Law / Frameworks / NIST Privacy Framework / Protect-P

NIST Privacy Framework, Protect-PPR.DS-P5

Protections against data leaks are implemented.NIST Privacy Framework, version 1.0, January 2020, PR.DS-P5

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

94
laws
78
places
0
with court rulings behind them
7
not yet in force
3
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Albania
  • Algeria
  • Andorra
  • Angola
  • Antigua and Barbuda
  • Argentina
  • Arkansas
  • Belarus
  • Bolivia
  • Botswana
  • Brazil
  • Burkina Faso
  • Cabo Verde
  • California
  • Cambodia
  • Central African Republic
  • Chad
  • Colombia
  • Comoros
  • Costa Rica
  • Cuba
  • Democratic Republic of the Congo
  • Djibouti
  • Dominican Republic
  • Ecuador
  • Egypt
  • El Salvador
  • Equatorial Guinea
  • Eswatini
  • Ethiopia
  • Gabon
  • Ghana
  • Grenada
  • Honduras
  • Jamaica
  • Kiribati
  • Kosovo
  • Lebanon
  • Lesotho
  • Liberia
  • Madagascar
  • Malawi
  • Maldives
  • Mali
  • Marshall Islands
  • Mexico
  • Moldova
  • Monaco
  • Montenegro
  • Morocco
  • Mozambique
  • Nauru
  • Nicaragua
  • Niger
  • Panama
  • Paraguay
  • Peru
  • Republic of the Congo
  • Rwanda
  • Saint Kitts and Nevis
  • Saint Lucia
  • San Marino
  • Sao Tome and Principe
  • Somalia
  • South Africa
  • Suriname
  • Syria
  • Tanzania
  • Togo
  • Tonga
  • Trinidad and Tobago
  • Uganda
  • Uruguay
  • Utah
  • Vanuatu
  • Vatican City
  • Zambia
  • Zimbabwe

Comprehensive regime

74 laws, 72 places
PlaceLawWhat it asks, as read here
Algeria Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11

Implement technical and organisational measures appropriate to the risk, and choose a processor only for the sufficiency of its own security guarantees, governed by a written contract.

Andorra LQPD, Llei 29/2021 del 28 d'octubre

Put appropriate technical and organisational security measures in place, proportionate to the risk, before and during processing.

Angola Law on the Protection of Personal Data

Implement technical and organisational measures adequate to the risk presented by the processing and the nature of the data, and keep a document describing the security measures, standards and procedures applied.

Antigua and Barbuda Data Protection Act, 2013

Take practical security steps against loss, misuse, unauthorised or accidental access, disclosure, alteration or destruction of personal data, having regard to its sensitivity, where it is stored, and the reliability of personnel with access, and secure the same guarantees from any data processor you engage.

Argentina Ley 25.326, Ley de Protección de los Datos Personales

Adopt the technical and organizational measures needed to guarantee the security and confidentiality of personal data and to detect unauthorized or accidental deviations, and do not register personal data in a file that lacks adequate technical integrity and security conditions.

Belarus Law of the Republic of Belarus On Personal Data Protection

Take legal, organizational and technical measures against unauthorized or accidental access, modification, termination, copying, dissemination, transmission or erasure of personal data, appoint a data protection officer or a dedicated unit, publish your data processing policy, and train staff who handle personal data, under Article 17.

Bolivia Ley General de Telecomunicaciones, Inviolabilidad y Secreto de las Comunicaciones y Protección de Datos Personales

Protect the personal data and privacy of your users, apart from what regulation permits in directories, invoices, and similar records.

Bolivia Reglamento para el Desarrollo de TIC, Tratamiento de los Datos Personales

Adopt technical and organisational measures, matched to the state of technology and the data's nature and risk, to keep personal data secure and prevent its alteration, loss, or unauthorised processing.

Botswana Data Protection Act, 2024 (Act No. 18 of 2024)

Implement appropriate technical and organisational measures, including data protection by design and by default, to secure personal data at a level appropriate to the risk and to be able to demonstrate compliance with the Act.

Brazil Lei Geral de Proteção de Dados Pessoais (LGPD)

Adopt technical and administrative security measures suited to protect personal data against unauthorized access and accidental or unlawful destruction, loss, alteration, communication, or improper processing, from the design of the product or service through its execution.

