Law / Frameworks / NIST Privacy Framework
NIST Privacy Framework
Below are its 100 controls in the framework's own order, and under each one the laws we track that bear on it. Each mapping is our reading that a law bears on a control, never a finding that running the control meets the law.
Where the law lands in the framework
62of 100 controls have law1,212laws234places
Of these laws, 1,069 are in force, 118 not yet in force, and 25 proposed and not law.
17 of the 30 controls under Protect-P have no law we track under them.
- in force
- not yet in force
- blocked by a court
- proposed
- no law we track
Each requirement line of the privacy and communications laws we track was read on its own and mapped to the control it bears on most closely, and to a second or third only where the line has more than one limb.
Identify-P
13 of 21 controls with lawDevelop the organizational understanding to manage privacy risk for individuals arising from data processing.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| ID.IM-PInventory and Mapping: Data processing by systems, products, or services is understood and informs the management of privacy risk. | ||||||
| ID.IM-P1 | Systems/products/services that process data are inventoried. no law we track | no law we track | ||||
| ID.IM-P2 | Owners or operators (e.g., the organization or third parties such as service providers, partners, customers, and developers) and their roles with respect to the systems/products/services and components (e.g., internal or external) that process data are inventoried. 1 law | 1 | 1 | 0 | 0 | |
| ID.IM-P3 | Categories of individuals (e.g., customers, employees or prospective employees, consumers) whose data are being processed are inventoried. no law we track | no law we track | ||||
| ID.IM-P4 | Data actions of the systems/products/services are inventoried. 33 laws, 4 not yet in force, 2 proposed | 33 | 30 | 4 | 2 | |
| ID.IM-P5 | The purposes for the data actions are inventoried. 1 law | 1 | 1 | 0 | 0 | |
| ID.IM-P6 | Data elements within the data actions are inventoried. 5 laws, 1 not yet in force | 5 | 5 | 1 | 0 | |
| ID.IM-P7 | The data processing environment is identified (e.g., geographic location, internal, cloud, third parties). 16 laws, 1 not yet in force | 16 | 15 | 1 | 0 | |
| ID.IM-P8 | Data processing is mapped, illustrating the data actions and associated data elements for systems/products/services, including components; roles of the component owners/operators; and interactions of individuals or third parties with the systems/products/services. no law we track | no law we track | ||||
| ID.BE-PBusiness Environment: The organization’s mission, objectives, stakeholders, and activities are understood and prioritized; this information is used to inform privacy roles, responsibilities, and risk management decisions. | ||||||
| ID.BE-P1 | The organization’s role(s) in the data processing ecosystem are identified and communicated. 3 laws | 3 | 3 | 0 | 0 | |
| ID.BE-P2 | Priorities for organizational mission, objectives, and activities are established and communicated. no law we track | no law we track | ||||
| ID.BE-P3 | Systems/products/services that support organizational priorities are identified and key requirements communicated. no law we track | no law we track | ||||
| ID.RA-PRisk Assessment: The organization understands the privacy risks to individuals and how such privacy risks may create follow-on impacts on organizational operations, including mission, functions, other risk management priorities (e.g., compliance, financial), reputation, workforce, and culture. | ||||||
| ID.RA-P1 | Contextual factors related to the systems/products/services and the data actions are identified (e.g., individuals’ demographics and privacy interests or perceptions, data sensitivity and/or types, visibility of data processing to individuals and third parties). no law we track | no law we track | ||||
| ID.RA-P2 | Data analytic inputs and outputs are identified and evaluated for bias. 1 law | 1 | 1 | 0 | 0 | |
| ID.RA-P3 | Potential problematic data actions and associated problems are identified. 6 laws | 6 | 6 | 0 | 0 | |
| ID.RA-P4 | Problematic data actions, likelihoods, and impacts are used to determine and prioritize risk. 44 laws, 4 not yet in force, 2 proposed | 44 | 41 | 4 | 2 | |
| ID.RA-P5 | Risk responses are identified, prioritized, and implemented. 10 laws, 1 not yet in force, 1 proposed | 10 | 10 | 1 | 1 | |
| ID.DE-PData Processing Ecosystem Risk Management: The organization’s priorities, constraints, risk tolerance, and assumptions are established and used to support risk decisions associated with managing privacy risk and third parties within the data processing ecosystem. The organization has established and implemented the processes to identify, assess, and manage privacy risks within the data processing ecosystem. | ||||||
