Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIST 800-53 privacy controls explained

NIST 800-53 Privacy Controls: The 8 PT Controls Explained (2026)

The NIST 800-53 privacy controls live mainly in one family that did not exist before Revision 5: PT, Personally Identifiable Information Processing and Transparency — eight base controls and thirteen enhancements covering the authority to process PII, the purposes of processing, consent, privacy notice, system of records notices, special categories of PII and computer matching. PT is unusual among the twenty families in three ways. Its controls are not allocated to the low, moderate or high security baselines at all; they are selected through the privacy baseline in SP 800-53B, which applies regardless of impact level whenever a system processes PII. It replaced the Appendix J privacy controls of Revision 4, which had sat outside the catalogue proper. And it is only part of the privacy picture, because Rev 5 also marked privacy-relevant controls across other families — the PM-18 to PM-27 privacy programme controls, RA-8 privacy impact assessments, SI-18 PII quality operations and SI-19 de-identification among them. This guide sets out every PT control and enhancement, the privacy baseline allocation, the privacy controls outside PT, how the family maps to GDPR-style obligations, and how to implement it in a system that has only ever run the security baselines.

NIST 800-53 privacy controls: the PT family
PT-1 policy · PT-2 authority to process · PT-3 processing purposes · PT-4 consent · PT-5 privacy notice · PT-6 system of records notice · PT-7 specific categories of PII · PT-8 computer matching — 8 controls, 13 enhancements; selected via the 800-53B privacy baseline, never via the security baselines.

The eight NIST 800-53 privacy controls in the PT family

Control Title What it requires (condensed)
PT-1 Policy and Procedures Develop, document and disseminate a PII processing and transparency policy — organisation, mission or system level — addressing purpose, scope, roles, responsibilities, management commitment, coordination and compliance, consistent with applicable law; procedures to implement it; a designated official; review and update at defined frequencies and events
PT-2 Authority to Process Personally Identifiable Information Determine and document the authority that permits the processing of PII, and restrict processing to what is authorised
PT-3 Personally Identifiable Information Processing Purposes Identify and document the purposes for processing; describe them in public notices and policies; restrict processing to what is compatible with the purposes; monitor changes in processing and implement mechanisms to ensure it stays compatible
PT-4 Consent Implement tools or mechanisms for individuals to consent to processing before collection, facilitating informed decision-making
PT-5 Privacy Notice Provide notice at first interaction and at a defined frequency; clear and plain language; identifying the authority, the purposes, the types of PII and the elements processed, and other defined content
PT-6 System of Records Notice For Privacy Act systems of records: draft SORNs per OMB guidance, submit new and significantly modified ones to OMB and Congress for advance review, publish in the Federal Register, keep accurate and current
PT-7 Specific Categories of Personally Identifiable Information Apply defined processing conditions for specific categories of PII
PT-8 Computer Matching Requirements For matching programmes: Data Integrity Board approval, a computer matching agreement, a Federal Register notice, independent verification before adverse action, and notice and an opportunity to contest

NIST 800-53 privacy controls: the thirteen PT enhancements and the privacy baseline

Enhancement Title In the privacy baseline?
PT-2(1) Data Tagging — attach tags that carry authority to process No
PT-2(2) Automation — manage enforcement of authorised processing with automated mechanisms No
PT-3(1) Data Tagging — tags carrying processing purposes No
PT-3(2) Automation — automated enforcement of purpose compatibility No
PT-4(1) Tailored Consent — options tailored to the type and processing of PII No
PT-4(2) Just-in-Time Consent — consent presented at the point of processing No
PT-4(3) Revocation — mechanisms to revoke consent No
PT-5(1) Just-in-Time Notice — notice at the point of collection or processing No
PT-5(2) Privacy Act Statements — statements where PII is collected under the Privacy Act Yes
PT-6(1) Routine Uses — review routine uses at a defined frequency Yes
PT-6(2) Exemption Rules — review exemption rules at a defined frequency Yes
PT-7(1) Social Security Numbers — eliminate unnecessary collection, use and display; alternatives Yes
PT-7(2) First Amendment Information — prohibit processing describing how individuals exercise First Amendment rights unless authorised Yes

All eight base controls and the five enhancements marked are in the 800-53B privacy baseline, which is selected on the basis of whether the system processes PII, not on impact level; the PT table in 800-53B states that PT controls “are not allocated to the security control baselines”. A federal system at any impact level that processes PII carries the thirteen privacy-baseline items; a non-federal adopter drops PT-6, PT-8 and the Privacy Act enhancements and keeps the rest. Our guide to the NIST 800-53 control families covers where PT sits among the twenty.