Show the other 64 laws
Burkina Faso Loi n°001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel

Implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or unauthorized access.

Cabo Verde Law No. 133/V/2001 on the Protection of Personal Data

Implement technical and organisational measures adequate to the risk to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, and choose a processor offering sufficient security guarantees under a written contract that binds them to your instructions.

Cambodia Draft Law on Personal Data Protection, final draft proposed

If enacted as drafted, a data controller or processor would have to implement personal data protection by design and by default, and would have to secure personal data with technical and organizational measures against unauthorized access, collection, use, disclosure, copying, modification, or destruction, and against the loss of any storage medium on which it is held.

Central African Republic Loi n° 24.001 portant protection des données à caractère personnel

Take precautions appropriate to the data's nature and the risks involved to keep personal data secure, including protection against accidental or unlawful destruction, loss, alteration, or unauthorized access.

Chad Loi n°007/PR/2015, principes directeurs du traitement des données (consentement, licéité, finalité, conservation)

Inform the data subject about the processing of their personal data, and process it confidentially and with security measures against unauthorized access.

Colombia Ley 1581 de 2012, General Personal Data Protection

Keep proof of the data subject's authorization, tell them at authorization the purpose of the processing, keep their personal data updated and accurate, secure it against unauthorized alteration, loss, consultation, use or access, and correct it once it is shown to be incorrect.

As a data processor, keep personal data secure in the same way, update or correct it as the controller instructs within five business days, and adopt an internal manual of policies and procedures for handling consultations and claims.

Colombia Superintendencia Circular on AI and Personal Data

Adopt technological, human, administrative, physical and contractual security measures to prevent unauthorized access to, manipulation, destruction, or unauthorized use or circulation of personal data processed in an artificial intelligence system, and keep those measures auditable by the authorities.

Comoros Law on the Protection of Personal Data

Take precautions appropriate to the nature of the data and the risks the processing presents to preserve its security, including against distortion, damage, or access by unauthorized third parties.

Costa Rica Protección de la Persona frente al Tratamiento de sus Datos Personales

Adopt technical and organizational security measures to prevent the alteration, loss, or unauthorized access of personal data.

Democratic Republic of the Congo Digital Code, Title III: Personal Data Protection

Implement technical and organizational measures against unauthorized or unlawful processing and against accidental loss, destruction or alteration, confine internal access to what each role requires, and train staff on their data protection duties.

Djibouti Digital Code, Book I: Personal Data Protection and CNDP

Build data protection into the design and the default settings of your processing, restrict processing to persons acting under your authority and on your instructions, and take the measures necessary to secure personal data against loss, alteration, or unauthorized access, having regard to its nature and the risks the processing presents.

Dominican Republic Ley No. 172-13 sobre Protección Integral de los Datos Personales

Adopt the technical, organizational, and security measures necessary to prevent the alteration, loss, or unauthorized access of personal data, and maintain adequate information policies with security and control measures for every archive, registry, or databank you keep.

Keep personal data confidential under a duty of professional secrecy that continues after your relationship with the data subject or the data controller ends, unless a court relieves you of it for reasons of public security, national defense, or public health.

+1 more
Ecuador LOPDP, comprehensive personal-data protection regime

Secure personal data with the technical and organisational measures articles 37 to 41 require, determined from a risk, threat and vulnerability analysis, and build data protection into the design of your processing and make it the default.

Egypt Law No. 151 of 2020 Promulgating the Personal Data Protection Law

Adopt technical and regulatory procedures and the necessary standard criteria to protect Personal Data and keep it confidential, preventing any hack, damage, alteration or manipulation.

El Salvador Ley para la Protección de Datos Personales

Maintain the technological, regulatory and procedural security measures the Entidad Rectora sets to keep personal data confidential, available and unaltered.

Equatorial Guinea Ley de Protección de Datos Personales

Keep personal data secure, confidential, and limited to what is adequate and not excessive for the stated purpose.

Eswatini Data Protection Act, 2022 (Act No. 5 of 2022)

Take appropriate, reasonable technical and administrative measures to secure the integrity of personal information in your possession or under your control against loss, modification, damage, unauthorised destruction or unlawful access, and govern any data processor who processes information on your behalf by a written contract that requires the same measures.

