Law / Frameworks / NIST Privacy Framework / Identify-P
NIST Privacy Framework, Identify-PID.IM-P7
The data processing environment is identified (e.g., geographic location, internal, cloud, third parties).NIST Privacy Framework, version 1.0, January 2020, ID.IM-P7
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 16
- laws
- 15
- places
- 0
- with court rulings behind them
- 1
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations3.2 Data Governance
- NIST CSF 2.0ID.AM-03 Representations of the organization's authorized network communication and internal...
- NIST CSF 2.0ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
A law in force is unmarked; the rest wear their state: not yet in force
Cross border transfer
14 laws, 14 places| Place | Law | What it asks, as read here |
|---|---|---|
| Data Protection Act, 2024, transfer of personal data to third countries or international organisations |
Keep a copy of any personal data transferred to a third country or an international organisation in Botswana for the period of processing. |
|
| Personal Information Protection Law, Cross-Border Transfer |
Store personal information collected within China domestically if operating as a critical information infrastructure operator or processing above the state-set volume threshold; export only after a security assessment. |
|
| Resolución 58/2022 (MINCOM), security and localization rules for personal data in electronic form |
Host or replicate any registry, file, archive, or database containing personal data in electronic form only on servers located within Cuba's national territory, absent a case the law provides for. |
|
| Digital Code, Title III, cross-border transfer of personal data |
Store personal data in the Democratic Republic of the Congo, and do not transfer it to a third country, digital embassy, or international organization unless the Data Protection Authority finds an adequate level of protection. |
|
| Personal Data Protection Proclamation, cross-border transfer and data sovereignty |
Store personal data collected or obtained in Ethiopia on a server or data center located in Ethiopia, and keep any category of critical personal data the Authority prescribes on a server or data center there. |
|
| Law on Personal Data and Their Protection, localization and cross-border transfer |
An app storing or processing the personal data of individuals in Kazakhstan, including a voiceprint or other biometric identifier, must maintain a database located within Kazakhstan; Kazakhstani law does not on its own text forbid an additional copy abroad. Transferring that data to another country requires that the destination state ensure equivalent protection, or one of four fallback grounds: the subject's consent, a ratified treaty, statutory necessity, or protection of constitutional rights where consent cannot be obtained. |
|
| Data Protection Act, 2019, transfer of personal data outside Kenya |
Check whether the Cabinet Secretary has designated your category of processing for mandatory handling on a server or data centre located in Kenya. |
|
| Federal Law No. 152-FZ, Article 18(5), Data Localization and Cross-Border Transfer, as Amended by Federal Law No. 23-FZ |
Record, systematize, accumulate, store, update, and retrieve personal data of Russian citizens in a database physically located in Russia, whether you act as operator or processor, under Federal Law No. 152-FZ Article 18(5) as amended by Federal Law No. 23-FZ. |
|
| Law relating to the Protection of Personal Data and Privacy, cross-border transfer and data storage |
Store personal data in Rwanda, and store it outside Rwanda only where you hold a valid registration certificate from the supervisory authority authorising storage abroad. |
|
| Law on the Protection of Personal Data, localization and cross-border transfer |
An app storing or processing the personal data of individuals in Tajikistan, including a voiceprint or other biometric identifier, must by default keep the database exclusively inside Tajikistan, unless it has an arrangement agreed with the authorized state body for personal data protection. Transferring that data abroad separately requires the subject's consent, a ratified treaty, statutory necessity, or protection of constitutional rights where consent cannot be obtained. |
Show the other 4 laws
| Law on Information About Private Life, localization and cross-border transfer |
An app storing or processing the personal information of individuals in Turkmenistan, including a voiceprint or other biometric identifier, must maintain a database located within Turkmenistan; only data contained in that domestic database may be transferred abroad at all. Transfer to another country additionally requires that the destination ensure protection of personal information, or one of four fallback grounds: written consent, a ratified treaty, statutory necessity, or protection of vital interests or constitutional rights where consent cannot be obtained. |
|
| Genetic sequencing, storage of genetic information (HB 182) from , in 15 months |
Beginning , if you operate a medical facility or genomic research facility, do not store Utah genetic-sequencing data within the territory of a designated foreign adversary, and do not use a genetic sequencer or sequencing software that is a final product of a foreign adversary. |
|
| Law on Personal Data, cross-border transfer and citizen data localization |
An app transferring the personal data of an Uzbek data subject outside Uzbekistan must rely on the destination state's adequate protection, or on consent, statutory necessity, or a treaty where adequacy is absent. Separately, an app processing the personal data of Uzbek citizens, including a voiceprint or other biometric identifier, over the internet must collect, systematize, and store that data on technical means physically located in Uzbekistan and register the database in the State Register of Personal Data Bases. Several major platforms have been blocked in Uzbekistan for noncompliance with this storage duty. |
|
| Data Protection Act, 2021, transfer of personal data outside the Republic |
Store and process personal data on a server or data centre located in Zambia unless the Minister has prescribed an exception, and do not store sensitive personal data outside Zambia without the data subject's explicit consent. |
Biometric privacy
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Law on Personal Data and Their Protection, biometric data provisions |
An app is not exempt from Kazakhstan's Law on Personal Data merely because biometric data has no dedicated definition in the Act. Collecting biometric data in a public place for identification purposes is restricted to constitutional-order, public-order, rights, health, or morality grounds unless the subject consents, and biometric data stored on Kazakhstani subjects must sit in a database located inside Kazakhstan like any other personal data. Confidentiality of biometric data specifically is deferred to other Kazakh legislation, which the Act does not name and which is not identified here. |
Comprehensive regime
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Loi n°001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel |
Obtain the CIL's authorization, given after the Health Research Ethics Committee's concurring opinion, before processing personal data for health research, anonymize the data before transmission wherever the research's purpose allows it, and host any health data that still permits identification on national territory. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.