Law / Frameworks / NIST Privacy Framework / Protect-P
NIST Privacy Framework, Protect-PPR.DS-P5
Protections against data leaks are implemented.NIST Privacy Framework, version 1.0, January 2020, PR.DS-P5
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 94
- laws
- 78
- places
- 0
- with court rulings behind them
- 7
- not yet in force
- 3
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of...
- NIST AI RMFMEASURE 2.6 The AI system is evaluated regularly for safety risks – as identified in the MAP...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations2.1 Model & Infrastructure Security
- MIT mitigations2.3 Model Safety Engineering
- NIST CSF 2.0ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
- NIST CSF 2.0ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
A law in force is unmarked; the rest wear their state: not yet in force proposed
Comprehensive regime
74 laws, 72 places| Place | Law | What it asks, as read here |
|---|---|---|
| Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11 |
Implement technical and organisational measures appropriate to the risk, and choose a processor only for the sufficiency of its own security guarantees, governed by a written contract. |
|
| LQPD, Llei 29/2021 del 28 d'octubre |
Put appropriate technical and organisational security measures in place, proportionate to the risk, before and during processing. |
|
| Law on the Protection of Personal Data |
Implement technical and organisational measures adequate to the risk presented by the processing and the nature of the data, and keep a document describing the security measures, standards and procedures applied. |
|
| Data Protection Act, 2013 |
Take practical security steps against loss, misuse, unauthorised or accidental access, disclosure, alteration or destruction of personal data, having regard to its sensitivity, where it is stored, and the reliability of personnel with access, and secure the same guarantees from any data processor you engage. |
|
| Ley 25.326, Ley de Protección de los Datos Personales |
Adopt the technical and organizational measures needed to guarantee the security and confidentiality of personal data and to detect unauthorized or accidental deviations, and do not register personal data in a file that lacks adequate technical integrity and security conditions. |
|
| Law of the Republic of Belarus On Personal Data Protection |
Take legal, organizational and technical measures against unauthorized or accidental access, modification, termination, copying, dissemination, transmission or erasure of personal data, appoint a data protection officer or a dedicated unit, publish your data processing policy, and train staff who handle personal data, under Article 17. |
|
| Ley General de Telecomunicaciones, Inviolabilidad y Secreto de las Comunicaciones y Protección de Datos Personales |
Protect the personal data and privacy of your users, apart from what regulation permits in directories, invoices, and similar records. |
|
| Reglamento para el Desarrollo de TIC, Tratamiento de los Datos Personales |
Adopt technical and organisational measures, matched to the state of technology and the data's nature and risk, to keep personal data secure and prevent its alteration, loss, or unauthorised processing. |
|
| Data Protection Act, 2024 (Act No. 18 of 2024) |
Implement appropriate technical and organisational measures, including data protection by design and by default, to secure personal data at a level appropriate to the risk and to be able to demonstrate compliance with the Act. |
|
| Lei Geral de Proteção de Dados Pessoais (LGPD) |
Adopt technical and administrative security measures suited to protect personal data against unauthorized access and accidental or unlawful destruction, loss, alteration, communication, or improper processing, from the design of the product or service through its execution. |
Show the other 64 laws
| Loi n°001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel |
Implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or unauthorized access. |
|
| Law No. 133/V/2001 on the Protection of Personal Data |
Implement technical and organisational measures adequate to the risk to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, and choose a processor offering sufficient security guarantees under a written contract that binds them to your instructions. |
|
| Draft Law on Personal Data Protection, final draft proposed |
If enacted as drafted, a data controller or processor would have to implement personal data protection by design and by default, and would have to secure personal data with technical and organizational measures against unauthorized access, collection, use, disclosure, copying, modification, or destruction, and against the loss of any storage medium on which it is held. |
|
| Loi n° 24.001 portant protection des données à caractère personnel |
Take precautions appropriate to the data's nature and the risks involved to keep personal data secure, including protection against accidental or unlawful destruction, loss, alteration, or unauthorized access. |
|
| Loi n°007/PR/2015, principes directeurs du traitement des données (consentement, licéité, finalité, conservation) |
