ITU-T X.805 - Security Architecture for End-to-End Communications
X.805 Security Dimension 8 - Privacy

ITU-T X.805 - Security Architecture for End-to-End Communications X805-Dim8-Privacy-Identification-Network-Activity-Personal-Information-Confidentiality: ITU-T X.805 Security Dimension 8 - Privacy + Identification of Network Activity + Personal Information Confidentiality + Subscriber Anonymity + Pseudonymity + Anti-Tracking + Location Privacy + Data Minimization + GDPR/CCPA Alignment

Security Dimension 8 Privacy per X.805 Clause 6.8: Privacy shields what could be inferred by watching activity on the network, for example websites visited by users + their geographic location + the IP addresses and DNS names assigned to devices inside a provider's network. Privacy is distinct from Data Confidentiality (Dim 4) which protects the data content itself - Privacy protects the metadata + identification + and observation of network activity. (1) Privacy Categories: (a) Anonymity - inability to determine the identity of the user; (b) Pseudonymity - use of an alias decoupling identity from real-world; (c) Unobservability - inability to determine whether activity has occurred; (d) Unlinkability - inability to determine whether two activities are related; (e) Plausible Deniability; (f) Minimal Disclosure. (2) Privacy by Design (PbD) per Ann Cavoukian 7 Principles: (a) Proactive not Reactive; (b) Privacy as Default Setting; (c) Privacy Embedded into Design; (d) Full Functionality - positive-sum not zero-sum; (e) End-to-End Security - lifecycle protection; (f) Visibility and Transparency; (g) Respect for User Privacy. (3) Privacy by Default + GDPR Article 25: data protection by design and by default + minimum data + minimum retention + minimum access + minimum persistence. (4) Personal Information Categories: (a) PII Personally Identifiable Information - direct + indirect identifiers; (b) Sensitive PII (special categories per GDPR Art 9) - health + genetic + biometric + racial + religious + political + sexual orientation; (c) Quasi-Identifiers (combinations enabling re-identification); (d) PHI Protected Health Information; (e) PCI Cardholder Data; (f) Financial Information; (g) Location data; (h) Behavioural data; (i) Inferred attributes. (5) Network-Specific Privacy Threats: (a) Traffic Analysis - metadata about who talks to whom + when + how often; (b) Network Element Logging - DHCP + DNS + ARP + NAT logs reveal user identity; (c) Subscriber Identifier exposure (IMSI + MSISDN + IMEI + MAC + cookies); (d) Location tracking via cell tower triangulation + GPS + Wi-Fi positioning + IP geolocation; (e) Device fingerprinting (canvas + WebGL + audio + behavioural); (f) Cookie tracking + Pixel tracking + Browser fingerprinting; (g) ISP traffic observation; (h) DNS query analysis; (i) TLS SNI exposure; (j) IPv6 EUI-64 stable identifier; (k) Mobile signalling SS7/Diameter location leakage. (6) Privacy-Enhancing Technologies (PETs): (a) Anonymisation + Pseudonymisation + K-Anonymity + L-Diversity + T-Closeness; (b) Differential Privacy (Laplace + Gaussian + Exponential mechanisms + epsilon-delta privacy budget) - Apple + Google + Microsoft + US Census 2020 + Meta; (c) Tor + Onion Routing; (d) VPN; (e) End-to-End Encryption (Signal + WhatsApp + iMessage); (f) Encrypted DNS (DoT + DoH + ODoH + DNSCrypt); (g) Encrypted SNI (ESNI + ECH Encrypted Client Hello); (h) MAC Address Randomization (iOS + Android + Windows); (i) Federated Learning (decentralised ML training); (j) Homomorphic Encryption for computation on encrypted data; (k) Secure Multi-Party Computation; (l) Zero-Knowledge Proofs; (m) Trusted Execution Environments (TEE) for