| ID.DE-P1 | Data processing ecosystem risk management policies, processes, and procedures are identified, established, assessed, managed, and agreed to by organizational stakeholders. no law we track | no law we track | ||||
| ID.DE-P2 | Data processing ecosystem parties (e.g., service providers, customers, partners, product manufacturers, application developers) are identified, prioritized, and assessed using a privacy risk assessment process. 22 laws, 6 not yet in force | 22 | 20 | 6 | 0 | |
| ID.DE-P3 | Contracts with data processing ecosystem parties are used to implement appropriate measures designed to meet the objectives of an organization’s privacy program. 54 laws, 4 not yet in force, 1 proposed | 54 | 47 | 4 | 1 | |
| ID.DE-P4 | Interoperability frameworks or similar multi-party approaches are used to manage data processing ecosystem privacy risks. no law we track | no law we track | ||||
| ID.DE-P5 | Data processing ecosystem parties are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their contractual, interoperability framework, or other obligations. 4 laws | 4 | 4 | 0 | 0 | |
Govern-P
14 of 20 controls with lawDevelop and implement the organizational governance structure to enable an ongoing understanding of the organization’s risk management priorities that are informed by privacy risk.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| GV.PO-PGovernance Policies, Processes, and Procedures: The policies, processes, and procedures to manage and monitor the organization’s regulatory, legal, risk, environmental, and operational requirements are understood and inform the management of privacy risk. | ||||||
| GV.PO-P1 | Organizational privacy values and policies (e.g., conditions on data processing such as data uses or retention periods, individuals’ prerogatives with respect to data processing) are established and communicated. 81 laws, 4 not yet in force, 5 proposed | 81 | 79 | 4 | 5 | |
| GV.PO-P2 | Processes to instill organizational privacy values within system/product/service development and operations are established and in place. 26 laws, 2 not yet in force, 3 proposed | 26 | 25 | 2 | 3 | |
| GV.PO-P3 | Roles and responsibilities for the workforce are established with respect to privacy. 51 laws, 3 not yet in force, 3 proposed | 51 | 50 | 3 | 3 | |
| GV.PO-P4 | Privacy roles and responsibilities are coordinated and aligned with third-party stakeholders (e.g., service providers, customers, partners). 9 laws, 1 not yet in force | 9 | 9 | 1 | 0 | |
| GV.PO-P5 | Legal, regulatory, and contractual requirements regarding privacy are understood and managed. 184 laws, 13 not yet in force, 3 proposed | 184 | 110 | 13 | 3 | |
| GV.PO-P6 | Governance and risk management policies, processes, and procedures address privacy risks. no law we track | no law we track | ||||
| GV.RM-PRisk Management Strategy: The organization’s priorities, constraints, risk tolerances, and assumptions are established and used to support operational risk decisions. | ||||||
| GV.RM-P1 | Risk management processes are established, managed, and agreed to by organizational stakeholders. 1 law | 1 | 1 | 0 | 0 | |
| GV.RM-P2 | Organizational risk tolerance is determined and clearly expressed. no law we track | no law we track | ||||
| GV.RM-P3 | The organization’s determination of risk tolerance is informed by its role(s) in the data processing ecosystem. no law we track | no law we track | ||||
| GV.AT-PAwareness and Training: The organization’s workforce and third parties engaged in data processing are provided privacy awareness education and are trained to perform their privacy-related duties and responsibilities consistent with related policies, processes, procedures, and agreements and organizational privacy values. | ||||||
| GV.AT-P1 | The workforce is informed and trained on its roles and responsibilities. 7 laws | 7 | 7 | 0 | 0 | |
| GV.AT-P2 | Senior executives understand their roles and responsibilities. no law we track | no law we track | ||||
| GV.AT-P3 | Privacy personnel understand their roles and responsibilities. 1 law | 1 | 1 | 0 | 0 | |
| GV.AT-P4 | Third parties (e.g., service providers, customers, partners) understand their roles and responsibilities. no law we track | no law we track | ||||
| GV.MT-PMonitoring and Review: The policies, processes, and procedures for ongoing review of the organization’s privacy posture are understood and inform the management of privacy risk. | ||||||