Inform the data subject about the processing of their personal data, and process it confidentially and with security measures against unauthorized access. |
|
| Ley 1581 de 2012, General Personal Data Protection |
Keep proof of the data subject's authorization, tell them at authorization the purpose of the processing, keep their personal data updated and accurate, secure it against unauthorized alteration, loss, consultation, use or access, and correct it once it is shown to be incorrect. As a data processor, keep personal data secure in the same way, update or correct it as the controller instructs within five business days, and adopt an internal manual of policies and procedures for handling consultations and claims. |
|
| Superintendencia Circular on AI and Personal Data |
Adopt technological, human, administrative, physical and contractual security measures to prevent unauthorized access to, manipulation, destruction, or unauthorized use or circulation of personal data processed in an artificial intelligence system, and keep those measures auditable by the authorities. |
|
| Law on the Protection of Personal Data |
Take precautions appropriate to the nature of the data and the risks the processing presents to preserve its security, including against distortion, damage, or access by unauthorized third parties. |
|
| Protección de la Persona frente al Tratamiento de sus Datos Personales |
Adopt technical and organizational security measures to prevent the alteration, loss, or unauthorized access of personal data. |
|
| Digital Code, Title III: Personal Data Protection |
Implement technical and organizational measures against unauthorized or unlawful processing and against accidental loss, destruction or alteration, confine internal access to what each role requires, and train staff on their data protection duties. |
|
| Digital Code, Book I: Personal Data Protection and CNDP |
Build data protection into the design and the default settings of your processing, restrict processing to persons acting under your authority and on your instructions, and take the measures necessary to secure personal data against loss, alteration, or unauthorized access, having regard to its nature and the risks the processing presents. |
|
| Ley No. 172-13 sobre Protección Integral de los Datos Personales |
Adopt the technical, organizational, and security measures necessary to prevent the alteration, loss, or unauthorized access of personal data, and maintain adequate information policies with security and control measures for every archive, registry, or databank you keep. Keep personal data confidential under a duty of professional secrecy that continues after your relationship with the data subject or the data controller ends, unless a court relieves you of it for reasons of public security, national defense, or public health. +1 more |
|
| LOPDP, comprehensive personal-data protection regime |
Secure personal data with the technical and organisational measures articles 37 to 41 require, determined from a risk, threat and vulnerability analysis, and build data protection into the design of your processing and make it the default. |
|
| Law No. 151 of 2020 Promulgating the Personal Data Protection Law |
Adopt technical and regulatory procedures and the necessary standard criteria to protect Personal Data and keep it confidential, preventing any hack, damage, alteration or manipulation. |
|
| Ley para la Protección de Datos Personales |
Maintain the technological, regulatory and procedural security measures the Entidad Rectora sets to keep personal data confidential, available and unaltered. |
|
| Ley de Protección de Datos Personales |
Keep personal data secure, confidential, and limited to what is adequate and not excessive for the stated purpose. |
|
| Data Protection Act, 2022 (Act No. 5 of 2022) |
Take appropriate, reasonable technical and administrative measures to secure the integrity of personal information in your possession or under your control against loss, modification, damage, unauthorised destruction or unlawful access, and govern any data processor who processes information on your behalf by a written contract that requires the same measures. |
|
| Personal Data Protection Proclamation |
Implement appropriate technical and organizational measures against unauthorized or unlawful processing and against accidental loss, destruction or damage, including pseudonymization and encryption, the ability to restore access to personal data after a physical or technical incident, and a process for regularly testing their effectiveness. |
|
| Loi n°001/2011 relative à la protection des données à caractère personnel, modifiée par la loi n°025/2023 |
Implement technical and organizational security measures adapted to the risk, including pseudonymization and encryption, and regularly test, assess and evaluate their effectiveness. |
|
| Data Protection Act |
Take appropriate, reasonable technical and organisational measures to secure personal data against loss, damage, unauthorised destruction, and unlawful access, and require a data processor acting on your behalf to maintain the same measures under a written contract. |
