Law / Frameworks / NIST Privacy Framework / Communicate-P
NIST Privacy Framework, Communicate-PCM.PO-P1
Transparency policies, processes, and procedures for communicating data processing purposes, practices, and associated privacy risks are established and in place.NIST Privacy Framework, version 1.0, January 2020, CM.PO-P1
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 2
- laws
- 2
- places
- 0
- with court rulings behind them
- 0
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 4.2 Organizational teams document the risks and potential impacts of the AI technology...
- NIST AI RMFMAP 2.2 Information about the AI system’s knowledge limits and how system output may be...
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- NIST AI 600-1GAI-RISK-08 Information Integrity
- MIT mitigations4.1 System Documentation
- MIT mitigations4.2 Risk Disclosure
- NIST CSF 2.0RS.CO-02 Internal and external stakeholders are notified of incidents
- NIST CSF 2.0RC.CO-04 Public updates on incident recovery are shared using approved methods and messaging
Comprehensive regime
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Cyber and Data Protection Act [Chapter 12:07] |
Take the security measures section 18 requires, keep your processing open as section 23 requires, and be accountable for it as section 24 requires. |
Data subject rights
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Personal Information Protection Law, automated decisions |
Ensure transparency and non-discriminatory treatment in any automated decision made using personal information, and do not use it for unreasonable differential pricing. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.