Law / Frameworks / NIST Privacy Framework / Identify-P

NIST Privacy Framework, Identify-PID.RA-P4

Problematic data actions, likelihoods, and impacts are used to determine and prioritize risk.NIST Privacy Framework, version 1.0, January 2020, ID.RA-P4

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

44
laws
41
places
0
with court rulings behind them
4
not yet in force
2
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Albania
  • Andorra
  • Barbados
  • Benin
  • Bosnia and Herzegovina
  • Botswana
  • Cambodia
  • China
  • Colombia
  • Colorado
  • Cyprus
  • Democratic Republic of the Congo
  • Ecuador
  • Ethiopia
  • France
  • Gambia
  • Ireland
  • Jamaica
  • Kenya
  • Kiribati
  • Kosovo
  • Lithuania
  • Moldova
  • Monaco
  • Niger
  • Nigeria
  • Paraguay
  • Republic of the Congo
  • Rwanda
  • San Marino
  • Serbia
  • Somalia
  • Sweden
  • Switzerland
  • Texas
  • Ukraine
  • United Kingdom
  • Uruguay
  • Zambia
  • Zimbabwe

Comprehensive regime

29 laws, 29 places
PlaceLawWhat it asks, as read here
Albania Law No. 124/2024 On the Protection of Personal Data

From two years after the law's publication in the Official Gazette, carry out a data protection impact assessment before processing likely to result in a high risk to the rights and freedoms of a person in Albania, and seek the Commissioner's opinion in advance where the risk cannot be mitigated; until then, Articles 31 and 32 do not themselves bind.

Andorra LQPD, Llei 29/2021 del 28 d'octubre

Carry out a data protection impact assessment before high-risk processing such as systematic automated evaluation with legal effects, large-scale special-category processing, or large-scale systematic monitoring of a publicly accessible area, and consult the Agency first where the assessment shows a risk you have not mitigated.

Barbados Data Protection Act, 2019

Carry out a data protection impact assessment before any type of processing, in particular using new technologies, that is likely to result in a high risk to the rights and freedoms of an individual, taking the advice of the data privacy officer where one is designated, and consult the Commissioner beforehand where the assessment shows a high risk.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel)

Carry out a data protection impact assessment before a processing likely to create a high risk to individuals' rights and freedoms, and consult the Autorité first where the assessment shows a risk you cannot mitigate.

Bosnia and Herzegovina Law on the Protection of Personal Data of Bosnia and Herzegovina

Carry out a data protection impact assessment under Article 37 before processing likely to result in a high risk to a person's rights and freedoms, and consult the Agency in advance under Article 38 wherever the assessment shows a high risk the controller cannot mitigate.

Botswana Data Protection Act, 2024 (Act No. 18 of 2024)

Carry out a data protection impact assessment before processing that is likely to result in a high risk to a natural person's rights and freedoms, and designate a data protection officer where your core activities require regular and systematic large-scale monitoring, or large-scale processing of sensitive personal data or of data relating to criminal convictions and offences.

Cambodia Draft Law on Personal Data Protection, final draft proposed

If enacted as drafted, a data controller determining that its processing may pose a high risk to a data subject's rights and freedoms would have to conduct a personal data impact assessment and submit its report to the Ministry of Post and Telecommunications.

Colombia Superintendencia Circular on AI and Personal Data

Weigh whether processing personal data in an artificial intelligence system is suitable to the goal pursued, necessary because no less intrusive measure achieves it equally well, reasonable because it serves a constitutional purpose, and proportionate because its benefits are not outweighed by the harm to the right to data protection.

Complete and document a privacy impact assessment before an artificial intelligence system likely to pose a high risk to data subjects processes their personal data, covering the processing operations, a risk evaluation, and the measures planned to prevent the risks identified.

Democratic Republic of the Congo Digital Code, Title III: Personal Data Protection

Carry out a data protection impact assessment before processing likely to create a high risk to individuals' rights and freedoms, and consult the Data Protection Authority in advance where that assessment shows a high risk you have not sufficiently mitigated.

Ecuador LOPDP, comprehensive personal-data protection regime

Carry out an impact assessment of the processing where article 42 requires one.

Show the other 19 laws
Ethiopia Personal Data Protection Proclamation

Carry out a data protection impact assessment before processing that may risk data subjects' rights and freedoms, including systematic and extensive evaluation based on automated processing, large-scale processing of sensitive personal data, and systematic monitoring of a publicly accessible area on a large scale.

