CINXE.COM
Privacy Laws, Policies and Guidance | U.S. Department of Commerce
<!DOCTYPE html> <html lang="en" dir="ltr" prefix="content: http://purl.org/rss/1.0/modules/content/ dc: http://purl.org/dc/terms/ foaf: http://xmlns.com/foaf/0.1/ og: http://ogp.me/ns# rdfs: http://www.w3.org/2000/01/rdf-schema# schema: http://schema.org/ sioc: http://rdfs.org/sioc/ns# sioct: http://rdfs.org/sioc/types# skos: http://www.w3.org/2004/02/skos/core# xsd: http://www.w3.org/2001/XMLSchema# "> <head> <meta charset="utf-8" /> <noscript><style>form.antibot * :not(.antibot-message) { display: none !important; }</style> </noscript><script async src="https://www.googletagmanager.com/gtag/js?id=G-43SPHKNB7Z"></script> <script>window.dataLayer = window.dataLayer || [];function gtag(){dataLayer.push(arguments)};gtag("js", new Date());gtag("set", "developer_id.dMDhkMT", true);gtag("config", "G-43SPHKNB7Z", {"groups":"default","page_placeholder":"PLACEHOLDER_page_location","allow_ad_personalization_signals":false});gtag("config", "UA-122485059-1", {"groups":"default","anonymize_ip":true,"page_placeholder":"PLACEHOLDER_page_path","allow_ad_personalization_signals":false});</script> <link rel="canonical" href="https://www.commerce.gov/opog/privacy/privacy-laws-policies-and-guidance" /> <link rel="shortlink" href="https://www.commerce.gov/node/4666" /> <meta name="generator" content="Drupal 8 (https://www.drupal.org)" /> <meta name="description" content="General privacy laws, OMB privacy policies and guidance, Departmental policies, and bureau/operating unit privacy policies." /> <meta name="keywords" content="," /> <meta property="og:site_name" content="U.S. Department of Commerce" /> <meta property="og:type" content="Website" /> <meta property="og:url" content="https://www.commerce.gov/opog/privacy/privacy-laws-policies-and-guidance" /> <meta property="og:title" content="Privacy Laws, Policies and Guidance" /> <meta property="og:description" content="General privacy laws, OMB privacy policies and guidance, Departmental policies, and bureau/operating unit privacy policies." /> <meta property="og:image:url" content="https://www.commerce.gov/sites/default/files/2021-03/commerce_twittercard_default.png" /> <meta property="og:updated_time" content="2024-04-04T18:51:25-04:00" /> <meta name="twitter:card" content="summary_large_image" /> <meta name="twitter:site" content="@CommerceGov" /> <meta name="twitter:description" content="General privacy laws, OMB privacy policies and guidance, Departmental policies, and bureau/operating unit privacy policies." /> <meta name="twitter:title" content="Privacy Laws, Policies and Guidance" /> <meta name="twitter:url" content="https://www.commerce.gov/opog/privacy/privacy-laws-policies-and-guidance" /> <meta name="twitter:image" content="https://www.commerce.gov/sites/default/files/2021-03/commerce_twittercard_default.png" /> <meta name="Generator" content="Drupal 9 (https://www.drupal.org)" /> <meta name="MobileOptimized" content="width" /> <meta name="HandheldFriendly" content="true" /> <meta name="viewport" content="width=device-width, initial-scale=1.0" /> <link rel="icon" href="/themes/custom/commerce/assets/img/favicons/favicon.svg" type="image/svg+xml" /> <title>Privacy Laws, Policies and Guidance | U.S. Department of Commerce</title> <link rel="stylesheet" media="all" href="/sites/default/files/css/css_ITzG_cFVXpByBy0yam4A1-gIQg6gB72RjhIFalEPamM.css" /> <link rel="stylesheet" media="all" href="/sites/default/files/css/css_ywfcVqIZC45G2IIr0QmAsDLklOs6S9nhLNvWgIRXIng.css" /> <link rel="stylesheet" media="all" href="/sites/default/files/css/css_9KBlq8AjCgYtJN-oE3FKIU-lO7tHszKsNzmgZ5IW7Ds.css" /> <link rel="stylesheet" media="all" href="/sites/default/files/css/css_xjHKQvtsHFlb55EFUXzJuHVNyOtU3UtiH6lFf7_PYBk.css" /> <link rel="stylesheet" media="all" href="/sites/default/files/css/css_FeqO6N8R02_fC8clS4w4acKpSRw6oU1UB5KdaYiYKNA.css" /> <script src="//use.fontawesome.com/releases/v5.12.0/js/all.js" defer crossorigin="anonymous"></script> <script src="//use.fontawesome.com/releases/v5.12.0/js/v4-shims.js" defer crossorigin="anonymous"></script> <link rel="apple-touch-icon" sizes="180x180" href="/themes/custom/commerce/assets/img/favicons/apple-touch-icon.png"> <link rel="icon" type="image/png" sizes="32x32" href="/themes/custom/commerce/assets/img/favicons/favicon-32x32.png"> <link rel="icon" type="image/png" sizes="16x16" href="/themes/custom/commerce/assets/img/favicons/favicon-16x16.png"> <link rel="manifest" href="/themes/custom/commerce/assets/img/favicons/site.webmanifest"> <link rel="mask-icon" href="/themes/custom/commerce/assets/img/favicons/safari-pinned-tab.svg" color="#5bbad5"> <meta name="msapplication-TileColor" content="#2b5797"> <meta name="theme-color" content="#ffffff"> </head> <body class="opog-site path-node page-node-type-page"> <div class="skip-main" role="complementary" aria-label="skip-to-main"> <a href="#main-content" class="visually-hidden focusable skip-link"> Skip to main content </a> </div> <div class="dialog-off-canvas-main-canvas" data-off-canvas-main-canvas> <section class="usa-banner" aria-label="Official government website"> <div class="usa-accordion"> <header class="usa-banner__header"> <div class="usa-banner__inner"> <div class="grid-col-auto"> <img class="usa-banner__header-flag" src="/themes/custom/commerce/assets/img/us_flag_small.png" alt="U.S. flag"> </div> <div class="grid-col-fill tablet:grid-col-auto"> <p class="usa-banner__header-text">An official website of the United States government</p> <p class="usa-banner__header-action" aria-hidden="true">Here’s how you know</p> </div> <button class="usa-accordion__button usa-banner__button" aria-expanded="false" aria-controls="gov-banner"> <span class="usa-banner__button-text">Here’s how you know</span> </button> </div> </header> <div class="usa-banner__content usa-accordion__content" id="gov-banner"> <div class="grid-row grid-gap-lg"> <div class="usa-banner__guidance tablet:grid-col-6"> <img class="usa-banner__icon usa-media-block__img" src="/themes/custom/commerce/assets/img/icon-dot-gov.svg" role="presentation" alt="Dot gov"> <div class="usa-media-block__body"> <p> <strong> Official websites use .gov </strong> <br/> A <strong>.gov</strong> website belongs to an official government organization in the United States. </p> </div> </div> <div class="usa-banner__guidance tablet:grid-col-6"> <img class="usa-banner__icon usa-media-block__img" src="/themes/custom/commerce/assets/img/icon-https.svg" role="presentation" alt="Https"> <div class="usa-media-block__body"> <p> <strong> Secure .gov websites use HTTPS </strong> <br/> A <strong>lock</strong> (<span class="icon-lock"><svg xmlns="http://www.w3.org/2000/svg" width="52" height="64" viewBox="0 0 52 64" class="usa-banner__lock-image" role="presentation" aria-labelledby="banner-lock-title banner-lock-description"><title id="banner-lock-title">Lock</title><desc id="banner-lock-description">A locked padlock</desc><path fill="#000000" fill-rule="evenodd" d="M26 0c10.493 0 19 8.507 19 19v9h3a4 4 0 0 1 4 4v28a4 4 0 0 1-4 4H4a4 4 0 0 