4.1 Privacy Risk Models and Frameworks: Contextual Integrity, Calo, Solove, FIPPs, OECD, NIST, and FAIR

Key Takeaways

  • Contextual integrity holds that an information flow is appropriate only if it matches the norms of its context, described by sender, recipient, subject, information type, and transmission principle.

  • Ryan Calo divides privacy harm into subjective harm (the perception of unwanted observation) and objective harm (the unanticipated or coerced use of information against a person).

  • Solove's 2006 taxonomy groups 16 privacy problems into information collection, information processing, information dissemination, and invasions.

  • The 1980 OECD Guidelines (revised 2013) set eight principles: collection limitation, data quality, purpose specification, use limitation, security safeguards, openness, individual participation, and accountability.

  • The NIST Privacy Framework 1.0 organizes privacy risk management into Identify-P, Govern-P, Control-P, Communicate-P, and Protect-P; FAIR quantifies risk from loss event frequency and loss magnitude.

Last updated: October 2026

4.1 Privacy Risk Models and Frameworks: Contextual Integrity, Calo, Solove, FIPPs, OECD, NIST, and FAIR

Quick Summary: A risk model defines what a privacy risk is (which flows or harms count), while a framework organizes how an organization finds and manages those risks. The CIPT BoK names Nissenbaum's contextual integrity, Calo's harm dimensions, FAIR, the NIST and NICE frameworks, the FIPPs, and the OECD principles. Solove's taxonomy supplies much of the BoK's own vocabulary (aggregation, exposure, blackmail, appropriation, distortion, intrusion, decisional interference). Exam questions usually describe a scenario and ask which model best explains it, or which framework function an activity belongs to.

No single model captures every privacy problem. Security has the CIA triad; privacy has several complementary lenses. Experienced technologists combine them: contextual integrity to test whether a new data flow fits expectations, Solove's taxonomy or NIST's catalog to name the specific problem, and a quantitative method such as FAIR to decide how much to spend on the fix.


Nissenbaum's Contextual Integrity

Philosopher Helen Nissenbaum introduced contextual integrity in "Privacy as Contextual Integrity" (2004) and developed it in the book Privacy in Context (2010). Its central claim is that privacy is neither pure secrecy nor pure control; it is the appropriate flow of information. Every social context (health care, employment, banking, friendship, education) has informational norms about how information should move. A flow respects privacy when it matches those norms and violates privacy when it breaks them.

A flow is described by five parameters:

ParameterQuestionExample in a Health App
SenderWho passes the information on?The patient's app
RecipientWho receives it?The patient's physician, or an advertising network
SubjectWhom is it about?The patient
Information type (attribute)What kind of information?Medication list
Transmission principleUnder what conditions does it flow?In confidence, with consent, as required by law, in exchange for payment

The same medication list flowing from patient to physician in confidence fits health-care norms. The same list flowing to an advertising network for targeting changes the recipient and the transmission principle, so it violates contextual integrity even if the patient clicked "I agree" on a long consent screen.

Why technologists use it: contextual integrity maps directly onto data flow diagrams. Each arrow in a diagram is a flow with a sender, recipient, subject, attribute, and transmission principle, so a design review can ask, for every new arrow, which norm governs the context and whether the arrow fits it. Contextual integrity also explains why "public" data can still be private: scraping public profiles into a searchable database changes both the recipients and the transmission principle.

Evaluating a new flow: Nissenbaum's heuristic is to describe the new flow, identify the prevailing context and its norms, locate the parameters that changed, and then ask whether the change supports or undermines the values and purposes of that context. A new flow is not automatically wrong; it needs a justification grounded in the context's goals.


Calo's Subjective and Objective Privacy Harms

Law professor Ryan Calo, in "The Boundaries of Privacy Harm" (Indiana Law Journal, 2011), argued that privacy harms fall into two related categories:

  • Subjective privacy harm: the perception of unwanted observation, such as anxiety, embarrassment, or the chilling effect people feel when they believe they are being watched. An employee who stops searching for health information on a work laptop because of monitoring software suffers this harm even if no one ever reads the searches.
  • Objective privacy harm: the unanticipated or coerced use of information concerning a person against that person, such as identity theft after a breach, a price increase driven by an inferred trait, or a job rejection based on a scraped social media post.

Calo's dimensions matter for risk assessment because many technical controls address only objective harm (for example, encryption against theft) while leaving subjective harm untouched (for example, visible, pervasive tracking). A smart speaker that never sends audio to the cloud still causes subjective harm if people believe it does, so transparency and visible hardware indicators are part of the mitigation.


Daniel Solove's Taxonomy of Privacy Harms

In 2006, legal scholar Daniel J. Solove published a landmark taxonomy that shifted the conceptualization of privacy from an abstract right to a concrete catalog of harms. Solove recognized that privacy violations do not occur in a vacuum; they arise during specific stages of data handling. The taxonomy groups 16 distinct privacy harms into four operational categories:

+-----------------------------------------------------------------------------------------+
|                           DANIEL SOLOVE'S TAXONOMY OF PRIVACY                           |
+----------------------------+-----------------------------+------------------------------+
| 1. Information Collection  | 2. Information Processing   | 3. Information Dissemination |
|    - Surveillance          |    - Aggregation            |    - Breach of Confid.       |
|    - Interrogation         |    - Identification         |    - Disclosure              |
|                            |    - Insecurity             |    - Exposure                |
|                            |    - Secondary Use          |    - Increased Access.       |
|                            |    - Exclusion              |    - Blackmail               |
|                            +-----------------------------+    - Appropriation           |
|                                                          |    - Distortion              |
+----------------------------------------------------------+------------------------------+
| 4. Invasions                                                                            |
|    - Intrusion                                                                          |
|    - Decisional Interference                                                            |
+-----------------------------------------------------------------------------------------+

1. Information Collection

  • Surveillance: The tracking, listening to, or recording of an individual's activities, movements, or communications. In software architecture, surveillance manifests as background location beacons, session replay scripts (e.g., recording mouse movements and form inputs), and persistent device fingerprinting.
  • Interrogation: Pressuring an individual to disclose information through coercive form design, intrusive onboarding workflows, or mandatory data fields that have no bearing on the requested service.

2. Information Processing

  • Aggregation: Gathering disparate, seemingly harmless pieces of information from multiple systems to synthesize a comprehensive profile. For example, combining a user's grocery loyalty card history with their mobile fitness app steps to infer chronic health conditions.
  • Identification: Associating anonymized, pseudonymous, or aggregated data records back to a specific, named human being.
  • Insecurity: Inadequate data maintenance, weak cryptographic storage, or careless data handling that leaves personal records exposed to potential compromise.
  • Secondary Use: Utilizing personal data collected for an authorized primary purpose (e.g., fulfilling an e-commerce shipment) for a completely unrelated secondary purpose (e.g., training a commercial recommendation algorithm) without the subject's consent.
  • Exclusion: Failing to notify individuals that their data is being processed, denying them access to view their records, or barring them from correcting inaccuracies.

3. Information Dissemination

  • Breach of Confidentiality: Violating an explicit or implicit obligation of trust by revealing private information to unauthorized third parties.
  • Disclosure: Revealing truthful personal information about an individual in a manner that damages their social standing, employment, or personal relationships.
  • Exposure: Revealing intimate physical, medical, or emotional aspects of an individual that violates human dignity.
  • Increased Accessibility: Making personal data that was previously obscure or difficult to locate instantly searchable, indexable, and accessible to the public (e.g., building a reverse lookup search engine from public court filings).
  • Blackmail: Threatening to expose sensitive personal data to coerce an individual into performing an action.
  • Appropriation: Using an individual's identity, likeness, voice, or persona for another party's commercial or reputational advantage without authorization.
  • Distortion: Creating or disseminating inaccurate, misleading, or out-of-context representations of an individual (e.g., training a credit-scoring model on faulty data, resulting in false debt flags).

