Privacy Impact Assessments - PowerPoint PPT Presentation

1 / 11
About This Presentation
Title:

Privacy Impact Assessments

Description:

Slavish adherence may not cover all relevant issues; may result in inferior product ... Allows agency to provide clearer explanations and more detailed analysis ... – PowerPoint PPT presentation

Number of Views:32
Avg rating:3.0/5.0
Slides: 12
Provided by: tsas52
Category:

less

Transcript and Presenter's Notes

Title: Privacy Impact Assessments


1
Privacy Impact Assessments
  • Content and Structure

2
Template or Freestyle?
  • Templates are easy, faster
  • Enable consistency across the agency
  • Slavish adherence may not cover all relevant
    issues may result in inferior product

3
Freestyle
  • Takes longer to draft and review
  • Requires more reading
  • Allows agency to provide clearer explanations and
    more detailed analysis

4
A Good PIA answers numerous questions
  • Data and Its Purposes
  • What info is being collected?
  • Why?
  • What is intended use?
  • What are sources of info in the system?
  • How will info be checked for accuracy?
  • New data collections or potential for
    aggregation?

5
Data and Its Purposes, Contd
  • Will any new data be placed in a system of
    records? Which one?
  • Can new determinations be made about individuals
    that were not possible before?
  • How to verify for relevance and accuracy?
  • Are data elements described in detail and
    documented?

6
Questions About Redress
  • Is it available?
  • What opportunities to consent to uses of the
    information?
  • How to grant consent?
  • Access procedures?
  • Correction procedures?

7
Access to the Data?
  • Who has access?
  • How is access determined?
  • Documentation of access procedures and controls?
  • Role-based access to the data?
  • Controls on misuse of data?
  • Data sharing with other systems or agencies?

8
Maintenance of Administrative Controls
  • Security requirements and procedures being
    followed?
  • Risk assessment conducted?
  • Monitoring/evaluating/testing?
  • Point of contact for users?
  • Retention periods for system data?
  • Deletion of data after retention period?
  • Controls on unauthorized monitoring?

9
Decision Analysis
  • Evaluate competing technologies for privacy
    impacts?
  • Changes made as a result of this analysis?

10
General Rules
  • Plain English is best
  • When in doubt, explain
  • Remember your audience
  • Combination of text and charts
  • A PIA is a living document so you can always
    revise

11
Sample PIA
  • www.dhs.gov/interweb/assetlibrary/VISITPIAfinal3.p
    df.
Write a Comment
User Comments (0)
About PowerShow.com