Law / Frameworks / NIST Privacy Framework / Protect-P

NIST Privacy Framework, Protect-PPR.AC-P4

Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties.NIST Privacy Framework, version 1.0, January 2020, PR.AC-P4

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

20
laws
18
places
0
with court rulings behind them
1
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • Belgium
  • Benin
  • Bosnia and Herzegovina
  • Cabo Verde
  • Democratic Republic of the Congo
  • Italy
  • Kosovo
  • Marshall Islands
  • Mauritius
  • Montenegro
  • Morocco
  • Poland
  • Rwanda
  • Sao Tome and Principe
  • Senegal
  • Turkmenistan
  • United States
  • Vietnam

Sensitive categories

10 laws, 10 places
PlaceLawWhat it asks, as read here
Belgium Act of 30 July 2018 Articles 8-10, Special-Category Processing Grounds

Designate the specific staff with access to genetic, biometric, or health data of a person in Belgium, keep that list available to the GBA/APD, and bind those staff to confidentiality, per Act Article 9.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, données sensibles et mineurs

Designate the categories of staff with access to sensitive personal data, keep that list available to the Autorité, and bind them to confidentiality by a legal, statutory, or contractual obligation.

Cabo Verde Law No. 133/V/2001 on the Protection of Personal Data, sensitive data categories

Take the listed special security measures for sensitive, credit and solvency, and criminal record data, including controlling entry to processing premises, controlling who can read, copy, alter or transmit the data, and logically separating health and sex life data, including genetic data, from other personal data.

Democratic Republic of the Congo Digital Code, Title III, sensitive personal data and minors

Designate by function the staff who may access special-category personal data, keep that list available to the Data Protection Authority, and bind those staff to confidentiality by a legal, statutory or contractual duty.

Kosovo Law No. 06/L-082 on Protection of Personal Data, special categories, children and criminal-offence data

Where you rely on an Article 8(2) exception, protect special categories of personal data with heightened, classified safeguards against unauthorised access and use.

Mauritius Data Protection Act 2017, special categories of personal data

Handle special-category health data only by or under a person bound by professional secrecy where the processing is for preventive or occupational medicine, diagnosis, or healthcare.

Montenegro Law on Personal Data Protection, special categories of data from a date not yet set

Distinctively designate and protect special categories of data against unauthorised access, under Article 13.

Morocco Law No. 09-08, sensitive personal data and offense records

Where you process sensitive or health data, put in place the heightened technical measures Article 24 lists: control who can enter the processing facility, who can read, copy, modify, or remove the data media, and who can access, transmit, or input the data, and keep a record of what sensitive data was input, when, and by whom.

Rwanda Law relating to the Protection of Personal Data and Privacy, sensitive personal data and children's data

When processing sensitive personal data, build the capacity of staff involved, control who can access it, and apply technical and organisational measures appropriate to the risk, including storing it separately and applying tokenisation, pseudonymisation or encryption where appropriate.

Sao Tome and Principe Lei n.º 03/2016, sensitive categories and suspect records

Put in place the special safety measures the Law requires for sensitive or credit data: control of premises entry, data-carrier handling, unauthorized disclosure, system access, transmission, and data-entry logging, and keep health and sex-life data logically separated from other personal data.

Comprehensive regime

5 laws, 5 places
PlaceLawWhat it asks, as read here
Bosnia and Herzegovina Law on the Protection of Personal Data of Bosnia and Herzegovina

Implement technical and organizational measures appropriate to the risk under Article 34, including pseudonymization and encryption where appropriate, and instruct anyone with access to personal data not to process it beyond the controller's authorization.

Cabo Verde Law No. 133/V/2001 on the Protection of Personal Data

Do not process personal data you access in the course of your duties except on the controller's instructions, unless the law requires otherwise, and keep personal data confidential as a matter of professional secrecy, both during and after your role ends.

Democratic Republic of the Congo Digital Code, Title III: Personal Data Protection

Implement technical and organizational measures against unauthorized or unlawful processing and against accidental loss, destruction or alteration, confine internal access to what each role requires, and train staff on their data protection duties.

Marshall Islands Personal Data Protection Act 2025, government personal-data protection principles

Store or process personal data with technical and organizational security measures that protect against unauthorized or unlawful processing and against unintentional loss, destruction, or damage, and limit access to staff who need it for their duties.

Senegal Loi n° 2008-12 du 25 janvier 2008 sur la Protection des Données à Caractère Personnel (Personal Data Protection Act)

Take precautions appropriate to the nature of the data, including restricting access to authorized staff and keeping security copies.

Biometric privacy

4 laws, 4 places
PlaceLawWhat it asks, as read here
Italy Garante Provvedimento n. 146/2019, Genetic, Health, and Biometric Data Prescriptions

Apply Provvedimento 146/2019's security measures (documented access controls, encryption or pseudonymization, controlled transmission) before processing genetic data of a person in Italy.

Poland GDPR Article 9, Act Article 107(2), and Kodeks Pracy Article 22(1b), Biometric Data

Limit an employer's no-consent biometric processing of a Polish employee to controlling access to particularly sensitive information or specially protected premises, and restrict access to authorized, confidentiality-bound staff, per Kodeks pracy Article 22(1b).

Turkmenistan Law on Information About Private Life, biometric information

An app that processes a faceprint, voiceprint, or other biometric identifier of a Turkmen data subject must treat it as automatically confidential and limited to the purpose for which it was collected. The Act's own consent, retention, and destruction rules for biometric data specifically are deferred to other Turkmen legislation, which the Act does not name and which is not identified here.

Vietnam Law on Personal Data Protection, biometric and location data protection

An app that collects or processes biometric data, meaning physical attributes and unique, stable biological characteristics used to identify a person, from an individual in Vietnam must apply physical security measures, limit access, and maintain a monitoring system to detect infringement, and is liable for damage its processing causes.

Cross border transfer

1 law, 1 place
PlaceLawWhat it asks, as read here
United States DOJ Data Security Program (Bulk Sensitive Personal Data Rule)

Apply the required security safeguards to a restricted vendor, employment, or investment transaction that would give a country of concern or covered person access to that data.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.