Law / Frameworks / NIST Privacy Framework / Govern-P
NIST Privacy Framework, Govern-PGV.PO-P4
Privacy roles and responsibilities are coordinated and aligned with third-party stakeholders (e.g., service providers, customers, partners).NIST Privacy Framework, version 1.0, January 2020, GV.PO-P4
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 9
- laws
- 9
- places
- 0
- with court rulings behind them
- 1
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 6.1 Policies and procedures are in place that address AI risks associated with third-party...
- NIST AI RMFMANAGE 3.1 AI risks and benefits from third-party resources are regularly monitored, and risk...
- NIST AI 600-1GAI-RISK-12 Value Chain and Component Integration
- MIT mitigations3.3 Access Management
- NIST CSF 2.0GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are...
- NIST CSF 2.0GV.SC-05 Requirements to address cybersecurity risks in supply chains are established,...
A law in force is unmarked; the rest wear their state: not yet in force
Comprehensive regime
8 laws, 8 places| Place | Law | What it asks, as read here |
|---|---|---|
| Ley 25.326, Ley de Protección de los Datos Personales |
As a data-processing service provider acting for another party, use the personal data only for the purpose stated in the service contract, do not disclose it to others, and destroy it once the contracted service ends unless further engagements are reasonably expected, in which case you may keep it securely for up to two years. |
|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel) |
Where two or more controllers jointly determine the purposes and means of a processing, allocate your respective obligations toward data subjects in a transparent arrangement made available to them. |
|
| Personal Data Protection and Privacy Act, 2025 from a date not yet set |
Where you determine the purposes and means of processing jointly with another controller, specify each party's compliance responsibilities. |
|
| Telecommunications Act of 2007, Protection of Personal Information (§§ 51-52) |
Be responsible for customer information and customer communications in your custody or control, or in the custody or control of your agents. |
|
| Law No. 195/2024 on Personal Data Protection |
Establish a lawful basis and allocate controller and processor duties before processing personal data of a person in Moldova. Where you engage a processor, govern the engagement as article 28 requires, and settle each party's responsibilities in an arrangement where you are a joint controller. |
|
| Electronic Transactions Law, Protection of Personal Electronic Data |
Remain responsible for personal data in your possession or custody, including data you transferred to a third party for processing. |
|
| Loi n° 2022-59, protection des données à caractère personnel |
Where two or more controllers jointly determine the purposes and means of processing, define transparently each one's role toward data subjects, who may exercise their rights against each of them. |
|
| San Marino Law No. 171 on the Protection of Natural Persons |
Where you engage a processor, govern the engagement as article 29 requires, and settle each party's responsibilities in an arrangement where you are a joint controller. |
Cross border transfer
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Ley 81 de 2019, cross border transfer of personal data |
Remain responsible, as the party transferring or receiving personal data internationally, for the lawfulness of the processing you send or take in. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.