Law / Frameworks / NIST Privacy Framework / Control-P

NIST Privacy Framework, Control-PCT.DM-P8

Audit/log records are determined, documented, implemented, and reviewed in accordance with policy and incorporating the principle of data minimization.NIST Privacy Framework, version 1.0, January 2020, CT.DM-P8

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

9
laws
9
places
0
with court rulings behind them
0
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

  • Algeria
  • China
  • Delaware
  • Lebanon
  • Morocco
  • Rwanda
  • Sao Tome and Principe
  • Tunisia
  • United States

Comprehensive regime

4 laws, 4 places
PlaceLawWhat it asks, as read here
Algeria Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11

Keep a written or electronic record of your processing activities and an automated log of processing operations, and make each available to the ANPDP on request.

Lebanon Law No. 81/2018 on Electronic Transactions and Personal Data, Part V (Personal Data Protection)

As a network service provider or data host, keep the traffic data of everyone using your service, the data that identifies them and the other technical data of their communications for three years from the service delivery date, keep it under professional secrecy, and produce it to the judicial police or the court when the competent judicial authority so decides.

As a data host, store for ten years the identification data of a non-professional who makes information available online to the public anonymously.

Rwanda Law relating to the Protection of Personal Data and Privacy

Log every collection, alteration, access, disclosure, combination and erasure of personal data, and maintain a record of all processing activities, producing both to the supervisory authority on request.

Tunisia Organic Act on the Protection of Personal Data

Take all necessary precautions to secure personal data against unauthorized modification, alteration or consultation, including physical access controls, a log of who accessed the system and when, and secure backup copies.

Sensitive categories

2 laws, 2 places
PlaceLawWhat it asks, as read here
Morocco Law No. 09-08, sensitive personal data and offense records

Where you process sensitive or health data, put in place the heightened technical measures Article 24 lists: control who can enter the processing facility, who can read, copy, modify, or remove the data media, and who can access, transmit, or input the data, and keep a record of what sensitive data was input, when, and by whom.

Sao Tome and Principe Lei n.º 03/2016, sensitive categories and suspect records

Put in place the special safety measures the Law requires for sensitive or credit data: control of premises entry, data-carrier handling, unauthorized disclosure, system access, transmission, and data-entry logging, and keep health and sex-life data logically separated from other personal data.

Telephone contact

2 laws, 2 places
PlaceLawWhat it asks, as read here
Delaware Delaware Telemarketing Fraud Act

Keep your advertising and scripts, prize-recipient records, customer and sales records, telemarketing employee records, and payment authorizations for 24 months.

United States Telemarketing Sales Rule

Keep telemarketing records, including scripts, prerecorded messages, and call logs, for five years.

Data subject rights

1 law, 1 place
PlaceLawWhat it asks, as read here
China Personal Information Protection Law, automated decisions

Complete a personal-information-protection impact assessment before deploying automated decision-making, and keep the assessment report and the processing record for at least three years.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.