Skip to main content
PRI

Data Privacy

102 controls

Execute risk-based and legally defensible data privacy practices that conform with applicable statutory, regulatory and contractual obligations to protect sensitive Personal Data (sPD) throughout its lifecycle.

SCF # Control Name Weight NIST CSF Frameworks
PRI-01 Data Privacy Policy 10 — Critical Govern 2
PRI-02 Data Privacy Program 10 — Critical Govern 60
PRI-03 Data Privacy Accountability Structure 8 — High Govern 15
PRI-03.1 Chief Privacy Officer (CPO) 3 — Low Identify 27
PRI-03.2 Data Protection Officer (DPO) 7 — High Identify 27
PRI-03.3 Personal Data Process Manager (PDPM) 5 — Medium Protect 2
PRI-03.4 Data Fiduciary 7 — High Protect 2
PRI-04 Privacy-Aware Design 7 — High Protect 2
PRI-05 Documenting Data Processing Activities 8 — High Identify 38
PRI-05.1 Personal Data (PD) Lineage 5 — Medium Identify 8
PRI-06 Personal Data (PD) Categories 5 — Medium Identify 22
PRI-07 Inventory of Personal Data (PD) 8 — High Identify 22
PRI-07.1 Personal Data (PD) Inventory Automation Support 1 — Low Identify 7
PRI-08 Updating Personal Data (PD) Process 9 — Critical Identify 5
PRI-08.1 Updating & Correcting Personal Data (PD) 6 — Medium Protect 17
PRI-08.2 Flaw Remediation with Personal Data (PD) 8 — High Identify 1
PRI-09 Reasonable Data Privacy Practices 9 — Critical Protect 66
PRI-10 Security of Personal Data (PD) 7 — High Protect 74
PRI-11 Personal Data (PD) Control Testing, Training & Monitoring 8 — High Identify 19
PRI-12 Authority To Collect, Process, Store & Share Personal Data (PD) 7 — High Identify 42
PRI-13 Product or Service Delivery Restrictions 7 — High Identify 15
PRI-14 Data Privacy Requirements for Contractors & Service Providers 10 — Critical Identify 56
PRI-15 Binding Corporate Rules (BCR) 5 — Medium Identify 29
PRI-16 Information Sharing With Third Parties 9 — Critical Identify 46
PRI-17 Limiting Personal Data (PD) Disclosures 7 — High Protect 11
PRI-17.1 Accounting of Disclosures 8 — High Identify 27
PRI-18 Notification of Disclosure Requests To Data Subject 5 — Medium Identify 6
PRI-18.1 Disclosure Request Rejections 5 — Medium Identify 17
PRI-18.2 Justification To Reject Disclosure Requests 5 — Medium Identify 16
PRI-19 Financial Incentives For Personal Data (PD) 3 — Low Protect 2
PRI-19.1 Notice of Financial Incentive 2 — Low Identify 3
PRI-20 Dissemination of Data Privacy Program Information 5 — Medium Identify 28
PRI-20.1 Privacy Act Statements 2 — Low Identify 8
PRI-20.2 Privacy Act Exemptions 1 — Low Identify 4
PRI-20.3 System of Records Notice (SORN) 1 — Low Identify 6
PRI-20.4 System of Records Notice (SORN) Review Process 1 — Low Identify 4
PRI-20.5 Computer Matching Agreements (CMA) 1 — Low Identify 9
PRI-21 Data Privacy Notice 7 — High Identify 78
PRI-21.1 Privacy Notice Formatting 4 — Medium Protect 2
PRI-21.2 Conspicuous Link To Data Privacy Notice 4 — Medium Protect 4
PRI-21.3 Alternative Means To Deliver Privacy Notice 4 — Medium Protect 2
PRI-21.4 Notice of Right To Limit 4 — Medium Protect 3
PRI-21.5 Real-Time or Layered Notice 2 — Low Identify 3
PRI-22 Purpose Specification 7 — High Identify 38
PRI-22.1 Purpose Compatibility 4 — Medium Protect 3
PRI-23 Choice Architecture 4 — Medium Protect 2
PRI-23.1 Symmetry In Choice 4 — Medium Protect 1
PRI-23.2 Choice Architecture Testing 4 — Medium Protect 1
PRI-24 Data Subject Consent 7 — High Identify 62
PRI-24.1 Active Participation For Consent By Data Subjects 3 — Low Protect 13