Ethiopia Personal Data Protection Proclamation

Implement appropriate technical and organizational measures against unauthorized or unlawful processing and against accidental loss, destruction or damage, including pseudonymization and encryption, the ability to restore access to personal data after a physical or technical incident, and a process for regularly testing their effectiveness.

Gabon Loi n°001/2011 relative à la protection des données à caractère personnel, modifiée par la loi n°025/2023

Implement technical and organizational security measures adapted to the risk, including pseudonymization and encryption, and regularly test, assess and evaluate their effectiveness.

Ghana Data Protection Act

Take appropriate, reasonable technical and organisational measures to secure personal data against loss, damage, unauthorised destruction, and unlawful access, and require a data processor acting on your behalf to maintain the same measures under a written contract.

Grenada Data Protection Act, No. 1 of 2023 from a date not yet set

Take practical steps to secure personal data against loss, misuse, unauthorised access, alteration or destruction, and obtain a data processor's own security guarantees before letting it process personal data on your behalf.

Jamaica Data Protection Act, 2020, registration, lawful basis and standards for processing

Take appropriate technical and organisational measures, including pseudonymisation and encryption, against unauthorised or unlawful processing of personal data and against its accidental loss, destruction or damage.

Kiribati Data Protection Act 2025 from a date not yet set

On commencement, implement appropriate technical and organisational measures against accidental or unlawful destruction, loss, misuse or alteration and unauthorised disclosure or access, taking into account the amount of personal data, the likelihood of harm, the extent of processing, the retention period, and the availability and cost of measures.

Kosovo Law No. 06/L-082 on Protection of Personal Data

Put appropriate technical and organisational security measures in place, proportionate to the risk, before and during processing.

Lebanon Law No. 81/2018 on Electronic Transactions and Personal Data, Part V (Personal Data Protection)

Take all measures, in light of the nature of the data and the risks of processing it, to keep the data intact and secure and to protect it against distortion, damage and access by unauthorized persons.

Lesotho Data Protection Act, 2011 (Act No. 5 of 2012)

Take appropriate, reasonable technical measures to secure the integrity of personal information in your possession or under your control against loss, damage, unauthorised destruction or unlawful access, and govern any agent who processes information on your behalf by a written contract that requires the same measures.

Liberia Telecommunications Act of 2007, Protection of Personal Information (§§ 51-52)

Protect customer information and customer communications with security safeguards appropriate to their sensitivity.

Madagascar Law No. 2014-038, protection of personal data

Take security precautions appropriate to the data and the risk, to prevent unauthorized access, alteration, loss, or disclosure.

Malawi Electronic Transactions and Cyber Security Act, 2016, personal data processing and security duties (Part VII)

Implement technical and organizational security measures appropriate to the risk, including where you transmit personal data over a network, to protect it against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure or access.

Maldives Personal Data Protection Bill, pending before the People's Majlis proposed

If enacted as drafted, a Controller or Processor would have to secure personal data with appropriate technical, physical or organizational measures against unauthorized or unlawful processing and against accidental loss, destruction or damage.

Mali Loi n° 2013-015, protection des données à caractère personnel

Take every precaution useful to preserve the security of personal data, including preventing unauthorized access, deformation, or damage, and use a processor only where it offers sufficient security and confidentiality guarantees, which does not relieve you of your own duty to see those guarantees are met.

Marshall Islands Personal Data Protection Act 2025, government personal-data protection principles

Store or process personal data with technical and organizational security measures that protect against unauthorized or unlawful processing and against unintentional loss, destruction, or damage, and limit access to staff who need it for their duties.

Mexico Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP)

Establish and maintain administrative, technical, and physical security measures to protect personal data against damage, loss, alteration, destruction, or unauthorized use, access, or processing, at a level no lower than the measures you keep for your own information.

Moldova Law No. 195/2024 on Personal Data Protection

Implement technical and organisational measures giving a level of security appropriate to the risk.

Monaco Loi sur la Protection des Données Personnelles

Take appropriate technical and organisational security measures, including pseudonymisation and encryption, proportionate to the risk of destruction, loss, alteration, or unauthorised disclosure of or access to the personal data you process.

