Law / Frameworks / NIST Privacy Framework / Control-P

NIST Privacy Framework, Control-PCT.DP-P1

Data are processed to limit observability and linkability (e.g., data actions take place on local devices, privacy-preserving cryptography).NIST Privacy Framework, version 1.0, January 2020, CT.DP-P1

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

4
laws
4
places
0
with court rulings behind them
0
not yet in force
  • Chad
  • China
  • Monaco
  • New Zealand

Sensitive categories

2 laws, 2 places
PlaceLawWhat it asks, as read here
Chad Loi n°007/PR/2015, traitement des catégories particulières de données (données sensibles et biométriques)

Where processing genetic data or data revealing health-related secrets, use a unique patient identifier distinct from other identification numbers, and interconnect it with another identifying number only with ANSICE's express authorization.

Monaco Loi sur la Protection des Données Personnelles, données sensibles et mineurs

As an administrative or judicial authority acting in the exercise of your public powers, do not process genetic or biometric data for authentication or identity control without first obtaining the Authority's opinion, and store the raw biometric data separately from any template derived from it.

Do not interconnect data from the judicial criminal record with any other file or processing operation.

Biometric privacy

1 law, 1 place
PlaceLawWhat it asks, as read here
China Provisions on Security Management of Facial Recognition Technology Application

Store captured facial information only on the recognition device itself; do not transmit it over the internet unless a legal exception applies or the individual has separately consented.

Comprehensive regime

1 law, 1 place
PlaceLawWhat it asks, as read here
New Zealand Privacy Act 2020, Information Privacy Principles and Extraterritorial Reach

Do not assign a unique identifier to an individual unless it is necessary to carry out your organisation's functions efficiently, and do not assign the same identifier already assigned by another agency except in limited circumstances.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.