1-4-4V32a4 4 0 0 1 4-4h3v-9C7 8.507 15.507 0 26 0zm0 8c-5.979 0-10.843 4.77-10.996 10.712L15 19v9h22v-9c0-6.075-4.925-11-11-11z"/></svg></span>) or <strong>https://</strong> means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. </p> </div> </div> </div> </div> </div> </section> <div class="usa-overlay"></div> <header class="usa-header usa-header--extended usa-header--extended-megamenu" role="banner"> <div class="usa-navbar"> <div class="region region-header"> <div class="usa-logo" id="office-logo"> <a class="logo-img" href="/" title="Department of Commerce Home" aria-label="Department of Commerce Home"> <img src="/themes/custom/commerce/assets/img/doc_logo.png" width="92" height="92" alt="Department of Commerce logo"/> </a> <h1 class="usa-logo-text opog-logo-text"> <a class="office-of-style" href="/opog" accesskey="1" title="Office of Privacy and Open Government" aria-label="Office of">Office of </a><br> <a href="/opog" accesskey="2" title="Office of Privacy and Open Government" aria-label="Privacy and Open Government">Privacy and Open Government</a> </h1> </div> </div> <button class="usa-menu-btn">Menu</button> </div> <nav class="usa-nav" role="navigation"> <button class="usa-nav__close"> <img src="/themes/custom/commerce/assets/img/close.svg" alt="close" /> </button> <div class="usa-nav__inner"> <div class="usa-nav-mobile"> <div class="region region-mobile-menu"> <div id="block-fixed-block-content-opog-mobile-search-fixed-block" class="block block-fixed-block-content block-fixed-block-contentopog-mobile-search-fixed-block"> <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item"><div class="usasearch-search-block-form usa-form-large block block-usasearch block-usasearch-search-form-block" data-drupal-selector="usasearch-search-block-form" id="commerce_search_block_mobile"> <form accept-charset="UTF-8" action="https://search.commerce.gov/search/docs" id="usasearch-search-block-form-mobile" method="GET"> <div class="js-form-item form-item js-form-type-search form-item-query js-form-item-query form-no-label"><label class="visually-hidden" for="mobile_query">Search</label><br /> <input aria-autocomplete="list" aria-haspopup="" autocomplete="off" class="usagov-search-autocomplete form-search ui-autocomplete-input" data-drupal-selector="edit-query" id="mobile_query" maxlength="128" name="query" placeholder="Search" size="60" title="Enter the terms you wish to search for." type="search" value="" /></div> <input data-drupal-selector="edit-affiliate" name="affiliate" type="hidden" value="www.commerce.gov" /> <input name="dc" type="hidden" value="9992" /> <div class="form-actions js-form-wrapper form-wrapper" data-drupal-selector="edit-actions" id="edit-actions-mobile"> <input class="usa-button js-form-submit form-submit" data-drupal-selector="edit-submit" id="edit-submit-mobile" type="submit" value="Search" /></div> </form> </div> </div> </div> <ul class="usa-nav__mobile usa-accordion" aria-multiselectable="true"> <li class="usa-nav__primary-item"> <button class="usa-accordion__button usa-nav__link aria-expanded="false" aria-controls="basic-mega-nav-section-/opog/about/about-opog"> <span>About</span> </button> <div id="basic-mega-nav-section-/opog/about/about-opog" class="usa-nav__submenu usa-megamenu" hidden="" > <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/about/about-opog" > <span>About </span> </a> </div> </div> <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/about/leadership" > <span>Leadership </span> </a> </div> </div> <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/about/about-saop" > <span>Chief Privacy Officer & Director of Open Government </span> </a> </div> </div> <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/about/contact-information" > <span>Contact Information </span> </a> </div> </div> </div> </li> <li class="usa-nav__primary-item"> <button class="usa-accordion__button usa-nav__link usa-current" aria-expanded="true" aria-controls="basic-mega-nav-section-/opog/privacy-privacy-act"> <span>Privacy </span> </button> <div id="basic-mega-nav-section-/opog/privacy-privacy-act" class="usa-nav__submenu usa-megamenu" hidden="" > <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/privacy/privacy-act-requests" > <span>Privacy Act Requests </span> </a> </div> </div> <div class="usa-col level-1"> <button class="usa-accordion__button usa-nav__link commerce-menu-sub-levels aria-expanded="false" aria-controls="basic-nav-section-/opog/privacy/SORN"> <span>System of Records Notices</span> </button> <ul id="basic-nav-section-/opog/privacy/SORN" class="usa-nav__submenu-list" hidden=""> <div class="usa-col level-2"> <a href="/opog/privacy/SORN#bis" > <span>Bureau of Industry and Security </span> </a> </li> <div class="usa-col level-2"> <a href="/opog/privacy/SORN#cens" > <span>Census Bureau </span> </a> </li> <div class="usa-col level-2"> <a href="/opog/privacy/SORN#ita" > <span>International Trade Administration </span> </a> </li> <div class="usa-col level-2"> <a href="/opog/privacy/SORN#mbda" > <span>Minority Business Development Agency </span> </a> </li> <div class="usa-col level-2"> <a href="/opog/privacy/SORN#nist" > <span>National Institute of Standards and Technology </span> </a> </li> <div class="usa-col level-2"> <a href="/opog/privacy/SORN#noaa" > <span>National Oceanic and Atmospheric Administration </span> </a> </li> <div class="usa-col level-2"> <a href="/opog/privacy/SORN#ntis" > <span>National Technical Informations Services </span> </a> </li> <div class="usa-col level-2"> <a href="/opog/privacy/SORN#oig" > <span>Office of Inspector General </span> </a> </li> <div class="usa-col level-2"> <a href="/opog/privacy/SORN#pto" > <span>U.S. Patent and Trademark Office </span> </a> </li> </ul> </div> <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/privacy/PIA" > <span>Privacy Impact Assessments </span> </a> </div> </div> <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/privacy/breach-response" > <span>Breach Response </span> </a> </div> </div> <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/privacy/privacy-laws-policies-and-guidance" class="usa-current" > <span>Laws, Policies, Guidance & Resources </span> </a> </div> </div> <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/privacy/bureau-chief-privacy-officers" > <span>DOC Bureau Privacy Contacts </span> </a> </div> </div> </div> </li> <li class="usa-nav__primary-item"> <button class="usa-accordion__button usa-nav__link aria-expanded="false" aria-controls="basic-mega-nav-section-/opog/directives-main"> <span>Directives</span> </button> <div id="basic-mega-nav-section-/opog/directives-main" class="usa-nav__submenu usa-megamenu" hidden="" > <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/directives" > <span>Directives Overview </span> </a> </div> </div> <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/directives/DAO" > <span>Department Administrative Orders </span> </a> </div> </div> <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/directives/DOO" > <span>Department Organizational Orders </span> </a> </div> </div> <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/directives/updates" > <span>Updates </span> </a> </div> </div> </div> </li> <li class="usa-nav__primary-item"> <button class="usa-accordion__button usa-nav__link aria-expanded="false" aria-controls="basic-mega-nav-section-/opog/foia"> <span>FOIA</span> </button> <div id="basic-mega-nav-section-/opog/foia" class="usa-nav__submenu usa-megamenu" hidden="" > <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/foia/foia-requests" > <span>FOIA Requests </span> </a> </div> </div> <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/foia/electronic-foia-library" > <span>FOIA Library </span> </a> </div> </div> <div class="usa-col level-1"> <button class="usa-accordion__button usa-nav__link commerce-menu-sub-levels aria-expanded="false" aria-controls="basic-nav-section-/opog/foia/foia-reports/annual-reports"> <span>FOIA Reports</span> </button> <ul id="basic-nav-section-/opog/foia/foia-reports/annual-reports" class="usa-nav__submenu-list" hidden=""> <div class="usa-col level-2"> <a href="/opog/foia/foia-reports/annual-reports" > <span>Annual Reports </span> </a> </li> <div class="usa-col level-2"> <a href="/opog/foia/foia-reports/quarterly-reports" > <span>Quarterly Reports </span> </a> </li> <div class="usa-col level-2"> <a href="/opog/foia/foia-reports/chief-foia-officer-reports" > <span>Chief FOIA Officer Reports </span> </a> </li> </ul> </div> <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/foia/foia-resources" > <span>FOIA Resources </span> </a> </div> </div> <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/foia/doc-foia-bureau-operating-unit-contact-information" > <span>DOC FOIA Contacts </span> </a> </div> </div> </div> </li> <li class="usa-nav__primary-item"> <button class="usa-accordion__button usa-nav__link aria-expanded="false" aria-controls="basic-mega-nav-section-"> <span>FACA</span> </button> <div id="basic-mega-nav-section-" class="usa-nav__submenu usa-megamenu" hidden="" > <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/faca/federal-advisory-committees" > <span>Federal Advisory Committees </span> </a> </div> </div> </div> </li> <li class="usa-nav__primary-item"> <button class="usa-accordion__button usa-nav__link aria-expanded="false" aria-controls="basic-mega-nav-section-/opog/open-government"> <span>Open Government</span> </button> <div id="basic-mega-nav-section-/opog/open-government" class="usa-nav__submenu usa-megamenu" hidden="" > <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/open-government/open-government-plan" > <span>Open Government Plans </span> </a> </div> </div> <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/open-government/open-government-blog" > <span>Blogs </span> </a> </div> </div> <div class="usa-col level-1"> <div class="usa-nav__submenu-item"> <a href="/opog/open-government/open-government-authorities-laws-policies-and-guidance" > <span>Laws, Policies, Guidance, Resources </span> </a> </div> </div> </div> </li> </ul> </div> </div> <div class="usa-nav__secondary"> <div class="region region-secondary-menu"> <div class="secondary-menu-search block block-fixed-block-content block-fixed-block-contentopog-search-block-fixed-block" id="block-fixed-block-content-opog-search-block-fixed-block"> <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item"><div class="usasearch-search-block-form usa-form-large block block-usasearch block-usasearch-search-form-block" data-drupal-selector="usasearch-search-block-form" id="block-usasearchform"> <form accept-charset="UTF-8" action="https://search.commerce.gov/search/docs" class="usasearch-search-block-form-desktop" method="GET"> <div class="js-form-item form-item js-form-type-search form-item-query js-form-item-query form-no-label"><label class="visually-hidden" for="desktop_query">Search</label><br /> <input aria-autocomplete="list" aria-haspopup="" autocomplete="off" class="usagov-search-autocomplete form-search ui-autocomplete-input" data-drupal-selector="edit-query" id="desktop_query" maxlength="128" name="query" placeholder="Search" size="60" title="Enter the terms you wish to search for." type="search" value="" /></div> <input data-drupal-selector="edit-affiliate" name="affiliate" type="hidden" value="www.commerce.gov" /> <input name="dc" type="hidden" value="9992" /> <div class="form-actions js-form-wrapper form-wrapper" data-drupal-selector="edit-actions-desktop" id="edit-actions"> <input class="usa-button js-form-submit form-submit" data-drupal-selector="edit-submit" id="edit-submit-desktop" type="submit" value="Search" /></div> </form> </div> </div> </div> </div> </div> <div class="usa-nav-desktop"> <div class="region region-primary-menu"> <ul class="usa-nav__primary usa-accordion"> <li class="usa-nav__primary-item"> <button class="usa-accordion__button usa-nav__link " aria-expanded="false" aria-controls="basic-nav-section-1"> <span>About </span> </button> <ul id="basic-nav-section-1" class="usa-nav__submenu" hidden=""> <li class="usa-nav__submenu-item"> <a href="/opog/about/about-opog"> <span>About</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/about/leadership"> <span>Leadership</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/about/about-saop"> <span>Chief Privacy Officer & Director of Open Government</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/about/contact-information"> <span>Contact Information</span> </a> </li> </ul> </li> <li class="usa-nav__primary-item"> <button class="usa-accordion__button usa-nav__link usa-current" aria-expanded="false" aria-controls="basic-nav-section-2"> <span>Privacy </span> </button> <ul id="basic-nav-section-2" class="usa-nav__submenu" hidden=""> <li class="usa-nav__submenu-item"> <a href="/opog/privacy/privacy-act-requests"> <span>Privacy Act Requests</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/privacy/SORN"> <span>System of Records Notices</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/privacy/PIA"> <span>Privacy Impact Assessments</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/privacy/breach-response"> <span>Breach Response</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/privacy/privacy-laws-policies-and-guidance"> <span>Laws, Policies, Guidance & Resources</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/privacy/bureau-chief-privacy-officers"> <span>DOC Bureau Privacy Contacts</span> </a> </li> </ul> </li> <li class="usa-nav__primary-item"> <button class="usa-accordion__button usa-nav__link " aria-expanded="false" aria-controls="basic-nav-section-3"> <span>Directives </span> </button> <ul id="basic-nav-section-3" class="usa-nav__submenu" hidden=""> <li class="usa-nav__submenu-item"> <a href="/opog/directives"> <span>Directives Overview</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/directives/DAO"> <span>Department Administrative Orders</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/directives/DOO"> <span>Department Organizational Orders</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/directives/updates"> <span>Updates</span> </a> </li> </ul> </li> <li class="usa-nav__primary-item"> <button class="usa-accordion__button