DEPARTMENT OF TRANSPORTATION
Federal Aviation Administration
PRIVACY IMPACT ASSESSMENT
Date: January 5, 2009
System Overview
The Federal Aviation Administration (FAA), within the Department of Transportation (DOT), has been given the responsibility to carry out safety programs and is responsible for providing the safest, most efficient aerospace system in the world. The FAA is responsible for:
One of the programs that helps FAA fulfill its safety mission is the Investigative Tracking System (ITS), which records, tracks, and reports on investigations pertaining to security background checks and clearances on employees, contractors and other individuals with access to FAA facilities, systems or information, as well as internal administrative investigations relative to inappropriate conduct and associated disciplinary actions and tort claims against FAA. The ITS also supports the FAA’s mandate to investigate the actual or probable violation by pilots, aircraft owners, or aircraft mechanics of civil and criminal laws regulating controlled substances. Within FAA, the Office of the Assistant Administrator for Security and Hazardous Materials has the lead responsibility for managing ITS and all related investigatory activities.
Information, Including Personally Identifiable Information (PII), in the System
The ITS system contains Personally Identifiable Information (PII) pertaining to the following categories of individuals, consisting of current or former employees and contractors (many of whom work in safety sensitive positions), other individuals with access to FAA facilities, systems or information, individuals involved in tort claims against FAA, and members of the public who are subjects of investigations regarding the actual or probable violation of civil and criminal laws regulating controlled substances:
PII is collected and entered into ITS in two major ways: by manual data entry and by automated agency downloads. Manually-entered PII consists of the following information which is collected from the individuals through the Office of Personnel Management (OPM) e-QIP (Electronic Questionnaire for Investigations Processing), the Standard Form 85p Questionnaire for Public Trust Positions or the DOT Form 1681 Identification Card/Credential Application when they apply for jobs at FAA or request a FAA identification badge:
Manually-entered PII is entered into ITS by FAA Human Resource personnel and FAA ASH personnel security specialists during the employment suitability determination or FAA identification badge issuance process. Additionally, FAA internal investigators may enter data into ITS that they have collected verbally through interviews with the individual, review of records provided by the individual as well as from other Federal, State, tribal, local and foreign investigative and law enforcement agencies, and other authorized applicable investigative techniques.
Downloaded PII consists of results of investigations and inquiries conducted by the FAA Office of the Assistant Administrator for Security and Hazardous Materials and the FAA Security and Hazardous Materials Divisions in regional offices and designated FAA centers; information received in various formats as the result of investigations conducted by Federal, State, local, and foreign investigative or law enforcement agencies, which relate to the mission and function of the Assistant Administrator for Security and Hazardous Materials and field offices; and information received in various formats as the result of investigations conducted by authorized personnel of the FAA, other Federal agencies, and State and local drug enforcement agencies regarding the actual or probable violation by pilots, aircraft owners, or aircraft mechanics of civil and criminal laws regulating controlled substances.
Downloaded PII is received via regular downloads from the following internal and external Federal agency databases, as necessary to directly support FAA’s personnel and other security investigative efforts:
To monitor these downloads, the FAA’s Office of the Assistant Administrator for Security and Hazardous Materials has a Memorandum of Understanding (MOU) between ASH and FAA’s Human Resource Management Office (AHR) to share data with the FPPS system. Similar MOUs are in-progress and being established for sharing data with PIPS/OPM, MedXPress/CAMI, NDR/NHTSA, and AFS/Airmen and Aircraft Registry database systems.
Why ITS Collects Information
PII is collected by ITS to facilitate the FAA’s security programs and its mission to promote civil aviation safety. The PII collected by ITS allows the FAA to conduct its investigations and personnel security programs in an efficient manner and document official actions taken on the basis of information contained in these records. The PII within ITS is used to maintain the categories of records listed above, as well as for uses associated with the following programs:
Access to Classified Information
National Industrial Security Program.
Legal Authority for Information Collection
Authority for maintenance of the ITS system and collection of the PII data is provided by: Title 49 U.S.C., chapter 449, Air Transportation Security, enacted as Pub. L. 103-272 on July 5, 1994; Transportation Safety Act of 1974; FAA Drug Enforcement Assistance Act of 1988; Executive Order (E.O.) 10450, Security Requirements for Government Employment; E.O. 12968, and E.O. 12829. The ITS is subject to the Privacy Act. Portions of the ITS system are exempt from provisions of the Privacy Act under 5 U.S.C. 552a (j)(2) and 5 U.S.C. 552a (k)(1), (2) and (5).
How ITS Uses Information
The ITS is a web-based application system and an on-line repository of sensitive, unclassified information that can be accessed only by authorized FAA users in ASH (personnel security specialists, internal investigators, system administrators) and AHR (human resource specialists).
The information contained in the ITS is used to do the following:
The ITS is a system of records subject to the Privacy Act and uses information only in accordance with the Privacy Act System of Records Notices: DOT/FAA 815, Investigative Record System. http://www.dot.gov/privacy/privacyactnotices/faa.htm and DOT/ALL 9 Identification Media Record Systems. http://www.dot.gov/privacy/privacyactnotices/
How ITS Shares Information
The ITS shares information with individuals within DOT/FAA who are authorized to access the system in order to conduct the above-mentioned investigations. The ITS also shares the results of investigations with the following systems:
Finally, the ITS shares information with authorized individuals at other Federal, State, tribal, local and foreign law enforcement agencies actively involved in these investigations on an as-needed basis using a secure connection or portable media with digital encryption to protect the data from unauthorized access.
