Law / Frameworks / NIST Privacy Framework / Identify-P
NIST Privacy Framework, Identify-PID.RA-P3
Potential problematic data actions and associated problems are identified.NIST Privacy Framework, version 1.0, January 2020, ID.RA-P3
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 6
- laws
- 6
- places
- 0
- with court rulings behind them
- 0
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMAP 1.1 Intended purposes, potentially beneficial uses, context-specific laws, norms and...
- NIST AI RMFMAP 5.1 Likelihood and magnitude of each identified impact (both potentially beneficial and...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations1.2 Risk Management
- MIT mitigations1.7 Societal Impact Assessment
- NIST CSF 2.0ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified...
- NIST CSF 2.0ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent...
Comprehensive regime
5 laws, 5 places| Place | Law | What it asks, as read here |
|---|---|---|
| Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11 |
If you are the judicial authority, a body legally empowered to investigate offences, a judicial auxiliary or the prison administration processing personal data under Title V bis for the prevention or detection of offences, investigations, inquiries, criminal prosecutions or the execution of sentences, study the impact of a type of processing likely to create a high risk to a person's rights and freedoms before carrying it out. |
|
| SB 21-190, Colorado Privacy Act (CPA) |
Offer consumers a way to opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects, and complete a data protection assessment before processing that presents a heightened risk of harm. |
|
| Danish Data Protection Act (Databeskyttelsesloven) |
Conduct a Data Protection Impact Assessment for high risk processing under the Databeskyttelsesloven and GDPR Article 35. |
|
| Québec | Act respecting the protection of personal information in the private sector, comprehensive regime |
Establish and implement governance policies and practices for personal information, including a framework for retention and destruction, and conduct a privacy impact assessment before acquiring, developing or overhauling a system or service that collects, uses, communicates, keeps or destroys personal information. |
| Kamerabevakningslagen (Camera Surveillance Act) |
Run a documented impact assessment weighing public interest against individual privacy, and register the surveillance, before operating a camera or optical-electronic monitoring system in Sweden, whether or not it performs facial recognition. |
Enforcement supervision
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| FTC Act Section 5, Unfair or Deceptive Acts or Practices (privacy and data-security enforcement) |
Assess foreseeable privacy harms before deploying a system that collects or uses biometric identifiers derived from photographs, videos, or voice recordings, and disclose material facts about that collection. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.