4. Invasions

  • Intrusion: Disrupting an individual's tranquility, private life, or home environment (e.g., intrusive push notifications, unsolicited telemarketing, invasive desktop monitoring).
  • Decisional Interference: Manipulating or coercing an individual's personal decision-making process through behavioral profiling, targeted micro-propaganda, or algorithmic dark patterns.

The Fair Information Practice Principles (FIPPs) and the OECD Guidelines

The Fair Information Practice Principles (FIPPs) began with a 1973 report by the U.S. Department of Health, Education, and Welfare, Records, Computers and the Rights of Citizens, and underpin the U.S. Privacy Act of 1974. Different agencies have published different lists. The U.S. Department of Homeland Security's 2008 version, for example, names eight principles: transparency, individual participation, purpose specification, data minimization, use limitation, data quality and integrity, security, and accountability and auditing. The FTC's consumer-protection version emphasizes notice, choice, access, security, and enforcement.

The OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data (1980, revised in 2013) are the most influential international statement of the same ideas, and their eight principles appear in laws worldwide:

OECD PrincipleEngineering Translation
Collection LimitationCollect by lawful and fair means, with knowledge or consent where appropriate; schema allowlists and minimization at ingestion
Data QualityKeep data relevant, accurate, complete, and up to date; validation and rectification flows
Purpose SpecificationState purposes no later than collection; purpose tags on fields and datasets
Use LimitationNo use or disclosure beyond specified purposes without consent or legal authority; purpose-based access control
Security SafeguardsReasonable protection against loss, unauthorized access, destruction, use, modification, or disclosure
OpennessBe transparent about practices and the controller's identity; accurate notices and inventories
Individual ParticipationPeople can learn what is held about them, challenge it, and have it corrected or erased; access and correction APIs
AccountabilityThe data controller is accountable for complying; evidence, audit trails, and owners

The 2013 revision added expectations for privacy management programs, security breach notification, and stronger enforcement cooperation. When an exam option says a control "implements purpose specification" or "use limitation," it is using OECD language.


The NIST Privacy Framework

On January 16, 2020, the National Institute of Standards and Technology (NIST) published the NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management (Version 1.0). Modeled after the NIST Cybersecurity Framework (CSF), it gives engineers, lawyers, and executives a common vocabulary for privacy risk. Version 1.0 is still the final edition: NIST released a Privacy Framework 1.1 Initial Public Draft on April 14, 2025 (comments closed June 13, 2025) to realign it with CSF 2.0 and add AI-related guidance, but as of October 2026 that revision remains a draft. The five functions below are the same in both versions.

The Five Core Functions

The framework organizes privacy activities into five core Functions:

  1. Identify-P: Developing the organizational understanding to manage privacy risk arising from data processing. Includes inventorying systems, identifying data actions across the lifecycle, mapping legal requirements, and cataloging potential privacy harms.
  2. Govern-P: Establishing organizational privacy governance mechanisms. Includes defining executive risk tolerances, publishing internal data governance policies, training staff, and maintaining ongoing compliance monitoring.
  3. Control-P: Developing and implementing ongoing data management activities to enable organizations and individuals to manage personal data with granularity. Includes technical controls for data minimization, automated retention schedules, schema segregation, and data subject rights fulfillment (access, correction, erasure).
  4. Communicate-P: Developing and implementing activities to enable organizations and individuals to understand how personal data is processed. Includes deploying transparent, just-in-time notices, verifiable consent capture, and communication channels for data subject inquiries.
  5. Protect-P: Developing and implementing data protection safeguards to prevent cybersecurity-related privacy events (e.g., unauthorized data breaches). Includes identity management, access control, network segmentation, and encryption.
+-----------------------------------------------------------------------------------------+
|                              NIST PRIVACY FRAMEWORK FUNCTIONS                           |
+-----------------+-----------------+-----------------+-----------------+-----------------+
|   Identify-P    |    Govern-P     |    Control-P    |  Communicate-P  |    Protect-P    |
| - Inventories   | - Risk appetite | - Data mgmt     | - Notices       | - Encryption    |
| - Data actions  | - Privacy roles | - Retention     | - Consent logs  | - Access control|
| - Harm analysis | - Monitoring    | - Disassociation| - Transparency  | - Security ops  |
+-----------------+-----------------+-----------------+-----------------+-----------------+

