82_FR_35843 82 FR 35697 - Privacy Act Regulations

82 FR 35697 - Privacy Act Regulations

NATIONAL CAPITAL PLANNING COMMISSION

Federal Register Volume 82, Issue 146 (August 1, 2017)

Page Range35697-35705
FR Document2017-15882

The National Capital Planning Commission (NCPC or Commission) proposes to adopt new regulations governing NCPC's implementation of the Privacy Act, as amended and the privacy provisions of the E- Government Act of 2002. NCPC must comply with the requirements of the Privacy Act and the privacy provisions of the E-Government Act of 2002 for records maintained on individuals and personal information stored as a hard copy or electronically.

Federal Register, Volume 82 Issue 146 (Tuesday, August 1, 2017)
[Federal Register Volume 82, Number 146 (Tuesday, August 1, 2017)]
[Proposed Rules]
[Pages 35697-35705]
From the Federal Register Online  [www.thefederalregister.org]
[FR Doc No: 2017-15882]


-----------------------------------------------------------------------

NATIONAL CAPITAL PLANNING COMMISSION

1 CFR Chapters IV and VI


Privacy Act Regulations

AGENCY: National Capital Planning Commission.

ACTION: Proposed rule.

-----------------------------------------------------------------------

SUMMARY: The National Capital Planning Commission (NCPC or Commission) 
proposes to adopt new regulations governing NCPC's implementation of 
the Privacy Act, as amended and the privacy provisions of the E-
Government Act of 2002. NCPC must comply with the requirements of the 
Privacy Act and the privacy provisions of the E-Government Act of 2002 
for records maintained on individuals and personal information stored 
as a hard copy or electronically.

DATES: Submit comments on or before August 31, 2017.

ADDRESSES: You may submit written comments on the proposed Privacy Act 
regulations by either of the methods listed below.
    1. U.S. mail, courier, or hand delivery: Anne R. Schuyler, General 
Counsel/National Capital Planning Commission, 401 9th Street NW., Suite 
500, Washington, DC 20004.
    2. Electronically: [email protected].

FOR FURTHER INFORMATION CONTACT: Anne R. Schuyler, General Counsel at 
202-482-7223, [email protected].

SUPPLEMENTARY INFORMATION: NCPC's adopted its current Privacy 
Regulations (1 CFR 455) in 1977. Since that time, Congress amended the 
Privacy Act multiple times including the E-Government Act of 2002 which 
addressed requirements for maintaining electronic privacy records. The 
proposed regulations update NCPC's existing Privacy Regulations to 
reflect amendments over time. The Office of the Federal Register 
recently assigned NCPC a new chapter of 1 CFR--Chapter VI--to allow 
NCPC to group all its regulations together in one chapter. NCPC 
proposes to codify the new Privacy Regulations at 1 CFR 603.

Section by Section Analysis of NCPC's Privacy Act Regulations

    Sec.  603.1 Purpose and scope. This section advises the purpose of 
the regulations is to implement a privacy program consistent with the 
requirements of the Privacy Act and the privacy related provision of 
the E-Government Act of 2002. As stated in the section, NCPC's privacy 
program extends to all Records maintained by NCPC in a System of 
Records; the responsibilities of NCPC to safeguard this information; 
the procedures by which Individuals may request notification of the 
existence of a Record about them, access to Records about them, an 
amendment to or correction of the Records about them, and an accounting 
of disclosures of those Records by the NCPC; the procedures by which an 
Individual may appeal an Adverse Determination, and the conduct of a 
Privacy Impact Assessment.
    Sec.  603.2 Definitions. This section defines terms frequently used 
in the regulations. The section includes the five terms defined in the 
existing regulations--Individual, Maintain, Record, Routine Use and 
System of Records. It adds the definitions for the following terms: 
Adverse Determination, E-Government Act of 2002, Information in 
Identifiable Form (IIF), Information Technology, Privacy Act Officer 
(PAO), Privacy Act, Privacy Impact Assessment (PIA), Record, Requester, 
Request for Access to a Record, Request for Amendment or Correction of 
a Record, Senor Agency Official for Privacy (SAOP), System of Records 
Notice (SORN), and Workday.
    Sec.  603.3 Privacy Act program responsibilities. This section 
requires NCPC to designate a SAOP and a PAO and outlines the 
responsibilities associated with both positions. It also enumerates the 
Privacy Act responsibilities of other NCPC personnel.
    Sec.  603.4 Standards used to Maintain Records. This section 
establishes the standards NCPC must follow regarding privacy 
information. The section

[[Page 35698]]

requires NCPC to limit private information to only that necessary to 
achieve the purposes for which it is collected and stored; to ensure 
all information collected is accurate, relevant, timely, and complete; 
and to collect privacy information regarding an Individual's rights, 
benefits and privileges under federal programs from the Individual to 
the maximum extent possible subject to collection from third parties in 
certain circumstances.
    Sec.  603.5 Notice to Individuals supplying information. This 
section enumerates the information NCPC must provide Individuals who 
are asked to supply information about themselves. The required 
information enumerated includes the purpose for which NCPC intends to 
use the information; the effects upon an Individual for not providing 
the information; and the form of notice NCPC must supply in response to 
an Individual's provision of information.
    Sec.  603.6 System of Records (SOR) Notice (SORN). This section 
requires NCPC to publish a notice in the Federal Register describing 
each SOR 40-days before establishing a new or revising an existing SOR. 
The section requires the SORN to include the purpose of the Records and 
their location; the types of Individuals contained in the SOR; the 
authority for maintaining the SOR; the purpose or reason why NCPC 
collects the Records and their intended routine uses; the sources of 
the Records in the SOR; the policies and practices regarding storage, 
retrieval, access controls, retention, and disposal of the Records; the 
identification of the agency official responsible for the SOR; and the 
procedures for notifying an Individual who requests whether the SOR 
contains information about him/her.
    Sec.  603.7 Procedures to safeguard Records. This section describes 
the procedures utilized by NCPC to safeguard hard copy and computerized 
records subject to the Privacy Act. The section requires hard copy 
Records to be stored in a locked room subject to restricted access with 
external posted warning signs limiting access to authorized personnel 
and/or stored in a locked container with identical precautions to those 
used for a locked room. The section requires computerized Records to be 
maintained subject to the Safeguards recommended by the National 
Institute of Standards and Technology (NIST).
    Sec.  603.8 Employee conduct. This section requires employees with 
duties requiring access to and handling of Records to do so in a manner 
that protects the integrity, security and confidentiality of the 
Records. It prohibits employee disclosure of records unless authorized 
by the rules in this part, permitted by NCPC's FOIA regulations, or 
disclosed to the Individual to whom the Record pertains. The section 
also prohibits destruction or alteration of Records unless required as 
part of an employee's regular duties, required by regulations published 
by the National Archives Record Administration (NARA), or required by a 
court of law.
    Sec.  603.9 Government contracts. This section requires contractors 
operating a System of Records on behalf of NCPC to abide by the 
requirements of the Privacy Act. It also requires a NCPC employee to 
oversee and manage the SOR operated by a contractor.
    Sec.  603.10 Conditions for disclosure. Subject to a list of 
enumerated exceptions, this section precludes disclosure of a Record 
contained in a SOR unless prior written consent is obtained from the 
Individual to whom the record pertains.
    Sec.  603.11 Accounting of disclosures. This section requires NCPC 
to prepare an accounting of disclosure when a Record is disclosed to 
any person or to another agency. The section requires the contents of 
an accounting to include the date, nature, and purpose of the 
disclosure and the name and address of the person or agency to whom the 
disclosure was made. The section also requires Accountings of 
disclosures to be made available to the Individual about whom the 
disclosed Record pertains except under limited circumstances. It 
further requires changes to disclosed Records to be shared with the 
person or agency to whom the Record was originally disclosed.
    Sec.  603.12 Requests for notification of the existence of Records. 
This section advises Individuals how to determine whether a System of 
Records maintained by NCPC contains Records pertaining to them. It 
requires Individuals either to contact NCPC in writing or appear at 
NCPC's offices by appointment to make the subject request. The section 
requires the NCPC PAO to respond to a request in writing within 20-
Workdays, to include in the response the Reason(s) for the PAO's 
determination, and to advise the requester of the right to appeal the 
decision.
    Sec.  603.13 Request for access to Records. This section advises 
Individuals how to access NCPC records about themselves. It requires 
Individuals to request the right to access Records either in writing or 
to appear at NCPC's offices by appointment. The section enumerates the 
information required to be included in a request, and obligates 
Individuals to present certain specified identification to access the 
requested Records. The section also requires the NCPC PAO to respond to 
a request for access in writing within 20-Workdays, to state in the 
response the reason for the PAO's determination, and to advise the 
Requester of the right to appeal an Adverse Determination.
    Sec.  603.14 Requests for amendment or correction of Records. This 
section outlines the process Individuals must follow to amend or 
correct Records about them that they believe are inaccurate, 
irrelevant, untimely or incomplete. The section requires a request for 
amendment or correction to be in writing, include certain specified 
information, and to be made only if the Individual has previously 
requested and been granted access to the Record. The section also 
requires the NCPC PAO to respond to a request for amendment or 
correction in writing within 20-Workdays, to state the reason for the 
PAO's determination in the response, to advise the requester of the 
right to appeal an Adverse Determination, to ensure the Record is 
amended or corrected in whole or in part if the PAO approves the 
request, and to place a notation of a dispute on the Record if the 
request is denied.
    Sec.  603.15. Requests for an accounting of Records disclosures. 
This section outlines the process Individuals must follow to obtain 
information about disclosures of Records pertaining to them. It 
requires a request for information about Records disclosed to include 
certain specified information. The section also requires the NCPC PAO 
to respond to a request for information about disclosures in writing 
within 20-Workdays, to include, in the event of a disclosure, the date, 
nature and purpose of the disclosure, the name and address of the 
person or agency to whom the disclosure was made. The section further 
requires the PAO to state the reason for his/her determination and to 
advise the requester of the right to appeal an Adverse Determination.
    Sec.  602.16 Appeals of Adverse Determinations. This section 
describes the process Individuals must follow to appeal an Adverse 
Determination. As defined in the definition section of the regulations 
Adverse Determination means a decision to withhold any requested Record 
in whole or in part; a decision that the requested Record does not 
exist or cannot be located; a decision that the requested information 
is not a Record subject to the Privacy Act; a decision that a Record, 
or part thereof, does not require amendment or correction; a decision 
to refuse to

[[Page 35699]]

disclose an accounting of disclosure; and a decision to deny a fee 
waiver. The term also encompasses a challenge to NCPC's determination 
that Records have not been described adequately, that there are no 
responsive Records, or that an adequate search has been conducted. The 
section requires an Individual to submit a written appeal to the 
Chairman of the Commission stating the legal, factual or other basis 
for the Appeal, and it requires the Chairman to provide a written 
response within 30-Workdays. The section also requires NCPC to take 
prompt action to respond affirmatively to the Individual's original 
request if the Chairman grants the request and to state the reasons for 
a denial and the right to appeal the denial to a court of competent 
jurisdiction.
    Sec.  603.17 Fees. This section states the fees to be charged for 
the search for and duplication of Records. It advises fees for 
duplication shall be those established by NCPC's FOIA Regulations, and 
it states there are no fees for the search or review of Records 
requested by an Individual.
    Sec.  603.18 Privacy Impact Assessments. This section states when 
NCPC must conduct a Privacy Impact Assessment (PIA), the contents of a 
PIA, and the process for approving the PIA. The section requires a PIA 
to be conducted before developing or procuring an IT system that 
collects, maintains or disseminates Information that identifies an 
Individual (IFF or Information in Identifiable Form) or when NCPC 
installs a new collection of IFF for 10 or more persons other than 
employees, or agencies of the federal government. The section also 
requires a PIA to analyze a number of factors related to the 
collection, use, owner, storage and manner of securing the IFF, and it 
requires the PIA to be approved and posted on NCPC's Web site prior to 
undertaking the action that required the PIA.

Compliance With Laws and Executive Orders

Executive Orders 12866 and 13563

    By Memorandum dated October 12, 1993 from Sally Katzen, 
Administrator, Office of Information and Regulatory Affairs (OIRA) to 
Heads of Executive Departments and Agencies, and Independent Agencies, 
OMB rendered the NCPC exempt from the requirements of Executive Order 
12866 (See, Appendix A of cited Memorandum). Nonetheless, NCPC 
endeavors to adhere to the provisions of Executive Orders and developed 
this proposed rule in a manner consistent with the requirements of 
Executive Order 13563.

Executive Order 13771

    By virtue of its exemption from the requirements of EO 12866, NCPC 
is exempted from this Executive Order. NCPC confirmed this fact with 
OIRA.

Regulatory Flexibility Act

    As required by the Regulatory Flexibility Act (5 U.S.C. 601 et 
seq.), the NCPC certifies that the proposed rule will not have a 
significant economic effect on a substantial number of small entities.

Small Business Regulatory Enforcement Fairness Act

    This is not a major rule under 5 U.S.C. 804(2), the Small Business 
Regulatory Enforcement Fairness Act. It does not have an annual effect 
on the economy of $100 million or more; will not cause a major increase 
in costs for individuals, various levels of governments or various 
regions; and does not have a significant adverse effect on completion, 
employment, investment, productivity, innovation or the competitiveness 
of US enterprises with foreign enterprises.

Unfunded Mandates Reform Act (2 U.S.C. 1531 et seq.)

    A statement regarding the Unfunded Mandates Reform Act is not 
required. The proposed rule neither imposes an unfunded mandate of more 
than $100 million per year nor imposes a significant or unique effect 
on State, local or tribal governments or the private sector.

Federalism (Executive Order 13132)

    In accordance with Executive Order 13132, the proposed rule does 
not have sufficient federalism implications to warrant the preparation 
of a Federalism Assessment. The proposed rule does not substantially 
and directly affect the relationship between the Federal and state 
governments.

Civil Justice Reform (Executive Order 12988)

    The General Counsel of NCPC has determined that the proposed rule 
does not unduly burden the judicial system and meets the requirements 
of Executive Order 12988 3(a) and 3(b)(2).

Paperwork Reduction Act

    The proposed rule does not contain information collection 
requirements, and it does not require a submission to the Office of 
Management and Budget under the Paperwork Reduction Act.

National Environmental Policy Act

    The proposed rule is of an administrative nature, and its adoption 
does not constitute a major federal action significantly affecting the 
quality of the human environment. NCPC's adoption of the proposed rule 
will have minimal or no effect on the environment; impose no 
significant change to existing environmental conditions; and will have 
no cumulative environmental impacts.

