Law / Frameworks / NIST Privacy Framework / Protect-P

NIST Privacy Framework, Protect-PPR.DS-P1

Data-at-rest are protected.NIST Privacy Framework, version 1.0, January 2020, PR.DS-P1

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

8
laws
8
places
0
with court rulings behind them
0
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

  • Albania
  • Barbados
  • Benin
  • Bosnia and Herzegovina
  • Israel
  • Italy
  • Rwanda
  • Texas

Comprehensive regime

4 laws, 4 places
PlaceLawWhat it asks, as read here
Albania Law No. 124/2024 On the Protection of Personal Data

Implement technical and organizational security measures appropriate to the risk, including pseudonymization and encryption, the ability to restore access after an incident, and a process for regularly testing their effectiveness.

Barbados Data Protection Act, 2019

Implement technical and organisational measures giving a level of security appropriate to the risk, including pseudonymisation and encryption of personal data, the ability to restore availability and access in a timely manner after a physical or technical incident, and a process for regularly testing their effectiveness.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel)

Implement appropriate technical and organizational measures against unauthorized or unlawful processing and against accidental loss, destruction, or damage, including pseudonymization and encryption where appropriate, and test their effectiveness regularly.

Bosnia and Herzegovina Law on the Protection of Personal Data of Bosnia and Herzegovina

Implement technical and organizational measures appropriate to the risk under Article 34, including pseudonymization and encryption where appropriate, and instruct anyone with access to personal data not to process it beyond the controller's authorization.

Biometric privacy

3 laws, 3 places
PlaceLawWhat it asks, as read here
Israel Protection of Privacy Law, biometric identifier definition and security-level tiering

An app that captures or stores a facial image, voiceprint, or other biometric identifier of a person in Israel, including one derived from a photo, video, or audio recording, must treat it as data of special sensitivity and apply Israel's tiered security-level obligations, which scale up automatically at 100,000 or more biometric identifiers held.

Italy Garante Provvedimento n. 146/2019, Genetic, Health, and Biometric Data Prescriptions

Apply Provvedimento 146/2019's security measures (documented access controls, encryption or pseudonymization, controlled transmission) before processing genetic data of a person in Italy.

Texas Capture or Use of Biometric Identifier Act (CUBI), as amended by HB 149

Store and transmit a captured biometric identifier with reasonable care equal to or exceeding the protection given your other confidential information, and destroy it within a reasonable time, no later than the first anniversary of when the collection purpose expires.

Sensitive categories

1 law, 1 place
PlaceLawWhat it asks, as read here
Rwanda Law relating to the Protection of Personal Data and Privacy, sensitive personal data and children's data

When processing sensitive personal data, build the capacity of staff involved, control who can access it, and apply technical and organisational measures appropriate to the risk, including storing it separately and applying tokenisation, pseudonymisation or encryption where appropriate.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.