Privacy A y Act of ct of 1 1974 Bio iometric ic Research Dat - - PowerPoint PPT Presentation

privacy a y act of ct of 1 1974
SMART_READER_LITE
LIVE PREVIEW

Privacy A y Act of ct of 1 1974 Bio iometric ic Research Dat - - PowerPoint PPT Presentation

Privacy A y Act of ct of 1 1974 Bio iometric ic Research Dat atab abases an and the Pr Privac acy Act of 1974 Professor Dorothy Glancy Santa Clara University School of Law Improving Biometric and Forensic Technology: The Future of


slide-1
SLIDE 1

Privacy A y Act of ct of 1 1974

Bio iometric ic Research Dat atab abases an and the Pr Privac acy Act of 1974 Professor Dorothy Glancy Santa Clara University School of Law

“Improving Biometric and Forensic Technology: The Future of Research Datasets,” Gaithersburg, Maryland January 26, 2015

slide-2
SLIDE 2

Do Do you rec ecognize th e this ma man?

Sam J. Ervin, Jr.

slide-3
SLIDE 3

In 1974 . . .

  • The Int

Interne net did not exist

  • Ce

Cellu llular t tele lephones did not exist

  • Much less smart phones
  • NIST, as NIST, did not exist

(It was the Bureau of Standards)

slide-4
SLIDE 4

However, In 1974,

  • Bio

Biometr tric ics did exist

  • Privacy Act referred to
  • Finger prints
  • “Voice prints”
  • Photographs

as personal identifiers

  • Datab

atabas ases existed

  • In fact, there were about 863 federal

agency “data banks” that maintained records containing personal information about millions of individuals.

slide-5
SLIDE 5

Privacy Act 1974 focused on Databases – data banks

  • US Senate Judiciary Subcommittee on Constitutional Rights study
  • f federal agency data banks that contained personal information

about individuals

  • Federal Data Banks and Constitutional Rights
  • Part of the Privacy Act’s legislative background
  • I was privacy counsel to the Constitutional Rights Subcommittee
  • My boss was Senator Sam Ervin, chairman of the subcommittee
  • Part of my work included completing and publishing the study of just

how many and what kinds of federal agency data banks were collecting personally identifiable information about individuals

slide-6
SLIDE 6

Privacy Act of 1974

  • Federal executive branch agencies,

including the Executive Office of the President

  • Restricts personally identifiable information disclosure
  • Restricts "matching programs“
  • Requires fair information practices in maintenance of systems of

records containing personal information

  • Individual notice and consent before collection and disclosure
  • Provides for individual access to that individual’s personal data
  • Restricts records of First Amendment activities
  • Restricts use of Social Security Numbers as personal identifiers
  • Requires Transparency through Federal Register publication of

Systems of Records retrievable by personal identifiers, including biometrics

  • Provides Civil and Criminal penalties for violations
  • Private court actions by individuals

5 USC 552a - Effective September 27, 1975

slide-7
SLIDE 7

Why should those who work with Biometric Research Datasets care about the Privacy Act of 1974?

  • Calls o
  • ut

ut bi biometric i c iden entifier ers f for particular p privacy cy co concer ncern

  • Crea

eated ed P Per er

  • sonall

lly Ident entifiabl ble e Inf nformation (PI PII) co concep ncept

  • Reco

ecogni nized ed

  • Sc

Scale of Big ig Dat ata a sys ystems mat atters

  • Mat

Matching mat atters (C

(Computer M Matchi hing A Act ct, 1988) 988)

  • Disc

isclosure r e req equires es n notice t e to a and c consen ent b by in indiv ividual d data subje jects

  • Publi

lished Sy Systems of

  • f Personal I

Infor

  • rmation
  • n R

Recor

  • rds
  • Led t

to Privac acy I Impac act A Anal alysis (eGover

ernment Act of 2002)

slide-8
SLIDE 8

Privacy Act of 1974

5 USC §552a(b) Disclosure and Matching Provisions

  • "No agency shall disclose any record ... to any person, or to

another agency, except ... with the prior written consent of, the individual to whom the record pertains, unless disclosure of the record would be --

  • ... used solely as a statistical research or reporting record,

and the record is to be transferred in a form that is not individually identifiable" [not defined]

  • Restriction on "matching programs"
  • Any computerized comparison of-- (i) two or more

automated systems of records ... [certain exceptions]

slide-9
SLIDE 9

Privacy Act of 1974

Re Record - individually identified Personal information

Pr Privac acy I Impac act Anal alysis (PIA) A) eGovernmen ment Act ct System of Records Not

  • tice

(SO (SORN)

Individual human being Accountability

slide-10
SLIDE 10

Than ank y k you!

Look Looking f for

  • rward t

to

  • you
  • ur q

que uestions . . . .

Biometric c Res esea earch ch a and nd t the e Pr Privacy A Act ct of 1974

Professor D Dorothy Glancy Sant nta C a Clara a University S Sch chool of Law

“Improving Biometric and Forensic Technology: The Future of Research Datasets,” Gaithersburg, Maryland January 26, 2015