Law / Frameworks / NIST Privacy Framework

NIST Privacy Framework

Below are its 100 controls in the framework's own order, and under each one the laws we track that bear on it. Each mapping is our reading that a law bears on a control, never a finding that running the control meets the law.

Where the law lands in the framework

62of 100 controls have law1,212laws234places

ID.IM-P1: no law we trackID.IM-P2: 1 law in 1 placeID.IM-P3: no law we trackID.IM-P4: 33 laws in 30 placesID.IM-P5: 1 law in 1 placeID.IM-P6: 5 laws in 5 placesID.IM-P7: 16 laws in 15 placesID.IM-P8: no law we trackID.BE-P1: 3 laws in 3 placesID.BE-P2: no law we trackID.BE-P3: no law we trackID.RA-P1: no law we trackID.RA-P2: 1 law in 1 placeID.RA-P3: 6 laws in 6 placesID.RA-P4: 44 laws in 41 placesID.RA-P5: 10 laws in 10 placesID.DE-P1: no law we trackID.DE-P2: 22 laws in 20 placesID.DE-P3: 54 laws in 47 placesID.DE-P4: no law we trackID.DE-P5: 4 laws in 4 placesGV.PO-P1: 81 laws in 79 placesGV.PO-P2: 26 laws in 25 placesGV.PO-P3: 51 laws in 50 placesGV.PO-P4: 9 laws in 9 placesGV.PO-P5: 184 laws in 110 placesGV.PO-P6: no law we trackGV.RM-P1: 1 law in 1 placeGV.RM-P2: no law we trackGV.RM-P3: no law we trackGV.AT-P1: 7 laws in 7 placesGV.AT-P2: no law we trackGV.AT-P3: 1 law in 1 placeGV.AT-P4: no law we trackGV.MT-P1: 1 law in 1 placeGV.MT-P2: no law we trackGV.MT-P3: 11 laws in 10 placesGV.MT-P4: 7 laws in 6 placesGV.MT-P5: 3 laws in 3 placesGV.MT-P6: 1 law in 1 placeGV.MT-P7: 28 laws in 28 placesCT.PO-P1: 515 laws in 210 placesCT.PO-P1 515CT.PO-P2: 204 laws in 165 placesCT.PO-P2 204CT.PO-P3: 282 laws in 185 placesCT.PO-P3 282CT.PO-P4: no law we trackCT.DM-P1: 61 laws in 58 placesCT.DM-P2: 19 laws in 19 placesCT.DM-P3: 18 laws in 18 placesCT.DM-P4: 21 laws in 21 placesCT.DM-P5: 34 laws in 33 placesCT.DM-P6: 2 laws in 2 placesCT.DM-P7: no law we trackCT.DM-P8: 9 laws in 9 placesCT.DM-P9: 1 law in 1 placeCT.DM-P10: 70 laws in 68 placesCT.DP-P1: 4 laws in 4 placesCT.DP-P2: 7 laws in 7 placesCT.DP-P3: no law we trackCT.DP-P4: 4 laws in 4 placesCT.DP-P5: no law we trackCM.PO-P1: 2 laws in 2 placesCM.PO-P2: no law we trackCM.AW-P1: 189 laws in 120 placesCM.AW-P2: no law we trackCM.AW-P3: 10 laws in 10 placesCM.AW-P4: 10 laws in 10 placesCM.AW-P5: 50 laws in 46 placesCM.AW-P6: no law we trackCM.AW-P7: 185 laws in 176 placesCM.AW-P8: 2 laws in 2 placesPR.PO-P1: no law we trackPR.PO-P2: no law we trackPR.PO-P3: 3 laws in 3 placesPR.PO-P4: no law we trackPR.PO-P5: 1 law in 1 placePR.PO-P6: no law we trackPR.PO-P7: 31 laws in 29 placesPR.PO-P8: no law we trackPR.PO-P9: 14 laws in 14 placesPR.PO-P10: no law we trackPR.AC-P1: no law we trackPR.AC-P2: 4 laws in 4 placesPR.AC-P3: no law we trackPR.AC-P4: 20 laws in 18 placesPR.AC-P5: no law we trackPR.AC-P6: 1 law in 1 placePR.DS-P1: 8 laws in 8 placesPR.DS-P2: 6 laws in 6 placesPR.DS-P3: 1 law in 1 placePR.DS-P4: no law we trackPR.DS-P5: 94 laws in 78 placesPR.DS-P6: no law we trackPR.DS-P7: no law we trackPR.DS-P8: no law we trackPR.MA-P1: no law we trackPR.MA-P2: no law we trackPR.PT-P1: 1 law in 1 placePR.PT-P2: no law we trackPR.PT-P3: 1 law in 1 placePR.PT-P4: no law we trackIMBERADEPORMATMTPODMDPPOAWPOACDSMAPTID-PGV-PCT-PCM-PPR-P

Of these laws, 1,069 are in force, 118 not yet in force, and 25 proposed and not law.