|
| Data Protection Act, No. 1 of 2023 from a date not yet set |
Take practical steps to secure personal data against loss, misuse, unauthorised access, alteration or destruction, and obtain a data processor's own security guarantees before letting it process personal data on your behalf. |
|
| Data Protection Act, 2020, registration, lawful basis and standards for processing |
Take appropriate technical and organisational measures, including pseudonymisation and encryption, against unauthorised or unlawful processing of personal data and against its accidental loss, destruction or damage. |
|
| Data Protection Act 2025 from a date not yet set |
On commencement, implement appropriate technical and organisational measures against accidental or unlawful destruction, loss, misuse or alteration and unauthorised disclosure or access, taking into account the amount of personal data, the likelihood of harm, the extent of processing, the retention period, and the availability and cost of measures. |
|
| Law No. 06/L-082 on Protection of Personal Data |
Put appropriate technical and organisational security measures in place, proportionate to the risk, before and during processing. |
|
| Law No. 81/2018 on Electronic Transactions and Personal Data, Part V (Personal Data Protection) |
Take all measures, in light of the nature of the data and the risks of processing it, to keep the data intact and secure and to protect it against distortion, damage and access by unauthorized persons. |
|
| Data Protection Act, 2011 (Act No. 5 of 2012) |
Take appropriate, reasonable technical measures to secure the integrity of personal information in your possession or under your control against loss, damage, unauthorised destruction or unlawful access, and govern any agent who processes information on your behalf by a written contract that requires the same measures. |
|
| Telecommunications Act of 2007, Protection of Personal Information (§§ 51-52) |
Protect customer information and customer communications with security safeguards appropriate to their sensitivity. |
|
| Law No. 2014-038, protection of personal data |
Take security precautions appropriate to the data and the risk, to prevent unauthorized access, alteration, loss, or disclosure. |
|
| Electronic Transactions and Cyber Security Act, 2016, personal data processing and security duties (Part VII) |
Implement technical and organizational security measures appropriate to the risk, including where you transmit personal data over a network, to protect it against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure or access. |
|
| Personal Data Protection Bill, pending before the People's Majlis proposed |
If enacted as drafted, a Controller or Processor would have to secure personal data with appropriate technical, physical or organizational measures against unauthorized or unlawful processing and against accidental loss, destruction or damage. |
|
| Loi n° 2013-015, protection des données à caractère personnel |
Take every precaution useful to preserve the security of personal data, including preventing unauthorized access, deformation, or damage, and use a processor only where it offers sufficient security and confidentiality guarantees, which does not relieve you of your own duty to see those guarantees are met. |
|
| Personal Data Protection Act 2025, government personal-data protection principles |
Store or process personal data with technical and organizational security measures that protect against unauthorized or unlawful processing and against unintentional loss, destruction, or damage, and limit access to staff who need it for their duties. |
|
| Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) |
Establish and maintain administrative, technical, and physical security measures to protect personal data against damage, loss, alteration, destruction, or unauthorized use, access, or processing, at a level no lower than the measures you keep for your own information. |
|
| Law No. 195/2024 on Personal Data Protection |
Implement technical and organisational measures giving a level of security appropriate to the risk. |
|
| Loi sur la Protection des Données Personnelles |
Take appropriate technical and organisational security measures, including pseudonymisation and encryption, proportionate to the risk of destruction, loss, alteration, or unauthorised disclosure of or access to the personal data you process. |
|
| Law on Personal Data Protection from a date not yet set |
Implement technical, personnel and organizational safeguards appropriate to the nature of the data processed to protect it against loss, destruction, unauthorized access, alteration, publicizing and abuse, under Article 24, and keep confidential any personal data your staff become privy to in the course of their work, under Article 25. |
|
| Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data |
Implement technical and organizational measures appropriate to the risk and the state of the art, protecting personal data against accidental or unlawful destruction, accidental loss, alteration, unauthorized disclosure, and unauthorized access, including where the processing involves network transmission. |
