Frameworks / NIST Privacy Framework / NISTPF-3 NIST Privacy Framework
Control-P
NIST Privacy Framework NISTPF-3: Control-P - Privacy Controls, Data Management, and Disassociated Processing Apply Control-P function including: Control Policies (CT.PO-P) covering policies + plans + processes for privacy risk control; Data Management (CT.DM-P) covering data quality + retention + destruction + access + transmission + alteration + deletion + correction + portability + opt-out + redress; and Disassociated Processing (CT.DP-P) covering data minimisation + anonymisation + de-identification + pseudonymisation + differential privacy + privacy-enhancing technologies (PETs) including homomorphic encryption + multi-party computation + zero-knowledge proofs.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 196 controls across 87 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
GDPR-Art.10 Processing of personal data relating to criminal convictions GDPR-Art.11 Processing which does not require identification GDPR-Art.15 Right of access by the data subject GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction GDPR-Art.9 Processing of special categories of personal data OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10) ISMSP-AC-01 Access Control Policy ISMSP-PI-01 Personal Information Collection ISMSP-PI-04 Cross-Border Transfer ISMSP-SYS-02 Encryption Implementation APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A33 Request for Disclosure of Retained Personal Data APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing AZ-DPA-12 Article 13 - Cross-border transfer AZ-DPA-14 Article 16 - Liability for violations AZ-DPA-15 Article 17 - Dispute resolution BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-21 Sections 61-69 - Data Privacy Officer UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) 27400-5.4 Data and privacy risks 27400-6.1 Secure Device Design 27400-7.3 Data minimization and purpose limitation 29100-6.10 Information security 29100-6.5 Use, retention and disclosure limitation 29100-6.9 Accountability 29134-1 Scope 29134-3 Terms and definitions 29134-9.1 PIA report structure NISTSP122-4 PII Minimisation, Purpose Limitation, and Pseudonymisation NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP122-6 PII Breach Response and Incident Handling DSOMM-1 Culture, Organization, Education, and Governance DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) 27557-3 Terms and definitions 27557-4.3 Individual impact consideration OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA OWASPAPI-3 Broken Object Property Level Authorization (BOPLA) OMANCS-3 Identity and Access Management, Authentication, Privileged Access OMANCS-4 Data Protection, Cryptography, and Privacy Alignment PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement PERU-2 Consent, Privacy Notice, Sensitive Data PERU-5 Security of Personal Data and Processor Agreements AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response NZPRV-2 IPP 5 Storage and Security of Personal Information NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design RUSPD-1 Scope, Definitions, Principles under 152-FZ RUSPD-4 Special Categories, Biometric Data USMCADIGITAL-1 Cross-Border Data Flows and Localisation USMCADIGITAL-2 Personal Information Protection and Consumer Protection VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) VIETNAMCYBER-4 Incident Reporting and Cooperation AL-DPA-12 International Data Transfers DS-2 Ensure software supply chain security BSI-02 Access enforcement and least privilege CA-10 Selects and Develops Control Activities DSO-3 Data Access Management CAT-IRP-4 Organizational characteristics FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) 62351-8 Role-based access control (RBAC) ISO-19650-2-5.7 Information model delivery ISO27799-01 ePHI access controls and authorization ISO23894-A.5 Privacy and Data Protection in AI 27011-8.1 User Endpoint Devices ISO27043-14 Privileged access management ISO21434-14 Privileged access management NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP123-3 Authentication, Access Control, and Account Management NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NIST190-08 Privileged access in cloud environments NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) SAPAIA-4 Information Regulator Cooperation and Appeals PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 TEFCAREC-1 Common Agreement Conformance and Onboarding TURKEYKVKK-2 Information Notice and Data Subject Rights OB-CX.2 Granular Consent Management ACE-CR-4 Cargo Release Authorization VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VIETNAMPDP-1 Scope, Categorisation, Lawful Basis Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 196 it maps to, and the evidence behind each claim, over MCP and REST.