Law / Frameworks / NIST Privacy Framework / Identify-P

NIST Privacy Framework, Identify-PID.IM-P4

Data actions of the systems/products/services are inventoried.NIST Privacy Framework, version 1.0, January 2020, ID.IM-P4

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

33
laws
30
places
0
with court rulings behind them
4
not yet in force
2
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Albania
  • Algeria
  • Andorra
  • Barbados
  • Benin
  • Bosnia and Herzegovina
  • Brazil
  • Cambodia
  • Cameroon
  • Côte d'Ivoire
  • Democratic Republic of the Congo
  • Ecuador
  • Egypt
  • Ethiopia
  • Gabon
  • Gambia
  • Kosovo
  • Moldova
  • Monaco
  • Montenegro
  • Niger
  • Republic of the Congo
  • Rwanda
  • San Marino
  • Serbia
  • Suriname
  • Syria
  • Togo
  • Vatican City
  • Zambia

Comprehensive regime

29 laws, 29 places
PlaceLawWhat it asks, as read here
Albania Law No. 124/2024 On the Protection of Personal Data

Maintain written and electronic records of processing activities naming the controller, the purposes, the categories of data and recipients, any transfer outside Albania, and the envisaged erasure periods, and make the records available to the Commissioner on request.

Algeria Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11

Keep a written or electronic record of your processing activities and an automated log of processing operations, and make each available to the ANPDP on request.

Andorra LQPD, Llei 29/2021 del 28 d'octubre

Apply data protection by design and by default, keep a written record of your processing activities unless you employ fewer than fifty workers and none of the high-risk, non-occasional or special-category exceptions apply, and block rather than delete personal data pending any liability claim when you rectify or erase it.

Barbados Data Protection Act, 2019

Build data protection into the design of your processing and make it the default, and keep records of your processing activities.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel)

Keep a written record of your processing activities, covering the purposes, the categories of data subjects and data, the recipients, retention periods, and security measures, and make it available to the Autorité on request.

Bosnia and Herzegovina Law on the Protection of Personal Data of Bosnia and Herzegovina

Keep a written record of processing activities under Article 32, covering the purposes, the categories of data subjects and data, the recipients, any transfer abroad, and the envisaged erasure periods, and make it available to the Agency on request.

Brazil Lei Geral de Proteção de Dados Pessoais (LGPD)

Keep a record of your processing operations, especially those based on legitimate interest, and name a person in charge (encarregado) whose identity and contact details you publish, preferably on your website.

Cambodia Draft Law on Personal Data Protection, final draft proposed

If enacted as drafted, a data controller and processor would each have to appoint a personal data protection officer and notify the Ministry of Post and Telecommunications of that appointment within 30 working days, maintain records of processing activities, and, if located outside Cambodia, appoint a local representative.

Cameroon Loi n°2024/017 du 23 décembre 2024 relative à la protection des données à caractère personnel au Cameroun from a date not yet set

Keep a register of processing activities covering purposes, data categories, recipients, international transfers, retention periods, and security measures, and make it available to the authority on request.

Côte d'Ivoire Law No. 2013-450 on the Protection of Personal Data

Include in every declaration or application for authorization the identity of the person responsible, the purpose, the data categories and their origin, the retention period, the recipients, the office where access is exercised, the planned security measures, and any subcontractor or cross-border transfer.

Show the other 19 laws
Democratic Republic of the Congo Digital Code, Title III: Personal Data Protection

Appoint a data protection officer where your processing is non-occasional, high-risk, or touches special-category or criminal-record data, and keep a written record of your processing activities available to the Data Protection Authority.

Egypt Law No. 151 of 2020 Promulgating the Personal Data Protection Law

Maintain a record of the Personal Data in your possession, describing its categories, the persons it may be disclosed to, and the basis, duration, restrictions and scope of that disclosure.

Ethiopia Personal Data Protection Proclamation

Maintain a record, including logs, of all processing operations under your responsibility, covering the purposes, the categories of data subjects, personal data and recipients, any transfers to another country and their safeguards, and make it available to the Authority on request.

Gabon Loi n°001/2011 relative à la protection des données à caractère personnel, modifiée par la loi n°025/2023

Keep a written or electronic register of your processing activities, and require the same of any processor, naming the controller, purposes, data categories, recipients, transfers and retention periods, and produce it to the APDPVP on request; an organization of fewer than ten employees is exempt unless the processing is not occasional, carries a risk to rights and freedoms, or touches sensitive or criminal-offence data.