17 of the 30 controls under Protect-P have no law we track under them.

  • in force
  • not yet in force
  • blocked by a court
  • proposed
  • no law we track
A bar's height is its number of laws. Select one to open the control.

Each requirement line of the privacy and communications laws we track was read on its own and mapped to the control it bears on most closely, and to a second or third only where the line has more than one limb.

Identify-P

13 of 21 controls with law

Develop the organizational understanding to manage privacy risk for individuals arising from data processing.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
ID.IM-PInventory and Mapping: Data processing by systems, products, or services is understood and informs the management of privacy risk.
ID.IM-P1 Systems/products/services that process data are inventoried. no law we track no law we track
ID.IM-P2 Owners or operators (e.g., the organization or third parties such as service providers, partners, customers, and developers) and their roles with respect to the systems/products/services and components (e.g., internal or external) that process data are inventoried. 1 law 1 1 0 0
ID.IM-P3 Categories of individuals (e.g., customers, employees or prospective employees, consumers) whose data are being processed are inventoried. no law we track no law we track
ID.IM-P4 Data actions of the systems/products/services are inventoried. 33 laws, 4 not yet in force, 2 proposed 33 30 4 2
ID.IM-P5 The purposes for the data actions are inventoried. 1 law 1 1 0 0
ID.IM-P6 Data elements within the data actions are inventoried. 5 laws, 1 not yet in force 5 5 1 0
ID.IM-P7 The data processing environment is identified (e.g., geographic location, internal, cloud, third parties). 16 laws, 1 not yet in force 16 15 1 0
ID.IM-P8 Data processing is mapped, illustrating the data actions and associated data elements for systems/products/services, including components; roles of the component owners/operators; and interactions of individuals or third parties with the systems/products/services. no law we track no law we track
ID.BE-PBusiness Environment: The organization’s mission, objectives, stakeholders, and activities are understood and prioritized; this information is used to inform privacy roles, responsibilities, and risk management decisions.
ID.BE-P1 The organization’s role(s) in the data processing ecosystem are identified and communicated. 3 laws 3 3 0 0
ID.BE-P2 Priorities for organizational mission, objectives, and activities are established and communicated. no law we track no law we track
ID.BE-P3 Systems/products/services that support organizational priorities are identified and key requirements communicated. no law we track no law we track
ID.RA-PRisk Assessment: The organization understands the privacy risks to individuals and how such privacy risks may create follow-on impacts on organizational operations, including mission, functions, other risk management priorities (e.g., compliance, financial), reputation, workforce, and culture.
ID.RA-P1 Contextual factors related to the systems/products/services and the data actions are identified (e.g., individuals’ demographics and privacy interests or perceptions, data sensitivity and/or types, visibility of data processing to individuals and third parties). no law we track no law we track
ID.RA-P2 Data analytic inputs and outputs are identified and evaluated for bias. 1 law 1 1 0 0
ID.RA-P3 Potential problematic data actions and associated problems are identified. 6 laws 6 6 0 0
ID.RA-P4 Problematic data actions, likelihoods, and impacts are used to determine and prioritize risk. 44 laws, 4 not yet in force, 2 proposed 44 41 4 2
ID.RA-P5 Risk responses are identified, prioritized, and implemented. 10 laws, 1 not yet in force, 1 proposed 10 10 1 1
ID.DE-PData Processing Ecosystem Risk Management: The organization’s priorities, constraints, risk tolerance, and assumptions are established and used to support risk decisions associated with managing privacy risk and third parties within the data processing ecosystem. The organization has established and implemented the processes to identify, assess, and manage privacy risks within the data processing ecosystem.
ID.DE-P1 Data processing ecosystem risk management policies, processes, and procedures are identified, established, assessed, managed, and agreed to by organizational stakeholders. no law we track no law we track
ID.DE-P2 Data processing ecosystem parties (e.g., service providers, customers, partners, product manufacturers, application developers) are identified, prioritized, and assessed using a privacy risk assessment process. 22 laws, 6 not yet in force 22 20 6 0
ID.DE-P3 Contracts with data processing ecosystem parties are used to implement appropriate measures designed to meet the objectives of an organization’s privacy program. 54 laws, 4 not yet in force, 1 proposed 54 47 4 1
ID.DE-P4 Interoperability frameworks or similar multi-party approaches are used to manage data processing ecosystem privacy risks. no law we track no law we track
ID.DE-P5 Data processing ecosystem parties are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their contractual, interoperability framework, or other obligations. 4 laws 4 4 0 0

