NIST Releases Updated Privacy Framework

Maynard Nexsen
Contact

Maynard Nexsen

On April 14, 2025, the National Institute of Standards and Technology (“NIST”) released draft updates to the NIST Privacy Framework, designed to address current privacy risk management needs, enhance usability, and align the Privacy Framework with Version 2.0 of the NIST Cybersecurity Framework (“NIST CSF”), released in February of last year.  NIST has solicited public stakeholder comment on the draft updates, which are due no later than June 13, 2025. Comments may be submitted to privacyframework@nist.gov, using the comment template found at the link below.

After the public comment period ends, NIST may hold a further workshop in Q3, with a final draft released in Q4 2025.

Key updates to the NIST Privacy Framework include:

  1. Revisions to and re-organization within the Core section to better align with the updated CSF, focusing on specific functions – particularly related to oversight and governance (i.e., risk management strategy and policies), and other similar issues.
  2. Incorporate targeted improvements based on stakeholder feedback
  3. A new separate AI and Privacy Risk Management Section (Section 1.2.2), (now withdrawn from PF1.1 Core in version 1.0 to keep it technology-neutral).  The new section describes how AI tools relate to privacy risks, such as the potential for privacy harm when: (a) AI systems are trained on data collected without individual consent, (b) have missing or inadequate privacy safeguards, or (c) reveal information about individuals by estimating personal attributes or through privacy attacks such as data reconstruction, prompt injections, or membership inference.
  4. A standalone online guide (versus the previous version, where it was embedded within Section 3 (“Using Privacy Framework 1.1)). The online guide is now located on the Privacy Framework website as an Informative Reference. Section 3 now contains a short summary with a link to the online content.

More information about the updated Privacy Framework, a mapping that traces changes to the Core Categories and Subcategories between Framework versions, a comment template, and a highlights video that summarizes the development process and reviews key updates, can all be found here.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Maynard Nexsen

Written by:

Maynard Nexsen
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Maynard Nexsen on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide