82_FR_43816 82 FR 43637 - Privacy Act of 1974; System of Records

82 FR 43637 - Privacy Act of 1974; System of Records

DEPARTMENT OF STATE

Federal Register Volume 82, Issue 179 (September 18, 2017)

Page Range43637-43640
FR Document2017-19818

Ombudsperson Mechanism Records includes information about individuals who have submitted requests relating to national security access to data transmitted to the United States pursuant to the Privacy Shield Framework Ombudsperson Mechanism and any similar mechanism established between the United States and another country or countries. The system assists in the overall management of the request review process and the provision of responses thereto by facilitating accurate and up-to-date record keeping.

Federal Register, Volume 82 Issue 179 (Monday, September 18, 2017)
[Federal Register Volume 82, Number 179 (Monday, September 18, 2017)]
[Notices]
[Pages 43637-43640]
From the Federal Register Online  [www.thefederalregister.org]
[FR Doc No: 2017-19818]


=======================================================================
-----------------------------------------------------------------------

DEPARTMENT OF STATE

[Public Notice: 10126]


Privacy Act of 1974; System of Records

AGENCY: Department of State.

ACTION: Notice of a New System of Records.

-----------------------------------------------------------------------

SUMMARY: Ombudsperson Mechanism Records includes information about 
individuals who have submitted requests relating to national security 
access to data transmitted to the United States pursuant to the Privacy 
Shield

[[Page 43638]]

Framework Ombudsperson Mechanism and any similar mechanism established 
between the United States and another country or countries. The system 
assists in the overall management of the request review process and the 
provision of responses thereto by facilitating accurate and up-to-date 
record keeping.

DATES: In accordance with 5 U.S.C. 552a(e)(4) and (11), this system of 
records notice is effective upon publication, with the exception of the 
routine uses that are subject to a 30-day period during which 
interested persons may submit comments to the Department. Please submit 
any comments by October 18, 2017.

ADDRESSES: Questions can be submitted by mail or email. If mail, please 
write to: U.S Department of State; Office of Global Information 
Systems, Privacy Staff; A/GIS/PRV; SA-2, Suite 8100; Washington, DC 
20522-0208. If email, please address the email to the Chief Privacy 
Officer, Margaret P. Grafeld, at [email protected]. Please write 
``Ombudsperson Mechanism Records, State-83'' on the envelope or the 
subject line of your email.

FOR FURTHER INFORMATION CONTACT: Margaret P. Grafeld, Chief Privacy 
Officer; U.S. Department of State; Office of Global Information 
Services, A/GIS/PRV; SA-2, Suite 8100; Washington, DC 20522-0208.

SUPPLEMENTARY INFORMATION: None.
SYSTEM NAME AND NUMBER:
    Ombudsperson Mechanism Records, State-83.

SECURITY CLASSIFICATION:
    Unclassified.

SYSTEM LOCATION:
    Department of State (``Department''), located at 2201 C Street NW., 
Washington, DC 20520, and within a government cloud provided, 
implemented, and overseen by the Department's Enterprise Server 
Operations Center (ESOC), 2201 C Street NW., Washington, DC 20520.

SYSTEM MANAGER(S):
    International Communication and Information Policy Officer for 
Europe, Office of Communications & Information Policy, Bureau of 
Economic and Business Affairs; U.S. Department of State, 2201 C St. 
Washington, DC 20520. System Managers can be reached at (202) 647-8784.

AUTHORITY FOR MAINTENANCE OF THE SYSTEM:
    (a) State Department Basic Authorities Act of 1956, as amended (22 
U.S.C. 2708 et seq.); (b) Privacy Shield Framework (81 FR 51042).

PURPOSE(S) OF THE SYSTEM:
    The EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy 
Shield Framework create a mechanism for companies on both sides of the 
Atlantic to comply with EU data protection requirements when 
transferring personal data from the European Union and Switzerland, 
respectively, to the United States in support of transatlantic 
commerce. The Frameworks each established an Ombudsperson Mechanism to 
address appropriate inquiries by individuals relating to U.S. 
Intelligence Community access to personal data transmitted from the EU 
or Switzerland to the United States through Privacy Shield and related 
commercial transfer mechanisms. The information will be used by the 
Ombudsperson to ensure that requests are properly investigated and 
addressed in a timely manner, and that the relevant U.S. laws have been 
complied with or, if the laws have been violated, that the situation 
has been remedied.

CATEGORIES OF INDIVIDUALS COVERED BY THE SYSTEM:
    Individuals whose requests relating to national security access to 
data transmitted from the European Union to the United States under the 
Privacy Shield Framework (81 FR 51042), and the EU-U.S. Privacy Shield 
Ombudsperson Mechanism Regarding Signals Intelligence (``Ombudsperson 
Mechanism'') thereunder, are submitted by the ``EU individual complaint 
handling body'' to the Department. Individuals who submit requests 
relating to national security access to data transmitted under any 
similar mechanism established between the United States and another 
country or countries. The Privacy Act defines an individual at 5 U.S.C. 
552a(a)(2) as a United States citizen or lawful permanent resident.

CATEGORIES OF RECORDS IN THE SYSTEM:
    These records may include biographic and contact information, such 
as name, address, email address, phone number, and information about 
residency or nationality, as well as other information that requesters 
and foreign government officials include in the requests submitted to 
the Department. The records also may include information about an 
individual's request and the processing of that request.

RECORD SOURCE CATEGORIES:
    Individuals who submit requests for review under the Privacy Shield 
Ombudsperson Mechanism or similar arrangement are the primary source of 
record information, although that information is provided to the 
Department by the EU Individual Complaint Handling Body or 
corresponding body under similar arrangements. Additional information 
necessary to process individual requests may be provided by these 
bodies as well as other federal agencies.

