Sekit CSF · Privacy · Policy
RCF-0355Privacy risk assessments (DPIA)
The company formally assesses privacy risks before starting new data processing activities
Mapping at a glance
RCF-0355Privacy risk assessments (DPIA)Privacy · Policy
A.5.31Legal, statutory, regulatory and contractual requirementsISO/IEC 27001:2022A.5.34Privacy and protection of personal identifiable information (PII)ISO/IEC 27001:2022GV.RM-03Cyber risk in enterprise risk managementNIST CSF 2.0ID.RA-01Vulnerabilities identified and recordedNIST CSF 2.0ID.RA-03Threats identified and recordedNIST CSF 2.0
RCF-0355 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.31Legal, statutory, regulatory and contractual requirementsrelatedAssessing privacy risk before new processing begins is one specific legal obligation, under data protection law, that this control's broader tracking should capture.A.5.34Privacy and protection of personal identifiable information (PII)supportsA written commitment to assess privacy risk before new processing begins covers the DPIA trigger piece of this control, not the full range of PII protections A.5.34 requires, such as consent, transfers or rights handling.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.RM-03Cyber risk in enterprise risk managementID.RA-01Vulnerabilities identified and recordedID.RA-03Threats identified and recorded
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
A.5.2AI system impact assessment processsupportsCommitting to assess privacy risk before new processing covers the personal-data leg of an AI impact assessment but not the wider effects on affected people.A.5.4Assessing AI system impact on individuals or groups of individualssupportsCommitting to assess privacy risk before processing begins covers the data-protection leg but does not ask whether an AI system's decisions differ across groups.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
DPIA and cross-border transfer records
The privacy impact assessments done before new data processing and the records of personal-data transfers to other countries.
From the Sekit evidence catalog
This topic through the other lenses
All Privacy controls
Ask Sekura: “What evidence proves RCF-0355?”
Also via MCP, free with account