Download:
pdf |
pdfThe Privacy Office
U.S. Department of Homeland Security
Washington, DC 20528
202-343-1717, [email protected]
www.dhs.gov/privacy
Privacy Threshold Analysis
Version date: November 6, 2012
Page 1 of 7
PRIVACY THRESHOLD ANALYSIS (PTA)
This form is used to determine whether
a Privacy Impact Assessment is required.
Please use the attached form to determine whether a Privacy Impact Assessment (PIA) is required under
the E-Government Act of 2002 and the Homeland Security Act of 2002.
Please complete this form and send it to your component Privacy Office. If you do not have a component
Privacy Office, please send the PTA to the DHS Privacy Office:
Rebecca J. Richards
Senior Director of Privacy Compliance
The Privacy Office
U.S. Department of Homeland Security
Washington, DC 20528
Tel: 202-343-1717
[email protected]
Upon receipt from your component Privacy Office, the DHS Privacy Office will review this form. If a
PIA is required, the DHS Privacy Office will send you a copy of the Official Privacy Impact Assessment
Guide and accompanying Template to complete and return.
A copy of the Guide and Template is available on the DHS Privacy Office website,
www.dhs.gov/privacy, on DHSConnect and directly from the DHS Privacy Office via email:
[email protected], phone: 202-343-1717.
The Privacy Office
U.S. Department of Homeland Security
Washington, DC 20528
202-343-1717, [email protected]
www.dhs.gov/privacy
Privacy Threshold Analysis
Version date: November 6, 2012
Page 2 of 7
PRIVACY THRESHOLD ANALYSIS (PTA)
SUMMARY INFORMATION
Project or
Program Name:
FEMA 1660-0002 Disaster Assistance Registration
Component:
Federal Emergency
Management Agency (FEMA)
Office or
Program:
Click here to enter text.
TAFISMA Name:
Click here to enter text.
TAFISMA
Number:
Click here to enter text.
Type of Project or
Program:
Form or other Information
Collection
Project or
program
status:
Modification
PROJECT OR PROGRAM MANAGER
Name:
Elizabeth McDowell
Office:
ORR - Recovery
Title:
Lead Program Specialist
Phone:
540.686.3630
Email:
[email protected]
INFORMATION SYSTEM SECURITY OFFICER (ISSO)
Name:
Click here to enter text.
Phone:
Click here to enter text.
Email:
ROUTING INFORMATION
Date submitted to Component Privacy Office:
August 20, 2013
Date submitted to DHS Privacy Office:
October 23, 2013
Date approved by DHS Privacy Office:
October 28, 2013
Click here to enter text.
The Privacy Office
U.S. Department of Homeland Security
Washington, DC 20528
202-343-1717, [email protected]
www.dhs.gov/privacy
Privacy Threshold Analysis
Version date: November 6, 2012
Page 3 of 7
SPECIFIC PTA QUESTIONS
1. Please describe the purpose of the project or program:
Please provide a general description of the project and its purpose in a way a non-technical person could
understand.
The Federal Emergency Management Agency provides financial needs and services to individuals who
apply for disaster assistance benefits in the event of a federal declared disaster, in accordance with the
Robert T Stafford Disaster Relief and Emergency Act, as amended, 42 U.S.C. § 5174. FEMA implements
the policies and procedures of this provision under 44 C.F.R. § 206.110 et seq. FEMA provides financial
assistance and, if necessary, direct assistance to eligible individuals and households who, as a direct
result of a major disaster or emergency, have uninsured or under-insured, necessary expenses and
serious needs and are unable to meet such expense or needs through other means. Individuals and
households that apply for this assistance must provide information detailing their losses and needs.
Through its ICR 1660-0002, FEMA collects personally identifiable information (PII) and other information
from registrants to facilitate the provision of the assistance noted above. FEMA collects this PII through a
variety of media including paper forms (009-0-1 and 009-0-2, 009-0-3, 009-0-4, 009-0-5 and 009-0-6), via
telephone, and the www.disasterassistance.gov website, and its smartphone application.
In 2013, the President signed into law the Sandy Recovery Improvement Act of 2013 (SRIA), Pub. L. No.
113-2, amending the Stafford Act. This collection accounts for changes to the Stafford Act; specifically the
ability of Indian Tribes to work directly with FEMA as a sovereign nation and the addition of child care
(Section 1108) as an eligible disaster expense under the IHP.
2. Project or Program status
July 1, 2006
Date first developed:
August 20, 2013
Date last updated:
Choose an item.