Clarity of the Regulation

    Executive Order 12866, Executive Order 12988, and the Presidential 
Memorandum of June 1, 1998 requires the NCPC to write all rules in 
plain language. NCPC maintains the proposed rule meets this 
requirement. Those individuals reviewing the proposed rule who believe 
otherwise should submit specific comments to the addresses noted above 
recommending revised language for those provision or portions thereof 
where they believe compliance is lacking.

Public Availability of Comments

    Be advised that personal information such as name, address, phone 
number, electronic address, or other identifying personal information 
contained in a comment may be made publically available. Individuals 
may ask NCPC to withhold the personal information in their comment, but 
there is no guarantee the agency can do so.

List of Subjects in 1 CFR Part 603

    Privacy Act Regulations.

    For the reasons stated in the preamble, the National Capital 
Planning Commission proposes amend 1 CFR Chapters IV and VI as proposed 
to be established at 82 FR 24570 to read as follows:

CHAPTER IV--MISCELLANEOUS AGENCIES

PART 455 [Removed].

0
1. Under the authority of 40 U.S.C. 8711(a) remove part 455.
0
2. Add part 603 to read as follows:

CHAPTER VI--NATIONAL CAPITAL PLANNING COMMISSION [Proposed]

PART 603--NATIONAL CAPITAL PLANNING COMMISSION PRIVACY ACT 
REGULATIONS

Sec.
603.1 Purpose and scope.
603.2 Definitions.
603.3 Privacy Act program responsibilities.
603.4 Standard used to Maintain Records.
603.5 Notice to Individuals supplying information.
603.6 System of Records Notice or SORN.
603.7 Procedures to safeguard Records.
603.8 Employee conduct.
603.9 Government contracts.
603.10 Conditions for disclosure.

[[Page 35700]]

603.11 Accounting for disclosures.
603.12 Request for notification of the existence of Records.
603.13 Requests for access to Records.
603.14 Request for Amendment or Correction of Records.
603.15 Request for Accounting of Record disclosures.
603.16 Appeal of Adverse Determinations.
603.17 Fees.
603.18 Privacy Impact Assessments.

    Authority: 5 U.S.C. 552a as amended and 44 U.S.C. ch. 36.


Sec.  603.1  Purpose and scope.

    (a) This part contain the rules the National Capital Planning 
Commission (NCPC) shall follow to implement a privacy program as 
required by the Privacy Act of 1974, 5 U.S.C. 552a (Privacy Act or Act) 
and the privacy provisions of the E-Government Act of 2002 (44 U.S.C. 
ch. 36) (E-Government Act). These rules should be read together with 
the Privacy Act and the privacy related provisions of the E-Government 
Act, which provide additional information respectively about Records 
maintained on individuals and protections for the privacy of personal 
information as agencies implement citizen-centered electronic 
Government.
    (b) Consistent with the requirements of the Privacy Act, the rules 
in this part apply to all Records maintained by NCPC in a System of 
Records; the responsibilities of the NCPC to safeguard this 
information; the procedures by which Individuals may request 
notification of the existence of a record, request access to Records 
about themselves, request an amendment to or correction of those 
Records, and request an accounting of disclosures of those Records by 
the NCPC; and the procedures by which an Individual may appeal an 
Adverse Determination.
    (c) Consistent with the privacy related requirements of the E-
Government Act, the rules in this part also address the conduct of a 
privacy impact assessment prior to developing or procuring information 
technology that collects, maintains, or disseminates information in an 
identifiable form, initiating a new electronic collection of 
information in identifiable form for 10 or more persons excluding 
agencies, instrumentalities or employees of the federal government, or 
changing an existing System that creates new privacy risks.
    (d) In addition to the rules in this part, the NCPC shall process 
all Privacy Act Requests for Access to Records in accordance with the 
Freedom of Information Act (FOIA), 5 U.S.C. 552, and NCPC's FOIA rules.


Sec.  603.2  Definitions.

    For purposes of this part, the following definitions shall apply:
    Adverse Determination shall mean a decision to withhold any 
requested Record in whole or in part; a decision that the requested 
Record does not exist or cannot be located; a decision that the 
requested information is not a Record subject to the Privacy Act; a 
decision that a Record, or part thereof, does not require amendment or 
correction; a decision to refuse to disclose an accounting of 
disclosure; and a decision to deny a fee waiver. The term shall also 
encompass a challenge to NCPC's determination that Records have not 
been described adequately, that there are no responsive Records or that 
an adequate search has been conducted.
    E-Government Act of 2002 shall mean Public Law 107-347, Dec. 17, 
2002, 116 Stat. 2899, the privacy portions of which are set out as a 
note under section 3501 of title 44.
    Individual shall mean a citizen of the United States or an alien 
lawfully admitted for permanent residence.
    Information in Identifiable Form (IFF) shall mean information in an 
Information Technology system or an online collection that directly 
identifies an individual, e.g., name, address, social security number 
or other identifying number or code, telephone number, email address 
and the like; or information by which the NCPC intends to identify 
specific individuals in conjunction with other data elements, e.g., 
indirect identification that may include a combination of gender, race, 
birth date, geographic identifiers, and other descriptions.
    Information Technology (IT) shall mean, as defined in the Clinger 
Cohen Act (40 U.S.C. 11101(6)), any equipment, software or 
interconnected system or subsystem that is used in the automatic 
acquisition, storage, manipulation, management, movement, control, 
display, switching, interchange, transmission or reception of data.
    Maintain shall include maintain, collect, use or disseminate a 
Record.
    Privacy Act Officer shall mean the individual within the NCPC 
charged with responsibility for coordinating and implementing NCPC's 
Privacy Act program.
    Privacy Act or Act shall mean the Privacy Act of 1974, as amended 
and codified at 5 U.S.C. 552a.
    Privacy Impact Assessment (PIA) shall mean an analysis of how 
information is handled to ensure handling conforms to applicable legal, 
regulatory, and policy requirements regarding privacy; to determine the 
risks and effects of collecting, maintaining and disseminating 
information in identifiable form in an electronic system; and to 
examine and evaluate protections and alternative processes for handling 
information to mitigate potential privacy risks.
    Record shall mean any item, collection, or grouping of information 
about an Individual that is Maintained by the NCPC, including, but not 
limited to, an Individual's education, financial transactions, medical 
history, and criminal or employment history and that contains a name, 
or identifying number, symbol, or other identifying particular assigned 
to the Individual, such as a finger or voice print or photograph.
    Requester shall mean an Individual who makes a Request for Access 
to a Record, a Request for Amendment or Correction of a Record, or a 
Request for Accounting of a Record under the Privacy Act.
    Request for Access to a Record shall mean a request by an 
Individual made to the NCPC pursuant to subsection (d)(1) of the 
Privacy Act to gain access to his/her Records or to any information 
pertaining to him/her in the system and to permit him/her, or a person 
of his/her choosing, to review and copy all or any portion thereof.
    Request for Amendment or Correction of a Record shall mean a 
request made by an Individual to the NCPC pursuant to subsection (d)(2) 
of the Privacy Act to amend or correct a Record pertaining to him/her.
    Routine Use shall mean with respect to disclosure of a Record, the 
use of such Record for a purpose which is compatible with the purpose 
for which the Record is collected.
    Senior Agency Official for Privacy (SAOP) shall mean the individual 
within NCPC responsible for establishing and overseeing the NCPC's 
Privacy Act program.
    System of Records or System (SOR or Systems) shall mean a group of 
any Records under the control of the NCPC from which information is 
retrieved by the name of the individual or by some identifying number, 
symbol, or other identifying particular assigned to the individual.
    System of Record Notice (SORN) shall mean a notice published in the 
Federal Register by the NCPC for each new or revised System of Records 
intended to solicit public comment on the System prior to 
implementation.
    Workday shall mean a regular Federal workday excluding Saturday, 
Sunday and legal Federal holidays when the federal government is 
closed.

[[Page 35701]]

Sec.  603.3  Privacy Act program responsibilities.

    (a) The NCPC shall designate a Senior Agency Official for Privacy 
(SAOP) to establish and oversee the NCPC's Privacy Act Program and 
ensure compliance with privacy laws, regulations and the NCPC's privacy 
policies. Specific responsibilities of the SAOP shall include:
    (1) Reporting to the Office of Management and Budget (OMB) and 
Congress on the establishment of or revision to Privacy Act Systems;
    (2) Reporting periodically to OMB on Privacy Act activities as 
required by law and OMB;
    (3) Signing Privacy Act SORNS for publication in the Federal 
Register;
    (4) Approving and signing PIAs; and
    (5) Serving as head of the agency response team when responding to 
a large-scale information breach.
    (b) The NCPC shall designate a Privacy Act Officer (PAO) to 
coordinate and implement the NCPC's Privacy Act program. Specific 
responsibilities of the PAO shall include:
    (1) Developing, issuing and updating, as necessary, the NCPC's 
Privacy Act policies, standards, and procedures;
    (2) Maintaining Privacy Act program Records and documentation;
    (3) Responding to Privacy Act Requests for Records and coordinating 
appeals of Adverse Determinations for Requests for access to Records, 
Requests for Amendment or Correction of Records, and Requests for 
accounting for disclosures;
    (4) Informing Individuals of information disclosures;
    (5) Working with the NCPC's Division Directors or designated staff 
to develop an appropriate form for collection of Privacy Act 
information and including in the form a Privacy Act statement 
explaining the purpose for collecting the information, how it will be 
used, the authority for such collection, its routine uses, and the 
effect upon the Individual of not providing the requested information;
    (6) Assisting in the development of new or revised SORNs;
    (7) Developing SORN reports for OMB and Congress;
    (8) Submitting new or revised SORNS to the Federal Register for 
publication;
    (9) Assisting in the development of computer matching systems;
    (10) Preparing Privacy Act, Computer Matching, and other reports to 
OMB as required; and
    (11) Evaluating PIA to ensure compliance with E-Government Act 
requirements.
    (c) Other Privacy related responsibilities shall be shared by the 
NCPC Division Directors, the NCPC Chief Information Officer (CIO), the 
NCPC System Developers and Designers, the NCPC Configuration Control 
Board, the NCPC employees, and the Chairman of the Commission.
    (1) The NCPC Division Directors shall be responsible for 
coordinating with the PAO the implementation of the requirements set 
forth in this part for Systems of Records applicable to their area of 
management and the preparation of PIA prior to development or 
procurement of new systems that collect, maintain or disseminate IFF. 
Specific responsibilities include:
    (i) Reviewing existing SOR for need, relevance, and purpose for 
existence, and proposing SOR changes to the PAO as necessary in 
response to altered circumstances;
    (ii) Reviewing existing SOR to ensure information is accurate, 
complete and up to date;
    (iii) Coordinating with the PAO the preparation of new or revised 
SORN;
    (iv) Coordinating with the PAO the development of an appropriate 
form for collection of Privacy Act information and including in the 
form a Privacy Act statement explaining the purpose for collecting the 
information, how it will be used, the authority for such collection, 
its routine uses, and the effect upon the Individual of not providing 
the requested information;
    (v) Collecting information directly from individuals whenever 
possible;
    (vi) Assisting the PAO with providing access to Individuals who 
request information in accordance with the procedures established in 
Sec. Sec.  603.12, 603.13, 603.14 and 603.15;
    (vii) Amending Records if and when appropriate, and working with 
the PAO to inform recipients of former Records of such amendments;
    (viii) Ensuring that System information is used only for its stated 
purpose;
    (ix) Establishing and overseeing appropriate administrative, 
technical, and physical safeguards to ensure security and 
confidentiality of Records; and
    (x) Working with the SAOP, the PAO and Configuration Control 
Board(CCB) on SORs, preparing a PIA, if needed, and obtaining SAOP 
approval for a PIA prior to its publication on the NCPC Web site.
    (2) The CIO shall be responsible for implementing IT security 
management to include security for information protected by the Privacy 
Act and the E-Government Act of 2002. Specific responsibilities 
include:
    (i) Overseeing security policy for privacy data; and
    (ii) Reviewing PIAs prepared for information security 
considerations.
    (3) The NCPC System Developers and Designers shall be responsible 
for ensuring that the IT system design and specifications conform to 
privacy standards and requirements and that technical controls are in 
place for safeguarding personal information from unauthorized access.
    (4) The NCPC CCB shall, among other responsibilities, verify that a 
PIA has been prepared prior to approving a request to develop or 
procure information technology that collects, maintains, or 
disseminates Information in Identifiable Form.
    (5) The NCPC employees shall ensure that any personal information 
they use in the conduct of their official responsibilities is protected 
in accordance with the rules set forth in this part.
    (6) The Chairman of the Commission shall be responsible for acting 
on all appeals of Adverse Determinations.


Sec.  603.4  Standards used to Maintain Records.

    (a) Records Maintained by the NCPC shall contain only such 
information about an Individual as is relevant and necessary to 
accomplish a purpose NCPC must accomplish to comply with relevant 
statutes or Executive Orders of the President.
    (b) Records Maintained by the NCPC and used to make a determination 
about an Individual shall be accurate, relevant, timely, and complete 
to assure a fair determination.
    (c) Information used by the NCPC in making a determination about an 
Individual's rights, benefits, and privileges under federal programs 
shall be collected, to the greatest extent practicable, directly from 
the Individual. In deciding whether collection of information about an 
Individual, as opposed to a third party is practicable, the NCPC shall 
consider the following:
    (1) Whether the information sought can only be obtained from a 
third party;
    (2) Whether the cost to collect the information from an Individual 
is unreasonable compared to the cost of collecting the information from 
a third party;
    (3) Whether there is a risk of collecting inaccurate information 
from a third party that could result in a determination adverse to the 
Individual concerned;
    (4) Whether the information collected from an Individual requires 
verification by a third party; and
    (5) Whether the Individual can verify information collected from 
third parties.

[[Page 35702]]

    (d) The NCPC shall not Maintain Records describing how an 
Individual exercises rights guaranteed by the First Amendment to the 
Constitution unless the maintenance of the Record is expressly 
authorized by statute or by the Individual about whom the Record is 
Maintained or pertinent to and within the scope of an authorized law 
enforcement activity.


Sec.  603.5  Notice to Individuals supplying information.

    (a) Each Individual asked to supply information about himself/
herself to be added to a System of Records shall be informed by the 
NCPC of the basis for requesting the information, its potential use, 
and the consequences, if any, of not supplying the information. Notice 
to the Individual shall state at a minimum:
    (1) The legal authority for NCPC's solicitation of the information 
and whether disclosure is mandatory or voluntary;
    (2) The principal purpose(s) for which the NCPC intends to use the 
information;
    (3) The potential routine uses of the information by the NCPC as 
published in a Systems of Records Notice; and
    (4) The effects upon the individual, if any, of not providing all 
or any part of the requested Information to the NCPC.
    (b) When NCPC collects information on a standard form, the notice 
to the Individual shall either be provided on the form, on a tear off 
sheet attached to the form, or on a separate form, whichever is deemed 
the most practical by the NCPC.
    (c) NCPC may ask an Individual to acknowledge, in writing, receipt 
of the notice required by this section.