ROUTINE USES OF RECORDS MAINTAINED IN THE SYSTEM, INCLUDING CATEGORIES 
OF USERS AND PURPOSES OF SUCH USES:
    The information in Ombudsperson Mechanism Records may be disclosed:
    A. To other Federal Agencies or bodies to facilitate the 
consideration, processing and resolution of requests consistent with 
Section 2 of the Ombudsperson Mechanism (accessed via https://www.state.gov/e/privacyshield/ombud/).
    B. To an EU individual complaint handling body and any other 
complaint handling body established under a similar arrangement with 
another country to coordinate the discharge of commitments made 
therein. For example, the Privacy Shield Ombudsperson will communicate 
directly with the EU individual complaint handling body regarding 
requests submitted pursuant to the Ombudsperson Mechanism for reasons 
including acknowledging receipt of the request from the EU individual 
complaint handling body, requesting additional information necessary to 
perfect the request, and providing a final response. The EU individual 
complaint handling body will in turn be responsible for all 
communications with individuals who submit requests.
    C. To a contractor of the Department having need for the 
information in the performance of the contract, but not operating a 
system of records within the meaning of 5 U.S.C. 552a(m).
    D. To appropriate agencies, entities, and persons when (1) the 
Department of State suspects or has confirmed that there has been a 
breach of the system of records; (2) the Department of State has 
determined that as a result of the suspected or confirmed breach there 
is a risk of harm to individuals, the Department of State (including 
its information systems, programs, and operations), the Federal 
Government, or national security; and (3) the disclosure made to such 
agencies, entities, and persons is reasonably necessary to assist in 
connection with the Department of State efforts to respond to the 
suspected or confirmed breach or to prevent, minimize, or remedy such 
harm.

[[Page 43639]]

    E. To another Federal agency or Federal entity, when the Department 
of State determines that information from this system of records is 
reasonably necessary to assist the recipient agency or entity in (1) 
responding to a suspected or confirmed breach or (2) preventing, 
minimizing, or remedying the risk of harm to individuals, the recipient 
agency or entity (including its information systems, programs, and 
operations), the Federal Government, or national security, resulting 
from a suspected or confirmed breach.
    F. To an agency, whether federal, state, local or foreign, where a 
record indicates a violation or potential violation of law, whether 
civil, criminal or regulatory in nature, and whether arising by general 
statute or particular program statute, or by regulation, rule or order 
issued pursuant thereto, so that the recipient agency can fulfill its 
responsibility to investigate or prosecute such violation or enforce or 
implement the statute, rule, regulation, or order.
    G. To the Federal Bureau of Investigation, the Department of 
Homeland Security, the National Counter-Terrorism Center (NCTC), the 
Terrorist Screening Center (TSC), or other appropriate federal 
agencies, for the integration and use of such information to protect 
against terrorism, if that record is about one or more individuals 
known, or suspected, to be or to have been involved in activities 
constituting, in preparation for, in aid of, or related to terrorism. 
Such information may be further disseminated by recipient agencies to 
Federal, State, local, territorial, tribal, and foreign government 
authorities, and to support private sector processes as contemplated in 
Homeland Security Presidential Directive/HSPD-6 and other relevant laws 
and directives, for terrorist screening, threat-protection and other 
homeland security purposes.
    H. To a congressional office from the record of an individual in 
response to an inquiry from the Congressional office made at the 
request of that individual.
    I. To a court, adjudicative body, or administrative body before 
which the Department is authorized to appear when (a) the Department; 
(b) any employee of the Department in his or her official capacity; (c) 
any employee of the Department in his or her individual capacity where 
the U.S. Department of Justice (``DOJ'') or the Department has agreed 
to represent the employee; or (d) the Government of the United States, 
when the Department determines that litigation is likely to affect the 
Department, is a party to litigation or has an interest in such 
litigation, and the use of such records by the Department is deemed to 
be relevant and necessary to the litigation or administrative 
proceeding.
    J. To the Department of Justice (``DOJ'') for its use in providing 
legal advice to the Department or in representing the Department in a 
proceeding before a court, adjudicative body, or other administrative 
body before which the Department is authorized to appear, where the 
Department deems DOJ's use of such information relevant and necessary 
to the litigation, and such proceeding names as a party or interests:
    (a) The Department or any component of it;
    (b) Any employee of the Department in his or her official capacity;
    (c) Any employee of the Department in his or her individual 
capacity where DOJ has agreed to represent the employee; or
    (d) The Government of the United States, where the Department 
determines that litigation is likely to affect the Department or any of 
its components.
    K. To the National Archives and Records Administration and the 
General Services Administration: For records management inspections, 
surveys and studies; following transfer to a Federal records center for 
storage; and to determine whether such records have sufficient 
historical or other value to warrant accessioning into the National 
Archives of the United States.

POLICIES AND PRACTICES FOR STORAGE OF RECORDS:
    Records are stored both in hard copy and on electronic media. A 
description of standard Department of State policies concerning storage 
of electronic records is found here https://fam.state.gov/FAM/05FAM/05FAM0440.html. All hard copies of records containing personal 
information are maintained in secured file cabinets in restricted 
areas, access to which is limited to authorized personnel only.

POLICIES AND PRACTICES FOR RETRIEVAL OF RECORDS:
    By individual name or other personal identifier, if available, and 
by a tracking number.

POLICIES AND PRACTICES FOR RETENTION AND DISPOSAL OF RECORDS:
    The Department of State is in the process of developing a retention 
schedule for these records. Once the schedule is approved by the 
National Archives and Records Administration, the Records will be 
retired in accordance with published Department of State Records 
Disposition Schedule that shall be published here: https://foia.state.gov/Learn/RecordsDisposition.aspx. More specific information 
may be obtained by writing to U.S. Department of State; Director, 
Office of Information Programs and Services; A/GIS/IPS; SA-2, Suite 
8100; Washington, DC 20522-0208.