Gambia Personal Data Protection and Privacy Act, 2025 from a date not yet set

Carry out a data protection impact assessment before high-risk processing such as profiling or large-scale surveillance.

Ireland DPC Guidance: AI, Large Language Models and Data Protection

Perform a data protection impact assessment before training or deploying an AI system on personal data of people in Ireland where the processing is new to you, combines data sets, or may involve minors or vulnerable people.

Jamaica Data Protection Act, 2020, registration, lawful basis and standards for processing

Submit a data protection impact assessment covering all personal data in your custody or control to the Information Commissioner within 90 days after the end of each calendar year.

Kiribati Data Protection Act 2025 from a date not yet set

On commencement, if you are a controller of major importance, carry out a data protection impact assessment and submit the report to the Digital Transformation Office before processing likely to expose 10,000 or more data subjects to a high risk of significant harm, and proceed only with the Office's approval if the risk remains high after mitigation; this duty does not apply until the second anniversary of commencement.

Kosovo Law No. 06/L-082 on Protection of Personal Data

Carry out a data protection impact assessment before high-risk processing such as systematic automated evaluation with legal effects, large-scale special-category processing, or large-scale systematic monitoring of a publicly accessible area, and consult the Agency first where the assessment shows a risk you cannot mitigate.

Moldova Law No. 195/2024 on Personal Data Protection

Carry out a data protection impact assessment before processing likely to result in a high risk, and consult the National Centre for Personal Data Protection beforehand where that risk remains.

Monaco Loi sur la Protection des Données Personnelles

Carry out a data protection impact assessment before processing likely to create a high risk to a person's rights and freedoms, such as large scale profiling with legal effects, large scale sensitive data processing, large scale public area surveillance, or large scale use of a digital identifier, and consult the Authority first where the assessment still shows a high risk you cannot mitigate.

Niger Loi n° 2022-59, protection des données à caractère personnel

Carry out a privacy impact assessment before implementing a sensitive or high-risk processing operation the HAPDP requires one for.

Nigeria Nigeria Data Protection Act, 2023 (NDPA), general data protection duties

Carry out a Data Privacy Impact Assessment where required, including where deploying software to process sensitive personal data, and file it with the Commission.

Before deploying data processing software that tracks a data subject or opens a communication link with one, carry out an impact assessment, design it for privacy by design and by default, put a data privacy policy inside the software, and give a prospective user a privacy statement before installation.

Paraguay Ley N° 7593/2025, de Protección de Datos Personales en la República del Paraguay from , in 14 months

Carry out an impact assessment before implementing processing that warrants one, and consult the supervisory authority beforehand where article 15 requires it.

Republic of the Congo Law No. 29-2019 on the Protection of Personal Data

Carry out a data protection impact assessment before a type of processing likely to create a high risk to the rights and freedoms of natural persons, and designate a data protection officer where article 83 requires one.

Rwanda Law relating to the Protection of Personal Data and Privacy

Carry out a data protection impact assessment before processing likely to result in a high risk to a natural person's rights and freedoms, including large-scale processing of sensitive personal data or systematic monitoring of a publicly accessible area on a large scale.

San Marino San Marino Law No. 171 on the Protection of Natural Persons

Carry out a data protection impact assessment before processing likely to result in a high risk, and consult the Data Protection Authority beforehand where the assessment shows that risk remains.

Serbia Law on Personal Data Protection

Carry out a data protection impact assessment before processing likely to create high risk to a person's rights and freedoms, and consult the Commissioner first where the assessment shows the risk cannot be brought down.

Somalia Data Protection Act No. 005 of 2023

As a data controller of major importance, carry out a data protection impact assessment before processing likely to result in a high risk to a data subject, and submit the assessment report to the Authority before you start.

Ukraine Draft Law No. 8153 on Personal Data Protection (GDPR-Aligned Reform) proposed

Once enacted, carry out a data protection impact assessment under Article 39 before processing that involves systematic automated analysis or another high risk activity.

Uruguay Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended

Adopt privacy-by-design, privacy-by-default, and data-protection impact assessment measures as part of a proactive-accountability duty, and be able to demonstrate their effective implementation.

