Law / Frameworks / NIST Privacy Framework / Govern-P

NIST Privacy Framework, Govern-PGV.MT-P5

Policies, processes, and procedures are established and in place to receive, analyze, and respond to problematic data actions disclosed to the organization from internal and external sources (e.g., internal discovery, privacy researchers, professional events).NIST Privacy Framework, version 1.0, January 2020, GV.MT-P5

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

3
laws
3
places
0
with court rulings behind them
2
not yet in force
1
proposed, not law

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Grenada
  • Saint Kitts and Nevis
  • Suriname

Enforcement supervision

3 laws, 3 places
PlaceLawWhat it asks, as read here
Grenada Data Protection Act, No. 1 of 2023, Information Commission, enforcement and offences from a date not yet set

Do not dismiss, suspend, demote, discipline, harass or otherwise disadvantage an employee because they reported, or refused to take part in, a contravention of the Act in good faith.

Saint Kitts and Nevis Data Protection Act, 2018, Information Commissioner, enforcement and offences from a date not yet set

Do not dismiss, suspend, demote, discipline, harass, or otherwise disadvantage an employee for reporting or refusing to participate in a contravention of the Act in good faith.

Suriname Draft Law on the Protection of Privacy and Personal Data, Commissioner, remedies and fines proposed

Do not dismiss, suspend, demote, discipline, fine, intimidate, or otherwise disadvantage an employee for reporting in good faith that you have or will violate this law.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.