ADMINISTRATIVE, TECHNICAL, AND PHYSICAL SAFEGUARDS:
    All users are given cyber security awareness training that covers 
the procedures for handling Sensitive but Unclassified information, 
including personally identifiable information (PII). Annual refresher 
training is mandatory. In addition, all Foreign Service and Civil 
Service employees and those Locally Employed Staff who handle PII are 
required to take the Foreign Service Institute distance learning course 
instructing employees on privacy and security requirements, including 
the rules of behavior for handling PII and the potential consequences 
if it is handled improperly. Before being granted access to 
Ombudsperson Mechanism Records, a user must first be granted access to 
the Department of State computer system.
    Department of State employees and contractors may remotely access 
this system of records using non-Department owned information 
technology. Such access is subject to approval by the Department's 
access program, and is limited to information maintained in 
unclassified information systems. Remote access to the Department's 
information systems is configured in compliance with OMB Circular A-130 
multifactor authentication requirements and includes a time-out 
function.
    All Department of State employees and contractors with authorized 
access to records maintained in this system of records have undergone a 
thorough background security investigation. Access to the Department of 
State, its annexes and posts abroad is controlled by security guards 
and admission is limited to those individuals possessing a valid 
identification card or individuals under proper escort. While the 
majority of records in Ombudsperson Mechanism will be in an electronic 
format, paper mailings from the EU individual complaint handling body 
could be included in the system. All paper records containing personal 
information are maintained in secured file cabinets in restricted 
areas, access to which is limited to authorized personnel only. Access 
to computerized files is password-protected and under the direct 
supervision of the system manager. The system manager has the 
capability of printing audit trails of access from the computer media,

[[Page 43640]]

thereby permitting regular and ad hoc monitoring of computer usage.
    When it is determined that a user no longer needs access, the user 
account is disabled. The Department of State will store records 
maintained in this system of records in cloud systems. All cloud 
systems that provide IT services and process Department of State 
information must be authorized to operate by the Department of State 
Authorizing Official and Senior Agency Official for Privacy. Only 
information that conforms with Department-specific definitions for 
FISMA low or moderate categorization are permissible for cloud usage 
unless specifically authorized by the Department's Cloud Computing 
Governance Board. The categorization of information in this system of 
records is designated as low. Prior to operation, all Cloud systems 
must comply with applicable security measures that are outlined in 
FISMA, FedRAMP, OMB guidance, NIST Federal Information Processing 
Standards (FIPS) and Special Publications, and Department of State 
policy and standards.

RECORD ACCESS PROCEDURES:
    Individuals who wish to gain access to or to amend records 
pertaining to themselves should write to U.S. Department of State; 
Director, Office of Information Programs and Services; A/GIS/IPS; SA-2, 
Suite 8100; Washington, DC 20522-0208. The individual must specify that 
he or she wishes the Ombudsperson Mechanism Records to be checked. At a 
minimum, the individual must include: Full name (including maiden name, 
if appropriate) and any other names used; current mailing address and 
zip code; date and place of birth; notarized signature or statement 
under penalty of perjury; a brief description of the circumstances that 
caused the creation of the record (including the city and/or country 
and the approximate dates) which gives the individual cause to believe 
that the Ombudsperson Mechanism Records include records pertaining to 
him or her. Detailed instructions on Department of State procedures for 
accessing and amending records can be found at https://foia.state.gov/Request/Guide.aspx.

CONTESTING RECORD PROCEDURES:
    Individuals who wish to contest record procedures should write to 
U.S. Department of State; Director, Office of Information Programs and 
Services; A/GIS/IPS; SA-2, Suite 8100; Washington, DC 20522-0208.

NOTIFICATION PROCEDURES:
    Individuals who have reason to believe that this system of records 
may contain information pertaining to them may write to U.S. Department 
of State; Director, Office of Information Programs and Services; A/GIS/
IPS; SA-2, Suite 8100; Washington, DC 20522-0208. The individual must 
specify that he or she wishes the Ombudsperson Mechanism Records to be 
checked. At a minimum, the individual must include: Full name 
(including maiden name, if appropriate) and any other names used; 
current mailing address and zip code; date and place of birth; 
notarized signature or statement under penalty of perjury; a brief 
description of the circumstances that caused the creation of the record 
(including the city and/or country and the approximate dates) which 
gives the individual cause to believe that the Ombudsperson Mechanism 
Records include records pertaining to him or her.

EXEMPTIONS PROMULGATED FOR THE SYSTEM:
    None.

HISTORY:
    None.

Mary R. Avery,
Senior Agency Official for Privacy, Senior Advisor, Office of Global 
Information Services, Bureau of Administration, Department of State.
[FR Doc. 2017-19818 Filed 9-15-17; 8:45 am]
 BILLING CODE 4710-24-P



                                                                          Federal Register / Vol. 82, No. 179 / Monday, September 18, 2017 / Notices                                                  43637