Govern-P

14 of 20 controls with law

Develop and implement the organizational governance structure to enable an ongoing understanding of the organization’s risk management priorities that are informed by privacy risk.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
GV.PO-PGovernance Policies, Processes, and Procedures: The policies, processes, and procedures to manage and monitor the organization’s regulatory, legal, risk, environmental, and operational requirements are understood and inform the management of privacy risk.
GV.PO-P1 Organizational privacy values and policies (e.g., conditions on data processing such as data uses or retention periods, individuals’ prerogatives with respect to data processing) are established and communicated. 81 laws, 4 not yet in force, 5 proposed 81 79 4 5
GV.PO-P2 Processes to instill organizational privacy values within system/product/service development and operations are established and in place. 26 laws, 2 not yet in force, 3 proposed 26 25 2 3
GV.PO-P3 Roles and responsibilities for the workforce are established with respect to privacy. 51 laws, 3 not yet in force, 3 proposed 51 50 3 3
GV.PO-P4 Privacy roles and responsibilities are coordinated and aligned with third-party stakeholders (e.g., service providers, customers, partners). 9 laws, 1 not yet in force 9 9 1 0
GV.PO-P5 Legal, regulatory, and contractual requirements regarding privacy are understood and managed. 184 laws, 13 not yet in force, 3 proposed 184 110 13 3
GV.PO-P6 Governance and risk management policies, processes, and procedures address privacy risks. no law we track no law we track
GV.RM-PRisk Management Strategy: The organization’s priorities, constraints, risk tolerances, and assumptions are established and used to support operational risk decisions.
GV.RM-P1 Risk management processes are established, managed, and agreed to by organizational stakeholders. 1 law 1 1 0 0
GV.RM-P2 Organizational risk tolerance is determined and clearly expressed. no law we track no law we track
GV.RM-P3 The organization’s determination of risk tolerance is informed by its role(s) in the data processing ecosystem. no law we track no law we track
GV.AT-PAwareness and Training: The organization’s workforce and third parties engaged in data processing are provided privacy awareness education and are trained to perform their privacy-related duties and responsibilities consistent with related policies, processes, procedures, and agreements and organizational privacy values.
GV.AT-P1 The workforce is informed and trained on its roles and responsibilities. 7 laws 7 7 0 0
GV.AT-P2 Senior executives understand their roles and responsibilities. no law we track no law we track
GV.AT-P3 Privacy personnel understand their roles and responsibilities. 1 law 1 1 0 0
GV.AT-P4 Third parties (e.g., service providers, customers, partners) understand their roles and responsibilities. no law we track no law we track
GV.MT-PMonitoring and Review: The policies, processes, and procedures for ongoing review of the organization’s privacy posture are understood and inform the management of privacy risk.
GV.MT-P1 Privacy risk is re-evaluated on an ongoing basis and as key factors, including the organization’s business environment (e.g., introduction of new technologies), governance (e.g., legal obligations, risk tolerance), data processing, and systems/products/services change. 1 law 1 1 0 0
GV.MT-P2 Privacy values, policies, and training are reviewed and any updates are communicated. no law we track no law we track
GV.MT-P3 Policies, processes, and procedures for assessing compliance with legal requirements and privacy policies are established and in place. 11 laws, 2 not yet in force, 1 proposed 11 10 2 1
GV.MT-P4 Policies, processes, and procedures for communicating progress on managing privacy risks are established and in place. 7 laws, 1 not yet in force 7 6 1 0
GV.MT-P5 Policies, processes, and procedures are established and in place to receive, analyze, and respond to problematic data actions disclosed to the organization from internal and external sources (e.g., internal discovery, privacy researchers, professional events). 3 laws, 2 not yet in force, 1 proposed 3 3 2 1
GV.MT-P6 Policies, processes, and procedures incorporate lessons learned from problematic data actions. 1 law 1 1 0 0
GV.MT-P7 Policies, processes, and procedures for receiving, tracking, and responding to complaints, concerns, and questions from individuals about organizational privacy practices are established and in place. 28 laws, 1 not yet in force, 1 proposed 28 28 1 1

