82_FR_44225 82 FR 44044 - Privacy Act Regulations

82 FR 44044 - Privacy Act Regulations

NATIONAL CAPITAL PLANNING COMMISSION

Federal Register Volume 82, Issue 181 (September 20, 2017)

Page Range44044-44052
FR Document2017-19996

The National Capital Planning Commission (NCPC or Commission) hereby adopts new regulations governing NCPC's implementation of the Privacy Act, as amended and the privacy provisions of the E-Government Act of 2002. NCPC must comply with the requirements of the Privacy Act and the privacy provisions of the E-Government Act of 2002 for records maintained on individuals and personal information stored as a hard copy or electronically.

Federal Register, Volume 82 Issue 181 (Wednesday, September 20, 2017)
[Federal Register Volume 82, Number 181 (Wednesday, September 20, 2017)]
[Rules and Regulations]
[Pages 44044-44052]
From the Federal Register Online  [www.thefederalregister.org]
[FR Doc No: 2017-19996]


-----------------------------------------------------------------------

NATIONAL CAPITAL PLANNING COMMISSION

1 CFR Parts 455 and 603


Privacy Act Regulations

AGENCY: National Capital Planning Commission.

ACTION: Final rule.

-----------------------------------------------------------------------

SUMMARY: The National Capital Planning Commission (NCPC or Commission) 
hereby adopts new regulations governing NCPC's implementation of the 
Privacy Act, as amended and the privacy provisions of the E-Government 
Act of 2002. NCPC must comply with the requirements of the Privacy Act 
and the privacy provisions of the E-Government Act of 2002 for records 
maintained on individuals and personal information stored as a hard 
copy or electronically.

DATES: This rule is effective October 20, 2017.

FOR FURTHER INFORMATION CONTACT: Anne R. Schuyler, General Counsel at 
202-482-7223, [email protected].

SUPPLEMENTARY INFORMATION: NCPC adopted its current Privacy Regulations 
(1 CFR part 455) in 1977 pursuant to 5 U.S.C. 552a. Since that time, 
Congress amended the Privacy Act multiple times including the E-
Government Act of 2002 which addressed requirements for maintaining 
electronic privacy records. The regulations update NCPC's existing 
Privacy Regulations to reflect amendments over time. The Office of the 
Federal Register recently assigned NCPC a new chapter of 1 CFR--Chapter 
VI--to allow NCPC to group all its regulations together in one chapter.
    NCPC eliminates its Privacy Regulations at 1 CFR part 455 and 
codifies the new Privacy Regulations at 1 CFR part 603.

I. Section by Section Analysis of NCPC's Privacy Act Regulations

    Sec.  603.1 Purpose and scope. This section advises the purpose of 
the regulations is to implement a privacy program consistent with the 
requirements of the Privacy Act and the privacy related provision of 
the E-Government Act of 2002. As stated in the section, NCPC's privacy 
program extends to all Records maintained by NCPC in a System of 
Records; the responsibilities of NCPC to safeguard this information; 
the procedures by which Individuals may request notification of the 
existence of a Record about them, access to Records about them, an 
amendment to or correction of the Records about them, and an accounting 
of disclosures of those Records by the NCPC; the procedures by which an 
Individual may appeal an Adverse Determination, and the conduct of a 
Privacy Impact Assessment.
    Sec.  603.2 Definitions. This section defines terms frequently used 
in the regulations. The section includes the five terms defined in the 
existing regulations--Individual, Maintain, Record, Routine Use and 
System of Records. It adds the definitions for the following terms: 
Adverse Determination, E-Government Act of 2002, Information in 
Identifiable Form (IIF), Information Technology, Privacy Act Officer 
(PAO), Privacy Act, Privacy Impact Assessment (PIA), Record, Requester, 
Request for Access to a Record, Request for Amendment or Correction of 
a Record, Senior Agency Official for Privacy (SAOP), System of Records 
Notice (SORN), and Workday.
    Sec.  603.3 Privacy Act program responsibilities. This section 
requires NCPC to designate a SAOP and a PAO and outlines the 
responsibilities associated with both positions. It also enumerates the 
Privacy Act responsibilities of other NCPC personnel.
    Sec.  603.4 Standards used to Maintain Records. This section 
establishes the standards NCPC must follow regarding privacy 
information. The section requires NCPC to limit private information to 
only that necessary to achieve the purposes for which it is collected 
and stored; to ensure all information collected is accurate, relevant, 
timely, and complete; and to collect privacy information regarding an 
Individual's rights, benefits and privileges under federal programs 
from the Individual to the maximum extent possible subject to 
collection from third parties in certain circumstances.
    Sec.  603.5 Notice to Individuals supplying information. This 
section enumerates the information NCPC must provide Individuals who 
are asked to supply information about themselves. The required 
information enumerated includes the purpose for which NCPC intends to 
use the information; the effects upon an Individual for not providing 
the information; and the form of notice NCPC must supply in response to 
an Individual's provision of information.
    Sec.  603.6 System of Records (SOR) Notice (SORN). This section 
requires NCPC to publish a notice in the Federal Register describing 
each SOR 40-days before establishing a new or revising an existing SOR. 
The section requires the SORN to include the purpose of the Records and 
their location; the types of Individuals contained in the SOR; the

[[Page 44045]]

authority for maintaining the SOR; the purpose or reason why NCPC 
collects the Records and their intended routine uses; the sources of 
the Records in the SOR; the policies and practices regarding storage, 
retrieval, access controls, retention, and disposal of the Records; the 
identification of the agency official responsible for the SOR; and the 
procedures for notifying an Individual who requests whether the SOR 
contains information about him/her.
    Sec.  603.7 Procedures to safeguard Records. This section describes 
the procedures utilized by NCPC to safeguard hard copy and computerized 
records subject to the Privacy Act. The section requires hard copy 
Records to be stored in a locked room subject to restricted access with 
external posted warning signs limiting access to authorized personnel 
and/or stored in a locked container with identical precautions to those 
used for a locked room. The section requires computerized Records to be 
maintained subject to the Safeguards recommended by the National 
Institute of Standards and Technology (NIST).
    Sec.  603.8 Employee conduct. This section requires employees with 
duties requiring access to and handling of Records to do so in a manner 
that protects the integrity, security and confidentiality of the 
Records. It prohibits employee disclosure of records unless authorized 
by the rules in this part, permitted by NCPC's FOIA regulations (1 CFR 
part 602), or disclosed to the Individual to whom the Record pertains. 
The section also prohibits destruction or alteration of Records unless 
required as part of an employee's regular duties, required by 
regulations published by the National Archives Record Administration 
(NARA), or required by a court of law.
    Sec.  603.9 Government contracts. This section requires contractors 
operating a System of Records on behalf of NCPC to abide by the 
requirements of the Privacy Act. It also equires a NCPC employee to 
oversee and manage the SOR operated by a contractor.
    Sec.  603.10 Conditions for disclosure. Subject to a list of 
enumerated exceptions, this section precludes disclosure of a Record 
contained in a SOR unless prior written consent is obtained from the 
Individual to whom the record pertains.
    Sec.  603.11 Accounting of disclosures. This section requires NCPC 
to prepare an accounting of disclosure when a Record is disclosed to 
any person or to another agency.
    The section requires the contents of an accounting to include the 
date, nature, and purpose of the disclosure and the name and address of 
the person or agency to whom the disclosure was made. The section also 
requires Accountings of disclosures to be made available to the 
Individual about whom the disclosed Record pertains except under 
limited circumstances. It further requires changes to disclosed Records 
to be shared with the person or agency to whom the Record was 
originally disclosed.
    Sec.  603.12 Requests for notification of the existence of Records. 
This section advises Individuals how to determine whether a System of 
Records maintained by NCPC contains Records pertaining to them. It 
requires Individuals either to contact NCPC in writing or appear at 
NCPC's offices by appointment to make the subject request. The section 
requires the NCPC PAO to respond to a request in writing within 20 
Workdays, to include in the response the Reason(s) for the PAO's 
determination, and to advise the requester of the right to appeal the 
decision.
    Sec.  603.13 Request for access to Records. This section advises 
Individuals how to access NCPC records about themselves. It requires 
Individuals to request the right to access Records either in writing or 
to appear at NCPC's offices by appointment. The section enumerates the 
information required to be included in a request, and obligates 
Individuals to present certain specified identification to access the 
requested Records. The section also requires the NCPC PAO to respond to 
a request for access in writing within 20 Workdays, to state in the 
response the reason for the PAO's determination, and to advise the 
Requester of the right to appeal an Adverse Determination.
    Sec.  603.14 Requests for amendment or correction of Records. This 
section outlines the process Individuals must follow to amend or 
correct Records about them that they believe are inaccurate, 
irrelevant, untimely or incomplete. The section requires a request for 
amendment or correction to be in writing, include certain specified 
information, and to be made only if the Individual has previously 
requested and been granted access to the Record. The section also 
requires the NCPC PAO to respond to a request for amendment or 
correction in writing within 20 Workdays, to state the reason for the 
PAO's determination in the response, to advise the requester of the 
right to appeal an Adverse Determination, to ensure the Record is 
amended or corrected in whole or in part if the PAO approves the 
request, and to place a notation of a dispute on the Record if the 
request is denied.
    Sec.  603.15 Requests for an accounting of Records disclosures. 
This section outlines the process Individuals must follow to obtain 
information about disclosures of Records pertaining to them. It 
requires a request for information about Records disclosed to include 
certain specified information. The section also requires the NCPC PAO 
to respond to a request for information about disclosures in writing 
within 20 Workdays, to include, in the event of a disclosure, the date, 
nature and purpose of the disclosure, the name and address of the 
person or agency to whom the disclosure was made. The section further 
requires the PAO to state the reason for his/her determination and to 
advise the requester of the right to appeal an Adverse Determination.
    Sec.  602.16 Appeals of Adverse Determinations. This section 
describes the process Individuals must follow to appeal an Adverse 
Determination. As defined in the definition section of the regulations 
Adverse Determination means a decision to withhold any requested Record 
in whole or in part; a decision that the requested Record does not 
exist or cannot be located; a decision that the requested information 
is not a Record subject to the Privacy Act; a decision that a Record, 
or part thereof, does not require amendment or correction; a decision 
to refuse to disclose an accounting of disclosure; and a decision to 
deny a fee waiver. The term also encompasses a challenge to NCPC's 
determination that Records have not been described adequately, that 
there are no responsive Records, or that an adequate search has been 
conducted. The section requires an Individual to submit a written 
appeal to the Chairman of the Commission stating the legal, factual or 
other basis for the Appeal, and it requires the Chairman to provide a 
written response within 30 Workdays. The section also requires NCPC to 
take prompt action to respond affirmatively to the Individual's 
original request if the Chairman grants the request and to state the 
reasons for a denial and the right to appeal the denial to a court of 
competent jurisdiction.
    Sec.  603.17 Fees. This section states the fees to be charged for 
the search for and duplication of Records. It advises fees for 
duplication shall be those established by NCPC's FOIA Regulations, and 
it states there are no fees for the search or review of Records 
requested by an Individual.
    Sec.  603.18 Privacy Impact Assessments. This section states when 
NCPC must conduct a Privacy Impact Assessment (PIA), the contents of a 
PIA, and the process for approving the PIA. The section requires a PIA 
to be

[[Page 44046]]

conducted before developing or procuring an IT system that collects, 
maintains or disseminates Information that identifies an Individual 
(IIF or Information in Identifiable Form) or when NCPC installs a new 
collection of IIF for 10 or more persons other than employees, or 
agencies of the federal government. The section also requires a PIA to 
analyze a number of factors related to the collection, use, owner, 
storage and manner of securing the IIF, and it requires the PIA to be 
approved and posted on NCPC's Web site prior to undertaking the action 
that required the PIA.

II. Summary of and Response to Comments

    NCPC published a proposed rule addressing revisions to its current 
Privacy Act Regulations in the Federal Register on August 1, 2017 for a 
30-day public comment period. The public comment period closed on 
August 31, 2017.
    NCPC received no comments on its proposed Privacy Act Regulations. 
Consequently, the proposed Privacy Act Regulations are now being 
advertised as the final Privacy Act Regulations.

III. Compliance With Laws and Executive Orders

Executive Orders 12866 and 13563

    By Memorandum dated October 12, 1993 from Sally Katzen, 
Administrator, Office of Information and Regulatory Affairs (OIRA) to 
Heads of Executive Departments and Agencies, and Independent Agencies, 
OMB rendered the NCPC exempt from the requirements of Executive Order 
12866 (See, Appendix A of cited Memorandum). Nonetheless, NCPC 
endeavors to adhere to the provisions of Executive Orders and developed 
this rule in a manner consistent with the requirements of Executive 
Order 13563.

Executive Order 13771

    By virtue of its exemption from the requirements of EO 12866, NCPC 
is exempted from this Executive Order. NCPC confirmed this fact with 
OIRA.

Regulatory Flexibility Act

    As required by the Regulatory Flexibility Act (5 U.S.C. 601 et 
seq.), the NCPC certifies that the rule will not have a significant 
economic effect on a substantial number of small entities.

Small Business Regulatory Enforcement Fairness Act

    This is not a major rule under 5 U.S.C. 804(2), the Small Business 
Regulatory Enforcement Fairness Act. It does not have an annual effect 
on the economy of $100 million or more; will not cause a major increase 
in costs for individuals, various levels of governments or various 
regions; and does not have a significant adverse effect on completion, 
employment, investment, productivity, innovation or the competitiveness 
of US enterprises with foreign enterprises.

Unfunded Mandates Reform Act (2 U.S.C. 1531 et seq.)

    A statement regarding the Unfunded Mandates Reform Act is not 
required. The rule neither imposes an unfunded mandate of more than 
$100 million per year nor imposes a significant or unique effect on 
State, local or tribal governments or the private sector.