                                                SMALL BUSINESS ADMINISTRATION                           granting a request for a class waiver of              manufacturer or processor, if the
                                                                                                        the Nonmanufacturer Rule (NMR) for                    recipient is other than the actual
                                                [Disaster Declaration # 15245 and #15246;
                                                NEW HAMPSHIRE Disaster Number NH–
                                                                                                        Positive Airway Pressure Devices and                  manufacturer or processor of the
                                                00038]                                                  Supplies Manufacturing. This U.S.                     product. This requirement is commonly
                                                                                                        industry comprises establishments                     referred to as the Nonmanufacturer Rule
                                                Presidential Declaration Amendment of                   primarily engaged in manufacturing                    (NMR). 13 CFR 121.406(b). Sections
                                                a Major Disaster for Public Assistance                  Continuous Positive Airway Pressure                   8(a)(17)(B)(iv)(II) and 46(a)(4)(B) of the
                                                Only for the State of New Hampshire                     (CPAP) devices, Bi-level Positive                     Act authorize SBA to waive the NMR for
                                                                                                        Airway Pressure (BiPAP) devices, and                  a ‘‘class of products’’ for which there are
                                                AGENCY: U.S. Small Business                             other products intended to treat sleep                no small business manufacturers or
                                                Administration.                                         apnea by keeping a person’s airways                   processors available to participate in the
                                                ACTION: Amendment 1.                                    open during sleep. According to the                   Federal market.
                                                                                                        request, no small business                               As implemented in SBA’s regulations
                                                SUMMARY:   This is an amendment of the
                                                                                                        manufacturers supply this product to                  at 13 CFR 121.1202(c), in order to be
                                                Presidential declaration of a major
                                                                                                        the Federal government. If granted, the               considered available to participate in
                                                disaster for Public Assistance Only for
                                                                                                        class waiver would allow otherwise                    the Federal market for a class of
                                                the State of New Hampshire (FEMA–
                                                                                                        qualified regular dealers to supply the               products, a small business manufacturer
                                                4329–DR), dated August 9, 2017.
                                                                                                        product of any manufacturer on a                      must have submitted a proposal for a
                                                DATES: Issued on September 11, 2017.                    Federal contract set aside for small
                                                  Physical Loan Application Deadline                                                                          contract solicitation or been awarded a
                                                                                                        business, service-disabled veteran-                   contract to supply the class of products
                                                Date: 10/09/2017.                                       owned small business (SDVOSB),
                                                  Economic Injury (EIDL) Loan                                                                                 within the last 24 months.
                                                                                                        women-owned small business (WOSB),                       The SBA defines ‘‘class of products’’
                                                Application Deadline Date: 05/09/2018.
                                                                                                        economically disadvantaged women-                     based on a combination of (1) the six
                                                ADDRESSES: Submit completed loan                        owned small business (EDWOSB), or                     digit North American Industry
                                                applications to: U.S. Small Business                    participants in the SBA’s 8(a) Business               Classification System (NAICS) code, (2)
                                                Administration, Processing and                          Development (BD) program.                             the four digit Product Service Code
                                                Disbursement Center, 14925 Kingsport
                                                                                                        DATES: Comments and source                            (PSC), and (3) a description of the class
                                                Road, Fort Worth, TX 76155.                             information must be submitted by                      of products.
                                                FOR FURTHER INFORMATION CONTACT: A.                     October 18, 2017.                                        The SBA is currently processing a
                                                Escobar, Office of Disaster Assistance,                 ADDRESSES: You may submit comments                    request to waive the NMR for Positive
                                                U.S. Small Business Administration,                     and source information via the Federal                Airway Pressure Devices and Supplies
                                                409 3rd Street SW., Suite 6050,                         Rulemaking Portal at https://                         under NAICS codes 339112 and 339113,
                                                Washington, DC 20416, (202) 205–6734.                   www.regulations.gov under Docket ID                   PSC 6515. The public is invited to
                                                SUPPLEMENTARY INFORMATION: The notice                   SBA–2017–0006. If you wish to submit                  comment or provide source information
                                                of the President’s major disaster                       confidential business information (CBI)               on any small business manufacturers of
                                                declaration for Private Non-Profit                      as defined in the User Notice at http://              this class of products that are available
                                                organizations in the State of New                       www.regulations.gov, please submit the                to participate in the Federal market. The
                                                Hampshire, dated 08/09/2017, is hereby                  information to Roman Ivey, Program                    public comment period will run for 30
                                                amended to include the following areas                  Analyst, Office of Government                         days after the date of publication in the
                                                as adversely affected by the disaster.                  Contracting, U.S. Small Business                      Federal Register.
                                                  Incident: Severe Storms and Flooding.                 Administration, 409 Third Street SW.,                    More information on the NMR and
                                                  Incident Period: 07/01/2017 through                                                                         Class Waivers can be found at https://
                                                                                                        8th Floor, Washington, DC 20416, and
                                                07/02/2017.                                                                                                   www.sba.gov/contracting/contracting-
                                                                                                        highlight the information that you
                                                Primary Counties: Coos.                                                                                       officials/non-manufacturer-rule/non-
                                                                                                        consider to be CBI and explain why you
                                                  All other information in the original                 believe this information should be held               manufacturer-waivers.
                                                declaration remains unchanged.                          confidential. SBA will review the                       Dated: September 6, 2017.
                                                (Catalog of Federal Domestic Assistance                 information and make a final                          Seán F. Crean,
                                                Number 59008)                                           determination as to whether or not the                Director, Office of Government Contracting.
                                                James E. Rivera,                                        information will be published.                        [FR Doc. 2017–19457 Filed 9–15–17; 8:45 am]
                                                Associate Administrator for Disaster                    FOR FURTHER INFORMATION CONTACT:
                                                                                                                                                              BILLING CODE 8025–01–P
                                                Assistance.                                             Roman Ivey, Program Analyst, by
                                                [FR Doc. 2017–19735 Filed 9–15–17; 8:45 am]             telephone at 202–401–1420; or by email
                                                BILLING CODE 8025–01–P                                  at roman.ivey@sba.gov.
                                                                                                                                                              DEPARTMENT OF STATE
                                                                                                        SUPPLEMENTARY INFORMATION: Section
                                                                                                        8(a)(17) and 46 of the Small Business                 [Public Notice: 10126]
                                                SMALL BUSINESS ADMINISTRATION                           Act (Act), 15 U.S.C. 637(a)(17) and 657,
                                                                                                        and SBA’s implementing regulations                    Privacy Act of 1974; System of
                                                Small Business Size Standards: Class                    require that recipients of Federal supply             Records
                                                Waiver of the Nonmanufacturer Rule                      contracts (except those valued between                AGENCY:  Department of State.
                                                AGENCY: U.S. Small Business                             $3,500 and $150,000) set aside for small              ACTION:Notice of a New System of
                                                                                                        business, service-disabled veteran-
sradovich on DSKBBY8HB2PROD with NOTICES




                                                Administration.                                                                                               Records.
                                                ACTION: Notice of Intent To Waive the                   owned small business (SDVOSB),
                                                Nonmanufacturer Rule for Positive                       women-owned small business (WOSB),                    SUMMARY:   Ombudsperson Mechanism
                                                Airway Pressure Devices and Supplies                    economically disadvantaged women-                     Records includes information about
                                                Manufacturing.                                          owned small business (EDWOSB), or                     individuals who have submitted
                                                                                                        participants in the SBA’s 8(a) Business               requests relating to national security
                                                SUMMARY: The U.S. Small Business                        Development (BD) program provide the                  access to data transmitted to the United
                                                Administration (SBA) is considering                     product of a small business                           States pursuant to the Privacy Shield


