Control statement
Maintain a central resource webpage on the organization’s principal public website that serves as a central source of information about the organization’s privacy program and that:
- a.Ensures that the public has access to information about organizational privacy activities and can communicate with its senior agency official for privacy;
- b.Ensures that organizational privacy practices and reports are publicly available; and
- c.Employs publicly facing email addresses and/or phone lines to enable the public to provide feedback and/or direct questions to privacy offices regarding privacy practices.
Discussion
For federal agencies, the webpage is located at www.[agency].gov/privacy. Federal agencies include public privacy impact assessments, system of records notices, computer matching notices and agreements, [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) exemption and implementation rules, privacy reports, privacy policies, instructions for individuals making an access or amendment request, email addresses for questions/complaints, blogs, and periodic publications.
From control text to operational evidence
Use Dissemination of Privacy Program Information as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to enterprise program governance, accountability, resources, metrics, and organization-wide risk decisions.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- program charters and policies
- governance meeting records
- risk and performance metrics
- resource and responsibility assignments
Common failure patterns
- program metrics count activity instead of outcomes
- system-level risks never reach enterprise governance
- responsibilities assigned without authority or resources
- privacy and security managed in separate silos
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- PM-20[01]a central resource webpage is maintained on the organization’s principal public website;
- PM-20[02]the webpage serves as a central source of information about the organization’s privacy program;
- PM-20a.
- PM-20a.[01]the webpage ensures that the public has access to information about organizational privacy activities;
- PM-20a.[02]the webpage ensures that the public can communicate with its senior agency official for privacy;
- PM-20b.
- PM-20b.[01]the webpage ensures that organizational privacy practices are publicly available;
- PM-20b.[02]the webpage ensures that organizational privacy reports are publicly available;
- PM-20c.the webpage employs publicly facing email addresses and/or phone numbers to enable the public to provide feedback and/or direct questions to privacy offices regarding privacy practices.
Examine
- Public website
- publicly posted privacy program documents, including policies, procedures, plans, and reports
- position description of the senior agency official for privacy
- public privacy notices, including Federal Register notices
- privacy impact assessments
- privacy risk assessments
- Privacy Act statements and system of records notices
- computer matching agreements and notices
- other relevant documents or records
Interview
- Organizational personnel with privacy program information dissemination responsibilities
- organizational personnel with privacy responsibilities
Test
- Location, access, availability, and functionality of privacy resource webpage
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
PM-20(1) — Privacy Policies on Websites, Applications, and Digital Services
Develop and post privacy policies on all external-facing websites, mobile applications, and other digital services, that:
- (a)Are written in plain language and organized in a way that is easy to understand and navigate;
- (b)Provide information needed by the public to make an informed decision about whether and how to interact with the organization; and
- (c)Are updated whenever the organization makes a substantive change to the practices it describes and includes a time/date stamp to inform the public of the date of the most recent changes.
Official discussion
Organizations post privacy policies on all external-facing websites, mobile applications, and other digital services. Organizations post a link to the relevant privacy policy on any known, major entry points to the website, application, or digital service. In addition, organizations provide a link to the privacy policy on any webpage that collects personally identifiable information. Organizations may be subject to applicable laws, executive orders, directives, regulations, or policies that require the provision of specific information to the public. Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such requirements.
Assessment objectives and methods
- PM-20(01)[01]privacy policies are developed and posted on all external-facing websites;
- PM-20(01)[02]privacy policies are developed and posted on all mobile applications;
- PM-20(01)[03]privacy policies are developed and posted on all other digital services;
- PM-20(01)(a)
- PM-20(01)(a)[01]the privacy policies are written in plain language;
- PM-20(01)(a)[02]the privacy policies are organized in a way that is easy to understand and navigate;
- PM-20(01)(b)
- PM-20(01)(b)[01]the privacy policies provide the information needed by the public to make an informed decision about whether to interact with the organization;
- PM-20(01)(b)[02]the privacy policies provide the information needed by the public to make an informed decision about how to interact with the organization;
- PM-20(01)(c)
- PM-20(01)(c)[01]the privacy policies are updated whenever the organization makes a substantive change to the practices it describes;
- PM-20(01)(c)[02]the privacy policies include a time/date stamp to inform the public of the date of the most recent changes.
Examine
- Privacy program plan
- privacy policies on the agency website, mobile applications, and/or other digital services
Interview
- Organizational personnel with privacy program information dissemination responsibilities
- organizational personnel with privacy responsibilities
Test
- Organizational procedures and practices for authorizing, conducting, managing, and reviewing personally identifiable information processing
- organizational procedures and practices for disseminating privacy program information
- mechanisms supporting the dissemination of privacy program information
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.