Law / Frameworks / NIST Privacy Framework / Govern-P
NIST Privacy Framework, Govern-PGV.AT-P1
The workforce is informed and trained on its roles and responsibilities.NIST Privacy Framework, version 1.0, January 2020, GV.AT-P1
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 7
- laws
- 7
- places
- 0
- with court rulings behind them
- 0
- not yet in force
Comprehensive regime
5 laws, 5 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law of the Republic of Belarus On Personal Data Protection |
Take legal, organizational and technical measures against unauthorized or accidental access, modification, termination, copying, dissemination, transmission or erasure of personal data, appoint a data protection officer or a dedicated unit, publish your data processing policy, and train staff who handle personal data, under Article 17. |
|
| Digital Code, Title III: Personal Data Protection |
Implement technical and organizational measures against unauthorized or unlawful processing and against accidental loss, destruction or alteration, confine internal access to what each role requires, and train staff on their data protection duties. |
|
| Digital Code, comprehensive personal data regime |
An app that collects, uses, or discloses the personal data of individuals in Kyrgyzstan must process it lawfully, fairly, and transparently, limit use to the stated purpose, minimize what is collected, keep it accurate, and limit retention to the processing purpose. An organization with more than ten employees must designate a personal-data-responsible person and provide staff training. |
|
| Nigeria Data Protection Act, 2023 (NDPA), general data protection duties |
Follow schedules for monitoring, evaluating and maintaining the data security system, and for organisation-wide internal sensitisation and training on data privacy. |
|
| Data Protection Act |
Take security measures appropriate to the risk of unauthorized access, alteration, or loss of personal data, taking the state of technology and the cost of the measures into account, and make sure staff know and follow them. |
Sensitive categories
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Law relating to the Protection of Personal Data and Privacy, sensitive personal data and children's data |
When processing sensitive personal data, build the capacity of staff involved, control who can access it, and apply technical and organisational measures appropriate to the risk, including storing it separately and applying tokenisation, pseudonymisation or encryption where appropriate. |
Telephone contact
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Telephone Consumer Protection Act, National Do Not Call Registry and Company-Specific List |
Maintain your own written do-not-call policy, train personnel in it, and honor an individual's request not to be called by you again within a reasonable time not to exceed ten business days. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.