Law / Frameworks / NIST Privacy Framework / Govern-P

NIST Privacy Framework, Govern-PGV.PO-P3

Roles and responsibilities for the workforce are established with respect to privacy.NIST Privacy Framework, version 1.0, January 2020, GV.PO-P3

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

51
laws
50
places
0
with court rulings behind them
3
not yet in force
3
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Albania
  • Algeria
  • Andorra
  • Barbados
  • Belarus
  • Benin
  • Bosnia and Herzegovina
  • Botswana
  • Brazil
  • Cambodia
  • Central African Republic
  • Democratic Republic of the Congo
  • Ecuador
  • Egypt
  • El Salvador
  • Ethiopia
  • European Union
  • Gabon
  • Gambia
  • Israel
  • Jamaica
  • Jordan
  • Kosovo
  • Kyrgyzstan
  • Madagascar
  • Malaysia
  • Moldova
  • Monaco
  • Mozambique
  • Niger
  • Nigeria
  • Paraguay
  • Republic of the Congo
  • Romania
  • Rwanda
  • San Marino
  • Serbia
  • Somalia
  • South Africa
  • Spain
  • Suriname
  • Syria
  • Togo
  • Trinidad and Tobago
  • Ukraine
  • Uruguay
  • Vatican City
  • Zambia
  • Zimbabwe

Comprehensive regime

46 laws, 46 places
PlaceLawWhat it asks, as read here
Albania Law No. 124/2024 On the Protection of Personal Data

Implement data protection by design and by default in every processing tool and process, and appoint a data protection officer where processing is carried out by a public authority, requires regular and systematic large scale monitoring of data subjects, or involves large scale processing of sensitive data or criminal records.

Algeria Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11

Designate a data protection officer chosen for their professional qualifications, who may serve more than one controller given your organisational structure and size.

Andorra LQPD, Llei 29/2021 del 28 d'octubre

Appoint a Data Protection Officer if you are a public authority, or if your core activities involve automated decisions with legal effects, large-scale special-category processing, or large-scale processing that could seriously affect a large number of data subjects, and notify the Agency of that officer's contact details within ten working days of appointment.

Barbados Data Protection Act, 2019

Designate a data privacy officer where the Act requires one, give them the position and independence it prescribes, and let them carry out the duties it lists.

Belarus Law of the Republic of Belarus On Personal Data Protection

Take legal, organizational and technical measures against unauthorized or accidental access, modification, termination, copying, dissemination, transmission or erasure of personal data, appoint a data protection officer or a dedicated unit, publish your data processing policy, and train staff who handle personal data, under Article 17.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel)

Designate a data protection officer where you are a public body, or your core activities require regular and systematic large scale monitoring or large scale processing of sensitive personal data, and publish that officer's contact details.

Bosnia and Herzegovina Law on the Protection of Personal Data of Bosnia and Herzegovina

Establish a lawful basis under Article 8 before processing personal data of a person in Bosnia and Herzegovina, and appoint a Data Protection Officer under Articles 39 to 41 wherever the processing meets the threshold the Act sets, such as processing carried out by a public authority or large-scale monitoring or special-category processing.

Botswana Data Protection Act, 2024 (Act No. 18 of 2024)

Carry out a data protection impact assessment before processing that is likely to result in a high risk to a natural person's rights and freedoms, and designate a data protection officer where your core activities require regular and systematic large-scale monitoring, or large-scale processing of sensitive personal data or of data relating to criminal convictions and offences.

Brazil Lei Geral de Proteção de Dados Pessoais (LGPD)

Keep a record of your processing operations, especially those based on legitimate interest, and name a person in charge (encarregado) whose identity and contact details you publish, preferably on your website.

Cambodia Draft Law on Personal Data Protection, final draft proposed

If enacted as drafted, a data controller and processor would each have to appoint a personal data protection officer and notify the Ministry of Post and Telecommunications of that appointment within 30 working days, maintain records of processing activities, and, if located outside Cambodia, appoint a local representative.

Show the other 36 laws
Central African Republic Loi n° 24.001 portant protection des données à caractère personnel

Designate a data protection officer to keep the processing register, review new processing before it starts, consult the agency in case of doubt, and handle data subject requests; only a person residing in the Central African Republic with the necessary qualifications may hold the role, and the agency must be told before the officer is removed.

Democratic Republic of the Congo Digital Code, Title III: Personal Data Protection

Appoint a data protection officer where your processing is non-occasional, high-risk, or touches special-category or criminal-record data, and keep a written record of your processing activities available to the Data Protection Authority.

Ecuador LOPDP, comprehensive personal-data protection regime

Designate a data protection delegate where the law requires one, and let the delegate carry out the functions article 49 sets.

