MarketplacePrivacyNIST Privacy Framework v 1.0
PrivacyFramework

NIST Privacy Framework v 1.0

NIST Privacy Framework: A Tool for Improving Privacy Through Enterprise Risk Management

The NIST Privacy Framework Version 1.0 is a voluntary framework that helps organizations integrate privacy risk management into enterprise risk management by providing a structured approach for managing privacy risks, protecting personal data, and improving privacy governance.

Overview

The NIST Privacy Framework: A Tool for Improving Privacy Through Enterprise Risk Management, Version 1.0 is a voluntary privacy risk management framework developed by the National Institute of Standards and Technology (NIST) to help organizations identify, assess, manage, and communicate privacy risks arising from the processing of personal data. Published in January 2020, the framework provides a flexible and scalable approach to integrating privacy into enterprise risk management and organizational decision-making. It is structured around three components: the Core, which outlines privacy protection activities and outcomes; Profiles, which help organizations align privacy activities with business objectives and risk tolerance; and Implementation Tiers, which support the assessment of privacy risk management maturity. Designed to be used alongside the NIST Cybersecurity Framework, Version 1.0 helps organizations strengthen privacy governance, support regulatory compliance efforts, build customer trust, and manage the privacy impacts of products, services, and data processing activities.

Related in Privacy

PrivacyLaw

Croatia - Personal Data Protection Act

The Act governs the implementation of the EU General Data Protection Regulation (GDPR) in Croatia. It outlines specific roles such as the responsibilities of the supervisory authority, the Croatian Data Protection Agency (AZOP), and sets additional national measures related to GDPR compliance.

Government of Croatia β€’ Croatia

View details
PrivacyLaw

Maine Notice of Risk to Personal Data β€” Title 10, Chapter 210-B: Notice of Risk to Personal Data

Maine's Title 10, Chapter 210-B establishes regulations around personal data protection and security breach notifications. It includes provisions on prohibited use of personal data, mandatory breach notification, enforcement mechanisms, and rules for reporting identity theft.

State of Maine β€’ Maine, USA

View details
PrivacyLaw

France Act no. 78-17 of 6 January 1978 β€” Act no. 78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties

This French law governs the protection of personal data and the rights of individuals in relation to data processing. It sets principles for the use of information technology to ensure it serves citizens without violating human rights, privacy, or individual liberties.

Government of France β€’ France

View details
PrivacyLaw

Law No.59 β€” Vietnam - Law on Protection of Consumers' Rights

The Vietnam Law on Protection of Consumers' Rights is a consumer protection framework that establishes consumer rights, business obligations, consumer information protection requirements, and mechanisms for resolving disputes between consumers and traders.

Government of Vietnam β€’ Vietnam β€’ vLaw No.59/2010/QH12

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks β€” automatically.

Book your strategy call