Control-P

15 of 19 controls with law

Develop and implement appropriate activities to enable organizations or individuals to manage data with sufficient granularity to manage privacy risks.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
CT.PO-PData Processing Policies, Processes, and Procedures: Policies, processes, and procedures are maintained and used to manage data processing (e.g., purpose, scope, roles and responsibilities in the data processing ecosystem, and management commitment) consistent with the organization’s risk strategy to protect individuals’ privacy.
CT.PO-P1 Policies, processes, and procedures for authorizing data processing (e.g., organizational decisions, individual consent), revoking authorizations, and maintaining authorizations are established and in place. 515 laws, 39 not yet in force, 9 proposed 515 210 39 9
CT.PO-P2 Policies, processes, and procedures for enabling data review, transfer, sharing or disclosure, alteration, and deletion are established and in place (e.g., to maintain data quality, manage data retention). 204 laws, 16 not yet in force, 4 proposed 204 165 16 4
CT.PO-P3 Policies, processes, and procedures for enabling individuals’ data processing preferences and requests are established and in place. 282 laws, 23 not yet in force, 5 proposed 282 185 23 5
CT.PO-P4 A data life cycle to manage data is aligned and implemented with the system development life cycle to manage systems. no law we track no law we track
CT.DM-PData Processing Management: Data are managed consistent with the organization’s risk strategy to protect individuals’ privacy, increase manageability, and enable the implementation of privacy principles (e.g., individual participation, data quality, data minimization).
CT.DM-P1 Data elements can be accessed for review. 61 laws, 7 not yet in force 61 58 7 0
CT.DM-P2 Data elements can be accessed for transmission or disclosure. 19 laws, 2 proposed 19 19 0 2
CT.DM-P3 Data elements can be accessed for alteration. 18 laws, 4 not yet in force 18 18 4 0
CT.DM-P4 Data elements can be accessed for deletion. 21 laws, 2 not yet in force, 1 proposed 21 21 2 1
CT.DM-P5 Data are destroyed according to policy. 34 laws, 3 not yet in force 34 33 3 0
CT.DM-P6 Data are transmitted using standardized formats. 2 laws 2 2 0 0
CT.DM-P7 Mechanisms for transmitting processing permissions and related data values with data elements are established and in place. no law we track no law we track
CT.DM-P8 Audit/log records are determined, documented, implemented, and reviewed in accordance with policy and incorporating the principle of data minimization. 9 laws 9 9 0 0
CT.DM-P9 Technical measures implemented to manage data processing are tested and assessed. 1 law 1 1 0 0
CT.DM-P10 Stakeholder privacy preferences are included in algorithmic design objectives and outputs are evaluated against these preferences. 70 laws, 5 not yet in force, 3 proposed 70 68 5 3
CT.DP-PDisassociated Processing: Data processing solutions increase disassociability consistent with the organization’s risk strategy to protect individuals’ privacy and enable implementation of privacy principles (e.g., data minimization).
CT.DP-P1 Data are processed to limit observability and linkability (e.g., data actions take place on local devices, privacy-preserving cryptography). 4 laws 4 4 0 0
CT.DP-P2 Data are processed to limit the identification of individuals (e.g., de-identification privacy techniques, tokenization). 7 laws 7 7 0 0
CT.DP-P3 Data are processed to limit the formulation of inferences about individuals’ behavior or activities (e.g., data processing is decentralized, distributed architectures). no law we track no law we track
CT.DP-P4 System or device configurations permit selective collection or disclosure of data elements. 4 laws 4 4 0 0
CT.DP-P5 Attribute references are substituted for attribute values. no law we track no law we track

Communicate-P

7 of 10 controls with law

Develop and implement appropriate activities to enable organizations and individuals to have a reliable understanding and engage in a dialogue about how data are processed and associated privacy risks.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
CM.PO-PCommunication Policies, Processes, and Procedures: Policies, processes, and procedures are maintained and used to increase transparency of the organization’s data processing practices (e.g., purpose, scope, roles and responsibilities in the data processing ecosystem, and management commitment) and associated privacy risks.
CM.PO-P1 Transparency policies, processes, and procedures for communicating data processing purposes, practices, and associated privacy risks are established and in place. 2 laws 2 2 0 0
CM.PO-P2 Roles and responsibilities (e.g., public relations) for communicating data processing purposes, practices, and associated privacy risks are established. no law we track no law we track
CM.AW-PData Processing Awareness: Individuals and organizations have reliable knowledge about data processing practices and associated privacy risks, and effective mechanisms are used and maintained to increase predictability consistent with the organization’s risk strategy to protect individuals’ privacy.
CM.AW-P1 Mechanisms (e.g., notices, internal or public reports) for communicating data processing purposes, practices, associated privacy risks, and options for enabling individuals’ data processing preferences and requests are established and in place. 189 laws, 13 not yet in force, 5 proposed 189 120 13 5
CM.AW-P2 Mechanisms for obtaining feedback from individuals (e.g., surveys or focus groups) about data processing and associated privacy risks are established and in place. no law we track no law we track
CM.AW-P3 System/product/service design enables data processing visibility. 10 laws, 2 not yet in force 10 10 2 0
CM.AW-P4 Records of data disclosures and sharing are maintained and can be accessed for review or transmission/disclosure. 10 laws, 2 not yet in force 10 10 2 0
CM.AW-P5 Data corrections or deletions can be communicated to individuals or organizations (e.g., data sources) in the data processing ecosystem. 50 laws, 5 not yet in force 50 46 5 0
CM.AW-P6 Data provenance and lineage are maintained and can be accessed for review or transmission/disclosure. no law we track no law we track
CM.AW-P7 Impacted individuals and organizations are notified about a privacy breach or event. 185 laws, 37 not yet in force, 4 proposed 185 176 37 4
CM.AW-P8 Individuals are provided with mitigation mechanisms (e.g., credit monitoring, consent withdrawal, data alteration or deletion) to address impacts of problematic data actions. 2 laws, 1 not yet in force 2 2 1 0

