PM-21: Accounting of Disclosures

PM-21 requires your organization to track every instance where personally identifiable information (PII) leaves its custody, recording who

Quick-reference card

FieldValue
Control IDPM-21
Control NameAccounting of Disclosures
FrameworkNIST SP 800-53 Revision 5
Control FamilyProgram Management
BaselinesPRIVACY
RelevanceOrganization (First Party)
Risk SeverityMedium

What this control requires

PM-21 requires your organization to track every instance where personally identifiable information (PII) leaves its custody, recording who received it, when, and why. This isn’t a passive record-keeping exercise. It’s an active obligation to maintain a disclosure log that can be produced on demand for the individuals whose data you’ve shared.

Each disclosure entry must capture the date, the nature and purpose of the sharing event, and the recipient’s name and contact information. In practice, this means building a structured system that captures disclosure metadata at the point of transfer rather than reconstructing it after the fact. Most organizations that fail PM-21 audits don’t lack a policy. They lack a mechanism that reliably populates the log before anyone asks to see it.

You’re also required to retain these records for the longer of two periods: the lifespan of the PII itself, or five years from the date of disclosure. That retention commitment directly shapes your data architecture decisions. And when an individual requests their disclosure history, you must be able to assemble and deliver it, which means your accounting system needs to support retrieval by data subject, not just by date or recipient.

Why it matters

Disclosure accounting sits at the intersection of compliance monitoring and individual rights, and most organizations underestimate how quickly gaps here become audit findings. Without a functioning PM-21 process, you can’t demonstrate that your privacy program actually governs the movement of PII outside your organization.

Failure to maintain this control introduces audit risk and may result in regulatory findings or loss of authority to operate systems containing PII. For federal agencies operating under NIST SP 800-53, PM-21 is anchored to the Privacy Act, which means a missing or incomplete disclosure log isn’t just a best-practice gap. It’s a statutory violation that auditors are specifically trained to flag.

The downstream consequences compound. If disclosed PII turns out to be inaccurate and you can’t identify which recipients received it, you have no way to issue corrections. That leaves your organization exposed to both regulatory action and reputational damage from data subjects who discover their information was shared without adequate tracking.

What auditors flag

  • No structured disclosure log. The organization tracks disclosures informally (or not at all), relying on email threads or tribal knowledge rather than a searchable system of record.
  • Incomplete metadata. Disclosure entries exist but are missing required fields, particularly recipient contact information or the stated purpose of the disclosure.
  • Retention violations. Disclosure records are purged on a fixed schedule that doesn’t account for the five-year minimum or the lifespan of the underlying PII.
  • No subject-access capability. The organization can’t produce a disclosure history for a specific individual upon request, even though records technically exist somewhere in the environment.
  • No connection to system of records notices. Disclosure accounting isn’t linked to the organization’s published system of records notices (SORNs), making it impossible to verify that disclosures align with stated routine uses.

How to implement

For your organization

The most common failure mode with PM-21 isn’t a missing policy. It’s a disclosure process that exists on paper but doesn’t capture disclosures at the point they actually happen. Organizations write procedures, then route PII through channels that bypass the logging mechanism entirely.

Step 1: Define what constitutes a disclosure. Start by establishing clear criteria for when PII leaves your organization’s control. This includes transfers to other agencies, contractors, researchers, law enforcement, and any third party. Document these criteria in your privacy program plan and align them with your published system of records notices.

Step 2: Build the disclosure log structure. Create a centralized record system with mandatory fields for date, nature of disclosure, purpose, and full recipient contact details. Spreadsheet-based tracking works for small programs, but organizations handling frequent disclosures should consider a privacy management platform or a purpose-built database. The key requirement is that the system supports retrieval by individual data subject.

Step 3: Integrate logging into disclosure workflows. Embed the logging step directly into each process that moves PII externally. If your organization uses data-sharing agreements, tie the log entry to the agreement execution. If disclosures happen through automated systems, configure audit logging to capture the required metadata at the point of transfer.

