Laws and Statutes

Privacy Act — The Privacy Act, enacted in 1974, can be thought of as a “code of fair information practices” regulating the collection, maintenance, and use of personal information by Federal executive branch agencies.  The Privacy Act covers individuals (defined as U.S. citizens and permanent resident aliens), not groups, and pertains only to information held in a “System of Records”–a group of “records” from which information is retrieved by the name of the individual or by some identifying particular.

The creation of a System of Records requires public notice of its existence through a “Systems of Record Notice” (SORN) in the Federal Register. The notice informs the public of what data is being collected;   the purpose and authority for doing so; and publicly discloses the rules by which the system will collect, maintain and use personal information.

The Privacy Act imposes several obligations on Federal agencies to make sure that the data they collect are accurate, secure and used for lawful purposes.  Collectively these obligations are referred to as “fair information practices.” The Act permits exemption  from its coverage those systems:  a) maintained by the Central Intelligence Agency;  b) maintained for law enforcement or other investigatory purposes, and c) containing classified data. But even exempted systems are subject to certain minimal standards.  Agencies maintaining such a system of records must, for example, maintain a record of any disclosures of information they make and make reasonable efforts to assure that such records are accurate, complete, timely, and relevant for agency purposes prior to disclosure.  And, of course, they still must establish appropriate safeguards to ensure the security, integrity and confidentiality of records and rules of conduct for persons involved in the design, development, operation, or maintenance of any system of records, or in maintaining any record.  Finally, even in the IC systems there is an explicit prohibition on maintaining any records describing how any individual exercises rights guaranteed by the First Amendment.

E-Government Act of 2002 — The E-Government Act of 2002 (2002 Act), Pub. L. 107-347, 116 Stat. 2899 (codified at 44 U.S.C. §101 note) included a requirement that agencies’ post privacy policies on public websites.  It also required agencies to conduct a Privacy Impact Assessment (PIA) before deploying any new system for collecting or administering data that is or may be made personally identifiable in conjunction with other data.

The Act (in Title III) exempts National Security Systems from the requirement for privacy impact assessments, thus many Intelligence Community (IC) elements are not legally obliged to conduct these assessments.  Despite the exemption, some IC elements conduct PIAs routinely, and other do so on a discretionary basis or as required by other laws.

Data Mining Report Act — As its name implies, the Data Mining Report Act (§804 of the Implementing the Recommendations of the 9/11 Commission Act, Pub. L. No. 110-53, 121 Stat. 266) requires annual reports on data mining activities of all federal agencies.  In addition to cataloging the data mining activities being conducted and assessing their efficacy, the agencies are specifically mandated to: 1) assess the impact or likely impact of the implementation of the data mining activity on the privacy and civil liberties of individuals; and 2) include a description of the policies, that are in place or that are to be developed and applied in the use of such data mining activity in order to protect the privacy and due process rights of individuals, e.g., redress procedures; and , 3) ensure that only accurate and complete information is collected, reviewed, gathered, analyzed, or used, and guard against any harmful consequences of potential inaccuracies.

Privacy Impact Assessment (PIA) —  The E-Government Act of 2002 (section 208 of Public Law 107-347 which is codified at 44 U.S.C. Ch 36) requires  that a PIA be conducted for all new IT systems that maintain personally identifiable information (PII).  A PIA is defined as “an analysis of how information is handled: (i) to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy, (ii) to determine the risks and effects of collecting, maintaining and disseminating information in identifiable form in an electronic information system, and (iii) to examine and evaluate protections and alternative processes for handling information to mitigate potential privacy risks.”  In short, the PIA is a written document that describes how a new government system that collects information will protect privacy and assesses whether or not there are viable alternatives to prefer.

As part of a PIA, the agency must analyze and describe:

  • what information is to be collected, why it is being collected, and with whom it will be shared;
  • what opportunities individuals have to decline to provide information (where doing so is voluntary) or to consent to particular uses of the information (other than required or authorized uses)  and how individuals can grant consent;
  • how the information will be secured (e.g., administrative and technical controls);  and,
  • whether a system of records, as defined by the Privacy Act, is being created.

PIA’s must also identify what choices were made to effect safeguards for privacy and civil liberties in the new electronic business as a result of performing the PIA.

 

System of Records Notice (SORN) – The Privacy Act of 1974 (5 U.S.C. § 552a(e)(4)) requires that any new system of records (that is, a collection of retrievable files) have a notice published describing what the system does.  “A SORN identifies the purpose for the system of records, which individuals are covered by information in the system of records, what categories of records are maintained about the individuals, and how the information is shared by the agency (routine uses). The SORN also provides notice to the public regarding the rights and procedures of the Privacy Act for accessing and correcting PII maintained by an agency on an individual.”

 

Comments are closed.