Law / Frameworks / NIST Privacy Framework / Identify-P

NIST Privacy Framework, Identify-PID.DE-P3

Contracts with data processing ecosystem parties are used to implement appropriate measures designed to meet the objectives of an organization’s privacy program.NIST Privacy Framework, version 1.0, January 2020, ID.DE-P3

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

54
laws
47
places
0
with court rulings behind them
4
not yet in force
1
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Albania
  • Algeria
  • Angola
  • Australia
  • Austria
  • Belarus
  • Benin
  • Burkina Faso
  • Cabo Verde
  • Canada
  • Central African Republic
  • China
  • Comoros
  • Democratic Republic of the Congo
  • El Salvador
  • Eswatini
  • European Union
  • Gabon
  • Gambia
  • Ghana
  • Israel
  • Jamaica
  • Kentucky
  • Kiribati
  • Lesotho
  • Maldives
  • Mauritania
  • Mexico
  • Moldova
  • Montenegro
  • Morocco
  • Niger
  • Nigeria
  • Philippines
  • Republic of the Congo
  • Rwanda
  • Saint Lucia
  • San Marino
  • Sao Tome and Principe
  • Senegal
  • Serbia
  • South Africa
  • Togo
  • Tunisia
  • Uganda
  • Utah

Comprehensive regime

40 laws, 40 places
PlaceLawWhat it asks, as read here
Albania Law No. 124/2024 On the Protection of Personal Data

Keep personal data confidential wherever an employee or processor has access to it for professional reasons, bind that confidentiality into every processor contract and employment contract, and continue it after the contract or employment ends.

Algeria Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11

Implement technical and organisational measures appropriate to the risk, and choose a processor only for the sufficiency of its own security guarantees, governed by a written contract.

Angola Law on the Protection of Personal Data

Treat a recipient who processes communicated personal data for its own purposes as a controller in its own right, and one who processes it on your behalf and under your instructions as a subcontractor bound by a written contract, and obtain the APD's authorisation before interconnecting personal data held in different files unless a legal provision already permits it.

Austria Datenschutzgesetz (DSG), Data Protection Act

Allocate and document controller and processor responsibilities in a written agreement wherever a third party processes personal data on your behalf, following GDPR Articles 24 to 28.

Belarus Law of the Republic of Belarus On Personal Data Protection

Fix the purposes, permitted actions, confidentiality duty and protection measures in a contract, act of legislation or public authority decision before entrusting processing to an authorized person, under Article 7, and remain responsible to the personal data subject for that person's actions.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel)

Choose a processor offering sufficient security and confidentiality guarantees, fix the processor's obligations in a written contract, and ensure the processor acts only on your documented instructions.

Burkina Faso Loi n°001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel

Before using a processor, choose one that offers sufficient guarantees of protection, and sign a written agreement with it fixing the processing operations it may carry out and what happens to the data when the contract ends.

Cabo Verde Law No. 133/V/2001 on the Protection of Personal Data

Implement technical and organisational measures adequate to the risk to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, and choose a processor offering sufficient security guarantees under a written contract that binds them to your instructions.

Canada Personal Information Protection and Electronic Documents Act (PIPEDA)

Remain accountable for personal information transferred to a third party for processing, in Canada or abroad, and use contractual or other means to ensure a comparable level of protection.

Central African Republic Loi n° 24.001 portant protection des données à caractère personnel

Process personal data as a subcontractor only on the controller's instruction, offer sufficient guarantees to implement security and confidentiality measures, and put those obligations in the contract with the controller.

Show the other 30 laws
China Personal Information Protection Law of the PRC, General Processing Rules and Lawful Bases

Where personal information is entrusted to a third party processor, execute a written entrustment agreement and supervise that processor's handling; the processor may not exceed the agreed purpose or method and must return or delete the data when the entrustment ends.

Where two or more processors jointly decide a shared processing purpose and method, agree in writing on each party's respective duties; the individual may still exercise rights against any one of them, and the processors bear joint and several liability for resulting harm.

Comoros Law on the Protection of Personal Data

Confine a sub processor to your instructions under a written contract addressing security and confidentiality, without relieving yourself of the duty to see those measures respected.

Democratic Republic of the Congo Digital Code, Title III: Personal Data Protection

Govern any processor's engagement by a written contract confining it to your documented instructions, and require the processor not to engage a sub-processor without your prior written authorization.

El Salvador Ley para la Protección de Datos Personales

Document your ARCO-POL request procedures, and hold any subcontractor with access to personal data to this Law.

Eswatini Data Protection Act, 2022 (Act No. 5 of 2022)

Take appropriate, reasonable technical and administrative measures to secure the integrity of personal information in your possession or under your control against loss, modification, damage, unauthorised destruction or unlawful access, and govern any data processor who processes information on your behalf by a written contract that requires the same measures.

