Law / Frameworks / NIST Privacy Framework / Protect-P
NIST Privacy Framework, Protect-PPR.PO-P7
Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are established, in place, and managed.NIST Privacy Framework, version 1.0, January 2020, PR.PO-P7
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 31
- laws
- 29
- places
- 0
- with court rulings behind them
- 4
- not yet in force
- 1
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 4.3 Organizational practices are in place to enable AI testing, identification of...
- NIST AI RMFMANAGE 4.1 Post-deployment AI system monitoring plans are implemented, including mechanisms for...
- NIST AI 600-1GAI-RISK-09 Information Security
- NIST AI 600-1GAI-RISK-04 Data Privacy
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations3.6 Incident Response & Recovery
- MIT mitigations4.3 Incident Reporting
- NIST CSF 2.0ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are...
- NIST CSF 2.0RS.CO-02 Internal and external stakeholders are notified of incidents
A law in force is unmarked; the rest wear their state: not yet in force proposed
Breach notification
28 laws, 28 places| Place | Law | What it asks, as read here |
|---|---|---|
| Alaska Personal Information Protection Act, breach notification duty from a date not yet set |
Document and retain for five years any determination, made after investigation and written notice to the Alaska Attorney General, that a breach is unlikely to cause resident harm and so does not require disclosure. |
|
| Law No. 124/2024, notification of a personal data breach |
Document every personal data breach, its facts, its effects, and the corrective measures taken, so the Commissioner can verify compliance. |
|
| Loi n° 18-07 relative à la protection des personnes physiques, notification des violations de données |
Keep an up-to-date inventory of personal-data breaches and the measures you took to remedy them. |
|
| LQPD, personal data breach notification |
Document every personal data breach, its facts, effects and remedial measures, so the Agency can verify your compliance. |
|
| Data Protection Act, 2019, personal data breach notification |
Document every personal data breach, its facts, its effects and the remedial action taken, so the Commissioner can assess compliance. |
|
| Law on the Protection of Personal Data of Bosnia and Herzegovina, personal data breach notification |
Describe in the notification the nature of the breach, the data protection officer's or another contact point's details, the likely consequences and the measures taken or proposed, supplying the information in phases if it cannot all be given at once, and document every breach, its facts, effects and remedial action for the Agency to review. |
|
| Personal Information Protection Law, Data Breach Notification |
Upon discovering an actual or possible leak, alteration, or loss of personal information, immediately take remedial measures and notify both the competent personal information protection department and every affected individual, unless the remedial measures can be shown to effectively prevent harm. |
|
| Digital Code, Book I: personal-data breach notification |
Keep a register of every personal-data breach, its facts, its effects and the remedial measures taken, and make it available to the Commission on request. |
|
| Egypt Personal Data Protection Law, Personal Data Infringement notification |
Be ready to give the Center a description of the infringement's nature, form and reasons and the approximate number of Personal Data and records affected, the Data Protection Officer's information, the potential consequences, the procedures followed and proposed to minimise the impact, and evidence documenting the infringement and the corrective actions taken. |
|
| Ley para la Protección de Datos Personales, personal data breach notification |
Within that same seventy two hours, begin a thorough review of the breach's magnitude, adopt corrective and preventive measures, and update your security policies to prevent a recurrence. Document every breach that risks the security of personal data, noting its date, cause, related facts, effects and corrective measures, and keep that record available to the Agencia de Ciberseguridad del Estado. |
Show the other 18 laws
| Personal Data Protection Proclamation, personal data breach notification |
Document every personal data breach, its facts, its effects and the remedial action taken, so the Authority can assess compliance. |
|
| Law No. 025/2023, personal-data breach notification |
Keep an up-to-date register of every personal-data breach, its circumstances, its impact and the remedial measures taken, and make it available to the APDPVP. |
|
| Data Protection Act, notification of security compromises |
Take steps to restore the integrity of the information system after unauthorised access or acquisition of personal data, and delay notifying the data subject only where the Commission or a security agency says notification would impede a criminal investigation. |
|
| Kansas Breach Notification Act, notice of security breach from a date not yet set |
Conduct a good-faith, reasonable, and prompt investigation on becoming aware of a breach of system security involving personal information about a Kansas resident. |