Sec.  603.6   System of Records Notice or SORN.

    (a) The NCPC shall publish a notice in the Federal Register 
describing each System of Records 40-days prior to the establishment of 
a new or revision to an existing System of Records.
    (b) The SORN shall include:
    (1) The name and location of the System of Records. The name shall 
identify the general purpose, and the location shall include whether 
the system is located on the NCPC's main server or central files. The 
physical address of either shall also be included.
    (2) The categories or types of Individuals on whom NCPC Maintains 
Records in the System of Records;
    (3) The categories or types of Records in the System;
    (4) The statutory or Executive Order authority for Maintenance of 
the System;
    (5) The purpose(s) or explanation of why the NCPC collects the 
particular Records including identification of all internal and routine 
uses;
    (6) The policies and practices of the NCPC regarding storage, 
retrieval, access controls, retention and disposal of Records;
    (7) The title and business address of the agency official 
responsible for the identified System of Records;
    (8) The NCPC procedures for notification to an Individual who 
requests if a System of Records contains a Record about the Individual; 
and
    (9) The NCPC sources of Records in the System.


Sec.  603.7  Procedures to safeguard Records.

    (a) The NCPC shall implement the procedures set forth in this 
section to insure sufficient administrative, technical and physical 
safeguards exist to protect the security and confidentiality of 
Records. The enumerated procedures shall also protect against any 
anticipated threats or hazards to the security of Records with the 
potential to cause substantial harm, embarrassment, inconvenience, or 
unfairness to any Individual on whom information is Maintained.
    (b) Manual Records subject to the Privacy Act shall be maintained 
by the NCPC in a manner commensurate with the sensitivity of the 
information contained in the Records. The following minimum safeguards 
or safeguards affording comparable protection shall apply to manual 
Systems of Records:
    (1) The NCPC shall post areas where Records are maintained or 
regularly used with an appropriate warning sign stating access to the 
Records shall be limited to authorized persons. The warning shall also 
advise that the Privacy Act prescribes criminal penalties for 
unauthorized disclosure of Records subject to the Act.
    (2) During work hours, the NCPC shall protect areas in which 
Records are Maintained or regularly used by restricting occupancy of 
the area to authorized persons or storing the Records in a locked 
container and room.
    (3) During non-working hours, access to Records shall be restricted 
by their storage in a locked storage container and room.
    (4) Any lock used to secure a room where Records are stored shall 
not be capable of being disengaged with a master key that opens rooms 
other than those in which Records are stored.
    (c) Computerized Records subject to the Privacy Act shall be 
maintained, at a minimum, subject to the safeguards recommended by the 
National Institute of Standards and Technology (NIST) Special 
Publications 800-53, Recommended Security Controls for Federal 
Information Systems and Organizations as revised from time to time or 
any superseding guidance offered by NIST or other federal agency 
charged with the responsibility for providing recommended safeguards 
for computerized Records subject to the Privacy Act.
    (d) NCPC shall maintain a System of Records comprised of Office of 
Personnel Management (OPM) personnel Records in accordance with 
standards prescribed by OPM and published at 5 CFR 293.106--293.107.


Sec.  603.8  Employee conduct.

    (a) Employees with duties requiring access to and handling of 
Records shall, at all times, take care to protect the integrity, 
security, and confidentiality of the Records.
    (b) No employee of the NCPC shall disclose Records unless 
disclosure is permitted by Sec.  603.10(b) of this part, by NCPC's FOIA 
Regulations, or disclosed to the Individual to whom the Record 
pertains.
    (c) No employee of the NCPC shall alter or destroy a Record unless 
such Record or destruction is undertaken in the course of the 
employee's regular duties or such alteration or destruction is allowed 
pursuant to regulations published by the National Archives and Records 
Administration (NARA) or required by a court of competent jurisdiction. 
Records shall not be destroyed or disposed of while they are the 
subject of a pending request, appeal or lawsuit under the Privacy Act.


Sec.  603.9  Government contracts.

    (a) When a contract provides for third party operation of a SOR on 
behalf of the NCPC to accomplish a NCPC function, the contract shall 
require that the requirements of the Privacy Act and the rules in this 
part be applied to such System.
    (b) The Division Director responsible for the contract shall 
designate a NCPC employee to oversee and manage the SOR operated by the 
contractor.


Sec.  603.10  Conditions for disclosure.

    (a) Except as set forth in paragraph (b) of this section, no Record 
contained in a SOR shall be disclosed by any means of communication to 
any person, or to another agency, unless prior written consent is 
obtained from the Individual to whom the Record pertains.
    (b) The limitations on disclosure contained in paragraph (a) of 
this section shall not apply when disclosure of a Record is:
    (1) To employees of the NCPC for use in the performance of their 
duties;
    (2) Required by the Freedom of Information Act (FOIA), 5 U.S.C. 
555;

[[Page 35703]]

    (3) For a Routine Use as described in a SORN;
    (4) To the Bureau of Census for statistical purposes, provided that 
the Record must be transferred in a form that precludes individual 
identification;
    (5) To an Individual who provides NCPC adequate written assurance 
that the Record shall be used solely for statistical or research 
purposes, provided that the Record must be transferred in a form that 
precludes Individual identification;
    (6) To the NARA because the Record warrants permanent retention 
because of historical or other national value as determined by NARA or 
to permit NARA to determine whether the Record has such value;
    (7) To a law enforcement agency for a civil or criminal law 
enforcement activity, provided that the law enforcement agency must 
submit a written request to the NCPC specifying the Record(s) sought 
and the purpose for which they will be used;
    (8) To any person upon demonstration of compelling information that 
an Individual's health or safety is at stake and provided that upon 
disclosure, notification is given to the Individual to whom the Record 
pertains at that Individual's last known address;
    (9) To either House of Congress, and any committee or subcommittee 
thereof, to include joint committees of both houses and any 
subcommittees thereof, when a Record falls within their jurisdiction;
    (10) To the Comptroller General, or any of his authorized 
representatives, to allow the Government Accountability Office to 
perform its duties;
    (11) Pursuant to a court order by a court of competent 
jurisdiction; and
    (12) To a consumer reporting agency trying to collect a claim of 
the government as authorized by 31 U.S.C. 3711(e).


Sec.  603.11  Accounting of disclosures.

    (a) Except for disclosures made under Sec. Sec.  603.10(b)(1)-(2), 
when a Record is disclosed to any person, or to another agency, NCPC 
shall prepare an accounting of the disclosure. The accounting shall 
Record the date, nature, and purpose of the disclosure and the name and 
address of the person or agency to whom the disclosure was made. The 
NCPC shall maintain all accountings for a minimum of five years or the 
life of the Record, whichever is greatest, after the disclosure is 
made.
    (b) Except for disclosures under Sec.  603.10(b)(7), accountings of 
all disclosures shall be made available to the Individual about whom 
the disclosed Records pertains at his/her request. Such request shall 
be made in accordance with the requirements of Sec.  603.15.
    (c) For any disclosure for which an accounting is made, if a 
subsequent amendment or correction or notation of dispute is made to a 
Record by the NCPC in accordance with the requirements of section 
603.14, the Individual and/or agency to whom the Record was originally 
disclosed shall be informed.


Sec.  603.12  Requests for notification of the existence of Records.

    (a) An Individual seeking to determine whether a System of Records 
contains Records pertaining to him/her shall do so by appearing in 
person at NCPC's official place of business or by written 
correspondence to the NCPC PAO. In-person requests shall be by 
appointment only with the PAO on a Workday during regular office hours. 
Written requests sent via the U.S. mail shall be directed to the 
Privacy Act Officer at NCPC's official address listed at www.ncpc.gov. 
If sent via email or facsimile, the request shall be directed to the 
email address or facsimile number indicated on the NCPC Web site. To 
expedite internal handling of Privacy Act Requests, the words Privacy 
Act Request shall appear prominently on the envelop or the subject line 
of an email or facsimile cover sheet.
    (b) The Request shall state that the Individual is seeking 
information concerning the existence of Records about himself/herself 
and shall supply information describing the System where such Records 
might be maintained as set forth in a System of Record Notice.
    (c) The NCPC PAO shall notify the Requester in writing within 20-
Workdays of the Request whether a System contains Records pertaining to 
him/her unless the Records were compiled in reasonable anticipation of 
a civil action or proceeding or the Records are NCPC employee Records 
under the jurisdiction of the OPM. In both of the later cases the 
Request shall be denied. If the Request is denied because the Record(s) 
is/are under the jurisdiction of the OPM, the response shall advise the 
Requester to contact OPM. If the PAO denies the Request, the response 
shall state the reason for the denial and advise the Requester of the 
right to appeal the decision within 60 days of the date of the letter 
denying the request in accordance with the requirements set forth in 
Sec.  603.16.


Sec.  603.13  Requests for access to Records.

    (a) An Individual seeking access to Records about himself/herself 
shall do so by appearing in person at NCPC's official place of business 
or by written correspondence to the NCPC Privacy Act Officer. In-person 
requests shall be by appointment only with the Privacy Act Officer on a 
Workday during regular office hours. For written requests sent via the 
U.S. mail, the Request shall be directed to the Privacy Act Officer at 
NCPC's official address listed at www.ncpc.gov. If sent via email or 
facsimile, the request shall be directed to the email address or 
facsimile number indicated on the NCPC Web site. To expedite internal 
handling of Privacy Act Requests, the words Privacy Act Request shall 
appear prominently on the envelop or the subject line of an email or 
facsimile cover sheet.
    (b) The Request shall:
    (1) State the Request is made pursuant to the Privacy Act;
    (2) Describe the requested Records in sufficient detail to enable 
their location including, without limitation, the dates the Records 
were compiled and the name or identifying number of each System of 
Record in which they are kept as identified in the list of NCPC's SORNs 
published on its Web site; and
    (3) State pursuant to the fee schedule set forth in Sec.  603.17 a 
willingness to pay all fees associated with the Privacy Act Request or 
the maximum fee the Requester is willing to pay.
    (c) The NCPC shall require identification as follows before 
releasing Records to an Individual:
    (1) An Individual Requesting Privacy Act Records in person shall 
present a valid, photographic form of identification such as a driver's 
license, employee identification card, or passport that renders it 
possible for the PAO to verify that the Individual is the same 
Individual as contained in the requested Records.
    (2) An Individual Requesting Privacy Act Records by mail shall 
state their full name, address and date of birth in their 
correspondence. The Request must be signed and the signature must 
either be notarized or submitted with a statement signed and dated as 
follows: I declare under penalty of perjury that the foregoing facts 
establishing my identification are true and correct.
    (d) The PAO shall determine within 20 Workdays whether to grant or 
deny an Individual's Request for Access to the requested Record(s) and 
notify the Individual in writing accordingly. The PAO's response shall 
state his/her determination and the reasons therefor. If the Request is 
denied because the Record(s) is/are under the jurisdiction of the OPM, 
the response shall advise the Requester to contact OPM. In the case of 
an Adverse Determination, the written

[[Page 35704]]

notification shall advise the Individual of his/her right to appeal the 
Adverse Determination in accordance with the requirements of Sec.  
603.16.


Sec.  603.14  Requests for Amendment or Correction of Records.

    (a) An Individual seeking to amend or correct a Record pertaining 
to him/her that he/she believes to be inaccurate, irrelevant, untimely 
or incomplete shall submit a written request to the PAO at the address 
listed on NCPC's official Web site www.ncpc.gov. If sent via email or 
facsimile, the Request shall be directed to the email address or 
facsimile number indicated on the NCPC Web site. To expedite internal 
handling, the words Privacy Act Request shall appear prominently on the 
envelop or the subject line of an email or facsimile cover sheet.
    (b) The Request shall:
    (1) State the Request is made pursuant to the Privacy Act;
    (2) Describe the requested Record in sufficient detail to enable 
its location including, without limitation, the dates the Records were 
compiled and the name or identifying number of the System of Record in 
which the Record is kept as identified in the list of NCPC's SORNs 
published on its Web site;
    (3) State in detail the reasons why the Record, or objectionable 
portion(s) thereof, is/are not accurate, relevant, timely or complete.
    (4) Include copies of documents or evidence relied upon in support 
of the Request for Amendment or Correction; and
    (5) State specifically, and in detail, the changes sought to the 
Record, and if the changes include rewriting the Record, or portions 
thereof, or adding new language, the Individual shall propose specific 
language to implement the requested changes.
    (c) A request to Amend or Correct a Record shall be submitted only 
if the Requester has previously requested and been granted access to 
the Record and has inspected or been given a copy of the Record.
    (d) The PAO shall render a decision within 20 workdays. If the 
Request for an Amendment or Correction fails to meet the requirements 
of Sec. Sec.  (b)(1)-(5) of this Section, the PAO shall advise the 
Individual of the deficiency and advise what additional information is 
required to act upon the Request. The timeframe for a decision on the 
Request shall be tolled (stopped) during the pendency of a request for 
additional information and shall resume when the additional information 
is received. If the Requester fails to submit the requested additional 
information within a reasonable time, the PAO shall reject the Request.
    (e) The PAO's decision on a Request for Amendment or Correction 
shall be in writing and state the basis for the decision. If the 
Request is denied because the Record(s) is/are under the jurisdiction 
of the OPM, the response shall advise the Requester to contact OPM. In 
the event of an Adverse Determination, the written notification shall 
advise the Individual of his/her right to appeal the Adverse 
Determination in accordance with the requirements of Sec.  603.16.
    (f) If the PAO approves the Request for Amendment or Correction, 
the PAO shall ensure that subject Record is amended or corrected, in 
whole or in part. If the PAO denies the Request for Amendment or 
Correction, a notation of dispute shall be noted on the Record. If an 
accounting of disclosure has been made pursuant to Section 603.11, the 
PAO shall advise all previous recipients of the Record that an 
amendment or correction or notation of dispute has been made and, if 
applicable, the substance of the change.


Sec.  603.15  Requests for accounting of Record disclosures.

    (a) An Individual seeking information regarding an accounting of 
disclosure of a Record pertaining to him/her made in accordance with 
Sec.  603.11 shall submit a written request to the PAO at the address 
listed on NCPC's official Web site www.ncpc.gov. If sent via email or 
facsimile, the Request shall be directed to the email address or 
facsimile number indicated on the NCPC Web site. To expedite internal 
handling, the words Privacy Act Request shall appear prominently on the 
envelope or the subject line of an email or facsimile cover sheet.
    (b) The Request shall:
    (1) State the Request is made pursuant to the Privacy Act; and
    (2) Describe the requested Record in sufficient detail to determine 
whether it is or is not contained in an accounting of disclosure.
    (c) The NCPC PAO shall notify the Requester in writing within 20-
Workdays of the Request and advise if the Record was included in an 
accounting of disclosure. In the event of a disclosure, the response 
shall include the date, nature, and purpose of the disclosure and the 
name and address of the person or agency to whom the disclosure was 
made. If the Request is denied because the Record(s) is/are under the 
jurisdiction of the OPM, the response shall advise the Requester to 
contact OPM. In the event of an Adverse Determination, the written 
notification shall advise the Individual of his/her right to appeal the 
Adverse Determination in accordance with the requirements of Sec.  
603.16.


Sec.  603.16  Appeals of Adverse Determinations.

    (a) Except for appeals pursuant to subsection (d) below, an appeal 
of an Adverse Determination shall be made in writing addressed to the 
Chairman (Chairman) of the National Capital Planning Commission at the 
address listed on NCPC's official Web site www.ncpc.gov. If sent via 
email or facsimile, the Request shall be directed to the email address 
or facsimile number indicated on the NCPC Web site. To expedite 
internal handling, the words Privacy Act Request shall appear 
prominently on the envelope or the subject line of an email or 
facsimile cover sheet. An appeal of an Adverse Determination shall be 
made within 30 Workdays of the date of the decision.
    (b) An appeal of an Adverse Determination shall include a statement 
of the legal, factual or other basis for the Requester's objection to 
an Adverse Determination; a daytime phone number or email where the 
Requester can be reached if the Chairman requires additional 
information or clarification regarding the appeal; copies of the 
initial request and the PAO's written response; and for an Adverse 
Determination regarding a fee waiver, a demonstration of compliance 
with the NCPC's FOIA Regulations.
    (c) The Chairman shall respond to an appeal of an Adverse 
Determination in writing within 20 Workdays of receipt of the appeal. 
If the Chairman grants the appeal, the Chairman shall notify the 
Requester, and the NCPC shall take prompt action to respond 
affirmatively to the original Request upon receipt of any fees that may 
be required. If the Chairman denies the appeal, the letter shall state 
the reason(s) for the denial, a statement that the decision is final, 
and advise the Requester of the right to seek judicial review of the 
denial in the District Court of the United States in either the 
district in which the Requester resides, the district in which the 
Requester has his/her principal place of business or the District of 
Columbia.
    (d) The appeal of an Adverse Determination based on OPM 
jurisdiction of the Records shall be made to OPM pursuant to 5 CFR 
297.306.
    (e) The NCPC shall not act on an appeal of an Adverse Determination 
if the underlying Request becomes the subject of litigation.

[[Page 35705]]

    (f) A party seeking court review of an Adverse Determination must 
first appeal the Adverse Determination under this section.


Sec.  603.17  Fees.

    (a) The NCPC shall charge for the duplication of Records under this 
subpart in accordance with the schedule of fees set forth in NCPC's 
FOIA Regulations. The NCPC shall not charge duplication fees when the 
Requester asks to inspect the Records personally but is provided copies 
at the discretion of the agency.
    (b) The NCPC shall not charge any fees for the search for or review 
of Records requested by an Individual.


Sec.  603.18  Privacy Impact Assessments.

    (a) Consistent with the requirements of the E-Government Act and 
OMB Memorandum M-03-22, the NCPC shall conduct a PIA before:
    (1) Developing or procuring IT systems or projects that collect, 
maintain, or disseminate IFF; or
    (2) Installing a new collection of information that will be 
collected, maintained, or disseminated using IT and includes IFF for 10 
or more persons (excluding agencies, instrumentalities or employees of 
the federal government).
    (b) The PIA shall be prepared through the coordinated effort of the 
NCPC's privacy Officers (SAOP, PAO), Division Directors, CIO, and IT 
staff.
    (c) As a general rule, the level of detail and content of a PIA 
shall be commensurate with the nature of the information to be 
collected and the size and complexity of the IT system involved. 
Specifically, a PIA shall analyze and describe:
    (1) The information to be collected;
    (2) The reason the information is being collected;
    (3) The intended use for the information;
    (4) The identity of those with whom the information will be shared;
    (5) The opportunities Individuals have to decline to provide the 
information or to consent to particular uses and how to consent;
    (6) The manner in which the information will be secured; and
    (7) The extent to which the system of records is being created 
under the Privacy Act.
    (d) In addition to the information specified in Sec. Sec.  (b)(1)-
(7) above, the PIA must also identify the choices NCPC made regarding 
an IT system or collection of information as result of preparing the 
PIA.
    (e) The CCB shall verify that a PIA has been prepared prior to 
approving a request to develop or procure information technology that 
collects, maintains, or disseminates Information in Identifiable Form.
    (f) The SAOP shall approve and sign the NCPC's PIA. If the SAOP is 
the Contracting Officer for the IT system that necessitated preparation 
of the PIA, the Executive Director shall approve and sign the PIA.
    (g) Following approval of the PIA, the NCPC shall post the PIA 
document on the NCPC Web site located at www.ncpc.gov.

    Dated: July 24, 2017.
Anne R. Schuyler,
General Counsel.
[FR Doc. 2017-15882 Filed 7-31-17; 8:45 am]
BILLING CODE 7502-02-P



                                                                            Federal Register / Vol. 82, No. 146 / Tuesday, August 1, 2017 / Proposed Rules                                         35697

                                                    enhanced by the disclosure to a                          § 456.16   Preservation of FOIA records.              Congress amended the Privacy Act
                                                    significant extent, as compared to the                     (a) The NCPC shall preserve all                     multiple times including the E-
                                                    level of public understanding existing                   correspondence pertaining to FOIA                     Government Act of 2002 which
                                                    prior to the disclosure. The NCPC shall                  Requests received and copies or Records               addressed requirements for maintaining
                                                    not make value judgments about                           provided until disposition or                         electronic privacy records. The
                                                    whether information that would                           destruction is authorized by the NCPC’s               proposed regulations update NCPC’s
                                                    contribute significantly to public                       General Records schedule established in               existing Privacy Regulations to reflect
                                                    understanding of the operations or                       accordance with the National Archives                 amendments over time. The Office of
                                                    activities of the government is important                and Records Administration (NARA)                     the Federal Register recently assigned
                                                    enough to be made public.                                approved schedule.                                    NCPC a new chapter of 1 CFR—Chapter
                                                                                                               (b) Materials that are responsive to a              VI—to allow NCPC to group all its
                                                      (c) To determine whether disclosure
                                                                                                             FOIA Request shall not be disposed of                 regulations together in one chapter.
                                                    of the information is not primarily in
                                                                                                             or destroyed while the Request or a                   NCPC proposes to codify the new
                                                    the commercial interest of the                                                                                 Privacy Regulations at 1 CFR 603.
                                                                                                             related lawsuit is pending even if the
                                                    Requester, the Requester shall
                                                                                                             Records would otherwise be authorized       Section by Section Analysis of NCPC’s
                                                    demonstrate, and NCPC shall consider,
                                                                                                             for disposition under the NCPC’s            Privacy Act Regulations
                                                    the following factors:
                                                                                                             General Records Schedule or NARA or
                                                      (1) Whether the Requester has a                        other NARA-approved records schedule.          § 603.1 Purpose and scope. This
                                                    commercial interest that would be                                                                    section advises the purpose of the
                                                                                                                Dated: July 24, 2017.                    regulations is to implement a privacy
                                                    furthered by the Requested disclosure.
                                                                                                             Anne R. Schuyler,                           program consistent with the
                                                    The NCPC shall consider any
                                                    commercial interest of the Requester                     General Counsel.                            requirements of the Privacy Act and the
                                                    (with reference to the definition of                     [FR Doc. 2017–15887 Filed 7–31–17; 8:45 am] privacy related provision of the E-
                                                    Commercial Use Request in § 456.3(f)),                   BILLING CODE 7502–02–P                      Government Act of 2002. As stated in
                                                    or of any person on whose behalf the                                                                 the section, NCPC’s privacy program
                                                    Requester may be acting, that would be                                                               extends to all Records maintained by
                                                    furthered by the Requested disclosure.                   NATIONAL CAPITAL PLANNING                   NCPC in a System of Records; the
                                                    Requesters shall be given an                             COMMISSION                                  responsibilities of NCPC to safeguard
                                                    opportunity in the administrative                                                                    this information; the procedures by
                                                                                                             1 CFR Chapters IV and VI                    which Individuals may request
                                                    process to provide explanatory
                                                    information regarding this                                                                           notification of the existence of a Record
                                                                                                             Privacy Act Regulations                     about them, access to Records about
                                                    consideration.
                                                                                                             AGENCY: National Capital Planning           them, an amendment to or correction of
                                                      (2) Whether any identified                             Commission.                                 the Records about them, and an
                                                    commercial interest of the Requester is                                                              accounting of disclosures of those
                                                                                                             ACTION: Proposed rule.
                                                    sufficiently large in comparison with                                                                Records by the NCPC; the procedures by
                                                    the public interest in disclosure that                   SUMMARY: The National Capital Planning which an Individual may appeal an
                                                    disclosure is primarily in the                           Commission (NCPC or Commission)             Adverse Determination, and the conduct
                                                    commercial interest of the Requester. A                  proposes to adopt new regulations           of a Privacy Impact Assessment.
                                                    Fee Waiver is justified where the public                 governing NCPC’s implementation of             § 603.2 Definitions. This section
                                                    interest standard of paragraph (b) of this               the Privacy Act, as amended and the         defines terms frequently used in the
                                                    section is satisfied and that public                     privacy provisions of the E-Government regulations. The section includes the
                                                    interest is greater in magnitude than that               Act of 2002. NCPC must comply with          five terms defined in the existing
                                                    of any identified commercial interest in                 the requirements of the Privacy Act and regulations—Individual, Maintain,
                                                    disclosure. The NCPC ordinarily shall                    the privacy provisions of the E-            Record, Routine Use and System of
                                                    presume that a Representative of the                     Government Act of 2002 for records          Records. It adds the definitions for the
                                                    News Media satisfies the public interest                 maintained on individuals and personal following terms: Adverse
                                                    standard, and the public interest will be                information stored as a hard copy or        Determination, E-Government Act of
                                                    the interest primarily served by                         electronically.                             2002, Information in Identifiable Form
                                                    disclosure to that Requester. Disclosure                 DATES: Submit comments on or before
                                                                                                                                                         (IIF), Information Technology, Privacy
                                                    to data brokers or others who merely                     August 31, 2017.                            Act Officer (PAO), Privacy Act, Privacy
                                                    compile and market government                                                                        Impact Assessment (PIA), Record,
                                                                                                             ADDRESSES: You may submit written
                                                    information for direct economic return                                                               Requester, Request for Access to a
                                                                                                             comments on the proposed Privacy Act
                                                    shall not be presumed to primarily serve                                                             Record, Request for Amendment or
                                                                                                             regulations by either of the methods
                                                    the public interest.                                                                                 Correction of a Record, Senor Agency
                                                                                                             listed below.
                                                      (d) Where only some of the Records                        1. U.S. mail, courier, or hand delivery: Official for Privacy (SAOP), System of
                                                    to be released satisfy the requirements                  Anne R. Schuyler, General Counsel/          Records Notice (SORN), and Workday.
                                                                                                                                                            § 603.3 Privacy Act program
                                                    for a Fee Waiver, a Fee Waiver shall be                  National Capital Planning Commission,
                                                                                                                                                         responsibilities. This section requires
                                                    granted for those Records.                               401 9th Street NW., Suite 500,
                                                                                                                                                         NCPC to designate a SAOP and a PAO
                                                      (e) Requests for a Fee Waiver should                   Washington, DC 20004.
                                                                                                                                                         and outlines the responsibilities
mstockstill on DSK30JT082PROD with PROPOSALS




                                                    address the factors listed in paragraphs                    2. Electronically: Privacy@ncpc.gov.
                                                                                                                                                         associated with both positions. It also
                                                    (b) and (c) of this section, insofar as they             FOR FURTHER INFORMATION CONTACT:
                                                                                                                                                         enumerates the Privacy Act
                                                    apply to each Request. The NCPC shall                    Anne R. Schuyler, General Counsel at        responsibilities of other NCPC
                                                    exercise its discretion to consider the                  202–482–7223, anne.schuyler@                personnel.
                                                    cost-effectiveness of its investment of                  ncpc.gov.                                      § 603.4 Standards used to Maintain
                                                    administrative resources in this                         SUPPLEMENTARY INFORMATION: NCPC’s           Records. This section establishes the
                                                    decision-making process in deciding to                   adopted its current Privacy Regulations     standards NCPC must follow regarding
                                                    grant Fee Waivers.                                       (1 CFR 455) in 1977. Since that time,       privacy information. The section


                                               VerDate Sep<11>2014   17:34 Jul 31, 2017   Jkt 241001   PO 00000   Frm 00009   Fmt 4702   Sfmt 4702   E:\FR\FM\01AUP1.SGM   01AUP1


