PM-20 Dissemination of Privacy Program Information

Program Management

Privacy New in Rev 5

Description

Maintain a central resource page on the organization's principal public website that serves as a central source of information for the organization's privacy program and that: a. Ensures that the public has access to information about the organizational privacy activities and can communicate with its senior agency official for privacy; b. Ensures that organizational privacy practices and reports are publicly available; and c. Employs publicly facing email addresses and/or other mechanisms to enable the public to provide feedback and/or direct questions to privacy offices regarding privacy practices.

Supplemental Guidance

For federal agencies, the webpage is located at www.[agency].gov/privacy. Organizations employ publicly facing email addresses and/or other mechanisms to inform the public about changes to privacy practices, privacy impacts, or organizational actions.

Changes from Rev 4

New control in Rev 5. Public transparency for privacy programs.

Compliance Mappings

EBA ICT Guidelines

3.8(a)

BOT Cyber Resilience

Ch9.2

Lloyd's Minimum Standards

MS7.1

NAIC Insurance Data Security

6-b

HITRUST CSF v11

13.a13.b

FDA Cybersecurity Guidance

TR-1