Law / Frameworks / NIST Privacy Framework / Govern-P
NIST Privacy Framework, Govern-PGV.PO-P2
Processes to instill organizational privacy values within system/product/service development and operations are established and in place.NIST Privacy Framework, version 1.0, January 2020, GV.PO-P2
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 26
- laws
- 25
- places
- 0
- with court rulings behind them
- 2
- not yet in force
- 3
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMAP 1.6 System requirements (e.g., “the system shall respect the privacy of its users”) are...
- NIST AI RMFMAP 5.1 Likelihood and magnitude of each identified impact (both potentially beneficial and...
- NIST AI 600-1GAI-RISK-03 Dangerous, Violent, or Hateful Content
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations2.3 Model Safety Engineering
- MIT mitigations2.4 Content Safety Controls
A law in force is unmarked; the rest wear their state: not yet in force proposed
Comprehensive regime
20 laws, 20 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 124/2024 On the Protection of Personal Data |
Implement data protection by design and by default in every processing tool and process, and appoint a data protection officer where processing is carried out by a public authority, requires regular and systematic large scale monitoring of data subjects, or involves large scale processing of sensitive data or criminal records. |
|
| LQPD, Llei 29/2021 del 28 d'octubre |
Apply data protection by design and by default, keep a written record of your processing activities unless you employ fewer than fifty workers and none of the high-risk, non-occasional or special-category exceptions apply, and block rather than delete personal data pending any liability claim when you rectify or erase it. |
|
| Data Protection Act, 2019 |
Build data protection into the design of your processing and make it the default, and keep records of your processing activities. |
|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel) |
Implement data protection by design and by default, including pseudonymization and data minimization, so that only the personal data necessary to each specific purpose is processed by default. |
|
| Data Protection Act, 2024 (Act No. 18 of 2024) |
Implement appropriate technical and organisational measures, including data protection by design and by default, to secure personal data at a level appropriate to the risk and to be able to demonstrate compliance with the Act. |
|
| Draft Law on Personal Data Protection, final draft proposed |
If enacted as drafted, a data controller or processor would have to implement personal data protection by design and by default, and would have to secure personal data with technical and organizational measures against unauthorized access, collection, use, disclosure, copying, modification, or destruction, and against the loss of any storage medium on which it is held. |
|
| Digital Code, Title III: Personal Data Protection |
Build data protection into the processing by design and by default, including pseudonymization, and process by default only the personal data necessary for each specific purpose. |
|
| Digital Code, Book I: Personal Data Protection and CNDP |
Build data protection into the design and the default settings of your processing, restrict processing to persons acting under your authority and on your instructions, and take the measures necessary to secure personal data against loss, alteration, or unauthorized access, having regard to its nature and the risks the processing presents. |
|
| LOPDP, comprehensive personal-data protection regime |
Secure personal data with the technical and organisational measures articles 37 to 41 require, determined from a risk, threat and vulnerability analysis, and build data protection into the design of your processing and make it the default. |
|
| Personal Data Protection and Privacy Act, 2025 from a date not yet set |
Design your technical and organisational measures to implement the data protection principles, and ensure that by default only the personal data necessary for each specific purpose is processed. |
Show the other 10 laws
| Law No. 06/L-082 on Protection of Personal Data |
Apply data protection by design and by default, keep a written record of your processing activities unless you employ fewer than two hundred and fifty people and none of the high-risk, non-occasional or special-category exceptions apply, and cooperate with the Agency for Information and Privacy on request. |
|
| Law No. 195/2024 on Personal Data Protection |
Build data protection into the design of your processing and make it the default, and keep records of your processing activities. |
|
| Loi sur la Protection des Données Personnelles |
Build data protection by design and by default into a processing operation, so that by default only the personal data necessary for each specific purpose is processed, collected, retained, or made accessible. |
|
| Loi n° 2022-59, protection des données à caractère personnel |
Keep personal data confidential and implement technical and organizational measures against unauthorized access, loss or damage, including pseudonymization, encryption, and data protection by design and by default. |
|
| Nigeria Data Protection Act, 2023 (NDPA), general data protection duties |
Before deploying data processing software that tracks a data subject or opens a communication link with one, carry out an impact assessment, design it for privacy by design and by default, put a data privacy policy inside the software, and give a prospective user a privacy statement before installation. |
|
| San Marino Law No. 171 on the Protection of Natural Persons |
Build data protection into the design of your processing and make it the default, and keep records of your processing activities. |
|
| Law on Personal Data Protection |
Build data protection into your processing by design and by default, including pseudonymization and data minimization. |
|
| Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens) proposed |
Implement data protection by design and by default, taking into account the state of the art, the cost of implementation, and the risks the processing poses to data subjects' rights and freedoms. |
|
| Draft Law No. 8153 on Personal Data Protection (GDPR-Aligned Reform) proposed |
Once enacted, implement data protection by design and by default so that only the personal data necessary for each specific purpose is processed by default. |
|
| Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended |
Adopt privacy-by-design, privacy-by-default, and data-protection impact assessment measures as part of a proactive-accountability duty, and be able to demonstrate their effective implementation. |
Sensitive categories
6 laws, 6 places| Place | Law | What it asks, as read here |
|---|---|---|
| SB 24-041, Protecting Minors' Online Data |
Do not collect a minor's precise geolocation data beyond what is necessary to provide the service, and do not use a design feature meant to significantly increase, sustain, or extend a minor's use of the service without consent. |
|
| Ley para la Protección de Datos Personales, sensitive personal data and children |
Guarantee the best interests of a child or adolescent in any processing of their data, and inform both the child and their parent or guardian, in clear and age appropriate language, before exercising the child's rights. |
|
| Law No. 025/2023, sensitive categories of personal data and children's data |
Where your online service is aimed at children, build in privacy-protective technical measures such as marking and filtering, write information for them in terms they can understand, keep advertising, entertainment and games clearly distinct from content, never incite a child to buy goods or enter an online contract, and never use prizes, rewards or links to a non-compliant site to keep them engaged. |
|
| Law on Personal Data Protection, special categories of data from a date not yet set |
Process a child's personal data in a manner that is in the best interest of the child, under Article 12. |
|
| Nigeria Data Protection Act, 2023, sensitive personal data and a child's data |
Where you deploy an emerging technology such as artificial intelligence, the Internet of Things or blockchain to process personal data, set technical and organisational parameters that take account of safeguards for sensitive personal data, safeguards for child rights and other vulnerable groups, the right against solely automated decisions, the right to be forgotten, cross-border data flows, and privacy by design and by default. |
|
| Cyber and Data Protection Regulations 2024, children's information and automated decisions |
Conduct regular data protection impact assessments to identify and mitigate privacy risks to children, and ensure data protection by design and by default when processing children's data. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.