NIST 800-53 privacy controls outside the PT family

Control Family What it does for privacy
PM-18 to PM-27 Program Management Privacy programme plan, privacy programme leadership role, dissemination of privacy programme information, accounting of disclosures, PII quality management, data governance body, data integrity board, minimisation of PII used in testing, training and research, complaint management, privacy reporting
RA-8 Risk Assessment Privacy impact assessments for systems, programmes and activities that process PII
RA-3 Risk Assessment Risk assessment now includes privacy risk
SI-18 System and Information Integrity PII quality operations: accuracy, relevance, timeliness, completeness; correction; individual requests
SI-19 System and Information Integrity De-identification of PII, with enhancements for collection, archiving, release, removal and re-identification risk
SI-12 System and Information Integrity Information management and retention, including limiting PII elements and minimising PII in testing
AC-3(14) Access Control Individual access to their own PII
IR-8(1) Incident Response Breaches — the incident response plan addresses PII breaches
SA-8(33) System and Services Acquisition Minimisation as a privacy engineering principle
CM-4, CA-2, CA-7 Various Privacy impact analysis of changes; privacy control assessments; continuous monitoring of privacy controls

The privacy baseline draws from these families as well as PT, which is why Rev 5 could integrate privacy into the catalogue rather than keep it as an appendix. Our guide to NIST 800-53 Rev 5 vs Rev 4 covers the move from Appendix J.

Mapping the NIST 800-53 privacy controls to other frameworks

PT control GDPR NIST Privacy Framework 1.0 ISO/IEC 27701:2025
PT-2 Authority to process Article 6 lawful basis; Article 9 special categories Govern-P: legal requirements Determination of lawful basis
PT-3 Processing purposes Article 5(1)(b) purpose limitation; Article 6(4) compatibility Control-P: data processing management Purpose identification and limitation
PT-4 Consent Articles 7–8 consent and children’s consent Control-P: consent mechanisms Consent obtaining and recording
PT-5 Privacy notice Articles 12–14 transparency and information Communicate-P: transparency Information provided to PII principals
PT-7 Specific categories Article 9 special categories; Article 87 national identification numbers Govern-P: risk assessment for sensitive data Special categories controls
PT-6 SORN, PT-8 Computer matching No equivalent (US Privacy Act)

Implementing the PT family in a security-only programme

  1. Decide whether the system processes PII. That question, not the impact level, triggers the privacy baseline. Record the determination in the SSP either way.
  2. Write PT-1 as a policy, not a paragraph. Purpose, scope, roles, management commitment, coordination, compliance — the same seven elements as every -1 control — plus the procedures and a review cycle.
  3. Document authority and purposes (PT-2, PT-3). A register: for each processing operation, the legal or policy authority and the purpose, with a compatibility check when processing changes. This register is also the GDPR Article 30 record for organisations that need one.
  4. Design consent and notice together (PT-4, PT-5). Notice at first interaction and on a schedule; consent before collection where consent is the authority; just-in-time variants where the enhancements apply.
  5. Set conditions for special categories (PT-7). SSNs, health, biometric, children’s and First Amendment data get named processing conditions; PT-7(1) requires eliminating unnecessary SSN use outright.
  6. Apply the federal-only controls where they apply (PT-6, PT-8). SORNs and computer matching belong to Privacy Act agencies; non-federal adopters mark them not applicable with the reason.
  7. Assess under 800-53A. The PT procedures test the register, the notices, the consent mechanism and the conditions; 800-53A lets an assessor disregard a privacy statement on a system without PII and still find the control satisfied, provided the inapplicability is recorded. Our guide to NIST 800-53A covers the method.

Frequently asked questions

What are the NIST 800-53 privacy controls?
Principally the PT family — PII Processing and Transparency — added in Rev 5: eight base controls (PT-1 to PT-8) and thirteen enhancements covering policy, authority to process, purposes, consent, notice, system of records notices, specific categories of PII and computer matching. Privacy-relevant controls also sit in PM (PM-18 to PM-27), RA-8, SI-18, SI-19 and elsewhere.

Are PT controls in the moderate baseline?
No. PT controls are not allocated to the low, moderate or high security baselines. They are selected through the 800-53B privacy baseline, which applies regardless of impact level to systems that process PII.

Which PT items are in the privacy baseline?
All eight base controls plus PT-5(2) Privacy Act Statements, PT-6(1) Routine Uses, PT-6(2) Exemption Rules, PT-7(1) Social Security Numbers and PT-7(2) First Amendment Information — thirteen items.

Do PT controls apply outside the US federal government?
PT-1 to PT-5 and PT-7 apply to any organisation processing PII and map closely to GDPR lawful basis, purpose limitation, consent, transparency and special categories. PT-6 and PT-8 implement the US Privacy Act and are marked not applicable elsewhere.

What replaced Rev 4 Appendix J?
The PT family plus privacy-relevant controls integrated across the catalogue — PM-18 to PM-27, RA-8, SI-18, SI-19, AC-3(14), IR-8(1) and others — and a privacy baseline in SP 800-53B.

Where this leaves you

Treat the NIST 800-53 privacy controls as a second baseline that a PII determination switches on: implement PT-1 to PT-5 and PT-7 as a processing register, a notice-and-consent design and named conditions for special categories, add the PM, RA and SI privacy controls the privacy baseline pulls in, mark the Privacy Act controls not applicable with reasons if you are not a federal agency — and assess them under 800-53A like every other family, because Rev 5 made privacy part of the catalogue and the assessor will read it that way.

References

More on NIST 800-53

The PII Processing and Transparency Policy, the processing authority and purpose register, the privacy notice and consent templates, the special-categories conditions and the privacy baseline implementation matrix are in the NIST SP 800-53 Security Controls Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.