Federalism (Executive Order 13132)

    In accordance with Executive Order 13132, the rule does not have 
sufficient federalism implications to warrant the preparation of a 
Federalism Assessment. The rule does not substantially and directly 
affect the relationship between the Federal and state governments.

Civil Justice Reform (Executive Order 12988)

    The General Counsel of NCPC has determined that the rule does not 
unduly burden the judicial system and meets the requirements of 
Executive Order 12988 3(a) and 3(b)(2).

Paperwork Reduction Act

    The rule does not contain information collection requirements, and 
it does not require a submission to the Office of Management and Budget 
under the Paperwork Reduction Act.

9. National Environmental Policy Act

    The rule is of an administrative nature, and its adoption does not 
constitute a major federal action significantly affecting the quality 
of the human environment. NCPC's adoption of the rule will have minimal 
or no effect on the environment; impose no significant change to 
existing environmental conditions; and will have no cumulative 
environmental impacts.

10. Clarity of the Regulation

    Executive Order 12866, Executive Order 12988, and the Presidential 
Memorandum of June 1, 1998 requires the NCPC to write all rules in 
plain language. NCPC maintains the rule meets this requirement. Those 
individuals reviewing the rule who believe otherwise should submit 
specific comments to the addresses noted above recommending revised 
language for those provision or portions thereof where they believe 
compliance is lacking.

11. Public Availability of Comments

    Be advised that personal information such as name, address, phone 
number, electronic address, or other identifying personal information 
contained in a comment may be made publically available. Individuals 
may ask NCPC to withhold the personal information in their comment, but 
there is no guarantee the agency can do so.

List of Subjects in 1 CFR Parts 455 and 603 Privacy

    For the reasons stated in the preamble, the National Capital 
Planning Commission amends 1 CFR Chapters IV and VI as follows:

CHAPTER IV--MISCELLANEOUS AGENCIES

PART 455--[Removed]

0
1. Under the authority of 40 U.S.C. 8711(a) remove part 455.

CHAPTER VI--NATIONAL CAPITAL PLANNING COMMISSION

0
2. Add part 603 to read as follows:

PART 603--PRIVACY ACT REGULATIONS

Sec.
603.1 Purpose and scope.
603.2 Definitions.
603.3 Privacy Act program responsibilities.
603.4 Standard used to Maintain Records.
603.5 Notice to Individuals supplying information.
603.6 System of Records Notice or SORN.
603.7 Procedures to safeguard Records.
603.8 Employee conduct.
603.9 Government contracts.
603.10 Conditions of disclosure.
603.11 Accounting for disclosures.
603.12 Requests for notification of the existence of Records.
603.13 Requests for access to Records.
603.14 Requests for Amendment or Correction of Records.
603.15 Requests for Accounting of Record disclosures.
603.16 Appeals of Adverse Determinations.
603.17 Fees.
603.18 Privacy Impact Assessments.

    Authority: 5 U.S.C. 552a as amended and 44 U.S.C. ch. 36.


Sec.  603.1  Purpose and scope.

    (a) This part contain the rules the National Capital Planning 
Commission (NCPC) shall follow to implement a privacy program as 
required by the Privacy Act of 1974, 5 U.S.C. 552a (Privacy Act or Act) 
and the privacy provisions of the E-Government Act of 2002 (44 U.S.C. 
ch. 36) (E-Government Act). These rules should be read together with 
the Privacy Act and the

[[Page 44047]]

privacy related provisions of the E-Government Act, which provide 
additional information respectively about Records maintained on 
individuals and protections for the privacy of personal information as 
agencies implement citizen-centered electronic Government.
    (b) Consistent with the requirements of the Privacy Act, the rules 
in this part apply to all Records maintained by NCPC in a System of 
Records; the responsibilities of the NCPC to safeguard this 
information; the procedures by which Individuals may request 
notification of the existence of a record, request access to Records 
about themselves, request an amendment to or correction of those 
Records, and request an accounting of disclosures of those Records by 
the NCPC; and the procedures by which an Individual may appeal an 
Adverse Determination.
    (c) Consistent with the privacy related requirements of the E-
Government Act, the rules in this part also address the conduct of a 
privacy impact assessment prior to developing or procuring information 
technology that collects, maintains, or disseminates information in an 
identifiable form, initiating a new electronic collection of 
information in identifiable form for 10 or more persons excluding 
agencies, instrumentalities or employees of the federal government, or 
changing an existing System that creates new privacy risks.
    (d) In addition to the rules in this part, the NCPC shall process 
all Privacy Act Requests for Access to Records in accordance with the 
Freedom of Information Act (FOIA), 5 U.S.C. 552, and part 602 of this 
chapter.


Sec.  603.2  Definitions.

    For purposes of this part, the following definitions shall apply:
    Adverse Determination shall mean a decision to withhold any 
requested Record in whole or in part; a decision that the requested 
Record does not exist or cannot be located; a decision that the 
requested information is not a Record subject to the Privacy Act; a 
decision that a Record, or part thereof, does not require amendment or 
correction; a decision to refuse to disclose an accounting of 
disclosure; and a decision to deny a fee waiver. The term shall also 
encompass a challenge to NCPC's determination that Records have not 
been described adequately, that there are no responsive Records or that 
an adequate search has been conducted.
    E-Government Act of 2002 shall mean Public Law 107-347, Dec. 17, 
2002, 116 Stat. 2899, the privacy portions of which are set out as a 
note under section 3501 of title 44.
    Individual shall mean a citizen of the United States or an alien 
lawfully admitted for permanent residence.
    Information in Identifiable Form (IIF) shall mean information in an 
Information Technology system or an online collection that directly 
identifies an individual, e.g., name, address, social security number 
or other identifying number or code, telephone number, email address 
and the like; or information by which the NCPC intends to identify 
specific individuals in conjunction with other data elements, e.g., 
indirect identification that may include a combination of gender, race, 
birth date, geographic identifiers, and other descriptions.
    Information Technology (IT) shall mean, as defined in the Clinger 
Cohen Act (40 U.S.C. 11101(6)), any equipment, software or 
interconnected system or subsystem that is used in the automatic 
acquisition, storage, manipulation, management, movement, control, 
display, switching, interchange, transmission or reception of data.
    Maintain shall include maintain, collect, use or disseminate a 
Record.
    Privacy Act Officer shall mean the individual within the NCPC 
charged with responsibility for coordinating and implementing NCPC's 
Privacy Act program.
    Privacy Act or Act shall mean the Privacy Act of 1974, as amended 
and codified at 5 U.S.C. 552a.
    Privacy Impact Assessment (PIA) shall mean an analysis of how 
information is handled to ensure handling conforms to applicable legal, 
regulatory, and policy requirements regarding privacy; to determine the 
risks and effects of collecting, maintaining and disseminating 
information in identifiable form in an electronic system; and to 
examine and evaluate protections and alternative processes for handling 
information to mitigate potential privacy risks.
    Record shall mean any item, collection, or grouping of information 
about an Individual that is Maintained by the NCPC, including, but not 
limited to, an Individual's education, financial transactions, medical 
history, and criminal or employment history and that contains a name, 
or identifying number, symbol, or other identifying particular assigned 
to the Individual, such as a finger or voice print or photograph.
    Requester shall mean an Individual who makes a Request for Access 
to a Record, a Request for Amendment or Correction of a Record, or a 
Request for Accounting of a Record under the Privacy Act.
    Request for Access to a Record shall mean a request by an 
Individual made to the NCPC pursuant to subsection (d)(1) of the 
Privacy Act to gain access to his/her Records or to any information 
pertaining to him/her in the system and to permit him/her, or a person 
of his/her choosing, to review and copy all or any portion thereof.
    Request for Amendment or Correction of a Record shall mean a 
request made by an Individual to the NCPC pursuant to subsection (d)(2) 
of the Privacy Act to amend or correct a Record pertaining to him/her.
    Routine Use shall mean with respect to disclosure of a Record, the 
use of such Record for a purpose which is compatible with the purpose 
for which the Record is collected.
    Senior Agency Official for Privacy (SAOP) shall mean the individual 
within NCPC responsible for establishing and overseeing the NCPC's 
Privacy Act program.
    System of Records or System (SOR or Systems) shall mean a group of 
any Records under the control of the NCPC from which information is 
retrieved by the name of the individual or by some identifying number, 
symbol, or other identifying particular assigned to the individual.
    System of Record Notice (SORN) shall mean a notice published in the 
Federal Register by the NCPC for each new or revised System of Records 
intended to solicit public comment on the System prior to 
implementation.
    Workday shall mean a regular Federal workday excluding Saturday, 
Sunday and legal Federal holidays when the federal government is 
closed.


Sec.  603.3  Privacy Act program responsibilities.

    (a) The NCPC shall designate a Senior Agency Official for Privacy 
(SAOP) to establish and oversee the NCPC's Privacy Act Program and 
ensure compliance with privacy laws, regulations and the NCPC's privacy 
policies. Specific responsibilities of the SAOP shall include:
    (1) Reporting to the Office of Management and Budget (OMB) and 
Congress on the establishment of or revision to Privacy Act Systems;
    (2) Reporting periodically to OMB on Privacy Act activities as 
required by law and OMB;
    (3) Signing Privacy Act SORNS for publication in the Federal 
Register;
    (4) Approving and signing PIAs; and
    (5) Serving as head of the agency response team when responding to 
a large-scale information breach.
    (b) The NCPC shall designate a Privacy Act Officer (PAO) to 
coordinate

[[Page 44048]]

and implement the NCPC's Privacy Act program. Specific responsibilities 
of the PAO shall include:
    (1) Developing, issuing and updating, as necessary, the NCPC's 
Privacy Act policies, standards, and procedures;
    (2) Maintaining Privacy Act program Records and documentation;
    (3) Responding to Privacy Act Requests for Records and coordinating 
appeals of Adverse Determinations for Requests for access to Records, 
Requests for Amendment or Correction of Records, and Requests for 
accounting for disclosures;
    (4) Informing Individuals of information disclosures;
    (5) Working with the NCPC's Division Directors or designated staff 
to develop an appropriate form for collection of Privacy Act 
information and including in the form a Privacy Act statement 
explaining the purpose for collecting the information, how it will be 
used, the authority for such collection, its routine uses, and the 
effect upon the Individual of not providing the requested information;
    (6) Assisting in the development of new or revised SORNs;
    (7) Developing SORN reports for OMB and Congress;
    (8) Submitting new or revised SORNS to the Federal Register for 
publication;
    (9) Assisting in the development of computer matching systems;
    (10) Preparing Privacy Act, Computer Matching, and other reports to 
OMB as required; and
    (11) Evaluating PIA to ensure compliance with E-Government Act 
requirements.
    (c) Other Privacy related responsibilities shall be shared by the 
NCPC Division Directors, the NCPC Chief Information Officer (CIO), the 
NCPC System Developers and Designers, the NCPC Configuration Control 
Board, the NCPC employees, and the Chairman of the Commission.
    (1) The NCPC Division Directors shall be responsible for 
coordinating with the PAO the implementation of the requirements set 
forth in this part for Systems of Records applicable to their area of 
management and the preparation of PIA prior to development or 
procurement of new systems that collect, maintain or disseminate IIF. 
Specific responsibilities include:
    (i) Reviewing existing SOR for need, relevance, and purpose for 
existence, and proposing SOR changes to the PAO as necessary in 
response to altered circumstances;
    (ii) Reviewing existing SOR to ensure information is accurate, 
complete and up to date;
    (iii) Coordinating with the PAO the preparation of new or revised 
SORN;
    (iv) Coordinating with the PAO the development of an appropriate 
form for collection of Privacy Act information and including in the 
form a Privacy Act statement explaining the purpose for collecting the 
information, how it will be used, the authority for such collection, 
its routine uses, and the effect upon the Individual of not providing 
the requested information;
    (v) Collecting information directly from individuals whenever 
possible;
    (vii) Assisting the PAO with providing access to Individuals who 
request information in accordance with the procedures established in 
Sec. Sec.  603.12, 603.13, 603.14 and 603.15.
    (vii) Amending Records if and when appropriate, and working with 
the PAO to inform recipients of former Records of such amendments;
    (viii) Ensuring that System information is used only for its stated 
purpose;
    (ix) Establishing and overseeing appropriate administrative, 
technical, and physical safeguards to ensure security and 
confidentiality of Records; and
    (x) Working with the SAOP, the PAO and Configuration Control Board 
(CCB) on SORs, preparing a PIA, if needed, and obtaining SAOP approval 
for a PIA prior to its publication on the NCPC Web site.
    (2) The CIO shall be responsible for implementing IT security 
management to include security for information protected by the Privacy 
Act and the E-Government Act of 2002. Specific responsibilities 
include:
    (i) Overseeing security policy for privacy data; and
    (ii) Reviewing PIAs prepared for information security 
considerations.
    (3) The NCPC System Developers and Designers shall be responsible 
for ensuring that the IT system design and specifications conform to 
privacy standards and requirements and that technical controls are in 
place for safeguarding personal information from unauthorized access.
    (4) The NCPC CCB shall, among other responsibilities, verify that a 
PIA has been prepared prior to approving a request to develop or 
procure information technology that collects, maintains, or 
disseminates Information in Identifiable Form.
    (5) The NCPC employees shall ensure that any personal information 
they use in the conduct of their official responsibilities is protected 
in accordance with the rules set forth in this part.
    (6) The Chairman of the Commission shall be responsible for acting 
on all appeals of Adverse Determinations.


Sec.  603.4  Standards used to Maintain Records.

    (a) Records Maintained by the NCPC shall contain only such 
information about an Individual as is relevant and necessary to 
accomplish a purpose NCPC must accomplish to comply with relevant 
statutes or Executive Orders of the President.
    (b) Records Maintained by the NCPC and used to make a determination 
about an Individual shall be accurate, relevant, timely, and complete 
to assure a fair determination.
    (c) Information used by the NCPC in making a determination about an 
Individual's rights, benefits, and privileges under federal programs 
shall be collected, to the greatest extent practicable, directly from 
the Individual. In deciding whether collection of information about an 
Individual, as opposed to a third party is practicable, the NCPC shall 
consider the following:
    (1) Whether the information sought can only be obtained from a 
third party;
    (2) Whether the cost to collect the information from an Individual 
is unreasonable compared to the cost of collecting the information from 
a third party;
    (3) Whether there is a risk of collecting inaccurate information 
from a third party that could result in a determination adverse to the 
Individual concerned;
    (4) Whether the information collected from an Individual requires 
verification by a third party; and
    (5) Whether the Individual can verify information collected from 
third parties.
    (d) The NCPC shall not Maintain Records describing how an 
Individual exercises rights guaranteed by the First Amendment to the 
Constitution unless the maintenance of the Record is expressly 
authorized by statute or by the Individual about whom the Record is 
Maintained or pertinent to and within the scope of an authorized law 
enforcement activity.


Sec.  603.5  Notice to Individuals supplying information.

    (a) Each Individual asked to supply information about himself/
herself to be added to a System of Records shall be informed by the 
NCPC of the basis for requesting the information, its potential use, 
and the consequences, if any, of not supplying the information. Notice 
to the Individual shall state at a minimum:
    (1) The legal authority for NCPC's solicitation of the information 
and whether disclosure is mandatory or voluntary;
    (2) The principal purpose(s) for which the NCPC intends to use the 
information;

[[Page 44049]]

    (3) The potential routine uses of the information by the NCPC as 
published in a Systems of Records Notice; and
    (4) The effects upon the individual, if any, of not providing all 
or any part of the requested Information to the NCPC.
    (b) When NCPC collects information on a standard form, the notice 
to the Individual shall either be provided on the form, on a tear off 
sheet attached to the form, or on a separate form, whichever is deemed 
the most practical by the NCPC.
    (c) NCPC may ask an Individual to acknowledge, in writing, receipt 
of the notice required by this section.


Sec.  603.6  System of Records Notice or SORN.

    (a) The NCPC shall publish a notice in the Federal Register 
describing each System of Records 40-days prior to the establishment of 
a new or revision to an existing System of Records.
    (b) The SORN shall include:
    (1) The name and location of the System of Records. The name shall 
identify the general purpose, and the location shall include whether 
the system is located on the NCPC's main server or central files. The 
physical address of either shall also be included.
    (2) The categories or types of Individuals on whom NCPC Maintains 
Records in the System of Records;
    (3) The categories or types of Records in the System;
    (4) The statutory or Executive Order authority for Maintenance of 
the System;
    (5) The purpose(s) or explanation of why the NCPC collects the 
particular Records including identification of all internal and routine 
uses;
    (6) The policies and practices of the NCPC regarding storage, 
retrieval, access controls, retention and disposal of Records;
    (7) The title and business address of the agency official 
responsible for the identified System of Records;
    (8) The NCPC procedures for notification to an Individual who 
requests if a System of Records contains a Record about the Individual; 
and
    (9) The NCPC sources of Records in the System.


Sec.  603.7  Procedures to safeguard Records.

    (a) The NCPC shall implement the procedures set forth in this 
section to insure sufficient administrative, technical and physical 
safeguards exist to protect the security and confidentiality of 
Records. The enumerated procedures shall also protect against any 
anticipated threats or hazards to the security of Records with the 
potential to cause substantial harm, embarrassment, inconvenience, or 
unfairness to any Individual on whom information is Maintained.
    (b) Manual Records subject to the Privacy Act shall be maintained 
by the NCPC in a manner commensurate with the sensitivity of the 
information contained in the Records. The following minimum safeguards 
or safeguards affording comparable protection shall apply to manual 
Systems of Records:
    (1) The NCPC shall post areas where Records are maintained or 
regularly used with an appropriate warning sign stating access to the 
Records shall be limited to authorized persons. The warning shall also 
advise that the Privacy Act prescribes criminal penalties for 
unauthorized disclosure of Records subject to the Act.
    (2) During work hours, the NCPC shall protect areas in which 
Records are Maintained or regularly used by restricting occupancy of 
the area to authorized persons or storing the Records in a locked 
container and room.
    (3) During non-working hours, access to Records shall be restricted 
by their storage in a locked storage container and room.
    (4) Any lock used to secure a room where Records are stored shall 
not be capable of being disengaged with a master key that opens rooms 
other than those in which Records are stored.
    (c) Computerized Records subject to the Privacy Act shall be 
maintained, at a minimum, subject to the safeguards recommended by the 
National Institute of Standards and Technology (NIST) Special 
Publications 800-53, Recommended Security Controls for Federal 
Information Systems and Organizations as revised from time to time or 
any superseding guidance offered by NIST or other federal agency 
charged with the responsibility for providing recommended safeguards 
for computerized Records subject to the Privacy Act.
    (d) NCPC shall maintain a System of Records comprised of Office of 
Personnel Management (OPM) personnel Records in accordance with 
standards prescribed by OPM and published at 5 CFR 293.106-293.107.


Sec.  603.8  Employee conduct.

    (a) Employees with duties requiring access to and handling of 
Records shall, at all times, take care to protect the integrity, 
security, and confidentiality of the Records.
    (b) No employee of the NCPC shall disclose Records unless 
disclosure is permitted by Sec.  603.10(b), by part 602 of this 
chapter, or disclosed to the Individual to whom the Record pertains.
    (c) No employee of the NCPC shall alter or destroy a Record unless 
such Record or destruction is undertaken in the course of the 
employee's regular duties or such alteration or destruction is allowed 
pursuant to regulations published by the National Archives and Records 
Administration (NARA) or required by a court of competent jurisdiction. 
Records shall not be destroyed or disposed of while they are the 
subject of a pending request, appeal or lawsuit under the Privacy Act.


Sec.  603.9  Government contracts.

    (a) When a contract provides for third party operation of a SOR on 
behalf of the NCPC to accomplish a NCPC function, the contract shall 
require that the requirements of the Privacy Act and the rules in this 
part be applied to such System.
    (b) The Division Director responsible for the contract shall 
designate a NCPC employee to oversee and manage the SOR operated by the 
contractor.


Sec.  603.10  Conditions for disclosure.

    (a) Except as set forth in paragraph (b) of this section, no Record 
contained in a SOR shall be disclosed by any means of communication to 
any person, or to another agency, unless prior written consent is 
obtained from the Individual to whom the Record pertains.
    (b) The limitations on disclosure contained in paragraph (a) of 
this section shall not apply when disclosure of a Record is:
    (1) To employees of the NCPC for use in the performance of their 
duties;
    (2) Required by the Freedom of Information Act (FOIA), 5 U.S.C. 
555;
    (3) For a Routine Use as described in a SORN;
    (4) To the Bureau of Census for statistical purposes, provided that 
the Record must be transferred in a form that precludes individual 
identification;
    (5) To an Individual who provides NCPC adequate written assurance 
that the Record shall be used solely for statistical or research 
purposes, provided that the Record must be transferred in a form that 
precludes Individual identification;
    (6) To the NARA because the Record warrants permanent retention 
because of historical or other national value as determined by NARA or 
to permit NARA to determine whether the Record has such value;
    (7) To a law enforcement agency for a civil or criminal law 
enforcement activity, provided that the law enforcement agency must 
submit a written request to the NCPC specifying the Record(s) sought 
and the purpose for which they will be used;

[[Page 44050]]

    (8) To any person upon demonstration of compelling information that 
an Individual's health or safety is at stake and provided that upon 
disclosure, notification is given to the Individual to whom the Record 
pertains at that Individual's last known address;
    (9) To either House of Congress, and any committee or subcommittee 
thereof, to include joint committees of both houses and any 
subcommittees thereof, when a Record falls within their jurisdiction;
    (10) To the Comptroller General, or any of his authorized 
representatives, to allow the Government Accountability Office to 
perform its duties;
    (11) Pursuant to a court order by a court of competent 
jurisdiction; and
    (12) To a consumer reporting agency trying to collect a claim of 
the government as authorized by 31 U.S.C. 3711(e).


Sec.  603.11  Accounting of disclosures.

    (a) Except for disclosures made under Sec. Sec.  603.10(b)(1)-(2), 
when a Record is disclosed to any person, or to another agency, NCPC 
shall prepare an accounting of the disclosure. The accounting shall 
Record the date, nature, and purpose of the disclosure and the name and 
address of the person or agency to whom the disclosure was made. The 
NCPC shall maintain all accountings for a minimum of five years or the 
life of the Record, whichever is greatest, after the disclosure is 
made.
    (b) Except for disclosures under Sec.  603.10(b)(7), accountings of 
all disclosures shall be made available to the Individual about whom 
the disclosed Records pertains at his/her request. Such request shall 
be made in accordance with the requirements of Sec.  603.15.
    (c) For any disclosure for which an accounting is made, if a 
subsequent amendment or correction or notation of dispute is made to a 
Record by the NCPC in accordance with the requirements of Sec.  603.14, 
the Individual and/or agency to whom the Record was originally 
disclosed shall be informed.


Sec.  603.12  Requests for notification of the existence of Records.

    (a) An Individual seeking to determine whether a System of Records 
contains Records pertaining to him/her shall do so by appearing in 
person at NCPC's official place of business or by written 
correspondence to the NCPC PAO. In-person requests shall be by 
appointment only with the PAO on a Workday during regular office hours. 
Written requests sent via the U.S. mail shall be directed to the 
Privacy Act Officer at NCPC's official address listed at www.ncpc.gov. 
If sent via email or facsimile, the request shall be directed to the 
email address or facsimile number indicated on the NCPC Web site. To 
expedite internal handling of Privacy Act Requests, the words Privacy 
Act Request shall appear prominently on the envelop or the subject line 
of an email or facsimile cover sheet.
    (b) The Request shall state that the Individual is seeking 
information concerning the existence of Records about himself/herself 
and shall supply information describing the System where such Records 
might be maintained as set forth in a System of Record Notice.
    (c) The NCPC PAO shall notify the Requester in writing within 20 
Workdays of the Request whether a System contains Records pertaining to 
him/her unless the Records were compiled in reasonable anticipation of 
a civil action or proceeding or the Records are NCPC employee Records 
under the jurisdiction of the OPM. In both of the later cases the 
Request shall be denied. If the Request is denied because the Record(s) 
is/are under the jurisdiction of the OPM, the response shall advise the 
Requester to contact OPM. If the PAO denies the Request, the response 
shall state the reason for the denial and advise the Requester of the 
right to appeal the decision within 60 days of the date of the letter 
denying the request in accordance with the requirements set forth in 
Sec.  603.16.


Sec.  603.13  Requests for access to Records.

    (a) An Individual seeking access to Records about himself/herself 
shall do so by appearing in person at NCPC's official place of business 
or by written correspondence to the NCPC Privacy Act Officer. In-person 
requests shall be by appointment only with the Privacy Act Officer on a 
Workday during regular office hours. For written requests sent via the 
U.S. mail, the Request shall be directed to the Privacy Act Officer at 
NCPC's official address listed at www.ncpc.gov. If sent via email or 
facsimile, the request shall be directed to the email address or 
facsimile number indicated on the NCPC Web site. To expedite internal 
handling of Privacy Act Requests, the words Privacy Act Request shall 
appear prominently on the envelop or the subject line of an email or 
facsimile cover sheet.
    (b) The Request shall:
    (1) State the Request is made pursuant to the Privacy Act;
    (2) Describe the requested Records in sufficient detail to enable 
their location including, without limitation, the dates the Records 
were compiled and the name or identifying number of each System of 
Record in which they are kept as identified in the list of NCPC's SORNs 
published on its Web site; and
    (3) State pursuant to the fee schedule in set forth in Sec.  603.17 
a willingness to pay all fees associated with the Privacy Act Request 
or the maximum fee the Requester is willing to pay.
    (c) The NCPC shall require identification as follows before 
releasing Records to an Individual:
    (1) An Individual Requesting Privacy Act Records in person shall 
present a valid, photographic form of identification such as a driver's 
license, employee identification card, or passport that renders it 
possible for the PAO to verify that the Individual is the same 
Individual as contained in the requested Records.
    (2) An Individual Requesting Privacy Act Records by mail shall 
state their full name, address and date of birth in their 
correspondence. The Request must be signed and the signature must 
either be notarized or submitted with a statement signed and dated as 
follows: I declare under penalty of perjury that the foregoing facts 
establishing my identification are true and correct.
    (d) The PAO shall determine within 20 Workdays whether to grant or 
deny an Individual's Request for Access to the requested Record(s) and 
notify the Individual in writing accordingly. The PAO's response shall 
state his/her determination and the reasons therefor. If the Request is 
denied because the Record(s) is/are under the jurisdiction of the OPM, 
the response shall advise the Requester to contact OPM. In the case of 
an Adverse Determination, the written notification shall advise the 
Individual of his/her right to appeal the Adverse Determination in 
accordance with the requirements of Sec.  603.16.


Sec.  603.14  Requests for Amendment or Correction of Records.

