Back to glossary

Privacy

Mahremiyet

D5

Privacy concerns people’s interests and rights in relation to the processing and protection of information about them.

Review status: 2027-02-24

Technical explanation

Privacy risk management considers how data processing can create problematic impacts for individuals and how an organization governs, controls, communicates about, and protects that processing.

Conceptual boundaries

Privacy is not identical to confidentiality, security, anonymity, consent, or compliance with a particular legal regime.

Provider-neutral example

Before using customer messages to evaluate an AI assistant, a team can identify the processing purpose, limit access, document retention choices, and communicate relevant handling information.

Limitations

A privacy framework supports risk management but does not itself determine legal compliance in every jurisdiction.

Related concepts

Atomic claims and evidence

  1. 1.1NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management, Version 1.0
    Source
    NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management, Version 1.0
    Source role
    Authoritative source
    Exact locator
    Executive Summary, printed pp. i-ii, and Section 2.1, printed pp. 6-7
    Supported claim
    NIST’s Privacy Framework is designed to help organizations identify and manage privacy risk arising from data processing through Identify-P, Govern-P, Control-P, Communicate-P, and Protect-P functions.
    Last verification
    Review due
    Scope limitation
    NIST states that the framework does not have the force of law and is not a jurisdiction-specific compliance determination.
    1.2OECD AI Principles
    Source
    OECD AI Principles
    Source role
    Authoritative source
    Exact locator
    Human rights and democratic values, including fairness and privacy
    Supported claim
    NIST’s Privacy Framework is designed to help organizations identify and manage privacy risk arising from data processing through Identify-P, Govern-P, Control-P, Communicate-P, and Protect-P functions.
    Last verification
    Review due
    Scope limitation
    NIST states that the framework does not have the force of law and is not a jurisdiction-specific compliance determination.
  2. 2.1NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management, Version 1.0
    Source
    NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management, Version 1.0
    Source role
    Authoritative source
    Exact locator
    Section 1.2.1, printed pp. 3-4, and Section 2.1, printed pp. 6-7
    Supported claim
    NIST distinguishes management of privacy risk from cybersecurity-related privacy events, for which Protect-P is specifically focused.
    Last verification
    Review due
    Scope limitation
    This distinction does not make privacy and security unrelated; it avoids treating them as identical.
    2.2OECD AI Principles
    Source
    OECD AI Principles
    Source role
    Authoritative source
    Exact locator
    Human rights and democratic values, including fairness and privacy; Robustness, security and safety
    Supported claim
    NIST distinguishes management of privacy risk from cybersecurity-related privacy events, for which Protect-P is specifically focused.
    Last verification
    Review due
    Scope limitation
    This distinction does not make privacy and security unrelated; it avoids treating them as identical.