# Department of Defense Privacy Program

> Briefs, arguments, decisions, and more.

URL: https://www.frixlaw.com/law-library/documents/fr%3AE7-6118

## Record

- **Collection:** Federal Register
- **Document type:** Rule
- **Published:** April 13, 2007
- **Citation:** 72 FR 18758

## Text

DEPARTMENT OF DEFENSE
Office of the Secretary
[DoD-2006-OS-0129]
RIN 0790-AB03
32 CFR Part 310
Department of Defense Privacy Program

AGENCY:

Department of Defense.

ACTION:

Final rule.

SUMMARY:

The Department of Defense is updating policies and responsibilities for the Defense Privacy Program which implements the Privacy Act of 1974.

EFFECTIVE DATE:

April 13, 2007.

FOR FURTHER INFORMATION CONTACT:

Mr. Vahan Moushegian, Jr., at (703) 607-2943.

SUPPLEMENTARY INFORMATION:

The proposed rule was published in the
Federal Register
on July 14, 2006 at 71 FR 40282. No public comments were received. Some administrative changes were made as a result of comments on the corresponding DoD issuance and Office of Management and Budget guidance. Changes involve revision of the terms for personal and compromised information; the incorporation of additional considerations when determining if a social security number will be collected; a reorganization of the procedures involving Congressional or General Accountability Office access to records; an expanded explanation of record disposal procedures and the access exemption; additional consideration involving training and technical/special security requirements; and new notification procedures when there is a loss or theft of information.

Executive Order (E.O.) 12866, “Regulatory Planning and Review”

It has been determined that 32 CFR part 310 is not a significant regulatory action. The rule does not

(1) Have an annual effect on the economy of $100 million or more or adversely affect in a material way the economy; a sector of the economy; productivity; competition; jobs; the environment; public health or safety; or State, local, or tribal governments or communities;

(2) Create a serious inconsistency or otherwise interfere with an action taken or planned by another Agency;

(3) Materially alter the budgetary impact of entitlements, grants, user fees, or loan programs, or the rights and obligations of recipients thereof; or

(4) Raise novel legal or policy issues arising out of legal mandates, the President's priorities, or the principles set forth in this Executive Order.

Public Law 96-354, “Regulatory Flexibility Act” (5 U.S.C. Chapter 6)

It has been determined that this rule is not subject to the Regulatory Flexibility Act because it would not, if promulgated, have a significant economic impact on a substantial number of small entities because it is only concerned with the administration of Privacy Program within the Department of Defense.

Public Law 96-511, “Paperwork Reduction Act” (44 U.S.C. Chapter 35)

It has been determined that this rule does not impose information requirements beyond the Department of Defense and that the information collected within the Department of Defense is necessary and consistent with 5 U.S.C. 552a, known as the Privacy Act of 1974.

Section 202, Public Law 104-4, “Unfunded Mandates Reform Act”

It has been determined that the rule does not involve a Federal mandate that may result in the expenditure by State, local and tribal governments, in the aggregate, or by the private sector, of $100 million or more in any one year.

Executive Order 13132, “Federalism”

It has been determined that this rule does not have federalism implications. The rule does not have substantial direct effects on the States, the relationship between the National Government and the States, or on the distribution of power and responsibilities among the various levels of government.

List of Subjects in 32 CFR Part 310

Privacy.

Accordingly, 32 CFR part 310 is revised as follows.

PART 310—DOD PRIVACY PROGRAM

Subpart A—DoD Policy

Sec.
310.1
Reissuance.
310.2
Purpose.
310.3
Applicability and scope.
310.4
Definitions.
310.5
Policy.
310.6
Responsibilities.
310.7
Information requirements.
310.8
Rules of conduct.
310.9
Privacy boards and office, composition and responsibilities.

Subpart B—Systems of Records

310.10
General.
310.11
Standards of accuracy.
310.12
Government contractors.
310.13
Safeguarding personal information.
310.14
Notification when information is lost, stolen, or compromised.

Subpart C—Collecting Personal Information

310.15
General considerations.
310.16
Forms.

Subpart D—Access by Individuals

310.17
Individual access to personal information.
310.18
Denial of individual access.
310.19
Amendment of records.
310.20
Reproduction fees.

Subpart E—Disclosure of Personal Information to Other Agencies and Third Parties

310.21
Conditions of disclosure.
310.22
Non-consensual conditions of disclosure.
310.23
Disclosures to commercial enterprises.
310.24
Disclosures to the public from medical records.
310.25
Disclosure accounting.

Subpart F—Exemptions

310.26
Use and establishment of exemptions.
310.27
Access exemption.
310.28
General exemption.
310.29
Specific exemptions.

Subpart G—Publication Requirements

310.30

Federal Register
publication.

310.31
Exemption rules.
310.32
System notices.
310.33
New and altered record systems.
310.34
Amendment and deletion of system notices.

Subpart H—Training Requirements

310.35
Statutory training requirements.
310.36
OMB training guidelines.
310.37
DoD training programs.
310.38
Training methodology and procedures.
310.39
Funding for training.

Subpart I—Reports

310.40
Requirement for reports.
310.41
Suspense for submission of reports.
310.42
Reports control symbol.

Subpart J—Inspections

310.43
Privacy Act inspections.
310.44
Inspection reporting.

Subpart K—Privacy Act Violations

310.45
Administrative remedies.
310.46
Civil actions.
310.47
Civil remedies.
310.48
Criminal penalties.
310.49
Litigation status sheet.
310.50
Lost, stolen, or compromised information.

Subpart L—Computer Matching Program Procedures

310.51
General.
310.52
Computer matching publication and review requirements.
310.53
Computer matching agreements (CMAs).

Appendix A to Part 310—Safeguarding Personally Identifiable Information

Appendix B to Part 310—Sample Notification Letter

Appendix C to Part 310—DoD Blanket Routine Uses

Appendix D to Part 310—Provisions of the Privacy Act From Which a General or Specific Exemption May Be Claimed

Appendix E to Part 310—Sample of New or Altered System of Records Notice in
Federal Register
Format

Appendix F to Part 310—Format for New or Altered System Report

Appendix G to Part 310—Sample Amendments or Deletions to System Notices in
Federal Register
Format

Appendix H to Part 310—Litigation Status Sheet

Authority:

Pub. L. 93-579, 88 Stat. 1896 (5 U.S.C. 552a).

Subpart A—DoD Policy

§ 310.1
Reissuance.

This part consolidates into a single location (32 CFR part 310) Department of Defense (DoD) policies and procedures for implementing the Privacy Act of 1974, as amended (5 U.S.C. 552a) by authorizing the development, publication and maintenance of the DoD Privacy Program set forth by DoD Directive 5400.11
1

and 5400.11-R,
2

both entitled: “DoD Privacy Program.”

1
Copies may be obtained at
http://www.dtic.mil/whs/directives.

2
See footnote 1 to § 310.1.

§ 310.2
Purpose.
This part:

(a) Updates policies and responsibilities of the DoD Privacy Program under 5 U.S.C. 552a and OMB Circular A-130.

(b) Authorizes the Defense Privacy Board, the Defense Privacy Board Legal Committee, and the Defense Data Integrity Board.

(c) Continues to authorize the publication of DoD 5400.11-R.

(d) Continues to delegate authorities and responsibilities for the effective administration of the DoD Privacy Program.

§ 310.3
Applicability and scope.
This part:

(a) Applies to the Office of the Secretary of Defense (OSD), the Military Departments, the Chairman of the Joint Chiefs of Staff, the Combatant Commands, the Office of the Inspector General of the Department of Defense (IG, DoD), the Defense Agencies, the DoD Field Activities, and all other organizational entities in the Department of Defense (hereinafter referred to collectively as “the DoD Components”).

(b) Shall be made applicable to DoD contractors who are operating a system of records on behalf of a DoD Component, to include any of the activities, such as collecting and disseminating records, associated with maintaining a system of records.

(c) This part does not apply to:

(1) Requests for information made under the Freedom of Information Act. They are processed in accordance with DoD 5400.7-R.
3

3
See footnote 1 to § 310.3(c)(1).

(2) Requests for information from systems of records controlled by the Office of Personnel Management (OPM), although maintained by a DoD Component. These are processed in accordance with policies established by OPM “Privacy Procedures for Personnel Records” (5 CFR 297).

(3) Requests for personal information from the General Accounting Office. These are processed in accordance with DoD Directive 7650.1.
4

4
See footnote 1 to § 310.3(c)(1).

(4) Requests for personal information from Congress. These are processed in accordance with DoD Directive 5400.4 except those specific provisions in Subpart E—Disclosure of Personal Information to Other Agencies and Third Parties.

§ 310.4.
Definitions.

(a)
Access
. The review of a record or a copy of a record or parts thereof in a system of records by any individual.

(b)
Agency
. For the purposes of disclosing records subject to the Privacy Act among the DoD Components, the Department of Defense is a considered a single agency. For all other purposes to include requests for access and amendment, denial of access or amendment, appeals from denials, and record keeping as relating to release of records to non-DoD Agencies, each DoD Component is considered an agency within the meaning of the Privacy Act.

(c)
Computer Matching Program
. The computerized comparison of two or more automated systems of records or a system of records with non-Federal records. Manual comparison of systems of records or a system of records with non-Federal records are not covered.

(d)
Confidential source
. A person or organization who has furnished information to the Federal Government under an express promise, if made on or after September 27, 1975, that the person's or the organization's identity shall be held in confidence or under an implied promise of such confidentiality if this implied promise was made on or before September 26, 1975.

(e)
Disclosure
. The transfer of any personal information from a system of records by any means of communication (such as oral, written, electronic, mechanical, or actual review) to any person, private entity, or Government Agency, other than the subject of the record, the subject's designated agent or the subject's legal guardian.

(f)
Federal benefit program
. A program administered or funded by the Federal Government, or by any agent or State on behalf of the Federal Government, providing cash or in-kind assistance in the form of payments, grants, loans, or loan guarantees to individuals.

(g)
Federal personnel
. Officers and employees of the Government of the United States, members of the uniformed services (including members of the Reserve Components), individuals entitled to receive immediate or deferred retirement benefits under any retirement program of the United States (including survivor benefits).

(h)
Individual
. A living person who is a citizen of the United States or an alien lawfully admitted for permanent residence. The parent of a minor or the legal guardian of any individual also may act on behalf of an individual. Members of the United States Armed Forces are “individuals.” Corporations, partnerships, sole proprietorships, professional groups, businesses, whether incorporated or unincorporated, and other commercial entities are not “individuals” when acting in an entrepreneurial capacity with the Department of Defense but are “individuals” otherwise (e.g., security clearances, entitlement to DoD privileges or benefits, etc.).

(i)
Individual access
. Access to information pertaining to the individual by the individual or his or her designated agent or legal guardian.

(j)
Lost, stolen, or compromised information
. Actual or possible loss of control, unauthorized disclosure, or unauthorized access of personal information where persons other than authorized users gain access or potential access to such information for an other than authorized purpose where one or more individuals will be adversely affected. Such incidents also are known as
breaches
.

(k)
Maintain
. To maintain, collect, use, or disseminate records contained in a system of records.

(l)
Non-Federal agency
. Any state or local government, or agency thereof, which receives records contained in a system of records from a source agency for use in a computer matching program.

(m)
Official use
. Within the context of this part, this term is used when officials and employees of a DoD Component have a demonstrated a need for the record or the information

contained therein in the performance of their official duties, subject to DoD 5200.1-R.
5

5
See footnote 1 to § 310.1.

(n)
Personal information
. Information about an individual that identifies, links, relates, or is unique to, or describes him or her, e.g., a social security number; age; military rank; civilian grade; marital status; race; salary; home/office phone numbers; other demographic, biometric, personnel, medical, and financial information, etc. Such information also is known as
personally identifiable information
(i.e., information which can be used to distinguish or trace an individual's identity, such as their name, social security number, date and place of birth, mother's maiden name, biometric records, including any other personal information which is linked or linkable to a specified individual).

