Law / Frameworks / NIST Privacy Framework / Identify-P
NIST Privacy Framework, Identify-PID.RA-P4
Problematic data actions, likelihoods, and impacts are used to determine and prioritize risk.NIST Privacy Framework, version 1.0, January 2020, ID.RA-P4
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 44
- laws
- 41
- places
- 0
- with court rulings behind them
- 4
- not yet in force
- 2
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMAP 1.1 Intended purposes, potentially beneficial uses, context-specific laws, norms and...
- NIST AI RMFMAP 5.1 Likelihood and magnitude of each identified impact (both potentially beneficial and...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations1.2 Risk Management
- MIT mitigations1.7 Societal Impact Assessment
- NIST CSF 2.0ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified...
- NIST CSF 2.0ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent...
A law in force is unmarked; the rest wear their state: not yet in force proposed
Comprehensive regime
29 laws, 29 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 124/2024 On the Protection of Personal Data |
From two years after the law's publication in the Official Gazette, carry out a data protection impact assessment before processing likely to result in a high risk to the rights and freedoms of a person in Albania, and seek the Commissioner's opinion in advance where the risk cannot be mitigated; until then, Articles 31 and 32 do not themselves bind. |
|
| LQPD, Llei 29/2021 del 28 d'octubre |
Carry out a data protection impact assessment before high-risk processing such as systematic automated evaluation with legal effects, large-scale special-category processing, or large-scale systematic monitoring of a publicly accessible area, and consult the Agency first where the assessment shows a risk you have not mitigated. |
|
| Data Protection Act, 2019 |
Carry out a data protection impact assessment before any type of processing, in particular using new technologies, that is likely to result in a high risk to the rights and freedoms of an individual, taking the advice of the data privacy officer where one is designated, and consult the Commissioner beforehand where the assessment shows a high risk. |
|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel) |
Carry out a data protection impact assessment before a processing likely to create a high risk to individuals' rights and freedoms, and consult the Autorité first where the assessment shows a risk you cannot mitigate. |
|
| Law on the Protection of Personal Data of Bosnia and Herzegovina |
Carry out a data protection impact assessment under Article 37 before processing likely to result in a high risk to a person's rights and freedoms, and consult the Agency in advance under Article 38 wherever the assessment shows a high risk the controller cannot mitigate. |
|
| Data Protection Act, 2024 (Act No. 18 of 2024) |
Carry out a data protection impact assessment before processing that is likely to result in a high risk to a natural person's rights and freedoms, and designate a data protection officer where your core activities require regular and systematic large-scale monitoring, or large-scale processing of sensitive personal data or of data relating to criminal convictions and offences. |
|
| Draft Law on Personal Data Protection, final draft proposed |
If enacted as drafted, a data controller determining that its processing may pose a high risk to a data subject's rights and freedoms would have to conduct a personal data impact assessment and submit its report to the Ministry of Post and Telecommunications. |
|
| Superintendencia Circular on AI and Personal Data |
Weigh whether processing personal data in an artificial intelligence system is suitable to the goal pursued, necessary because no less intrusive measure achieves it equally well, reasonable because it serves a constitutional purpose, and proportionate because its benefits are not outweighed by the harm to the right to data protection. Complete and document a privacy impact assessment before an artificial intelligence system likely to pose a high risk to data subjects processes their personal data, covering the processing operations, a risk evaluation, and the measures planned to prevent the risks identified. |
|
| Digital Code, Title III: Personal Data Protection |
Carry out a data protection impact assessment before processing likely to create a high risk to individuals' rights and freedoms, and consult the Data Protection Authority in advance where that assessment shows a high risk you have not sufficiently mitigated. |
|
| LOPDP, comprehensive personal-data protection regime |
Carry out an impact assessment of the processing where article 42 requires one. |
Show the other 19 laws
| Personal Data Protection Proclamation |
Carry out a data protection impact assessment before processing that may risk data subjects' rights and freedoms, including systematic and extensive evaluation based on automated processing, large-scale processing of sensitive personal data, and systematic monitoring of a publicly accessible area on a large scale. |
|
| Personal Data Protection and Privacy Act, 2025 from a date not yet set |