    (a) An Individual seeking to amend or correct a Record pertaining 
to him/her that he/she believes to be inaccurate, irrelevant, untimely 
or incomplete shall submit a written request to the PAO at the address 
listed on NCPC's official Web site www.ncpc.gov. If sent via email or 
facsimile, the Request shall be directed to the email address or 
facsimile number indicated on the NCPC Web site. To expedite internal 
handling, the words Privacy Act Request shall appear prominently on the 
envelop or the subject line of an email or facsimile cover sheet.
    (b) The Request shall:
    (1) State the Request is made pursuant to the Privacy Act;
    (2) Describe the requested Record in sufficient detail to enable 
its location

[[Page 44051]]

including, without limitation, the dates the Records was compiled and 
the name or identifying number of the System of Record in which the 
Record is kept as identified in the list of NCPC's SORNs published on 
its Web site;
    (3) State in detail the reasons why the Record, or objectionable 
portion(s) thereof, is/are not accurate, relevant, timely or complete.
    (4) Include copies of documents or evidence relied upon in support 
of the Request for Amendment or Correction; and
    (5) State specifically, and in detail, the changes sought to the 
Record, and if the changes include rewriting the Record, or portions 
thereof, or adding new language, the Individual shall propose specific 
language to implement the requested changes.
    (c) A request to Amend or Correct a Record shall be submitted only 
if the Requester has previously requested and been granted access to 
the Record and has inspected or been given a copy of the Record.
    (d) The PAO shall render a decision within 20 Workdays. If the 
Request for an Amendment or Correction fails to meet the requirements 
of paragraphs (b)(1)-(5) of this section, the PAO shall advise the 
Individual of the deficiency and advise what additional information is 
required to act upon the Request. The timeframe for a decision on the 
Request shall be tolled (stopped) during the pendency of a request for 
additional information and shall resume when the additional information 
is received. If the Requester fails to submit the requested additional 
information within a reasonable time, the PAO shall reject the Request.
    (e) The PAO's decision on a Request for Amendment or Correction 
shall be in writing and state the basis for the decision. If the 
Request is denied because the Record(s) is/are under the jurisdiction 
of the OPM, the response shall advise the Requester to contact OPM. In 
the event of an Adverse Determination, the written notification shall 
advise the Individual of his/her right to appeal the Adverse 
Determination in accordance with the requirements of Sec.  603.16.
    (f) If the PAO approves the Request for Amendment or Correction, 
the PAO shall ensure that subject Record is amended or corrected, in 
whole or in part. If the PAO denies the Request for Amendment or 
Correction, a notation of dispute shall be noted on the Record. If an 
accounting of disclosure has been made pursuant to Sec.  603.11, the 
PAO shall advise all previous recipients of the Record that an 
amendment or correction or notation of dispute has been made and, if 
applicable, the substance of the change.


Sec.  603.15  Requests for Accounting of Record disclosures.

    (a) An Individual seeking information regarding an accounting of 
disclosure of a Record pertaining to him/her made in accordance with 
Sec.  603.11 shall submit a written request to the PAO at the address 
listed on NCPC's official Web site www.ncpc.gov. If sent via email or 
facsimile, the Request shall be directed to the email address or 
facsimile number indicated on the NCPC Web site. To expedite internal 
handling, the words Privacy Act Request shall appear prominently on the 
envelop or the subject line of an email or facsimile cover sheet.
    (b) The Request shall:
    (1) State the Request is made pursuant to the Privacy Act; and
    (2) Describe the requested Record in sufficient detail to determine 
whether it is or is not contained in an accounting of disclosure.
    (c) The NCPC PAO shall notify the Requester in writing within 20 
Workdays of the Request and advise if the Record was included in an 
accounting of disclosure. In the event of a disclosure, the response 
shall include the date, nature, and purpose of the disclosure and the 
name and address of the person or agency to whom the disclosure was 
made. If the Request is denied because the Record(s) is/are under the 
jurisdiction of the OPM, the response shall advise the Requester to 
contact OPM. In the event of an Adverse Determination, the written 
notification shall advise the Individual of his/her right to appeal the 
Adverse Determination in accordance with the requirements of Sec.  
603.16.


Sec.  603.16  Appeals of Adverse Determinations.

    (a) Except for appeals pursuant to paragraph (d) of this section, 
an appeal of an Adverse Determination shall be made in writing 
addressed to the Chairman (Chairman) of the National Capital Planning 
Commission at the address listed on NCPC's official Web site 
www.ncpc.gov. If sent via email or facsimile, the Request shall be 
directed to the email address or facsimile number indicated on the NCPC 
Web site. To expedite internal handling, the words Privacy Act Request 
shall appear prominently on the envelop or the subject line of an email 
or facsimile cover sheet. An appeal of an Adverse Determination shall 
be made within 30 Workdays of the date of the decision.
    (b) An appeal of an Adverse Determination shall include a statement 
of the legal, factual or other basis for the Requester's objection to 
an Adverse Determination; a daytime phone number or email where the 
Requester can be reached if the Chairman requires additional 
information or clarification regarding the appeal; copies of the 
initial request and the PAO's written response; and for an Adverse 
Determination regarding a fee waiver, a demonstration of compliance 
with part 602 of this chapter.
    (c) The Chairman shall respond to an appeal of an Adverse 
Determination in writing within 20 Workdays of receipt of the appeal. 
If the Chairman grants the appeal, the Chairman shall notify the 
Requester, and the NCPC shall take prompt action to respond 
affirmatively to the original Request upon receipt of any fees that may 
be required. If the Chairman denies the appeal, the letter shall state 
the reason(s) for the denial, a statement that the decision is final, 
and advise the Requester of the right to seek judicial review of the 
denial in the District Court of the United States in either the 
district in which the Requester resides, the district in which the 
Requester has his/her principal place of business or the District of 
Columbia.
    (d) The appeal of an Adverse Determination based on OPM 
jurisdiction of the Records shall be made to OPM pursuant to 5 CFR 
297.306.
    (e) The NCPC shall not act on an appeal of an Adverse Determination 
if the underlying Request becomes the subject of litigation.
    (f) A party seeking court review of an Adverse Determination must 
first appeal the Adverse Determination under this section.


Sec.  603.17  Fees.

    (a) The NCPC shall charge for the duplication of Records under this 
subpart in accordance with the schedule of fees set forth in part 602 
of this chapter. The NCPC shall not charge duplication fees when the 
Requester asks to inspect the Records personally but is provided copies 
at the discretion of the agency.
    (b) The NCPC shall not charge any fees for the search for or review 
of Records requested by an Individual.


Sec.  603.18  Privacy Impact Assessments.

    (a) Consistent with the requirements of the E-Government Act and 
OMB Memorandum M-03-22, the NCPC shall conduct a PIA before:
    (1) Developing or procuring IT systems or projects that collect, 
maintain, or disseminate IIF; or

[[Page 44052]]

    (2) Installing a new collection of information that will be 
collected, maintained, or disseminated using IT and includes IIF for 10 
or more persons (excluding agencies, instrumentalities or employees of 
the federal government).
    (b) The PIA shall be prepared through the coordinated effort of the 
NCPC's privacy Officers (SAOP, PAO), Division Directors, CIO, and IT 
staff.
    (c) As a general rule, the level of detail and content of a PIA 
shall be commensurate with the nature of the information to be 
collected and the size and complexity of the IT system involved. 
Specifically, a PIA shall analyze and describe:
    (1) The information to be collected;
    (2) The reason the information is being collected;
    (3) The intended use for the information;
    (4) The identity of those with whom the information will be shared;
    (5) The opportunities Individuals have to decline to provide the 
information or to consent to particular uses and how to consent;
    (6) The manner in which the information will be secured; and
    (7) The extent to which the system of records is being created 
under the Privacy Act.
    (d) In addition to the information specified in paragraphs (b)(1)-
(7) of this section, the PIA must also identify the choices NCPC made 
regarding an IT system or collection of information as result of 
preparing the PIA.
    (e) The CCB shall verify that a PIA has been prepared prior to 
approving a request to develop or procure information technology that 
collects, maintains, or disseminates Information in Identifiable Form.
    (f) The SAOP shall approve and sign the NCPC's PIA. If the SAOP is 
the Contracting Officer for the IT system that necessitated preparation 
of the PIA, the Executive Director shall approve and sign the PIA.
    (g) Following approval of the PIA, the NCPC shall post the PIA 
document on the NCPC Web site located at www.ncpc.gov.

    Dated: September 14, 2017.
Anne R. Schuyler,
General Counsel.
[FR Doc. 2017-19996 Filed 9-19-17; 8:45 am]
 BILLING CODE 7520-01-P



                                               44044        Federal Register / Vol. 82, No. 181 / Wednesday, September 20, 2017 / Rules and Regulations

                                                  (2) Whether any identified                           NATIONAL CAPITAL PLANNING                 accounting of disclosures of those
                                               commercial interest of the Requester is                 COMMISSION                                Records by the NCPC; the procedures by
                                               sufficiently large in comparison with                                                             which an Individual may appeal an
                                               the public interest in disclosure that                  1 CFR Parts 455 and 603                   Adverse Determination, and the conduct
                                               disclosure is primarily in the                                                                    of a Privacy Impact Assessment.
                                                                                                       Privacy Act Regulations                      § 603.2 Definitions. This section
                                               commercial interest of the Requester. A
                                               Fee Waiver is justified where the public                AGENCY: National Capital Planning         defines  terms frequently used in the
                                               interest standard of paragraph (b) of this              Commission.                               regulations. The section includes the
                                                                                                       ACTION: Final rule.
                                                                                                                                                 five terms defined in the existing
                                               section is satisfied and that public
                                                                                                                                                 regulations—Individual, Maintain,
                                               interest is greater in magnitude than that
                                                                                                       SUMMARY: The National Capital Planning Record, Routine Use and System of
                                               of any identified commercial interest in                                                          Records. It adds the definitions for the
                                                                                                       Commission (NCPC or Commission)
                                               disclosure. The NCPC ordinarily shall                   hereby adopts new regulations             following terms: Adverse
                                               presume that a Representative of the                    governing NCPC’s implementation of        Determination, E-Government Act of
                                               News Media satisfies the public interest                the Privacy Act, as amended and the       2002, Information in Identifiable Form
                                               standard, and the public interest will be               privacy provisions of the E-Government (IIF), Information Technology, Privacy
                                               the interest primarily served by                        Act of 2002. NCPC must comply with        Act Officer (PAO), Privacy Act, Privacy
                                               disclosure to that Requester. Disclosure                the requirements of the Privacy Act and Impact Assessment (PIA), Record,
                                               to data brokers or others who merely                    the privacy provisions of the E-          Requester, Request for Access to a
                                               compile and market government                           Government Act of 2002 for records        Record, Request for Amendment or
                                               information for direct economic return                  maintained on individuals and personal Correction of a Record, Senior Agency
                                               shall not be presumed to primarily serve                information stored as a hard copy or      Official for Privacy (SAOP), System of
                                               the public interest.                                    electronically.                           Records Notice (SORN), and Workday.
                                                                                                                                                    § 603.3 Privacy Act program
                                                  (d) Where only some of the Records                   DATES: This rule is effective October 20,
                                                                                                                                                 responsibilities. This section requires
                                               to be released satisfy the requirements                 2017.
                                                                                                                                                 NCPC to designate a SAOP and a PAO
                                               for a Fee Waiver, a Fee Waiver shall be                 FOR FURTHER INFORMATION CONTACT:
                                                                                                                                                 and outlines the responsibilities
                                               granted for those Records.                              Anne R. Schuyler, General Counsel at      associated with both positions. It also
                                                  (e) Requests for a Fee Waiver should                 202–482–7223, anne.schuyler@              enumerates the Privacy Act
                                                                                                       ncpc.gov.                                 responsibilities of other NCPC
                                               address the factors listed in paragraphs
                                               (a) through (c) of this section, insofar as             SUPPLEMENTARY INFORMATION: NCPC           personnel.
                                               they apply to each Request. The NCPC                    adopted its current Privacy Regulations      § 603.4 Standards used to Maintain
                                               shall exercise its discretion to consider               (1 CFR part 455) in 1977 pursuant to 5    Records. This section establishes the
                                               the cost-effectiveness of its investment                U.S.C. 552a. Since that time, Congress    standards NCPC must follow regarding
                                               of administrative resources in this                     amended the Privacy Act multiple times privacy information. The section
                                               decision-making process in deciding to                  including the E-Government Act of 2002 requires NCPC to limit private
                                                                                                       which addressed requirements for          information to only that necessary to
                                               grant Fee Waivers.
                                                                                                       maintaining electronic privacy records.   achieve the purposes for which it is
                                               § 602.15   Preservation of FOIA records.                The regulations update NCPC’s existing collected and stored; to ensure all
                                                                                                       Privacy Regulations to reflect            information collected is accurate,
                                                 (a) The NCPC shall preserve all                       amendments over time. The Office of       relevant, timely, and complete; and to
                                               correspondence pertaining to FOIA                       the Federal Register recently assigned    collect privacy information regarding an
                                               Requests received and copies or Records                 NCPC a new chapter of 1 CFR—Chapter Individual’s rights, benefits and
                                               provided until disposition or                           VI—to allow NCPC to group all its         privileges under federal programs from
                                               destruction is authorized by the NCPC’s                 regulations together in one chapter.      the Individual to the maximum extent
                                               General Records schedule established in                    NCPC eliminates its Privacy            possible subject to collection from third
                                               accordance with the National Archives                   Regulations at 1 CFR part 455 and         parties in certain circumstances.
                                               and Records Administration (NARA)                       codifies the new Privacy Regulations at      § 603.5 Notice to Individuals
                                               approved schedule.                                      1 CFR part 603.                           supplying information. This section
                                                                                                                                                 enumerates the information NCPC must
                                                 (b) Materials that are responsive to a                I. Section by Section Analysis of         provide Individuals who are asked to
                                               FOIA Request shall not be disposed of                   NCPC’s Privacy Act Regulations            supply information about themselves.
                                               or destroyed while the Request or a                        § 603.1 Purpose and scope. This        The required information enumerated
                                               related lawsuit is pending even if the                  section advises the purpose of the        includes the purpose for which NCPC
                                               Records would otherwise be authorized                   regulations is to implement a privacy     intends to use the information; the
                                               for disposition under the NCPC’s                        program consistent with the               effects upon an Individual for not
                                               General Records Schedule or NARA or                     requirements of the Privacy Act and the providing the information; and the form
                                               other NARA-approved records schedule.                   privacy related provision of the E-       of notice NCPC must supply in response
                                                 Dated: September 14, 2017.                            Government Act of 2002. As stated in      to an Individual’s provision of
                                               Anne R. Schuyler,
                                                                                                       the section, NCPC’s privacy program       information.
                                                                                                       extends to all Records maintained by         § 603.6 System of Records (SOR)
                                               General Counsel.
                                                                                                       NCPC in a System of Records; the          Notice (SORN). This section requires
sradovich on DSKBBY8HB2PROD with RULES2