| GV.MT-P1 | Privacy risk is re-evaluated on an ongoing basis and as key factors, including the organization’s business environment (e.g., introduction of new technologies), governance (e.g., legal obligations, risk tolerance), data processing, and systems/products/services change. 1 law | 1 | 1 | 0 | 0 | |
| GV.MT-P2 | Privacy values, policies, and training are reviewed and any updates are communicated. no law we track | no law we track | ||||
| GV.MT-P3 | Policies, processes, and procedures for assessing compliance with legal requirements and privacy policies are established and in place. 11 laws, 2 not yet in force, 1 proposed | 11 | 10 | 2 | 1 | |
| GV.MT-P4 | Policies, processes, and procedures for communicating progress on managing privacy risks are established and in place. 7 laws, 1 not yet in force | 7 | 6 | 1 | 0 | |
| GV.MT-P5 | Policies, processes, and procedures are established and in place to receive, analyze, and respond to problematic data actions disclosed to the organization from internal and external sources (e.g., internal discovery, privacy researchers, professional events). 3 laws, 2 not yet in force, 1 proposed | 3 | 3 | 2 | 1 | |
| GV.MT-P6 | Policies, processes, and procedures incorporate lessons learned from problematic data actions. 1 law | 1 | 1 | 0 | 0 | |
| GV.MT-P7 | Policies, processes, and procedures for receiving, tracking, and responding to complaints, concerns, and questions from individuals about organizational privacy practices are established and in place. 28 laws, 1 not yet in force, 1 proposed | 28 | 28 | 1 | 1 | |
Control-P
15 of 19 controls with lawDevelop and implement appropriate activities to enable organizations or individuals to manage data with sufficient granularity to manage privacy risks.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| CT.PO-PData Processing Policies, Processes, and Procedures: Policies, processes, and procedures are maintained and used to manage data processing (e.g., purpose, scope, roles and responsibilities in the data processing ecosystem, and management commitment) consistent with the organization’s risk strategy to protect individuals’ privacy. | ||||||
| CT.PO-P1 | Policies, processes, and procedures for authorizing data processing (e.g., organizational decisions, individual consent), revoking authorizations, and maintaining authorizations are established and in place. 515 laws, 39 not yet in force, 9 proposed | 515 | 210 | 39 | 9 | |
| CT.PO-P2 | Policies, processes, and procedures for enabling data review, transfer, sharing or disclosure, alteration, and deletion are established and in place (e.g., to maintain data quality, manage data retention). 204 laws, 16 not yet in force, 4 proposed | 204 | 165 | 16 | 4 | |
| CT.PO-P3 | Policies, processes, and procedures for enabling individuals’ data processing preferences and requests are established and in place. 282 laws, 23 not yet in force, 5 proposed | 282 | 185 | 23 | 5 | |
| CT.PO-P4 | A data life cycle to manage data is aligned and implemented with the system development life cycle to manage systems. no law we track | no law we track | ||||
| CT.DM-PData Processing Management: Data are managed consistent with the organization’s risk strategy to protect individuals’ privacy, increase manageability, and enable the implementation of privacy principles (e.g., individual participation, data quality, data minimization). | ||||||
| CT.DM-P1 | Data elements can be accessed for review. 61 laws, 7 not yet in force | 61 | 58 | 7 | 0 | |
| CT.DM-P2 | Data elements can be accessed for transmission or disclosure. 19 laws, 2 proposed | 19 | 19 | 0 | 2 | |
| CT.DM-P3 | Data elements can be accessed for alteration. 18 laws, 4 not yet in force | 18 | 18 | 4 | 0 | |
| CT.DM-P4 | Data elements can be accessed for deletion. 21 laws, 2 not yet in force, 1 proposed | 21 | 21 | 2 | 1 | |
| CT.DM-P5 | Data are destroyed according to policy. 34 laws, 3 not yet in force | 34 | 33 | 3 | 0 | |
| CT.DM-P6 | Data are transmitted using standardized formats. 2 laws | 2 | 2 | 0 | 0 | |
| CT.DM-P7 | Mechanisms for transmitting processing permissions and related data values with data elements are established and in place. no law we track | no law we track | ||||
| CT.DM-P8 | Audit/log records are determined, documented, implemented, and reviewed in accordance with policy and incorporating the principle of data minimization. 9 laws | 9 | 9 | 0 | 0 | |
| CT.DM-P9 | Technical measures implemented to manage data processing are tested and assessed. 1 law | 1 | 1 | 0 | 0 | |
| CT.DM-P10 | Stakeholder privacy preferences are included in algorithmic design objectives and outputs are evaluated against these preferences. 70 laws, 5 not yet in force, 3 proposed | 70 | 68 | 5 | 3 | |
