NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
Consumer Privacy and Marketing

NRF Cybersecurity and Data Privacy Framework (National Retail Federation) NRFCS-4: Consumer Privacy Rights, Consent, Marketing, and Loyalty Data

Honor consumer privacy rights + consent + marketing + loyalty data obligations per applicable jurisdiction privacy law + sectoral marketing law. Privacy rights must (a) honor data subject access + deletion + correction + portability + opt-out of sale or sharing + opt-out of targeted advertising + limit use of sensitive personal information + non-discrimination per CCPA + CPRA + similar state laws, (b) provide privacy notice at collection with content per applicable law, (c) honor Global Privacy Control signal + Universal Opt-Out Mechanism where applicable, (d) age-gate children data per COPPA + state child privacy laws + sensitive flag transgender/non-binary data per state-specific provisions. Consent must (a) obtain opt-in consent where required (sensitive data + marketing email/SMS per CAN-SPAM/TCPA + cross-border transfers per GDPR + EU consumer products per ePrivacy), (b) distinguish opt-in vs opt-out per data type + per jurisdiction + per processing purpose, (c) maintain consent receipts + revocation processes + audit trail. Marketing and loyalty data must (a) bind loyalty data uses to disclosed purposes + obtain explicit consent for novel uses (third-party sharing + behavioral advertising + cross-context advertising), (b) implement marketing preference centers + suppression lists + CAN-SPAM unsubscribe + TCPA prior express written consent for autodialed/prerecorded calls + texts + DNC compliance, (c) maintain transparency around personalisation + recommendation + price discrimination (where used + watch the regulatory trajectory).

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.