A Basic Overview of The Privacy Act of 1974

Similar documents
Privacy Act of 1974: A Basic Overview. Purpose of the Act. Congress goals. ASAP Conference: Arlington, VA Monday, July 27, 2015, 9:30-10:45am

Codified at 5 U.S.C. 552a. Passed in 1974, became effective September 27, Act passed in haste as an outgrowth of Watergate reforms and the

THE PRIVACY ACT OF 1974 (As Amended) Public Law , as codified at 5 U.S.C. 552a

PRIVACY ACT OVERVIEW The Basic Concepts of the Act

Role of PAS in the Privacy Act

COMMENTS OF THE ELECTRONIC PRIVACY INFORMATION CENTER THE DEPARTMENT OF HOMELAND SECURITY. [Docket No. DHS ]

MEEKER COUNTY GUIDELINES AND PROCEDURES FOR MINNESOTA GOVERNMENT DATA PRACTICES ACT

Privacy. Purpose. Scope. Policy. Appendix A

The Privacy Act. Disclaimers. Paul Klingenberg 6/14/2017 PRIVACY ACT AND SYSTEMS OF RECORDS 1

Page M.1 APPENDIX M NOAA ADMINISTRATIVE ORDER

RESOLUTION OF THE NAVAJO NATION COUNCIL

POLICIES AND PROCEDURES FOR DETECTING AND PREVENTING FRAUD, WASTE AND ABUSE

WASHINGTON COUNTY GUIDELINES AND PROCEDURES FOR MINNESOTA GOVERNMENT DATA PRACTICES ACT

FREEDOM OF INFORMATION ACT AND THE FDA

Notes on how to read the chart:

DEPARTMENT OF DEFENSE BILLING CODE

Privacy Act; System of Records: Legal Case Management Records, State- to amend an existing system of records, Legal Case Management Records,

proposes to add a new system of records in its inventory of record systems subject to the Privacy Act of 1974 (5 U.S.C.

FREEDOM OF INFORMATION ACT

This is in response to your Freedom of Information Act (FOIA) requests and subsequent civil

draft by-laws advice or recommendations by an officer, employee or consultant; might interfere with law enforcement,

PUBLIC RECORDS POLICY OF COVENTRY TOWNSHIP, SUMMIT COUNTY

DEPARTMENT OF DEFENSE BILLING CODE Defense Contract Audit Agency (DCAA) Privacy Act Program

Pursuant to Article 95 item 3 of the Constitution of Montenegro, I hereby issue the DECREE

Drivers Privacy Protection Act 18 U.S.C et. seq. (Public Law )

REPORT BY. An Informed Public Assures That Federal Agencies Will Better Comply With Freedom Of Information/Privacy Laws OF THE UNITED STATES RELEASED

UNCLASSIFIED INSTRUCTION

Data Protection Act 1998 Policy

Case 1:14-cv LGS Document 105 Filed 02/26/16 Page 1 of 5

City of Midland. Freedom of Information Act. (P.A. 442 of 1976, as amended) Administrative Policy

Privacy Law Template. Prepared for The Alberta First Nations Information Governance Centre. By Krista Yao

CRS Report for Congress

B I L L. No. 30 An Act to amend The Freedom of Information and Protection of Privacy Act

U.S. Victims of State Sponsored Terrorism Fund Application Form OMB No Expires 1/31/2017

NC General Statutes - Chapter 147 Article 5A 1

COMMENTS OF THE ELECTRONIC FRONTIER FOUNDATION

Privacy Act of 1974; Department of Homeland Security, U.S. Customs and Border

President Obama s FOIA Memorandum and Attorney General Holder s FOIA Guidelines. Creating a "New Era of Open Government"

BUSINESS ASSOCIATE AGREEMENT WITH COVERED ENTITY

Executive Order Access to Classified Information August 2, 1995

February 4, 2009, Date Last Declared Current: August 3, 2016 REQUESTS FOR SMITHSONIAN INSTITUTION INFORMATION. Policy

CITY OF DOVER FREEDOM OF INFORMATION ACT POLICY - PUBLIC RECORDS ACCESS

The Army Privacy Program

FOIA Exemptions 6 & 7C Personal Privacy Exemptions

MEDICAL UNIVERSITY OF SOUTH CAROLINA DEPARTMENT OF PUBLIC SAFETY

I. REGULATION OF INVESTIGATORY POWERS BILL

Basic Considerations. - Lines :

IC Chapter 10. Release of Social Security Number

PERSONAL INFORMATION PROTECTION ACT

7112. Authority to execute compact. The Governor of Pennsylvania, on behalf of this State, is hereby authorized to execute a compact in substantially

IC Chapter 10. Release of Social Security Number

The Health Information Protection Act

AP3. APPENDIX 3 CONTROLLED UNCLASSIFIED INFORMATION

Federal Information Technology Supply Chain Risk Management Improvement Act of 2018 A BILL

United States v. Biocompatibles, Inc. Criminal Case No.

