Law / Frameworks / NIST Privacy Framework / Protect-P
NIST Privacy Framework, Protect-PPR.DS-P2
Data-in-transit are protected.NIST Privacy Framework, version 1.0, January 2020, PR.DS-P2
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 6
- laws
- 6
- places
- 0
- with court rulings behind them
- 0
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of...
- NIST AI RMFMEASURE 2.6 The AI system is evaluated regularly for safety risks – as identified in the MAP...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations2.1 Model & Infrastructure Security
- MIT mitigations2.3 Model Safety Engineering
- NIST CSF 2.0ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
- NIST CSF 2.0ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
Comprehensive regime
3 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| Ley General de Telecomunicaciones, Inviolabilidad y Secreto de las Comunicaciones y Protección de Datos Personales |
Guarantee the inviolability and secrecy of communications you carry as a telecommunications, network, or ICT service provider. |
|
| Telecommunications Act 2005, confidentiality and protection of customer personal information |
Take all reasonable steps to keep customer communications confidential, and do not intercept, monitor, alter, or modify their content except as the Act permits. |
|
| Telecommunications Act 2009, Confidentiality and Consent Duties |
Take all reasonable steps to keep a consumer's communications confidential, and do not intercept, monitor, alter, or modify the content of a message without authorisation. |
Cross border transfer
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Ley para la Protección de Datos Personales, cross border transfer of personal data |
Before transferring personal data to another country or international organization, confirm the receiving country meets at minimum this Law's data protection principles or applicable international standards, and take appropriate measures to secure the data at the point of transfer if the receiving country's protection is not adequate. |
|
| Loi n° 2022-59, transfert transfrontalier des données |
Before any transfer, implement technical and organisational security measures, including encryption and measures for availability, confidentiality, integrity and system resilience, and obtain the HAPDP's authorisation for the transfer. |
Biometric privacy
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Garante Provvedimento n. 146/2019, Genetic, Health, and Biometric Data Prescriptions |
Apply Provvedimento 146/2019's security measures (documented access controls, encryption or pseudonymization, controlled transmission) before processing genetic data of a person in Italy. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.