Law / Frameworks / NIST Privacy Framework / Identify-P
NIST Privacy Framework, Identify-PID.DE-P3
Contracts with data processing ecosystem parties are used to implement appropriate measures designed to meet the objectives of an organization’s privacy program.NIST Privacy Framework, version 1.0, January 2020, ID.DE-P3
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 54
- laws
- 47
- places
- 0
- with court rulings behind them
- 4
- not yet in force
- 1
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 6.1 Policies and procedures are in place that address AI risks associated with third-party...
- NIST AI RMFMANAGE 3.1 AI risks and benefits from third-party resources are regularly monitored, and risk...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-12 Value Chain and Component Integration
- MIT mitigations3.2 Data Governance
- MIT mitigations3.3 Access Management
- NIST CSF 2.0GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are...
- NIST CSF 2.0GV.SC-05 Requirements to address cybersecurity risks in supply chains are established,...
A law in force is unmarked; the rest wear their state: not yet in force proposed
Comprehensive regime
40 laws, 40 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 124/2024 On the Protection of Personal Data |
Keep personal data confidential wherever an employee or processor has access to it for professional reasons, bind that confidentiality into every processor contract and employment contract, and continue it after the contract or employment ends. |
|
| Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11 |
Implement technical and organisational measures appropriate to the risk, and choose a processor only for the sufficiency of its own security guarantees, governed by a written contract. |
|
| Law on the Protection of Personal Data |
Treat a recipient who processes communicated personal data for its own purposes as a controller in its own right, and one who processes it on your behalf and under your instructions as a subcontractor bound by a written contract, and obtain the APD's authorisation before interconnecting personal data held in different files unless a legal provision already permits it. |
|
| Datenschutzgesetz (DSG), Data Protection Act |
Allocate and document controller and processor responsibilities in a written agreement wherever a third party processes personal data on your behalf, following GDPR Articles 24 to 28. |
|
| Law of the Republic of Belarus On Personal Data Protection |
Fix the purposes, permitted actions, confidentiality duty and protection measures in a contract, act of legislation or public authority decision before entrusting processing to an authorized person, under Article 7, and remain responsible to the personal data subject for that person's actions. |
|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel) |
Choose a processor offering sufficient security and confidentiality guarantees, fix the processor's obligations in a written contract, and ensure the processor acts only on your documented instructions. |
|
| Loi n°001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel |
Before using a processor, choose one that offers sufficient guarantees of protection, and sign a written agreement with it fixing the processing operations it may carry out and what happens to the data when the contract ends. |
|
| Law No. 133/V/2001 on the Protection of Personal Data |
Implement technical and organisational measures adequate to the risk to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, and choose a processor offering sufficient security guarantees under a written contract that binds them to your instructions. |
|
| Personal Information Protection and Electronic Documents Act (PIPEDA) |
Remain accountable for personal information transferred to a third party for processing, in Canada or abroad, and use contractual or other means to ensure a comparable level of protection. |
|
| Loi n° 24.001 portant protection des données à caractère personnel |
Process personal data as a subcontractor only on the controller's instruction, offer sufficient guarantees to implement security and confidentiality measures, and put those obligations in the contract with the controller. |
Show the other 30 laws
| Personal Information Protection Law of the PRC, General Processing Rules and Lawful Bases |
Where personal information is entrusted to a third party processor, execute a written entrustment agreement and supervise that processor's handling; the processor may not exceed the agreed purpose or method and must return or delete the data when the entrustment ends. Where two or more processors jointly decide a shared processing purpose and method, agree in writing on each party's respective duties; the individual may still exercise rights against any one of them, and the processors bear joint and several liability for resulting harm. |
|
| Law on the Protection of Personal Data |
Confine a sub processor to your instructions under a written contract addressing security and confidentiality, without relieving yourself of the duty to see those measures respected. |
|
| Digital Code, Title III: Personal Data Protection |
Govern any processor's engagement by a written contract confining it to your documented instructions, and require the processor not to engage a sub-processor without your prior written authorization. |
|
| Ley para la Protección de Datos Personales |
Document your ARCO-POL request procedures, and hold any subcontractor with access to personal data to this Law. |
|
| Data Protection Act, 2022 (Act No. 5 of 2022) |
Take appropriate, reasonable technical and administrative measures to secure the integrity of personal information in your possession or under your control against loss, modification, damage, unauthorised destruction or unlawful access, and govern any data processor who processes information on your behalf by a written contract that requires the same measures. |
|
| General Data Protection Regulation (GDPR), Comprehensive Regime |
Allocate and document controller and processor responsibilities in a written agreement wherever a third party processes personal data on your behalf, and appoint a Data Protection Officer where your core activities involve large scale monitoring or large scale special category processing. |
