Law / Frameworks / NIST Privacy Framework / Identify-P
NIST Privacy Framework, Identify-PID.RA-P5
Risk responses are identified, prioritized, and implemented.NIST Privacy Framework, version 1.0, January 2020, ID.RA-P5
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 10
- laws
- 10
- places
- 0
- with court rulings behind them
- 1
- not yet in force
- 1
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMAP 1.1 Intended purposes, potentially beneficial uses, context-specific laws, norms and...
- NIST AI RMFMAP 5.1 Likelihood and magnitude of each identified impact (both potentially beneficial and...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations1.2 Risk Management
- MIT mitigations1.7 Societal Impact Assessment
- NIST CSF 2.0ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified...
- NIST CSF 2.0ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent...
A law in force is unmarked; the rest wear their state: not yet in force proposed
Sensitive categories
7 laws, 7 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law of the Republic of Belarus On Personal Data Protection, special personal data |
Adopt a set of measures against the risks processing poses to a personal data subject's rights and freedoms before relying on any Article 8 exception to process special personal data. |
|
| SB 24-041, Protecting Minors' Online Data |
If you offer an online service, product, or feature that you actually know or willfully disregard is used by a minor, use reasonable care to avoid a heightened risk of harm to that minor, and complete a data protection assessment where that risk exists. |
|
| Personal Data Protection and Privacy Act, 2025, sensitive personal data and children's data from a date not yet set |
Apply specific safeguards to any marketing or profiling directed at children, and put anything addressed to a child in clear, plain language they can easily understand. |
|
| Law No. 2014-038, sensitive personal data |
Where an exception permits sensitive data to be processed, put in place the safeguards the law or the CMIL requires for that exception. |
|
| Loi sur la Protection des Données Personnelles, données sensibles et mineurs |
Put safeguards in place to prevent discrimination or another risk to a person's rights and freedoms wherever an exception lets you process their sensitive data on a public interest, medical, or archival, research, or statistical ground. |
|
| Data Protection Act, sensitive personal data |
Where you rely on the vital-interests or right-or-obligation grounds to process sensitive personal data without consent, put appropriate safeguards in place first. |
|
| Draft Law on the Protection of Privacy and Personal Data, special categories, children and criminal data proposed |
Take particular care when you do process the data listed above, so it does not cause unfair discrimination, prejudice, or other harm to the data subject. |
Comprehensive regime
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Superintendencia Circular on AI and Personal Data |
Where you cannot be certain an artificial intelligence system's processing will not cause serious, irreversible harm, refrain from that processing or adopt precautionary measures, and adapt your risk management systems to identify, measure, control and monitor the situations that could affect your compliance with personal data protection rules. |
|
| Law on Personal Data Protection (LPDP), video surveillance |
Analyse the goal of a video surveillance system before installing it, and reassess it every two years, covering the continuing need for it, its goals, and feasible technical alternatives. |
Biometric privacy
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| CNIL Standard Regulation on Workplace Biometric Access Control (Deliberation No. 2019-001) |
Run a data protection impact assessment and document why a less intrusive alternative was rejected before deploying a biometric access-control system for employees or building access in France. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.