Law / Frameworks / NIST Privacy Framework / Govern-P

NIST Privacy Framework, Govern-PGV.MT-P4

Policies, processes, and procedures for communicating progress on managing privacy risks are established and in place.NIST Privacy Framework, version 1.0, January 2020, GV.MT-P4

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

7
laws
6
places
0
with court rulings behind them
1
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • California
  • Cameroon
  • Côte d'Ivoire
  • Marshall Islands
  • Nigeria
  • Syria

Comprehensive regime

4 laws, 4 places
PlaceLawWhat it asks, as read here
California CCPA Cybersecurity Audit Regulations

Submit a written certification of completion to the California Privacy Protection Agency by April 1 following each year you were required to complete an audit, starting for the largest businesses and reaching every covered business by .

Cameroon Loi n°2024/017 du 23 décembre 2024 relative à la protection des données à caractère personnel au Cameroun from a date not yet set

Notify the data protection authority of a personal-data breach without delay, and inform an affected person where their rights are threatened; submit an annual security report to the authority.

Côte d'Ivoire Law No. 2013-450 on the Protection of Personal Data

Send ARTCI an annual report on compliance with these security measures.

Nigeria Nigeria Data Protection Act, 2023 (NDPA), general data protection duties

Designate a Data Protection Officer as section 32 of the Act mandates, give the officer the position the Directive prescribes, and have the officer prepare semi-annual data protection reports.

Enforcement supervision

2 laws, 2 places
PlaceLawWhat it asks, as read here
Marshall Islands Personal Data Protection Act 2025, competent authority, remedies, and complaints

Report that information to the competent authority by July 1 of each year, in anonymized form for its statistical and Nitijela reporting.

Syria Law No. 12 of 2024 on Protection of Electronic Personal Data, Authority, complaints and penalties

Provide the Authority with any reports, statistics or information it requests about your personal data protection activities.

Sensitive categories

1 law, 1 place
PlaceLawWhat it asks, as read here
Nigeria Nigeria Data Protection Act, 2023, sensitive personal data and a child's data

Document those parameters and file them with the Commission as part of your Compliance Audit Returns, with an impact assessment that weighs disparate outcomes of the processing and the Data Subjects' Vulnerability Indexes in Schedule 6.

State in your Compliance Audit Returns whether you rely on consent for any of the activities article 18 lists.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.