Quick-reference card
| Field | Value |
|---|---|
| Control ID | PT-07 |
| Control Name | Specific Categories of Personally Identifiable Information |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Personally Identifiable Information Processing and Transparency |
| Baselines | PRIVACY |
| Relevance | Organization (First Party) |
| Risk Severity | Medium |
What this control requires
PT-07 requires your organization to identify which categories of personally identifiable information (PII) demand extra processing conditions and then enforce those conditions consistently. Most privacy programs treat all PII the same, but certain categories carry legal obligations, contextual sensitivities, or risk profiles that generic safeguards don’t address. This control closes that gap by mandating category-specific protections rather than a single blanket policy.
In practice, you need to determine which data categories qualify as sensitive under applicable laws, executive orders, regulations, and internal risk assessments. Social Security numbers, biometric identifiers, health records, financial account data, and information protected under the First Amendment all fall into categories that typically require heightened conditions. The conditions themselves vary. Some categories require stricter access controls, others demand purpose limitations or encryption at rest, and several carry mandatory breach notification timelines that differ from your standard PII handling procedures.
The control also requires you to revisit these determinations as context changes. A privacy risk assessment may reveal that a data category previously treated as routine now poses elevated risk because of a new processing purpose, a system migration, or a regulatory update. Your senior agency official for privacy and legal counsel should be involved in these determinations, and the resulting conditions must be documented, communicated to data handlers, and enforced through technical and administrative measures.
Why it matters
Organizations that fail to apply category-specific processing conditions expose themselves to regulatory findings, audit deficiencies, and potential enforcement actions. Privacy controls in the NIST SP 800-53 PRIVACY baseline receive direct scrutiny during federal privacy program assessments, and PT-07 is where auditors look for evidence that you’ve moved beyond generic data handling into risk-informed, category-aware protection.
The compliance risk here is concrete. Without documented processing conditions for sensitive PII categories, your organization can’t demonstrate that it meets the requirements of the Privacy Act, sector-specific regulations, or organizational privacy policies that mandate differential treatment for high-sensitivity data. An audit finding on PT-07 signals a structural gap in your privacy program, not a minor documentation oversight.
Where this control becomes particularly consequential is at the intersection of data classification and privacy governance. If your organization processes health information, financial records, or biometric data without category-specific safeguards, you aren’t just non-compliant with PT-07. You’re also likely out of alignment with the statutes and regulations that PT-07 is designed to enforce, which compounds audit exposure across multiple compliance frameworks.
Failure to maintain this control introduces audit risk and may result in certification withdrawal or regulatory findings. Auditors treat the absence of category-specific conditions as a systemic weakness because it suggests that the organization hasn’t conducted a privacy risk assessment that accounts for the varying sensitivity of the data it processes.
What auditors look for
- Documented inventory of PII categories with assigned sensitivity tiers and corresponding processing conditions
- Evidence that a privacy risk assessment informed the selection of categories and conditions
- Records showing that the senior agency official for privacy and legal counsel were consulted
- Proof that processing conditions are communicated to staff who handle sensitive PII categories
- Monitoring or enforcement mechanisms that verify conditions are applied in practice, not just documented
How to implement
For your organization
The most common failure mode for PT-07 is treating it as a documentation exercise rather than an operational requirement. Organizations create a PII inventory and assign sensitivity labels but never translate those labels into enforceable processing conditions that data handlers follow day-to-day.
Start by conducting a comprehensive PII categorization review. Work with your senior agency official for privacy and legal counsel to identify every category of PII your organization processes. Map each category against the legal authorities, regulations, and organizational policies that impose specific requirements on it. Federal agencies should reference the Privacy Act system of records notices, computer matching agreements, and any sector-specific mandates. Commercial organizations should map categories against state privacy laws, HIPAA, GLBA, or other applicable frameworks.
Once you’ve identified the categories, define the processing conditions for each one. These conditions should specify who can access the data, under what circumstances, for which purposes, and with what safeguards. A data classification program is essential here because PT-07’s conditions need to align with your broader classification tiers. If your classification scheme doesn’t distinguish between routine contact information and biometric identifiers, your processing conditions won’t be granular enough.
Document these conditions in your privacy plan and link them to the specific PII categories they govern. Ensure that privacy notices reflect the conditions applied to sensitive categories. Update computer matching agreements, memoranda of understanding, and information sharing agreements to incorporate category-specific terms.
