Law / Frameworks / NIST Privacy Framework / Govern-P

NIST Privacy Framework, Govern-PGV.MT-P3

Policies, processes, and procedures for assessing compliance with legal requirements and privacy policies are established and in place.NIST Privacy Framework, version 1.0, January 2020, GV.MT-P3

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

11
laws
10
places
0
with court rulings behind them
2
not yet in force
1
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • California
  • Colombia
  • Ecuador
  • Grenada
  • Marshall Islands
  • Mauritius
  • Nigeria
  • Rwanda
  • Serbia
  • Suriname

Comprehensive regime

6 laws, 6 places
PlaceLawWhat it asks, as read here
California CCPA Cybersecurity Audit Regulations

If your business meets the CCPA's business-scale thresholds, deriving 50 percent or more of annual revenue from selling or sharing personal information, or having more than $25 million in annual gross revenue and having processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers, in the preceding calendar year, complete a cybersecurity audit.

Complete that audit using a qualified, objective, independent auditor, who may be internal or external to the business, and who did not develop, implement, or maintain the cybersecurity program being audited.

+2 more
Grenada Data Protection Act, No. 1 of 2023 from a date not yet set

Establish formal procedures implementing these principles, and review them, with a self-assessment, at least once every five years.

Marshall Islands Personal Data Protection Act 2025, government personal-data protection principles

Be able to demonstrate compliance with these principles on request of the competent authority, the Economic Policy, Planning and Statistics Office.

Nigeria Nigeria Data Protection Act, 2023 (NDPA), general data protection duties

Register with the Commission as a data controller or data processor of major importance where the Commission so determines, conduct a compliance audit within fifteen months of commencing business and annually thereafter, and file Compliance Audit Returns by 31 March each year in the Ultra-High and Extra-High Level categories.

Serbia Law on Personal Data Protection

Take appropriate technical, organizational and staff measures proportionate to the processing's risk, keep them under review, and be able to demonstrate compliance.

Suriname Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens) proposed

Take appropriate technical and organizational measures so you can demonstrate compliance with this law on request, and require anyone with access to personal data under your authority to keep it confidential or be bound by a legal duty of confidentiality.

Cross border transfer

2 laws, 2 places
PlaceLawWhat it asks, as read here
Mauritius Data Protection Act 2017, transfer of personal data outside Mauritius

Be prepared to demonstrate the effectiveness of your transfer safeguards to the Commissioner on request.

Rwanda Law relating to the Protection of Personal Data and Privacy, cross-border transfer and data storage

Be ready to demonstrate compliance with the transfer safeguards this Law requires, including where a transfer rests on your own compelling legitimate interests, and expect the supervisory authority to prohibit or suspend an outbound transfer to protect data subjects' rights.

Enforcement supervision

2 laws, 2 places
PlaceLawWhat it asks, as read here
Colombia SIC Circular on AI, Demonstrated Accountability

Be ready to demonstrate to the Superintendencia de Industria y Comercio, on its request, that you have implemented measures that are appropriate and effective to comply with Ley 1581 de 2012 and Decreto 1074 de 2015 for any artificial intelligence system that processes personal data.

Nigeria Nigeria Data Protection Act, 2023, complaints, enforcement and redress

Keep concrete evidence of compliance with each provision you may be complained about: registration, annual Compliance Audit Returns, a filed impact assessment and an approved cross-border transfer instrument show good faith but do not answer a complaint about anything else.

Data subject rights

1 law, 1 place
PlaceLawWhat it asks, as read here
Ecuador SPDP Norma General guaranteeing personal-data protection in the use of AI systems from a date not yet set

Maintain a record of processing activities and audit the AI system's operation in proportion to its level of risk.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.