No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
    • Upcoming
    • On-Demand
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

4 Key Values of the New NIST Privacy Framework

How the Tool Can Help Companies “Do Privacy Right”

by Dov Goldman
March 2, 2020
in Data Privacy, Featured
brain tangle

The National Institute of Standards and Technology recently released the first version of its privacy framework. Panorays’ Dov Goldman discusses its benefit to organizations in terms of managing and mitigating privacy risk.

The world is rapidly turning into a tangled web of data privacy regulations. First, the General Data Protection Regulation (GDPR) shook up businesses with EU resident customers by setting high expectations for consumer data privacy, as well as large penalties for companies that didn’t comply. That groundbreaking regulation was followed by a host of U.S. state privacy laws, including the California Consumer Privacy Act (CCPA), the Nevada Privacy Law and the New York SHIELD Act. Internationally, over 80 countries and independent territories have now adopted some form of data privacy laws, and even more far-reaching privacy legislation is slated to be passed this year.

While this new focus on data privacy is certainly beneficial to consumers, it introduces unprecedented challenges for organizations, which often must comply with multiple regulations that may overlap in some ways and may seem contradictory in others. The solution is to educate the organization on the importance and fundamentals of data privacy, which will result in implementing a holistic data privacy program. It’s much easier to demonstrate compliance when privacy is “baked in” to the DNA of an organization and implemented by design in its processes and systems, rather than imposed by multiple and often inconsistent regulations.

How can this be accomplished? Enter the new National Institute of Standards and Technology (NIST) Privacy Framework, which provides the building blocks organizations need to reach those goals. The framework aims to help organizations “do privacy right,” regardless of which regulations they are subject to. Here are some of the NIST Privacy Framework’s key values:

1. It establishes overall best practices for privacy.

The NIST Privacy Framework helps companies internalize data privacy as a core element of business culture. A firm following these guidelines will develop and maintain data privacy policies specific to its business, and it will educate the entire company and its third parties (suppliers, partners, etc.) about them. NIST Privacy Framework helps a firm implement the tools to enforce its privacy policies.

Before creating privacy policies, the firm must understand the data it holds, and how that data is collected, processed and eventually deleted. NIST directs us to start this by mapping out all of the company’s data systems — including those operated by vendors and partners — and assessing them from the perspective of the privacy of the individuals whose data they contain and process, as well as the risks these efforts pose to the business. This isn’t a one-time event. It’s actually a continuous process, as management must understand the privacy risk picture at all times. With an inventory and mapping in hand, the company can build privacy policies based on the NIST Privacy Framework guidelines.

Next, the company must translate privacy policies into working safeguards, both technical and procedural, to actually protect the privacy of data subjects and to ensure the rights to see, correct, transfer, delete and restrict the processing of that data.

2. It creates a common, business-friendly language for discussing privacy processes.

Complying with regulations like GDPR, CCPA and the New York SHIELD Act may be a compelling driver for investing in data privacy, but it’s unlikely to inspire an organization to make privacy a core part of its strategy.

NIST addresses this issue by articulating the core principles of data privacy in business-friendly language. It presents privacy as a series of high-level business processes, with very specific, well-defined goals. Businesspeople will find the NIST Privacy Framework to be a quick, easily digestible read, especially when compared to the 100 pages of GDPR or the dense legal terms of CCPA.

3. It presents the gold standard benchmark for measuring a company’s privacy efforts.

The NIST Privacy Framework outlines a process that will ultimately lead to what is known as “privacy by design,” meaning that privacy will be taken into account throughout the systems engineering and maintenance processes.

When a company implements privacy by design, it considers the rights and interests of the people whose data is processed before creating a new data system or updating an existing one. Every step in a data process must be cognitive and respectful of the consumer or data subject. Organizations must address questions such as:

  • Why should someone give me personal data?
  • How long do I have to keep the data to satisfy the implied or explicit contract with the individual?
  • What am I doing to ensure that I am scrupulously following all the terms of that agreement?

Companies adopting the NIST Privacy Framework will have tools to measure their systems against a robust yardstick of privacy as a fundamental consumer right.

4. It’s a foundation that will simplify compliance to all regulations.

Perhaps most significantly, the NIST Privacy Framework succeeds in introducing an approach to privacy that will ultimately streamline organizations’ compliance. Instead of struggling with the particulars of each regulation, organizations that adopt the framework’s overarching, comprehensive program for privacy by design will have the building blocks in place to easily comply with all privacy requirements.

The company that learns and implements the NIST Privacy Framework will be prepared with the language needed to communicate with stakeholders, constituents and third-party partners about privacy, as well as the best practices to safeguard consumer privacy and engender trust. With this foundational work in place, demonstrating compliance with any one privacy regulation will simply be a matter of mapping existing efforts and documentation to the particular regulation, rather than starting from scratch each time. This is a forward-thinking and welcome way to untangle the current privacy regulations web organizations currently find themselves in.


Tags: California Consumer Privacy Act (CCPA)GDPR
Previous Post

The Compliance and Operational Risks in a Total Compensation Approach

Next Post

Refinitiv Acquires Scivantage Creating Next-Generation Digital Wealth Management Solutions

Dov Goldman

Dov Goldman

Dov Goldman is the Director of Risk & Compliance at Panorays. He has years of experience in the third-party risk and compliance field, as well as a long history as a serial entrepreneur, software and network engineer. Dov focuses on the evolving best practices and industry standards in third-party management and regulatory compliance. Previously, Dov was VP of Innovation at Opus, Director of Product Marketing at Navigant and Founder and CEO of Cognet Corp and Dynalog Technologies.

Related Posts

todd snyder runway show scarf

Lessons Learned: Todd Snyder CCPA Enforcement Action

by Richart Ruddie
May 29, 2025

Third-party risk, overcollection of data and lax training all cited by California data privacy enforcer

federal trade commission building

[Q&A] Big Tech & Free Speech Under the Microscope: FTC’s New Direction

by FTI Consulting
April 28, 2025

What compliance teams need to know about the changing approach to consumer protection and data privacy

data governance concept

The US Still Lacks Its Own GDPR, But That Doesn’t Mean Data Privacy Enforcement Isn’t Happening

by Brian McGinnis and Maddie San Jose
April 16, 2025

Despite the absence of comprehensive federal privacy legislation, American businesses face mounting regulatory pressure from multiple directions. Brian McGinnis and...

origami tiger

Paper Tigers Won’t Protect You: The Reality of Effective NIS2 Compliance

by Hans Kayaert
March 24, 2025

Why Belgium's early adoption model could prevent another round of ‘compliance theater’ across Europe

Next Post
refinitiv logo

Refinitiv Acquires Scivantage Creating Next-Generation Digital Wealth Management Solutions

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
    • Upcoming
    • On-Demand
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights