Law / Frameworks / NIST Privacy Framework / Identify-P

NIST Privacy Framework, Identify-PID.DE-P5

Data processing ecosystem parties are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their contractual, interoperability framework, or other obligations.NIST Privacy Framework, version 1.0, January 2020, ID.DE-P5

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

4
laws
4
places
0
with court rulings behind them
0
not yet in force
  • China
  • Côte d'Ivoire
  • New Hampshire
  • Somalia

Comprehensive regime

4 laws, 4 places
PlaceLawWhat it asks, as read here
China Personal Information Protection Law of the PRC, General Processing Rules and Lawful Bases

Where personal information is entrusted to a third party processor, execute a written entrustment agreement and supervise that processor's handling; the processor may not exceed the agreed purpose or method and must return or delete the data when the entrustment ends.

Côte d'Ivoire Law No. 2013-450 on the Protection of Personal Data

Choose a subcontractor who gives sufficient guarantees for the protection and security of the data, and ensure the subcontractor complies with this Law.

New Hampshire New Hampshire Data Privacy Act (NHDPA), general applicability and controller and processor duties

Confirm a processor you use acts only on your instructions and assists with rights requests, security, and breach notification.

Somalia Data Protection Act No. 005 of 2023

Keep a record of every data processor handling personal data you control, and take reasonable measures to ensure each one processes in a way that keeps you compliant.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.