usa-nav__link " aria-expanded="false" aria-controls="basic-nav-section-4"> <span>FOIA </span> </button> <ul id="basic-nav-section-4" class="usa-nav__submenu" hidden=""> <li class="usa-nav__submenu-item"> <a href="/opog/foia/foia-requests"> <span>FOIA Requests</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/foia/electronic-foia-library"> <span>FOIA Library</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/foia/foia-reports/annual-reports"> <span>FOIA Reports</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/foia/foia-resources"> <span>FOIA Resources</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/foia/doc-foia-bureau-operating-unit-contact-information"> <span>DOC FOIA Contacts</span> </a> </li> </ul> </li> <li class="usa-nav__primary-item"> <button class="usa-accordion__button usa-nav__link " aria-expanded="false" aria-controls="basic-nav-section-5"> <span>FACA </span> </button> <ul id="basic-nav-section-5" class="usa-nav__submenu" hidden=""> <li class="usa-nav__submenu-item"> <a href="/opog/faca/federal-advisory-committees"> <span>Federal Advisory Committees</span> </a> </li> </ul> </li> <li class="usa-nav__primary-item"> <button class="usa-accordion__button usa-nav__link " aria-expanded="false" aria-controls="basic-nav-section-6"> <span>Open Government </span> </button> <ul id="basic-nav-section-6" class="usa-nav__submenu" hidden=""> <li class="usa-nav__submenu-item"> <a href="/opog/open-government/open-government-plan"> <span>Open Government Plans</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/open-government/open-government-blog"> <span>Blogs</span> </a> </li> <li class="usa-nav__submenu-item"> <a href="/opog/open-government/open-government-authorities-laws-policies-and-guidance"> <span>Laws, Policies, Guidance, Resources</span> </a> </li> </ul> </li> </ul> </div> </div> </div> </nav> </header> <main class="usa-section"> <a id="main-content" tabindex="-1"></a> <div class="grid-container"> <div class="grid-row grid-gap"> <div class="grid-col-12"> <div class="region region-highlighted"> <div data-drupal-messages-fallback class="hidden"></div> </div> </div> </div> <div class="grid-row grid-gap"> <aside class="tablet:grid-col-3"> <div class="region region-sidebar-first"> <ul class="usa-sidenav"> <li class="usa-sidenav__item"> <a href="/opog/privacy/privacy-act-requests"> <span>Privacy Act Requests</span> </a> </li> <li class="usa-sidenav__item"> <a href="/opog/privacy/SORN"> <span>System of Records Notices</span> </a> </li> <li class="usa-sidenav__item"> <a href="/opog/privacy/PIA"> <span>Privacy Impact Assessments</span> </a> </li> <li class="usa-sidenav__item"> <a href="/opog/privacy/breach-response"> <span>Breach Response</span> </a> </li> <li class="usa-sidenav__item"> <a href="/opog/privacy/privacy-laws-policies-and-guidance" class="usa-current"> <span>Laws, Policies, Guidance & Resources</span> </a> </li> <li class="usa-sidenav__item"> <a href="/opog/privacy/bureau-chief-privacy-officers"> <span>DOC Bureau Privacy Contacts</span> </a> </li> </ul> <div id="block-votingblock-2" class="block block-voting-modal block-modal-block"> <h2>Was this page helpful?</h2> <button type="submit" href="/voting/modal/4666/true" class="usa-button-secondary use-ajax" data-dialog-type="modal"><i alt="Thumbs up icon to indicate helpful" class="fas fa-thumbs-up"></i> Helpful </button><button type="submit" href="/voting/modal/4666/false" class="usa-button-secondary use-ajax" data-dialog-type="modal"><i alt="Thumbs down icon to indicate not helpful" class="fas fa-thumbs-down"></i> Not helpful</button> </div> </div> </aside> <div class="region-content tablet:grid-col-fill"> <div class="region region-content"> <div class="block block-system block-system-breadcrumb-block"> <h2 id="system-breadcrumb" class="visually-hidden">Breadcrumb</h2> <ol class="add-list-reset uswds-breadcrumbs uswds-horizontal-list"> <li> <a href="/">Home</a> </li> <li> <a href="/opog">Opog</a> </li> </ol> </div> <div id="block-votingblock" class="block block-voting-modal block-modal-block"> <h2>Was this page helpful?</h2> <button type="submit" href="/voting/modal/4666/true" class="usa-button-secondary use-ajax" data-dialog-type="modal"><i alt="Thumbs up icon to indicate helpful" class="fas fa-thumbs-up"></i> Helpful </button><button type="submit" href="/voting/modal/4666/false" class="usa-button-secondary use-ajax" data-dialog-type="modal"><i alt="Thumbs down icon to indicate not helpful" class="fas fa-thumbs-down"></i> Not helpful</button> </div> <div class="block block-core block-page-title-block"> <h1 class="uswds-page-title page-title"><span property="schema:name" class="field field--name-title field--type-string field--label-hidden">Privacy Laws, Policies and Guidance</span> </h1> </div> <div id="block-commerce-content" class="block block-system block-system-main-block"> <article data-history-node-id="4666" role="article" about="/opog/privacy/privacy-laws-policies-and-guidance" typeof="schema:WebPage"> <span property="schema:name" content="Privacy Laws, Policies and Guidance" class="rdf-meta hidden"></span> <div> <div property="schema:text" class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item"><p>General privacy laws, OMB privacy policies and guidance, Departmental policies, and bureau/operating unit privacy policies.</p> <hr /><h2><a id="Authorities" name="Authorities"></a>Authorities</h2> <ul><li>The <a href="//www.commerce.gov/sites/default/files/opog/privacy_act-1974-usc552a.pdf">Privacy Act of 1974, 5 U.S.C. 552a</a>, provides privacy protections for records containing information about individuals (i.e., citizen and legal permanent resident) that are collected and maintained by the federal government and are retrieved by a personal identifier. The Act requires agencies to safeguard information contained in a system of records (SOR). It is currently being revised.<em> It is currently being revised</em>.</li> <li>The <a href="//www.commerce.gov/sites/default/files/opog/federal_info_security_mod_act-2014.pdf">Federal Information Security Modernization Act of 2014</a> (amends the Federal Information Security Management Act of 2002, 44 U.S.C. 3541), requires agencies to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of an agency.</li> <li>The <a href="//www.commerce.gov/sites/default/files/opog/e-government-act-2002.pdf" target="_blank" rel="noopener">E-Government Act of 2002</a> (44 U.S.C. 3601<em>et seq</em>.) establishes procedures to ensure the privacy of personal information in electronic records.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/foia-5usc552.pdf">Freedom of Information Act (FOIA)</a> generally provides that any person has a right, enforceable in court, to obtain access to federal agency records, except to the extent that such records (or portions of them) are protected from public disclosure by one of nine exemptions or by one of three special law enforcement record exclusions.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/trade_secrets_act-18-usc-1905.pdf">Trade Secrets Act</a> (18 U.S.C. 1905) provides criminal penalties for the theft of trade secrets and other business identifiable information.