HomeFrameworksAI Governance & Privacy FrameworksNIST Privacy Framework

Framework  AI Governance & Privacy Frameworks

NIST Privacy Framework

The NIST Privacy Framework is a voluntary US tool for managing the privacy risks that arise from how an organization processes personal data.

Version 1.0 was published in January 2020 and is built like the NIST Cybersecurity Framework: a Core of functions (Identify-P, Govern-P, Control-P, Communicate-P, and Protect-P), Profiles that describe current and target states, and Implementation Tiers.

NIST released an initial public draft of version 1.1 on April 14, 2025 to line the framework up with CSF 2.0 and the AI RMF, with a section on AI privacy risks; final publication was signaled for 2026 (verify current status on the NIST page).

The framework itself imposes nothing, but organizations that adopt it end up producing a data inventory and data flow maps, a privacy governance policy with assigned roles, privacy risk assessments, a record of the controls chosen to manage each risk, notices and consent mechanisms, and processes for handling individual requests and incidents.

It is commonly used to structure compliance with US state privacy laws, GDPR, and sector rules, and to support ISO/IEC 27701 work.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedPrivacy policy v3by name, on record
Govern-P Handledwith AllyMatter
Frame It the Modern WayEvery privacy policy, acknowledged by everyone who processes
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every processor on record
Who read which version, and when
03
Show the regulator the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Voluntary. Any organization processing personal data. It is referenced by some US state laws and regulators as an acceptable structure for a privacy program but is not mandated.

What the assessor asks to see

Data inventory and processing maps; privacy governance policy and role assignments; privacy risk assessment method and results; control selections tied to risks; privacy notices and consent records; data subject request handling logs; vendor and processor agreements; incident and breach handling records; training records; management review of the target Profile.

Where the requirement sits: Privacy Framework 1.0 Identify-P / Govern-P / Control-P / Communicate-P / Protect-P

Version 1.1

The initial public draft of Privacy Framework 1.1 was issued April 14, 2025 with comments accepted until June 13, 2025. It keeps the 1.0 structure, realigns with Cybersecurity Framework 2.0, and adds AI-related privacy content. Check the NIST Privacy Framework page for whether the final version has been published.

What AllyMatter does here

Organise privacy policies against the framework.

AllyMatter publishes this site.

Assessors

Who assesses NIST Privacy Framework

None. No certification exists. Organizations self-assess or have privacy controls examined as part of another engagement such as a SOC 2 privacy criteria report or ISO/IEC 27701 audit.

No firm has claimed a NIST Privacy Framework assessor listing yet. Claim yours →

Consultants

Who helps with NIST Privacy Framework

Privacy consultancies, law firms, and GRC platform vendors offer mapping and program-build services. Typical engagement is a gap assessment against the Core, a data inventory exercise, and drafting of the governance policy and risk register, followed by a target Profile and roadmap.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

TevoraIrvine, CA, USANot yet verified
What they do
Enterprise multi-framework
Who they help
Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Control and FunctionDenver, CO, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Cybervantage 360Navi Mumbai, IndiaNot yet verified
What they do
Multi-framework consultancy
Who they help
Cybervantage 360 is a multi-framework consultancy based in Navi Mumbai, India. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
XpertDPOUK/IrelandNot yet verified
What they do
Privacy governance + ISO 27001
Who they help
XpertDPO is a privacy governance + ISO 27001 based in UK/Ireland. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Related reading

  1. A view from DC: an updated NIST Privacy FrameworkPrivacy profession's read on the 1.1 revision and why realignment with the Cybersecurity Framework matters for programme design.IAPP
  2. NIST updates Privacy Framework with AI and governance revisionsExplains the new AI and privacy risk section and the reshaped Govern function in plain terms.Dark Reading
  3. NIST releases updated Privacy FrameworkCounsel's summary of what moved in the Core and how the framework maps onto existing privacy obligations.Maynard Nexsen

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for NIST Privacy Framework

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of NIST Privacy Framework in AllyMatter

Approve the policies NIST Privacy Framework asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.