Citizen Advocacy Center Guide to Illinois Freedom of Information Act

H.R.3162 SEC EXPANSION OF THE BIOLOGICAL WEAPONS STATUTE. Chapter 10 of title 18, United States Code, is amended-- (1) in section 175--

Controlled Unclassified Information (CUI) Office Notice : Initial Implementation Guidance for Executive Order 13556

CHAPTER 457. (Senate Bill 796) Vehicle Laws Motor Vehicle Accident Reports Access

FOIA Request Department of the Treasury Washington, DC Fax: FOIA Online Request Form

Chapter PERSONAL INFORMATION PROTECTION ACT. Article 01. BREACH OF SECURITY INVOLVING PERSONAL INFORMATION

Security Breach Notification Chart

COMMENTS OF THE ELECTRONIC PRIVACY INFORMATION CENTER. to the DEPARTMENT OF HOMELAND SECURITY

Miami-Dade County False Claims Ordinance. (1) This article shall be known and may be cited as the Miami-Dade County False Claims Ordinance.

3RD SESSION, 41ST LEGISLATURE, ONTARIO 67 ELIZABETH II, Bill 14. An Act with respect to the custody, use and disclosure of personal information

FOIA Exemptions 6 & 7C Personal Privacy Exemptions

INTERSTATE COMPACT FOR THE SUPERVISION OF ADULT OFFENDERS PREAMBLE

MONTEFIORE HEALTH SYSTEM ADMINISTRATIVE POLICY AND PROCEDURE SUBJECT: SUMMARY OF FEDERAL AND STATE NUMBER: JC31.1 FALSE CLAIMS LAWS

FEES AND FEE WAIVERS

2.16 Freedom of Information and Protection of Privacy Act

Are There Cases When You Should Not Use This Form? What Information Is Needed to Search for USCIS Records? Verification of Identity in Person.

2011 Open Government Update Patricia R. Gleason

The Local Authority Freedom of Information and Protection of Privacy Regulations

ORDINANCE ESTABLISHING REGULATION OF LOBBYISTS IN OAKLAND MUNICIPAL CODE CHAPTER Chapter THE CITY OF OAKLAND LOBBYIST REGISTRATION ACT

THE INTERSTATE COMPACT FOR JUVENILES ARTICLE I PURPOSE

MANITOBA FREEDOM OF INFORMATION AND PROTECTION OF PRIVACY RESOURCE MANUAL

Data Protection Policy

Access to Personal Information Procedure

THE FREEDOM OF INFORMATION ACT, Arrangement of Sections PART I PRELIMINARY

U.S. POSTAL SERVICE FREEDOM OF INFORMATION ACT (FOIA) REPORT FOR FISCAL YEAR 2013 I. BASIC INFORMATION REGARDING REPORT

PlainSite. Legal Document. District Of Columbia District Court Case No. 1:07-mc RJL TROLLINGER et al v. TYSON FOODS, INC.

Health Information Privacy Code 1994

Rhode Island False Claims Act

BILL NO. 42. Health Information Act

Data Protection Bill [HL]

Broward College Focused Report August 26, 2013

EXPLANATORY NOTES B I L L. No. 31. An Act to amend The Local Authority Freedom of Information and Protection of Privacy Amendment Act

THEMATIC COMPILATION OF RELEVANT INFORMATION SUBMITTED BY THE UNITED STATES ARTICLE 10 UNCAC PUBLIC REPORTING

Privacy Impact Assessment. April 25, 2006

GUYANA. ACT No. 5 of 2004 AUDIT ACT 2004

FREEDOM OF INFORMATION ACT (FOIA) PROCEDURES AND GUIDELINES

Government Data Practices Law Survey Legislative Commission on Data Practices December 22, House Research Department

PROFESSIONAL SERVICES CONSULTING AGREEMENT

District of Columbia False Claims Act

POLICY STATEMENT. Topic: False Claims Act Date Effective: 10/13/08. X Revised New Section: Corporate Compliance Number: 10.05

To amend the Communications Act of 1934 to require 105TH CONGRESS 2D SESSION AN ACT H. R. 3783

IC Chapter 2. Criminal Justice Data Division

FREEDOM OF INFORMATION

Data Protection Bill [HL]

ADS Chapter 105. Committee Management

Transcription:

A Basic Overview of The Privacy Act of 1974 Denver, CO June 17, 2015 Presented by: Michael E. Reheuser Department of Defense What are today s goals? Gain a basic understanding of: The Privacy Act Compliance requirements Exceptions and exemptions to the Privacy Act Civil remedies and criminal penalties Purpose of The Privacy Act To regulate the collection, maintenance, use, and dissemination of personal information held by the Executive Branch of Government 1

