Law / Frameworks / NIST Privacy Framework / Govern-P
NIST Privacy Framework, Govern-PGV.MT-P7
Policies, processes, and procedures for receiving, tracking, and responding to complaints, concerns, and questions from individuals about organizational privacy practices are established and in place.NIST Privacy Framework, version 1.0, January 2020, GV.MT-P7
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 28
- laws
- 28
- places
- 0
- with court rulings behind them
- 1
- not yet in force
- 1
- proposed, not law
A law in force is unmarked; the rest wear their state: not yet in force proposed
Data subject rights
19 laws, 19 places| Place | Law | What it asks, as read here |
|---|---|---|
| Data Protection Act, 2013, notice and rights of data subjects |
Where you deny an access request, state the specific statutory ground in the refusal notice, tell the data subject of the right to complain to the Information Commissioner, and treat a failure to respond within the time limits as a deemed refusal. Correct personal data on a data subject's written application where it is incomplete, incorrect, misleading, excessive or irrelevant to the purpose it is held for, without obliterating the pre-amendment text of the document, or give written reasons for refusing and tell the data subject of the right to complain to the Information Commissioner within twenty-eight days. |
|
| Law on Protection of Personal Data, data subject rights |
An app holding the personal data of a person in Armenia must give that person a way to receive information about their own data and to appeal a processor's action or inaction under Art. 17. |
|
| Data Protection Act, 2022, rights of data subjects |
Give a data subject written reasons where you deny an access request, and let them challenge those reasons. |
|
| Florida Digital Bill of Rights, consumer rights |
Respond to a consumer rights request without undue delay and no later than 45 days after receipt, with one 15-day extension available when reasonably necessary, and decide an appeal of a denial within 60 days. |
|
| Law on Personal Data Protection, data subject rights |
An app holding the personal data of a person in Georgia must give that person a way to withdraw consent and to appeal, and must act on a request to exercise their Chapter III rights on demand. |
|
| Iowa Consumer Data Protection Act, consumer rights |
Respond to a consumer rights request without undue delay and within 90 days of receipt, with one 45-day extension available, and decide an appeal of a refusal within 60 days. |
|
| Kentucky Consumer Data Protection Act, consumer rights |
Respond to a consumer rights request without undue delay and within 45 days of receipt, with one 45-day extension available, and decide an appeal within 60 days of receipt. |
|
| Data Protection Act, 2011, rights of data subjects |
Give a data subject written reasons where you deny an access request, and let them challenge those reasons. |
|
| Louisiana Data Privacy Act (Act No. 502), consumer rights from , in 3 months |
Respond to a consumer rights request without undue delay and no later than 45 days after receipt, with one 45-day extension available, and respond to an appeal of a refusal within 60 days. |
|
| Maryland Online Data Privacy Act (MODPA), consumer rights and appeal |
Respond to a consumer rights request no later than 45 days after receipt, with one 45-day extension available if you tell the consumer the reason within the initial period, and provide a conspicuous process to appeal a refusal. |
Show the other 9 laws
| Montana Consumer Data Privacy Act, consumer rights |
Respond to a consumer rights request without undue delay and within 45 days of receipt, with one 45-day extension available, and decide an appeal of a refusal within 60 days. |
|
| New Hampshire Data Privacy Act, consumer rights |
Respond to a consumer rights request without undue delay and no later than 45 days after receipt, with one 45-day extension available, and decide an appeal of a refusal within 60 days. |
|
| Nigeria Data Protection Act, 2023, rights of a data subject |
Carry a clause on the right to lodge a complaint with the Commission in every regulation, policy, framework or legal instrument of yours that pertains to processing personal data, and answer a Standard Notice to Address Grievance a data subject serves on you. |
|
| Oregon Consumer Privacy Act, consumer rights |
Respond to a consumer rights request without undue delay and within 45 days of receipt, decide an appeal within 45 days, and honor a consent revocation within 15 days. |
|
| Rhode Island Data Transparency and Privacy Protection Act, customer rights |
Respond to a customer rights request without undue delay and not later than 45 days after receipt, with one 45-day extension available, and decide an appeal within 60 days of receipt. |
|
| National Digital Identification Act 2024, registered persons' data-subject rights |
Implement measures that let a registered person effectively exercise these access, correction, and information rights, and provide a way to lodge a grievance over improper use of their data. |
|
| Tennessee Information Protection Act, consumer rights |
Respond to a consumer rights request within 45 days of receipt (extendable once by 45 days) and to an appeal of a denial within 60 days of receipt. |
|
| Texas Data Privacy and Security Act, consumer rights and assessments |
Respond to a consumer rights request without undue delay and no later than 45 days after receipt, with one 45-day extension available, and respond to an appeal of a refusal within 60 days. |
|
| Virginia Consumer Data Protection Act, consumer rights |
Respond to a consumer rights request without undue delay and within 45 days of receipt, with one 45-day extension available, and decide an appeal of a refusal within 60 days. |
Enforcement supervision
5 laws, 5 places| Place | Law | What it asks, as read here |
|---|---|---|
| Personal Data Protection Act 2025, competent authority, remedies, and complaints |
Compile and record, for each calendar year, the policies, decisions and actions taken to implement this Chapter and the complaints received about it, including how many were received, which principles they alleged were contravened, and how they were resolved. Establish a process for natural persons residing in the Republic to submit complaints about alleged violations of the personal data protection principles, consistent with any guidance the competent authority adopts, and retain records of the complaints and any action taken. |
|
| Ley Federal de Protección de Datos Personales en Posesión de los Particulares, enforcement, sanctions and offences |
Answer a rights-protection request the Secretaría serves on you within fifteen days, offering the evidence and arguments you rely on. |
|
| Draft Law on the Protection of Privacy and Personal Data, Commissioner, remedies and fines proposed |
Let a data subject or their representative lodge a complaint with the Commissioner about your processing, and give reasonable assistance to a person who wants to put a complaint in writing. |
|
| Law No. 12 of 2024 on Protection of Electronic Personal Data, Authority, complaints and penalties |
Respond within seven working days to a decision the Authority issues on a data subject's complaint against you, after the Authority has decided the complaint within thirty days of it being filed. |
|
| General Regulation on the Protection of Personal Data, Data Protection Officer and complaints |
Where this Regulation binds your processing, route a written complaint from the Interested party that your treatment violates the Regulation to the Data Protection Officer, a function assigned to the General Councillor of Vatican City State who acts independently and autonomously, except in a matter involving the judicial authority of Vatican City State. |
Comprehensive regime
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Personal Information Protection and Electronic Documents Act (PIPEDA) |
Give individuals access to their own personal information on request and a way to challenge the organization's compliance with these obligations. |
|
| Ley 1581 de 2012, General Personal Data Protection |
As a data processor, keep personal data secure in the same way, update or correct it as the controller instructs within five business days, and adopt an internal manual of policies and procedures for handling consultations and claims. |
|
| Communications and Broadcasting Act 2018, confidentiality of subscriber information and communications |
Let a subscriber require you to correct or remove information relating to them, and handle any complaint about how you responded to that request. |
|
| Data Protection Act, 2011 |
Make available to individuals your policies and practices for managing personal information, and give an individual the ability to challenge your compliance with these Principles and a timely, appropriate response. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.