Law / Frameworks / NIST Privacy Framework / Protect-P

NIST Privacy Framework, Protect-PPR.DS-P2

Data-in-transit are protected.NIST Privacy Framework, version 1.0, January 2020, PR.DS-P2

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

6
laws
6
places
0
with court rulings behind them
0
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

  • Bolivia
  • El Salvador
  • Italy
  • Niger
  • Samoa
  • Solomon Islands

Comprehensive regime

3 laws, 3 places
PlaceLawWhat it asks, as read here
Bolivia Ley General de Telecomunicaciones, Inviolabilidad y Secreto de las Comunicaciones y Protección de Datos Personales

Guarantee the inviolability and secrecy of communications you carry as a telecommunications, network, or ICT service provider.

Samoa Telecommunications Act 2005, confidentiality and protection of customer personal information

Take all reasonable steps to keep customer communications confidential, and do not intercept, monitor, alter, or modify their content except as the Act permits.

Solomon Islands Telecommunications Act 2009, Confidentiality and Consent Duties

Take all reasonable steps to keep a consumer's communications confidential, and do not intercept, monitor, alter, or modify the content of a message without authorisation.

Cross border transfer

2 laws, 2 places
PlaceLawWhat it asks, as read here
El Salvador Ley para la Protección de Datos Personales, cross border transfer of personal data

Before transferring personal data to another country or international organization, confirm the receiving country meets at minimum this Law's data protection principles or applicable international standards, and take appropriate measures to secure the data at the point of transfer if the receiving country's protection is not adequate.

Niger Loi n° 2022-59, transfert transfrontalier des données

Before any transfer, implement technical and organisational security measures, including encryption and measures for availability, confidentiality, integrity and system resilience, and obtain the HAPDP's authorisation for the transfer.

Biometric privacy

1 law, 1 place
PlaceLawWhat it asks, as read here
Italy Garante Provvedimento n. 146/2019, Genetic, Health, and Biometric Data Prescriptions

Apply Provvedimento 146/2019's security measures (documented access controls, encryption or pseudonymization, controlled transmission) before processing genetic data of a person in Italy.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.