Law / Frameworks / NIST Privacy Framework / Control-P

NIST Privacy Framework, Control-PCT.DP-P2

Data are processed to limit the identification of individuals (e.g., de-identification privacy techniques, tokenization).NIST Privacy Framework, version 1.0, January 2020, CT.DP-P2

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

7
laws
7
places
0
with court rulings behind them
0
not yet in force
  • Argentina
  • Brazil
  • Burkina Faso
  • Colombia
  • Niger
  • North Macedonia
  • United States

Comprehensive regime

4 laws, 4 places
PlaceLawWhat it asks, as read here
Argentina Ley 25.326, Ley de Protección de los Datos Personales

Treat opinion-poll, market-research, or scientific-research data as outside this Act only while it cannot be attributed to an identifiable person, and apply a dissociation technique where anonymity cannot otherwise be kept during collection.

Burkina Faso Loi n°001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel

Obtain the CIL's authorization, given after the Health Research Ethics Committee's concurring opinion, before processing personal data for health research, anonymize the data before transmission wherever the research's purpose allows it, and host any health data that still permits identification on national territory.

Colombia Superintendencia Circular on AI and Personal Data

Apply privacy by design and by default, including techniques such as differential privacy, so that data used to train an artificial intelligence system does not allow the person who provided it to be identified.

North Macedonia Law on Personal Data Protection (LPDP)

Apply appropriate safeguards, such as pseudonymisation or data minimisation, when processing personal data for archiving in the public interest, or for scientific, historical or statistical purposes.

Sensitive categories

3 laws, 3 places
PlaceLawWhat it asks, as read here
Brazil LGPD, sensitive personal data and children's data

Give a public-health research body access to personal data only within a controlled and secure environment, anonymized or pseudonymized where possible, and never transfer that data to a third party.

Niger Loi n° 2022-59, données sensibles, de santé et biométriques

Limit the exchange of health data between health professionals to what coordination or continuity of care strictly requires, and anonymize health data before sharing it or publishing research drawn from it.

United States HIPAA Privacy Rule

Strip biometric identifiers, including voiceprints and full-face photographic images, before treating health data as de-identified.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.