|
| Loi n°001/2011 relative à la protection des données à caractère personnel, modifiée par la loi n°025/2023 |
Keep processing confidential, bind everyone who processes the data under your authority to a signed written undertaking, and impose the same security and confidentiality guarantees on any processor by contract. |
|
| Personal Data Protection and Privacy Act, 2025 from a date not yet set |
Use only a processor that provides sufficient guarantees of compliance, govern the engagement by a contract setting out the subject matter, duration, nature and purpose of the processing, and do not engage a sub-processor without the controller's prior written authorisation. |
|
| Data Protection Act |
Take appropriate, reasonable technical and organisational measures to secure personal data against loss, damage, unauthorised destruction, and unlawful access, and require a data processor acting on your behalf to maintain the same measures under a written contract. |
|
| Data Protection Act, 2020, registration, lawful basis and standards for processing |
Engage a data processor only under a written contract under which it acts on your instructions alone and carries obligations equivalent to your own security measures. |
|
| Kentucky Consumer Data Protection Act (KCDPA), general applicability and controller and processor duties |
Limit collection to the purposes disclosed to the consumer, and use a written contract to bind any processor to your instructions. |
|
| Data Protection Act 2025 from a date not yet set |
On commencement, put a written agreement in place with any person who processes personal data on your behalf, requiring that person to give you the notifications and assistance you need to comply with the Act and to impose the same written-agreement requirement on anyone it engages for downstream processing. |
|
| Data Protection Act, 2011 (Act No. 5 of 2012) |
Take appropriate, reasonable technical measures to secure the integrity of personal information in your possession or under your control against loss, damage, unauthorised destruction or unlawful access, and govern any agent who processes information on your behalf by a written contract that requires the same measures. |
|
| Loi n° 2017-020, protection des données à caractère personnel |
Choose a sub-processor offering sufficient guarantees, bind them by a written act limited to your instructions, and extend the confidentiality duty to anyone who takes part in the sub-processing. |
|
| Law No. 195/2024 on Personal Data Protection |
Where you engage a processor, govern the engagement as article 28 requires, and settle each party's responsibilities in an arrangement where you are a joint controller. |
|
| Law on Personal Data Protection from a date not yet set |
Enter into a written contract before entrusting personal data processing to a processor, and use only a processor registered to carry out personal data processing and able to guarantee technical, personnel and organizational protection measures, under Article 16. |
|
| Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data |
Bind any processor you use to security guarantees equivalent to your own by contract, and hold anyone with authorized access to personal data, including after they leave that role, to professional secrecy. |
|
| Loi n° 2022-59, protection des données à caractère personnel |
Choose a processor that offers sufficient security and confidentiality guarantees, govern its processing under a written confidentiality contract, and hold it to the same obligations that bind you. |
|
| Nigeria Data Protection Act, 2023 (NDPA), general data protection duties |
Put a Data Processing Agreement in place with any data processor you engage, setting out the obligations of both parties under section 29 of the Act. |
|
| Law No. 29-2019 on the Protection of Personal Data |
Choose a processor offering sufficient technical and organisational security guarantees, govern the engagement by a written contract confining the processor to your instructions, and process personal data under your own or the processor's authority only on the controller's instructions. |
|
| Law relating to the Protection of Personal Data and Privacy |
Enter into a written contract with a data processor before it processes personal data on your behalf, and authorise only a processor who gives sufficient guarantees to implement appropriate technical and organisational measures. |
|
| San Marino Law No. 171 on the Protection of Natural Persons |
Where you engage a processor, govern the engagement as article 29 requires, and settle each party's responsibilities in an arrangement where you are a joint controller. |
|
| Lei n.º 03/2016, Protecção de Dados Pessoais |
Implement appropriate technical and organizational measures against accidental or unlawful destruction, loss, unauthorized alteration, disclosure or access to personal data, choose a subcontractor offering sufficient guarantees, bind it by contract to your instructions and the same measures, and record that contract in a document with legally recognized probative value. |
|
| Loi n° 2008-12 du 25 janvier 2008 sur la Protection des Données à Caractère Personnel (Personal Data Protection Act) |
Choose a sub-processor offering sufficient guarantees, bind them by a written contract limited to your instructions, and keep processing confidential and restricted to authorized staff. |
|
| Law on Personal Data Protection |
Engage only a processor who guarantees appropriate technical, organizational and staff measures under a written processing agreement, and never let a processor act outside a controller's documented instructions. |
|
| Protection of Personal Information Act 4 of 2013 (POPIA) |
Where an operator processes personal information on your behalf, bind it by written contract to the same security measures, and require it to notify you immediately if it has reasonable grounds to believe the information was accessed or acquired by an unauthorised person. |
|
| Loi n° 2019-014, protection des données à caractère personnel |
