# PM-20 Dissemination of Privacy Program Information

NIST SP 800-53 control. Family: PM Program Management. Function: preventative. Baselines: privacy. Mapping licence: CC BY-SA 4.0.

Statement: Maintain a central resource webpage on the organization’s principal public website that serves as a central source of information about the organization’s privacy program and that: a. Ensures that the public has access to information about organizational privacy activities and can communicate with its senior agency official for privacy; b. Ensures that organizational privacy practices and reports are publicly available; and c. Employs publicly facing email addresses and/or phone lines to enable the public to provide feedback and/or direct questions to privacy offices regarding privacy practices.
Guidance: For federal agencies, the webpage is located at www.[agency].gov/privacy. Federal agencies include public privacy impact assessments, system of records notices, computer matching notices and agreements, [PRIVACT] exemption and implementation rules, privacy reports, privacy policies, instructions for individuals making an access or amendment request, email addresses for questions/complaints, blogs, and periodic publications.

## Enhancements (1)
- PM-20(01) Privacy Policies on Websites, Applications, and Digital Services. Baselines: privacy
Each enhancement's statement: /api/v1/controls/PM-20?fields=enhancements

## Clauses by framework (7 frameworks)
- bot_cyber: Ch9.2
- eba_ict: 3.8(a)
- fda_cyber: TR-1
- hitrust_csf: 13.a, 13.b
- lloyds_ms: MS7.1
- naic_ds: 6-b
- dpdpa: Act.6(3), Act.8(9), Rules.9, Rules.14(1)-(2), Rules.14(3), Rules.Sch2

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PM-20
- Clauses only: /api/v1/controls/PM-20?fields=mappings
- Page for people: /controls/pm-20/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