                                                    35698                   Federal Register / Vol. 82, No. 146 / Tuesday, August 1, 2017 / Proposed Rules

                                                    requires NCPC to limit private                           prohibits employee disclosure of                      required to be included in a request, and
                                                    information to only that necessary to                    records unless authorized by the rules                obligates Individuals to present certain
                                                    achieve the purposes for which it is                     in this part, permitted by NCPC’s FOIA                specified identification to access the
                                                    collected and stored; to ensure all                      regulations, or disclosed to the                      requested Records. The section also
                                                    information collected is accurate,                       Individual to whom the Record pertains.               requires the NCPC PAO to respond to a
                                                    relevant, timely, and complete; and to                   The section also prohibits destruction or             request for access in writing within 20-
                                                    collect privacy information regarding an                 alteration of Records unless required as              Workdays, to state in the response the
                                                    Individual’s rights, benefits and                        part of an employee’s regular duties,                 reason for the PAO’s determination, and
                                                    privileges under federal programs from                   required by regulations published by the              to advise the Requester of the right to
                                                    the Individual to the maximum extent                     National Archives Record                              appeal an Adverse Determination.
                                                    possible subject to collection from third                Administration (NARA), or required by                    § 603.14 Requests for amendment or
                                                    parties in certain circumstances.                        a court of law.                                       correction of Records. This section
                                                       § 603.5 Notice to Individuals                            § 603.9 Government contracts. This                 outlines the process Individuals must
                                                    supplying information. This section                      section requires contractors operating a              follow to amend or correct Records
                                                    enumerates the information NCPC must                     System of Records on behalf of NCPC to                about them that they believe are
                                                    provide Individuals who are asked to                     abide by the requirements of the Privacy              inaccurate, irrelevant, untimely or
                                                    supply information about themselves.                     Act. It also requires a NCPC employee                 incomplete. The section requires a
                                                    The required information enumerated                      to oversee and manage the SOR                         request for amendment or correction to
                                                    includes the purpose for which NCPC                      operated by a contractor.                             be in writing, include certain specified
                                                    intends to use the information; the                         § 603.10 Conditions for disclosure.                information, and to be made only if the
                                                    effects upon an Individual for not                       Subject to a list of enumerated                       Individual has previously requested and
                                                    providing the information; and the form                  exceptions, this section precludes                    been granted access to the Record. The
                                                    of notice NCPC must supply in response                   disclosure of a Record contained in a                 section also requires the NCPC PAO to
                                                    to an Individual’s provision of                          SOR unless prior written consent is                   respond to a request for amendment or
                                                    information.                                             obtained from the Individual to whom                  correction in writing within 20-
                                                       § 603.6 System of Records (SOR)                       the record pertains.                                  Workdays, to state the reason for the
                                                    Notice (SORN). This section requires                        § 603.11 Accounting of disclosures.                PAO’s determination in the response, to
                                                    NCPC to publish a notice in the Federal                  This section requires NCPC to prepare                 advise the requester of the right to
                                                    Register describing each SOR 40-days                     an accounting of disclosure when a                    appeal an Adverse Determination, to
                                                    before establishing a new or revising an                 Record is disclosed to any person or to               ensure the Record is amended or
                                                    existing SOR. The section requires the                   another agency. The section requires the              corrected in whole or in part if the PAO
                                                    SORN to include the purpose of the                       contents of an accounting to include the              approves the request, and to place a
                                                    Records and their location; the types of                 date, nature, and purpose of the                      notation of a dispute on the Record if
                                                    Individuals contained in the SOR; the                    disclosure and the name and address of                the request is denied.
                                                    authority for maintaining the SOR; the                   the person or agency to whom the                         § 603.15. Requests for an accounting
                                                    purpose or reason why NCPC collects                      disclosure was made. The section also                 of Records disclosures. This section
                                                    the Records and their intended routine                   requires Accountings of disclosures to                outlines the process Individuals must
                                                    uses; the sources of the Records in the                  be made available to the Individual                   follow to obtain information about
                                                    SOR; the policies and practices                          about whom the disclosed Record                       disclosures of Records pertaining to
                                                    regarding storage, retrieval, access                     pertains except under limited                         them. It requires a request for
                                                    controls, retention, and disposal of the                 circumstances. It further requires                    information about Records disclosed to
                                                    Records; the identification of the agency                changes to disclosed Records to be                    include certain specified information.
                                                    official responsible for the SOR; and the                shared with the person or agency to                   The section also requires the NCPC PAO
                                                    procedures for notifying an Individual                   whom the Record was originally                        to respond to a request for information
                                                    who requests whether the SOR contains                    disclosed.                                            about disclosures in writing within 20-
                                                    information about him/her.                                  § 603.12 Requests for notification of              Workdays, to include, in the event of a
                                                       § 603.7 Procedures to safeguard                       the existence of Records. This section                disclosure, the date, nature and purpose
                                                    Records. This section describes the                      advises Individuals how to determine                  of the disclosure, the name and address
                                                    procedures utilized by NCPC to                           whether a System of Records                           of the person or agency to whom the
                                                    safeguard hard copy and computerized                     maintained by NCPC contains Records                   disclosure was made. The section
                                                    records subject to the Privacy Act. The                  pertaining to them. It requires                       further requires the PAO to state the
                                                    section requires hard copy Records to be                 Individuals either to contact NCPC in                 reason for his/her determination and to
                                                    stored in a locked room subject to                       writing or appear at NCPC’s offices by                advise the requester of the right to
                                                    restricted access with external posted                   appointment to make the subject                       appeal an Adverse Determination.
                                                    warning signs limiting access to                         request. The section requires the NCPC                   § 602.16 Appeals of Adverse
                                                    authorized personnel and/or stored in a                  PAO to respond to a request in writing                Determinations. This section describes
                                                    locked container with identical                          within 20-Workdays, to include in the                 the process Individuals must follow to
                                                    precautions to those used for a locked                   response the Reason(s) for the PAO’s                  appeal an Adverse Determination. As
                                                    room. The section requires                               determination, and to advise the                      defined in the definition section of the
                                                    computerized Records to be maintained                    requester of the right to appeal the                  regulations Adverse Determination
                                                    subject to the Safeguards recommended                    decision.                                             means a decision to withhold any
mstockstill on DSK30JT082PROD with PROPOSALS




                                                    by the National Institute of Standards                      § 603.13 Request for access to                     requested Record in whole or in part; a
                                                    and Technology (NIST).                                   Records. This section advises                         decision that the requested Record does
                                                       § 603.8 Employee conduct. This                        Individuals how to access NCPC records                not exist or cannot be located; a
                                                    section requires employees with duties                   about themselves. It requires                         decision that the requested information
                                                    requiring access to and handling of                      Individuals to request the right to access            is not a Record subject to the Privacy
                                                    Records to do so in a manner that                        Records either in writing or to appear at             Act; a decision that a Record, or part
                                                    protects the integrity, security and                     NCPC’s offices by appointment. The                    thereof, does not require amendment or
                                                    confidentiality of the Records. It                       section enumerates the information                    correction; a decision to refuse to


                                               VerDate Sep<11>2014   17:34 Jul 31, 2017   Jkt 241001   PO 00000   Frm 00010   Fmt 4702   Sfmt 4702   E:\FR\FM\01AUP1.SGM   01AUP1


                                                                            Federal Register / Vol. 82, No. 146 / Tuesday, August 1, 2017 / Proposed Rules                                            35699

                                                    disclose an accounting of disclosure;                    Executive Order 13771                                 action significantly affecting the quality
                                                    and a decision to deny a fee waiver. The                   By virtue of its exemption from the                 of the human environment. NCPC’s
                                                    term also encompasses a challenge to                     requirements of EO 12866, NCPC is                     adoption of the proposed rule will have
                                                    NCPC’s determination that Records have                   exempted from this Executive Order.                   minimal or no effect on the
                                                    not been described adequately, that                      NCPC confirmed this fact with OIRA.                   environment; impose no significant
                                                    there are no responsive Records, or that                                                                       change to existing environmental
                                                    an adequate search has been conducted.                   Regulatory Flexibility Act                            conditions; and will have no cumulative
                                                    The section requires an Individual to                       As required by the Regulatory                      environmental impacts.
                                                    submit a written appeal to the Chairman                  Flexibility Act (5 U.S.C. 601 et seq.), the           Clarity of the Regulation
                                                    of the Commission stating the legal,                     NCPC certifies that the proposed rule
                                                    factual or other basis for the Appeal,                   will not have a significant economic                     Executive Order 12866, Executive
                                                    and it requires the Chairman to provide                  effect on a substantial number of small               Order 12988, and the Presidential
                                                    a written response within 30-Workdays.                   entities.                                             Memorandum of June 1, 1998 requires
                                                    The section also requires NCPC to take                                                                         the NCPC to write all rules in plain
                                                    prompt action to respond affirmatively                   Small Business Regulatory Enforcement                 language. NCPC maintains the proposed
                                                    to the Individual’s original request if the              Fairness Act                                          rule meets this requirement. Those
                                                    Chairman grants the request and to state                   This is not a major rule under 5 U.S.C.             individuals reviewing the proposed rule
                                                    the reasons for a denial and the right to                804(2), the Small Business Regulatory                 who believe otherwise should submit
                                                    appeal the denial to a court of                          Enforcement Fairness Act. It does not                 specific comments to the addresses
                                                    competent jurisdiction.                                  have an annual effect on the economy                  noted above recommending revised
                                                      § 603.17 Fees. This section states the                 of $100 million or more; will not cause               language for those provision or portions
                                                    fees to be charged for the search for and                a major increase in costs for individuals,            thereof where they believe compliance
                                                    duplication of Records. It advises fees                  various levels of governments or various              is lacking.
                                                    for duplication shall be those                           regions; and does not have a significant              Public Availability of Comments
                                                    established by NCPC’s FOIA                               adverse effect on completion,
                                                    Regulations, and it states there are no                  employment, investment, productivity,                   Be advised that personal information
                                                    fees for the search or review of Records                 innovation or the competitiveness of US               such as name, address, phone number,
                                                    requested by an Individual.                              enterprises with foreign enterprises.                 electronic address, or other identifying
                                                      § 603.18 Privacy Impact Assessments.                                                                         personal information contained in a
                                                    This section states when NCPC must                       Unfunded Mandates Reform Act (2                       comment may be made publically
                                                    conduct a Privacy Impact Assessment                      U.S.C. 1531 et seq.)                                  available. Individuals may ask NCPC to
                                                    (PIA), the contents of a PIA, and the                      A statement regarding the Unfunded                  withhold the personal information in
                                                    process for approving the PIA. The                       Mandates Reform Act is not required.                  their comment, but there is no guarantee
                                                    section requires a PIA to be conducted                   The proposed rule neither imposes an                  the agency can do so.
                                                    before developing or procuring an IT                     unfunded mandate of more than $100                    List of Subjects in 1 CFR Part 603
                                                    system that collects, maintains or                       million per year nor imposes a
                                                    disseminates Information that identifies                 significant or unique effect on State,                  Privacy Act Regulations.
                                                    an Individual (IFF or Information in                     local or tribal governments or the                      For the reasons stated in the
                                                    Identifiable Form) or when NCPC                          private sector.                                       preamble, the National Capital Planning
                                                    installs a new collection of IFF for 10 or                                                                     Commission proposes amend 1 CFR
                                                                                                             Federalism (Executive Order 13132)                    Chapters IV and VI as proposed to be
                                                    more persons other than employees, or
                                                    agencies of the federal government. The                    In accordance with Executive Order                  established at 82 FR 24570 to read as
                                                    section also requires a PIA to analyze a                 13132, the proposed rule does not have                follows:
                                                    number of factors related to the                         sufficient federalism implications to
                                                                                                                                                                   CHAPTER IV—MISCELLANEOUS
                                                    collection, use, owner, storage and                      warrant the preparation of a Federalism               AGENCIES
                                                    manner of securing the IFF, and it                       Assessment. The proposed rule does not
                                                    requires the PIA to be approved and                      substantially and directly affect the                 PART 455 [Removed].
                                                    posted on NCPC’s Web site prior to                       relationship between the Federal and
                                                    undertaking the action that required the                 state governments.                                    ■ 1. Under the authority of 40 U.S.C.
                                                    PIA.                                                                                                           8711(a) remove part 455.
                                                                                                             Civil Justice Reform (Executive Order                 ■ 2. Add part 603 to read as follows:
                                                    Compliance With Laws and Executive                       12988)
                                                                                                                                                                   CHAPTER VI—NATIONAL CAPITAL
                                                    Orders                                                     The General Counsel of NCPC has                     PLANNING COMMISSION [Proposed]
                                                    Executive Orders 12866 and 13563                         determined that the proposed rule does
                                                                                                             not unduly burden the judicial system                 PART 603—NATIONAL CAPITAL
                                                      By Memorandum dated October 12,                        and meets the requirements of Executive               PLANNING COMMISSION PRIVACY
                                                    1993 from Sally Katzen, Administrator,                   Order 12988 3(a) and 3(b)(2).                         ACT REGULATIONS
                                                    Office of Information and Regulatory
                                                    Affairs (OIRA) to Heads of Executive                     Paperwork Reduction Act                               Sec.
                                                    Departments and Agencies, and                              The proposed rule does not contain                  603.1 Purpose and scope.
                                                    Independent Agencies, OMB rendered                       information collection requirements,                  603.2 Definitions.
mstockstill on DSK30JT082PROD with PROPOSALS




                                                    the NCPC exempt from the requirements                    and it does not require a submission to               603.3 Privacy Act program responsibilities.
                                                    of Executive Order 12866 (See,                                                                                 603.4 Standard used to Maintain Records.
                                                                                                             the Office of Management and Budget                   603.5 Notice to Individuals supplying
                                                    Appendix A of cited Memorandum).                         under the Paperwork Reduction Act.                         information.
                                                    Nonetheless, NCPC endeavors to adhere                                                                          603.6 System of Records Notice or SORN.
                                                    to the provisions of Executive Orders                    National Environmental Policy Act
                                                                                                                                                                   603.7 Procedures to safeguard Records.
                                                    and developed this proposed rule in a                      The proposed rule is of an                          603.8 Employee conduct.
                                                    manner consistent with the                               administrative nature, and its adoption               603.9 Government contracts.
                                                    requirements of Executive Order 13563.                   does not constitute a major federal                   603.10 Conditions for disclosure.



                                               VerDate Sep<11>2014   17:34 Jul 31, 2017   Jkt 241001   PO 00000   Frm 00011   Fmt 4702   Sfmt 4702   E:\FR\FM\01AUP1.SGM   01AUP1