Montenegro Law on Personal Data Protection from a date not yet set

Implement technical, personnel and organizational safeguards appropriate to the nature of the data processed to protect it against loss, destruction, unauthorized access, alteration, publicizing and abuse, under Article 24, and keep confidential any personal data your staff become privy to in the course of their work, under Article 25.

Morocco Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data

Implement technical and organizational measures appropriate to the risk and the state of the art, protecting personal data against accidental or unlawful destruction, accidental loss, alteration, unauthorized disclosure, and unauthorized access, including where the processing involves network transmission.

Mozambique Electronic Transactions Law, Protection of Personal Electronic Data

Protect personal data against risk, loss, unauthorised access, destruction, unauthorised use, modification, or disclosure.

Nauru Communications and Broadcasting Act 2018, confidentiality of subscriber information and communications

Take reasonable steps to maintain the confidentiality of a subscriber's communications, and do not intercept, monitor, alter, or modify their content except as permitted or required by law.

Nicaragua Ley No. 787, Ley de Protección de Datos Personales

Process personal data only to the extent adequate, proportional, and necessary for the stated purpose, and adopt technical and organizational security measures against unauthorized access, use, alteration, loss, disclosure, transfer, or dissemination.

Keep personal data confidential under a duty of professional secrecy that survives the end of your relationship with the data controller, releasable only by judicial order for reasons of national security, national defense, public security, or public health.

Niger Loi n° 2022-59, protection des données à caractère personnel

Keep personal data confidential and implement technical and organizational measures against unauthorized access, loss or damage, including pseudonymization, encryption, and data protection by design and by default.

Panama Ley 81 de 2019, Sobre Protección de Datos Personales

Keep confidential any personal data you access that did not come from a source open to the public, even after your relationship to the processing ends.

Hand over stored personal data to a competent judicial authority only on a properly substantiated request, never in response to a bulk request, and, if you operate a public communications network, maintain the security measures this Law requires to protect it.

Paraguay Ley N° 7593/2025, de Protección de Datos Personales en la República del Paraguay from , in 14 months

Take the security measures article 16 requires of a controller and of a processor.

Peru Ley 29733, Ley de Protección de Datos Personales

Adopt technical, organizational, and legal measures that guarantee the security of personal data and prevent its alteration, loss, unauthorized processing, or access, and do not process personal data in a data bank that does not meet the Authority's security requirements.

Republic of the Congo Law No. 29-2019 on the Protection of Personal Data

Keep processing confidential and take precautions appropriate to the data and the risk to preserve its security, including against unauthorised access, alteration or loss.

Rwanda Law relating to the Protection of Personal Data and Privacy

Implement appropriate technical measures against loss, damage or destruction of personal data, verify regularly that they work, and keep them updated against new or identified risks.

Saint Kitts and Nevis Data Protection Act, 2018 from a date not yet set

Take practical steps to protect personal data from loss, misuse, unauthorised access, alteration or destruction, having regard to the nature of the data, its storage, and the personnel with access to it, and require a data processor you engage to give sufficient security guarantees and comply with them.

Saint Lucia Data Protection Act

Take security measures appropriate to the risk of unauthorized access, alteration, or loss of personal data, taking the state of technology and the cost of the measures into account, and make sure staff know and follow them.

San Marino San Marino Law No. 171 on the Protection of Natural Persons

Implement technical and organisational measures giving a level of security appropriate to the risk, and cooperate with the Data Protection Authority in the performance of its tasks.

Sao Tome and Principe Lei n.º 03/2016, Protecção de Dados Pessoais

Implement appropriate technical and organizational measures against accidental or unlawful destruction, loss, unauthorized alteration, disclosure or access to personal data, choose a subcontractor offering sufficient guarantees, bind it by contract to your instructions and the same measures, and record that contract in a document with legally recognized probative value.

Somalia Data Protection Act No. 005 of 2023

Implement appropriate technical and organisational measures to secure personal data, taking into account the amount and sensitivity of the data and the harm its loss or misuse would cause.

South Africa Protection of Personal Information Act 4 of 2013 (POPIA)

Secure the integrity and confidentiality of personal information in your possession with appropriate technical and organisational measures, identify the foreseeable risks to it, and keep those measures updated as risks change.

