NIST Privacy Framework Version 1.0
The NIST Privacy Framework Version 1.0 (January 2020) is a voluntary tool for improving privacy through enterprise risk management. Structured similarly to the NIST Cybersecurity Framework with Core, Profiles, and Implementation Tiers. The Core consists of five functions: Identify-P, Govern-P, Control-P, Communicate-P, and Protect-P. Designed to complement the NIST CSF — together they address the intersection of privacy and cybersecurity risk. Used by organisations of all sizes across sectors.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (10)
Communicate-P
| Code | Title |
|---|---|
| PF-CM-AW-P1 | Stakeholder Engagement and Feedback |
| PF-CM-PO-P1 | Transparency Through Notice |
Communicate-P (CM-P)
| Code | Title |
|---|---|
| CM.AW-P | Data Processing Awareness |
| CM.PO-P | Communication Policies, Processes, and Procedures |
Control-P
| Code | Title |
|---|---|
| PF-CT-DM-P1 | Data Minimization and Quality |
| PF-CT-DM-P2 | Individual Decision Mechanisms |
| PF-CT-PO-P1 | Purpose Specification and Use Limitation |
Control-P (CT-P)
| Code | Title |
|---|---|
| CT.DM-P | Data Processing Management |
| CT.DP-P | Disassociated Processing |
| CT.PO-P | Data Processing Policies, Processes, and Procedures |
Govern-P
| Code | Title |
|---|---|
| PF-GV-AT-P1 | Workforce Knowledge and Competency |
| PF-GV-MT-P1 | Continuous Improvement of Privacy Program |
| PF-GV-PO-P1 | Privacy Values and Principles |
| PF-GV-RM-P1 | Risk Tolerance and Appetite for Privacy |
Govern-P (GV-P)
| Code | Title |
|---|---|
| GV.AT-P | Awareness and Training |
| GV.MT-P | Monitoring and Review |
| GV.PO-P | Governance Policies, Processes, and Procedures |
| GV.RM-P | Risk Management Strategy |
Identify-P
| Code | Title |
|---|---|
| PF-ID-DE-P1 | Disassociability Considerations |
| PF-ID-IM-P1 | Data Processing Ecosystem Inventory |
| PF-ID-IM-P2 | Roles, Responsibilities, and Authorities |
| PF-ID-RA-P1 | Contextual Privacy Risk Identification |
Identify-P (ID-P)
| Code | Title |
|---|---|
| ID.BE-P | Business Environment |
| ID.DE-P | Data Processing Ecosystem Risk Management |
| ID.IM-P | Inventory and Mapping |
| ID.RA-P | Risk Assessment |
Protect-P
| Code | Title |
|---|---|
| PF-PR-AC-P1 | Authentication and Identity Proofing Risk |
| PF-PR-DS-P1 | Protection of Data in Use |
| PF-PR-IP-P1 | Information Protection Processes and Procedures |
| PF-PR-MA-P1 | Maintenance and Operational Hygiene |
| PF-PR-PO-P1 | Data Protection by Design and by Default |
| PF-PR-PT-P1 | Protective Technology Configuration |
Protect-P (PR-P)
| Code | Title |
|---|---|
| PR.AC-P | Identity Management, Authentication, and Access Control |
| PR.DS-P | Data Security |
| PR.MA-P | Maintenance |
| PR.PO-P | Data Protection Policies, Processes, and Procedures |
| PR.PT-P | Protective Technology |
Your Compliance Coverage
If you comply with NIST Privacy Framework Version 1.0, you already cover:
CSA CCM v4
24%
9 controls mapped
Compare →NIST Privacy Framework 1.0
24%
9 controls mapped
Compare →TISAX — Trusted Information Security Assessment Exchange
24%
9 controls mapped
Compare →+ 607 more: SOC for Cybersecurity — Cybersecurity Risk Management Examination (24%), NIS2 Directive (22%)
See all 610 mapped frameworks ↓Maps to 610 other frameworks
Frequently Asked Questions
What is NIST Privacy Framework Version 1.0?
NIST Privacy Framework Version 1.0 is a compliance framework from United States (NIST) with 10 domains and 37 controls. The NIST Privacy Framework Version 1.0 (January 2020) is a voluntary tool for improving privacy through enterprise risk management. Structured similarly to the NIST Cybersecurity Framework with Core, Profiles, and Implementation Tiers. The Core consists of five functions: Identify-P, Govern-P, Control-P, Communicate-P, and Protect-P. Designed to complement the NIST CSF — together they address the intersection of privacy and cybersecurity risk. Used by organisations of all sizes across sectors. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NIST Privacy Framework Version 1.0 have?
NIST Privacy Framework Version 1.0 has 37 controls organised across 10 domains. The largest domains are Protect-P (6 controls), Protect-P (PR-P) (5 controls), Govern-P (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NIST Privacy Framework Version 1.0 map to?
NIST Privacy Framework Version 1.0 maps to 610 other compliance frameworks. The top mapping partners are CSA CCM v4 (24% coverage), NIST Privacy Framework 1.0 (24% coverage), TISAX — Trusted Information Security Assessment Exchange (24% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NIST Privacy Framework Version 1.0 compliance?
Start your NIST Privacy Framework Version 1.0 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST Privacy Framework Version 1.0 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 37 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required