                                                    35700                   Federal Register / Vol. 82, No. 146 / Tuesday, August 1, 2017 / Proposed Rules

                                                    603.11 Accounting for disclosures.                       § 603.2   Definitions.                                and disseminating information in
                                                    603.12 Request for notification of the                      For purposes of this part, the                     identifiable form in an electronic
                                                        existence of Records.                                following definitions shall apply:                    system; and to examine and evaluate
                                                    603.13 Requests for access to Records.                      Adverse Determination shall mean a                 protections and alternative processes for
                                                    603.14 Request for Amendment or
                                                                                                             decision to withhold any requested                    handling information to mitigate
                                                        Correction of Records.
                                                    603.15 Request for Accounting of Record
                                                                                                             Record in whole or in part; a decision                potential privacy risks.
                                                        disclosures.                                         that the requested Record does not exist                 Record shall mean any item,
                                                    603.16 Appeal of Adverse Determinations.                 or cannot be located; a decision that the             collection, or grouping of information
                                                    603.17 Fees.                                             requested information is not a Record                 about an Individual that is Maintained
                                                    603.18 Privacy Impact Assessments.                       subject to the Privacy Act; a decision                by the NCPC, including, but not limited
                                                      Authority: 5 U.S.C. 552a as amended and                that a Record, or part thereof, does not              to, an Individual’s education, financial
                                                    44 U.S.C. ch. 36.                                        require amendment or correction; a                    transactions, medical history, and
                                                                                                             decision to refuse to disclose an                     criminal or employment history and
                                                    § 603.1   Purpose and scope.                             accounting of disclosure; and a decision              that contains a name, or identifying
                                                      (a) This part contain the rules the                    to deny a fee waiver. The term shall also             number, symbol, or other identifying
                                                    National Capital Planning Commission                     encompass a challenge to NCPC’s                       particular assigned to the Individual,
                                                    (NCPC) shall follow to implement a                       determination that Records have not                   such as a finger or voice print or
                                                    privacy program as required by the                       been described adequately, that there                 photograph.
                                                    Privacy Act of 1974, 5 U.S.C. 552a                       are no responsive Records or that an                     Requester shall mean an Individual
                                                    (Privacy Act or Act) and the privacy                     adequate search has been conducted.                   who makes a Request for Access to a
                                                                                                                E-Government Act of 2002 shall mean
                                                    provisions of the E-Government Act of                                                                          Record, a Request for Amendment or
                                                                                                             Public Law 107–347, Dec. 17, 2002, 116
                                                    2002 (44 U.S.C. ch. 36) (E-Government                                                                          Correction of a Record, or a Request for
                                                                                                             Stat. 2899, the privacy portions of
                                                    Act). These rules should be read                                                                               Accounting of a Record under the
                                                                                                             which are set out as a note under
                                                    together with the Privacy Act and the                                                                          Privacy Act.
                                                                                                             section 3501 of title 44.
                                                    privacy related provisions of the E-                        Individual shall mean a citizen of the                Request for Access to a Record shall
                                                    Government Act, which provide                            United States or an alien lawfully                    mean a request by an Individual made
                                                    additional information respectively                      admitted for permanent residence.                     to the NCPC pursuant to subsection
                                                    about Records maintained on                                 Information in Identifiable Form (IFF)             (d)(1) of the Privacy Act to gain access
                                                    individuals and protections for the                      shall mean information in an                          to his/her Records or to any information
                                                    privacy of personal information as                       Information Technology system or an                   pertaining to him/her in the system and
                                                    agencies implement citizen-centered                      online collection that directly identifies            to permit him/her, or a person of his/her
                                                    electronic Government.                                   an individual, e.g., name, address, social            choosing, to review and copy all or any
                                                      (b) Consistent with the requirements                   security number or other identifying                  portion thereof.
                                                    of the Privacy Act, the rules in this part               number or code, telephone number,                        Request for Amendment or Correction
                                                    apply to all Records maintained by                       email address and the like; or                        of a Record shall mean a request made
                                                    NCPC in a System of Records; the                         information by which the NCPC intends                 by an Individual to the NCPC pursuant
                                                    responsibilities of the NCPC to                          to identify specific individuals in                   to subsection (d)(2) of the Privacy Act to
                                                    safeguard this information; the                          conjunction with other data elements,                 amend or correct a Record pertaining to
                                                    procedures by which Individuals may                      e.g., indirect identification that may                him/her.
                                                    request notification of the existence of a               include a combination of gender, race,                   Routine Use shall mean with respect
                                                    record, request access to Records about                  birth date, geographic identifiers, and               to disclosure of a Record, the use of
                                                    themselves, request an amendment to or                   other descriptions.                                   such Record for a purpose which is
                                                    correction of those Records, and request                    Information Technology (IT) shall                  compatible with the purpose for which
                                                    an accounting of disclosures of those                    mean, as defined in the Clinger Cohen                 the Record is collected.
                                                    Records by the NCPC; and the                             Act (40 U.S.C. 11101(6)), any                            Senior Agency Official for Privacy
                                                    procedures by which an Individual may                    equipment, software or interconnected                 (SAOP) shall mean the individual
                                                    appeal an Adverse Determination.                         system or subsystem that is used in the               within NCPC responsible for
                                                      (c) Consistent with the privacy related                automatic acquisition, storage,                       establishing and overseeing the NCPC’s
                                                    requirements of the E-Government Act,                    manipulation, management, movement,                   Privacy Act program.
                                                    the rules in this part also address the                  control, display, switching, interchange,                System of Records or System (SOR or
                                                    conduct of a privacy impact assessment                   transmission or reception of data.                    Systems) shall mean a group of any
                                                    prior to developing or procuring                            Maintain shall include maintain,
                                                                                                                                                                   Records under the control of the NCPC
                                                    information technology that collects,                    collect, use or disseminate a Record.
                                                                                                                Privacy Act Officer shall mean the                 from which information is retrieved by
                                                    maintains, or disseminates information                                                                         the name of the individual or by some
                                                                                                             individual within the NCPC charged
                                                    in an identifiable form, initiating a new                                                                      identifying number, symbol, or other
                                                                                                             with responsibility for coordinating and
                                                    electronic collection of information in                                                                        identifying particular assigned to the
                                                                                                             implementing NCPC’s Privacy Act
                                                    identifiable form for 10 or more persons                                                                       individual.
                                                                                                             program.
                                                    excluding agencies, instrumentalities or                    Privacy Act or Act shall mean the                     System of Record Notice (SORN) shall
                                                    employees of the federal government, or                  Privacy Act of 1974, as amended and                   mean a notice published in the Federal
mstockstill on DSK30JT082PROD with PROPOSALS




                                                    changing an existing System that creates                 codified at 5 U.S.C. 552a.                            Register by the NCPC for each new or
                                                    new privacy risks.                                          Privacy Impact Assessment (PIA)                    revised System of Records intended to
                                                      (d) In addition to the rules in this                   shall mean an analysis of how                         solicit public comment on the System
                                                    part, the NCPC shall process all Privacy                 information is handled to ensure                      prior to implementation.
                                                    Act Requests for Access to Records in                    handling conforms to applicable legal,                   Workday shall mean a regular Federal
                                                    accordance with the Freedom of                           regulatory, and policy requirements                   workday excluding Saturday, Sunday
                                                    Information Act (FOIA), 5 U.S.C. 552,                    regarding privacy; to determine the risks             and legal Federal holidays when the
                                                    and NCPC’s FOIA rules.                                   and effects of collecting, maintaining                federal government is closed.


                                               VerDate Sep<11>2014   17:34 Jul 31, 2017   Jkt 241001   PO 00000   Frm 00012   Fmt 4702   Sfmt 4702   E:\FR\FM\01AUP1.SGM   01AUP1


                                                                            Federal Register / Vol. 82, No. 146 / Tuesday, August 1, 2017 / Proposed Rules                                          35701

                                                    § 603.3 Privacy Act program                              NCPC Division Directors, the NCPC                       (ii) Reviewing PIAs prepared for
                                                    responsibilities.                                        Chief Information Officer (CIO), the                  information security considerations.
                                                      (a) The NCPC shall designate a Senior                  NCPC System Developers and                              (3) The NCPC System Developers and
                                                    Agency Official for Privacy (SAOP) to                    Designers, the NCPC Configuration                     Designers shall be responsible for
                                                    establish and oversee the NCPC’s                         Control Board, the NCPC employees,                    ensuring that the IT system design and
                                                    Privacy Act Program and ensure                           and the Chairman of the Commission.                   specifications conform to privacy
                                                    compliance with privacy laws,                               (1) The NCPC Division Directors shall              standards and requirements and that
                                                    regulations and the NCPC’s privacy                       be responsible for coordinating with the              technical controls are in place for
                                                    policies. Specific responsibilities of the               PAO the implementation of the                         safeguarding personal information from
                                                    SAOP shall include:                                      requirements set forth in this part for               unauthorized access.
                                                      (1) Reporting to the Office of                         Systems of Records applicable to their                  (4) The NCPC CCB shall, among other
                                                    Management and Budget (OMB) and                          area of management and the preparation                responsibilities, verify that a PIA has
                                                    Congress on the establishment of or                      of PIA prior to development or                        been prepared prior to approving a
                                                    revision to Privacy Act Systems;                         procurement of new systems that                       request to develop or procure
                                                      (2) Reporting periodically to OMB on                   collect, maintain or disseminate IFF.                 information technology that collects,
                                                    Privacy Act activities as required by law                Specific responsibilities include:                    maintains, or disseminates Information
                                                    and OMB;                                                    (i) Reviewing existing SOR for need,               in Identifiable Form.
                                                      (3) Signing Privacy Act SORNS for                      relevance, and purpose for existence,                   (5) The NCPC employees shall ensure
                                                    publication in the Federal Register;                     and proposing SOR changes to the PAO                  that any personal information they use
                                                      (4) Approving and signing PIAs; and                    as necessary in response to altered                   in the conduct of their official
                                                      (5) Serving as head of the agency                      circumstances;                                        responsibilities is protected in
                                                    response team when responding to a                          (ii) Reviewing existing SOR to ensure              accordance with the rules set forth in
                                                    large-scale information breach.                          information is accurate, complete and                 this part.
                                                      (b) The NCPC shall designate a                         up to date;                                             (6) The Chairman of the Commission
                                                    Privacy Act Officer (PAO) to coordinate                     (iii) Coordinating with the PAO the                shall be responsible for acting on all
                                                    and implement the NCPC’s Privacy Act                     preparation of new or revised SORN;                   appeals of Adverse Determinations.
                                                    program. Specific responsibilities of the                   (iv) Coordinating with the PAO the
                                                    PAO shall include:                                       development of an appropriate form for                § 603.4 Standards used to Maintain
                                                      (1) Developing, issuing and updating,                  collection of Privacy Act information                 Records.
                                                    as necessary, the NCPC’s Privacy Act                     and including in the form a Privacy Act                  (a) Records Maintained by the NCPC
                                                    policies, standards, and procedures;                     statement explaining the purpose for                  shall contain only such information
                                                      (2) Maintaining Privacy Act program                    collecting the information, how it will               about an Individual as is relevant and
                                                    Records and documentation;                               be used, the authority for such                       necessary to accomplish a purpose
                                                      (3) Responding to Privacy Act                          collection, its routine uses, and the                 NCPC must accomplish to comply with
                                                    Requests for Records and coordinating                    effect upon the Individual of not                     relevant statutes or Executive Orders of
                                                    appeals of Adverse Determinations for                    providing the requested information;                  the President.
                                                    Requests for access to Records, Requests                    (v) Collecting information directly                   (b) Records Maintained by the NCPC
                                                    for Amendment or Correction of                           from individuals whenever possible;                   and used to make a determination about
                                                    Records, and Requests for accounting                        (vi) Assisting the PAO with providing              an Individual shall be accurate,
                                                    for disclosures;                                         access to Individuals who request                     relevant, timely, and complete to assure
                                                      (4) Informing Individuals of                           information in accordance with the                    a fair determination.
                                                    information disclosures;                                 procedures established in §§ 603.12,                     (c) Information used by the NCPC in
                                                      (5) Working with the NCPC’s Division                   603.13, 603.14 and 603.15;                            making a determination about an
                                                    Directors or designated staff to develop                    (vii) Amending Records if and when                 Individual’s rights, benefits, and
                                                    an appropriate form for collection of                    appropriate, and working with the PAO                 privileges under federal programs shall
                                                    Privacy Act information and including                    to inform recipients of former Records                be collected, to the greatest extent
                                                    in the form a Privacy Act statement                      of such amendments;                                   practicable, directly from the
                                                    explaining the purpose for collecting the                   (viii) Ensuring that System                        Individual. In deciding whether
                                                    information, how it will be used, the                    information is used only for its stated               collection of information about an
                                                    authority for such collection, its routine               purpose;                                              Individual, as opposed to a third party
                                                    uses, and the effect upon the Individual                    (ix) Establishing and overseeing                   is practicable, the NCPC shall consider
                                                    of not providing the requested                           appropriate administrative, technical,                the following:
                                                    information;                                             and physical safeguards to ensure                        (1) Whether the information sought
                                                      (6) Assisting in the development of                    security and confidentiality of Records;              can only be obtained from a third party;
                                                    new or revised SORNs;                                    and                                                      (2) Whether the cost to collect the
                                                      (7) Developing SORN reports for OMB                       (x) Working with the SAOP, the PAO                 information from an Individual is
                                                    and Congress;                                            and Configuration Control Board(CCB)                  unreasonable compared to the cost of
                                                      (8) Submitting new or revised SORNS                    on SORs, preparing a PIA, if needed,                  collecting the information from a third
                                                    to the Federal Register for publication;                 and obtaining SAOP approval for a PIA                 party;
                                                      (9) Assisting in the development of                    prior to its publication on the NCPC                     (3) Whether there is a risk of
                                                    computer matching systems;                               Web site.                                             collecting inaccurate information from a
mstockstill on DSK30JT082PROD with PROPOSALS




                                                      (10) Preparing Privacy Act, Computer                      (2) The CIO shall be responsible for               third party that could result in a
                                                    Matching, and other reports to OMB as                    implementing IT security management                   determination adverse to the Individual
                                                    required; and                                            to include security for information                   concerned;
                                                      (11) Evaluating PIA to ensure                          protected by the Privacy Act and the E-                  (4) Whether the information collected
                                                    compliance with E-Government Act                         Government Act of 2002. Specific                      from an Individual requires verification
                                                    requirements.                                            responsibilities include:                             by a third party; and
                                                      (c) Other Privacy related                                 (i) Overseeing security policy for                    (5) Whether the Individual can verify
                                                    responsibilities shall be shared by the                  privacy data; and                                     information collected from third parties.


