Law / Frameworks / NIST Privacy Framework / Govern-P
NIST Privacy Framework, Govern-PGV.PO-P3
Roles and responsibilities for the workforce are established with respect to privacy.NIST Privacy Framework, version 1.0, January 2020, GV.PO-P3
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 51
- laws
- 50
- places
- 0
- with court rulings behind them
- 3
- not yet in force
- 3
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.4 The risk management process and its outcomes are established through transparent...
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations1.1 Board Structure & Oversight
- MIT mitigations1.2 Risk Management
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and...
A law in force is unmarked; the rest wear their state: not yet in force proposed
Comprehensive regime
46 laws, 46 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 124/2024 On the Protection of Personal Data |
Implement data protection by design and by default in every processing tool and process, and appoint a data protection officer where processing is carried out by a public authority, requires regular and systematic large scale monitoring of data subjects, or involves large scale processing of sensitive data or criminal records. |
|
| Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11 |
Designate a data protection officer chosen for their professional qualifications, who may serve more than one controller given your organisational structure and size. |
|
| LQPD, Llei 29/2021 del 28 d'octubre |
Appoint a Data Protection Officer if you are a public authority, or if your core activities involve automated decisions with legal effects, large-scale special-category processing, or large-scale processing that could seriously affect a large number of data subjects, and notify the Agency of that officer's contact details within ten working days of appointment. |
|
| Data Protection Act, 2019 |
Designate a data privacy officer where the Act requires one, give them the position and independence it prescribes, and let them carry out the duties it lists. |
|
| Law of the Republic of Belarus On Personal Data Protection |
Take legal, organizational and technical measures against unauthorized or accidental access, modification, termination, copying, dissemination, transmission or erasure of personal data, appoint a data protection officer or a dedicated unit, publish your data processing policy, and train staff who handle personal data, under Article 17. |
|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel) |
Designate a data protection officer where you are a public body, or your core activities require regular and systematic large scale monitoring or large scale processing of sensitive personal data, and publish that officer's contact details. |
|
| Law on the Protection of Personal Data of Bosnia and Herzegovina |
Establish a lawful basis under Article 8 before processing personal data of a person in Bosnia and Herzegovina, and appoint a Data Protection Officer under Articles 39 to 41 wherever the processing meets the threshold the Act sets, such as processing carried out by a public authority or large-scale monitoring or special-category processing. |
|
| Data Protection Act, 2024 (Act No. 18 of 2024) |
Carry out a data protection impact assessment before processing that is likely to result in a high risk to a natural person's rights and freedoms, and designate a data protection officer where your core activities require regular and systematic large-scale monitoring, or large-scale processing of sensitive personal data or of data relating to criminal convictions and offences. |
|
| Lei Geral de Proteção de Dados Pessoais (LGPD) |
Keep a record of your processing operations, especially those based on legitimate interest, and name a person in charge (encarregado) whose identity and contact details you publish, preferably on your website. |
|
| Draft Law on Personal Data Protection, final draft proposed |
If enacted as drafted, a data controller and processor would each have to appoint a personal data protection officer and notify the Ministry of Post and Telecommunications of that appointment within 30 working days, maintain records of processing activities, and, if located outside Cambodia, appoint a local representative. |
Show the other 36 laws
| Loi n° 24.001 portant protection des données à caractère personnel |
Designate a data protection officer to keep the processing register, review new processing before it starts, consult the agency in case of doubt, and handle data subject requests; only a person residing in the Central African Republic with the necessary qualifications may hold the role, and the agency must be told before the officer is removed. |
|
| Digital Code, Title III: Personal Data Protection |
Appoint a data protection officer where your processing is non-occasional, high-risk, or touches special-category or criminal-record data, and keep a written record of your processing activities available to the Data Protection Authority. |
|
| LOPDP, comprehensive personal-data protection regime |
Designate a data protection delegate where the law requires one, and let the delegate carry out the functions article 49 sets. |
|
| Law No. 151 of 2020 Promulgating the Personal Data Protection Law |
Appoint a Data Protection Officer, have the officer registered in the Center's register, and let the officer carry out the duties articles 9 and 13 set. |
|
| Personal Data Protection Proclamation |
Register with the Ethiopian Communications Authority before processing personal data, and appoint a data protection officer where the Proclamation requires one. |
|
