Attachment-G7-ACF_Privacy Impact Assessment_V1.0.docx

DOCX document 50 KB Posted

Attached to
Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
Solicitation number
75P00126R00003
Issued by
Not on record

About this file

This is a Privacy Impact Assessment (PIA) form template used to evaluate privacy considerations for federal information systems and data handling practices. The form is a blank template designed for the Office of Personnel Development and Information (OPDIV) within the Department of Health and Human Services (HHS) to assess systems that collect, maintain, or share personally identifiable information (PII).

The form requires the submitting organization to identify the system name, lifecycle phase, and whether it is FISMA-reportable. It requests designation of whether the system is operated by an agency or contractor and requires point of contact information. The template prompts identification of PII types including Social Security numbers, dates of birth, names, photographic identifiers, driver's license numbers, biometric identifiers, email addresses, mailing addresses, phone numbers, financial account information, medical records, passports, and other sensitive data. It also requires categorization of individuals whose information is collected, such as employees, public citizens, business partners, vendors, contractors, or patients. The form includes sections for describing the purpose and scope of the system, the types of data collected and maintained, and assessment of changes to existing systems. This template is essential for ensuring HHS systems comply with federal privacy requirements and protections, particularly relevant given this solicitation's focus on legal services for unaccompanied alien children who require sensitive information handling protocols.

View the file

Other files for this federal contract opportunity

Other files attached to Legal Services for Unaccompanied Alien Children (UAC), newest first.
File Type Posted
Amendment 15 - RFP UAC Legal Services.pdf PDF
Amendment 15 - Attachment K Direct Representation Case Inventory Report June 06 2026.pdf PDF
Attachment-G5-ACF_Incident Response Plan_V1.0.docx DOCX document
Attachment E - Quality Assurance Surveillance Plan (QASP) UAC Legal Services_20260515.docx DOCX document
Attachment-G6-ACF_Interconnection Security Agreement_V1.0.docx DOCX document
Attachment-G3-ACF_Configuration Management Plan.docx_V1.0.docx DOCX document
Attachment-G2-ACF_Business Impact Analysis.docx_V1.0.docx DOCX document
Attachment-G1-ACF_ E-Authentication Agreement_V1.0.docx DOCX document
Attachment H - Glossary of Abbreviations and Acronyms_20260513.docx DOCX document
Attachment F - ACF External System Control Implementation Policy and Procedures_20251203.docx DOCX document
RFP UAC LEGAL SERVICES 20260515.pdf PDF
Attachment-G8-ACF_System Categorization_V1.0.docx DOCX document
Attachment I - Contractor Past Performance Narrative Template_20260513.docx DOCX document
Attachment C - Standard Form (SF)-1449_20260513.pdf PDF
Attachment B - Section C- Performance Work Statement (PWS) UAC Legal Services_20260515.docx DOCX document
Attachment A - Pricing Worksheet UAC Legal Services_20260513.xlsx XLSX spreadsheet
Attachment J- Questions and Answers_2026.03.24 (Amd 0010).pdf PDF
Attachment A- Pricing Worksheet_2026.03.24 (Amd 0010).xlsx XLSX spreadsheet
Attachment C- Standard Form (SF)-1449.pdf PDF
75P00126R00003_2026.03.24 (Amd 0010).pdf PDF
Attachment A- Pricing Worksheet UAC Legal Services (Amd. 0007) 2026.02.23.xlsx XLSX spreadsheet
Attachment B- Section C- PWS (Amd 0007) 2026.02.23.pdf PDF
Attachment E- Quality Assurance Surveillance Plan (QASP) (Amd. 0007) 2026.02.23.pdf PDF
Attachment H- Glossary of Abbreviations and Acronyms.pdf PDF
Attachment G- ATO Templates-2025.zip ZIP file
75P00126R00003_2026.02.23.pdf PDF
Attachment D - ORR Facilities by State.xlsx XLSX spreadsheet
Attachment F- ACF External System Control Implementation Policy and Procedures.pdf PDF
Attachment I- Past Performance Questionnaire.docx DOCX document
Attachment C- Standard Form (SF)-1449.pdf PDF
QA-75P00126R00003(Rev1) (Amd 0004)(12.11.2025)#Q127.pdf PDF
75P00126R00003 (Rev2)(Amd 0004)(12.11.2025).pdf PDF
Attachment B-Pricing Worksheet UAC Legal Services (Rev2) (Amd 0004)(12.11.2025).xlsx XLSX spreadsheet
Attachment A- Performance Work Statement (PWS) (Rev1) (Amd 0003) (12.09.2025).pdf PDF
Attachment F- Quality Assurance Surveillance Plan (QASP)(Rev1)(Amd 0003)(12.09.2025).pdf PDF
Attachment H- ATO Templates_2025 (Amd 0003).zip ZIP file
QA-75P00126R00003(12.09.2025) (Amd 0003).pdf PDF
75P00126R00003 (Rev1)(Amd 0003)(12.09.2025).pdf PDF
Attachment J- Selected Controls (Low) (Amd 0003).xlsx XLSX spreadsheet
Attachment B-Pricing Worksheet UAC Legal Services (Rev1) (Amd 0003)(12.09.2025).xlsx XLSX spreadsheet
Attachment E- ORR Facilities by State (Amd 0003).pdf PDF
Attachment G- ACF External System Control Implementation Policy and Procedures (Amd 0003).pdf PDF
Attachment I- Selected Controls (Moderate) (Amd 0003).xlsx XLSX spreadsheet
Attachment B- Pricing Worksheet UAC Legal Services (11.25.2025).xlsx XLSX spreadsheet
Attachment B- Pricing Worksheet UAC Legal Services.xlsx XLSX spreadsheet
Attachment C- HHS Subcontracting Plan Review Form.doc DOC document
75P00126R00003.pdf PDF
Attachment A - Performance Work Statement (PWS)_2025.11.24.pdf PDF
Attachment D- Standard Form (SF)-1449.pdf PDF
Attachment F- Quality Assurance Surveillance Plan (QASP).pdf PDF
Show all 50

Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Privacy Impact Assessment Form

1
OPDIV:
2
PIA Unique Identifier:
2a
Name:
Enter System Name
3
The subject of this PIA is which of the following?
☐ General Support System (GSS)

☐ Major Application ☐ Minor Application (stand-alone) ☐ Minor Application (child) ☐ Electronic Information Collection ☐ Unknown

3a
Identify the Enterprise Performance Lifecycle Phase of the system.
☐ Initiation

☐ Concept ☐ Planning ☐ Requirements Analysis ☐ Design ☐ Development ☐ Test ☐ Implementation ☐ Operations and Maintenance ☐ Disposition

3b
Is this a FISMA-Reportable system?
☐ Yes

☐ No

4
Does the system include a Website or online application available to and for the use of the general public?
☐ Yes

☐ No (skip questions 39 onwards)

5
Identify the operator.
☐ Agency

☐ Contractor

6
Point of Contact (POC):
POC Title

POC Name

POC Organization

POC Email

POC Phone

7
Is this a new or existing system?
☐ New (skip questions 9-10)

☐ Existing

8
Does the system have Security Authorization (SA)?
☐ Yes (skip question 8b)

☐ No (skip question 8a)

8a
Date of Security Authorization
8b
Planned Date of Security Authorization

☐ Not Applicable

9
Indicate the following reason(s) for updating this PIA. Choose from the following options.
☐PIA Validation (PIA Refresh/Annual Review)
☐ Significant System Management Change
☐ Anonymous to Non-Anonymous
☐ Alteration in Character of Data
☐ New Public Access
☐ New Interagency Uses
☐ Internal Flow or Collection
☐ Conversion

☐ Commercial Sources

10
Describe in further detail any changes to the system that have occurred since the last PIA.
11
Describe the purpose of the system.
12
Describe the type of information the system will collect, maintain (store), or share. (Subsequent questions will identify if this information is PII and ask about the specific data elements.)
13
Provide an overview of the system and describe the information it will collect, maintain (store), or share, either permanently or temporarily.
14
Does the system collect, maintain, use or share PII?
☐ Yes

☐ No (skip questions 15-38)

15
Indicate the type of PII that the system will collect or maintain.
☐ Social Security Number
☐ Date of Birth
☐ Name
☐ Photographic Identifiers
☐ Driver's License Number
☐ Biometric Identifiers
☐ Mother's Maiden Name
☐ Vehicle Identifiers
☐ E-Mail Address
☐ Mailing Address
☐ Phone Numbers
☐ Medical Records Number
☐ Medical Notes
☐ Financial Account Info
☐ Certificates
☐ Legal Documents
☐ Education Records
☐ Device Identifiers
☐ Military Status
☐ Employment Status
☐ Foreign Activities
☐ Passport Number

☐ Taxpayer ID

16
Indicate the categories of individuals about whom PII is collected, maintained or shared.
☐ Employees

☐ Public Citizens ☐ Business Partners/Contacts (Federal, state, local agencies) ☐ Vendors/Suppliers/Contractors ☐ Patients

Other

17
How many individuals' PII is in the system?
☐ <100
☐ 10,000-49,999
☐ 100-499
☐ 50,000-99,999
☐ 500-4,999
☐ 100,000-999,999
☐ 5,000-9,999
☐ 1,000,000 or more
18
For what primary purpose is the PII used?
19
Describe the secondary uses for which the PII will be used (e.g. testing, training or research)
20
Describe the function of the SSN.
20a
Cite the legal authority to use the SSN.
21
Identify legal authorities governing information use and disclosure specific to the system and program.
22
Are records on the system retrieved by one or more PII data elements?
☐ Yes

☐ No (skip question 22a)

22a
Identify the number and title of the Privacy Act

System of Records Notice (SORN) that is being used to cover the system or identify if a SORN is being developed.