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/privacy_reduction_act-1995.pdf" target="_top" rel="noopener">Paperwork Reduction Act (PRA) of 1995</a> (44 U.S.C. 3501<em>et seq</em>.) is designed to reduce the public's burden of answering unnecessary, duplicative, and burdensome government surveys.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/coppa-16-cfr-part-312.pdf" target="_top" rel="noopener">Children's Online Privacy Protection Act of 1998</a> (15 U.S.C. 6501-06) (COPPA) regulates the online collection and use of personal information provided by and relating to children under the age of 13 (<a href="https://www.ftc.gov/enforcement/rules/rulemaking-regulatory-reform-proceedings/childrens-online-privacy-protection-rule" rel="noreferrer">COPPA's Online Privacy Protection Rule</a>).</li> <li>The <a href="//www.commerce.gov/sites/default/files/opog/ssn-fraud_prevention_act_2017.pdf">Social Security Number <strong>Fraud</strong> <strong>Prevention</strong> <strong>Act</strong> of 2017 </a>(<strong>Public Law</strong> <strong>115-59)</strong>: (1) prohibits federal agencies from including any individual's Social Security account number on any document sent by mail unless the agency head determines that such inclusion is necessary; and (2) requires agencies that have Chief Financial Officers to issue regulations, within five years of this bill's enactment, that specify the circumstances under which such inclusion is necessary.</li> </ul><h2><a id="OMBMemo" name="OMBMemo"></a>Office of Management and Budget (OMB) Memoranda</h2> <ul><li><a href="//www.commerce.gov/sites/default/files/opog/omb_m-01-05.pdf">OMB Memorandum M-01-05</a>, Guidance on Inter-Agency Sharing of Personal Data - Protecting Personal Privacy, applies to data matching activities or programs for purposes of establishing or verifying eligibility for Federal benefit programs or recouping payments or delinquent debts under such programs covered by the Computer Matching and Privacy Protection Act ("Matching Act"), an amendment to the Privacy Act of 1974, 5 U.S.C. Section 552a, whether data are shared between Federal agencies or matched with State agency data.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_m-03-22.pdf" target="_top" rel="noopener">OMB Memorandum M-03-22</a>, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002 (September 26, 2003), requires agencies to conduct reviews of how information about individuals is handled when information technology (IT) is used to collect new information, or when agencies develop or buy new IT systems to handle collections of personally identifiable information (PII), and describes how the agency handles information that individuals provide electronically.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_m-06-16.pdf" target="_top" rel="noopener">OMB Memorandum M-06-16</a>, Protection of Sensitive Agency Information (June 23, 2006), requires agencies to implement encryption protections for PII being transported and/or stored offsite, allowing remote access only with two-factor authentication, using a time-out function for remote access, and logging all computer-readable data extracts from databases holding sensitive information; and verifies each extract, including sensitive data, has been erased within 90 days or its use is still required.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_m-10-22.pdf">OMB Memorandum M-10-22</a>, Guidance for Online Use of Web Measurement and Customization Technologies, establishes new procedures and provides updated guidance and requirements for agency use of web measurement and customization technology.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_m-10-23.pdf">OMB Memorandum M-10-23</a>, Guidance for Agency use of Third-Party Websites and Applications, requires Federal agencies to take specific steps to protect the individual privacy whenever they use third-party websites and applications to engage with the public.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_m-11-02.pdf">OMB Memorandum M-11-02</a>, Sharing Data While Protecting Privacy (November 3, 2010), requires agencies to develop and implement solutions that allow data sharing to move forward in a manner that complies with applicable privacy laws, regulations, and policies.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_m-13-13.pdf">OMB Memorandum M-13-13</a>, Open Data Policy - Managing Information as an Asset requires agencies to collect or create information in a way that supports downstream information processing and dissemination activities. This includes using machine readable and open formats, data standards, and common core and extensible metadata for all new information creation and collection efforts.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_m-13-20.pdf">OMB Memorandum M-13-20</a>, Protecting Privacy while Reducing Improper Payments with the Do Not Pay Initiative which implements Section 5 of the Improper Payments Elimination and Recovery Improvement Act of 2012 (IPERIA) and provides guidance to help Federal agencies protect privacy while reducing improper payments with the Do Not Pay (DNP) Initiative.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_m-14-04.pdf">OMB Memorandum M-14-04</a>, Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management, provides agencies with instructions for meeting their agencies "fiscal year reporting requirements under the Federal Information Security Management Act (FISMA) and includes reporting instructions on agencies" privacy management program.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_m-14-06.pdf">OMB Memorandum M-14-06</a>, Guidance for Providing and Using Administrative Data for Statistical Purposes, provides agencies with guidance for addressing the legal, policy, and operational issues that exist with respect to using administrative data for statistical purposes.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_m-16-04.pdf">OMB Memorandum M-16-04</a>, Cybersecurity Strategy and Implementation Plan (CSIP) for the Federal Civilian Government, identifies and addresses critical cybersecurity gaps and emerging priorities, and makes specific recommendations to address those gaps and priorities. The CSIP was developed to assist to strengthen Federal civilian cybersecurity through the following five objectives: (1) Prioritized Identification and Protection of high value information and assets; (2) Timely Detection of and Rapid Response to cyber incidents; (3) Rapid Recovery from incidents when they occur and Accelerated Adoption of lessons learned from the Sprint assessment; (4) Recruitment and Retention of the most highly-qualified Cybersecurity Workforce talent the Federal Government can bring to bear; and (5) Efficient and Effective Acquisition and Deployment of Existing and Emerging Technology.