PT-5: Privacy Notice

PT-05 requires your organization to provide individuals with clear, plain-language notice about how their personally identifiable

Quick-reference card

FieldValue
Control IDPT-05
Control NamePrivacy Notice
FrameworkNIST SP 800-53 Revision 5
Control FamilyPersonally Identifiable Information Processing and Transparency
BaselinesPRIVACY
RelevanceOrganization (First Party)
Risk SeverityLow

What this control requires

PT-05 requires your organization to provide individuals with clear, plain-language notice about how their personally identifiable information (PII) is processed. That notice must be available at the point of first interaction and updated at a frequency your organization defines, so individuals are never left guessing about what happens to their data.

The notice must identify the legal authority under which PII is collected and processed, the specific purposes for that processing, and any additional information your organization determines is necessary. Those additional elements typically include categories of PII collected, retention periods, data sharing with third parties, and the choices individuals have regarding their information. The goal is informed decision-making, not just disclosure for its own sake.

Where this control differs from general privacy policy obligations is in its specificity. PT-05 doesn’t ask for a generic statement about data practices. It requires organizations to tie each processing activity to a documented authority and communicate that linkage in language any individual can understand. In practice, this control sits at the center of the Personally Identifiable Information Processing and Transparency family, connecting legal obligations to operational transparency by forcing organizations to articulate exactly what they do with PII and make that articulation accessible to the people whose information they hold.

Why it matters

Most organizations treat privacy notices as a legal formality rather than an operational control. That gap between intention and execution is where audit findings accumulate. When notices are vague, outdated, or buried in legalese, auditors flag the disconnect between stated practices and actual PII processing activities.

Failure to maintain this control introduces audit risk and may result in certification withdrawal or regulatory findings. Privacy notice requirements appear across multiple regulatory frameworks. A deficient notice under NIST SP 800-53 often signals deficiencies under other privacy frameworks as well, compounding audit exposure. GDPR compliance demands transparent privacy notices with similar rigor.

The overlap is substantial. HIPAA’s Privacy Rule requires covered entities to provide a notice of privacy practices describing how protected health information is used and disclosed. State laws like the Colorado Privacy Act impose their own notice obligations on controllers that process personal data. The Virginia Consumer Data Protection Act requires similar transparency around data collection purposes and third-party sharing. Organizations that fall short on PT-05 typically face findings across these parallel requirements during comprehensive privacy assessments.

Beyond compliance, unclear privacy notices erode trust with customers, employees, and partners. When individuals can’t understand how their information is used, they’re less likely to engage with your organization’s services or share the data you need to operate effectively. Specifically, when individuals file complaints with regulators because they didn’t understand a privacy notice, those complaints can trigger investigations that extend well beyond the original notice deficiency.

The downstream effect is organizational. Privacy teams that can’t point to a current, well-structured notice face harder conversations during assessments, and audit remediation for notice deficiencies often reveals deeper gaps in PII processing documentation and authority mapping.

What auditors flag

  • Privacy notices that haven’t been updated to reflect current PII processing activities
  • Notices written in dense legal language that fails the plain-language standard
  • Missing identification of processing authority or legal basis
  • No documented frequency for reviewing and reissuing notices
  • Notices that omit third-party sharing practices or individual choice mechanisms

How to implement

For your organization

The central challenge with PT-05 isn’t producing a privacy notice. It’s keeping that notice accurate as your PII processing activities evolve over time and across systems. Organizations that write a notice once and file it away inevitably drift out of alignment with their actual data practices, and that drift is exactly what auditors are trained to identify.

Step 1: Inventory your PII processing activities. Before you can describe what you do with PII, you need a current, comprehensive inventory. Map every system, application, and process that collects, stores, transmits, or shares PII. Document the categories of PII involved, the legal authority for each processing activity, and the purposes served. This inventory becomes the foundation of your notice content.

Step 2: Identify your legal authority. For each processing activity, document the specific statute, regulation, executive order, or organizational policy that authorizes the collection and use of PII. Federal agencies should reference applicable Privacy Act system of records notices (SORNs) and consult with their senior agency official for privacy (SAOP) and legal counsel.

Step 3: Draft the notice in plain language. Write the notice at or below an eighth-grade reading level. Avoid legal jargon and technical terms. Structure the notice so individuals can quickly find what matters to them, including what PII is collected, why, under what authority, who it’s shared with, how long it’s retained, and what choices they have. Privacy risk assessments, such as those conducted under RA-03, help determine which elements to include.

Step 4: Determine delivery timing and frequency. Define when the notice is first presented (at the point of initial data collection or first system interaction) and how often it’s reissued or updated. Document this frequency in your privacy plan and ensure it accounts for material changes in processing activities.

Step 5: Establish a review and update process. Assign ownership for reviewing the notice against actual processing activities at a defined cadence. When new systems are deployed, new data sharing agreements are executed, or processing purposes change, trigger a notice review. Maintain version history to demonstrate compliance over time.

