PogoWasRight.org

Menu
  • About
  • Privacy
Menu

NIST Releases Updated Privacy Framework

Posted on April 30, 2025 by Dissent

Seen at Hunton Andrews Kurth’s Privacy & Information Security Law Blog:

On April 14, 2025, the National Institute of Standards and Technology (“NIST”) announced the release of a draft update to its voluntary Privacy Framework, “NIST Privacy Framework 1.1 Initial Public Draft” (“PFW 1.1”). The update is designed to address current privacy risk management needs, enhance usability, and align the Privacy Framework with version 2.0 of the NIST Cybersecurity Framework (“CSF”), which was released in February 2024.

The updated Privacy Framework includes the following key changes:

  • Revised Core Structure and Content: The Core section has been revised to align with the updated CSF, with a focus specific functions such as governance (i.e., risk management strategy and policies).
  • New AI and Privacy Risk Management Section: PFW 1.1 includes a new section that describes how AI tools relate to privacy risks, such as the potential (1) that an AI system could reveal information about individuals through data reconstruction, prompt injection, or membership interference; or (2) for systemic, computational, statistical and human biases that make important decisions and predictions about individuals.
  • Interactive Online Guidelines: Previously, NIST embedded a guide to the Privacy Framework as Section 3 within the previous version. As part of the update, NIST published a standalone online guide.

NIST has invited stakeholder feedback on PFW 1.1 until June 13, 2025.

Related posts:

  • On Privacy and Cloud Computing Challenges
  • Fifteen More Smart Grid Privacy Concerns
  • Department of Commerce Launches Collaborative Privacy Framework Effort
Category: AnnouncementsGovtMisc

Post navigation

← Car Subscription Features Raise Your Risk of Government Surveillance, Police Records Show
Google warns of data security risks if Chrome is sold off →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Attorney General James Takes Action to Protect Sensitive Personal Information of Tens of Millions of People
  • Searches of Your Private Data in the Cloud Amount to Illicit State Action
  • How a Tax Subpoena in Ohio Tests European Privacy Law
  • Cambodia moves to enact comprehensive data privacy law
  • White House ordered to restore Medicaid funding to Planned Parenthood clinics
  • California Attorney General Announces $1.55M CCPA Settlement with Healthline.com
  • Canada’s Bill C-2 Opens the Floodgates to U.S. Surveillance

RSS Recent Posts on DataBreaches.net

  • Oops! Catasauqua employees’ Social Security numbers, other data accidentally sent to government watchdog group
  • EU-wide Breach Notification Template on the Horizon
  • Sex toy maker Lovense caught leaking users’ email addresses and exposing accounts to takeovers
  • Hackers wipe out Rs 384 crore from Bengaluru cryptocurrency firm Neblio Technologies; firm says inside job
  • Intelligence cyberattack on Crimea. Documents confirming abduction of children from Ukraine found
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy