Knowledge Hub
Privacy standards & frameworks
The international standards and recognised frameworks most relevant to privacy governance, assurance and AI. Curated to the essentials and growing — with links to the authoritative source for each.
| Reference | What it is | Source |
|---|---|---|
| ISO/IEC 27701:2025 | Privacy information management systems — requirements and guidance. Second edition, published 14 October 2025, and now a stand-alone management system standard: ISO's own guidance is that it can be used alone, where the 2019 first edition was an extension to ISO/IEC 27001 and 27002 and could not be certified independently. 64 pages. The 2019 edition is withdrawn. | iso.org |
| ISO/IEC 29100:2024 | Privacy framework — terminology and principles for protecting PII. Second edition, February 2024; the 2011 edition and its 2018 amendment are withdrawn. Published by ISO free of charge. | iso.org |
| NIST Privacy Framework | Voluntary US framework for managing privacy risk, structured to sit alongside the NIST CSF. Version 1.0 remains the current published version — a 1.1 initial public draft (CSWP 40) was issued in April 2025 and has not been finalised. | nist.gov |
| NIST SP 800-188 | De-Identifying Government Datasets: Techniques and Governance. Written with the US Census Bureau for US government agencies, but the governance model — disclosure review, re-identification studies, the Five Safes — travels. Final September 2023. | csrc.nist.gov |
| NIST SP 800-226 | Guidelines for evaluating differential privacy guarantees — a structured way to interrogate a supplier's differential-privacy claim. Final March 2025. | csrc.nist.gov |
| BS 10012 | British Standard for a personal information management system, aligned to UK GDPR. | bsigroup.com |
| Data Protection Trustmark (SS 714:2025) | Singapore's voluntary, third-party-audited enterprise data protection certification, elevated to a national standard in July 2025. Published by IMDA. The standard itself is paywalled; the mapping document and implementation guide are free. | imda.gov.sg |
| Reference | What it is | Source |
|---|---|---|
| ISO/IEC 27001 | Information Security Management System (ISMS) — the foundational certifiable security standard. | iso.org |
| ISO/IEC 27002 | Information security controls — implementation guidance for 27001. | iso.org |
| ISO/IEC 27018:2025 | Guidelines for protecting personally identifiable information in public clouds acting as PII processors. Third edition, published 26 August 2025, aligned to ISO/IEC 27002:2022 with a new Annex B of extended implementation guidance. 35 pages. The 2019 edition is withdrawn. | iso.org |
| SOC 2 (AICPA TSC) | Trust Services Criteria — assurance reporting on security, availability, confidentiality & privacy. | aicpa-cima.com |
| NIST SP 800-53 | Security and privacy controls for information systems and organisations, including the PT (PII Processing and Transparency) control family. Rev. 5, now maintained as incremental releases — Release 5.2.0, August 2025; the original September 2020 issue is marked withdrawn in favour of the December 2020 update. Official crosswalks to ISO/IEC 27001:2022 and to the CSF are published alongside it. | csrc.nist.gov |
| NIST SP 800-63-4 | Digital identity guidelines in four volumes — identity proofing, authentication and federation. Final July 2025; supersedes SP 800-63-3. Scoped to US government information systems, but volume 63B-4 is the volume most often cited for password and authenticator policy. | csrc.nist.gov |
| NIST SP 800-88 Rev. 2 | Guidelines for media sanitization — the Clear, Purge and Destroy model that retention and asset-disposal policies cite for "securely erased". Final September 2025; Rev. 1 was withdrawn on 26 September 2025. | csrc.nist.gov |
| NIST SP 800-171 Rev. 3 | Protecting controlled unclassified information in nonfederal systems. Final May 2024. A US federal contracting instrument — relevant chiefly where a client sits in a US federal or defence supply chain. | csrc.nist.gov |
| CSA CCM / STAR | Cloud Security Alliance Cloud Controls Matrix and STAR assurance programme. | cloudsecurityalliance.org |
| PCI DSS | Payment Card Industry Data Security Standard for cardholder data. | pcisecuritystandards.org |
| Reference | What it is | Source |
|---|---|---|
| ISO/IEC 42001 | AI Management System (AIMS) — the first certifiable AI governance standard. | iso.org |
| NIST AI RMF | AI Risk Management Framework for trustworthy AI (AI 100-1, 2023) — the Govern, Map, Measure, Manage structure, with a Generative AI Profile (AI 600-1) added in 2024. NIST states the framework is being revised. | nist.gov |
| Model AI Governance Framework for Generative AI | Singapore's nine-dimension framework covering accountability, data, incident reporting, testing and assurance, security and content provenance. Published 19 June 2024 by the AI Verify Foundation, an IMDA-established body, with IMDA. | aiverifyfoundation.sg |
| Artificial Intelligence: Model Personal Data Protection Framework | Hong Kong's framework for organisations procuring and deploying AI — strategy and governance, risk assessment and human oversight, model customisation, and communication with stakeholders. Published June 2024 by the PCPD. | pcpd.org.hk |
| EU AI Act | Regulation (EU) 2024/1689 — risk-based regulation of AI systems. | eur-lex.europa.eu |
| Reference | What it is | Source |
|---|---|---|
| ISO 31000 | Risk management — principles and guidelines. | iso.org |
| ISO 22301:2019 | Business continuity management systems — requirements. Second edition, October 2019, with Amendment 1:2024 (climate action). ISO has it under revision. | iso.org |
| NIST CSF 2.0 | Cybersecurity Framework — govern, identify, protect, detect, respond, recover. | nist.gov |
| COBIT | ISACA framework for governance and management of enterprise IT. | isaca.org |
Sponsor slot
Reach privacy & assurance professionals researching standards. Sponsorship enquiries.
This directory is curated to the essentials and expanding. Spotted a standard we should add, or a detail to fix? Flag it for the curation team — curated lists take tip-offs, not self-listings.
