AFI_33-332 _Privacy_Act_Program.pdf

PDF 721 KB Posted

Attached to
OPERATIONAL TEST AND EVALUATION SERVICES (OTES) Federal contract opportunity
Solicitation number
FA7046-11-R-0003
Issued by
Department of the Air Force Materiel Command Test Center

About this file

AFI_33-332 _Privacy_Act_Program

View the file

Other files for this federal contract opportunity

Other files attached to OPERATIONAL TEST AND EVALUATION SERVICES (OTES), newest first.
File Type Posted
OTES TO 0003 Amendment 3 - 14 Oct 11.doc DOC document
OTES TO 0003 Amendment 3 - 14 Oct 11.doc DOC document
TO_02_Det_5_Bomber_Test_Division Amendment 3 - 14 Oct 11.docx DOCX document
OTES_RFP_Amendment 2 - 14 Oct 11.doc DOC document
PWS TO_01_Nuclear_Space Amendment 2 - 14 Oct 11.docx DOCX document
OTES Final RFP-PPI QuestionsResponses 14 Oct 11.xls XLS spreadsheet
Section L Amendment 2 - 14 Oct 11.docx DOCX document
Amendment 1Section L 10-7.docx DOCX document
ppi_tool.accdb —
Amendment 1 PWS Oct 7.docx DOCX document
Amendment 1 RFP.doc DOC document
Amendment 1 OTES_CDRLs10-7.docx DOCX document
Amendment 1OTES_QASP 10-7.docx DOCX document
AFTECMAN99-101.pdf PDF
Form_4.pdf PDF
Form_6.pdf PDF
Form_2.pdf PDF
Form_3.pdf PDF
Form_5.pdf PDF
Form_1.pdf PDF
Form_5.xfdl XFDL file
Final_ TO_02_Det_5_Bomber_Test_Division.docx DOCX document
Final_Sample_TO_03 JSPDS.docx DOCX document
FINAL OTES_QASP.docx DOCX document
Final_OTES_RFP_30Sep11.doc DOC document
Form_3.xfdl XFDL file
Form_4.xfdl XFDL file
Form_6.xfdl XFDL file
DRAFT OTES Responses.xlsx XLSX spreadsheet
form_1.xfdl XFDL file
OTES PWS 25_ Jul_ 11_AFL_A —
Det 5 Bomber Test Division TO_7_15_11_AFL.docx DOCX document
JSPDS Task Order 15_Jul_11_AFL.docx DOCX document
AFI_33-200 _Information_Assurance_Program.pdf PDF
OTES CDRLs 27 Jun 11.docx DOCX document
CJCS_Instruction_3170.01G_Joint_Capabilities_Intergration_ _Development_System.pdf PDF
AFOTECPAM_99-104 _AFOTEC_Operational_Suitability_Test_ _Evaluation_Guide.pdf PDF
Front_Ver_54_June_15_2010_34x22.pdf PDF
Air Force Proposal Adequacy Checklist —
DRAFT OTES RFP.doc DOC document
AFI_16-1001 _Verification _Validation_and_Accreditation_(VV A).pdf PDF
AFI_10-601 _Capabilities-based_Requirements_Development.pdf PDF
Det 5 Bomber Test Division TO_7_15_11_AFL.docx DOCX document
AFI_16-1002 _Modeling_ _Simulation_(M S)_Support_to_Acquisition.pdf PDF
AFI_33-100 _User_Responsibilities_ _Guidance_for_Information_Systems.pdf PDF
DoD_Instruction_5000.2 _Operation_of_the_Defense_Acquisition_System.pdf PDF
513408p CBRN DoD Implementation Directive.pdf PDF
AFOTEC_OT E_Guide _6th_Edition.pdf PDF
AFMAN_63-119 _Certification_of_System_Readiness_for_Dedicated_Operational_Test_ _Evaluation.pdf PDF
AFI_63-101 _Acquisition_ _Sustainment_Life_Cycle_Management.pdf PDF
Show all 50

OPERATIONAL TEST AND EVALUATION SERVICES (OTES) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

BY ORDER OF THE

SECRETARY OF THE AIR FORCE

AIR FORCE INSTRUCTION 33-332

29 JANUARY 2004

Communications and Information

PRIVACY ACT PROGRAM

COMPLIANCE WITH THIS PUBLICATION IS MANDATORY

ACCESSIBILITY: Publications and forms are available on the e-Publishing website at www.e-publishing.af.mil for downloading or ordering.

RELEASABILITY: There are no releasability restrictions on this publication.

OPR: AF-CIO/PX Certified by: AF-CIO/P (Col Anne Leary) Supersedes AFI 33-332, 8 November 2000. Pages: 63

This instruction implements Air Force Policy Directive (AFPD) 37-1, Air Force Information Manage-ment (will convert to AFPD 33-3). It also implements Department of Defense Directive (DoDD) 5400.11, DoD Privacy Program, December 13, 1999, and DoD 5400.11-R, Department of Defense Privacy Pro-gram, August 1983. It sets mandatory guidelines for collecting, safeguarding, maintaining, using, access-ing, amending and disseminating personal information kept in systems of records to comply with the Privacy Act, Title 5, United States Code (U.S.C.), Section 552a. Subject to the requirements of DoD 6025.18R, DoD Health Information Privacy Program, it takes precedence over any other instruction that deals with personal privacy and rights of individuals regarding their records. This instruction applies to the Air Force Reserve, Air National Guard, and those combatant commands where the Air Force is the executive agent; and to contractors by contract or other legally binding action, whenever an Air Force contract provides for the operation of a system of records or portion of a system of records to accomplish an Air Force function. This instruction requires collecting and maintaining information protected by the Privacy Act of 1974 authorized by Title 10, U.S.C., Section 8013. System of Records notice F033 AF B, Privacy Act Request File, applies. Maintain and dispose of records created as a result of processes pre-scribed by this instruction in accordance with Air Force Manual (AFMAN) 37-139, Records Disposition Schedule. Use of the term “MAJCOM” throughout this instruction includes major commands (MAJ- COM), field operating agencies (FOA), direct reporting units (DRU), and those combatant commands where Air Force is the executive agent. Send all supplements to this instruction to Air Force Chief Infor-mation Officer (AF-CIO)/P, 1155 Air Force Pentagon, Washington DC 20330-1155. Send recommended changes or comments to Headquarters Air Force Communications Agency (HQ AFCA/ITXD), 203 W.

