Law / Frameworks / NIST Privacy Framework / Control-P
NIST Privacy Framework, Control-PCT.DM-P5
Data are destroyed according to policy.NIST Privacy Framework, version 1.0, January 2020, CT.DM-P5
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 34
- laws
- 33
- places
- 1
- with court rulings behind it
- 3
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations3.2 Data Governance
- MIT mitigations4.1 System Documentation
- NIST CSF 2.0ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
- NIST CSF 2.0ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
A law in force is unmarked; the rest wear their state: not yet in force
Comprehensive regime
21 laws, 21 places| Place | Law | What it asks, as read here |
|---|---|---|
| Data Protection Act, 2013 |
Do not keep personal data longer than necessary for the purpose it was collected for, and destroy or permanently delete it once that purpose has lapsed. |
|
| Ley 25.326, Ley de Protección de los Datos Personales |
As a military, security, police, or intelligence body, limit consent-free processing of personal data for defense or public-security purposes to what your legally assigned mission strictly requires, keep the resulting files specific and classified by reliability, and cancel police-purpose data once it is no longer needed for the inquiry that justified it. As a data-processing service provider acting for another party, use the personal data only for the purpose stated in the service contract, do not disclose it to others, and destroy it once the contracted service ends unless further engagements are reasonably expected, in which case you may keep it securely for up to two years. +2 more |
|
| Lei Geral de Proteção de Dados Pessoais (LGPD) |
Delete personal data once processing ends, unless retention is needed to comply with a legal or regulatory obligation, for research with anonymization where possible, for an authorized transfer, or for your own exclusive anonymized use. |
|
| Law No. 151 of 2020 Promulgating the Personal Data Protection Law |
Delete Personal Data once the purpose it was collected for is satisfied, or hold it in a form that does not allow the Data Subject to be identified, and correct any error immediately on being told of it or becoming aware of it. |
|
| Data Protection Act, 2022 (Act No. 5 of 2022) |
Destroy, delete or de-identify a record of personal information as soon as reasonably practicable after you are no longer authorised to retain it, in a manner that prevents its reconstruction. |
|
| Personal Data Protection Proclamation |
Destroy personal data as soon as is reasonably practicable once the purpose for storing it has lapsed, in a manner that prevents its reconstruction in an intelligible form, and tell any data processor holding the data to do the same. |
|
| Data Protection Act, 2011 (Act No. 5 of 2012) |
Destroy, delete or de-identify a record of personal information as soon as reasonably practicable after you are no longer authorised to retain it, in a manner that prevents its reconstruction. |
|
| Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) |
Delete personal data relating to a contractual default once seventy-two months have passed from the date the default occurred, and otherwise suppress personal data, after any blocking period, once it is no longer necessary for the purposes stated in the privacy notice. |
|
| Loi sur la Protection des Données Personnelles |
Get the Minister of State's prior authorisation before installing a video surveillance system in a place open to the public or filming a public way, and do not keep recorded images for more than 30 days. |
|
| Law on Personal Data Protection from a date not yet set |
Where you run video surveillance of business or official premises, display a public notice of it, avoid recording residential interiors or apartment entrances, and store the recordings for no longer than one year, under Articles 35 to 40. |
Show the other 11 laws
| Law on Personal Data Protection (LPDP), video surveillance |
Store video surveillance recordings for no longer than 30 days unless another law sets a longer period with its own safeguards, and remove, at your own expense, any camera installed contrary to this Law. |
|
| Ley 29733, Ley de Protección de Datos Personales |
As a processor handling personal data under contract for a third party, use it only for the purpose the contract states, do not transfer it to anyone else, and delete it once the contract is performed unless the data bank's owner authorized retaining it against a likely further engagement. |
|
| Law relating to the Protection of Personal Data and Privacy |
Retain personal data only until the purpose of processing is fulfilled unless a listed ground extends retention, and destroy it in a manner that prevents reconstruction once the retention period ends. |
|
| Data Protection Act, 2018 from a date not yet set |
Do not keep personal data longer than the purpose requires, and take reasonable steps to destroy or permanently delete it once no longer needed. |
|
| Data Protection Act |
Destroy personal data as soon as reasonably practicable once the purpose for holding it has lapsed. |
|
| Protection of Personal Information Act 4 of 2013 (POPIA) |
Do not retain a record of personal information longer than the purpose for which it was collected requires, and destroy, delete, or de-identify it as soon as reasonably practicable once you are no longer authorised to keep it. |
|
| Law No. 12 of 2024 on Protection of Electronic Personal Data |
Erase personal data once the purpose for holding it lapses, unless a lawful reason permits retention, in which case keep it in a form that no longer identifies the data subject. |
|
| Privacy Act 2025, comprehensive personal information protection regime from a date not yet set |
Do not retain personal information longer than the purpose requires, and once retention is no longer necessary, return, destroy, render inaccessible or permanently de-identify it within a reasonable time. |
|
| Organic Act on the Protection of Personal Data |
Destroy personal data once its declared or authorized retention period expires, its purpose is achieved, or it is no longer useful to your activity, by a bailiff's report made with an INPDP-appointed expert. |
|