Gambia Personal Data Protection and Privacy Act, 2025 from a date not yet set

Maintain a written record of your processing activities, as a controller and as a processor alike.

Kosovo Law No. 06/L-082 on Protection of Personal Data

Apply data protection by design and by default, keep a written record of your processing activities unless you employ fewer than two hundred and fifty people and none of the high-risk, non-occasional or special-category exceptions apply, and cooperate with the Agency for Information and Privacy on request.

Moldova Law No. 195/2024 on Personal Data Protection

Build data protection into the design of your processing and make it the default, and keep records of your processing activities.

Monaco Loi sur la Protection des Données Personnelles

Keep a written record of your processing activities covering the particulars Article 27 lists, and make it available to the Authority on request, unless you are an undertaking of fewer than 50 employees in Monaco whose processing is occasional, low risk, and free of sensitive or criminal record data.

Montenegro Law on Personal Data Protection from a date not yet set

Keep records of every personal data filing system you establish, covering the matters Article 26 lists, and obtain the Agency for Personal Data Protection and Free Access to Information's prior consent before establishing or materially altering one, under Articles 27 and 28.

Niger Loi n° 2022-59, protection des données à caractère personnel

Keep a register of processing operations recording the collection, modification, consultation, disclosure, transfers, interconnection and deletion of personal data, and make it available to the HAPDP on request.

Republic of the Congo Law No. 29-2019 on the Protection of Personal Data

Keep a written register of your processing activities and make it available to the national commission on demand, and cooperate with the commission when it asks.

Rwanda Law relating to the Protection of Personal Data and Privacy

Log every collection, alteration, access, disclosure, combination and erasure of personal data, and maintain a record of all processing activities, producing both to the supervisory authority on request.

San Marino San Marino Law No. 171 on the Protection of Natural Persons

Build data protection into the design of your processing and make it the default, and keep records of your processing activities.

Serbia Law on Personal Data Protection

Maintain a record of processing activities covering your identity, the purposes, the categories of data subjects and data, the recipients including in other countries, any cross-border transfer and its safeguards, and the retention periods, and make it available to the Commissioner on request.

Suriname Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens) proposed

Keep a written or electronic register of your processing activities, covering the categories of data, recipients, retention periods, and security measures, and notify it to the Commissioner for Personal Data Protection, updating the notification whenever needed and at least once a year.

Syria Law No. 12 of 2024 on Protection of Electronic Personal Data

Keep a register describing the categories of personal data you hold, who you disclose it to, the retention periods, and any cross border transfer, and make it available for the Authority's inspection.

Togo Loi n° 2019-014, protection des données à caractère personnel

Where you appoint a data protection correspondent to qualify for the formality exemption, notify the appointment to the Instance and have the correspondent advise on compliance, cooperate with the Instance, and keep an accessible list of the processing you carry out.

Vatican City General Regulation on the Protection of Personal Data for Vatican City State

Where this Regulation binds your processing, identify the Data Controller as the Governorate, represented by the General Secretary, and put in place organizational and technical security measures suitable to protect the personal data you process. Appoint a Representative in writing where the Regulation calls for one, and record the activity in the Register of treatment activities.

Zambia Data Protection Act, 2021, personal data processing framework

Keep a written record of your processing activities and of all categories of processing you carry out, and make it available to the Data Protection Commissioner on demand.

Cross border transfer

3 laws, 3 places
PlaceLawWhat it asks, as read here
Andorra LQPD, transfers of personal data to third countries or international organisations

Document in your processing register the assessment and safeguards behind any transfer you make under Article 45(2).

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, transfert transfrontalier de données

Identify in your register of processing activities every transfer of personal data to a third country or international organization, including that country's or organization's identity and, where relied on, the documents evidencing appropriate safeguards.

Kosovo Law No. 06/L-082 on Protection of Personal Data, transfer of personal data to other states and international organisations

Where you rely on Article 49, keep a record of the transfer authorisation as part of your Article 29 processing register.

Data subject rights

1 law, 1 place
PlaceLawWhat it asks, as read here
Ecuador SPDP Norma General guaranteeing personal-data protection in the use of AI systems from a date not yet set

Maintain a record of processing activities and audit the AI system's operation in proportion to its level of risk.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.