PII Processing and Transparency Plan
Documents how the system manages PII processing authority, lawful purpose, transparency to data subjects, consent, system-of-records notices, individual rights (access / amendment), and dissemination across third parties. Covers the controls of the PT family in NIST SP 800-53 r5 and aligns with the Privacy Act of 1974 (5 U.S.C. § 552a), E-Government Act of 2002 (Section 208 — PIA), OMB M-03-22 (PIA guidance), OMB M-17-12 (breach response), NIST IR 8062 (Privacy Risk Management Framework), NIST IR 8112 (Attribute Metadata), GDPR / state privacy laws where applicable, and Fair Information Practice Principles (FIPPs).