                                           VerDate Sep<11>2014   16:54 Sep 15, 2017   Jkt 241001   PO 00000   Frm 00124   Fmt 4703   Sfmt 4703   E:\FR\FM\18SEN1.SGM   18SEN1


                                                43638                     Federal Register / Vol. 82, No. 179 / Monday, September 18, 2017 / Notices

                                                Framework Ombudsperson Mechanism                        et seq.); (b) Privacy Shield Framework                Ombudsperson Mechanism or similar
                                                and any similar mechanism established                   (81 FR 51042).                                        arrangement are the primary source of
                                                between the United States and another                                                                         record information, although that
                                                                                                        PURPOSE(S) OF THE SYSTEM:
                                                country or countries. The system assists                                                                      information is provided to the
                                                in the overall management of the                           The EU–U.S. Privacy Shield                         Department by the EU Individual
                                                request review process and the                          Framework and the Swiss-U.S. Privacy                  Complaint Handling Body or
                                                provision of responses thereto by                       Shield Framework create a mechanism                   corresponding body under similar
                                                facilitating accurate and up-to-date                    for companies on both sides of the                    arrangements. Additional information
                                                record keeping.                                         Atlantic to comply with EU data                       necessary to process individual requests
                                                                                                        protection requirements when                          may be provided by these bodies as well
                                                DATES: In accordance with 5 U.S.C.                      transferring personal data from the
                                                552a(e)(4) and (11), this system of                                                                           as other federal agencies.
                                                                                                        European Union and Switzerland,
                                                records notice is effective upon                        respectively, to the United States in                 ROUTINE USES OF RECORDS MAINTAINED IN THE
                                                publication, with the exception of the                  support of transatlantic commerce. The                SYSTEM, INCLUDING CATEGORIES OF USERS AND
                                                routine uses that are subject to a 30-day               Frameworks each established an                        PURPOSES OF SUCH USES:
                                                period during which interested persons                  Ombudsperson Mechanism to address
                                                may submit comments to the                                                                                       The information in Ombudsperson
                                                                                                        appropriate inquiries by individuals                  Mechanism Records may be disclosed:
                                                Department. Please submit any                           relating to U.S. Intelligence Community
                                                comments by October 18, 2017.                                                                                    A. To other Federal Agencies or
                                                                                                        access to personal data transmitted from              bodies to facilitate the consideration,
                                                ADDRESSES: Questions can be submitted                   the EU or Switzerland to the United                   processing and resolution of requests
                                                by mail or email. If mail, please write to:             States through Privacy Shield and                     consistent with Section 2 of the
                                                U.S Department of State; Office of                      related commercial transfer                           Ombudsperson Mechanism (accessed
                                                Global Information Systems, Privacy                     mechanisms. The information will be                   via https://www.state.gov/e/
                                                Staff; A/GIS/PRV; SA–2, Suite 8100;                     used by the Ombudsperson to ensure
                                                                                                                                                              privacyshield/ombud/).
                                                Washington, DC 20522–0208. If email,                    that requests are properly investigated
                                                please address the email to the Chief                   and addressed in a timely manner, and                    B. To an EU individual complaint
                                                Privacy Officer, Margaret P. Grafeld, at                that the relevant U.S. laws have been                 handling body and any other complaint
                                                Privacy@state.gov. Please write                         complied with or, if the laws have been               handling body established under a
                                                ‘‘Ombudsperson Mechanism Records,                       violated, that the situation has been                 similar arrangement with another
                                                State-83’’ on the envelope or the subject               remedied.                                             country to coordinate the discharge of
                                                line of your email.                                                                                           commitments made therein. For
                                                                                                        CATEGORIES OF INDIVIDUALS COVERED BY THE              example, the Privacy Shield
                                                FOR FURTHER INFORMATION CONTACT:                        SYSTEM:                                               Ombudsperson will communicate
                                                Margaret P. Grafeld, Chief Privacy                         Individuals whose requests relating to             directly with the EU individual
                                                Officer; U.S. Department of State; Office               national security access to data                      complaint handling body regarding
                                                of Global Information Services, A/GIS/                  transmitted from the European Union to                requests submitted pursuant to the
                                                PRV; SA–2, Suite 8100; Washington, DC                   the United States under the Privacy                   Ombudsperson Mechanism for reasons
                                                20522–0208.                                             Shield Framework (81 FR 51042), and                   including acknowledging receipt of the
                                                SUPPLEMENTARY INFORMATION: None.                        the EU–U.S. Privacy Shield                            request from the EU individual
                                                                                                        Ombudsperson Mechanism Regarding                      complaint handling body, requesting
                                                SYSTEM NAME AND NUMBER:
                                                                                                        Signals Intelligence (‘‘Ombudsperson                  additional information necessary to
                                                  Ombudsperson Mechanism Records,                       Mechanism’’) thereunder, are submitted                perfect the request, and providing a
                                                State-83.                                               by the ‘‘EU individual complaint                      final response. The EU individual
                                                                                                        handling body’’ to the Department.                    complaint handling body will in turn be
                                                SECURITY CLASSIFICATION:
                                                                                                        Individuals who submit requests                       responsible for all communications with
                                                   Unclassified.                                        relating to national security access to               individuals who submit requests.
                                                SYSTEM LOCATION:
                                                                                                        data transmitted under any similar                       C. To a contractor of the Department
                                                                                                        mechanism established between the                     having need for the information in the
                                                  Department of State (‘‘Department’’),                 United States and another country or                  performance of the contract, but not
                                                located at 2201 C Street NW.,                           countries. The Privacy Act defines an                 operating a system of records within the
                                                Washington, DC 20520, and within a                      individual at 5 U.S.C. 552a(a)(2) as a                meaning of 5 U.S.C. 552a(m).
                                                government cloud provided,                              United States citizen or lawful
                                                implemented, and overseen by the                                                                                 D. To appropriate agencies, entities,
                                                                                                        permanent resident.                                   and persons when (1) the Department of
                                                Department’s Enterprise Server
                                                Operations Center (ESOC), 2201 C Street                 CATEGORIES OF RECORDS IN THE SYSTEM:                  State suspects or has confirmed that
                                                NW., Washington, DC 20520.                                These records may include biographic                there has been a breach of the system of
                                                                                                        and contact information, such as name,                records; (2) the Department of State has
                                                SYSTEM MANAGER(S):
                                                                                                        address, email address, phone number,                 determined that as a result of the
                                                   International Communication and                      and information about residency or                    suspected or confirmed breach there is
                                                Information Policy Officer for Europe,                  nationality, as well as other information             a risk of harm to individuals, the
                                                Office of Communications &                              that requesters and foreign government                Department of State (including its
                                                Information Policy, Bureau of Economic                  officials include in the requests                     information systems, programs, and
                                                                                                                                                              operations), the Federal Government, or
sradovich on DSKBBY8HB2PROD with NOTICES