| General Data Protection Regulation (GDPR), Comprehensive Regime |
Allocate and document controller and processor responsibilities in a written agreement wherever a third party processes personal data on your behalf, and appoint a Data Protection Officer where your core activities involve large scale monitoring or large scale special category processing. |
|
| Loi n°001/2011 relative à la protection des données à caractère personnel, modifiée par la loi n°025/2023 |
Designate a data protection officer, notify the APDPVP of the designation, and give the officer the office, resources and independence to advise you, monitor compliance, and liaise with the APDPVP, where you are a public authority, carry out large-scale systematic monitoring, or process sensitive or criminal-offence data at scale. |
|
| Personal Data Protection and Privacy Act, 2025 from a date not yet set |
Designate a data protection officer if you are a public authority, or if you engage in large-scale monitoring or large-scale processing of sensitive data. |
|
| Protection of Privacy Law, comprehensive regime and database registration |
An app that operates a database of the personal data of individuals in Israel above the small-collection thresholds must register with, or separately notify, the Privacy Protection Authority under Art. 8A, and must name a Data Protection Officer where the Act requires one. |
|
| Data Protection Act, 2020, registration, lawful basis and standards for processing |
Appoint a qualified data protection officer with no conflict of interest if you are a public authority, process sensitive personal data or data relating to criminal convictions, or process personal data on a large scale, and give the Commissioner that officer's name and contact information. |
|
| Personal Data Protection Law, comprehensive regime and lawful basis |
An app that collects, uses, or discloses the personal data of an individual in Jordan must obtain consent or rely on one of the Law's enumerated alternative bases, must confine retention to the processing purpose unless legislation specifies otherwise, and must appoint a data-protection lead if it processes Sensitive Personal Data or transfers personal data to a database outside Jordan. |
|
| Law No. 06/L-082 on Protection of Personal Data |
Appoint a Data Protection Officer if you are a public authority, or if your core activities require regular and systematic large-scale monitoring of data subjects or large-scale processing of special categories of data or criminal-offence data, and publish that officer's contact details to the Agency. |
|
| Digital Code, comprehensive personal data regime |
An app that collects, uses, or discloses the personal data of individuals in Kyrgyzstan must process it lawfully, fairly, and transparently, limit use to the stated purpose, minimize what is collected, keep it accurate, and limit retention to the processing purpose. An organization with more than ten employees must designate a personal-data-responsible person and provide staff training. |
|
| Law No. 2014-038, protection of personal data |
Designate a data protection officer to keep the processing register current, advise on new processing before it starts, take in data subjects' requests and complaints, and escalate an uncorrected breach to the CMIL. |
|
| Law No. 195/2024 on Personal Data Protection |
Designate a data protection officer where the law requires one, give them the position article 38 prescribes, and let them carry out the tasks article 39 lists. |
|
| Loi sur la Protection des Données Personnelles |
Designate a data protection officer wherever you are a public body, your core activities require large scale regular and systematic monitoring, or your core activities involve large scale processing of sensitive or criminal record data, and let that officer report to top management free of instructions. |
|
| Electronic Transactions Law, Protection of Personal Electronic Data |
Designate one or more individuals responsible for compliance with this chapter's data protection principles. |
|
| Loi n° 2022-59, protection des données à caractère personnel |
Appoint a data-protection correspondent within your organization and notify the appointment to the HAPDP; a public-sector controller appoints a focal point instead. |
|
| Nigeria Data Protection Act, 2023 (NDPA), general data protection duties |
Designate a Data Protection Officer as section 32 of the Act mandates, give the officer the position the Directive prescribes, and have the officer prepare semi-annual data protection reports. |
|
| Ley N° 7593/2025, de Protección de Datos Personales en la República del Paraguay from , in 14 months |
Appoint a data protection officer as article 18 provides. |
|
| Québec | Act respecting the protection of personal information in the private sector, comprehensive regime |
Designate a person in charge of the protection of personal information, by default your enterprise's highest-ranking officer, and publish that person's title and contact information on your website. |
| Law No. 29-2019 on the Protection of Personal Data |
Carry out a data protection impact assessment before a type of processing likely to create a high risk to the rights and freedoms of natural persons, and designate a data protection officer where article 83 requires one. |
|
| Law relating to the Protection of Personal Data and Privacy |
Register with the supervisory authority as a data controller or data processor before processing personal data, and designate a data protection officer where article 40 requires one. |
|
| San Marino Law No. 171 on the Protection of Natural Persons |