The ITS is a system of records subject to the Privacy Act and shares information only in accordance with the Privacy Act System of Records Notices: DOT/FAA 815, Investigative Record System. http://www.dot.gov/privacy/privacyactnotices/faa.htm
and DOT/ALL 9 Identification Media Record Systems. http://www.dot.gov/privacy/privacyactnotices/
How ITS Provides Notice and Consent
For an individual’s PII to be included in the ITS, that individual must have applied for employment with the FAA or a credential to access FAA facilities, or have been the subject of a safety-related complaint or investigation. With respect to information received through subject interviews, review of records, and other authorized applicable investigative techniques, the individual subject receives a Privacy Act Statement that is issued from the investigator during the investigative interview. Employees, contractors and applicants also receives a privacy act statement through the Office of Personnel Management (OPM) e-QIP (Electronic Questionnaire for Investigations Processing), the Standard Form 85p Questionnaire for Public Trust Positions or the DOT Form 1681 Identification Card/Credential Application when they apply for jobs at FAA or request a FAA identification badge. Notice also is provided to employees, contractors, grant recipients, and credential applicants through the applicable Privacy Act System of Records Notice, DOT/FAA 815, Investigative Records System. Employment applicants consent to submission and release of PII when they complete the employment application forms to apply for FAA jobs. The FAA Office of the Assistant Administrator for Security and Hazardous Materials and the FAA Security and Hazardous Materials Divisions in regional offices and designated FAA centers; receives information in various formats as the result of investigations conducted and provides notice to employees, contractors and applicants on FAA Form 1600-73 and FAA Form 1600-73. These forms notify employees, contractors and applicants of the scope of information requested, the routine uses and allow them to consent or decline to provide the information.
How ITS Ensures Data Accuracy
The ITS receives PII directly from the FPPS and OPM system daily and NDR/CAMI/Airmen database system on a weekly basis. System owners of these source systems are responsible for sending accurate files and changing records appropriately. Data collected by an investigator through subject interviews, review of records, and other authorized applicable investigative techniques is entered directly into ITS by the investigator. The investigator entering the data is responsible for its accuracy. The following documents are scanned into ITS. DOT Form 1681 Identification Card/Credential Application, OPM Forms SF-85, SF-85p, or SF-86 and FAA Form 1600-73, FAA Form 1600-73
Additionally, the ITS has programmatic checks that prevent records with duplicate SSN to be stored within the system. An audit trail for the ITS system is maintained. PII changes are validated electronically.
Under the provisions of the Privacy Act, individuals may request searches of the ITS system to determine if any records have been added that may pertain to them and if such records are accurate. This is accomplished by sending a letter to the system manager at the address provided in the section below on “How ITS Provides Redress.”
The FAA protects the integrity of the information in ITS by allowing Internet and Intranet access to a limited number of authorized FAA personnel whose official duties require them to access and use the information. Only the Site Administrator can change or delete information in ITS. Other system users can only make changes to their user group profile information.
How ITS Provides Redress
Additions, deletions, and changes to the PII in ITS on FAA employees are obtained from the FPPS system daily. Additionally, PII updates are obtained from the National Driver Registry (NDR) on a weekly basis. Individuals interested in any challenges to these data items should contact the source system / agency for corrections noted in the section “Information, Including Personally Identifiable Information (PII), in the System”
For all other inquiries, a letter should be sent to the system manager at the address specified below:
Office of the Assistant Administrator for Security and Hazardous Materials
Federal Aviation Administration
800 Independence Avenue, SW
Washington, DC 20591
Individuals with concerns about privacy and ITS may also email the FAA Privacy Officer via the contact information provided in the privacy policy on the FAA’s web site (www.faa.gov/privacy).
How ITS Secures Information
ITS system has a number of security measures and safeguards in place to protect the PII that it stores:
The following matrix describes the levels of access and safeguards around each of these roles as they pertain to PII.
ROLE |
ACCESS |
SAFEGUARDS |
|---|---|---|
User (Level 3) |
|
|
User (Level 2) |
|
|
Site Administrator |
|
|
ITS is certified and accredited to ensure the protection of system information in accordance with the National Institute of Standards and Technology (NIST). NIST issues guidance for the protection of information systems in the Federal government.
How Long ITS Retains Information
Paper records generated by ITS will be retained in accordance with the current version of FAA Order 1350.15, Records Organization, Transfer and Destruction Standards, which provides a retention period of approximately 5 years (see https://employees.faa.gov/tools_resources/orders_notices). The electronic records generated by ITS are currently unscheduled with the National Archives and Records Administration (NARA). A retention period of approximately 5 years is proposed for the records. Until they are scheduled, the electronic records will be maintained indefinitely, as required by 36 CFR 1228.26(a)(1) and (2).
System of Records
The ITS is a system of records subject to the Privacy Act and uses information only in accordance with the Privacy Act System of Records Notices: DOT/FAA 815, Investigative Record System. http://www.dot.gov/privacy/privacyactnotices/faa.htm and DOT/ALL 9 Identification Media Record Systems. http://www.dot.gov/privacy/privacyactnotices/
See PIA for FAA’s Medical Certification System at: http://www.dot.gov/pia/faa_medxpress.htm.
See PIA for NHTSA’s NDR system at: http://www.dot.gov/pia/nhtsa_ndr.htm.
See PIA for FAA’s Airmen/Aircraft Registry Modernization System at: http://www.dot.gov/pia/faa_rms.htm.
Last updated: 1/8/2009