Law / Frameworks / NIST Privacy Framework / Identify-P
NIST Privacy Framework, Identify-PID.DE-P5
Data processing ecosystem parties are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their contractual, interoperability framework, or other obligations.NIST Privacy Framework, version 1.0, January 2020, ID.DE-P5
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 4
- laws
- 4
- places
- 0
- with court rulings behind them
- 0
- not yet in force
Comprehensive regime
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Personal Information Protection Law of the PRC, General Processing Rules and Lawful Bases |
Where personal information is entrusted to a third party processor, execute a written entrustment agreement and supervise that processor's handling; the processor may not exceed the agreed purpose or method and must return or delete the data when the entrustment ends. |
|
| Law No. 2013-450 on the Protection of Personal Data |
Choose a subcontractor who gives sufficient guarantees for the protection and security of the data, and ensure the subcontractor complies with this Law. |
|
| New Hampshire Data Privacy Act (NHDPA), general applicability and controller and processor duties |
Confirm a processor you use acts only on your instructions and assists with rights requests, security, and breach notification. |
|
| Data Protection Act No. 005 of 2023 |
Keep a record of every data processor handling personal data you control, and take reasonable measures to ensure each one processes in a way that keeps you compliant. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.