Egypt Law No. 151 of 2020 Promulgating the Personal Data Protection Law

Appoint a Data Protection Officer, have the officer registered in the Center's register, and let the officer carry out the duties articles 9 and 13 set.

Ethiopia Personal Data Protection Proclamation

Register with the Ethiopian Communications Authority before processing personal data, and appoint a data protection officer where the Proclamation requires one.

European Union General Data Protection Regulation (GDPR), Comprehensive Regime

Allocate and document controller and processor responsibilities in a written agreement wherever a third party processes personal data on your behalf, and appoint a Data Protection Officer where your core activities involve large scale monitoring or large scale special category processing.

Gabon Loi n°001/2011 relative à la protection des données à caractère personnel, modifiée par la loi n°025/2023

Designate a data protection officer, notify the APDPVP of the designation, and give the officer the office, resources and independence to advise you, monitor compliance, and liaise with the APDPVP, where you are a public authority, carry out large-scale systematic monitoring, or process sensitive or criminal-offence data at scale.

Gambia Personal Data Protection and Privacy Act, 2025 from a date not yet set

Designate a data protection officer if you are a public authority, or if you engage in large-scale monitoring or large-scale processing of sensitive data.

Israel Protection of Privacy Law, comprehensive regime and database registration

An app that operates a database of the personal data of individuals in Israel above the small-collection thresholds must register with, or separately notify, the Privacy Protection Authority under Art. 8A, and must name a Data Protection Officer where the Act requires one.

Jamaica Data Protection Act, 2020, registration, lawful basis and standards for processing

Appoint a qualified data protection officer with no conflict of interest if you are a public authority, process sensitive personal data or data relating to criminal convictions, or process personal data on a large scale, and give the Commissioner that officer's name and contact information.

Jordan Personal Data Protection Law, comprehensive regime and lawful basis

An app that collects, uses, or discloses the personal data of an individual in Jordan must obtain consent or rely on one of the Law's enumerated alternative bases, must confine retention to the processing purpose unless legislation specifies otherwise, and must appoint a data-protection lead if it processes Sensitive Personal Data or transfers personal data to a database outside Jordan.

Kosovo Law No. 06/L-082 on Protection of Personal Data

Appoint a Data Protection Officer if you are a public authority, or if your core activities require regular and systematic large-scale monitoring of data subjects or large-scale processing of special categories of data or criminal-offence data, and publish that officer's contact details to the Agency.

Kyrgyzstan Digital Code, comprehensive personal data regime

An app that collects, uses, or discloses the personal data of individuals in Kyrgyzstan must process it lawfully, fairly, and transparently, limit use to the stated purpose, minimize what is collected, keep it accurate, and limit retention to the processing purpose. An organization with more than ten employees must designate a personal-data-responsible person and provide staff training.

Madagascar Law No. 2014-038, protection of personal data

Designate a data protection officer to keep the processing register current, advise on new processing before it starts, take in data subjects' requests and complaints, and escalate an uncorrected breach to the CMIL.

Moldova Law No. 195/2024 on Personal Data Protection

Designate a data protection officer where the law requires one, give them the position article 38 prescribes, and let them carry out the tasks article 39 lists.

Monaco Loi sur la Protection des Données Personnelles

Designate a data protection officer wherever you are a public body, your core activities require large scale regular and systematic monitoring, or your core activities involve large scale processing of sensitive or criminal record data, and let that officer report to top management free of instructions.

Mozambique Electronic Transactions Law, Protection of Personal Electronic Data

Designate one or more individuals responsible for compliance with this chapter's data protection principles.

Niger Loi n° 2022-59, protection des données à caractère personnel

Appoint a data-protection correspondent within your organization and notify the appointment to the HAPDP; a public-sector controller appoints a focal point instead.

Nigeria Nigeria Data Protection Act, 2023 (NDPA), general data protection duties

Designate a Data Protection Officer as section 32 of the Act mandates, give the officer the position the Directive prescribes, and have the officer prepare semi-annual data protection reports.

Paraguay Ley N° 7593/2025, de Protección de Datos Personales en la República del Paraguay from , in 14 months

Appoint a data protection officer as article 18 provides.

Québec Act respecting the protection of personal information in the private sector, comprehensive regime

Designate a person in charge of the protection of personal information, by default your enterprise's highest-ranking officer, and publish that person's title and contact information on your website.

Republic of the Congo Law No. 29-2019 on the Protection of Personal Data

Carry out a data protection impact assessment before a type of processing likely to create a high risk to the rights and freedoms of natural persons, and designate a data protection officer where article 83 requires one.

