Just-in-time Consent
LOW MODERATE HIGHRequirements NIST SOURCE
Present [consent mechanisms] to individuals at [frequency] and in conjunction with [personally identifiable information processing].
Discussion (NIST Supplemental Guidance)
Just-in-time consent enables individuals to participate in how their personally identifiable information is being processed at the time or in conjunction with specific types of data processing when such participation may be most useful to the individual. Individual assumptions about how personally identifiable information is being processed might not be accurate or reliable if time has passed since the individual last gave consent or the type of processing creates significant privacy risk. Organizations use discretion to determine when to use just-in-time consent and may use supporting information on demographics, focus groups, or surveys to learn more about individuals’ privacy interests and concerns.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for PT-4(2) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- consent mechanisms to be presented to individuals are defined;
- the frequency at which to present consent mechanisms to individuals is defined;
- personally identifiable information processing to be presented in conjunction with organization-defined consent mechanisms is defined;
- <PT-04(02)_ODP[01] consent mechanisms> are presented to individuals <PT-04(02)_ODP[02] frequency> and in conjunction with <PT-04(02)_ODP[03] personally identifiable information processing>.
Examine
[SELECT FROM: Personally identifiable information processing and transparency policy and procedures; consent policies and procedures; privacy plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with personally identifiable information processing and transparency responsibilities; organizational personnel with user interface or user experience responsibilities; organizational personnel with information security and privacy responsibilities].
Test
[SELECT FROM: Organizational processes for the collection of personally identifiable information; mechanisms for obtaining just-in-time consent from users for the processing of their personally identifiable information; mechanisms implementing just-in-time consent].
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for PT-4(2). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Personally identifiable information processing and transparency policy and procedures
- consent policies and procedures
- privacy plan
Testing
- Organizational processes for the collection of personally identifiable information
- mechanisms for obtaining just-in-time consent from users for the processing of their personally identifiable information
- mechanisms implementing just-in-time consent
Other Records
- other relevant documents or records