Problematic Data Actions vs. Cybersecurity Incidents

A critical distinction in the NIST Privacy Framework is the definition of privacy risk:

  • Cybersecurity Risk: Arises from a loss of confidentiality, integrity, or availability caused by an unauthorized event (e.g., a SQL injection vulnerability exploited by an attacker).
  • Privacy Risk: Can arise as a byproduct of data processing itself. NIST defines a problematic data action as "a data action that could cause an adverse effect for individuals." NIST's illustrative catalog lists nine problematic data actions (appropriation, distortion, induced disclosure, insecurity, re-identification, stigmatization, surveillance, unanticipated revelation, and unwarranted restriction) and the problems they cause: dignity loss, discrimination, economic loss, loss of self-determination (loss of autonomy, loss of liberty, physical harm), and loss of trust.

Crucially, problematic data actions frequently occur when the system operates in full compliance with security policies and without any security incident occurring.


FAIR: Quantitative Risk Analysis Applied to Privacy

Traditional enterprise risk assessments rely on qualitative "heat maps" (e.g., scoring risk as High, Medium, or Low). Qualitative matrices suffer from subjective bias, inconsistent scoring across teams, and difficulty justifying control spending to executives.

Factor Analysis of Information Risk (FAIR) is a quantitative risk ontology published as the Open Group's Open FAIR standard and promoted by the FAIR Institute. Privacy engineers, notably R. Jason Cronk and Stuart Shapiro, have adapted FAIR to privacy: the "threat event" becomes a problematic data action and the loss analysis includes the harm to individuals, not only the cost to the organization. This adaptation is often called FAIR privacy analysis.

The Structure of a FAIR Analysis

FAIR expresses risk as a probability distribution of loss over a stated period (typically one year):

Risk=Loss Event Frequency×Loss Magnitude\text{Risk} = \text{Loss Event Frequency} \times \text{Loss Magnitude}

  1. Loss Event Frequency (LEF): How often a loss event is expected, derived from Threat Event Frequency (how often the triggering action occurs) and Vulnerability (the probability that the action results in loss).
  2. Loss Magnitude (LM): How large the loss is when it happens, usually estimated as a range (minimum, most likely, maximum) and simulated.

Primary vs. Secondary Loss and the Six Forms of Loss

Open FAIR separates primary loss, which the primary stakeholder (the organization) suffers directly from the event, from secondary loss, which arises when secondary stakeholders (customers, regulators, courts, partners) react to it. It then classifies every loss into six forms of loss:

Form of LossTypical Privacy ExampleUsually Primary or Secondary
ProductivityEngineers diverted to emergency deletion workPrimary
ResponseForensics, legal counsel, notification letters, call centersPrimary (and secondary when driven by stakeholders)
ReplacementRe-issuing credentials or rebuilding a compromised data storePrimary
Fines and JudgmentsGDPR fines (up to 4% of worldwide annual turnover or EUR 20 million), class-action settlementsSecondary
Competitive AdvantageLoss of proprietary data or modelsSecondary
ReputationCustomers and partners leave after a privacy scandalSecondary

FAIR privacy analysis adds a step standard FAIR leaves out: it estimates the frequency and magnitude of harm to individuals (for example, using NIST's problem categories or Calo's harm dimensions), so that a processing activity that is cheap for the organization but harmful to people is not scored as "low risk." Quantified output (for example, "a 15% annual probability of a $4.2 million loss from SDK location aggregation") lets engineering leadership compare mitigation costs with expected loss.