Pilot launch date:
Pilot end date:
Click here to enter a date.
Click here to enter a date.
DHS Employees
3. From whom does the Project or
Program collect, maintain, use or
disseminate information?
Please check all that apply.
1
Contractors working on behalf of DHS
Members of the public
This program does not collect any personally
identifiable information1
DHS defines personal information as “Personally Identifiable Information” or PII, which is any information that permits the
identity of an individual to be directly or indirectly inferred, including any information that is linked or linkable to that individual,
regardless of whether the individual is a U.S. citizen, lawful permanent resident, visitor to the U.S., or employee or contractor to
The Privacy Office
U.S. Department of Homeland Security
Washington, DC 20528
202-343-1717, [email protected]
www.dhs.gov/privacy
Privacy Threshold Analysis
Version date: November 6, 2012
Page 4 of 7
4. What specific information about individuals could be collected, generated or retained?
Please provide a specific description of information that might be collected, generated or retained such
as names, addresses, emails, etc.
The registrant and/or household members name, damaged dwelling address, current mailing address,
current phone number, alternate phone number, cell phone number, birth date, Social Security Number,
household income, banking information (bank name, bank account information), insurance information,
residence type, vehicle information, and email address.
Does the Project or Program use Social
Security Numbers (SSNs)?
Yes
If yes, please provide the legal authority for
the collection of SSNs:
Debt Collection Improvement Act of 1996, 31
U.S.C. § 7701(c)(1).
If yes, please describe the uses of the SSNs
within the Project or Program:
SSN is to facilitate payment of disaster assistance,
verify/validate identity, prevent a duplication of
benefits and the recoupment of any potential debt or
overpayment.
5. Does this system employ any of the
following technologies:
Closed Circuit Television (CCTV)
Sharepoint-as-a-Service
If project or program utilizes any of these
technologies, please contact Component Privacy
Officer for specialized PTA.
Social Media
Mobile Application (or GPS)
Web portal2
None of the above
If this project is a technology/system, does
it relate solely to infrastructure?
For example, is the system a Local Area Network
(LAN) or Wide Area Network (WAN)?
No. Please continue to next question.
Yes. If a log kept of communication traffic,
please answer the following question.
the Department. “Sensitive PII” is PII, which if lost, compromised, or disclosed without authorization, could result in substantial
harm, embarrassment, inconvenience, or unfairness to an individual. For the purposes of this PTA, SPII and PII are treated the
same.
2
Informational and collaboration-based portals in operation at DHS and its components which collect, use,
maintain, and share limited personally identifiable information (PII) about individuals who are “members” of the
portal or who seek to gain access to the portal “potential members.”
The Privacy Office
U.S. Department of Homeland Security
Washington, DC 20528
202-343-1717, [email protected]
www.dhs.gov/privacy
Privacy Threshold Analysis
Version date: November 6, 2012
Page 5 of 7
If header or payload data3 is stored in the communication traffic log, please detail the data
elements stored.
Click here to enter text.
No.
6. Does this project or program connect,
receive, or share PII with any other
DHS programs or systems4?
Yes. Individual Assistance (IA); Disaster
Assistance Improvement Program (DAIP);
Document Management and Records Tracking
System (DMARTS); Automated Construction
Estimating (ACE) System
Click here to enter text.
7. Does this project or program connect,
receive, or share PII with any external
(non-DHS) partners or systems?
No.
Yes. If yes, please list:
Click here to enter text.
Is this external sharing pursuant to new
or existing information sharing access
agreement (MOU, MOA, LOI, etc.)?
Existing
FEMA has an existing Computer Matching
Agreement with the Small Business Administration.
Click here to enter text.
3
When data is sent over the Internet, each unit transmitted includes both header information and the actual data
being sent. The header identifies the source and destination of the packet, while the actual data is referred to as the
payload. Because header information, or overhead data, is only used in the transmission process, it is stripped from
the packet when it reaches its destination. Therefore, the payload is the only data received by the destination system.
4 PII may be shared, received, or connected to other DHS systems directly, automatically, or by manual processes.
Often, these systems are listed as “interconnected systems” in TAFISMA.
The Privacy Office
U.S. Department of Homeland Security
Washington, DC 20528
202-343-1717, [email protected]
www.dhs.gov/privacy
Privacy Threshold Analysis
Version date: November 6, 2012
Page 6 of 7
PRIVACY THRESHOLD REVIEW
(TO BE COMPLETED BY COMPONENT PRIVACY OFFICE)
Component Privacy Office Reviewer:
Lane Raffray
Date submitted to DHS Privacy Office:
Click here to enter a date.