Step 6: Coordinate across stakeholders. Privacy notices touch legal, IT, product, and compliance functions. Establish a cross-functional review process that ensures changes to PII processing in any part of the organization trigger a corresponding notice update. Federal agencies should involve their senior agency official for privacy and legal counsel in this coordination, as required by applicable law and policy.

Step 7: Test readability and accessibility. Run the draft notice through a readability assessment to confirm it meets plain-language standards. Verify that the notice is accessible to individuals with disabilities, is available in the languages your user population requires, and can be found without requiring extensive navigation through your website or application.

Common mistakes to avoid:

  • Copying notice language from another organization without tailoring it to your specific processing activities
  • Relying on website cookie banners as the sole privacy notice mechanism
  • Failing to coordinate between privacy, legal, and IT teams when processing activities change
  • Using technical or legal terminology that doesn’t meet the plain-language requirement
  • Providing notice only at initial interaction without a defined schedule for updates

Evidence examples

Evidence TypeExample Artifact
Privacy noticePublished privacy notice identifying processing authority, purposes, PII categories, third-party sharing, retention periods, and individual choices
PII processing and transparency policyPolicy document defining notice delivery timing, update frequency, plain-language standards, and roles responsible for notice maintenance
Privacy Act statementsSystem of records notices (SORNs) or Privacy Act statements for each system that collects PII from individuals
Privacy planOrganizational privacy plan documenting the schedule for notice review, stakeholder coordination procedures, and version control process
Privacy risk assessmentCompleted privacy risk assessment (per RA-03) used to determine which elements to include in the privacy notice
Notice distribution recordsLogs or screenshots showing when and how privacy notices were delivered to individuals at first interaction and subsequent intervals

Cross-framework mapping table

No cross-framework mappings are currently configured for PT-05.

  • PM-20 — Dissemination of Privacy Program Information: establishes the broader program under which privacy notices are developed and distributed to the public
  • PM-22 — Personally Identifiable Information Quality Management: ensures the PII referenced and collected through privacy notices is accurate and complete
  • PT-02 — Authority to Process Personally Identifiable Information: defines the legal authorities that PT-05 notices must disclose to individuals
  • PT-03 — Personally Identifiable Information Processing Purposes: identifies the processing purposes that privacy notices must communicate clearly
  • PT-04 — Consent: governs how organizations obtain and manage individual consent, which privacy notices support by explaining available choices
  • PT-07 — Specific Categories of Personally Identifiable Information: addresses protections for sensitive PII categories that may require enhanced notice provisions
  • RA-03 — Risk Assessment: privacy risk assessments inform which elements should be included in privacy notices based on identified risks
  • SC-42 — Sensor Capability and Data: addresses automated data collection mechanisms that trigger privacy notice requirements when they capture PII
  • SI-18 — PII Quality Management: supports notice accuracy by ensuring the PII processing descriptions in notices match actual data quality practices

Frequently asked questions

What is NIST SP 800-53 PT-05

PT-05 requires organizations to provide clear, plain-language privacy notices that identify the authority for PII processing, the purposes of that processing, and additional organization-defined information. The notice must be available to individuals at the point of first interaction and then reissued at an organization-defined frequency. This control ensures transparency by making individuals aware of exactly how their information is handled before and during processing. It applies to any organization that processes PII and is assessed under the NIST SP 800-53 PRIVACY baseline.

What happens if PT-05 is not implemented

Without PT-05, your organization lacks a documented mechanism for informing individuals about PII processing authority and purposes, which auditors flag as a control gap during privacy assessments. Regulatory frameworks that reference NIST SP 800-53 expect evidence of current, plain-language privacy notices delivered at first interaction and maintained on a defined schedule. Missing or outdated notices can result in findings that cascade across related privacy controls, including PT-02 (processing authority) and PT-03 (processing purposes), and create exposure under state and federal privacy laws.

How do you audit PT-05

Auditors verify PT-05 by confirming that a privacy notice exists, that it’s written in plain language, and that it identifies the processing authority and processing purposes for each PII collection activity. They check whether the notice was available at first interaction and whether records show it was reissued at the organization’s defined frequency. Auditors also review Privacy Act statements, privacy plans, and privacy risk assessments to confirm the notice content reflects current processing activities rather than outdated descriptions of discontinued practices.

What should a privacy notice include under NIST SP 800-53

A privacy notice under NIST SP 800-53 must, at minimum, identify the legal authority for PII processing, the specific purposes for which PII is collected and used, and any additional organization-defined elements. Those additional elements typically cover categories of PII collected, data retention periods, third-party sharing practices, and the choices available to individuals regarding their information. The notice must be written in plain language that avoids jargon, ensuring individuals can understand it without specialized knowledge. Organizations should use privacy risk assessments to determine which additional elements are necessary based on the sensitivity and volume of PII they process.

Experience superior visibility and a simpler approach to cyber risk management