Law / Frameworks / NIST Privacy Framework / Protect-P

NIST Privacy Framework, Protect-PPR.PO-P7

Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are established, in place, and managed.NIST Privacy Framework, version 1.0, January 2020, PR.PO-P7

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

31
laws
29
places
0
with court rulings behind them
4
not yet in force
1
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Alaska
  • Albania
  • Algeria
  • Andorra
  • Barbados
  • Bosnia and Herzegovina
  • China
  • Colorado
  • Djibouti
  • Egypt
  • El Salvador
  • Ethiopia
  • Gabon
  • Ghana
  • Kansas
  • Kiribati
  • Kosovo
  • Monaco
  • Nebraska
  • Samoa
  • San Marino
  • Serbia
  • Singapore
  • Somalia
  • Suriname
  • Uruguay
  • Utah
  • Zimbabwe

Breach notification

28 laws, 28 places
PlaceLawWhat it asks, as read here
Alaska Alaska Personal Information Protection Act, breach notification duty from a date not yet set

Document and retain for five years any determination, made after investigation and written notice to the Alaska Attorney General, that a breach is unlikely to cause resident harm and so does not require disclosure.

Albania Law No. 124/2024, notification of a personal data breach

Document every personal data breach, its facts, its effects, and the corrective measures taken, so the Commissioner can verify compliance.

Algeria Loi n° 18-07 relative à la protection des personnes physiques, notification des violations de données

Keep an up-to-date inventory of personal-data breaches and the measures you took to remedy them.

Andorra LQPD, personal data breach notification

Document every personal data breach, its facts, effects and remedial measures, so the Agency can verify your compliance.

Barbados Data Protection Act, 2019, personal data breach notification

Document every personal data breach, its facts, its effects and the remedial action taken, so the Commissioner can assess compliance.

Bosnia and Herzegovina Law on the Protection of Personal Data of Bosnia and Herzegovina, personal data breach notification

Describe in the notification the nature of the breach, the data protection officer's or another contact point's details, the likely consequences and the measures taken or proposed, supplying the information in phases if it cannot all be given at once, and document every breach, its facts, effects and remedial action for the Agency to review.

China Personal Information Protection Law, Data Breach Notification

Upon discovering an actual or possible leak, alteration, or loss of personal information, immediately take remedial measures and notify both the competent personal information protection department and every affected individual, unless the remedial measures can be shown to effectively prevent harm.

Djibouti Digital Code, Book I: personal-data breach notification

Keep a register of every personal-data breach, its facts, its effects and the remedial measures taken, and make it available to the Commission on request.

Egypt Egypt Personal Data Protection Law, Personal Data Infringement notification

Be ready to give the Center a description of the infringement's nature, form and reasons and the approximate number of Personal Data and records affected, the Data Protection Officer's information, the potential consequences, the procedures followed and proposed to minimise the impact, and evidence documenting the infringement and the corrective actions taken.

El Salvador Ley para la Protección de Datos Personales, personal data breach notification

Within that same seventy two hours, begin a thorough review of the breach's magnitude, adopt corrective and preventive measures, and update your security policies to prevent a recurrence.

Document every breach that risks the security of personal data, noting its date, cause, related facts, effects and corrective measures, and keep that record available to the Agencia de Ciberseguridad del Estado.

Show the other 18 laws
Ethiopia Personal Data Protection Proclamation, personal data breach notification

Document every personal data breach, its facts, its effects and the remedial action taken, so the Authority can assess compliance.

Gabon Law No. 025/2023, personal-data breach notification

Keep an up-to-date register of every personal-data breach, its circumstances, its impact and the remedial measures taken, and make it available to the APDPVP.

Ghana Data Protection Act, notification of security compromises

Take steps to restore the integrity of the information system after unauthorised access or acquisition of personal data, and delay notifying the data subject only where the Commission or a security agency says notification would impede a criminal investigation.

Kansas Kansas Breach Notification Act, notice of security breach from a date not yet set

Conduct a good-faith, reasonable, and prompt investigation on becoming aware of a breach of system security involving personal information about a Kansas resident.

