Privacy Standards Skill
This skill is the reusable privacy reference package for the Privacy Planner and Privacy Reviewer. It consolidates the privacy standards backbone, the core data-flow and classification heuristics, and the DPIA threshold logic needed to keep privacy reviews focused on workflow, evidence, and implementation readiness.
[!NOTE]
This skill is a planning aid, not legal advice. Its standards summaries support privacy reasoning and review preparation; they do not substitute for qualified legal counsel or a formal regulatory interpretation.
Attribution and licensing posture
- NIST Privacy Framework and NISTIR 8062 are U.S. Government documents and are referenced here with attribution as public-domain reference material. Public-domain material carries no license obligation, so it adds no term to the package license expression.
- GDPR and CCPA/CPRA content is paraphrased and attributed rather than quoted verbatim, consistent with the repository's open legal-text posture. The paraphrase is this repository's own expression.
- OWASP privacy-risk material is adapted from the OWASP Top 10 Privacy Risks project, which is licensed CC BY-SA 3.0. ShareAlike propagates to that derivative, so it is the one file carrying a copyleft term.
The frontmatter expression is the conjunction of every license present in the package. The table states which license governs each file.
| Path |
License |
Origin |
references/owasp-top-10-privacy-risks.md |
CC-BY-SA-3.0 |
Adapted from OWASP Top 10 Privacy Risks v2.0 (CC BY-SA 3.0) |
references/nist-privacy-framework.md |
CC-BY-4.0 |
Adapted from NIST Privacy Framework v1.0 (public domain) |
references/nistir-8062.md |
CC-BY-4.0 |
Adapted from NISTIR 8062 (public domain) |
references/gdpr.md |
CC-BY-4.0 |
Paraphrase of GDPR, not reproduced |
references/ccpa-cpra.md |
CC-BY-4.0 |
Paraphrase of CCPA/CPRA, not reproduced |
references/dpia-thresholds.md |
CC-BY-4.0 |
Repository-original planning synthesis |
references/data-governance-controls.md |
CC-BY-4.0 |
Repository-original planning synthesis |
SKILL.md and remaining package content |
CC-BY-4.0 |
Repository-original |
Framework index
- NIST Privacy Framework
- NISTIR 8062
- GDPR overview
- CCPA/CPRA overview
- OWASP Top 10 Privacy Risks
- DPIA threshold heuristics
- Data governance controls for release readiness
Privacy planning heuristics
- Start with a data inventory and map the personal data lifecycle: collection, transfer, storage, use, sharing, retention, and deletion.
- Separate the data categories from the processing purpose so the planner or reviewer can assess necessity, proportionality, and appropriate control selection.
- Identify whether the workflow involves sensitive data, automated decision-making, profiling, or cross-organization sharing, because these conditions often trigger a deeper review.
- Track the evidence trail for each privacy decision so the handoff can include the standards references, the supporting rationale, and the review context.
Citation-field vocabulary
Use these fields when capturing a finding, control, or risk so the reviewer can assert a stable source-control reference:
gdpr_article
ccpa_section
nist_pf_category
nistir8062_objective
owasp_privacy_id
Phase-to-framework mapping
| Privacy phase |
Primary standards package |
Notes |
| Phase 1 Capture |
NIST Privacy Framework + GDPR |
Context, scope, and legal basis framing |
| Phase 2 Data Mapping |
NIST Privacy Framework + NISTIR 8062 |
Data inventory, purpose, and minimization reasoning |
| Phase 3 Risk and DPIA |
GDPR + CCPA/CPRA + NISTIR 8062 |
DPIA triggers, risk analysis, and proportionality |
| Phase 4 Controls |
NIST Privacy Framework + OWASP Privacy Risks |
Controls for collection, use, sharing, and retention |
| Phase 5 Impact |
GDPR + CCPA/CPRA + OWASP Privacy Risks |
Potential harm, mitigation, and monitoring |
| Phase 6 Handoff |
All sources |
Evidence handoff, review notes, and action tracking |
Open-standards catalog
Use the links below as the reference catalog for open privacy standards and governance resources. Treat the material as planning and review guidance rather than a substitute for legal advice or formal regulatory interpretation.
1---2name: privacy-standards3description: Privacy planning reference for data-flow reasoning, standards mapping, and DPIA thresholds4license: CC-BY-4.0 AND CC-BY-SA-3.05---6
7## Privacy Standards Skill
8
9This skill is the reusable privacy reference package for the Privacy Planner and Privacy Reviewer. It consolidates the privacy standards backbone, the core data-flow and classification heuristics, and the DPIA threshold logic needed to keep privacy reviews focused on workflow, evidence, and implementation readiness.
10
11> [!NOTE]
12> This skill is a planning aid, not legal advice. Its standards summaries support privacy reasoning and review preparation; they do not substitute for qualified legal counsel or a formal regulatory interpretation.