Losey Street, Room 1100, Scott AFB IL 62225-5222, through appropriate channels, using AF IMT 847, Recommendation for Change of Publication, with an information copy to AF-CIO/P. AFI 33-360, Vol-ume 2, Forms Management Program, affect this publication. Refer to Attachment 1 for a glossary of ref-erences and supporting information.

http://www.e-publishing.af.mil

2 AFI33-332 29 JANUARY 2004

SUMMARY OF CHANGES

This document is substantially revised and must be completely reviewed.

This revision moves responsibility for the Air Force Privacy Program from AFCIC to AF-CIO; prescribes AFVA 33-276, Privacy Act Label, as optional; adds the E-Government Act of 2002 requirement for a Privacy Impact Assessment for all information technology systems that collect, maintain, or disseminate information in identifiable form from or about members of the public; changes appeal processing from AFCIC to Air Force Legal Services Agency (AFLSA/JACL); adds Privacy Act warning language to use on information systems subject to the Privacy Act, includes guidance on sending personal information via e-mail; adds procedures on complaints; and provides guidance on recall rosters; social rosters; consent statements, systems of records operated by a contractor, and placing information on shared drives.

Chapter 1— OVERVIEW OF THE PRIVACY ACT PROGRAM 5

1.1. Basic Guidelines

1.2. Violation Penalties

1.3. Privacy Act Complaints

1.4. Personal Notes

1.5. Systems of Records Operated by a Contractor

1.6. Responsibilities

Chapter 2— OBTAINING LAW ENFORCEMENT RECORDS AND

CONFIDENTIALITY PROMISES 10

2.1. Obtaining Law Enforcement Records

2.2. Confidentiality Promises

Chapter 3— COLLECTING PERSONAL INFORMATION 11

3.1. How To Collect Personal Information

3.2. When To Give Privacy Act Statements (PAS)

3.3. Requesting the Social Security Number (SSN)

Chapter 4— GIVING ACCESS TO PRIVACY ACT RECORDS 13

4.1. Making a Request for Access

4.2. Processing a Request for Access

4.3. Fees

4.4. Denying or Limiting Access

4.5. Denial Authorities

AFI33-332 29 JANUARY 2004 3

Chapter 5— AMENDING THE RECORD 16

5.1. Amendment Reasons

5.2. Responding to Amendment Requests

5.3. Approving or Denying a Record Amendment

5.4. Seeking Review of Unfavorable Agency Determinations

5.5. Contents of PA Case Files

Chapter 6— APPEALS 18

6.1. Appeal Procedures

Chapter 7— PRIVACY ACT NOTIFICATIONS 19

7.1. When To Include a Privacy Act Warning Statement in Publications

7.2. Warning Banners

7.3. Sending Personal Information Over Electronic Mail

Chapter 8— PRIVACY IMPACT ASSESSMENTS 20

8.1. Evaluating Information Systems for Privacy Act Compliance

8.2. The system owner will conduct a PIA as outlined in Attachment 4 and send it to their MAJCOM Privacy Act office for review

8.3. Whenever practicable, approved PIAs will be posted to the FOIA/Privacy Act Web site for public access

Chapter 9— PREPARING AND PUBLISHING SYSTEM NOTICES FOR

THE FEDERAL REGISTER 21

9.1. Publishing System Notices

9.2. Submitting Notices for Publication in the Federal Register

9.3. Reviewing Notices

Chapter 10— PROTECTING AND DISPOSING OF RECORDS 22

10.1. Protecting Records

10.2. Balancing Protection

10.3. Disposing of Records

Chapter 11— PRIVACY ACT EXEMPTIONS 23

11.1. Exemption Types

11.2. Authorizing Exemptions

11.3. Requesting an Exemption

4 AFI33-332 29 JANUARY 2004

11.4. Exemptions

Chapter 12— DISCLOSING RECORDS TO THIRD PARTIES 25

12.1. Disclosure Considerations

12.2. Releasable Information

12.3. Disclosing Other Information

12.4. Rules for Releasing Privacy Act Information Without Consent of the Subject

12.5. Disclosing the Medical Records of Minors

12.6. Disclosure Accountings

12.7. Computer Matching

12.8. Privacy and the Web

Chapter 13— TRAINING 30

13.1. Who Needs Training

13.2. Training Tools

13.3. Information Collections, Records, and Forms or Information Management Tools (IMT)

13.4. Forms or IMTs (Adopted and Prescribed)

Attachment 1— GLOSSARY OF REFERENCES AND SUPPORTING INFORMATION 31

Attachment 2— PREPARING A SYSTEM NOTICE 35

Attachment 3— GENERAL AND SPECIFIC EXEMPTIONS 37

Attachment 4— PRIVACY IMPACT ASSESSMENT 52

Attachment 5— DOD ‘BLANKET ROUTINE USES’ 62

AFI33-332 29 JANUARY 2004 5

Chapter 1

OVERVIEW OF THE PRIVACY ACT PROGRAM

1.1. Basic Guidelines. This instruction implements the Privacy Act of 1974 and applies to records on liv-ing US citizens and permanent resident aliens that are retrieved by name or personal identifier. This instruction also provides guidance on collecting and disseminating personal information in general.

1.1.1. Records that are retrieved by name or personal identifier are subject to Privacy Act (PA) requirements and are referred to as PA systems of records. The Air Force must publish notices in the Federal Register, describing the collection of information for new, changed or deleted systems to inform the public and give them an opportunity to comment before implementing or changing the sys-tem. (see Attachment 2).

