Privacy
NIST Privacy Framework
A voluntary framework structured like the Cybersecurity Framework (Identify, Govern, Control, Communicate, Protect) for managing privacy risk arising from data processing, not only from breaches.
Its useful contribution is separating privacy risk from security risk: problematic data actions can be entirely secure and still harm people. That distinction is what data minimisation and purpose limitation arguments hang on.
At a glance
- Category
- Privacy
- Jurisdiction
- US / Global
- Governance
- NIST
- Status
- Version 1.0 (2020); 1.1 in development alongside CSF 2.0
- First released
- 2020
Links
Related frameworks
Other entries under Privacy.
- ISO/IEC 27701: Privacy Information Management System
- ISO/IEC 27018: Protection of PII in Public Clouds
- ISO/IEC 29100: Privacy Framework
See NIST Privacy Framework in context
Open the interactive Data Landscape for Regulation to compare NIST Privacy Framework against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.