                                               [FR Doc. 2017–19997 Filed 9–19–17; 8:45 am]             responsibilities of NCPC to safeguard     NCPC to publish a notice in the Federal
                                               BILLING CODE 7502–20–P                                  this information; the procedures by       Register describing each SOR 40-days
                                                                                                       which Individuals may request             before establishing a new or revising an
                                                                                                       notification of the existence of a Record existing SOR. The section requires the
                                                                                                       about them, access to Records about       SORN to include the purpose of the
                                                                                                       them, an amendment to or correction of Records and their location; the types of
                                                                                                       the Records about them, and an            Individuals contained in the SOR; the


                                          VerDate Sep<11>2014   18:44 Sep 19, 2017   Jkt 241001   PO 00000   Frm 00010   Fmt 4701   Sfmt 4700   E:\FR\FM\20SER2.SGM   20SER2


                                                            Federal Register / Vol. 82, No. 181 / Wednesday, September 20, 2017 / Rules and Regulations                                         44045

                                               authority for maintaining the SOR; the                  and the name and address of the person                   § 603.15 Requests for an accounting
                                               purpose or reason why NCPC collects                     or agency to whom the disclosure was                  of Records disclosures. This section
                                               the Records and their intended routine                  made. The section also requires                       outlines the process Individuals must
                                               uses; the sources of the Records in the                 Accountings of disclosures to be made                 follow to obtain information about
                                               SOR; the policies and practices                         available to the Individual about whom                disclosures of Records pertaining to
                                               regarding storage, retrieval, access                    the disclosed Record pertains except                  them. It requires a request for
                                               controls, retention, and disposal of the                under limited circumstances. It further               information about Records disclosed to
                                               Records; the identification of the agency               requires changes to disclosed Records to              include certain specified information.
                                               official responsible for the SOR; and the               be shared with the person or agency to                The section also requires the NCPC PAO
                                               procedures for notifying an Individual                  whom the Record was originally                        to respond to a request for information
                                               who requests whether the SOR contains                   disclosed.                                            about disclosures in writing within 20
                                               information about him/her.                                § 603.12 Requests for notification of               Workdays, to include, in the event of a
                                                 § 603.7 Procedures to safeguard                       the existence of Records. This section                disclosure, the date, nature and purpose
                                               Records. This section describes the                     advises Individuals how to determine                  of the disclosure, the name and address
                                               procedures utilized by NCPC to                          whether a System of Records                           of the person or agency to whom the
                                               safeguard hard copy and computerized                    maintained by NCPC contains Records                   disclosure was made. The section
                                               records subject to the Privacy Act. The                 pertaining to them. It requires                       further requires the PAO to state the
                                               section requires hard copy Records to be                Individuals either to contact NCPC in                 reason for his/her determination and to
                                               stored in a locked room subject to                      writing or appear at NCPC’s offices by                advise the requester of the right to
                                               restricted access with external posted                  appointment to make the subject                       appeal an Adverse Determination.
                                               warning signs limiting access to                        request. The section requires the NCPC                   § 602.16 Appeals of Adverse
                                               authorized personnel and/or stored in a                 PAO to respond to a request in writing                Determinations. This section describes
                                               locked container with identical                         within 20 Workdays, to include in the                 the process Individuals must follow to
                                               precautions to those used for a locked                  response the Reason(s) for the PAO’s                  appeal an Adverse Determination. As
                                               room. The section requires                              determination, and to advise the                      defined in the definition section of the
                                               computerized Records to be maintained                   requester of the right to appeal the                  regulations Adverse Determination
                                               subject to the Safeguards recommended                   decision.                                             means a decision to withhold any
                                               by the National Institute of Standards                    § 603.13 Request for access to                      requested Record in whole or in part; a
                                               and Technology (NIST).                                  Records. This section advises                         decision that the requested Record does
                                                 § 603.8 Employee conduct. This                        Individuals how to access NCPC records                not exist or cannot be located; a
                                               section requires employees with duties                  about themselves. It requires                         decision that the requested information
                                               requiring access to and handling of                     Individuals to request the right to access            is not a Record subject to the Privacy
                                               Records to do so in a manner that                       Records either in writing or to appear at             Act; a decision that a Record, or part
                                               protects the integrity, security and                    NCPC’s offices by appointment. The                    thereof, does not require amendment or
                                               confidentiality of the Records. It                      section enumerates the information                    correction; a decision to refuse to
                                               prohibits employee disclosure of                        required to be included in a request, and             disclose an accounting of disclosure;
                                               records unless authorized by the rules                  obligates Individuals to present certain              and a decision to deny a fee waiver. The
                                               in this part, permitted by NCPC’s FOIA                  specified identification to access the                term also encompasses a challenge to
                                               regulations (1 CFR part 602), or                        requested Records. The section also                   NCPC’s determination that Records have
                                               disclosed to the Individual to whom the                 requires the NCPC PAO to respond to a                 not been described adequately, that
                                               Record pertains. The section also                       request for access in writing within 20               there are no responsive Records, or that
                                               prohibits destruction or alteration of                  Workdays, to state in the response the                an adequate search has been conducted.
                                               Records unless required as part of an                   reason for the PAO’s determination, and               The section requires an Individual to
                                               employee’s regular duties, required by                  to advise the Requester of the right to               submit a written appeal to the Chairman
                                               regulations published by the National                   appeal an Adverse Determination.                      of the Commission stating the legal,
                                               Archives Record Administration                            § 603.14 Requests for amendment or                  factual or other basis for the Appeal,
                                               (NARA), or required by a court of law.                  correction of Records. This section                   and it requires the Chairman to provide
                                                 § 603.9 Government contracts. This                    outlines the process Individuals must                 a written response within 30 Workdays.
                                               section requires contractors operating a                follow to amend or correct Records                    The section also requires NCPC to take
                                               System of Records on behalf of NCPC to                  about them that they believe are                      prompt action to respond affirmatively
                                               abide by the requirements of the Privacy                inaccurate, irrelevant, untimely or                   to the Individual’s original request if the
                                               Act. It also equires a NCPC employee to                 incomplete. The section requires a                    Chairman grants the request and to state
                                               oversee and manage the SOR operated                     request for amendment or correction to                the reasons for a denial and the right to
                                               by a contractor.                                        be in writing, include certain specified              appeal the denial to a court of
                                                 § 603.10 Conditions for disclosure.                   information, and to be made only if the               competent jurisdiction.
                                               Subject to a list of enumerated                         Individual has previously requested and                  § 603.17 Fees. This section states the
                                               exceptions, this section precludes                      been granted access to the Record. The                fees to be charged for the search for and
                                               disclosure of a Record contained in a                   section also requires the NCPC PAO to                 duplication of Records. It advises fees
                                               SOR unless prior written consent is                     respond to a request for amendment or                 for duplication shall be those
                                               obtained from the Individual to whom                    correction in writing within 20                       established by NCPC’s FOIA
                                               the record pertains.                                    Workdays, to state the reason for the                 Regulations, and it states there are no
                                                 § 603.11 Accounting of disclosures.                   PAO’s determination in the response, to               fees for the search or review of Records
sradovich on DSKBBY8HB2PROD with RULES2




                                               This section requires NCPC to prepare                   advise the requester of the right to                  requested by an Individual.
                                               an accounting of disclosure when a                      appeal an Adverse Determination, to                      § 603.18 Privacy Impact
                                               Record is disclosed to any person or to                 ensure the Record is amended or                       Assessments. This section states when
                                               another agency.                                         corrected in whole or in part if the PAO              NCPC must conduct a Privacy Impact
                                                 The section requires the contents of                  approves the request, and to place a                  Assessment (PIA), the contents of a PIA,
                                               an accounting to include the date,                      notation of a dispute on the Record if                and the process for approving the PIA.
                                               nature, and purpose of the disclosure                   the request is denied.                                The section requires a PIA to be


                                          VerDate Sep<11>2014   18:44 Sep 19, 2017   Jkt 241001   PO 00000   Frm 00011   Fmt 4701   Sfmt 4700   E:\FR\FM\20SER2.SGM   20SER2


                                               44046        Federal Register / Vol. 82, No. 181 / Wednesday, September 20, 2017 / Rules and Regulations

                                               conducted before developing or                          of $100 million or more; will not cause               thereof where they believe compliance
                                               procuring an IT system that collects,                   a major increase in costs for individuals,            is lacking.
                                               maintains or disseminates Information                   various levels of governments or various
                                                                                                                                                             11. Public Availability of Comments
                                               that identifies an Individual (IIF or                   regions; and does not have a significant
                                               Information in Identifiable Form) or                    adverse effect on completion,                           Be advised that personal information
                                               when NCPC installs a new collection of                  employment, investment, productivity,                 such as name, address, phone number,
                                               IIF for 10 or more persons other than                   innovation or the competitiveness of US               electronic address, or other identifying
                                               employees, or agencies of the federal                   enterprises with foreign enterprises.                 personal information contained in a
                                               government. The section also requires a                                                                       comment may be made publically
                                               PIA to analyze a number of factors                      Unfunded Mandates Reform Act (2                       available. Individuals may ask NCPC to
                                               related to the collection, use, owner,                  U.S.C. 1531 et seq.)                                  withhold the personal information in
                                               storage and manner of securing the IIF,                    A statement regarding the Unfunded                 their comment, but there is no guarantee
                                               and it requires the PIA to be approved                  Mandates Reform Act is not required.                  the agency can do so.
                                               and posted on NCPC’s Web site prior to                  The rule neither imposes an unfunded                  List of Subjects in 1 CFR Parts 455 and
                                               undertaking the action that required the                mandate of more than $100 million per                 603 Privacy
                                               PIA.                                                    year nor imposes a significant or unique
                                                                                                       effect on State, local or tribal                        For the reasons stated in the
                                               II. Summary of and Response to
                                                                                                       governments or the private sector.                    preamble, the National Capital Planning
                                               Comments
                                                                                                                                                             Commission amends 1 CFR Chapters IV
                                                  NCPC published a proposed rule                       Federalism (Executive Order 13132)                    and VI as follows:
                                               addressing revisions to its current                       In accordance with Executive Order                  CHAPTER IV—MISCELLANEOUS
                                               Privacy Act Regulations in the Federal
                                                                                                       13132, the rule does not have sufficient              AGENCIES
                                               Register on August 1, 2017 for a 30-day
                                                                                                       federalism implications to warrant the
                                               public comment period. The public                                                                             PART 455—[Removed]
                                                                                                       preparation of a Federalism Assessment.
                                               comment period closed on August 31,
                                                                                                       The rule does not substantially and
                                               2017.                                                                                                         ■ 1. Under the authority of 40 U.S.C.
                                                  NCPC received no comments on its                     directly affect the relationship between
                                                                                                                                                             8711(a) remove part 455.
                                               proposed Privacy Act Regulations.                       the Federal and state governments.
                                                                                                                                                             CHAPTER VI—NATIONAL CAPITAL
                                               Consequently, the proposed Privacy Act                  Civil Justice Reform (Executive Order                 PLANNING COMMISSION
                                               Regulations are now being advertised as                 12988)
                                               the final Privacy Act Regulations.                                                                            ■   2. Add part 603 to read as follows:
                                                                                                         The General Counsel of NCPC has
                                               III. Compliance With Laws and                           determined that the rule does not                     PART 603—PRIVACY ACT
                                               Executive Orders                                        unduly burden the judicial system and                 REGULATIONS
                                               Executive Orders 12866 and 13563                        meets the requirements of Executive
                                                                                                                                                             Sec.
                                                                                                       Order 12988 3(a) and 3(b)(2).                         603.1 Purpose and scope.
                                                 By Memorandum dated October 12,
                                                                                                       Paperwork Reduction Act                               603.2 Definitions.
                                               1993 from Sally Katzen, Administrator,
                                                                                                                                                             603.3 Privacy Act program responsibilities.
                                               Office of Information and Regulatory                      The rule does not contain information               603.4 Standard used to Maintain Records.
                                               Affairs (OIRA) to Heads of Executive                    collection requirements, and it does not              603.5 Notice to Individuals supplying
                                               Departments and Agencies, and                           require a submission to the Office of                      information.
                                               Independent Agencies, OMB rendered                      Management and Budget under the                       603.6 System of Records Notice or SORN.
                                               the NCPC exempt from the requirements                   Paperwork Reduction Act.                              603.7 Procedures to safeguard Records.
                                               of Executive Order 12866 (See,                                                                                603.8 Employee conduct.
                                               Appendix A of cited Memorandum).                        9. National Environmental Policy Act                  603.9 Government contracts.
                                                                                                                                                             603.10 Conditions of disclosure.
                                               Nonetheless, NCPC endeavors to adhere                      The rule is of an administrative                   603.11 Accounting for disclosures.
                                               to the provisions of Executive Orders                   nature, and its adoption does not                     603.12 Requests for notification of the
                                               and developed this rule in a manner                     constitute a major federal action                          existence of Records.
                                               consistent with the requirements of                     significantly affecting the quality of the            603.13 Requests for access to Records.
                                               Executive Order 13563.                                  human environment. NCPC’s adoption                    603.14 Requests for Amendment or
                                                                                                       of the rule will have minimal or no                        Correction of Records.
                                               Executive Order 13771                                                                                         603.15 Requests for Accounting of Record
                                                 By virtue of its exemption from the                   effect on the environment; impose no                       disclosures.
                                               requirements of EO 12866, NCPC is                       significant change to existing                        603.16 Appeals of Adverse Determinations.
                                               exempted from this Executive Order.                     environmental conditions; and will                    603.17 Fees.
                                               NCPC confirmed this fact with OIRA.                     have no cumulative environmental                      603.18 Privacy Impact Assessments.
                                                                                                       impacts.                                                Authority: 5 U.S.C. 552a as amended and
                                               Regulatory Flexibility Act                                                                                    44 U.S.C. ch. 36.
                                                                                                       10. Clarity of the Regulation
                                                 As required by the Regulatory
                                               Flexibility Act (5 U.S.C. 601 et seq.), the               Executive Order 12866, Executive                    § 603.1    Purpose and scope.
                                               NCPC certifies that the rule will not                   Order 12988, and the Presidential                       (a) This part contain the rules the
                                               have a significant economic effect on a                 Memorandum of June 1, 1998 requires                   National Capital Planning Commission
                                               substantial number of small entities.                   the NCPC to write all rules in plain                  (NCPC) shall follow to implement a
sradovich on DSKBBY8HB2PROD with RULES2




                                                                                                       language. NCPC maintains the rule                     privacy program as required by the
                                               Small Business Regulatory Enforcement                   meets this requirement. Those                         Privacy Act of 1974, 5 U.S.C. 552a
                                               Fairness Act                                            individuals reviewing the rule who                    (Privacy Act or Act) and the privacy
                                                 This is not a major rule under 5 U.S.C.               believe otherwise should submit                       provisions of the E-Government Act of
                                               804(2), the Small Business Regulatory                   specific comments to the addresses                    2002 (44 U.S.C. ch. 36) (E-Government
                                               Enforcement Fairness Act. It does not                   noted above recommending revised                      Act). These rules should be read
                                               have an annual effect on the economy                    language for those provision or portions              together with the Privacy Act and the


                                          VerDate Sep<11>2014   18:44 Sep 19, 2017   Jkt 241001   PO 00000   Frm 00012   Fmt 4701   Sfmt 4700   E:\FR\FM\20SER2.SGM    20SER2


                                                            Federal Register / Vol. 82, No. 181 / Wednesday, September 20, 2017 / Rules and Regulations                                        44047

                                               privacy related provisions of the E-                       Individual shall mean a citizen of the                Request for Access to a Record shall
                                               Government Act, which provide                           United States or an alien lawfully                    mean a request by an Individual made
                                               additional information respectively                     admitted for permanent residence.                     to the NCPC pursuant to subsection
                                               about Records maintained on                                Information in Identifiable Form (IIF)             (d)(1) of the Privacy Act to gain access
                                               individuals and protections for the                     shall mean information in an                          to his/her Records or to any information
                                               privacy of personal information as                      Information Technology system or an                   pertaining to him/her in the system and
                                               agencies implement citizen-centered                     online collection that directly identifies            to permit him/her, or a person of his/her
                                               electronic Government.                                  an individual, e.g., name, address, social            choosing, to review and copy all or any
                                                 (b) Consistent with the requirements                  security number or other identifying                  portion thereof.
                                               of the Privacy Act, the rules in this part              number or code, telephone number,                        Request for Amendment or Correction
                                               apply to all Records maintained by                      email address and the like; or                        of a Record shall mean a request made
                                               NCPC in a System of Records; the                        information by which the NCPC intends                 by an Individual to the NCPC pursuant
                                               responsibilities of the NCPC to                         to identify specific individuals in                   to subsection (d)(2) of the Privacy Act to
                                               safeguard this information; the                         conjunction with other data elements,                 amend or correct a Record pertaining to
                                               procedures by which Individuals may                     e.g., indirect identification that may                him/her.
                                               request notification of the existence of a              include a combination of gender, race,                   Routine Use shall mean with respect
                                               record, request access to Records about                 birth date, geographic identifiers, and               to disclosure of a Record, the use of
                                               themselves, request an amendment to or                  other descriptions.                                   such Record for a purpose which is
                                               correction of those Records, and request                   Information Technology (IT) shall                  compatible with the purpose for which
                                               an accounting of disclosures of those                   mean, as defined in the Clinger Cohen                 the Record is collected.
                                               Records by the NCPC; and the                            Act (40 U.S.C. 11101(6)), any                            Senior Agency Official for Privacy
                                               procedures by which an Individual may                   equipment, software or interconnected                 (SAOP) shall mean the individual
                                               appeal an Adverse Determination.                        system or subsystem that is used in the               within NCPC responsible for
                                                 (c) Consistent with the privacy related               automatic acquisition, storage,                       establishing and overseeing the NCPC’s
                                               requirements of the E-Government Act,                   manipulation, management, movement,                   Privacy Act program.
                                               the rules in this part also address the                 control, display, switching, interchange,                System of Records or System (SOR or
                                               conduct of a privacy impact assessment                  transmission or reception of data.                    Systems) shall mean a group of any
                                               prior to developing or procuring                           Maintain shall include maintain,                   Records under the control of the NCPC
                                               information technology that collects,                   collect, use or disseminate a Record.                 from which information is retrieved by
                                               maintains, or disseminates information                     Privacy Act Officer shall mean the                 the name of the individual or by some
                                               in an identifiable form, initiating a new               individual within the NCPC charged                    identifying number, symbol, or other
                                               electronic collection of information in                 with responsibility for coordinating and              identifying particular assigned to the
                                               identifiable form for 10 or more persons                implementing NCPC’s Privacy Act                       individual.
                                               excluding agencies, instrumentalities or                program.                                                 System of Record Notice (SORN) shall
                                               employees of the federal government, or                    Privacy Act or Act shall mean the                  mean a notice published in the Federal
                                               changing an existing System that creates                Privacy Act of 1974, as amended and                   Register by the NCPC for each new or
                                               new privacy risks.                                      codified at 5 U.S.C. 552a.                            revised System of Records intended to
                                                 (d) In addition to the rules in this                                                                        solicit public comment on the System
                                                                                                          Privacy Impact Assessment (PIA)
                                               part, the NCPC shall process all Privacy                                                                      prior to implementation.
                                                                                                       shall mean an analysis of how
                                               Act Requests for Access to Records in                                                                            Workday shall mean a regular Federal
                                                                                                       information is handled to ensure
                                               accordance with the Freedom of                                                                                workday excluding Saturday, Sunday
                                                                                                       handling conforms to applicable legal,
                                               Information Act (FOIA), 5 U.S.C. 552,                                                                         and legal Federal holidays when the
                                                                                                       regulatory, and policy requirements
                                               and part 602 of this chapter.                                                                                 federal government is closed.
                                                                                                       regarding privacy; to determine the risks
                                               § 603.2   Definitions.                                  and effects of collecting, maintaining                § 603.3 Privacy Act program
                                                 For purposes of this part, the                        and disseminating information in                      responsibilities.
                                               following definitions shall apply:                      identifiable form in an electronic                      (a) The NCPC shall designate a Senior
                                                 Adverse Determination shall mean a                    system; and to examine and evaluate                   Agency Official for Privacy (SAOP) to
                                               decision to withhold any requested                      protections and alternative processes for             establish and oversee the NCPC’s
                                               Record in whole or in part; a decision                  handling information to mitigate                      Privacy Act Program and ensure
                                               that the requested Record does not exist                potential privacy risks.                              compliance with privacy laws,
                                               or cannot be located; a decision that the                  Record shall mean any item,                        regulations and the NCPC’s privacy
                                               requested information is not a Record                   collection, or grouping of information                policies. Specific responsibilities of the
                                               subject to the Privacy Act; a decision                  about an Individual that is Maintained                SAOP shall include:
                                               that a Record, or part thereof, does not                by the NCPC, including, but not limited                 (1) Reporting to the Office of
                                               require amendment or correction; a                      to, an Individual’s education, financial              Management and Budget (OMB) and
                                               decision to refuse to disclose an                       transactions, medical history, and                    Congress on the establishment of or
                                               accounting of disclosure; and a decision                criminal or employment history and                    revision to Privacy Act Systems;
                                               to deny a fee waiver. The term shall also               that contains a name, or identifying                    (2) Reporting periodically to OMB on
                                               encompass a challenge to NCPC’s                         number, symbol, or other identifying                  Privacy Act activities as required by law
                                               determination that Records have not                     particular assigned to the Individual,                and OMB;
                                               been described adequately, that there                   such as a finger or voice print or                      (3) Signing Privacy Act SORNS for
sradovich on DSKBBY8HB2PROD with RULES2




                                               are no responsive Records or that an                    photograph.                                           publication in the Federal Register;
                                               adequate search has been conducted.                        Requester shall mean an Individual                   (4) Approving and signing PIAs; and
                                                 E-Government Act of 2002 shall mean                   who makes a Request for Access to a                     (5) Serving as head of the agency
                                               Public Law 107–347, Dec. 17, 2002, 116                  Record, a Request for Amendment or                    response team when responding to a
                                               Stat. 2899, the privacy portions of                     Correction of a Record, or a Request for              large-scale information breach.
                                               which are set out as a note under                       Accounting of a Record under the                        (b) The NCPC shall designate a
                                               section 3501 of title 44.                               Privacy Act.                                          Privacy Act Officer (PAO) to coordinate


                                          VerDate Sep<11>2014   18:44 Sep 19, 2017   Jkt 241001   PO 00000   Frm 00013   Fmt 4701   Sfmt 4700   E:\FR\FM\20SER2.SGM   20SER2


                                               44048        Federal Register / Vol. 82, No. 181 / Wednesday, September 20, 2017 / Rules and Regulations

                                               and implement the NCPC’s Privacy Act                       (iv) Coordinating with the PAO the                 § 603.4 Standards used to Maintain
                                               program. Specific responsibilities of the               development of an appropriate form for                Records.
                                               PAO shall include:                                      collection of Privacy Act information                    (a) Records Maintained by the NCPC
                                                 (1) Developing, issuing and updating,                 and including in the form a Privacy Act               shall contain only such information
                                               as necessary, the NCPC’s Privacy Act                    statement explaining the purpose for                  about an Individual as is relevant and
                                               policies, standards, and procedures;                    collecting the information, how it will               necessary to accomplish a purpose
                                                 (2) Maintaining Privacy Act program                   be used, the authority for such                       NCPC must accomplish to comply with
                                               Records and documentation;                              collection, its routine uses, and the                 relevant statutes or Executive Orders of
                                                 (3) Responding to Privacy Act                         effect upon the Individual of not                     the President.
                                               Requests for Records and coordinating                   providing the requested information;                     (b) Records Maintained by the NCPC
                                               appeals of Adverse Determinations for                      (v) Collecting information directly                and used to make a determination about
                                               Requests for access to Records, Requests                from individuals whenever possible;                   an Individual shall be accurate,
                                               for Amendment or Correction of                             (vii) Assisting the PAO with                       relevant, timely, and complete to assure
                                               Records, and Requests for accounting                    providing access to Individuals who                   a fair determination.
                                               for disclosures;                                        request information in accordance with                   (c) Information used by the NCPC in
                                                 (4) Informing Individuals of                          the procedures established in §§ 603.12,              making a determination about an
                                               information disclosures;                                603.13, 603.14 and 603.15.                            Individual’s rights, benefits, and
                                                 (5) Working with the NCPC’s Division                     (vii) Amending Records if and when                 privileges under federal programs shall
                                               Directors or designated staff to develop                appropriate, and working with the PAO                 be collected, to the greatest extent
                                               an appropriate form for collection of                   to inform recipients of former Records                practicable, directly from the
                                               Privacy Act information and including                   of such amendments;                                   Individual. In deciding whether
                                               in the form a Privacy Act statement                        (viii) Ensuring that System                        collection of information about an
                                               explaining the purpose for collecting the               information is used only for its stated               Individual, as opposed to a third party
                                               information, how it will be used, the                   purpose;                                              is practicable, the NCPC shall consider
                                               authority for such collection, its routine                 (ix) Establishing and overseeing                   the following:
                                               uses, and the effect upon the Individual                appropriate administrative, technical,                   (1) Whether the information sought
                                               of not providing the requested                          and physical safeguards to ensure                     can only be obtained from a third party;
                                               information;                                            security and confidentiality of Records;                 (2) Whether the cost to collect the
                                                 (6) Assisting in the development of                   and                                                   information from an Individual is
                                               new or revised SORNs;                                      (x) Working with the SAOP, the PAO                 unreasonable compared to the cost of
                                                 (7) Developing SORN reports for OMB                   and Configuration Control Board (CCB)                 collecting the information from a third
                                               and Congress;                                           on SORs, preparing a PIA, if needed,                  party;
                                                 (8) Submitting new or revised SORNS                                                                            (3) Whether there is a risk of
                                                                                                       and obtaining SAOP approval for a PIA
                                               to the Federal Register for publication;                                                                      collecting inaccurate information from a
                                                 (9) Assisting in the development of                   prior to its publication on the NCPC
                                                                                                       Web site.                                             third party that could result in a
                                               computer matching systems;                                                                                    determination adverse to the Individual
                                                 (10) Preparing Privacy Act, Computer                     (2) The CIO shall be responsible for
                                                                                                       implementing IT security management                   concerned;
                                               Matching, and other reports to OMB as                                                                            (4) Whether the information collected
                                               required; and                                           to include security for information
                                                                                                       protected by the Privacy Act and the E-               from an Individual requires verification
                                                 (11) Evaluating PIA to ensure                                                                               by a third party; and
                                               compliance with E-Government Act                        Government Act of 2002. Specific
                                                                                                                                                                (5) Whether the Individual can verify
                                               requirements.                                           responsibilities include:
                                                                                                                                                             information collected from third parties.
                                                 (c) Other Privacy related                                (i) Overseeing security policy for
                                                                                                                                                                (d) The NCPC shall not Maintain
                                               responsibilities shall be shared by the                 privacy data; and                                     Records describing how an Individual
                                               NCPC Division Directors, the NCPC                          (ii) Reviewing PIAs prepared for
                                                                                                                                                             exercises rights guaranteed by the First
                                               Chief Information Officer (CIO), the                    information security considerations.
                                                                                                                                                             Amendment to the Constitution unless
                                               NCPC System Developers and                                 (3) The NCPC System Developers and
                                                                                                                                                             the maintenance of the Record is
                                               Designers, the NCPC Configuration                       Designers shall be responsible for
                                                                                                                                                             expressly authorized by statute or by the
                                               Control Board, the NCPC employees,                      ensuring that the IT system design and
                                                                                                                                                             Individual about whom the Record is
                                               and the Chairman of the Commission.                     specifications conform to privacy
                                                                                                                                                             Maintained or pertinent to and within
                                                 (1) The NCPC Division Directors shall                 standards and requirements and that
                                                                                                                                                             the scope of an authorized law
                                               be responsible for coordinating with the                technical controls are in place for
                                                                                                                                                             enforcement activity.
                                               PAO the implementation of the                           safeguarding personal information from
                                               requirements set forth in this part for                 unauthorized access.                                  § 603.5 Notice to Individuals supplying
                                               Systems of Records applicable to their                     (4) The NCPC CCB shall, among other                information.
                                               area of management and the preparation                  responsibilities, verify that a PIA has                 (a) Each Individual asked to supply
                                               of PIA prior to development or                          been prepared prior to approving a                    information about himself/herself to be
                                               procurement of new systems that                         request to develop or procure                         added to a System of Records shall be
                                               collect, maintain or disseminate IIF.                   information technology that collects,                 informed by the NCPC of the basis for
                                               Specific responsibilities include:                      maintains, or disseminates Information                requesting the information, its potential
                                                 (i) Reviewing existing SOR for need,                  in Identifiable Form.                                 use, and the consequences, if any, of not
                                               relevance, and purpose for existence,                      (5) The NCPC employees shall ensure                supplying the information. Notice to the
                                               and proposing SOR changes to the PAO                    that any personal information they use                Individual shall state at a minimum:
sradovich on DSKBBY8HB2PROD with RULES2




                                               as necessary in response to altered                     in the conduct of their official                        (1) The legal authority for NCPC’s
                                               circumstances;                                          responsibilities is protected in                      solicitation of the information and
                                                 (ii) Reviewing existing SOR to ensure                 accordance with the rules set forth in                whether disclosure is mandatory or
                                               information is accurate, complete and                   this part.                                            voluntary;
                                               up to date;                                                (6) The Chairman of the Commission                   (2) The principal purpose(s) for which
                                                 (iii) Coordinating with the PAO the                   shall be responsible for acting on all                the NCPC intends to use the
                                               preparation of new or revised SORN;                     appeals of Adverse Determinations.                    information;


                                          VerDate Sep<11>2014   18:44 Sep 19, 2017   Jkt 241001   PO 00000   Frm 00014   Fmt 4701   Sfmt 4700   E:\FR\FM\20SER2.SGM   20SER2


                                                            Federal Register / Vol. 82, No. 181 / Wednesday, September 20, 2017 / Rules and Regulations                                               44049

                                                 (3) The potential routine uses of the                 harm, embarrassment, inconvenience, or                   (c) No employee of the NCPC shall
                                               information by the NCPC as published                    unfairness to any Individual on whom                  alter or destroy a Record unless such
                                               in a Systems of Records Notice; and                     information is Maintained.                            Record or destruction is undertaken in
                                                 (4) The effects upon the individual, if                  (b) Manual Records subject to the                  the course of the employee’s regular
                                               any, of not providing all or any part of                Privacy Act shall be maintained by the                duties or such alteration or destruction
                                               the requested Information to the NCPC.                  NCPC in a manner commensurate with                    is allowed pursuant to regulations
                                                 (b) When NCPC collects information                    the sensitivity of the information                    published by the National Archives and
                                               on a standard form, the notice to the                   contained in the Records. The following               Records Administration (NARA) or
                                               Individual shall either be provided on                  minimum safeguards or safeguards                      required by a court of competent
                                               the form, on a tear off sheet attached to               affording comparable protection shall                 jurisdiction. Records shall not be
                                               the form, or on a separate form,                        apply to manual Systems of Records:                   destroyed or disposed of while they are
                                               whichever is deemed the most practical                     (1) The NCPC shall post areas where                the subject of a pending request, appeal
                                               by the NCPC.                                            Records are maintained or regularly                   or lawsuit under the Privacy Act.
                                                 (c) NCPC may ask an Individual to                     used with an appropriate warning sign
                                               acknowledge, in writing, receipt of the                                                                       § 603.9    Government contracts.
                                                                                                       stating access to the Records shall be
                                               notice required by this section.                        limited to authorized persons. The                      (a) When a contract provides for third
                                                                                                       warning shall also advise that the                    party operation of a SOR on behalf of
                                               § 603.6   System of Records Notice or                                                                         the NCPC to accomplish a NCPC
                                               SORN.                                                   Privacy Act prescribes criminal
                                                                                                       penalties for unauthorized disclosure of              function, the contract shall require that
                                                 (a) The NCPC shall publish a notice                                                                         the requirements of the Privacy Act and
                                                                                                       Records subject to the Act.
                                               in the Federal Register describing each                                                                       the rules in this part be applied to such
                                                                                                          (2) During work hours, the NCPC shall
                                               System of Records 40-days prior to the                                                                        System.
                                                                                                       protect areas in which Records are
                                               establishment of a new or revision to an                                                                        (b) The Division Director responsible
                                                                                                       Maintained or regularly used by
                                               existing System of Records.                                                                                   for the contract shall designate a NCPC
                                                                                                       restricting occupancy of the area to
                                                 (b) The SORN shall include:                                                                                 employee to oversee and manage the
                                                 (1) The name and location of the                      authorized persons or storing the
                                                                                                       Records in a locked container and room.               SOR operated by the contractor.
                                               System of Records. The name shall
                                               identify the general purpose, and the                      (3) During non-working hours, access               § 603.10    Conditions for disclosure.
                                               location shall include whether the                      to Records shall be restricted by their                  (a) Except as set forth in paragraph (b)
                                               system is located on the NCPC’s main                    storage in a locked storage container and             of this section, no Record contained in
                                               server or central files. The physical                   room.                                                 a SOR shall be disclosed by any means
                                               address of either shall also be included.                  (4) Any lock used to secure a room                 of communication to any person, or to
                                                 (2) The categories or types of                        where Records are stored shall not be                 another agency, unless prior written
                                               Individuals on whom NCPC Maintains                      capable of being disengaged with a                    consent is obtained from the Individual
                                               Records in the System of Records;                       master key that opens rooms other than                to whom the Record pertains.
                                                 (3) The categories or types of Records                those in which Records are stored.                       (b) The limitations on disclosure
                                               in the System;                                             (c) Computerized Records subject to                contained in paragraph (a) of this
                                                 (4) The statutory or Executive Order                  the Privacy Act shall be maintained, at               section shall not apply when disclosure
                                               authority for Maintenance of the                        a minimum, subject to the safeguards                  of a Record is:
                                               System;                                                 recommended by the National Institute                    (1) To employees of the NCPC for use
                                                 (5) The purpose(s) or explanation of                  of Standards and Technology (NIST)                    in the performance of their duties;
                                               why the NCPC collects the particular                    Special Publications 800–53,                             (2) Required by the Freedom of
                                               Records including identification of all                 Recommended Security Controls for                     Information Act (FOIA), 5 U.S.C. 555;
                                               internal and routine uses;                              Federal Information Systems and                          (3) For a Routine Use as described in
                                                 (6) The policies and practices of the                 Organizations as revised from time to                 a SORN;
                                               NCPC regarding storage, retrieval, access               time or any superseding guidance                         (4) To the Bureau of Census for
                                               controls, retention and disposal of                     offered by NIST or other federal agency               statistical purposes, provided that the
                                               Records;                                                charged with the responsibility for                   Record must be transferred in a form
                                                 (7) The title and business address of                 providing recommended safeguards for                  that precludes individual identification;
                                               the agency official responsible for the                 computerized Records subject to the                      (5) To an Individual who provides
                                               identified System of Records;                           Privacy Act.                                          NCPC adequate written assurance that
                                                 (8) The NCPC procedures for                              (d) NCPC shall maintain a System of                the Record shall be used solely for
                                               notification to an Individual who                       Records comprised of Office of                        statistical or research purposes,
                                               requests if a System of Records contains                Personnel Management (OPM)                            provided that the Record must be
                                               a Record about the Individual; and                      personnel Records in accordance with                  transferred in a form that precludes
                                                 (9) The NCPC sources of Records in                    standards prescribed by OPM and                       Individual identification;
                                               the System.                                             published at 5 CFR 293.106–293.107.                      (6) To the NARA because the Record
                                                                                                                                                             warrants permanent retention because
                                               § 603.7   Procedures to safeguard Records.              § 603.8   Employee conduct.                           of historical or other national value as
                                                 (a) The NCPC shall implement the                         (a) Employees with duties requiring                determined by NARA or to permit
                                               procedures set forth in this section to                 access to and handling of Records shall,              NARA to determine whether the Record
                                               insure sufficient administrative,                       at all times, take care to protect the                has such value;
sradovich on DSKBBY8HB2PROD with RULES2




                                               technical and physical safeguards exist                 integrity, security, and confidentiality of              (7) To a law enforcement agency for
                                               to protect the security and                             the Records.                                          a civil or criminal law enforcement
                                               confidentiality of Records. The                            (b) No employee of the NCPC shall                  activity, provided that the law
                                               enumerated procedures shall also                        disclose Records unless disclosure is                 enforcement agency must submit a
                                               protect against any anticipated threats                 permitted by § 603.10(b), by part 602 of              written request to the NCPC specifying
                                               or hazards to the security of Records                   this chapter, or disclosed to the                     the Record(s) sought and the purpose for
                                               with the potential to cause substantial                 Individual to whom the Record pertains.               which they will be used;


                                          VerDate Sep<11>2014   18:44 Sep 19, 2017   Jkt 241001   PO 00000   Frm 00015   Fmt 4701   Sfmt 4700   E:\FR\FM\20SER2.SGM    20SER2


                                               44050        Federal Register / Vol. 82, No. 181 / Wednesday, September 20, 2017 / Rules and Regulations

                                                  (8) To any person upon demonstration                 at www.ncpc.gov. If sent via email or                 System of Record in which they are kept
                                               of compelling information that an                       facsimile, the request shall be directed              as identified in the list of NCPC’s
                                               Individual’s health or safety is at stake               to the email address or facsimile                     SORNs published on its Web site; and
                                               and provided that upon disclosure,                      number indicated on the NCPC Web                         (3) State pursuant to the fee schedule
                                               notification is given to the Individual to              site. To expedite internal handling of                in set forth in § 603.17 a willingness to
                                               whom the Record pertains at that                        Privacy Act Requests, the words Privacy               pay all fees associated with the Privacy
                                               Individual’s last known address;                        Act Request shall appear prominently                  Act Request or the maximum fee the
                                                  (9) To either House of Congress, and                 on the envelop or the subject line of an              Requester is willing to pay.
                                               any committee or subcommittee thereof,                  email or facsimile cover sheet.                          (c) The NCPC shall require
                                               to include joint committees of both                        (b) The Request shall state that the               identification as follows before releasing
                                               houses and any subcommittees thereof,                   Individual is seeking information                     Records to an Individual:
                                               when a Record falls within their                        concerning the existence of Records                      (1) An Individual Requesting Privacy
                                               jurisdiction;                                           about himself/herself and shall supply                Act Records in person shall present a
                                                  (10) To the Comptroller General, or                  information describing the System                     valid, photographic form of
                                               any of his authorized representatives, to               where such Records might be                           identification such as a driver’s license,
                                               allow the Government Accountability                     maintained as set forth in a System of                employee identification card, or
                                               Office to perform its duties;                           Record Notice.                                        passport that renders it possible for the
                                                  (11) Pursuant to a court order by a                     (c) The NCPC PAO shall notify the                  PAO to verify that the Individual is the
                                               court of competent jurisdiction; and                    Requester in writing within 20                        same Individual as contained in the
                                                  (12) To a consumer reporting agency                  Workdays of the Request whether a                     requested Records.
                                               trying to collect a claim of the                        System contains Records pertaining to                    (2) An Individual Requesting Privacy
                                               government as authorized by 31 U.S.C.                   him/her unless the Records were                       Act Records by mail shall state their full
                                               3711(e).                                                compiled in reasonable anticipation of a              name, address and date of birth in their
                                                                                                       civil action or proceeding or the Records             correspondence. The Request must be
                                               § 603.11   Accounting of disclosures.                   are NCPC employee Records under the                   signed and the signature must either be
                                                 (a) Except for disclosures made under                 jurisdiction of the OPM. In both of the               notarized or submitted with a statement
                                               §§ 603.10(b)(1)–(2), when a Record is                   later cases the Request shall be denied.              signed and dated as follows: I declare
                                               disclosed to any person, or to another                  If the Request is denied because the                  under penalty of perjury that the
                                               agency, NCPC shall prepare an                           Record(s) is/are under the jurisdiction of            foregoing facts establishing my
                                               accounting of the disclosure. The                       the OPM, the response shall advise the                identification are true and correct.
                                               accounting shall Record the date,                       Requester to contact OPM. If the PAO                     (d) The PAO shall determine within
                                               nature, and purpose of the disclosure                   denies the Request, the response shall                20 Workdays whether to grant or deny
                                               and the name and address of the person                  state the reason for the denial and                   an Individual’s Request for Access to
                                               or agency to whom the disclosure was                    advise the Requester of the right to                  the requested Record(s) and notify the
                                               made. The NCPC shall maintain all                       appeal the decision within 60 days of                 Individual in writing accordingly. The
                                               accountings for a minimum of five years                 the date of the letter denying the request            PAO’s response shall state his/her
                                               or the life of the Record, whichever is                 in accordance with the requirements set               determination and the reasons therefor.
                                               greatest, after the disclosure is made.                 forth in § 603.16.                                    If the Request is denied because the
                                                 (b) Except for disclosures under                                                                            Record(s) is/are under the jurisdiction of
                                               § 603.10(b)(7), accountings of all                      § 603.13    Requests for access to Records.           the OPM, the response shall advise the
                                               disclosures shall be made available to                     (a) An Individual seeking access to                Requester to contact OPM. In the case of
                                               the Individual about whom the                           Records about himself/herself shall do                an Adverse Determination, the written
                                               disclosed Records pertains at his/her                   so by appearing in person at NCPC’s                   notification shall advise the Individual
                                               request. Such request shall be made in                  official place of business or by written              of his/her right to appeal the Adverse
                                               accordance with the requirements of                     correspondence to the NCPC Privacy                    Determination in accordance with the
                                               § 603.15.                                               Act Officer. In-person requests shall be              requirements of § 603.16.
                                                 (c) For any disclosure for which an                   by appointment only with the Privacy
                                               accounting is made, if a subsequent                     Act Officer on a Workday during regular               § 603.14 Requests for Amendment or
                                               amendment or correction or notation of                  office hours. For written requests sent               Correction of Records.
                                               dispute is made to a Record by the                      via the U.S. mail, the Request shall be                  (a) An Individual seeking to amend or
                                               NCPC in accordance with the                             directed to the Privacy Act Officer at                correct a Record pertaining to him/her
                                               requirements of § 603.14, the Individual                NCPC’s official address listed at                     that he/she believes to be inaccurate,
                                               and/or agency to whom the Record was                    www.ncpc.gov. If sent via email or                    irrelevant, untimely or incomplete shall
                                               originally disclosed shall be informed.                 facsimile, the request shall be directed              submit a written request to the PAO at
                                                                                                       to the email address or facsimile                     the address listed on NCPC’s official
                                               § 603.12 Requests for notification of the               number indicated on the NCPC Web                      Web site www.ncpc.gov. If sent via
                                               existence of Records.                                                                                         email or facsimile, the Request shall be
                                                                                                       site. To expedite internal handling of
                                                 (a) An Individual seeking to                          Privacy Act Requests, the words Privacy               directed to the email address or
                                               determine whether a System of Records                   Act Request shall appear prominently                  facsimile number indicated on the
                                               contains Records pertaining to him/her                  on the envelop or the subject line of an              NCPC Web site. To expedite internal
                                               shall do so by appearing in person at                   email or facsimile cover sheet.                       handling, the words Privacy Act
                                               NCPC’s official place of business or by                    (b) The Request shall:                             Request shall appear prominently on the
sradovich on DSKBBY8HB2PROD with RULES2