1.1.2. An official system of records is:

1.1.2.1. Authorized by law or Executive Order.

1.1.2.2. Needed to carry out an Air Force mission or function.

1.1.2.3. Published in the Federal Register.

1.1.3. The Air Force will not:

1.1.3.1. Keep records on how a person exercises First Amendment rights. EXCEPTIONS are when: The Air Force has the permission of that individual or is authorized by Federal statute; or the information pertains to and is within the scope of, an authorized law enforcement activity. First Amendment rights include, but are not limited to, freedom of religion, freedom of political beliefs, freedom of speech, freedom of the press, the right to assemble, and the right to petition.

1.1.3.2. Penalize or harass an individual for exercising rights guaranteed under the PA. We must reasonably help individuals exercise their rights under the PA.

1.1.4. Air Force members will:

1.1.4.1. Keep paper and electronic records that are retrieved by name or personal identifier only in approved PA systems published in the Federal Register.

1.1.4.2. Collect, maintain, and use information in such systems, for purposes described in the pub-lished notice, to support programs authorized by law or Executive Order.

1.1.4.3. Safeguard the records in the system and keep them the minimum time required.

1.1.4.4. Ensure records are timely, accurate, complete, and relevant.

1.1.4.5. Amend and correct records on request.

1.1.4.6. Allow individuals to review and receive copies of their own records unless an exemption for the system has been published in the Federal Register; or the Air Force created the records in anticipation of a civil action or proceeding (Title 5 United States Code Section 552a(d)(5)).

1.1.4.7. Provide a review of decisions that deny individuals access to or amendment of their records through appellate procedures.

6 AFI33-332 29 JANUARY 2004

1.2. Violation Penalties. An individual may file a civil law suit against the Air Force for failing to com-ply with the PA. The courts may find an individual offender guilty of a misdemeanor and fine that indi-vidual offender not more than $5,000 for:

1.2.1. Willfully maintaining a system of records that doesn’t meet the public notice requirements.

1.2.2. Disclosing information from a system of records to someone not entitled to the information.

1.2.3. Obtaining someone else’s records under false pretenses.

1.3. Privacy Act Complaints. Process PA complaints or allegations of PA violations through the appro-priate base or MAJCOM PA office, to the local systems manager. The base or MAJCOM PA officer directs the process and provides guidance to the system manager. The local systems manager will investi-gate complaints, or allegations of PA violations; will establish and review the facts when possible; inter-view individuals as needed; determine validity of the complaint; take appropriate corrective action; and ensure a response is sent to the complainant through the PA Officer. In cases where no system manager can be identified, the local PA officer will assume these duties. Issues that cannot be resolved at the local level will be elevated to the MAJCOM Privacy Office. When appropriate, local system managers will also: refer cases for more formal investigation, refer cases for command disciplinary action, and consult the servicing SJA.

1.3.1. In unified combatant commands, process component unique system complaints through the respective component chain of command.

1.3.2. For Privacy Act complaints filed in a U.S. District Court against the Air Force, an Air Force activity, or any Air Force employee, AFLSA/JACL will provide AF-CIO/P a litigation summary to include: the case number, requester name, the nature of the case (denial of access, refusal to amend, incorrect records, or specify the particular violation of the Privacy Act), date complaint filed, court, defendants, and any appropriate remarks, as well as updates during the litigation process. When the court renders a formal opinion or judgment, AFLSA/JACL sends AF-CIO/P a copy of the judgment and opinion.

1.4. Personal Notes. The Privacy Act does not apply to personal notes on individuals used as memory aids. Personal notes may become Privacy Act records if they are retrieved by name or other personal iden-tifier and at least one of the following three conditions apply: (1) keeping or destroying the records is not at the sole discretion of the author; (2) the notes are required by oral or written directive, regulation, or command policy; or (3) they are shown to other agency personnel.

1.5. Systems of Records Operated by a Contractor. Contractors who are required to operate or main-tain a PA system of records by contract must follow this instruction for collecting, safeguarding, main-taining, using, accessing, amending and disseminating personal information. The record system affected is considered to be maintained by the Air Force and is subject to this instruction. Systems managers for offices who have contractors operating or maintaining such record systems must ensure the contract con-tains the proper PA clauses, and identify the record system number, as required by the Defense Acquisi-tion Regulation and this instruction.

1.5.1. Contracts for systems of records operated or maintained by a contractor will be reviewed annu-ally by the appropriate MAJCOM Privacy Officer to ensure compliance with this instruction.

AFI33-332 29 JANUARY 2004 7

1.5.2. Disclosure of personal records to a contractor for use in the performance of an Air Force con-tract is considered a disclosure within the agency under exception (b)(1) of the Privacy Act (see para 12.4.1.).

1.6. Responsibilities.

1.6.1. The Air Force Chief Information Officer (AF-CIO) is the senior Air Force Privacy Official with overall responsibility for the Air Force Privacy Act Program.

1.6.2. The Office of the General Counsel to the Secretary of the Air Force (SAF/GCA) makes final decisions on appeals.

1.6.3. The General Litigation Division, AFLSA/JACL, receives PA appeals and provides recommen-dations to the appellate authority. Service unique appeals, from unified combatant commands, should go through the respective chain of command.

1.6.4. The Plans and Policy Directorate, Office of the Chief Information Officer (AF-CIO/P) manages the program through the Air Force PA Officer who:

1.6.4.1. Administers procedures outlined in this instruction.

1.6.4.2. Reviews publications and forms for compliance with this instruction.

1.6.4.3. Reviews and approves proposed new, altered, and amended systems of records; and sub-mits system notices and required reports to the Defense Privacy Office.

1.6.4.4. Serves as the Air Force member on the Defense Privacy Board and the Defense Data Integrity Board.

1.6.4.5. Provides guidance and assistance to MAJCOMs, FOAs, DRUs and combatant commands for which AF is executive agent in their implementation and execution of the Air Force Privacy Program. Ensures availability of training and training tools for a variety of audiences.

1.6.4.6. Provides advice and support to those commands to ensure that information requirements developed to collect or maintain personal data conform to PA standards; and that appropriate pro-cedures and safeguards are developed, implemented, and maintained to protect the information.