(o)
Privacy Act request
. A request from an individual for notification as to the existence of, access to, or amendment of records pertaining to that individual. These records must be maintained in a system of records.

(p)
Member of the public
. Any individual or party acting in a private capacity to include Federal employees or military personnel.

(q)
Recipient agency
. Any agency, or contractor thereof, receiving records contained in a system of records from a source agency for use in a computer matching program.

(r)
Record
. Any item, collection, or grouping of information, whatever the storage media (e.g., paper, electronic, etc.), about an individual that is maintained by a DoD Component, including, but not limited to, his or her education, financial transactions, medical history, criminal or employment history, and that contains his or her name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a finger or voice print or a photograph.

(s)
Risk assessment
. An analysis considering information sensitivity, vulnerabilities, and cost in safeguarding personal information processed or stored in the facility or activity.

(t)
Routine use
. The disclosure of a record outside the Department of Defense for a use that is compatible with the purpose for which the information was collected and maintained by the Department of Defense. The routine use must be included in the published system notice for the system of records involved.

(u)
Source agency
. Any agency which discloses records contained in a system of records to be used in a computer matching program, or any state or local government, or agency thereof, which discloses records to be used in a computer matching program.

(v)
Statistical record
. A record maintained only for statistical research or reporting purposes and not used in whole or in part in making determinations about specific individuals.

(w)
System of records
. A group of records under the control of a DoD Component from which personal information about an individual is retrieved by the name of the individual or by some other identifying number, symbol, or other identifying particular assigned, that is unique to the individual.

§ 310.5
Policy.
It is DoD policy that:

(a) The privacy of an individual is a personal and fundamental right that shall be respected and protected.

(1) The Department's need to collect, maintain, use, or disseminate personal information about individuals for purposes of discharging its statutory responsibilities shall be balanced against the right of the individual to be protected against unwarranted invasions of their privacy.

(2) The legal rights of individuals, as guaranteed by Federal law, regulation, and policy, shall be protected when collecting, maintaining, using, or disseminating personal information about individuals.

(3) DoD personnel, to include contractors, have an affirmative responsibility to protect an individual's privacy when collecting, maintaining, using, or disseminating personal information about an individual.

(4) Departmental legislative, regulatory, or other policy proposals shall be evaluated to ensure that privacy implications, including those relating to the collection, maintenance, use, or dissemination of personal information, are assessed, to include, when required and consistent with the Privacy Provision of the E-Government Act of 2002 (44 U.S.C. 3501, Note), the preparation of a Privacy Impact Assessment.

(b) Personal information shall be collected, maintained, used, or disclosed to ensure that:

(1) It shall be relevant and necessary to accomplish a lawful DoD purpose required to be accomplished by statute or Executive order.

(2) It shall be collected to the greatest extent practicable directly from the individual.

(3) The individual shall be informed as to why the information is being collected, the authority for collection, what uses will be made of it, whether disclosure is mandatory or voluntary, and the consequences of not providing that information.

(4) It shall be relevant, timely, complete, and accurate for its intended use; and

(5) Appropriate administrative, technical, and physical safeguards shall be established, based on the media (e.g., paper, electronic, etc.) involved, to ensure the security of the records and to prevent compromise or misuse during storage, transfer, or use, including working at authorized alternative worksites.

(c) No record shall be maintained on how an individual exercises rights guaranteed by the First Amendment to the Constitution, except as follows:

(1) When specifically authorized by statute;

(2) When expressly authorized by the individual on whom the record is maintained; or

(3) When the record is pertinent to and within the scope of an authorized law enforcement activity.

(d) Notices shall be published in the
Federal Register
and reports shall be submitted to Congress and the Office of Management and Budget, in accordance with, and as required by, 5 U.S.C. 552a, OMB Circular A-130, and DoD 5400.11-R, as to the existence and character of any system of records being established or revised by the DoD Components. Information shall not be collected, maintained, used, or disseminated until the required publication and review requirements, as set forth in 5 U.S.C. 552a, OMB Circular A-130, and DoD 5400.11-R, are satisfied.

(e) Individuals shall be permitted, to the extent authorized by 5 U.S.C. 552a and DoD 5400.11-R, to:

(1) Determine what records pertaining to them are contained in a system of records.

(2) Gain access to such records and obtain a copy of those records or a part thereof.

(3) Correct or amend such records once it has been determined that the records are not accurate, relevant, timely, or complete.

(4) Appeal a denial of access or a request for amendment.

(f) Disclosure of records pertaining to an individual from a system of records shall be prohibited except with the consent of the individual or as otherwise authorized by 5 U.S.C. 552a, DoD 5400.11-R, and DoD 5400.7-R. When disclosures are made, the individual shall be permitted, to the

extent authorized by references 5 U.S.C. 552a and/or DoD 5400.11-R, to seek an accounting of such disclosures from the DoD Component making the release.

(g) Disclosure of records pertaining to personnel of the National Security Agency, the Defense Intelligence Agency, the National Reconnaissance Office, and the National Geospatial-Intelligence Agency shall be prohibited to the extent authorized by Public Law 86-36 (1959) and 10 U.S.C. 424. Disclosure of records pertaining to personnel of overseas, sensitive, or routinely deployable units shall be prohibited to the extent authorized by 10 U.S.C. 130b. Disclosure of medical records is prohibited except as authorized by DoD 6025.18-R.
6

6
See footnote 1 to § 310.1.

(h) Computer matching programs between the DoD Components and the Federal, State, or local governmental agencies shall be conducted in accordance with the requirements of 5 U.S.C. 552a, OMB Circular A-130, and DoD 5400.11-R.

(i) DoD personnel and system managers shall conduct themselves consistent with established rules of conduct 310.8 so that personal information to be stored in a system of records only shall be collected, maintained, used, and disseminated as is authorized by this part, 5 U.S.C. 552a and DoD 5400.11-R.

(j) DoD personnel, including but not limited to family members, retirees, contractor employees, and volunteers, shall be notified, in a timely manner, consistent with the requirements of DoD 5400.11-R, if their personal information, whether or not included in a system of records, is lost, stolen, or compromised.

(k) DoD Field Activities shall receive Privacy Program support from the Director, Washington Headquarters Services.

§ 310.6
Responsibilities.
(a) The Director of Administration and Management, Office of the Secretary of Defense, shall:

(1) Serve as the Senior Privacy Official for the Department of Defense.

(2) Provide policy guidance for, and coordinate and oversee administration of, the DoD Privacy Program to ensure compliance with policies and procedures in 5 U.S.C. 552a and OMB Circular A-130.

(3) Publish DoD 5400.11-R and other guidance, including Defense Privacy Board Advisory Opinions, to ensure timely and uniform implementation of the DoD Privacy Program.

(4) Serve as the Chair to the Defense Privacy Board and the Defense Data Integrity Board (see § 310.9).

(5) Supervise and oversee the activities of the Defense Privacy Office (see § 310.9).

(b) The Director, WHS, under the DA&M, shall provide Privacy Program support for DoD Field Activities.

(c) The General Counsel of the Department of Defense shall:

(1) Provide advice and assistance on all legal matters arising out of, or incident to, the administration of the DoD Privacy Program.

(2) Review and be the final approval authority on all advisory opinions issued by the Defense Privacy Board or the Defense Privacy Board Legal Committee.

(3) Serve as a member of the Defense Privacy Board, the Defense Data Integrity Board, and the Defense Privacy Board Legal Committee (310.9).

(d) The Secretaries of the Military Departments and the Heads of the Other DoD Components, except as noted in § 310.5(k), shall:

(1) Provide adequate funding and personnel to establish and support an effective DoD Privacy Program, to include the appointment of a senior official to serve as the principal point of contact (POC) for DoD Privacy Program matters.

(2) Establish procedures, as well as rules of conduct, necessary to implement this part and DoD 5400.11-R to ensure compliance with the requirements of 5 U.S.C. 552a and OMB Circular A-130.

(3) Conduct training, consistent with the requirements of DoD 5400.11-R, on the provisions of this part, 5 U.S.C. 552a, OMB Circular A-130, and DoD 5400.11-R, for assigned, employed and detailed, to include contractor, personnel and individuals having primary responsibility for implementing the DoD Privacy Program.

(4) Ensure all Component legislative proposals, policies, or programs having privacy implications, such as the DoD Privacy Impact Assessment Program, are evaluated to ensure consistency with the information privacy principles of this part and DoD 5400.11-R.

(5) Assess the impact of technology on the privacy of personal information and, when feasible, adopt privacy-enhancing technology both to preserve and protect personal information contained in Component systems of records and to permit auditing of compliance with the requirements of this part and DoD 5400.11-R.

(6) Ensure the DoD Privacy Program periodically shall be reviewed by the Inspectors General or other officials, who shall have specialized knowledge of the DoD Privacy Program.

(7) Submit reports, consistent with the requirements of DoD 5400.11-R, as mandated by 5 U.S.C. 552a and OMB Circular A-130, and DoD Directive 5500.1, and as otherwise directed by the DPO.

(e) The Secretaries of the Military Departments shall provide support to the Combatant Commands, as identified in DoD Directive 5100.3,
7

in the administration of the DoD Privacy Program.

7
See footnote 1 to § 310.1.

§ 310.7
Information requirements.
The reporting requirements in § 310.6(d)(7) are assigned Report Control Symbol DD-DA&M(A)1379.

§ 310.8
Rules of conduct.
(a) DoD personnel shall:

(1) Take such actions, as considered appropriate, to ensure that personal information contained in a system of records, to which they have access to or are using incident to the conduct of official business, shall be protected so that the security and confidentiality of the information shall be preserved.

(2) Not disclose any personal information contained in any system of records except as authorized by DoD 5400.11-R or other applicable law or regulation. Personnel willfully making such a disclosure when knowing that disclosure is prohibited are subject to possible criminal penalties and/or administrative sanctions.

(3) Report any unauthorized disclosures of personal information from a system of records or the maintenance of any system of records that are not authorized by this part to the applicable Privacy POC for his or her DoD Component.

(b) DoD System Managers for each system of records shall:

(1) Ensure that all personnel who either shall have access to the system of records or who shall develop or supervise procedures for handling records in the system of records shall be aware of their responsibilities and are properly trained to safeguard personal information being collected and maintained under the DoD Privacy Program.

(2) Prepare promptly any required new, amended, or altered system notices for the system of records and submit them through their DoD Component Privacy POC to the DPO for publication in the
Federal Register
.

(3) Not maintain any official files on individuals which are retrieved by name or other personal identifier without first

ensuring that a notice for the system of records shall have been published in the
Federal Register
. Any official who willfully maintains a system of records without meeting the publication requirements, as prescribed by 5 U.S.C. 552a, OMB Circular A-130, and DoD 5400.11-R, is subject to possible criminal penalties and/or administrative sanctions.

§ 310.9
Privacy boards and office, composition and responsibilities.

(a)
The Defense Privacy Board
—(1)
Membership.
The Board shall consist of the DA&M, OSD, who shall serve as the Chair; the Director of the DPO, DA&M, who shall serve as the Executive Secretary and as a member; the representatives designated by the Secretaries of the Military Departments; and the following officials or their designees: the Deputy Under Secretary of Defense for Program Integration (DUSD(PI)); the Assistant Secretary of Defense for Health Affairs; the Assistant Secretary of Defense for Networks and Information Integration (ASD) (NII)/Chief Information Officer (CIO); the Director, Executive Services and Communications Directorate, WHS; the GC, DoD; and the Director for Information Technology Management Directorate (ITMD), WHS. The designees also may be the principal POC for the DoD Component for privacy matters.