                                                and Business Affairs; U.S. Department                   submitted to the Department. The
                                                of State, 2201 C St. Washington, DC                     records also may include information                  national security; and (3) the disclosure
                                                20520. System Managers can be reached                   about an individual’s request and the                 made to such agencies, entities, and
                                                at (202) 647–8784.                                      processing of that request.                           persons is reasonably necessary to assist
                                                                                                                                                              in connection with the Department of
                                                AUTHORITY FOR MAINTENANCE OF THE SYSTEM:                RECORD SOURCE CATEGORIES:                             State efforts to respond to the suspected
                                                 (a) State Department Basic Authorities                   Individuals who submit requests for                 or confirmed breach or to prevent,
                                                Act of 1956, as amended (22 U.S.C. 2708                 review under the Privacy Shield                       minimize, or remedy such harm.


                                           VerDate Sep<11>2014   16:54 Sep 15, 2017   Jkt 241001   PO 00000   Frm 00125   Fmt 4703   Sfmt 4703   E:\FR\FM\18SEN1.SGM   18SEN1


                                                                          Federal Register / Vol. 82, No. 179 / Monday, September 18, 2017 / Notices                                              43639

                                                   E. To another Federal agency or                      Department is deemed to be relevant                   foia.state.gov/Learn/Records
                                                Federal entity, when the Department of                  and necessary to the litigation or                    Disposition.aspx. More specific
                                                State determines that information from                  administrative proceeding.                            information may be obtained by writing
                                                this system of records is reasonably                       J. To the Department of Justice                    to U.S. Department of State; Director,
                                                necessary to assist the recipient agency                (‘‘DOJ’’) for its use in providing legal              Office of Information Programs and
                                                or entity in (1) responding to a                        advice to the Department or in                        Services; A/GIS/IPS; SA–2, Suite 8100;
                                                suspected or confirmed breach or (2)                    representing the Department in a                      Washington, DC 20522–0208.
                                                preventing, minimizing, or remedying                    proceeding before a court, adjudicative
                                                                                                                                                              ADMINISTRATIVE, TECHNICAL, AND PHYSICAL
                                                the risk of harm to individuals, the                    body, or other administrative body                    SAFEGUARDS:
                                                recipient agency or entity (including its               before which the Department is
                                                information systems, programs, and                                                                              All users are given cyber security
                                                                                                        authorized to appear, where the
                                                operations), the Federal Government, or                                                                       awareness training that covers the
                                                                                                        Department deems DOJ’s use of such
                                                national security, resulting from a                                                                           procedures for handling Sensitive but
                                                                                                        information relevant and necessary to
                                                suspected or confirmed breach.                                                                                Unclassified information, including
                                                                                                        the litigation, and such proceeding
                                                   F. To an agency, whether federal,                                                                          personally identifiable information (PII).
                                                                                                        names as a party or interests:
                                                state, local or foreign, where a record                    (a) The Department or any component                Annual refresher training is mandatory.
                                                indicates a violation or potential                      of it;                                                In addition, all Foreign Service and
                                                violation of law, whether civil, criminal                  (b) Any employee of the Department                 Civil Service employees and those
                                                or regulatory in nature, and whether                    in his or her official capacity;                      Locally Employed Staff who handle PII
                                                arising by general statute or particular                   (c) Any employee of the Department                 are required to take the Foreign Service
                                                program statute, or by regulation, rule or              in his or her individual capacity where               Institute distance learning course
                                                order issued pursuant thereto, so that                  DOJ has agreed to represent the                       instructing employees on privacy and
                                                the recipient agency can fulfill its                    employee; or                                          security requirements, including the
                                                responsibility to investigate or prosecute                 (d) The Government of the United                   rules of behavior for handling PII and
                                                such violation or enforce or implement                  States, where the Department                          the potential consequences if it is
                                                the statute, rule, regulation, or order.                determines that litigation is likely to               handled improperly. Before being
                                                   G. To the Federal Bureau of                          affect the Department or any of its                   granted access to Ombudsperson
                                                Investigation, the Department of                        components.                                           Mechanism Records, a user must first be
                                                Homeland Security, the National                            K. To the National Archives and                    granted access to the Department of
                                                Counter-Terrorism Center (NCTC), the                    Records Administration and the General                State computer system.
                                                Terrorist Screening Center (TSC), or                    Services Administration: For records                    Department of State employees and
                                                other appropriate federal agencies, for                 management inspections, surveys and                   contractors may remotely access this
                                                the integration and use of such                         studies; following transfer to a Federal              system of records using non-Department
                                                information to protect against terrorism,               records center for storage; and to                    owned information technology. Such
                                                if that record is about one or more                     determine whether such records have                   access is subject to approval by the
                                                individuals known, or suspected, to be                  sufficient historical or other value to               Department’s access program, and is
                                                or to have been involved in activities                  warrant accessioning into the National                limited to information maintained in
                                                constituting, in preparation for, in aid                Archives of the United States.                        unclassified information systems.
                                                of, or related to terrorism. Such                                                                             Remote access to the Department’s
                                                                                                        POLICIES AND PRACTICES FOR STORAGE OF                 information systems is configured in
                                                information may be further
                                                                                                        RECORDS:                                              compliance with OMB Circular A–130
                                                disseminated by recipient agencies to
                                                Federal, State, local, territorial, tribal,                Records are stored both in hard copy               multifactor authentication requirements
                                                and foreign government authorities, and                 and on electronic media. A description                and includes a time-out function.
                                                to support private sector processes as                  of standard Department of State policies                All Department of State employees
                                                contemplated in Homeland Security                       concerning storage of electronic records              and contractors with authorized access
                                                Presidential Directive/HSPD–6 and                       is found here https://fam.state.gov/                  to records maintained in this system of
                                                other relevant laws and directives, for                 FAM/05FAM/05FAM0440.html. All                         records have undergone a thorough
                                                terrorist screening, threat-protection and              hard copies of records containing                     background security investigation.
                                                other homeland security purposes.                       personal information are maintained in                Access to the Department of State, its
                                                   H. To a congressional office from the                secured file cabinets in restricted areas,            annexes and posts abroad is controlled
                                                record of an individual in response to                  access to which is limited to authorized              by security guards and admission is
                                                an inquiry from the Congressional office                personnel only.                                       limited to those individuals possessing
                                                made at the request of that individual.                 POLICIES AND PRACTICES FOR RETRIEVAL OF
                                                                                                                                                              a valid identification card or individuals
                                                   I. To a court, adjudicative body, or                 RECORDS:                                              under proper escort. While the majority
                                                administrative body before which the                      By individual name or other personal                of records in Ombudsperson Mechanism
                                                Department is authorized to appear                      identifier, if available, and by a tracking           will be in an electronic format, paper
                                                when (a) the Department; (b) any                        number.                                               mailings from the EU individual
                                                employee of the Department in his or                                                                          complaint handling body could be
                                                her official capacity; (c) any employee of              POLICIES AND PRACTICES FOR RETENTION AND              included in the system. All paper
                                                the Department in his or her individual                 DISPOSAL OF RECORDS:                                  records containing personal information
                                                capacity where the U.S. Department of                     The Department of State is in the                   are maintained in secured file cabinets
                                                Justice (‘‘DOJ’’) or the Department has                 process of developing a retention                     in restricted areas, access to which is
sradovich on DSKBBY8HB2PROD with NOTICES




                                                agreed to represent the employee; or (d)                schedule for these records. Once the                  limited to authorized personnel only.
                                                the Government of the United States,                    schedule is approved by the National                  Access to computerized files is
                                                when the Department determines that                     Archives and Records Administration,                  password-protected and under the
                                                litigation is likely to affect the                      the Records will be retired in                        direct supervision of the system
                                                Department, is a party to litigation or                 accordance with published Department                  manager. The system manager has the
                                                has an interest in such litigation, and                 of State Records Disposition Schedule                 capability of printing audit trails of
                                                the use of such records by the                          that shall be published here: https://                access from the computer media,


                                           VerDate Sep<11>2014   16:54 Sep 15, 2017   Jkt 241001   PO 00000   Frm 00126   Fmt 4703   Sfmt 4703   E:\FR\FM\18SEN1.SGM   18SEN1


                                                43640                     Federal Register / Vol. 82, No. 179 / Monday, September 18, 2017 / Notices

                                                thereby permitting regular and ad hoc                   NOTIFICATION PROCEDURES:                              in command authority, are being
                                                monitoring of computer usage.                              Individuals who have reason to                     investigated, prosecuted, and
                                                  When it is determined that a user no                  believe that this system of records may               appropriately sanctioned, and military
                                                longer needs access, the user account is                contain information pertaining to them                officers credibly alleged to have
                                                disabled. The Department of State will                  may write to U.S. Department of State;                committed such crimes are removed
                                                store records maintained in this system                 Director, Office of Information Programs              from positions of command authority
                                                of records in cloud systems. All cloud                  and Services; A/GIS/IPS; SA–2, Suite                  until the completion of judicial
                                                systems that provide IT services and                    8100; Washington, DC 20522–0208. The                  proceedings; and
                                                process Department of State information                 individual must specify that he or she                   (3) The Government of Colombia is
                                                                                                        wishes the Ombudsperson Mechanism                     continuing to dismantle illegal armed
                                                must be authorized to operate by the
                                                                                                        Records to be checked. At a minimum,                  groups, taking effective steps to protect
                                                Department of State Authorizing Official
                                                                                                        the individual must include: Full name                the rights of human rights defenders,
                                                and Senior Agency Official for Privacy.
                                                                                                        (including maiden name, if appropriate)               journalists, trade unionists, and other
                                                Only information that conforms with
                                                                                                        and any other names used; current                     social activists, and protecting the rights
                                                Department-specific definitions for
                                                                                                        mailing address and zip code; date and                and territory of indigenous and Afro-
                                                FISMA low or moderate categorization                    place of birth; notarized signature or                Colombian communities.
                                                are permissible for cloud usage unless                  statement under penalty of perjury; a
                                                specifically authorized by the                                                                                   This Certification shall be published
                                                                                                        brief description of the circumstances                in the Federal Register and, along with
                                                Department’s Cloud Computing                            that caused the creation of the record                the accompanying Report and
                                                Governance Board. The categorization of                 (including the city and/or country and                Memorandum of Justification, shall be
                                                information in this system of records is                the approximate dates) which gives the                transmitted to the appropriate
                                                designated as low. Prior to operation, all              individual cause to believe that the                  committees of Congress.
                                                Cloud systems must comply with                          Ombudsperson Mechanism Records
                                                applicable security measures that are                                                                           Dated: September 11, 2017.
                                                                                                        include records pertaining to him or
                                                outlined in FISMA, FedRAMP, OMB                                                                               Rex W. Tillerson,
                                                                                                        her.
                                                guidance, NIST Federal Information                                                                            Secretary of State.
                                                Processing Standards (FIPS) and Special                 EXEMPTIONS PROMULGATED FOR THE SYSTEM:                [FR Doc. 2017–19837 Filed 9–15–17; 8:45 am]
                                                Publications, and Department of State                     None.                                               BILLING CODE 4710–29–P
                                                policy and standards.                                   HISTORY:
                                                                                                          None.
                                                RECORD ACCESS PROCEDURES:
                                                                                                        Mary R. Avery,                                        OFFICE OF THE UNITED STATES
                                                   Individuals who wish to gain access
                                                                                                        Senior Agency Official for Privacy, Senior            TRADE REPRESENTATIVE
                                                to or to amend records pertaining to