1.6.5. MAJCOM commanders, and Deputy Chiefs of Staff (DCS) and comparable officials at Secre-tary of the Air Force and Headquarters United States Air Force (HQ USAF) offices implement this instruction.

1.6.6. 11th Communications Squadron (11 CS/SCS), will provide PA training and submit PA reports for HQ USAF and SAF offices.

1.6.7. MAJCOM Commanders:

1.6.7.1. Appoint a command PA officer, and send the name, office symbol, phone number, and e-mail address to AF-CIO/P.

1.6.8. MAJCOM and Headquarters Air Force (HAF) Functional CIOs:

1.6.8.1. Review and provide final approval on Privacy Impact Assessments (PIA) (see Chapter 8).

1.6.8.2. Send a copy of approved PIAs to AF-CIO/P.

8 AFI33-332 29 JANUARY 2004

1.6.9. MAJCOM PA Officers:

1.6.9.1. Train base PA officers. May authorize appointment of unit PA monitors to assist with implementation of the program.

1.6.9.2. Promote PA awareness throughout the organization.

1.6.9.3. Review publications and forms for compliance with this instruction (do forms require a Privacy Act Statement (PAS); is PAS correct?)

1.6.9.4. Submit reports as required.

1.6.9.5. Review system notices to validate currency.

1.6.9.6. Evaluate the health of the program at regular intervals using this instruction as guidance.

1.6.9.7. Review and provide recommendations on completed Privacy Impact Assessments (PIA) for information systems.

1.6.9.8. Resolve complaints or allegations of PA violations.

1.6.9.9. Review and process denial recommendations.

1.6.9.10. Provide guidance as needed to functionals on implementing the Privacy Act.

1.6.10. Base PA Officers:

1.6.10.1. Provide guidance and training to base personnel.

1.6.10.2. Submit reports as required.

1.6.10.3. Review publications and forms for compliance with this instruction.

1.6.10.4. Review system notices to validate currency.

1.6.10.5. Direct investigations of complaints/violations.

1.6.10.6. Evaluate the health of the program at regular intervals using this instruction as guidance.

1.6.11. System Managers:

1.6.11.1. Manage and safeguard the system.

1.6.11.2. Train users on PA requirements.

1.6.11.3. Protect records from unauthorized disclosure, alteration, or destruction.

1.6.11.4. Prepare system notices and reports.

1.6.11.5. Answer PA requests.

1.6.11.6. Keep records of disclosures.

1.6.11.7. Validate system notices annually.

1.6.11.8. Investigate PA complaints.

1.6.12. System owners and developers:

1.6.12.1. Decide the need for, and content of systems.

1.6.12.2. Evaluate PA requirements of information systems in early stages of development.

AFI33-332 29 JANUARY 2004 9

1.6.12.3. Complete a PIA and submit to the PA Officer:

10 AFI33-332 29 JANUARY 2004

Chapter 2

OBTAINING LAW ENFORCEMENT RECORDS AND CONFIDENTIALITY PROMISES

2.1. Obtaining Law Enforcement Records. The Commander, Air Force Office of Special Investigation (AFOSI); the Commander, Air Force Security Forces Center (HQ AFSFC); MAJCOM, FOA, and base chiefs of security forces; AFOSI detachment commanders; and designees of those offices may ask another agency for records for law enforcement under 5 U.S.C. 552a(b)(7). The requesting office must indicate in writing the specific part of the record desired and identify the law enforcement activity asking for the record.

2.2. Confidentiality Promises. Promises of confidentiality must be prominently annotated in the record to protect from disclosure any “confidential” information under 5 United States Code 552a (k)(2), (k)(5), or (k)(7) of the Privacy Act.

AFI33-332 29 JANUARY 2004 11

Chapter 3

COLLECTING PERSONAL INFORMATION

3.1. How To Collect Personal Information. Collect personal information directly from the subject of the record whenever possible. Only ask third parties when:

3.1.1. You must verify information.

3.1.2. You want opinions or evaluations.

3.1.3. You can’t contact the subject.

3.1.4. You are doing so at the request of the subject individual.

3.2. When To Give Privacy Act Statements (PAS). Give a PAS orally or in writing to the subject of the record when you are collecting information from them that will go in a system of records. NOTE: Do this regardless of how you collect or record the answers. You may display a sign in areas where people routinely furnish this kind of information. Give a copy of the PAS if asked. Do not ask the person to sign the PAS.

3.2.1. A PAS must include four items:

3.2.1.1. Authority: The legal authority, that is, the U.S.C. or Executive Order authorizing the pro-gram the system supports.

3.2.1.2. Purpose: The reason you are collecting the information and what you intend to do with it.

3.2.1.3. Routine Uses: A list of where and why the information will be disclosed outside DOD.

3.2.1.4. Disclosure: Voluntary or Mandatory. (Use Mandatory only when disclosure is required by law and the individual will be penalized for not providing information.) Include any conse-quences of nondisclosure in nonthreatening language.

3.3. Requesting the Social Security Number (SSN). When asking an individual for his or her SSN, always give a Privacy Act Statement that tells the person: (1) the legal authority for requesting it; (2) the uses that will be made of the SSN; and (3) whether providing the SSN is voluntary or mandatory. Do not deny anyone a legal right, benefit, or privilege for refusing to give their SSN unless the law requires dis-closure, or a law or regulation adopted before January 1, 1975 required the SSN and the Air Force uses it to verify a person’s identity in a system of records established before that date.

3.3.1. The Air Force requests an individual’s SSN and provides the individual information required by law when anyone enters military service or becomes an Air Force civilian employee. The Air Force uses the SSN as a service or employment number to reference the individual’s official records. When you ask someone for an SSN as identification to retrieve an existing record, you do not have to restate this information.

3.3.2. Executive Order 9397, Numbering System for Federal Accounts Relating to Individual Per-sons, authorizes using the SSN as a personal identifier. This order is not adequate authority to collect an SSN to create a record. When law does not require disclosing the SSN or when the system of records was created after January 1, 1975, you may ask for the SSN, but the individual does not have to disclose it. If the individual refuses to respond, use alternative means of identifying records.