(2)
Responsibilities.
(i) The Board shall have oversight responsibility for implementation of the DoD Privacy Program. It shall ensure the policies, practices, and procedures of that Program are premised on the requirements of 5 U.S.C. 552a and OMB Circular A-130, as well as other pertinent authority, and the Privacy Programs of the DoD Component are consistent with, and in furtherance of, the DoD Privacy Program.

(ii) The Board shall serve as the primary DoD policy forum for matters involving the DoD Privacy Program, meeting as necessary, to address issues of common concern so as to ensure uniform and consistent policy shall be adopted and followed by the DoD Components. The Board shall issue advisory opinions as necessary on the DoD Privacy Program so as to promote uniform and consistent application of 5 U.S.C. 552a, OMB Circular A-130, and DoD 5400.11-R.

(iii) Perform such other duties as determined by the Chair or the Board.

(b)
The Defense Data Integrity Board
—(1)
Membership.
The Board shall consist of the DA&M, OSD, who shall serve as the Chair; the Director of the DPO, DA&M, who shall serve as the Executive Secretary; and the following officials or their designees: the representatives designated by the Secretaries of the Military Departments; the DUSD(PI); the (ASD) (NII)/CIO; the GC, DoD; the Inspector General, DoD; the ITMD, WHS; and the Director, Defense Manpower Data Center. The designees also may be the principal points of contact for the DoD Component for privacy matters.

(2)
Responsibilities.
(i) The Board shall oversee and coordinate, consistent with the requirements of 5 U.S.C. 552a, OMB Circular A-130, and DoD 5400.11-R, all computer matching programs involving personal records contained in system of records maintained by the DoD Components.

(ii) The Board shall review and approve all computer matching agreements between the Department of Defense and the other Federal, State or local governmental agencies, as well as memoranda of understanding when the match is internal to the Department of Defense, to ensure, under 5 U.S.C. 552a, OMB Circular A-130, and DoD 5400.11-R, appropriate procedural and due process requirements shall have been established before engaging in computer matching activities.

(c)
The Defense Privacy Board Legal Committee
—(1)
Membership.
The Committee shall consist of the Director, DPO, DA&M, who shall serve as the Chair and the Executive Secretary; the GC, DoD, or designee; and civilian and/or military counsel from each of the DoD Components. The General Counsels (GCs) and The Judge Advocates General of the Military Departments shall determine who shall provide representation for their respective Department to the Committee. This does not preclude representation from each office. The GCs of the other DoD Components shall provide legal representation to the Committee. Other DoD civilian or military counsel may be appointed by the Executive Secretary, after coordination with the DoD Component concerned, to serve on the Committee on those occasions when specialized knowledge or expertise shall be required.

(2)
Responsibilities.
(i) The Committee shall serve as the primary legal forum for addressing and resolving all legal issues arising out of or incident to the operation of the DoD Privacy Program.

(ii) The Committee shall consider legal questions regarding the applicability of 5 U.S.C. 552a, OMB Circular A-130, and DoD 5400.11-R and questions arising out of or as a result of other statutory and regulatory authority, to include the impact of judicial decisions, on the DoD Privacy Program. The Committee shall provide advisory opinions to the Defense Privacy Board and, on request, to the DoD Components.

(d)
The DPO
—(1)
Membership.
It shall consist of a Director and a staff. The Director also shall serve as the Executive Secretary and a member of the Defense Privacy Board; as the Executive Secretary to the Defense Data Integrity Board; and as the Chair and the Executive Secretary to the Defense Privacy Board Legal Committee.

(2)
Responsibilities.
(i) Manage activities in support of the Privacy Program oversight responsibilities of the DA&M.

(ii) Provide operational and administrative support to the Defense Privacy Board, the Defense Data Integrity Board, and the Defense Privacy Board Legal Committee.

(iii) Direct the day-to-day activities of the DoD Privacy Program.

(iv) Provide guidance and assistance to the DoD Components in their implementation and execution of the DoD Privacy Program.

(v) Review DoD legislative, regulatory, and other policy proposals which implicate information privacy issues relating to the Department's collection, maintenance, use, or dissemination of personal information, to include any testimony and comments having such implications under DoD Directive 5500.1.

(vi) Review proposed new, altered, and amended systems of records, to include submission of required notices for publication in the
Federal Register
and, when required, providing advance notification to the OMB and the Congress, consistent with 5 U.S.C. 552a, OMB Circular A-130, and DoD 5400.11-R.

(vii) Review proposed DoD Component privacy rulemaking, to include submission of the rule to the Office of the Federal Register for publication and providing to the OMB and the Congress reports, consistent with 5 U.S.C. 552a, OMB Circular A-130, and DoD 5400.11-R.

(viii) Develop, coordinate, and maintain all DoD computer matching agreements, to include the submission of required match notices for publication in the
Federal Register
and the provision of advance notification to the OMB and the Congress, consistent with 5 U.S.C. 552a, OMB Circular A-130, and DoD 5400.11-R.

(ix) Provide advice and support to the DoD Components to ensure:

(A) All information requirements developed to collect or maintain personal data conform to DoD Privacy Program standards;

(B) Appropriate procedures and safeguards shall be developed, implemented, and maintained to protect personal information when it is stored in either a manual and/or automated system of records or transferred by electronic or non-electronic means; and

(C) Specific procedures and safeguards shall be developed and implemented when personal data is collected and maintained for research purposes.

(x) Serve as the principal POC for coordination of privacy and related matters with the OMB and other Federal, State, and local governmental agencies.

(xi) Compile and submit the “Biennial Matching Activity Report” to the OMB as required by OMB Circular A-130 and DoD 5400.11-R, and the Quarterly and Annual Federal Information Security Management Agency (FISMA) Privacy Reports, as required by 44 U.S.C. 3544(c), such other reports as may be required.

(xii) Update and maintain this part and DoD 5400.11-R.

Subpart B—Systems of Records

§ 310.10
General.

(a)
System of Records.
To be subject to the provisions of this part, a “system of records” must:

(1) Consist of “records” (as defined in 310.4(r)) that are retrieved by the name of an individual or some other personal identifier; and

(2) Be under the control of a DoD Component.

(b)
Retrieval practices.
(1) Records in a group of records that MAY be retrieved by a name or personal identifier are not covered by this part even if the records contain personal data and are under control of a DoD Component. The records MUST be retrieved by name or other personal identifier to become a system of records for the purpose of this part.

(i) When records are contained in an automated (Information Technology) system that is capable of being manipulated to retrieve information about an individual, this does not automatically transform the system into a system of records as defined in this part.

(ii) In determining whether an automated system is a system of records that is subject to this part, retrieval policies and practices shall be evaluated. If DoD Component policy is to retrieve personal information by the name or other unique personal identifier, it is a system of records. If DoD Component policy prohibits retrieval by name or other identifier, but the actual practice of the Component is to retrieve information by name or identifier, even if done infrequently, it is a system of records.

(2) If records are retrieved by name or personal identifier, a system notice must be submitted in accordance with § 310.33.

(3) If records are not retrieved by name or personal identifier but then are rearranged in such a manner that they are retrieved by name or personal identifier, a new systems notice must be submitted in accordance with § 310.33.

(4) If records in a system of records are rearranged so that retrieval is no longer by name or other personal identifier, the records are no longer subject to this part and the system notice for the records shall be deleted in accordance with § 310.34.

(c)
Relevance and necessity.
Information or records about an individual shall only be maintained in a system of records that is relevant and necessary to accomplish a DoD Component purpose required by a Federal statute or an Executive Order.

(d)
Authority to establish systems of records.
Identify the specific statute or the Executive Order that authorizes maintaining personal information in each system of records. The existence of a statute or Executive Order mandating the maintenance of a system of records does not abrogate the responsibility to ensure that the information in the system of records is relevant and necessary. If a statute or Executive Order does not expressly direct the creation of a system of records, but the establishment of a system of records is necessary in order to discharge the requirements of the statute or Executive Order, the statute or Executive Order shall be cited as authority.

(e)
Exercise of First Amendment rights.
(1) Do not maintain any records describing how an individual exercises his or her rights guaranteed by the First Amendment of the U.S. Constitution except when:

(i) Expressly authorized by Federal statute;

(ii) Expressly authorized by the individual; or

(iii) Maintenance of the information is pertinent to and within the scope of an authorized law enforcement activity.

(2) First Amendment rights include, but are not limited to, freedom of religion, freedom of political beliefs, freedom of speech, freedom of the press, the right to assemble, and the right to petition.

(f)
System Manager's evaluation.
(1) Evaluate the information to be included in each new system before establishing the system and evaluate periodically the information contained in each existing system of records for relevancy and necessity. Such a review shall also occur when a system notice alteration or amendment is prepared (see § 310.33 and § 310.34).

(2) Consider the following:

(i) The relationship of each item of information retained and collected to the purpose for which the system is maintained;

(ii) The specific impact on the purpose or mission of not collecting each category of information contained in the system;

(iii) The possibility of meeting the informational requirements through use of information not individually identifiable or through other techniques, such as sampling;

(iv) The length of time each item of personal information must be retained;

(v) The cost of maintaining the information; and

(vi) The necessity and relevancy of the information to the purpose for which it was collected.

(g)
Discontinued information requirements.
(1) Stop collecting immediately any category or item of personal information for which retention is no longer justified. Also delete this information from existing records, when feasible.

(2) Do not destroy any records that must be retained in accordance with disposal authorizations established under 44 U.S.C. 3303a, Examination by Archivist of Lists and Schedules of Records Lacking Preservation Value; Disposal of Records.”

§ 310.11
Standards of accuracy.

(a)
Accuracy of information maintained.
Maintain all personal information used or may be used to make any determination about an individual with such accuracy, relevance, timeliness, and completeness as is reasonably necessary to ensure fairness to the individual in making any such determination.

(b)
Accuracy determinations before dissemination.
Before disseminating any personal information from a system of records to any person outside the Department of Defense, other than a Federal Agency, make reasonable efforts to ensure the information to be disclosed is accurate, relevant, timely, and complete for the purpose it is being maintained (see § 310.21(d)).

§ 310.12
Government contractors.

(a)
Applicability to government contractors.
(1) When a DoD Component contract requires the operation or maintenance of a system of records or a portion of a system of records or

requires the performance of any activities associated with maintaining a system of records, including the collection, use, and dissemination of records, the record system or the portion of the record system affected are considered to be maintained by the DoD Component and are subject to this part. The Component is responsible for applying the requirements of this part to the contractor. The contractor and its employees are to be considered employees of the DoD Component for purposes of the criminal provisions of 5 U.S.C 552a(i) during the performance of the contract. Consistent with the Federal Acquisition Regulation (FAR), Part 24.1, contracts requiring the maintenance or operation of a system of records or the portion of a system of records shall include in the solicitation and resulting contract such terms as are prescribed by the FAR.

(2) If the contractor must use, have access to, or disseminate individually identifiable information subject to this part in order to perform any part of a contract, and the information would have been collected, maintained, used, or disseminated by the DoD Component but for the award of the contract, these contractor activities are subject to this part.

(3) The restriction in paragraphs (a)(1) and (2) of this section do not apply to records:

(i) Established and maintained to assist in making internal contractor management decisions, such as records maintained by the contractor for use in managing the contract;

(ii) Maintained as internal contractor employee records even when used in conjunction with providing goods and services to the Department of Defense; or

(iii) Maintained as training records by an educational organization contracted by a DoD Component to provide training when the records of the contract students are similar to and commingled with training records of other students (for example, admission forms, transcripts, academic counseling and similar records).