Rwanda Law relating to the Protection of Personal Data and Privacy

Register with the supervisory authority as a data controller or data processor before processing personal data, and designate a data protection officer where article 40 requires one.

San Marino San Marino Law No. 171 on the Protection of Natural Persons

Designate a data protection officer where the law requires one, give them the position article 39 prescribes, and let them carry out the tasks article 40 lists.

Serbia Law on Personal Data Protection

Designate a data protection officer where a government body processes personal data, where core activities require regular and systematic large-scale monitoring, or where core activities involve large-scale processing of special categories of personal data, and give that officer the independence and resources Article 58 requires.

Somalia Data Protection Act No. 005 of 2023

As a data controller of major importance, register with the Authority within six months of qualifying, and designate a data protection officer.

South Africa Protection of Personal Information Act 4 of 2013 (POPIA)

Register your information officer with the Information Regulator before that officer takes up duties under the Act.

Spain Ley Orgánica 3/2018 (LOPDGDD), GDPR-Aligned Comprehensive Regime

Follow LOPDGDD Titulo V's controller and processor obligations, including its DPO qualification rule at Article 35.

Suriname Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens) proposed

Appoint a data protection officer to advise you and your staff on this law's duties, liaise with the Commissioner, and act as the contact point for data subjects exercising their rights.

Syria Law No. 12 of 2024 on Protection of Electronic Personal Data

Take the technical and organizational security measures the Authority approves to protect personal data against unauthorized or unlawful processing and against loss or damage, and appoint a data protection officer, registered with the Authority, if you are a legal person.

Togo Loi n° 2019-014, protection des données à caractère personnel

Where you appoint a data protection correspondent to qualify for the formality exemption, notify the appointment to the Instance and have the correspondent advise on compliance, cooperate with the Instance, and keep an accessible list of the processing you carry out.

Ukraine Draft Law No. 8153 on Personal Data Protection (GDPR-Aligned Reform) proposed

Once enacted, appoint a data protection officer where you regularly and systematically monitor data subjects at large scale, process large volumes of sensitive data, or process biometric or genetic data of a person in Ukraine.

Uruguay Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended

If a public entity, a wholly or partly state-owned entity, or a private entity that processes sensitive data as a main line of business or processes large volumes of data, designate a data-protection officer with technical autonomy.

Vatican City General Regulation on the Protection of Personal Data for Vatican City State

Where this Regulation binds your processing, identify the Data Controller as the Governorate, represented by the General Secretary, and put in place organizational and technical security measures suitable to protect the personal data you process. Appoint a Representative in writing where the Regulation calls for one, and record the activity in the Register of treatment activities.

Zambia Data Protection Act, 2021, personal data processing framework

Appoint a data protection officer in accordance with the Commissioner's guidelines.

Zimbabwe Cyber and Data Protection Act [Chapter 12:07]

Notify the Authority of the appointment of your data protection officer, and have the officer ensure compliance, handle requests made to you and work with the Authority.

Enforcement supervision

2 laws, 2 places
PlaceLawWhat it asks, as read here
Trinidad and Tobago Data Protection Act, 2011, Commissioner, contravention and enforcement

Once Part IV is in force, every director and officer of a corporation must take reasonable care to ensure the corporation complies with the Act, the Regulations, and any Commissioner order.

Zimbabwe Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024

Appoint a certified data protection officer and notify the Authority of the appointment in writing.

Appoint the data protection officer within ninety days of the Regulations' promulgation or of a contract ending, and tell the Authority in writing within fourteen days of any change to the officer's number, email address or physical address, or of their dismissal or resignation.

Breach notification

1 law, 1 place
PlaceLawWhat it asks, as read here
Malaysia Personal Data Protection Act, data protection officer and breach notification

An app that controls or processes the personal data of individuals in Malaysia must appoint a Data Protection Officer, and a data controller who reasonably believes a personal data breach has occurred must notify the Commissioner as soon as practicable, and must notify affected data subjects without unnecessary delay where the breach causes or is likely to cause significant harm.

Data subject rights

1 law, 1 place
PlaceLawWhat it asks, as read here
El Salvador Ley para la Protección de Datos Personales, rights of data subjects

Appoint a delegate to manage ARCO-POL requests and answer them within twenty business days, extendable once by another twenty for justified cause, referring an incompetent request within five business days and notifying anyone who received the corrected or deleted data within five business days of granting a request.

Sensitive categories

1 law, 1 place
PlaceLawWhat it asks, as read here
Romania GDPR Article 9 and Law 190/2018 Automated Decision-Making and CNP Rules from a date not yet set

Appoint a Data Protection Officer and set specific retention and deletion deadlines if relying on legitimate interests to process a Romanian national identification number, per commentary describing the Act; verify against the Act's own text before relying on it.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.