Law / Frameworks / NIST Privacy Framework / Protect-P
NIST Privacy Framework, Protect-PPR.DS-P3
Systems/products/services and associated data are formally managed throughout removal, transfers, and disposition.NIST Privacy Framework, version 1.0, January 2020, PR.DS-P3
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 1
- law
- 1
- place
- 0
- with court rulings behind them
- 1
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations3.2 Data Governance
- MIT mitigations4.1 System Documentation
- NIST CSF 2.0ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
- NIST CSF 2.0ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
A law in force is unmarked; the rest wear their state: not yet in force
Breach notification
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Arkansas Personal Information Protection Act, breach notification and security from a date not yet set |
Implement and maintain reasonable security procedures and practices to protect Arkansas residents' personal information, and dispose of records containing it in a manner that renders the information unreadable or undecipherable. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.