Kiribati Data Protection Act 2025, personal data breaches from a date not yet set

On commencement, keep a record of every personal data breach, regardless of whether it meets that threshold, including the facts, its effects and the remedial action taken, and make your threshold analysis available to the Office on request.

Kosovo Law No. 06/L-082 on Protection of Personal Data, personal data breach notification

Document every personal data breach, its facts, effects and remedial action, so the Agency can verify your compliance.

Monaco Loi sur la Protection des Données Personnelles, notification des violations de données

Document every personal data breach, its facts, its effects, and the remedial steps you took, and expect the Authority to be able to require you to communicate the breach to the affected person if you have not already done so.

Nebraska Nebraska Financial Data Protection and Consumer Notification of Data Security Breach Act from a date not yet set

Conduct a reasonable and prompt investigation upon becoming aware of a breach of security involving a Nebraska resident's personal information.

Québec Confidentiality incident notification and register

If you have cause to believe a confidentiality incident involving personal information you hold has occurred, take reasonable measures to reduce the risk of injury and prevent further incidents of the same nature.

Keep a register of every confidentiality incident, and send a copy to the Commission d’accès à l’information on request.

Samoa National Digital Identification Act 2024, personal data breach notification

Keep a record of every personal data breach, its effects, and the remedial action taken, sufficient to demonstrate compliance with the Act's breach notification duties.

San Marino San Marino Law No. 171, personal data breach notification

Describe in the notification the nature of the breach, including where possible the categories and approximate number of data subjects and of records concerned, the contact point, the likely consequences and the measures taken, and document every breach, its effects and the remedial action.

Serbia Law on Personal Data Protection, personal data breach notification

Document every breach, including its facts, effects and remedial action, so the Commissioner can assess compliance.

Singapore Personal Data Protection Act, data breach notification

An app that experiences a data breach affecting an individual's personal data in Singapore must assess whether the breach is likely to cause significant harm or is of significant scale, and if so must notify the PDPC as soon as practicable and in any case within 3 calendar days of that assessment, and must also notify each affected individual unless a statutory exception applies.

Somalia Data Protection Act, 2023, personal data breach notification

Keep a record of every personal data breach.

Suriname Draft Law on the Protection of Privacy and Personal Data, breach notification proposed

Document every breach relating to personal data, including the facts, its effects, and the corrective measures taken, in a form that lets the Commissioner verify your compliance with this duty.

Uruguay Ley N° 19.670, personal data breach notification

Notify the Unidad Reguladora y de Control de Datos Personales immediately and in detail on becoming aware of the breach, coordinating your response with the national cybersecurity incident response center (CERTuy).

Utah Protection of Personal Information Act

If unencrypted Utah-resident data combining a name with a Social Security number, a driver license or state ID number, or a financial account or card number with its access code is breached, investigate promptly in good faith and notify each affected Utah resident without unreasonable delay.

Zimbabwe Cyber and Data Protection Regulations 2024, security breach notification

Keep robust breach detection, investigation and internal reporting procedures in place, and keep a record of all personal data breaches.

Comprehensive regime

2 laws, 2 places
PlaceLawWhat it asks, as read here
Albania Law No. 124/2024 On the Protection of Personal Data

Implement technical and organizational security measures appropriate to the risk, including pseudonymization and encryption, the ability to restore access after an incident, and a process for regularly testing their effectiveness.

Barbados Data Protection Act, 2019

Implement technical and organisational measures giving a level of security appropriate to the risk, including pseudonymisation and encryption of personal data, the ability to restore availability and access in a timely manner after a physical or technical incident, and a process for regularly testing their effectiveness.

Biometric privacy

1 law, 1 place
PlaceLawWhat it asks, as read here
Colorado HB 24-1130, Privacy of Biometric Identifiers and Data

Adopt and publish a written policy that sets a retention schedule and a destruction timeline (the earliest of purpose satisfied, 24 months after the consumer's last interaction, or 45 days, extendable by up to 45 more, after the identifier is no longer needed) and a data-security-incident response protocol.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.