DEPARTMENT OF TRANSPORTATION
Federal Aviation Administration
Office of ATO
PRIVACY IMPACT ASSESSMENT
April 2010
The Federal Aviation Administration (FAA), within the Department of Transportation (DOT), has been given the responsibility to carry out safety programs to ensure the safest, most efficient aerospace system in the world. The FAA is responsible for:
The ATO Application Portal (AAP) system contains both personally identifiable information (PII) and non-personally identifiable information pertaining to ATO employees. PII contained within the ATO Application Portal (AAP) system includes:
ATO Application Portal (AAP) collects information in order to correctly identify and map a user’s Nextgen ID with their facility record to provide appropriate access to the employee within an application hosted on the portal.
An individual is prompted to enter their last name and the last four digits of their SSN when they first attempt to enter into the portal. This information is used to map the user’s NexGen ID with their information obtained from the facility database.
The legal authority for this collection is 49 U.S.C. 322, 49 U.S.C. 40122(g), 49 U.S.C. 40101, 40 U.S.C. 1441, 5 U.S.C. 302
Information in the ATO Application Portal (AAP) is used by the system to correctly identify the employee and tie that individual to their facility record. The portal provides single-sign-on access to the list of applications that are available to that specific user. The portal is responsible for passing the user name to those particular applications.
PII contained in ATO Application Portal (AAP) is not shared with any parties, except for the individual’s username being transmitted to the application the individual is looking to use via their single sign-on privileges. The list of systems that the particular user can access will be listed when they sign into the portal.
For an individual’s PII to be included in the ATO Application Portal (AAP) that individual must be an FAA employee and their record should be present in the facility database. This information is used by the system if and when the user logs on to the portal for the first time to map to their NextGen ID. You have to agree to the privacy policy each time you sign in by clicking OK.
PII information is obtained electronically from the facility databases via automated processes. These processes were tested and validated when they were implemented. For accuracy of the data, AAP relies on the data that is available in the facility databases. For instance, if an individual leaves the FAA, they automatically lose access to the portal as their NextGen username would be removed.
Under the provisions of the Privacy Act, individuals may request searches of the ATO Application Portal (AAP) file to determine if any records have been added that may pertain to them. This is accomplished by contacting the ATO Application Portal Administration team.
The Privacy Office should be contacted in order to make a request for access to AAP records.
ATO Application Portal (AAP) takes appropriate security measures to safeguard PII and other sensitive date.
AAP is not a system of records as a general user cannot search the application.