13
14## Attribution and licensing posture
15
16- NIST Privacy Framework and NISTIR 8062 are U.S. Government documents and are referenced here with attribution as public-domain reference material. Public-domain material carries no license obligation, so it adds no term to the package license expression.
17- GDPR and CCPA/CPRA content is paraphrased and attributed rather than quoted verbatim, consistent with the repository's open legal-text posture. The paraphrase is this repository's own expression.
18- OWASP privacy-risk material is adapted from the OWASP Top 10 Privacy Risks project, which is licensed CC BY-SA 3.0. ShareAlike propagates to that derivative, so it is the one file carrying a copyleft term.
19
20The frontmatter expression is the conjunction of every license present in the package. The table states which license governs each file.
21
22| Path | License | Origin |
23|--------------------------------------------|--------------|-------------------------------------------------------------|
24| `references/owasp-top-10-privacy-risks.md` | CC-BY-SA-3.0 | Adapted from OWASP Top 10 Privacy Risks v2.0 (CC BY-SA 3.0) |
25| `references/nist-privacy-framework.md` | CC-BY-4.0 | Adapted from NIST Privacy Framework v1.0 (public domain) |
26| `references/nistir-8062.md` | CC-BY-4.0 | Adapted from NISTIR 8062 (public domain) |
27| `references/gdpr.md` | CC-BY-4.0 | Paraphrase of GDPR, not reproduced |
28| `references/ccpa-cpra.md` | CC-BY-4.0 | Paraphrase of CCPA/CPRA, not reproduced |
29| `references/dpia-thresholds.md` | CC-BY-4.0 | Repository-original planning synthesis |
30| `references/data-governance-controls.md` | CC-BY-4.0 | Repository-original planning synthesis |
31| `SKILL.md` and remaining package content | CC-BY-4.0 | Repository-original |
32
33## Framework index
34
35- [NIST Privacy Framework](references/nist-privacy-framework.md)
36- [NISTIR 8062](references/nistir-8062.md)
37- [GDPR overview](references/gdpr.md)
38- [CCPA/CPRA overview](references/ccpa-cpra.md)
39- [OWASP Top 10 Privacy Risks](references/owasp-top-10-privacy-risks.md)
40- [DPIA threshold heuristics](references/dpia-thresholds.md)
41- [Data governance controls for release readiness](references/data-governance-controls.md)
42
43## Privacy planning heuristics
44
45- Start with a data inventory and map the personal data lifecycle: collection, transfer, storage, use, sharing, retention, and deletion.
46- Separate the data categories from the processing purpose so the planner or reviewer can assess necessity, proportionality, and appropriate control selection.
47- Identify whether the workflow involves sensitive data, automated decision-making, profiling, or cross-organization sharing, because these conditions often trigger a deeper review.
48- Track the evidence trail for each privacy decision so the handoff can include the standards references, the supporting rationale, and the review context.
49
50## Citation-field vocabulary
51
52Use these fields when capturing a finding, control, or risk so the reviewer can assert a stable source-control reference:
53
54- `gdpr_article`
55- `ccpa_section`
56- `nist_pf_category`
57- `nistir8062_objective`
58- `owasp_privacy_id`
59
60## Phase-to-framework mapping
61
62| Privacy phase | Primary standards package | Notes |
63|-----------------------|----------------------------------------------|------------------------------------------------------|
64| Phase 1 Capture | NIST Privacy Framework + GDPR | Context, scope, and legal basis framing |
65| Phase 2 Data Mapping | NIST Privacy Framework + NISTIR 8062 | Data inventory, purpose, and minimization reasoning |
66| Phase 3 Risk and DPIA | GDPR + CCPA/CPRA + NISTIR 8062 | DPIA triggers, risk analysis, and proportionality |
67| Phase 4 Controls | NIST Privacy Framework + OWASP Privacy Risks | Controls for collection, use, sharing, and retention |
68| Phase 5 Impact | GDPR + CCPA/CPRA + OWASP Privacy Risks | Potential harm, mitigation, and monitoring |
69| Phase 6 Handoff | All sources | Evidence handoff, review notes, and action tracking |
70
71## Open-standards catalog
72
73Use the links below as the reference catalog for open privacy standards and governance resources. Treat the material as planning and review guidance rather than a substitute for legal advice or formal regulatory interpretation.
74
75- NIST Privacy Framework: https://www.nist.gov/privacy-framework
76- NISTIR 8062: https://doi.org/10.6028/NIST.IR.8062
77- GDPR: https://gdpr-info.eu
78- CCPA/CPRA: https://oag.ca.gov/privacy/ccpa
79- OWASP Top 10 Privacy Risks: https://owasp.org/www-project-top-10-privacy-risks/