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_m-16-14.pdf">OMB Memorandum M-16-14</a>, Category Management Policy 16-2: Providing Comprehensive Identity Protection Services, Identity Monitoring, and Data Breach Response (July 1, 2016), which requires federal agencies, with limited exceptions, to address their requirements, when they need to identify protection services, by using the government-wide blanket purchase agreements (BPAs) for Identity Monitoring Data Breach Response and Protection Services (i.e., IPS BPAs) awarded by the General Services Administration (GSA).</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_m-16-24.pdf">OMB Memorandum M-16-24</a>, Role and Designation of Senior Agency Officials for Privacy, revises policies on the role and designation of the Senior Agency Official for Privacy (SAOP), as required by Executive Order 13719, Establishment of the Federal Privacy Council.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_memo_17-06.pdf">OMB Memorandum 17-06</a>, Policies for Federal Agency Public Websites and Digital Services, updates policies regarding Federal Agency public websites and digital services and requires that each agency maintain a central resource page dedicated to its privacy program on the agency's principal website.The agency's Privacy Program page must serve as a central source for information about the agency's practices with respect to PII.The agency's Privacy Program Page must be located at<u>www.[agency].gov/privacy</u>and must be accessible through the agency's "About" page.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_memo_17-09.pdf">OMB Memorandum 17-09</a>, Management of Federal High Value Assets, contains general guidance for the planning, identification, categorization, prioritization, reporting, assessment, and remediation of Federal High Value Assets (HVAs), as well as the handling of information related to HVAs by the Federal Government.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_m-17-12.pdf">OMB Memorandum 17-12</a>, Preparing for and Responding to a Breach of Personally Identifiable Information, which sets forth the policy for Federal agencies to prepare for and respond to a breach of personally identifiable information (PII).</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_m-18-02.pdf">OMB Memoradum 18-02</a>, Fiscal Year (FY) 2017-2018 Guidance on Federal Information Security and Privacy Management Requirements, which provides agencies with FY 2017-2018 Federal Information Security Modernization Act of 2014 (FISMA) reporting guidance and deadlines.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_m-21-04.pdf" title="OMB M-21-04">OMB Memorandum 21-04, Modernizing Access to and Consent for Disclosure of Records Subject to the Privacy Act</a>, which provides guidance for Federal agencies to modernize the processes by which individuals may request access to, and consent to the disclosure of, records protected under the Privacy Act of 1974. As required by the Creating Advanced Streamlined Electronic Services for Constituents Act of 2019 (" CASES Act"), this guidance outlines the responsibilities of agencies for accepting access and consent forms provided in a digital format from individuals who are properly identity-proofed and authenticated.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb-memo-biennial_reporting_requirements_pact.pdf">Memorandum for Privacy Act Officers of Departments and Agencies</a>, Status of Biennial Reporting Requirements under the Privacy Act and the Computer Matching and Privacy Protection Act (June 21, 2000), streamlines some of the reporting requirements for federal departments and agencies under OMB Circular A-130, Appendix I.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/model-pia-agency-use-third-party-websites-and-applications.pdf">Model Privacy Impact Assessment for Agency Use of Third-Party Websites and Applications</a> (December 29, 2011), is the required PIA model for agencies to use when preparing an adapted PIA before engaging the public through third-party websites and applications.</li> </ul><h2><a id="Circulars" name="Circulars"></a>OMB Circulars</h2> <ul><li><a href="//www.commerce.gov/sites/default/files/opog/omb_circular_a-108.pdf">OMB Circular A-108,</a> Federal Agency Responsibilities for Review, Reporting, and Publication under the Privacy Act, which describes agency responsibilities for implementing the review, reporting, and publication requirements of the Privacy Act of 1974 ("the Privacy Act"),and related OMB policies.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_circular_a-123.pdf">OMB Circular A-123,</a> Management's Responsibility for Internal Control, which defines management's responsibility for internal control in Federal agencies. The policy changes in this circular are intended to strengthen the requirements for conducting managemen's assessment of internal control over financial reporting. The circular also emphasizes the need for agencies to integrate and coordinate internal control assessments with other internal control-related activities.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_circular_a-130revised.pdf" target="_top" rel="noopener">OMB Circular A-130</a>, Management of Federal Information Resources, provides uniform government-wide information resources management policies as required by the Paperwork Reduction Act of 1980, as amended by the Paperwork Reduction Act of 1995, 44 U.S.C. Chapter 35.</li> </ul><h2><a id="guidance" name="guidance"></a>Privacy Guidance</h2> <ul><li><a href="//www.commerce.gov/sites/default/files/opog/privacy_program_plan.pdf">DOC Privacy Program Plan</a> - An overview of the Department's privacy program.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/privacy_continuous_monitoring_strategy_fy20.pdf" title="DOC Continuous Monitoring Strategy">DOC Continuous Monitoring Strategy</a> - Determines if the complete set of planned, required, and deployed privacy controls, within an information system or inherited by the system, continue to be effective over time in light of the inevitable changes that occur.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/pia_guide_september_2020.pdf">DOC Guide to Effective Privacy Impact Assessments (PIA)</a> - This guide provides a framework for conducting PIAs at the Department of Commerce (DOC or Department) and a methodology for assessing how PII is to be managed in electronic information systems. The DOC Senior Agency Official for Privacy (SAOP)/Chief Privacy Officer (CPO) requires that all PIAs at the Department be conducted in accordance with this guidance.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/privacy_overlays_entire_document.pdf">DOC Privacy Overlays</a> - Specification of security controls, control enhancements, supplemental guidance, and other supporting information that is intended to complement (and further refine) security control baselines. The purposes of the privacy overlays include implementing standard security and privacy controls for systems containing PII, ensuring integration of privacy considerations into the system development life cycle and security processes in the early stages, and providing guidance for privacy requirements for protected health information.