Control statement
For systems that process information that will be maintained in a Privacy Act system of records:
- a.Draft system of records notices in accordance with OMB guidance and submit new and significantly modified system of records notices to the OMB and appropriate congressional committees for advance review;
- b.Publish system of records notices in the Federal Register; and
- c.Keep system of records notices accurate, up-to-date, and scoped in accordance with policy.
Discussion
The [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) requires that federal agencies publish a system of records notice in the Federal Register upon the establishment and/or modification of a [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) system of records. As a general matter, a system of records notice is required when an agency maintains a group of any records under the control of the agency from which information is retrieved by the name of an individual or by some identifying number, symbol, or other identifier. The notice describes the existence and character of the system and identifies the system of records, the purpose(s) of the system, the authority for maintenance of the records, the categories of records maintained in the system, the categories of individuals about whom records are maintained, the routine uses to which the records are subject, and additional details about the system as described in [OMB A-108](#3671ff20-c17c-44d6-8a88-7de203fa74aa).
From control text to operational evidence
Use System of Records Notice as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to privacy authority, purpose, transparency, consent, individual rights, and data-processing governance.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- privacy notices and consent records
- authority and purpose documentation
- data-processing inventories
- individual request and redress records
Common failure patterns
- collection justified by convenience rather than authority
- notices do not reflect actual processing
- secondary use expands without review
- retention and deletion commitments not enforced
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- PT-06a.
- PT-06a.[01]system of records notices are drafted in accordance with OMB guidance for systems that process information that will be maintained in a Privacy Act system of records;
- PT-06a.[02]new and significantly modified system of records notices are submitted to the OMB and appropriate congressional committees for advance review for systems that process information that will be maintained in a Privacy Act system of records;
- PT-06b.system of records notices are published in the Federal Register for systems that process information that will be maintained in a Privacy Act system of records;
- PT-06c.system of records notices are kept accurate, up-to-date, and scoped in accordance with policy for systems that process information that will be maintained in a Privacy Act system of records.
Examine
- Personally identifiable information processing and transparency policy and procedures
- privacy notice
- Privacy Act system of records
- Federal Register notices
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with personally identifiable information processing and transparency responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Organizational processes for Privacy Act system of records maintenance
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
PT-6(1) — Routine Uses
Review all routine uses published in the system of records notice at [Organization-defined: frequency] to ensure continued accuracy, and to ensure that routine uses continue to be compatible with the purpose for which the information was collected.
Official discussion
A [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) routine use is a particular kind of disclosure of a record outside of the federal agency maintaining the system of records. A routine use is an exception to the [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) prohibition on the disclosure of a record in a system of records without the prior written consent of the individual to whom the record pertains. To qualify as a routine use, the disclosure must be for a purpose that is compatible with the purpose for which the information was originally collected. The [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) requires agencies to describe each routine use of the records maintained in the system of records, including the categories of users of the records and the purpose of the use. Agencies may only establish routine uses by explicitly publishing them in the relevant system of records notice.
Organization-defined parameters (1)
Assessment objectives and methods
all routine uses published in the system of records notice are reviewed [Organization-defined: frequency] to ensure continued accuracy, and to ensure that routine uses continue to be compatible with the purpose for which the information was collected.
Examine
- Personally identifiable information processing and transparency policy and procedures
- privacy notice
- Privacy Act system of records
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with personally identifiable information processing and transparency responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Organizational processes for reviewing system of records notices
PT-6(2) — Exemption Rules
Review all Privacy Act exemptions claimed for the system of records at [Organization-defined: frequency] to ensure they remain appropriate and necessary in accordance with law, that they have been promulgated as regulations, and that they are accurately described in the system of records notice.
Official discussion
The [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) includes two sets of provisions that allow federal agencies to claim exemptions from certain requirements in the statute. In certain circumstances, these provisions allow agencies to promulgate regulations to exempt a system of records from select provisions of the [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) . At a minimum, organizations’ [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) exemption regulations include the specific name(s) of any system(s) of records that will be exempt, the specific provisions of the [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) from which the system(s) of records is to be exempted, the reasons for the exemption, and an explanation for why the exemption is both necessary and appropriate.
Organization-defined parameters (1)
Assessment objectives and methods
- PT-06(02)[01]all Privacy Act exemptions claimed for the system of records are reviewed [Organization-defined: frequency] to ensure that they remain appropriate and necessary in accordance with law;
- PT-06(02)[02]all Privacy Act exemptions claimed for the system of records are reviewed [Organization-defined: frequency] to ensure that they have been promulgated as regulations;
- PT-06(02)[03]all Privacy Act exemptions claimed for the system of records are reviewed [Organization-defined: frequency] to ensure that they are accurately described in the system of records notice.
Examine
- Personally identifiable information processing and transparency policy and procedures
- privacy notice
- Privacy Act system of records
- Privacy Act exemptions
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with personally identifiable information processing and transparency responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Organizational processes for Privacy Act system of records maintenance
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.