Law / Frameworks / NIST Privacy Framework / Govern-P

NIST Privacy Framework, Govern-PGV.PO-P2

Processes to instill organizational privacy values within system/product/service development and operations are established and in place.NIST Privacy Framework, version 1.0, January 2020, GV.PO-P2

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

26
laws
25
places
0
with court rulings behind them
2
not yet in force
3
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Albania
  • Andorra
  • Barbados
  • Benin
  • Botswana
  • Cambodia
  • Colorado
  • Democratic Republic of the Congo
  • Djibouti
  • Ecuador
  • El Salvador
  • Gabon
  • Gambia
  • Kosovo
  • Moldova
  • Monaco
  • Montenegro
  • Niger
  • Nigeria
  • San Marino
  • Serbia
  • Suriname
  • Ukraine
  • Uruguay
  • Zimbabwe

Comprehensive regime

20 laws, 20 places
PlaceLawWhat it asks, as read here
Albania Law No. 124/2024 On the Protection of Personal Data

Implement data protection by design and by default in every processing tool and process, and appoint a data protection officer where processing is carried out by a public authority, requires regular and systematic large scale monitoring of data subjects, or involves large scale processing of sensitive data or criminal records.

Andorra LQPD, Llei 29/2021 del 28 d'octubre

Apply data protection by design and by default, keep a written record of your processing activities unless you employ fewer than fifty workers and none of the high-risk, non-occasional or special-category exceptions apply, and block rather than delete personal data pending any liability claim when you rectify or erase it.

Barbados Data Protection Act, 2019

Build data protection into the design of your processing and make it the default, and keep records of your processing activities.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel)

Implement data protection by design and by default, including pseudonymization and data minimization, so that only the personal data necessary to each specific purpose is processed by default.

Botswana Data Protection Act, 2024 (Act No. 18 of 2024)

Implement appropriate technical and organisational measures, including data protection by design and by default, to secure personal data at a level appropriate to the risk and to be able to demonstrate compliance with the Act.

Cambodia Draft Law on Personal Data Protection, final draft proposed

If enacted as drafted, a data controller or processor would have to implement personal data protection by design and by default, and would have to secure personal data with technical and organizational measures against unauthorized access, collection, use, disclosure, copying, modification, or destruction, and against the loss of any storage medium on which it is held.

Democratic Republic of the Congo Digital Code, Title III: Personal Data Protection

Build data protection into the processing by design and by default, including pseudonymization, and process by default only the personal data necessary for each specific purpose.

Djibouti Digital Code, Book I: Personal Data Protection and CNDP

Build data protection into the design and the default settings of your processing, restrict processing to persons acting under your authority and on your instructions, and take the measures necessary to secure personal data against loss, alteration, or unauthorized access, having regard to its nature and the risks the processing presents.

Ecuador LOPDP, comprehensive personal-data protection regime

Secure personal data with the technical and organisational measures articles 37 to 41 require, determined from a risk, threat and vulnerability analysis, and build data protection into the design of your processing and make it the default.

Gambia Personal Data Protection and Privacy Act, 2025 from a date not yet set

Design your technical and organisational measures to implement the data protection principles, and ensure that by default only the personal data necessary for each specific purpose is processed.

Show the other 10 laws
Kosovo Law No. 06/L-082 on Protection of Personal Data

Apply data protection by design and by default, keep a written record of your processing activities unless you employ fewer than two hundred and fifty people and none of the high-risk, non-occasional or special-category exceptions apply, and cooperate with the Agency for Information and Privacy on request.

Moldova Law No. 195/2024 on Personal Data Protection

Build data protection into the design of your processing and make it the default, and keep records of your processing activities.

Monaco Loi sur la Protection des Données Personnelles

Build data protection by design and by default into a processing operation, so that by default only the personal data necessary for each specific purpose is processed, collected, retained, or made accessible.

Niger Loi n° 2022-59, protection des données à caractère personnel

Keep personal data confidential and implement technical and organizational measures against unauthorized access, loss or damage, including pseudonymization, encryption, and data protection by design and by default.

Nigeria Nigeria Data Protection Act, 2023 (NDPA), general data protection duties

Before deploying data processing software that tracks a data subject or opens a communication link with one, carry out an impact assessment, design it for privacy by design and by default, put a data privacy policy inside the software, and give a prospective user a privacy statement before installation.

San Marino San Marino Law No. 171 on the Protection of Natural Persons

Build data protection into the design of your processing and make it the default, and keep records of your processing activities.

Serbia Law on Personal Data Protection

Build data protection into your processing by design and by default, including pseudonymization and data minimization.

Suriname Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens) proposed

Implement data protection by design and by default, taking into account the state of the art, the cost of implementation, and the risks the processing poses to data subjects' rights and freedoms.

Ukraine Draft Law No. 8153 on Personal Data Protection (GDPR-Aligned Reform) proposed

Once enacted, implement data protection by design and by default so that only the personal data necessary for each specific purpose is processed by default.

Uruguay Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended

Adopt privacy-by-design, privacy-by-default, and data-protection impact assessment measures as part of a proactive-accountability duty, and be able to demonstrate their effective implementation.

Sensitive categories

6 laws, 6 places
PlaceLawWhat it asks, as read here
Colorado SB 24-041, Protecting Minors' Online Data

Do not collect a minor's precise geolocation data beyond what is necessary to provide the service, and do not use a design feature meant to significantly increase, sustain, or extend a minor's use of the service without consent.

El Salvador Ley para la Protección de Datos Personales, sensitive personal data and children

Guarantee the best interests of a child or adolescent in any processing of their data, and inform both the child and their parent or guardian, in clear and age appropriate language, before exercising the child's rights.

Gabon Law No. 025/2023, sensitive categories of personal data and children's data

Where your online service is aimed at children, build in privacy-protective technical measures such as marking and filtering, write information for them in terms they can understand, keep advertising, entertainment and games clearly distinct from content, never incite a child to buy goods or enter an online contract, and never use prizes, rewards or links to a non-compliant site to keep them engaged.

Montenegro Law on Personal Data Protection, special categories of data from a date not yet set

Process a child's personal data in a manner that is in the best interest of the child, under Article 12.

Nigeria Nigeria Data Protection Act, 2023, sensitive personal data and a child's data

Where you deploy an emerging technology such as artificial intelligence, the Internet of Things or blockchain to process personal data, set technical and organisational parameters that take account of safeguards for sensitive personal data, safeguards for child rights and other vulnerable groups, the right against solely automated decisions, the right to be forgotten, cross-border data flows, and privacy by design and by default.

Zimbabwe Cyber and Data Protection Regulations 2024, children's information and automated decisions

Conduct regular data protection impact assessments to identify and mitigate privacy risks to children, and ensure data protection by design and by default when processing children's data.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.