12 AFI33-332 29 JANUARY 2004

3.3.3. SSNs are personal and unique to each individual. Protect them as FOR OFFICIAL USE ONLY (FOUO). Within DOD, do not disclose them to anyone without an official need to know. Outside DOD, they are not releasable without the person’s consent, or unless authorized under one of the 12 exceptions to the Privacy Act (see paragraph 12.4.).

AFI33-332 29 JANUARY 2004 13

Chapter 4

GIVING ACCESS TO PRIVACY ACT RECORDS

4.1. Making a Request for Access. Persons or their designated representatives may ask for a copy of their records in a system of records. Requesters need not state why they want access to their records. Ver-ify the identity of the requester to avoid unauthorized disclosures. How you verify identity will depend on the sensitivity of the requested records. Persons may use a notary or an unsworn declaration in the follow-ing format: “I declare under penalty of perjury (if outside the United States, add “under the laws of the United States of America”) that the foregoing is true and correct. Executed on (date). (Signature).”

4.2. Processing a Request for Access. Consider a request from an individual for his or her own records in a system of records under both the Freedom of Information Act (FOIA) and the PA regardless of the Act cited. The requester does not need to cite either Act if the records they want are contained in a system of records. Process the request under whichever Act gives the most information. When necessary, tell the requester which Act you used and why.

4.2.1. Requesters should describe the records they want. They do not have to name a system of records number, but they should at least name a type of record or functional area. For requests that ask for “all records about me,” ask for more information and tell the person how to review the Air Force systems of records published in the Federal Register or at http://www.defenselink.mil/privacy/notices/usaf.

4.2.2. Requesters should not use government equipment, supplies, stationery, postage, telephones, or official mail channels for making PA requests. System managers will process such requests and tell requesters that using government resources to make PA requests is not authorized.

4.2.3. Tell the requester if a record exists and how to review the record. If possible, respond to requests within 10 workdays of receipt. If you cannot answer the request in 10 workdays, send a letter explaining why and give an approximate completion date no more than 20 workdays after the first office received the request.

4.2.4. Show or give a copy of the record to the requester within 30 workdays of receiving the request unless the system has an exemption published in the Federal Register as a final rule. Give information in a form the requester can understand. If the system is exempt under the PA, provide any parts releas-able under FOIA, with appeal rights (see Chapter 6), citing appropriate exemptions from the Privacy Act and FOIA, if applicable.

4.2.5. If the requester wants another person present during the record review, the system manager may ask for written consent to authorize discussing the record with another person present.

4.3. Fees. Give the first 100 pages free, and charge only reproduction costs for the remainder. Copies cost $.15 per page; microfiche costs $.25 per fiche. Charge fees for all pages for subsequent requests for the same records. Do not charge fees:

4.3.1. When the requester can get the record without charge under another publication (for example, medical records).

4.3.2. For search.

4.3.3. For reproducing a document for the convenience of the Air Force.

http://www.defenselink.mil/privacy/notices/usaf

14 AFI33-332 29 JANUARY 2004

4.3.4. For reproducing a record so the requester can review it.

4.3.5. Fee waivers. Waive fees automatically if the direct cost of reproduction is less than $15, unless the individual is seeking an obvious extension or duplication of a previous request for which he or she was granted a waiver. Decisions to waive or reduce fees that exceed $15 are made on a case-by-case basis.

4.4. Denying or Limiting Access. System managers process access denials within 5 workdays after you receive a request for access. When you may not release a record, send a copy of the request, the record, and why you recommend denying access (include the applicable exemption) to the denial authority through the legal office and the PA office. Judge Advocate (JA) offices will include a written legal opin-ion. The PA officer reviews the file, and makes a recommendation to the denial authority. The denial authority sends the requester a letter with the decision. If the denial authority grants access, release the record. If the denial authority refuses access, tell the requester why and explain pertinent appeal rights (see Chapter 6).

4.4.1. Before you deny a request for access to a record, make sure that:

4.4.1.1. The system has an exemption published in the Federal Register as a final rule.

4.4.1.2. The exemption covers each document. (All parts of a system are not automatically exempt.)

4.4.1.3. Nonexempt parts are segregated.

4.4.2. Special Provision for Certain Medical Records. If a physician believes that disclosing requested medical records could harm the person’s mental or physical health, you should:

4.4.2.1. Ask the requester to get a letter from a physician to whom you can send the records.

Include a letter explaining to the physician that giving the records directly to the individual could be harmful.

4.4.2.2. Offer the services of a military physician other than one who provided treatment if nam-ing the physician poses a hardship on the individual.

4.4.2.3. The Privacy Act requires that we ultimately ensure that the subject receives the records.

4.4.3. Third Party Information in a Privacy Act System of Record. Ordinarily a person is entitled to their entire record under the Privacy Act. However, the law is not uniform regarding whether a sub-ject is entitled to information that is not “about” him or her (for example, the home address of a third party contained in the subject's records). Consult your servicing SJA before disclosing third party information. Generally, if the requester will be denied a right, privilege or benefit, the requester must be given access to relevant portions of the file.

4.4.4. Information Compiled in Anticipation of Civil Action. Withhold records compiled in con-nection with a civil action or other proceeding including any action where the Air Force expects judi-cial or administrative adjudicatory proceedings. This exemption does not cover criminal actions. Do not release attorney work products prepared before, during, or after the action or proceeding.

4.5. Denial Authorities. These officials or a designee may deny access or amendment of records as authorized by the Privacy Act. Send a letter to AF-CIO/P with the position titles of designees. Authorities are:

AFI33-332 29 JANUARY 2004 15

4.5.1. DCSs and chiefs of comparable offices or higher level at SAF or HQ USAF or designees.

4.5.2. MAJCOM, FOA, or DRU commanders or designees.

4.5.3. HQ USAF/DPF, 1040 Air Force Pentagon, Washington DC 20330-1040 (for civilian personnel records).

4.5.4. Commander, Air Force Office of Special Investigations (AFOSI), Washington DC 20332-6001 (for AFOSI records).

4.5.5. Unified Commanders or designees.

16 AFI33-332 29 JANUARY 2004

Chapter 5

AMENDING THE RECORD

5.1. Amendment Reasons. Individuals may ask to have their records amended to make them accurate, timely, relevant, or complete. System managers will routinely correct a record if the requester can show that it is factually wrong (e.g., date of birth is wrong).