Component Privacy Office Recommendation:
Please include recommendation below, including what new privacy compliance documentation is needed.
PIA: DHS/FEMA/PIA - 012a Disaster Assistance Improvement Program (DIAP), DHS/FEMA/PIA –
009(a) Document Management and Records Tracking System (DMARTS)
SORN: DHS/FEMA 008 Disaster Recovery Assistance Files
(TO BE COMPLETED BY THE DHS PRIVACY OFFICE)
DHS Privacy Office Reviewer:
Jameson Morgan
Date approved by DHS Privacy Office:
October 28, 2013
PCTS Workflow Number:
997849
DESIGNATION
Privacy Sensitive System:
Category of System:
Determination:
Yes
If “no” PTA adjudication is complete.
IT System
If “other” is selected, please describe: Click here to enter text.
PTA sufficient at this time.
Privacy compliance documentation determination in progress.
New information sharing arrangement is required.
DHS Policy for Computer-Readable Extracts Containing Sensitive PII
applies.
Privacy Act Statement required.
Privacy Impact Assessment (PIA) required.
System of Records Notice (SORN) required.
System covered by existing PIA
PIA:
If covered by existing PIA, please list: DHS/FEMA/PIA – 009(a) Document Management
and Records Tracking System (DMARTS), May 15, 2013, (PDF, 18 pages-283KB);
DHS/FEMA/PIA – 12(a) Disaster Assistance Improvement Program (DAIP) November 16,
The Privacy Office
U.S. Department of Homeland Security
Washington, DC 20528
202-343-1717, [email protected]
www.dhs.gov/privacy
Privacy Threshold Analysis
Version date: November 6, 2012
Page 7 of 7
2012 (PDF, 27 pages-384 KB).
System covered by existing SORN
SORN:
If covered by existing SORN, please list: DHS/FEMA-008 - Disaster Recovery Assistance
Files
DHS Privacy Office Comments:
Please describe rationale for privacy compliance determination above.
The DHS Privacy Office agrees with the FEMA Privacy Office’s recommendation that this The
Disaster Assistance Registration PTA should receive coverage under the DHS/FEMA/PIA – 012a
Disaster Assistance Improvement Program (DIAP) PIA, the DHS/FEMA/PIA – 009(a) Document
Management and Records Tracking System (DMARTS), and the DHS/FEMA - 008 Disaster Recovery
Assistance Files SORN.
This program collects information from members of the public in order to facilitate the provision of
financial assistance to members of the public affected by the result of a disaster or emergency. This
information collection directly supports FEMA’s mission of providing assistance to people that are
uninsured or under-insured, and who have serious needs and are unable to meet such expense or needs
through other means. This PTA is being submitted to account for changes to the Stafford Act;
specifically the ability of Indian Tribes to work directly with FEMA as a sovereign nation and the
addition of child care (Section 1108) as an eligible disaster expense under the IHP.
The DHS/FEMA/PIA-012(a) DAIP PIA provides coverage for collection of information related to
disaster survivor application and registration information collected through various media including:
(1) DAIP paper forms (attached at Appendix A), (2) the www.disasterassistance.gov website, (3) the
http://m.fema.gov mobile website, and (4) via telephone. This PIA covers the collection of information
from members of the public by the Federal Assistance to Individuals and Households Program. The
DHS/FEMA/PIA-009(a) DMARTS PIA covers the storage, retrieval, and dissemination of information
about individuals applying for disaster assistance in the Document Management and Records Tracking
System (DMARTS). The appendices of the DHS/FEMA/PIA - 009(a) DMARTS PIA and the
DHS/FEMA/PIA – 012(a) do not need to be updated because all of the forms used by Disaster
Assistance Registration are listed in both PIAs.
The DHS/FEMA – 008 Disaster Recovery Assistance Files SORN allows for information collection
from members of the public in a variety of instances including: individuals seeking disaster assistance
from FEMA, for the verification of IHP applicant information, and in order to determine eligibility of
applicants. All categories of records, categories of individuals, and routine uses of the information
collected in the program are consistent with the DHS/FEMA – 008 SORN. If this program changes a
new PTA should be submitted.
File Type | application/pdf |
File Title | DHS PRIVACY OFFICE |
Author | marilyn.powell |
File Modified | 2013-10-29 |
File Created | 2013-10-29 |