Published:

Published:

Published:

☐ In Progress

23
Identify the sources of PII in the system.
Directly from an individual about whom the information pertains

☐ In-Person ☐ Hard Copy: Mail/Fax ☐ Email ☐ Online ☐ Other Government Sources ☐ Within the OPDIV ☐ Other HHS OPDIV ☐ State/Local/Tribal ☐ Foreign ☐ Other Federal Entities ☐ Other Non-Government Sources ☐ Members of the Public ☐ Commercial Data Broker ☐ Public Media/Internet ☐ Private Sector ☐ Other

23a
Identify the OMB information collection approval number and expiration date.
24
Is the PII shared with other organizations?
☐ Yes

☐ No (skip question 24a-c)

24a
Identify with whom the PII is shared or disclosed and for what purpose.
☐ Within HHS

☐ Other Federal Agency/Agencies

☐ State or Local Agency/Agencies

☐ Private Sector

24b

Describe any agreements in place that authorizes the information sharing or disclosure (e.g. Computer Matching Agreement, Memorandum of Understanding (MOU), or Information Sharing Agreement (ISA)).

24c
Describe the procedures for accounting for disclosures
25
Describe the process in place to notify individuals that their personal information will be collected. If no prior notice is given, explain the reason.
26
Is the submission of PII by individuals voluntary or mandatory?
☐ Voluntary

☐ Mandatory

27
Describe the method for individuals to opt-out of the collection or use of their PII. If there is no option to object to the information collection, provide a reason.
28
Describe the process to notify and obtain consent from the individuals whose PII is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of original collection). Alternatively, describe why they cannot be notified or have their consent obtained.
29
Describe the process in place to resolve an individual's concerns when they believe their PII has been inappropriately obtained, used, or disclosed, or that the PII is inaccurate. If no process exists, explain why not.
30
Describe the process in place for periodic reviews of PII contained in the system to ensure the data's integrity, availability, accuracy and relevancy. If no processes are in place, explain why not.
31
Identify who will have access to the PII in the system and the reason why they require access.
☐ Users

☐ Administrators

☐ Developers

☐ Contractors

☐ Others

32
Describe the procedures in place to determine which system users (administrators, developers, contractors, etc.) may access PII.
33
Describe the methods in place to allow those with access to PII to only access the minimum amount of information necessary to perform their job.
34
Identify training and awareness provided to personnel (system owners, managers, operators, contractors and/or program managers) using the system to make them aware of their responsibilities for protecting the information being collected and maintained.
35
Describe training system users receive (above and beyond general security and privacy awareness training).
36
Do contracts include Federal Acquisition Regulation and other appropriate clauses ensuring adherence to privacy provisions and practices?
☐ Yes

☐ No

37
Describe the process and guidelines in place with regard to the retention and destruction of PII. Cite specific records retention schedules.
38
Describe, briefly but with specificity, how the PII will be secured in the system using administrative, technical, and physical controls.
39
Identify the publicly-available URL:
40
Does the website have a posted privacy notice?
☐ Yes

☐ No (skip question 40a)

40a
Is the privacy policy available in a machine-readable format?
☐ Yes

☐ No

41
Does the website use web measurement and customization technology?
☐ Yes

☐ No (skip question 41a)

41a
41a Select the type of website measurement and customization technologies is in use and if it is used to collect PII. (Select all that apply)
Technologies
Collects PII?
☐ Web beacons
☐ Yes

☐ No

☐ Web bugs
☐ Yes
☐ Session Cookies
☐ Yes
☐ Persistent Cookies
☐ Yes

Other

☐ Yes ☐ No

42
Does the website have any information or pages directed at children under the age of thirteen?
☐ Yes

☐ No (skip question 42a)

42a
Is there a unique privacy policy for the website, and does the unique privacy policy address the process for obtaining parental consent if any information is collected?
☐ Yes

☐ No

43
Does the website contain links to non- federal government websites external to HHS?
☐ Yes

☐ No (skip question 43a)

43a
Is a disclaimer notice provided to users that follow external links to websites not owned or operated by HHS?
☐ Yes

File details come from the government source that posted it. Updated .