Law / Frameworks / NIST AI RMF / Measure
NIST AI RMF, MeasureMEASURE 2.10
Privacy risk of the AI system – as identified in the MAP function – is examined and documented.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MEASURE 2.10
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 15
- laws
- 15
- places
- 2
- with court rulings behind them
- 2
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- MIT mitigations3.2 Data Governance
- MIT mitigations1.2 Risk Management
- NIST Privacy FrameworkCT.PO-P1 Policies, processes, and procedures for authorizing data processing (e.g.,...
- NIST Privacy FrameworkID.IM-P6 Data elements within the data actions are inventoried.
- NIST CSF 2.0ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified...
- NIST CSF 2.0ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent...
A law in force is unmarked; the rest wear their state: not yet in force
Personal data
8 laws, 8 places| Place | Law | What it asks, as read here |
|---|---|---|
| Ley 25.326, personal data reached by scraping |
Scraping personal data from a public source excuses obtaining the data subject's consent, but does not excuse registering the resulting file or database, keeping the data accurate and secure, or observing the cross-border transfer restriction. |
|
| Privacy Act 1988 (Cth), Reach Over Scraped Personal Information |
Do not collect personal information, including personal information scraped from a public website, unless it is reasonably necessary for one or more of the entity's functions or activities. Do not use or disclose personal information collected for one purpose for another purpose, including model training, unless the individual consented or an Australian Privacy Principle 6.2 exception applies. |
|
| Law on Personal Data, open-category personal data and scraped public information |
An app scraping personal data that was made public by someone other than the data subject, or without the subject's consent, does not benefit from the open-category ground and needs a separate lawful basis under Art. 9.6 before collecting or processing it. |
|
| Data Protection Act, 2019, reach over scraped personal data |
Establish a lawful basis before collecting or processing personal data scraped from a public Barbadian website; public availability is not itself an exemption. Do not scrape or otherwise process a biometric identifier unless the data subject consents or a specific statutory ground applies. |
|
| Personal Information Protection and Electronic Documents Act (PIPEDA), scraped personal data |
Apply PIPEDA's purpose-limitation and accountability obligations to personal information collected by crawling, the same as personal information collected any other way. |
|
| Loi n° 24.001 portant protection des données à caractère personnel, collecte de données publiquement accessibles et transfert transfrontalier |
Before relying on data a person has made freely accessible as your lawful basis for collecting it, confirm your use fits the context in which the person made it accessible; freely accessible data supports the legitimate-interest basis but is not an exemption from the Act's other duties. |
|
| Personal Information Protection Act, Art. 15(1)(vi), as applied by the PIPC's publicly-available-data AI guideline |
Document a balancing assessment showing your interest clearly overrides the affected individuals' rights, and adopt the named technical and procedural safeguards, including a disclosure, impact assessment, and an erasure or objection mechanism. |
|
| Federal Decree-Law on the Protection of Personal Data, reach over scraped public personal data |
A scraper collecting the personal data of an individual in onshore UAE from a public, unauthenticated page must still establish a lawful basis under Art. 4 for any use beyond the narrow act that made the data public, and must treat a biometric identifier derived from public photographs, video, or audio as Sensitive Personal Data requiring explicit consent. |
AI governance
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Ley de Fomento a la Inteligencia Artificial y Tecnologías, marco institucional, registro y evaluación de riesgos |
If your AI system handles data classified as confidential, reserved or personal, comply with the risk-evaluation framework the Agencia Nacional de Inteligencia Artificial (ANIA) sets. When you use personal data to develop, research or apply AI, comply with the Ley para la Protección de Datos Personales, under ANIA and ACE supervision. |
|
| AI Act, Article 26(9) (using Article 13 information for a data protection impact assessment) from , in 14 months |
If you are the deployer of a high-risk AI system and you are separately required to carry out a data protection impact assessment under the GDPR or the Law Enforcement Directive, use the information the provider supplies you under Article 13 in that assessment. |
AI sector rules
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| SB 63 (2026), Artificial Intelligence in Health Insurance Prior Authorization from , in 2 days |
Make prominent written disclosure of your use of artificial intelligence in utilization review in your policies and procedures, review its outcomes periodically for accuracy, and keep patient data used in that review within its stated purpose under HIPAA. |
|
| AB 406 (2025), licensed provider restriction on direct clinical use of AI |
Where you use AI for administrative support, ensure the use complies with HIPAA, HITECH, and Nevada's own health-information privacy statutes (NRS 439.581 to 439.597). |
Computer misuse
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Loi n° 09-04 relative à la prévention et à la lutte contre les infractions liées aux technologies de l'information et de la communication |
Do not use data obtained through a judicially-authorized surveillance measure for any purpose other than the investigation it was gathered for. |
|
| Código Penal, Decreto 17-73, Arts. 274 'A' a 274 'G' (Delitos Informáticos) |
Do not create a data bank or computerized record containing data that could affect a person's privacy. |
AI transparency
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Artificial Intelligence Video Interview Act |
Do not share an applicant's video except with a person whose expertise or technology is necessary to evaluate fitness for the position. |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.