Law / Frameworks / NIST Privacy Framework / Govern-P
NIST Privacy Framework, Govern-PGV.PO-P1
Organizational privacy values and policies (e.g., conditions on data processing such as data uses or retention periods, individuals’ prerogatives with respect to data processing) are established and communicated.NIST Privacy Framework, version 1.0, January 2020, GV.PO-P1
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 81
- laws
- 79
- places
- 0
- with court rulings behind them
- 4
- not yet in force
- 5
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.4 The risk management process and its outcomes are established through transparent...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations4.1 System Documentation
- MIT mitigations1.1 Board Structure & Oversight
- NIST CSF 2.0ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
- NIST CSF 2.0PR.PS-04 Log records are generated and made available for continuous monitoring
A law in force is unmarked; the rest wear their state: not yet in force proposed
Comprehensive regime
76 laws, 75 places| Place | Law | What it asks, as read here |
|---|---|---|
| Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11 |
Process personal data lawfully and fairly, for determined and legitimate purposes, keeping it adequate, accurate and no longer than those purposes require. |
|
| Data Protection Act, 2013 |
Process personal data only for a lawful purpose directly related to your activity, keep the processing necessary for that purpose, and keep the data adequate but not excessive for it. |
|
| Ley 25.326, Ley de Protección de los Datos Personales |
Collect only personal data that is true, adequate, relevant, and not excessive for the purpose you obtained it, use it only for that purpose, keep it accurate and updated, correct or delete it once you learn it is inaccurate or incomplete, store it so the data subject's access right can be exercised, and destroy it once it is no longer necessary. |
|
| Data Protection Act 2003, application and processing principles |
Collect personal data only by means that are lawful and fair, keep it accurate and up to date, and hold it only for the specified purposes it was collected for. |
|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel) |
Collect personal data only for determined, explicit, and legitimate purposes, and do not process it further in a way incompatible with those purposes. |
|
| Personal Information Protection Act 2016, application and general principles |
Use personal information only for the specific purposes it was collected for, in a fair and lawful manner, and adopt measures and policies giving effect to these obligations. |
|
| Anteproyecto de Ley de Protección de Datos Personales (AGETIC) proposed |
Process a natural person's personal data lawfully, for a stated purpose, and with the security, transparency, and accountability the draft's principles describe. |
|
| Reglamento para el Desarrollo de TIC, Tratamiento de los Datos Personales |
Do not use personal data for a purpose other than the one stated when it was collected. |
|
| Data Protection Act, 2024 (Act No. 18 of 2024) |
Process personal data lawfully, fairly and transparently, only for a specified and legitimate purpose, and collect no more than is adequate and relevant to that purpose. |
|
| Loi n°001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel |
Collect personal data only for determined, explicit and legitimate purposes, keep it accurate and updated, and do not retain it beyond the period the purpose requires. |
Show the other 66 laws
| Law No. 133/V/2001 on the Protection of Personal Data |
Process personal data lawfully and in good faith, collect it only for specified, explicit and legitimate purposes, keep it accurate and proportionate to those purposes, and do not keep it identifiable for longer than the purposes require. |
|
| California Consumer Privacy Act, as amended by the California Privacy Rights Act (Proposition 24) |
Limit your collection, use, retention, and sharing of a California consumer's personal information to what is reasonably necessary and proportionate to the purpose you disclosed. |
|
| Personal Information Protection and Electronic Documents Act (PIPEDA) |
Comply with the ten Schedule 1 fair information principles, including limiting use and disclosure to the purposes for which information was collected and keeping it only as long as necessary. |
|
| Data Protection Act 2021 Revision, application, principles and data subject rights |
Have a lawful basis for collecting and processing personal data, and hold it only for specified purposes. |
|
| Loi n° 24.001 portant protection des données à caractère personnel |
Apply the Act's core principles to every processing activity: lawfulness, fairness, transparency, security, purpose limitation, accuracy, proportionality, and a retention period no longer than the purpose requires. If you provide electronic signature certification services, collect the personal data needed for issuing and keeping the certificates directly from the person concerned, and use it only for that purpose absent the person's express consent otherwise. |
|
| Loi n°007/PR/2015, principes directeurs du traitement des données (consentement, licéité, finalité, conservation) |
Collect and process personal data only for determined, explicit, and legitimate purposes, and do not process it later in a way incompatible with those purposes. |
