TMCnet News
Office of the Secretary of Defense and Joint Staff Privacy ProgramOct 30, 2009 (Defense Department Documents and Publications/ContentWorks via COMTEX) -- SUMMARY: This rule revises 32 CFR part 311 to update Office of the Secretary of Defense (OSD) and Joint Staff (JS) policy, assigns responsibilities, and prescribes procedures for the effective administration of the Privacy Act (PA) Program in OSD and JS. This rule supplements and implements 32 CFR part 310, the DoD Privacy Program. EFFECTIVE DATE: Effective Date: This rule is effective November 30, 2009. FOR FURTHER INFORMATION CONTACT: Cindy Allard, 703-588-6830. SUPPLEMENTARY INFORMATION: A proposed rule published in the Federal Register on January 23, 2007 (72 FR 2819-2823). No comments were received. The following has been included in the final rule based on internal comments received on the corresponding DoD administrative instruction: A reordering of some sections was accomplished to facilitate readability. A new section "OSD/JS Privacy Office Processes" was added to define the role of the OSD/JS Privacy Office in the program. Executive Order 12866, "Regulatory Planning and Review" It has been certified that 32 CFR part 311 does not: (1) Have an annual effect on the economy of $100 million or more or adversely affect in a material way the economy; a section of the economy; productivity; competition; jobs; the environment; public health or safety; or State, local, or tribunal governments or communities; (2) Create a serious inconsistency or otherwise interfere with an action taken or planned by another Agency; (3) Materially alter the budgetary impact of entitlements, grants, user fees, or loan programs, or the rights and obligations of recipients thereof; or (4) Raise novel legal or policy issues arising out of legal mandates, the President's priorities, or the principles set forth in this Executive Order 12866, as amended by Executive Order 13422. Sec. 202, Pub. L. 104-4, "Unfunded Mandates Reform Act" It has been certified that 32 CFR part 311 does not contain a Federal mandate that may result in the expenditure by State, local and tribunal governments, in aggregate, or by the private sector, of $100 million or more in any one year. Public Law 96-354, "Regulatory Flexibility Act" (5 U.S.C. 601) It has been certified that 32 CFR part 311 is not subject to the Regulatory Flexibility Act (5 U.S.C. 601) because it would not, if promulgated, have a significant economic impact on a substantial number of small entities. The rule implements the procedures for the effective administration of the Privacy Act Program in OSD and the JS. Public Law 96-511, "Paperwork Reduction Act" (44 U.S.C. Chapter 35) It has been certified that 32 CFR part 311 does not impose reporting or recordkeeping requirements under the Paperwork Reduction Act of 1995. Executive Order 13132, "Federalism" It has been certified that 32 CFR part 311 does not have federalism implications, as set forth in Executive Order 13132. This rule does not have substantial direct effects on: (1) The States; (2) The relationship between the National Government and the States; or (3) The distribution of power and responsibilities among the various levels of Government. List of Subjects in 32 CFR Part 311 Privacy Act. Accordingly, 32 CFR part 311 is revised to read as follows: PART 311--OFFICE OF THE SECRETARY OF DEFENSE AND JOINT STAFF PRIVACY PROGRAM Sec. 311.1 Purpose. 311.2 Applicability. 311.3 Definitions. 311.4 Policy. 311.5 Responsibilities. 311.6 Procedures. 311.7 OSD/JS Privacy Office Processes. Authority: 5 U.S.C. 552a. SEC 311.1. Purpose. This part revises 32 CFR part 311 to update Office of the Secretary of Defense (OSD) and Joint Staff (JS) policy, assigns responsibilities, and prescribes procedures for the effective administration of the Privacy Program in OSD and the JS. This part supplements and implements part 32 CFR part 310, the DoD Privacy Program. SEC 311.2. Applicability. This part: (a) Applies to OSD, the Office of the Chairman of the Joint Chiefs of Staff and the Joint Staff, and all other activities serviced by Washington Headquarters Services (WHS) that receive privacy program support from OSD/JS Privacy Office, Executive Services Directorate (ESD), WHS (hereafter referred to collectively as the "WHS-Serviced Components)." (b) Covers systems of records maintained by the WHS-Serviced Components and governs the maintenance, access, change, and release information contained in those systems of records, from which information about an individual is retrieved by a personal identifier. SEC 311.3. Definitions. (a) Access. The review of a record or a copy of a record or parts thereof in a system of records by any individual. (b) Computer matching program. A program that matches the personal records in computerized databases of two or more Federal agencies. (c) Disclosure. The transfer of any personal information from a system of records by any means of communication (such as oral, written, electronic, mechanical, or actual review) to any person, private entity, or Government Agency, other than the subject of the record, the subject's designated agent or the subject's legal guardian. (d) Individual. A living person who is a citizen of the United States or an alien lawfully admitted for permanent residence. The parent of a minor or the legal guardian of any individual also may act on behalf of an individual. Members of the United States Armed Forces are "individuals." Corporations, partnerships, sole proprietorships, professional groups, businesses, whether incorporated or unincorporated, and other commercial entities are not "individuals" when acting in an entrepreneurial capacity with the Department of Defense but are "individuals" otherwise (e.g., security clearances, entitlement to DoD privileges or benefits, etc.). (e) Individual access. Access to information pertaining to the individual by the individual or his or her designated agent or legal guardian. (f) Maintain. To maintain, collect, use, or disseminate records contained in a system of records. (g) Personal information. Information about an individual that identifies, links, relates, or is unique to, or describes him or her, e.g., a social security number; age; military rank; civilian grade; marital status; race; salary; home/office phone numbers; other demographic, biometric, personnel, medical, and financial information, etc. Such information also is known as personally identifiable information (i.e., information which can be used to distinguish or trace an individual's identity, such as their name, social security number, date and place of birth, mother's maiden name, biometric records, including any other personal information which is linked or linkable to a specified individual). (h) Record. Any item, collection, or grouping of information, whatever the storage media (e.g., paper, electronic, etc.), about an individual that is maintained by a WHS-Serviced Component, including, but not limited to, his or her education, financial transactions, medical history, criminal or employment history, and that contains his or her name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a finger or voice print or a photograph. (i) System manager. A WHS-Serviced Component official who has overall responsibility for a system of records. The system manager may serve at any level in OSD. Systems managers are indicated in the published systems of records notices. If more than one official is indicated as a system manager, initial responsibility resides with the manager at the appropriate level (i.e., for local records, at the local activity). (j) System of records. A group of records under the control of a WHS-Serviced Component from which personal information about an individual is retrieved by the name of the individual or by some other identifying number, symbol, or other identifying particular assigned, that is unique to the individual. SEC 311.4. Policy. It is DoD policy, in accordance with 32 CFR part 310, that: (a) Personal information contained in any system of records maintained by any DoD organization shall be safeguarded. To the extent authorized by section 552a of title 5, United States Code, commonly known and hereafter referred to as the "Privacy Act" and Appendix I of Office of Management and Budget Circular No. A-130 (available at http://www.whitehouse.gov/omb/assets/omb/circulars/a130/a130trans4.pdf), an individual shall be permitted to know what existing records pertain to him or her consistent with 32 CFR part 310. (b) Each office maintaining records and information about individuals shall ensure that this data is protected from unauthorized collection, use, dissemination and/or disclosure of personal information. These offices shall permit individuals to have access to and have a copy made of all or any portion of records about them, except as provided in 32 CFR 310.17 and 310.18. The individuals will also have an opportunity to request that such records be amended as provided by 32 CFR 310.19 . Individuals requesting access to their records shall receive concurrent consideration under section 552 of title 5, United States Code (commonly known and hereafter referred to as the "Freedom of Information Act"). --This is a summary of a Federal Register article originally published on the page number listed below-- Final rule. CFR Part: "32 CFR Part 311" Citation: "74 FR 56113" Document Number: "DoD-2006-OS-0033; RIN 0790-AI26" Federal Register Page Number: "56113" "Rules and Regulations" |