(iv) Maintained by a consumer reporting agency to which records have been disclosed under contract in accordance with the Federal Claims Collection Act of 1966, 31 U.S.C. 3711(e).

(v) Maintained by the contractor incident to normal business practices and operations.

(4) The DoD Components shall publish instructions that:

(i) Furnish DoD Privacy Program guidance to their personnel who solicit, award, or administer Government contracts;

(ii) Inform prospective contractors of their responsibilities, and provide training as appropriate, regarding the DoD Privacy Program; and

(iii) Establish an internal system of contractor performance review to ensure compliance with the DoD Privacy Program.

(b)
Contracting procedures.
The Defense Acquisition Regulations Council shall develop the specific policies and procedures to be followed when soliciting bids, awarding contracts or administering contracts that are subject to this part.

(c)
Contractor compliance.
Through the various contract surveillance programs, ensure contractors comply with the procedures established in accordance with § 310.12(b).

(d)
Disclosure of records to contractors.
Disclosure of records contained in a system of records by a DoD Component to a contractor for use in the performance of a DoD contract is considered a disclosure within the Department of Defense (see § 310.21(b)). The contractor is considered the agent of the contracting DoD Component and to be maintaining and receiving the records for that Component.

§ 310.13
Safeguarding personal information.

(a)
General responsibilities.
DoD Components shall establish appropriate administrative, technical and physical safeguards to ensure that the records in each system of records are protected from unauthorized access, alteration, or disclosure and that their confidentiality is preserved and protected. Records shall be protected against reasonably anticipated threats or hazards that could result in substantial harm, embarrassment, inconvenience, or unfairness to any individual about whom information is kept.

(b)
Minimum standards.
(1) Tailor system safeguards to conform to the type of records in the system, the sensitivity of the personal information stored, the storage medium used and, to a degree, the number of records maintained.

(2) Treat all unclassified records that contain personal information that normally would be withheld from the public under Freedom of Information Exemption Numbers 6 and 7 of 286.12, subpart C of 32 CFR part 286 (“DoD Freedom of Information Act Program”) as “For Official Use Only,” and safeguard them accordingly, in accordance with DoD 5200.1-R even if they are not actually marked “For Official Use Only.”

(3) Personal information that does not meet the criteria discussed in paragraph (b)(2) of this section shall be accorded protection commensurate with the nature and type of information involved.

(4) Special administrative, physical, and technical procedures are required to protect data that is stored or processed in an information technology system to protect against threats unique to an automated environment (see Appendix A).

(5) Tailor safeguards specifically to the vulnerabilities of the system.

(c)
Records disposal.
(1) Dispose of records containing personal data so as to prevent inadvertent compromise. Disposal methods are those approved by the Component or the National Institute of Standards and Technology. For paper records, disposal methods, such as tearing, burning, melting, chemical decomposition, pulping, pulverizing, shredding, or mutilation are acceptable. For electronic records, and media, disposal methods, such as overwriting, degaussing, disintegration, pulverization, burning, melting, incineration, shredding or sanding, are acceptable.

(2) Disposal methods are considered adequate if the personal data is rendered unrecognizable or beyond reconstruction.

§ 310.14
Notification when information is lost, stolen, or compromised.
(a) If records containing personal information are lost, stolen, or compromised, the potential exists that the records may be used for unlawful purposes, such as identity theft, fraud, stalking, etc. The personal impact on the affected individual may be severe if the records are misused. To assist the individual, the Component shall promptly notify the individual of any loss, theft, or compromise (See also, § 310.50 for reporting of the breach to Senior Component Official for Privacy and the Defense Privacy Office).

(1) The notification shall be made whenever a breach occurs that involves personal information pertaining to a service member, civilian employee (appropriated or non-appropriated fund), military retiree, family member, DoD contractor, other persons that are affiliated with the Component (e.g., volunteer), and/or any other member of the public on whom information is maintained by the Component or by a contractor on behalf of the Component.

(2) The notification shall be made as soon as possible, but not later than 10 working days after the loss, theft, or compromise is discovered and the identities of the individuals ascertained.

(i) The 10 day period begins to run after the Component is able to determine the identities of the individuals whose records were lost.

(ii) If the Component is only able to identify some but not all of the affected individuals, notification shall be given to those that can be identified with follow-up notifications made to those subsequently identified.

(iii) If the Component cannot readily identify the affected individuals or will not be able to identify the individuals, the Component shall provide a generalized notice to the potentially impacted population by whatever means the Component believes is most likely to reach the affected individuals.

(3) When personal information is maintained by a DoD contractor on behalf of the Component, the contractor shall notify the Component immediately upon discovery that a loss, theft or compromise has occurred.

(i) The Component shall determine whether the Component or the contractor shall make the required notification.

(ii) If the contractor is to notify the impacted population, it shall submit the notification letters to the Component for review and approval. The Component shall coordinate with the Contractor to ensure the letters meet the requirements of § 310.14.

(4) Subject to paragraph (a)(2) of this section, the Component shall inform the Deputy Secretary of Defense of the reasons why notice was not provided to the individuals or the affected population within the 10-day period.

(i) If for good cause (e.g., law enforcement authorities request delayed notification as immediate notification will jeopardize investigative efforts), notice can be delayed, but the delay shall only be for a reasonable period of time. In determining what constitutes a reasonable period of delay, the potential harm to the individual must be weighed against the necessity for delayed notification.

(ii) The required notification shall be prepared and forwarded to the Senior Component Official for Privacy who shall forward it to the Defense Privacy Office. The Defense Privacy Office, in coordination with the Office of the Under Secretary of Defense for Personnel and Readiness, shall forward the notice to the Deputy Secretary.

(5) The notice to the individual, at a minimum, shall include the following:

(i) The individuals shall be advised of what specific data was involved. It is insufficient to simply state that personal information has been lost. Where names, social security numbers, and dates of birth are involved, it is critical that the individual be advised that these data elements potentially have been compromised.

(ii) The individual shall be informed of the facts and circumstances surrounding the loss, theft, or compromise. The description of the loss should be sufficiently detailed so that the individual clearly understands how the compromise occurred.

(iii) The individual shall be informed of what protective actions the Component is taking or the individual can take to mitigate against potential future harm. The Component should refer the individual to the Federal Trade Commission's public Web site on identity theft at
http://www.consumer.gov/idtheft/con_steps.htm.
The site provides valuable information as to what steps individuals can take to protect themselves if their identities potentially have been or are stolen.

(iv) A sample notification letter is at Appendix B.

(b) The notification shall be made whether or not the personal information is contained in a system of records (See § 310.10(a)).

Subpart C—Collecting Personal Information

§ 310.15
General considerations.

(a)
Collect directly from the individual.
Collect to the greatest extent practicable personal information directly from the individual to whom it pertains if the information may result in adverse determination about an individual's rights, privileges, or benefits under any Federal program.

(b)
Collecting social security numbers (SSNs).
(1) It is unlawful for any Federal, State, or local governmental agency to deny an individual any right, benefit, or privilege provided by law because the individual refuses to provide his or her SSN. However, if a Federal statute requires the SSN be furnished or if the SSN is furnished to a DoD Component maintaining a system of records in existence that was established and in operation before January 1, 1975, and the SSN was required under a statute or regulation adopted prior to this date for purposes of verifying the identity of an individual, this restriction does not apply.

(2) When an individual is requested to provide his or her SSN, he or she must be told:

(i) What uses will be made of the SSN;

(ii) The statute, regulation, or rule authorizing the solicitation of the SSN; and

(iii) Whether providing the SSN is voluntary or mandatory.

(3) Include in any systems notice for any system of records that contains SSNs a statement indicating the authority for maintaining the SSN.

(4) E.O. 9397,”Numbering System for Federal Accounts Relating to Individual Persons”, November 30, 1943, authorizes solicitation and use of SSNs as a numerical identifier for Federal personnel that are identified in most Federal record systems. However, it does not constitute authority for mandatory disclosure of the SSN.

(5) Upon entrance into military service or civilian employment with the Department of Defense, individuals are asked to provide their SSNs. The SSN becomes the service or employment number for the individual and is used to establish personnel, financial, medical, and other official records. The notification in paragraph (b)(2) of this section shall be provided the individual when originally soliciting his or her SSN. The notification is not required if an individual is requested to furnish his SSN for identification purposes and the SSN is solely used to verify the SSN that is contained in the records. However, if the SSN is solicited and retained for any purposes other than verifying the existing SSN in the records, the requesting official shall provide the individual the notification required by paragraph (b)(2) of this section.

(6) Components shall ensure that the SSN is only collected when there is a demonstrated need for collection. If collection is not essential for the purposes for which the record or records are being maintained, it should not be solicited.

(7) DoD Components shall continually review their use of the SSN to determine whether such use can be eliminated, restricted, or concealed in Component business processes, systems and paper and electronic forms. While use of the SSN may be essential for program integrity and national security when information about an individual is disclosed outside the DoD, it may not be as critical when the information is being used for internal Departmental purposes.

(c)
Collecting personal information from third parties.
When information being solicited is of an objective nature and is not subject to being altered, the information should first be collected from the individual. But it may not be practicable to collect personal information first from the individual in all cases. Some examples of this are:

(1) Verification of information through third-party sources for security

or employment suitability determinations;

(2) Seeking third-party opinions such as supervisor comments as to job knowledge, duty performance, or other opinion-type evaluations;

(3) When obtaining information first from the individual may impede rather than advance an investigative inquiry into the actions of the individual; and

(4) Contacting a third party at the request of the individual to furnish certain information such as exact periods of employment, termination dates, copies of records, or similar information.

(d) Privacy Act Statements. (1) When an individual is requested to furnish personal information about himself or herself for inclusion in a system of records, a Privacy Act Statement is required regardless of the medium used to collect the information (forms, personal interviews, telephonic interviews, or other methods). The Privacy Act Statement consists of the elements set forth in paragraph (d)(2)of this section. The statement enables the individual to make an informed decision whether to provide the information requested. If the personal information solicited is not to be incorporated into a system of records, the statement need not be given. However, personal information obtained without a Privacy Act Statement shall not be incorporated into any system of records. When soliciting SSNs for any purpose, see paragraph (b)(2) of this section.

(2) The Privacy Act Statement shall include:

(i) The Federal statute or Executive Order that authorizes collection of the requested information (See § 310.10(d)).

(ii) The principal purpose or purposes for which the information is to be used;

(iii) The routine uses that will be made of the information (See § 310.22(d));

(iv) Whether providing the information is voluntary or mandatory (See paragraph (e) of this section); and

(v) The effects on the individual if he or she chooses not to provide the requested information.

(3) The Privacy Act Statement shall be concise, current, and easily understood.

(4) The Privacy Act statement may appear as a public notice (sign or poster), conspicuously displayed in the area where the information is collected, such as at check-cashing facilities or identification photograph facilities (but see § 310.16(a)).

(5) The individual normally is not required to sign the Privacy Act Statement.

(6) The individual shall be provided a written copy of the Privacy Act Statement upon request. This must be done regardless of the method chosen to furnish the initial advisement.

(e)
Mandatory as opposed to voluntary disclosures.
Include in the Privacy Act Statement specifically whether furnishing the requested personal data is mandatory or voluntary. A requirement to furnish personal data is mandatory only when the DoD Component is authorized to impose a penalty on the individual for failure to provide the requested information. If a penalty cannot be imposed, disclosing the information is always voluntary.

§ 310.16
Forms.

(a)
DoD Forms.
(1) DoD Instruction 7750.7
8

provides guidance for preparing Privacy Act Statements for use with forms (see also paragraph (b) of this section).

8
See footnote 1 to § 310.1.

(2) When forms are used to collect personal information, the Privacy Act Statement shall appear as follows (listed in the order of preference):

(i) In the body of the form, preferably just below the title so that the reader will be advised of the contents of the statement before he or she begins to complete the form;

(ii) On the reverse side of the form with an appropriate annotation under the title giving its location;

(iii) On a tear-off sheet attached to the form; or

(iv) As a separate supplement to the form.