| Data Protection and Privacy Act, 2019, comprehensive personal-data regime |
Retain personal data no longer than necessary for the purpose collected, and destroy, delete or de-identify it at the expiry of the retention period in a manner that prevents its reconstruction. |
|
| Data Protection Act, 2021, personal data processing framework |
Tell a data subject of the right to withdraw consent before they give it, present the request separately from other matters in clear and plain language, be able to prove the consent was given, and destroy immediately every piece of personal data collected after a withdrawal. |
Biometric privacy
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law on Personal Data, biometric data enumeration and general processing conditions |
An app that captures or stores a facial image, voiceprint (sound fragment and its acoustic parameters in the Act's own term), or other biometric identifier from a person in Azerbaijan is still bound by this Act's ordinary processing conditions, a lawful basis under Art. 9.6 and destruction under Art. 9.4 once the purpose is achieved, even though Azerbaijan does not treat biometric data as a heightened special category and imposes no biometric-specific consent, retention, or storage-technology duty. |
|
| Biometric Information Privacy Act (BIPA) |
Publish a written, publicly available policy establishing a retention schedule, and permanently destroy biometric identifiers and biometric information within 3 years of the individual's last interaction or when the collection purpose is satisfied, whichever occurs first. |
|
| Federal Law No. 572-FZ, Unified Biometric System for Identification and Authentication |
Obtain written consent before processing a person's biometric data in Russia, never condition service on that consent, and retain any biometric sample your organization holds only up to 10 days before deleting it, since the durable copy of record lives in the state system. |
|
| Capture or Use of Biometric Identifier Act (CUBI), as amended by HB 149 |
Store and transmit a captured biometric identifier with reasonable care equal to or exceeding the protection given your other confidential information, and destroy it within a reasonable time, no later than the first anniversary of when the collection purpose expires. |
Sensitive categories
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Act of 30 July 2018 Article 10/1, Recorded Commercial Communications |
Inform both parties of a call or communication recording, its precise purposes, and its storage period before recording it for proof of a commercial transaction with a person in Belgium, and erase the data once the transaction can no longer be challenged in court. Limit a call-centre quality-monitoring recording to a maximum one-month retention, with prior information to staff, under Act Article 10/1 paragraph 2. |
|
| Personal Data Protection Law, sensitive personal data and biometric data |
An app that processes biometric data about an individual in Jordan, including a faceprint or voiceprint, must treat it as Sensitive Personal Data and obtain consent or rely on one of the Law's enumerated exceptions, and must not retain it beyond the processing purpose unless legislation specifies otherwise. Whether Jordan requires a heightened, explicit-consent standard specifically for biometric processing, beyond ordinary consent, is not confirmed. |
|
| Personal Data Protection Law, sensitive data and biometric processing |
An app that derives a faceprint, voiceprint, or other identity-linked biometric identifier from an individual in Saudi Arabia, for any purpose the purpose-based Sensitive Data definition would reach, must obtain the Data Subject's explicit consent before processing it, and must destroy it once the processing purpose is fulfilled or consent is withdrawn. |
|
| Genetic Data Privacy Act, definitions, consent, and consumer rights |
Honor a consumer's revocation of consent and destroy their biological sample within 30 days. |
Enforcement supervision
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 133/V/2001 on the Protection of Personal Data, enforcement and supervision |
Interrupt, cease or block processing once notified to do so, cooperate with a CNPD request, and destroy personal data once its retention period under article 6 has elapsed, on pain of the penalty for qualified non-compliance. |
|
| Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, article 74 (atteinte à la vie privée et traitement illicite des données à caractère personnel) |
Do not retain nominative or encrypted personal data beyond the legal duration stated in the request for opinion or prior declaration for the processing, and do not disclose nominative data in a way that harms the person it concerns. |
Interception and recording consent
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Illinois Eavesdropping Article, Interception and Civil Remedies (720 ILCS 5/14-2 as rewritten by Public Act 98-1142) |
If your business monitors or records employees' marketing, opinion research or telephone solicitation calls (including order-taking, customer assistance and credit collection calls) under the one-party exemption, use it only for service quality control, training or internal research, never furnish or divulge the recordings to law enforcement or any third party, stop and destroy any recording of an unrelated call, give employees notice including prominent workplace signage, and provide personal-only lines that are not monitored. |
|
| Wiretapping and Electronic Surveillance Control Act, Interception, Consent Exception and Civil Action |
If you record telephone marketing or customer service communications for training, quality control or monitoring, have one party's consent, use the recordings only for training or quality control, and destroy them within one year unless federal or State law requires otherwise. |
Data subject rights
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Ley No. 787, Ley de Protección de Datos Personales, rights of data subjects |
On a data subject's request, suppress and cancel their personal data from a social network, browser, or server, and, once your contractual relationship with them ends, suppress and cancel the personal data you collected during it. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.