NIST Privacy Framework
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Communicate-P
Apply Communicate-P function including: Communication Policies (CM.PO-P) covering policies for privacy communications + records of disclosures + privacy notice strategy; and Data Processing Awareness (CM.AW-P) covering individual privacy notice + mechanisms for individual access + correction + deletion + portability + opt-out + complaint + appeals + redress + data subject rights aligned with GDPR + CCPA + 24 US state privacy laws + ongoing communications during incidents and breaches. Apply transparency principles per OECD + FIPPs + APEC CBPR.
- Privacy notice
- Records of disclosures
- DSAR/individual rights workflow
- Complaint procedures
- Annual notice review
- No privacy notice
- No DSAR workflow
- No complaint process
- Stale notice
Control-P
Apply Control-P function including: Control Policies (CT.PO-P) covering policies + plans + processes for privacy risk control; Data Management (CT.DM-P) covering data quality + retention + destruction + access + transmission + alteration + deletion + correction + portability + opt-out + redress; and Disassociated Processing (CT.DP-P) covering data minimisation + anonymisation + de-identification + pseudonymisation + differential privacy + privacy-enhancing technologies (PETs) including homomorphic encryption + multi-party computation + zero-knowledge proofs.
- Control policy statement
- Data retention schedule
- Data minimisation evidence
- De-identification techniques
- PETs deployment
- Differential privacy parameters
- No control policy
- Excessive retention
- No minimisation
- No PETs
Govern-P
Apply Govern-P function including: Governance Policies (GV.PO-P) covering policies + responsibilities + roles + legal/regulatory requirements + privacy risk in governance; Risk Management Strategy (GV.RM-P) covering risk tolerance + ecosystem-informed risk; Awareness and Training (GV.AT-P) covering workforce training + role-based + privileged user + third-party awareness; and Monitoring and Review (GV.MT-P) covering programme monitoring + effectiveness review + privacy values incorporated + workforce informed + processes improvements. Integrate with NIST CSF 2.0 GOVERN function.
- Privacy policies
- Risk management strategy
- Risk tolerance statement
- Annual training records
- Monitoring dashboards
- Programme review
- Outdated policies
- No risk tolerance
- Missing training
- No monitoring
Identify-P
Apply NIST Privacy Framework v1.0 (January 2020) Identify-P function categories: Business Environment (ID.BE-P) covering organizational mission + roles + responsibilities + stakeholders; Data Processing Ecosystem (ID.DE-P) covering ecosystem parties + interoperability + privacy measures in contracts; Inventory and Mapping (ID.IM-P) covering data actions inventory + purposes + data elements + processing environments + data flow mapping; and Risk Assessment (ID.RA-P) covering problematic data actions + likelihood and impact + risk responses. Cross-walk with NIST CSF 2.0 GOVERN and IDENTIFY functions. Version 1.1 in development 2024-2025.
- Organizational mission statement
- Data processing ecosystem map
- Data action inventory
- Data flow mapping
- Risk assessment register
- Problematic data action analysis
- Annual review
- No business context
- Missing ecosystem mapping
- Stale inventory
- No risk assessment
Protect-P Access
Apply Protect-P Identity Management Authentication and Access Control (PR.AC-P) including: identity proofing + lifecycle management + credentials issued + revoked + physical access managed + remote access managed + access permissions managed (least privilege + separation of duties) + network integrity protected + individuals and devices proofed and authenticated to manage privacy risks. Implement MFA + zero trust architecture + RBAC + ABAC + PAM + JIT access aligned with NIST SP 800-63 + 800-207.
- Identity proofing procedures
- MFA deployment
- RBAC matrices
- Zero trust architecture
- Access reviews
- Annual evaluation
- No identity proofing
- Weak MFA
- Stale RBAC
- No zero trust
Protect-P Data Security
Apply Protect-P Data Security (PR.DS-P) including: data-at-rest protected + data-in-transit protected + systems managed during removal/transfer/disposition + adequate capacity to ensure availability + data leak protections + integrity verification for software/firmware/information + development/test separated from production + hardware integrity verified. Implement encryption (AES-256 + TLS 1.3 + PQC migration per FIPS 203/204/205) + DLP + secure software/hardware supply chain.
- Encryption inventory
- DLP deployment
- Integrity verification
- Dev/test segregation
- Capacity planning
- Annual evaluation
- Weak encryption
- No DLP
- No integrity verification
- Mixed dev/prod
Protect-P Maintenance and Technology
Apply Maintenance (PR.MA-P) including system maintenance + repair with approved tools + remote maintenance with prevention of unauthorised access. Apply Protective Technology (PR.PT-P) including: audit/log records determined + maintained + reviewed + removable media protected + use restricted per policy + least functionality incorporated + communications and control networks protected + resilience mechanisms implemented (high availability + DR + business continuity).
- Maintenance procedures
- Approved tool inventory
- SIEM with retention
- Removable media policy
- Least functionality baselines
- DR/BCP test reports
- Unauthorised maintenance
- No SIEM
- No removable media policy
- No DR testing
Protect-P Processes
Apply Protect-P Information Protection Processes and Procedures (PR.PO-P) including: baseline configuration management + configuration change control + backups conducted and tested + physical operating environment policy + protection processes improved + effectiveness of protection technologies shared + response and recovery plans established + response and recovery plans tested + privacy in HR practices + vulnerability management plan. Integrate with NIST CSF Protective Processes + RESPOND function.
- Configuration baselines
- Backup test records
- Response/recovery plans
- Annual tabletop exercise
- Vulnerability management programme
- HR privacy practices
- No baselines
- No backup testing
- No response plan
- No vulnerability management
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST Privacy Framework framework page.