Controls are your cybersecurity & data privacy program ---- A control is the power to influence or direct behaviors and the course of events.

SCF Data Privacy Management Principles

In support of the Cybersecurity & Data Privacy by Design (C|P) initiative, a volunteer effort created the SCF Data Privacy Management Principles (DPMP). When you tie the broader C|P in with these privacy management principles, you have an excellent foundation for building and maintaining secure systems, applications and services that address cybersecurity and privacy considerations by default and by design.

We saw a need and we took action, since many cybersecurity and even privacy professionals have a hard time identifying "what right looks like" when picking a set of privacy principles for an organization to align to. What we did was select over a dozen of the most common privacy frameworks and create a "best in class" approach to managing privacy expectations. The best part is these are all mapped to the SCF, so you can leverage the SCF for both your cybersecurity and privacy needs!

The end result is the SCF's Data Privacy Management Principles (the DPMP is a tab that is part of the SCF download).

SCF Privacy Management Principles

 
For organizations, we found the “apples to oranges” comparison between disparate privacy frameworks was difficult for most non-privacy lawyers to understand. What this project did was identify a dozen of the leading privacy frameworks and create a set of simplified, yet comprehensive, privacy management principles. Below are the thirty-one (31) different frameworks the SCF Data Privacy Management Principles is mapped to:
  1. AICPA TSC 2017:2022 (used for SOC 2)
  2. Asia-Pacific Economic Cooperation (APEC) Privacy Framework 2015
  3. Generally Accepted Privacy Principles (GAPP)
  4. ISO 27701:2025
  5. ISO 29100:2024
  6. NIST Privacy Framework 1.0
  7. NIST 800-53 R5
  8. NIST CSF 2.0
  9. Organization for Economic Co-operation and Development (OECD) Privacy Principles
  10. US Federal - Data Privacy Framework (DPF)
  11. US Federal - Fair Information Practice Principles (FIPPs)
  12. US Federal - HIPAA Administrative Simplification 2013
  13. US State - Alaska Personal Information Protection Act (PIPA)
  14. US State - California Consumer Privacy Act (CCPA) January 2026 (amended California Privacy Rights Act (CPRA))
  15. US State - Colorado Privacy Act
  16. US State - Illinois Biometric Information Privacy Act (BIPA)
  17. US State - Illinois Identity Protection Act (IPA)
  18. US State - Illinois Personal Information Protection Act (PIPA)
  19. US State - Nevada Privacy Law (SB220)
  20. US State - Oregon Consumer Privacy Act (SB 619)
  21. US State - Tennessee Information Protection Act
  22. US State - Texas BC521
  23. US State - Virginia Consumer Data Protection Act (CDPA) 2025
  24. US State - Vermont Act 171 of 2018
  25. EMEA - European Union General Data Protection Regulation (EU GDPR)
  26. EMEA - Saudi Arabia Personal Data Protection Law (PDPL)
  27. APAC - Australia Privacy Act
  28. APAC - Australian Privacy Principles
  29. APAC - India DPDPA 2023
  30. APAC - New Zealand Privacy Act of 2020
  31. Americas - Canada Personal Information Protection and Electronic Documents Act (PIPEDA)

We took these frameworks and looked for similarities and also for gaps. If you download the SCF Data Privacy Management Principles, you will see the direct mapping to these leading privacy frameworks so you know the origin of the principle we include in our document. This will be a great tool for organizations that may have to address multiple requirements, since it brings a common language to simply things.
 
The eighty-six (86) principles of the SCF Data Privacy Management Principles are organized into eleven (11) domains:

  1. Privacy by Design
  2. Data Subject Participation
  3. Limited Collection & Use
  4. Transparency
  5. Data Lifecycle Management
  6. Data Subject Rights
  7. Security by Design
  8. Incident Response
  9. Risk Management
  10. Third-Party Management
  11. Business Environment
1 of 1 Items
  • Excel version of STRM mapping

    STRM Bundle - Excel Versions

    This is for a digital download of the current Excel spreadsheet versions of the Set Theory Relationship Mapping (STRM) used to crosswalk the Secure Controls Framework (SCF).  There is a one (1) month period of time to access the STRM download (from...

    $20.00
1 of 1 Items