| CT.DP-PDisassociated Processing: Data processing solutions increase disassociability consistent with the organization’s risk strategy to protect individuals’ privacy and enable implementation of privacy principles (e.g., data minimization). | ||||||
| CT.DP-P1 | Data are processed to limit observability and linkability (e.g., data actions take place on local devices, privacy-preserving cryptography). 4 laws | 4 | 4 | 0 | 0 | |
| CT.DP-P2 | Data are processed to limit the identification of individuals (e.g., de-identification privacy techniques, tokenization). 7 laws | 7 | 7 | 0 | 0 | |
| CT.DP-P3 | Data are processed to limit the formulation of inferences about individuals’ behavior or activities (e.g., data processing is decentralized, distributed architectures). no law we track | no law we track | ||||
| CT.DP-P4 | System or device configurations permit selective collection or disclosure of data elements. 4 laws | 4 | 4 | 0 | 0 | |
| CT.DP-P5 | Attribute references are substituted for attribute values. no law we track | no law we track | ||||
Communicate-P
7 of 10 controls with lawDevelop and implement appropriate activities to enable organizations and individuals to have a reliable understanding and engage in a dialogue about how data are processed and associated privacy risks.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| CM.PO-PCommunication Policies, Processes, and Procedures: Policies, processes, and procedures are maintained and used to increase transparency of the organization’s data processing practices (e.g., purpose, scope, roles and responsibilities in the data processing ecosystem, and management commitment) and associated privacy risks. | ||||||
| CM.PO-P1 | Transparency policies, processes, and procedures for communicating data processing purposes, practices, and associated privacy risks are established and in place. 2 laws | 2 | 2 | 0 | 0 | |
| CM.PO-P2 | Roles and responsibilities (e.g., public relations) for communicating data processing purposes, practices, and associated privacy risks are established. no law we track | no law we track | ||||
| CM.AW-PData Processing Awareness: Individuals and organizations have reliable knowledge about data processing practices and associated privacy risks, and effective mechanisms are used and maintained to increase predictability consistent with the organization’s risk strategy to protect individuals’ privacy. | ||||||
| CM.AW-P1 | Mechanisms (e.g., notices, internal or public reports) for communicating data processing purposes, practices, associated privacy risks, and options for enabling individuals’ data processing preferences and requests are established and in place. 189 laws, 13 not yet in force, 5 proposed | 189 | 120 | 13 | 5 | |
| CM.AW-P2 | Mechanisms for obtaining feedback from individuals (e.g., surveys or focus groups) about data processing and associated privacy risks are established and in place. no law we track | no law we track | ||||
| CM.AW-P3 | System/product/service design enables data processing visibility. 10 laws, 2 not yet in force | 10 | 10 | 2 | 0 | |
| CM.AW-P4 | Records of data disclosures and sharing are maintained and can be accessed for review or transmission/disclosure. 10 laws, 2 not yet in force | 10 | 10 | 2 | 0 | |
| CM.AW-P5 | Data corrections or deletions can be communicated to individuals or organizations (e.g., data sources) in the data processing ecosystem. 50 laws, 5 not yet in force | 50 | 46 | 5 | 0 | |
| CM.AW-P6 | Data provenance and lineage are maintained and can be accessed for review or transmission/disclosure. no law we track | no law we track | ||||
| CM.AW-P7 | Impacted individuals and organizations are notified about a privacy breach or event. 185 laws, 37 not yet in force, 4 proposed | 185 | 176 | 37 | 4 | |
| CM.AW-P8 | Individuals are provided with mitigation mechanisms (e.g., credit monitoring, consent withdrawal, data alteration or deletion) to address impacts of problematic data actions. 2 laws, 1 not yet in force | 2 | 2 | 1 | 0 | |
Protect-P
13 of 30 controls with lawDevelop and implement appropriate data processing safeguards.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| PR.PO-PData Protection Policies, Processes, and Procedures: Security and privacy policies (e.g., purpose, scope, roles and responsibilities in the data processing ecosystem, and management commitment), processes, and procedures are maintained and used to manage the protection of data. | ||||||
| PR.PO-P1 | A baseline configuration of information technology is created and maintained incorporating security principles (e.g., concept of least functionality). no law we track | no law we track | ||||