|
| Electronic Transactions Law, Protection of Personal Electronic Data |
Protect personal data against risk, loss, unauthorised access, destruction, unauthorised use, modification, or disclosure. |
|
| Communications and Broadcasting Act 2018, confidentiality of subscriber information and communications |
Take reasonable steps to maintain the confidentiality of a subscriber's communications, and do not intercept, monitor, alter, or modify their content except as permitted or required by law. |
|
| Ley No. 787, Ley de Protección de Datos Personales |
Process personal data only to the extent adequate, proportional, and necessary for the stated purpose, and adopt technical and organizational security measures against unauthorized access, use, alteration, loss, disclosure, transfer, or dissemination. Keep personal data confidential under a duty of professional secrecy that survives the end of your relationship with the data controller, releasable only by judicial order for reasons of national security, national defense, public security, or public health. |
|
| Loi n° 2022-59, protection des données à caractère personnel |
Keep personal data confidential and implement technical and organizational measures against unauthorized access, loss or damage, including pseudonymization, encryption, and data protection by design and by default. |
|
| Ley 81 de 2019, Sobre Protección de Datos Personales |
Keep confidential any personal data you access that did not come from a source open to the public, even after your relationship to the processing ends. Hand over stored personal data to a competent judicial authority only on a properly substantiated request, never in response to a bulk request, and, if you operate a public communications network, maintain the security measures this Law requires to protect it. |
|
| Ley N° 7593/2025, de Protección de Datos Personales en la República del Paraguay from , in 14 months |
Take the security measures article 16 requires of a controller and of a processor. |
|
| Ley 29733, Ley de Protección de Datos Personales |
Adopt technical, organizational, and legal measures that guarantee the security of personal data and prevent its alteration, loss, unauthorized processing, or access, and do not process personal data in a data bank that does not meet the Authority's security requirements. |
|
| Law No. 29-2019 on the Protection of Personal Data |
Keep processing confidential and take precautions appropriate to the data and the risk to preserve its security, including against unauthorised access, alteration or loss. |
|
| Law relating to the Protection of Personal Data and Privacy |
Implement appropriate technical measures against loss, damage or destruction of personal data, verify regularly that they work, and keep them updated against new or identified risks. |
|
| Data Protection Act, 2018 from a date not yet set |
Take practical steps to protect personal data from loss, misuse, unauthorised access, alteration or destruction, having regard to the nature of the data, its storage, and the personnel with access to it, and require a data processor you engage to give sufficient security guarantees and comply with them. |
|
| Data Protection Act |
Take security measures appropriate to the risk of unauthorized access, alteration, or loss of personal data, taking the state of technology and the cost of the measures into account, and make sure staff know and follow them. |
|
| San Marino Law No. 171 on the Protection of Natural Persons |
Implement technical and organisational measures giving a level of security appropriate to the risk, and cooperate with the Data Protection Authority in the performance of its tasks. |
|
| Lei n.º 03/2016, Protecção de Dados Pessoais |
Implement appropriate technical and organizational measures against accidental or unlawful destruction, loss, unauthorized alteration, disclosure or access to personal data, choose a subcontractor offering sufficient guarantees, bind it by contract to your instructions and the same measures, and record that contract in a document with legally recognized probative value. |
|
| Data Protection Act No. 005 of 2023 |
Implement appropriate technical and organisational measures to secure personal data, taking into account the amount and sensitivity of the data and the harm its loss or misuse would cause. |
|
| Protection of Personal Information Act 4 of 2013 (POPIA) |
Secure the integrity and confidentiality of personal information in your possession with appropriate technical and organisational measures, identify the foreseeable risks to it, and keep those measures updated as risks change. |
|
| Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens) proposed |
Take appropriate technical and organizational security measures against accidental or unauthorized access, destruction, loss, use, alteration, or disclosure of personal data, matched to the risk. |
|
| Law No. 12 of 2024 on Protection of Electronic Personal Data |
Take the technical and organizational security measures the Authority approves to protect personal data against unauthorized or unlawful processing and against loss or damage, and appoint a data protection officer, registered with the Authority, if you are a legal person. |