PRI-24.2 Tailored Consent 1 — Low Identify 12
PRI-24.3 Revoke Consent 3 — Low Respond 31
PRI-24.4 Just-In-Time Notice & Updated Consent 1 — Low Identify 15
PRI-24.5 Prohibition of Selling, Processing and/or Sharing Personal Data (PD) 5 — Medium Identify 17
PRI-25 Cookie Management 5 — Medium Identify 1
PRI-26 Data Subject Right To Opt-Out 6 — Medium Protect 7
PRI-26.1 Opt-Out Links 6 — Medium Protect 3
PRI-26.2 Alternative Opt-Out Link 6 — Medium Protect 2
PRI-26.3 Global Privacy Control (GPC) 5 — Medium Protect 5
PRI-27 Data Subject Opt-In Consent 4 — Medium Protect 9
PRI-27.1 Parent or Guardian Opt-In Consent For Minors 6 — Medium Protect 11
PRI-28 Authorized Agent 6 — Medium Protect 20
PRI-29 Usage Restrictions of Personal Data (PD) 8 — High Identify 79
PRI-29.1 Continued Use of Personal Data (PD) 5 — Medium Protect 15
PRI-29.2 Cease Processing, Storing and/or Sharing Personal Data (PD) 6 — Medium Protect 8
PRI-29.3 Internal Use of Personal Data (PD) For Testing, Training and Research 8 — High Identify 32
PRI-30 Personal Data (PD) Retention & Disposal 8 — High Identify 91
PRI-30.1 Personal Data (PD) Formats 4 — Medium Protect 1
PRI-30.2 Temporary Files Containing Personal Data (PD) 5 — Medium Protect 1
PRI-31 Personal Data (PD) Collection Methods 3 — Low Protect 4
PRI-31.1 Restrict Collection, Processing & Sharing To Identified Purpose 7 — High Identify 41
PRI-32 Primary Source Collection For Personal Data (PD) 7 — High Identify 10
PRI-33 Identifiable Image Collection 7 — High Identify 0
PRI-34 Acquired Personal Data (PD) 6 — Medium Identify 1
PRI-34.1 Data Brokers 7 — High Protect 1
PRI-35 Personal Data (PD) Accuracy & Integrity 5 — Medium Identify 44
PRI-35.1 Validate Collected Personal Data (PD) 1 — Low Identify 4
PRI-35.2 Re-Validate Collected Personal Data (PD) 1 — Low Identify 2
PRI-36 Automated Decision-Making Technology (ADMT) 1 — Low Identify 11
PRI-36.1 Automated Decision-Making Technology (ADMT) For Data Subject Actions 6 — Medium Protect 14
PRI-36.2 Automated Decision-Making Technology (ADMT) Use Notification 6 — Medium Protect 3
PRI-36.3 Automated Decision-Making Technology (ADMT) Opt-Out Consent 6 — Medium Protect 7
PRI-36.4 Automated Decision-Making Technology (ADMT) Transparency 6 — Medium Protect 7
PRI-37 Data Subject Communications 6 — Medium Protect 22
PRI-37.1 Communicating Processing Changes 5 — Medium Protect 4
PRI-37.2 Data Subject Communications Documentation 5 — Medium Protect 6
PRI-37.3 Data Subject Communications Metrics 3 — Low Protect 1
PRI-37.4 Data Subject Communications Disclosure 3 — Low Protect 1
PRI-38 Data Subject Authentication 6 — Medium Protect 15
PRI-39 Data Subject Rights Management 5 — Medium Respond 59
PRI-39.1 Data Subject Empowerment 6 — Medium Identify 66
PRI-39.2 Enabling Data Subjects To Update Personal Data (PD) 4 — Medium Protect 3
PRI-39.3 Correcting Inaccurate Personal Data (PD) 5 — Medium Respond 42
PRI-39.4 Notice of Correction or Processing Change 4 — Medium Respond 18
PRI-39.5 Appeal Adverse Decision 4 — Medium Respond 23
PRI-40 Right to Erasure 5 — Medium Respond 25
PRI-41 Data Portability 3 — Low Identify 19
PRI-41.1 Personal Data (PD) Exports 5 — Medium Identify 21
PRI-42 Obligation To Inform Third-Parties 5 — Medium Identify 15
PRI-43 Joint Processing of Personal Data (PD) 5 — Medium Identify 14
PRI-44 Data Controller Communications 7 — High Govern 8
PRI-45 Register As A Data Controller and/or Data Processor 3 — Low Identify 10

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.