Why the Privacy Act? To curb the illegal surveillance and investigation of individuals by federal agencies exposed during the Watergate scandal Concerned with potential abuses presented by the Government s increasing use of computers to store and retrieve personal data by means of a universal identifier Balance between government and citizens Privacy Act balances the federal government s obligations to collect data with citizens rights to have that data be accurate and not available for disclosure without their consent 5 Basic Policy Objectives To restrict disclosure of personally identifiable records maintained by Executive branch agencies To grant individuals increased rights of access to agency records maintained on themselves To grant individuals the right to seek amendment of agency records that are not accurate, relevant, timely, or complete To establish a code of "fair information practices that regulates the collection, use, maintenance and disclosure of personally identifiable information 2

Privacy Act Basics What info is protected by the Privacy Act? Whose info is protected by the Privacy Act? How does the Privacy Act protect you? What info is protected by the Privacy Act? Privacy Act protects information on individuals held by an agency that is in a system of records Group of records from which information is retrieved by the name of an individual or by some other identifying particular assigned to the individual Retrieved vs. Retrievable A system of records exists if: There is an indexing or retrieval capability using identifying particulars built into the system, and The agency does in fact retrieve records about individuals by utilizing a personal identifier 3

System of Records Notice Requirements: Must Publish a System of Records Notice in the Federal Register Why is this important? Most of the rights and requirements of the Privacy Act depend on whether the definition is met Agency Requirements Maintain only accurate, relevant, complete and timely information Collect information directly from the source Provide a Privacy Act Statement Publish new or altered notice in the Federal Register Agency Requirements Establish rules of conduct for those who work with records protected by the Privacy Act Establish appropriate administrative and technical controls Maintain no record regarding an individual s exercise of their First Amendment rights unless expressly authorized by statute, the individual, or unless pertinent to and within the scope of an authorized law enforcement activity 4

Government Contractors Subsection (m) of the Privacy Act makes provisions of the Act binding on contractors who operate a system of records to accomplish an agency function For the purposes of criminal penalties, subsection (m) contractors are considered agency employees Whose info is protected by the Privacy Act? An individual United States citizens or an alien lawfully admitted for permanent residence Deceased individuals are not covered Corporations and organizations not covered How does the Privacy Act protect you? Access rights Amendment rights Private right of actions for violations Criminal and civil penalties 5

Individuals Right of Access The Privacy Act provides an individual with an independent means of access to his/her records that are maintained in a system of records. No Disclosure Without Consent General Rule - NO disclosure unless you have: (1) Written request from the subject or (2) Prior written consent from the subject authorizing a 3 rd party to gain access (3) One of the 12 Exceptions established in 5 U.S.C. 552a(b) Exceptions and Exemptions Exceptions-When can an agency provide someone s records to another without their consent? Exemptions-When can an agency deny someone access to their own records? 6

Twelve Exceptions (b)(1) Intra-agency disclosures need to know (b)(2) Disclosure required by FOIA (b)(3) Routine Use (b)(4) Bureau of Census (b)(5) Statistical research and reporting (b)(6) NARA Twelve Exceptions (b)(7) Law enforcement (b)(8) Compelling circumstances affecting health and safety (b)(9) Congress (b)(10) GAO (b)(11) Court Order (b)(12) Debt Collection Act Ten Exemptions 1. (d)(5) exempts information compiled in the reasonable anticipation of a civil action or proceeding from the access provisions of the Privacy Act. Most similar to attorney work product Not limited to purely judicial proceedings, but also covers administrative hearings 7

Ten Exemptions 2. (j)(1) information maintained by the CIA 3. (j)(2) information maintained by a principal function criminal law enforcement agency and compiled for a criminal law enforcement purpose Ten Exemptions 4. (k)(1) classified information 5. (k)(2) investigatory material compiled for law enforcement purposes, other than material within the scope of (j)(2) 6. (k)(3) maintained in connection with providing protective services for the President of the United States or other individuals 7. (k)(4) required by statute to be maintained and used solely as a statistical record Ten Exemptions 8. (k)(5) information that reveals a source who was provided an express promise of confidentiality in the context of background investigation materials 9. (k)(6) testing materials used solely to determine an individuals qualifications for appointment or promotions in the Federal service 10. (k)(7) evaluation materials used to determine potential for promotion in the military 8

Accounting of Certain Disclosures Each agency must maintain an accounting of disclosures from a system of record except when disclosures are made under: (b)(1) (b)(2) Agencies must make the accounting available to the subject except for those made under (b)(7) Civil Remedies Amendment lawsuits Access lawsuits Accuracy lawsuits for damages Other damages lawsuits Criminal Penalties Misdemeanor and fine not to exceed $5,000 Any officer or employee who knowingly and willfully discloses identifiable information to any person who is not entitled to receive it Any officer or employee who willfully maintains a secret system of records Knowingly and willingly requests or obtains Privacy Act protected records under false pretenses. 9

Privacy Act Resources Under subsection (v). OMB has primary responsibility for Privacy Act oversight Office of Information and Regulatory Affairs OMB Privacy Act guidelines - 40 Fed Reg. 28,948-78 (July 1975) http://www.whitehouse.gov/omb/inforeg/inf opoltech.html Text of the Privacy Act and Privacy Act Overview are available online at www.justice.gov 10