5.2. Responding to Amendment Requests.

5.2.1. Anyone may request minor corrections orally. Requests for more serious modifications should be in writing.

5.2.2. After verifying the identity of the requester, make the change, notify all known recipients of the record, and inform the individual.

5.2.3. Acknowledge requests within 10 workdays of receipt. Give an expected completion date unless you complete the change within that time. Final decisions must take no longer than 30 workdays.

5.3. Approving or Denying a Record Amendment. The Air Force does not usually amend a record when the change is based on opinion, interpretation, or subjective official judgment. Determinations not to amend such records constitutes a denial, and requesters may appeal (see Chapter 6).

5.3.1. If the system manager decides not to amend the record, send a copy of the request, the record, and the recommended denial reasons to the denial authority through the legal office and the PA office.

Legal offices will include a written legal opinion. The PA officer reviews the proposed denial and legal opinion and makes a recommendation to the denial authority.

5.3.2. The denial authority sends the requester a letter with the decision. If the denial authority approves the request, amend the record and notify all previous recipients that it has been changed. If the authority denies the request, give the requester the statutory authority, reason, and pertinent appeal rights (see Chapter 6).

5.4. Seeking Review of Unfavorable Agency Determinations. Requesters should pursue record cor-rections of subjective matters and opinions through proper channels to the Civilian Personnel Office using grievance procedures or the Air Force Board for Correction of Military Records (AFBCMR). Record cor-rection requests denied by the AFBCMR are not subject to further consideration under this instruction.

Military personnel, other than USAF personnel, should pursue service-unique record corrections through their component chain of command.

5.5. Contents of PA Case Files. Do not keep copies of disputed records in this file. File disputed records in their appropriate series. Use the file solely for statistics and to process requests. Do not use the case files to make any kind of determination about an individual. Document reasons for untimely responses.

These files include:

5.5.1. Requests from and replies to individuals on whether a system has records about them.

5.5.2. Requests for access or amendment.

5.5.3. Approvals, denials, appeals, and final review actions.

AFI33-332 29 JANUARY 2004 17

5.5.4. Coordination actions and related papers.

18 AFI33-332 29 JANUARY 2004

Chapter 6

APPEALS

6.1. Appeal Procedures. Individuals who receive a denial to their access or amendment request may request a denial review by writing to the Secretary of the Air Force, through the denial authority, within 60 calendar days after receiving a denial letter. The denial authority promptly sends a complete appeal package to AFLSA/JACL. The package must include: (1) the original appeal letter; (2) the initial request;

(3) the initial denial; (4) a copy of the record; (5) any internal records or coordination actions relating to the denial; (6) the denial authority’s comments on the appellant’s arguments; and (7) the legal reviews.

6.1.1. If the denial authority reverses an earlier denial and grants access or amendment, notify the requester immediately.

6.1.2. AFLSA/JACL reviews the denial and provides a final recommendation to SAF/GCA. SAF/ GCA tells the requester the final Air Force decision and explains judicial review rights.

6.1.3. The requester may file a concise statement of disagreement with the system manager if SAF/ GCA denies the request to amend the record. SAF/GCA explains the requester’s rights when they issue the final appeal decision.

6.1.4. The records should clearly show that a statement of disagreement is filed with the record or separately.

6.1.5. The disputed part of the record must show that the requester filed a statement of disagreement.

6.1.6. Give copies of the statement of disagreement to the record’s previous recipients. Inform subse-quent record users about the dispute and give them a copy of the statement with the record.

6.1.7. The system manager may include a brief summary of the reasons for not amending the record.

Limit the summary to the reasons SAF/GCA gave to the individual. The summary is part of the indi-vidual’s record, but it is not subject to amendment procedures.

AFI33-332 29 JANUARY 2004 19

Chapter 7

PRIVACY ACT NOTIFICATIONS

7.1. When To Include a Privacy Act Warning Statement in Publications. Include a PA Warning Statement in each Air Force publication that requires collecting or keeping information in a system of records. Also include the Warning Statement when publications direct collection of the SSN, or any part of the SSN, from the individual. The warning statement will cite legal authority and when part of a record system, the PA system of records number and title. You can use the following warning statement: “This instruction requires collecting and maintaining information protected by the Privacy Act of 1974 autho-rized by (U.S.C. citation and or Executive Order number). System of records notice (number and title) applies.”

7.2. Warning Banners. Information systems that contain information on individuals that is retrieved by name or personal identifier are subject to the Privacy Act. The Privacy Act requires these systems to have a PA system notice published in the Federal Register that covers the information collection before collec-tion begins. In addition, all information systems subject to the Privacy Act will have warning banners dis-played on the first screen (at a minimum) to assist in safeguarding the information. Use the following language for the banner: “PRIVACY ACT INFORMATION - The information accessed through this sys-tem is FOR OFFICIAL USE ONLY and must be protected in accordance with the Privacy Act and AFI 33-332.”

7.3. Sending Personal Information Over Electronic Mail. Exercise caution before transmitting per-sonal information over e-mail to ensure it is adequately safeguarded. Some information may be so sensi-tive and personal that e-mail may not be the proper way to transmit it. When sending personal information over e-mail within DOD, ensure: (1) there is an official need; (2) all addressee(s) (including “cc” address-ees) are authorized to receive it under the Privacy Act; and (3) it is protected from unauthorized disclo-sure, loss, or alteration. Protection methods may include encryption or password protecting the information in a separate Word document. When transmitting personal information over e-mail, add “FOUO” to the beginning of the subject line, followed by the subject, and apply the following statement at the beginning of the e-mail:

“This e-mail contains FOR OFFICIAL USE ONLY (FOUO) information which must be protected under the Privacy Act and AFI 33-332.”