Carry out a data protection impact assessment before high-risk processing such as profiling or large-scale surveillance. |
|
| DPC Guidance: AI, Large Language Models and Data Protection |
Perform a data protection impact assessment before training or deploying an AI system on personal data of people in Ireland where the processing is new to you, combines data sets, or may involve minors or vulnerable people. |
|
| Data Protection Act, 2020, registration, lawful basis and standards for processing |
Submit a data protection impact assessment covering all personal data in your custody or control to the Information Commissioner within 90 days after the end of each calendar year. |
|
| Data Protection Act 2025 from a date not yet set |
On commencement, if you are a controller of major importance, carry out a data protection impact assessment and submit the report to the Digital Transformation Office before processing likely to expose 10,000 or more data subjects to a high risk of significant harm, and proceed only with the Office's approval if the risk remains high after mitigation; this duty does not apply until the second anniversary of commencement. |
|
| Law No. 06/L-082 on Protection of Personal Data |
Carry out a data protection impact assessment before high-risk processing such as systematic automated evaluation with legal effects, large-scale special-category processing, or large-scale systematic monitoring of a publicly accessible area, and consult the Agency first where the assessment shows a risk you cannot mitigate. |
|
| Law No. 195/2024 on Personal Data Protection |
Carry out a data protection impact assessment before processing likely to result in a high risk, and consult the National Centre for Personal Data Protection beforehand where that risk remains. |
|
| Loi sur la Protection des Données Personnelles |
Carry out a data protection impact assessment before processing likely to create a high risk to a person's rights and freedoms, such as large scale profiling with legal effects, large scale sensitive data processing, large scale public area surveillance, or large scale use of a digital identifier, and consult the Authority first where the assessment still shows a high risk you cannot mitigate. |
|
| Loi n° 2022-59, protection des données à caractère personnel |
Carry out a privacy impact assessment before implementing a sensitive or high-risk processing operation the HAPDP requires one for. |
|
| Nigeria Data Protection Act, 2023 (NDPA), general data protection duties |
Carry out a Data Privacy Impact Assessment where required, including where deploying software to process sensitive personal data, and file it with the Commission. Before deploying data processing software that tracks a data subject or opens a communication link with one, carry out an impact assessment, design it for privacy by design and by default, put a data privacy policy inside the software, and give a prospective user a privacy statement before installation. |
|
| Ley N° 7593/2025, de Protección de Datos Personales en la República del Paraguay from , in 14 months |
Carry out an impact assessment before implementing processing that warrants one, and consult the supervisory authority beforehand where article 15 requires it. |
|
| Law No. 29-2019 on the Protection of Personal Data |
Carry out a data protection impact assessment before a type of processing likely to create a high risk to the rights and freedoms of natural persons, and designate a data protection officer where article 83 requires one. |
|
| Law relating to the Protection of Personal Data and Privacy |
Carry out a data protection impact assessment before processing likely to result in a high risk to a natural person's rights and freedoms, including large-scale processing of sensitive personal data or systematic monitoring of a publicly accessible area on a large scale. |
|
| San Marino Law No. 171 on the Protection of Natural Persons |
Carry out a data protection impact assessment before processing likely to result in a high risk, and consult the Data Protection Authority beforehand where the assessment shows that risk remains. |
|
| Law on Personal Data Protection |
Carry out a data protection impact assessment before processing likely to create high risk to a person's rights and freedoms, and consult the Commissioner first where the assessment shows the risk cannot be brought down. |
|
| Data Protection Act No. 005 of 2023 |
As a data controller of major importance, carry out a data protection impact assessment before processing likely to result in a high risk to a data subject, and submit the assessment report to the Authority before you start. |
|
| Draft Law No. 8153 on Personal Data Protection (GDPR-Aligned Reform) proposed |
Once enacted, carry out a data protection impact assessment under Article 39 before processing that involves systematic automated analysis or another high risk activity. |
|
| Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended |
Adopt privacy-by-design, privacy-by-default, and data-protection impact assessment measures as part of a proactive-accountability duty, and be able to demonstrate their effective implementation. |