Step 4: Establish retention rules. Configure retention periods to enforce the “longer of” rule: the lifespan of the PII or five years from disclosure. This requires your disclosure log to reference the retention schedule of the underlying PII, not operate on a standalone deletion cycle.

Step 5: Build the subject-access retrieval process. Create a documented procedure for responding to individual requests for their disclosure history. Test the retrieval process periodically to confirm you can produce a complete accounting within a reasonable timeframe.

Common mistakes to avoid:

  • Treating the disclosure log as a compliance artifact that gets updated quarterly rather than at the time of each disclosure
  • Failing to capture disclosures made through informal channels like email or phone
  • Storing disclosure records in the same system as the PII itself, creating a single point of failure for both the data and its audit trail
  • Not linking disclosure accounting to Privacy Act exemption rules, which define categories of disclosures that may be exempt from the accounting requirement

Evidence examples

Evidence TypeExample Artifact
Program documentationPrivacy program plan defining the scope, roles, and procedures for tracking PII disclosures
Policy and proceduresDisclosure policies specifying what constitutes a reportable disclosure, required metadata fields, and retention periods
Disclosure recordsStructured log entries showing date, nature, purpose, and recipient contact information for each PII disclosure event
Audit trailSystem-generated audit logs capturing automated PII transfers with timestamps and recipient identifiers
Compliance documentationPrivacy Act policies and procedures documenting applicable exemption rules and their effect on disclosure accounting obligations
Records managementSystem of records notice (SORN) linking each system’s routine uses to the corresponding disclosure tracking requirements

Cross-framework mapping

No cross-framework mappings have been configured for this control.

  • AC-03 — Access Enforcement: Access enforcement determines who can reach PII in the first place, directly shaping which disclosures your PM-21 log needs to capture.
  • AU-02 — Event Logging: Event logging provides the automated audit trail that feeds your disclosure accounting system with timestamped transfer records.
  • PT-02 — Authority to Process Personally Identifiable Information: This control establishes the legal basis for processing PII, and your disclosure log must demonstrate that each sharing event aligns with that documented authority.

Frequently asked questions

What is NIST SP 800-53 PM-21?

PM-21 requires organizations to maintain a structured accounting of every PII disclosure, capturing the date, nature, purpose, and recipient contact information for each event and making that history available to data subjects upon request. This control ensures individuals can learn who received their information and gives organizations an audit trail for verifying compliance with their published disclosure policies. For federal agencies, PM-21 directly implements a requirement under the Privacy Act.

What happens if PM-21 is not implemented?

Without a functioning disclosure accounting process, your organization can’t produce records of disclosures upon request from data subjects, which is a direct statutory violation for federal agencies operating under the Privacy Act. Auditors will flag the absence of a structured disclosure log as a material finding, particularly when your system of records notices promise specific routine uses that can’t be verified against actual disclosure activity. The inability to trace past disclosures also prevents you from notifying recipients when PII corrections are needed.

How do you audit PM-21?

Auditors verify PM-21 by selecting a sample of known PII disclosures and checking that each entry in the disclosure log contains the required fields: date, nature, purpose, and recipient name and contact information. They’ll also test the retention posture by confirming that records are held for the longer of the PII’s lifespan or five years from disclosure. The subject-access retrieval process gets tested by requesting a disclosure history for a specific individual and evaluating whether the organization can produce it completely and within a reasonable timeframe.

How long must disclosure records be retained under PM-21?

You must retain disclosure records for whichever period is longer: the full duration that the underlying PII is maintained in your systems, or five years from the date the disclosure was made. This “longer of” rule means your retention schedule for disclosure logs can’t operate independently from your PII retention policies. Organizations that apply a blanket five-year retention period without checking whether the PII itself is kept longer will fall out of compliance when auditors compare the two timelines.

Experience superior visibility and a simpler approach to cyber risk management