Quick-reference card
| Field | Value |
|---|---|
| Control ID | PT-02 |
| Control Name | Authority to Process Personally Identifiable Information |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Personally Identifiable Information Processing and Transparency |
| Baselines | PRIVACY |
| Relevance | Organization (First Party) |
| Risk Severity | Medium |
What this control requires
PT-02 requires your organization to identify, document, and enforce the legal authorities that permit it to process personally identifiable information (PII). Without a documented basis for every PII processing activity, you can’t demonstrate that collection, storage, use, or disclosure of personal data is lawful or authorized.
In practice, this control has two parts. First, you must determine and record which laws, executive orders, directives, regulations, or policies grant your organization the authority to process PII. Second, you must restrict PII processing to only those activities the documented authority permits. This means every system that touches personal data needs a traceable link back to a specific legal or policy basis.
The scope of “processing” under PT-02 is broad. It covers creation, collection, use, storage, maintenance, dissemination, disclosure, disposal, logging, generation, transformation, and data mining. Organizations operating under NIST SP 800-53 must ensure that each of these activities has a documented authorization chain, typically recorded in privacy policies, system of records notices, privacy impact assessments, or interagency agreements.
Why it matters
Failure to maintain documented PII processing authority introduces direct audit risk. When assessors review your privacy program, PT-02 is one of the first controls they examine because it establishes whether your organization has a lawful basis for handling personal data at all. A gap here calls every downstream privacy control into question.
The consequence extends beyond a single audit finding. Undocumented processing authority makes it impossible to demonstrate compliance with the Privacy Act, OMB directives, or sector-specific regulations during oversight reviews. Auditors treat a missing or incomplete authority chain as a systemic program weakness rather than an isolated documentation gap.
Where this control breaks down most often is in decentralized environments. Agencies and organizations frequently add new PII processing activities through system upgrades, data-sharing agreements, or interagency partnerships without updating the corresponding authority documentation. Over time, actual processing activities drift from what the privacy program formally authorizes.
Organizations that lack documented authority also struggle to enforce processing restrictions. Without a clear record of what processing is permitted, training programs can’t teach staff the boundaries, and monitoring systems can’t flag unauthorized activities. The result is uncontrolled data sprawl that increases both regulatory exposure and the likelihood of a privacy incident.
What auditors flag
- PII processing activities with no corresponding documented legal authority or policy basis
- Privacy impact assessments that don’t identify the specific statute, regulation, or directive authorizing the processing
- Systems of records notices that are outdated or don’t reflect current processing activities
- No formal process for reviewing and updating authority documentation when processing activities change
- Staff unable to identify which authority permits the PII processing they perform
How to implement
Most organizations struggle with PT-02 not because the concept is complex, but because PII processing activities are scattered across dozens of systems, contracts, and workflows. The implementation challenge is creating a single, auditable thread from each processing activity back to a specific legal or policy authority.
Start by inventorying every system and business process that touches PII. For each one, identify the specific law, executive order, regulation, directive, or organizational policy that authorizes the processing. Record this mapping in a structured format, and make sure it covers all processing types including collection, storage, use, sharing, and disposal.
Document the authority chain in your privacy impact assessments, Privacy Act statements, system of records notices, and any applicable computer matching agreements or memoranda of understanding. Each document should clearly state what processing is authorized, by whom, and under what conditions. Use your organization’s data action mapping process to connect systems to their authorized processing activities.
Build a review cycle into your privacy program. At minimum, revisit authority documentation annually and whenever you introduce new systems, modify existing data flows, or enter new data-sharing arrangements. Assign ownership of each authority document to a specific role, and require sign-off from your senior agency official for privacy and legal counsel before new PII processing begins.
Implement monitoring controls to detect unauthorized processing. This can include access logging, data loss prevention tools, or periodic audits comparing actual system behavior against documented authorities. Train staff who handle PII on the specific authorities that govern their work and the boundaries those authorities set.
