Law / Frameworks / NIST Privacy Framework / Identify-P

NIST Privacy Framework, Identify-PID.RA-P3

Potential problematic data actions and associated problems are identified.NIST Privacy Framework, version 1.0, January 2020, ID.RA-P3

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

6
laws
6
places
0
with court rulings behind them
0
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

  • Algeria
  • Colorado
  • Denmark
  • Sweden
  • United States

Comprehensive regime

5 laws, 5 places
PlaceLawWhat it asks, as read here
Algeria Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11

If you are the judicial authority, a body legally empowered to investigate offences, a judicial auxiliary or the prison administration processing personal data under Title V bis for the prevention or detection of offences, investigations, inquiries, criminal prosecutions or the execution of sentences, study the impact of a type of processing likely to create a high risk to a person's rights and freedoms before carrying it out.

Colorado SB 21-190, Colorado Privacy Act (CPA)

Offer consumers a way to opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects, and complete a data protection assessment before processing that presents a heightened risk of harm.

Denmark Danish Data Protection Act (Databeskyttelsesloven)

Conduct a Data Protection Impact Assessment for high risk processing under the Databeskyttelsesloven and GDPR Article 35.

Québec Act respecting the protection of personal information in the private sector, comprehensive regime

Establish and implement governance policies and practices for personal information, including a framework for retention and destruction, and conduct a privacy impact assessment before acquiring, developing or overhauling a system or service that collects, uses, communicates, keeps or destroys personal information.

Sweden Kamerabevakningslagen (Camera Surveillance Act)

Run a documented impact assessment weighing public interest against individual privacy, and register the surveillance, before operating a camera or optical-electronic monitoring system in Sweden, whether or not it performs facial recognition.

Enforcement supervision

1 law, 1 place
PlaceLawWhat it asks, as read here
United States FTC Act Section 5, Unfair or Deceptive Acts or Practices (privacy and data-security enforcement)

Assess foreseeable privacy harms before deploying a system that collects or uses biometric identifiers derived from photographs, videos, or voice recordings, and disclose material facts about that collection.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.