Aranisdocs
aranis.ai
Docs/Privacy Risk/Privacy controls

Privacy controls

The 34 controls in the privacy pillar and why they use a fixed severity weight.

Updated on August 17, 2026

The privacy pillar

There are 34 controls, the privacy slice of the shared library. They cover what the cybersecurity framework does not reach in enough depth: impact assessments, legal bases, consent and revocation, data subject rights, international transfer, and breach notification to the authority.

A P1 supplier already answers 19 of them

The distribution by profile is 19 at P1, 27 cumulative at P2, and all 34 at P3. Privacy starts early on purpose: even a supplier of low operational criticality may process personal data, and joint liability between controller and processor does not shrink because the contract is small.

Fixed severity weight

In the other pillars, an unmet control weighs according to the technical severity associated with it. Not here: privacy controls use a fixed synthetic weight, 7.5 by default and configurable per organization.

The reason is that a legal obligation has no CVE. There is no technical severity to look up for "no defined legal basis" — the risk is regulatory, set by statute, and does not vary with the vulnerability of any particular piece of software. A fixed weight is more honest than a number derived from a source that does not apply.

What the answer feeds

These controls' maturity feeds the privacy risk category, the residual of risks that relate them, and adherence per regulatory requirement. Thirty-three controls in the cyber pillar carry cross-coverage with other pillars, which avoids asking the respondent the same thing twice.