Privacy
Mahremiyet
D5
Privacy concerns people’s interests and rights in relation to the processing and protection of information about them.
Review status: 2027-02-24
Technical explanation
Privacy risk management considers how data processing can create problematic impacts for individuals and how an organization governs, controls, communicates about, and protects that processing.
Conceptual boundaries
Privacy is not identical to confidentiality, security, anonymity, consent, or compliance with a particular legal regime.
Provider-neutral example
Before using customer messages to evaluate an AI assistant, a team can identify the processing purpose, limit access, document retention choices, and communicate relevant handling information.
Limitations
A privacy framework supports risk management but does not itself determine legal compliance in every jurisdiction.
Related concepts
Atomic claims and evidence
1.1NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management, Version 1.0
- Source
- NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management, Version 1.0
- Source role
- Authoritative source
- Exact locator
- Executive Summary, printed pp. i-ii, and Section 2.1, printed pp. 6-7
- Supported claim
- NIST’s Privacy Framework is designed to help organizations identify and manage privacy risk arising from data processing through Identify-P, Govern-P, Control-P, Communicate-P, and Protect-P functions.
- Last verification
- Review due
- Scope limitation
- NIST states that the framework does not have the force of law and is not a jurisdiction-specific compliance determination.
1.2OECD AI Principles
- Source
- OECD AI Principles
- Source role
- Authoritative source
- Exact locator
- Human rights and democratic values, including fairness and privacy
- Supported claim
- NIST’s Privacy Framework is designed to help organizations identify and manage privacy risk arising from data processing through Identify-P, Govern-P, Control-P, Communicate-P, and Protect-P functions.
- Last verification
- Review due
- Scope limitation
- NIST states that the framework does not have the force of law and is not a jurisdiction-specific compliance determination.
2.1NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management, Version 1.0
- Source
- NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management, Version 1.0
- Source role
- Authoritative source
- Exact locator
- Section 1.2.1, printed pp. 3-4, and Section 2.1, printed pp. 6-7
- Supported claim
- NIST distinguishes management of privacy risk from cybersecurity-related privacy events, for which Protect-P is specifically focused.
- Last verification
- Review due
- Scope limitation
- This distinction does not make privacy and security unrelated; it avoids treating them as identical.
2.2OECD AI Principles
- Source
- OECD AI Principles
- Source role
- Authoritative source
- Exact locator
- Human rights and democratic values, including fairness and privacy; Robustness, security and safety
- Supported claim
- NIST distinguishes management of privacy risk from cybersecurity-related privacy events, for which Protect-P is specifically focused.
- Last verification
- Review due
- Scope limitation
- This distinction does not make privacy and security unrelated; it avoids treating them as identical.