</li> </ul><h2><a id="DOCPolicies" name="DOCPolicies"></a>Department of Commerce (DOC) Policies</h2> <ul><li><a href="//www.commerce.gov/sites/default/files/opog/privacy_bulletin_002_fy2020_re-certification_process.pdf">Delegation of SAOP Concurrence for Re-issuance of an ATO for PII/BII Processing Systems Eligible for the Re-certification Process</a> - Privacy Bulletin #002 provides the criteria, as well as instruction to the Bureau Chief Privacy Officers (BPCOs) on reviewing and approving Privacy Impact Assessments (PIAs) for PII processing systems which are eligible for the re-certification process.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/privacy_bulletin_003_fy2020_crb_meetings_low.pdf">Delegation of SAOP Concurrence for Re-issuance of an ATO for Low PII Confidentiality Impact Level Processing Systems</a> - Privacy Bulletin #003 provides the criteria, as well as instruction to the Bureau Chief Privacy Officers (BPCOs) on reviewing and approving Privacy Impact Assessments (PIAs) for Low PII Confidentiality Impact Level processing systems that require a Compliance Review Board (CRB) meeting.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/dlp-memo_04152016.pdf">Departmental Privacy Standards for Commerce Data Loss Prevention (DLP) Security Tools</a> - this memorandum establishes the requirement for all bureaus/operating units (BOUs) to configure their DLP security tools to implement privacy control capabilities that meet Departmental privacy DLP standards.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/doc_ssn_justification_process_memo_2017.pdf">DOC Social Security Numbers (SSNs) Justification Process Memorandum</a> - As part of Commerce's ongoing SSN reduction effort, this memorandum documents the process requirements for justifying SSN collections.</li> <li><a data-entity-substitution="canonical" data-entity-type="media" data-entity-uuid="03b70b30-5d36-491f-88b5-18ea903611cf" href="//www.commerce.gov/opog/privacy/USMDL"><em>DOC Un-redacted SSN Mailed Documents Listing (USMDL)</em></a> - the Department's approved list of designated documents for which the inclusion of SSN is determined to be necessary to fulfill a compelling Department business need when the documents are requested by individuals outside the Department or other Federal agencies, as determined jointly by the Senior Agency Official for Privacy (SAOP) and the Departmental Privacy Act Officer.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/omb_14-04_ato_memo_11182014.pdf">Issuance of an Authorization to Operate (ATO)</a> - this memorandum documents Commerce Policy regarding 1) implementing National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Revision 4, Appendix J Privacy Controls; and 2) SAOP Approval as a precondition for the issuance of an ATO.</li> <li><a href="//www.commerce.gov/sites/default/files/opog/memo_notifying_mgmt_ofcls_2015.pdf">Notifying Management Officials</a> - This memorandum contains the procedures on notifying officials on individuals (employees and contractors) who fail to safeguard sensitive personally Identifiable Information (PII).</li> </ul><h2><a id="BOUPP" name="BOUPP"></a>Bureau/Operating Unit Privacy Policies</h2> <ul><li><u><a href="//www.commerce.gov/page/privacy-policy" rel="noreferrer">Commerce Privacy Policy</a></u></li> <li><a href="http://www.bea.gov/about/Privacy_Statement.htm" target="_blank" rel="noopener noreferrer">Bureau of Economic Analysis (BEA) Privacy Policy</a><u> </u></li> <li><a href="http://www.bis.doc.gov/PrivacyInfo.html" target="_blank" rel="noopener noreferrer">Bureau of Industry and Security (BIS) Privacy Policy</a><u> </u></li> <li><a href="http://www.census.gov/privacy/" target="_blank" rel="noopener noreferrer">Bureau of the Census Privacy Policy</a><u> </u></li> <li><a href="//www.commerce.gov/page/privacy-policy" target="_blank" rel="noopener noreferrer">Economic Development Administration (EDA) Privacy Policy</a><u> </u></li> <li><a href="http://www.esa.gov/privacy-policy" rel="noreferrer">Economics and Statistics Administration (ESA) Privacy Policy</a><u> </u></li> <li><a href="http://trade.gov/privacy.asp" target="_blank" rel="noopener noreferrer">International Trade Administration (ITA) Privacy Policy</a><u> </u></li> <li><a href="http://www.mbda.gov/privacy-policy" target="_blank" rel="noopener noreferrer">Minority Business Development Agency (MBDA) Privacy Policy</a><u> </u></li> <li><a href="http://www.noaa.gov/protecting-your-privacy" rel="noreferrer">National Oceanic and Atmospheric Administration (NOAA) Privacy Policy</a></li> <li><a href="https://www.nist.gov/privacy-policy#privpolicy" rel="noreferrer">National Institute of Standards and Technology Privacy Policy</a></li> <li><a href="https://www.ntia.doc.gov/page/2011/ntia-privacy-policy" rel="noreferrer">National Telecommunications and Information Administration (NTIA) Privacy Policy</a></li> <li><a href="https://www.ntis.gov/privacy/" rel="noreferrer">National Technical Information Service (NTIS) Privacy Policy</a><u> </u></li> <li><a href="https://www.oig.doc.gov/pages/Privacy-Policy.aspx" rel="noreferrer">Office of Inspector General (OIG) Privacy Policy</a></li> <li><a href="//www.commerce.gov/page/privacy-policy" rel="noreferrer">Office of the Secretary (OS) Privacy Policy</a></li> <li><a href="https://www.uspto.gov/privacy-policy" rel="noreferrer">United States Patent and Trademark Office</a></li> </ul></div> </div> </article> </div> </div> </div> </div> </div> </main> <footer class="usa-footer usa-footer--big" role="contentinfo"> <div class="usa-grid usa-footer-return-to-top"> <a href="#">Return to top</a> </div> <div class="usa-footer__secondary-section"> <div class="grid-container"> <div class="grid-row grid-gap"> <div class="usa-footer__logo grid-row mobile-lg:grid-col-6 mobile-lg:grid-gap-2"> <div class="mobile-lg:grid-col-auto"> <a href="/"> <img class="usa-footer__logo-img" src="/themes/custom/commerce/assets/img/doc_logo.png" width="80" height="80" alt="Department of Commerce logo"/> </a> </div> <div class="mobile-lg:grid-col-auto"> <div class="footer-address"> 1401 Constitution Ave NW<br/> Washington, DC 20230 </div> </div> </div> <div class="usa-footer__contact-links mobile-lg:grid-col-6"> <div class="usa-footer__social-links grid-row"> <a href="https://twitter.com/commercegov" aria-label="U. S. Department of Commerce Twitter page"> <span class="fa-layers fa-fw usa-social_link x_twitter_social_link"> <svg xmlns="http://www.w3.org/2000/svg" width="30" height="30" fill="currentColor" class="bi bi-twitter-x" viewBox="0 0 16 16"> <path d="M12.6.75h2.454l-5.36 6.142L16 15.25h-4.937l-3.867-5.07-4.425 5.07H.316l5.733-6.57L0 .75h5.063l3.495 4.633L12.601.75Zm-.86 13.028h1.36L4.323 2.145H2.865z"/></svg> </span> </a> <a href="https://www.facebook.com/Commercegov/" aria-label="U. S. Department of Commerce Facebook page"> <span class="fa-layers fa-fw usa-social_link"> <i class="fas fa-square fa-2x" style="color:white" alt="Department of Commerce Facebook page" aria-label="Department of Commerce Facebook page"></i> <i