Skip to main content

INCPAS Blog

Uncategorized

Privacy Management Framework

By March 25, 2024August 4th, 2025No Comments


The Privacy Management Framework (PMF) can be used as a foundational element in establishing and operating a comprehensive information privacy program that addresses privacy obligations and risks while facilitating current and future business opportunities.

The PMF was created as an update to the former 2009 Generally Accepted Privacy Principles (GAPP). Because of significant changes in technologies and in global, country-specific, local information and data privacy laws and standards, including the publication of the General Data Protection Regulation (GDPR) and updates to the AICPA’s Trust Services Criteria (TSC), the AICPA Privacy Task Force updated the PMF in 2020.

The PMF is a guide to help organizations address the business activities that involve collecting, creating, using, storing and transmitting personal information of individuals.

There are nine components of the PMF:

  1. Management
  2. Agreement, notice and communication
  3. Collection and creation
  4. Use, retention and disposal
  5. Access
  6. Disclosure to third parties
  7. Security for privacy
  8. Data integrity and quality
  9. Monitoring and enforcement

This updated PMF has been approved by both the AICPA Privacy Task Force and the AICPA Information Management and Technology Assurance Executive Committee. The adoption of the PMF is voluntary.

Download the Privacy Management Framework

Related Content

Plotting Your Path: Summer is the Season for Accounting Success

Plotting Your Path: Summer is the Season for Accounting Success

How Your Firm Can Strengthen AI Adoption and Stay Competitive

How Your Firm Can Strengthen AI Adoption and Stay Competitive

Meet INCPAS’ Student Ambassadors: Accounting Students Leading on Campus

Meet INCPAS’ Student Ambassadors: Accounting Students Leading on Campus