|
| Data Protection Act, 2021, personal data processing framework |
Carry out a data protection impact assessment before processing that uses new technologies and is likely to result in a high risk, and in particular before automated processing including profiling that produces legal effects, large-scale processing of sensitive personal data, or systematic monitoring of a publicly accessible area on a large scale. |
Sensitive categories
6 laws, 6 places| Place | Law | What it asks, as read here |
|---|---|---|
| SB 24-041, Protecting Minors' Online Data |
If you offer an online service, product, or feature that you actually know or willfully disregard is used by a minor, use reasonable care to avoid a heightened risk of harm to that minor, and complete a data protection assessment where that risk exists. |
|
| GDPR Article 9, Special Categories of Personal Data as Applied in Lithuania |
Conduct a data protection impact assessment before processing biometric data or telephone-conversation recordings of a person in Lithuania, per VDAI guidance describing these as triggering situations. |
|
| Nigeria Data Protection Act, 2023, sensitive personal data and a child's data |
Document those parameters and file them with the Commission as part of your Compliance Audit Returns, with an impact assessment that weighs disparate outcomes of the processing and the Data Subjects' Vulnerability Indexes in Schedule 6. |
|
| FADP Article 5 lit. c, Sensitive Personal Data Including Biometric Data |
Perform a Data Protection Impact Assessment before large-scale processing of biometric or other sensitive personal data, or before systematic large-scale public-space monitoring, under FADP Article 22. |
|
| R (Bridges) v Chief Constable of South Wales Police, Automated Facial Recognition by Police |
If you are a public authority deploying facial recognition or another biometric surveillance system in the United Kingdom, put an adequate legal framework and a proper Data Protection Impact Assessment in place before deployment, not after. |
|
| Cyber and Data Protection Regulations 2024, children's information and automated decisions |
Conduct regular data protection impact assessments to identify and mitigate privacy risks to children, and ensure data protection by design and by default when processing children's data. |
Data subject rights
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Personal Information Protection Law, automated decisions |
Complete a personal-information-protection impact assessment before deploying automated decision-making, and keep the assessment report and the processing record for at least three years. |
|
| GDPR Articles 12-21 and Law 125(I)/2018 Article 11, Data Subject Rights in Cyprus |
Before you restrict, in whole or in part, a person's rights under GDPR Articles 12, 18, 19 or 20 in Cyprus on a ground in GDPR Article 23(1), carry out an impact assessment and consult the Commissioner, and tell the person about the restriction, under Law 125(I)/2018 Article 11. |
|
| SPDP Norma General guaranteeing personal-data protection in the use of AI systems from a date not yet set |
Before developing an AI system that will process personal data, carry out a risk-management process and an impact assessment. |
|
| Texas Data Privacy and Security Act, consumer rights and assessments |
Conduct and document a data protection assessment before targeted advertising, sale of personal data, certain profiling, or sensitive-data processing. |
Biometric privacy
3 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| CNIL Standard Regulation on Workplace Biometric Access Control (Deliberation No. 2019-001) |
Run a data protection impact assessment and document why a less intrusive alternative was rejected before deploying a biometric access-control system for employees or building access in France. |
|
| GDPR Article 9, Dataskyddslagen Chapter 3, and the IMY Skelleftea Facial-Recognition Decision |
Obtain a GDPR Article 9(2) basis, and expect weighty grounds plus a data protection impact assessment to be required, before deploying a biometric identification system in Sweden. |
|
| Ley N° 18.331, biometric data |
Before processing biometric data, such as fingerprint data or facial or voice recognition used to identify a person, carry out a data protection impact assessment. |
Breach notification
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Data Protection (General) Regulations, 2021 |
Conduct a data protection impact assessment before undertaking automated decision-making or profiling that has a legal or similarly significant effect on a data subject. |
Cross border transfer
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Québec | Privacy impact assessment before communicating personal information outside Québec |
Before communicating personal information outside Québec, or having a person or body outside Québec collect, use, communicate or keep it on your behalf, conduct a privacy impact assessment covering the information's sensitivity, its intended use, available protection measures including contractual ones, and the destination's legal framework. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.