|
| Loi n° 2019-014, protection des données à caractère personnel |
Take appropriate technical and organizational measures to prevent unauthorized access to, alteration of, or loss of personal data, and keep the data usable regardless of changes in the storage technology used. |
|
| Privacy Act 2025, comprehensive personal information protection regime from a date not yet set |
Implement appropriate and reasonable technical and organisational measures to prevent accidental, unauthorised or unlawful loss, misuse, destruction of or damage to personal information, and unlawful or unauthorised access to or processing of it. |
|
| Data Protection Act, 2011 |
Keep personal information accurate, complete and up to date as necessary for the purpose of collection, and protect it with safeguards appropriate to its sensitivity. |
|
| Data Protection and Privacy Act, 2019, comprehensive personal-data regime |
Identify foreseeable risks to personal data in your possession, establish and maintain safeguards against them, verify regularly that the safeguards work, and update them as risks or deficiencies change. As an operator or other person processing personal data on a controller's behalf, treat the data as confidential and do not disclose it unless required by law or in the course of discharging your duty. |
|
| Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended |
Adopt the security and confidentiality measures needed to prevent unauthorized alteration, loss, consultation, or processing of personal data, and store it so the data subject can exercise their right of access. |
|
| Utah Consumer Privacy Act |
Establish reasonable administrative, technical, and physical security practices for personal data, and enter into a written contract with any processor before it processes personal data on your behalf. |
|
| Data Protection and Privacy Act 2024, comprehensive personal data protection regime |
Process personal data with reasonable and appropriate security measures against unauthorised or unlawful processing and against accidental or unauthorised access, destruction, loss, use, modification or disclosure. |
|
| General Regulation on the Protection of Personal Data for Vatican City State |
Where this Regulation binds your processing, identify the Data Controller as the Governorate, represented by the General Secretary, and put in place organizational and technical security measures suitable to protect the personal data you process. Appoint a Representative in writing where the Regulation calls for one, and record the activity in the Register of treatment activities. |
|
| Data Protection Act, 2021, personal data processing framework |
Implement security safeguards proportionate to the risk, including pseudonymisation and encryption, measures against misuse, unauthorised access, modification, disclosure or destruction, and data protection policies, and review them periodically against the Commissioner's guidelines. |
|
| Cyber and Data Protection Act [Chapter 12:07] |
Take the security measures section 18 requires, keep your processing open as section 23 requires, and be accountable for it as section 24 requires. |
Sensitive categories
12 laws, 12 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 124/2024, special categories of personal data, criminal records and children's data |
Do not process sensitive data about race or ethnic origin unless the processing ensures justice and equality on that ground and carries appropriate safeguards, and put appropriate technical and security safeguards in place before relying on any Article 9 exception. |
|
| Loi n° 18-07 relative à la protection des personnes physiques, catégories de données sensibles et biométriques |
If you are the judicial authority, a body legally empowered to investigate offences, a judicial auxiliary or the prison administration processing personal data under Title V bis for the prevention or detection of offences, investigations, inquiries, criminal prosecutions or the execution of sentences, put in place technical and organisational measures giving an appropriate level of protection for sensitive and biometric data. |
|
| Law on the Protection of Personal Data, sensitive data categories |
Notify the Agência de Protecção de Dados of sensitive-data processing carried out under a legal provision, and carry it out with guarantees of non-discrimination and special security measures. |
|
| Ley 25.326, sensitive data categories and health data |
As a health establishment or health professional, collect and process a patient's physical or mental health data under the rules of professional secrecy. |
|
| Loi n° 24.001 portant protection des données à caractère personnel, données sensibles et mineurs |
Get a data subject's explicit consent, and apply extra security and organisational safeguards, before processing a sensitive category of data such as racial origin, biometric or genetic data, health data, or political, religious, or trade union information. When a processing activity involves sensitive data or a particularly vulnerable person's data, put additional organizational and technical safeguards in place and give that person heightened information before you process it. |
