Security Dimension 8 Privacy per X.805 Clause 6.8: Privacy provides protection of information that might be derived from the observation of network activities. Examples include websites visited by users + their geographic location + the IP addresses + DNS names of devices in a service provider network. Privacy is distinct from Data Confidentiality (Dim 4) which protects the data content itself - Privacy protects the metadata + identification + and observation of network activity. (1) Privacy Categories: (a) Anonymity - inability to determine the identity of the user; (b) Pseudonymity - use of an alias decoupling identity from real-world; (c) Unobservability - inability to determine whether activity has occurred; (d) Unlinkability - inability to determine whether two activities are related; (e) Plausible Deniability; (f) Minimal Disclosure. (2) Privacy by Design (PbD) per Ann Cavoukian 7 Principles: (a) Proactive not Reactive; (b) Privacy as Default Setting; (c) Privacy Embedded into Design; (d) Full Functionality - positive-sum not zero-sum; (e) End-to-End Security - lifecycle protection; (f) Visibility and Transparency; (g) Respect for User Privacy. (3) Privacy by Default + GDPR Article 25: data protection by design and by default + minimum data + minimum retention + minimum access + minimum persistence. (4) Personal Information Categories: (a) PII Personally Identifiable Information - direct + indirect identifiers; (b) Sensitive PII (special categories per GDPR Art 9) - health + genetic + biometric + racial + religious + political + sexual orientation; (c) Quasi-Identifiers (combinations enabling re-identification); (d) PHI Protected Health Information; (e) PCI Cardholder Data; (f) Financial Information; (g) Location data; (h) Behavioural data; (i) Inferred attributes. (5) Network-Specific Privacy Threats: (a) Traffic Analysis - metadata about who talks to whom + when + how often; (b) Network Element Logging - DHCP + DNS + ARP + NAT logs reveal user identity; (c) Subscriber Identifier exposure (IMSI + MSISDN + IMEI + MAC + cookies); (d) Location tracking via cell tower triangulation + GPS + Wi-Fi positioning + IP geolocation; (e) Device fingerprinting (canvas + WebGL + audio + behavioural); (f) Cookie tracking + Pixel tracking + Browser fingerprinting; (g) ISP traffic observation; (h) DNS query analysis; (i) TLS SNI exposure; (j) IPv6 EUI-64 stable identifier; (k) Mobile signalling SS7/Diameter location leakage. (6) Privacy-Enhancing Technologies (PETs): (a) Anonymisation + Pseudonymisation + K-Anonymity + L-Diversity + T-Closeness; (b) Differential Privacy (Laplace + Gaussian + Exponential mechanisms + epsilon-delta privacy budget) - Apple + Google + Microsoft + US Census 2020 + Meta; (c) Tor + Onion Routing; (d) VPN; (e) End-to-End Encryption (Signal + WhatsApp + iMessage); (f) Encrypted DNS (DoT + DoH + ODoH + DNSCrypt); (g) Encrypted SNI (ESNI + ECH Encrypted Client Hello); (h) MAC Address Randomization (iOS + Android + Windows); (i) Federated Learning (decentralised ML training); (j) Homomorphic Encryption for computation on encrypted data; (k) Secure Multi-Party Computation; (l) Zero-Knowledge Proofs; (m) Trusted Execution Environments (TEE) for sensitive processing. (7) Mobile + Telecom Privacy Specifics: (a) IMSI catchers (Stingray + DRTBox) + 5G SUPI/SUCI concealing; (b) SUPI Subscription Permanent Identifier vs SUCI Subscription Concealed Identifier per 3GPP TS 33.501; (c) 5G ECIES-based identifier concealment; (d) GSMA SUPI Privacy; (e) Lawful Intercept exceptions + judicial authorisation; (f) Carrier subscriber data retention vs minimisation; (g) GDPR Article 23 derogations; (h) ePrivacy Directive 2002/58 + ePrivacy Regulation pending. (8) Privacy per X.805 Layers: (a) Infrastructure - subscriber identifier privacy + IMSI concealment + MAC randomisation + IPv6 temporary addresses RFC 4941; (b) Services - service-level subscriber data protection + minimum data collection + purpose limitation; (c) Applications - application-level user privacy + cookie consent + GDPR data subject rights + DSAR. (9) Privacy per X.805 Planes: (a) Management - administrator access to subscriber data restricted + audit + RBAC; (b) Control - signalling subscriber identifier minimization + 5G SUCI; (c) End-User - subscriber Privacy Choice + Opt-Out + Cookie Consent + Granular Permissions. (10) Threats Mitigated per X.805 Table 1: (a) Disclosure (Y) - direct mitigation against unauthorised observation. (11) Legal + Regulatory Privacy Frameworks: (a) EU GDPR Regulation 2016/679 + ePrivacy Directive 2002/58/EC + LED Law Enforcement Directive 2016/680; (b) UK GDPR + DPA 2018; (c) US CCPA + CPRA + CDPA Virginia + CPA Colorado + Utah + Connecticut + 19+ state laws; (d) Brazil LGPD; (e) Canada PIPEDA + Quebec Law 25 + AIDA; (f) Japan APPI; (g) Korea PIPA; (h) Singapore PDPA; (i) Australia Privacy Act + Notifiable Data Breaches; (j) India DPDP Act 2023; (k) China PIPL + DSL + CSL; (l) HIPAA US Health; (m) GLBA US Financial; (n) FERPA US Education; (o) COPPA US Children. (12) Privacy Standards: (a) ISO/IEC 27701 PIMS Privacy Information Management System; (b) ISO/IEC 27018 Cloud Privacy; (c) ISO/IEC 29100 Privacy Framework; (d) ISO/IEC 29134 PIA Privacy Impact Assessment; (e) ISO/IEC 27018 Cloud PII; (f) ITU-T X.1058 PII Privacy Architecture; (g) NIST Privacy Framework v1.0; (h) AICPA SOC 2 Privacy Trust Principle; (i) IAPP CIPP/CIPM/CIPT certifications; (j) PETs Network (UK + Canada + USA). (13) Modern Evolution: (a) Privacy Engineering (NIST SP 800-160 Vol 2); (b) Data Protection Impact Assessment (DPIA) GDPR Article 35; (c) Privacy Impact Assessment (PIA); (d) Cookie Banner Compliance (IAB TCF v2.2); (e) Global Privacy Control (GPC); (f) PRIVACY SANDBOX (Google Chrome); (g) App Tracking Transparency (Apple ATT); (h) Consent Management Platforms (CMP); (i) Data Subject Access Request (DSAR) automation; (j) Right to Be Forgotten + Erasure automation; (k) Cross-border data transfers (SCCs + BCRs + Privacy Shield + EU-US DPF + adequacy decisions). Coordinates with X.805 Layer 1/2/3 + Plane 1/2/3 + Threats Disclosure + Security Dimension 1 Access Control + Security Dimension 4 Confidentiality + ITU-T X.1058 Privacy + ISO/IEC 27701 + 27018 + 29100 + 29134 + NIST Privacy Framework + GDPR + CCPA + ePrivacy + LGPD + LED + ISO/IEC 27018 + HIPAA + GLBA + PIPL + DPDP Act + 3GPP TS 33.501 5G SUCI + ENISA + EDPB + IAPP. ITU-T X.805 Security Dimension 8 Privacy applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.