NIST 800-53 Rev 5

424 controls available

PT-6(2)privacy

Exemption Rules

Personally Identifiable Information Processing and Transparency

Control Statement

Review all Privacy Act exemptions claimed for the system of records at {{ insert: param, pt-06.02_odp }} to ensure they remain appropriate and necessary in accordance with law, that they have been promulgated as regulations, and that they are accurately described in the system of records notice.

Discussion

The [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) includes two sets of provisions that allow federal agencies to claim exemptions from certain requirements in the statute. In certain circumstances, these provisions allow agencies to promulgate regulations to exempt a system of records from select provisions of the [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) . At a minimum, organizations’ [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) exemption regulations include the specific name(s) of any system(s) of records that will be exempt, the specific provisions of the [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) from which the system(s) of records is to be exempted, the reasons for the exemption, and an explanation for why the exemption is both necessary and appropriate.

Framework
NIST SP 800-53 Rev 5
Family
Personally Identifiable Information Processing and Transparency
Baselines
privacy

Related Frameworks

5 paths across 2 frameworks
SCF1 mapping
PRI-02.6Privacy Act Exemptions
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
CCI4 mappings
CCI-004588
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004589
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004590
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004591
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

No STIGs in the current catalog reference any CCI mapped to this control.