Law / Frameworks / NIST Privacy Framework / Control-P
NIST Privacy Framework, Control-PCT.DM-P8
Audit/log records are determined, documented, implemented, and reviewed in accordance with policy and incorporating the principle of data minimization.NIST Privacy Framework, version 1.0, January 2020, CT.DM-P8
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 9
- laws
- 9
- places
- 0
- with court rulings behind them
- 0
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.4 The risk management process and its outcomes are established through transparent...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations4.1 System Documentation
- MIT mitigations1.1 Board Structure & Oversight
- NIST CSF 2.0ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
- NIST CSF 2.0PR.PS-04 Log records are generated and made available for continuous monitoring
Comprehensive regime
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11 |
Keep a written or electronic record of your processing activities and an automated log of processing operations, and make each available to the ANPDP on request. |
|
| Law No. 81/2018 on Electronic Transactions and Personal Data, Part V (Personal Data Protection) |
As a network service provider or data host, keep the traffic data of everyone using your service, the data that identifies them and the other technical data of their communications for three years from the service delivery date, keep it under professional secrecy, and produce it to the judicial police or the court when the competent judicial authority so decides. As a data host, store for ten years the identification data of a non-professional who makes information available online to the public anonymously. |
|
| Law relating to the Protection of Personal Data and Privacy |
Log every collection, alteration, access, disclosure, combination and erasure of personal data, and maintain a record of all processing activities, producing both to the supervisory authority on request. |
|
| Organic Act on the Protection of Personal Data |
Take all necessary precautions to secure personal data against unauthorized modification, alteration or consultation, including physical access controls, a log of who accessed the system and when, and secure backup copies. |
Sensitive categories
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 09-08, sensitive personal data and offense records |
Where you process sensitive or health data, put in place the heightened technical measures Article 24 lists: control who can enter the processing facility, who can read, copy, modify, or remove the data media, and who can access, transmit, or input the data, and keep a record of what sensitive data was input, when, and by whom. |
|
| Lei n.º 03/2016, sensitive categories and suspect records |
Put in place the special safety measures the Law requires for sensitive or credit data: control of premises entry, data-carrier handling, unauthorized disclosure, system access, transmission, and data-entry logging, and keep health and sex-life data logically separated from other personal data. |
Telephone contact
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Delaware Telemarketing Fraud Act |
Keep your advertising and scripts, prize-recipient records, customer and sales records, telemarketing employee records, and payment authorizations for 24 months. |
|
| Telemarketing Sales Rule |
Keep telemarketing records, including scripts, prerecorded messages, and call logs, for five years. |
Data subject rights
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Personal Information Protection Law, automated decisions |
Complete a personal-information-protection impact assessment before deploying automated decision-making, and keep the assessment report and the processing record for at least three years. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.