|
| Personal Information Protection Law of the PRC, General Processing Rules and Lawful Bases |
Limit personal information processing to the minimum scope and duration necessary for a stated, specific purpose. |
|
| Ley 1581 de 2012, General Personal Data Protection |
Apply the legality, purpose limitation, freedom, accuracy, transparency, restricted access and confidentiality principles to every processing operation, and do not process partial, incomplete, fragmented or misleading personal data. |
|
| Law on the Protection of Personal Data |
Collect and process personal data lawfully and fairly, only for determined and legitimate purposes, keep it accurate and up to date, and do not retain it beyond the period necessary for those purposes. Collect personal data for an electronic certification service directly from the data subject, and use it only for the purpose it was collected for, unless the data subject expressly consents otherwise. |
|
| Protección de la Persona frente al Tratamiento de sus Datos Personales |
Do not use collected data for a purpose incompatible with the one disclosed at collection. |
|
| Law No. 2013-450 on the Protection of Personal Data |
Collect and process personal data lawfully and fairly, for specified and legitimate purposes, keeping it no longer than those purposes require, accurate, and transparent to the person concerned. |
|
| Digital Code, Title III: Personal Data Protection |
Do not process personal data for historical, statistical or scientific purposes beyond its original collection unless one of the statutory safeguards applies, or process only anonymous data for that further purpose. |
|
| Law No. 151 of 2020 Promulgating the Personal Data Protection Law |
Collect Personal Data only for legitimate, specific purposes that are transparent to the Data Subject, keep it correct, valid and secured, and do not retain it longer than that purpose needs. |
|
| Ley para la Protección de Datos Personales |
Collect only personal data that is sufficient, relevant and not excessive for your specific, legitimate purpose, and keep it accurate, complete and up to date. If you are a private entity, process a data subject's data only for the services you actually provide them, and do not transfer or use a third party's data for a different purpose without that party's authorization. |
|
| Ley de Protección de Datos Personales |
Keep personal data secure, confidential, and limited to what is adequate and not excessive for the stated purpose. |
|
| Data Protection Act, 2022 (Act No. 5 of 2022) |
Collect personal information only for a specified, explicit and legitimate purpose, and do not further process it in a way incompatible with that purpose. |
|
| Loi n°001/2011 relative à la protection des données à caractère personnel, modifiée par la loi n°025/2023 |
Collect and process personal data fairly and lawfully, only for determined, explicit and legitimate purposes, and keep it accurate, adequate and no longer than those purposes need. |
|
| Personal Data Protection and Privacy Act, 2025 from a date not yet set |
Collect personal data only for explicit and legitimate purposes, keep it adequate and relevant to those purposes, keep it accurate and up to date, and process it securely. Carry out a compatibility assessment before putting personal data to a new purpose, weighing the relationship between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place. |
|
| Data Protection Act, No. 1 of 2023 from a date not yet set |
Process personal data only for a lawful purpose directly related to your activity, and hold no more than is adequate and not excessive for that purpose. |
|
| Indiana Consumer Data Protection Act (INCDPA), general applicability and controller duties |
Limit the collection of personal data from an Indiana consumer to what is adequate, relevant, and reasonably necessary for the purposes disclosed to that consumer, and do not process it for an incompatible purpose without consent. |
|
| Data Protection Act, 2020, registration, lawful basis and standards for processing |
Obtain personal data only for one or more specified and lawful purposes, and do not further process it in a manner incompatible with those purposes. Hold no more personal data than is adequate, relevant and limited to what is necessary for the purpose, keep it accurate and up to date, and do not keep it for longer than that purpose requires. |
|
| Act on the Protection of Personal Information, comprehensive regime and lawful basis |
An app that collects, uses, or discloses the personal data of an individual in Japan must give notice of, or publicly disclose, its purpose of use before or promptly after collection, must not acquire the data by wrongful or deceptive means, and must confine use to the stated purpose unless a statutory exception or the data subject's consent applies. |
|
| Kentucky Consumer Data Protection Act (KCDPA), general applicability and controller and processor duties |
Limit collection to the purposes disclosed to the consumer, and use a written contract to bind any processor to your instructions. |
|
| Data Protection Act, 2019 |
Process personal data lawfully, fairly and transparently, only for an explicit and legitimate purpose, and collect no more than is necessary for that purpose. |
|
| Law No. 06/L-082 on Protection of Personal Data |
