Law / Frameworks / NIST Privacy Framework / Control-P

NIST Privacy Framework, Control-PCT.DM-P5

Data are destroyed according to policy.NIST Privacy Framework, version 1.0, January 2020, CT.DM-P5

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

34
laws
33
places
1
with court rulings behind it
3
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • Antigua and Barbuda
  • Argentina
  • Azerbaijan
  • Belgium
  • Brazil
  • Cabo Verde
  • Cameroon
  • Egypt
  • Eswatini
  • Ethiopia
  • Illinois
  • Jordan
  • Lesotho
  • Mexico
  • Monaco
  • Montenegro
  • Nicaragua
  • North Macedonia
  • Pennsylvania
  • Peru
  • Russia
  • Rwanda
  • Saint Kitts and Nevis
  • Saint Lucia
  • Saudi Arabia
  • South Africa
  • South Dakota
  • Syria
  • Texas
  • Tonga
  • Tunisia
  • Uganda
  • Zambia

Comprehensive regime

21 laws, 21 places
PlaceLawWhat it asks, as read here
Antigua and Barbuda Data Protection Act, 2013

Do not keep personal data longer than necessary for the purpose it was collected for, and destroy or permanently delete it once that purpose has lapsed.

Argentina Ley 25.326, Ley de Protección de los Datos Personales

As a military, security, police, or intelligence body, limit consent-free processing of personal data for defense or public-security purposes to what your legally assigned mission strictly requires, keep the resulting files specific and classified by reliability, and cancel police-purpose data once it is no longer needed for the inquiry that justified it.

As a data-processing service provider acting for another party, use the personal data only for the purpose stated in the service contract, do not disclose it to others, and destroy it once the contracted service ends unless further engagements are reasonably expected, in which case you may keep it securely for up to two years.

+2 more
Brazil Lei Geral de Proteção de Dados Pessoais (LGPD)

Delete personal data once processing ends, unless retention is needed to comply with a legal or regulatory obligation, for research with anonymization where possible, for an authorized transfer, or for your own exclusive anonymized use.

Egypt Law No. 151 of 2020 Promulgating the Personal Data Protection Law

Delete Personal Data once the purpose it was collected for is satisfied, or hold it in a form that does not allow the Data Subject to be identified, and correct any error immediately on being told of it or becoming aware of it.

Eswatini Data Protection Act, 2022 (Act No. 5 of 2022)

Destroy, delete or de-identify a record of personal information as soon as reasonably practicable after you are no longer authorised to retain it, in a manner that prevents its reconstruction.

Ethiopia Personal Data Protection Proclamation

Destroy personal data as soon as is reasonably practicable once the purpose for storing it has lapsed, in a manner that prevents its reconstruction in an intelligible form, and tell any data processor holding the data to do the same.

Lesotho Data Protection Act, 2011 (Act No. 5 of 2012)

Destroy, delete or de-identify a record of personal information as soon as reasonably practicable after you are no longer authorised to retain it, in a manner that prevents its reconstruction.

Mexico Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP)

Delete personal data relating to a contractual default once seventy-two months have passed from the date the default occurred, and otherwise suppress personal data, after any blocking period, once it is no longer necessary for the purposes stated in the privacy notice.

Monaco Loi sur la Protection des Données Personnelles

Get the Minister of State's prior authorisation before installing a video surveillance system in a place open to the public or filming a public way, and do not keep recorded images for more than 30 days.

Montenegro Law on Personal Data Protection from a date not yet set

Where you run video surveillance of business or official premises, display a public notice of it, avoid recording residential interiors or apartment entrances, and store the recordings for no longer than one year, under Articles 35 to 40.

Show the other 11 laws
North Macedonia Law on Personal Data Protection (LPDP), video surveillance

Store video surveillance recordings for no longer than 30 days unless another law sets a longer period with its own safeguards, and remove, at your own expense, any camera installed contrary to this Law.

Peru Ley 29733, Ley de Protección de Datos Personales

As a processor handling personal data under contract for a third party, use it only for the purpose the contract states, do not transfer it to anyone else, and delete it once the contract is performed unless the data bank's owner authorized retaining it against a likely further engagement.

Rwanda Law relating to the Protection of Personal Data and Privacy

Retain personal data only until the purpose of processing is fulfilled unless a listed ground extends retention, and destroy it in a manner that prevents reconstruction once the retention period ends.

Saint Kitts and Nevis Data Protection Act, 2018 from a date not yet set

Do not keep personal data longer than the purpose requires, and take reasonable steps to destroy or permanently delete it once no longer needed.

Saint Lucia Data Protection Act

Destroy personal data as soon as reasonably practicable once the purpose for holding it has lapsed.

South Africa Protection of Personal Information Act 4 of 2013 (POPIA)

Do not retain a record of personal information longer than the purpose for which it was collected requires, and destroy, delete, or de-identify it as soon as reasonably practicable once you are no longer authorised to keep it.

