US Codex
C.F.R.
Browse by date
Notes

28 C.F.R. §§ 16.41–16.45

5 sections in range

§16.41. Privacy Act requests for access to records.

28 C.F.R. § 16.41

(a)
General information.
(1)
The Department has a decentralized system for responding to Privacy Act requests for access to records, with each component designating an office to process Privacy Act requests for access to records maintained by that component. A requester may make a Privacy Act request for access to records about the requester by writing directly to the component that maintains the records. All components have the capability to receive requests electronically either through email or a web portal. The request should be sent or delivered to the component's office at the address listed in appendix I to this part, or in accordance with the access procedures outlined in the corresponding SORN. The functions of each component are summarized in part 0 of this title and in the description of the Department and its components in the United States Government Manual, which is updated on a year-round basis and is available free of charge at https://www.usgovernmentmanual.gov/.
(2)
If a requester cannot determine where within the Department to send the Privacy Act request for access to records, the requester may send it by mail to the FOIA/PA Mail Referral Unit, Justice Management Division, Department of Justice, 950 Pennsylvania Avenue NW, Washington, DC 20530-0001; by email to [email protected]; or by fax to (202) 616-6695. The Mail Referral Unit will forward the request to the component(s) it believes most likely to have the requested records. For the quickest possible handling, the requester should mark both the request letter and the envelope “Privacy Act Access Request.”
(b)
Description of records sought. Requesters must describe the records sought in sufficient detail to enable Department personnel to locate the applicable system of records containing them with a reasonable amount of effort. To the extent possible, requesters should include specific information that may assist a component in identifying the requested records, such as the name or identifying number of each system of records in which the requester believes the records are maintained, or the date, title, name, author, recipient, case number, file designation, reference number, or subject matter of the record. The Department publishes SORNs in the Federal Register that describe the type and categories of records maintained in Department-wide and component-specific systems of records. Department SORNs may be found in published issues of the Federal Register and a list is available at https://www.justice.gov/opcl/doj-systems-records. Requesters may also request the record in a particular form or format.
(c)
Agreement to pay fees. A Privacy Act request for access may specify the amount of fees that the requester is willing to pay in accordance with § 16.49. The component responsible for responding to the request shall confirm this agreement in an acknowledgement letter, in accordance with § 16.43.
(d)
Verification of identity.
(1)
A requester must verify the requester's identity when making a Privacy Act request for access. The requester must state the requester's full name, current address, and date and place of birth. The requester must:
(i)
Sign the request, and the signature must either be notarized or submitted by the requester under 28 U.S.C. 1746, a law that permits statements to be made under penalty of perjury as a substitute for notarization; or
(ii)
When available, use one of the Department's approved digital services, as indicated on the Department's Privacy Act Request web page, to verify the identity of the requester through identity proofing and authentication processes.
(2)
While no specific form is required, the requester may obtain forms for this purpose from the FOIA/PA Mail Referral Unit, Justice Management Division, Department of Justice, 950 Pennsylvania Avenue NW, Washington, DC 20530-0001, or obtain the form at https://www.justice.gov/oip/doj-reference-guide-attachment-d-copies-forms.
(3)
To help identify and locate requested records, a requester may also include, at the requester's option, any additional identifying information which may be helpful in identifying and locating the requested records. Components shall establish appropriate administrative, technical, and physical safeguards to ensure the security and confidentiality of information provided by the requester, and to protect against any anticipated threats, in accordance with § 16.51.
(e)
Verification of guardianship.
(1)
The parent of a minor, or the legal guardian of an individual who has been declared incompetent due to physical or mental incapacity or age by a court of competent jurisdiction, is permitted to act on behalf of the individual. In order for a parent of a minor or the legal guardian of an individual to make a Privacy Act request for access on behalf of the individual, the parent or legal guardian must establish:
(i)
The identity of the individual who is the subject of the request, by stating the name, current address, date and place of birth, and, at the parent or legal guardian's option, any additional identifying information that may be helpful in identifying and locating the requested records;
(ii)
The parent or legal guardian's own identity, as required in paragraph (d) of this section;
(iii)
Proof of parentage or legal guardianship, which may be proven by providing a copy of the individual's birth certificate or by providing a court order establishing legal guardianship; and
(iv)
That the parent or legal guardian is acting on behalf of that individual in making the request.
(2)
Components shall establish appropriate administrative, technical, and physical safeguards to ensure the security and confidentiality of information provided by the parent or legal guardian, and to protect against any anticipated threats, in accordance with § 16.51.
Notes, amendments, and revision history

Source

Source: AG Order No. 5851-2024, 89 FR 1450, Jan. 10, 2024, unless otherwise noted.

Authority

Authority: 5 U.S.C. 301, 552, 552a, 553; 28 U.S.C. 509, 510, 534; 31 U.S.C. 3717; 42 U.S.C. 405.