title="Facebook" class="fab fa-facebook-square fa-2x" style="color:#3b5998"></i> </span> </a> <a href="https://www.linkedin.com/company/u-s--department-of-commerce" aria-label="Department of Commerce Linkedin page"> <span class="fa-layers fa-fw usa-social_link"> <i class="fas fa-square fa-2x" style="color:white" alt="Department of Commerce Linkedin page" aria-label="Department of Commerce Linkedin page"></i> <i title="LinkedIn" class="fab fa-linkedin fa-2x" style="color:#0077b5"></i> </span> </a> <a href="https://www.youtube.com/channel/UCDk7XARReoJChTwu1WojgRQ" aria-label="U. S. Department of Commerce YouTube page"> <span class="fa-layers fa-fw usa-social_link"> <i class="fas fa-square fa-2x" style="color:white" alt="Department of Commerce YouTube page" aria-label="Department of Commerce YouTube page"></i> <i title="YouTube" class="fab fa-youtube-square fa-2x" style="color:#ff0000"></i> </span> </a> <a href="/rss" aria-label="Department of Commerce rss feed"> <span class="fa-layers fa-fw usa-social_link"> <i class="fas fa-square fa-2x" style="color:white" alt="Department of Commerce rss feed" aria-label="Department of Commerce rss feed"></i> <i title="RSS" class="fas fa-rss-square fa-2x" style="color:#ffA500"></i> </span> </a> </div> </div> </div> <div class="grid-row grid-gap"> <div class="mobile-lg:grid-col-12"> <div class="region region-footer-secondary"> <ol class="dotsbetween"> <li> <a href="/archives">Archives</a> </li> <li> <a href="/about/policies/accessibility">Accessibility</a> </li> <li> <a href="/ofm/agency-financial-reports">Agency Financial Report</a> </li> <li> <a href="/about/policies/comments">Comment policy</a> </li> <li> <a href="/digitalstrategy">Digital strategy</a> </li> <li> <a href="/about/policies/information-quality">Information quality</a> </li> <li> <a href="/cr/reports-and-resources/no-fear-act">No Fear Act</a> </li> <li> <a href="https://www.oig.doc.gov/">Inspector General</a> </li> <li> <a href="/about/policies/plain-language">Plain language</a> </li> <li> <a href="/about/policies/privacy">Privacy policy</a> </li> <li> <a href="https://www.commerce.gov/ofm/payment-integrity/department-commerce-payment-integrity-website">Payment Integrity</a> </li> <li> <a href="https://www.usa.gov/">USA.gov</a> </li> <li> <a href="https://www.vote.gov">Vote.gov</a> </li> <li> <a href="/vulnerability-disclosure-policy">Vulnerability Disclosure Policy</a> </li> <li> <a href="https://www.oig.doc.gov/Pages/Hotline.aspx">Whistleblower Protection</a> </li> <li> <a href="https://www.whitehouse.gov/">WhiteHouse.gov</a> </li> </ol> <div id="block-govdeliverysignup-fixed-block" class="block block-fixed-block-content block-fixed-block-contentgovdelivery-sign-up-fixed-block"> <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item"><form accept-charset="UTF-8" action="https://public.govdelivery.com/accounts/USDOC/subscribers/qualify" id="GD-snippet-form" method="post"> <input name="utf8" type="hidden" value="✓" /> <input name="authenticity_token" type="hidden" value="KYi9hmgKqvcMOKf453K61tlo2i3pCo8sVKFUH73sfXB1gecwmSLcalxpsqf6Vj4zDIv5vztIijVjsn5SGnDrfw==" /> <fieldset> <legend> Sign up for email updates </legend> <div> <p>To sign up for updates or to access your subscriber preferences, please enter your contact information below.</p> </div> <ol class="form"> <li class="email_fields" style="display: block"><label for="email"><img alt="Required" class="required" src="https://content.govdelivery.com/images/required.gif" />Email Address</label><br /> <input class="long" id="email" name="email" type="text" /></li> </ol> <div class="button_panel"> <input class="form-button usa-button" name="commit" type="submit" value="Subscribe" /></div> </fieldset> </form> </div> </div> </div> </div> </div> </div> </div> </footer> </div> <script type="application/json" data-drupal-selector="drupal-settings-json">{"path":{"baseUrl":"\/","scriptPath":null,"pathPrefix":"","currentPath":"node\/4666","currentPathIsAdmin":false,"isFront":false,"currentLanguage":"en","currentQuery":{"q":"\/opog\/privacy\/privacy-laws-policies-and-guidance"}},"pluralDelimiter":"\u0003","suppressDeprecationErrors":true,"ajaxPageState":{"libraries":"back_to_top\/back_to_top_icon,back_to_top\/back_to_top_js,classy\/base,classy\/messages,commerce\/accessibility,commerce\/digital_analytics_program,commerce\/footer,commerce\/govdelivery,commerce\/header,commerce\/offices,commerce\/openid_connect,commerce\/uswds,core\/drupal.dialog.ajax,core\/normalize,custom\/offices,extlink\/drupal.extlink,fontawesome\/fontawesome.svg,fontawesome\/fontawesome.svg.shim,google_analytics\/google_analytics,system\/base,uswds\/drupal,uswds\/footer,uswds\/header,uswds\/uswds","theme":"commerce","theme_token":null},"ajaxTrustedUrl":[],"back_to_top":{"back_to_top_button_trigger":100,"back_to_top_prevent_on_mobile":false,"back_to_top_prevent_in_admin":false,"back_to_top_button_type":"image","back_to_top_button_text":"Back to top"},"google_analytics":{"account":"G-43SPHKNB7Z","trackOutbound":true,"trackMailto":true,"trackTel":true,"trackDownload":true,"trackDownloadExtensions":"7z|aac|arc|arj|asf|asx|avi|bin|csv|doc(x|m)?|dot(x|m)?|exe|flv|gif|gz|gzip|hqx|jar|jpe?g|js|mp(2|3|4|e?g)|mov(ie)?|msi|msp|pdf|phps|png|ppt(x|m)?|pot(x|m)?|pps(x|m)?|ppam|sld(x|m)?|thmx|qtm?|ra(m|r)?|sea|sit|tar|tgz|torrent|txt|wav|wma|wmv|wpd|xls(x|m|b)?|xlt(x|m)|xlam|xml|z|zip"},"data":{"extlink":{"extTarget":false,"extTargetNoOverride":false,"extNofollow":false,"extNoreferrer":false,"extFollowNoOverride":false,"extClass":"ext","extLabel":"(link is external)","extImgClass":false,"extSubdomains":true,"extExclude":".\\.gov","extInclude":"","extCssExclude":".usa-footer-contact-links a, .usa-footer__social-links a","extCssExplicit":"","extAlert":true,"extAlertText":"The United States Department of Commerce\r\n\r\nYou are now leaving a Department of Commerce Web site.\r\n\r\nThe Department of Commerce does not endorse the organizations or views represented by this site and takes no responsibility for, and exercises no control over, the accuracy, accessibility, copyright or trademark compliance or legality of the material contained on this site. Thank you for visiting our site.","mailtoClass":"mailto","mailtoLabel":"(link sends email)","extUseFontAwesome":false,"extIconPlacement":"append","extFaLinkClasses":"fa fa-external-link","extFaMailtoClasses":"fa fa-envelope-o","whitelistedDomains":[]}},"user":{"uid":0,"permissionsHash":"e9a22412fbff4b4af13117b9144b0dd2d0e2af631e1c0e8982e0e8845f07503d"}}</script> <script src="/sites/default/files/js/js_hW63Fut6k7ky8K_Ex0QpaVH_cUEVgN7HbLQc953_4pI.js"></script> <script src="/sites/default/files/js/js_kcBrTxnzjmhVKfnoVhm9paNB6H8-eQrjLC3u-TGj2wU.js"></script> <script src="/sites/default/files/js/js_XJRvibceJbDsOko_9SyiFm0HzNtH4Fudxarp397y2uM.js"></script> <script src="//content.govdelivery.com/overlay/js/1374.js"></script> <script src="//dap.digitalgov.gov/Universal-Federated-Analytics-Min.js?agency=DOC" id="_fed_an_ua_tag"></script> <script src="/sites/default/files/js/js_oiyrtTNxaFHw-ixjOaWbF1n-7lcbNYq__065GP4TAiE.js"></script> </body> </html>