Suriname Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens) proposed

Take appropriate technical and organizational security measures against accidental or unauthorized access, destruction, loss, use, alteration, or disclosure of personal data, matched to the risk.

Syria Law No. 12 of 2024 on Protection of Electronic Personal Data

Take the technical and organizational security measures the Authority approves to protect personal data against unauthorized or unlawful processing and against loss or damage, and appoint a data protection officer, registered with the Authority, if you are a legal person.

Togo Loi n° 2019-014, protection des données à caractère personnel

Take appropriate technical and organizational measures to prevent unauthorized access to, alteration of, or loss of personal data, and keep the data usable regardless of changes in the storage technology used.

Tonga Privacy Act 2025, comprehensive personal information protection regime from a date not yet set

Implement appropriate and reasonable technical and organisational measures to prevent accidental, unauthorised or unlawful loss, misuse, destruction of or damage to personal information, and unlawful or unauthorised access to or processing of it.

Trinidad and Tobago Data Protection Act, 2011

Keep personal information accurate, complete and up to date as necessary for the purpose of collection, and protect it with safeguards appropriate to its sensitivity.

Uganda Data Protection and Privacy Act, 2019, comprehensive personal-data regime

Identify foreseeable risks to personal data in your possession, establish and maintain safeguards against them, verify regularly that the safeguards work, and update them as risks or deficiencies change.

As an operator or other person processing personal data on a controller's behalf, treat the data as confidential and do not disclose it unless required by law or in the course of discharging your duty.

Uruguay Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended

Adopt the security and confidentiality measures needed to prevent unauthorized alteration, loss, consultation, or processing of personal data, and store it so the data subject can exercise their right of access.

Utah Utah Consumer Privacy Act

Establish reasonable administrative, technical, and physical security practices for personal data, and enter into a written contract with any processor before it processes personal data on your behalf.

Vanuatu Data Protection and Privacy Act 2024, comprehensive personal data protection regime

Process personal data with reasonable and appropriate security measures against unauthorised or unlawful processing and against accidental or unauthorised access, destruction, loss, use, modification or disclosure.

Vatican City General Regulation on the Protection of Personal Data for Vatican City State

Where this Regulation binds your processing, identify the Data Controller as the Governorate, represented by the General Secretary, and put in place organizational and technical security measures suitable to protect the personal data you process. Appoint a Representative in writing where the Regulation calls for one, and record the activity in the Register of treatment activities.

Zambia Data Protection Act, 2021, personal data processing framework

Implement security safeguards proportionate to the risk, including pseudonymisation and encryption, measures against misuse, unauthorised access, modification, disclosure or destruction, and data protection policies, and review them periodically against the Commissioner's guidelines.

Zimbabwe Cyber and Data Protection Act [Chapter 12:07]

Take the security measures section 18 requires, keep your processing open as section 23 requires, and be accountable for it as section 24 requires.

Sensitive categories

12 laws, 12 places
PlaceLawWhat it asks, as read here
Albania Law No. 124/2024, special categories of personal data, criminal records and children's data

Do not process sensitive data about race or ethnic origin unless the processing ensures justice and equality on that ground and carries appropriate safeguards, and put appropriate technical and security safeguards in place before relying on any Article 9 exception.

Algeria Loi n° 18-07 relative à la protection des personnes physiques, catégories de données sensibles et biométriques

If you are the judicial authority, a body legally empowered to investigate offences, a judicial auxiliary or the prison administration processing personal data under Title V bis for the prevention or detection of offences, investigations, inquiries, criminal prosecutions or the execution of sentences, put in place technical and organisational measures giving an appropriate level of protection for sensitive and biometric data.

Angola Law on the Protection of Personal Data, sensitive data categories

Notify the Agência de Protecção de Dados of sensitive-data processing carried out under a legal provision, and carry it out with guarantees of non-discrimination and special security measures.

Argentina Ley 25.326, sensitive data categories and health data

As a health establishment or health professional, collect and process a patient's physical or mental health data under the rules of professional secrecy.

