Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

PT-3 — Personally Identifiable Information Processing Purposes

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

2Enhancements
4Parameters
1Baseline memberships
3Assessment methods

PT — Personally Identifiable Information Processing and Transparency · NIST SP 800-53 Release 5.2.0

Privacy
Official NIST control content

Control statement

  1. a.Identify and document the [Organization-defined: purpose(s)] for processing personally identifiable information;
  2. b.Describe the purpose(s) in the public privacy notices and policies of the organization;
  3. c.Restrict the [Organization-defined: processing] of personally identifiable information to only that which is compatible with the identified purpose(s); and
  4. d.Monitor changes in processing personally identifiable information and implement [Organization-defined: mechanisms] to ensure that any changes are made in accordance with [Organization-defined: requirements].
Official NIST discussion

Discussion

Identifying and documenting the purpose for processing provides organizations with a basis for understanding why personally identifiable information may be processed. The term "process" includes every step of the information life cycle, including creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposal. Identifying and documenting the purpose of processing is a prerequisite to enabling owners and operators of the system and individuals whose information is processed by the system to understand how the information will be processed. This enables individuals to make informed decisions about their engagement with information systems and organizations and to manage their privacy interests. Once the specific processing purpose has been identified, the purpose is described in the organization’s privacy notices, policies, and any related privacy compliance documentation, including privacy impact assessments, system of records notices, [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) statements, computer matching notices, and other applicable Federal Register notices. Organizations take steps to help ensure that personally identifiable information is processed only for identified purposes, including training organizational personnel and monitoring and auditing organizational processing of personally identifiable information. Organizations monitor for changes in personally identifiable information processing. Organizational personnel consult with the senior agency official for privacy and legal counsel to ensure that any new purposes that arise from changes in processing are compatible with the purpose for which the information was collected, or if the new purpose is not compatible, implement mechanisms in accordance with defined requirements to allow for the new processing, if appropriate. Mechanisms may include obtaining consent from individuals, revising privacy policies, or other measures to manage privacy risks that arise from changes in personally identifiable information processing purposes.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

purpose(s)the purpose(s) for processing personally identifiable information is/are defined;
processingthe processing of personally identifiable information to be restricted is defined;
mechanismsmechanisms to be implemented for ensuring any changes in the processing of personally identifiable information are made in accordance with requirements are defined;
requirementsrequirements for changing the processing of personally identifiable information are defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Personally Identifiable Information Processing Purposes as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to privacy authority, purpose, transparency, consent, individual rights, and data-processing governance.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • privacy notices and consent records
  • authority and purpose documentation
  • data-processing inventories
  • individual request and redress records

Common failure patterns

  • collection justified by convenience rather than authority
  • notices do not reflect actual processing
  • secondary use expands without review
  • retention and deletion commitments not enforced

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. PT-03a.the [Organization-defined: purpose(s)] for processing personally identifiable information is/are identified and documented;
  2. PT-03b.
    1. PT-03b.[01]the purpose(s) is/are described in the public privacy notices of the organization;
    2. PT-03b.[02]the purpose(s) is/are described in the policies of the organization;
  3. PT-03c.the [Organization-defined: processing] of personally identifiable information are restricted to only that which is compatible with the identified purpose(s);
  4. PT-03d.
    1. PT-03d.[01]changes in the processing of personally identifiable information are monitored;
    2. PT-03d.[02][Organization-defined: mechanisms] are implemented to ensure that any changes are made in accordance with [Organization-defined: requirements].

Examine

  • Personally identifiable information processing and transparency policy and procedures
  • configuration management plan
  • organizational privacy notices
  • organizational policies
  • Privacy Act statements
  • computer matching notices
  • applicable Federal Register notices
  • documented requirements for enforcing and monitoring the processing of personally identifiable information
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with personally identifiable information processing and transparency responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for authorizing the processing of personally identifiable information
  • mechanisms supporting and/or implementing the management of authorized personally identifiable information processing
  • organizational processes for monitoring changes in processing personally identifiable information
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

PT-3(1) — Data Tagging

Attach data tags containing the following purposes to [Organization-defined: elements of personally identifiable information]: [Organization-defined: processing purposes].

Official discussion

Data tags support the tracking of processing purposes by conveying the purposes along with the relevant elements of personally identifiable information throughout the system. By conveying the processing purposes in a data tag along with the personally identifiable information as the information transits a system, a system owner or operator can identify whether a change in processing would be compatible with the identified and documented purposes. Data tags may also support the use of automated tools.

Organization-defined parameters (2)
processing purposesprocessing purposes to be contained in data tags are defined;
elements of personally identifiable informationelements of personally identifiable information to be tagged are defined;
Assessment objectives and methods

data tags containing [Organization-defined: processing purposes] are attached to [Organization-defined: elements of personally identifiable information].

Examine

  • Personally identifiable information processing and transparency policy and procedures
  • documented description of how data tags are used to identify personally identifiable information data elements and their authorized uses
  • data tag schema
  • data extracts with corresponding data tags
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with personally identifiable information processing and transparency responsibilities
  • organizational personnel with data tagging responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for authorizing the processing of personally identifiable information
  • mechanisms supporting and/or implementing data tagging
Related controls
Official NIST control enhancement

PT-3(2) — Automation

Track processing purposes of personally identifiable information using [Organization-defined: automated mechanisms].

Official discussion

Automated mechanisms augment tracking of the processing purposes.

Organization-defined parameters (1)
automated mechanismsautomated mechanisms for tracking the processing purposes of personally identifiable information are defined;
Assessment objectives and methods

the processing purposes of personally identifiable information are tracked using [Organization-defined: automated mechanisms].

Examine

  • Personally identifiable information processing and transparency policy and procedures
  • data extracts with corresponding data tags
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with personally identifiable information processing and transparency responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for managing the enforcement of authorized processing of personally identifiable information
  • automated tracking mechanisms
Related controls
Source record

Authoritative sources