Establishing secure connection…Loading editor…Preparing document…

Privacy Act Handbook

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HUD Privacy Act Handbook

Directive Number: Revision:

U.S. Department of Housing and Urban Development

Office of Administration

Table of Contents

This handbook contains chapters, appendices, exhibits, and procedural guidance related to the Privacy Act of 1974 and related Departmental procedures.

Chapter 1. Introduction to the Handbook

1-1 Purpose.

1-2 Records Subject to the Privacy Act.

1-3 HUD Employees and the Privacy Act.

1-4 Citations and References.

1-5 Definitions.

Chapter 2. Introduction to the Privacy Act

2-1 Necessity.

2-2 Purpose.

2-3 Departmental Policy.

2-4 Your Responsibilities.

2-5 Criminal Penalties.

Chapter 3. Procedures for Processing and Monitoring Requests for Records Subject to the Privacy Act

3-1 Introduction.

3-2 Personnel involved in Privacy Act activities.

3-3 Relationship between the Privacy Act and the Freedom of Information Act.

3-4 Choosing the Appropriate Act.

3-5 Exemptions from the Privacy Act.

3-6 Conditions of Disclosure.

3-7 Accounting for Certain Disclosures.

3-8 Inquiries concerning Systems of Records.

3-9 Individual Requests for Access to Information Maintained in Systems of Records.

3-10 Verification of Identity.

3-11 Disclosure of Requested Information to Individuals.

3-12 Initial Denial of Access to Records.

3-13 Appeal of Initial Denial of Access to Records.

3-14 Request for Correction or Amendment to a Record.

3-15 Criteria for Considering a Request for Correction or Amendment.

3-16 Initial Denial to Correct or Amend a Record.

3-17 Appeal from Initial Denial to Correct or Amend a Record.

3-18 Reproduction Fees.

Chapter 4. Establishing and Managing Privacy Act Systems of Records

4-1 Introduction.

4-2 Responsibilities of the System Manager.

4-3 Situations Requiring a Report and Federal Register Notice.

4-4 Contents of the New or Altered System Report.

4-5 Timing, OMB Concurrence, and Publication of the Federal Register Notice.

Chapter 5. Computer Matching Programs

5-1 General.

5-2 Definitions.

5-3 The Data Integrity Board.

5-4 Conducting Matching Programs.

5-5 Due Process for Matching Subjects.

Chapter 6. Application of the Privacy Act to Other Related Functions

6-1 Introduction.

6-2 Automated Data Reporting Systems.

6-3 ADP Security.

6-4 Procurement of Computer Equipment and Systems.

6-5 Procurement and Contracts.

6-6 Forms and Reports Management.

6-7 The Privacy Conscience of the Department.

Chapter 7. Reporting Requirements

7-1 Introduction.

7-2 Examples of Privacy Act Reviews.

7-3 Privacy Act Reports.

Appendices

A. Privacy Act Case Log

B. Privacy Act Officers' Locations

C. Privacy Act of 1974 (as amended)

D. Appeal Procedures

E. Responsibilities of Privacy Act Systems Managers

F. Computer Matching Programs Timetable

G. Guidelines for Establishing Safeguards for Records Subject to the Privacy Act

H. Guide to the Privacy Act of 1974 and the Departmental Privacy Act Regulations

I. Privacy Act Systems of Records

List of Exhibits

3-1 Sample Letter to Inform Individual of a Request for Access to his Personal Information.

3-2 Sample Form to Obtain Consent to Disclose Personal Information.

3-3 Sample Form for Recording Accounting Disclosures.

3-4 Sample Privacy Act Request Letter.

3-5 Sample Letter Informing Requester of Transfer of Privacy Act Request to Appropriate HUD Office.

3-6 Sample Letter Used to Obtain Additional Information.

3-7 Sample Record Search Information Log.

3-8 Sample Letter for Privacy Act Processing Over 10 Days.

3-9 Sample Letter to Inform Requester of Departmental Action.

3-10 Sample Statement of Identity.

3-11 Sample Requester's Authorization for an Accompanying Individual.

4-1 Sample of a New System of Records Notice.

4-2 Sample of an Altered or Amended System of Records Notice.


Chapter 1. Introduction to the Handbook

1-1 Purpose. This Handbook has two main goals.

A. To provide every employee of the Department with information on their rights and responsibilities under the Privacy Act.

B. To establish policies, procedures, requirements and guidelines for the implementation of the Department's Privacy Act responsibilities.

1-2 Records Subject to the Privacy Act. A group of records is subject to the Privacy Act if it satisfies all three of the following criteria:

A. Contains an item, collection, or grouping of information about an individual.

B. Contains name, or identifying number, symbol, or other identifying particular assigned to the individual such as a finger or voice print.

C. Consists of a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.

1-3 HUD Employees and the Privacy Act. The Privacy Act imposes requirements on staff members performing in different roles.

1-4 Citations and References.

THE PRIVACY ACT OF 1974 (As Amended)

Public Law 93-579

Title 5, United States Code, Section 552a

Computer Matching and Privacy Protection Act

Public Law 100-503

IMPLEMENTATION OF THE PRIVACY ACT OF 1974

Rules and Regulations

Title 24, Subtitle A, Code of Federal Regulations, Part 16

1-5 Definitions.

This section includes defined terms such as Accounting, Access, Agency, Appeal, Denial of access or correction, Department, Disclosure, Individual, Inquiry, Maintain, Privacy Act, Privacy Act Request, Record, Request for access, Request for correction or amendment, Routine use, Statistical record, System Manager, and System of records.


Sample Form Fields

The following fields represent common items appearing in the sample letters, logs, and request forms shown in the handbook excerpts.

