Law / Frameworks / NIST Privacy Framework / Identify-P

NIST Privacy Framework, Identify-PID.IM-P7

The data processing environment is identified (e.g., geographic location, internal, cloud, third parties).NIST Privacy Framework, version 1.0, January 2020, ID.IM-P7

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

16
laws
15
places
0
with court rulings behind them
1
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • Botswana
  • Burkina Faso
  • China
  • Cuba
  • Democratic Republic of the Congo
  • Ethiopia
  • Kazakhstan
  • Kenya
  • Russia
  • Rwanda
  • Tajikistan
  • Turkmenistan
  • Utah
  • Uzbekistan
  • Zambia

Cross border transfer

14 laws, 14 places
PlaceLawWhat it asks, as read here
Botswana Data Protection Act, 2024, transfer of personal data to third countries or international organisations

Keep a copy of any personal data transferred to a third country or an international organisation in Botswana for the period of processing.

China Personal Information Protection Law, Cross-Border Transfer

Store personal information collected within China domestically if operating as a critical information infrastructure operator or processing above the state-set volume threshold; export only after a security assessment.

Cuba Resolución 58/2022 (MINCOM), security and localization rules for personal data in electronic form

Host or replicate any registry, file, archive, or database containing personal data in electronic form only on servers located within Cuba's national territory, absent a case the law provides for.

Democratic Republic of the Congo Digital Code, Title III, cross-border transfer of personal data

Store personal data in the Democratic Republic of the Congo, and do not transfer it to a third country, digital embassy, or international organization unless the Data Protection Authority finds an adequate level of protection.

Ethiopia Personal Data Protection Proclamation, cross-border transfer and data sovereignty

Store personal data collected or obtained in Ethiopia on a server or data center located in Ethiopia, and keep any category of critical personal data the Authority prescribes on a server or data center there.

Kazakhstan Law on Personal Data and Their Protection, localization and cross-border transfer

An app storing or processing the personal data of individuals in Kazakhstan, including a voiceprint or other biometric identifier, must maintain a database located within Kazakhstan; Kazakhstani law does not on its own text forbid an additional copy abroad. Transferring that data to another country requires that the destination state ensure equivalent protection, or one of four fallback grounds: the subject's consent, a ratified treaty, statutory necessity, or protection of constitutional rights where consent cannot be obtained.

Kenya Data Protection Act, 2019, transfer of personal data outside Kenya

Check whether the Cabinet Secretary has designated your category of processing for mandatory handling on a server or data centre located in Kenya.

Russia Federal Law No. 152-FZ, Article 18(5), Data Localization and Cross-Border Transfer, as Amended by Federal Law No. 23-FZ

Record, systematize, accumulate, store, update, and retrieve personal data of Russian citizens in a database physically located in Russia, whether you act as operator or processor, under Federal Law No. 152-FZ Article 18(5) as amended by Federal Law No. 23-FZ.

Rwanda Law relating to the Protection of Personal Data and Privacy, cross-border transfer and data storage

Store personal data in Rwanda, and store it outside Rwanda only where you hold a valid registration certificate from the supervisory authority authorising storage abroad.

Tajikistan Law on the Protection of Personal Data, localization and cross-border transfer

An app storing or processing the personal data of individuals in Tajikistan, including a voiceprint or other biometric identifier, must by default keep the database exclusively inside Tajikistan, unless it has an arrangement agreed with the authorized state body for personal data protection. Transferring that data abroad separately requires the subject's consent, a ratified treaty, statutory necessity, or protection of constitutional rights where consent cannot be obtained.

Show the other 4 laws
Turkmenistan Law on Information About Private Life, localization and cross-border transfer

An app storing or processing the personal information of individuals in Turkmenistan, including a voiceprint or other biometric identifier, must maintain a database located within Turkmenistan; only data contained in that domestic database may be transferred abroad at all. Transfer to another country additionally requires that the destination ensure protection of personal information, or one of four fallback grounds: written consent, a ratified treaty, statutory necessity, or protection of vital interests or constitutional rights where consent cannot be obtained.

Utah Genetic sequencing, storage of genetic information (HB 182) from , in 15 months

Beginning , if you operate a medical facility or genomic research facility, do not store Utah genetic-sequencing data within the territory of a designated foreign adversary, and do not use a genetic sequencer or sequencing software that is a final product of a foreign adversary.

Uzbekistan Law on Personal Data, cross-border transfer and citizen data localization

An app transferring the personal data of an Uzbek data subject outside Uzbekistan must rely on the destination state's adequate protection, or on consent, statutory necessity, or a treaty where adequacy is absent. Separately, an app processing the personal data of Uzbek citizens, including a voiceprint or other biometric identifier, over the internet must collect, systematize, and store that data on technical means physically located in Uzbekistan and register the database in the State Register of Personal Data Bases. Several major platforms have been blocked in Uzbekistan for noncompliance with this storage duty.

Zambia Data Protection Act, 2021, transfer of personal data outside the Republic

Store and process personal data on a server or data centre located in Zambia unless the Minister has prescribed an exception, and do not store sensitive personal data outside Zambia without the data subject's explicit consent.

Biometric privacy

1 law, 1 place
PlaceLawWhat it asks, as read here
Kazakhstan Law on Personal Data and Their Protection, biometric data provisions

An app is not exempt from Kazakhstan's Law on Personal Data merely because biometric data has no dedicated definition in the Act. Collecting biometric data in a public place for identification purposes is restricted to constitutional-order, public-order, rights, health, or morality grounds unless the subject consents, and biometric data stored on Kazakhstani subjects must sit in a database located inside Kazakhstan like any other personal data. Confidentiality of biometric data specifically is deferred to other Kazakh legislation, which the Act does not name and which is not identified here.

Comprehensive regime

1 law, 1 place
PlaceLawWhat it asks, as read here
Burkina Faso Loi n°001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel

Obtain the CIL's authorization, given after the Health Research Ethics Committee's concurring opinion, before processing personal data for health research, anonymize the data before transmission wherever the research's purpose allows it, and host any health data that still permits identification on national territory.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.