§16.42. Responsibility for responding to Privacy Act requests for access to records.

28 C.F.R. § 16.42

(a)
In general. Except as stated in paragraphs (c) through (f) of this section, the component that first receives a Privacy Act request for access is the component responsible for responding to the request. In determining which records are responsive to a request, a component ordinarily will include only those records it maintained as of the date the component begins its search. If any other date is used, the component shall inform the requester of that date.
(b)
Authority to grant or deny requests. The head of a component, or the component head's designee, is authorized to grant or deny any Privacy Act request for access to records maintained by that component.
(c)
Re-routing of misdirected requests. When a component's FOIA/Privacy Act office determines that a request was misdirected within the Department, the receiving component's FOIA/Privacy Act office shall route the request to the FOIA/Privacy Act office of the proper component(s).
(d)
Consultations, referrals, and coordination. When a component receives a Privacy Act request for access to a record in its possession, it shall determine whether another component, or another agency of the Federal Government, is better able to determine whether the record is exempt from access under the Privacy Act. If the receiving component determines that it is best able to process the record in response to the request, then it shall do so. If the receiving component determines that it is not best able to process the record, then it shall follow the consultation, referral, and coordination procedures under § 16.4, subject to the requirements in this section. Components may make agreements with other components or agencies to eliminate the need for consultations or referrals for particular types of records.
(e)
Consultations, referrals, and coordination concerning law enforcement information. When a component receives a Privacy Act request for access to a record in its possession containing information that relates to an investigation of a possible violation of law and that originated with another component or agency of the Federal Government, the receiving component shall either refer the responsibility for responding to the request regarding that information to that other component or agency or shall consult with that other component or agency.
(f)
Consultations, referrals, and coordination concerning classified information.
(1)
When a component receives a Privacy Act request for access to a record containing information that has been classified or may be appropriate for classification by another component or agency under any applicable Executive order concerning the classification of records, the receiving component shall consult with or refer the responsibility for responding to the request regarding that information to the component or agency that classified the information, or that should consider the information for classification.
(2)
When a component receives a Privacy Act request for access to a record containing information that has been derivatively classified, the receiving component shall consult with or refer the responsibility for responding to that portion of the request to the component or agency that classified the underlying information.
Notes, amendments, and revision history

Source

Source: AG Order No. 5851-2024, 89 FR 1450, Jan. 10, 2024, unless otherwise noted.

Authority

Authority: 5 U.S.C. 301, 552, 552a, 553; 28 U.S.C. 509, 510, 534; 31 U.S.C. 3717; 42 U.S.C. 405.

§16.43. Responses to a Privacy Act requests for access to records.

28 C.F.R. § 16.43

(a)
In general. Components should, to the extent practicable, communicate with requesters who have access to the internet using electronic means, such as through email or a web portal. A component shall honor a requester's preference for receiving a record in a particular form or format where it is readily reproducible by the component in the form or format requested.
(b)
Acknowledgement of requests. The component responsible for responding to the request must acknowledge, in writing, receipt of a Privacy Act request for access. A component shall initially respond to the requester by acknowledging the Privacy Act request for access, assigning the request an individualized tracking number, and, if applicable, confirming, in writing, the requester's agreement to pay fees in accordance with § 16.49.
(c)
Timing of responses to a Privacy Act request for access.
(1)
Components ordinarily will respond to Privacy Act requests for access according to their order of receipt. The response time will commence on the date that the request is received by the proper component's office designated to receive requests, but in any event not later than ten (10) working days after the request is first received by any component's office designated by this subpart to receive requests.
(2)
A component may designate multiple processing tracks that distinguish between simple and more complex Privacy Act requests for access, based on the estimated amount of work or time needed to process the request. Among the factors a component may consider are the number of pages involved in processing the request and the need for consultations or referrals. Components may advise requesters of the track into which their request falls and, when appropriate, may offer requesters an opportunity to narrow their request so that it can be placed in a different processing track.
(d)
Granting a Privacy Act request for access. Once a component makes a determination to grant a Privacy Act request for access, in whole or in part, it shall notify the requester in writing. The component shall inform the requester in the notice of any fee charged under § 16.49 and shall disclose records to the requester promptly on payment of any applicable fee.
(e)
Adverse determination to a Privacy Act request for access. A component that makes an adverse determination to a Privacy Act request for access, in whole or in part, shall notify the requester of the adverse determination in writing. An adverse determination to a Privacy Act request for access includes a determination by the component that: the request did not reasonably describe the record sought; the information requested is not a record subject to the Privacy Act; the requested record is not maintained in a system of records; the requested record is exempt, in whole or in part, from a Privacy Act request for access under applicable exemption(s); the requested record does not exist, cannot be located, or has been destroyed; the record is not readily reproducible in a comprehensible form; or there is a matter regarding disputed fees.
(f)
Content of adverse determination response. An adverse determination to a Privacy Act request for access, in whole or in part, shall be signed by the head of the component, or the component head's designee, and shall include:
(1)
The name and title or position of the person responsible for the adverse determination to the Privacy Act request for access;
(2)
A brief statement of the reason(s) for the adverse determination to the Privacy Act request for access, including any Privacy Act exemption(s) applied by the component;
(3)
An estimate of the volume of any records or information withheld, if applicable, such as the number of pages or some other reasonable form of estimation, although such an estimate is not required if the volume is otherwise indicated or if providing an estimate would harm an interest protected by an applicable exemption; and
(4)
A statement that the adverse determination to the Privacy Act request for access may be appealed under § 16.45, and a description of the requirements set forth in § 16.45.
Notes, amendments, and revision history

