← Controls / PM

PM-20 Dissemination of Privacy Program Information

Program Management

Privacy New in Rev 5

Description

Maintain a central resource webpage on the organization’s principal public website that serves as a central source of information about the organization’s privacy program and that: a. Ensures that the public has access to information about organizational privacy activities and can communicate with its senior agency official for privacy; b. Ensures that organizational privacy practices and reports are publicly available; and c. Employs publicly facing email addresses and/or phone lines to enable the public to provide feedback and/or direct questions to privacy offices regarding privacy practices.

Supplemental Guidance

For federal agencies, the webpage is located at www.[agency].gov/privacy. Federal agencies include public privacy impact assessments, system of records notices, computer matching notices and agreements, [PRIVACT] exemption and implementation rules, privacy reports, privacy policies, instructions for individuals making an access or amendment request, email addresses for questions/complaints, blogs, and periodic publications.

Changes from Rev 4

New control in Rev 5. Public transparency for privacy programs.

Enhancements (1)

What NIST adds to this control. Select one to read its statement.

PM-20(01) Privacy Policies on Websites, Applications, and Digital Services Privacy

Develop and post privacy policies on all external-facing websites, mobile applications, and other digital services, that: a. Are written in plain language and organized in a way that is easy to understand and navigate; b. Provide information needed by the public to make an informed decision about whether and how to interact with the organization; and c. Are updated whenever the organization makes a substantive change to the practices it describes and includes a time/date stamp to inform the public of the date of the most recent changes.

Compliance Mappings

EBA ICT Guidelines

3.8(a)

BOT Cyber Resilience

Ch9.2

Lloyd's Minimum Standards

MS7.1

NAIC Insurance Data Security

6-b

HITRUST CSF v11

13.a13.b

FDA Cybersecurity Guidance

TR-1

India DPDPA

Act.6(3)Act.8(9)Rules.9Rules.14(1)-(2)Rules.14(3)Rules.Sch2