Showing posts with label Privacy Act. Show all posts
Showing posts with label Privacy Act. Show all posts

Thursday, September 16, 2021

OMB Approves DHS Privacy Act Update NPRM

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking (NPRM) for the Office of the Secretary at DHS for “Privacy Act of 1974”. This rulemaking showed up for the first time in the Spring 2021 Unified Agenda. According to the abstract for that listing:

“The Department of Homeland Security (DHS or Department) is proposing to amend its regulations under the Privacy Act of 1974. DHS is proposing to update and streamline the language of several provisions.”

There is not enough information available at this time to determine what sort of impacts this might have on the Chemical Facility Anti-Terrorism Standards or the cybersecurity operations at CISA.

Thursday, September 29, 2011

FEMA SAR Privacy Exemption NPRM

Yesterday I wrote about a new Privacy Act system of records being established by the Federal Emergency Management Administration (FEMA) to support that agency’s implementation of the Department of Homeland Security’s ‘See Something Say Something’ program. Today, FEMA published in the Federal Register (76 FR 60387-60388) the notice of proposed rulemaking (NPRM) that I mentioned in that posting proposing the standard law enforcement Privacy Act exemptions for disclosure of personal information be applied to this new system of records.

Generally the Privacy Act provides that if a Federal government agency is keeping personal information on an individual that agency has a responsibility for notifying the individual of that record keeping, allowing the individual access to the information in those records, and providing a method for the individual to correct any incorrect information in that record.

The Privacy Act provides guidance on when those rules may legitimately be ignored by Federal agencies upon notice of proposed rulemaking. One of the typical examples is for records maintained for law enforcement or national security related investigations. Obviously law enforcement and intelligence type agencies cannot be forced to disclose information obtained in the process of an investigation while that investigation is on-going; that would allow subjects of investigation to better hide their illegal activities.

This NPRM is proposing that the FEMA Suspicious Activity Reporting system of records be exempted from four specific requirements related to the processing of requests for information under the Privacy Act. Those exemptions would be applied on a case-by-case basis when such requests are received by FEMA. Those exemptions cover:

• Accounting for disclosure of information to other Federal, State and local investigational agencies;

• Allowing individuals access to personal information being held about them in the system of records;

• Justifying the relevancy and necessity of the information being held in the system of records; and

• Maintaining rules and procedures for allowing access to the information being exempted.

As with all NPRM’s, public comments are being solicited. Comments may be posted to the Federal eRulemaking Portal (www.regulations.gov; Docket Number: DHS-2011-0091) and need to be submitted by October 31, 2011.

Friday, September 10, 2010

Information Sharing Environment Notices

Today the Department of Homeland Security published two notices in the Federal Register. The first notice announced the establishment of a new system of records that will be maintained by the Department while the second notice is a required notice of proposed rule making (NPRM) notifying the public that it intends to exempt portions of that new record system from one or more provisions of the Privacy Act because of criminal, civil, and administrative enforcement requirements.

The new record system that will be maintained by DHS is the Information Sharing Environment (ISE) Suspicious Activity Reporting (SAR) Initiative System of Records. This will allow currently collected Suspicious Activity Reports from various agencies within DHS to be collected, analyzed and shared. The information is expected to be shared “with authorized participants in the Nationwide Suspicious Activity Reporting Initiative, including other DHS components, federal departments and agencies, state, local and tribal law enforcement agencies, and the private sector” (75 FR 55335).

The compilation of the SARS will be authorized as long as those reports meet the established ISE Functional Standard for Suspicious Activity Reporting. According to the program notice that standard “defines an ISE-SAR as official documentation of observed behavior determined to have a potential nexus to terrorism (i.e., to be reasonably indicative of criminal activity associated with terrorism)” (75 FR 55336).

The exemption to Privacy Act rules is being claimed because some of the information being collected analyzed and disseminated relates “to official DHS national security, law enforcement, immigration, intelligence activities, and protective services to the President of the U.S. or other individuals pursuant to Section 3056 and 3056A of Title 18” (75 FR 55291). The NPRM notes that the “exemptions proposed here are standard law enforcement and national security exemptions exercised by a large number of federal law enforcement and intelligence agencies” (75 FR 55291).

Public comments on both the establishment of the system of records (Docket DHS-2010-0075) and the claimed law enforcement exemption to provisions of the Privacy Act (Docket DHS-2010-0076) may be filed via the Federal e-Rulemaking Portal. Such comments need to be filed by October 12th, 2010.

Saturday, November 29, 2008

CSAT Privacy Act Information

Earlier this week, DHS updated the Chemical Security portion of their Laws and Regulations web page. They added a link to the updated CSAT Privacy Impact Assessment required under the Privacy Act. The new Impact Assessment was needed because changes made in October to the CSAT web site allowed users to see the names and positions of other users registered with CSAT for the same facility. The Help Desk also has access to this information as well as the CVI training status of users. This aids them in dealing with users having problems with the CSAT system. CSAT registered users should review the Impact Assessment document to ensure that they know how their personal information is being used and shared. Or may be they ought to do it just to help justify the government’s cost of maintaining these documents
 
/* Use this with templates/template-twocol.html */