Law / Frameworks / NIST Privacy Framework / Identify-P
NIST Privacy Framework, Identify-PID.IM-P4
Data actions of the systems/products/services are inventoried.NIST Privacy Framework, version 1.0, January 2020, ID.IM-P4
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 33
- laws
- 30
- places
- 0
- with court rulings behind them
- 4
- not yet in force
- 2
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.4 The risk management process and its outcomes are established through transparent...
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations1.1 Board Structure & Oversight
- MIT mitigations1.2 Risk Management
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and...
A law in force is unmarked; the rest wear their state: not yet in force proposed
Comprehensive regime
29 laws, 29 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 124/2024 On the Protection of Personal Data |
Maintain written and electronic records of processing activities naming the controller, the purposes, the categories of data and recipients, any transfer outside Albania, and the envisaged erasure periods, and make the records available to the Commissioner on request. |
|
| Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11 |
Keep a written or electronic record of your processing activities and an automated log of processing operations, and make each available to the ANPDP on request. |
|
| LQPD, Llei 29/2021 del 28 d'octubre |
Apply data protection by design and by default, keep a written record of your processing activities unless you employ fewer than fifty workers and none of the high-risk, non-occasional or special-category exceptions apply, and block rather than delete personal data pending any liability claim when you rectify or erase it. |
|
| Data Protection Act, 2019 |
Build data protection into the design of your processing and make it the default, and keep records of your processing activities. |
|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel) |
Keep a written record of your processing activities, covering the purposes, the categories of data subjects and data, the recipients, retention periods, and security measures, and make it available to the Autorité on request. |
|
| Law on the Protection of Personal Data of Bosnia and Herzegovina |
Keep a written record of processing activities under Article 32, covering the purposes, the categories of data subjects and data, the recipients, any transfer abroad, and the envisaged erasure periods, and make it available to the Agency on request. |
|
| Lei Geral de Proteção de Dados Pessoais (LGPD) |
Keep a record of your processing operations, especially those based on legitimate interest, and name a person in charge (encarregado) whose identity and contact details you publish, preferably on your website. |
|
| Draft Law on Personal Data Protection, final draft proposed |
If enacted as drafted, a data controller and processor would each have to appoint a personal data protection officer and notify the Ministry of Post and Telecommunications of that appointment within 30 working days, maintain records of processing activities, and, if located outside Cambodia, appoint a local representative. |
|
| Loi n°2024/017 du 23 décembre 2024 relative à la protection des données à caractère personnel au Cameroun from a date not yet set |
Keep a register of processing activities covering purposes, data categories, recipients, international transfers, retention periods, and security measures, and make it available to the authority on request. |
|
| Law No. 2013-450 on the Protection of Personal Data |
Include in every declaration or application for authorization the identity of the person responsible, the purpose, the data categories and their origin, the retention period, the recipients, the office where access is exercised, the planned security measures, and any subcontractor or cross-border transfer. |
Show the other 19 laws
| Digital Code, Title III: Personal Data Protection |
Appoint a data protection officer where your processing is non-occasional, high-risk, or touches special-category or criminal-record data, and keep a written record of your processing activities available to the Data Protection Authority. |
|
| Law No. 151 of 2020 Promulgating the Personal Data Protection Law |
Maintain a record of the Personal Data in your possession, describing its categories, the persons it may be disclosed to, and the basis, duration, restrictions and scope of that disclosure. |
|
| Personal Data Protection Proclamation |
Maintain a record, including logs, of all processing operations under your responsibility, covering the purposes, the categories of data subjects, personal data and recipients, any transfers to another country and their safeguards, and make it available to the Authority on request. |
|
| Loi n°001/2011 relative à la protection des données à caractère personnel, modifiée par la loi n°025/2023 |
Keep a written or electronic register of your processing activities, and require the same of any processor, naming the controller, purposes, data categories, recipients, transfers and retention periods, and produce it to the APDPVP on request; an organization of fewer than ten employees is exempt unless the processing is not occasional, carries a risk to rights and freedoms, or touches sensitive or criminal-offence data. |
|
| Personal Data Protection and Privacy Act, 2025 from a date not yet set |
Maintain a written record of your processing activities, as a controller and as a processor alike. |