Syria Law No. 12 of 2024 on Protection of Electronic Personal Data

Erase personal data once the purpose for holding it lapses, unless a lawful reason permits retention, in which case keep it in a form that no longer identifies the data subject.

Tonga Privacy Act 2025, comprehensive personal information protection regime from a date not yet set

Do not retain personal information longer than the purpose requires, and once retention is no longer necessary, return, destroy, render inaccessible or permanently de-identify it within a reasonable time.

Tunisia Organic Act on the Protection of Personal Data

Destroy personal data once its declared or authorized retention period expires, its purpose is achieved, or it is no longer useful to your activity, by a bailiff's report made with an INPDP-appointed expert.

Uganda Data Protection and Privacy Act, 2019, comprehensive personal-data regime

Retain personal data no longer than necessary for the purpose collected, and destroy, delete or de-identify it at the expiry of the retention period in a manner that prevents its reconstruction.

Zambia Data Protection Act, 2021, personal data processing framework

Tell a data subject of the right to withdraw consent before they give it, present the request separately from other matters in clear and plain language, be able to prove the consent was given, and destroy immediately every piece of personal data collected after a withdrawal.

Biometric privacy

4 laws, 4 places
PlaceLawWhat it asks, as read here
Azerbaijan Law on Personal Data, biometric data enumeration and general processing conditions

An app that captures or stores a facial image, voiceprint (sound fragment and its acoustic parameters in the Act's own term), or other biometric identifier from a person in Azerbaijan is still bound by this Act's ordinary processing conditions, a lawful basis under Art. 9.6 and destruction under Art. 9.4 once the purpose is achieved, even though Azerbaijan does not treat biometric data as a heightened special category and imposes no biometric-specific consent, retention, or storage-technology duty.

Illinois Biometric Information Privacy Act (BIPA)

Publish a written, publicly available policy establishing a retention schedule, and permanently destroy biometric identifiers and biometric information within 3 years of the individual's last interaction or when the collection purpose is satisfied, whichever occurs first.

Russia Federal Law No. 572-FZ, Unified Biometric System for Identification and Authentication

Obtain written consent before processing a person's biometric data in Russia, never condition service on that consent, and retain any biometric sample your organization holds only up to 10 days before deleting it, since the durable copy of record lives in the state system.

Texas Capture or Use of Biometric Identifier Act (CUBI), as amended by HB 149

Store and transmit a captured biometric identifier with reasonable care equal to or exceeding the protection given your other confidential information, and destroy it within a reasonable time, no later than the first anniversary of when the collection purpose expires.

Sensitive categories

4 laws, 4 places
PlaceLawWhat it asks, as read here
Belgium Act of 30 July 2018 Article 10/1, Recorded Commercial Communications

Inform both parties of a call or communication recording, its precise purposes, and its storage period before recording it for proof of a commercial transaction with a person in Belgium, and erase the data once the transaction can no longer be challenged in court.

Limit a call-centre quality-monitoring recording to a maximum one-month retention, with prior information to staff, under Act Article 10/1 paragraph 2.

Jordan Personal Data Protection Law, sensitive personal data and biometric data

An app that processes biometric data about an individual in Jordan, including a faceprint or voiceprint, must treat it as Sensitive Personal Data and obtain consent or rely on one of the Law's enumerated exceptions, and must not retain it beyond the processing purpose unless legislation specifies otherwise. Whether Jordan requires a heightened, explicit-consent standard specifically for biometric processing, beyond ordinary consent, is not confirmed.

Saudi Arabia Personal Data Protection Law, sensitive data and biometric processing

An app that derives a faceprint, voiceprint, or other identity-linked biometric identifier from an individual in Saudi Arabia, for any purpose the purpose-based Sensitive Data definition would reach, must obtain the Data Subject's explicit consent before processing it, and must destroy it once the processing purpose is fulfilled or consent is withdrawn.

South Dakota Genetic Data Privacy Act, definitions, consent, and consumer rights

Honor a consumer's revocation of consent and destroy their biological sample within 30 days.

Enforcement supervision

2 laws, 2 places
PlaceLawWhat it asks, as read here
Cabo Verde Law No. 133/V/2001 on the Protection of Personal Data, enforcement and supervision

Interrupt, cease or block processing once notified to do so, cooperate with a CNPD request, and destroy personal data once its retention period under article 6 has elapsed, on pain of the penalty for qualified non-compliance.

Cameroon Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, article 74 (atteinte à la vie privée et traitement illicite des données à caractère personnel)

Do not retain nominative or encrypted personal data beyond the legal duration stated in the request for opinion or prior declaration for the processing, and do not disclose nominative data in a way that harms the person it concerns.

Data subject rights

1 law, 1 place
PlaceLawWhat it asks, as read here
Nicaragua Ley No. 787, Ley de Protección de Datos Personales, rights of data subjects

On a data subject's request, suppress and cancel their personal data from a social network, browser, or server, and, once your contractual relationship with them ends, suppress and cancel the personal data you collected during it.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.