                                                                                                        Advisor, Office of Global Information
                                                themselves should write to U.S.                         Services, Bureau of Administration,                   Senior Executive Service Performance
                                                Department of State; Director, Office of                Department of State.                                  Review Board Members
                                                Information Programs and Services; A/                   [FR Doc. 2017–19818 Filed 9–15–17; 8:45 am]
                                                GIS/IPS; SA–2, Suite 8100; Washington,                                                                        AGENCY: Office of the United States
                                                                                                        BILLING CODE 4710–24–P
                                                DC 20522–0208. The individual must                                                                            Trade Representative.
                                                specify that he or she wishes the                                                                             ACTION: Notice.
                                                Ombudsperson Mechanism Records to                       DEPARTMENT OF STATE
                                                be checked. At a minimum, the                                                                                 SUMMARY:   The Office of the United
                                                                                                        [Public Notice: 10130]                                States Trade Representative (USTR) is
                                                individual must include: Full name
                                                (including maiden name, if appropriate)                 Certification Related to Foreign Military             publishing the names of the members
                                                and any other names used; current                       Financing for Colombia Under Section                  selected to serve on its Senior Executive
                                                mailing address and zip code; date and                  7045(b)(6) of the Department of State,                Service Performance Review Board
                                                place of birth; notarized signature or                  Foreign Operations, and Related                       (PRB). This notice supersedes all
                                                statement under penalty of perjury; a                   Programs Appropriations Act, 2017                     previous PRB membership notices.
                                                brief description of the circumstances                                                                        FOR FURTHER INFORMATION CONTACT: Ron
                                                that caused the creation of the record                    Pursuant to the authority vested in the             Nerida, Human Capital Specialist,
                                                (including the city and/or country and                  Secretary of State, including under                   Office of Human Capital and Services, at
                                                the approximate dates) which gives the                  section 7045(b)(6) of the Department of               (202) 395–7360 or RNerida@
                                                individual cause to believe that the                    State, Foreign Operations, and Related                ustr.eop.gov.
                                                Ombudsperson Mechanism Records                          Programs Appropriations Act, 2017
                                                                                                        (Div. J, Pub. L. 115–31) I hereby certify             SUPPLEMENTARY INFORMATION:     Provisions
                                                include records pertaining to him or
                                                                                                        and report that:                                      of the Civil Service Reform Act of 1978,
                                                her. Detailed instructions on
                                                                                                          (1) The Peace Tribunal and other                    as amended (5 U.S.C. 4314(c)(1)–(5)),
                                                Department of State procedures for
                                                                                                        judicial bodies within the special                    require USTR to establish a PRB to
                                                accessing and amending records can be
                                                                                                        jurisdiction for peace are independent                review and evaluate the initial appraisal
                                                found at https://foia.state.gov/Request/
                                                                                                        and have authority to document ‘‘truth                of a senior executive’s performance by
                                                Guide.aspx.
                                                                                                        declarations’’ from perpetrators of gross             the supervisor, and make
                                                                                                        violations of human rights and to                     recommendations regarding
sradovich on DSKBBY8HB2PROD with NOTICES




                                                CONTESTING RECORD PROCEDURES:
                                                                                                        sentence such perpetrators to                         performance ratings to the United States
                                                  Individuals who wish to contest                       meaningful sanctions, including                       Trade Representative or his designee.
                                                record procedures should write to U.S.                  victims’ reparations, guarantee of non-               The Act (5 U.S.C. 4314(c)(4)) requires
                                                Department of State; Director, Office of                repetition, and deprivation of liberty;               USTR to publish the PRB membership
                                                Information Programs and Services; A/                     (2) Military personnel responsible for              in the Federal Register. The following
                                                GIS/IPS; SA–2, Suite 8100; Washington,                  ordering, committing, or covering up                  individuals have been selected to serve
                                                DC 20522–0208.                                          cases of false positives, including those             on USTR’s PRB:


                                           VerDate Sep<11>2014   16:54 Sep 15, 2017   Jkt 241001   PO 00000   Frm 00127   Fmt 4703   Sfmt 4703   E:\FR\FM\18SEN1.SGM   18SEN1



Document Created: 2017-09-16 00:51:45
Document Modified: 2017-09-16 00:51:45
CategoryRegulatory Information
CollectionFederal Register
sudoc ClassAE 2.7:
GS 4.107:
AE 2.106:
PublisherOffice of the Federal Register, National Archives and Records Administration
SectionNotices
ActionNotice of a New System of Records.
DatesIn accordance with 5 U.S.C. 552a(e)(4) and (11), this system of records notice is effective upon publication, with the exception of the routine uses that are subject to a 30-day period during which interested persons may submit comments to the Department. Please submit any comments by October 18, 2017.
ContactMargaret P. Grafeld, Chief Privacy Officer; U.S. Department of State; Office of Global Information Services, A/GIS/PRV; SA-2, Suite 8100; Washington, DC 20522-0208.
FR Citation82 FR 43637 

2025 Federal Register | Disclaimer | Privacy Policy
USC | CFR | eCFR