Protect-P

13 of 30 controls with law

Develop and implement appropriate data processing safeguards.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
PR.PO-PData Protection Policies, Processes, and Procedures: Security and privacy policies (e.g., purpose, scope, roles and responsibilities in the data processing ecosystem, and management commitment), processes, and procedures are maintained and used to manage the protection of data.
PR.PO-P1 A baseline configuration of information technology is created and maintained incorporating security principles (e.g., concept of least functionality). no law we track no law we track
PR.PO-P2 Configuration change control processes are established and in place. no law we track no law we track
PR.PO-P3 Backups of information are conducted, maintained, and tested. 3 laws 3 3 0 0
PR.PO-P4 Policy and regulations regarding the physical operating environment for organizational assets are met. no law we track no law we track
PR.PO-P5 Protection processes are improved. 1 law 1 1 0 0
PR.PO-P6 Effectiveness of protection technologies is shared. no law we track no law we track
PR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are established, in place, and managed. 31 laws, 4 not yet in force, 1 proposed 31 29 4 1
PR.PO-P8 Response and recovery plans are tested. no law we track no law we track
PR.PO-P9 Privacy procedures are included in human resources practices (e.g., deprovisioning, personnel screening). 14 laws, 1 not yet in force, 1 proposed 14 14 1 1
PR.PO-P10 A vulnerability management plan is developed and implemented. no law we track no law we track
PR.AC-PIdentity Management, Authentication, and Access Control: Access to data and devices is limited to authorized individuals, processes, and devices, and is managed consistent with the assessed risk of unauthorized access.
PR.AC-P1 Identities and credentials are issued, managed, verified, revoked, and audited for authorized individuals, processes, and devices. no law we track no law we track
PR.AC-P2 Physical access to data and devices is managed. 4 laws 4 4 0 0
PR.AC-P3 Remote access is managed. no law we track no law we track
PR.AC-P4 Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties. 20 laws, 1 not yet in force 20 18 1 0
PR.AC-P5 Network integrity is protected (e.g., network segregation, network segmentation). no law we track no law we track
PR.AC-P6 Individuals and devices are proofed and bound to credentials, and authenticated commensurate with the risk of the transaction (e.g., individuals’ security and privacy risks and other organizational risks). 1 law 1 1 0 0
PR.DS-PData Security: Data are managed consistent with the organization’s risk strategy to protect individuals’ privacy and maintain data confidentiality, integrity, and availability.
PR.DS-P1 Data-at-rest are protected. 8 laws 8 8 0 0
PR.DS-P2 Data-in-transit are protected. 6 laws 6 6 0 0
PR.DS-P3 Systems/products/services and associated data are formally managed throughout removal, transfers, and disposition. 1 law, 1 not yet in force 1 1 1 0
PR.DS-P4 Adequate capacity to ensure availability is maintained. no law we track no law we track
PR.DS-P5 Protections against data leaks are implemented. 94 laws, 7 not yet in force, 3 proposed 94 78 7 3
PR.DS-P6 Integrity checking mechanisms are used to verify software, firmware, and information integrity. no law we track no law we track
PR.DS-P7 The development and testing environment(s) are separate from the production environment. no law we track no law we track
PR.DS-P8 Integrity checking mechanisms are used to verify hardware integrity. no law we track no law we track
PR.MA-PMaintenance: System maintenance and repairs are performed consistent with policies, processes, and procedures.
PR.MA-P1 Maintenance and repair of organizational assets are performed and logged, with approved and controlled tools. no law we track no law we track
PR.MA-P2 Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access. no law we track no law we track
PR.PT-PProtective Technology: Technical security solutions are managed to ensure the security and resilience of systems/products/services and associated data, consistent with related policies, processes, procedures, and agreements.
PR.PT-P1 Removable media is protected and its use restricted according to policy. 1 law 1 1 0 0
PR.PT-P2 The principle of least functionality is incorporated by configuring systems to provide only essential capabilities. no law we track no law we track
PR.PT-P3 Communications and control networks are protected. 1 law 1 1 0 0
PR.PT-P4 Mechanisms (e.g., failsafe, load balancing, hot swap) are implemented to achieve resilience requirements in normal and adverse situations. no law we track no law we track

Privacy duties with no home in the NIST Privacy Framework

2 lines in 2 laws

Each line below was read against the Privacy Framework and recorded as having no control to sit under.

