# PM-19 Privacy Program Leadership Role

NIST SP 800-53 control. Family: PM Program Management. Function: preventative. Baselines: privacy. Mapping licence: CC BY-SA 4.0.

Statement: Appoint a senior agency official for privacy with the authority, mission, accountability, and resources to coordinate, develop, and implement, applicable privacy requirements and manage privacy risks through the organization-wide privacy program.
Guidance: The privacy officer is an organizational official. For federal agencies—as defined by applicable laws, executive orders, directives, regulations, policies, standards, and guidelines—this official is designated as the senior agency official for privacy. Organizations may also refer to this official as the chief privacy officer. The senior agency official for privacy also has roles on the data management board (see PM-23) and the data integrity board (see PM-24).

## Clauses by framework (3 frameworks)
- nist_csf_2: GV.OV-02, GV.RR-01, GV.RR-02, GV.SC-09
- hitrust_csf: 13.a
- dpdpa: Act.8(1), Act.8(4), Act.8(9), Act.10(2)(a), Rules.9, Rules.Sch2
OSA's mapping for nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PM-19
- Clauses only: /api/v1/controls/PM-19?fields=mappings
- Page for people: /controls/pm-19/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
