Frameworks / NIST SP 800-122 / NISTSP122-4 NIST SP 800-122
Minimisation and De-Identification
NIST SP 800-122 NISTSP122-4: PII Minimisation, Purpose Limitation, and Pseudonymisation Apply Section 4.2-4.5 PII minimisation principles: collect only PII necessary + purpose limitation + storage limitation + accuracy + record retention per NARA schedule + secure disposal. Implement Section 5 de-identification techniques: pseudonymisation + anonymisation + aggregation + suppression + masking + differential privacy + k-anonymity + l-diversity + t-closeness + synthetic data generation. Reference NIST IR 8053 De-Identification of Personal Information + NIST SP 800-188 De-Identifying Government Datasets + NIST IR 8214A Threshold Schemes.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 150 controls across 43 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
GDPR-Art.10 Processing of personal data relating to criminal convictions GDPR-Art.11 Processing which does not require identification GDPR-Art.15 Right of access by the data subject GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction GDPR-Art.9 Processing of special categories of personal data UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2 APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A33 Request for Disclosure of Retained Personal Data APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing AZ-DPA-12 Article 13 - Cross-border transfer AZ-DPA-14 Article 16 - Liability for violations AZ-DPA-15 Article 17 - Dispute resolution BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-21 Sections 61-69 - Data Privacy Officer ISO23894-6.3.1 AI Risk Identification ISO23894-A.1 Data Quality and Representativeness ISO23894-A.5 Privacy and Data Protection in AI ISO-25012-5.1 Establishing data quality requirements ISO-25012-5.2 Defining data quality measures ISO-25012-5.3 Planning and performing data quality evaluations 29100-6.10 Information security 29100-6.5 Use, retention and disclosure limitation 29100-6.9 Accountability 29134-1 Scope 29134-3 Terms and definitions 29134-9.1 PIA report structure NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-7 Data Protection Assessments and Processor Contracts NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP NGOB-2 Customer Consent Management and Lifecycle NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN ISMSP-PI-01 Personal Information Collection ISMSP-PI-04 Cross-Border Transfer ISMSP-SYS-02 Encryption Implementation AL-DPA-12 International Data Transfers AL-DPA-7 Right of Access DIQ-2 Data Quality Management DIQ-3 Metadata Management FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) 27400-5.4 Data and privacy risks 27400-7.3 Data minimization and purpose limitation 27557-3 Terms and definitions 27557-4.3 Individual impact consideration RUSPD-1 Scope, Definitions, Principles under 152-FZ RUSPD-4 Special Categories, Biometric Data TURKEYKVKK-2 Information Notice and Data Subject Rights TURKEYKVKK-3 Special Categories and Sensitive Data USMCADIGITAL-1 Cross-Border Data Flows and Localisation USMCADIGITAL-2 Personal Information Protection and Consumer Protection VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) VIETNAMCYBER-4 Incident Reporting and Cooperation DS-2 Ensure software supply chain security CA-10 Selects and Develops Control Activities FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training EHDS-HOLD-3 Dataset Descriptions and Catalogues RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) TEFCAREC-1 Common Agreement Conformance and Onboarding VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 150 it maps to, and the evidence behind each claim, over MCP and REST.