The NIST 800-53 privacy controls live mainly in one family that did not exist before Revision 5: PT, Personally Identifiable Information Processing and Transparency — eight base controls and thirteen enhancements covering the authority to process PII, the purposes of processing, consent, privacy notice, system of records notices, special categories of PII and computer matching. PT is unusual among the twenty families in three ways. Its controls are not allocated to the low, moderate or high security baselines at all; they are selected through the privacy baseline in SP 800-53B, which applies regardless of impact level whenever a system processes PII. It replaced the Appendix J privacy controls of Revision 4, which had sat outside the catalogue proper. And it is only part of the privacy picture, because Rev 5 also marked privacy-relevant controls across other families — the PM-18 to PM-27 privacy programme controls, RA-8 privacy impact assessments, SI-18 PII quality operations and SI-19 de-identification among them. This guide sets out every PT control and enhancement, the privacy baseline allocation, the privacy controls outside PT, how the family maps to GDPR-style obligations, and how to implement it in a system that has only ever run the security baselines.

The eight NIST 800-53 privacy controls in the PT family
| Control | Title | What it requires (condensed) |
|---|---|---|
| PT-1 | Policy and Procedures | Develop, document and disseminate a PII processing and transparency policy — organisation, mission or system level — addressing purpose, scope, roles, responsibilities, management commitment, coordination and compliance, consistent with applicable law; procedures to implement it; a designated official; review and update at defined frequencies and events |
| PT-2 | Authority to Process Personally Identifiable Information | Determine and document the authority that permits the processing of PII, and restrict processing to what is authorised |
| PT-3 | Personally Identifiable Information Processing Purposes | Identify and document the purposes for processing; describe them in public notices and policies; restrict processing to what is compatible with the purposes; monitor changes in processing and implement mechanisms to ensure it stays compatible |
| PT-4 | Consent | Implement tools or mechanisms for individuals to consent to processing before collection, facilitating informed decision-making |
| PT-5 | Privacy Notice | Provide notice at first interaction and at a defined frequency; clear and plain language; identifying the authority, the purposes, the types of PII and the elements processed, and other defined content |
| PT-6 | System of Records Notice | For Privacy Act systems of records: draft SORNs per OMB guidance, submit new and significantly modified ones to OMB and Congress for advance review, publish in the Federal Register, keep accurate and current |
| PT-7 | Specific Categories of Personally Identifiable Information | Apply defined processing conditions for specific categories of PII |
| PT-8 | Computer Matching Requirements | For matching programmes: Data Integrity Board approval, a computer matching agreement, a Federal Register notice, independent verification before adverse action, and notice and an opportunity to contest |
NIST 800-53 privacy controls: the thirteen PT enhancements and the privacy baseline
| Enhancement | Title | In the privacy baseline? |
|---|---|---|
| PT-2(1) | Data Tagging — attach tags that carry authority to process | No |
| PT-2(2) | Automation — manage enforcement of authorised processing with automated mechanisms | No |
| PT-3(1) | Data Tagging — tags carrying processing purposes | No |
| PT-3(2) | Automation — automated enforcement of purpose compatibility | No |
| PT-4(1) | Tailored Consent — options tailored to the type and processing of PII | No |
| PT-4(2) | Just-in-Time Consent — consent presented at the point of processing | No |
| PT-4(3) | Revocation — mechanisms to revoke consent | No |
| PT-5(1) | Just-in-Time Notice — notice at the point of collection or processing | No |
| PT-5(2) | Privacy Act Statements — statements where PII is collected under the Privacy Act | Yes |
| PT-6(1) | Routine Uses — review routine uses at a defined frequency | Yes |
| PT-6(2) | Exemption Rules — review exemption rules at a defined frequency | Yes |
| PT-7(1) | Social Security Numbers — eliminate unnecessary collection, use and display; alternatives | Yes |
| PT-7(2) | First Amendment Information — prohibit processing describing how individuals exercise First Amendment rights unless authorised | Yes |
All eight base controls and the five enhancements marked are in the 800-53B privacy baseline, which is selected on the basis of whether the system processes PII, not on impact level; the PT table in 800-53B states that PT controls “are not allocated to the security control baselines”. A federal system at any impact level that processes PII carries the thirteen privacy-baseline items; a non-federal adopter drops PT-6, PT-8 and the Privacy Act enhancements and keeps the rest. Our guide to the NIST 800-53 control families covers where PT sits among the twenty.
NIST 800-53 privacy controls outside the PT family
| Control | Family | What it does for privacy |
|---|---|---|
| PM-18 to PM-27 | Program Management | Privacy programme plan, privacy programme leadership role, dissemination of privacy programme information, accounting of disclosures, PII quality management, data governance body, data integrity board, minimisation of PII used in testing, training and research, complaint management, privacy reporting |
| RA-8 | Risk Assessment | Privacy impact assessments for systems, programmes and activities that process PII |
| RA-3 | Risk Assessment | Risk assessment now includes privacy risk |
| SI-18 | System and Information Integrity | PII quality operations: accuracy, relevance, timeliness, completeness; correction; individual requests |
| SI-19 | System and Information Integrity | De-identification of PII, with enhancements for collection, archiving, release, removal and re-identification risk |
| SI-12 | System and Information Integrity | Information management and retention, including limiting PII elements and minimising PII in testing |
| AC-3(14) | Access Control | Individual access to their own PII |
| IR-8(1) | Incident Response | Breaches — the incident response plan addresses PII breaches |
| SA-8(33) | System and Services Acquisition | Minimisation as a privacy engineering principle |
| CM-4, CA-2, CA-7 | Various | Privacy impact analysis of changes; privacy control assessments; continuous monitoring of privacy controls |
The privacy baseline draws from these families as well as PT, which is why Rev 5 could integrate privacy into the catalogue rather than keep it as an appendix. Our guide to NIST 800-53 Rev 5 vs Rev 4 covers the move from Appendix J.
