Integrated Data Privacy Capability Model
The Integrated Data Privacy Capability Model is a set of open-source standards published by OCEG to help organizations design, operate, and assess their approach to protecting personal data. It offers step-by-step guidance that organizations can adapt to their own circumstances rather than a one-size-fits-all rulebook. It is intended to bring privacy activities together with broader governance, management, and assurance efforts.
The Integrated Data Privacy Capability Model is a capability model developed by OCEG that establishes standards from which an organization may customize its approach to data privacy governance, management, and assurance. Distributed as a free, open-source resource, it provides guidance on designing, running, and assessing a data privacy program, and is positioned to integrate privacy with related disciplines including governance, strategy, performance, risk, compliance, ethics, security, and audit. As a capability model, it defines standards and guidance for building and evaluating an organization's privacy program rather than prescribing specific legal requirements; jurisdiction-specific and sector-specific privacy obligations, implementation tooling, and legal advice fall outside its scope. A related credential, the Integrated Data Privacy Professional (IDPP) certification, is offered by OCEG in connection with the Model.
Why it matters
Data privacy programs frequently develop in isolation from an organization's broader governance, risk, and compliance structures, leaving privacy activities disconnected from strategy, security, ethics, and assurance. This fragmentation can create gaps where personal data is not adequately protected and where accountability for privacy outcomes is unclear. The Integrated Data Privacy Capability Model addresses this by offering a set of standards that organizations can adapt to bring privacy into alignment with related disciplines rather than treating it as a standalone compliance exercise.
Because the Model is distributed as a free, open-source resource, it lowers the barrier for organizations of varying sizes and sectors to establish or evaluate a structured approach to privacy governance, management, and assurance. According to OCEG, the Model is designed to help organizations avoid the types of problems that Drizly appears to have had, illustrating the practical intent behind an integrated rather than siloed approach.
It is important to note what the Model does not do. As a capability model, it defines standards and guidance for designing, running, and assessing a privacy program; it does not prescribe specific legal requirements. Jurisdiction-specific and sector-specific privacy obligations, implementation tooling, and legal advice fall outside its scope, so organizations should continue to consult applicable laws and qualified advisors alongside adopting the Model.
Who it's relevant to
Inside Integrated Data Privacy Capability Model
Common questions
Answers to the questions practitioners most commonly ask about Integrated Data Privacy Capability Model.