(b)
Forms issued by non-DoD activities.
(1) Forms subject to the Privacy Act issued by other Federal Agencies must have a Privacy Act Statement. Always ensure the statement prepared by the originating Agency is adequate for the purpose for which the form shall be used by the DoD activity. If the Privacy Act Statement provided is inadequate, the DoD Component concerned shall prepare a new statement or a supplement to the existing statement before using the form.

(2) Forms issued by agencies not subject to the Privacy Act (State, municipal, and other local agencies) do not contain Privacy Act Statements. Before using a form prepared by such agencies to collect personal data subject to this part, an appropriate Privacy Act Statement must be added.

Subpart D—Access by Individuals

§ 310.17
Individual access to personal information.

(a)
Individual access.
(1) The access provisions of this part are intended for use by individuals who seek access to records about themselves that are maintained in a system of records. Release of personal information to individuals under this part is not considered public release of the information.

(2) Make available to the individual to whom the record pertains all of the personal information contained in the system of records except where access may be denied pursuant to an exemption claimed for the system (see subpart F to this part). However, when the access provisions of this subpart are not available to the individual due to a claimed exemption, the request shall be processed to provide information that is disclosable pursuant to the DoD Freedom of Information Act program (see 32 CFR, part 286).

(b)
Individual requests for access.
Individuals shall address requests for access to personal information in a system of records to the system manager or to the office designated in the DoD Component procedural rules or the system notice.

(c)
Verification of identity.
(1) Before granting access to personal data, an individual may be required to provide reasonable proof of his or her identity.

(2) Identity verification procedures shall not:

(i) Be so complicated as to discourage unnecessarily individuals from seeking access to information about themselves; or

(ii) Be required of an individual seeking access to records that normally would be available under the DoD Freedom of Information Act Program (see 32 CFR, part 286).

(iii) When an individual seeks personal access to records pertaining to themselves in person, proof of identity is normally provided by documents that an individual ordinarily possesses, such as employee and military identification cards, driver's license, other licenses, permits or passes used for routine identification purposes.

(iv) When access is requested by mail, identity verification may consist of the individual providing certain minimum identifying data, such as full name, date and place of birth, or such other personal information necessary to locate the record sought and information that is ordinarily only known to the individual. If the information sought is of a sensitive nature, additional identifying data may be required. An unsworn declaration under penalty of perjury (28 U.S.C. 1746, “Unsworn Declaration under Penalty of Perjury”) or notarized signatures are acceptable as a means of proving the identity of the individual.

(A) If an unsworn declaration is executed within the United States, its territories, possessions, or commonwealths, it shall read “I declare (or certify, verify, or state) under penalty of perjury that the foregoing is true and correct. Executed on (date). (Signature).”

(B) If an unsworn declaration is executed outside the United States, it shall read “I declare (or certify, verify, or state) under penalty of perjury under the laws of the United States of America that the foregoing is true and correct. Executed on (date). (Signature).”

(v) If an individual wishes to be accompanied by a third party when seeking access to his or her records or to have the records released directly to a third party, the individual may be required to furnish a signed access authorization granting the third-party access.

(vi) An individual shall not be refused access to his or her record solely because he or she refuses to divulge his or her SSN unless the SSN is the only method by which retrieval can be made. (See § 310.15(b).)

(vii) The individual is not required to explain or justify his or her need for access to any record under this part.

(viii) Only a denial authority may deny access and the denial must be in writing and contain the information required by 310.18.

(d)
Granting individual access to records.
(1) Grant the individual access to the original record or an exact copy of the original record without any changes or deletions, except when deletions have been made in accordance with paragraph (e) of this Section. For the purpose of granting access, a record that has been amended under § 310.19(b)is considered to be the original. See paragraph (e) of this Section for the policy regarding the use of summaries and extracts.

(2) Provide exact copies of the record when furnishing the individual copies of records under this part.

(3) Explain in terms understood by the requestor any record or portion of a record that is not clear.

(e)
Illegible, incomplete, or partially exempt records.
(1) Do not deny an individual access to a record or a copy of a record solely because the physical condition or format of the record does not make it readily available (for example, deteriorated state or on magnetic tape). Either prepare an extract or recopy the document exactly.

(2) If a portion of the record contains information that is exempt from access, an extract or summary containing all of the information in the record that is releasable shall be prepared.

(3) When the physical condition of the record or its state makes it necessary to prepare an extract for release, ensure the extract can be understood by the requester.

(4) Explain to the requester all deletions or changes to the records.

(f)
Access to medical records.
(1) Access to medical records is not only governed by the access provisions of this part but also by the access provisions of DoD 6025.18-R. The Privacy Act, as implemented by this part, however, provides greater access to an individual's medical record than that authorized by DoD 6025.18-R.

(2) Medical records in a system of records shall be disclosed to the individual to whom they pertain, even if a minor, but when it is believed that access to such records could have an adverse effect on the mental or physical health of the individual or may result in harm to a third party, the following special procedures apply.

(i) If a determination is made in consultation with a medical doctor that release of the medical information may be harmful to the mental or physical health of the individual or to a third party, the Component shall:

(A) Send the record to a physician named by the individual; and

(B) In the transmittal letter to the physician explain why access by the individual without proper professional supervision could be harmful (unless it is obvious from the record).

(ii) The Component shall not require the physician to request the records for the individual.

(3) If the individual refuses or fails to designate a physician, the record shall not be provided. Such refusal of access is not considered a denial under the Privacy Act (see paragraph (a) of § 310.18).

(4) If records are provided the designated physician, but the physician declines or refuses to provide the records to the individual, the DoD Component is under an affirmative duty to take action to deliver the records to the individual by whatever means deemed appropriate. Such action should be taken expeditiously especially if there has been a significant delay between the time the records were furnished the physician and the decision by the physician not to release the records.

(5) Access to a minor's medical records may be granted to his or her parents or legal guardians. However, access is subject to the restrictions as set forth at paragraph C9.7.3 of DoD 6025.18-R.

(6) All members of the Military Services and all married persons are not considered minors regardless of age, and the parents of these individual do not have access to their medical records without written consent of the individual.

(g)
Access to information compiled in anticipation of civil action (see § 310.27).

(h)
Non-Agency Records.
(1) Certain documents under the physical control of DoD personnel and used to assist them in performing official functions, are not considered “Agency records” within the meaning of this part. Uncirculated personal notes and records that are not disseminated or circulated to any person or organization (for example, personal telephone lists or memory aids) that are retained or discarded at the author's discretion and over which the Component exercises no direct control are not considered Agency records. However, if personnel are officially directed or encouraged, either in writing or orally, to maintain such records, they may become “Agency records,” and may be subject to this part.

(2) The personal uncirculated handwritten notes of unit leaders, office supervisors, or military supervisory personnel concerning subordinates are not systems of records within the meaning of this part. Such notes are an extension of the individual's memory. These notes, however, must be maintained and discarded at the discretion of the individual supervisor and not circulated to others. Any established requirement to maintain such notes (such as, written or oral directives, regulations, or command policy) may transform these notes into “Agency records” and they then must be made a part of a system of records. If the notes are circulated, they must be made a part of a system of records. Any action that gives personal notes the appearance of official Agency records is prohibited, unless the notes have been incorporated into a system of records.

(i)
Relationship between the Privacy Act (5 U.S.C. 552a) and the FOIA (5 U.S.C. 552).
Not all requesters are knowledgeable of the appropriate statutory authority to cite when requesting records. In some instances, they may cite neither Act, but will imply one or both Acts. The below guidelines are provided to ensure requesters are given the maximum amount of information as authorized under both statutes.

(1) Process requests for individual access as follows:

(i) If the records are required to be released under the Privacy Act, the FOIA (32 CFR part 286) does not bar release even if a FOIA exemption could

be invoked if the request had been processed solely under FOIA. Conversely, if the records are required to be released under the FOIA, the Privacy Act does not bar disclosure.

(ii) Requesters who seek records about themselves contained in a Privacy Act system of records, and who cite or imply only the Privacy Act, will have their records processed under the provisions of this part and the FOIA (32 CFR part 286). If the system of records is exempt from the access provisions of this part, and if the records, or any portion thereof, are exempt under the FOIA, the requester shall be advised and informed of the appropriate Privacy and FOIA exemption. Only if the records can be denied under both statutes may the Department withhold the records from the individual. Appeals shall be processed under both Acts.

(iii) Requesters who seek records about themselves that are not contained in a Privacy Act system of records, and who cite or imply only the Privacy Act, will have their requests processed under the provisions of the FOIA (32 CFR part 286), because the access provisions of this part do not apply. Appeals shall be processed under the FOIA.

(iv) Requesters who seek records about themselves that are contained in a Privacy Act system of records, and who cite or imply the FOIA or both Acts, will have their requests processed under the provisions of this part and the FOIA (32 CFR part 286). If the system of records is exempt from the access provisions of this part, and if the records, or any portion thereof, are exempt under the FOIA, the requester shall be advised and informed of the appropriate Privacy and FOIA exemption. Appeals shall be processed under both Acts.

(v) Requesters who seek records about themselves that are not contained in a Privacy Act system of records, and who cite or imply the Privacy Act and FOIA, will have their requests processed under the FOIA (32 CFR part 286), because the access provisions of this part do not apply. Appeals shall be processed under the FOIA.

(2) Do not deny individuals' access to personal information concerning themselves that would otherwise be releasable to them under either Act solely because they fail to cite or imply either Act or cite the wrong Act or part.

(3) Explain to the requester which Act(s) was(were) used when granting or denying access under either Act.

(j)
Time limits.
DoD Components normally shall acknowledge requests for access within 10 working days after receipt and provide access within 30 working days.

(k)
Privacy case file.
Establish a Privacy Act case file when required. (See paragraph (p) of § 310.19.)

§ 310.18
Denial of individual access.

(a)
Denying individual access.
(1) An individual may be denied access to a record pertaining to him or her only if the record:

(i) Was compiled in reasonable anticipation of a civil action or proceeding (see § 310.27).

(ii) Is in a system of records that has been exempted from the access provisions of this part under one of the permitted exemptions. (See § 310.28 and § 310.29.)

(iii) Contains classified information that has been exempted from the access provision of this part under the blanket exemption for such material claimed for all DoD records systems. (See § 310.26(c).).

(iv) Is contained in a system of records for which access may be denied under some other Federal statute that excludes the record from coverage of the Privacy Act (5 U.S.C. 552a).

(2) Where a basis for denial exists, do not deny the record, or portions of the record, if denial does not serve a legitimate governmental purpose.

(b)
Other reasons to refuse access:

(1) An individual may be refused access if:

(i) The record is not described well enough to enable it to be located with a reasonable amount of effort on the part of an employee familiar with the file; or

(ii) Access is sought by an individual who fails or refuses to comply with the established procedural requirements, including refusing to name a physician to receive medical records when required (see paragraph (f) of § 310.17) or to pay fees (see § 310.20).

(2) Always explain to the individual the specific reason access has been refused and how he or she may obtain access.

(c)
Notifying the individual.
Formal denials of access must be in writing and include as a minimum:

(1) The name, title or position, and signature of a designated Component denial authority.

(2) The date of the denial.

(3) The specific reason for the denial, including specific citation to the appropriate sections of the Privacy Act (5 U.S.C. 552a) or other statutes, this part, DoD Component instructions, or CFR authorizing the denial;

(4) Notice to the individual of his or her right to appeal the denial through the Component appeal procedure within 60 calendar days; and

(5) The title or position and address of the Privacy Act appeals official for the Component.

