Shows & Panels
- AFCEA Answers
- Ask the CIO
- The Big Data Dilemma
- Carrying On with Continuity of Operations
- Connected Government
- Constituent Servicing
- Continuous Monitoring: Tools and Techniques for Trustworthy Government IT
- The Cyber Imperative
- Cyber Solutions for 2013 and Beyond
- Expert Voices
- Federal Executive Forum
- Federal IT Challenge
- Federal Tech Talk
- Mission-critical Apps in the Cloud
- The Path from Legacy Systems
- The Real Deal on Digital Government
- The Reality of Continuous Monitoring... Is Your Agency Secure?
- Veterans in Private Sector: Making the Transition
Shows & Panels
OIRA outlines privacy assessments for using 3rd party websites
Thursday - 1/5/2012, 3:02pm EST
Kevin Nyland, the deputy administrator in OMB's Office of Information and Regulatory Policy, sent agency chief information officers a memo Dec. 29 outlining how agencies should prepare an adapted Privacy Impact Assessment (PIA). The PIA should address specific functions of a third-party website or application that the agency is using.
Agencies must complete the PIA before using a third-party website, which could include commercial offerings such as YouTube, Facebook or survey sites.
"To facilitate agency use of third-party websites and applications, OMB has worked with the CIO Council's Privacy Committee to develop a model PIA reflecting the requirements for an adapted PIA," the memo stated.
The PIA memo calls on agencies to develop a PIA with eight sections:
- Specific purpose of how the agency is using the third-party site or application.
- Any personal identifiable information (PII) likely to become available to the agency through the use of the site or app.
- How the agency will use the PII.
- How the agency will share or disclose the personal information.
- How the agency will maintain and retain the personal information.
- How will the PII be secured.
- How the agency will identify and mitigate other privacy risks.
- How the agency will create or modify a system of records.
"An agency may prepare one PIA to cover multiple websites or applications that are functionally comparable, as long as the agency's practices are substantially similar across each website and application," the memo stated.
"For example, one PIA may be sufficient to cover an agency's use of multiple social media websites where limited PII is made available to the agency, but none is collected, shared or maintained. However, if an agency's use of a website or application raises distinct privacy risks, the agency should prepare a PIA that is exclusive to that website or application."