NIST and NICE: Frameworks for Organizing People and Activities

The NIST Privacy Framework (above) organizes activities. The NICE Workforce Framework for Cybersecurity (NIST SP 800-181 Rev. 1, November 2020; its components were updated to version 2.0.0 in March 2025) organizes people: it defines work roles, competency areas, and Task, Knowledge, and Skill (TKS) statements, including roles such as privacy compliance. NIST has also been developing a Privacy Workforce Taxonomy keyed to the Privacy Framework. Together they help a privacy technologist answer "who is responsible for this control, and what skills do they need?" when building a privacy engineering program. NIST frameworks also connect to one another: the Privacy Framework shares its structure with the Cybersecurity Framework, so a single program can cover both the Protect-P outcomes and security outcomes without duplicating work.

Choosing the Right Lens on the Exam

Scenario CueBest-Fitting Model or Framework
"The data moved to a new recipient under different conditions"Contextual integrity
"Users feel watched and change their behavior"Calo's subjective harm
"Combining datasets revealed new facts"Solove's aggregation (information processing)
"Organize the program into functions and outcomes"NIST Privacy Framework
"Put a dollar range on the risk"FAIR
"Principles such as purpose specification and use limitation"OECD Guidelines / FIPPs
"Define roles and skills for the privacy team"NICE Framework / NIST Privacy Workforce Taxonomy
Test Your Knowledge

An analytics startup merges an encrypted database of customer supermarket purchases with a commercial vehicle toll-tag dataset. By matching purchase timestamps with highway exit records, engineers construct detailed weekly behavioral profiles of specific users without their consent. Under Daniel Solove's Taxonomy of Privacy, which specific harm categories have occurred?

A

Insecurity and Intrusion

B

Surveillance and Blackmail

C

Interrogation and Appropriation

D

Aggregation and Secondary Use

Test Your Knowledge

According to the NIST Privacy Framework, how does a 'problematic data action' creating privacy risk fundamentally differ from a conventional cybersecurity incident?

A

A problematic data action only applies to non-profit entities, whereas cybersecurity incidents apply to commercial enterprises.

B

A problematic data action requires physical theft of server hardware, whereas a cybersecurity incident is always strictly digital in nature.

C

It can arise from authorized processing that harms people, while a cybersecurity incident involves unauthorized loss of confidentiality, integrity, or availability.

D

A problematic data action occurs only when an unpatched zero-day vulnerability is exploited by an external threat actor against the system.

Test Your Knowledge

A fitness app shares users' heart-rate data with their own doctors when users request it. The company now proposes sending the same data to a life insurer that will use it to set premiums. Which model most directly explains why the new flow raises a privacy problem even though the data itself has not changed?

A

Contextual integrity, because the recipient and the conditions of the flow change

B

The NIST Cybersecurity Framework, because the insurer may protect the data with weaker encryption than the doctors' systems

C

The OECD data quality principle, because consumer-grade heart-rate readings may be inaccurate for underwriting

D

FAIR, because the loss event frequency of a breach increases with the number of recipients

Test Your Knowledge

After a company installs visible ceiling cameras with analytics in its open-plan office, employees stop holding candid conversations at their desks, although the footage has never been reviewed or misused. Which harm does Ryan Calo's framework identify here?

A

Objective privacy harm, the unanticipated use of information against a person

B

Subjective privacy harm, the perception of unwanted observation that changes behavior

C

Distortion, the dissemination of inaccurate information about a person

D

Breach of confidentiality, the disclosure of information shared in trust

Sections you finish are checked off in the contents.