CGRC Privacy Impact Assessment (PIA) — Questions and Answers
Question 1: Under which U.S. federal law are agencies required to conduct a Privacy Impact Assessment (PIA) before developing or procuring information technology that collects, maintains, or disseminates personally identifiable information (PII)?
- The Privacy Act of 1974
- The E-Government Act of 2002 (Correct answer)
- The Federal Information Security Modernization Act (FISMA) of 2014
- The Clinger-Cohen Act of 1996
Correct answer: The E-Government Act of 2002
Section 208 of the E-Government Act of 2002 specifically mandates PIAs for federal IT systems that collect or use PII. The Privacy Act of 1974 governs records systems but does not require PIAs. FISMA addresses security programs, and the Clinger-Cohen Act addresses IT acquisition and management.
Question 2: What is the MAIN difference between a Privacy Threshold Analysis (PTA) and a full Privacy Impact Assessment (PIA)?
- A PTA is performed by the agency's legal counsel, while a PIA is performed by the system owner
- A PTA determines whether a system collects PII and whether a full PIA is required, while a PIA provides the comprehensive privacy analysis (Correct answer)
- A PTA is required only for classified systems, while a PIA is required for all federal systems
- A PTA assesses third-party privacy risks, while a PIA assesses only internal privacy risks
Correct answer: A PTA determines whether a system collects PII and whether a full PIA is required, while a PIA provides the comprehensive privacy analysis
A PTA is a preliminary screening tool that identifies whether a system handles PII at a level that triggers the requirement for a full PIA. If the PTA determines that PII is collected and a PIA threshold is met, the organization proceeds to develop the comprehensive PIA. They are sequential, not interchangeable.
Question 3: Which of the following scenarios would MOST likely require the agency to conduct a new or updated Privacy Impact Assessment?
- The system's operating system is patched to the latest security update
- A new module is added to an existing system that begins collecting Social Security Numbers from users (Correct answer)
- The system's backup frequency is changed from daily to hourly
- The system administrator role is reassigned to a different employee
Correct answer: A new module is added to an existing system that begins collecting Social Security Numbers from users
A new PIA (or update to an existing one) is required when a system undergoes a significant change that creates new privacy risks — such as collecting a new category of PII like Social Security Numbers. Routine patches, backup policy changes, and personnel changes do not constitute PIA-triggering system changes.
Question 4: According to OMB guidance, which of the following must be TRUE about a completed PIA for a federal system?
- It must be classified at the SECRET level to protect the PII described within it
- It must be made publicly available on the agency's website unless the system is national security-related (Correct answer)
- It must be reviewed and approved by the Department of Homeland Security before publication
- It must be submitted to Congress annually along with the agency's FISMA report
Correct answer: It must be made publicly available on the agency's website unless the system is national security-related
OMB guidance requires agencies to make PIAs publicly available, typically on their official websites, to promote transparency about how the government handles personal information. Exceptions exist for national security systems or where disclosure would reveal sensitive information. PIAs are not classified, DHS-reviewed, or submitted to Congress.
Question 5: A federal system that maintains a group of records about individuals retrievable by a personal identifier (such as name or SSN) is BEST described as which of the following?
- A Sensitive Compartmented Information Facility (SCIF)
- A System of Records (SOR) subject to the Privacy Act (Correct answer)
- A High-Impact information system under FIPS 199
- A Controlled Unclassified Information (CUI) repository
Correct answer: A System of Records (SOR) subject to the Privacy Act
Under the Privacy Act of 1974, a System of Records (SOR) is defined as a group of records under agency control from which information is retrieved by the name of an individual or by an identifying number, symbol, or other identifier. Systems of Records require a System of Records Notice (SORN) published in the Federal Register.
Question 6: During a PIA, an agency determines that a new web portal will collect users' home addresses and date of birth. Which analysis BEST demonstrates that the agency is applying fair information practice principles (FIPPs)?
- Confirming that the data will be encrypted at rest and in transit using AES-256
- Documenting the legal authority for collection, the purpose, and the planned retention and disposal schedule for the data (Correct answer)
- Verifying that the system has received an Authority to Operate (ATO) before collecting the data
- Ensuring that the system owner has signed a Rules of Behavior document
Correct answer: Documenting the legal authority for collection, the purpose, and the planned retention and disposal schedule for the data
Fair Information Practice Principles (FIPPs) require agencies to document the legal authority for collection, limit collection to what is necessary (data minimization), state the purpose, and define retention and disposal. While encryption and ATOs are important security measures, they address confidentiality and authorization — not the privacy-specific FIPPs that PIAs are designed to analyze.
Under which U.S. federal law are agencies required to conduct a Privacy Impact Assessment (PIA) before developing or procuring information technology that collects, maintains, or disseminates personally identifiable information (PII)?