Dear Colleagues,
Please find the agenda for next week’s monthly meeting attached.
We’re pleased to announce that Project Team 9: Data Processing Awareness (CM.AW-P) is now live!
Project Team 9 (PT9) will create Task, Knowledge, and Skill Statements aligned with the following NIST Privacy Framework Category and Subcategories:
· CM.AW-P: Data Processing Awareness: Individuals and organizations have reliable knowledge about data processing practices and associated privacy risks, and effective mechanisms are used and maintained to increase predictability consistent with the organization’s risk strategy to protect individuals’ privacy.
o CM.AW-P1: Mechanisms (e.g., notices, internal or public reports) for communicating data processing purposes, practices, associated privacy risks, and options for enabling individuals’ data processing preferences and requests are established and in place.
o CM.AW-P2: Mechanisms for obtaining feedback from individuals (e.g., surveys or focus groups) about data processing and associated privacy risks are established and in place.
o CM.AW-P3: System/product/service design enables data processing visibility.
o CM.AW-P4: Records of data disclosures and sharing are maintained and can be accessed for review or transmission/disclosure.
o CM.AW-P5: Data corrections or deletions can be communicated to individuals or organizations (e.g., data sources) in the data processing ecosystem.
o CM.AW-P6: Data provenance and lineage are maintained and can be accessed for review or transmission/disclosure.
o CM.AW-P7: Impacted individuals and organizations are notified about a privacy breach or event.
o CM.AW-P8: Individuals are provided with mitigation mechanisms (e.g., credit monitoring, consent withdrawal, data alteration or deletion) to address impacts of problematic data actions.
PT9 is led by three great Co-Leads:
·
Paul Lanois,
Director, Data, Fieldfisher
We hope you’ll contribute your expertise to the great work that PT9 will be doing. To subscribe to the PT9 mailing list for the latest updates:
· Send an email to this address: PrivacyWorkfor...@list.nist.gov
· For additional instructions, click here.
When approved, you will only gain access to the Project Team 9 listserv. If you have more than one email address at which you would like to receive PT9 mailing list messages, please subscribe using all relevant email addresses.
The first PT9 meeting will take place during the week of November 13 (day/time to be determined) and will be held on the Microsoft Teams platform. A calendar schedular for the first PT9 meeting will be sent to PT9 members via the Team’s dedicated mailing list in the next week.
If you have any issues joining PT9, please email pw...@nist.gov and a member of the NIST PWWG Team will help with troubleshooting.
Best,
NIST PWWG Team