sensitive processing. (7) Mobile + Telecom Privacy Specifics: (a) IMSI catchers (Stingray + DRTBox) + 5G SUPI/SUCI concealing; (b) SUPI Subscription Permanent Identifier vs SUCI Subscription Concealed Identifier per 3GPP TS 33.501; (c) 5G ECIES-based identifier concealment; (d) GSMA SUPI Privacy; (e) Lawful Intercept exceptions + judicial authorisation; (f) Carrier subscriber data retention vs minimisation; (g) GDPR Article 23 derogations; (h) ePrivacy Directive 2002/58 + ePrivacy Regulation pending. (8) Privacy per X.805 Layers: (a) Infrastructure - subscriber identifier privacy + IMSI concealment + MAC randomisation + IPv6 temporary addresses RFC 4941; (b) Services - service-level subscriber data protection + minimum data collection + purpose limitation; (c) Applications - application-level user privacy + cookie consent + GDPR data subject rights + DSAR. (9) Privacy per X.805 Planes: (a) Management - administrator access to subscriber data restricted + audit + RBAC; (b) Control - signalling subscriber identifier minimization + 5G SUCI; (c) End-User - subscriber Privacy Choice + Opt-Out + Cookie Consent + Granular Permissions. (10) Threats Mitigated per X.805 Table 1: (a) Disclosure (Y) - direct mitigation against unauthorised observation. (11) Legal + Regulatory Privacy Frameworks: (a) EU GDPR Regulation 2016/679 + ePrivacy Directive 2002/58/EC + LED Law Enforcement Directive 2016/680; (b) UK GDPR + DPA 2018; (c) US CCPA + CPRA + CDPA Virginia + CPA Colorado + Utah + Connecticut + 19+ state laws; (d) Brazil LGPD; (e) Canada PIPEDA + Quebec Law 25 + AIDA; (f) Japan APPI; (g) Korea PIPA; (h) Singapore PDPA; (i) Australia Privacy Act + Notifiable Data Breaches; (j) India DPDP Act 2023; (k) China PIPL + DSL + CSL; (l) HIPAA US Health; (m) GLBA US Financial; (n) FERPA US Education; (o) COPPA US Children. (12) Privacy Standards: (a) ISO/IEC 27701 PIMS Privacy Information Management System; (b) ISO/IEC 27018 Cloud Privacy; (c) ISO/IEC 29100 Privacy Framework; (d) ISO/IEC 29134 PIA Privacy Impact Assessment; (e) ISO/IEC 27018 Cloud PII; (f) ITU-T X.1058 PII Privacy Architecture; (g) NIST Privacy Framework v1.0; (h) AICPA SOC 2 Privacy Trust Principle; (i) IAPP CIPP/CIPM/CIPT certifications; (j) PETs Network (UK + Canada + USA). (13) Modern Evolution: (a) Privacy Engineering (NIST SP 800-160 Vol 2); (b) Data Protection Impact Assessment (DPIA) GDPR Article 35; (c) Privacy Impact Assessment (PIA); (d) Cookie Banner Compliance (IAB TCF v2.2); (e) Global Privacy Control (GPC); (f) PRIVACY SANDBOX (Google Chrome); (g) App Tracking Transparency (Apple ATT); (h) Consent Management Platforms (CMP); (i) Data Subject Access Request (DSAR) automation; (j) Right to Be Forgotten + Erasure automation; (k) Cross-border data transfers (SCCs + BCRs + Privacy Shield + EU-US DPF + adequacy decisions). Coordinates with X.805 Layer 1/2/3 + Plane 1/2/3 + Threats Disclosure + Security Dimension 1 Access Control + Security Dimension 4 Confidentiality + ITU-T X.1058 Privacy + ISO/IEC 27701 + 27018 + 29100 + 29134 + NIST Privacy Framework + GDPR + CCPA + ePrivacy + LGPD + LED + ISO/IEC 27018 + HIPAA + GLBA + PIPL + DPDP Act + 3GPP TS 33.501 5G SUCI + ENISA + EDPB + IAPP. ITU-T X.805 Security Dimension 8 Privacy applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 251 controls across 94 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 5 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.9 Processing of special categories of personal data
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • Standard 13 Nudge Techniques
  • Standard 14 Connected Toys and Devices
  • Standard 5 Detrimental Use of Data
  • Standard 8 Data Minimisation

APPI · 3 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution

Bahrain PDPL · 3 controls

  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

Malaysia PDPA 2010 · 3 controls

  • MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing
  • MY-PDPA-Data-Subject-Rights-Access-Correction-Portability-Withdraw-Consent-Prevent-Marketing-Sections-30-43 Malaysia PDPA Subject Rights + Access + Correction + Portability + Withdraw Consent + Prevent Marketing + Sections 30 to 43
  • MY-PDPA-Seven-Personal-Data-Protection-Principles-General-Notice-Choice-Disclosure-Security-Retention-Data-Integrity-Access Malaysia PDPA Seven Principles + General + Notice and Choice + Disclosure + Security + Retention + Data Integrity + Access

NIST SP 800-122 · 3 controls

  • NISTSP122-4 PII Minimisation, Purpose Limitation, and Pseudonymisation
  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit
  • NISTSP122-6 PII Breach Response and Incident Handling
  • NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NHPA-6 Reasonable Data Security and Breach Response
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP
  • NGOB-2 Customer Consent Management and Lifecycle
  • NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN
  • OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs

SASB Standards · 3 controls

  • SASB-4 Social Capital (SC)
  • SASB-SC-1 Customer Privacy and Data Security
  • SASB-SOC-2 Customer Privacy

SOC 2 · 3 controls

  • SOC2-P3.1 P3.1 Collecting personal information consistent with objectives
  • SOC2-P4.3 P4.3 Securely disposing of personal information
  • SOC2-P6.1 P6.1 Disclosure to third parties with consent

Saudi Arabia PDPL · 3 controls

  • SA-PDPL-13 Encryption of personal data
  • SA-PDPL-15 Access control for personal data
  • SA-PDPL-22 Privacy by design and default

South Korea ISMS-P · 3 controls

  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-SYS-02 Encryption Implementation
  • SWE-1 Scope and Purpose
  • SWE-11 Integritetsskyddsmyndigheten (IMY)
  • SWE-2 Relationship to GDPR
  • UK-DPA18-GEN-04 UK-Specific Exemptions
  • UK-DPA18-LE-02 Data Subject Rights (Law Enforcement)
  • UK-DPA18-LE-03 International Transfers (Law Enforcement)

ISO/IEC 27400:2022 · 2 controls

  • 27400-5.4 Data and privacy risks
  • 27400-7.3 Data minimization and purpose limitation
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration

Liechtenstein DPA · 2 controls

Mauritius DPA · 2 controls

  • MU-DPA-Data-Subject-Rights-Sections-26-33-Access-Rectification-Erasure-Restriction-Portability-Objection Mauritius DPA Subject Rights + Sections 26 to 33 + Access + Rectification + Erasure + Restriction + Portability + Objection
  • MU-DPA-Seven-Principles-Section-21-Lawfulness-Purpose-Minimisation-Accuracy-Storage-Integrity-Accountability Mauritius DPA Seven Principles + Section 21 + Lawfulness + Purpose + Minimisation + Accuracy + Storage + Integrity + Accountability

