Shows & Panels
- Accelerate and Streamline for Better Customer Service
- Ask the CIO
- The Big Data Dilemma
- Carrying On with Continuity of Operations
- Client Virtualization Solutions
- Data Protection in a Virtual World
- Expert Voices
- Federal Executive Forum
- Federal IT Challenge
- Federal Tech Talk
- Feds in the Cloud
- Health IT: A Policy Change Agent
- Improving Healthcare Outcomes through IT Policy
- IT Innovation in the New Era of Government
- Making Dollars And Sense Out of Data Center Consolidation
- Navigating the Private Cloud
- One Step to the Cloud, Two Steps Toward Innovation
- Path to FDCCI Compliance
- Take Command of Your Mobility Initiative
- Veterans in Private Sector: Making the Transition
Shows & Panels
OIRA outlines privacy assessments for using 3rd party websites
Thursday - 1/5/2012, 3:02pm EST
Kevin Nyland, the deputy administrator in OMB's Office of Information and Regulatory Policy, sent agency chief information officers a memo Dec. 29 outlining how agencies should prepare an adapted Privacy Impact Assessment (PIA). The PIA should address specific functions of a third-party website or application that the agency is using.
Agencies must complete the PIA before using a third-party website, which could include commercial offerings such as YouTube, Facebook or survey sites.
"To facilitate agency use of third-party websites and applications, OMB has worked with the CIO Council's Privacy Committee to develop a model PIA reflecting the requirements for an adapted PIA," the memo stated.
The PIA memo calls on agencies to develop a PIA with eight sections:
- Specific purpose of how the agency is using the third-party site or application.
- Any personal identifiable information (PII) likely to become available to the agency through the use of the site or app.
- How the agency will use the PII.
- How the agency will share or disclose the personal information.
- How the agency will maintain and retain the personal information.
- How will the PII be secured.
- How the agency will identify and mitigate other privacy risks.
- How the agency will create or modify a system of records.
"An agency may prepare one PIA to cover multiple websites or applications that are functionally comparable, as long as the agency's practices are substantially similar across each website and application," the memo stated.
"For example, one PIA may be sufficient to cover an agency's use of multiple social media websites where limited PII is made available to the agency, but none is collected, shared or maintained. However, if an agency's use of a website or application raises distinct privacy risks, the agency should prepare a PIA that is exclusive to that website or application."