                                               VerDate Sep<11>2014   17:34 Jul 31, 2017   Jkt 241001   PO 00000   Frm 00013   Fmt 4702   Sfmt 4702   E:\FR\FM\01AUP1.SGM   01AUP1


                                                    35702                   Federal Register / Vol. 82, No. 146 / Tuesday, August 1, 2017 / Proposed Rules

                                                      (d) The NCPC shall not Maintain                        Records including identification of all               Federal Information Systems and
                                                    Records describing how an Individual                     internal and routine uses;                            Organizations as revised from time to
                                                    exercises rights guaranteed by the First                   (6) The policies and practices of the               time or any superseding guidance
                                                    Amendment to the Constitution unless                     NCPC regarding storage, retrieval, access             offered by NIST or other federal agency
                                                    the maintenance of the Record is                         controls, retention and disposal of                   charged with the responsibility for
                                                    expressly authorized by statute or by the                Records;                                              providing recommended safeguards for
                                                    Individual about whom the Record is                        (7) The title and business address of               computerized Records subject to the
                                                    Maintained or pertinent to and within                    the agency official responsible for the               Privacy Act.
                                                    the scope of an authorized law                           identified System of Records;                           (d) NCPC shall maintain a System of
                                                    enforcement activity.                                      (8) The NCPC procedures for                         Records comprised of Office of
                                                                                                             notification to an Individual who                     Personnel Management (OPM)
                                                    § 603.5 Notice to Individuals supplying                  requests if a System of Records contains              personnel Records in accordance with
                                                    information.                                             a Record about the Individual; and                    standards prescribed by OPM and
                                                      (a) Each Individual asked to supply                      (9) The NCPC sources of Records in                  published at 5 CFR 293.106—293.107.
                                                    information about himself/herself to be                  the System.
                                                    added to a System of Records shall be                                                                          § 603.8    Employee conduct.
                                                    informed by the NCPC of the basis for                    § 603.7   Procedures to safeguard Records.               (a) Employees with duties requiring
                                                    requesting the information, its potential                   (a) The NCPC shall implement the                   access to and handling of Records shall,
                                                    use, and the consequences, if any, of not                procedures set forth in this section to               at all times, take care to protect the
                                                    supplying the information. Notice to the                 insure sufficient administrative,                     integrity, security, and confidentiality of
                                                    Individual shall state at a minimum:                     technical and physical safeguards exist               the Records.
                                                      (1) The legal authority for NCPC’s                     to protect the security and                              (b) No employee of the NCPC shall
                                                    solicitation of the information and                      confidentiality of Records. The                       disclose Records unless disclosure is
                                                    whether disclosure is mandatory or                       enumerated procedures shall also                      permitted by § 603.10(b) of this part, by
                                                    voluntary;                                               protect against any anticipated threats               NCPC’s FOIA Regulations, or disclosed
                                                      (2) The principal purpose(s) for which                 or hazards to the security of Records                 to the Individual to whom the Record
                                                    the NCPC intends to use the                              with the potential to cause substantial               pertains.
                                                    information;                                             harm, embarrassment, inconvenience, or                   (c) No employee of the NCPC shall
                                                      (3) The potential routine uses of the                  unfairness to any Individual on whom                  alter or destroy a Record unless such
                                                    information by the NCPC as published                     information is Maintained.                            Record or destruction is undertaken in
                                                    in a Systems of Records Notice; and                         (b) Manual Records subject to the                  the course of the employee’s regular
                                                      (4) The effects upon the individual, if                Privacy Act shall be maintained by the                duties or such alteration or destruction
                                                    any, of not providing all or any part of                 NCPC in a manner commensurate with                    is allowed pursuant to regulations
                                                    the requested Information to the NCPC.                   the sensitivity of the information                    published by the National Archives and
                                                      (b) When NCPC collects information                     contained in the Records. The following               Records Administration (NARA) or
                                                    on a standard form, the notice to the                    minimum safeguards or safeguards                      required by a court of competent
                                                    Individual shall either be provided on                   affording comparable protection shall                 jurisdiction. Records shall not be
                                                    the form, on a tear off sheet attached to                apply to manual Systems of Records:                   destroyed or disposed of while they are
                                                    the form, or on a separate form,                            (1) The NCPC shall post areas where                the subject of a pending request, appeal
                                                    whichever is deemed the most practical                   Records are maintained or regularly                   or lawsuit under the Privacy Act.
                                                    by the NCPC.                                             used with an appropriate warning sign
                                                      (c) NCPC may ask an Individual to                                                                            § 603.9    Government contracts.
                                                                                                             stating access to the Records shall be                  (a) When a contract provides for third
                                                    acknowledge, in writing, receipt of the                  limited to authorized persons. The
                                                    notice required by this section.                                                                               party operation of a SOR on behalf of
                                                                                                             warning shall also advise that the                    the NCPC to accomplish a NCPC
                                                    § 603.6   System of Records Notice or                    Privacy Act prescribes criminal                       function, the contract shall require that
                                                    SORN.                                                    penalties for unauthorized disclosure of              the requirements of the Privacy Act and
                                                      (a) The NCPC shall publish a notice                    Records subject to the Act.                           the rules in this part be applied to such
                                                    in the Federal Register describing each                     (2) During work hours, the NCPC shall
                                                                                                                                                                   System.
                                                    System of Records 40-days prior to the                   protect areas in which Records are                      (b) The Division Director responsible
                                                    establishment of a new or revision to an                 Maintained or regularly used by                       for the contract shall designate a NCPC
                                                    existing System of Records.                              restricting occupancy of the area to                  employee to oversee and manage the
                                                      (b) The SORN shall include:                            authorized persons or storing the                     SOR operated by the contractor.
                                                      (1) The name and location of the                       Records in a locked container and room.
                                                    System of Records. The name shall                           (3) During non-working hours, access               § 603.10    Conditions for disclosure.
                                                    identify the general purpose, and the                    to Records shall be restricted by their                 (a) Except as set forth in paragraph (b)
                                                    location shall include whether the                       storage in a locked storage container and             of this section, no Record contained in
                                                    system is located on the NCPC’s main                     room.                                                 a SOR shall be disclosed by any means
                                                    server or central files. The physical                       (4) Any lock used to secure a room                 of communication to any person, or to
                                                    address of either shall also be included.                where Records are stored shall not be                 another agency, unless prior written
                                                      (2) The categories or types of                         capable of being disengaged with a                    consent is obtained from the Individual
                                                    Individuals on whom NCPC Maintains                       master key that opens rooms other than                to whom the Record pertains.
mstockstill on DSK30JT082PROD with PROPOSALS




                                                    Records in the System of Records;                        those in which Records are stored.                      (b) The limitations on disclosure
                                                      (3) The categories or types of Records                    (c) Computerized Records subject to                contained in paragraph (a) of this
                                                    in the System;                                           the Privacy Act shall be maintained, at               section shall not apply when disclosure
                                                      (4) The statutory or Executive Order                   a minimum, subject to the safeguards                  of a Record is:
                                                    authority for Maintenance of the                         recommended by the National Institute                   (1) To employees of the NCPC for use
                                                    System;                                                  of Standards and Technology (NIST)                    in the performance of their duties;
                                                      (5) The purpose(s) or explanation of                   Special Publications 800–53,                            (2) Required by the Freedom of
                                                    why the NCPC collects the particular                     Recommended Security Controls for                     Information Act (FOIA), 5 U.S.C. 555;


                                               VerDate Sep<11>2014   17:34 Jul 31, 2017   Jkt 241001   PO 00000   Frm 00014   Fmt 4702   Sfmt 4702   E:\FR\FM\01AUP1.SGM   01AUP1


                                                                            Federal Register / Vol. 82, No. 146 / Tuesday, August 1, 2017 / Proposed Rules                                           35703

                                                       (3) For a Routine Use as described in                 request. Such request shall be made in                so by appearing in person at NCPC’s
                                                    a SORN;                                                  accordance with the requirements of                   official place of business or by written
                                                       (4) To the Bureau of Census for                       § 603.15.                                             correspondence to the NCPC Privacy
                                                    statistical purposes, provided that the                    (c) For any disclosure for which an                 Act Officer. In-person requests shall be
                                                    Record must be transferred in a form                     accounting is made, if a subsequent                   by appointment only with the Privacy
                                                    that precludes individual identification;                amendment or correction or notation of                Act Officer on a Workday during regular
                                                       (5) To an Individual who provides                     dispute is made to a Record by the                    office hours. For written requests sent
                                                    NCPC adequate written assurance that                     NCPC in accordance with the                           via the U.S. mail, the Request shall be
                                                    the Record shall be used solely for                      requirements of section 603.14, the                   directed to the Privacy Act Officer at
                                                    statistical or research purposes,                        Individual and/or agency to whom the                  NCPC’s official address listed at
                                                    provided that the Record must be                         Record was originally disclosed shall be              www.ncpc.gov. If sent via email or
                                                    transferred in a form that precludes                     informed.                                             facsimile, the request shall be directed
                                                    Individual identification;                                                                                     to the email address or facsimile
                                                       (6) To the NARA because the Record                    § 603.12 Requests for notification of the             number indicated on the NCPC Web
                                                    warrants permanent retention because                     existence of Records.
                                                                                                                                                                   site. To expedite internal handling of
                                                    of historical or other national value as                    (a) An Individual seeking to                       Privacy Act Requests, the words Privacy
                                                    determined by NARA or to permit                          determine whether a System of Records                 Act Request shall appear prominently
                                                    NARA to determine whether the Record                     contains Records pertaining to him/her                on the envelop or the subject line of an
                                                    has such value;                                          shall do so by appearing in person at                 email or facsimile cover sheet.
                                                       (7) To a law enforcement agency for                   NCPC’s official place of business or by                  (b) The Request shall:
                                                    a civil or criminal law enforcement                      written correspondence to the NCPC                       (1) State the Request is made pursuant
                                                    activity, provided that the law                          PAO. In-person requests shall be by                   to the Privacy Act;
                                                    enforcement agency must submit a                         appointment only with the PAO on a                       (2) Describe the requested Records in
                                                    written request to the NCPC specifying                   Workday during regular office hours.                  sufficient detail to enable their location
                                                    the Record(s) sought and the purpose for                 Written requests sent via the U.S. mail               including, without limitation, the dates
                                                    which they will be used;                                 shall be directed to the Privacy Act                  the Records were compiled and the
                                                       (8) To any person upon demonstration                  Officer at NCPC’s official address listed             name or identifying number of each
                                                    of compelling information that an                        at www.ncpc.gov. If sent via email or                 System of Record in which they are kept
                                                    Individual’s health or safety is at stake                facsimile, the request shall be directed              as identified in the list of NCPC’s
                                                    and provided that upon disclosure,                       to the email address or facsimile                     SORNs published on its Web site; and
                                                    notification is given to the Individual to               number indicated on the NCPC Web                         (3) State pursuant to the fee schedule
                                                    whom the Record pertains at that                         site. To expedite internal handling of                set forth in § 603.17 a willingness to pay
                                                    Individual’s last known address;                         Privacy Act Requests, the words Privacy               all fees associated with the Privacy Act
                                                       (9) To either House of Congress, and                  Act Request shall appear prominently                  Request or the maximum fee the
                                                    any committee or subcommittee thereof,                   on the envelop or the subject line of an              Requester is willing to pay.
                                                    to include joint committees of both                      email or facsimile cover sheet.                          (c) The NCPC shall require
                                                    houses and any subcommittees thereof,                       (b) The Request shall state that the               identification as follows before releasing
                                                    when a Record falls within their                         Individual is seeking information                     Records to an Individual:
                                                    jurisdiction;                                            concerning the existence of Records                      (1) An Individual Requesting Privacy
                                                       (10) To the Comptroller General, or                   about himself/herself and shall supply                Act Records in person shall present a
                                                    any of his authorized representatives, to                information describing the System                     valid, photographic form of
                                                    allow the Government Accountability                      where such Records might be                           identification such as a driver’s license,
                                                    Office to perform its duties;                            maintained as set forth in a System of                employee identification card, or
                                                       (11) Pursuant to a court order by a                   Record Notice.                                        passport that renders it possible for the
                                                    court of competent jurisdiction; and                        (c) The NCPC PAO shall notify the                  PAO to verify that the Individual is the
                                                       (12) To a consumer reporting agency                   Requester in writing within 20-                       same Individual as contained in the
                                                    trying to collect a claim of the                         Workdays of the Request whether a                     requested Records.
                                                    government as authorized by 31 U.S.C.                    System contains Records pertaining to                    (2) An Individual Requesting Privacy
                                                    3711(e).                                                 him/her unless the Records were                       Act Records by mail shall state their full
                                                                                                             compiled in reasonable anticipation of a              name, address and date of birth in their
                                                    § 603.11   Accounting of disclosures.                    civil action or proceeding or the Records             correspondence. The Request must be
                                                      (a) Except for disclosures made under                  are NCPC employee Records under the                   signed and the signature must either be
                                                    §§ 603.10(b)(1)–(2), when a Record is                    jurisdiction of the OPM. In both of the               notarized or submitted with a statement
                                                    disclosed to any person, or to another                   later cases the Request shall be denied.              signed and dated as follows: I declare
                                                    agency, NCPC shall prepare an                            If the Request is denied because the                  under penalty of perjury that the
                                                    accounting of the disclosure. The                        Record(s) is/are under the jurisdiction of            foregoing facts establishing my
                                                    accounting shall Record the date,                        the OPM, the response shall advise the                identification are true and correct.
                                                    nature, and purpose of the disclosure                    Requester to contact OPM. If the PAO                     (d) The PAO shall determine within
                                                    and the name and address of the person                   denies the Request, the response shall                20 Workdays whether to grant or deny
                                                    or agency to whom the disclosure was                     state the reason for the denial and                   an Individual’s Request for Access to
                                                    made. The NCPC shall maintain all                        advise the Requester of the right to                  the requested Record(s) and notify the
mstockstill on DSK30JT082PROD with PROPOSALS




                                                    accountings for a minimum of five years                  appeal the decision within 60 days of                 Individual in writing accordingly. The
                                                    or the life of the Record, whichever is                  the date of the letter denying the request            PAO’s response shall state his/her
                                                    greatest, after the disclosure is made.                  in accordance with the requirements set               determination and the reasons therefor.
                                                      (b) Except for disclosures under                       forth in § 603.16.                                    If the Request is denied because the
                                                    § 603.10(b)(7), accountings of all                                                                             Record(s) is/are under the jurisdiction of
                                                    disclosures shall be made available to                   § 603.13   Requests for access to Records.            the OPM, the response shall advise the
                                                    the Individual about whom the                              (a) An Individual seeking access to                 Requester to contact OPM. In the case of
                                                    disclosed Records pertains at his/her                    Records about himself/herself shall do                an Adverse Determination, the written


                                               VerDate Sep<11>2014   17:34 Jul 31, 2017   Jkt 241001   PO 00000   Frm 00015   Fmt 4702   Sfmt 4702   E:\FR\FM\01AUP1.SGM   01AUP1


