NIST Privacy Framework
Control-P

NIST Privacy Framework NISTPF-3: Control-P - Privacy Controls, Data Management, and Disassociated Processing

Apply Control-P function including: Control Policies (CT.PO-P) covering policies + plans + processes for privacy risk control; Data Management (CT.DM-P) covering data quality + retention + destruction + access + transmission + alteration + deletion + correction + portability + opt-out + redress; and Disassociated Processing (CT.DP-P) covering data minimisation + anonymisation + de-identification + pseudonymisation + differential privacy + privacy-enhancing technologies (PETs) including homomorphic encryption + multi-party computation + zero-knowledge proofs.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 196 controls across 87 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 5 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.9 Processing of special categories of personal data
  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09)
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10)

South Korea ISMS-P · 4 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-SYS-02 Encryption Implementation

APPI · 3 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution

Bahrain PDPL · 3 controls

  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)

ISO/IEC 27400:2022 · 3 controls

  • 27400-5.4 Data and privacy risks
  • 27400-6.1 Secure Device Design
  • 27400-7.3 Data minimization and purpose limitation

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

NIST SP 800-122 · 3 controls

  • NISTSP122-4 PII Minimisation, Purpose Limitation, and Pseudonymisation
  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit
  • NISTSP122-6 PII Breach Response and Incident Handling

NIST SP 800-53 Rev 5 · 3 controls

  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-3 Broken Object Property Level Authorization (BOPLA)

OWASP Top 10:2025 · 2 controls

  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment

PDPA Singapore · 2 controls

  • PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis
  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 2 controls

  • PDPATH-5 Security Measures and Data Protection
  • PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement

Peru DPL · 2 controls

  • PERU-2 Consent, Privacy Notice, Sensitive Data
  • PERU-5 Security of Personal Data and Processor Agreements
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response

Privacy Act 2020 · 2 controls

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-4 Incident Reporting and Cooperation
  • AL-DPA-12 International Data Transfers
  • DS-2 Ensure software supply chain security

BSI IT-Grundschutz · 1 control

  • BSI-02 Access enforcement and least privilege
  • CA-10 Selects and Develops Control Activities
  • CTDPA-1 Definitions
  • DSO-3 Data Access Management
  • CAT-IRP-4 Organizational characteristics
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • 62351-8 Role-based access control (RBAC)

ISO 27799:2025 · 1 control

  • ISO27799-01 ePHI access controls and authorization

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.5 Privacy and Data Protection in AI

ISO/IEC 27011:2024 · 1 control

  • 27011-8.1 User Endpoint Devices

ISO/IEC 27043:2015 · 1 control

  • ISO27043-14 Privileged access management

ISO/SAE 21434 · 1 control

  • ISO21434-14 Privileged access management
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 1 control

  • NISTSP123-3 Authentication, Access Control, and Account Management

NIST SP 800-137 · 1 control

  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-145 · 1 control

  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 1 control

NIST SP 800-190 · 1 control

  • NIST190-08 Privileged access in cloud environments
  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OECD AI Principles · 1 control

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

OWASP ASVS · 1 control

OWASP MASVS · 1 control

OpenSSF Scorecard · 1 control

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • SAPAIA-4 Information Regulator Cooperation and Appeals

South Korea PIPA · 1 control

  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • OB-CX.2 Granular Consent Management
  • ACE-CR-4 Cargo Release Authorization
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Vietnam PDPD · 1 control

  • VIETNAMPDP-1 Scope, Categorisation, Lawful Basis

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 196 it maps to, and the evidence behind each claim, over MCP and REST.