Privacy and Civil Liberties Policy Development Guide and Implementation Templates
Total Page:16
File Type:pdf, Size:1020Kb
NT O E F M JU T S R T Global Justice A I P C E E Information D Sharing Initiative United States Department of Justice Privacy and Civil Liberties Policy Development Guide and Implementation Templates Providing justice practitioners with practical guidance for the privacy policy development process Privacy and Civil Liberties Policy Development Guide and Implementation Templates Privacy and Civil Liberties Policy Development Guide and Implementation Templates i About Global The U.S. Department of Justice’s Global Justice Information Sharing Initiative (Global) serves as a Federal Advisory Committee to the U.S. Attorney General on critical justice information sharing initiatives. Global promotes standards- based electronic information exchange to provide justice and public safety communities with timely, accurate, complete, and accessible information in a secure and trusted environment. Global is administered by the U.S. Department of Justice, Office of Justice Programs, Bureau of JusticeAssistance. This project was supported by Grant No. 2007-NC-BX-K001 awarded by the Bureau of Justice Assistance, in collaboration with the U.S. Department of Justice’s Global Justice Information Sharing Initiative. The Bureau of Justice Assistance is a component of the Office of Justice Programs, which also includes the Bureau of Justice Statistics, the National Institute of Justice, the Office of Juvenile Justice and Delinquency Prevention, the SMART Office, and the Office for Victims of Crime. Points of view or opinions in this document are those of the author and do not represent the official position or policies of the U.S. Department of Justice. ii Privacy and Civil Liberties Policy Development Guide and Implementation Templates Contents Section 1 Acknowledgments ............................................................................................................. 1-1 Section 2 Foreword ............................................................................................................................. 2-1 Section 3 Introduction ........................................................................................................................ 3-1 Section 4 Privacy Policy Overview .................................................................................................... 4-1 4.1 What Is Privacy? ...................................................................................................................... 4-1 4.2 What Is Personally Identifiable Information? ............................................................................ 4-1 4.3 What Are Civil Liberties? .......................................................................................................... 4-1 4.4 What Is a Privacy and Civil Liberties Policy? ........................................................................... 4-1 4.5 When Should an Entity Develop a Privacy and Civil Liberties Policy? ..................................... 4-2 4.6 The Intersection Between Privacy, Information Quality, and Security ...................................... 4-2 4.6.1 Privacy and Information Quality ..................................................................................... 4-2 4.6.2 Privacy and Security ...................................................................................................... 4-2 4.6.3 Future Guidance Statement ........................................................................................... 4-2 4.7 Resources ................................................................................................................................ 4-3 Section 5 Governance ........................................................................................................................ 5-1 5.1 Identifying the Project Champion or Sponsor ........................................................................... 5-1 5.1.1 Privacy and Civil Liberties Officer .................................................................................. 5-2 5.2 Resource Justification .............................................................................................................. 5-2 5.3 Identifying the Project Team Leader ......................................................................................... 5-3 5.4 Building the Project Team and Stakeholder Contacts .............................................................. 5-3 5.4.1 Project Team .................................................................................................................. 5-3 5.4.2 Stakeholder Contacts .................................................................................................... 5-4 5.5 Team Dynamics ........................................................................................................................ 5-5 5.6 Resources ................................................................................................................................ 5-5 Section 6 Planning .............................................................................................................................. 6-1 6.1 Developing a Vision, Mission, Values Statement, and Goals and Objectives .......................... 6-1 6.1.1 Vision Statement ............................................................................................................ 6-1 6.1.2 Mission Statement ......................................................................................................... 6-2 6.1.3 Values Statement ........................................................................................................... 6-2 6.1.4 Goals and Objectives ..................................................................................................... 6-3 6.1.4.1 Goals ............................................................................................................... 6-3 6.1.4.2 Objectives ....................................................................................................... 6-3 Privacy and Civil Liberties Policy Development Guide and Implementation Templates iii 6.2 Writing the Charter ................................................................................................................... 6-3 6.3 Resources ................................................................................................................................ 6-4 Section 7 Process ............................................................................................................................... 7-1 7.1 Understanding Information Exchanges .................................................................................... 7-1 7.1.1 Tools to Assist With Understanding the Flow of Information .......................................... 7-3 7.1.1.1 Justice System Sequence of Events Flowchart .............................................. 7-3 7.1.1.2 Justice Information Privacy Guideline ............................................................. 7-3 7.1.1.3 Justice Information Exchange Model (JIEM) .................................................. 7-4 7.1.1.4 Privacy Impact Assessment (PIA) ................................................................... 7-5 7.2 Analyzing the Legal Requirements .......................................................................................... 7-5 7.2.1 Introduction .................................................................................................................... 7-5 7.2.2 Approach to the Legal Analysis ..................................................................................... 7-5 7.2.3 Focusing the Legal Analysis .......................................................................................... 7-6 7.2.3.1 Suggestions for Approaching the Legal Analysis ............................................ 7-6 7.2.3.2 Potential Sources of Legal Authority and Limitations ...................................... 7-7 7.2.3.3 Particular Events and Actions ......................................................................... 7-7 7.2.3.4 Information Related to a Specific Person ........................................................ 7-8 7.2.4. Performing the Legal Analysis ....................................................................................... 7-8 7.2.4.1 Principles ........................................................................................................ 7-8 7.2.4.1.1 Collection of Information ................................................................. 7-9 7.2.4.1.2 Information Quality Relative to Collection and Maintenance of Information ................................................................................ 7-10 7.2.4.1.3 Sharing and Dissemination of Information—Public Access .......... 7-10 7.2.4.1.4 Provisions Relevant to the Individual About Whom Information Has Been Collected ................................................... 7-11 7.2.4.1.5 Information and Record Retention and Destruction ...................... 7-11 7.2.4.1.6 Agency or Project Transparency ................................................... 7-12 7.2.4.1.7 Accountability and Enforcement ................................................... 7-12 7.2.4.2 Specific Laws to Examine ............................................................................. 7-13 7.3 Identifying Critical Issues and Policy Gaps ............................................................................ 7-15 7.3.1 Identifying Team Members’ Privacy Concerns ............................................................