Law / Frameworks / NIST Privacy Framework / Govern-P
NIST Privacy Framework, Govern-PGV.MT-P3
Policies, processes, and procedures for assessing compliance with legal requirements and privacy policies are established and in place.NIST Privacy Framework, version 1.0, January 2020, GV.MT-P3
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 11
- laws
- 10
- places
- 0
- with court rulings behind them
- 2
- not yet in force
- 1
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.4 The risk management process and its outcomes are established through transparent...
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations1.1 Board Structure & Oversight
- MIT mitigations1.2 Risk Management
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and...
A law in force is unmarked; the rest wear their state: not yet in force proposed
Comprehensive regime
6 laws, 6 places| Place | Law | What it asks, as read here |
|---|---|---|
| CCPA Cybersecurity Audit Regulations |
If your business meets the CCPA's business-scale thresholds, deriving 50 percent or more of annual revenue from selling or sharing personal information, or having more than $25 million in annual gross revenue and having processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers, in the preceding calendar year, complete a cybersecurity audit. Complete that audit using a qualified, objective, independent auditor, who may be internal or external to the business, and who did not develop, implement, or maintain the cybersecurity program being audited. +2 more |
|
| Data Protection Act, No. 1 of 2023 from a date not yet set |
Establish formal procedures implementing these principles, and review them, with a self-assessment, at least once every five years. |
|
| Personal Data Protection Act 2025, government personal-data protection principles |
Be able to demonstrate compliance with these principles on request of the competent authority, the Economic Policy, Planning and Statistics Office. |
|
| Nigeria Data Protection Act, 2023 (NDPA), general data protection duties |
Register with the Commission as a data controller or data processor of major importance where the Commission so determines, conduct a compliance audit within fifteen months of commencing business and annually thereafter, and file Compliance Audit Returns by 31 March each year in the Ultra-High and Extra-High Level categories. |
|
| Law on Personal Data Protection |
Take appropriate technical, organizational and staff measures proportionate to the processing's risk, keep them under review, and be able to demonstrate compliance. |
|
| Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens) proposed |
Take appropriate technical and organizational measures so you can demonstrate compliance with this law on request, and require anyone with access to personal data under your authority to keep it confidential or be bound by a legal duty of confidentiality. |
Cross border transfer
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Data Protection Act 2017, transfer of personal data outside Mauritius |
Be prepared to demonstrate the effectiveness of your transfer safeguards to the Commissioner on request. |
|
| Law relating to the Protection of Personal Data and Privacy, cross-border transfer and data storage |
Be ready to demonstrate compliance with the transfer safeguards this Law requires, including where a transfer rests on your own compelling legitimate interests, and expect the supervisory authority to prohibit or suspend an outbound transfer to protect data subjects' rights. |
Enforcement supervision
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| SIC Circular on AI, Demonstrated Accountability |
Be ready to demonstrate to the Superintendencia de Industria y Comercio, on its request, that you have implemented measures that are appropriate and effective to comply with Ley 1581 de 2012 and Decreto 1074 de 2015 for any artificial intelligence system that processes personal data. |
|
| Nigeria Data Protection Act, 2023, complaints, enforcement and redress |
Keep concrete evidence of compliance with each provision you may be complained about: registration, annual Compliance Audit Returns, a filed impact assessment and an approved cross-border transfer instrument show good faith but do not answer a complaint about anything else. |
Data subject rights
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| SPDP Norma General guaranteeing personal-data protection in the use of AI systems from a date not yet set |
Maintain a record of processing activities and audit the AI system's operation in proportion to its level of risk. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.