Establish a lawful basis under Article 5 before processing personal data of a person in Kosovo, and apply the Article 4 principles of lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability throughout. |
|
| Digital Code, comprehensive personal data regime |
An app that collects, uses, or discloses the personal data of individuals in Kyrgyzstan must process it lawfully, fairly, and transparently, limit use to the stated purpose, minimize what is collected, keep it accurate, and limit retention to the processing purpose. An organization with more than ten employees must designate a personal-data-responsible person and provide staff training. |
|
| Law No. 81/2018 on Electronic Transactions and Personal Data, Part V (Personal Data Protection) |
Collect personal data faithfully and for legitimate, specific and explicit purposes, keep it appropriate to and within those purposes, correct, complete and as relevant as possible, and do not later process it for purposes out of line with the objectives you stated, except for statistical, historical or scientific research. |
|
| Data Protection Act, 2011 (Act No. 5 of 2012) |
Collect personal information only for a specified, explicit and legitimate purpose, and do not further process it in a way incompatible with that purpose. |
|
| Telecommunications Act of 2007, Protection of Personal Information (§§ 51-52) |
Identify the purposes for which customer information is collected, at or before collection, and do not use it for an undisclosed purpose. |
|
| Law No. 2014-038, protection of personal data |
Collect and process personal data fairly, lawfully, and only for determined, explicit, and legitimate purposes, and do not use it later for another purpose without the data subject's consent or a purpose the law itself provides. Keep personal data adequate, relevant, accurate, and no longer than those purposes require, unless it is kept for archival, historical, statistical, or scientific purposes under the safeguards the law or the CMIL sets. +1 more |
|
| Electronic Transactions and Cyber Security Act, 2016, personal data processing and security duties (Part VII) |
Process personal data fairly and lawfully, collect it only for specified, explicit and legitimate purposes, and do not process it further in a way incompatible with those purposes. Keep personal data adequate, relevant and not excessive for its purpose, accurate and up to date, and take every reasonable step to erase or rectify data that is inaccurate or incomplete; do not keep it in identifiable form for longer than the purpose requires. |
|
| Personal Data Protection Bill, pending before the People's Majlis proposed |
If enacted as drafted, a Controller or Processor would need a lawful basis before processing personal data, would have to collect it only for specific, explicit and legitimate purposes declared before collection, and would not be able to process it further in a way incompatible with those purposes. If enacted as drafted, personal data would have to be adequate, relevant and necessary to the declared purposes, accurate and kept up to date, and retained in identifiable form no longer than those purposes need. |
|
| Loi n° 2013-015, protection des données à caractère personnel |
Collect and process personal data fairly, lawfully, and without fraud, only for determined, explicit, and legitimate purposes, never using it for another purpose, and keep it adequate, proportionate, and relevant to those purposes, accurate and updated where necessary, and identifiable for no longer than those purposes require. |
|
| Personal Data Protection Act 2025, government personal-data protection principles |
Process personal data lawfully, fairly, and transparently, for a specified and legitimate purpose, and do not further process it in a way incompatible with that purpose. Collect personal data only by lawful and fair means, and limit it to what is relevant and necessary to fulfill the purpose for which it is processed. |
|
| Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) |
Limit processing of personal data to the purposes stated in the privacy notice, and obtain the data subject's consent again before processing it for a different purpose. |
|
| Minnesota Consumer Data Privacy Act (MCDPA), general applicability |
Limit your collection of a Minnesota resident's personal data to what is adequate, relevant, and reasonably necessary for the purpose you disclosed to them, and obtain consent before processing it for an undisclosed, incompatible secondary purpose. |
|
| Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data |
Process personal data only where it is collected fairly and lawfully for determined, explicit and legitimate purposes, and do not process it later in a way incompatible with those purposes. Keep personal data adequate, relevant, accurate, and not excessive for those purposes, and do not retain it in identifiable form longer than the purposes require. |
|
| Electronic Transactions Law, Protection of Personal Electronic Data |
Specify the purpose for collecting personal data and your identity as the processor before collecting it, and limit any later use to that stated purpose. |
|
| New Hampshire Data Privacy Act (NHDPA), general applicability and controller and processor duties |
Limit personal data collection to what is adequate, relevant, and reasonably necessary, and describe your purposes in a privacy notice. |
