Law / Frameworks / NIST Privacy Framework / Protect-P
NIST Privacy Framework, Protect-PPR.PO-P9
Privacy procedures are included in human resources practices (e.g., deprovisioning, personnel screening).NIST Privacy Framework, version 1.0, January 2020, PR.PO-P9
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 14
- laws
- 14
- places
- 0
- with court rulings behind them
- 1
- not yet in force
- 1
- proposed, not law
A law in force is unmarked; the rest wear their state: not yet in force proposed
Comprehensive regime
12 laws, 12 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 124/2024 On the Protection of Personal Data |
Keep personal data confidential wherever an employee or processor has access to it for professional reasons, bind that confidentiality into every processor contract and employment contract, and continue it after the contract or employment ends. |
|
| Law on the Protection of Personal Data |
Keep personal data confidential, both as a data controller and as anyone who learns of it in the course of their duties, including after the relationship ends. |
|
| Loi n°001/2011 relative à la protection des données à caractère personnel, modifiée par la loi n°025/2023 |
Keep processing confidential, bind everyone who processes the data under your authority to a signed written undertaking, and impose the same security and confidentiality guarantees on any processor by contract. |
|
| Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) |
Require everyone who takes part in any stage of processing personal data to keep it confidential, an obligation that survives the end of their relationship with you. |
|
| Law on Personal Data Protection from a date not yet set |
Implement technical, personnel and organizational safeguards appropriate to the nature of the data processed to protect it against loss, destruction, unauthorized access, alteration, publicizing and abuse, under Article 24, and keep confidential any personal data your staff become privy to in the course of their work, under Article 25. |
|
| Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data |
Bind any processor you use to security guarantees equivalent to your own by contract, and hold anyone with authorized access to personal data, including after they leave that role, to professional secrecy. |
|
| Ley 29733, Ley de Protección de Datos Personales |
Keep confidential any personal data you hold or process, and continue to do so even after your relationship with the data bank's owner ends. |
|
| Telecommunications Act 2005, confidentiality and protection of customer personal information |
Do not divulge information overheard from a customer's telephone conversation, or a customer's personal particulars obtained in the course of duties, without good and sufficient cause. |
|
| Lei n.º 03/2016, Protecção de Dados Pessoais |
Do not process personal data you access as a subcontractor, or on the controller's authority, beyond the controller's instructions except under a legal obligation, and keep confidential any personal data you learn of in the course of your duties, including after those duties end. |
|
| Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens) proposed |
Take appropriate technical and organizational measures so you can demonstrate compliance with this law on request, and require anyone with access to personal data under your authority to keep it confidential or be bound by a legal duty of confidentiality. |
Show the other 2 laws
| Loi n° 2019-014, protection des données à caractère personnel |
Choose a processor that offers sufficient guarantees, govern the engagement with a written contract confining the processor to your instructions, and keep processing confidential under the authority of persons who have signed a written confidentiality undertaking. |
|
| Organic Act on the Protection of Personal Data |
Preserve the confidentiality of personal data and the information you process, even after the processing ends or you leave your position, unless the person consented in writing to its disclosure or the law provides otherwise. |
Enforcement supervision
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Personal Data Protection Act 2025, competent authority, remedies, and complaints |
Maintain confidentiality of personal data obtained while performing duties for the competent authority, if engaged by it as a director, employee, or consultant. |
Sensitive categories
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Act of 30 July 2018 Articles 8-10, Special-Category Processing Grounds |
Designate the specific staff with access to genetic, biometric, or health data of a person in Belgium, keep that list available to the GBA/APD, and bind those staff to confidentiality, per Act Article 9. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.