Law / Frameworks / NIST Privacy Framework / Identify-P

NIST Privacy Framework, Identify-PID.DE-P2

Data processing ecosystem parties (e.g., service providers, customers, partners, product manufacturers, application developers) are identified, prioritized, and assessed using a privacy risk assessment process.NIST Privacy Framework, version 1.0, January 2020, ID.DE-P2

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

22
laws
20
places
0
with court rulings behind them
6
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • Antigua and Barbuda
  • Bahamas
  • Barbados
  • Bosnia and Herzegovina
  • Central African Republic
  • Côte d'Ivoire
  • Egypt
  • Ethiopia
  • Gambia
  • Grenada
  • Jamaica
  • Madagascar
  • Malaysia
  • Mali
  • Mauritania
  • Montenegro
  • Niger
  • Saint Kitts and Nevis
  • Seychelles
  • Utah

Cross border transfer

11 laws, 11 places
PlaceLawWhat it asks, as read here
Bahamas Data Protection Act 2003, cross-border transfer of personal data

Before transferring personal data collected in The Bahamas to another country, be prepared to show the recipient provides protection equivalent to this Act if the Data Protection Commissioner questions the transfer.

Barbados Data Protection Act, 2019, transfers of personal data outside of Barbados

Assess adequacy on all the circumstances before the transfer, weighing the nature of the data, the countries of origin and final destination, the purposes and period of the intended processing, the law in force and international obligations there, any enforceable codes of conduct, and the security measures taken in that country or territory.

Bosnia and Herzegovina Law on the Protection of Personal Data of Bosnia and Herzegovina, cross-border transfer

As a competent authority transferring personal data to another country or international organisation for a criminal-law purpose, apply the same adequacy-or-safeguards test and document your assessment, under Articles 91 to 95.

Central African Republic Loi n° 24.001 portant protection des données à caractère personnel, flux transfrontalier

Assess the destination's level of protection against the nature of the data, the purpose and duration of the processing, the countries of origin and destination, and the legal, professional, and security rules it applies, before any transfer.

Egypt Egypt Personal Data Protection Law, cross-border transfer of Personal Data

Before disclosing Personal Data to a Controller or Processor abroad, hold a Licence from the Center and satisfy yourself that your work or purpose corresponds, that there is a legitimate interest in the data, and that the legal and technical protection there is not below Egypt's own.

Ethiopia Personal Data Protection Proclamation, cross-border transfer and data sovereignty

Assess the level of protection in the destination jurisdiction before the transfer, weighing the nature of the data, the purpose and duration of the processing, the countries of origin and final destination, and the rules of law and security measures in force there.

Gambia Personal Data Protection and Privacy Act, 2025, transfer of personal data outside The Gambia from a date not yet set

Assess the level of protection yourself, taking into account the nature of the data, the purpose of the transfer, and the recipient country's legal regime.

Document the assessment of the safeguards or criteria that justify each transfer out of The Gambia.

Jamaica Data Protection Act, 2020, transfer of personal data outside Jamaica

Assess adequacy on the nature of the personal data, the State or territory of origin and of final destination, the purposes and period of the intended processing, the law and international obligations of the receiving State or territory, any enforceable codes of conduct there, and the security measures applied to the data.

Malaysia Personal Data Protection Act, cross-border transfer

An app transferring the personal data of an individual in Malaysia, including a faceprint, voiceprint, or other biometric identifier, to a recipient outside Malaysia must self-assess that the recipient's jurisdiction has a substantially similar law or an adequate level of protection before the transfer.

Seychelles Data Protection Act, 2023, cross-border data flows

Confirm the recipient country's processor ensures a comparable level of protection for data subjects' rights before transferring personal data outside Seychelles.

Show the other 1 law
Utah Genetic sequencing, storage of genetic information (HB 182) from , in 15 months

Beginning , if you operate a medical facility or genomic research facility, do not store Utah genetic-sequencing data within the territory of a designated foreign adversary, and do not use a genetic sequencer or sequencing software that is a final product of a foreign adversary.

Comprehensive regime

10 laws, 10 places
PlaceLawWhat it asks, as read here
Antigua and Barbuda Data Protection Act, 2013

Take practical security steps against loss, misuse, unauthorised or accidental access, disclosure, alteration or destruction of personal data, having regard to its sensitivity, where it is stored, and the reliability of personnel with access, and secure the same guarantees from any data processor you engage.

Côte d'Ivoire Law No. 2013-450 on the Protection of Personal Data

Choose a subcontractor who gives sufficient guarantees for the protection and security of the data, and ensure the subcontractor complies with this Law.

Gambia Personal Data Protection and Privacy Act, 2025 from a date not yet set

Use only a processor that provides sufficient guarantees of compliance, govern the engagement by a contract setting out the subject matter, duration, nature and purpose of the processing, and do not engage a sub-processor without the controller's prior written authorisation.

Grenada Data Protection Act, No. 1 of 2023 from a date not yet set

Take practical steps to secure personal data against loss, misuse, unauthorised access, alteration or destruction, and obtain a data processor's own security guarantees before letting it process personal data on your behalf.

Madagascar Law No. 2014-038, protection of personal data

Process data on a subcontractor's behalf only on the controller's instructions, and use only a subcontractor that offers sufficient guarantees to implement the required security measures.

Mali Loi n° 2013-015, protection des données à caractère personnel

Take every precaution useful to preserve the security of personal data, including preventing unauthorized access, deformation, or damage, and use a processor only where it offers sufficient security and confidentiality guarantees, which does not relieve you of your own duty to see those guarantees are met.

Mauritania Loi n° 2017-020, protection des données à caractère personnel

Choose a sub-processor offering sufficient guarantees, bind them by a written act limited to your instructions, and extend the confidentiality duty to anyone who takes part in the sub-processing.

Montenegro Law on Personal Data Protection from a date not yet set

Enter into a written contract before entrusting personal data processing to a processor, and use only a processor registered to carry out personal data processing and able to guarantee technical, personnel and organizational protection measures, under Article 16.

Niger Loi n° 2022-59, protection des données à caractère personnel

Choose a processor that offers sufficient security and confidentiality guarantees, govern its processing under a written confidentiality contract, and hold it to the same obligations that bind you.

Saint Kitts and Nevis Data Protection Act, 2018 from a date not yet set

Take practical steps to protect personal data from loss, misuse, unauthorised access, alteration or destruction, having regard to the nature of the data, its storage, and the personnel with access to it, and require a data processor you engage to give sufficient security guarantees and comply with them.

Breach notification

1 law, 1 place
PlaceLawWhat it asks, as read here
Jamaica Data Protection Act, 2020, reporting a contravention or security breach

Engage a data processor only where it gives sufficient guarantees as to the reporting of security breaches to you, under a written contract binding it to obligations equivalent to your own.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.