|
| New Jersey Data Privacy Act (NJDPA), general applicability and scope |
Limit your collection of a New Jersey resident's personal data to what is adequate, relevant, and reasonably necessary for the purpose disclosed to the consumer. |
|
| Privacy Act 2020, Information Privacy Principles and Extraterritorial Reach |
Collect personal information directly from the individual concerned unless an exception applies, such as the individual's authorisation, the source being a publicly available publication, or non-compliance not prejudicing the individual's interests. |
|
| Ley No. 787, Ley de Protección de Datos Personales |
Process personal data only to the extent adequate, proportional, and necessary for the stated purpose, and adopt technical and organizational security measures against unauthorized access, use, alteration, loss, disclosure, transfer, or dissemination. |
|
| Loi n° 2022-59, protection des données à caractère personnel |
Collect personal data only for determined, explicit and legitimate purposes, and do not process it later in a way incompatible with those purposes or keep it longer than the purposes require. |
|
| Nigeria Data Protection Act, 2023 (NDPA), general data protection duties |
Process personal data on one of the lawful bases section 25 recognises, and hold to the section 24 principles of fairness, lawfulness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, confidentiality, integrity and availability. |
|
| Law on Personal Data Protection (LPDP), video surveillance |
Limit video surveillance to the area sufficient for the goal it was installed for, and never install it in changing rooms, dressing rooms, toilets or similar rooms. |
|
| Ley 81 de 2019, Sobre Protección de Datos Personales |
Have a lawful basis, such as consent, contractual necessity or a legal obligation, before processing a person's personal data, and use it only for the purpose for which it was collected. |
|
| Ley 29733, Ley de Protección de Datos Personales |
Do not collect personal data by fraudulent, unfair, or unlawful means, and collect only data that is updated, necessary, relevant, and adequate to a determined, explicit, and lawful purpose stated at the time of collection. Do not use personal data for a purpose other than the one that justified its collection, unless you first apply an anonymization or dissociation procedure. +1 more |
|
| Québec | Act respecting the protection of personal information in the private sector, comprehensive regime |
Establish and implement governance policies and practices for personal information, including a framework for retention and destruction, and conduct a privacy impact assessment before acquiring, developing or overhauling a system or service that collects, uses, communicates, keeps or destroys personal information. |
| Data Protection Act |
Collect personal data only for a lawful purpose connected with your function or activity, and only where the collection is necessary for that purpose. Keep personal data only for the specified purpose it was collected for, do not use or disclose it in a way incompatible with that purpose, keep it adequate and relevant and not excessive, and keep it accurate and up to date. |
|
| Telecommunications Act 2005, confidentiality and protection of customer personal information |
Identify the purposes for which customer information is collected at or before collection, and do not collect, use, maintain, or disclose customer information for an undisclosed purpose without the customer's consent or legal authority. |
|
| Lei n.º 03/2016, Protecção de Dados Pessoais |
Process personal data lawfully and in good faith, collect it only for specified, explicit and legitimate purposes tied to your activity, keep it adequate, relevant and not excessive, accurate and updated, and retain it in identifiable form no longer than the collection purpose requires. Do not process personal data you access as a subcontractor, or on the controller's authority, beyond the controller's instructions except under a legal obligation, and keep confidential any personal data you learn of in the course of your duties, including after those duties end. |
|
| Telecommunications Act 2009, Confidentiality and Consent Duties |
Disclose to a consumer the purpose of collecting information about them, and do not use or maintain that information for an undisclosed purpose. |
|
| Data Protection Act No. 005 of 2023 |
Collect personal data for a specified, explicit and legitimate purpose, keep it to the minimum necessary for that purpose, keep it accurate, and retain it no longer than the purpose requires. |
|
| Protection of Personal Information Act 4 of 2013 (POPIA) |
Obtain a lawful basis, such as the data subject's consent, before processing personal information, and limit processing to the purpose for which it was collected. |
|
| Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens) proposed |
Process personal data lawfully and fairly, only for specified, explicit and legitimate purposes, and keep it adequate, relevant, accurate, and limited to what those purposes need. |
|
| Law No. 12 of 2024 on Protection of Electronic Personal Data |
Collect personal data only for legitimate and specific purposes, process it in a manner appropriate to those purposes, and do not retain it longer than the purpose requires unless the retention is for archiving in the public interest or for scientific, historical or statistical purposes. |
