made for text-and-data mining only for as long as the mining itself requires.

Ireland Text and Data Mining Exceptions, Copyright and Related Rights Act 2000 ss. 53A-53B

A reproduction made under the research and non-commercial text-and-data-mining exception must be stored in a secure manner appropriate to the work and retained only as necessary for the purposes of the scientific research, including verification of results (s. 53A(3A)).

Italy Legge sul Diritto d'Autore Artt. 70-ter and 70-quater, Text-and-Data-Mining Exceptions

Keep any copy made for text-and-data-mining purposes only for as long as needed for that purpose, and secure it to at least the level Article 70-ter requires.

Latvia Autortiesību likums Article 21.1, Text and Data Mining Exception (Scraping and AI Training)

Keep a copy made under the text-and-data-mining exception only as long as needed for the mining itself, per Article 21.1(2).

Netherlands Auteurswet, artt. 15n and 15o, Text and Data Mining Exceptions

Keep a reproduction made under either exception only as long as needed for the text-and-data-mining purpose.

Slovakia Autorský zákon, TDM Exception

Keep a reproduction made under the general text-and-data-mining exception only for as long as the mining requires.

Unfair competition 6

PlaceLawThe duty, as read
Austria UWG Section 1, General Unfair Commercial Practices Clause

Do not apply, in the course of trade, an unfair commercial practice or other unfair conduct capable of more than trivially disadvantaging a competing undertaking, per UWG Section 1.

California Unfair Competition Law (predicate vehicle for scraping claims)

Causing measurable harm to, or impairing the operation of, a target's computer system through your crawling can expose you to trespass to chattels; merely unwanted access without such harm does not, under Intel Corp. v. Hamidi (Cal. 2003).

Germany Verbot unlauterer geschaeftlicher Handlungen und Mitbewerberschutz (General Clause and Competitor Protection)

Do not denigrate or disparage a competitor's identifying marks, goods, services, activities, or personal or business circumstances.

Do not assert or spread unproven facts capable of damaging a competitor's business or credit.

+2 more
Oklahoma Oklahoma Deceptive Trade Practices Act

Do not pass off your goods or services as another's, or make a false representation about the source, sponsorship, approval, affiliation, characteristics, or quantity of goods or services, in the course of business.

South Korea Unfair Competition Prevention and Trade Secret Protection Act, Art. 2(1) items ka and pa (data misappropriation and general catch-all)

Do not create, provide, or distribute a technology or device whose main purpose is to circumvent a technical measure protecting data.

Taiwan Fair Trade Act, general clause against deceptive or unfair competitive conduct

Do not engage in deceptive conduct, or conduct that is obviously unfair and capable of affecting trading order, toward a competitor; Article 25 is a residual clause the Fair Trade Commission can apply to a novel unfair-competition claim, including one framed around reuse of a competitor's content or data, that no more specific provision of the Act covers.

Personal data 2

PlaceLawThe duty, as read
Barbados Data Protection Act, 2019, reach over scraped personal data

Before moving scraped personal data outside Barbados, confirm an adequate level of protection or an appropriate safeguard.

Central African Republic Loi n° 24.001 portant protection des données à caractère personnel, collecte de données publiquement accessibles et transfert transfrontalier

Before transferring personal data you collected in the Central African Republic, or personal data about a person there, to another country, confirm the destination offers a similar level of protection or rely on one of the Act's specific derogations.

Give the data protection agency prior notice before transferring personal data to a State outside the CEMAC or CEEAC, and rely on the agency's authorization, supported by appropriate contractual guarantees, where the destination lacks equivalent protection.

Contract terms of service (ToS) 1

PlaceLawThe duty, as read
Samoa Electronic Transactions Act 2008, electronic contract and signature recognition

Do not rely on an electronic signature to satisfy a signature requirement unless it identifies the signatory, indicates their approval, is as reliable as the purpose requires, and the recipient consents to receiving it.

Where the law and the framework part

35 of the 72 controls have no law we track under them.

165 requirement lines were read as having no control in this framework to sit under; they are listed above.

The framework's text

Full text of the NIST AI Risk Management Framework, public domain (a US government work).

Read it from the publisher: nvlpubs.nist.gov