| PR.PO-P2 | Configuration change control processes are established and in place. no law we track | no law we track | ||||
| PR.PO-P3 | Backups of information are conducted, maintained, and tested. 3 laws | 3 | 3 | 0 | 0 | |
| PR.PO-P4 | Policy and regulations regarding the physical operating environment for organizational assets are met. no law we track | no law we track | ||||
| PR.PO-P5 | Protection processes are improved. 1 law | 1 | 1 | 0 | 0 | |
| PR.PO-P6 | Effectiveness of protection technologies is shared. no law we track | no law we track | ||||
| PR.PO-P7 | Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are established, in place, and managed. 31 laws, 4 not yet in force, 1 proposed | 31 | 29 | 4 | 1 | |
| PR.PO-P8 | Response and recovery plans are tested. no law we track | no law we track | ||||
| PR.PO-P9 | Privacy procedures are included in human resources practices (e.g., deprovisioning, personnel screening). 14 laws, 1 not yet in force, 1 proposed | 14 | 14 | 1 | 1 | |
| PR.PO-P10 | A vulnerability management plan is developed and implemented. no law we track | no law we track | ||||
| PR.AC-PIdentity Management, Authentication, and Access Control: Access to data and devices is limited to authorized individuals, processes, and devices, and is managed consistent with the assessed risk of unauthorized access. | ||||||
| PR.AC-P1 | Identities and credentials are issued, managed, verified, revoked, and audited for authorized individuals, processes, and devices. no law we track | no law we track | ||||
| PR.AC-P2 | Physical access to data and devices is managed. 4 laws | 4 | 4 | 0 | 0 | |
| PR.AC-P3 | Remote access is managed. no law we track | no law we track | ||||
| PR.AC-P4 | Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties. 20 laws, 1 not yet in force | 20 | 18 | 1 | 0 | |
| PR.AC-P5 | Network integrity is protected (e.g., network segregation, network segmentation). no law we track | no law we track | ||||
| PR.AC-P6 | Individuals and devices are proofed and bound to credentials, and authenticated commensurate with the risk of the transaction (e.g., individuals’ security and privacy risks and other organizational risks). 1 law | 1 | 1 | 0 | 0 | |
| PR.DS-PData Security: Data are managed consistent with the organization’s risk strategy to protect individuals’ privacy and maintain data confidentiality, integrity, and availability. | ||||||
| PR.DS-P1 | Data-at-rest are protected. 8 laws | 8 | 8 | 0 | 0 | |
| PR.DS-P2 | Data-in-transit are protected. 6 laws | 6 | 6 | 0 | 0 | |
| PR.DS-P3 | Systems/products/services and associated data are formally managed throughout removal, transfers, and disposition. 1 law, 1 not yet in force | 1 | 1 | 1 | 0 | |
| PR.DS-P4 | Adequate capacity to ensure availability is maintained. no law we track | no law we track | ||||
| PR.DS-P5 | Protections against data leaks are implemented. 94 laws, 7 not yet in force, 3 proposed | 94 | 78 | 7 | 3 | |
| PR.DS-P6 | Integrity checking mechanisms are used to verify software, firmware, and information integrity. no law we track | no law we track | ||||
| PR.DS-P7 | The development and testing environment(s) are separate from the production environment. no law we track | no law we track | ||||
| PR.DS-P8 | Integrity checking mechanisms are used to verify hardware integrity. no law we track | no law we track | ||||
| PR.MA-PMaintenance: System maintenance and repairs are performed consistent with policies, processes, and procedures. | ||||||
| PR.MA-P1 | Maintenance and repair of organizational assets are performed and logged, with approved and controlled tools. no law we track | no law we track | ||||
| PR.MA-P2 | Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access. no law we track | no law we track | ||||
| PR.PT-PProtective Technology: Technical security solutions are managed to ensure the security and resilience of systems/products/services and associated data, consistent with related policies, processes, procedures, and agreements. | ||||||
| PR.PT-P1 | Removable media is protected and its use restricted according to policy. 1 law | 1 | 1 | 0 | 0 | |
| PR.PT-P2 | The principle of least functionality is incorporated by configuring systems to provide only essential capabilities. no law we track | no law we track | ||||
| PR.PT-P3 | Communications and control networks are protected. 1 law | 1 | 1 | 0 | 0 | |
| PR.PT-P4 | Mechanisms (e.g., failsafe, load balancing, hot swap) are implemented to achieve resilience requirements in normal and adverse situations. no law we track | no law we track | ||||
Privacy duties with no home in the NIST Privacy Framework
2 lines in 2 lawsEach line below was read against the Privacy Framework and recorded as having no control to sit under.