(d)
DoD Component appeal procedures.
Establish internal appeal procedures that, as a minimum, provide for:

(1) Review by the Head of the Component or his or her designee of any appeal by an individual from a denial of access to Component records.

(2) Formal written notification to the individual by the appeal authority that shall:

(i) If the denial is sustained totally or in part, include as a minimum:

(A) The exact reason for denying the appeal to include specific citation to the provisions of the Act or other statute, this part, Component instructions or the CFR upon which the determination is based;

(B) The date of the appeal determination;

(C) The name, title, and signature of the appeal authority; and

(D) A statement informing the applicant of his or her right to seek judicial relief.

(ii) If the appeal is granted, notify the individual and provide access to the material to which access has been granted.

(3) The written appeal notification granting or denying access is the final Component action as regards access.

(4) The individual shall file any appeal from denial of access within no less than 60 calendar days of receipt of the denial notification.

(5) Process all appeals within 30 days of receipt unless the appeal authority determines that a fair and equitable review cannot be made within that period. Notify the applicant in writing if additional time is required for the appellate review. The notification must include the reasons for the delay and state when the individual may expect an answer to the appeal.

(e)
Denial of appeals by failure to act.
A requester may consider his or her appeal formally denied if the appeal authority fails:

(1) To act on the appeal within 30 days;

(2) To provide the requester with a notice of extension within 30 days; or

(3) To act within the time limits established in the Component's notice of extension (see paragraph (d)(5) of this section).

(f)
Denying access to OPM records held by the DoD Components.
(1) The records in all systems of records maintained in accordance with the OPM Government-wide system notices are technically only in the temporary custody of the Department of Defense.

(2) All requests for access to these records must be processed in accordance with 5 CFR part 297 as well as applicable Component procedures.

(3) When a DoD Component refuses to grant access to a record in an OPM system, the Component shall advise the individual that his or her appeal must be directed to the Assistant Director for Workforce Information, Personnel Systems and Oversight Group, U.S. Office of Personnel Management, 1900 E Street, NW., Washington, DC, in accordance with the procedures of 5 CFR part 297.

§ 310.19
Amendment of records.

(a)
Individual review and correction.
Individuals are encouraged to review the personal information being maintained about them by the DoD Components periodically and to avail themselves of the procedures established by this part and other Regulations to update their records.

(b)
Amending records.
(1) An individual may request the amendment of any record contained in a system of records pertaining to him or her unless the system of records has been exempted specifically from the amendment procedures of this part under paragraph (b) of § 310.26. Normally, amendments under this part are limited to correcting factual matters and not matters of official judgment, such as performance ratings, promotion potential, and job performance appraisals.

(2) While a Component may require that the request for amendment be in writing, this requirement shall not be used to discourage individuals from requesting valid amendments or to burden needlessly the amendment process.

(3) A request for amendment must include:

(i) A description of the item or items to be amended;

(ii) The specific reason for the amendment;

(iii) The type of amendment action sought (deletion, correction, or addition); and

(iv) Copies of available documentary evidence supporting the request.

(c)
Burden of proof.
The applicant must support adequately his or her claim.

(d)
Identification of requesters.
(1) Individuals may be required to provide identification to ensure that they are indeed seeking to amend a record pertaining to themselves and not, inadvertently or intentionally, the record of others.

(2) The identification procedures shall not be used to discourage legitimate requests or to burden needlessly or delay the amendment process. (See paragraph (c) of § 310.17.)

(e)
Limits on attacking evidence previously submitted.
(1) The amendment process is not intended to permit the alteration of records presented in the course of judicial or quasi-judicial proceedings. Any amendments or changes to these records normally are made through the specific procedures established for the amendment of such records.

(2) Nothing in the amendment process is intended or designed to permit a collateral attack upon what has already been the subject of a judicial or quasi-judicial determination. However, while the individual may not attack the accuracy of the judicial or quasi-judicial determination under this part, he or she may challenge the accuracy of the recording of that action.

(f)
Sufficiency of a request to amend.
Consider the following factors when evaluating the sufficiency of a request to amend:

(1) The accuracy of the information; and

(2) The relevancy, timeliness, completeness, and necessity of the recorded information.

(g)
Time limits.
(1) Provide written acknowledgement of a request to amend within 10 working days of its receipt by the appropriate systems manager. There is no need to acknowledge a request if the action is completed within 10 working days and the individual is so informed.

(2) The letter of acknowledgement shall clearly identify the request and advise the individual when he or she may expect to be notified of the completed action.

(3) Only under the most exceptional circumstances shall more than 30 days be required to reach a decision on a request to amend. Document fully and explain in the Privacy Act case file (see paragraph (p) of this section) any such decision that takes more than 30 days to resolve.

(h)
Agreement to amend.
If the decision is made to grant all or part of the request for amendment, amend the record accordingly and notify the requester.

(i)
Notification of previous recipients.
(1) Notify all previous recipients of the record, as reflected in the disclosure accounting records, that an amendment has been made and the substance of the amendment. Recipients who are known to be no longer retaining the information need not be advised of the amendment. All DoD Components and Federal agencies known to be retaining the record or information, even if not reflected in a disclosure record, shall be notified of the amendment. Advise the requester of these notifications.

(2) Honor all requests by the requester to notify specific Federal agencies of the amendment action.

(j)
Denying amendment.
If the request for amendment is denied in whole or in part, promptly advise the individual in writing of the decision to include:

(1) The specific reason and authority for not amending;

(2) Notification that he or she may seek further independent review of the decision by the Head of the DoD Component or his or her designee;

(3) The procedures for appealing the decision citing the position and address of the official to whom the appeal shall be addressed; and

(4) Where he or she can receive assistance in filing the appeal.

(k)
DoD Component appeal procedures.
Establish procedures to ensure the prompt, complete, and independent review of each amendment denial upon appeal by the individual. These procedures must ensure:

(1) The appeal with all supporting materials both that furnished the individual and that contained in Component records is provided to the reviewing official; and

(2) If the appeal is denied completely or in part, the individual is notified in writing by the reviewing official that:

(i) The appeal has been denied and the specific reason and authority for the denial;

(ii) The individual may file a statement of disagreement with the appropriate authority and the procedures for filing this statement;

(iii) If filed properly, the statement of disagreement shall be included in the records, furnished to all future recipients of the records, and provided to all prior recipients of the disputed records who are known to hold the record; and

(iv) The individual may seek a judicial review of the decision not to amend.

(3) If the record is amended, ensure:

(i) The requester is notified promptly of the decision;

(ii) All prior known recipients of the records who are known to be retaining the record are notified of the decision and the specific nature of the amendment (see (l) of this Section); and

(iii) The requester is notified which DoD Components and Federal agencies have been told of the amendment.

(4) Process all appeals within 30 days unless the appeal authority determines that a fair review cannot be made within this time limit. If additional time is required for the appeal, notify the requester, in writing, of the delay, the reason for the delay, and when he or she may expect a final decision on the

appeal. Document fully all requirements for additional time in the Privacy Case File. (See paragraph (p) of this section.)

(l)
Denying amendment of OPM records held by the DoD Components.
(1) The records in all systems of records controlled by the OPM Government-wide system notices are technically only temporarily in the custody of the Department of Defense.

(2) All requests for amendment of these records must be processed in accordance with 5 CFR part 297. The Component denial authority may deny a request. However, when an amendment request is denied, the DoD Component shall advise the individual that his or her appeal must be directed to the Assistant Director for Workforce Information, Personnel Systems and Oversight Group, U.S. Office of Personnel Management, 1900 E Street, Washington, DC 20415 in accordance with the procedures of 5 CFR 297.

(m)
Statements of disagreement submitted by individuals.
(1) If the appellate authority refuses to amend the record as requested, the individual may submit a concise statement of disagreement setting forth his or her reasons for disagreeing with the decision not to amend.

(2) If an individual chooses to file a statement of disagreement, annotate the record to indicate that the statement has been filed (see paragraph (n) of this section).

(3) Furnish copies of the statement of disagreement to all DoD Components and Federal agencies that have been provided copies of the disputed information and who may be maintaining the information.

(n)
Maintaining statements of disagreement.
(1) When possible, incorporate the statement of disagreement into the record.

(2) If the statement cannot be made a part of the record, establish procedures to ensure that it is apparent from the records a statement of disagreement has been filed and maintain the statement so that it can be obtained readily when the disputed information is used or disclosed.

(3) Automated record systems that are not programmed to accept statements of disagreement shall be annotated or coded so they clearly indicate that a statement of disagreement is on file, and clearly identify the statement with the disputed information in the system.

(4) Provide a copy of the statement of disagreement whenever the disputed information is disclosed for any purpose.

(o)
The DoD Component statement of reasons for refusing to amend.
(1) A statement of reasons for refusing to amend may be included with any record for which a statement of disagreement is filed.

(2) Include in this statement only the reasons furnished to the individual for not amending the record. Do not comment on or respond to comments contained in the statement of disagreement. Normally, both statements are filed together.

(3) When disclosing information for which a statement of reasons has been filed, a copy of the statement may be released whenever the record and the statement of disagreement are disclosed.

(p)
Privacy case files.
(1) Establish a separate Privacy case file to retain the documentation received and generated during the amendment or access process.

(2) The Privacy case file shall contain as a minimum:

(i) The request for amendment and access.

(ii) Copies of the DoD Component's reply granting or denying the request;

(iii) Any appeals from the individual;

(iv) Copies of the action regarding the appeal with supporting documentation that is not in the basic file; and

(v) Any other correspondence generated in processing the appeal, to include coordination documentation.

(3) Only the items listed in paragraphs (p)(4) and (p)(5) of this section may be included in the system of records challenged for amendment or for which access is sought. Do not retain copies of the original record in the basic record system if the request for amendment is granted and the record has been amended.

(4) The following items relating to an amendment request may be included in the disputed record system:

(i) Copies of the amended record.

(ii) Copies of the individual's statement of disagreement (see paragraph (m) of this section).

(iii) Copies of the Component's statement of reasons for refusing to amend (see paragraph (o) of this section).

(iv) Supporting documentation submitted by the individual.

(5) The following items relating to an access request may be included in the basic records system:

(i) Copies of the request;

(ii) Copies of the Component's action granting total or partial access. (
Note:
A separate Privacy case file need not be created in such cases.)

(iii) Copies of the Component's action denying access.

(iv) Copies of any appeals filed.

(v) Copies of the reply to the appeal.

(6) Privacy case files shall not be furnished or disclosed to anyone for use in making any determination about the individual other than determinations made under this part.

§ 310.20
Reproduction fees.

(a)
Assessing fees.
(1) Charge the individual only the direct cost of reproduction.

(2) Do not charge reproduction fees if copying is:

(i) The only means to make the record available to the individual (for example, a copy of the record must be made to delete classified information); or

(ii) For the convenience of the DoD Component (for example, the Component has no reading room where an individual may review the record, or reproduction is done to keep the original in the Component's file).

(iii) No fees shall be charged when the record may be obtained without charge under any other Regulation, Directive, or statute.

(iv) Do not use fees to discourage requests.

(b)
No minimum fees authorized.
Use fees only to recoup direct reproduction costs associated with granting access. Minimum fees for duplication are not authorized and there is no automatic charge for processing a request.

(c)
Prohibited fees.
Do not charge or collect fees for:

(1) Search and retrieval of records;

(2) Review of records to determine releasability;

(3) Copying records for the DoD Component convenience or when the individual has not specifically requested a copy;

(4) Transportation of records and personnel; or

(5) Normal postage.

(d)
Waiver of fees.
(1) Normally, fees are waived automatically if the direct costs of a given request are less than $30. This fee waiver provision does not apply when a waiver has been granted to the individual before, and later requests appear to be an extension or duplication of that original request. A DoD Component may, however, set aside this automatic fee waiver provision when, on the basis of good evidence, it determines the waiver of fees is not in the public interest.

