Homeland Security:
DHS Privacy Office Has Made Progress but Faces Continuing Challenges
GAO-07-1024T: Published: Jul 24, 2007. Publicly Released: Jul 24, 2007.
Additional Materials:
- Highlights Page:
- Full Report:
- Accessible Text:
Contact:
(202) 512-6240
contact@gao.gov
Office of Public Affairs
(202) 512-4800
youngc1@gao.gov
The Department of Homeland Security (DHS) Privacy Office was established with the appointment of the first Chief Privacy Officer in April 2003, as required by the Homeland Security Act of 2002. The Privacy Office's major responsibilities include: (1) reviewing and approving privacy impact assessments (PIA)--analyses of how personal information is managed in a federal system, (2) integrating privacy considerations into DHS decision making and ensuring compliance with the Privacy Act of 1974, and (3) preparing and issuing annual reports and reports on key privacy concerns. GAO was asked to testify on its recent report examining progress made by the DHS Privacy Office in carrying out its statutory responsibilities. GAO compared statutory requirements with Privacy Office processes, documents, and activities.
The DHS Privacy Office has made significant progress in carrying out its statutory responsibilities under the Homeland Security Act and its related role in ensuring compliance with the Privacy Act of 1974 and E-Government Act of 2002, but more work remains to be accomplished. Specifically, the Privacy Office has established a compliance framework for conducting PIAs, which are required by the E-Gov Act. The framework includes formal written guidance, training sessions, and a process for identifying systems requiring such assessments. The framework has contributed to an increase in the quality and number of PIAs issued as well as the identification of many more affected systems. The resultant workload is likely to prove difficult to process in a timely manner. Designating privacy officers in certain DHS components could help speed processing of PIAs, but DHS has not yet taken action to make these designations. The Privacy Office has also taken actions to integrate privacy considerations into the DHS decision-making process by establishing an advisory committee, holding public workshops, and participating in policy development. However, limited progress has been made in one aspect of ensuring compliance with the Privacy Act--updating public notices for systems of records that were in existence prior to the creation of DHS. These notices should identify, among other things, the type of data collected, the types of individuals about whom information is collected, and the intended uses of the data. Until the notices are brought up-to-date, the department cannot assure the public that the notices reflect current uses and protections of personal information. Further, the Privacy Office has generally not been timely in issuing public reports. For example, a report on the Multi-state Anti-Terrorism Information Exchange program--a pilot project for law enforcement sharing of public records data--was not issued until long after the program had been terminated. Late issuance of reports has a number of negative consequences, including a potential reduction in the reports' value and erosion of the office's credibility.
Jan 21, 2021
-
Chemical Security:
Overlapping Programs Could Better Collaborate to Share Information and Identify Potential Security GapsGAO-21-12: Published: Jan 21, 2021. Publicly Released: Jan 21, 2021.
Jan 19, 2021
-
DHS Annual Assessment:
Most Acquisition Programs Are Meeting Goals but Data Provided to Congress Lacks Context Needed For Effective OversightGAO-21-175: Published: Jan 19, 2021. Publicly Released: Jan 19, 2021.
Dec 16, 2020
-
Coast Guard:
Actions Needed to Improve National Vessel Documentation Center OperationsGAO-21-100: Published: Dec 16, 2020. Publicly Released: Dec 16, 2020.
Nov 23, 2020
-
Southwest Border:
Information on Federal Agencies' Process for Acquiring Private Land for BarriersGAO-21-114: Published: Nov 17, 2020. Publicly Released: Nov 23, 2020.
Nov 12, 2020
-
Coast Guard Acquisitions:
Opportunities Exist to Reduce Risk for the Offshore Patrol Cutter ProgramGAO-21-9: Published: Oct 28, 2020. Publicly Released: Nov 12, 2020.
Oct 29, 2020
-
TSA Acquisitions:
TSA Needs to Establish Metrics and Evaluate Third Party Testing Outcomes for Screening TechnologiesGAO-21-50: Published: Oct 29, 2020. Publicly Released: Oct 29, 2020.
Oct 20, 2020
-
Homeland Security Acquisitions:
DHS Has Opportunities to Improve Its Component Acquisition OversightGAO-21-77: Published: Oct 20, 2020. Publicly Released: Oct 20, 2020.
Sep 30, 2020
-
Disaster Assistance:
Additional Actions Needed to Strengthen FEMA's Individuals and Households ProgramGAO-20-503: Published: Sep 30, 2020. Publicly Released: Sep 30, 2020. -
Supplemental Material for GAO-20-503:
FEMA Individuals and Households Program Applicant Data 2016 – 2018GAO-20-675SP: Published: Sep 30, 2020. Publicly Released: Sep 30, 2020. -
Supplemental Material for GAO-20-503:
Select Disaster Profiles for FEMA's Individuals and Households Program 2016-2018GAO-20-674SP: Published: Sep 30, 2020. Publicly Released: Sep 30, 2020.
Looking for more? Browse all our products here