NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
Consumer Privacy and Marketing

NRF Cybersecurity and Data Privacy Framework (National Retail Federation) NRFCS-4: Consumer Privacy Rights, Consent, Marketing, and Loyalty Data

Honor consumer privacy rights + consent + marketing + loyalty data obligations per applicable jurisdiction privacy law + sectoral marketing law. Privacy rights must (a) honor data subject access + deletion + correction + portability + opt-out of sale or sharing + opt-out of targeted advertising + limit use of sensitive personal information + non-discrimination per CCPA + CPRA + similar state laws, (b) provide privacy notice at collection with content per applicable law, (c) honor Global Privacy Control signal + Universal Opt-Out Mechanism where applicable, (d) age-gate children data per COPPA + state child privacy laws + sensitive flag transgender/non-binary data per state-specific provisions. Consent must (a) obtain opt-in consent where required (sensitive data + marketing email/SMS per CAN-SPAM/TCPA + cross-border transfers per GDPR + EU consumer products per ePrivacy), (b) distinguish opt-in vs opt-out per data type + per jurisdiction + per processing purpose, (c) maintain consent receipts + revocation processes + audit trail. Marketing and loyalty data must (a) bind loyalty data uses to disclosed purposes + obtain explicit consent for novel uses (third-party sharing + behavioral advertising + cross-context advertising), (b) implement marketing preference centers + suppression lists + CAN-SPAM unsubscribe + TCPA prior express written consent for autodialed/prerecorded calls + texts + DNC compliance, (c) maintain transparency around personalisation + recommendation + price discrimination (where used + watch the regulatory trajectory).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 28 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 502 Interoperability with Assistive Technology
  • 707 Real-Time Text Functionality
  • CH-FADP-09 Notification of data files to the FDPIC
  • FADP-13 Right to Data Portability (Article 28)

APPI · 1 control

  • APPI-A27 Restriction on Provision to Third Parties
  • DS-2 Ensure software supply chain security

Bahrain PDPL · 1 control

  • BB-DPA-14 Section 15 - Right to Data Portability
  • DIQ-1 Data Integration and Interoperability
  • UAE-PDPL-Art.8 Records of processing activities (UAE PDPL Article 8)

GDPR · 1 control

  • ISO8000-MDG-01 Master Data Quality
  • LV-PDPL-Data-Subject-Rights-Access-Correction-Erasure-Restriction-Portability-Objection-Sec18-Sec38 Latvia PDPL Data Subject Rights + Access + Correction + Erasure + Portability + Section 18 + 38
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NORWAY-2 Data Subject Rights and Automated Decision-Making
  • AUPRV-5 APP 12-13 Access and Correction of Personal Information
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • IM8-DAT.3 Data Sharing and Transfer

South Korea PIPA · 1 control

  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37

Turkey KVKK · 1 control

  • TURKEYKVKK-1 VERBIS Registration and Lawful Basis
  • CPSC-STD.4 Interoperability Safety
  • VERMONTAICDA-1 AI System Inventory and Risk Assessment

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 28 it maps to, and the evidence behind each claim, over MCP and REST.