European Union General Data Protection Regulation (GDPR), Comprehensive Regime

Allocate and document controller and processor responsibilities in a written agreement wherever a third party processes personal data on your behalf, and appoint a Data Protection Officer where your core activities involve large scale monitoring or large scale special category processing.

Gabon Loi n°001/2011 relative à la protection des données à caractère personnel, modifiée par la loi n°025/2023

Keep processing confidential, bind everyone who processes the data under your authority to a signed written undertaking, and impose the same security and confidentiality guarantees on any processor by contract.

Gambia Personal Data Protection and Privacy Act, 2025 from a date not yet set

Use only a processor that provides sufficient guarantees of compliance, govern the engagement by a contract setting out the subject matter, duration, nature and purpose of the processing, and do not engage a sub-processor without the controller's prior written authorisation.

Ghana Data Protection Act

Take appropriate, reasonable technical and organisational measures to secure personal data against loss, damage, unauthorised destruction, and unlawful access, and require a data processor acting on your behalf to maintain the same measures under a written contract.

Jamaica Data Protection Act, 2020, registration, lawful basis and standards for processing

Engage a data processor only under a written contract under which it acts on your instructions alone and carries obligations equivalent to your own security measures.

Kentucky Kentucky Consumer Data Protection Act (KCDPA), general applicability and controller and processor duties

Limit collection to the purposes disclosed to the consumer, and use a written contract to bind any processor to your instructions.

Kiribati Data Protection Act 2025 from a date not yet set

On commencement, put a written agreement in place with any person who processes personal data on your behalf, requiring that person to give you the notifications and assistance you need to comply with the Act and to impose the same written-agreement requirement on anyone it engages for downstream processing.

Lesotho Data Protection Act, 2011 (Act No. 5 of 2012)

Take appropriate, reasonable technical measures to secure the integrity of personal information in your possession or under your control against loss, damage, unauthorised destruction or unlawful access, and govern any agent who processes information on your behalf by a written contract that requires the same measures.

Mauritania Loi n° 2017-020, protection des données à caractère personnel

Choose a sub-processor offering sufficient guarantees, bind them by a written act limited to your instructions, and extend the confidentiality duty to anyone who takes part in the sub-processing.

Moldova Law No. 195/2024 on Personal Data Protection

Where you engage a processor, govern the engagement as article 28 requires, and settle each party's responsibilities in an arrangement where you are a joint controller.

Montenegro Law on Personal Data Protection from a date not yet set

Enter into a written contract before entrusting personal data processing to a processor, and use only a processor registered to carry out personal data processing and able to guarantee technical, personnel and organizational protection measures, under Article 16.

Morocco Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data

Bind any processor you use to security guarantees equivalent to your own by contract, and hold anyone with authorized access to personal data, including after they leave that role, to professional secrecy.

Niger Loi n° 2022-59, protection des données à caractère personnel

Choose a processor that offers sufficient security and confidentiality guarantees, govern its processing under a written confidentiality contract, and hold it to the same obligations that bind you.

Nigeria Nigeria Data Protection Act, 2023 (NDPA), general data protection duties

Put a Data Processing Agreement in place with any data processor you engage, setting out the obligations of both parties under section 29 of the Act.

Republic of the Congo Law No. 29-2019 on the Protection of Personal Data

Choose a processor offering sufficient technical and organisational security guarantees, govern the engagement by a written contract confining the processor to your instructions, and process personal data under your own or the processor's authority only on the controller's instructions.

Rwanda Law relating to the Protection of Personal Data and Privacy

Enter into a written contract with a data processor before it processes personal data on your behalf, and authorise only a processor who gives sufficient guarantees to implement appropriate technical and organisational measures.

San Marino San Marino Law No. 171 on the Protection of Natural Persons

Where you engage a processor, govern the engagement as article 29 requires, and settle each party's responsibilities in an arrangement where you are a joint controller.

Sao Tome and Principe Lei n.º 03/2016, Protecção de Dados Pessoais

Implement appropriate technical and organizational measures against accidental or unlawful destruction, loss, unauthorized alteration, disclosure or access to personal data, choose a subcontractor offering sufficient guarantees, bind it by contract to your instructions and the same measures, and record that contract in a document with legally recognized probative value.

Senegal Loi n° 2008-12 du 25 janvier 2008 sur la Protection des Données à Caractère Personnel (Personal Data Protection Act)

Choose a sub-processor offering sufficient guarantees, bind them by a written contract limited to your instructions, and keep processing confidential and restricted to authorized staff.

Serbia Law on Personal Data Protection

Engage only a processor who guarantees appropriate technical, organizational and staff measures under a written processing agreement, and never let a processor act outside a controller's documented instructions.

South Africa Protection of Personal Information Act 4 of 2013 (POPIA)

Where an operator processes personal information on your behalf, bind it by written contract to the same security measures, and require it to notify you immediately if it has reasonable grounds to believe the information was accessed or acquired by an unauthorised person.