(2) Decisions to waive or reduce fees that exceed the automatic waiver threshold shall be made on a case-by-case basis.

(e)
Fees for Members of Congress.
Do not charge members of Congress for copying records furnished even when the records are requested under the Privacy Act on behalf of a constituent (See § 310.22(i)). When replying to a constituent inquiry and the fees involved are substantial, consider

suggesting to the Congressman that the constituent can obtain the information directly by writing to the appropriate offices and paying the costs. When practical, suggest to the Congressman that the record can be examined at no cost if the constituent wishes to visit the custodian of the record.

(f)
Reproduction fees computation.
Compute fees using the appropriate portions of the fee schedule in 32 CFR part 286.

Subpart E—Disclosure of Personal Information to Other Agencies and Third Parties

§ 310.21
Conditions of disclosure.

(a)
Disclosures to third parties.
(1) The Privacy Act only compels disclosure of records from a system of records to the individuals to whom they pertain unless the records are contained in a system for which an exemption to the access provisions of this part has been claimed.

(2) Requests by other individuals (third parties) for the records of individuals that are contained in a system of records shall be processed under 32 CFR part 286 except for requests by the parents of a minor or the legal guardian of an individual for access to the records pertaining to the minor or individual.

(b)
Disclosures among the DoD Components.
For the purposes of disclosure and disclosure accounting, the Department of Defense is considered a single agency (see § 310.22(a)).

(c)
Disclosures outside the Department of Defense.
Do not disclose personal information from a system of records outside the Department of Defense unless:

(1) The record has been requested by the individual to whom it pertains.

(2) The written consent of the individual to whom the record pertains has been obtained for release of the record to the requesting Agency, activity, or individual; or

(3) The release is authorized pursuant to one of the specific non-consensual conditions of disclosure as set forth in § 310.22.

(d)
Validation before disclosure.
Except for releases made in accordance with 32 CFR part 286, the following steps shall be taken before disclosing any records to any recipient outside the Department of Defense, other than a Federal agency or the individual to whom it pertains:

(1) Ensure the records are accurate, timely, complete, and relevant for agency purposes;

(2) Contact the individual, if reasonably available, to verify the accuracy, timeliness, completeness, and relevancy of the information, if this cannot be determined from the record; or

(3) If the information is not current and the individual is not reasonably available, advise the recipient that the information is believed accurate as of a specific date and any other known factors bearing on its accuracy and relevancy.

§ 310.22
Non-consensual conditions of disclosure.

(a)
Disclosures within the Department of Defense.
(1) Records pertaining to an individual may be disclosed to a DoD official or employee provided:

(i) The requester has a need for the record in the performance of his or her assigned duties. The requester shall articulate in sufficient detail why the records are required so the custodian of the records may make an informed decision regarding their release;

(ii) The intended use of the record generally relates to the purpose for which the record is maintained; and

(iii) Only those records as are minimally required to accomplish the intended use are disclosed. The entire record is not released if only a part of the record will be responsive to the request.

(2) Rank, position, or title alone does not authorize access to personal information about others.

(b)
Disclosures required by the FOIA.
(1) All records must be disclosed if their release is required by FOIA (5 U.S.C. 552), as implemented by 32 CFR part 286. The FOIA requires records be made available to the public unless withholding is authorized pursuant to one of nine exemptions or one of three law enforcement exclusions under the Act.

(i) The DoD Component must be in receipt of a FOIA request and a determination made that the records are not withholdable pursuant to a FOIA exemption or exclusion before the records may be disclosed.

(ii) Records that have traditionally been released to the public by the Components may be disclosed whether or not a FOIA request has been received.

(2) The standard for exempting most personal records, such as personnel, medical, and similar records, is FOIA Exemption 6 (32 CFR part 286.12(e)). Under that exemption, records can be withheld when disclosure, if other than to the individual about whom the information pertains, would result in a clearly unwarranted invasion of the individual's personal privacy.

(3) The standard for exempting personal records compiled for law enforcement purposes, including personnel security investigation records, is FOIA Exemption 7(C) (32 CFR part 286.12(g)). Under that exemption, records can be withheld when disclosure, if other than to the individual about whom the information pertains, would result in an unwarranted invasion of the individual's personal privacy.

(4) If records or information are exempt from disclosure pursuant to the standards set forth in paragraphs (b)(2) and/or (b)(3) of this section, and the records are contained in a system of records (See § 310.10(a) of subpart B, the Privacy Act (5 U.S.C. 552a) prohibits release.

(5)
Personal information that is normally releasable.
(i)
DoD civilian employees.
(A) Some examples of personal information regarding DoD civilian employees that normally may be released without a clearly unwarranted invasion of personal privacy include:

(1)
Name.

(2)
Present and past position titles.

(3)
Present and past grades.

(4)
Present and past annual salary rates.

(5)
Present and past duty stations.

(6)
Office and duty telephone numbers.

(7)
Position descriptions.

(B) All disclosures of personal information regarding Federal civilian employees shall be made in accordance with OPM release policies (see 5 CFR part 293.311).

(ii)
Military members.
(A) While it is not possible to identify categorically information that must be released or withheld from military personnel records in every instance, the following items of personal information regarding military members normally may be disclosed without a clearly unwarranted invasion of their personal privacy:

(1)
Full name.

(2)
Rank.

(3)
Date of rank.

(4)
Gross salary.

(5)
Past duty assignments.

(6)
Present duty assignment.

(7)
Future assignments that are officially established.

(8)
Office or duty telephone numbers.

(9)
Source of commission.

(10)
Promotion sequence number.

(11)
Awards and decorations.

(12)
Attendance at professional military schools.

(13)
Duty status at any given time.

(14)
Home of record (identification of the state only).

(15)
Length of military service.

(16)
Basic Pay Entry Date.

(17)
Official Photo.

(B) All disclosures of personal information regarding military members

shall be made in accordance with 32 CFR part 286.

(iii)
Civilian employees not under the authority of OPM.
(A) While it is not possible to identify categorically those items of personal information that must be released regarding civilian employees not subject to 5 CFR parts 293, 294, and 297, such as nonappropriated fund employees, normally the following items may be released without a clearly unwarranted invasion of personal privacy:

(1)
Full name.

(2)
Grade or position.

(3)
Date of grade.

(4)
Gross salary.

(5)
Present and past assignments.

(6)
Future assignments, if officially established.

(7)
Office or duty telephone numbers.

(B) All releases of personal information regarding civilian personnel in this category shall be made in accordance with 32 CFR part 286.

(6) When military or civilian personnel are assigned, detailed, or employed by the National Security Agency, the Defense Intelligence Agency, the National Reconnaissance Office, or the National Geospatial-Intelligence agency, information about such personnel may only be disclosed as authorized by Public Law 86-36 (“National Security Agency-Officers and Employees”) and 10 U.S.C 424 (“Disclosure of Organizational and Personnel Information: Exemption for Specified Intelligence Agencies”). When military and civilian personnel are assigned, detailed or employed by an overseas unit, a sensitive unit, or to a routinely deployable unit, information about such personnel may only be disclosed as authorized by 10 U.S.C. 130b (“Personnel in Overseas, Sensitive, or Routinely Deployed Units: Nondisclosure of Personally Identifying Information”).

(7) Information about military or civilian personnel that otherwise may be disclosable consistent with § 310.22(b)(5) may not be releasable if a requester seeks listings of personnel currently or recently assigned/detailed/employed within a particular component, unit, organization or office with the Department of Defense if the disclosure of such a list would pose a privacy or security threat.

(c)
Disclosures for established routine uses.
(1) Records may be disclosed outside the Department of Defense pursuant to a routine use that has been established for the system of records that contains the records.

(2) A routine use shall:

(i) Be compatible with the purpose for which the record was collected;

(ii) Identify the persons or organizations to whom the record may be released;

(iii) Identify specifically the intended uses of the information by the persons or organization; and

(iv) Have been published in the
Federal Register
(see § 310.32(i)).

(3) If a Federal statute or an E.O. of the President directs records contained in a system of records be disclosed outside the Department of Defense, the statute or E.O. serves as authority for the establishment of a routine use.

(4) New or altered routine uses must be published in the
Federal Register
at least 30 days before any records may be disclosed pursuant to the terms of the routine use (see subpart G of this part).

(5) In addition to the specific routine uses established for each of the individual system notices, blanket routine uses have been established (see Appendix 3) that are applicable to all DoD system of records. However, in order for the blanket routine uses to apply to a specific system of records, the system notice shall expressly state that the blanket routine uses apply. These blanket routine uses are published only at the beginning of the listing of system notices for each Component in the
Federal Register
.

(d)
Disclosures to the Bureau of the Census.
Records in DoD systems of records may be disclosed without the consent of the individuals to whom they pertain to the Bureau of the Census for purposes of planning or carrying out a census survey or related activities pursuant to the provisions of 13 U.S.C. 6 (“Information from other Federal Departments and Agencies”).

(e)
Disclosures for statistical research or reporting.
(1) Records may be disclosed for statistical research or reporting but only after the intended recipient provides, in writing, the purpose for which the records are sought and assurances that the records will be used only for statistical research or reporting purposes.

(2) The records shall be transferred to the requester in a form that is not individually identifiable. DoD Components disclosing records under this provision are required to assure information being disclosed cannot reasonably be used in any way to make determinations about individuals.

(3) The records will not be used, in whole or in part, to make any determination about the rights, benefits, or entitlements of specific individuals.

(4) The written statement by the requester shall be made part of the Component's accounting of disclosures (See paragraph (a) of 310.25).

(f)
Disclosures to the National Archives and Record Administration (NARA), General Services Administration (GSA).
(1) Records may be disclosed to the NARA if they:

(i) Have historical or other value to warrant continued preservation; or

(ii) For evaluation by the Archivist of the United States, or his or her designee, to determine if a record has such historical or other value.

(2) Records transferred to a Federal Records Center (FRC) for safekeeping and storage do not fall within this category. These records are owned by the Component and remain under the control of the transferring Component. FRC personnel are considered agents of the Component that retains control over the records. No disclosure accounting is required for the transfer of records to the FRCs.

(g)
Disclosures for law enforcement purposes.
(1) Records may be disclosed to another Agency or an instrumentality of any Governmental jurisdiction within or under the control of the United States for a civil or criminal law enforcement activity, provided:

(i) The civil or criminal law enforcement activity is authorized by law;

(ii) The head of the law enforcement activity or a designee has made a written request specifying the particular records desired and the law enforcement purpose (such as criminal investigations, enforcement of a civil law, or a similar purpose) for which the record is sought; and

(iii) There is no Federal statute that prohibits the disclosure of the records.

(2) Blanket requests for any and all records pertaining to an individual shall not be honored absent justification.

(3) When a record is released to a law enforcement activity under this subparagraph, the disclosure accounting (see § 310.25) for the release shall not be made available to the individual to whom the record pertains if the law enforcement activity requests that the disclosure not be disclosed.

(4) The blanket routine use for law enforcement (Appendix C, Section A) applies to all DoD Component systems notices (see paragraph (b)(6) of this section). This permits Components, on their own initiative, to report indications of violations of law found in a system of records to a law enforcement activity.

(5) Disclosures may be made to Federal, State, or local, but not foreign law enforcement agencies. Disclosures to Foreign law enforcement agencies may be made if a routine use has been established for the system of records

from which the records are to be released.

(h)
Emergency disclosures.
(1) Records may be disclosed if disclosure is made under compelling circumstances affecting the health or safety of any individual. The affected individual need not be the subject of the record disclosed.