|
| Personal Data Protection Act (個人資料保護法) |
Collect, process, or use the personal data of an individual in Taiwan only for a specific purpose and on one of the Act's stated lawful bases, and confine use to the purpose stated at collection unless a further basis under Article 16 or 20 applies. |
|
| Personal Data Protection Act, 2022 |
Process personal data lawfully, fairly and transparently, and only for an explicit and legitimate purpose. |
|
| Loi n° 2019-014, protection des données à caractère personnel |
Collect and process personal data lawfully and fairly, only for determined and legitimate purposes, keep it accurate and up to date, and do not retain it beyond the period necessary for those purposes. |
|
| Privacy Act 2025, comprehensive personal information protection regime from a date not yet set |
Process personal information only for a lawful purpose related to your function or activity, take all reasonable steps to keep it accurate, complete, not misleading and up to date for that purpose, and hold no more than is adequate, relevant and limited to it. |
|
| Data Protection Act, 2011 |
Limit collection of personal information to what is legally undertaken and necessary for the identified purpose, retain it only as long as necessary for that purpose, and do not disclose it for another purpose without the individual's prior consent. |
|
| Organic Act on the Protection of Personal Data |
Collect and process personal data only for a lawful, determined and explicit purpose, and keep it accurate, precise and up to date. |
|
| Data Protection and Privacy Act, 2019, comprehensive personal-data regime |
Collect personal data directly from the data subject, unless a listed exception applies, such as the data being in a public record, already made public by the data subject, or collected with their consent. Collect personal data only for a lawful purpose that is specific, explicitly defined, and related to your functions or activities. +2 more |
|
| Draft Law No. 8153 on Personal Data Protection (GDPR-Aligned Reform) proposed |
Once enacted, process personal data of a person in Ukraine only under a lawful basis, applying the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability. |
|
| Data Protection Act, 2021, personal data processing framework |
Before processing personal data, establish a lawful basis such as consent, a contract, a legal obligation, or a legitimate interest, and process it fairly, transparently, and only for the purpose collected. Collect personal data directly from the data subject unless one of the exceptions in section 16(2) applies. +1 more |
|
| Cyber and Data Protection Act [Chapter 12:07] |
Process personal data necessarily, fairly, lawfully and for specified, legitimate purposes before a crawler or AI training pipeline collects or uses personal data of a person in Zimbabwe. |
Biometric privacy
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law on Personal Data Protection, biometric data article |
An app that captures or stores a facial image, voiceprint, or other biometric identifier from a person in Georgia must have a necessity-based purpose recognized by Art. 9 or the data subject's consent, and must determine in writing, before processing begins, the purpose, volume, storage period, and destruction procedure for that biometric data. |
|
| Law on Information About Private Life, biometric information |
An app that processes a faceprint, voiceprint, or other biometric identifier of a Turkmen data subject must treat it as automatically confidential and limited to the purpose for which it was collected. The Act's own consent, retention, and destruction rules for biometric data specifically are deferred to other Turkmen legislation, which the Act does not name and which is not identified here. |
Enforcement supervision
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Cybersecurity Code of Practice for ICT/Telecommunications Service Providers, privacy and PII duty |
A Telecom Service Provider or other ICT service provider with critical information infrastructure in Bhutan must establish and communicate a privacy and PII-protection policy, implement procedures to preserve that privacy, including for a biometric identifier such as a voiceprint or faceprint handled as PII, and put in place appropriate technical and organizational measures, consistent with its reporting obligations under the Information, Communications and Media Act of Bhutan 2018. |
|
| Student Data Accessibility, Transparency and Accountability Act (SDATAA) from a date not yet set |
If you are a school district or public charter school, adopt, implement, and post your student-data policy; failing to do so carries its own separate civil penalty. |
Sensitive categories
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Draft Law on the Protection of Privacy and Personal Data, special categories, children and criminal data proposed |
If you are not an official authority and you process criminal conviction data for an employment law purpose, keep an internal policy document explaining your procedures for complying with the article 5 principles and your retention and erasure policy for that data, and make it available to the Commissioner on request. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.