Togo Loi n° 2019-014, protection des données à caractère personnel

Choose a processor that offers sufficient guarantees, govern the engagement with a written contract confining the processor to your instructions, and keep processing confidential under the authority of persons who have signed a written confidentiality undertaking.

Tunisia Organic Act on the Protection of Personal Data

Choose a subcontractor with care before delegating any processing to it, hold it to the Act's own obligations, and correct, complete or erase a file once you learn it is inaccurate or insufficient, notifying the person and any recipient within two months.

Uganda Data Protection and Privacy Act, 2019, comprehensive personal-data regime

Do not let a data processor handle personal data on your behalf unless it has established and complies with this Act's security measures, and require that in your contract with the processor.

Utah Utah Consumer Privacy Act

Establish reasonable administrative, technical, and physical security practices for personal data, and enter into a written contract with any processor before it processes personal data on your behalf.

Cross border transfer

9 laws, 9 places
PlaceLawWhat it asks, as read here
Burkina Faso Personal Data Protection Law, cross-border transfer of personal data

Before any transfer of personal data outside Burkina Faso, obtain the CIL's authorization, sign a data confidentiality and reversibility clause with the receiving party letting data migrate back fully at the end of the contract, and put in place technical and organizational security measures covering encryption, availability, confidentiality, integrity and resilience.

Central African Republic Loi n° 24.001 portant protection des données à caractère personnel, flux transfrontalier

Give the agency prior notice before transferring personal data to a State outside the CEMAC or CEEAC, and rely on the agency's authorization, supported by appropriate contractual clauses, where the destination lacks equivalent protection.

El Salvador Ley para la Protección de Datos Personales, cross border transfer of personal data

Before transferring personal data internationally, sign a contract with the receiving party that holds it to at least the same personal data protection obligations you carry.

Israel Privacy Protection (Transfer of Data to Databases Abroad) Regulations, cross-border transfer from a date not yet set

An app transferring the personal data of a person in Israel to a recipient outside Israel must rely on the destination providing protection no less than Israeli law's, or on one of the regulation's eight alternative grounds, most commonly consent, a common-control guarantee, an inter-party agreement, or an authority-gazetted adequate jurisdiction, and must obtain a written guarantee from the recipient in every case.

Maldives Maldives Personal Data Protection Bill, cross-border transfers proposed

If enacted as drafted, an agreement with a cross-border recipient would have to carry a data protection process the Data Protection Authority endorses, or the transfer would have to rest on binding corporate rules the Authority has approved.

Mexico Ley Federal de Protección de Datos Personales en Posesión de los Particulares, transfer of personal data

Bind the recipient of a transfer to the same data-protection duties that apply to you as the transferring responsable.

Philippines Data Privacy Act of 2012, cross-border transfer accountability

An app transferring the personal information of an individual in the Philippines, including a faceprint, voiceprint, or other biometric identifier, to a recipient outside the country remains accountable for that data and must use contractual or other reasonable means to secure a level of protection comparable to the Act.

Québec Privacy impact assessment before communicating personal information outside Québec

Put the communication under a written agreement that reflects the assessment's results and any terms agreed to mitigate the risks it identified.

Rwanda Law relating to the Protection of Personal Data and Privacy, cross-border transfer and data storage

Enter into a written contract with anyone you authorise to access, share or transfer personal data outside Rwanda, setting out each party's respective roles and responsibilities.

Telephone contact

2 laws, 1 place
PlaceLawWhat it asks, as read here
Australia Do Not Call Register Act 2006, Unsolicited Marketing Faxes

Do not enter into a contract, arrangement or understanding with another person if there is a reasonable likelihood they, or their employees or agents, will send marketing faxes to numbers eligible for the Do Not Call Register, unless the contract expressly requires compliance with this Act.

Australia Do Not Call Register Act 2006, Unsolicited Telemarketing Calls

Do not enter into a contract, arrangement or understanding with another person if there is a reasonable likelihood they, or their employees or agents, will make telemarketing calls to numbers eligible for the Do Not Call Register, unless the contract expressly requires compliance with this Act.

Breach notification

1 law, 1 place
PlaceLawWhat it asks, as read here
Jamaica Data Protection Act, 2020, reporting a contravention or security breach

Engage a data processor only where it gives sufficient guarantees as to the reporting of security breaches to you, under a written contract binding it to obligations equivalent to your own.

Enforcement supervision

1 law, 1 place
PlaceLawWhat it asks, as read here
Democratic Republic of the Congo Digital Code, Data Protection Authority and sanctions

As joint controllers, allocate your respective duties by transparent agreement, including how you will handle a data subject's rights, and make the essence of that agreement available to the data subject.

Sensitive categories

1 law, 1 place
PlaceLawWhat it asks, as read here
Saint Lucia Data Protection Act, sensitive personal data

Before processing or disclosing sensitive personal data for research or statistical purposes, confirm identifiable data is genuinely necessary, commit not to use it to recruit research participants, get the responsible officer's approval of security and destruction conditions, and get the recipient's signed agreement to comply with them.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.