Data subject rights 1

PlaceLawThe duty, as read
Honduras Constitución de la República de Honduras, garantía de Hábeas Data

Do not affect the confidentiality of journalistic sources.

Enforcement supervision 1

PlaceLawThe duty, as read
Northern Mariana Islands CNMI Consumer Protection Act, general applicability

Do not misrepresent the sponsorship, approval, characteristics, or affiliation of your product, service, or automated system to a Commonwealth consumer, including a chatbot or AI agent that could be mistaken for a human representative.

Communications duties with no home in the NIST Privacy Framework

53 lines in 35 laws

Each line below was read against the Privacy Framework and recorded as having no control to sit under.

Telephone contact 22

PlaceLawThe duty, as read
Australia Telecommunications (Telemarketing and Research Calls) Industry Standard 2017

For a research or opinion-polling call, keep to the same calling times except that a weekday call may run until 8.30pm and a Sunday call is permitted from 9am to 5pm; the public-holiday bar still applies.

California Automatic Dialing-Announcing Devices Act

Do not operate an automatic dialing-announcing device to place a call received in California between 9 p.m. and 9 a.m. California time.

Before connecting an automatic dialing-announcing device to a telephone line, file a written application with the telephone corporation serving that line, which may deny or modify the application if the proposed calling pattern would create a traffic overload or harm its other customers.

Delaware Delaware Telemarketing Fraud Act

Before the initial sales call ends and before requesting payment, disclose the total price, any restrictions or conditions on the purchase, material aspects of the merchandise's performance, and the refund, cancellation or exchange policy, plus the specific disclosures this chapter requires for a prize promotion or an investment offer.

Treat a telemarketing sale as final only 7 business days after the customer receives a written cancellation notice, in at least 12-point bold type and in the language of the sales presentation, unless you give a full refund or satisfaction guarantee with at least 7 days to review the goods or services and disclose that policy and a return address.

+1 more
Florida Florida Telemarketing Act

Do not place a commercial telephone solicitation phone call, including one made through automated dialing or a recorded message, before 8 a.m. or after 8 p.m. local time in the called person's time zone.

Do not make more than three commercial telephone solicitation phone calls to a person over a 24-hour period on the same subject matter or issue, from any number.

Illinois Illinois Automatic Telephone Dialers Act

Do not operate an autodialer, a device that stores telephone numbers and dials them sequentially or randomly to connect a call with a recorded sales message, to place a call between 9 p.m. and 9 a.m., or to call an emergency telephone number.

Illinois Illinois Telephone Solicitations Act

Do not solicit a sale by a telephone call between 9 p.m. and 8 a.m., or call an emergency telephone number.

Do not obtain or submit for payment a check, draft, or other negotiable paper drawn on a person's account or bond without that person's express written consent.

Maryland Maryland prerecorded-message dialing and caller number blocking rules

Disconnect the prerecorded message machine from the recipient's line within 5 seconds after either party ends the call.

Michigan Home Solicitation Sales Act, Telephone Solicitation Rules (as amended effective 2003)

Before taking payment, disclose clearly and conspicuously the total price, any restrictions or conditions, the material terms of your refund, cancellation or exchange policy (or that you have none), prize terms and odds, material investment risks, and the quantity and characteristics of the goods or services; do not charge a consumer before receiving an express verifiable authorization (written, recorded oral, or confirmed by an independent third party).

Do not offer a prize promotion that requires a purchase or payment, and do not leave a voicemail or answering-machine message falsely claiming a current business matter or relationship and asking the consumer to call back.

Michigan Telephone Companies as Common Carriers Act, Recorded Commercial Advertising and Caller Identification (section 25 as amended effective 1999)

Make authorized recorded commercial advertising end, or free the subscriber's line for incoming and outgoing calls, immediately when the subscriber hangs up.

Nevada Nevada Deceptive Trade Practice Rules for Telephone and Text Solicitations

During a telephone or text-message solicitation or a sales presentation, do not use threatening, intimidating, profane or obscene language, and do not repeatedly or continuously conduct it in a manner a reasonable person would consider annoying, abusive or harassing.