|
| Data Protection Act, 2022, sensitive personal information |
Where you process a data subject's health or sexual life information under a listed exemption and are not otherwise bound by a confidentiality duty, treat the information as confidential unless required by law or your duties to disclose it. |
|
| Personal Data Protection Proclamation, sensitive personal data and minors |
Where an exception does permit sensitive personal data to be processed, put appropriate technical and security safeguards in place first. |
|
| Ley de Transparencia y Acceso a la Información Pública, protección de datos personales y hábeas data |
Keep personal data protected at all times, and let access to it proceed only by judicial order or at the request of the person whose data it is. |
|
| Data Protection Act, 2011, sensitive personal information |
Where you process a data subject's health or sexual life information under a listed exemption and are not otherwise bound by a confidentiality duty, treat the information as confidential unless required by law or your duties to disclose it. |
|
| Lei n.º 03/2016, sensitive categories and suspect records |
Where you process health or sex-life data, including genetic data, for preventive medicine, diagnosis, care or health-service management, do so only through a health professional or another person bound by professional secrecy, notify NAPPD of the processing, and secure it with appropriate information-security measures. |
Show the other 2 laws
| Protection of Personal Information Act, special personal information and children |
Only process a data subject's biometric information or record of criminal behaviour where you are a body charged with applying criminal law or you obtained the information lawfully, and put appropriate safeguards in place before relying on any special personal information exception. |
|
| Law No. 12 of 2024 on Protection of Electronic Personal Data, sensitive personal data |
Follow the information security plans, policies and procedures the Authority sets for protecting sensitive personal data, through your data protection officer and the staff under their supervision. |
Enforcement supervision
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law on the Protection of Personal Data, enforcement and supervision |
Keep personal data confidential once bound by professional secrecy, on pain of imprisonment of up to eighteen months, rising to two years for a public official, a financial gain motive, or harm to the data subject's reputation or privacy. |
|
| Law No. 133/V/2001 on the Protection of Personal Data, enforcement and supervision |
Keep personal data confidential once bound by professional secrecy, on pain of imprisonment from six months to three years or a fine of eighty to two hundred days, increased by half for a civil servant, a financial gain motive, or harm to the data subject's reputation, honour or privacy. |
|
| CCPA/CPRA Enforcement: California Privacy Protection Agency and Private Right of Action |
Maintain reasonable security procedures for a California consumer's unencrypted, unredacted personal information; a breach caused by their absence exposes your business to a private lawsuit for $100 to $750 in statutory damages per consumer per incident, which cannot be cured by improving security after the fact. |
|
| Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 |
Process personal data securely by appropriate technical and organisational measures, including risk assessments, organisational policies, physical and technical measures across all data phases, and processes to test how effective they are and to make the improvements they show are needed. |
Breach notification
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Arkansas Personal Information Protection Act, breach notification and security from a date not yet set |
Implement and maintain reasonable security procedures and practices to protect Arkansas residents' personal information, and dispose of records containing it in a manner that renders the information unreadable or undecipherable. |
|
| Personal Data Protection Act, 2022, security and breach notification |
Protect personal data with security safeguards reasonable in the circumstances. |
Cross border transfer
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Personal Data Protection Law, cross-border transfer of personal data |
Before any transfer of personal data outside Burkina Faso, obtain the CIL's authorization, sign a data confidentiality and reversibility clause with the receiving party letting data migrate back fully at the end of the contract, and put in place technical and organizational security measures covering encryption, availability, confidentiality, integrity and resilience. |
|
| Resolución 58/2022 (MINCOM), security and localization rules for personal data in electronic form |
Guarantee the security of personal data in electronic form and adopt the necessary technical and administrative measures for its processing. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.