NIST Privacy Framework 1.0
The NIST Privacy Framework (Version 1.0, 2020) is a voluntary tool for improving privacy through enterprise risk management. Designed to complement the NIST Cybersecurity Framework. Five core functions: Identify-P (develop understanding of privacy risks), Govern-P (develop governance structure), Control-P (manage data processing), Communicate-P (promote understanding of data processing), and Protect-P (develop safeguards for data processing). Applicable to all organisations regardless of size or sector. Provides a common vocabulary for privacy risk management across legal, business, and technical domains.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Communicate-P: Data Processing Awareness
Function: Communicate-P. Categories CM.PO-P, CM.AW-P. Develop and implement appropriate activities to enable organizations and individuals to have a reliable understanding of data processing practices.
| Code | Title |
|---|---|
| PF-CM.AW-P1 | Mechanisms for Awareness Exist |
| PF-CM.AW-P2 | Data Processing Purposes Communicated |
| PF-CM.AW-P3 | System Changes Communicated |
| PF-CM.AW-P4 | Data Retention Policies Communicated |
| PF-CM.AW-P5 | Data Corrections Communicated |
| PF-CM.AW-P6 | Data Provenance Communicated |
| PF-CM.AW-P7 | Impacted Individuals Informed |
| PF-CM.AW-P8 | Individuals Informed of Processing Changes |
| PF-CM.PO-P1 | Communication Policies Established |
| PF-CM.PO-P2 | Privacy Notice Framework |
Control-P: Data Processing Management
Function: Control-P. Categories CT.PO-P, CT.DM-P, CT.DP-P. Develop and implement appropriate activities to enable organizations or individuals to manage data with sufficient granularity.
| Code | Title |
|---|---|
| PF-CT.DM-P1 | Data Elements Managed |
| PF-CT.DM-P10 | Data Accuracy Maintained |
| PF-CT.DM-P2 | Data Managed for Transfer/Disclosure |
| PF-CT.DM-P3 | Data Managed for Correction/Deletion |
| PF-CT.DM-P4 | Data De-identification Managed |
| PF-CT.DM-P5 | Consent Mechanisms Managed |
| PF-CT.DM-P6 | Data Maintained Accurately |
| PF-CT.DM-P7 | Mechanisms for Transmitting Consent |
| PF-CT.DM-P8 | Audit/Log Records Maintained |
| PF-CT.DM-P9 | Technical Measures for Policy Compliance |
| PF-CT.DP-P1 | Disaggregated Data Processed |
| PF-CT.DP-P2 | Reduce Identifiability |
| PF-CT.DP-P3 | Reduce Linkability |
| PF-CT.DP-P4 | Measures to Prevent Re-identification |
| PF-CT.DP-P5 | Attribute Values Generalized |
| PF-CT.PO-P1 | Data Processing Policies Established |
| PF-CT.PO-P2 | Data Processing Managed Consistently |
| PF-CT.PO-P3 | Processing Aligned with Policies |
| PF-CT.PO-P4 | Data Lifecycle Managed |
Govern-P: Governance and Risk Management
Function: Govern-P. Categories GV.PO-P, GV.RM-P, GV.AT-P, GV.MT-P. Develop and implement organizational governance structure to enable ongoing understanding of the organization's risk management priorities.
| Code | Title |
|---|---|
| PF-GV.AT-P1 | Workforce Privacy Training |
| PF-GV.AT-P2 | Senior Executives Understand Privacy Risks |
| PF-GV.AT-P3 | Privacy Personnel Understand Duties |
| PF-GV.AT-P4 | Third Parties Understand Obligations |
| PF-GV.MT-P1 | Privacy Risk Monitored and Reviewed |
| PF-GV.MT-P2 | Privacy Practices Reviewed |
| PF-GV.MT-P3 | Policies Aligned with Risk Strategy |
| PF-GV.MT-P4 | Policies Updated for Legal Changes |
| PF-GV.MT-P5 | Privacy Outcomes Independently Verified |
| PF-GV.MT-P6 | Accountability Established |
| PF-GV.MT-P7 | Compliance Assessment Processes |
| PF-GV.PO-P1 | Organizational Privacy Values |
| PF-GV.PO-P2 | Process for Privacy Risk Management |
| PF-GV.PO-P3 | Roles and Responsibilities Assigned |
| PF-GV.PO-P4 | Privacy in Governance and Risk |
| PF-GV.PO-P5 | Legal and Regulatory Awareness |
| PF-GV.PO-P6 | Governance and Risk Management Policies |
| PF-GV.RM-P1 | Risk Management Process Established |
| PF-GV.RM-P2 | Risk Tolerance Established |
| PF-GV.RM-P3 | Risk Determination for Data Processing |
Identify-P: Inventory and Mapping
Function: Identify-P. Categories ID.IM-P, ID.BE-P, ID.RA-P, ID.DE-P. Develop organizational understanding to manage privacy risk for individuals arising from data processing.
