Law / Frameworks / NIST Privacy Framework / Communicate-P
NIST Privacy Framework, Communicate-PCM.AW-P4
Records of data disclosures and sharing are maintained and can be accessed for review or transmission/disclosure.NIST Privacy Framework, version 1.0, January 2020, CM.AW-P4
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 10
- laws
- 10
- places
- 0
- with court rulings behind them
- 2
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 4.2 Organizational teams document the risks and potential impacts of the AI technology...
- NIST AI RMFMAP 2.2 Information about the AI system’s knowledge limits and how system output may be...
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- NIST AI 600-1GAI-RISK-08 Information Integrity
- MIT mitigations4.1 System Documentation
- MIT mitigations4.2 Risk Disclosure
- NIST CSF 2.0RS.CO-02 Internal and external stakeholders are notified of incidents
- NIST CSF 2.0RC.CO-04 Public updates on incident recovery are shared using approved methods and messaging
A law in force is unmarked; the rest wear their state: not yet in force
Data subject rights
9 laws, 9 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law of the Republic of Belarus On Personal Data Protection, rights of the personal data subject |
Give a personal data subject, once a calendar year and free of charge, information about the transmission of their personal data to third parties, under Article 12. |
|
| LGPD, rights of the data subject |
Tell a data subject which public and private entities you shared their data with, let them object to processing carried out under a consent exemption where it violates this law, and let them revoke consent at any time through a free and easy procedure. |
|
| Law No. 06/L-082 on Protection of Personal Data, rights of the data subject |
Pass on any rectification, erasure or restriction to every recipient the data were disclosed to, unless that is impossible or disproportionately difficult, and tell the data subject who those recipients are on request. |
|
| Maryland Online Data Privacy Act (MODPA), consumer rights and appeal |
Give a Maryland consumer a means to confirm whether you process their personal data, access it, correct it, delete it, receive a portable copy, and obtain a list of third-party categories it was disclosed to. |
|
| Minnesota Consumer Data Privacy Act, consumer rights and profiling |
Provide a Minnesota consumer, on request, a list of the specific third parties you disclosed their personal data to, not merely categories of third parties. |
|
| Consumer Health Data, access, disclosure, and deletion rights from a date not yet set |
Give a Nevada consumer the right to access their consumer health data, obtain a list of third parties it was disclosed to, stop its collection, sharing, or sale, and delete it. |
|
| National Digital Identification Act 2024, registered persons' data-subject rights |
On a registered person's request, disclose what personal data has been accessed, when, by whom, the purpose, manner and duration of access, how long the data will be stored, and whether any profiling or automated decision-making process is being applied to it. |
|
| Vermont Data Privacy and Online Surveillance Act, consumer rights from , in 15 months |
Once in force, give a Vermont consumer access, correction, deletion, portability, opt-out of targeted advertising and sale, a profiling explanation and reevaluation right for housing decisions, and a list of third parties their data was sold to. |
|
| Data Protection Act, 2021, rights of the data subject |
Tell the data subject every third party their personal data has been disclosed to, and what safeguards are in place for it. |
Comprehensive regime
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Ley 81 de 2019, Sobre Protección de Datos Personales |
Maintain a registry of every database you disclose to third parties, covering its legal basis, its contents, who receives it, retention periods and everyone who accessed it, and produce that registry to ANTAI on request. Before disclosing personal data to a requester, identify the requester and the purpose, notify the data subject, and record how long the requester will hold the data and how it will be destroyed, unless the data subject has consented. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.