Mexico LFPDPPP · 2 controls

  • MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014
  • MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent
  • MN-CDPA-Enforcement-AG-Ellison-Section-325O-10-USD-7500-Per-Violation-Data-Broker-Registration-325O-13-Sunset-25-Jan-2026 Minnesota CDPA Enforcement + AG Ellison + Section 325O.10 + USD 7,500 Per Violation + Data Broker Registration + Sunset 25 January 2026
  • MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification
  • MT-CDPA-Privacy-Notice-MCA-30-14-2806-Categories-Purposes-Rights-Email-Online-Mechanism-Appeal Montana CDPA Privacy Notice + MCA 30-14-2806 + Categories + Purposes + Rights + Online Mechanism + Appeal
  • MT-CDPA-Scope-SB-384-Gianforte-19-May-2023-Effective-1-October-2024-MCA-30-14-2801-AG-Knudsen-50K-Threshold Montana CDPA Scope + SB 384 + Gianforte 19 May 2023 + Effective 1 October 2024 + MCA 30-14-2801 + AG Knudsen + 50K Threshold
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs

PDPA Singapore · 2 controls

  • PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis
  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 2 controls

  • PDPATH-5 Security Measures and Data Protection
  • PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement

POPIA · 2 controls

  • POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions
  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement

Peru DPL · 2 controls

  • PERU-2 Consent, Privacy Notice, Sensitive Data
  • PERU-5 Security of Personal Data and Processor Agreements
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response

Privacy Act 2020 · 2 controls

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design

Qatar DPL · 2 controls

  • QATAR-3 Data Subject Rights
  • QATAR-7 DPO, Records, Retention, Marketing, Training
  • RIDTPPA-11 Data Minimisation and Purpose Limitation
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • SSAE18-P1.1 P1.1 - Privacy Notice
  • SSAE18-P1.2 P1.2 - Choice and Consent

South Korea PIPA · 2 controls

  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2

Taiwan PDPA · 2 controls

  • TAIWAN-2 Consent, Notice, Sensitive Data
  • TAIWAN-3 Data Subject Rights
  • UKGDPRREG-2 Data Subject Rights (Articles 12-22)
  • UKGDPRREG-3 Controller and Processor (Articles 24-43)
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • UGA-13 Unlawful Obtaining or Disclosure
  • UGA-15 Unauthorized Sale of Data

Uruguay DPL · 2 controls

  • URUGUAY-1 Scope, Lawful Basis, Consent
  • URUGUAY-5 Database Registration with AGESIC URCDP
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-4 Incident Reporting and Cooperation
  • AL-DPA-12 International Data Transfers
  • DS-2 Ensure software supply chain security
  • CA-10 Selects and Develops Control Activities
  • CTDPA-1 Definitions
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.5 Privacy and Data Protection in AI

Japan AI Guidelines · 1 control

  • JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle

LGPD · 1 control

  • LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response
  • DOM172-Lawful-Basis-Consent-Notice-Information-Duty-Articles-4-12-Quality-Principle-Purpose-Limitation-Minimisation Dominican Republic Law 172-13 Lawful Basis + Consent + Notice + Information Duty + Articles 4-12

MARS-E · 1 control

  • NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7
  • NISTAI600-7 Confabulation, Bias, Information Integrity, Privacy, IP (Risks 2, 4, 5, 6, 7, 8, 10, 11)
  • NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection
  • NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management
  • NGNDPR-2 Governing Principles, Lawful Basis, and Consent under NDPR Section 2.1-2.3
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold

OECD AI Principles · 1 control

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • RCEPEC-1 Online Personal Information Protection (12.13)
  • SOC-CY-DC2 Nature of Sensitive Information
  • SAPAIA-4 Information Regulator Cooperation and Appeals
  • STUDPRV-2 Data Subject Rights for Students and Parents
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • TISAXASS-3 Prototype Protection and Confidentiality
  • TEXASTDPSA-3 Sensitive Data, Children, Sale Notice

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • UKAI-2 Sector-Specific Regulator Engagement
  • OB-CX.2 Granular Consent Management
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Vietnam PDPD · 1 control

  • VIETNAMPDP-1 Scope, Categorisation, Lawful Basis

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-1 Scope, Applicability, Definitions
  • SO3.2 Regulatory frameworks for digital health

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 251 it maps to, and the evidence behind each claim, over MCP and REST.