Central African Republic Loi n° 24.001 portant protection des données à caractère personnel, données sensibles et mineurs

Get a data subject's explicit consent, and apply extra security and organisational safeguards, before processing a sensitive category of data such as racial origin, biometric or genetic data, health data, or political, religious, or trade union information.

When a processing activity involves sensitive data or a particularly vulnerable person's data, put additional organizational and technical safeguards in place and give that person heightened information before you process it.

Eswatini Data Protection Act, 2022, sensitive personal information

Where you process a data subject's health or sexual life information under a listed exemption and are not otherwise bound by a confidentiality duty, treat the information as confidential unless required by law or your duties to disclose it.

Ethiopia Personal Data Protection Proclamation, sensitive personal data and minors

Where an exception does permit sensitive personal data to be processed, put appropriate technical and security safeguards in place first.

Honduras Ley de Transparencia y Acceso a la Información Pública, protección de datos personales y hábeas data

Keep personal data protected at all times, and let access to it proceed only by judicial order or at the request of the person whose data it is.

Lesotho Data Protection Act, 2011, sensitive personal information

Where you process a data subject's health or sexual life information under a listed exemption and are not otherwise bound by a confidentiality duty, treat the information as confidential unless required by law or your duties to disclose it.

Sao Tome and Principe Lei n.º 03/2016, sensitive categories and suspect records

Where you process health or sex-life data, including genetic data, for preventive medicine, diagnosis, care or health-service management, do so only through a health professional or another person bound by professional secrecy, notify NAPPD of the processing, and secure it with appropriate information-security measures.

Show the other 2 laws
South Africa Protection of Personal Information Act, special personal information and children

Only process a data subject's biometric information or record of criminal behaviour where you are a body charged with applying criminal law or you obtained the information lawfully, and put appropriate safeguards in place before relying on any special personal information exception.

Syria Law No. 12 of 2024 on Protection of Electronic Personal Data, sensitive personal data

Follow the information security plans, policies and procedures the Authority sets for protecting sensitive personal data, through your data protection officer and the staff under their supervision.

Enforcement supervision

4 laws, 4 places
PlaceLawWhat it asks, as read here
Angola Law on the Protection of Personal Data, enforcement and supervision

Keep personal data confidential once bound by professional secrecy, on pain of imprisonment of up to eighteen months, rising to two years for a public official, a financial gain motive, or harm to the data subject's reputation or privacy.

Cabo Verde Law No. 133/V/2001 on the Protection of Personal Data, enforcement and supervision

Keep personal data confidential once bound by professional secrecy, on pain of imprisonment from six months to three years or a fine of eighty to two hundred days, increased by half for a civil servant, a financial gain motive, or harm to the data subject's reputation, honour or privacy.

California CCPA/CPRA Enforcement: California Privacy Protection Agency and Private Right of Action

Maintain reasonable security procedures for a California consumer's unencrypted, unredacted personal information; a breach caused by their absence exposes your business to a private lawsuit for $100 to $750 in statutory damages per consumer per incident, which cannot be cured by improving security after the fact.

Zimbabwe Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024

Process personal data securely by appropriate technical and organisational measures, including risk assessments, organisational policies, physical and technical measures across all data phases, and processes to test how effective they are and to make the improvements they show are needed.

Breach notification

2 laws, 2 places
PlaceLawWhat it asks, as read here
Arkansas Arkansas Personal Information Protection Act, breach notification and security from a date not yet set

Implement and maintain reasonable security procedures and practices to protect Arkansas residents' personal information, and dispose of records containing it in a manner that renders the information unreadable or undecipherable.

Tanzania Personal Data Protection Act, 2022, security and breach notification

Protect personal data with security safeguards reasonable in the circumstances.

Cross border transfer

2 laws, 2 places
PlaceLawWhat it asks, as read here
Burkina Faso Personal Data Protection Law, cross-border transfer of personal data

Before any transfer of personal data outside Burkina Faso, obtain the CIL's authorization, sign a data confidentiality and reversibility clause with the receiving party letting data migrate back fully at the end of the contract, and put in place technical and organizational security measures covering encryption, availability, confidentiality, integrity and resilience.

Cuba Resolución 58/2022 (MINCOM), security and localization rules for personal data in electronic form

Guarantee the security of personal data in electronic form and adopt the necessary technical and administrative measures for its processing.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.