Law / Frameworks / NIST Privacy Framework / Govern-P

NIST Privacy Framework, Govern-PGV.PO-P4

Privacy roles and responsibilities are coordinated and aligned with third-party stakeholders (e.g., service providers, customers, partners).NIST Privacy Framework, version 1.0, January 2020, GV.PO-P4

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

9
laws
9
places
0
with court rulings behind them
1
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • Argentina
  • Benin
  • Gambia
  • Liberia
  • Moldova
  • Mozambique
  • Niger
  • Panama
  • San Marino

Comprehensive regime

8 laws, 8 places
PlaceLawWhat it asks, as read here
Argentina Ley 25.326, Ley de Protección de los Datos Personales

As a data-processing service provider acting for another party, use the personal data only for the purpose stated in the service contract, do not disclose it to others, and destroy it once the contracted service ends unless further engagements are reasonably expected, in which case you may keep it securely for up to two years.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel)

Where two or more controllers jointly determine the purposes and means of a processing, allocate your respective obligations toward data subjects in a transparent arrangement made available to them.

Gambia Personal Data Protection and Privacy Act, 2025 from a date not yet set

Where you determine the purposes and means of processing jointly with another controller, specify each party's compliance responsibilities.

Liberia Telecommunications Act of 2007, Protection of Personal Information (§§ 51-52)

Be responsible for customer information and customer communications in your custody or control, or in the custody or control of your agents.

Moldova Law No. 195/2024 on Personal Data Protection

Establish a lawful basis and allocate controller and processor duties before processing personal data of a person in Moldova.

Where you engage a processor, govern the engagement as article 28 requires, and settle each party's responsibilities in an arrangement where you are a joint controller.

Mozambique Electronic Transactions Law, Protection of Personal Electronic Data

Remain responsible for personal data in your possession or custody, including data you transferred to a third party for processing.

Niger Loi n° 2022-59, protection des données à caractère personnel

Where two or more controllers jointly determine the purposes and means of processing, define transparently each one's role toward data subjects, who may exercise their rights against each of them.

San Marino San Marino Law No. 171 on the Protection of Natural Persons

Where you engage a processor, govern the engagement as article 29 requires, and settle each party's responsibilities in an arrangement where you are a joint controller.

Cross border transfer

1 law, 1 place
PlaceLawWhat it asks, as read here
Panama Ley 81 de 2019, cross border transfer of personal data

Remain responsible, as the party transferring or receiving personal data internationally, for the lawfulness of the processing you send or take in.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.