Mapping the NIST 800-53 privacy controls to other frameworks
| PT control | GDPR | NIST Privacy Framework 1.0 | ISO/IEC 27701:2025 |
|---|---|---|---|
| PT-2 Authority to process | Article 6 lawful basis; Article 9 special categories | Govern-P: legal requirements | Determination of lawful basis |
| PT-3 Processing purposes | Article 5(1)(b) purpose limitation; Article 6(4) compatibility | Control-P: data processing management | Purpose identification and limitation |
| PT-4 Consent | Articles 7–8 consent and children’s consent | Control-P: consent mechanisms | Consent obtaining and recording |
| PT-5 Privacy notice | Articles 12–14 transparency and information | Communicate-P: transparency | Information provided to PII principals |
| PT-7 Specific categories | Article 9 special categories; Article 87 national identification numbers | Govern-P: risk assessment for sensitive data | Special categories controls |
| PT-6 SORN, PT-8 Computer matching | No equivalent (US Privacy Act) | — | — |
Implementing the PT family in a security-only programme
- Decide whether the system processes PII. That question, not the impact level, triggers the privacy baseline. Record the determination in the SSP either way.
- Write PT-1 as a policy, not a paragraph. Purpose, scope, roles, management commitment, coordination, compliance — the same seven elements as every -1 control — plus the procedures and a review cycle.
- Document authority and purposes (PT-2, PT-3). A register: for each processing operation, the legal or policy authority and the purpose, with a compatibility check when processing changes. This register is also the GDPR Article 30 record for organisations that need one.
- Design consent and notice together (PT-4, PT-5). Notice at first interaction and on a schedule; consent before collection where consent is the authority; just-in-time variants where the enhancements apply.
- Set conditions for special categories (PT-7). SSNs, health, biometric, children’s and First Amendment data get named processing conditions; PT-7(1) requires eliminating unnecessary SSN use outright.
- Apply the federal-only controls where they apply (PT-6, PT-8). SORNs and computer matching belong to Privacy Act agencies; non-federal adopters mark them not applicable with the reason.
- Assess under 800-53A. The PT procedures test the register, the notices, the consent mechanism and the conditions; 800-53A lets an assessor disregard a privacy statement on a system without PII and still find the control satisfied, provided the inapplicability is recorded. Our guide to NIST 800-53A covers the method.
Frequently asked questions
What are the NIST 800-53 privacy controls?
Principally the PT family — PII Processing and Transparency — added in Rev 5: eight base controls (PT-1 to PT-8) and thirteen enhancements covering policy, authority to process, purposes, consent, notice, system of records notices, specific categories of PII and computer matching. Privacy-relevant controls also sit in PM (PM-18 to PM-27), RA-8, SI-18, SI-19 and elsewhere.
Are PT controls in the moderate baseline?
No. PT controls are not allocated to the low, moderate or high security baselines. They are selected through the 800-53B privacy baseline, which applies regardless of impact level to systems that process PII.
Which PT items are in the privacy baseline?
All eight base controls plus PT-5(2) Privacy Act Statements, PT-6(1) Routine Uses, PT-6(2) Exemption Rules, PT-7(1) Social Security Numbers and PT-7(2) First Amendment Information — thirteen items.
Do PT controls apply outside the US federal government?
PT-1 to PT-5 and PT-7 apply to any organisation processing PII and map closely to GDPR lawful basis, purpose limitation, consent, transparency and special categories. PT-6 and PT-8 implement the US Privacy Act and are marked not applicable elsewhere.
What replaced Rev 4 Appendix J?
The PT family plus privacy-relevant controls integrated across the catalogue — PM-18 to PM-27, RA-8, SI-18, SI-19, AC-3(14), IR-8(1) and others — and a privacy baseline in SP 800-53B.
Where this leaves you
Treat the NIST 800-53 privacy controls as a second baseline that a PII determination switches on: implement PT-1 to PT-5 and PT-7 as a processing register, a notice-and-consent design and named conditions for special categories, add the PM, RA and SI privacy controls the privacy baseline pulls in, mark the Privacy Act controls not applicable with reasons if you are not a federal agency — and assess them under 800-53A like every other family, because Rev 5 made privacy part of the catalogue and the assessor will read it that way.
References
- NIST SP 800-53 Rev. 5 — Security and Privacy Controls for Information Systems and Organizations — The PT family, PT-1 to PT-8 and enhancements.
- NIST SP 800-53B — Control Baselines for Information Systems and Organizations — Table 3-15 and the privacy control baseline.
- NIST SP 800-53A Rev. 5 — Assessing Security and Privacy Controls — PT assessment procedures.
More on NIST 800-53
- The NIST 800-53 privacy controls — you are here
- NIST SP 800-53: the baselines and Release 5.2.0
- NIST 800-53 control families: all 20
- NIST 800-53 Rev 5 vs Rev 4
- NIST 800-53A: assessment procedures
- NIST 800-53 vs ISO 27001
The PII Processing and Transparency Policy, the processing authority and purpose register, the privacy notice and consent templates, the special-categories conditions and the privacy baseline implementation matrix are in the NIST SP 800-53 Security Controls Toolkit, or start with the free templates.