                                               written correspondence to the NCPC                         (1) State the Request is made pursuant             envelop or the subject line of an email
                                               PAO. In-person requests shall be by                     to the Privacy Act;                                   or facsimile cover sheet.
                                               appointment only with the PAO on a                         (2) Describe the requested Records in                 (b) The Request shall:
                                               Workday during regular office hours.                    sufficient detail to enable their location               (1) State the Request is made pursuant
                                               Written requests sent via the U.S. mail                 including, without limitation, the dates              to the Privacy Act;
                                               shall be directed to the Privacy Act                    the Records were compiled and the                        (2) Describe the requested Record in
                                               Officer at NCPC’s official address listed               name or identifying number of each                    sufficient detail to enable its location


                                          VerDate Sep<11>2014   18:44 Sep 19, 2017   Jkt 241001   PO 00000   Frm 00016   Fmt 4701   Sfmt 4700   E:\FR\FM\20SER2.SGM   20SER2


                                                            Federal Register / Vol. 82, No. 181 / Wednesday, September 20, 2017 / Rules and Regulations                                          44051

                                               including, without limitation, the dates                been made and, if applicable, the                     of the legal, factual or other basis for the
                                               the Records was compiled and the name                   substance of the change.                              Requester’s objection to an Adverse
                                               or identifying number of the System of                                                                        Determination; a daytime phone number
                                               Record in which the Record is kept as                   § 603.15 Requests for Accounting of                   or email where the Requester can be
                                                                                                       Record disclosures.
                                               identified in the list of NCPC’s SORNs                                                                        reached if the Chairman requires
                                               published on its Web site;                                 (a) An Individual seeking information              additional information or clarification
                                                  (3) State in detail the reasons why the              regarding an accounting of disclosure of              regarding the appeal; copies of the
                                               Record, or objectionable portion(s)                     a Record pertaining to him/her made in                initial request and the PAO’s written
                                               thereof, is/are not accurate, relevant,                 accordance with § 603.11 shall submit a               response; and for an Adverse
                                               timely or complete.                                     written request to the PAO at the                     Determination regarding a fee waiver, a
                                                  (4) Include copies of documents or                   address listed on NCPC’s official Web                 demonstration of compliance with part
                                               evidence relied upon in support of the                  site www.ncpc.gov. If sent via email or               602 of this chapter.
                                               Request for Amendment or Correction;                    facsimile, the Request shall be directed                 (c) The Chairman shall respond to an
                                               and                                                     to the email address or facsimile                     appeal of an Adverse Determination in
                                                  (5) State specifically, and in detail,               number indicated on the NCPC Web                      writing within 20 Workdays of receipt
                                               the changes sought to the Record, and                   site. To expedite internal handling, the              of the appeal. If the Chairman grants the
                                               if the changes include rewriting the                    words Privacy Act Request shall appear                appeal, the Chairman shall notify the
                                               Record, or portions thereof, or adding                  prominently on the envelop or the                     Requester, and the NCPC shall take
                                               new language, the Individual shall                      subject line of an email or facsimile                 prompt action to respond affirmatively
                                               propose specific language to implement                  cover sheet.                                          to the original Request upon receipt of
                                               the requested changes.                                     (b) The Request shall:
                                                  (c) A request to Amend or Correct a                                                                        any fees that may be required. If the
                                                                                                          (1) State the Request is made pursuant
                                               Record shall be submitted only if the                                                                         Chairman denies the appeal, the letter
                                                                                                       to the Privacy Act; and
                                               Requester has previously requested and                                                                        shall state the reason(s) for the denial,
                                                                                                          (2) Describe the requested Record in
                                               been granted access to the Record and                                                                         a statement that the decision is final,
                                                                                                       sufficient detail to determine whether it
                                               has inspected or been given a copy of                                                                         and advise the Requester of the right to
                                                                                                       is or is not contained in an accounting
                                               the Record.                                                                                                   seek judicial review of the denial in the
                                                                                                       of disclosure.
                                                  (d) The PAO shall render a decision                                                                        District Court of the United States in
                                                                                                          (c) The NCPC PAO shall notify the
                                               within 20 Workdays. If the Request for                                                                        either the district in which the
                                                                                                       Requester in writing within 20
                                               an Amendment or Correction fails to                                                                           Requester resides, the district in which
                                                                                                       Workdays of the Request and advise if
                                               meet the requirements of paragraphs                                                                           the Requester has his/her principal
                                                                                                       the Record was included in an
                                               (b)(1)–(5) of this section, the PAO shall                                                                     place of business or the District of
                                                                                                       accounting of disclosure. In the event of
                                               advise the Individual of the deficiency                                                                       Columbia.
                                                                                                       a disclosure, the response shall include
                                               and advise what additional information                  the date, nature, and purpose of the                     (d) The appeal of an Adverse
                                               is required to act upon the Request. The                disclosure and the name and address of                Determination based on OPM
                                               timeframe for a decision on the Request                 the person or agency to whom the                      jurisdiction of the Records shall be
                                               shall be tolled (stopped) during the                    disclosure was made. If the Request is                made to OPM pursuant to 5 CFR
                                               pendency of a request for additional                    denied because the Record(s) is/are                   297.306.
                                               information and shall resume when the                   under the jurisdiction of the OPM, the                   (e) The NCPC shall not act on an
                                               additional information is received. If the              response shall advise the Requester to                appeal of an Adverse Determination if
                                               Requester fails to submit the requested                 contact OPM. In the event of an Adverse               the underlying Request becomes the
                                               additional information within a                         Determination, the written notification               subject of litigation.
                                               reasonable time, the PAO shall reject the               shall advise the Individual of his/her                   (f) A party seeking court review of an
                                               Request.                                                right to appeal the Adverse                           Adverse Determination must first appeal
                                                  (e) The PAO’s decision on a Request                  Determination in accordance with the                  the Adverse Determination under this
                                               for Amendment or Correction shall be in                 requirements of § 603.16.                             section.
                                               writing and state the basis for the
                                               decision. If the Request is denied                      § 603.16 Appeals of Adverse                           § 603.17   Fees.
                                               because the Record(s) is/are under the                  Determinations.                                         (a) The NCPC shall charge for the
                                               jurisdiction of the OPM, the response                      (a) Except for appeals pursuant to                 duplication of Records under this
                                               shall advise the Requester to contact                   paragraph (d) of this section, an appeal              subpart in accordance with the schedule
                                               OPM. In the event of an Adverse                         of an Adverse Determination shall be                  of fees set forth in part 602 of this
                                               Determination, the written notification                 made in writing addressed to the                      chapter. The NCPC shall not charge
                                               shall advise the Individual of his/her                  Chairman (Chairman) of the National                   duplication fees when the Requester
                                               right to appeal the Adverse                             Capital Planning Commission at the                    asks to inspect the Records personally
                                               Determination in accordance with the                    address listed on NCPC’s official Web                 but is provided copies at the discretion
                                               requirements of § 603.16.                               site www.ncpc.gov. If sent via email or               of the agency.
                                                  (f) If the PAO approves the Request                  facsimile, the Request shall be directed                (b) The NCPC shall not charge any
                                               for Amendment or Correction, the PAO                    to the email address or facsimile                     fees for the search for or review of
                                               shall ensure that subject Record is                     number indicated on the NCPC Web                      Records requested by an Individual.
                                               amended or corrected, in whole or in                    site. To expedite internal handling, the
                                               part. If the PAO denies the Request for                 words Privacy Act Request shall appear                § 603.18   Privacy Impact Assessments.
sradovich on DSKBBY8HB2PROD with RULES2




                                               Amendment or Correction, a notation of                  prominently on the envelop or the                       (a) Consistent with the requirements
                                               dispute shall be noted on the Record. If                subject line of an email or facsimile                 of the E-Government Act and OMB
                                               an accounting of disclosure has been                    cover sheet. An appeal of an Adverse                  Memorandum M–03–22, the NCPC shall
                                               made pursuant to § 603.11, the PAO                      Determination shall be made within 30                 conduct a PIA before:
                                               shall advise all previous recipients of                 Workdays of the date of the decision.                   (1) Developing or procuring IT
                                               the Record that an amendment or                            (b) An appeal of an Adverse                        systems or projects that collect,
                                               correction or notation of dispute has                   Determination shall include a statement               maintain, or disseminate IIF; or


                                          VerDate Sep<11>2014   18:44 Sep 19, 2017   Jkt 241001   PO 00000   Frm 00017   Fmt 4701   Sfmt 4700   E:\FR\FM\20SER2.SGM   20SER2


                                               44052        Federal Register / Vol. 82, No. 181 / Wednesday, September 20, 2017 / Rules and Regulations

                                                 (2) Installing a new collection of                      (3) The intended use for the                        request to develop or procure
                                               information that will be collected,                     information;                                          information technology that collects,
                                               maintained, or disseminated using IT                      (4) The identity of those with whom                 maintains, or disseminates Information
                                               and includes IIF for 10 or more persons                 the information will be shared;                       in Identifiable Form.
                                               (excluding agencies, instrumentalities or                 (5) The opportunities Individuals
                                                                                                                                                               (f) The SAOP shall approve and sign
                                               employees of the federal government).                   have to decline to provide the
                                                                                                                                                             the NCPC’s PIA. If the SAOP is the
                                                 (b) The PIA shall be prepared through                 information or to consent to particular
                                                                                                                                                             Contracting Officer for the IT system
                                               the coordinated effort of the NCPC’s                    uses and how to consent;
                                                                                                         (6) The manner in which the                         that necessitated preparation of the PIA,
                                               privacy Officers (SAOP, PAO), Division                                                                        the Executive Director shall approve
                                               Directors, CIO, and IT staff.                           information will be secured; and
                                                                                                         (7) The extent to which the system of               and sign the PIA.
                                                 (c) As a general rule, the level of                   records is being created under the                      (g) Following approval of the PIA, the
                                               detail and content of a PIA shall be                    Privacy Act.                                          NCPC shall post the PIA document on
                                               commensurate with the nature of the                       (d) In addition to the information                  the NCPC Web site located at
                                               information to be collected and the size                specified in paragraphs (b)(1)–(7) of this            www.ncpc.gov.
                                               and complexity of the IT system                         section, the PIA must also identify the
                                               involved. Specifically, a PIA shall                                                                             Dated: September 14, 2017.
                                                                                                       choices NCPC made regarding an IT
                                               analyze and describe:                                   system or collection of information as                Anne R. Schuyler,
                                                 (1) The information to be collected;                  result of preparing the PIA.                          General Counsel.
                                                 (2) The reason the information is                       (e) The CCB shall verify that a PIA has             [FR Doc. 2017–19996 Filed 9–19–17; 8:45 am]
                                               being collected;                                        been prepared prior to approving a                    BILLING CODE 7520–01–P
sradovich on DSKBBY8HB2PROD with RULES2




                                          VerDate Sep<11>2014   18:44 Sep 19, 2017   Jkt 241001   PO 00000   Frm 00018   Fmt 4701   Sfmt 9990   E:\FR\FM\20SER2.SGM   20SER2



Document Created: 2018-10-24 14:22:53
Document Modified: 2018-10-24 14:22:53
CategoryRegulatory Information
CollectionFederal Register
sudoc ClassAE 2.7:
GS 4.107:
AE 2.106:
PublisherOffice of the Federal Register, National Archives and Records Administration
SectionRules and Regulations
ActionFinal rule.
DatesThis rule is effective October 20, 2017.
ContactAnne R. Schuyler, General Counsel at 202-482-7223, [email protected]
FR Citation82 FR 44044 
CFR Citation1 CFR 455
1 CFR 603

2025 Federal Register | Disclaimer | Privacy Policy
USC | CFR | eCFR