Do not knowingly cause a caller-identification service for voice or text messages to display inaccurate or misleading information in order to defraud, wrongfully obtain something of value from, or otherwise harm a person.

Show the other 12 laws
New Hampshire New Hampshire Automatic Telephone Dialing Systems and Caller Identification Services Act

Generate the system's calls randomly at unequal intervals and keep them off every emergency line.

Oklahoma Anti-Caller ID Spoofing Act

Do not knowingly insert false caller identification information into a caller identification system with the intent to mislead, defraud, or deceive the recipient of a telephone call; inserting the true name or number of the person on whose behalf an authorized call is placed is not false information.

Oklahoma Commercial telephone seller registration and unlawful telemarketing practices

Allow a purchaser in a telephone sales transaction to cancel the purchase within three business days of receiving the goods, services, or property, disclose that cancellation right to the purchaser during the call, and refund all payments within thirty days of a valid cancellation.

Oklahoma Telephone Solicitation Act of 2022

Do not alter a caller's voice to disguise the caller's identity in order to defraud, confuse or injure the recipient, or to obtain personal information for fraudulent or unlawful use.

Oregon Oregon Automatic Dialing and Announcing Device Statute (as amended by 2025 Or. Laws ch. 580, effective January 1, 2026)

Do not misrepresent or falsify your identity, the identity of a person you represent, your telephone number, your location, or the purpose of the call when speaking with the subscriber or in the prerecorded, synthesized-voice or text message a device disseminates.

Whether or not you use such a device, do not intentionally alter, misrepresent or falsify the information a caller identification service would ordinarily provide to the called subscriber.

+1 more
Oregon Oregon Unlawful Telephone Solicitations Act (as amended by 2025 Or. Laws ch. 580, effective January 1, 2026)

Do not misrepresent or falsify your own identity, the identity of a person you are calling on behalf of, or the purpose of the telephone solicitation.

Texas Telephone Solicitation Business Registration Act

Do not require a credit card or checking account number as a condition of receiving an item you represent as free.

United States Telemarketing Sales Rule

Do not abandon more than 3% of answered outbound calls in a calling campaign measured over 30 days, where a call is abandoned if not connected to a sales representative within two seconds of the called person's completed greeting.

United States Telephone Consumer Protection Act, National Do Not Call Registry and Company-Specific List

Do not initiate a telephone solicitation to a residential subscriber before 8 a.m. or after 9 p.m. local time at the called party's location.

United States Truth in Caller ID Act

Do not cause a caller identification service to knowingly transmit misleading or inaccurate caller identification information on a voice call or text message, with the intent to defraud, cause harm, or wrongfully obtain anything of value; this does not restrict blocking your own caller ID.

Virginia Virginia Automatic Dialing-Announcing Devices Act

Design and operate an automatic dialing-announcing device, or any other device playing a prerecorded or synthesized voice message, to disconnect, disengage or terminate the call within five seconds after the called party ends it.

Washington Telephone Solicitation Act

Do not place a telephone solicitation call that will be received before 8 a.m. or after 8 p.m. local time at the called party's location.

Commercial messages 12

PlaceLawThe duty, as read
California Unsolicited Commercial Email Advertisements, False or Misleading Header Information

Do not advertise in a commercial email sent from California, or sent to a California email address, that contains or is accompanied by a third party's domain name used without permission, falsified, misrepresented, or forged header information, or a subject line you know would likely mislead a recipient, acting reasonably, about a material fact regarding the message's contents.

Delaware Delaware Unrequested or Unauthorized Electronic Mail Statute

Do not use a computer or computer network without authority to falsify or forge electronic mail transmission information in connection with sending unsolicited bulk electronic mail, and do not sell, give, distribute, or possess with intent to distribute, software primarily designed, of only limited other significant use, or marketed for falsifying that information.

Florida Florida Electronic Mail Communications Act

Do not initiate or assist in transmitting an unsolicited commercial email from a computer in Florida, or to an address held by a Florida resident, that uses a third party's Internet domain name without permission, carries falsified or missing routing information, a false or misleading subject line, or false or deceptive body content designed to damage the recipient's device; this does not apply to a message a computer virus sends or retransmits without the sender's knowledge or consent.

Do not distribute software or another system designed to falsify or omit information identifying the point of origin or transmission path of a commercial email message.

Illinois Illinois Electronic Mail Act

Do not initiate, or cause to be initiated, an unsolicited commercial email (one to a recipient with whom you have no prior or existing business or personal relationship, sent without their request or express consent) that uses a third party's Internet domain name without permission, otherwise misrepresents its point of origin or transmission path, or contains false or misleading information in the subject line.