                                                    35704                   Federal Register / Vol. 82, No. 146 / Tuesday, August 1, 2017 / Proposed Rules

                                                    notification shall advise the Individual                 information within a reasonable time,                 shall advise the Individual of his/her
                                                    of his/her right to appeal the Adverse                   the PAO shall reject the Request.                     right to appeal the Adverse
                                                    Determination in accordance with the                        (e) The PAO’s decision on a Request                Determination in accordance with the
                                                    requirements of § 603.16.                                for Amendment or Correction shall be in               requirements of § 603.16.
                                                                                                             writing and state the basis for the
                                                    § 603.14 Requests for Amendment or                       decision. If the Request is denied                    § 603.16 Appeals of Adverse
                                                    Correction of Records.                                                                                         Determinations.
                                                                                                             because the Record(s) is/are under the
                                                       (a) An Individual seeking to amend or                 jurisdiction of the OPM, the response                    (a) Except for appeals pursuant to
                                                    correct a Record pertaining to him/her                   shall advise the Requester to contact                 subsection (d) below, an appeal of an
                                                    that he/she believes to be inaccurate,                   OPM. In the event of an Adverse                       Adverse Determination shall be made in
                                                    irrelevant, untimely or incomplete shall                 Determination, the written notification               writing addressed to the Chairman
                                                    submit a written request to the PAO at                   shall advise the Individual of his/her                (Chairman) of the National Capital
                                                    the address listed on NCPC’s official                    right to appeal the Adverse                           Planning Commission at the address
                                                    Web site www.ncpc.gov. If sent via                       Determination in accordance with the                  listed on NCPC’s official Web site
                                                    email or facsimile, the Request shall be                 requirements of § 603.16.                             www.ncpc.gov. If sent via email or
                                                    directed to the email address or                            (f) If the PAO approves the Request                facsimile, the Request shall be directed
                                                    facsimile number indicated on the                        for Amendment or Correction, the PAO                  to the email address or facsimile
                                                    NCPC Web site. To expedite internal                      shall ensure that subject Record is                   number indicated on the NCPC Web
                                                    handling, the words Privacy Act                          amended or corrected, in whole or in                  site. To expedite internal handling, the
                                                    Request shall appear prominently on the                  part. If the PAO denies the Request for               words Privacy Act Request shall appear
                                                    envelop or the subject line of an email                  Amendment or Correction, a notation of                prominently on the envelope or the
                                                    or facsimile cover sheet.                                dispute shall be noted on the Record. If              subject line of an email or facsimile
                                                       (b) The Request shall:                                an accounting of disclosure has been                  cover sheet. An appeal of an Adverse
                                                       (1) State the Request is made pursuant                made pursuant to Section 603.11, the                  Determination shall be made within 30
                                                    to the Privacy Act;                                      PAO shall advise all previous recipients              Workdays of the date of the decision.
                                                       (2) Describe the requested Record in                  of the Record that an amendment or                       (b) An appeal of an Adverse
                                                    sufficient detail to enable its location                 correction or notation of dispute has                 Determination shall include a statement
                                                    including, without limitation, the dates                 been made and, if applicable, the                     of the legal, factual or other basis for the
                                                    the Records were compiled and the                        substance of the change.                              Requester’s objection to an Adverse
                                                    name or identifying number of the                                                                              Determination; a daytime phone number
                                                                                                             § 603.15 Requests for accounting of
                                                    System of Record in which the Record                                                                           or email where the Requester can be
                                                                                                             Record disclosures.
                                                    is kept as identified in the list of NCPC’s                                                                    reached if the Chairman requires
                                                                                                                (a) An Individual seeking information              additional information or clarification
                                                    SORNs published on its Web site;
                                                                                                             regarding an accounting of disclosure of              regarding the appeal; copies of the
                                                       (3) State in detail the reasons why the
                                                                                                             a Record pertaining to him/her made in                initial request and the PAO’s written
                                                    Record, or objectionable portion(s)
                                                                                                             accordance with § 603.11 shall submit a               response; and for an Adverse
                                                    thereof, is/are not accurate, relevant,
                                                                                                             written request to the PAO at the                     Determination regarding a fee waiver, a
                                                    timely or complete.
                                                                                                             address listed on NCPC’s official Web                 demonstration of compliance with the
                                                       (4) Include copies of documents or                    site www.ncpc.gov. If sent via email or
                                                    evidence relied upon in support of the                                                                         NCPC’s FOIA Regulations.
                                                                                                             facsimile, the Request shall be directed
                                                    Request for Amendment or Correction;                                                                              (c) The Chairman shall respond to an
                                                                                                             to the email address or facsimile
                                                    and                                                                                                            appeal of an Adverse Determination in
                                                                                                             number indicated on the NCPC Web
                                                       (5) State specifically, and in detail,                                                                      writing within 20 Workdays of receipt
                                                                                                             site. To expedite internal handling, the
                                                    the changes sought to the Record, and                                                                          of the appeal. If the Chairman grants the
                                                                                                             words Privacy Act Request shall appear
                                                    if the changes include rewriting the                                                                           appeal, the Chairman shall notify the
                                                                                                             prominently on the envelope or the
                                                    Record, or portions thereof, or adding                                                                         Requester, and the NCPC shall take
                                                                                                             subject line of an email or facsimile
                                                    new language, the Individual shall                                                                             prompt action to respond affirmatively
                                                                                                             cover sheet.
                                                    propose specific language to implement                      (b) The Request shall:                             to the original Request upon receipt of
                                                    the requested changes.                                      (1) State the Request is made pursuant             any fees that may be required. If the
                                                       (c) A request to Amend or Correct a                   to the Privacy Act; and                               Chairman denies the appeal, the letter
                                                    Record shall be submitted only if the                       (2) Describe the requested Record in               shall state the reason(s) for the denial,
                                                    Requester has previously requested and                   sufficient detail to determine whether it             a statement that the decision is final,
                                                    been granted access to the Record and                    is or is not contained in an accounting               and advise the Requester of the right to
                                                    has inspected or been given a copy of                    of disclosure.                                        seek judicial review of the denial in the
                                                    the Record.                                                 (c) The NCPC PAO shall notify the                  District Court of the United States in
                                                       (d) The PAO shall render a decision                   Requester in writing within 20-                       either the district in which the
                                                    within 20 workdays. If the Request for                   Workdays of the Request and advise if                 Requester resides, the district in which
                                                    an Amendment or Correction fails to                      the Record was included in an                         the Requester has his/her principal
                                                    meet the requirements of §§ (b)(1)–(5) of                accounting of disclosure. In the event of             place of business or the District of
                                                    this Section, the PAO shall advise the                   a disclosure, the response shall include              Columbia.
                                                    Individual of the deficiency and advise                  the date, nature, and purpose of the                     (d) The appeal of an Adverse
mstockstill on DSK30JT082PROD with PROPOSALS




                                                    what additional information is required                  disclosure and the name and address of                Determination based on OPM
                                                    to act upon the Request. The timeframe                   the person or agency to whom the                      jurisdiction of the Records shall be
                                                    for a decision on the Request shall be                   disclosure was made. If the Request is                made to OPM pursuant to 5 CFR
                                                    tolled (stopped) during the pendency of                  denied because the Record(s) is/are                   297.306.
                                                    a request for additional information and                 under the jurisdiction of the OPM, the                   (e) The NCPC shall not act on an
                                                    shall resume when the additional                         response shall advise the Requester to                appeal of an Adverse Determination if
                                                    information is received. If the Requester                contact OPM. In the event of an Adverse               the underlying Request becomes the
                                                    fails to submit the requested additional                 Determination, the written notification               subject of litigation.


                                               VerDate Sep<11>2014   17:34 Jul 31, 2017   Jkt 241001   PO 00000   Frm 00016   Fmt 4702   Sfmt 4702   E:\FR\FM\01AUP1.SGM   01AUP1


                                                                            Federal Register / Vol. 82, No. 146 / Tuesday, August 1, 2017 / Proposed Rules                                                     35705

                                                      (f) A party seeking court review of an                 information technology that collects,                 PropRegs.aspx. Follow the instructions
                                                    Adverse Determination must first appeal                  maintains, or disseminates Information                for submitting comments.
                                                    the Adverse Determination under this                     in Identifiable Form.                                   • Email: Address to regcomments@
                                                    section.                                                   (f) The SAOP shall approve and sign                 ncua.gov. Include ‘‘[Your name]—
                                                                                                             the NCPC’s PIA. If the SAOP is the                    Comments on Requirements for
                                                    § 603.17   Fees.                                         Contracting Officer for the IT system                 Insurance; National Credit Union Share
                                                      (a) The NCPC shall charge for the                      that necessitated preparation of the PIA,             Insurance Fund Equity Distributions’’ in
                                                    duplication of Records under this                        the Executive Director shall approve                  the email subject line.
                                                    subpart in accordance with the schedule                  and sign the PIA.                                       • Fax: (703) 518–6319. Use the
                                                    of fees set forth in NCPC’s FOIA                           (g) Following approval of the PIA, the              subject line described above for email.
                                                    Regulations. The NCPC shall not charge                   NCPC shall post the PIA document on
                                                    duplication fees when the Requester                      the NCPC Web site located at                            • Mail: Address to Gerard Poliquin,
                                                    asks to inspect the Records personally                   www.ncpc.gov.                                         Secretary of the Board, National Credit
                                                    but is provided copies at the discretion                                                                       Union Administration, 1775 Duke
                                                                                                               Dated: July 24, 2017.                               Street, Alexandria, Virginia 22314–
                                                    of the agency.
                                                                                                             Anne R. Schuyler,                                     3428.
                                                      (b) The NCPC shall not charge any
                                                    fees for the search for or review of                     General Counsel.                                        • Hand Delivery/Courier: Same as
                                                    Records requested by an Individual.                      [FR Doc. 2017–15882 Filed 7–31–17; 8:45 am]           mail address.
                                                                                                             BILLING CODE 7502–02–P
                                                    § 603.18   Privacy Impact Assessments.                                                                         PUBLIC INSPECTION: You can view all
                                                                                                                                                                   public comments on NCUA’s Web site
                                                      (a) Consistent with the requirements                                                                         at http://www.ncua.gov/Legal/Regs/
                                                    of the E-Government Act and OMB                          NATIONAL CREDIT UNION                                 Pages/PropRegs.aspx as submitted,
                                                    Memorandum M–03–22, the NCPC shall                       ADMINISTRATION                                        except for those we cannot post for
                                                    conduct a PIA before:                                                                                          technical reasons. NCUA will not edit or
                                                      (1) Developing or procuring IT                         12 CFR Part 741
                                                                                                                                                                   remove any identifying or contact
                                                    systems or projects that collect,                        RIN 3133–AE77                                         information from the public comments
                                                    maintain, or disseminate IFF; or
                                                                                                                                                                   submitted. You may inspect paper
                                                      (2) Installing a new collection of                     Requirements for Insurance; National                  copies of comments in NCUA’s law
                                                    information that will be collected,                      Credit Union Share Insurance Fund                     library at 1775 Duke Street, Alexandria,
                                                    maintained, or disseminated using IT                     Equity Distributions                                  Virginia 22314–3428, by appointment
                                                    and includes IFF for 10 or more persons
                                                                                                             AGENCY: National Credit Union                         weekdays between 9 a.m. and 3 p.m. To
                                                    (excluding agencies, instrumentalities or
                                                                                                             Administration (NCUA).                                make an appointment, call (703) 518–
                                                    employees of the federal government).
                                                                                                             ACTION: Notice of proposed rulemaking.
                                                                                                                                                                   6546 or send an email to OGCMail@
                                                      (b) The PIA shall be prepared through
                                                                                                                                                                   ncua.gov.
                                                    the coordinated effort of the NCPC’s
                                                    privacy Officers (SAOP, PAO), Division                   SUMMARY:   The NCUA Board (Board)
                                                                                                                                                                   FOR FURTHER INFORMATION CONTACT:
                                                    Directors, CIO, and IT staff.                            proposes to amend its share insurance
                                                                                                                                                                   Benjamin M. Litchfield, Staff Attorney,
                                                      (c) As a general rule, the level of                    requirements rule to provide federally
                                                                                                                                                                   Office of General Counsel, at (703) 518–
                                                    detail and content of a PIA shall be                     insured credit unions (FICUs) with
                                                                                                                                                                   6540; or Steve Farrar, Supervisory
                                                    commensurate with the nature of the                      greater transparency regarding the
                                                                                                                                                                   Financial Analyst, Office of
                                                    information to be collected and the size                 calculation of a FICU’s proportionate
                                                                                                                                                                   Examination and Insurance, at (703)
                                                    and complexity of the IT system                          share of a declared equity distribution
                                                                                                                                                                   518–6360. You may also contact them at
                                                    involved. Specifically, a PIA shall                      from the National Credit Union Share
                                                                                                                                                                   the National Credit Union
                                                    analyze and describe:                                    Insurance Fund (NCUSIF) and to add a
                                                                                                                                                                   Administration, 1775 Duke Street,
                                                      (1) The information to be collected;                   temporary provision to govern NCUSIF
                                                                                                                                                                   Alexandria, Virginia 22314–3428.
                                                      (2) The reason the information is                      equity distributions resulting from the
                                                                                                             Corporate System Resolution Program.                  SUPPLEMENTARY INFORMATION:
                                                    being collected;
                                                      (3) The intended use for the                           The Board also proposes to prohibit a                 I. Background
                                                    information;                                             FICU that terminates federal share                    II. Section-by-Section Analysis
                                                      (4) The identity of those with whom                    insurance coverage during a particular                III. Technical and Conforming Amendments
                                                                                                             calendar year from receiving an NCUSIF                IV. Regulatory Procedures
                                                    the information will be shared;
                                                      (5) The opportunities Individuals                      equity distribution for that calendar year            I. Background
                                                    have to decline to provide the                           to provide greater fairness to FICUs that
                                                    information or to consent to particular                  remain federally insured. The Board                     NCUA is the chartering authority for
                                                    uses and how to consent;                                 proposes to make technical and                        federal credit unions and the federal
                                                      (6) The manner in which the                            conforming amendments to other                        share insurer for FICUs.1 In NCUA’s
                                                    information will be secured; and                         aspects of the share insurance                        capacity as federal share insurer, the
                                                      (7) The extent to which the system of                  requirements rule in light of these                   Board, among other things, administers
                                                    records is being created under the                       proposed changes.                                     the NCUSIF, a revolving fund created
                                                    Privacy Act.                                             DATES: Comments must be received on                   within the United States Treasury to
                                                      (d) In addition to the information                     or before Tuesday, September 5, 2017.
mstockstill on DSK30JT082PROD with PROPOSALS




                                                                                                                                                                     1 NCUA’s authority to charter federal credit
                                                    specified in §§ (b)(1)–(7) above, the PIA                ADDRESSES: You may submit comments
                                                                                                                                                                   unions is contained in Title I of the Federal Credit
                                                    must also identify the choices NCPC                      by any of the following methods (Please               Union Act (12 U.S.C. 1752–1775), and its various
                                                    made regarding an IT system or                           send comments by one method only):                    authorities as federal share insurer are contained in
                                                    collection of information as result of                     • Federal eRulemaking Portal: http://               Title II of the Federal Credit Union Act (12 U.S.C.
                                                    preparing the PIA.                                       www.regulations.gov. Follow the                       1781–1790e). Title III of the Federal Credit Union
                                                                                                                                                                   Act (12 U.S.C. 1795–1795k) governs the Board’s
                                                      (e) The CCB shall verify that a PIA has                instructions for submitting comments.                 responsibilities overseeing the NCUA Central
                                                    been prepared prior to approving a                          • NCUA Web site: http://                           Liquidity Facility, a federal instrumentality that
                                                    request to develop or procure                            www.ncua.gov/Legal/Regs/Pages/                        provides liquidity for member credit unions.



                                               VerDate Sep<11>2014   17:34 Jul 31, 2017   Jkt 241001   PO 00000   Frm 00017   Fmt 4702   Sfmt 4702   E:\FR\FM\01AUP1.SGM   01AUP1



Document Created: 2018-10-24 11:44:59
Document Modified: 2018-10-24 11:44:59
CategoryRegulatory Information
CollectionFederal Register
sudoc ClassAE 2.7:
GS 4.107:
AE 2.106:
PublisherOffice of the Federal Register, National Archives and Records Administration
SectionProposed Rules
ActionProposed rule.
DatesSubmit comments on or before August 31, 2017.
ContactAnne R. Schuyler, General Counsel at 202-482-7223, [email protected]
FR Citation82 FR 35697 

2025 Federal Register | Disclaimer | Privacy Policy
USC | CFR | eCFR