Law / Frameworks / NIST Privacy Framework / Protect-P
NIST Privacy Framework, Protect-PPR.DS-P1
Data-at-rest are protected.NIST Privacy Framework, version 1.0, January 2020, PR.DS-P1
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 8
- laws
- 8
- places
- 0
- with court rulings behind them
- 0
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of...
- NIST AI RMFMEASURE 2.6 The AI system is evaluated regularly for safety risks – as identified in the MAP...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations2.1 Model & Infrastructure Security
- MIT mitigations2.3 Model Safety Engineering
- NIST CSF 2.0ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
- NIST CSF 2.0ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
Comprehensive regime
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 124/2024 On the Protection of Personal Data |
Implement technical and organizational security measures appropriate to the risk, including pseudonymization and encryption, the ability to restore access after an incident, and a process for regularly testing their effectiveness. |
|
| Data Protection Act, 2019 |
Implement technical and organisational measures giving a level of security appropriate to the risk, including pseudonymisation and encryption of personal data, the ability to restore availability and access in a timely manner after a physical or technical incident, and a process for regularly testing their effectiveness. |
|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel) |
Implement appropriate technical and organizational measures against unauthorized or unlawful processing and against accidental loss, destruction, or damage, including pseudonymization and encryption where appropriate, and test their effectiveness regularly. |
|
| Law on the Protection of Personal Data of Bosnia and Herzegovina |
Implement technical and organizational measures appropriate to the risk under Article 34, including pseudonymization and encryption where appropriate, and instruct anyone with access to personal data not to process it beyond the controller's authorization. |
Biometric privacy
3 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| Protection of Privacy Law, biometric identifier definition and security-level tiering |
An app that captures or stores a facial image, voiceprint, or other biometric identifier of a person in Israel, including one derived from a photo, video, or audio recording, must treat it as data of special sensitivity and apply Israel's tiered security-level obligations, which scale up automatically at 100,000 or more biometric identifiers held. |
|
| Garante Provvedimento n. 146/2019, Genetic, Health, and Biometric Data Prescriptions |
Apply Provvedimento 146/2019's security measures (documented access controls, encryption or pseudonymization, controlled transmission) before processing genetic data of a person in Italy. |
|
| Capture or Use of Biometric Identifier Act (CUBI), as amended by HB 149 |
Store and transmit a captured biometric identifier with reasonable care equal to or exceeding the protection given your other confidential information, and destroy it within a reasonable time, no later than the first anniversary of when the collection purpose expires. |
Sensitive categories
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Law relating to the Protection of Personal Data and Privacy, sensitive personal data and children's data |
When processing sensitive personal data, build the capacity of staff involved, control who can access it, and apply technical and organisational measures appropriate to the risk, including storing it separately and applying tokenisation, pseudonymisation or encryption where appropriate. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.