ITU-T X.805 - Security Architecture for End-to-End Communications
X.805 Security Dimension 8 - Privacy
ITU-T X.805 - Security Architecture for End-to-End Communications X805-Dim8-Privacy-Identification-Network-Activity-Personal-Information-Confidentiality: ITU-T X.805 Security Dimension 8 - Privacy + Identification of Network Activity + Personal Information Confidentiality + Subscriber Anonymity + Pseudonymity + Anti-Tracking + Location Privacy + Data Minimization + GDPR/CCPA Alignment
Security Dimension 8 Privacy per X.805 Clause 6.8: Privacy shields what could be inferred by watching activity on the network, for example websites visited by users + their geographic location + the IP addresses and DNS names assigned to devices inside a provider's network. Privacy is distinct from Data Confidentiality (Dim 4) which protects the data content itself - Privacy protects the metadata + identification + and observation of network activity. (1) Privacy Categories: (a) Anonymity - inability to determine the identity of the user; (b) Pseudonymity - use of an alias decoupling identity from real-world; (c) Unobservability - inability to determine whether activity has occurred; (d) Unlinkability - inability to determine whether two activities are related; (e) Plausible Deniability; (f) Minimal Disclosure. (2) Privacy by Design (PbD) per Ann Cavoukian 7 Principles: (a) Proactive not Reactive; (b) Privacy as Default Setting; (c) Privacy Embedded into Design; (d) Full Functionality - positive-sum not zero-sum; (e) End-to-End Security - lifecycle protection; (f) Visibility and Transparency; (g) Respect for User Privacy. (3) Privacy by Default + GDPR Article 25: data protection by design and by default + minimum data + minimum retention + minimum access + minimum persistence. (4) Personal Information Categories: (a) PII Personally Identifiable Information - direct + indirect identifiers; (b) Sensitive PII (special categories per GDPR Art 9) - health + genetic + biometric + racial + religious + political + sexual orientation; (c) Quasi-Identifiers (combinations enabling re-identification); (d) PHI Protected Health Information; (e) PCI Cardholder Data; (f) Financial Information; (g) Location data; (h) Behavioural data; (i) Inferred attributes. (5) Network-Specific Privacy Threats: (a) Traffic Analysis - metadata about who talks to whom + when + how often; (b) Network Element Logging - DHCP + DNS + ARP + NAT logs reveal user identity; (c) Subscriber Identifier exposure (IMSI + MSISDN + IMEI + MAC + cookies); (d) Location tracking via cell tower triangulation + GPS + Wi-Fi positioning + IP geolocation; (e) Device fingerprinting (canvas + WebGL + audio + behavioural); (f) Cookie tracking + Pixel tracking + Browser fingerprinting; (g) ISP traffic observation; (h) DNS query analysis; (i) TLS SNI exposure; (j) IPv6 EUI-64 stable identifier; (k) Mobile signalling SS7/Diameter location leakage. (6) Privacy-Enhancing Technologies (PETs): (a) Anonymisation + Pseudonymisation + K-Anonymity + L-Diversity + T-Closeness; (b) Differential Privacy (Laplace + Gaussian + Exponential mechanisms + epsilon-delta privacy budget) - Apple + Google + Microsoft + US Census 2020 + Meta; (c) Tor + Onion Routing; (d) VPN; (e) End-to-End Encryption (Signal + WhatsApp + iMessage); (f) Encrypted DNS (DoT + DoH + ODoH + DNSCrypt); (g) Encrypted SNI (ESNI + ECH Encrypted Client Hello); (h) MAC Address Randomization (iOS + Android + Windows); (i) Federated Learning (decentralised ML training); (j) Homomorphic Encryption for computation on encrypted