|
| Law No. 06/L-082 on Protection of Personal Data |
Apply data protection by design and by default, keep a written record of your processing activities unless you employ fewer than two hundred and fifty people and none of the high-risk, non-occasional or special-category exceptions apply, and cooperate with the Agency for Information and Privacy on request. |
|
| Law No. 195/2024 on Personal Data Protection |
Build data protection into the design of your processing and make it the default, and keep records of your processing activities. |
|
| Loi sur la Protection des Données Personnelles |
Keep a written record of your processing activities covering the particulars Article 27 lists, and make it available to the Authority on request, unless you are an undertaking of fewer than 50 employees in Monaco whose processing is occasional, low risk, and free of sensitive or criminal record data. |
|
| Law on Personal Data Protection from a date not yet set |
Keep records of every personal data filing system you establish, covering the matters Article 26 lists, and obtain the Agency for Personal Data Protection and Free Access to Information's prior consent before establishing or materially altering one, under Articles 27 and 28. |
|
| Loi n° 2022-59, protection des données à caractère personnel |
Keep a register of processing operations recording the collection, modification, consultation, disclosure, transfers, interconnection and deletion of personal data, and make it available to the HAPDP on request. |
|
| Law No. 29-2019 on the Protection of Personal Data |
Keep a written register of your processing activities and make it available to the national commission on demand, and cooperate with the commission when it asks. |
|
| Law relating to the Protection of Personal Data and Privacy |
Log every collection, alteration, access, disclosure, combination and erasure of personal data, and maintain a record of all processing activities, producing both to the supervisory authority on request. |
|
| San Marino Law No. 171 on the Protection of Natural Persons |
Build data protection into the design of your processing and make it the default, and keep records of your processing activities. |
|
| Law on Personal Data Protection |
Maintain a record of processing activities covering your identity, the purposes, the categories of data subjects and data, the recipients including in other countries, any cross-border transfer and its safeguards, and the retention periods, and make it available to the Commissioner on request. |
|
| Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens) proposed |
Keep a written or electronic register of your processing activities, covering the categories of data, recipients, retention periods, and security measures, and notify it to the Commissioner for Personal Data Protection, updating the notification whenever needed and at least once a year. |
|
| Law No. 12 of 2024 on Protection of Electronic Personal Data |
Keep a register describing the categories of personal data you hold, who you disclose it to, the retention periods, and any cross border transfer, and make it available for the Authority's inspection. |
|
| Loi n° 2019-014, protection des données à caractère personnel |
Where you appoint a data protection correspondent to qualify for the formality exemption, notify the appointment to the Instance and have the correspondent advise on compliance, cooperate with the Instance, and keep an accessible list of the processing you carry out. |
|
| General Regulation on the Protection of Personal Data for Vatican City State |
Where this Regulation binds your processing, identify the Data Controller as the Governorate, represented by the General Secretary, and put in place organizational and technical security measures suitable to protect the personal data you process. Appoint a Representative in writing where the Regulation calls for one, and record the activity in the Register of treatment activities. |
|
| Data Protection Act, 2021, personal data processing framework |
Keep a written record of your processing activities and of all categories of processing you carry out, and make it available to the Data Protection Commissioner on demand. |
Cross border transfer
3 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| LQPD, transfers of personal data to third countries or international organisations |
Document in your processing register the assessment and safeguards behind any transfer you make under Article 45(2). |
|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, transfert transfrontalier de données |
Identify in your register of processing activities every transfer of personal data to a third country or international organization, including that country's or organization's identity and, where relied on, the documents evidencing appropriate safeguards. |
|
| Law No. 06/L-082 on Protection of Personal Data, transfer of personal data to other states and international organisations |
Where you rely on Article 49, keep a record of the transfer authorisation as part of your Article 29 processing register. |
Data subject rights
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| SPDP Norma General guaranteeing personal-data protection in the use of AI systems from a date not yet set |
Maintain a record of processing activities and audit the AI system's operation in proportion to its level of risk. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.