Source

Source: AG Order No. 5851-2024, 89 FR 1450, Jan. 10, 2024, unless otherwise noted.

Authority

Authority: 5 U.S.C. 301, 552, 552a, 553; 28 U.S.C. 509, 510, 534; 31 U.S.C. 3717; 42 U.S.C. 405.

§16.44. Classified information.

28 C.F.R. § 16.44

In processing a Privacy Act request for access, a Privacy Act request for amendment or correction, or a Privacy Act request for accounting, in which information is classified under any applicable Executive order concerning the classification of records, to the extent the requester lacks the appropriate security clearance and fails otherwise to meet all requirements to access the classified record or information, the originating component shall review the information in the record to determine whether it should remain classified. Information determined to no longer require classification shall be de-classified and the record evaluated for an appropriate release to the requester, subject to any applicable exemptions or exceptions. On receipt of any appeal involving classified information, the official responsible for adjudicating the appeal shall take appropriate action to ensure compliance with part 17 of this title.
Notes, amendments, and revision history

Source

Source: AG Order No. 5851-2024, 89 FR 1450, Jan. 10, 2024, unless otherwise noted.

Authority

Authority: 5 U.S.C. 301, 552, 552a, 553; 28 U.S.C. 509, 510, 534; 31 U.S.C. 3717; 42 U.S.C. 405.

§16.45. Privacy Act access appeals.

28 C.F.R. § 16.45

(a)
Requirement for making a Privacy Act access appeal. A requester may appeal an adverse determination to a Privacy Act request for access to the Office of Information Policy (“OIP”). The contact information for OIP is contained in the FOIA Reference Guide, which is available at https://www.justice.gov/oip/04_3.html. Appeals may also be submitted through the web portal accessible on OIP's website. Examples of an adverse determination to a Privacy Act request for access are provided in § 16.43. The requester must make the appeal in writing. To be considered timely, the requester must postmark, or in the case of electronic submissions, submit the request, within 90 calendar days after the date of the adverse determination. The appeal should indicate the assigned request number and clearly identify the component's determination that is being appealed. To facilitate handling, the requester should mark both the appeal letter and envelope, or include in the subject line of any electronic communication, “Privacy Act Access Appeal.”
(b)
Adjudication of Privacy Act access appeals.
(1)
The Director of OIP, or a designee of the Director of OIP, shall act on behalf of the Attorney General on all Privacy Act access appeals under this section, unless the Attorney General directs otherwise.
(2)
Should the Attorney General exercise the right to respond to a Privacy Act request for access, the Attorney General's decision shall serve as the final action of the Department and will not be subject to a Privacy Act access appeal.
(3)
A Privacy Act access appeal ordinarily will not be adjudicated if the request becomes a matter of litigation.
(c)
Responses to Privacy Act access appeals.
(1)
OIP shall make its decision on an appeal in writing.
(2)
A decision that upholds a component's adverse determination to the Privacy Act request for access, in whole or in part, shall include a brief statement of the reason(s) for the affirmance, including any Privacy Act exemption applied, and shall provide the requester with notification of the statutory right to file a lawsuit.
(3)
A decision that reverses or modifies, in whole or in part, a component's adverse determination to the Privacy Act request for access shall include notice to the requester of the specific reversal or modification. The component(s) shall thereafter further process the request, in accordance with the appeal decision, and respond directly to the requester, as appropriate.
(d)
When a Privacy Act access appeal is required. Before seeking review by a court of a component's refusal to grant a Privacy Act request for access, a requester generally must first submit a timely appeal in accordance with this section.
Notes, amendments, and revision history

Source

Source: AG Order No. 5851-2024, 89 FR 1450, Jan. 10, 2024, unless otherwise noted.

Authority

Authority: 5 U.S.C. 301, 552, 552a, 553; 28 U.S.C. 509, 510, 534; 31 U.S.C. 3717; 42 U.S.C. 405.