data; (k) Secure Multi-Party Computation; (l) Zero-Knowledge Proofs; (m) Trusted Execution Environments (TEE) for sensitive processing. (7) Mobile + Telecom Privacy Specifics: (a) IMSI catchers (Stingray + DRTBox) + 5G SUPI/SUCI concealing; (b) SUPI Subscription Permanent Identifier vs SUCI Subscription Concealed Identifier per 3GPP TS 33.501; (c) 5G ECIES-based identifier concealment; (d) GSMA SUPI Privacy; (e) Lawful Intercept exceptions + judicial authorisation; (f) Carrier subscriber data retention vs minimisation; (g) GDPR Article 23 derogations; (h) ePrivacy Directive 2002/58 + ePrivacy Regulation pending. (8) Privacy per X.805 Layers: (a) Infrastructure - subscriber identifier privacy + IMSI concealment + MAC randomisation + IPv6 temporary addresses RFC 4941; (b) Services - service-level subscriber data protection + minimum data collection + purpose limitation; (c) Applications - application-level user privacy + cookie consent + GDPR data subject rights + DSAR. (9) Privacy per X.805 Planes: (a) Management - administrator access to subscriber data restricted + audit + RBAC; (b) Control - signalling subscriber identifier minimization + 5G SUCI; (c) End-User - subscriber Privacy Choice + Opt-Out + Cookie Consent + Granular Permissions. (10) Threats Mitigated per X.805 Table 1: (a) Disclosure (Y) - direct mitigation against unauthorised observation. (11) Legal + Regulatory Privacy Frameworks: (a) EU GDPR Regulation 2016/679 + ePrivacy Directive 2002/58/EC + LED Law Enforcement Directive 2016/680; (b) UK GDPR + DPA 2018; (c) US CCPA + CPRA + CDPA Virginia + CPA Colorado + Utah + Connecticut + 19+ state laws; (d) Brazil LGPD; (e) Canada PIPEDA + Quebec Law 25 + AIDA; (f) Japan APPI; (g) Korea PIPA; (h) Singapore PDPA; (i) Australia Privacy Act + Notifiable Data Breaches; (j) India DPDP Act 2023; (k) China PIPL + DSL + CSL; (l) HIPAA US Health; (m) GLBA US Financial; (n) FERPA US Education; (o) COPPA US Children. (12) Privacy Standards: (a) ISO/IEC 27701 PIMS Privacy Information Management System; (b) ISO/IEC 27018 Cloud Privacy; (c) ISO/IEC 29100 Privacy Framework; (d) ISO/IEC 29134 PIA Privacy Impact Assessment; (e) ISO/IEC 27018 Cloud PII; (f) ITU-T X.1058 PII Privacy Architecture; (g) NIST Privacy Framework v1.0; (h) AICPA SOC 2 Privacy Trust Principle; (i) IAPP CIPP/CIPM/CIPT certifications; (j) PETs Network (UK + Canada + USA). (13) Modern Evolution: (a) Privacy Engineering (NIST SP 800-160 Vol 2); (b) Data Protection Impact Assessment (DPIA) GDPR Article 35; (c) Privacy Impact Assessment (PIA); (d) Cookie Banner Compliance (IAB TCF v2.2); (e) Global Privacy Control (GPC); (f) PRIVACY SANDBOX (Google Chrome); (g) App Tracking Transparency (Apple ATT); (h) Consent Management Platforms (CMP); (i) Data Subject Access Request (DSAR) automation; (j) Right to Be Forgotten + Erasure automation; (k) Cross-border data transfers (SCCs + BCRs + Privacy Shield + EU-US DPF + adequacy decisions). Coordinates with X.805 Layer 1/2/3 + Plane 1/2/3 + Threats Disclosure + Security Dimension 1 Access Control + Security Dimension 4 Confidentiality + ITU-T X.1058 Privacy + ISO/IEC 27701 + 27018 + 29100 + 29134 + NIST Privacy Framework + GDPR + CCPA + ePrivacy + LGPD + LED + ISO/IEC 27018 + HIPAA + GLBA + PIPL + DPDP Act + 3GPP TS 33.501 5G SUCI + ENISA + EDPB + IAPP. ITU-T X.805 Security Dimension 8 Privacy applies.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 251 controls across 94 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent
JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle