24Q0002_ATTCH72930a.pdf
PDF 3 MB Posted
- Attached to
- World Language Instructional Resources Federal contract opportunity
- Solicitation number
- HE125424Q0002
- Issued by
- Department of Defense Education Activity
About this file
This document is an Adapted Privacy Impact Assessment form used by the Department of Defense to assess privacy risks associated with using third-party websites and applications. The form requires the DoD component to identify any personally identifiable information made available through the third-party system, how it will be used and secured, whether the activities create a system of records, and other privacy risks and mitigation plans. It also requires multiple sign-offs before use.
The related federal contract opportunity is a solicitation from the Department of Defense Education Activity for world language instructional resources. The solicitation includes reference number HE125424Q0002 but no other details such as response date, period of performance, pricing terms, or incumbent are provided in this document form.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 24Q0002_Amend_122023.pdf | ||
| 24Q0002_Attch9_121623.pdf | ||
| 24Q0002_ATTCH2TOS.docx | DOCX document | |
| 24Q0002_ATTCH1_PRICNGWKSHT_120423.xlsx | XLSX spreadsheet | |
| 24Q0002_SOL_120523.pdf | ||
| 24Q0002_PWS_120523.pdf | ||
| 24Q0002_ATTCH4CloudQ.pdf | ||
| 24Q0002_ATTCH6PrivChklist.pdf | ||
| 24Q0002_ATTCH8PPQuestionnaire.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
DD FORM 2930A, AUG 2011
Page of DD Form 2930A, Adapted Privacy Impact Assessment (Adp-PIA), August 2011
WHS/ESD/IMD
Adapted PRIVACY IMPACT ASSESSMENT (Adp-PIA) Third-Party Website or Application Name:
DoD Component Name:
This Adapted PIA (Adp-PIA) Form 2930A is to be used when personally identifiable information (PII) is likely to become available via a third-party website or application (such as Facebook and YouTube). Refer to the Appendix for the definition of third-party websites or applications.
This Adapted PIA (Adp-PIA) is intended to support the management of risk to privacy. If it is likely that personally identifiable information (PII) will become available via a third-party website or application, complete this form.
(1) Describe the specific purpose of the DoD Component's use of the third-party website or application.
(2) Describe any personally identifiable information (PII) that is likely to become available to the DoD Component through public use of the third-party website or application.
(3) Describe the circumstances under which PII will likely become available on the third-party website or application.
(4) With whom will the DoD Component share PII?
(5) Will the DoD Component maintain PII? If yes, for how long, and under what circumstances?
(6) Describe the means and steps by which the DoD Component will secure PII that it uses or maintains.
(7) Describe what other privacy risks exist and how the DoD Component will mitigate those risks.
(8) Will the DoD Component's activities create or modify a "system of records" under the Privacy Act? If yes, describe.
REVIEW AND APPROVAL SIGNATURES
Action Officer or Requestor Component Senior Official for Privacy (CSOP), or designee Component CIO or designee (i.e., Department of the Navy CIO, Department of the Air Force CIO, etc.)
APPENDIX
Definitions.
Make PII Available - The term "make PII available" includes any agency action that causes PII to become available or accessible to the agency, whether or not the agency solicits or collects it. In general, an individual can make PII available to an agency when he or she provides, submits, communicates, posts, or associates PII while using the website or application. "Associate" can include activities commonly referred to as "friend-ing," "following," "liking," joining a "group," becoming a "fan," and comparable functions.
Personally Identifiable Information (PII) - The term “PII,” as defined in OMB Memorandum M-07-16 (Note 1) refers to information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other personal or identifying information that is linked or linkable to a specific individual. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-PII can become PII whenever additional information is made publicly available — in any medium and from any source — that, when combined with other available information, could be used to identify an individual.
Privacy Impact Assessment (PIA) - The term “PIA,” which is now subject to the modifications in this Memorandum, was defined in OMB Memorandum M-03-22 (Note 2) as:
[A]n analysis of how information is handled: (i) to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy, (ii) to determine the risks and effects of collecting, maintaining and disseminating information in identifiable form in an electronic information system, and (iii) to examine and evaluate protections and alternative processes for handling information to mitigate potential privacy risks.
Third-party Websites or Applications - The term "third-party websites or applications" refers to web-based technologies that are not exclusively operated or controlled by a government entity, or web-based technologies that involve significant participation of a government entity. Often these technologies are located on a ".com" website or other location that is not part of an official government domain (Note 3). However, third-party applications can also be embedded or incorporated on an agency's official website.
Note 1: OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information (May 22, 2007), available at:
http://www.whitehouse.gov/OMB/memoranda/fy2007/m07-16.pdf.
Note 2: OMB Memorandum M-03-22, OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002 (Sept. 26, 2003), available at: http://www.whitehouse.gov/omb/memoranda_m03-22/.
Note 3: See OMB Memorandum M-05-04, Policies for Public Agency Websites (Dec. 17, 2004) (identifying ".gov," ".mil," and "Fed.us" as appropriate government domains), available at:
http://www.whitehouse.gov/OMB/memoranda/fy2005/m05-04.pdf.
| CurrentPage: |
| PageCount: |
| Third-Party Website(s)/Application(s) Name:: |
| DoD Component Name: Department of Defense Education Activity (DoDEA) |
| (1) What is the specific purpose of the agency's use of IbC?: Define what this system/application will be used for. |
| (2) List any PII that is likely to become available to the agency through use of IbC:: List any PII to be used for this service (name, home address, home email, home phone, spouse name, health/medical information, SSN, etc.). Please include any biometric identifiers (fingerprints, facial photography, hand geometry, etc.) that will be used with this service. |
| (3) What is the agency's intended or expected use of PII?: How will PII become available to the vendor? User submission, data pulls from SIS or other DoDEA system, etc.? |
| (4) With whom will the agency share PII?: Who will DoDEA share PII with (other than the Contractor)? Include any routine uses outside of DoDEA, if any. |
| (5) Describe whether and how agency will maintain PII, and for how long.: Will DoDEA be maintaining the PII shared with this service? |
*If YES, add the records disposition instructions from records series 1900, DoD/DoDEA Schools and Institutions Records (https://www.dodea.edu/Offices/ExecutiveServices/RecordsManagement.cfm) and complete question (6).
| (6) Describe how the agency will secure PII that it uses or maintains.: Include technical safeguards and user restrictions/limitations, if any. |
| (7) Describe what other privacy risks exist and how the agency will mitigate those risks.: Defer to CISO (IA Risk Assessment). |
| (8) Describe whether the agency's activities will create or modify a "system of records" under the Privacy Act.: Is the information collected covered under SORN 26 (Department of Defense Education Activity Educational Records)? Refer to question (2). |
*Complete list of DoDEA SORNS (https://www.dodea.edu/Offices/ExecutiveServices/Privacy-Information-Collections-and-Forms-Management.cfm).
| ProgramMgrSign: |
| POCName: |
| POCTitle: |
| POCOrganization: |
| POCWorkPhone: |
| POCDSN: |
| POCEmailAddress: |
| POCReviewDate: |
| OtherOffSign1: |
| OtherOff1Name: |
| OtherOff1Title: |
| OtherOff1Org: |
| OtherOff1WPhone: |
| OtherOff1DSN: |
| OtherOff1Email: |
| OtherOff1RevDate: |
| OtherOffSign2: |
| OtherOff2Name: |
| OtherOff2Title: |
| OtherOff2Org: |
| OtherOff2WPhone: |
| OtherOff2DSN: |
| OtherOff2Email: |
| OtherOff2RevDate: |
| IASignature: |
| SAOPName: |
| SAOPTitle: |
| SAOPOrganization: |
| SAOPWorkPhone: |
| SAOPDSN: |
| SAOPEmail: |
| SAOPRevDate: |
| CIOSignature: |
| ReviewingName: |
| ReviewingTitle: |
| ReviewingOrganization: |
| ReviewingWork: |
| ReviewingDSN: |
| ReviewingEmail: |
| SignedReviewing: |
File details come from the government source that posted it. Updated .