|
controlPT-3

Personally Identifiable Information Processing Purposes (PT-3)

Identify and document the [organization-defined] for processing personally identifiable information; Describe the purpose(s) in the public privacy notices and policies of the organization; Restrict the [organization-defined] of personally identifiable information to only that which is compatible with the identified purpose(s); and Monitor changes in processing personally identifiable information and implement [organization-defined] to ensure that any changes are made in accordance with [organiza

piiprivacytransparencydata-processing

Why These Connect

Maps To1

These are equivalent or closely aligned requirements in other frameworks.

Supports24

These related controls work together — a change to one may affect the others.

Enhances2

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(1)

ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022

Organization-Defined Parameters(4)

Assignmentorganization-defined purpose(s)
Assignmentorganization-defined processing
Assignmentorganization-defined mechanisms
Assignmentorganization-defined requirements

Control Enhancements(2)