Common mistakes include documenting authority at the program level without mapping it to individual systems, failing to update authority documentation when processing activities change, and treating the initial privacy impact assessment as a one-time exercise rather than a living document. A NIST 800-53 security questionnaire can help you structure your self-assessment and identify gaps before an auditor does.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| PII processing authority register | Inventory mapping each PII processing activity to the specific statute, executive order, or policy that authorizes it |
| Privacy impact assessment | Completed PIA identifying the legal authority, PII categories processed, and authorized uses for each system |
| System of records notice | Published SORN documenting the authority, purpose, routine uses, and retention schedule for a PII record system |
| Privacy Act statement | Notice provided at the point of PII collection stating the authority, purpose, and consequences of not providing information |
| Data-sharing agreement | Memorandum of understanding or information sharing agreement specifying the legal basis and permitted uses for PII exchanged between organizations |
| Privacy plan | Organizational privacy plan describing the governance structure, authority documentation requirements, and review cadence |
| Training records | Completion records for PII handling training that covers authorized processing activities and boundaries |
Cross-framework mapping
No cross-framework mappings are currently configured for PT-02. However, ISO 27001 Control 5.34 addresses related PII protection themes, covering the requirements for privacy and protection of personal data under applicable legislation. You can review ISO 27001 Control 5.34 for a comparison of how that framework approaches PII governance.
Related controls
- AC-02 — Account Management: Governs user account lifecycle management, which intersects with PT-02 because accounts determine who can access and process PII.
- AC-03 — Access Enforcement: Enforces approved authorizations for system access, supporting PT-02 by restricting PII processing to authorized personnel.
- CM-13 — Data Action Mapping: Maps data actions to system components, directly supporting PT-02 by documenting where and how PII processing occurs.
- IR-09 — Information Spillage Response: Addresses incidents where PII is processed outside authorized boundaries, a direct consequence of PT-02 failures.
- PM-09 — Risk Management Strategy: Defines the organizational approach to managing risk, including privacy risk from unauthorized PII processing.
- PM-24 — Data Integrity Board: Oversees computer matching agreements involving PII, which require documented processing authority under PT-02.
- PT-01 — Policy and Procedures: Establishes the policy framework within which PII processing authorities are documented and enforced.
- PT-03 — Personally Identifiable Information Processing Purposes: Defines the specific purposes for PII processing, which must align with the authorities documented under PT-02.
- PT-05 — Privacy Notice: Communicates to individuals the authorities and purposes for PII processing, translating PT-02 documentation into public-facing transparency.
- PT-06 — System of Records Notice: Requires publication of SORNs that document the authority and purpose for each PII record system, a key evidence artifact for PT-02.
Frequently asked questions
What is NIST SP 800-53 PT-02
PT-02 is the NIST SP 800-53 control that requires organizations to determine, document, and enforce the legal authorities permitting them to process personally identifiable information. It applies to all forms of PII processing, including collection, storage, use, dissemination, and disposal. Organizations must trace each processing activity back to a specific statute, regulation, executive order, or policy, and restrict processing to only what that authority permits.
What happens if PT-02 is not implemented
Without PT-02, your organization cannot demonstrate a lawful basis for processing PII, which creates a systemic audit finding that undermines your entire privacy program. Assessors will flag the absence of a documented authority chain in your privacy impact assessments and system of records notices as a material weakness. The resulting compliance exposure can trigger corrective action plans, increased oversight, and restrictions on data-sharing agreements with other organizations.
How do you audit PT-02
Auditing PT-02 starts with verifying that a PII processing authority register exists and maps each processing activity to a specific legal or policy basis. Assessors then review privacy impact assessments, Privacy Act statements, system of records notices, and computer matching agreements to confirm that documented authorities match actual processing. They also interview staff to determine whether personnel can identify the authority governing the PII processing they perform and check for a review cycle that updates authority documentation when processing activities change.
What documents establish authority to process PII
The primary documents include privacy policies, system of records notices, privacy impact assessments, Privacy Act statements, computer matching agreements, contracts, information sharing agreements, and memoranda of understanding. Each document should identify the specific statute, executive order, directive, regulation, or organizational policy that authorizes the PII processing activity it covers. Your organization’s senior agency official for privacy and legal counsel should review these documents before new processing begins.