In This Section

Privacy Management Framework

Mar 25, 2024
Privacy Management Framework
The Privacy Management Framework (PMF) can be used as a foundational element in establishing and operating a comprehensive information privacy program that addresses privacy obligations and risks while facilitating current and future business opportunities.

The PMF was created as an update to the former 2009 Generally Accepted Privacy Principles (GAPP). Because of significant changes in technologies and in global, country-specific, local information and data privacy laws and standards, including the publication of the General Data Protection Regulation (GDPR) and updates to the AICPA’s Trust Services Criteria (TSC), the AICPA Privacy Task Force updated the PMF in 2020.

The PMF is a guide to help organizations address the business activities that involve collecting, creating, using, storing and transmitting personal information of individuals.

There are nine components of the PMF:
  1. Management

  2. Agreement, notice and communication

  3. Collection and creation

  4. Use, retention and disposal

  5. Access

  6. Disclosure to third parties

  7. Security for privacy

  8. Data integrity and quality

  9. Monitoring and enforcement


This updated PMF has been approved by both the AICPA Privacy Task Force and the AICPA Information Management and Technology Assurance Executive Committee. The adoption of the PMF is voluntary.

Download the
Privacy Management Framework



Load more comments
Thank you for the comment! Your comment must be approved first
avatar
New code