Implement technical controls to enforce the documented conditions. Common tooling categories include data loss prevention systems, access control mechanisms with role-based restrictions, encryption solutions for data at rest and in transit, and audit logging that tracks access to sensitive PII categories. Automated classification tools can help detect and label sensitive data categories as they enter your environment.
Train your staff on the specific conditions that apply to each category. Generic privacy awareness training doesn’t satisfy PT-07’s intent. Personnel who handle Social Security numbers need to know the specific restrictions on that category, not just general PII handling best practices.
Common mistakes to avoid:
- Defining categories without assigning enforceable processing conditions to each one
- Relying on a single processing condition for all sensitive categories rather than tailoring conditions to the legal and risk context of each
- Failing to update category determinations after changes in processing purpose, system architecture, or regulatory requirements
- Omitting consultation with the senior agency official for privacy or legal counsel during category determination
- Treating the PII inventory as a static document rather than a living artifact tied to operational controls
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Privacy policy and procedures | PII Processing and Transparency Policy defining category-specific processing conditions, review cadence, and roles responsible for enforcement |
| PII category inventory | Data inventory mapping each PII category to its sensitivity tier, applicable legal authorities, and assigned processing conditions |
| Privacy notices | Public-facing privacy notice specifying how sensitive PII categories are collected, used, retained, and protected |
| Privacy Act documentation | System of records notices and computer matching agreements identifying PII categories and their processing terms |
| Information sharing agreements | Memoranda of understanding and privacy information sharing agreements with category-specific handling clauses |
| Privacy risk assessment | Completed risk assessment documenting how PII categories were evaluated, including contextual factors that informed sensitivity determinations |
| Privacy plan | Organizational privacy plan linking PII categories to processing conditions, responsible officials, and review schedules |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.34 Privacy and protection of personal identifiable information (PII) | Partial |
No NIST SP 800-171 mapping exists for this control.
Related controls
- IR-09 — Information Spillage Response: defines the response procedures when sensitive PII categories are exposed or disclosed improperly, directly supporting the protective conditions PT-07 establishes
- PT-02 — Authority to Process Personally Identifiable Information: establishes the legal basis for processing PII, which PT-07 builds on by adding category-specific conditions beyond the general authority
- PT-03 — Personally Identifiable Information Processing Purposes: restricts PII processing to defined purposes, complementing PT-07’s requirement that specific categories receive tailored conditions aligned with those purposes
- RA-03 — Risk Assessment: provides the risk assessment methodology that PT-07 relies on to determine which PII categories require elevated processing conditions based on contextual risk factors
Frequently asked questions
What is NIST SP 800-53 PT-07
PT-07 requires organizations to apply specific processing conditions to categories of personally identifiable information that carry heightened sensitivity or legal obligations. These conditions go beyond standard PII protections and are informed by laws, regulations, privacy risk assessments, and consultation with the senior agency official for privacy. The control ensures that data categories such as Social Security numbers, biometric identifiers, and health records receive protections proportional to their risk, rather than being governed by a single set of generic safeguards.
What happens if PT-07 is not implemented
Without PT-07, your organization lacks documented processing conditions for sensitive PII categories, which creates audit deficiencies and regulatory exposure. Auditors reviewing the PRIVACY baseline will flag the absence of a PII category inventory tied to enforceable conditions as a systemic gap in your privacy program. This finding can cascade into non-compliance with the Privacy Act, sector-specific regulations, and any information sharing agreements that reference category-specific handling requirements.
How do you audit PT-07
Auditing PT-07 starts with examining whether the organization maintains a current PII category inventory with documented processing conditions for each category. Assessors verify that a privacy risk assessment informed the category determinations and that the senior agency official for privacy and legal counsel were consulted. They also review privacy notices, computer matching agreements, and memoranda of understanding to confirm that category-specific conditions are reflected in external-facing and interagency documents.
What are examples of sensitive PII categories under NIST 800-53
Sensitive PII categories typically include Social Security numbers, biometric identifiers, health and medical records, financial account information, and information protected under the First Amendment. The specific categories that require elevated processing conditions depend on your organization’s applicable laws, executive orders, and the results of privacy risk assessments. PT-07 doesn’t prescribe a universal list because the determination is contextual, driven by the legal authorities and risk factors relevant to each organization’s processing environment.