GAO: Senior privacy officials need authority

Agencies need to delegate oversight to their senior privacy officials to ensure the government protects the personal data it collects, the Government Accountability Office said in a recent report.

Senior agency privacy officials conduct a variety of activities required under privacy laws to coordinate privacy policy and compliance.

However, not all agencies give their senior privacy officials full oversight over all key privacy functions, Linda Koontz, director of GAO’s information management issues, said June 18.

“As a result, agencies may not be implementing privacy protections consistently,” she said. Without authority over all key privacy functions, these designated senior officials may be unable to effectively serve as the agency’s central point for information policy, she added.

Of the 12 agencies that GAO reviewed from September 2007 to May 2008, six assigned their senior privacy officials oversight of all key privacy functions. Those were the Homeland Security, State, Transportation and Veterans Affairs departments, and the Social Security Administration and the U.S. Agency for International Development, the report said.

However, six agencies relied on other offices in the agency that the designated official did not oversee, to perform some of the privacy functions. GAO recommended that those departments revise their policy to give the senior agency officials for privacy oversight over those activities. They are the departments of Commerce, Defense, Health and Human Services and Labor. At the Justice and Treasury departments, the sole function that the senior agency official for privacy does not oversee is redress of privacy complaints, according to the report.

Among their activities, the designated senior agency officials for privacy:



  • Perform activities to comply with the Privacy Act, such as publishing notices in the Federal Register of data to be collected and used in a system of records.

  • Conduct privacy impact assessments to evaluate risk from use of information systems to process personal data.

  • Produce reports on the status of privacy protections as part of compliance with the Federal Information Security Management Act.

  • Establish redress procedures to handle privacy complaints.

  • Assure that employees and contractors receive appropriate training.

About the Author

Mary Mosquera is a reporter for Federal Computer Week.

Featured

  • Defense
    Ryan D. McCarthy being sworn in as Army Secretary Oct. 10, 2019. (Photo credit: Sgt. Dana Clarke/U.S. Army)

    Army wants to spend nearly $1B on cloud, data by 2025

    Army Secretary Ryan McCarthy said lack of funding or a potential delay in the JEDI cloud bid "strikes to the heart of our concern."

  • Congress
    Rep. Jim Langevin (D-R.I.) at the Hack the Capitol conference Sept. 20, 2018

    Jim Langevin's view from the Hill

    As chairman of of the Intelligence and Emerging Threats and Capabilities subcommittee of the House Armed Services Committe and a member of the House Homeland Security Committee, Rhode Island Democrat Jim Langevin is one of the most influential voices on cybersecurity in Congress.

Stay Connected

FCW INSIDER

Sign up for our newsletter.

I agree to this site's Privacy Policy.