DEPARTMENT OF TRANSPORTATION
Departmental Office of Civil Rights
PRIVACY IMPACT ASSESSMENT
August 15, 2009
The Departmental Office of Civil Rights, Office of the Secretary, Transportation, will be responsible for the system, which will be used by all of the modes in DOT.
The purpose of this system is to track reasonable accommodation requests submitted by DOT employees and applicants. The system enforces compliance with Executive Order 13164 and Equal Employment Opportunity Commission (EEOC) guidance. DOT is required to collect information on accommodation requests and report annually whether requested accommodations were provided or denied within the allowable time frame (a maximum of 25 business days). The system will assist all decision makers in ensuring that a decision is made and the accommodation is provided within the time frame allowed. Access to the system is controlled by user credentials maintained in a secure database. All personally identifiable information maintained in the system is encrypted via AES technology. The system uses Secure Socket Layer to ensure secure data transmission over the internet.
The privacy management process is built upon a methodology that has been developed and implemented in leading companies around the country and globally. The methodology is designed to help ensure that DOT and OST will have the information, tools and technology necessary to manage privacy effectively and employ the highest level of fair information practices while allowing OST to achieve its mission of protecting and enhancing the U.S. transportation system. The methodology is based upon the following steps:
OATS contains both PII and non-PII. The PII will apply to applicants and employees who make accommodation requests as well as the decision makers who process the requests. The information will include for the applicants: name, address, phone number, type of accommodation requested, and reason for the request. For employees the system will track: the employee’s name, email address, office, job series, pay grade, type of accommodation requested, reason for the request, a summary of any discussion of the request, whether medical documentation was requested, whether it was provided, and the outcome of the request (approved, denied, or if an interim accommodation was provided). The name, contact information, job title, and office of the decision maker will be recorded.
This system collects information necessary to comply with Executive Order (EO) 13164 and EEOC Policy Guidance No. 915-002: Establishing Procedures to Facilitate the Provision of Reasonable Accommodation, which requires agencies to track information on requests and to strive to meet the timeframe established by the agency. For DOT, the processing time frame is 25 business days. The information collected by the system meets the requirements of the EO and EEOC guidelines. The agency must analyze the information collected to ensure that requests are processed appropriately and timely. EEOC has set a standard that 90% of requests be processed within the time limit; DOT must report annually whether it has met the standard.
Executive Order 13164, issued July 26, 2000, requires that DOT utilize a system of recordkeeping that tracks the processing of requests for reasonable accommodation. EEOC’s Policy Guidance on Executive Order 13164: Establishing Procedures to Facilitate the Provision of Reasonable Accommodation issued October 20, 2000, lists the data elements which must be captured.
These records may be used:
Specific information collected by OATS will be shared with individuals outside of DOT only if it becomes the subject of an EEO complaint that is not settled before it goes to the courts or EEOC. The OATS record then becomes part of the discovery process. Aside from EEO complaint usage, the only information that will be reported is an affirmative or negative response to the annual question on whether 90% of requests were met timely. All reports created by OATS are for internal use to ensure that accommodations are provided in a timely manner, that the response is not impacted by the requestor’s pay level, that the interactive process is conducted and recorded, and that medical information is requested only when necessary. Other possible routine uses of the information, applicable to all DOT systems, are published in the Federal Register at 65 F.R. 19476 (April 11, 2000), under “Prefatory Statement of Routine Uses” (available at: www.dot.gov/privacy/privacyactnotices/ ).
The system does not collect any information that is not already collected in order to process reasonable accommodation requests; it simply records it in an automated system. Any employee requesting accommodation is acquiescing to the collection of this information. Medical records are not stored in the system.
The system contains a link describing the privacy policy currently in place.
Supervisors enter the information for employees who request accommodation in order to perform their job or to enjoy the benefits and privileges of employment. Human resources staff enters the information for applicants who request accommodation for the application and/or interview process. Accommodation requests may be made in any form, for example, the request may be verbal, by e-mail communication, or in a letter.
Employees will not have access to the system, but will receive an email confirmation of their request. Applicants who provide an email will receive a similar confirmation. If no email address is provided by the applicant, the confirmation will be sent to their home address. The confirmation provides the applicant or employee with an opportunity to request corrections, if necessary. No documents will be scanned into OATS.
The system is designed to automatically calculate the number of business days from the date of the request to the date medical documentation (if necessary) is requested, and the number of business days from when the medical documentation was submitted to when the accommodation was provided or denied. This calculation is one of the most crucial benefits of the system. (If a supervisor discovers that s/he entered the wrong date, the OATS Administrator will be contacted to make the correction.) OATS Administrators and the system administrator will use to the system to run aggregate reports. The review will be used to identify discrepancies, for example, in meeting time limits or if a large number of denials is reflected for a single organization.
DOT provides Web site access to a privacy officer who addresses privacy concerns and questions.
Individuals wishing to know if their records appear in this system should direct their requests to Christy Compton, Departmental Office of Civil Rights, at 1200 New Jersey Avenue S.E., W78-308, Washington, D.C., 20590 or christy.compton@dot.gov.
Only designated, approved federal employees (supervisors, OA HR staff, OA system Administrators, and the DOCR system manager will have access to this system based on a “need to know” basis. No supervisor will have access to another supervisor’s records. The OATS Administrator for each Operating Administration (OA)will have access to all records in that OA, and the DOCR system manager will have access to all DOT records.
Data files are maintained in a secure government facility. All IT support staff and contractors are briefed on IT security requirements and associated responsibilities.
Federal staff with access to this system receives basic security training with some privacy components. These users also annually read and sign a Non-Disclosure Agreement containing privacy provisions and penalties for unauthorized disclosure of data. In addition to physical access, electronic access to PII is limited according to job function. DOT controls access privileges according to a documented roles matrix, with each individual receiving the minimum necessary access to PII and permissions. Many IT users receive read-only access to all or some of the data.
In addition, access to PII requires access to a secure site with complex password requirements. Password and account procedures comply with the following basic guidelines:The EEOC requires each agency to keep records related to a particular individual who has requested a reasonable accommodation for the duration of that individual's employment. These records would include any documentation of the individual's disability or need for reasonable accommodation, as well as information about the disposition of that individual's accommodation request. The EEOC also requires that agencies keep any cumulative records used to track the agency's performance with regard to reasonable accommodation for at least three years.
Because OATS will contain PII and OATS records will be retrieved by name or personal identifier, OATS is a Privacy Act system of records. DOCR has certified and accredited this system in accordance with DOT requirements. System of Records Notice (SORN) for OATS is at: www.dot.gov/privacy/privacyactnotices/ . DOCR has certified and accredited this system in accordance with DOT requirements.