Do not indiscriminately apply this statement to e-mails. Use it only in situations when you are actually transmitting personal information. DoD Regulation 5400.7/AF Supp, Chapter 4, provides additional guid-ance regarding FOUO information.

7.3.1. Do not disclose personal information to anyone outside DOD unless specifically authorized by the Privacy Act (see paragraph 12.4.).

7.3.2. Do not send PA information to distribution lists or group e-mail addresses unless each member has an official need to know the personal information. When in doubt, send only to individual accounts.

7.3.3. Before forwarding e-mails you have received that contain personal information, verify that your intended recipients are authorized to receive the information under the Privacy Act (see para-graph 12.4.).

20 AFI33-332 29 JANUARY 2004

Chapter 8

PRIVACY IMPACT ASSESSMENTS

8.1. Evaluating Information Systems for Privacy Act Compliance. Information system owners and developers must address PA requirements in the development stage of the system and integrate privacy protections into the development life cycle of the information system. This is accomplished with a Pri-vacy Impact Assessment (PIA).

8.1.1. The PIA addresses what information is to be collected; why the information is being collected;

the intended use of the information; with whom the information will be shared; what notice or oppor-tunities for the individual to decline or consent to providing the information collected, and how that information is shared; secured; and whether a system of records is being created, or an existing system is being amended. The E-Government Act of 2002 requires PIAs to be conducted before:

8.1.1.1. Developing or procuring information technology (IT) systems or projects that collect, maintain, or disseminate information in identifiable form from or about members of the public.

8.1.1.2. Initiating a new electronic collection of information, in identifiable form for 10 or more persons excluding agencies, instrumentalities, or employees of the Federal Government.

8.1.2. In general, Privacy Impact Assessments are required to be performed and updated as necessary where a system change creates new privacy risks.

8.1.3. No Privacy Impact Assessment is required where information relates to internal government operations, has been previously assessed under an evaluation similar to a Privacy Impact Assessment, or where privacy issues are unchanged.

8.1.4. The depth and content of the Privacy Impact Assessment should be appropriate for the nature of the information to be collected and the size and complexity of the information technology system.

8.2. The system owner will conduct a PIA as outlined in Attachment 4 and send it to their MAJCOM Privacy Act office for review and final approval by the MAJCOM or HAF Functional CIO. The MAJ- COM or HAF Functional CIO will send a copy of the approved PIAs to AF-CIO/P,1155 Air Force Penta-gon, Washington DC 20330-1155; or e-mail mailto:af.foia@pentagon.af.mil.

8.3. Whenever practicable, approved PIAs will be posted to the FOIA/Privacy Act Web site for public access at http://www.foia.af.mil (this requirement will be waived for security reasons, or to protect clas-sified, sensitive, or private information contained in an assessment).

mailto:af.foia@pentagon.af.mil http://www.foia.af.mil

AFI33-332 29 JANUARY 2004 21

Chapter 9

PREPARING AND PUBLISHING SYSTEM NOTICES FOR THE FEDERAL REGISTER

9.1. Publishing System Notices. The Air Force must publish notices in the Federal Register of new, changed, and deleted systems to inform the public of what records the Air Force keeps and give them an opportunity to comment before the system is implemented or changed. The PA also requires submission of new or significantly changed systems to the OMB and both houses of Congress before publication in the Federal Register. This includes:

9.1.1. Starting a new system.

9.1.2. Instituting significant changes to an existing system.

9.1.3. Sending out data collection forms or instructions.

9.1.4. Issuing a request for proposal or invitation for bid to support a new system.

9.2. Submitting Notices for Publication in the Federal Register. At least 120 days before implement-ing a new system, or a major change to an existing system, subject to this instruction, system managers must send a proposed notice, through the MAJCOM Privacy Office, to AF-CIO/P. Send notices electron-ically to mailto:af.foia@pentagon.af.mil using Microsoft Word, using the Track Changes tool in Word to indicate additions/changes to existing notices. Follow the format outlined in Attachment 2. For new systems, system managers must include a statement that a risk assessment was accomplished and is avail-able should the OMB request it.

9.3. Reviewing Notices. System managers will review and validate their PA system notices annually and submit changes to AF-CIO/P through the MAJCOM Privacy Office.

mailto:af.foia@pentagon.af.mil

22 AFI33-332 29 JANUARY 2004

Chapter 10

PROTECTING AND DISPOSING OF RECORDS

10.1. Protecting Records. Maintaining information privacy is the responsibility of every federal employee, military member, and contractor who comes into contact with information in identifiable form.

Protect information according to its sensitivity level. Consider the personal sensitivity of the information and the risk of disclosure, loss or alteration. Most information in systems of records is FOUO. Refer to DoD 5400.7-R/AF Supp, DoD Freedom of Information Act Program, for protection methods.

10.2. Balancing Protection. Balance additional protection against sensitivity, risk and cost. In some sit-uations, a password may be enough protection for an automated system with a log-on protocol. Others may require more sophisticated security protection based on the sensitivity of the information. Classified computer systems or those with established audit and password systems are obviously less vulnerable than unprotected files. Follow AFI 33-202, Computer Security, for procedures on safeguarding personal information in automated records.

10.2.1. AF Form 3227, Privacy Act Cover Sheet, is optional and available for use with Privacy Act material. Use it to cover and protect personal information that you are using in office environments that are widely unprotected and accessible to many individuals. After use, such information should be protected as outlined in DoD 5400.7-R/AF Supp.

10.2.2. Privacy Act Labels. Use of AFVA 33-276, Privacy Act Label, is optional to assist in protect-ing Privacy Act information on compact disks, diskettes, and tapes.

10.3. Disposing of Records. You may use the following methods to dispose of records protected by the Privacy Act and authorized for destruction according to records retention schedules:

10.3.1. Destroy by any method that prevents compromise, such as tearing, burning, or shredding, so long as the personal data is not recognizable and beyond reconstruction.

