The NIST Privacy Framework is a voluntary tool for managing privacy risks to individuals from data processing. Version 1.0 has five Functions: Identify-P, Govern-P, Control-P, Communicate-P and Protect-P. See the NIST Privacy Framework guidance.
Use in a programme
Define processing activities, affected people and responsibilities. Use the Core, Profiles and Tiers to understand the current programme, identify desired outcomes and prioritise work.
Privacy risk can arise from legitimate data processing as well as a security incident. Review impacts on individuals alongside security and compliance concerns; technical protection alone does not answer every privacy question.
Use in CSFaaS
The reviewed library offers NIST PF 1.0 in English and Spanish. Check the exact edition and keep it with the assessment record.
NIST's Privacy Framework 1.1 project page identifies the update and its public-draft material. Distinguish that work from the 1.0 edition currently named in the reviewed catalogue.
Link relevant policies, assign owners and preserve the processing context and evidence behind each assessment. An internal framework result does not establish compliance with every privacy law.