Law / Frameworks / NIST Privacy Framework / Identify-P
NIST Privacy Framework, Identify-PID.DE-P2
Data processing ecosystem parties (e.g., service providers, customers, partners, product manufacturers, application developers) are identified, prioritized, and assessed using a privacy risk assessment process.NIST Privacy Framework, version 1.0, January 2020, ID.DE-P2
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 22
- laws
- 20
- places
- 0
- with court rulings behind them
- 6
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 6.1 Policies and procedures are in place that address AI risks associated with third-party...
- NIST AI RMFMANAGE 3.1 AI risks and benefits from third-party resources are regularly monitored, and risk...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-12 Value Chain and Component Integration
- MIT mitigations3.2 Data Governance
- MIT mitigations3.3 Access Management
- NIST CSF 2.0GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are...
- NIST CSF 2.0GV.SC-05 Requirements to address cybersecurity risks in supply chains are established,...
A law in force is unmarked; the rest wear their state: not yet in force
Cross border transfer
11 laws, 11 places| Place | Law | What it asks, as read here |
|---|---|---|
| Data Protection Act 2003, cross-border transfer of personal data |
Before transferring personal data collected in The Bahamas to another country, be prepared to show the recipient provides protection equivalent to this Act if the Data Protection Commissioner questions the transfer. |
|
| Data Protection Act, 2019, transfers of personal data outside of Barbados |
Assess adequacy on all the circumstances before the transfer, weighing the nature of the data, the countries of origin and final destination, the purposes and period of the intended processing, the law in force and international obligations there, any enforceable codes of conduct, and the security measures taken in that country or territory. |
|
| Law on the Protection of Personal Data of Bosnia and Herzegovina, cross-border transfer |
As a competent authority transferring personal data to another country or international organisation for a criminal-law purpose, apply the same adequacy-or-safeguards test and document your assessment, under Articles 91 to 95. |
|
| Loi n° 24.001 portant protection des données à caractère personnel, flux transfrontalier |
Assess the destination's level of protection against the nature of the data, the purpose and duration of the processing, the countries of origin and destination, and the legal, professional, and security rules it applies, before any transfer. |
|
| Egypt Personal Data Protection Law, cross-border transfer of Personal Data |
Before disclosing Personal Data to a Controller or Processor abroad, hold a Licence from the Center and satisfy yourself that your work or purpose corresponds, that there is a legitimate interest in the data, and that the legal and technical protection there is not below Egypt's own. |
|
| Personal Data Protection Proclamation, cross-border transfer and data sovereignty |
Assess the level of protection in the destination jurisdiction before the transfer, weighing the nature of the data, the purpose and duration of the processing, the countries of origin and final destination, and the rules of law and security measures in force there. |
|
| Personal Data Protection and Privacy Act, 2025, transfer of personal data outside The Gambia from a date not yet set |
Assess the level of protection yourself, taking into account the nature of the data, the purpose of the transfer, and the recipient country's legal regime. Document the assessment of the safeguards or criteria that justify each transfer out of The Gambia. |
|
| Data Protection Act, 2020, transfer of personal data outside Jamaica |
Assess adequacy on the nature of the personal data, the State or territory of origin and of final destination, the purposes and period of the intended processing, the law and international obligations of the receiving State or territory, any enforceable codes of conduct there, and the security measures applied to the data. |
|
| Personal Data Protection Act, cross-border transfer |
An app transferring the personal data of an individual in Malaysia, including a faceprint, voiceprint, or other biometric identifier, to a recipient outside Malaysia must self-assess that the recipient's jurisdiction has a substantially similar law or an adequate level of protection before the transfer. |
|
| Data Protection Act, 2023, cross-border data flows |
Confirm the recipient country's processor ensures a comparable level of protection for data subjects' rights before transferring personal data outside Seychelles. |
Show the other 1 law
| Genetic sequencing, storage of genetic information (HB 182) from , in 15 months |
Beginning , if you operate a medical facility or genomic research facility, do not store Utah genetic-sequencing data within the territory of a designated foreign adversary, and do not use a genetic sequencer or sequencing software that is a final product of a foreign adversary. |
Comprehensive regime
10 laws, 10 places| Place | Law | What it asks, as read here |
|---|---|---|
| Data Protection Act, 2013 |
Take practical security steps against loss, misuse, unauthorised or accidental access, disclosure, alteration or destruction of personal data, having regard to its sensitivity, where it is stored, and the reliability of personnel with access, and secure the same guarantees from any data processor you engage. |
|
| Law No. 2013-450 on the Protection of Personal Data |
Choose a subcontractor who gives sufficient guarantees for the protection and security of the data, and ensure the subcontractor complies with this Law. |
|
| Personal Data Protection and Privacy Act, 2025 from a date not yet set |
Use only a processor that provides sufficient guarantees of compliance, govern the engagement by a contract setting out the subject matter, duration, nature and purpose of the processing, and do not engage a sub-processor without the controller's prior written authorisation. |
|
| Data Protection Act, No. 1 of 2023 from a date not yet set |
Take practical steps to secure personal data against loss, misuse, unauthorised access, alteration or destruction, and obtain a data processor's own security guarantees before letting it process personal data on your behalf. |
|
| Law No. 2014-038, protection of personal data |
Process data on a subcontractor's behalf only on the controller's instructions, and use only a subcontractor that offers sufficient guarantees to implement the required security measures. |
|
| Loi n° 2013-015, protection des données à caractère personnel |
Take every precaution useful to preserve the security of personal data, including preventing unauthorized access, deformation, or damage, and use a processor only where it offers sufficient security and confidentiality guarantees, which does not relieve you of your own duty to see those guarantees are met. |
|
| Loi n° 2017-020, protection des données à caractère personnel |
Choose a sub-processor offering sufficient guarantees, bind them by a written act limited to your instructions, and extend the confidentiality duty to anyone who takes part in the sub-processing. |
|
| Law on Personal Data Protection from a date not yet set |
Enter into a written contract before entrusting personal data processing to a processor, and use only a processor registered to carry out personal data processing and able to guarantee technical, personnel and organizational protection measures, under Article 16. |
|
| Loi n° 2022-59, protection des données à caractère personnel |
Choose a processor that offers sufficient security and confidentiality guarantees, govern its processing under a written confidentiality contract, and hold it to the same obligations that bind you. |
|
| Data Protection Act, 2018 from a date not yet set |
Take practical steps to protect personal data from loss, misuse, unauthorised access, alteration or destruction, having regard to the nature of the data, its storage, and the personnel with access to it, and require a data processor you engage to give sufficient security guarantees and comply with them. |
Breach notification
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Data Protection Act, 2020, reporting a contravention or security breach |
Engage a data processor only where it gives sufficient guarantees as to the reporting of security breaches to you, under a written contract binding it to obligations equivalent to your own. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.