(2) When such a disclosure is made, the Component shall notify the individual who is the subject of the record. Notification sent to the last known address of the individual as known to the Component is sufficient.

(3) The specific data to be disclosed is at the discretion of the Component.

(4) Emergency medical information may be released by telephone.

(i)
Disclosures to Congress.
(1) Records may be disclosed to either House of the Congress or to any committee, joint committee or subcommittee of Congress if the release pertains to a matter within the jurisdiction of the committee. Disclosure is only authorized when in response to an official request on behalf of either House, committee, subcommittee, or joint committee.

(2) Requests from members of Congress who are seeking records in their individual capacity or on behalf of a constituent.

(i) Requests made in their individual capacity. Request for records shall be processed under the provisions of DoD 5400.7-R.

(ii) Requests made on behalf of constituents.

(A) The blanket routine use for “Congressional Inquiries” (see Appendix C, section D) applies to all systems. When an individual requests the assistance of the Congressional member, the blanket routine use permits the disclosure of records pertaining to the individual without the express written consent of the individual.

(B) If necessary, accept constituent letters requesting a member of Congress to investigate a matter pertaining to the individual as written authorization to provide access to the records to the congressional member or his or her staff.

(C) When a Congressional inquiry indicates that the request is being made on the basis of a request from the individual to whom the record pertains, consent can be inferred even if the constituent request is not provided the Component. The verbal statement by a Congressional staff member is acceptable to establish that a request has been received by the Member of Congress from the person to whom the records pertain.

(D) If the constituent inquiry is being made on behalf of someone other than the individual to whom the record pertains, the Member of Congress shall be provided only that information releasable under DoD 5400.7-R. Advise the Congressional member that the written consent of the individual to whom the record pertains is required before any additional information may be disclosed. Do not contact individuals to obtain their consents for release to Congressional members unless a Congressional office specifically requests that this be done.

(E) Nothing in paragraph (i)(2)(ii)(A) of this section prohibits a Component, when appropriate, from providing the record directly to the individual and notifying the Congressional office that this has been done without providing the record to the Congressional member.

(3) See paragraph (e) of § 310.20 for the policy on assessing fees for Members of Congress.

(4) Make a disclosure accounting each time a record is disclosed to either House of Congress, to any committee, joint committee, or subcommittee of Congress, or to any congressional member.

(j)
Disclosures to the General Accountability Office.
Records may be disclosed to the Comptroller General, or any of his authorized representatives, in the course of the performance of the duties of the General Accountability Office.

(k)
Disclosures under court orders.
(1) Records may be disclosed without the consent of the person to whom they pertain under a court order signed by a judge of a court of competent jurisdiction.

(2) When a record is disclosed under this provision, make reasonable efforts to notify the individual to whom the record pertains, if the legal process is a matter of public record.

(3) If the process is not a matter of public record at the time it is issued, seek information as to when the process is to be made public and make reasonable efforts to notify the individual at that time.

(4) Notification sent to the last known address of the individual as reflected in the records is considered a reasonable effort to notify.

(5) Make a disclosure accounting each time a record is disclosed under a court order or compulsory legal process.

(l)
Disclosures to Consumer Reporting Agencies.
(1) Certain personal information may be disclosed to consumer reporting agencies as provided in the Federal Claims Collection Act (31 U.S.C. 3711(e)).

(2) Under the provisions of paragraph (l)(1) of this section, the following information may be disclosed to a consumer reporting agency:

(i) Name, address, taxpayer identification number (SSN), and other information necessary to establish the identity of the individual.

(ii) The amount, status, and history of the claim.

(iii) The Agency or program under which the claim arose.

(3) The Federal Claims Collection Act (31 U.S.C. 3711(e)) requires the system notice for the system of records from which the information will be disclosed, indicates that the information may be disclosed to a consumer reporting agency.

§ 310.23
Disclosures to commercial enterprises.

(a)
General policy.
(1) Make releases of personal information to commercial enterprises under the criteria established by 32 CFR part 286.

(2) The relationship of commercial enterprises to their clients or customers and to the Department of Defense is not changed by this part.

(3) The DoD policy on personal indebtedness for military personnel is contained 32 CFR part 112, “Indebtedness of Military Personnel,” and for civilian employees in 5 CFR part 735.

(b)
Release of personal information.
(1) Any information that must be released under 32 CFR part 286, the “DoD Freedom of Information Act Program,” may be released to a commercial enterprise without the individual's consent (see paragraph (b) of § 310.22).

(2) Commercial enterprises may present a signed consent statement setting forth specific conditions for release of personal information. Statements such as the following, if signed by the individual, are considered valid:

I hereby authorize the Department of Defense to verify my Social Security Number or other identifying information and to disclose my home address and telephone number to authorized representatives of (name of commercial enterprise) so that they may use this information in connection with my commercial dealings with that enterprise. All information furnished shall be used in connection with my financial relationship with (name of commercial enterprise).

(3) When a statement of consent as outlined in paragraph (b)(2) of this section is presented, provide the requested information if its release is not prohibited by some other regulation or statute.

(4) Blanket statements of consent that do not identify the Department of Defense or any of its Components, or

that do not specify exactly the type of information to be released, may be honored if it is clear the individual in signing the consent statement intended to obtain a personal benefit (for example, a loan to buy a house) and was aware of the type of information that would be sought. Care should be exercised in these situations to release only the minimum amount of personal information essential to obtain the benefit sought.

(5) Do not honor requests from commercial enterprises for official evaluation of personal characteristics, such as evaluation of personal financial habits.

§ 310.24
Disclosures to the public from medical records.
(a) Disclosures from medical records are not only governed by the requirement of this part but also by the disclosure provisions of DoD 6025.18-R.”

(b) Any medical records that are subject to both this part and DoD 6025.18-R may only be disclosed if disclosure is authorized under both. If disclosure is permitted under this part (e.g., pursuant to a routine use), but the disclosure is not authorized under DoD 6025.18-R, disclosure is not authorized. If a disclosure is authorized under DoD 6025.18-R (e.g., releases outside the Department of Defense), but the disclosure is not authorized under this part, disclosure is not authorized.

§ 310.25
Disclosure accounting.

(a)
Disclosure accountings.
(1)
Keep an accurate record of all disclosures made from any system of records except disclosures:

(i) To DoD personnel for use in the performance of their official duties; or

(ii) Under 5 U.S.C. 552, the FOIA.

(2) In all other cases a disclosure accounting is required even if the individual has consented to the disclosure of the information.

(3) Disclosure accountings:

(i) Permit individuals to determine to whom information has been disclosed;

(ii) Enable the activity to notify past recipients of disputed or corrected information (§ 310.19(i)); and

(iii) Provide a method of determining compliance with paragraph (c) of § 310.21.

(b)
Contents of disclosure accountings.
As a minimum, disclosure accounting shall contain:

(1) The date of the disclosure.

(2) A description of the information released.

(3) The purpose of the disclosure.

(4) The name and address of the person or Agency to whom the disclosure was made.

(c)
Methods of disclosure accounting.
Use any system of disclosure accounting that shall provide readily the necessary disclosure information (see paragraph (a)(3) of this section).

(d)
Accounting for mass disclosures.
When numerous similar records are released, identify the category of records disclosed and include the data required by paragraph (b) of this section in a form that can be used to construct an accounting disclosure record for individual records if required (see paragraph (a)(3) of this section).

(e)
Disposition of disclosure accounting records.
Retain disclosure accounting records for 5 years after the disclosure or the life of the record, whichever is longer.

(f)
Furnishing disclosure accountings to the individual.
(1) Make available to the individual to whom the record pertains all disclosure accountings except when:

(i) The disclosure has been made to a law enforcement activity under paragraph (g) of § 310.22 and the law enforcement activity has requested that disclosure not be made; or

(ii) The system of records has been exempted from the requirement to furnish the disclosure accounting under the provisions of § 310.26(b).

(2) If disclosure accountings are not maintained with the record and the individual requests access to the accounting, prepare a listing of all disclosures (see paragraph (b) of this section) and provide this to the individual upon request.

Subpart F—Exemptions

§ 310.26
Use and establishment of exemptions.

(a)
Types of exemptions.
(1) There are three types of exemptions permitted by the Privacy Act (5 U.S.C. 552a).

(i) An access exemption that exempts records compiled in reasonable anticipation of a civil action or proceeding from the access provisions of the Act.

(ii) General exemptions that authorize the exemption of a system of records from all but certain specifically identified provisions of the Act (see Appendix D).

(iii) Specific exemptions that allow a system of records to be exempted only from certain designated provisions of the Act (see Appendix D).

(2) Nothing in the Act permits exemption of any system of records from all provisions of the Act.

(b)
Establishing exemptions.
(1) The access exemption is self-executing. It does not require an implementing rule to be effective.

(2) Neither a general nor a specific exemption is established automatically for any system of records. The Heads of the DoD Components maintaining the system of records must make a determination whether the system is one for which an exemption properly may be claimed and then propose and establish an exemption rule for the system. No system of records within the Department of Defense shall be considered exempted until the Head of the Component has approved the exemption and an exemption rule has been published as a final rule in the
Federal Register
(See § 310.30(e).)

(3) Only the Head of the DoD Component or an authorized designee may claim an exemption for a system of records.

(4) A system of records is considered exempt only from those provision of the Privacy Act (5 U.S.C. 552a) that are identified specifically in the Component exemption rule for the system and that are authorized by the Privacy Act.

(5) To establish an exemption rule, see § 310.31.

(c)
Blanket exemption for classified material.
(1) Component rules shall include a blanket exemption under 5 U.S.C. 552a(k)(1) of the Privacy Act from the access provisions (5 U.S.C. 552a(d)) and the notification of access procedures (5 U.S.C. 522a(e)(4)(H)) of the Act for all classified material in any systems of records maintained.

(2) Do not claim specifically an exemption under section 552a(k)(1) of the Privacy Act for any system of records. The blanket exemption affords protection to all classified material in all system of records maintained.

(d)
Provisions from which exemptions may be claimed.
The Head of a DoD Component may claim an exemption from any provision of the Act from which an exemption is allowed (see Appendix D).

(e)
Use of exemptions.
(1) Use exemptions only for the specific purposes set forth in the exemption rules (see paragraph (b) of § 310.31).

(2) Use exemptions only when they are in the best interest of the Government and limit them to the specific portions of the records requiring protection.

(3) Do not use an exemption to deny an individual access to any record to which he or she would have access under 32 CFR part 286.

(f)
Exempt records in non-exempt systems.
(1) Exempt records temporarily in the custody of another Component are considered the property of the originating Component. Access to these records is controlled by the system

notices and rules of the originating Component.

(2) Exempt records that have been incorporated into a nonexempt system of records are still exempt but only to the extent to which the provisions of the Act for which an exemption has been claimed are identified and an exemption claimed for the system of records from which the record is obtained and only when the purposes underlying the exemption for the record are still valid and necessary to protect the contents of the record.

(3) If a record is accidentally misfiled into a system of records, the system notice and rules for the system in which it should actually be filed shall govern.

§ 310.27
Access exemption.
(a) An individual is not entitled to access information that is compiled in reasonable anticipation of a civil action or proceeding.

(b) The term “civil action or proceeding” is intended to include court proceedings, preliminary judicial steps, and quasi-judicial administrative hearings or proceedings (i.e., adversarial proceedings that are subject to rules of evidence).

(c) Any information prepared in anticipation of such actions or proceedings, to include information prepared to advise the DoD Component officials of the possible legal or other consequences of a given course of action, is protected.

(d) The exemption is similar to the attorney work-product privilege except that it applies even when the information is prepared by nonattorneys.

(e) The exemption does not apply to information co

[Text truncated at 120,000 characters. The full text is on the page linked above.]

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/documents/fr%3AE7-6118. Public record. Not legal advice.