Begin the subject line of every unsolicited commercial email with ADV:, or with ADV:ADLT where the message concerns goods, services or credit that only a person 18 or older may obtain.

Maryland Maryland Commercial Electronic Mail Act

Do not initiate, conspire to initiate, or assist in transmitting commercial email that is sent from a computer in Maryland, or to an address you know or should know is held by a Maryland resident (you are presumed to know where the registrant of the recipient's domain name makes that available on request), and that uses a third party's Internet domain name or email address without permission, carries false or misleading information about the message's origin or transmission path, or carries false or misleading information in the subject line that has the capacity, tendency, or effect of deceiving the recipient.

Michigan Unsolicited Commercial E-mail Protection Act

Do not use a third party's internet domain name or e-mail address in identifying the point of origin or transmission path of a commercial e-mail without that third party's consent, misrepresent that information, or fail to include the information necessary to identify the point of origin.

Do not sell, give, distribute, or possess with intent to sell, give or distribute, software primarily designed, of only limited other commercially significant use, or marketed for falsifying commercial e-mail transmission or routing information.

Oklahoma Unsolicited commercial electronic mail labeling and opt-out

When sending a commercial electronic mail message, do not falsify the message's routing information or use a false or misleading subject line, and do not use a third party's internet address or domain name without that party's consent to make it appear the third party sent the message.

Pennsylvania Unlawful Transmission of Electronic Mail

Do not use a computer or computer network without authority, and with the intent to falsify or forge electronic mail transmission information or other routing information, in connection with transmitting unsolicited electronic mail through or into the network of an email or Internet service provider or its subscribers; for this offense electronic mail includes a fax and a wireless advertisement.

Do not sell, give, distribute, or possess with intent to distribute, software primarily designed or produced to enable falsification of electronic mail transmission or routing information, software with only limited other commercially significant use, or software marketed for that purpose.

Pennsylvania Unsolicited Telecommunication Advertisement Act

Do not initiate, conspire to initiate, or assist the transmission of an unsolicited commercial email or fax from a computer or fax machine in Pennsylvania or to an email address that uses a third party's Internet domain name in the return address without permission, carries false or misleading return-address information that keeps the recipient from replying to you, or carries false or misleading information in the subject line.

Do not falsify or forge email, fax or wireless-advertisement routing information, misrepresent or obscure a message's point of origin or transmission path, or sell or distribute software primarily designed to enable that falsification.

Texas Regulation of Electronic Mail

Do not intentionally transmit an unsolicited commercial electronic mail message that falsifies its transmission or routing information, or any commercial electronic mail message with false, deceptive or misleading information in the subject line or that uses another person's Internet domain name without that person's consent.

Show the other 2 laws
Virginia Virginia Transmission of Unsolicited Commercial Electronic Mail Statute

Do not use a computer or computer network with intent to falsify or forge electronic mail transmission information or other routing information in connection with transmitting unsolicited commercial email (spam), and do not knowingly sell, give, distribute, or possess with intent to distribute software primarily designed, of limited other commercial use, or marketed to enable that falsification.

Washington Commercial Electronic Mail Act, Email

Do not initiate, conspire to initiate, or assist in transmitting a commercial email message, from a Washington computer or to an address you know or have reason to know is a Washington resident's, that uses a third party's internet domain name without permission or otherwise misrepresents or obscures the message's point of origin or transmission path.

Do not use a subject line that, based on your actual knowledge or knowledge fairly implied on the basis of objective circumstances, contains false or misleading information.

Device storage and tracking consent 1

PlaceLawThe duty, as read
Pennsylvania Consumer Protection Against Computer Spyware Act

Do not use deceptive means to modify the page a browser opens on launch, the default provider or proxy used to access or search the Internet, or the user's list of bookmarks; deception includes an intentionally and materially false or fraudulent statement, an intentional omission or misrepresentation of material information in order to deceive the user, and an intentional and material failure to give the user any notice of the download or installation of software in order to deceive.

Without the user's authorization and through deceptive means, do not prevent the user's reasonable efforts to block or disable software by causing software the user has properly removed or disabled to reinstall or reactivate itself; do not misrepresent, knowing it to be untrue, that software will be uninstalled or disabled by the user's action; and do not use deceptive means to remove, disable or render inoperative security, antispyware or antivirus software installed on the computer.

+2 more

Where the law and the framework part

38 of the 100 controls have no law we track under them.

55 requirement lines were read as having no control in this framework to sit under; they are listed above.

The framework's text

Full text of the NIST Privacy Framework, public domain (a US government work).

Read it from the publisher: nvlpubs.nist.gov