Designate a data protection officer where the law requires one, give them the position article 39 prescribes, and let them carry out the tasks article 40 lists. |
|
| Law on Personal Data Protection |
Designate a data protection officer where a government body processes personal data, where core activities require regular and systematic large-scale monitoring, or where core activities involve large-scale processing of special categories of personal data, and give that officer the independence and resources Article 58 requires. |
|
| Data Protection Act No. 005 of 2023 |
As a data controller of major importance, register with the Authority within six months of qualifying, and designate a data protection officer. |
|
| Protection of Personal Information Act 4 of 2013 (POPIA) |
Register your information officer with the Information Regulator before that officer takes up duties under the Act. |
|
| Ley Orgánica 3/2018 (LOPDGDD), GDPR-Aligned Comprehensive Regime |
Follow LOPDGDD Titulo V's controller and processor obligations, including its DPO qualification rule at Article 35. |
|
| Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens) proposed |
Appoint a data protection officer to advise you and your staff on this law's duties, liaise with the Commissioner, and act as the contact point for data subjects exercising their rights. |
|
| Law No. 12 of 2024 on Protection of Electronic Personal Data |
Take the technical and organizational security measures the Authority approves to protect personal data against unauthorized or unlawful processing and against loss or damage, and appoint a data protection officer, registered with the Authority, if you are a legal person. |
|
| Loi n° 2019-014, protection des données à caractère personnel |
Where you appoint a data protection correspondent to qualify for the formality exemption, notify the appointment to the Instance and have the correspondent advise on compliance, cooperate with the Instance, and keep an accessible list of the processing you carry out. |
|
| Draft Law No. 8153 on Personal Data Protection (GDPR-Aligned Reform) proposed |
Once enacted, appoint a data protection officer where you regularly and systematically monitor data subjects at large scale, process large volumes of sensitive data, or process biometric or genetic data of a person in Ukraine. |
|
| Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended |
If a public entity, a wholly or partly state-owned entity, or a private entity that processes sensitive data as a main line of business or processes large volumes of data, designate a data-protection officer with technical autonomy. |
|
| General Regulation on the Protection of Personal Data for Vatican City State |
Where this Regulation binds your processing, identify the Data Controller as the Governorate, represented by the General Secretary, and put in place organizational and technical security measures suitable to protect the personal data you process. Appoint a Representative in writing where the Regulation calls for one, and record the activity in the Register of treatment activities. |
|
| Data Protection Act, 2021, personal data processing framework |
Appoint a data protection officer in accordance with the Commissioner's guidelines. |
|
| Cyber and Data Protection Act [Chapter 12:07] |
Notify the Authority of the appointment of your data protection officer, and have the officer ensure compliance, handle requests made to you and work with the Authority. |
Enforcement supervision
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Data Protection Act, 2011, Commissioner, contravention and enforcement |
Once Part IV is in force, every director and officer of a corporation must take reasonable care to ensure the corporation complies with the Act, the Regulations, and any Commissioner order. |
|
| Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 |
Appoint a certified data protection officer and notify the Authority of the appointment in writing. Appoint the data protection officer within ninety days of the Regulations' promulgation or of a contract ending, and tell the Authority in writing within fourteen days of any change to the officer's number, email address or physical address, or of their dismissal or resignation. |
Breach notification
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Personal Data Protection Act, data protection officer and breach notification |
An app that controls or processes the personal data of individuals in Malaysia must appoint a Data Protection Officer, and a data controller who reasonably believes a personal data breach has occurred must notify the Commissioner as soon as practicable, and must notify affected data subjects without unnecessary delay where the breach causes or is likely to cause significant harm. |
Data subject rights
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Ley para la Protección de Datos Personales, rights of data subjects |
Appoint a delegate to manage ARCO-POL requests and answer them within twenty business days, extendable once by another twenty for justified cause, referring an incompetent request within five business days and notifying anyone who received the corrected or deleted data within five business days of granting a request. |
Sensitive categories
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| GDPR Article 9 and Law 190/2018 Automated Decision-Making and CNP Rules from a date not yet set |
Appoint a Data Protection Officer and set specific retention and deletion deadlines if relying on legitimate interests to process a Romanian national identification number, per commentary describing the Act; verify against the Act's own text before relying on it. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.