10.3.2. Degauss or overwrite magnetic tapes or other magnetic medium.

10.3.3. Dispose of paper products through the Defense Reutilization and Marketing Office or through activities that manage a base-wide recycling program. The recycling sales contract must contain a clause requiring the contractor to safeguard privacy material until its destruction and to pulp, macer-ate, shred, or otherwise completely destroy the records. Originators must safeguard PA material until it is transferred to the recycling contractor. A Federal employee or, if authorized, a contractor employee must witness the destruction. This transfer does not require a disclosure accounting.

AFI33-332 29 JANUARY 2004 23

Chapter 11

PRIVACY ACT EXEMPTIONS

11.1. Exemption Types. There are two types of exemptions permitted by 5 U.S.C. 552a:

11.1.1. A General exemption authorizes the exemption of a system of records from most parts of the

PA.

11.1.2. A Specific exemption authorizes the exemption of a system of records from only a few parts.

11.2. Authorizing Exemptions. Denial authorities may withhold records using Privacy Act exemptions only when an exemption for the system of records has been published in the Federal Register as a final rule. Attachment 3 lists the systems of records that have published exemptions with rationale.

11.3. Requesting an Exemption. A system manager who believes that a system needs an exemption from some or all of the requirements of the PA will send a request to AF-CIO/P through the MAJCOM or FOA PA Officer. The request will detail the reasons for the exemption, the section of the Act that allows the exemption, and the specific subsections of the PA from which the system is to be exempted, with jus-tification for each subsection.

11.4. Exemptions. Exemptions permissible under 5 U.S.C. 552a (subject to paragraph 11.2.):

11.4.1. The (j)(2) exemption. Applies to investigative records created and maintained by law-enforce-ment activities whose principal function is criminal law enforcement.

11.4.2. The (k)(1) exemption. Applies to information specifically authorized to be classified accord-ing to DoD 5200.1R, Information Security Program.

11.4.3. The (k)(2) exemption. Applies to investigatory information compiled for law-enforcement purposes by nonlaw enforcement activities and which is not within the scope of the (j)(2) exemption (paragraph 11.4.1.). However, the Air Force must allow an individual access to any record that is used to deny rights, privileges or benefits to which he or she would otherwise be entitled by Federal law or for which he or she would otherwise be eligible as a result of the maintenance of the information (unless doing so would reveal a confidential source).

11.4.4. The (k)(3) exemption. Applies to records maintained in connection with providing protective services to the President and other individuals under Title 18, U.S.C., Section 3506.

11.4.5. The (k)(4) exemption. Applies to records maintained solely for statistical research or program evaluation purposes and which are not used to make decisions on the rights, benefits, or entitlement of an individual except for census records which may be disclosed under Title 13, U.S.C., Section 8.

11.4.6. The (k)(5) exemption. Applies to investigatory material compiled solely for the purpose of determining suitability, eligibility, or qualifications for federal civilian employment, military service, federal contracts, or access to classified information, but only to the extent such material would reveal the identity of a confidential source. This provision allows protection of confidential sources used in background investigations, employment inquiries, and similar inquiries that are for personnel screen-ing to determine suitability, eligibility, or qualifications.

24 AFI33-332 29 JANUARY 2004

11.4.7. The (k)(6) exemption. Applies to testing or examination material used solely to determine individual qualifications for appointment or promotion in the federal or military service, if the disclo-sure would compromise the objectivity or fairness of the test or examination process.

11.4.8. The (k)(7) exemption. Applies to evaluation material used to determine potential for promo-tion in the Military Services, but only to the extent that the disclosure of such material would reveal the identity of a confidential source.

AFI33-332 29 JANUARY 2004 25

Chapter 12

DISCLOSING RECORDS TO THIRD PARTIES

12.1. Disclosure Considerations. The Privacy Act requires the written consent of the subject before releasing personal information to third parties, unless one of the 12 exceptions of the Privacy Act applies (see paragraph 12.4.). Use this checklist before releasing personal information to third parties: (1) make sure it is authorized under the Privacy Act; (2) consider the consequences; and (3) check the accuracy of the information. You can release personal information to third parties when the subject agrees in writing.

Air Force members consent to releasing their home telephone number and address when they sign and check the “Do Consent” block on the AF Form 624, Base/Unit Locator and PSC Directory (see AFI 33-329, Base and Unit Personnel Locators).

12.1.1. Social Rosters. Before including personal information such as spouses names, home addresses, home phones, and similar information on social rosters or directories that are shared with groups of individuals, ask for signed consent statements. Otherwise, do not include the information.

Consent statements must give the individual a choice to consent or not consent, and clearly tell the individual what information is being solicited, the purpose, to whom you plan to disclose the informa-tion, and that consent is voluntary. Maintain the signed statements until no longer needed.

12.1.2. Placing Personal Information on Shared Drives. Personal information should never be placed on shared drives for access by groups of individuals unless each person has an official need to know the information to perform their job. Add appropriate access controls to ensure access by only authorized individuals. Recall rosters are FOUO because they contain personal information and should be shared with small groups at the lowest levels for official purposes to reduce the number of people with access to such personal information. Commanders and supervisors should give consider-ation to those individuals with unlisted phone numbers, who do not want their number included on the office recall roster. In those instances, disclosure to the Commander or immediate supervisor, or dep-uty, should normally be sufficient.

12.1.3. Personal Information That Requires Protection. Following are some examples of infor-mation that is not releasable without the written consent of the subject. This list is not all-inclusive.

12.1.3.1. Marital status (single, divorced, widowed, separated).

12.1.3.2. Number, name, and sex of dependents.

12.1.3.3. Civilian educational degrees and major areas of study (unless the request for the infor-mation relates to the professional qualifications for Federal employment).

12.1.3.4. School and year of graduation.

12.1.3.5. Home of record.

12.1.3.6. Home address and phone.

12.1.3.7. Age and date of birth (year).

12.1.3.8. Present or future assignments for overseas or for routinely deployable or sensitive units.

12.1.3.9. Office and unit address and duty phone for overseas or for routinely deployable or sen-sitive units.

26 AFI33-332 29 JANUARY 2004

12.1.3.10. Race/ethnic origin

12.1.3.11. Educational…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .