Notice of Intent To Request Revision and Extension of a Currently Approved Information Collection
In accordance with the Paperwork Reduction Act of 1995, this notice announces the intention of the National Agricultural Statistics Service (NASS) to request a revision and exte...
In accordance with the Paperwork Reduction Act of 1995, this notice announces the intention of the National Agricultural Statistics Service (NASS) to request a revision and extension of a currently approved information collection titled “NASS Data Security Requirements for Accessing Confidential Data.” NASS plans to collect information from the public to fulfill its data security requirements when providing access to restricted use data for the purpose of evidence building. NASS's data security agreements and other paperwork along with the corresponding security protocols allow NASS to maintain careful controls on confidentiality and privacy, as required by law.
DATES:
Comments on this notice must be received by October 5, 2026 to be assured of consideration.
ADDRESSES:
You may submit comments, identified by docket number 0535-0274, by any of the following methods:
Mail:
Mail any paper, disk, or CD-ROM submissions to: NASS OMB Clearance Officer, U.S. Department of Agriculture, Room 5336 South Building, 1400 Independence Avenue SW, Washington, DC 20250-2024.
Hand Delivery/Courier:
Hand deliver to: NASS OMB Clearance Officer, U.S. Department of Agriculture, Room 5336 South Building, 1400 Independence Avenue SW, Washington, DC 20250-2024.
FOR FURTHER INFORMATION CONTACT:
Jody R. McDaniel, Associate Administrator, National Agricultural Statistics Service, U.S. Department of Agriculture, (202) 720-2707. Copies of this information collection and related instructions can be obtained without charge from NASS OMB Clearance Officer, at (202) 720-2206 or at
ombofficer@nass.usda.gov.
SUPPLEMENTARY INFORMATION:
Title of collection:
NASS Data Security Requirements for Accessing Confidential Data.
OMB Control Number:
0535-0274.
Expiration Date of Current Approval:
April 30, 2027.
Type of Request:
Intent to revise and extend a currently approved information collection for a period of three years.
Abstract:
Title III of the Foundations for Evidence-Based Policymaking Act of 2018 (hereafter referred to as the Evidence Act) mandates that OMB establish a Standard Application Process (SAP) for requesting access to certain confidential data assets. Specifically, the Evidence Act requires OMB to establish a common application process through which agencies, the Congressional Budget Office, State, local, and Tribal governments, researchers, and other individuals, as appropriate, may apply for access to confidential data assets collected, accessed, or acquired by a statistical agency or unit. This new process will be implemented while maintaining stringent controls to protect confidentiality and privacy, as required by law.
Data collected, accessed, or acquired by statistical agencies and units is vital for developing evidence on conditions, characteristics, and behaviors of the public and on the operations and outcomes of public programs and policies. This evidence can benefit the stakeholders in the programs, the broader public, as well as policymakers and program managers at the local, State, Tribal, and National levels. The many benefits of access to data for evidence building notwithstanding, National Agricultural Statistics Service is required by law to maintain careful controls that allow it to minimize disclosure risk while protecting confidentiality and privacy.
The fulfillment of National Agricultural Statistics Service's data security requirements places a degree of burden on the public, which is outlined below.
The SAP Portal is a web-based application for the public to request access to confidential data assets from federal statistical agencies and units. The objective of the SAP Portal is to increase public access to confidential data for the purposes of evidence building and reduce the burden of applying for confidential data. Once an individual's application in the SAP Portal has received a positive determination, the data-owning agency(ies) or unit(s) will begin the process of collecting information to fulfill their data security requirements.
The paragraphs below outline the SAP Policy, the steps to complete an application through the SAP Portal, and the process for agencies to collect information fulfilling their data security requirements.
The SAP Policy
At the recommendation of the ICSP, the SAP Policy establishes the SAP to be implemented by statistical agencies and units and incorporates directives from the Evidence Act. The policy is intended to provide guidance as to the application and review processes using the SAP Portal, setting forth clear standards that enable statistical agencies and units to implement a common application form and a uniform review process. The SAP Policy renewal was submitted to the public for comment in June 2025 (90 FR 25380). The renewal policy was approved and has a current expiration date of 12-31-2028.