Zambia Data Protection Act, 2021, personal data processing framework

Carry out a data protection impact assessment before processing that uses new technologies and is likely to result in a high risk, and in particular before automated processing including profiling that produces legal effects, large-scale processing of sensitive personal data, or systematic monitoring of a publicly accessible area on a large scale.

Sensitive categories

6 laws, 6 places
PlaceLawWhat it asks, as read here
Colorado SB 24-041, Protecting Minors' Online Data

If you offer an online service, product, or feature that you actually know or willfully disregard is used by a minor, use reasonable care to avoid a heightened risk of harm to that minor, and complete a data protection assessment where that risk exists.

Lithuania GDPR Article 9, Special Categories of Personal Data as Applied in Lithuania

Conduct a data protection impact assessment before processing biometric data or telephone-conversation recordings of a person in Lithuania, per VDAI guidance describing these as triggering situations.

Nigeria Nigeria Data Protection Act, 2023, sensitive personal data and a child's data

Document those parameters and file them with the Commission as part of your Compliance Audit Returns, with an impact assessment that weighs disparate outcomes of the processing and the Data Subjects' Vulnerability Indexes in Schedule 6.

Switzerland FADP Article 5 lit. c, Sensitive Personal Data Including Biometric Data

Perform a Data Protection Impact Assessment before large-scale processing of biometric or other sensitive personal data, or before systematic large-scale public-space monitoring, under FADP Article 22.

United Kingdom R (Bridges) v Chief Constable of South Wales Police, Automated Facial Recognition by Police

If you are a public authority deploying facial recognition or another biometric surveillance system in the United Kingdom, put an adequate legal framework and a proper Data Protection Impact Assessment in place before deployment, not after.

Zimbabwe Cyber and Data Protection Regulations 2024, children's information and automated decisions

Conduct regular data protection impact assessments to identify and mitigate privacy risks to children, and ensure data protection by design and by default when processing children's data.

Data subject rights

4 laws, 4 places
PlaceLawWhat it asks, as read here
China Personal Information Protection Law, automated decisions

Complete a personal-information-protection impact assessment before deploying automated decision-making, and keep the assessment report and the processing record for at least three years.

Cyprus GDPR Articles 12-21 and Law 125(I)/2018 Article 11, Data Subject Rights in Cyprus

Before you restrict, in whole or in part, a person's rights under GDPR Articles 12, 18, 19 or 20 in Cyprus on a ground in GDPR Article 23(1), carry out an impact assessment and consult the Commissioner, and tell the person about the restriction, under Law 125(I)/2018 Article 11.

Ecuador SPDP Norma General guaranteeing personal-data protection in the use of AI systems from a date not yet set

Before developing an AI system that will process personal data, carry out a risk-management process and an impact assessment.

Texas Texas Data Privacy and Security Act, consumer rights and assessments

Conduct and document a data protection assessment before targeted advertising, sale of personal data, certain profiling, or sensitive-data processing.

Biometric privacy

3 laws, 3 places
PlaceLawWhat it asks, as read here
France CNIL Standard Regulation on Workplace Biometric Access Control (Deliberation No. 2019-001)

Run a data protection impact assessment and document why a less intrusive alternative was rejected before deploying a biometric access-control system for employees or building access in France.

Sweden GDPR Article 9, Dataskyddslagen Chapter 3, and the IMY Skelleftea Facial-Recognition Decision

Obtain a GDPR Article 9(2) basis, and expect weighty grounds plus a data protection impact assessment to be required, before deploying a biometric identification system in Sweden.

Uruguay Ley N° 18.331, biometric data

Before processing biometric data, such as fingerprint data or facial or voice recognition used to identify a person, carry out a data protection impact assessment.

Breach notification

1 law, 1 place
PlaceLawWhat it asks, as read here
Kenya Data Protection (General) Regulations, 2021

Conduct a data protection impact assessment before undertaking automated decision-making or profiling that has a legal or similarly significant effect on a data subject.

Cross border transfer

1 law, 1 place
PlaceLawWhat it asks, as read here
Québec Privacy impact assessment before communicating personal information outside Québec

Before communicating personal information outside Québec, or having a person or body outside Québec collect, use, communicate or keep it on your behalf, conduct a privacy impact assessment covering the information's sensitivity, its intended use, available protection measures including contractual ones, and the destination's legal framework.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.