Data subject rights 1
| Place | Law | The duty, as read |
|---|---|---|
| Constitución de la República de Honduras, garantía de Hábeas Data | Do not affect the confidentiality of journalistic sources. |
Enforcement supervision 1
| Place | Law | The duty, as read |
|---|---|---|
| CNMI Consumer Protection Act, general applicability | Do not misrepresent the sponsorship, approval, characteristics, or affiliation of your product, service, or automated system to a Commonwealth consumer, including a chatbot or AI agent that could be mistaken for a human representative. |
Communications duties with no home in the NIST Privacy Framework
53 lines in 35 lawsEach line below was read against the Privacy Framework and recorded as having no control to sit under.
Telephone contact 22
| Place | Law | The duty, as read |
|---|---|---|
| Telecommunications (Telemarketing and Research Calls) Industry Standard 2017 | For a research or opinion-polling call, keep to the same calling times except that a weekday call may run until 8.30pm and a Sunday call is permitted from 9am to 5pm; the public-holiday bar still applies. |
|
| Automatic Dialing-Announcing Devices Act | Do not operate an automatic dialing-announcing device to place a call received in California between 9 p.m. and 9 a.m. California time. Before connecting an automatic dialing-announcing device to a telephone line, file a written application with the telephone corporation serving that line, which may deny or modify the application if the proposed calling pattern would create a traffic overload or harm its other customers. |
|
| Delaware Telemarketing Fraud Act | Before the initial sales call ends and before requesting payment, disclose the total price, any restrictions or conditions on the purchase, material aspects of the merchandise's performance, and the refund, cancellation or exchange policy, plus the specific disclosures this chapter requires for a prize promotion or an investment offer. Treat a telemarketing sale as final only 7 business days after the customer receives a written cancellation notice, in at least 12-point bold type and in the language of the sales presentation, unless you give a full refund or satisfaction guarantee with at least 7 days to review the goods or services and disclose that policy and a return address. +1 more |
|
| Florida Telemarketing Act | Do not place a commercial telephone solicitation phone call, including one made through automated dialing or a recorded message, before 8 a.m. or after 8 p.m. local time in the called person's time zone. Do not make more than three commercial telephone solicitation phone calls to a person over a 24-hour period on the same subject matter or issue, from any number. |
|
| Illinois Automatic Telephone Dialers Act | Do not operate an autodialer, a device that stores telephone numbers and dials them sequentially or randomly to connect a call with a recorded sales message, to place a call between 9 p.m. and 9 a.m., or to call an emergency telephone number. |
|
| Illinois Telephone Solicitations Act | Do not solicit a sale by a telephone call between 9 p.m. and 8 a.m., or call an emergency telephone number. Do not obtain or submit for payment a check, draft, or other negotiable paper drawn on a person's account or bond without that person's express written consent. |
|
| Maryland prerecorded-message dialing and caller number blocking rules | Disconnect the prerecorded message machine from the recipient's line within 5 seconds after either party ends the call. |
|
| Home Solicitation Sales Act, Telephone Solicitation Rules (as amended effective 2003) | Before taking payment, disclose clearly and conspicuously the total price, any restrictions or conditions, the material terms of your refund, cancellation or exchange policy (or that you have none), prize terms and odds, material investment risks, and the quantity and characteristics of the goods or services; do not charge a consumer before receiving an express verifiable authorization (written, recorded oral, or confirmed by an independent third party). Do not offer a prize promotion that requires a purchase or payment, and do not leave a voicemail or answering-machine message falsely claiming a current business matter or relationship and asking the consumer to call back. |
|
| Telephone Companies as Common Carriers Act, Recorded Commercial Advertising and Caller Identification (section 25 as amended effective 1999) | Make authorized recorded commercial advertising end, or free the subscriber's line for incoming and outgoing calls, immediately when the subscriber hangs up. |
|
| Nevada Deceptive Trade Practice Rules for Telephone and Text Solicitations | During a telephone or text-message solicitation or a sales presentation, do not use threatening, intimidating, profane or obscene language, and do not repeatedly or continuously conduct it in a manner a reasonable person would consider annoying, abusive or harassing. Do not knowingly cause a caller-identification service for voice or text messages to display inaccurate or misleading information in order to defraud, wrongfully obtain something of value from, or otherwise harm a person. |
Show the other 12 laws
| New Hampshire Automatic Telephone Dialing Systems and Caller Identification Services Act | Generate the system's calls randomly at unequal intervals and keep them off every emergency line. |
|
| Anti-Caller ID Spoofing Act | Do not knowingly insert false caller identification information into a caller identification system with the intent to mislead, defraud, or deceive the recipient of a telephone call; inserting the true name or number of the person on whose behalf an authorized call is placed is not false information. |