( printed page 49404)
The SAP Portal
The SAP Portal is an application interface connecting applicants seeking data with a catalog of data assets owned by the federal statistical agencies and units. The SAP Portal is not a new data repository or warehouse; confidential data assets will continue to be stored in secure data access facilities owned and hosted by the federal statistical agencies and units. The SAP Portal will provide a streamlined application process across agencies, reducing redundancies in the application process. This single SAP Portal will improve the process for applicants, tracking and communicating the application process throughout its lifecycle. This reduces redundancies and burden on applicants that request access to data from multiple agencies. The SAP Portal will automate key tasks to save resources and time and will bring agencies into compliance with the Evidence Act statutory requirements.
Data Discovery
Individuals begin the process of accessing restricted use data by discovering confidential data assets through the SAP data catalog, maintained by federal statistical agencies at
www.sap.nsf.gov.
Potential applicants can search by agency, topic, or keyword to identify data of interest or relevance. Once they have identified data of interest, applicants can view metadata outlining the title, description or abstract, scope and coverage, and detailed methodology related to a specific data asset to determine its relevance to their research.
While statistical agencies and units shall endeavor to include metadata in the SAP data catalog on all confidential data assets for which they accept applications, it may not be feasible to include metadata for some data assets (
e.g.,
potential curated versions of administrative data). A statistical agency or unit may still accept an application even if the requested data asset is not listed in the SAP data catalog.
SAP Application Process
Individuals who have identified and wish to access confidential data assets will be able to apply for access through the SAP Portal. Applicants must create an account and follow all steps to complete the application. Applicants begin by entering their personal, contact, and institutional information, as well as the personal, contact, and institutional information of all individuals on their research team. Applicants proceed to provide summary information about their proposed project, to include project title, duration, funding, timeline, and other details including the data asset(s) they are requesting and any proposed linkages to data not listed in the SAP data catalog, including non-federal data sources. Applicants then proceed to enter detailed information regarding their proposed project, including a project abstract, research question(s), literature review, project scope, research methodology, project products, and anticipated output. Applicants must demonstrate a need for confidential data, outlining why their research question cannot be answered using publicly available information.
Submission for Review
Upon submission of their application, applicants will receive a notification that their application has been received and is under review by the data owning agency or agencies (in the event where data assets are requested from multiple agencies). At this point, applicants will also be notified that application approval does not alone grant access to confidential data, and that, if approved, applicants must comply with the data-owning agency's security requirements outside of the SAP Portal.
In accordance with the Evidence Act and the direction of the ICSP, agencies will approve or reject an application within a prompt timeframe. In some cases, agencies may determine that additional clarity, information, or modification is needed and request the applicant to “revise and resubmit” their application.
Data discovery, the SAP application process, and the submission for review are planned to take place within the web-based SAP Portal. As noted above, the renewal notice to collect information through the SAP Portal has been published separately (90 FR 25380).
Access to Restricted Use Data
In the event of a positive determination, the applicant will be notified that their proposal has been accepted. The positive or final adverse determination concludes the SAP Portal process. In the instance of a positive determination, the data-owning agency (or agencies) will contact the applicant to provide instructions on the agency's security requirements that must be completed to gain access to the confidential data. The completion and submission of the agency's security requirements will take place outside of the SAP Portal.
Collection of Information for Data Security Requirements
In the instance of a positive determination for an application requesting access to a National Agricultural Statistics Service (NASS) confidential data asset, NASS will contact the applicant(s) to initiate the process of collecting information to fulfill their security requirements. These include additional requirements necessary for the statistical agency or unit to place the applicant(s) in a trusted category that may include the applicant's successful completion of identity verification, confidentiality training, nondisclosure, inspection of the site the confidential data will be accessed, and data use agreements.
NASS's data security requirements include the collection of the following:
Security Briefing:
NASS personnel provide a Security Briefing to all applicants who were approved access to restricted data. The Briefing is provided prior to the applicant completing the three forms listed below and includes information on the Confidential Information Protection and Statistical Efficiency Act of 2018, Title III of Public Law 115-435, codified in 44 U.S.C. Ch. 35 and other applicable Federal laws that protect the restricted data.
Completion of formADM-043, Certification and Restrictions on Use of Unpublished Data.
This form is required to be signed by researchers who have been approved to access unpublished NASS data (alternatively, some approved researchers complete on-line training in lieu of completing this form). The form contains excerpts of the various laws that apply to the unpublished data being provided to the researcher. The form explains the restrictions associated with the unpublished data and includes a place for the research to sign the form, thereby acknowledging the restrictions and agreeing to abide by them.
Completion ofUser Attestation Form.
Researchers approved to access unpublished NASS data are provided with the document
Handbook for Special Sworn Data Users of a NASS Data Lab
that explains the policies and procedures associated with accessing unpublished NASS data in a NASS Data Lab (including data enclaves). Each researcher approved to access unpublished NASS data is required to sign the
User Attestation Form
to acknowledge they were provided with the
Handbook for Special Sworn Data Users of a NASS Data Lab
and agree to abide by its provisions.
( printed page 49405)
Completion ofNASS Site Inspection Checklist.
Researchers approved to access unpublished NASS data do so using a secure data enclave environment accessible at their own location. A NASS employee performs a site inspection (either in-person or via a video call) of the researcher's location prior to the researcher being granted access to the unpublished data. During the site inspection, the NASS employee administers the form
NASS Site Inspection Checklist,
which asks questions pertaining to the suitability of the location for restricted data access and some of the policies associated with accessing the restricted data. The form also collects information about the computer the researcher will use to access the NASS data enclave.
Specifically, researchers will be required to complete the OF-306 (Declaration for Federal Employment) to support onboarding into USDA's human capital management system. This step is necessary to establish a formal relationship between NASS and the researcher and to ensure compliance with federal identity verification and personnel tracking requirements. The OF-306 collects administrative PII such as Social Security Number (SSN), date of birth, sex, and citizenship. This information will be submitted directly to REE Onboarding and will not be retained or processed by NASS. The collection and maintenance of this data are governed by USDA's Privacy Act System of Records Notice (SORN) OCFO/NFC-1—Systems for Personnel, Payroll, and Time & Attendance (89 FR 5481, January 29, 2024). The OF-306 is approved under OMB Control No. 3206-0182. As such, burden associated with completing the OF-306 is not included in this ICR.
In alignment with the Animal and Plant Health Inspection Service (APHIS) notice published on August 19, 2024 (89 FR 67058), the National Agricultural Statistics Service (NASS) has transitioned certain data collection activities previously conducted under OMB Control Number 0579-0500 to OMB Control Number 0535-0274. These activities involve co-owned data between NASS and the National Animal Health Monitoring System (NAHMS). This consolidation under a single control number is intended to streamline data collection processes, enhance data security protocols, and maintain compliance with confidentiality standards as outlined in the APHIS notice.
Estimate of Burden:
The amount of time to complete the agreements and other paperwork, Security Briefing, and read the
Handbook for Special Sworn Data Users
that comprise NASS's security requirements will vary based on the confidential data assets requested and the access modality. To obtain access to NASS confidential data assets, it is estimated that the average time to complete and submit NASS's data security agreements and other paperwork, Security Briefing, and read the
Handbook for Special Sworn Data Users
is 145 minutes per applicant. This estimate does not include the time needed to complete and submit an application within the SAP Portal. All efforts related to SAP Portal applications occur prior to and separate from NASS's effort to collect information related to data security requirements.
The expected number of applications in the SAP Portal that receive a positive determination from NASS in a given year may vary. Overall, per year, NASS estimates it will collect data security information from 200 applicants that received a positive determination within the SAP Portal (note: an SAP Portal application may include access for more than one applicant) or other restricted use access approval. NASS estimates that the total burden for the collection of information for data security requirements over the course of the three-year OMB clearance will be about 1,452 hours and, as a result, an average annual burden of 484 hours.
Below we provide projected average estimates for the next three years:
Total Requests:
200.
Frequency of Request:
Once per request.
Average Minutes per Request:
145 minutes.
Total Estimated Burden Hours:
484
Comments:
Comments are invited on: (a) whether the proposed collection of information is necessary for the proper performance of the functions of the agency, including whether the information will have practical utility; (b) the accuracy of the agency's estimate of the burden of the proposed collection of information including the validity of the methodology and assumptions used; (c) ways to enhance the quality, utility, and clarity of the information to be collected; and (d) ways to minimize the burden of the collection of information on those who are to respond, including through the use of appropriate automated, electronic, mechanical, technological or other forms of information technology collection methods.
All responses to this notice will become a matter of public record and be summarized in the request for OMB approval.
Use this for formal legal and research references to the published document.
91 FR 49403
Web Citation
Suggested Web Citation
Use this when citing the archival web version of the document.
“Notice of Intent To Request Revision and Extension of a Currently Approved Information Collection,” thefederalregister.org (August 4, 2026), https://thefederalregister.org/documents/2026-15755/notice-of-intent-to-request-revision-and-extension-of-a-currently-approved-information-collection.