| Code | Title |
|---|---|
| PF-ID.BE-P1 | Organization Role in Data Ecosystem |
| PF-ID.BE-P2 | Data Processing Priorities |
| PF-ID.BE-P3 | System Dependencies Identified |
| PF-ID.DE-P1 | Data Processing Ecosystem Risks Identified |
| PF-ID.DE-P2 | Data Processing Ecosystem Parties Identified |
| PF-ID.DE-P3 | Data Processing Ecosystem Agreements |
| PF-ID.DE-P4 | Interoperability of Privacy Practices |
| PF-ID.DE-P5 | Performance Assessment of Ecosystem Parties |
| PF-ID.IM-P1 | Systems and Data Actions Inventoried |
| PF-ID.IM-P2 | Data Owners/Stewards Identified |
| PF-ID.IM-P3 | Data Categories Inventoried |
| PF-ID.IM-P4 | Data Actions Mapped |
| PF-ID.IM-P5 | Purpose Mapped |
| PF-ID.IM-P6 | Data Elements Mapped |
| PF-ID.IM-P7 | Environmental Context Mapped |
| PF-ID.IM-P8 | Data Processing Mapped to Legal Basis |
| PF-ID.RA-P1 | Contextual Factors Related to Systems |
| PF-ID.RA-P2 | Data Analytic Inputs Identified |
| PF-ID.RA-P3 | Potential Problems for Individuals Identified |
| PF-ID.RA-P4 | Problematic Data Actions Identified |
| PF-ID.RA-P5 | Likelihood and Impact Assessed |
Implementation and Use
Implementation guidance and profiles
| Code | Title |
|---|---|
| NIST-PF-IU-01 | Privacy Profiles |
| NIST-PF-IU-02 | CSF Alignment |
| NIST-PF-IU-03 | Stakeholder Engagement |
Privacy Core Functions
Five core privacy functions
| Code | Title |
|---|---|
| NIST-PF-PCF-01 | Identify-P and Govern-P |
| NIST-PF-PCF-02 | Control-P and Communicate-P |
| NIST-PF-PCF-03 | Protect-P |
Protect-P: Data Protection
Function: Protect-P. Categories PR.PO-P, PR.AC-P, PR.DS-P. Develop and implement appropriate data processing safeguards for cybersecurity-related privacy events.
| Code | Title |
|---|---|
| PF-PR.AC-P1 | Identity Management and Access Control |
| PF-PR.AC-P2 | Physical Access Managed |
| PF-PR.AC-P3 | Remote Access Managed |
| PF-PR.AC-P4 | Access Permissions Managed |
| PF-PR.AC-P5 | Network Integrity Protected |
| PF-PR.AC-P6 | Individuals Authenticated |
| PF-PR.DS-P1 | Data-at-Rest Protected |
| PF-PR.DS-P2 | Data-in-Transit Protected |
| PF-PR.DS-P3 | System Lifecycle Data Management |
| PF-PR.DS-P4 | Adequate Capacity Maintained |
| PF-PR.DS-P5 | Data Leakage Protections |
| PF-PR.DS-P6 | Integrity Checking Mechanisms |
| PF-PR.DS-P7 | Development and Testing Environments Separate |
| PF-PR.DS-P8 | Integrity of Hardware Verified |
| PF-PR.PO-P1 | Baseline Configuration Established |
| PF-PR.PO-P10 | Audit Log Policy Implemented |
| PF-PR.PO-P2 | Configuration Change Control |
| PF-PR.PO-P3 | Backups Maintained |
| PF-PR.PO-P4 | Record Retention Policy |
| PF-PR.PO-P5 | System Improvement Process |
| PF-PR.PO-P6 | Response and Recovery Plans Tested |
| PF-PR.PO-P7 | Response Plans Incorporate Lessons |
| PF-PR.PO-P8 | Response and Recovery Plans Managed |
| PF-PR.PO-P9 | Human Resource Controls |
Maps to 648 other frameworks
Frequently Asked Questions
What is NIST Privacy Framework 1.0?
NIST Privacy Framework 1.0 is a compliance framework from United States (NIST) with 7 domains and 100 controls. The NIST Privacy Framework (Version 1.0, 2020) is a voluntary tool for improving privacy through enterprise risk management. Designed to complement the NIST Cybersecurity Framework. Five core functions: Identify-P (develop understanding of privacy risks), Govern-P (develop governance structure), Control-P (manage data processing), Communicate-P (promote understanding of data processing), and Protect-P (develop safeguards for data processing). Applicable to all organisations regardless of size or sector. Provides a common vocabulary for privacy risk management across legal, business, and technical domains. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NIST Privacy Framework 1.0 have?
NIST Privacy Framework 1.0 has 100 controls organised across 7 domains. The largest domains are Protect-P: Data Protection (24 controls), Identify-P: Inventory and Mapping (21 controls), Govern-P: Governance and Risk Management (20 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NIST Privacy Framework 1.0 map to?
NIST Privacy Framework 1.0 maps to 648 other compliance frameworks. The top mapping partners are CSA CCM v4 (22% coverage), TISAX — Trusted Information Security Assessment Exchange (22% coverage), Oman National Cybersecurity Framework (20% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NIST Privacy Framework 1.0 compliance?
Start your NIST Privacy Framework 1.0 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST Privacy Framework 1.0 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 100 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required