Case Number:

Name:

Address:

Telephone Number:

Social Security Number:

Date of Inquiry:

Date of Request:

Date of Denial:

Effective Date:

Relationship with HUD at time record was created:

Additional Information:

Reason for Request:

Description of Requested Record:

Basis for Correction or Amendment:

Specific Wording to Delete:

Specific Wording to Add:

Date when record was created:

Current Address when record was created:

Privacy Act Notice Acknowledgment: I acknowledge the notice.

Consent to Disclose Personal Information: Grant consent

Refuse Consent to Disclose Personal Information: Refuse consent

System of Records Name:

System Manager Name:

System Manager Address:

Requester Signature:

Date:

Privacy Act Officer Signature:

Date:

Witness Signature:

Date:

Supporting Checklist

Request submitted in writing.

Identity verified.

Supporting documents attached.

Appeal requested.

Fee required.

Notes

Enter text✕

What the Privacy Act Handbook Covers

The Privacy Act Handbook is an operational guide agencies use to apply the Privacy Act of 1974 (5 U.S.C. §552a). It explains how to inventory and describe systems of records, collect and maintain personally identifiable information, process access and amendment requests, manage routine uses, and coordinate with Freedom of Information Act procedures. The handbook outlines role-based responsibilities, procedural safeguards, recordkeeping expectations, and sample forms and notices that help agencies meet statutory duties while protecting individual privacy and ensuring consistent practice across programs.

Why a Handbook Matters for Privacy Compliance

A concise Privacy Act Handbook reduces legal risk by standardizing how records are collected, disclosed, and amended under 5 U.S.C. §552a, promotes transparency for individuals, and documents internal controls for oversight and audits.

Why a Handbook Matters for Privacy Compliance

Who Uses the Privacy Act Handbook

The handbook is written for staff who create, manage, or respond to requests about agency records.

  • Privacy Officers and FOIA/Privacy staff who draft policy and respond to access/amendment requests.
  • Records Managers responsible for retention schedules, system of records notices, and secure storage.
  • Legal Counsel and program leads who review disclosures, exemptions, and cross-agency data sharing.

It also supports legal reviewers, privacy officers, and records managers who must document and defend agency practices.

Step-by-Step: Preparing a Privacy Act Response

Follow a consistent, documented sequence to acknowledge, verify, gather records, and deliver a response under agency procedures.

  • 01
    Acknowledge: Confirm receipt and provide point of contact.
  • 02
    Verify Identity: Use acceptable ID or process before releasing records.
  • 03
    Gather Records: Search relevant systems and compile responsive materials.
  • 04
    Respond: Provide records or denial with statutory basis.

Digital Workflow Configuration for Requests

Map each workflow setting to a control objective: authentication, access, disclosure logging, retention, and escalation.

Field Configuration
Authentication Multi-factor or credential analysis for identity proofing
Access Controls Role-based permissions and least-privilege enforcement
Disclosure Logging Automated audit trail with timestamps and recipient
Retention Schedule Automated application of disposition rules

Platform and Format Requirements

Choose platforms that preserve audit trails, secure data at rest and in transit, and support required export formats.

  • File Formats: PDF/A, DOCX, or exportable CSV
  • Integrations: Connectors to document repositories
  • Authentication: Supports MFA and KBA

How an Electronic Request and Response Flow Works

An online request workflow should capture requester data, verify identity, collect records, apply redaction, and deliver an auditable response.

  • Submit: Requester completes online form and attaches ID if required.
  • Verify: Agency verifies identity per published procedures.
  • Assemble: Search systems of records and gather responsive files.
  • Deliver: Send records with audit trail and redactions as needed.

Timelines and Typical Processing Targets

Agencies should set clear internal targets aligned with statutory standards and communicate expected timeframes to requesters.

Acknowledgment Target:

Acknowledge receipt within 10 business days to set expectations.

Substantive Response:

Complete response within 30 calendar days absent complexities.

FOIA Coordination:

FOIA responses default to 20 working days (5 U.S.C. §552(a)(6)).

Extensions:

Provide written notice for any extension and rationale.

Appeals Window:

Specify internal appeal period, commonly 30 days from notice.

Penalties and Key Risks

Unauthorized Disclosure: Civil liability under 5 U.S.C. §552a
Failure to Respond: Administrative sanctions and oversight findings
Recordkeeping Gaps: Loss of evidentiary support for decisions
Data Breach Costs: Remediation and notification expenses
Reputational Harm: Erodes public trust and stakeholder confidence
Criminal Exposure: Willful violations may trigger prosecution

Security Controls and Technical Baselines

Encryption In Transit: TLS 1.2/1.3
Encryption At Rest: AES-256
Audit & Controls: SOC 2 Type II reporting available
Regulatory Compliance: HIPAA support (BAA required)
Federal Records Support: 21 CFR Part 11 compatibility
Information Security: ISO 27001 certified

Common Preparation Mistakes to Avoid

  • Failing to map systems of records to published SORNs, which delays lawful disclosure decisions and invites administrative review.
  • Using vague routine-use language that permits overly broad disclosures rather than narrowly defined, purpose-limited sharing.
  • Not documenting identity-proofing steps before releasing records, causing potential unauthorized disclosures and liability.
  • Omitting retention and disposition instructions tied to official schedules, creating inconsistent retention and disposal practices.

eSignature Vendor Comparison for Handbook Workflows

Compare core vendor capabilities and pricing models commonly considered for document signing and records workflows; signNow is listed first per vendor convention.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No envelope cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

Frequently Asked Questions

Common operational and legal questions about the Privacy Act Handbook, record requests, and electronic handling are answered below.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users