Choose a processor that offers sufficient guarantees, govern the engagement with a written contract confining the processor to your instructions, and keep processing confidential under the authority of persons who have signed a written confidentiality undertaking. |
|
| Organic Act on the Protection of Personal Data |
Choose a subcontractor with care before delegating any processing to it, hold it to the Act's own obligations, and correct, complete or erase a file once you learn it is inaccurate or insufficient, notifying the person and any recipient within two months. |
|
| Data Protection and Privacy Act, 2019, comprehensive personal-data regime |
Do not let a data processor handle personal data on your behalf unless it has established and complies with this Act's security measures, and require that in your contract with the processor. |
|
| Utah Consumer Privacy Act |
Establish reasonable administrative, technical, and physical security practices for personal data, and enter into a written contract with any processor before it processes personal data on your behalf. |
Cross border transfer
9 laws, 9 places| Place | Law | What it asks, as read here |
|---|---|---|
| Personal Data Protection Law, cross-border transfer of personal data |
Before any transfer of personal data outside Burkina Faso, obtain the CIL's authorization, sign a data confidentiality and reversibility clause with the receiving party letting data migrate back fully at the end of the contract, and put in place technical and organizational security measures covering encryption, availability, confidentiality, integrity and resilience. |
|
| Loi n° 24.001 portant protection des données à caractère personnel, flux transfrontalier |
Give the agency prior notice before transferring personal data to a State outside the CEMAC or CEEAC, and rely on the agency's authorization, supported by appropriate contractual clauses, where the destination lacks equivalent protection. |
|
| Ley para la Protección de Datos Personales, cross border transfer of personal data |
Before transferring personal data internationally, sign a contract with the receiving party that holds it to at least the same personal data protection obligations you carry. |
|
| Privacy Protection (Transfer of Data to Databases Abroad) Regulations, cross-border transfer from a date not yet set |
An app transferring the personal data of a person in Israel to a recipient outside Israel must rely on the destination providing protection no less than Israeli law's, or on one of the regulation's eight alternative grounds, most commonly consent, a common-control guarantee, an inter-party agreement, or an authority-gazetted adequate jurisdiction, and must obtain a written guarantee from the recipient in every case. |
|
| Maldives Personal Data Protection Bill, cross-border transfers proposed |
If enacted as drafted, an agreement with a cross-border recipient would have to carry a data protection process the Data Protection Authority endorses, or the transfer would have to rest on binding corporate rules the Authority has approved. |
|
| Ley Federal de Protección de Datos Personales en Posesión de los Particulares, transfer of personal data |
Bind the recipient of a transfer to the same data-protection duties that apply to you as the transferring responsable. |
|
| Data Privacy Act of 2012, cross-border transfer accountability |
An app transferring the personal information of an individual in the Philippines, including a faceprint, voiceprint, or other biometric identifier, to a recipient outside the country remains accountable for that data and must use contractual or other reasonable means to secure a level of protection comparable to the Act. |
|
| Québec | Privacy impact assessment before communicating personal information outside Québec |
Put the communication under a written agreement that reflects the assessment's results and any terms agreed to mitigate the risks it identified. |
| Law relating to the Protection of Personal Data and Privacy, cross-border transfer and data storage |
Enter into a written contract with anyone you authorise to access, share or transfer personal data outside Rwanda, setting out each party's respective roles and responsibilities. |
Telephone contact
2 laws, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Do Not Call Register Act 2006, Unsolicited Marketing Faxes |
Do not enter into a contract, arrangement or understanding with another person if there is a reasonable likelihood they, or their employees or agents, will send marketing faxes to numbers eligible for the Do Not Call Register, unless the contract expressly requires compliance with this Act. |
|
| Do Not Call Register Act 2006, Unsolicited Telemarketing Calls |
Do not enter into a contract, arrangement or understanding with another person if there is a reasonable likelihood they, or their employees or agents, will make telemarketing calls to numbers eligible for the Do Not Call Register, unless the contract expressly requires compliance with this Act. |
Breach notification
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Data Protection Act, 2020, reporting a contravention or security breach |
Engage a data processor only where it gives sufficient guarantees as to the reporting of security breaches to you, under a written contract binding it to obligations equivalent to your own. |
Enforcement supervision
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Digital Code, Data Protection Authority and sanctions |
As joint controllers, allocate your respective duties by transparent agreement, including how you will handle a data subject's rights, and make the essence of that agreement available to the data subject. |
Sensitive categories
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Data Protection Act, sensitive personal data |
Before processing or disclosing sensitive personal data for research or statistical purposes, confirm identifiable data is genuinely necessary, commit not to use it to recruit research participants, get the responsible officer's approval of security and destruction conditions, and get the recipient's signed agreement to comply with them. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.