|
| Commercial telephone seller registration and unlawful telemarketing practices | Allow a purchaser in a telephone sales transaction to cancel the purchase within three business days of receiving the goods, services, or property, disclose that cancellation right to the purchaser during the call, and refund all payments within thirty days of a valid cancellation. |
|
| Telephone Solicitation Act of 2022 | Do not alter a caller's voice to disguise the caller's identity in order to defraud, confuse or injure the recipient, or to obtain personal information for fraudulent or unlawful use. |
|
| Oregon Automatic Dialing and Announcing Device Statute (as amended by 2025 Or. Laws ch. 580, effective January 1, 2026) | Do not misrepresent or falsify your identity, the identity of a person you represent, your telephone number, your location, or the purpose of the call when speaking with the subscriber or in the prerecorded, synthesized-voice or text message a device disseminates. Whether or not you use such a device, do not intentionally alter, misrepresent or falsify the information a caller identification service would ordinarily provide to the called subscriber. +1 more |
|
| Oregon Unlawful Telephone Solicitations Act (as amended by 2025 Or. Laws ch. 580, effective January 1, 2026) | Do not misrepresent or falsify your own identity, the identity of a person you are calling on behalf of, or the purpose of the telephone solicitation. |
|
| Telephone Solicitation Business Registration Act | Do not require a credit card or checking account number as a condition of receiving an item you represent as free. |
|
| Telemarketing Sales Rule | Do not abandon more than 3% of answered outbound calls in a calling campaign measured over 30 days, where a call is abandoned if not connected to a sales representative within two seconds of the called person's completed greeting. |
|
| Telephone Consumer Protection Act, National Do Not Call Registry and Company-Specific List | Do not initiate a telephone solicitation to a residential subscriber before 8 a.m. or after 9 p.m. local time at the called party's location. |
|
| Truth in Caller ID Act | Do not cause a caller identification service to knowingly transmit misleading or inaccurate caller identification information on a voice call or text message, with the intent to defraud, cause harm, or wrongfully obtain anything of value; this does not restrict blocking your own caller ID. |
|
| Virginia Automatic Dialing-Announcing Devices Act | Design and operate an automatic dialing-announcing device, or any other device playing a prerecorded or synthesized voice message, to disconnect, disengage or terminate the call within five seconds after the called party ends it. |
|
| Telephone Solicitation Act | Do not place a telephone solicitation call that will be received before 8 a.m. or after 8 p.m. local time at the called party's location. |
Commercial messages 12
| Place | Law | The duty, as read |
|---|---|---|
| Unsolicited Commercial Email Advertisements, False or Misleading Header Information | Do not advertise in a commercial email sent from California, or sent to a California email address, that contains or is accompanied by a third party's domain name used without permission, falsified, misrepresented, or forged header information, or a subject line you know would likely mislead a recipient, acting reasonably, about a material fact regarding the message's contents. |
|
| Delaware Unrequested or Unauthorized Electronic Mail Statute | Do not use a computer or computer network without authority to falsify or forge electronic mail transmission information in connection with sending unsolicited bulk electronic mail, and do not sell, give, distribute, or possess with intent to distribute, software primarily designed, of only limited other significant use, or marketed for falsifying that information. |
|
| Florida Electronic Mail Communications Act | Do not initiate or assist in transmitting an unsolicited commercial email from a computer in Florida, or to an address held by a Florida resident, that uses a third party's Internet domain name without permission, carries falsified or missing routing information, a false or misleading subject line, or false or deceptive body content designed to damage the recipient's device; this does not apply to a message a computer virus sends or retransmits without the sender's knowledge or consent. Do not distribute software or another system designed to falsify or omit information identifying the point of origin or transmission path of a commercial email message. |
|
| Illinois Electronic Mail Act | Do not initiate, or cause to be initiated, an unsolicited commercial email (one to a recipient with whom you have no prior or existing business or personal relationship, sent without their request or express consent) that uses a third party's Internet domain name without permission, otherwise misrepresents its point of origin or transmission path, or contains false or misleading information in the subject line. Begin the subject line of every unsolicited commercial email with ADV:, or with ADV:ADLT where the message concerns goods, services or credit that only a person 18 or older may obtain. |
|