|
| Data Protection Act 2025, personal data breaches from a date not yet set |
On commencement, keep a record of every personal data breach, regardless of whether it meets that threshold, including the facts, its effects and the remedial action taken, and make your threshold analysis available to the Office on request. |
|
| Law No. 06/L-082 on Protection of Personal Data, personal data breach notification |
Document every personal data breach, its facts, effects and remedial action, so the Agency can verify your compliance. |
|
| Loi sur la Protection des Données Personnelles, notification des violations de données |
Document every personal data breach, its facts, its effects, and the remedial steps you took, and expect the Authority to be able to require you to communicate the breach to the affected person if you have not already done so. |
|
| Nebraska Financial Data Protection and Consumer Notification of Data Security Breach Act from a date not yet set |
Conduct a reasonable and prompt investigation upon becoming aware of a breach of security involving a Nebraska resident's personal information. |
|
| Québec | Confidentiality incident notification and register |
If you have cause to believe a confidentiality incident involving personal information you hold has occurred, take reasonable measures to reduce the risk of injury and prevent further incidents of the same nature. Keep a register of every confidentiality incident, and send a copy to the Commission d’accès à l’information on request. |
| National Digital Identification Act 2024, personal data breach notification |
Keep a record of every personal data breach, its effects, and the remedial action taken, sufficient to demonstrate compliance with the Act's breach notification duties. |
|
| San Marino Law No. 171, personal data breach notification |
Describe in the notification the nature of the breach, including where possible the categories and approximate number of data subjects and of records concerned, the contact point, the likely consequences and the measures taken, and document every breach, its effects and the remedial action. |
|
| Law on Personal Data Protection, personal data breach notification |
Document every breach, including its facts, effects and remedial action, so the Commissioner can assess compliance. |
|
| Personal Data Protection Act, data breach notification |
An app that experiences a data breach affecting an individual's personal data in Singapore must assess whether the breach is likely to cause significant harm or is of significant scale, and if so must notify the PDPC as soon as practicable and in any case within 3 calendar days of that assessment, and must also notify each affected individual unless a statutory exception applies. |
|
| Data Protection Act, 2023, personal data breach notification |
Keep a record of every personal data breach. |
|
| Draft Law on the Protection of Privacy and Personal Data, breach notification proposed |
Document every breach relating to personal data, including the facts, its effects, and the corrective measures taken, in a form that lets the Commissioner verify your compliance with this duty. |
|
| Ley N° 19.670, personal data breach notification |
Notify the Unidad Reguladora y de Control de Datos Personales immediately and in detail on becoming aware of the breach, coordinating your response with the national cybersecurity incident response center (CERTuy). |
|
| Protection of Personal Information Act |
If unencrypted Utah-resident data combining a name with a Social Security number, a driver license or state ID number, or a financial account or card number with its access code is breached, investigate promptly in good faith and notify each affected Utah resident without unreasonable delay. |
|
| Cyber and Data Protection Regulations 2024, security breach notification |
Keep robust breach detection, investigation and internal reporting procedures in place, and keep a record of all personal data breaches. |
Comprehensive regime
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 124/2024 On the Protection of Personal Data |
Implement technical and organizational security measures appropriate to the risk, including pseudonymization and encryption, the ability to restore access after an incident, and a process for regularly testing their effectiveness. |
|
| Data Protection Act, 2019 |
Implement technical and organisational measures giving a level of security appropriate to the risk, including pseudonymisation and encryption of personal data, the ability to restore availability and access in a timely manner after a physical or technical incident, and a process for regularly testing their effectiveness. |
Biometric privacy
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| HB 24-1130, Privacy of Biometric Identifiers and Data |
Adopt and publish a written policy that sets a retention schedule and a destruction timeline (the earliest of purpose satisfied, 24 months after the consumer's last interaction, or 45 days, extendable by up to 45 more, after the identifier is no longer needed) and a data-security-incident response protocol. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.