{"data":{"id":"PM-20","name":"Dissemination of Privacy Program Information","family":"PM","family_name":"Program Management","withdrawn":false,"description":"Maintain a central resource webpage on the organization’s principal public website that serves as a central source of information about the organization’s privacy program and that:\na. Ensures that the public has access to information about organizational privacy activities and can communicate with its senior agency official for privacy;\nb. Ensures that organizational privacy practices and reports are publicly available; and\nc. Employs publicly facing email addresses and/or phone lines to enable the public to provide feedback and/or direct questions to privacy offices regarding privacy practices.","supplemental_guidance":"For federal agencies, the webpage is located at www.[agency].gov/privacy. Federal agencies include public privacy impact assessments, system of records notices, computer matching notices and agreements, [PRIVACT] exemption and implementation rules, privacy reports, privacy policies, instructions for individuals making an access or amendment request, email addresses for questions/complaints, blogs, and periodic publications.","enhancements":[{"id":"PM-20(01)","name":"Privacy Policies on Websites, Applications, and Digital Services","statement":"Develop and post privacy policies on all external-facing websites, mobile applications, and other digital services, that:\na. Are written in plain language and organized in a way that is easy to understand and navigate;\nb. Provide information needed by the public to make an informed decision about whether and how to interact with the organization; and\nc. Are updated whenever the organization makes a substantive change to the practices it describes and includes a time/date stamp to inform the public of the date of the most recent changes.","baselines":["privacy"]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"PM-20","name":"Dissemination of Privacy Program Information","description":"Maintain a central resource webpage on the organization’s principal public website that serves as a central source of information about the organization’s privacy program and that:\na. Ensures that the public has access to information about organizational privacy activities and can communicate with its senior agency official for privacy;\nb. Ensures that organizational privacy practices and reports are publicly available; and\nc. Employs publicly facing email addresses and/or phone lines to enable the public to provide feedback and/or direct questions to privacy offices regarding privacy practices.","discussion":"For federal agencies, the webpage is located at www.[agency].gov/privacy. Federal agencies include public privacy impact assessments, system of records notices, computer matching notices and agreements, [PRIVACT] exemption and implementation rules, privacy reports, privacy policies, instructions for individuals making an access or amendment request, email addresses for questions/complaints, blogs, and periodic publications.","related_controls":["AC-03","PM-19","PT-05","PT-06","PT-07","RA-08"],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":true,"new_in_rev5":true,"changes_from_rev4":"New control in Rev 5. Public transparency for privacy programs."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":[],"rbi_csf":[],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"bot_cyber":["Ch9.2"],"eba_ict":["3.8(a)"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":["TR-1"],"hitrust_csf":["13.a","13.b"],"iso_27799":[],"lloyds_ms":["MS7.1"],"naic_ds":["6-b"],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":["Act.6(3)","Act.8(9)","Rules.9","Rules.14(1)-(2)","Rules.14(3)","Rules.Sch2"]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-02-19","review_notes":"Generated from NIST SP 800-53 Rev 5 with compliance mappings extracted from framework-coverage data","mapping_status":"complete"},"function":"preventative","used_by_patterns":[]}}