HomeKnowledge Hub › Standards & Frameworks

Knowledge Hub

Privacy standards & frameworks

The international standards and recognised frameworks most relevant to privacy governance, assurance and AI. Curated to the essentials and growing — with links to the authoritative source for each.

Compiled & maintained by VulaPri Limited, a UK privacy consultancy · The nine NIST entries, the Data Protection Trustmark and the two AI framework entries verified 7 August 2026; the six ISO entries 10 August 2026; the remaining entries 16 June 2026

Privacy-specific standards & frameworks
ReferenceWhat it isSource
ISO/IEC 27701:2025Privacy information management systems — requirements and guidance. Second edition, published 14 October 2025, and now a stand-alone management system standard: ISO's own guidance is that it can be used alone, where the 2019 first edition was an extension to ISO/IEC 27001 and 27002 and could not be certified independently. 64 pages. The 2019 edition is withdrawn.iso.org
ISO/IEC 29100:2024Privacy framework — terminology and principles for protecting PII. Second edition, February 2024; the 2011 edition and its 2018 amendment are withdrawn. Published by ISO free of charge.iso.org
NIST Privacy FrameworkVoluntary US framework for managing privacy risk, structured to sit alongside the NIST CSF. Version 1.0 remains the current published version — a 1.1 initial public draft (CSWP 40) was issued in April 2025 and has not been finalised.nist.gov
NIST SP 800-188De-Identifying Government Datasets: Techniques and Governance. Written with the US Census Bureau for US government agencies, but the governance model — disclosure review, re-identification studies, the Five Safes — travels. Final September 2023.csrc.nist.gov
NIST SP 800-226Guidelines for evaluating differential privacy guarantees — a structured way to interrogate a supplier's differential-privacy claim. Final March 2025.csrc.nist.gov
BS 10012British Standard for a personal information management system, aligned to UK GDPR.bsigroup.com
Data Protection Trustmark (SS 714:2025)Singapore's voluntary, third-party-audited enterprise data protection certification, elevated to a national standard in July 2025. Published by IMDA. The standard itself is paywalled; the mapping document and implementation guide are free.imda.gov.sg
Security & cloud standards
ReferenceWhat it isSource
ISO/IEC 27001Information Security Management System (ISMS) — the foundational certifiable security standard.iso.org
ISO/IEC 27002Information security controls — implementation guidance for 27001.iso.org
ISO/IEC 27018:2025Guidelines for protecting personally identifiable information in public clouds acting as PII processors. Third edition, published 26 August 2025, aligned to ISO/IEC 27002:2022 with a new Annex B of extended implementation guidance. 35 pages. The 2019 edition is withdrawn.iso.org
SOC 2 (AICPA TSC)Trust Services Criteria — assurance reporting on security, availability, confidentiality & privacy.aicpa-cima.com
NIST SP 800-53Security and privacy controls for information systems and organisations, including the PT (PII Processing and Transparency) control family. Rev. 5, now maintained as incremental releases — Release 5.2.0, August 2025; the original September 2020 issue is marked withdrawn in favour of the December 2020 update. Official crosswalks to ISO/IEC 27001:2022 and to the CSF are published alongside it.csrc.nist.gov
NIST SP 800-63-4Digital identity guidelines in four volumes — identity proofing, authentication and federation. Final July 2025; supersedes SP 800-63-3. Scoped to US government information systems, but volume 63B-4 is the volume most often cited for password and authenticator policy.csrc.nist.gov
NIST SP 800-88 Rev. 2Guidelines for media sanitization — the Clear, Purge and Destroy model that retention and asset-disposal policies cite for "securely erased". Final September 2025; Rev. 1 was withdrawn on 26 September 2025.csrc.nist.gov
NIST SP 800-171 Rev. 3Protecting controlled unclassified information in nonfederal systems. Final May 2024. A US federal contracting instrument — relevant chiefly where a client sits in a US federal or defence supply chain.csrc.nist.gov
CSA CCM / STARCloud Security Alliance Cloud Controls Matrix and STAR assurance programme.cloudsecurityalliance.org
PCI DSSPayment Card Industry Data Security Standard for cardholder data.pcisecuritystandards.org
AI governance
ReferenceWhat it isSource
ISO/IEC 42001AI Management System (AIMS) — the first certifiable AI governance standard.iso.org
NIST AI RMFAI Risk Management Framework for trustworthy AI (AI 100-1, 2023) — the Govern, Map, Measure, Manage structure, with a Generative AI Profile (AI 600-1) added in 2024. NIST states the framework is being revised.nist.gov
Model AI Governance Framework for Generative AISingapore's nine-dimension framework covering accountability, data, incident reporting, testing and assurance, security and content provenance. Published 19 June 2024 by the AI Verify Foundation, an IMDA-established body, with IMDA.aiverifyfoundation.sg
Artificial Intelligence: Model Personal Data Protection FrameworkHong Kong's framework for organisations procuring and deploying AI — strategy and governance, risk assessment and human oversight, model customisation, and communication with stakeholders. Published June 2024 by the PCPD.pcpd.org.hk
EU AI ActRegulation (EU) 2024/1689 — risk-based regulation of AI systems.eur-lex.europa.eu
Risk, governance & resilience
ReferenceWhat it isSource
ISO 31000Risk management — principles and guidelines.iso.org
ISO 22301:2019Business continuity management systems — requirements. Second edition, October 2019, with Amendment 1:2024 (climate action). ISO has it under revision.iso.org
NIST CSF 2.0Cybersecurity Framework — govern, identify, protect, detect, respond, recover.nist.gov
COBITISACA framework for governance and management of enterprise IT.isaca.org
This directory is curated to the essentials and expanding. Spotted a standard we should add, or a detail to fix? Flag it for the curation team — curated lists take tip-offs, not self-listings.