| Maryland Commercial Electronic Mail Act | Do not initiate, conspire to initiate, or assist in transmitting commercial email that is sent from a computer in Maryland, or to an address you know or should know is held by a Maryland resident (you are presumed to know where the registrant of the recipient's domain name makes that available on request), and that uses a third party's Internet domain name or email address without permission, carries false or misleading information about the message's origin or transmission path, or carries false or misleading information in the subject line that has the capacity, tendency, or effect of deceiving the recipient. |
|
| Unsolicited Commercial E-mail Protection Act | Do not use a third party's internet domain name or e-mail address in identifying the point of origin or transmission path of a commercial e-mail without that third party's consent, misrepresent that information, or fail to include the information necessary to identify the point of origin. Do not sell, give, distribute, or possess with intent to sell, give or distribute, software primarily designed, of only limited other commercially significant use, or marketed for falsifying commercial e-mail transmission or routing information. |
|
| Unsolicited commercial electronic mail labeling and opt-out | When sending a commercial electronic mail message, do not falsify the message's routing information or use a false or misleading subject line, and do not use a third party's internet address or domain name without that party's consent to make it appear the third party sent the message. |
|
| Unlawful Transmission of Electronic Mail | Do not use a computer or computer network without authority, and with the intent to falsify or forge electronic mail transmission information or other routing information, in connection with transmitting unsolicited electronic mail through or into the network of an email or Internet service provider or its subscribers; for this offense electronic mail includes a fax and a wireless advertisement. Do not sell, give, distribute, or possess with intent to distribute, software primarily designed or produced to enable falsification of electronic mail transmission or routing information, software with only limited other commercially significant use, or software marketed for that purpose. |
|
| Unsolicited Telecommunication Advertisement Act | Do not initiate, conspire to initiate, or assist the transmission of an unsolicited commercial email or fax from a computer or fax machine in Pennsylvania or to an email address that uses a third party's Internet domain name in the return address without permission, carries false or misleading return-address information that keeps the recipient from replying to you, or carries false or misleading information in the subject line. Do not falsify or forge email, fax or wireless-advertisement routing information, misrepresent or obscure a message's point of origin or transmission path, or sell or distribute software primarily designed to enable that falsification. |
|
| Regulation of Electronic Mail | Do not intentionally transmit an unsolicited commercial electronic mail message that falsifies its transmission or routing information, or any commercial electronic mail message with false, deceptive or misleading information in the subject line or that uses another person's Internet domain name without that person's consent. |
Show the other 2 laws
| Virginia Transmission of Unsolicited Commercial Electronic Mail Statute | Do not use a computer or computer network with intent to falsify or forge electronic mail transmission information or other routing information in connection with transmitting unsolicited commercial email (spam), and do not knowingly sell, give, distribute, or possess with intent to distribute software primarily designed, of limited other commercial use, or marketed to enable that falsification. |
|
| Commercial Electronic Mail Act, Email | Do not initiate, conspire to initiate, or assist in transmitting a commercial email message, from a Washington computer or to an address you know or have reason to know is a Washington resident's, that uses a third party's internet domain name without permission or otherwise misrepresents or obscures the message's point of origin or transmission path. Do not use a subject line that, based on your actual knowledge or knowledge fairly implied on the basis of objective circumstances, contains false or misleading information. |
Device storage and tracking consent 1
| Place | Law | The duty, as read |
|---|---|---|
| Consumer Protection Against Computer Spyware Act | Do not use deceptive means to modify the page a browser opens on launch, the default provider or proxy used to access or search the Internet, or the user's list of bookmarks; deception includes an intentionally and materially false or fraudulent statement, an intentional omission or misrepresentation of material information in order to deceive the user, and an intentional and material failure to give the user any notice of the download or installation of software in order to deceive. Without the user's authorization and through deceptive means, do not prevent the user's reasonable efforts to block or disable software by causing software the user has properly removed or disabled to reinstall or reactivate itself; do not misrepresent, knowing it to be untrue, that software will be uninstalled or disabled by the user's action; and do not use deceptive means to remove, disable or render inoperative security, antispyware or antivirus software installed on the computer. +2 more |
Where the law and the framework part
38 of the 100 controls have no law we track under them.
55 requirement lines were read as having no control in this framework to sit under; they are listed above.
The framework's text
Full text of the NIST Privacy Framework, public domain (a US government work).
Read it from the publisher: nvlpubs.nist.gov