Privacy

NIST Privacy Framework

Formal standard US / Global NIST Since 2020

A voluntary framework structured like the Cybersecurity Framework (Identify, Govern, Control, Communicate, Protect) for managing privacy risk arising from data processing, not only from breaches.

Its useful contribution is separating privacy risk from security risk: problematic data actions can be entirely secure and still harm people. That distinction is what data minimisation and purpose limitation arguments hang on.

At a glance

Category
Privacy
Jurisdiction
US / Global
Governance
NIST
Status
Version 1.0 (2020); 1.1 in development alongside CSF 2.0
First released
2020

Links

Related frameworks

Other entries under Privacy.

See NIST Privacy Framework in context

Open the interactive Data Landscape for Regulation to compare NIST Privacy Framework against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.